Struct PacEnv
pub struct PacEnv { /* private fields */ }js and pac and std only.Expand description
Builds the PAC javascript environment.
Registering it on a JsRuntimeBuilder adds every standard PAC host
function, including Microsoft’s IPv6-aware extensions. Chromium defines
that set except for getClientVersion; rama supports the full Microsoft
surface.
Implementations§
§impl PacEnv
impl PacEnv
pub const DEFAULT_DNS_TIMEOUT: Duration
pub const DEFAULT_DNS_TIMEOUT: Duration
Default per-lookup timeout for the dns host functions.
pub const DEFAULT_MAX_LOOKUPS_PER_EVALUATION: u32 = 64
pub const DEFAULT_MAX_LOOKUPS_PER_EVALUATION: u32 = 64
Default number of dns lookups one evaluation may make.
Generous for any real policy — reference scripts resolve the request host and little else — while keeping a hostile script from turning one request into an unbounded burst of queries.
pub const DEFAULT_MAX_GLOB_STEPS_PER_EVALUATION: u64 = 50_000_000
pub const DEFAULT_MAX_GLOB_STEPS_PER_EVALUATION: u64 = 50_000_000
Default number of character comparisons shExpMatch may spend in one
evaluation, across every call it makes.
Glob matching is native work no deadline can interrupt, so it needs a
bound of its own. Far above what a real policy spends — a rule set
testing a url costs thousands of steps, not millions — and exhausting
it fails the evaluation rather than answering false, so a padded url
cannot quietly stop a rule from matching.
pub const DEFAULT_MAX_ALERTS_PER_EVALUATION: u32 = 32
pub const DEFAULT_MAX_ALERTS_PER_EVALUATION: u32 = 32
Default number of alert calls one evaluation may write to the log.
Diagnostics for a script author, not a channel a script may use to fill an operator’s disk.
pub const DEFAULT_MAX_BLOCKING_PER_EVALUATION: Duration
pub const DEFAULT_MAX_BLOCKING_PER_EVALUATION: Duration
Default wall clock the host functions may block one evaluation for.
Name resolution blocks the worker thread, and the execution time limit cannot interrupt it, so the lookup count alone would still let one evaluation hold its worker for count times the dns timeout.
pub fn new() -> PacEnv
pub fn new() -> PacEnv
Create a PAC environment with the default configuration: the global dns resolver and the system clock.
pub fn maybe_with_resolver(
self,
resolver: Option<BoxDnsAddressResolver>,
) -> PacEnv
pub fn maybe_with_resolver( self, resolver: Option<BoxDnsAddressResolver>, ) -> PacEnv
Resolve names through this resolver instead of the
GlobalDnsResolver.
pub fn maybe_set_resolver(
&mut self,
resolver: Option<BoxDnsAddressResolver>,
) -> &mut PacEnv
pub fn maybe_set_resolver( &mut self, resolver: Option<BoxDnsAddressResolver>, ) -> &mut PacEnv
Resolve names through this resolver instead of the
GlobalDnsResolver.
pub fn with_resolver(self, resolver: BoxDnsAddressResolver) -> PacEnv
pub fn with_resolver(self, resolver: BoxDnsAddressResolver) -> PacEnv
Resolve names through this resolver instead of the
GlobalDnsResolver.
pub fn set_resolver(&mut self, resolver: BoxDnsAddressResolver) -> &mut PacEnv
pub fn set_resolver(&mut self, resolver: BoxDnsAddressResolver) -> &mut PacEnv
Resolve names through this resolver instead of the
GlobalDnsResolver.
pub fn without_resolver(self) -> PacEnv
pub fn without_resolver(self) -> PacEnv
Resolve names through this resolver instead of the
GlobalDnsResolver.
pub fn unset_resolver(&mut self) -> &mut PacEnv
pub fn unset_resolver(&mut self) -> &mut PacEnv
Resolve names through this resolver instead of the
GlobalDnsResolver.
pub fn dns_timeout(&self) -> Duration
pub fn dns_timeout(&self) -> Duration
The timeout one dns lookup gets.
pub fn max_lookups_per_evaluation(&self) -> u32
pub fn max_lookups_per_evaluation(&self) -> u32
How many dns lookups one evaluation may make.
