Skip to main content

Safety

Enum Safety 

Source
pub enum Safety {
    Off,
    Detect,
    Enforce,
    Kernel,
}
Expand description

How much of the memory safety monitor is on, from -fsafety=.

Design: spec/safe-memory/15-integration.md section 15.4. One flag rather than a plane at a time, because the tiers of spec/safe-memory/02-threat-model.md are the product and the modifiers are how somebody who has read that document departs from one.

The tiers agree about which accesses are checked and disagree about what happens when a check says no and about how much of the boundary is covered. That is why they are one value here and not three booleans: a build asks for a tier, and everything else follows from it.

Variants§

§

Off

-fsafety=off. No checks and no runtime. The default, and what every existing build gets.

§

Detect

-fsafety=detect. Tier D: report and carry on, for a test run or a fuzzer.

§

Enforce

-fsafety=enforce. Tier E: report and stop, for a program that faces the network.

§

Kernel

-fsafety=kernel. Tier K: what a kernel can afford, with the allocator and the libc wrappers taken out because a kernel has neither.

Implementations§

Source§

impl Safety

Source

pub const fn as_str(self) -> &'static str

The spelling this tier is asked for by, without the flag in front of it.

Source

pub const fn instruments(self) -> bool

Whether checks are inserted at all.

The three tiers that are not off all insert the same checks at this milestone. What separates them is the reporter and the boundary, which are milestones S2 and S3 in spec/safe-memory/16-milestones.md.

Trait Implementations§

Source§

impl Clone for Safety

Source§

fn clone(&self) -> Safety

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Copy for Safety

Source§

impl Debug for Safety

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Default for Safety

Source§

fn default() -> Safety

Returns the “default value” for a type. Read more
Source§

impl Display for Safety

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Eq for Safety

Source§

impl FromStr for Safety

Source§

fn from_str(s: &str) -> Result<Self, ()>

Parses the part after -fsafety=.

Source§

type Err = ()

The associated error which can be returned from parsing.
Source§

impl Hash for Safety

Source§

fn hash<__H: Hasher>(&self, state: &mut __H)

Feeds this value into the given Hasher. Read more
1.3.0 · Source§

fn hash_slice<H>(data: &[Self], state: &mut H)
where H: Hasher, Self: Sized,

Feeds a slice of this type into the given Hasher. Read more
Source§

impl Ord for Safety

Source§

fn cmp(&self, other: &Safety) -> Ordering

This method returns an Ordering between self and other. Read more
1.21.0 (const: unstable) · Source§

fn max(self, other: Self) -> Self
where Self: Sized,

Compares and returns the maximum of two values. Read more
1.21.0 (const: unstable) · Source§

fn min(self, other: Self) -> Self
where Self: Sized,

Compares and returns the minimum of two values. Read more
1.50.0 (const: unstable) · Source§

fn clamp(self, min: Self, max: Self) -> Self
where Self: Sized,

Restrict a value to a certain interval. Read more
Source§

fn clamp_to<R>(self, range: R) -> Self
where Self: Sized, R: ClampBounds<Self>,

🔬This is a nightly-only experimental API. (clamp_to)
Restrict a value to a certain range. Read more
Source§

impl PartialEq for Safety

Source§

fn eq(&self, other: &Safety) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl PartialOrd for Safety

Source§

fn partial_cmp(&self, other: &Safety) -> Option<Ordering>

This method returns an ordering between self and other values if one exists. Read more
1.0.0 (const: unstable) · Source§

fn lt(&self, other: &Rhs) -> bool

Tests less than (for self and other) and is used by the < operator. Read more
1.0.0 (const: unstable) · Source§

fn le(&self, other: &Rhs) -> bool

Tests less than or equal to (for self and other) and is used by the <= operator. Read more
1.0.0 (const: unstable) · Source§

fn gt(&self, other: &Rhs) -> bool

Tests greater than (for self and other) and is used by the > operator. Read more
1.0.0 (const: unstable) · Source§

fn ge(&self, other: &Rhs) -> bool

Tests greater than or equal to (for self and other) and is used by the >= operator. Read more
Source§

impl StructuralPartialEq for Safety

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T> ToString for T
where T: Display + ?Sized,

Source§

fn to_string(&self) -> String

Converts the given value to a String. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.