Skip to main content

SecureProcess

Struct SecureProcess 

Source
pub struct SecureProcess { /* private fields */ }
Expand description

Launch a child process with hardware-backed secrets injected.

The run() method provides full security guarantees:

  • Secret env var values are mlocked before spawn and zeroized after the child exits.
  • The spawned child inherits RLIMIT_CORE=0 on Unix (preventing core dumps of the secret-laden environment).

The exec() method provides weaker guarantees:

  • Secrets are NOT mlocked (they are passed via Command::env without locking).
  • Secrets are NOT zeroized (the current process is replaced; no cleanup runs).
  • Prefer run() for Type 2 secret delivery. Use exec() only when you need to replace the current process image and accept the weaker guarantees.

Implementations§

Source§

impl SecureProcess

Source

pub fn new(program: impl Into<PathBuf>) -> Self

Source

pub fn arg(self, a: impl Into<OsString>) -> Self

Source

pub fn args(self, args: impl IntoIterator<Item = impl Into<OsString>>) -> Self

Source

pub fn secret_env( self, key: impl Into<String>, value: impl Into<String>, ) -> Self

Inject a secret value as an environment variable (Type 2 delivery). The value is mlocked and zeroized after the child exits.

Source

pub fn env(self, key: impl Into<String>, value: impl Into<String>) -> Self

Add a non-secret environment variable (e.g. a config file path).

Source

pub fn env_remove(self, key: impl Into<String>) -> Self

Remove an environment variable from the child’s environment.

Source

pub fn scrub(self, pattern: impl Into<String>) -> Self

Scrub inherited env vars matching this pattern before spawning. Accepts exact names or prefix patterns ending in *.

Source

pub fn run(self) -> Result<ExitStatus>

Spawn the child and wait for it to exit. Zeroizes secret env vars after child returns.

Source

pub fn exec(self) -> Result<Infallible>

Replace the current process image via execve() (Unix). On Windows, falls back to run() since CreateProcess cannot replace the calling image.

WARNING: secret env var zeroization is NOT possible after exec() because the current process no longer exists. Use run() when zeroization matters.

Trait Implementations§

Source§

impl Debug for SecureProcess

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more