pub struct LandlockRestrictFlags(/* private fields */);Expand description
Drapeaux de landlock_restrict_self(2) (cf. linux/landlock.h).
§Deux familles, deux natures
- les trois premiers ne changent aucune décision d’accès : ils disent au noyau ce qu’il doit tracer d’un refus (ABI v7). Utiles au diagnostic, ils appartiennent à l’appelant (ADR-156 D5) ;
- le quatrième,
TSYNC, change ce qui est borné — et c’est le seul qui ferme quelque chose.
§Ce que TSYNC répare
Sans lui, landlock_restrict_self ne borne que le fil appelant. Dans un processus
multifil qui se met lui-même en cage, les fils frères restent hors du domaine : la
cage se contourne en changeant de fil. Avec lui, la configuration s’applique
atomiquement à tous les fils du processus.
Le noyau propage aussi no_new_privs aux fils frères quand le fil appelant le porte —
ce qui évite l’incohérence d’un fil confiné et d’un fil qui peut encore élever ses
privilèges.
Le noyau dit qu’il « écrase » la configuration des fils frères, quels que soient les domaines déjà établis sur eux. Ce que cela fait exactement d’un fil frère plus strictement confiné est vérifié par un test dédié plutôt que supposé — c’est la différence entre borner et croire borner.
Implementations§
Source§impl LandlockRestrictFlags
impl LandlockRestrictFlags
Sourcepub const LOG_SAME_EXEC_OFF: Self
pub const LOG_SAME_EXEC_OFF: Self
Ne journalise pas les refus venant du fil qui crée le domaine, ni de ses enfants tant qu’ils exécutent le même code (ABI v7).
Sourcepub const LOG_NEW_EXEC_ON: Self
pub const LOG_NEW_EXEC_ON: Self
Journalise les refus après un execve dans le domaine créé (ABI v7).
Sourcepub const LOG_SUBDOMAINS_OFF: Self
pub const LOG_SUBDOMAINS_OFF: Self
Ne journalise pas les refus venant des sous-domaines créés par l’appelant ou ses descendants (ABI v7).
Source§impl LandlockRestrictFlags
impl LandlockRestrictFlags
Sourcepub const fn bits(&self) -> u32
pub const fn bits(&self) -> u32
Get the underlying bits value.
The returned value is exactly the bits set in this flags value.
Sourcepub const fn from_bits(bits: u32) -> Option<Self>
pub const fn from_bits(bits: u32) -> Option<Self>
Convert from a bits value.
This method will return None if any unknown bits are set.
Sourcepub const fn from_bits_truncate(bits: u32) -> Self
pub const fn from_bits_truncate(bits: u32) -> Self
Convert from a bits value, unsetting any unknown bits.
Sourcepub const fn from_bits_retain(bits: u32) -> Self
pub const fn from_bits_retain(bits: u32) -> Self
Convert from a bits value exactly.
Sourcepub fn from_name(name: &str) -> Option<Self>
pub fn from_name(name: &str) -> Option<Self>
Get a flags value with the bits of a flag with the given name set.
This method will return None if name is empty or doesn’t
correspond to any named flag.
Sourcepub const fn intersects(&self, other: Self) -> bool
pub const fn intersects(&self, other: Self) -> bool
Whether any set bits in other are also set in self.
Sourcepub const fn contains(&self, other: Self) -> bool
pub const fn contains(&self, other: Self) -> bool
Whether all set bits in other are also set in self.
Sourcepub fn remove(&mut self, other: Self)
pub fn remove(&mut self, other: Self)
The intersection of self with the complement of other (&!).
This method is not equivalent to self & !other when other has unknown bits set.
remove won’t truncate other, but the ! operator will.
Sourcepub fn toggle(&mut self, other: Self)
pub fn toggle(&mut self, other: Self)
The bitwise exclusive-or (^) of the bits in self and other.
Sourcepub fn set(&mut self, other: Self, value: bool)
pub fn set(&mut self, other: Self, value: bool)
Call insert when value is true or remove when value is false.
Sourcepub const fn intersection(self, other: Self) -> Self
pub const fn intersection(self, other: Self) -> Self
The bitwise and (&) of the bits in self and other.
Sourcepub const fn union(self, other: Self) -> Self
pub const fn union(self, other: Self) -> Self
The bitwise or (|) of the bits in self and other.
