pub struct LandlockAccessNet(/* private fields */);Expand description
Permissions réseau Landlock (cf. linux/landlock.h), ABI v4+
(Linux 6.7).
Landlock ne borne le réseau que sur TCP, et seulement pour ces deux verbes. Ce n’est pas un pare-feu : il ne filtre ni les adresses, ni UDP, ni les paquets. Il répond à une question plus étroite — ce processus a-t-il le droit d’écouter, ou de se connecter, sur ce port ? — et il y répond dans le noyau, sans démon ni règle globale.
Le confondre avec un pare-feu serait une erreur de conception : une
application qui reçoit CONNECT_TCP sur le port 443 peut joindre
n’importe quelle machine sur ce port.
| Bit | Depuis | Signification |
|---|---|---|
| BIND_TCP | Landlock v4 (Linux 6.7) | se lier à un port en écoute |
| CONNECT_TCP | Landlock v4 (Linux 6.7) | se connecter à un port |
Comme pour LandlockAccessFs, demander un bit que le noyau ne connaît
pas fait échouer la création du ruleset (EINVAL) : interroger
landlock_supported_abi() avant de composer.
Implementations§
Source§impl LandlockAccessNet
impl LandlockAccessNet
Sourcepub const CONNECT_TCP: Self
pub const CONNECT_TCP: Self
Se connecter à un port TCP (connect) — Landlock v4+.
Source§impl LandlockAccessNet
impl LandlockAccessNet
Sourcepub const fn bits(&self) -> u64
pub const fn bits(&self) -> u64
Get the underlying bits value.
The returned value is exactly the bits set in this flags value.
Sourcepub const fn from_bits(bits: u64) -> Option<Self>
pub const fn from_bits(bits: u64) -> Option<Self>
Convert from a bits value.
This method will return None if any unknown bits are set.
Sourcepub const fn from_bits_truncate(bits: u64) -> Self
pub const fn from_bits_truncate(bits: u64) -> Self
Convert from a bits value, unsetting any unknown bits.
Sourcepub const fn from_bits_retain(bits: u64) -> Self
pub const fn from_bits_retain(bits: u64) -> Self
Convert from a bits value exactly.
Sourcepub fn from_name(name: &str) -> Option<Self>
pub fn from_name(name: &str) -> Option<Self>
Get a flags value with the bits of a flag with the given name set.
This method will return None if name is empty or doesn’t
correspond to any named flag.
Sourcepub const fn intersects(&self, other: Self) -> bool
pub const fn intersects(&self, other: Self) -> bool
Whether any set bits in other are also set in self.
Sourcepub const fn contains(&self, other: Self) -> bool
pub const fn contains(&self, other: Self) -> bool
Whether all set bits in other are also set in self.
Sourcepub fn remove(&mut self, other: Self)
pub fn remove(&mut self, other: Self)
The intersection of self with the complement of other (&!).
This method is not equivalent to self & !other when other has unknown bits set.
remove won’t truncate other, but the ! operator will.
Sourcepub fn toggle(&mut self, other: Self)
pub fn toggle(&mut self, other: Self)
The bitwise exclusive-or (^) of the bits in self and other.
Sourcepub fn set(&mut self, other: Self, value: bool)
pub fn set(&mut self, other: Self, value: bool)
Call insert when value is true or remove when value is false.
Sourcepub const fn intersection(self, other: Self) -> Self
pub const fn intersection(self, other: Self) -> Self
The bitwise and (&) of the bits in self and other.
Sourcepub const fn union(self, other: Self) -> Self
pub const fn union(self, other: Self) -> Self
The bitwise or (|) of the bits in self and other.
Sourcepub const fn difference(self, other: Self) -> Self
pub const fn difference(self, other: Self) -> Self
The intersection of self with the complement of other (&!).
This method is not equivalent to self & !other when other has unknown bits set.
difference won’t truncate other, but the ! operator will.
