Skip to main content

BoundUnixSocket

Struct BoundUnixSocket 

Source
pub struct BoundUnixSocket { /* private fields */ }
Expand description

A bound AF_UNIX socket file: the node exists as long as this value does.

Hold it beside the UnixListener it was bound with. Dropping it removes the node, which is what keeps the next bind of the same path out of the unlink-then-bind race below.

Implementations§

Source§

impl BoundUnixSocket

Source

pub fn bind(path: &Path) -> Result<(BoundUnixSocket, UnixListener), Error>

Binds path with the hygiene a filesystem endpoint needs, replacing a stale socket file left by a crash.

Four things happen here, and each answers a documented hazard:

  1. The path budget. sun_path is 108 bytes on Linux and 104 on macOS including the terminator, and the kernel truncates rather than failing, so an over-long path binds something other than what was asked for. It is refused instead (docs/research/ipc.md §1.1, §2.1). libzmq’s ipc:// publishes the same limit as “113 characters including the prefix” and leaves the rest to the caller (docs/research/zeromq.md §11).
  2. The socket-type check. Closing a socket does not remove its node, so a crash leaves one and bind() then fails with EADDRINUSE. A stale node is a socket nobody is listening on; anything else at that path is not ours to remove, and removing it anyway is how a bind deletes a caller’s data.
  3. Unlink, then bind. The usual answer to the stale node, and it opens a substitution race that is closed only “unless directory ownership and permissions prevent endpoint substitution” (docs/research/ipc.md §1.2, §7). The directory is therefore load-bearing: the caller MUST place the socket in a directory it owns and that no other user may write. libzmq’s ipc:// has this hazard too and answers none of it — a local process can steal a bound endpoint.
  4. The mode, explicitly. 0600 set after bind, because a socket file is created with whatever umask allows, which is whatever the process happened to inherit.
Source

pub fn path(&self) -> &Path

The path this socket is bound at.

Trait Implementations§

Source§

impl Debug for BoundUnixSocket

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Drop for BoundUnixSocket

Source§

fn drop(&mut self)

Executes the destructor for this type. Read more
Source§

fn pin_drop(self: Pin<&mut Self>)

🔬This is a nightly-only experimental API. (pin_ergonomics)
Execute the destructor for this type, but different to Drop::drop, it requires self to be pinned. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.