pub struct AccessVectorRules { /* private fields */ }Expand description
Container for access vector rules optimizing rule lookups and memory layout while preserving byte-for-byte serialization.
This structure balances three primary goals:
- Separate Rule-Type Lookup Tables: Maintains independent lookup tables for each
[
RuleKind] (such asallow,dontaudit, andtype_transition) to avoid the overhead of hashing rule-type values and eliminate query-side type filtering. - Homogeneous Payload Arrays: Stores distinct rule payload types ([
AccessRule], [TypeTransitionRule], and [XpermRule]) in separate contiguous arrays to eliminate memory and performance penalties from padding when mixing differently sized and aligned payload types in the same table. - Byte-for-Byte Serialization: Retains the original binary policy order via
rule_orderto re-serialize policy data losslessly without storing ordering metadata inside individual rules.
Lookups map [RuleKey] hashes to array positions via compact [U24Index] values.
Implementations§
Source§impl AccessVectorRules
impl AccessVectorRules
Sourcepub fn new(
av_rules: Box<[AccessRule]>,
type_transitions: Box<[TypeTransitionRule]>,
xperm_rules: Box<[XpermRule]>,
rule_order: Box<[RuleKind]>,
) -> Result<Self, ParseError>
pub fn new( av_rules: Box<[AccessRule]>, type_transitions: Box<[TypeTransitionRule]>, xperm_rules: Box<[XpermRule]>, rule_order: Box<[RuleKind]>, ) -> Result<Self, ParseError>
Constructs a new AccessVectorRules table and builds dedicated lookup indexes for each rule type.
Sourcepub fn find_av_decisions(
&self,
source: TypeId,
target: TypeId,
class: ClassId,
) -> AccessVectorDecision
pub fn find_av_decisions( &self, source: TypeId, target: TypeId, class: ClassId, ) -> AccessVectorDecision
Finds standard allow, auditallow, and dontaudit access vector decisions for the specified tuple.
Sourcepub fn find_type_transition(
&self,
source: TypeId,
target: TypeId,
class: ClassId,
) -> Option<TypeId>
pub fn find_type_transition( &self, source: TypeId, target: TypeId, class: ClassId, ) -> Option<TypeId>
Finds the target domain type transition for the specified source, target, and class tuple.
Sourcepub fn find_xperms_decisions(
&self,
source: TypeId,
target: TypeId,
class: ClassId,
) -> XpermsDecisions<'_>
pub fn find_xperms_decisions( &self, source: TypeId, target: TypeId, class: ClassId, ) -> XpermsDecisions<'_>
Finds extended permission decisions (allowxperm, auditallowxperm, dontauditxperm) for the specified tuple.
Trait Implementations§
Source§impl Clone for AccessVectorRules
impl Clone for AccessVectorRules
Source§fn clone(&self) -> AccessVectorRules
fn clone(&self) -> AccessVectorRules
Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
Performs copy-assignment from
source. Read moreSource§impl Debug for AccessVectorRules
impl Debug for AccessVectorRules
impl Eq for AccessVectorRules
Source§impl PartialEq for AccessVectorRules
impl PartialEq for AccessVectorRules
Auto Trait Implementations§
impl Freeze for AccessVectorRules
impl RefUnwindSafe for AccessVectorRules
impl Send for AccessVectorRules
impl Sync for AccessVectorRules
impl Unpin for AccessVectorRules
impl UnsafeUnpin for AccessVectorRules
impl UnwindSafe for AccessVectorRules
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
§impl<T, D> Encode<Ambiguous1, D> for Twhere
D: ResourceDialect,
impl<T, D> Encode<Ambiguous1, D> for Twhere
D: ResourceDialect,
§impl<T, D> Encode<Ambiguous2, D> for Twhere
D: ResourceDialect,
impl<T, D> Encode<Ambiguous2, D> for Twhere
D: ResourceDialect,
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
Compare self to
key and return true if they are equal.Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
Compare self to
key and return true if they are equal.§impl<F, N> FidlIntoNative<Box<N>> for Fwhere
F: FidlIntoNative<N>,
impl<F, N> FidlIntoNative<Box<N>> for Fwhere
F: FidlIntoNative<N>,
fn fidl_into_native(self) -> Box<N>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
Converts
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
Converts
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more