Skip to main content

ServiceAccount

Enum ServiceAccount 

Source
pub enum ServiceAccount {
    LocalSystem,
    Root,
    InvokingUser,
}
Expand description

The account a registration runs under.

Not an operator choice. It is a function of the start mode and the platform, because the start mode decides which secret store the daemon must read and the store’s own access control decides which accounts can read it. See docs/service-account.md, and review_least_privilege for the check.

Variants§

§

LocalSystem

NT AUTHORITY\SYSTEM. The only stock Windows account named by the machine-scoped store’s DACL.

§

Root

root. What a LaunchDaemon and a systemd system unit run as, and what the macOS System Keychain’s root-only master key requires.

§

InvokingUser

The operator’s own account, for a login-mode registration.

Implementations§

Source§

impl ServiceAccount

Source

pub const fn for_definition(kind: DefinitionKind, mode: StartMode) -> Self

The account a given kind of definition obliges.

Keyed on the definition rather than on cfg!(windows), and the difference is not academic: a Windows developer rendering the launchd property list would otherwise write UserName = NT AUTHORITY\SYSTEM into it, which is not an account macOS has. A definition’s account is a property of the definition, and the whole point of rendering being pure is that any host can render any platform’s and get the right answer.

Source

pub const fn for_start_mode(mode: StartMode) -> Self

The account the given start mode obliges on the platform this binary was built for.

Source

pub const fn as_str(&self) -> &'static str

How the platform spells it.

Source

pub const fn justification(&self) -> &'static str

Why this is the minimum account that can do the job, not merely the convenient one.

Printed by service status and by review_least_privilege, because a privileged account with no stated reason is indistinguishable from a privileged account nobody thought about.

Source

pub const fn needs_elevation(&self) -> bool

Whether registering under this account needs administrative rights.

Trait Implementations§

Source§

impl Clone for ServiceAccount

Source§

fn clone(&self) -> ServiceAccount

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for ServiceAccount

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl<'de> Deserialize<'de> for ServiceAccount

Source§

fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>
where __D: Deserializer<'de>,

Deserialize this value from the given Serde deserializer. Read more
Source§

impl Display for ServiceAccount

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Eq for ServiceAccount

Source§

impl PartialEq for ServiceAccount

Source§

fn eq(&self, other: &ServiceAccount) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl Serialize for ServiceAccount

Source§

fn serialize<__S>(&self, __serializer: __S) -> Result<__S::Ok, __S::Error>
where __S: Serializer,

Serialize this value into the given Serde serializer. Read more
Source§

impl StructuralPartialEq for ServiceAccount

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DeserializeOwned for T
where T: for<'de> Deserialize<'de>,

Source§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

Source§

fn equivalent(&self, key: &K) -> bool

Checks if this value is equivalent to the given key. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T> ToString for T
where T: Display + ?Sized,

Source§

fn to_string(&self) -> String

Converts the given value to a String. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more