#[repr(transparent)]pub struct SecCodeStatus(pub u32);
CSCommon
only.Expand description
The code signing system attaches a set of status flags to each running code. These flags are maintained by the code’s host, and can be read by anyone. A code may change its own flags, a host may change its guests’ flags, and root may change anyone’s flags. However, these flags are sticky in that each can change in only one direction (and never back, for the lifetime of the code). Not even root can violate this restriction.
There are other flags in SecCodeStatus that are not publicly documented. Do not rely on them, and do not ever attempt to explicitly set them.
Indicates that the code is dynamically valid, i.e. it started correctly and has not been invalidated since then. The valid bit can only be cleared.
Warning: This bit is not your one-stop shortcut to determining the validity of code. It represents the dynamic component of the full validity function; if this bit is unset, the code is definitely invalid, but the converse is not always true. In fact, code hosts may represent the outcome of some delayed static validation work in this bit, and thus it strictly represents a blend of (all of) dynamic and (some of) static validity, depending on the implementation of the particular host managing the code. You can (only) rely that (1) dynamic invalidation will clear this bit; and (2) the combination of static validation and dynamic validity (as performed by the SecCodeCheckValidity* APIs) will give a correct answer.
Indicates that the code prefers to be denied access to resources if gaining access would invalidate it. This bit can only be set. It is undefined whether code that is marked hard and is already invalid will still be denied access to a resource that would invalidate it if it were still valid. That is, the code may or may not get access to such a resource while being invalid, and that choice may appear random.
Indicates that the code wants to be killed (terminated) if it ever loses its validity. This bit can only be set. Code that has the kill flag set will never be dynamically invalid (and live). Note however that a change in static validity does not necessarily trigger instant death.
Indicated that code has been debugged by another process that was allowed to do so. The debugger causes this to be set when it attachs.
Indicates the code is platform code, shipping with the operating system and signed by Apple.
See also Apple’s documentation
Tuple Fields§
§0: u32
Implementations§
Source§impl SecCodeStatus
impl SecCodeStatus
Source§impl SecCodeStatus
impl SecCodeStatus
Sourcepub const fn bits(&self) -> u32
pub const fn bits(&self) -> u32
Get the underlying bits value.
The returned value is exactly the bits set in this flags value.
Sourcepub const fn from_bits(bits: u32) -> Option<Self>
pub const fn from_bits(bits: u32) -> Option<Self>
Convert from a bits value.
This method will return None
if any unknown bits are set.
Sourcepub const fn from_bits_truncate(bits: u32) -> Self
pub const fn from_bits_truncate(bits: u32) -> Self
Convert from a bits value, unsetting any unknown bits.
Sourcepub const fn from_bits_retain(bits: u32) -> Self
pub const fn from_bits_retain(bits: u32) -> Self
Convert from a bits value exactly.
Sourcepub fn from_name(name: &str) -> Option<Self>
pub fn from_name(name: &str) -> Option<Self>
Get a flags value with the bits of a flag with the given name set.
This method will return None
if name
is empty or doesn’t
correspond to any named flag.
Sourcepub const fn intersects(&self, other: Self) -> bool
pub const fn intersects(&self, other: Self) -> bool
Whether any set bits in a source flags value are also set in a target flags value.
Sourcepub const fn contains(&self, other: Self) -> bool
pub const fn contains(&self, other: Self) -> bool
Whether all set bits in a source flags value are also set in a target flags value.
Sourcepub fn remove(&mut self, other: Self)
pub fn remove(&mut self, other: Self)
The intersection of a source flags value with the complement of a target flags value (&!
).
This method is not equivalent to self & !other
when other
has unknown bits set.
remove
won’t truncate other
, but the !
operator will.
Sourcepub fn toggle(&mut self, other: Self)
pub fn toggle(&mut self, other: Self)
The bitwise exclusive-or (^
) of the bits in two flags values.
Sourcepub fn set(&mut self, other: Self, value: bool)
pub fn set(&mut self, other: Self, value: bool)
Call insert
when value
is true
or remove
when value
is false
.
Sourcepub const fn intersection(self, other: Self) -> Self
pub const fn intersection(self, other: Self) -> Self
The bitwise and (&
) of the bits in two flags values.
