Skip to main content

SetupStep

Enum SetupStep 

Source
#[non_exhaustive]
#[repr(u32)]
pub enum SetupStep {
Show 54 variants Unshare = 1, DenySetgroups = 2, WriteGidMap = 3, WriteUidMap = 4, SetHostname = 5, ConfigureLoopback = 6, PrivatizeMounts = 7, BindRootfs = 8, EnterRootfs = 9, CreateMountTarget = 10, OpenMountTarget = 11, MountTmpfs = 12, MountDevpts = 13, BindMount = 14, RemountReadOnly = 15, CreateSymlink = 16, PivotRoot = 17, DetachOldRoot = 18, ChdirNewRoot = 19, ChdirWorkdir = 20, Exec = 21, ResetSignals = 22, ForkInit = 23, SendPidfd = 24, MountProc = 25, MountRaw = 26, SweepFds = 27, ForkCommand = 28, WatchCommand = 29, WireStdio = 30, DropCapabilities = 31, SetNoNewPrivs = 32, LandlockCreateRuleset = 33, LandlockAddRule = 34, LandlockRestrictSelf = 35, InstallSeccomp = 36, AwaitNetworkStack = 37, AwaitIdentityMap = 38, SetSecurebits = 39, SetGroups = 40, SetGid = 41, SetUid = 42, MountOverlayRoot = 43, SetRlimit = 44, NewSession = 45, SetControllingTerminal = 46, NestedUnshare = 47, NestedDenySetgroups = 48, NestedWriteGidMap = 49, NestedWriteUidMap = 50, AwaitNestedIdentityMap = 51, OpenSandboxProcfs = 52, NestedMapGate = 53, NosuidRootfs = 54,
}
Expand description

A step of the sandbox setup sequence, performed in the child process.

When a setup step fails inside the sandbox process, the failure is reported to the caller as Error::Setup, naming the step and the errno the kernel returned.

The explicit discriminants are the wire encoding of the setup-error pipe, which both ends of a single build write and read. They are an implementation detail: a step inserted in a later release renumbers the ones after it, and no discriminant is guaranteed to denote the same step across versions. Do not persist, transmit, or compare them — match on the variant, and use Display for a human-readable name.

Variants (Non-exhaustive)§

This enum is marked as non-exhaustive
Non-exhaustive enums could have additional variants added in future. Therefore, when matching against variants of non-exhaustive enums, an extra wildcard arm must be added to account for any future variants.
§

Unshare = 1

Unshare into the new namespaces.

§

DenySetgroups = 2

Write deny to /proc/self/setgroups.

§

WriteGidMap = 3

Write the single-identity gid map.

§

WriteUidMap = 4

Write the single-identity uid map.

§

SetHostname = 5

Set the sandbox hostname.

§

ConfigureLoopback = 6

Bring up the loopback interface in the isolated network namespace.

§

PrivatizeMounts = 7

Make mount propagation recursively private.

§

BindRootfs = 8

Bind the rootfs onto itself so it becomes a mount point.

§

EnterRootfs = 9

Enter the rootfs mount point.

§

CreateMountTarget = 10

Create a missing mount target inside the rootfs.

§

OpenMountTarget = 11

Open a mount target inside the rootfs.

§

MountTmpfs = 12

Mount a tmpfs.

§

MountDevpts = 13

Mount a devpts instance.

§

BindMount = 14

Bind-mount a host path into the rootfs.

§

RemountReadOnly = 15

Remount a bind mount read-only.

Create a symlink inside the rootfs.

§

PivotRoot = 17

Pivot the root into the rootfs.

§

DetachOldRoot = 18

Lazily detach the old root mount.

§

ChdirNewRoot = 19

Change directory to the new root.

§

ChdirWorkdir = 20

Change to the configured working directory.

§

Exec = 21

Execute the command.

§

ResetSignals = 22

Reset the inherited signal dispositions and mask.

§

ForkInit = 23

Fork the sandbox init process.

§

SendPidfd = 24

Send the supervisor’s pidfd back to the caller.

§

MountProc = 25

Mount a fresh procfs instance.

§

MountRaw = 26

Perform a raw mount.

§

SweepFds = 27

Sweep inherited file descriptors.

§

ForkCommand = 28

Fork the command process.

§

WatchCommand = 29

Open a pidfd for the command process.