Sourcepub const fn difference(self, other: Self) -> Self
pub const fn difference(self, other: Self) -> Self
The intersection of self with the complement of other (&!).
This method is not equivalent to self & !other when other has unknown bits set.
difference won’t truncate other, but the ! operator will.
Sourcepub const fn symmetric_difference(self, other: Self) -> Self
pub const fn symmetric_difference(self, other: Self) -> Self
The bitwise exclusive-or (^) of the bits in self and other.
Sourcepub const fn complement(self) -> Self
pub const fn complement(self) -> Self
The bitwise negation (!) of the bits in self, truncating the result.
Source§impl LandlockRestrictFlags
impl LandlockRestrictFlags
Sourcepub const fn iter(&self) -> Iter<LandlockRestrictFlags>
pub const fn iter(&self) -> Iter<LandlockRestrictFlags>
Yield a set of contained flags values.
Each yielded flags value will correspond to a defined named flag. Any unknown bits will be yielded together as a final flags value.
Sourcepub const fn iter_names(&self) -> IterNames<LandlockRestrictFlags>
pub const fn iter_names(&self) -> IterNames<LandlockRestrictFlags>
Yield a set of contained named flags values.
This method is like iter, except only yields bits in contained named flags.
Any unknown bits, or bits not corresponding to a contained flag will not be yielded.
Trait Implementations§
Source§impl Binary for LandlockRestrictFlags
impl Binary for LandlockRestrictFlags
Source§impl BitAnd for LandlockRestrictFlags
impl BitAnd for LandlockRestrictFlags
Source§impl BitAndAssign for LandlockRestrictFlags
impl BitAndAssign for LandlockRestrictFlags
Source§fn bitand_assign(&mut self, other: Self)
fn bitand_assign(&mut self, other: Self)
The bitwise and (&) of the bits in self and other.
Source§impl BitOr for LandlockRestrictFlags
impl BitOr for LandlockRestrictFlags
Source§fn bitor(self, other: LandlockRestrictFlags) -> Self
fn bitor(self, other: LandlockRestrictFlags) -> Self
The bitwise or (|) of the bits in self and other.
Source§type Output = LandlockRestrictFlags
type Output = LandlockRestrictFlags
| operator.Source§impl BitOrAssign for LandlockRestrictFlags
impl BitOrAssign for LandlockRestrictFlags
Source§fn bitor_assign(&mut self, other: Self)
fn bitor_assign(&mut self, other: Self)
The bitwise or (|) of the bits in self and other.
Source§impl BitXor for LandlockRestrictFlags
impl BitXor for LandlockRestrictFlags
Source§impl BitXorAssign for LandlockRestrictFlags
impl BitXorAssign for LandlockRestrictFlags
Source§fn bitxor_assign(&mut self, other: Self)
fn bitxor_assign(&mut self, other: Self)
The bitwise exclusive-or (^) of the bits in self and other.
Source§impl Clone for LandlockRestrictFlags
impl Clone for LandlockRestrictFlags
Source§fn clone(&self) -> LandlockRestrictFlags
fn clone(&self) -> LandlockRestrictFlags
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreimpl Copy for LandlockRestrictFlags
Source§impl Debug for LandlockRestrictFlags
impl Debug for LandlockRestrictFlags
Source§impl Default for LandlockRestrictFlags
impl Default for LandlockRestrictFlags
Source§fn default() -> LandlockRestrictFlags
fn default() -> LandlockRestrictFlags
impl Eq for LandlockRestrictFlags
Source§impl Extend<LandlockRestrictFlags> for LandlockRestrictFlags
impl Extend<LandlockRestrictFlags> for LandlockRestrictFlags
Source§fn extend<T: IntoIterator<Item = Self>>(&mut self, iterator: T)
fn extend<T: IntoIterator<Item = Self>>(&mut self, iterator: T)
The bitwise or (|) of the bits in each flags value.
