A low-overhead system performance analyzer for Windows 11: it samples running processes, keeps a short history, and produces plain-language findings about excessive CPU, memory, disk, and GPU use. Its credibility rests on being nearly invisible in its own measurements.
Full requirements and milestones: BUILD_SPEC.md.
The portable core is built and tested (on Linux, against a synthetic
process table). The Windows FFI — the actual NtQuerySystemInformation
sampler — is stubbed and lands on the target machine (M1).
| Area | State |
|---|---|
| model, delta arithmetic, history, 7 findings rules, denylist | done, unit-tested |
CLI (--top, --json, --self-check, --findings) |
done, runs on Linux via FakeRawSource |
Windows sampler (ntquery, identity, services, gpu) |
#[cfg(windows)] stubs — M1/M2/M5 |
| TUI, ETW, GUI | not started — M4/M6/M7 |
Read these before changing the core:
CONTEXT.md— the glossary (ubiquitous language).docs/adr/0001— history stores an identity table + compact sample records, not full snapshots.docs/adr/0002— the findings core is stateless; frontends track lifecycle via the(id, targets)key.docs/adr/0003— the sampler seam sits at raw counters, so all derivation is testable off-Windows.
cargo build --release
./target/release/sysperf --top 15 # top processes by CPU
./target/release/sysperf --json --interval 1000 --duration 60
./target/release/sysperf --findings # findings engine over a demo history
./target/release/sysperf --self-check # the tool's own per-tick costOn Linux the CLI drives a synthetic FakeRawSource; the numbers are fabricated.
On Windows the same code drives the real sampler.
cargo test
cargo clippy --all-targets -- -D warningsThe core carries #![deny(unsafe_code)]; only the Windows FFI submodules may use
unsafe. See BUILD_SPEC.md "How to work" for the milestone-at-a-time process.