#[non_exhaustive]pub struct SupervisorEntry {Show 23 fields
pub module_id: String,
pub state: String,
pub enabled: bool,
pub live: bool,
pub protocol: ModuleProtocol,
pub launch_nonce_env: Option<bool>,
pub launch_nonce_source: Option<String>,
pub health: SupervisorHealthStatus,
pub pending_reload: Option<PendingReloadVerdict>,
pub last_probe_ms: Option<u64>,
pub last_exit_code: Option<i32>,
pub last_exit_signal: Option<i32>,
pub last_exit_ms: Option<u64>,
pub last_exit_kind: Option<TerminalExitKind>,
pub restart_count: Option<u32>,
pub max_restarts: Option<u32>,
pub lifetime_restarts: Option<u32>,
pub spawn_generation: Option<u64>,
pub restart_window_secs: Option<u64>,
pub drain_timeout_ms: Option<u64>,
pub restart_backoff_ms: Option<u64>,
pub restart_max_backoff_ms: Option<u64>,
pub resources: Option<ChildResourceUsage>,
}Expand description
A supervised module’s current state and process observations.
Use SupervisorEntry::new and its with_* methods to construct entries so
future fields do not require changes to callers.
Struct literals and functional record updates are not supported outside this crate:
use subc_control::{SupervisorEntry, SupervisorHealthStatus};
let entry = SupervisorEntry::new("provider", "running", true, true, SupervisorHealthStatus::Unknown);
let entry = SupervisorEntry { resources: None, ..entry };Fields (Non-exhaustive)§
This struct is marked as non-exhaustive
Struct { .. } syntax; cannot be matched against without a wildcard ..; and struct update syntax will not work.module_id: String§state: String§enabled: bool§live: boolWhether this module is serving.
For a Subc module: enabled, running, process alive, AND registered.
For a None module the registration term is dropped, because a module
that speaks no subc wire never registers and the daemon cannot assert
more than “the process it launched is alive”. READ IT WITH protocol:
live: true means something weaker for a None module, and a renderer
that prints it as a bare boolean for one is claiming more than the daemon
knows.
protocol: ModuleProtocolThe module’s declared wire protocol. Absent on daemons predating the field, where every module was a subc module, so the default is exactly what those daemons meant.
launch_nonce_env: Option<bool>Retained for one release for older status consumers: false on Unix, true on Windows. Non-wire modules receive no nonce on either platform.
launch_nonce_source: Option<String>The daemon’s Windows per-spawn delivery result: pipe after the spawned
process read all bytes, otherwise env for the offered environment copy.
Returned in supervisor.list, independently of the source the module
declares in manifest.provenance.launch_nonce_source when registering.
Processes that do not speak the wire protocol and stopped modules omit it.
health: SupervisorHealthStatus§pending_reload: Option<PendingReloadVerdict>Computed from the stored launch spec and observed process at list time; None means an older daemon did not report this comparison.
last_probe_ms: Option<u64>When the daemon last collected this module’s health, as unix
milliseconds. Absent means NEVER PROBED (a module inside its first probe
window, whose health is therefore Unknown rather than good), not
probed-long-ago. An old value and an absent one call for opposite
readings, so do not render them alike.
last_exit_code: Option<i32>Exit code of the module’s most recent process exit, if the process has
exited at least once. Survives respawn so a now-running module still
reports what killed its previous incarnation.
last_exit_signal: Option<i32>Terminating signal of the module’s most recent process exit (Unix), if
any. Some(9) = SIGKILL (OOM/jetsam/kill-on-drop), Some(6) = SIGABRT
(often a panic-abort). Survives respawn.
last_exit_ms: Option<u64>Unix milliseconds when the most recent child exit was observed. Present even when the terminal ring is not queried, so existing list readers can order their latest observed exit against events they already received.
last_exit_kind: Option<TerminalExitKind>Classification of the most recent child exit. Absent on daemons that predate exit-kind reporting.
restart_count: Option<u32>Replacement processes spawned for this module so far, against the budget that disables it.
THIS IS THE COUNTER THAT ENDS A MODULE, and it is not the one beside it.
SupervisorHealthEntry::consecutive_failures returns to zero on any
successful probe, so a module can miss probes all day and read zero; this
one only decreases when an operator restarts, reloads, or re-enables the
module. Reaching the budget moves it to Failed and it stays there until
somebody intervenes.
So a module one restart from being disabled is indistinguishable from a freshly booted one unless this pair is read. Both are reported together because the count alone does not say how close it is.
Absent from daemons predating the field, which is why it is optional rather than defaulted to zero: zero would assert a full budget.
max_restarts: Option<u32>Replacement processes this module is allowed before it is disabled. See
restart_count; absent on daemons predating the field.
lifetime_restarts: Option<u32>Replacement processes spawned over this module’s entire supervisor lifetime.
Unlike restart_count, this value is never reset by an operator action.
spawn_generation: Option<u64>Successful child spawns in this daemon incarnation. Zero means the module has not successfully spawned; every successful spawn increments the value exactly once.
restart_window_secs: Option<u64>The span restart_count is counted over, in seconds. The crash budget is
a RATE, not a lifetime total: restart_count counts only the restarts
inside the last restart_window_secs, and older ones no longer hold a
slot. Without this field a reader cannot tell “2 of 3 crashes, ever” from
“2 of 3 crashes in the last ten minutes”, and those two call for opposite
reactions.
