Struct rustix::thread::CapabilitiesSecureBits
source · pub struct CapabilitiesSecureBits { /* private fields */ }thread only.Expand description
SECBIT_*.
Implementations§
source§impl CapabilitiesSecureBits
impl CapabilitiesSecureBits
sourcepub const NO_ROOT: Self = _
pub const NO_ROOT: Self = _
If this bit is set, then the kernel does not grant capabilities when
a set-user-ID-root program is executed, or when a process with an effective or real
UID of 0 calls execve.
sourcepub const NO_ROOT_LOCKED: Self = _
pub const NO_ROOT_LOCKED: Self = _
Set [NO_ROOT] irreversibly.
sourcepub const NO_SETUID_FIXUP: Self = _
pub const NO_SETUID_FIXUP: Self = _
Setting this flag stops the kernel from adjusting the process’s permitted, effective, and ambient capability sets when the thread’s effective and filesystem UIDs are switched between zero and nonzero values.
sourcepub const NO_SETUID_FIXUP_LOCKED: Self = _
pub const NO_SETUID_FIXUP_LOCKED: Self = _
Set [NO_SETUID_FIXUP] irreversibly.
sourcepub const KEEP_CAPS: Self = _
pub const KEEP_CAPS: Self = _
Setting this flag allows a thread that has one or more 0 UIDs to retain capabilities in its permitted set when it switches all of its UIDs to nonzero values.
sourcepub const KEEP_CAPS_LOCKED: Self = _
pub const KEEP_CAPS_LOCKED: Self = _
Set [KEEP_CAPS] irreversibly.
sourcepub const NO_CAP_AMBIENT_RAISE: Self = _
pub const NO_CAP_AMBIENT_RAISE: Self = _
Setting this flag disallows raising ambient capabilities via the prctl’s
PR_CAP_AMBIENT_RAISE operation.
sourcepub const NO_CAP_AMBIENT_RAISE_LOCKED: Self = _
pub const NO_CAP_AMBIENT_RAISE_LOCKED: Self = _
Set [NO_CAP_AMBIENT_RAISE] irreversibly.
sourcepub const fn from_bits(bits: u32) -> Option<Self>
pub const fn from_bits(bits: u32) -> Option<Self>
Convert from underlying bit representation, unless that representation contains bits that do not correspond to a flag.
sourcepub const fn from_bits_truncate(bits: u32) -> Self
pub const fn from_bits_truncate(bits: u32) -> Self
Convert from underlying bit representation, dropping any bits that do not correspond to flags.
sourcepub const unsafe fn from_bits_unchecked(bits: u32) -> Self
pub const unsafe fn from_bits_unchecked(bits: u32) -> Self
Convert from underlying bit representation, preserving all bits (even those not corresponding to a defined flag).
Safety
The caller of the bitflags! macro can chose to allow or
disallow extra bits for their bitflags type.
The caller of from_bits_unchecked() has to ensure that
all bits correspond to a defined flag or that extra bits
are valid for this bitflags type.
sourcepub const fn intersects(&self, other: Self) -> bool
pub const fn intersects(&self, other: Self) -> bool
Returns true if there are flags common to both self and other.
sourcepub const fn contains(&self, other: Self) -> bool
pub const fn contains(&self, other: Self) -> bool
Returns true if all of the flags in other are contained within self.
sourcepub fn set(&mut self, other: Self, value: bool)
pub fn set(&mut self, other: Self, value: bool)
Inserts or removes the specified flags depending on the passed value.
sourcepub const fn intersection(self, other: Self) -> Self
pub const fn intersection(self, other: Self) -> Self
Returns the intersection between the flags in self and
other.
Specifically, the returned set contains only the flags which are
present in both self and other.
This is equivalent to using the & operator (e.g.
ops::BitAnd), as in flags & other.
sourcepub const fn union(self, other: Self) -> Self
pub const fn union(self, other: Self) -> Self
Returns the union of between the flags in self and other.
Specifically, the returned set contains all flags which are
present in either self or other, including any which are
present in both (see Self::symmetric_difference if that
is undesirable).
This is equivalent to using the | operator (e.g.
ops::BitOr), as in flags | other.
sourcepub const fn difference(self, other: Self) -> Self
pub const fn difference(self, other: Self) -> Self
Returns the difference between the flags in self and other.
Specifically, the returned set contains all flags present in
self, except for the ones present in other.
It is also conceptually equivalent to the “bit-clear” operation:
flags & !other (and this syntax is also supported).
This is equivalent to using the - operator (e.g.
ops::Sub), as in flags - other.
sourcepub const fn symmetric_difference(self, other: Self) -> Self
pub const fn symmetric_difference(self, other: Self) -> Self
Returns the symmetric difference between the flags
in self and other.
Specifically, the returned set contains the flags present which
are present in self or other, but that are not present in
both. Equivalently, it contains the flags present in exactly
one of the sets self and other.
This is equivalent to using the ^ operator (e.g.
ops::BitXor), as in flags ^ other.
sourcepub const fn complement(self) -> Self
pub const fn complement(self) -> Self
Returns the complement of this set of flags.
