Skip to main content

SmoltcpNetwork

Struct SmoltcpNetwork 

Source
pub struct SmoltcpNetwork { /* private fields */ }
Expand description

The networking engine. Created from crate::config::NetworkConfig by the runtime.

Owns the smoltcp poll thread and provides:

Implementations§

Source§

impl SmoltcpNetwork

Source

pub fn default_gateway_mac(slot: u16) -> [u8; 6]

Gateway identity for an ordinary cold boot in the given host slot.

Source

pub fn with_captured_gateway_mac( self, mac: [u8; 6], ) -> Result<Self, NetworkInitError>

Preserve a captured gateway before starting this fresh network backend.

Host sockets, policy, queues and port ownership remain child-owned. Only the Ethernet identity visible to captured ARP/ND caches is retained. Panics if called after the network poll thread has started.

Source

pub fn new( config: ResolvedNetworkConfig, slot: u16, deployment_profile: DeploymentProfile, ) -> Result<Self, NetworkInitError>

Creates the network backend from a fully resolved runtime configuration.

MultiTenant applies platform-owned configuration floors before any sockets, resolvers, or TLS state are created. The requested tenant policy remains separate and is intersected with the platform’s public-network policy by the poll loop.

§Errors

Returns an error when the effective network configuration would allocate unsafe resources or TLS interception cannot initialize.

Source

pub fn defer_activation(&mut self) -> NetworkActivationHandle

Hold network processing and published-port creation behind an explicit one-shot gate.

This must be selected before start. It is used by checkpoint restore so ingress cannot reach the child until guest activation has completed. The gate is consumed once at poll-thread startup and adds no checks to steady-state packet processing.

Source

pub fn start(&mut self, tokio_handle: Handle)

Start the smoltcp poll thread.

Must be called before VM boot. Requires a tokio runtime handle for spawning proxy tasks, DNS resolution, and published port listeners.

Source

pub fn take_backend(&mut self) -> Box<dyn NetBackend + Send>

Take the NetBackend for VmBuilder::net(). One-shot.

Source

pub fn guest_mac(&self) -> [u8; 6]

Guest MAC address for VmBuilder::net().mac().

Source

pub fn guest_env_vars(&self) -> Vec<(String, String)>

Generate MSB_NET* environment variables for the guest.

The guest init (agentd) reads these to configure the network interface via ioctls + netlink.

Source

pub fn guest_bootstrap_network(&self) -> BootstrapNetwork

Build the typed network payload consumed by agentd during bootstrap.

Source

pub fn guest_host_alias(&self) -> &'static str

Return the stable hostname used by guests to address the host gateway.

Source

pub fn guest_secret_env(&self) -> Vec<BootstrapEnvVar>

Return guest-visible secret placeholders for the baseline environment.

Real secret values stay in the host-side network handler and never enter this payload.

Source

pub fn ca_cert_pem(&self) -> Option<Vec<u8>>

CA certificate PEM bytes if TLS interception is enabled.

Write to the runtime mount before VM boot so the guest can trust it.

Source

pub fn host_cas_cert_pem(&self) -> Option<Vec<u8>>

Host-trusted CA bundle to ship into the guest, if crate::config::NetworkConfig::trust_host_cas is enabled.

Returned PEM may concatenate CAs that the Mozilla root bundle in the guest already trusts; duplicates are harmless and saved the cost of computing a delta. Returns None when the host store is empty or the feature is disabled.

Source

pub fn termination_handle(&self) -> TerminationHandle

Create a handle for wiring runtime termination into the network stack.

Source

pub fn metrics_handle(&self) -> MetricsHandle

Create a handle for reading aggregate network byte counters.

Source

pub fn secrets_handle(&self) -> SecretsHandle

Live-swappable view of the secrets configuration. The runtime control socket uses it to apply secret rotation, removal, and allowed-host updates without restarting the sandbox.

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> AsAny for T
where T: Any,

Source§

fn as_any(&self) -> &(dyn Any + 'static)

Source§

fn as_mut_any(&mut self) -> &mut (dyn Any + 'static)

Source§

impl<'a, T, E> AsTaggedExplicit<'a, E> for T
where T: 'a,

Source§

fn explicit(self, class: Class, tag: u32) -> TaggedParser<'a, Explicit, Self, E>

Source§

impl<'a, T, E> AsTaggedImplicit<'a, E> for T
where T: 'a,

Source§

fn implicit( self, class: Class, constructed: bool, tag: u32, ) -> TaggedParser<'a, Implicit, Self, E>

Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self>

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more