Enum libscmp::Flag[][src]

#[non_exhaustive]
#[repr(i32)]
pub enum Flag {
    NoNewPrivs,
    Tsync,
    Tskip,
    Log,
    DisableSSB,
    SysRawRC,
}
Expand description

Represents a boolean flag that can be set on a filter.

Variants (Non-exhaustive)

This enum is marked as non-exhaustive
Non-exhaustive enums could have additional variants added in future. Therefore, when matching against variants of non-exhaustive enums, an extra wildcard arm must be added to account for any future variants.
NoNewPrivs

Whether libseccomp should enable the “no-new-privs” mechanism before loading the seccomp filter (default true).

In most cases, this should be set to true.

Tsync

Whether the kernel should attempt to synchronize the seccomp filters across all threads when loading them into the kernel (default false).

This is only supported on Linux 3.17+, and it may cause loading the seccomp filters to fail.

Tskip

Whether libseccomp should allow filter rules that target the -1 syscall (sometimes used by ptrace()rs to skip syscalls; default false). Only supported on libseccomp v2.4.0+.

Log

Whether the kernel should log all non-“allow” actions taken (default false). Only supported on libseccomp v2.4.0+.

DisableSSB

Whether to disable Speculative Store Bypass mitigation for this filter (default false). Only supported on libseccomp v2.5.0+.

SysRawRC

Whether libseccomp should pass system error codes back to the caller instead of returning ECANCELED (default false). Only supported on libseccomp v2.5.0+.

Note: Use of this option is not reccommended. The Error struct already specially checks for ECANCELED and retrieves the value of errno in that case; enabling this option will simply make the returned errors more confusing.

Trait Implementations

Returns a copy of the value. Read more

Performs copy-assignment from source. Read more

Formats the value using the given formatter. Read more

Feeds this value into the given Hasher. Read more

Feeds a slice of this type into the given Hasher. Read more

This method tests for self and other values to be equal, and is used by ==. Read more

This method tests for !=.

Auto Trait Implementations

Blanket Implementations

Gets the TypeId of self. Read more

Immutably borrows from an owned value. Read more

Mutably borrows from an owned value. Read more

Performs the conversion.

Performs the conversion.

The resulting type after obtaining ownership.

Creates owned data from borrowed data, usually by cloning. Read more

🔬 This is a nightly-only experimental API. (toowned_clone_into)

recently added

Uses borrowed data to replace owned data, usually by cloning. Read more

The type returned in the event of a conversion error.

Performs the conversion.

The type returned in the event of a conversion error.

Performs the conversion.