Absent on daemons predating the windowed budget, where the count really was a lifetime total.
drain_timeout_ms: Option<u64>Effective drain budget for this module, in milliseconds. This is the resolved policy the running supervisor uses, not a config-file reread. Absent on older daemons.
restart_backoff_ms: Option<u64>Effective base delay before a crash restart, in milliseconds. Absent on older daemons.
restart_max_backoff_ms: Option<u64>Effective maximum delay before a crash restart, in milliseconds. Absent on older daemons.
resources: Option<ChildResourceUsage>Memory and cumulative CPU time of the module’s process, read when this list was answered. Report only: the daemon keeps no history and acts on none of it.
It describes the one process the supervisor spawned (its pid), not
processes that one has started in turn, so a module that forks workers
reports only its own share.
Absent means the daemon predates the field. A daemon that has the field
but could not read the process (not running, unsupported platform, read
failed) says so with Unavailable and a reason, so neither case can be
mistaken for a process using nothing.
Implementations§
Source§impl SupervisorEntry
impl SupervisorEntry
Sourcepub fn new(
module_id: impl Into<String>,
state: impl Into<String>,
enabled: bool,
live: bool,
health: SupervisorHealthStatus,
) -> Self
pub fn new( module_id: impl Into<String>, state: impl Into<String>, enabled: bool, live: bool, health: SupervisorHealthStatus, ) -> Self
Construct an entry with its required fields and wire-compatible defaults.
Sourcepub fn with_protocol(self, protocol: ModuleProtocol) -> Self
pub fn with_protocol(self, protocol: ModuleProtocol) -> Self
Set the module’s declared wire protocol.
Sourcepub fn with_launch_nonce_env(self, launch_nonce_env: Option<bool>) -> Self
pub fn with_launch_nonce_env(self, launch_nonce_env: Option<bool>) -> Self
Set or clear the launch nonce environment indicator.
pub fn with_launch_nonce_source(self, source: Option<String>) -> Self
Sourcepub fn with_pending_reload(
self,
pending_reload: Option<PendingReloadVerdict>,
) -> Self
pub fn with_pending_reload( self, pending_reload: Option<PendingReloadVerdict>, ) -> Self
Set or clear the comparison between the launch spec and observed process.
Sourcepub fn with_last_probe_ms(self, last_probe_ms: Option<u64>) -> Self
pub fn with_last_probe_ms(self, last_probe_ms: Option<u64>) -> Self
Set or clear the last health collection timestamp.
Sourcepub fn with_last_exit_code(self, last_exit_code: Option<i32>) -> Self
pub fn with_last_exit_code(self, last_exit_code: Option<i32>) -> Self
Set or clear the most recent process exit code.
Sourcepub fn with_last_exit_signal(self, last_exit_signal: Option<i32>) -> Self
pub fn with_last_exit_signal(self, last_exit_signal: Option<i32>) -> Self
Set or clear the most recent process exit signal.
Sourcepub fn with_last_exit_ms(self, last_exit_ms: Option<u64>) -> Self
pub fn with_last_exit_ms(self, last_exit_ms: Option<u64>) -> Self
Set or clear the most recent process exit timestamp.
Sourcepub fn with_last_exit_kind(
self,
last_exit_kind: Option<TerminalExitKind>,
) -> Self
pub fn with_last_exit_kind( self, last_exit_kind: Option<TerminalExitKind>, ) -> Self
Set or clear the most recent process exit classification.
Sourcepub fn with_restart_count(self, restart_count: Option<u32>) -> Self
pub fn with_restart_count(self, restart_count: Option<u32>) -> Self
Set or clear the restart count for the current crash budget.
Sourcepub fn with_max_restarts(self, max_restarts: Option<u32>) -> Self
pub fn with_max_restarts(self, max_restarts: Option<u32>) -> Self
Set or clear the maximum restarts allowed by the crash budget.
Sourcepub fn with_lifetime_restarts(self, lifetime_restarts: Option<u32>) -> Self
pub fn with_lifetime_restarts(self, lifetime_restarts: Option<u32>) -> Self
Set or clear the lifetime restart count.
Sourcepub fn with_spawn_generation(self, spawn_generation: Option<u64>) -> Self
pub fn with_spawn_generation(self, spawn_generation: Option<u64>) -> Self
Set or clear the successful spawn count for this daemon incarnation.
Sourcepub fn with_restart_window_secs(self, restart_window_secs: Option<u64>) -> Self
pub fn with_restart_window_secs(self, restart_window_secs: Option<u64>) -> Self
Set or clear the time window of the crash budget.
Sourcepub fn with_drain_timeout_ms(self, drain_timeout_ms: Option<u64>) -> Self
pub fn with_drain_timeout_ms(self, drain_timeout_ms: Option<u64>) -> Self
Set or clear the effective drain budget in milliseconds.
Sourcepub fn with_restart_backoff_ms(self, restart_backoff_ms: Option<u64>) -> Self
pub fn with_restart_backoff_ms(self, restart_backoff_ms: Option<u64>) -> Self
Set or clear the effective base restart delay in milliseconds.
Sourcepub fn with_restart_max_backoff_ms(
self,
restart_max_backoff_ms: Option<u64>,
) -> Self
pub fn with_restart_max_backoff_ms( self, restart_max_backoff_ms: Option<u64>, ) -> Self
Set or clear the effective maximum restart delay in milliseconds.
Sourcepub fn with_resources(self, resources: Option<ChildResourceUsage>) -> Self
pub fn with_resources(self, resources: Option<ChildResourceUsage>) -> Self
Set or clear the observed resource usage of the supervised process.