Skip to main content

BackendCapability

Enum BackendCapability 

Source
pub enum BackendCapability {
Show 39 variants CommandExecution, WorkingDirectory, StdioInherit, StdioNull, StdioPipe, TimeoutBackendDefault, TimeoutLimit, TimeoutDisabled, FilesystemRestricted, FilesystemUnrestricted, FilesystemExternal, FilesystemScopes, FilesystemExecutableMapping, FilesystemAbsoluteScopes, FilesystemWorkspaceScopes, FilesystemRootScopes, FilesystemMinimalScopes, FilesystemTmpdirScopes, FilesystemConventionalTemporaryScopes, FilesystemGlobs, FilesystemGlobScanDepth, FilesystemReadOnlySubpaths, FilesystemMissingPathBehavior, FilesystemProtectedPaths, NetworkDisabled, NetworkEnabled, NetworkExternal, NetworkDomainRules, NetworkLocalAddressRestrictions, NetworkResolvedTargets, NetworkLocalIpcIsolation, NetworkLocalIpcRules, NetworkLocalIpcDenyRules, NetworkWindowsNamedPipeRules, EnvironmentAll, EnvironmentCore, EnvironmentNone, EnvironmentFilters, EnvironmentOverrides,
}
Expand description

One capability that a native backend may advertise.

A capability means that the backend can enforce the corresponding effective request safely. It is not a hint that the backend can parse the value. Backends must not advertise a capability whose enforcement would be best-effort or silently incomplete. Ord is used only for deterministic capability-set iteration and diagnostics; it is not an enforcement precedence.

Variants§

§

CommandExecution

Execute a validated command request.

§

WorkingDirectory

Resolve and enforce the effective working directory, including the runtime directory inherited when the command has no explicit cwd.

§

StdioInherit

Inherit a standard stream from the launcher.

§

StdioNull

Connect a standard stream to the platform null device.

§

StdioPipe

Create a pipe for a standard stream.

§

TimeoutBackendDefault

Apply the backend’s default timeout policy.

§

TimeoutLimit

Apply an explicit timeout duration.

§

TimeoutDisabled

Run without an automatic timeout.

§

FilesystemRestricted

Enforce a restricted filesystem policy.

§

FilesystemUnrestricted

Run without a local filesystem boundary.

§

FilesystemExternal

Delegate filesystem enforcement to an external owner.

§

FilesystemScopes

Enforce concrete and symbolic filesystem scopes, including workspace roots required by workspace-relative selectors and globs.

§

FilesystemExecutableMapping

Map executable files from explicitly validated runtime roots.

§

FilesystemAbsoluteScopes

Enforce native absolute filesystem scopes and absolute globs.

§

FilesystemWorkspaceScopes

Resolve filesystem scopes and globs against runtime workspace roots.

§

FilesystemRootScopes

Resolve filesystem scopes against caller-supplied system roots.

§

FilesystemMinimalScopes

Resolve filesystem scopes against the platform-minimal paths.

§

FilesystemTmpdirScopes

Resolve filesystem scopes against the platform temporary directory.

§

FilesystemConventionalTemporaryScopes

Resolve filesystem scopes against the platform’s conventional temporary path supplied by the runtime context.

§

FilesystemGlobs

Enforce filesystem deny globs.

§

FilesystemGlobScanDepth

Expand filesystem globs with the requested scan-depth semantics.

§

FilesystemReadOnlySubpaths

Enforce read-only subpaths below writable scopes.

§

FilesystemMissingPathBehavior

Enforce the error-or-skip behavior for missing concrete filesystem scopes.

§

FilesystemProtectedPaths

Enforce protected relative paths such as the default .git path.

§

NetworkDisabled

Disable outbound networking.

§

NetworkEnabled

Enforce local outbound networking.

§

NetworkExternal

Delegate network enforcement to an external owner.

§

NetworkDomainRules

Enforce domain rules and domain defaults.

§

NetworkLocalAddressRestrictions

Enforce the policy for non-public and special-purpose addresses.

§

NetworkResolvedTargets

Resolve once and authorize the exact address used for a connection.

§

NetworkLocalIpcIsolation

Prevent pathname local-IPC endpoint access while retaining process-local IPC.

§

NetworkLocalIpcRules

Enforce per-path local-IPC endpoint allow rules.

§

NetworkLocalIpcDenyRules

Enforce explicit pathname local-IPC deny rules when the default is otherwise allow-all.

§

NetworkWindowsNamedPipeRules

Enforce typed Windows named-pipe local-IPC endpoints.

§

EnvironmentAll

Start from all inherited environment variables.

§

EnvironmentCore

Start from a backend-selected core environment.

§

EnvironmentNone

Start from an empty environment.

§

EnvironmentFilters

Apply environment include and exclude filters.

§

EnvironmentOverrides

Apply environment set and remove overrides.

Trait Implementations§

Source§

impl Clone for BackendCapability

Source§

fn clone(&self) -> Self

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Copy for BackendCapability

Source§

impl Debug for BackendCapability

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Display for BackendCapability

Source§

fn fmt(&self, formatter: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Eq for BackendCapability

Source§

impl FromIterator<BackendCapability> for BackendCapabilities

Source§

fn from_iter<T: IntoIterator<Item = BackendCapability>>(iter: T) -> Self

Creates a value from an iterator. Read more
Source§

impl Hash for BackendCapability

Source§

fn hash<__H: Hasher>(&self, state: &mut __H)

Feeds this value into the given Hasher. Read more
1.3.0 · Source§

fn hash_slice<H>(data: &[Self], state: &mut H)
where H: Hasher, Self: Sized,

Feeds a slice of this type into the given Hasher. Read more
Source§

impl Ord for BackendCapability

Source§

fn cmp(&self, other: &Self) -> Ordering

This method returns an Ordering between self and other. Read more
1.21.0 (const: unstable) · Source§

fn max(self, other: Self) -> Self
where Self: Sized,

Compares and returns the maximum of two values. Read more
1.21.0 (const: unstable) · Source§

fn min(self, other: Self) -> Self
where Self: Sized,

Compares and returns the minimum of two values. Read more
1.50.0 (const: unstable) · Source§

fn clamp(self, min: Self, max: Self) -> Self
where Self: Sized,

Restrict a value to a certain interval. Read more
Source§

fn clamp_to<R>(self, range: R) -> Self
where Self: Sized, R: ClampBounds<Self>,

🔬This is a nightly-only experimental API. (clamp_to)
Restrict a value to a certain range. Read more
Source§

impl PartialEq for BackendCapability

Source§

fn eq(&self, other: &Self) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl PartialOrd for BackendCapability

Source§

fn partial_cmp(&self, other: &Self) -> Option<Ordering>

This method returns an ordering between self and other values if one exists. Read more
1.0.0 (const: unstable) · Source§

fn lt(&self, other: &Rhs) -> bool

Tests less than (for self and other) and is used by the < operator. Read more
1.0.0 (const: unstable) · Source§

fn le(&self, other: &Rhs) -> bool

Tests less than or equal to (for self and other) and is used by the <= operator. Read more
1.0.0 (const: unstable) · Source§

fn gt(&self, other: &Rhs) -> bool

Tests greater than (for self and other) and is used by the > operator. Read more
1.0.0 (const: unstable) · Source§

fn ge(&self, other: &Rhs) -> bool

Tests greater than or equal to (for self and other) and is used by the >= operator. Read more
Source§

impl StructuralPartialEq for BackendCapability

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T> ToString for T
where T: Display + ?Sized,

Source§

fn to_string(&self) -> String

Converts the given value to a String. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.