Specifically, the returned set contains all the flags which are
not set in self, but which are allowed for this type.
Alternatively, it can be thought of as the set difference
between Self::all() and self (e.g. Self::all() - self)
This is equivalent to using the ! operator (e.g.
ops::Not), as in !flags.
Trait Implementations§
source§impl Binary for CapabilitiesSecureBits
impl Binary for CapabilitiesSecureBits
source§impl BitAndAssign<CapabilitiesSecureBits> for CapabilitiesSecureBits
impl BitAndAssign<CapabilitiesSecureBits> for CapabilitiesSecureBits
source§fn bitand_assign(&mut self, other: Self)
fn bitand_assign(&mut self, other: Self)
Disables all flags disabled in the set.
source§impl BitOr<CapabilitiesSecureBits> for CapabilitiesSecureBits
impl BitOr<CapabilitiesSecureBits> for CapabilitiesSecureBits
source§fn bitor(self, other: CapabilitiesSecureBits) -> Self
fn bitor(self, other: CapabilitiesSecureBits) -> Self
Returns the union of the two sets of flags.
§type Output = CapabilitiesSecureBits
type Output = CapabilitiesSecureBits
| operator.source§impl BitOrAssign<CapabilitiesSecureBits> for CapabilitiesSecureBits
impl BitOrAssign<CapabilitiesSecureBits> for CapabilitiesSecureBits
source§fn bitor_assign(&mut self, other: Self)
fn bitor_assign(&mut self, other: Self)
Adds the set of flags.
source§impl BitXorAssign<CapabilitiesSecureBits> for CapabilitiesSecureBits
impl BitXorAssign<CapabilitiesSecureBits> for CapabilitiesSecureBits
source§fn bitxor_assign(&mut self, other: Self)
fn bitxor_assign(&mut self, other: Self)
Toggles the set of flags.
source§impl Clone for CapabilitiesSecureBits
impl Clone for CapabilitiesSecureBits
source§fn clone(&self) -> CapabilitiesSecureBits
fn clone(&self) -> CapabilitiesSecureBits
1.0.0 · source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moresource§impl Debug for CapabilitiesSecureBits
impl Debug for CapabilitiesSecureBits
source§impl Extend<CapabilitiesSecureBits> for CapabilitiesSecureBits
impl Extend<CapabilitiesSecureBits> for CapabilitiesSecureBits
source§fn extend<T: IntoIterator<Item = Self>>(&mut self, iterator: T)
fn extend<T: IntoIterator<Item = Self>>(&mut self, iterator: T)
source§fn extend_one(&mut self, item: A)
fn extend_one(&mut self, item: A)
extend_one)source§fn extend_reserve(&mut self, additional: usize)
fn extend_reserve(&mut self, additional: usize)
extend_one)source§impl FromIterator<CapabilitiesSecureBits> for CapabilitiesSecureBits
impl FromIterator<CapabilitiesSecureBits> for CapabilitiesSecureBits
source§fn from_iter<T: IntoIterator<Item = Self>>(iterator: T) -> Self
fn from_iter<T: IntoIterator<Item = Self>>(iterator: T) -> Self
source§impl Hash for CapabilitiesSecureBits
impl Hash for CapabilitiesSecureBits
source§impl LowerHex for CapabilitiesSecureBits
impl LowerHex for CapabilitiesSecureBits
source§impl Not for CapabilitiesSecureBits
impl Not for CapabilitiesSecureBits
source§impl Octal for CapabilitiesSecureBits
impl Octal for CapabilitiesSecureBits
source§impl Ord for CapabilitiesSecureBits
impl Ord for CapabilitiesSecureBits
source§fn cmp(&self, other: &CapabilitiesSecureBits) -> Ordering
fn cmp(&self, other: &CapabilitiesSecureBits) -> Ordering
1.21.0 · source§fn max(self, other: Self) -> Selfwhere
Self: Sized,
fn max(self, other: Self) -> Selfwhere
Self: Sized,
source§impl PartialEq<CapabilitiesSecureBits> for CapabilitiesSecureBits
impl PartialEq<CapabilitiesSecureBits> for CapabilitiesSecureBits
source§fn eq(&self, other: &CapabilitiesSecureBits) -> bool
fn eq(&self, other: &CapabilitiesSecureBits) -> bool
self and other values to be equal, and is used
by ==.source§impl PartialOrd<CapabilitiesSecureBits> for CapabilitiesSecureBits
impl PartialOrd<CapabilitiesSecureBits> for CapabilitiesSecureBits
source§fn partial_cmp(&self, other: &CapabilitiesSecureBits) -> Option<Ordering>
fn partial_cmp(&self, other: &CapabilitiesSecureBits) -> Option<Ordering>
1.0.0 · source§fn le(&self, other: &Rhs) -> bool
fn le(&self, other: &Rhs) -> bool
self and other) and is used by the <=
operator. Read moresource§impl SubAssign<CapabilitiesSecureBits> for CapabilitiesSecureBits
impl SubAssign<CapabilitiesSecureBits> for CapabilitiesSecureBits
source§fn sub_assign(&mut self, other: Self)
fn sub_assign(&mut self, other: Self)
Disables all flags enabled in the set.