mirror of
https://github.com/kata-containers/kata-containers.git
synced 2025-04-30 12:44:39 +00:00
agent/rustjail: Clean up some static definitions with vec! macro
DEFAULT_ALLOWED_DEVICES and DEFAULT_DEVICES are essentially global constant lists. They're implemented as a lazy_static! initialized Vec values. The code to initialize them creates an empty Vec then pushes values onto it. We can simplify this a bit by using the vec! macro. This might be slightly more efficient, and it definitely stops recent clippy versions (e.g. 1.51) from complaining about it. fixes #1611 Signed-off-by: David Gibson <david@gibson.dropbear.id.au>
This commit is contained in:
parent
eaec5a6c06
commit
3c4485ece3
@ -489,63 +489,61 @@ lazy_static! {
|
|||||||
};
|
};
|
||||||
|
|
||||||
pub static ref DEFAULT_ALLOWED_DEVICES: Vec<LinuxDeviceCgroup> = {
|
pub static ref DEFAULT_ALLOWED_DEVICES: Vec<LinuxDeviceCgroup> = {
|
||||||
let mut v = Vec::new();
|
vec![
|
||||||
|
|
||||||
// all mknod to all char devices
|
// all mknod to all char devices
|
||||||
v.push(LinuxDeviceCgroup {
|
LinuxDeviceCgroup {
|
||||||
allow: true,
|
allow: true,
|
||||||
r#type: "c".to_string(),
|
r#type: "c".to_string(),
|
||||||
major: Some(WILDCARD),
|
major: Some(WILDCARD),
|
||||||
minor: Some(WILDCARD),
|
minor: Some(WILDCARD),
|
||||||
access: "m".to_string(),
|
access: "m".to_string(),
|
||||||
});
|
},
|
||||||
|
|
||||||
// all mknod to all block devices
|
// all mknod to all block devices
|
||||||
v.push(LinuxDeviceCgroup {
|
LinuxDeviceCgroup {
|
||||||
allow: true,
|
allow: true,
|
||||||
r#type: "b".to_string(),
|
r#type: "b".to_string(),
|
||||||
major: Some(WILDCARD),
|
major: Some(WILDCARD),
|
||||||
minor: Some(WILDCARD),
|
minor: Some(WILDCARD),
|
||||||
access: "m".to_string(),
|
access: "m".to_string(),
|
||||||
});
|
},
|
||||||
|
|
||||||
// all read/write/mknod to char device /dev/console
|
// all read/write/mknod to char device /dev/console
|
||||||
v.push(LinuxDeviceCgroup {
|
LinuxDeviceCgroup {
|
||||||
allow: true,
|
allow: true,
|
||||||
r#type: "c".to_string(),
|
r#type: "c".to_string(),
|
||||||
major: Some(5),
|
major: Some(5),
|
||||||
minor: Some(1),
|
minor: Some(1),
|
||||||
access: "rwm".to_string(),
|
access: "rwm".to_string(),
|
||||||
});
|
},
|
||||||
|
|
||||||
// all read/write/mknod to char device /dev/pts/<N>
|
// all read/write/mknod to char device /dev/pts/<N>
|
||||||
v.push(LinuxDeviceCgroup {
|
LinuxDeviceCgroup {
|
||||||
allow: true,
|
allow: true,
|
||||||
r#type: "c".to_string(),
|
r#type: "c".to_string(),
|
||||||
major: Some(136),
|
major: Some(136),
|
||||||
minor: Some(WILDCARD),
|
minor: Some(WILDCARD),
|
||||||
access: "rwm".to_string(),
|
access: "rwm".to_string(),
|
||||||
});
|
},
|
||||||
|
|
||||||
// all read/write/mknod to char device /dev/ptmx
|
// all read/write/mknod to char device /dev/ptmx
|
||||||
v.push(LinuxDeviceCgroup {
|
LinuxDeviceCgroup {
|
||||||
allow: true,
|
allow: true,
|
||||||
r#type: "c".to_string(),
|
r#type: "c".to_string(),
|
||||||
major: Some(5),
|
major: Some(5),
|
||||||
minor: Some(2),
|
minor: Some(2),
|
||||||
access: "rwm".to_string(),
|
access: "rwm".to_string(),
|
||||||
});
|
},
|
||||||
|
|
||||||
// all read/write/mknod to char device /dev/net/tun
|
// all read/write/mknod to char device /dev/net/tun
|
||||||
v.push(LinuxDeviceCgroup {
|
LinuxDeviceCgroup {
|
