pub struct SandboxConfig {
pub enforce: SandboxEnforce,
pub provider: SandboxProvider,
pub image: Option<String>,
pub extra_write: Vec<String>,
pub egress: Vec<String>,
}Expand description
Per-role OS sandbox config.
Fields§
§enforce: SandboxEnforce§provider: SandboxProviderSandbox provider: process (default, tier 2) or container (tier 3).
container with enforce = "off" means no sandboxing, same as today.
image: Option<String>Container image used when provider = "container". Defaults to
sandbox_container::DEFAULT_IMAGE when unset.
extra_write: Vec<String>Extra paths the operator opts into as writable (e.g. “~/.cargo”). Stored as raw strings; not expanded or canonicalized here.
egress: Vec<String>Extra network destinations allowed under enforce = "fs+net" (for
example package registries). Stored as host:port strings. With
provider = "container" a non-empty list is refused by
config::validate (proxy-env advisory only — see
SandboxProvider::enforces_hard_net_boundary); an empty list keeps
the hard --network none boundary.
Trait Implementations§
Source§impl Clone for SandboxConfig
impl Clone for SandboxConfig
Source§fn clone(&self) -> SandboxConfig
fn clone(&self) -> SandboxConfig
Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
Performs copy-assignment from
source. Read moreSource§impl Debug for SandboxConfig
impl Debug for SandboxConfig
Source§impl Default for SandboxConfig
impl Default for SandboxConfig
Source§fn default() -> SandboxConfig
fn default() -> SandboxConfig
Returns the “default value” for a type. Read more
Source§impl<'de> Deserialize<'de> for SandboxConfigwhere
SandboxConfig: Default,
impl<'de> Deserialize<'de> for SandboxConfigwhere
SandboxConfig: Default,
Source§fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
Deserialize this value from the given Serde deserializer. Read more
Source§impl PartialEq for SandboxConfig
impl PartialEq for SandboxConfig
Source§impl Serialize for SandboxConfig
impl Serialize for SandboxConfig
impl StructuralPartialEq for SandboxConfig
Auto Trait Implementations§
impl Freeze for SandboxConfig
impl RefUnwindSafe for SandboxConfig
impl Send for SandboxConfig
impl Sync for SandboxConfig
impl Unpin for SandboxConfig
impl UnsafeUnpin for SandboxConfig
impl UnwindSafe for SandboxConfig
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more