Sourcepub const fn symmetric_difference(self, other: Self) -> Self
pub const fn symmetric_difference(self, other: Self) -> Self
The bitwise exclusive-or (^) of the bits in self and other.
Sourcepub const fn complement(self) -> Self
pub const fn complement(self) -> Self
The bitwise negation (!) of the bits in self, truncating the result.
Source§impl LandlockAccessNet
impl LandlockAccessNet
Sourcepub const fn iter(&self) -> Iter<LandlockAccessNet>
pub const fn iter(&self) -> Iter<LandlockAccessNet>
Yield a set of contained flags values.
Each yielded flags value will correspond to a defined named flag. Any unknown bits will be yielded together as a final flags value.
Sourcepub const fn iter_names(&self) -> IterNames<LandlockAccessNet>
pub const fn iter_names(&self) -> IterNames<LandlockAccessNet>
Yield a set of contained named flags values.
This method is like iter, except only yields bits in contained named flags.
Any unknown bits, or bits not corresponding to a contained flag will not be yielded.
Trait Implementations§
Source§impl Binary for LandlockAccessNet
impl Binary for LandlockAccessNet
Source§impl BitAnd for LandlockAccessNet
impl BitAnd for LandlockAccessNet
Source§impl BitAndAssign for LandlockAccessNet
impl BitAndAssign for LandlockAccessNet
Source§fn bitand_assign(&mut self, other: Self)
fn bitand_assign(&mut self, other: Self)
The bitwise and (&) of the bits in self and other.
Source§impl BitOr for LandlockAccessNet
impl BitOr for LandlockAccessNet
Source§fn bitor(self, other: LandlockAccessNet) -> Self
fn bitor(self, other: LandlockAccessNet) -> Self
The bitwise or (|) of the bits in self and other.
Source§type Output = LandlockAccessNet
type Output = LandlockAccessNet
| operator.Source§impl BitOrAssign for LandlockAccessNet
impl BitOrAssign for LandlockAccessNet
Source§fn bitor_assign(&mut self, other: Self)
fn bitor_assign(&mut self, other: Self)
The bitwise or (|) of the bits in self and other.
Source§impl BitXor for LandlockAccessNet
impl BitXor for LandlockAccessNet
Source§impl BitXorAssign for LandlockAccessNet
impl BitXorAssign for LandlockAccessNet
Source§fn bitxor_assign(&mut self, other: Self)
fn bitxor_assign(&mut self, other: Self)
The bitwise exclusive-or (^) of the bits in self and other.
Source§impl Clone for LandlockAccessNet
impl Clone for LandlockAccessNet
Source§fn clone(&self) -> LandlockAccessNet
fn clone(&self) -> LandlockAccessNet
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreimpl Copy for LandlockAccessNet
Source§impl Debug for LandlockAccessNet
impl Debug for LandlockAccessNet
Source§impl Default for LandlockAccessNet
impl Default for LandlockAccessNet
Source§fn default() -> LandlockAccessNet
fn default() -> LandlockAccessNet
impl Eq for LandlockAccessNet
Source§impl Extend<LandlockAccessNet> for LandlockAccessNet
impl Extend<LandlockAccessNet> for LandlockAccessNet
Source§fn extend<T: IntoIterator<Item = Self>>(&mut self, iterator: T)
fn extend<T: IntoIterator<Item = Self>>(&mut self, iterator: T)
The bitwise or (|) of the bits in each flags value.
