import { spawn, type ChildProcess } from 'node:child_process'; import { type CgroupOomSnapshot } from './oxigraph-memory.js'; export declare const OXIGRAPH_WATCHDOG_OOM_MARKER = "[oxigraph-watchdog] scoped child OOM-killed by cgroup memory cap (or host OOM)"; /** * SIGTERM → SIGKILL grace for Oxigraph, shared by every path that stops it. * GH#1400 — a LEAK GUARD, not a flush window. Measured: oxigraph 0.5.8 * installs no SIGTERM handler, so the child dies by default disposition and * the WAL is byte-identical across the signal. Raising this cannot buy a * RocksDB flush; it would only delay teardown. */ export declare const OXIGRAPH_STOP_GRACE_MS = 5000; /** * How the daemon launched this watchdog. `systemd-scope` places Oxigraph in a * sibling cgroup that stopping the daemon's service does not reach; `direct` * leaves it inside the daemon's own process tree and cgroup. */ export type OxigraphWatchdogLaunchMode = 'direct' | 'systemd-scope'; export interface OxigraphParentWatchdogOptions { parentPid: number; command: string; args: readonly string[]; launchMode?: OxigraphWatchdogLaunchMode; pollIntervalMs?: number; stopGraceMs?: number; spawnChild?: typeof spawn; isProcessAlive?: (pid: number) => boolean; /** This process's current parent PID. */ readParentPid?: () => number; readOomSnapshot?: (pid: number) => CgroupOomSnapshot | null; readOomKill?: (dir: string) => number | null; } export interface OxigraphParentWatchdogResult { code: number | null; signal: NodeJS.Signals | null; parentLost: boolean; oomKilled: boolean; } export interface OxigraphParentWatchdogHandle { child: ChildProcess; result: Promise; stop(signal?: NodeJS.Signals): void; } export interface OxigraphWatchdogLaunchPlan { readonly command: string; readonly args: readonly string[]; readonly protectedByParentDeathSignal: boolean; } /** * Pure host-policy seam; runtime callers cannot select a different platform. * Only a scoped child needs the kernel parent-death signal (and util-linux * `setpriv`): a direct child stays in the daemon's cgroup, so stopping the * service still reaches it, and requiring `setpriv` there would stop musl * hosts (which run a PATH Oxigraph and often lack util-linux) from starting. */ export declare function buildOxigraphWatchdogLaunchPlan(platform: NodeJS.Platform, watchdogPid: number, command: string, args: readonly string[], launchMode?: OxigraphWatchdogLaunchMode): OxigraphWatchdogLaunchPlan; /** * Keep Oxigraph tied to the DKG daemon worker. A worker SIGKILLed by the * supervisor's liveness watchdog cannot stop its children, and systemd may * place Oxigraph in a sibling cgroup. The typed watchdog forwards shutdown * signals and terminates Oxigraph when the original daemon PID disappears. * For a scoped child on Linux, a kernel parent-death signal also covers * abrupt death of the watchdog itself. */ export declare function startOxigraphParentWatchdog(opts: OxigraphParentWatchdogOptions): OxigraphParentWatchdogHandle; export declare const OXIGRAPH_WATCHDOG_DIRECT_FLAG = "--direct"; export declare function parseOxigraphParentWatchdogArgs(argv: readonly string[]): { parentPid: number; command: string; args: string[]; launchMode: OxigraphWatchdogLaunchMode; }; export declare function conventionalSignalExitCode(signal: NodeJS.Signals): number; //# sourceMappingURL=oxigraph-parent-watchdog.d.ts.map