Source§fn extend_one(&mut self, item: A)
fn extend_one(&mut self, item: A)
extend_one)Source§fn extend_reserve(&mut self, additional: usize)
fn extend_reserve(&mut self, additional: usize)
extend_one)Source§impl Flags for LandlockRestrictFlags
impl Flags for LandlockRestrictFlags
Source§const FLAGS: &'static [Flag<LandlockRestrictFlags>]
const FLAGS: &'static [Flag<LandlockRestrictFlags>]
Source§fn from_bits_retain(bits: u32) -> LandlockRestrictFlags
fn from_bits_retain(bits: u32) -> LandlockRestrictFlags
§fn known_bits(&self) -> Self::Bits
fn known_bits(&self) -> Self::Bits
§fn unknown_bits(&self) -> Self::Bits
fn unknown_bits(&self) -> Self::Bits
§fn contains_unknown_bits(&self) -> bool
fn contains_unknown_bits(&self) -> bool
true if any unknown bits are set.§fn from_bits_truncate(bits: Self::Bits) -> Self
fn from_bits_truncate(bits: Self::Bits) -> Self
§fn from_name(name: &str) -> Option<Self>
fn from_name(name: &str) -> Option<Self>
§fn iter_names(&self) -> IterNames<Self>
fn iter_names(&self) -> IterNames<Self>
§fn iter_defined_names() -> IterDefinedNames<Self>
fn iter_defined_names() -> IterDefinedNames<Self>
Self::FLAGS].§fn intersects(&self, other: Self) -> boolwhere
Self: Sized,
fn intersects(&self, other: Self) -> boolwhere
Self: Sized,
other are also set in self.§fn contains(&self, other: Self) -> boolwhere
Self: Sized,
fn contains(&self, other: Self) -> boolwhere
Self: Sized,
other are also set in self.§fn insert(&mut self, other: Self)where
Self: Sized,
fn insert(&mut self, other: Self)where
Self: Sized,
|) of the bits in self and other.§fn toggle(&mut self, other: Self)where
Self: Sized,
fn toggle(&mut self, other: Self)where
Self: Sized,
^) of the bits in self and other.§fn set(&mut self, other: Self, value: bool)where
Self: Sized,
fn set(&mut self, other: Self, value: bool)where
Self: Sized,
Flags::insert] when value is true or [Flags::remove] when value is false.§fn intersection(self, other: Self) -> Self
fn intersection(self, other: Self) -> Self
&) of the bits in self and other.§fn difference(self, other: Self) -> Self
fn difference(self, other: Self) -> Self
§fn symmetric_difference(self, other: Self) -> Self
fn symmetric_difference(self, other: Self) -> Self
^) of the bits in self and other.§fn complement(self) -> Self
fn complement(self) -> Self
!) of the bits in self, truncating the result.Source§impl FromIterator<LandlockRestrictFlags> for LandlockRestrictFlags
impl FromIterator<LandlockRestrictFlags> for LandlockRestrictFlags
Source§fn from_iter<T: IntoIterator<Item = Self>>(iterator: T) -> Self
fn from_iter<T: IntoIterator<Item = Self>>(iterator: T) -> Self
The bitwise or (|) of the bits in each flags value.
Source§impl Hash for LandlockRestrictFlags
impl Hash for LandlockRestrictFlags
Source§impl IntoIterator for LandlockRestrictFlags
impl IntoIterator for LandlockRestrictFlags
Source§impl LowerHex for LandlockRestrictFlags
impl LowerHex for LandlockRestrictFlags
Source§impl Not for LandlockRestrictFlags
impl Not for LandlockRestrictFlags
Source§impl Octal for LandlockRestrictFlags
impl Octal for LandlockRestrictFlags
Source§impl PartialEq for LandlockRestrictFlags
impl PartialEq for LandlockRestrictFlags
Source§impl PublicFlags for LandlockRestrictFlags
impl PublicFlags for LandlockRestrictFlags
impl StructuralPartialEq for LandlockRestrictFlags
Source§impl Sub for LandlockRestrictFlags
impl Sub for LandlockRestrictFlags
Source§fn sub(self, other: Self) -> Self
fn sub(self, other: Self) -> Self
The intersection of self with the complement of other (&!).
This method is not equivalent to self & !other when other has unknown bits set.
difference won’t truncate other, but the ! operator will.
Source§type Output = LandlockRestrictFlags
type Output = LandlockRestrictFlags
- operator.Source§impl SubAssign for LandlockRestrictFlags
impl SubAssign for LandlockRestrictFlags
Source§fn sub_assign(&mut self, other: Self)
fn sub_assign(&mut self, other: Self)
The intersection of self with the complement of other (&!).
This method is not equivalent to self & !other when other has unknown bits set.
difference won’t truncate other, but the ! operator will.