pub struct RulesEnforcer { /* private fields */ }Expand description
Enforces persistent application rules against real cgroups.
Implementations§
Source§impl RulesEnforcer
impl RulesEnforcer
Sourcepub fn new(cfg: &Config) -> Self
pub fn new(cfg: &Config) -> Self
Compile the rules from config. Rules with unparseable limits are skipped (logged once) rather than failing the whole enforcer.
pub fn rule_count(&self) -> usize
Sourcepub fn reconcile(
&mut self,
mgr: &CgroupManager,
procs: &[ProcessInfo],
held_cgroups: &[String],
) -> Vec<RuleAction>
pub fn reconcile( &mut self, mgr: &CgroupManager, procs: &[ProcessInfo], held_cgroups: &[String], ) -> Vec<RuleAction>
Reconcile every rule once against procs, a snapshot of the user’s
processes (the daemon shares one /proc scan per tick between the
guard and this). Best-effort: a failure on one rule or PID is logged
and never aborts the others. Returns the actions that were applied
(useful for logging/tests). An EnsureCgroup whose cgroup already
carries the limits (same inode as at the last write, see
needs_ensure) writes nothing and is not reported.
held_cgroups is PolicyEngine::intervened_cgroups(): the cgroups
the freeze guard currently holds a freeze or cap intervention on
(D1 fix). A rule whose cgroup is in that set is skipped entirely for
the tick: RulesEnforcer and the guard both write to the same rule
cgroup (act-in-place makes rule cgroups first-class guard targets),
and rewriting memory.high on a cgroup the guard just capped would
silently revert the cap while leaving PolicyEngine believing it
still holds one.