||||||
allow: true,
|
allow: true,
|
||||||
r#type: "c".to_string(),
|
r#type: "c".to_string(),
|
||||||
major: Some(10),
|
major: Some(10),
|
||||||
minor: Some(200),
|
minor: Some(200),
|
||||||
access: "rwm".to_string(),
|
access: "rwm".to_string(),
|
||||||
});
|
},
|
||||||
|
]
|
||||||
v
|
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
|
@ -132,8 +132,8 @@ lazy_static! {
|
|||||||
};
|
};
|
||||||
|
|
||||||
pub static ref DEFAULT_DEVICES: Vec<LinuxDevice> = {
|
pub static ref DEFAULT_DEVICES: Vec<LinuxDevice> = {
|
||||||
let mut v = Vec::new();
|
vec![
|
||||||
v.push(LinuxDevice {
|
LinuxDevice {
|
||||||
path: "/dev/null".to_string(),
|
path: "/dev/null".to_string(),
|
||||||
r#type: "c".to_string(),
|
r#type: "c".to_string(),
|
||||||
major: 1,
|
major: 1,
|
||||||
@ -141,8 +141,8 @@ lazy_static! {
|
|||||||
file_mode: Some(0o666),
|
file_mode: Some(0o666),
|
||||||
uid: Some(0xffffffff),
|
uid: Some(0xffffffff),
|
||||||
gid: Some(0xffffffff),
|
gid: Some(0xffffffff),
|
||||||
});
|
},
|
||||||
v.push(LinuxDevice {
|
LinuxDevice {
|
||||||
path: "/dev/zero".to_string(),
|
path: "/dev/zero".to_string(),
|
||||||
r#type: "c".to_string(),
|
r#type: "c".to_string(),
|
||||||
major: 1,
|
major: 1,
|
||||||
@ -150,8 +150,8 @@ lazy_static! {
|
|||||||
file_mode: Some(0o666),
|
file_mode: Some(0o666),
|
||||||
uid: Some(0xffffffff),
|
uid: Some(0xffffffff),
|
||||||
gid: Some(0xffffffff),
|
gid: Some(0xffffffff),
|
||||||
});
|
},
|
||||||
v.push(LinuxDevice {
|
LinuxDevice {
|
||||||
path: "/dev/full".to_string(),
|
path: "/dev/full".to_string(),
|
||||||
r#type: String::from("c"),
|
r#type: String::from("c"),
|
||||||
major: 1,
|
major: 1,
|
||||||
@ -159,8 +159,8 @@ lazy_static! {
|
|||||||
file_mode: Some(0o666),
|
file_mode: Some(0o666),
|
||||||
uid: Some(0xffffffff),
|
uid: Some(0xffffffff),
|
||||||
gid: Some(0xffffffff),
|
gid: Some(0xffffffff),
|
||||||
});
|
},
|
||||||
v.push(LinuxDevice {
|
LinuxDevice {
|
||||||
path: "/dev/tty".to_string(),
|
path: "/dev/tty".to_string(),
|
||||||
r#type: "c".to_string(),
|
r#type: "c".to_string(),
|
||||||
major: 5,
|
major: 5,
|
||||||
@ -168,8 +168,8 @@ lazy_static! {
|
|||||||
file_mode: Some(0o666),
|
file_mode: Some(0o666),
|
||||||
uid: Some(0xffffffff),
|
uid: Some(0xffffffff),
|
||||||
gid: Some(0xffffffff),
|
gid: Some(0xffffffff),
|
||||||
});
|
},
|
||||||
v.push(LinuxDevice {
|
LinuxDevice {
|
||||||
path: "/dev/urandom".to_string(),
|
path: "/dev/urandom".to_string(),
|
||||||
r#type: "c".to_string(),
|
r#type: "c".to_string(),
|
||||||
major: 1,
|
major: 1,
|
||||||
@ -177,8 +177,8 @@ lazy_static! {
|
|||||||
file_mode: Some(0o666),
|
file_mode: Some(0o666),
|
||||||
uid: Some(0xffffffff),
|
uid: Some(0xffffffff),
|
||||||
gid: Some(0xffffffff),
|
gid: Some(0xffffffff),
|
||||||
});
|
},
|
||||||
v.push(LinuxDevice {
|
LinuxDevice {
|
||||||
path: "/dev/random".to_string(),
|
path: "/dev/random".to_string(),
|
||||||
r#type: "c".to_string(),
|
r#type: "c".to_string(),
|
||||||
major: 1,
|
major: 1,
|
||||||
@ -186,8 +186,8 @@ lazy_static! {
|
|||||||
file_mode: Some(0o666),
|
file_mode: Some(0o666),
|
||||||
uid: Some(0xffffffff),
|
uid: Some(0xffffffff),
|
||||||
gid: Some(0xffffffff),
|
gid: Some(0xffffffff),
|
||||||
});
|
},
|
||||||
v
|
]
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
|
Loading…
Reference in New Issue
Block a user