Expand description
A drop-in replacement for std::process::Command that provides the ability
to set up namespaces, a seccomp filter, and more.
Modules§
- seccomp
- Provides helpers for constructing a
seccompfilter. This is a pure Rust implementation and does not require libseccomp.
Structs§
- Bind
- Represents a bind mount. Can be converted into a
Mount. - Child
- Represents a child process.
- Child
Start Context - Child-only setup context, constructed after namespace/filesystem setup.
- Child
Stderr - A handle to a child process’s stderr.
- Child
Stdin - A handle to a child process’s standard input (stdin).
- Child
Stdout - A handle to a child process’s standard output (stdout).
- Command
- A builder for spawning a process.
- Container
- A
Containeris a configuration of how a process shall be spawned. It can, but doesn’t have to, include Linux namespace configuration. - Deferred
Container Run - A provisional container result whose successful value remains owned by its mandatory cleanup check.
- Error
- An error from spawning a process. This is a thin wrapper around
crate::Errno, but with more context about what went wrong. - Mount
- A mount.
- Mount
Flags - Used with
mount. - Namespace
- A namespace that may be unshared with
Command::unshare. - Output
- The output of a finished process.
- Owned
Container Cleanup - Retains the atomically acquired child identity and exclusive wait obligation.
- Owned
Decode Failure - Decode refusal retaining the complete bytes and genuine child status.
- Owned
Deferred Container Run - A complete encoded result whose original child has not yet been settled.
- Owned
Finalization - Encoded bytes and the child, retained through pending or failed cleanup. No generic result value has been deserialized in the parent.
- Owned
Reaped Result - A successful child wait plus original encoded bytes. Decode is deliberately separate.
- Parent
Start Context - Parent-only startup context bound to this invocation’s unreaped child.
- Pid
- A process ID (PID).
- Pty
- Represents a pseudo-TTY “master”.
- PtyChild
- A pseudo-TTY child (or “slave” in TTY parlance). This is passed to child processes.
- Stdio
- Describes what to do with a standard I/O stream for a child process when
passed to the
stdin,stdout, andstderrmethods ofCommand.
Enums§
- Child
Cleanup Observation - An observation of the original child, never an inferred successful exit.
- Context
- Context associated with
Error. Useful for knowing which particular part ofsuper::Command::spawnfailed. - Exit
Status - Describes the result of a process after it has exited.
- Mount
Parse Error - An error from parsing a mount.
- Owned
Finalize - The distinction between real completion, persistent failure and an owned pending wait.
- Owned
RunFailure - The original failure, separate from subsequent cleanup observations.
- RunError
- An error that ocurred while running a containerized function.
- Signal
- Types of operating system signals
- Startup
Error - Failure of the finite container startup exchange.
- Startup
Owned Failure - An owned startup or result-acquisition refusal. Every post-clone failure retains the real child, including failures from an owned deferred workload.
- Startup
RunError - A startup failure together with the actual owned-child cleanup outcome.
Constants§
- MAX_
STARTUP_ FDS - Maximum number of owned descriptors transferred by one container startup.