Expand description
Persistent application rules: keep matching processes in a shared per-app
cgroup with the rule’s limits, continuously reconciled by rlm-guard.
The decision logic (plan) is pure and takes an injected snapshot of the
currently-running processes plus the set of PIDs already placed, so it is
unit-testable without root. RulesEnforcer::reconcile wires that decision
to the caller’s process snapshot and a CgroupManager.
Structs§
- Compiled
Rule - A rule with its limits parsed once up front.
- Rules
Enforcer - Enforces persistent application rules against real cgroups.
Enums§
- Rule
Action - One reconcile decision for a single rule.
Functions§
- cgroup_
name_ for - Sanitize a rule name into the
app-<name>cgroup form, matching the CLI’s existing scheme (app-{name with '/' and ' ' replaced by '_'}). - needs_
ensure - Whether a rule cgroup’s limits must be (re)written.
recorded_inodeis the cgroup directory’s inode when the limits were last written,current_inodeits inode now (None: the cgroup does not exist). Limits are rewritten only when the cgroup is new or was recreated: writingmemory.highbelow current usage makes the writer reclaim synchronously, so rewriting unchanged limits every tick costs the daemon real work under exactly the pressure it exists to handle. - plan
- Pure planner: decide the actions for one rule given the current process snapshot, the PIDs already in this rule’s cgroup, and whether this rule’s cgroup currently has any process in it.