6 releases

Uses old Rust 2015

0.3.2 May 22, 2022
0.3.1 Jun 6, 2021
0.3.0 Jan 10, 2021
0.2.1 Feb 16, 2020
0.1.0 Oct 20, 2018

#432 in Unix APIs

Download history 96/week @ 2024-04-01 46/week @ 2024-04-08 67/week @ 2024-04-15 62/week @ 2024-04-22 37/week @ 2024-04-29 46/week @ 2024-05-06 37/week @ 2024-05-13 50/week @ 2024-05-20 54/week @ 2024-05-27 50/week @ 2024-06-03 34/week @ 2024-06-10 44/week @ 2024-06-17 38/week @ 2024-06-24 15/week @ 2024-07-01 65/week @ 2024-07-08 46/week @ 2024-07-15

170 downloads per month
Used in 9 crates

MIT/Apache

8KB
120 lines

unveil-rs

Crate Documentation

Rust binding for OpenBSD's unveil(2).

Requirements

  • OpenBSD 6.4 or later

Usage

extern crate unveil;

use std::fs::File;
use std::io::prelude::*;
use unveil::unveil;

fn main() {
    let path = "public.txt";
    let contents = b"Hello world!";
    File::create(path).unwrap().write_all(contents).unwrap();

    // Restrict filesystem view by only allowing read operations on the specified path
    unveil(path, "r")
    .or_else(unveil::Error::ignore_platform)
    .unwrap();

    // Reading from unveiled paths will succeed
    let mut file = File::open(path).unwrap();
    let mut buffer = Vec::new();
    file.read_to_end(&mut buffer).unwrap();
    assert_eq!(contents, &buffer[..]);

    // Reading from paths which have not been unveiled will fail
    assert!(File::open("/etc/passwd").is_err());

    // Disable further calls to unveil
    unveil("", "")
    .or_else(unveil::Error::ignore_platform)
    .unwrap();

    // All calls to unveil will now fail
    assert!(unveil(path, "rw").is_err());
}
  • pledge-rs - Rust binding for OpenBSD's pledge(2).

Dependencies

~43KB