pub struct Policy {Show 39 fields
pub fs_writable: Vec<PathBuf>,
pub fs_readable: Vec<PathBuf>,
pub fs_denied: Vec<PathBuf>,
pub deny_syscalls: Option<Vec<String>>,
pub allow_syscalls: Option<Vec<String>>,
pub net_allow_hosts: Vec<String>,
pub net_bind: Vec<u16>,
pub net_connect: Vec<u16>,
pub no_raw_sockets: bool,
pub no_udp: bool,
pub isolate_ipc: bool,
pub isolate_signals: bool,
pub isolate_pids: bool,
pub max_memory: Option<ByteSize>,
pub max_processes: u32,
pub max_open_files: Option<u32>,
pub max_cpu: Option<u8>,
pub random_seed: Option<u64>,
pub time_start: Option<SystemTime>,
pub no_randomize_memory: bool,
pub no_huge_pages: bool,
pub deterministic_dirs: bool,
pub hostname: Option<String>,
pub fs_isolation: FsIsolation,
pub workdir: Option<PathBuf>,
pub fs_storage: Option<PathBuf>,
pub max_disk: Option<ByteSize>,
pub on_exit: BranchAction,
pub on_error: BranchAction,
pub chroot: Option<PathBuf>,
pub clean_env: bool,
pub env: HashMap<String, String>,
pub close_fds: bool,
pub gpu_devices: Option<Vec<u32>>,
pub cpu_cores: Option<Vec<u32>>,
pub num_cpus: Option<u32>,
pub port_remap: bool,
pub privileged: bool,
pub policy_fn: Option<PolicyCallback>,
}Expand description
Sandbox policy configuration.
Fields§
§fs_writable: Vec<PathBuf>§fs_readable: Vec<PathBuf>§fs_denied: Vec<PathBuf>§deny_syscalls: Option<Vec<String>>§allow_syscalls: Option<Vec<String>>§net_allow_hosts: Vec<String>§net_bind: Vec<u16>§net_connect: Vec<u16>§no_raw_sockets: bool§no_udp: bool§isolate_ipc: bool§isolate_signals: bool§isolate_pids: bool§max_memory: Option<ByteSize>§max_processes: u32§max_open_files: Option<u32>§max_cpu: Option<u8>§random_seed: Option<u64>§time_start: Option<SystemTime>§no_randomize_memory: bool§no_huge_pages: bool§deterministic_dirs: bool§hostname: Option<String>§fs_isolation: FsIsolation§workdir: Option<PathBuf>§fs_storage: Option<PathBuf>§max_disk: Option<ByteSize>§on_exit: BranchAction§on_error: BranchAction§chroot: Option<PathBuf>§clean_env: bool§env: HashMap<String, String>§close_fds: bool§gpu_devices: Option<Vec<u32>>§cpu_cores: Option<Vec<u32>>§num_cpus: Option<u32>§port_remap: bool§privileged: bool§policy_fn: Option<PolicyCallback>Implementations§
Trait Implementations§
Source§impl<'de> Deserialize<'de> for Policy
impl<'de> Deserialize<'de> for Policy
Source§fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
Deserialize this value from the given Serde deserializer. Read more
Auto Trait Implementations§
impl Freeze for Policy
impl !RefUnwindSafe for Policy
impl Send for Policy
impl Sync for Policy
impl Unpin for Policy
impl UnsafeUnpin for Policy
impl !UnwindSafe for Policy
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more