Skip to main content

StableDirectory

Struct StableDirectory 

Source
pub struct StableDirectory { /* private fields */ }
Expand description

Retained directory capability whose children are opened without following links or reparse points.

Implementations§

Source§

impl StableDirectory

Source

pub fn try_clone(&self) -> Result<Self>

Duplicate this retained directory capability without resolving its path again.

§Errors

Returns an error if the retained directory identity changed or the OS cannot duplicate its handle.

Source

pub fn lock_shared(&self) -> Result<()>

Acquire a cooperative shared lock on this retained Unix directory inode.

Windows directory handles cannot be byte-range locked; callers use a retained regular coordination file there instead.

Source

pub fn lock_exclusive(&self) -> Result<()>

Acquire a cooperative exclusive lock on this retained Unix directory inode.

Source

pub fn try_lock_exclusive(&self) -> Result<bool>

Try to acquire a cooperative exclusive lock on this retained Unix directory inode.

Source

pub fn unlock(&self) -> Result<()>

Release this retained Unix directory inode’s cooperative lock.

Source

pub fn open(path: &Path) -> Result<Self>

Open and retain a real directory at path.

Source

pub fn from_retained_handle( path: PathBuf, handle: OpenedDirectoryHandle, identity: FileIdentity, ) -> Result<Self, DirectoryValidationError>

Adopt an already retained handle and expected identity, validating both the named path and the handle before issuing a directory capability.

Source

pub fn as_file(&self) -> &File ⓘ

Borrow the retained handle for native volume queries and cooperative locks. Callers must revalidate around namespace-sensitive operations.

Source

pub fn path(&self) -> &Path

Return the named path associated with this capability.

Source

pub fn into_handle(self) -> OpenedDirectoryHandle

Transfer the policy-proven native handle for adoption by another capability.

Source

pub fn revalidate_named_detailed(&self) -> Result<(), DirectoryValidationError>

Require that the named path and retained handle still identify this ordinary directory, returning a typed failure stage for policy adapters.

Source

pub fn revalidate_named(&self) -> Result<()>

Require that the named path still identifies this retained directory.

Source

pub fn open_child_directory(&self, name: &OsStr) -> Result<Self>

Open one real child directory relative to this capability.

Source

pub fn create_child_directory(&self, name: &OsStr) -> Result<Self>

Create one child directory if absent, then retain it.

Source

pub fn open_child_file(&self, name: &OsStr) -> Result<File>

Open one regular child without following links or reparse points.

Source

pub fn revalidate_child_file(&self, name: &OsStr, file: &File) -> Result<()>

Revalidate a retained regular child against its current named path.

Performs the same fresh directory and child observations as opening the child, without replacing the retained handle or its seek position.

Source

pub fn open_publishing_child_file( &self, name: &OsStr, expected: FileIdentity, ) -> Result<File>

Reopen an already-admitted private publication source with write access for its file barrier and Windows delete sharing for its native rename. Ordinary immutable readers retain their existing anti-delete sharing.

Source

pub fn visit_regular_files( &self, remaining: &mut usize, visit: &mut impl FnMut(&File) -> Result<()>, ) -> Result<()>

Visit regular descendants through retained, no-follow directory handles.

Every child is opened relative to its retained parent and revalidated before it reaches visit. Links and non-regular objects are skipped.

§Errors

Returns an error if traversal exceeds remaining, a retained identity changes, directory enumeration fails, or visit fails. Targets without descriptor-relative directory enumeration return Unsupported.

Source

pub fn create_child_file(&self, name: &OsStr) -> Result<File>

Create one new regular child without following links or reparse points.

Source

pub fn create_replaceable_child_file(&self, name: &OsStr) -> Result<File>

Create a new regular child whose retained handle permits an atomic namespace replacement while it remains open.

Source

pub fn create_unpublished_replaceable_child( &self, name: &OsStr, ) -> Result<UnpublishedArtifactGuard>

Exclusively create one replaceable child and immediately bind cleanup ownership to its retained descriptor identity.

§Errors

Returns an error when creation, identity capture, or directory-capability cloning fails. Setup failure removes the exact created inode when safe.

Source

pub fn open_or_create_child_file(&self, name: &OsStr) -> Result<File>

Open an existing regular child for read/write, or create it once.

Source

pub fn child_names(&self) -> Result<Vec<OsString>>

Enumerate child names while retaining this directory capability.

Source

pub fn child_names_bounded(&self, limit: usize) -> Result<Vec<OsString>>

Enumerate no more than limit child names from this retained directory. Returns InvalidData instead of materializing an attacker-sized sibling inventory when the bound is exceeded.

Create a hard link between retained source and destination directories.

Remove a child under the caller’s held cooperative exclusive lifecycle guard, only while its current named identity matches expected.

Source

pub fn remove_child_directory_if_identity( &self, name: &OsStr, expected: FileIdentity, ) -> Result<()>

Remove one empty child directory only while its retained and named identities still match. Callers must first authenticate and empty the directory through the returned child capability.

Source

pub fn replace_child( &self, temporary: &OsStr, expected_temporary: FileIdentity, target: &OsStr, ) -> Result<()>

Atomically publish a retained temporary child as target within this retained directory. Cooperative publishers must serialize the target.

Source

pub fn replace_child_typed( &self, temporary: &OsStr, expected_temporary: FileIdentity, target: &OsStr, ) -> Result<(), ReplaceFileError>

Replace one child while retaining native visibility uncertainty.

Source

pub fn replace_authenticated_child( &self, temporary: &OsStr, expected_temporary: FileIdentity, target: &OsStr, expected_target: FileIdentity, ) -> Result<()>

Atomically replace an authenticated prior child, which may share its inode with immutable payloads or active snapshots. The source must be private. Callers must authenticate the prior contents and serialize publishers; this operation checks identity and never writes to the prior inode.

Source

pub fn replace_authenticated_child_typed( &self, temporary: &OsStr, expected_temporary: FileIdentity, target: &OsStr, expected_target: FileIdentity, ) -> Result<(), ReplaceFileError>

Replace an authenticated prior child without losing native error state.

Source

pub fn install_child( &self, temporary: &OsStr, expected_temporary: FileIdentity, target: &OsStr, ) -> Result<()>

Atomically install a retained temporary child without replacing an existing target. This is the creation authority for durable control records whose first publication must never overwrite competing state.

§Errors

Returns an I/O error when either name is invalid, the retained source identity changed, the target already exists, or durable installation and identity revalidation fail.

Source

pub fn install_child_typed( &self, temporary: &OsStr, expected_temporary: FileIdentity, target: &OsStr, ) -> Result<(), ReplaceFileError>

Preserve whether create-only publication definitely did not install or reached a native visibility boundary whose result needs reconciliation.

Source

pub fn sync(&self) -> Result<()>

Flush this retained directory capability.

Source

pub fn identity(&self) -> FileIdentity

Return the retained native identity.

Trait Implementations§

Source§

impl Debug for StableDirectory

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.