Sourcepub const fn union(self, other: Self) -> Self
pub const fn union(self, other: Self) -> Self
The bitwise or (|
) of the bits in two flags values.
Sourcepub const fn difference(self, other: Self) -> Self
pub const fn difference(self, other: Self) -> Self
The intersection of a source flags value with the complement of a target flags value (&!
).
This method is not equivalent to self & !other
when other
has unknown bits set.
difference
won’t truncate other
, but the !
operator will.
Sourcepub const fn symmetric_difference(self, other: Self) -> Self
pub const fn symmetric_difference(self, other: Self) -> Self
The bitwise exclusive-or (^
) of the bits in two flags values.
Sourcepub const fn complement(self) -> Self
pub const fn complement(self) -> Self
The bitwise negation (!
) of the bits in a flags value, truncating the result.
Source§impl SecCodeStatus
impl SecCodeStatus
Sourcepub const fn iter(&self) -> Iter<SecCodeStatus>
pub const fn iter(&self) -> Iter<SecCodeStatus>
Yield a set of contained flags values.
Each yielded flags value will correspond to a defined named flag. Any unknown bits will be yielded together as a final flags value.
Sourcepub const fn iter_names(&self) -> IterNames<SecCodeStatus>
pub const fn iter_names(&self) -> IterNames<SecCodeStatus>
Yield a set of contained named flags values.
This method is like iter
, except only yields bits in contained named flags.
Any unknown bits, or bits not corresponding to a contained flag will not be yielded.
Trait Implementations§
Source§impl Binary for SecCodeStatus
impl Binary for SecCodeStatus
Source§impl BitAnd for SecCodeStatus
impl BitAnd for SecCodeStatus
Source§impl BitAndAssign for SecCodeStatus
impl BitAndAssign for SecCodeStatus
Source§fn bitand_assign(&mut self, other: Self)
fn bitand_assign(&mut self, other: Self)
The bitwise and (&
) of the bits in two flags values.
Source§impl BitOr for SecCodeStatus
impl BitOr for SecCodeStatus
Source§fn bitor(self, other: SecCodeStatus) -> Self
fn bitor(self, other: SecCodeStatus) -> Self
The bitwise or (|
) of the bits in two flags values.
Source§type Output = SecCodeStatus
type Output = SecCodeStatus
|
operator.Source§impl BitOrAssign for SecCodeStatus
impl BitOrAssign for SecCodeStatus
Source§fn bitor_assign(&mut self, other: Self)
fn bitor_assign(&mut self, other: Self)
The bitwise or (|
) of the bits in two flags values.
Source§impl BitXor for SecCodeStatus
impl BitXor for SecCodeStatus
Source§impl BitXorAssign for SecCodeStatus
impl BitXorAssign for SecCodeStatus
Source§fn bitxor_assign(&mut self, other: Self)
fn bitxor_assign(&mut self, other: Self)
The bitwise exclusive-or (^
) of the bits in two flags values.
Source§impl Clone for SecCodeStatus
impl Clone for SecCodeStatus
Source§fn clone(&self) -> SecCodeStatus
fn clone(&self) -> SecCodeStatus
1.0.0 · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source
. Read moreSource§impl Debug for SecCodeStatus
impl Debug for SecCodeStatus
Source§impl Encode for SecCodeStatus
Available on crate feature objc2
only.
impl Encode for SecCodeStatus
objc2
only.Source§impl Extend<SecCodeStatus> for SecCodeStatus
impl Extend<SecCodeStatus> for SecCodeStatus
Source§fn extend<T: IntoIterator<Item = Self>>(&mut self, iterator: T)
fn extend<T: IntoIterator<Item = Self>>(&mut self, iterator: T)
The bitwise or (|
) of the bits in each flags value.
