Skip to main content

Module rules

Module rules 

Source
Expand description

Persistent application rules: keep matching processes in a shared per-app cgroup with the rule’s limits, continuously reconciled by rlm-guard.

The decision logic (plan) is pure and takes an injected snapshot of the currently-running processes plus the set of PIDs already placed, so it is unit-testable without root. RulesEnforcer::reconcile wires that decision to the caller’s process snapshot and a CgroupManager.

Structs§

CompiledRule
A rule with its limits parsed once up front.
RulesEnforcer
Enforces persistent application rules against real cgroups.

Enums§

RuleAction
One reconcile decision for a single rule.

Functions§

cgroup_name_for
Sanitize a rule name into the app-<name> cgroup form, matching the CLI’s existing scheme (app-{name with '/' and ' ' replaced by '_'}).
needs_ensure
Whether a rule cgroup’s limits must be (re)written. recorded_inode is the cgroup directory’s inode when the limits were last written, current_inode its inode now (None: the cgroup does not exist). Limits are rewritten only when the cgroup is new or was recreated: writing memory.high below current usage makes the writer reclaim synchronously, so rewriting unchanged limits every tick costs the daemon real work under exactly the pressure it exists to handle.
plan
Pure planner: decide the actions for one rule given the current process snapshot, the PIDs already in this rule’s cgroup, and whether this rule’s cgroup currently has any process in it.