#[non_exhaustive]#[repr(u32)]pub enum SetupStep {
Show 54 variants
Unshare = 1,
DenySetgroups = 2,
WriteGidMap = 3,
WriteUidMap = 4,
SetHostname = 5,
ConfigureLoopback = 6,
PrivatizeMounts = 7,
BindRootfs = 8,
EnterRootfs = 9,
CreateMountTarget = 10,
OpenMountTarget = 11,
MountTmpfs = 12,
MountDevpts = 13,
BindMount = 14,
RemountReadOnly = 15,
CreateSymlink = 16,
PivotRoot = 17,
DetachOldRoot = 18,
ChdirNewRoot = 19,
ChdirWorkdir = 20,
Exec = 21,
ResetSignals = 22,
ForkInit = 23,
SendPidfd = 24,
MountProc = 25,
MountRaw = 26,
SweepFds = 27,
ForkCommand = 28,
WatchCommand = 29,
WireStdio = 30,
DropCapabilities = 31,
SetNoNewPrivs = 32,
LandlockCreateRuleset = 33,
LandlockAddRule = 34,
LandlockRestrictSelf = 35,
InstallSeccomp = 36,
AwaitNetworkStack = 37,
AwaitIdentityMap = 38,
SetSecurebits = 39,
SetGroups = 40,
SetGid = 41,
SetUid = 42,
MountOverlayRoot = 43,
SetRlimit = 44,
NewSession = 45,
SetControllingTerminal = 46,
NestedUnshare = 47,
NestedDenySetgroups = 48,
NestedWriteGidMap = 49,
NestedWriteUidMap = 50,
AwaitNestedIdentityMap = 51,
OpenSandboxProcfs = 52,
NestedMapGate = 53,
NosuidRootfs = 54,
}Expand description
A step of the sandbox setup sequence, performed in the child process.
When a setup step fails inside the sandbox process, the failure is
reported to the caller as Error::Setup, naming the step and the
errno the kernel returned.
The explicit discriminants are the wire encoding of the setup-error
pipe, which both ends of a single build write and read. They are an
implementation detail: a step inserted in a later release renumbers the
ones after it, and no discriminant is guaranteed to denote the same step
across versions. Do not persist, transmit, or compare them — match on
the variant, and use Display for a human-readable
name.
Variants (Non-exhaustive)§
This enum is marked as non-exhaustive
Unshare into the new namespaces.
DenySetgroups = 2
Write deny to /proc/self/setgroups.
WriteGidMap = 3
Write the single-identity gid map.
WriteUidMap = 4
Write the single-identity uid map.
SetHostname = 5
Set the sandbox hostname.
ConfigureLoopback = 6
Bring up the loopback interface in the isolated network namespace.
PrivatizeMounts = 7
Make mount propagation recursively private.
BindRootfs = 8
Bind the rootfs onto itself so it becomes a mount point.
EnterRootfs = 9
Enter the rootfs mount point.
CreateMountTarget = 10
Create a missing mount target inside the rootfs.
OpenMountTarget = 11
Open a mount target inside the rootfs.
MountTmpfs = 12
Mount a tmpfs.
MountDevpts = 13
Mount a devpts instance.
BindMount = 14
Bind-mount a host path into the rootfs.
RemountReadOnly = 15
Remount a bind mount read-only.
CreateSymlink = 16
Create a symlink inside the rootfs.
PivotRoot = 17
Pivot the root into the rootfs.
DetachOldRoot = 18
Lazily detach the old root mount.
ChdirNewRoot = 19
Change directory to the new root.
ChdirWorkdir = 20
Change to the configured working directory.
Exec = 21
Execute the command.
ResetSignals = 22
Reset the inherited signal dispositions and mask.
ForkInit = 23
Fork the sandbox init process.
SendPidfd = 24
Send the supervisor’s pidfd back to the caller.
MountProc = 25
Mount a fresh procfs instance.
MountRaw = 26
Perform a raw mount.
SweepFds = 27
Sweep inherited file descriptors.
ForkCommand = 28
Fork the command process.
WatchCommand = 29
Open a pidfd for the command process.
WireStdio = 30
Wire the command’s standard streams.
DropCapabilities = 31
Drop or reduce the command’s capabilities.
SetNoNewPrivs = 32
Set the no-new-privileges flag before restricting the command.
LandlockCreateRuleset = 33
Create the Landlock ruleset.
LandlockAddRule = 34
Add a rule to the Landlock ruleset.
LandlockRestrictSelf = 35
Enforce the Landlock ruleset on the command.
InstallSeccomp = 36
Install the seccomp filter.
AwaitNetworkStack = 37
Wait at the launch gate for the caller to attach a network stack and release the command.
AwaitIdentityMap = 38
Wait for the caller’s delegate to establish the identity map.
SetSecurebits = 39
Lock the securebits that preserve capabilities across the identity switch.
SetGroups = 40
Set the command’s supplementary groups.
SetGid = 41
Switch to the command’s gid.
SetUid = 42
Switch to the command’s uid.
MountOverlayRoot = 43
Mount the overlay that roots an overlay-rooted cage.
SetRlimit = 44
Apply a resource limit to the command.
NewSession = 45
Start the sandbox’s own session, detaching it from the caller’s controlling terminal.
