pub enum ObservationCapability {
Show 16 variants
ProcessSpawnLineage,
ProcessExecOccurrence,
ProcessExecPathIdentity,
ProcessExit,
PathAccessIntent,
SuccessfulOpenFdIdentity,
OpenPathIdentity,
FdReadWriteEffect,
FdDupCloseLifecycle,
ForkFdInheritance,
CloseOnExec,
RenameDeleteEffects,
NetworkConnectDestination,
TraceTimeRelativePath,
CausalExecutableChain,
LossTruncationVisibility,
}Expand description
Typed observation capability vocabulary introduced by M8.3.
Occurrence and path-identity capabilities are deliberately separate. A backend that can prove that an exec/open happened must not thereby claim it established the path required by the existing ExecSurface raw model.
Variants§
ProcessSpawnLineage
ProcessExecOccurrence
ProcessExecPathIdentity
ProcessExit
PathAccessIntent
SuccessfulOpenFdIdentity
OpenPathIdentity
FdReadWriteEffect
FdDupCloseLifecycle
ForkFdInheritance
CloseOnExec
RenameDeleteEffects
NetworkConnectDestination
TraceTimeRelativePath
CausalExecutableChain
LossTruncationVisibility
Trait Implementations§
Source§impl Clone for ObservationCapability
impl Clone for ObservationCapability
impl Copy for ObservationCapability
Source§impl Debug for ObservationCapability
impl Debug for ObservationCapability
impl Eq for ObservationCapability
Source§impl Ord for ObservationCapability
impl Ord for ObservationCapability
1.21.0 (const: unstable) · Source§fn max(self, other: Self) -> Selfwhere
Self: Sized,
fn max(self, other: Self) -> Selfwhere
Self: Sized,
Compares and returns the maximum of two values. Read more
1.21.0 (const: unstable) · Source§fn min(self, other: Self) -> Selfwhere
Self: Sized,
fn min(self, other: Self) -> Selfwhere
Self: Sized,
Compares and returns the minimum of two values. Read more
Source§impl PartialEq for ObservationCapability
impl PartialEq for ObservationCapability
Source§impl PartialOrd for ObservationCapability
impl PartialOrd for ObservationCapability
impl StructuralPartialEq for ObservationCapability
Auto Trait Implementations§
impl Freeze for ObservationCapability
impl RefUnwindSafe for ObservationCapability
impl Send for ObservationCapability
impl Sync for ObservationCapability
impl Unpin for ObservationCapability
impl UnsafeUnpin for ObservationCapability
impl UnwindSafe for ObservationCapability
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more