§

WireStdio = 30

Wire the command’s standard streams.

§

DropCapabilities = 31

Drop or reduce the command’s capabilities.

§

SetNoNewPrivs = 32

Set the no-new-privileges flag before restricting the command.

§

LandlockCreateRuleset = 33

Create the Landlock ruleset.

§

LandlockAddRule = 34

Add a rule to the Landlock ruleset.

§

LandlockRestrictSelf = 35

Enforce the Landlock ruleset on the command.

§

InstallSeccomp = 36

Install the seccomp filter.

§

AwaitNetworkStack = 37

Wait at the launch gate for the caller to attach a network stack and release the command.

§

AwaitIdentityMap = 38

Wait for the caller’s delegate to establish the identity map.

§

SetSecurebits = 39

Lock the securebits that preserve capabilities across the identity switch.

§

SetGroups = 40

Set the command’s supplementary groups.

§

SetGid = 41

Switch to the command’s gid.

§

SetUid = 42

Switch to the command’s uid.

§

MountOverlayRoot = 43

Mount the overlay that roots an overlay-rooted cage.

§

SetRlimit = 44

Apply a resource limit to the command.

§

NewSession = 45

Start the sandbox’s own session, detaching it from the caller’s controlling terminal.

§

SetControllingTerminal = 46

Make the launch’s pseudoterminal the controlling terminal of the sandbox’s session.

§

NestedUnshare = 47

Enter the nested user namespace that locks the sandbox’s mount flags.

§

NestedDenySetgroups = 48

Write deny to the nested user namespace’s setgroups.

§

NestedWriteGidMap = 49

Write the nested user namespace’s gid map.

§

NestedWriteUidMap = 50

Write the nested user namespace’s uid map.

§

AwaitNestedIdentityMap = 51

Wait for the sandbox’s own delegate to establish the nested user namespace’s identity map.

§

OpenSandboxProcfs = 52

Open the procfs the nested user namespace’s identity map is established through.

§

NestedMapGate = 53

Create or operate the gate the nested identity map is established across.

§

NosuidRootfs = 54

Mark the sandbox’s root mount nosuid.

Trait Implementations§

Source§

impl Clone for SetupStep

Source§

fn clone(&self) -> SetupStep

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Copy for SetupStep

Source§

impl Debug for SetupStep

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Display for SetupStep

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Eq for SetupStep

Source§

impl Hash for SetupStep

Source§

fn hash<__H: Hasher>(&self, state: &mut __H)

Feeds this value into the given Hasher. Read more
1.3.0 · Source§

fn hash_slice<H>(data: &[Self], state: &mut H)
where H: Hasher, Self: Sized,

Feeds a slice of this type into the given Hasher. Read more
Source§

impl PartialEq for SetupStep

Source§

fn eq(&self, other: &SetupStep) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl StructuralPartialEq for SetupStep

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> Conv for T

Source§

fn conv<T>(self) -> T
where Self: Into<T>,

Converts self into T using Into<T>. Read more
Source§

impl<T> FmtForward for T

Source§

fn fmt_binary(self) -> FmtBinary<Self>
where Self: Binary,

Causes self to use its Binary implementation when Debug-formatted.
Source§

fn fmt_display(self) -> FmtDisplay<Self>
where Self: Display,

Causes self to use its Display implementation when Debug-formatted.
Source§

fn fmt_lower_exp(self) -> FmtLowerExp<Self>
where Self: LowerExp,

Causes self to use its LowerExp implementation when Debug-formatted.
Source§

fn fmt_lower_hex(self) -> FmtLowerHex<Self>
where Self: LowerHex,

Causes self to use its LowerHex implementation when Debug-formatted.
Source§

fn fmt_octal(self) -> FmtOctal<Self>
where Self: Octal,

Causes self to use its Octal implementation when Debug-formatted.
Source§

fn fmt_pointer(self) -> FmtPointer<Self>
where Self: Pointer,

Causes self to use its Pointer implementation when Debug-formatted.
Source§

fn fmt_upper_exp(self) -> FmtUpperExp<Self>
where Self: UpperExp,

Causes self to use its UpperExp implementation when Debug-formatted.
Source§

fn fmt_upper_hex(self) -> FmtUpperHex<Self>
where Self: UpperHex,

Causes self to use its UpperHex implementation when Debug-formatted.
Source§

fn fmt_list(self) -> FmtList<Self>
where &'a Self: for<'a> IntoIterator,

Formats each item in a sequence. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Pipe for T
where T: ?Sized,

