pub struct Process { /* private fields */ }Expand description
A handle on the process holding one pid at the moment it was opened.
Implementations§
Source§impl Process
impl Process
Sourcepub fn open(pid: u32) -> Result<Option<Self>>
pub fn open(pid: u32) -> Result<Option<Self>>
Open a handle on the process now holding pid.
Ok(None) means no process holds that pid (on macOS, also a zombie
awaiting its reap; on Linux a zombie opens, and Self::observe then
reports it as exited). On Linux this opens a pidfd,
which from then on refers to this exact process even if it exits and the
pid is reused; when the kernel cannot open one (older than 5.3, or a
seccomp policy refusing the call) the handle falls back to the pid, as
on macOS.
pub fn pid(&self) -> u32
Sourcepub fn signals_through_pidfd(&self) -> bool
pub fn signals_through_pidfd(&self) -> bool
True when signals go through a pidfd, so they cannot reach a different process that has since reused this pid.
Sourcepub fn observe(&self) -> Option<Observation>
pub fn observe(&self) -> Option<Observation>
The process’s start time and executable, or None when it has exited
(including as a zombie not yet reaped) or cannot be observed. On Linux,
Self::is_alive_but_unobservable distinguishes a hidden procfs entry.
Sourcepub fn is_alive_but_unobservable(&self) -> bool
pub fn is_alive_but_unobservable(&self) -> bool
Whether Linux hides the entire procfs entry while the process still exists. This proves existence, not identity, and never authorizes a signal. Other platforms return false without changing their observation behavior.
Sourcepub fn observe_with_executable_access(
&self,
) -> Option<(Observation, ExecutableAccess)>
pub fn observe_with_executable_access( &self, ) -> Option<(Observation, ExecutableAccess)>
Observe the process and distinguish Linux executable permission denial from other failures, without changing the legacy observation’s fields. Other platforms retain their existing readable/unavailable distinction.
Sourcepub fn signal(&self, signal: Signal) -> Result<bool>
pub fn signal(&self, signal: Signal) -> Result<bool>
Send signal to the process.
With a pidfd the signal can only reach the process this handle was
opened on: if that process has exited, the call fails with ESRCH even
if the pid has been reused. Without one (macOS, or a Linux kernel with no
pidfd) the signal goes to whatever holds the pid now, so callers should
Self::observe immediately before signalling. What remains is the
time between that check and this call; for a different process to be
hit, the checked one must exit, be reaped, and have its pid handed to a
new process inside that window, and both kernels hand out pids in
increasing order, so a reuse needs the whole pid space to wrap first.
Ok(false) means the process had already exited (ESRCH).