Expand description
Freeze-guard engine: watch memory pressure and proactively freeze/soft-cap
the non-protected app driving the pressure before the system locks up, healing
itself once pressure clears. Pure engine + sampler live here; the daemon loop
lives in the rlm-guard binary.
Re-exports§
pub use effector::Effector;pub use journal::Journal;pub use policy::PolicyEngine;pub use sampler::Sampler;pub use systemd::SystemdUser;pub use types::Action;pub use types::Intervention;pub use types::Level;pub use types::ProcInfo;pub use types::PsiSource;pub use types::Sample;pub use types::Target;
Modules§
- cgfs
- effector
- Executes
Actions against real cgroups, acting in place on the cgroup a process already lives in (a systemd unit’s scope/service, or an existing rlm rule cgroup) rather than moving it into an ephemeralguard-<pid>cgroup. Every action is best-effort and logged; a failure must never panic or otherwise crash the daemon loop.applymay returnErrso the caller can log it, but a missingnotify-send(or any other notification failure) is never treated as an error. - history
- Intervention history: an append-only JSONL log of what the guard actually
did (freeze/thaw/cap/lift, and failed attempts), separate from the
write-ahead restore
super::journal::Journal. The journal exists to make crash-restore correct; this log exists so a human can see what happened, viarlm guard history(and, later, the GUI). - journal
- Write-ahead restore journal for freeze-guard interventions.
- lock
- Single-instance lock for
rlm-guard. Two guards would each sweep and rewrite the same journal and each hold up toMAX_HELD_APPSapps, so a second one must stop before it touches anything. - policy
- Pure policy state machine: the self-healing circuit breaker at the heart of the freeze guard.
- report
- Formats guard state into the plain-text lines
rlm guard statusandrlm guard historyprint. Pure string formatting only, so the CLI and (later) the GUI can share it instead of duplicating the layout. - resolve
- Pure target resolution: determines whether a victim cgroup should be frozen, capped, or protected based on its path and membership.
- sampler
- Reads memory pressure (PSI) and picks escalation candidates from a process snapshot. Pure reads; no decisions. The parsing is factored into small pure free functions so it can be unit-tested without touching the filesystem.
- service
- Reads the
rlm-guardsystemd user service’s own active/enabled state, sorlm guard statuscan say whether the daemon is actually running instead of only reporting what it would do. - systemd
- Blocking systemd user-bus (
org.freedesktop.systemd1) client used on the freeze-guard’s storm path as an alternative to fork+exec’ingsystemctl. - types
- Shared types for the freeze-guard engine. This is the stable contract that the Sampler, PolicyEngine, and Effector all code against.
Functions§
- guard_
file - Path of a guard state file named
name, in a per-user dir. - journal_
path try_journal_pathfor read-only callers such asrlm guard status. Returns an empty path when no per-user dir is known; reading it finds nothing, which is the right answer since no guard can have written it.- lock_
path - Path of the lock file that keeps a second
rlm-guardfrom running. It sits next to the journal it protects.Nonemeans no per-user dir is known (seeguard_file); the caller then runs without the lock. - try_
journal_ path - Path of the guard’s write-ahead restore journal, or
Nonewhen no per-user dir is known (seeguard_file). Without it the guard must not freeze or cap, since it could not guarantee a restore.