Expand description
Blessed asynchronous process operations.
This crate is intentionally published as an implementation detail. It is
the only production owner of the Tokio process primitives used by the
async process API. Higher layers receive typed operations and never name
tokio::process::Command directly.
Re-exports§
pub use platform_imp::apply_process_priority;pub use platform_imp::assign_child_to_windows_job;pub use platform_imp::cancel_capture_reader;pub use platform_imp::canonical_environment_pairs;pub use platform_imp::capture_reader_done;pub use platform_imp::compat_shell_command;pub use platform_imp::configure_exact_trace;pub use platform_imp::configure_process_command;pub use platform_imp::configure_sync_contained_command;pub use platform_imp::configure_sync_daemon_command;pub use platform_imp::configure_sync_daemon_command_with_inheritance;pub use platform_imp::configure_trampoline_command;pub use platform_imp::current_executable_build_id;pub use platform_imp::exact_trace_capability;pub use platform_imp::exit_code;pub use platform_imp::exit_signal;pub use platform_imp::monitor_console_windows;pub use platform_imp::parent_has_console;pub use platform_imp::prepare_capture_reader;pub use platform_imp::send_interrupt;pub use platform_imp::set_process_name;pub use platform_imp::shell_command;pub use platform_imp::soft_terminate_process_group;pub use platform_imp::spawn_sync;pub use platform_imp::spawn_sync_daemon;pub use platform_imp::spawn_sync_daemon_with_inheritance;pub use platform_imp::start_attached_descendant_monitor;pub use platform_imp::start_descendant_monitor;pub use platform_imp::start_exact_trace;pub use platform_imp::sync_child_native_handle;pub use platform_imp::trampoline_exit_code;pub use platform_imp::unix_mark_extra_fds_close_on_exec;pub use platform_imp::unix_set_priority;pub use platform_imp::unix_signal_process;pub use platform_imp::unix_signal_process_group;pub use platform_imp::unix_signal_raw;pub use platform_imp::CaptureCancellation;pub use platform_imp::TracedChild;pub use platform_imp::WindowsJobHandle;pub use platform_imp::terminal_input;
Modules§
- env
- Explicit caller-owned foreground command execution. The mechanism for reading declared environment variables (#1101).
- env_
vars - Every environment variable this crate reads in production, declared in one place (#1101).
- foreground
- Caller-owned foreground command execution.
- platform
- Neutral capability indexes for the eventual workspace-wide host boundary.
Macros§
- declare_
env_ vars - Declare environment variables as
EnvVarconstants plus a table of all of them, so a crate’s inventory is one list rather than scattered literals.
Structs§
- Capture
Cancellation - Platform
Capture Readers - The two prepared, cancellable capture readers of a child.
- Platform
Child - Owned child handle returned by
SpawnSpec::spawn. - Platform
Emergency Signal - Opaque, non-reap-capable emergency termination capability.
- Platform
Lifecycle - Opaque exit-wait capability owned by a process actor.
- Platform
Output - Opaque stdout or stderr reader owned by a process actor.
- Platform
StdChild - A synchronously launched child whose exit is observed by polling.
- Platform
Stdin - Opaque piped stdin capability owned by a process actor.
- Process
Liveness - A live reference to another process, good for as long as it is held.
- Spawn
Admission - Admission callback shared by cloned spawn descriptions.
- Spawn
Spec - Typed spawn description accepted by the blessed process boundary.
- Traced
Child - Root-process control handle whose wait state is owned by the tracer.
- Windows
JobHandle
Enums§
- Host
Privileged Identity - A privileged system identity this process may be running as.
- Process
Priority - Scheduling intent for a newly created child.
- Stream
Mode - Stdio policy for one child stream.
Constants§
- APE_
EXECVP_ SHELL_ FALLBACK - Whether this libc’s
execvpruns anENOEXECimage with the shell, as POSIX requires. glibc does; musl does not. - APE_
LOADER_ HOST - Which embedded loader this host runs: the Linux static ELF.
- APE_
NEEDS_ LOADER - An APE image is not a native Linux executable.
- APE_
SHELL - Shell the kernel’s
ENOEXECconvention hands an unrecognized image to. - APE_
SYSTEM_ LOADERS - Where Cosmopolitan’s install instructions place a system-wide loader.
- EXECUTABLE_
EXTENSION - File-name extension the host requires on a runnable image, if any.
Functions§
- after_
compat_ tokio_ spawn - Complete host-owned setup after a legacy Tokio child has been spawned.
- ape_
anonymous_ executable - Last-resort executable with no filesystem home: a sealed memfd exec’d via
/proc/self/fd/N. Valid only for direct children of this process. - ape_
default_ loader_ dirs - Default directories for extracted loaders, most durable first.
- ape_
is_ exec_ format_ error - The kernel refused the image’s format.
- ape_
is_ executable - Whether metadata carries any execute permission bit.
- ape_
mark_ executable - Make an extracted loader executable by its owner and readable by others.
- ape_
private_ exec_ dir - Whether
dirmay hold an executable this crate installs: create it (mode 0700) if needed, then accept it only when it is a real directory owned by the effective user with no group/other write access – so no other account can plant or swap a file in it – on a mount that allows exec. - ape_
route_ through_ execvp - Make the next spawn fork and
execvpinstead ofposix_spawn. - ape_
route_ tokio_ through_ execvp route_through_execvpfor a Tokio command.- apply_
process_ priority - Apply a process priority expressed as a Unix nice value.
