Skip to main content

ExecutableIdentityPolicy

Enum ExecutableIdentityPolicy 

Source
pub enum ExecutableIdentityPolicy {
    ExactOpenedFile,
}
Expand description

Required executable-identity policy for an owned helper launch.

Variants§

§

ExactOpenedFile

Open and retain one absolute regular executable without any symlink traversal and apply the target’s documented image-identity checks. Linux executes the held object directly. macOS authenticates the running image against the retained file by content: the kernel- registered code-directory hash of the exact audit-token-bound child execution must match a hash computed from the held descriptor, at launch and again through ACCEPT, independent of pathnames and of the signing identity (an ad-hoc linker signature suffices). A macOS executable that carries no code directory — an unsigned image or a script — cannot be bound and fails construction closed. Windows retains the opened file, spawns from the retained image, binds the session transport to the exact spawned process identity, and holds the child and its descendants in a kill-on-close Job.

Trait Implementations§

Source§

impl Clone for ExecutableIdentityPolicy

Source§

fn clone(&self) -> ExecutableIdentityPolicy

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Copy for ExecutableIdentityPolicy

Source§

impl Debug for ExecutableIdentityPolicy

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Eq for ExecutableIdentityPolicy

Source§

impl PartialEq for ExecutableIdentityPolicy

Source§

fn eq(&self, other: &ExecutableIdentityPolicy) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl StructuralPartialEq for ExecutableIdentityPolicy

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.