pub struct Sampler { /* private fields */ }Expand description
Samples system pressure and the user’s eligible processes.
Implementations§
Source§impl Sampler
impl Sampler
Sourcepub fn new(
cfg: GuardConfig,
self_pid: u32,
uid: u32,
rlm_base: Option<String>,
) -> Self
pub fn new( cfg: GuardConfig, self_pid: u32, uid: u32, rlm_base: Option<String>, ) -> Self
self_pid is the guard’s own PID (always excluded). uid is the user
whose processes are eligible. rlm_base is
CgroupManager::base_path() with the /sys/fs/cgroup prefix
stripped (see strip_cgroup_root); None disables resolution
assembly entirely (fail closed — every process reports resolution: None, so the policy engine can never select an escalation victim).
Sourcepub fn sample(&self) -> Option<Sample>
pub fn sample(&self) -> Option<Sample>
Read current pressure. Prefers the user’s app.slice PSI (what the
processes the guard can act on actually feel) and falls back to system
PSI when that file is missing OR unreadable/unparseable. None if
neither is readable (e.g. a kernel built without CONFIG_PSI).
Sourcepub fn candidates(&self, snapshot: &[ProcessInfo]) -> Vec<ProcInfo>
pub fn candidates(&self, snapshot: &[ProcessInfo]) -> Vec<ProcInfo>
The escalation candidates in snapshot (normally
process::list_for_uid(uid), taken once per tick and shared with the
rules enforcer): owned by uid, not the guard itself, at least
min_rss_mb, and not protected (builtin + config protect-list, matched
on comm and on the untruncated exe basename). Sorted by rss_kb
descending.
Each candidate is named by its exe basename (comm fallback): Firefox
content processes have comm “Isolated Web Co” but run firefox.
Resolutions are cached per candidate cgroup, so N processes sharing
one cgroup cost a single member scan.