SetControllingTerminal = 46
Make the launch’s pseudoterminal the controlling terminal of the sandbox’s session.
Enter the nested user namespace that locks the sandbox’s mount flags.
NestedDenySetgroups = 48
Write deny to the nested user namespace’s setgroups.
NestedWriteGidMap = 49
Write the nested user namespace’s gid map.
NestedWriteUidMap = 50
Write the nested user namespace’s uid map.
AwaitNestedIdentityMap = 51
Wait for the sandbox’s own delegate to establish the nested user namespace’s identity map.
OpenSandboxProcfs = 52
Open the procfs the nested user namespace’s identity map is established through.
NestedMapGate = 53
Create or operate the gate the nested identity map is established across.
NosuidRootfs = 54
Mark the sandbox’s root mount nosuid.
Trait Implementations§
impl Copy for SetupStep
impl Eq for SetupStep
impl StructuralPartialEq for SetupStep
Auto Trait Implementations§
impl Freeze for SetupStep
impl RefUnwindSafe for SetupStep
impl Send for SetupStep
impl Sync for SetupStep
impl Unpin for SetupStep
impl UnsafeUnpin for SetupStep
impl UnwindSafe for SetupStep
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<T> FmtForward for T
impl<T> FmtForward for T
Source§fn fmt_binary(self) -> FmtBinary<Self>where
Self: Binary,
fn fmt_binary(self) -> FmtBinary<Self>where
Self: Binary,
self to use its Binary implementation when Debug-formatted.Source§fn fmt_display(self) -> FmtDisplay<Self>where
Self: Display,
fn fmt_display(self) -> FmtDisplay<Self>where
Self: Display,
self to use its Display implementation when
Debug-formatted.Source§fn fmt_lower_exp(self) -> FmtLowerExp<Self>where
Self: LowerExp,
fn fmt_lower_exp(self) -> FmtLowerExp<Self>where
Self: LowerExp,
self to use its LowerExp implementation when
Debug-formatted.Source§fn fmt_lower_hex(self) -> FmtLowerHex<Self>where
Self: LowerHex,
fn fmt_lower_hex(self) -> FmtLowerHex<Self>where
Self: LowerHex,
self to use its LowerHex implementation when
Debug-formatted.Source§fn fmt_octal(self) -> FmtOctal<Self>where
Self: Octal,
fn fmt_octal(self) -> FmtOctal<Self>where
Self: Octal,
self to use its Octal implementation when Debug-formatted.Source§fn fmt_pointer(self) -> FmtPointer<Self>where
Self: Pointer,
fn fmt_pointer(self) -> FmtPointer<Self>where
Self: Pointer,
self to use its Pointer implementation when
Debug-formatted.Source§fn fmt_upper_exp(self) -> FmtUpperExp<Self>where
Self: UpperExp,
fn fmt_upper_exp(self) -> FmtUpperExp<Self>where
Self: UpperExp,
self to use its UpperExp implementation when
Debug-formatted.Source§fn fmt_upper_hex(self) -> FmtUpperHex<Self>where
Self: UpperHex,
fn fmt_upper_hex(self) -> FmtUpperHex<Self>where
Self: UpperHex,
self to use its UpperHex implementation when
Debug-formatted.Source§impl<T> Pipe for Twhere
T: ?Sized,
impl<T> Pipe for Twhere
T: ?Sized,
Source§fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> Rwhere
Self: Sized,
fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> Rwhere
Self: Sized,
Source§fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> Rwhere
R: 'a,
fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> Rwhere
R: 'a,
self and passes that borrow into the pipe function. Read moreSource§fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> Rwhere
R: 'a,
fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> Rwhere
R: 'a,
self and passes that borrow into the pipe function. Read moreSource§fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
Source§fn pipe_borrow_mut<'a, B, R>(
&'a mut self,
func: impl FnOnce(&'a mut B) -> R,
) -> R
fn pipe_borrow_mut<'a, B, R>( &'a mut self, func: impl FnOnce(&'a mut B) -> R, ) -> R
Source§fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
self, then passes self.as_ref() into the pipe function.Source§fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
self, then passes self.as_mut() into the pipe
function.Source§fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
self, then passes self.deref() into the pipe function.impl<T> Read<Exclusive, BecauseExclusive> for Twhere
T: ?Sized,
Source§impl<T> Tap for T
impl<T> Tap for T
Source§fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
Borrow<B> of a value. Read moreSource§fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
BorrowMut<B> of a value. Read moreSource§fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
AsRef<R> view of a value. Read moreSource§fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
AsMut<R> view of a value. Read moreSource§fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
Deref::Target of a value. Read moreSource§fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
Deref::Target of a value. Read moreSource§fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self
fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self
.tap() only in debug builds, and is erased in release builds.Source§fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self
fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self
.tap_mut() only in debug builds, and is erased in release
builds.Source§fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
.tap_borrow() only in debug builds, and is erased in release
builds.Source§fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
.tap_borrow_mut() only in debug builds, and is erased in release
builds.Source§fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
.tap_ref() only in debug builds, and is erased in release
builds.Source§fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
.tap_ref_mut() only in debug builds, and is erased in release
builds.Source§fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
.tap_deref() only in debug builds, and is erased in release
builds.