pub struct BoundUnixSocket { /* private fields */ }Expand description
A bound AF_UNIX socket file: the node exists as long as this value
does.
Hold it beside the UnixListener it was bound with. Dropping it removes
the node, which is what keeps the next bind of the same path out of the
unlink-then-bind race below.
Implementations§
Source§impl BoundUnixSocket
impl BoundUnixSocket
Sourcepub fn bind(path: &Path) -> Result<(BoundUnixSocket, UnixListener), Error>
pub fn bind(path: &Path) -> Result<(BoundUnixSocket, UnixListener), Error>
Binds path with the hygiene a filesystem endpoint needs, replacing a
stale socket file left by a crash.
Four things happen here, and each answers a documented hazard:
- The path budget.
sun_pathis 108 bytes on Linux and 104 on macOS including the terminator, and the kernel truncates rather than failing, so an over-long path binds something other than what was asked for. It is refused instead (docs/research/ipc.md§1.1, §2.1). libzmq’sipc://publishes the same limit as “113 characters including the prefix” and leaves the rest to the caller (docs/research/zeromq.md§11). - The socket-type check. Closing a socket does not remove its
node, so a crash leaves one and
bind()then fails withEADDRINUSE. A stale node is a socket nobody is listening on; anything else at that path is not ours to remove, and removing it anyway is how a bind deletes a caller’s data. - Unlink, then bind. The usual answer to the stale node, and it
opens a substitution race that is closed only “unless directory
ownership and permissions prevent endpoint substitution”
(
docs/research/ipc.md§1.2, §7). The directory is therefore load-bearing: the caller MUST place the socket in a directory it owns and that no other user may write. libzmq’sipc://has this hazard too and answers none of it — a local process can steal a bound endpoint. - The mode, explicitly.
0600set after bind, because a socket file is created with whateverumaskallows, which is whatever the process happened to inherit.
Trait Implementations§
Source§impl Debug for BoundUnixSocket
impl Debug for BoundUnixSocket
Source§impl Drop for BoundUnixSocket
impl Drop for BoundUnixSocket
Auto Trait Implementations§
impl Freeze for BoundUnixSocket
impl RefUnwindSafe for BoundUnixSocket
impl Send for BoundUnixSocket
impl Sync for BoundUnixSocket
impl Unpin for BoundUnixSocket
impl UnsafeUnpin for BoundUnixSocket
impl UnwindSafe for BoundUnixSocket
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more