pub struct CgroupV2Manager { /* private fields */ }Expand description
cgroup v2 resource manager for a single agent.
One CgroupV2Manager is created per agent instance. It owns a sub-cgroup
that is a sibling of the calling process’s cgroup, providing resource
accounting, enforcement, and forcible termination.
Implementations§
Source§impl CgroupV2Manager
impl CgroupV2Manager
Sourcepub async fn is_available() -> bool
pub async fn is_available() -> bool
Check whether cgroup v2 is available on this system.
Returns true if /sys/fs/cgroup/cgroup.controllers exists.
Sourcepub async fn discover_cgroup_parent() -> Result<PathBuf, SandboxError>
pub async fn discover_cgroup_parent() -> Result<PathBuf, SandboxError>
Discover the parent of the calling process’s own cgroup.
Parses the 0:: entry (unified hierarchy) from /proc/self/cgroup to
obtain the process’s current cgroup path, then returns its parent.
Agent sub-cgroups are created there, making them siblings of the
process’s cgroup and enabling resource controllers without violating
the cgroup-v2 “no internal processes” constraint.
Falls back to the process’s own cgroup if it has no parent (e.g., running directly under the cgroup root — rare in practice).
§Errors
Returns SandboxError::CgroupParseFailed if /proc/self/cgroup
cannot be read or the 0:: entry is absent.
Sourcepub async fn new(
agent_id: Uuid,
resources: Option<&ResourceLimits>,
) -> Result<Self, SandboxError>
pub async fn new( agent_id: Uuid, resources: Option<&ResourceLimits>, ) -> Result<Self, SandboxError>
Create a new cgroup manager for the given agent UUID.
Discovers the process cgroup’s parent, creates the agent sub-cgroup
directory, enables required controllers on the parent and on the
synwire/ intermediate cgroup, and applies resource limits if provided.
Falls back gracefully (returns error, caller should log and disable cgroup tracking) if cgroup v2 is not available or the path is not writable.
§Errors
Returns a SandboxError variant if cgroup setup fails.
Sourcepub async fn move_pid(&self, pid: u32) -> Result<(), SandboxError>
pub async fn move_pid(&self, pid: u32) -> Result<(), SandboxError>
Move a process into this agent’s cgroup.
§Errors
Returns SandboxError::CgroupIo if writing to cgroup.procs fails.
Sourcepub async fn read_stats(&self) -> Option<CgroupStats>
pub async fn read_stats(&self) -> Option<CgroupStats>
Read live CPU and memory stats for this cgroup.
Returns None if either file is missing or unparseable (non-fatal).
Sourcepub async fn kill_all(&self) -> Result<(), SandboxError>
pub async fn kill_all(&self) -> Result<(), SandboxError>
Forcibly kill all processes in this cgroup.
Tries cgroup.kill (Linux 5.14+); falls back to reading cgroup.procs
and sending SIGKILL to each PID via nix.
§Errors
Returns SandboxError::CgroupIo if both kill mechanisms fail.
Trait Implementations§
Source§impl Debug for CgroupV2Manager
impl Debug for CgroupV2Manager
Auto Trait Implementations§
impl Freeze for CgroupV2Manager
impl RefUnwindSafe for CgroupV2Manager
impl Send for CgroupV2Manager
impl Sync for CgroupV2Manager
impl Unpin for CgroupV2Manager
impl UnsafeUnpin for CgroupV2Manager
impl UnwindSafe for CgroupV2Manager
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> FutureExt for T
impl<T> FutureExt for T
Source§fn with_context(self, otel_cx: Context) -> WithContext<Self>
fn with_context(self, otel_cx: Context) -> WithContext<Self>
Source§fn with_current_context(self) -> WithContext<Self>
fn with_current_context(self) -> WithContext<Self>
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
Source§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more