pub enum Isolation {
UidSplit,
Platform,
}Expand description
How an image ends, and the isolation that ending permits.
One value rather than two, because ALIEN_SANDBOX_ISOLATION and the trailing USER describe
the same decision from opposite sides: an image that asks for uid-split under a non-root
USER has no privilege left to drop with, and every exec in it fails.
Variants§
UidSplit
The agent starts as root and drops to the exec uid before every spawn, so a command can
never rewrite its own supervisor. The image declares no USER.
Platform
The agent starts as the exec uid and supervises commands under it, which is all a runtime
that refuses a root image can offer. The image ends USER <uid>:<uid>.
Implementations§
Trait Implementations§
impl Copy for Isolation
impl Eq for Isolation
impl StructuralPartialEq for Isolation
Auto Trait Implementations§
impl Freeze for Isolation
impl RefUnwindSafe for Isolation
impl Send for Isolation
impl Sync for Isolation
impl Unpin for Isolation
impl UnsafeUnpin for Isolation
impl UnwindSafe for Isolation
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
Compare self to
key and return true if they are equal.