pub enum EnforcementTier {
KernelDeny,
ObserveOnly,
ProxyOnly,
}Expand description
The platform’s enforcement tier, so operators don’t over-trust a weaker OS (PRODUCT.md W0 table). The proxy itself is cross-platform; what differs is whether kernel deny backs it up.
Variants§
KernelDeny
Inline kernel deny available (Linux LSM-BPF).
ObserveOnly
Observe-only kernel layer (macOS Endpoint Security is mostly observe); the proxy is the sole hard deny and MUST be fail-closed.
ProxyOnly
Proxy-only - no kernel layer wired at all; fully reliant on this PEP.
Implementations§
Source§impl EnforcementTier
impl EnforcementTier
Sourcepub fn current() -> Self
pub fn current() -> Self
The tier of the host this binary is running on.
macOS gets EnforcementTier::ObserveOnly: Endpoint Security is mostly
observe, so the cross-platform proxy is the only hard deny (PRODUCT.md W0).
Trait Implementations§
Source§impl Clone for EnforcementTier
impl Clone for EnforcementTier
Source§fn clone(&self) -> EnforcementTier
fn clone(&self) -> EnforcementTier
Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
Performs copy-assignment from
source. Read moreimpl Copy for EnforcementTier
Source§impl Debug for EnforcementTier
impl Debug for EnforcementTier
impl Eq for EnforcementTier
Source§impl PartialEq for EnforcementTier
impl PartialEq for EnforcementTier
Source§fn eq(&self, other: &EnforcementTier) -> bool
fn eq(&self, other: &EnforcementTier) -> bool
Tests for
self and other values to be equal, and is used by ==.impl StructuralPartialEq for EnforcementTier
Auto Trait Implementations§
impl Freeze for EnforcementTier
impl RefUnwindSafe for EnforcementTier
impl Send for EnforcementTier
impl Sync for EnforcementTier
impl Unpin for EnforcementTier
impl UnsafeUnpin for EnforcementTier
impl UnwindSafe for EnforcementTier
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more