Source§fn extend_one(&mut self, item: A)
fn extend_one(&mut self, item: A)
extend_one
)Source§fn extend_reserve(&mut self, additional: usize)
fn extend_reserve(&mut self, additional: usize)
extend_one
)Source§impl Flags for SecCodeStatus
impl Flags for SecCodeStatus
Source§const FLAGS: &'static [Flag<SecCodeStatus>]
const FLAGS: &'static [Flag<SecCodeStatus>]
Source§fn from_bits_retain(bits: u32) -> SecCodeStatus
fn from_bits_retain(bits: u32) -> SecCodeStatus
Source§fn contains_unknown_bits(&self) -> bool
fn contains_unknown_bits(&self) -> bool
true
if any unknown bits are set.Source§fn from_bits_truncate(bits: Self::Bits) -> Self
fn from_bits_truncate(bits: Self::Bits) -> Self
Source§fn from_name(name: &str) -> Option<Self>
fn from_name(name: &str) -> Option<Self>
Source§fn iter_names(&self) -> IterNames<Self>
fn iter_names(&self) -> IterNames<Self>
Source§fn intersects(&self, other: Self) -> boolwhere
Self: Sized,
fn intersects(&self, other: Self) -> boolwhere
Self: Sized,
Source§fn contains(&self, other: Self) -> boolwhere
Self: Sized,
fn contains(&self, other: Self) -> boolwhere
Self: Sized,
Source§fn insert(&mut self, other: Self)where
Self: Sized,
fn insert(&mut self, other: Self)where
Self: Sized,
|
) of the bits in two flags values.Source§fn remove(&mut self, other: Self)where
Self: Sized,
fn remove(&mut self, other: Self)where
Self: Sized,
&!
). Read moreSource§fn toggle(&mut self, other: Self)where
Self: Sized,
fn toggle(&mut self, other: Self)where
Self: Sized,
^
) of the bits in two flags values.Source§fn intersection(self, other: Self) -> Self
fn intersection(self, other: Self) -> Self
&
) of the bits in two flags values.Source§fn difference(self, other: Self) -> Self
fn difference(self, other: Self) -> Self
&!
). Read moreSource§fn symmetric_difference(self, other: Self) -> Self
fn symmetric_difference(self, other: Self) -> Self
^
) of the bits in two flags values.Source§fn complement(self) -> Self
fn complement(self) -> Self
!
) of the bits in a flags value, truncating the result.Source§impl FromIterator<SecCodeStatus> for SecCodeStatus
impl FromIterator<SecCodeStatus> for SecCodeStatus
Source§fn from_iter<T: IntoIterator<Item = Self>>(iterator: T) -> Self
fn from_iter<T: IntoIterator<Item = Self>>(iterator: T) -> Self
The bitwise or (|
) of the bits in each flags value.
Source§impl Hash for SecCodeStatus
impl Hash for SecCodeStatus
Source§impl IntoIterator for SecCodeStatus
impl IntoIterator for SecCodeStatus
Source§impl LowerHex for SecCodeStatus
impl LowerHex for SecCodeStatus
Source§impl Not for SecCodeStatus
impl Not for SecCodeStatus
Source§impl Octal for SecCodeStatus
impl Octal for SecCodeStatus
Source§impl Ord for SecCodeStatus
impl Ord for SecCodeStatus
Source§fn cmp(&self, other: &SecCodeStatus) -> Ordering
fn cmp(&self, other: &SecCodeStatus) -> Ordering
1.21.0 · Source§fn max(self, other: Self) -> Selfwhere
Self: Sized,
fn max(self, other: Self) -> Selfwhere
Self: Sized,
Source§impl PartialEq for SecCodeStatus
impl PartialEq for SecCodeStatus
Source§impl PartialOrd for SecCodeStatus
impl PartialOrd for SecCodeStatus
Source§impl RefEncode for SecCodeStatus
Available on crate feature objc2
only.
impl RefEncode for SecCodeStatus
objc2
only.Source§const ENCODING_REF: Encoding
const ENCODING_REF: Encoding
Source§impl Sub for SecCodeStatus
impl Sub for SecCodeStatus
Source§fn sub(self, other: Self) -> Self
fn sub(self, other: Self) -> Self
The intersection of a source flags value with the complement of a target flags value (&!
).
This method is not equivalent to self & !other
when other
has unknown bits set.
difference
won’t truncate other
, but the !
operator will.
Source§type Output = SecCodeStatus
type Output = SecCodeStatus
-
operator.Source§impl SubAssign for SecCodeStatus
impl SubAssign for SecCodeStatus
Source§fn sub_assign(&mut self, other: Self)
fn sub_assign(&mut self, other: Self)
The intersection of a source flags value with the complement of a target flags value (&!
).
This method is not equivalent to self & !other
when other
has unknown bits set.
difference
won’t truncate other
, but the !
operator will.