- assign_
child_ to_ windows_ job - autostart_
register - autostart_
render_ registration - Render the unit text without touching the filesystem.
- autostart_
unregister - cancel_
capture_ reader - canonical_
environment_ pairs - capture_
reader_ done - compat_
shell_ command - configure_
compat_ tokio_ command - Apply host-owned setup for the legacy Tokio-command compatibility surface.
- configure_
exact_ trace - Arrange for a successful
execto stop the child before user code runs. No pre-exec SIGSTOP is used: that would deadlockCommand::spawn’s exec error pipe. - configure_
process_ command - configure_
sync_ contained_ command - configure_
sync_ daemon_ command - configure_
sync_ daemon_ command_ with_ inheritance - configure_
trampoline_ command - current_
executable_ build_ id - Return the GNU build ID of the running executable without reading the executable from disk.
- exact_
trace_ capability - executable_
file_ name - Spell
barethe way this host names an executable file. - executable_
sibling_ of_ current_ image - Path to a sibling program installed beside the running image.
- exit_
code - exit_
signal - The signal that terminated
status’s process, if it died from one. - fs_
open_ handles_ block_ removal - Whether a handle another process holds open keeps a file from being removed.
- fs_
write_ all_ to_ descriptor - Write every byte of
bytes, or report why not. - host_
boot_ id - An identifier that changes on every boot of this machine.
- host_
current_ process_ privilege - The privileged identity this process is running as, if any.
- host_
environment_ keys_ are_ case_ insensitive - Unix environment variable names compare byte for byte.
- host_
filesystem_ device_ id - The filesystem device this path lives on.
- host_
hostname - This machine’s name as the host reports it.
- host_
login_ environment - The logged-in user’s environment, as a fresh login would see it.
- host_
login_ environment_ block - The login environment in the double-NUL-terminated UTF-16 block form.
- host_
machine_ id - A durable per-machine identifier that survives reboots.
- host_
namespace_ id - The mount and PID namespaces this process is in.
- host_
process_ cgroup - This process’s control-group membership (
/proc/self/cgroup). Linux has cgroups, so the answer is alwaysSome; the inner error is a read failure. - host_
user_ machine_ identity - A stable identity for this user on this machine.
- kill_
tree - monitor_
console_ windows - parent_
has_ console - prepare_
capture_ reader - process_
can_ replace_ current_ image - This host replaces a running image in place; see the facade for what that means for a caller that cannot accept a successor instead.
- process_
executable_ path - Resolve the on-disk image a running process was started from.
- process_
fault_ code_ name - Operator-facing name of a fatal fault code recorded by a crash handler.
- process_
force_ kill - Stop a process without asking.
- process_
install_ owner_ death_ cleanup - Ask the kernel to signal this process when its owner exits.
- process_
install_ shutdown_ request_ handler - Ask this host to report shutdown requests.
- process_
loaded_ images - Enumerate the file-backed ELF images mapped in this process, ordered by
(path, device, inode, load instance). - process_
observer_ backend - process_
open_ loaded_ image_ file - Reopen the file behind
image, refusing one that no longer has the device and inode recorded in/proc/self/maps. - process_
owner_ death_ cleanup_ target - What this host will attempt, without attempting it.
- process_
read_ argv - Return the process argv without flattening its argument boundaries.
- process_
read_ cmdline - Return a stable human-readable rendering of
read_process_argv. - process_
read_ file_ handles - process_
replace_ current_ image - Replace this process’s image with
command. - process_
same_ executable_ path - Whether two spellings name the same executable image on this host.
- process_
signal_ terminate - Ask a process to stop.
- process_
snapshot - process_
snapshot_ for_ pid - resources_
fd_ exhaustion_ error - One error this host would report for descriptor exhaustion.
- resources_
inode_ capacity - Probe inode capacity for the filesystem containing
path. - resources_
signals_ fd_ exhaustion - Whether this error means the process or the system is out of descriptors.
- resources_
signals_ storage_ exhaustion - Whether this error means the filesystem is out of space.
- resources_
storage_ exhaustion_ error - One error this host would report for storage exhaustion.
- send_
interrupt - Deliver the host’s interactive-interrupt request to
pid. - set_
process_ name - set_
window_ icon_ impl - Write
sourceonto this process’s terminal window. - shell_
command - shell_
spec - Build a shell command using the host platform’s supported shell.
- soft_
terminate_ process_ group - Request a graceful shutdown for a child-owned POSIX process group.
- spawn_
sync - spawn_
sync_ daemon - spawn_
sync_ daemon_ with_ inheritance - start_
attached_ descendant_ monitor - Attach to an already-running root (#1015). On this host the descendant monitor never depended on the spawn, so attaching is the same monitor.
- start_
descendant_ monitor - start_
exact_ trace - sync_
child_ native_ handle - trampoline_
exit_ code - unix_
mark_ ⚠extra_ fds_ close_ on_ exec - Mark inherited descriptors close-on-exec without breaking std’s exec-error pipe.
- unix_
set_ priority - unix_
signal_ process - unix_
signal_ process_ group - unix_
signal_ raw - window_
icon_ support_ impl - Whether this host can take a real icon.