Source§fn extend_one(&mut self, item: A)
fn extend_one(&mut self, item: A)
extend_one)Source§fn extend_reserve(&mut self, additional: usize)
fn extend_reserve(&mut self, additional: usize)
extend_one)Source§impl Flags for LandlockAccessNet
impl Flags for LandlockAccessNet
Source§const FLAGS: &'static [Flag<LandlockAccessNet>]
const FLAGS: &'static [Flag<LandlockAccessNet>]
Source§fn from_bits_retain(bits: u64) -> LandlockAccessNet
fn from_bits_retain(bits: u64) -> LandlockAccessNet
§fn known_bits(&self) -> Self::Bits
fn known_bits(&self) -> Self::Bits
§fn unknown_bits(&self) -> Self::Bits
fn unknown_bits(&self) -> Self::Bits
§fn contains_unknown_bits(&self) -> bool
fn contains_unknown_bits(&self) -> bool
true if any unknown bits are set.§fn from_bits_truncate(bits: Self::Bits) -> Self
fn from_bits_truncate(bits: Self::Bits) -> Self
§fn from_name(name: &str) -> Option<Self>
fn from_name(name: &str) -> Option<Self>
§fn iter_names(&self) -> IterNames<Self>
fn iter_names(&self) -> IterNames<Self>
§fn iter_defined_names() -> IterDefinedNames<Self>
fn iter_defined_names() -> IterDefinedNames<Self>
Self::FLAGS].§fn intersects(&self, other: Self) -> boolwhere
Self: Sized,
fn intersects(&self, other: Self) -> boolwhere
Self: Sized,
other are also set in self.§fn contains(&self, other: Self) -> boolwhere
Self: Sized,
fn contains(&self, other: Self) -> boolwhere
Self: Sized,
other are also set in self.§fn insert(&mut self, other: Self)where
Self: Sized,
fn insert(&mut self, other: Self)where
Self: Sized,
|) of the bits in self and other.§fn toggle(&mut self, other: Self)where
Self: Sized,
fn toggle(&mut self, other: Self)where
Self: Sized,
^) of the bits in self and other.§fn set(&mut self, other: Self, value: bool)where
Self: Sized,
fn set(&mut self, other: Self, value: bool)where
Self: Sized,
Flags::insert] when value is true or [Flags::remove] when value is false.§fn intersection(self, other: Self) -> Self
fn intersection(self, other: Self) -> Self
&) of the bits in self and other.§fn difference(self, other: Self) -> Self
fn difference(self, other: Self) -> Self
§fn symmetric_difference(self, other: Self) -> Self
fn symmetric_difference(self, other: Self) -> Self
^) of the bits in self and other.§fn complement(self) -> Self
fn complement(self) -> Self
!) of the bits in self, truncating the result.Source§impl FromIterator<LandlockAccessNet> for LandlockAccessNet
impl FromIterator<LandlockAccessNet> for LandlockAccessNet
Source§fn from_iter<T: IntoIterator<Item = Self>>(iterator: T) -> Self
fn from_iter<T: IntoIterator<Item = Self>>(iterator: T) -> Self
The bitwise or (|) of the bits in each flags value.
Source§impl Hash for LandlockAccessNet
impl Hash for LandlockAccessNet
Source§impl IntoIterator for LandlockAccessNet
impl IntoIterator for LandlockAccessNet
Source§impl LowerHex for LandlockAccessNet
impl LowerHex for LandlockAccessNet
Source§impl Not for LandlockAccessNet
impl Not for LandlockAccessNet
Source§impl Octal for LandlockAccessNet
impl Octal for LandlockAccessNet
Source§impl PartialEq for LandlockAccessNet
impl PartialEq for LandlockAccessNet
Source§impl PublicFlags for LandlockAccessNet
impl PublicFlags for LandlockAccessNet
impl StructuralPartialEq for LandlockAccessNet
Source§impl Sub for LandlockAccessNet
impl Sub for LandlockAccessNet
Source§fn sub(self, other: Self) -> Self
fn sub(self, other: Self) -> Self
The intersection of self with the complement of other (&!).
This method is not equivalent to self & !other when other has unknown bits set.
difference won’t truncate other, but the ! operator will.
Source§type Output = LandlockAccessNet
type Output = LandlockAccessNet
- operator.Source§impl SubAssign for LandlockAccessNet
impl SubAssign for LandlockAccessNet
Source§fn sub_assign(&mut self, other: Self)
fn sub_assign(&mut self, other: Self)
The intersection of self with the complement of other (&!).
This method is not equivalent to self & !other when other has unknown bits set.
difference won’t truncate other, but the ! operator will.