pub struct NamespaceContainer { /* private fields */ }Expand description
Spawns processes inside Linux containers via an OCI runtime.
Supports OciRuntime::Runc (standard namespace isolation) and
OciRuntime::Gvisor (user-space kernel via runsc).
For gVisor, the constructor probes whether the systrap platform works
(it requires CAP_SYS_PTRACE which is missing in rootless + host-network
mode due to a gVisor bug). If systrap fails, it falls back to ptrace
and caches the result for the lifetime of the process — all subsequent
gVisor containers skip the probe.
Implementations§
Source§impl NamespaceContainer
impl NamespaceContainer
Sourcepub fn new() -> Result<Self, SandboxError>
pub fn new() -> Result<Self, SandboxError>
Create a container using runc from $PATH.
§Errors
Returns SandboxError::RuntimeNotFound if runc is not on $PATH.
Sourcepub fn with_gvisor() -> Result<Self, SandboxError>
pub fn with_gvisor() -> Result<Self, SandboxError>
Create a container using gVisor (runsc) from $PATH.
On first call, probes the systrap platform by running a trivial
container. If systrap works, uses it for all future containers
(fastest). If it fails (e.g., missing CAP_SYS_PTRACE in rootless
mode), falls back to ptrace and logs a warning. The result is
cached process-wide — subsequent calls skip the probe.
§Errors
Returns SandboxError::RuntimeNotFound if runsc is not on $PATH.
Sourcepub fn with_runtime(kind: OciRuntime) -> Result<Self, SandboxError>
pub fn with_runtime(kind: OciRuntime) -> Result<Self, SandboxError>
Create a container using the specified OCI runtime.
§Errors
Returns SandboxError::RuntimeNotFound if the runtime binary is
not on $PATH.
Sourcepub fn spawn(
&self,
config: &ContainerConfig,
) -> Result<ContainerProcess, SandboxError>
pub fn spawn( &self, config: &ContainerConfig, ) -> Result<ContainerProcess, SandboxError>
Spawn a command inside a namespace container.
Creates a temporary OCI bundle, generates a runtime spec from config,
and runs the container in the foreground. Returns a
ContainerProcess that holds the runtime child and the bundle dir.
§Errors
Returns a SandboxError if bundle creation or process spawn fails.
Sourcepub fn spawn_captured(
&self,
config: &ContainerConfig,
mode: OutputMode,
) -> Result<ProcessCapture, SandboxError>
pub fn spawn_captured( &self, config: &ContainerConfig, mode: OutputMode, ) -> Result<ProcessCapture, SandboxError>
Spawn a command inside a namespace container with output captured to files in a temporary directory.
stdout and stderr are redirected to files rather than pipes. The files
persist even if the process is killed, and the temporary directory is
deleted when the last Arc<CapturedOutput> reference is dropped.
§Errors
Returns a SandboxError if directory creation, file opening, or
process spawn fails.
Sourcepub fn spawn_interactive(
&self,
config: &ContainerConfig,
) -> Result<PtySession, SandboxError>
pub fn spawn_interactive( &self, config: &ContainerConfig, ) -> Result<PtySession, SandboxError>
Spawn a command inside a namespace container with full PTY support for human-in-the-loop interaction.
Uses the OCI runtime’s --console-socket mechanism: the runtime
creates a PTY inside the container and sends the controller fd back
over a Unix socket via SCM_RIGHTS. The returned PtySession
contains the controller fd for host-side I/O.
§Errors
Returns a SandboxError if socket setup, process spawn, or PTY
fd handshake fails.
Sourcepub fn build_config(
sandbox: &SandboxConfig,
command: impl Into<String>,
args: Vec<String>,
) -> ContainerConfig
pub fn build_config( sandbox: &SandboxConfig, command: impl Into<String>, args: Vec<String>, ) -> ContainerConfig
Build a ContainerConfig from synwire-core’s SandboxConfig.
Derives namespace flags, bind mounts, and security parameters from the high-level configuration.
Trait Implementations§
Auto Trait Implementations§
impl Freeze for NamespaceContainer
impl RefUnwindSafe for NamespaceContainer
impl Send for NamespaceContainer
impl Sync for NamespaceContainer
impl Unpin for NamespaceContainer
impl UnsafeUnpin for NamespaceContainer
impl UnwindSafe for NamespaceContainer
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> FutureExt for T
impl<T> FutureExt for T
Source§fn with_context(self, otel_cx: Context) -> WithContext<Self>
fn with_context(self, otel_cx: Context) -> WithContext<Self>
Source§fn with_current_context(self) -> WithContext<Self>
fn with_current_context(self) -> WithContext<Self>
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
Source§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more