Skip to main content

CgroupV2Manager

Struct CgroupV2Manager 

Source
pub struct CgroupV2Manager { /* private fields */ }
Expand description

cgroup v2 resource manager for a single agent.

One CgroupV2Manager is created per agent instance. It owns a sub-cgroup that is a sibling of the calling process’s cgroup, providing resource accounting, enforcement, and forcible termination.

Implementations§

Source§

impl CgroupV2Manager

Source

pub async fn is_available() -> bool

Check whether cgroup v2 is available on this system.

Returns true if /sys/fs/cgroup/cgroup.controllers exists.

Source

pub async fn discover_cgroup_parent() -> Result<PathBuf, SandboxError>

Discover the parent of the calling process’s own cgroup.

Parses the 0:: entry (unified hierarchy) from /proc/self/cgroup to obtain the process’s current cgroup path, then returns its parent. Agent sub-cgroups are created there, making them siblings of the process’s cgroup and enabling resource controllers without violating the cgroup-v2 “no internal processes” constraint.

Falls back to the process’s own cgroup if it has no parent (e.g., running directly under the cgroup root — rare in practice).

§Errors

Returns SandboxError::CgroupParseFailed if /proc/self/cgroup cannot be read or the 0:: entry is absent.

Source

pub async fn new( agent_id: Uuid, resources: Option<&ResourceLimits>, ) -> Result<Self, SandboxError>

Create a new cgroup manager for the given agent UUID.

Discovers the process cgroup’s parent, creates the agent sub-cgroup directory, enables required controllers on the parent and on the synwire/ intermediate cgroup, and applies resource limits if provided.

Falls back gracefully (returns error, caller should log and disable cgroup tracking) if cgroup v2 is not available or the path is not writable.

§Errors

Returns a SandboxError variant if cgroup setup fails.

Source

pub fn base_path(&self) -> &Path

Absolute path to this agent’s cgroup directory.

Source

pub async fn move_pid(&self, pid: u32) -> Result<(), SandboxError>

Move a process into this agent’s cgroup.

§Errors

Returns SandboxError::CgroupIo if writing to cgroup.procs fails.

Source

pub async fn read_stats(&self) -> Option<CgroupStats>

Read live CPU and memory stats for this cgroup.

Returns None if either file is missing or unparseable (non-fatal).

Source

pub async fn kill_all(&self) -> Result<(), SandboxError>

Forcibly kill all processes in this cgroup.

Tries cgroup.kill (Linux 5.14+); falls back to reading cgroup.procs and sending SIGKILL to each PID via nix.

§Errors

Returns SandboxError::CgroupIo if both kill mechanisms fail.

Source

pub async fn destroy(&self)

Remove this agent’s cgroup directory.

Should only be called after all processes have exited. Logs a warning if removal fails (e.g., lingering processes).

Trait Implementations§

Source§

impl Debug for CgroupV2Manager

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Drop for CgroupV2Manager

Source§

fn drop(&mut self)

Executes the destructor for this type. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> FutureExt for T

Source§

fn with_context(self, otel_cx: Context) -> WithContext<Self>

Attaches the provided Context to this type, returning a WithContext wrapper. Read more
Source§

fn with_current_context(self) -> WithContext<Self>

Attaches the current Context to this type, returning a WithContext wrapper. Read more
Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self>

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> Pointable for T

Source§

const ALIGN: usize

The alignment of pointer.
Source§

type Init = T

The type for initializers.
Source§

unsafe fn init(init: <T as Pointable>::Init) -> usize

Initializes a with the given initializer. Read more
Source§

unsafe fn deref<'a>(ptr: usize) -> &'a T

Dereferences the given pointer. Read more
Source§

unsafe fn deref_mut<'a>(ptr: usize) -> &'a mut T

Mutably dereferences the given pointer. Read more
Source§

unsafe fn drop(ptr: usize)

Drops the object pointed to by the given pointer. Read more
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more