pub fn max_glob_steps_per_evaluation(&self) -> u64
pub fn max_glob_steps_per_evaluation(&self) -> u64
How many shExpMatch steps one evaluation may spend.
pub fn max_alerts_per_evaluation(&self) -> u32
pub fn max_alerts_per_evaluation(&self) -> u32
How many alert calls one evaluation may log.
pub fn max_blocking_per_evaluation(&self) -> Duration
pub fn max_blocking_per_evaluation(&self) -> Duration
How long the host functions may block one evaluation.
pub fn ipv6_extensions(&self) -> bool
pub fn ipv6_extensions(&self) -> bool
Whether the ipv6-aware extensions are defined.
pub fn with_dns_timeout(self, dns_timeout: Duration) -> PacEnv
pub fn with_dns_timeout(self, dns_timeout: Duration) -> PacEnv
Timeout for a single dns lookup made by a host function
(defaults to Self::DEFAULT_DNS_TIMEOUT).
A lookup that exceeds it reports the host as unresolvable rather than failing the evaluation.
pub fn set_dns_timeout(&mut self, dns_timeout: Duration) -> &mut PacEnv
pub fn set_dns_timeout(&mut self, dns_timeout: Duration) -> &mut PacEnv
Timeout for a single dns lookup made by a host function
(defaults to Self::DEFAULT_DNS_TIMEOUT).
A lookup that exceeds it reports the host as unresolvable rather than failing the evaluation.
pub fn with_max_lookups_per_evaluation(self, lookups: u32) -> PacEnv
pub fn with_max_lookups_per_evaluation(self, lookups: u32) -> PacEnv
How many distinct hosts one evaluation may resolve before further
lookups fail it (defaults to
Self::DEFAULT_MAX_LOOKUPS_PER_EVALUATION).
Repeats within an evaluation are served from its own cache and cost nothing. Exhausting the budget throws rather than reporting a host as unresolvable: a script must not be able to spend it and have the rule that follows quietly stop matching.
Only enforced for callers that arm the budget per evaluation, as
PacResolver does.
pub fn set_max_lookups_per_evaluation(&mut self, lookups: u32) -> &mut PacEnv
pub fn set_max_lookups_per_evaluation(&mut self, lookups: u32) -> &mut PacEnv
How many distinct hosts one evaluation may resolve before further
lookups fail it (defaults to
Self::DEFAULT_MAX_LOOKUPS_PER_EVALUATION).
Repeats within an evaluation are served from its own cache and cost nothing. Exhausting the budget throws rather than reporting a host as unresolvable: a script must not be able to spend it and have the rule that follows quietly stop matching.
Only enforced for callers that arm the budget per evaluation, as
PacResolver does.
pub fn with_sh_exp_match(self, sh_exp_match: PacShExpMatch) -> PacEnv
pub fn with_sh_exp_match(self, sh_exp_match: PacShExpMatch) -> PacEnv
How shExpMatch reads its pattern (defaults to
PacShExpMatch::Reference, what browsers do).
pub fn set_sh_exp_match(&mut self, sh_exp_match: PacShExpMatch) -> &mut PacEnv
pub fn set_sh_exp_match(&mut self, sh_exp_match: PacShExpMatch) -> &mut PacEnv
How shExpMatch reads its pattern (defaults to
PacShExpMatch::Reference, what browsers do).
pub fn with_ipv6_extensions(self, ipv6_extensions: bool) -> PacEnv
pub fn with_ipv6_extensions(self, ipv6_extensions: bool) -> PacEnv
Define the ipv6-aware extensions — dnsResolveEx,
isResolvableEx, isInNetEx, myIpAddressEx,
sortIpAddressList and getClientVersion — and prefer a
FindProxyForURLEx entry point (defaults to true).
Microsoft defines all six helpers and WinHTTP prefers the extended
entry point; rama follows both behaviours. Chromium adopted five
helpers but omits getClientVersion, while Firefox defines none of
them. Turning the option off exposes only the classic surface.
pub fn set_ipv6_extensions(&mut self, ipv6_extensions: bool) -> &mut PacEnv
pub fn set_ipv6_extensions(&mut self, ipv6_extensions: bool) -> &mut PacEnv
Define the ipv6-aware extensions — dnsResolveEx,
isResolvableEx, isInNetEx, myIpAddressEx,
sortIpAddressList and getClientVersion — and prefer a
FindProxyForURLEx entry point (defaults to true).
