Skip to main content

Module guard

Module guard 

Source
Expand description

Freeze-guard engine: watch memory pressure and proactively freeze/soft-cap the non-protected app driving the pressure before the system locks up, healing itself once pressure clears. Pure engine + sampler live here; the daemon loop lives in the rlm-guard binary.

Re-exports§

pub use effector::Applied;
pub use effector::Effector;
pub use journal::Journal;
pub use policy::PolicyEngine;
pub use sampler::Sampler;
pub use systemd::SystemdUser;
pub use types::Action;
pub use types::Intervention;
pub use types::Level;
pub use types::ProcInfo;
pub use types::PsiSource;
pub use types::Sample;
pub use types::Target;

Modules§

cgfs
effector
Executes Actions against real cgroups, acting in place on the cgroup a process already lives in (a systemd unit’s scope/service, or an existing rlm rule cgroup) rather than moving it into an ephemeral guard-<pid> cgroup. Every action is best-effort and logged; a failure must never panic or otherwise crash the daemon loop. apply may return Err so the caller can log it. Desktop notifications are not sent from here: the daemon loop hands each applied action to guard::notify.
history
Intervention history: an append-only JSONL log of what the guard actually did (freeze/thaw/cap/lift, and failed attempts), separate from the write-ahead restore super::journal::Journal. The journal exists to make crash-restore correct; this log exists so a human can see what happened, via rlm guard history (and, later, the GUI).
journal
Write-ahead restore journal for freeze-guard interventions.
lock
Single-instance lock for rlm-guard. Two guards would each sweep and rewrite the same journal and each hold up to MAX_HELD_APPS apps, so a second one must stop before it touches anything.
notify
Desktop notifications for guard interventions.
policy
Pure policy state machine: the self-healing circuit breaker at the heart of the freeze guard.
report
Formats guard state into the plain-text lines rlm guard status and rlm guard history print. Pure string formatting only, so the CLI and (later) the GUI can share it instead of duplicating the layout.
resolve
Pure target resolution: determines whether a victim cgroup should be frozen, capped, or protected based on its path and membership.
sampler
Reads memory pressure (PSI) and picks escalation candidates from a process snapshot. Pure reads; no decisions. The parsing is factored into small pure free functions so it can be unit-tested without touching the filesystem.
service
Reads the rlm-guard systemd user service’s own active/enabled state, so rlm guard status can say whether the daemon is actually running instead of only reporting what it would do.
systemd
Blocking systemd user-bus (org.freedesktop.systemd1) client used on the freeze-guard’s storm path as an alternative to fork+exec’ing systemctl.
types
Shared types for the freeze-guard engine. This is the stable contract that the Sampler, PolicyEngine, and Effector all code against.

Functions§

guard_file
Path of a guard state file named name, in a per-user dir.
journal_path
try_journal_path for read-only callers such as rlm guard status. Returns an empty path when no per-user dir is known; reading it finds nothing, which is the right answer since no guard can have written it.
lock_path
Path of the lock file that keeps a second rlm-guard from running. It sits next to the journal it protects. None means no per-user dir is known (see guard_file); the caller then runs without the lock.
try_journal_path
Path of the guard’s write-ahead restore journal, or None when no per-user dir is known (see guard_file). Without it the guard must not freeze or cap, since it could not guarantee a restore.