Source§

fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> R
where Self: Sized,

Pipes by value. This is generally the method you want to use. Read more
Source§

fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> R
where R: 'a,

Borrows self and passes that borrow into the pipe function. Read more
Source§

fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> R
where R: 'a,

Mutably borrows self and passes that borrow into the pipe function. Read more
Source§

fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
where Self: Borrow<B>, B: 'a + ?Sized, R: 'a,

Borrows self, then passes self.borrow() into the pipe function. Read more
Source§

fn pipe_borrow_mut<'a, B, R>( &'a mut self, func: impl FnOnce(&'a mut B) -> R, ) -> R
where Self: BorrowMut<B>, B: 'a + ?Sized, R: 'a,

Mutably borrows self, then passes self.borrow_mut() into the pipe function. Read more
Source§

fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
where Self: AsRef<U>, U: 'a + ?Sized, R: 'a,

Borrows self, then passes self.as_ref() into the pipe function.
Source§

fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
where Self: AsMut<U>, U: 'a + ?Sized, R: 'a,

Mutably borrows self, then passes self.as_mut() into the pipe function.
Source§

fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
where Self: Deref<Target = T>, T: 'a + ?Sized, R: 'a,

Borrows self, then passes self.deref() into the pipe function.
Source§

fn pipe_deref_mut<'a, T, R>( &'a mut self, func: impl FnOnce(&'a mut T) -> R, ) -> R
where Self: DerefMut<Target = T> + Deref, T: 'a + ?Sized, R: 'a,

Mutably borrows self, then passes self.deref_mut() into the pipe function.
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> Tap for T

Source§

fn tap(self, func: impl FnOnce(&Self)) -> Self

Immutable access to a value. Read more
Source§

fn tap_mut(self, func: impl FnOnce(&mut Self)) -> Self

Mutable access to a value. Read more
Source§

fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
where Self: Borrow<B>, B: ?Sized,

Immutable access to the Borrow<B> of a value. Read more
Source§

fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
where Self: BorrowMut<B>, B: ?Sized,

Mutable access to the BorrowMut<B> of a value. Read more
Source§

fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
where Self: AsRef<R>, R: ?Sized,

Immutable access to the AsRef<R> view of a value. Read more
Source§

fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
where Self: AsMut<R>, R: ?Sized,

Mutable access to the AsMut<R> view of a value. Read more
Source§

fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
where Self: Deref<Target = T>, T: ?Sized,

Immutable access to the Deref::Target of a value. Read more
Source§

fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
where Self: DerefMut<Target = T> + Deref, T: ?Sized,

Mutable access to the Deref::Target of a value. Read more
Source§

fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self

Calls .tap() only in debug builds, and is erased in release builds.
Source§

fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self

Calls .tap_mut() only in debug builds, and is erased in release builds.
Source§

fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
where Self: Borrow<B>, B: ?Sized,

Calls .tap_borrow() only in debug builds, and is erased in release builds.
Source§

fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
where Self: BorrowMut<B>, B: ?Sized,

Calls .tap_borrow_mut() only in debug builds, and is erased in release builds.
Source§

fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
where Self: AsRef<R>, R: ?Sized,

Calls .tap_ref() only in debug builds, and is erased in release builds.
Source§

fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
where Self: AsMut<R>, R: ?Sized,

Calls .tap_ref_mut() only in debug builds, and is erased in release builds.
Source§

fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
where Self: Deref<Target = T>, T: ?Sized,

Calls .tap_deref() only in debug builds, and is erased in release builds.
Source§

fn tap_deref_mut_dbg<T>(self, func: impl FnOnce(&mut T)) -> Self
where Self: DerefMut<Target = T> + Deref, T: ?Sized,

Calls .tap_deref_mut() only in debug builds, and is erased in release builds.
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T> ToString for T
where T: Display + ?Sized,

Source§

fn to_string(&self) -> String

Converts the given value to a String. Read more
Source§

impl<T> TryConv for T

Source§

fn try_conv<T>(self) -> Result<T, Self::Error>
where Self: TryInto<T>,

Attempts to convert self into T using TryInto<T>. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V