Microsoft defines all six helpers and WinHTTP prefers the extended
entry point; rama follows both behaviours. Chromium adopted five
helpers but omits getClientVersion, while Firefox defines none of
them. Turning the option off exposes only the classic surface.
pub fn with_max_blocking_per_evaluation(self, blocking: Duration) -> PacEnv
pub fn with_max_blocking_per_evaluation(self, blocking: Duration) -> PacEnv
How long the host functions may block one evaluation before the
rest fail it (defaults to
Self::DEFAULT_MAX_BLOCKING_PER_EVALUATION).
pub fn set_max_blocking_per_evaluation(
&mut self,
blocking: Duration,
) -> &mut PacEnv
pub fn set_max_blocking_per_evaluation( &mut self, blocking: Duration, ) -> &mut PacEnv
How long the host functions may block one evaluation before the
rest fail it (defaults to
Self::DEFAULT_MAX_BLOCKING_PER_EVALUATION).
pub fn with_max_alerts_per_evaluation(self, alerts: u32) -> PacEnv
pub fn with_max_alerts_per_evaluation(self, alerts: u32) -> PacEnv
How many alert calls one evaluation may write to the log
before the rest are dropped (defaults to
Self::DEFAULT_MAX_ALERTS_PER_EVALUATION).
pub fn set_max_alerts_per_evaluation(&mut self, alerts: u32) -> &mut PacEnv
pub fn set_max_alerts_per_evaluation(&mut self, alerts: u32) -> &mut PacEnv
How many alert calls one evaluation may write to the log
before the rest are dropped (defaults to
Self::DEFAULT_MAX_ALERTS_PER_EVALUATION).
pub fn with_max_glob_steps_per_evaluation(self, steps: u64) -> PacEnv
pub fn with_max_glob_steps_per_evaluation(self, steps: u64) -> PacEnv
How many shExpMatch character comparisons one evaluation may
spend before the evaluation fails (defaults to
Self::DEFAULT_MAX_GLOB_STEPS_PER_EVALUATION).
pub fn set_max_glob_steps_per_evaluation(&mut self, steps: u64) -> &mut PacEnv
pub fn set_max_glob_steps_per_evaluation(&mut self, steps: u64) -> &mut PacEnv
How many shExpMatch character comparisons one evaluation may
spend before the evaluation fails (defaults to
Self::DEFAULT_MAX_GLOB_STEPS_PER_EVALUATION).
pub fn with_local_addresses(self, local_addresses: PacLocalAddresses) -> PacEnv
pub fn with_local_addresses(self, local_addresses: PacLocalAddresses) -> PacEnv
Which local addresses myIpAddress() and myIpAddressEx()
disclose to the script (defaults to browser behaviour, see
PacLocalAddresses).
pub fn set_local_addresses(
&mut self,
local_addresses: PacLocalAddresses,
) -> &mut PacEnv
pub fn set_local_addresses( &mut self, local_addresses: PacLocalAddresses, ) -> &mut PacEnv
Which local addresses myIpAddress() and myIpAddressEx()
disclose to the script (defaults to browser behaviour, see
PacLocalAddresses).
pub fn with_promote_ipv4_in_net(self, promote_ipv4_in_net: bool) -> PacEnv
pub fn with_promote_ipv4_in_net(self, promote_ipv4_in_net: bool) -> PacEnv
Compare an ipv4 address against an ipv6 isInNetEx prefix as
its v4-mapped form, and vice versa (defaults to true, which
is what browsers do).
Note this makes an ipv6 catch-all such as ::/0 match ipv4
addresses too; disable it to keep families strictly apart.
pub fn set_promote_ipv4_in_net(
&mut self,
promote_ipv4_in_net: bool,
) -> &mut PacEnv
pub fn set_promote_ipv4_in_net( &mut self, promote_ipv4_in_net: bool, ) -> &mut PacEnv
Compare an ipv4 address against an ipv6 isInNetEx prefix as
its v4-mapped form, and vice versa (defaults to true, which
is what browsers do).
Note this makes an ipv6 catch-all such as ::/0 match ipv4
addresses too; disable it to keep families strictly apart.
pub fn maybe_with_clock(
self,
clock: Option<Arc<dyn Fn() -> Zoned + Sync + Send>>,
) -> PacEnv
pub fn maybe_with_clock( self, clock: Option<Arc<dyn Fn() -> Zoned + Sync + Send>>, ) -> PacEnv
Read the current time from this clock instead of the system one, so the time-based host functions can be pinned in tests.
pub fn maybe_set_clock(
&mut self,
clock: Option<Arc<dyn Fn() -> Zoned + Sync + Send>>,
) -> &mut PacEnv
pub fn maybe_set_clock( &mut self, clock: Option<Arc<dyn Fn() -> Zoned + Sync + Send>>, ) -> &mut PacEnv
Read the current time from this clock instead of the system one, so the time-based host functions can be pinned in tests.
pub fn with_clock(self, clock: Arc<dyn Fn() -> Zoned + Sync + Send>) -> PacEnv
pub fn with_clock(self, clock: Arc<dyn Fn() -> Zoned + Sync + Send>) -> PacEnv
Read the current time from this clock instead of the system one, so the time-based host functions can be pinned in tests.
pub fn set_clock(
&mut self,
clock: Arc<dyn Fn() -> Zoned + Sync + Send>,
) -> &mut PacEnv
pub fn set_clock( &mut self, clock: Arc<dyn Fn() -> Zoned + Sync + Send>, ) -> &mut PacEnv
Read the current time from this clock instead of the system one, so the time-based host functions can be pinned in tests.
pub fn without_clock(self) -> PacEnv
pub fn without_clock(self) -> PacEnv
Read the current time from this clock instead of the system one, so the time-based host functions can be pinned in tests.
pub fn unset_clock(&mut self) -> &mut PacEnv
pub fn unset_clock(&mut self) -> &mut PacEnv
Read the current time from this clock instead of the system one, so the time-based host functions can be pinned in tests.
pub fn with_dns_resolver(self, resolver: impl DnsAddressResolver) -> PacEnv
pub fn with_dns_resolver(self, resolver: impl DnsAddressResolver) -> PacEnv
Set the dns resolver, taking any DnsAddressResolver.
pub fn register(
self,
builder: JsRuntimeBuilder,
) -> Result<PacRuntimeBuilder, Box<dyn Error + Sync + Send>>
pub fn register( self, builder: JsRuntimeBuilder, ) -> Result<PacRuntimeBuilder, Box<dyn Error + Sync + Send>>
Register every PAC host function on the given runtime builder.
Requires an ambient tokio runtime: the dns host functions are synchronous and block the script’s worker thread on it.
Trait Implementations§
Auto Trait Implementations§
impl !RefUnwindSafe for PacEnv
impl !UnwindSafe for PacEnv
impl Freeze for PacEnv
impl Send for PacEnv
impl Sync for PacEnv
impl Unpin for PacEnv
impl UnsafeUnpin for PacEnv
Blanket Implementations§
§impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
§impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
§impl<T> Conv for T
impl<T> Conv for T
impl<T> ErasedDestructor for Twhere
T: 'static,
§impl<T> FutureExt for T
impl<T> FutureExt for T
§fn with_context(self, otel_cx: Context) -> WithContext<Self> ⓘ
fn with_context(self, otel_cx: Context) -> WithContext<Self> ⓘ
§fn with_current_context(self) -> WithContext<Self> ⓘ
fn with_current_context(self) -> WithContext<Self> ⓘ
§impl<T> Instrument for T
impl<T> Instrument for T
§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more§impl<T> IntoRequest<T> for T
impl<T> IntoRequest<T> for T
§fn into_request(self) -> Request<T>
fn into_request(self) -> Request<T>
T in a rama_grpc::Request§impl<T> Pipe for Twhere
T: ?Sized,
impl<T> Pipe for Twhere
T: ?Sized,
§fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> Rwhere
Self: Sized,
fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> Rwhere
Self: Sized,
§fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> Rwhere
R: 'a,
fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> Rwhere
R: 'a,
self and passes that borrow into the pipe function. Read more§fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> Rwhere
R: 'a,
fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> Rwhere
R: 'a,
self and passes that borrow into the pipe function. Read more§fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
§fn pipe_borrow_mut<'a, B, R>(
&'a mut self,
func: impl FnOnce(&'a mut B) -> R,
) -> R
fn pipe_borrow_mut<'a, B, R>( &'a mut self, func: impl FnOnce(&'a mut B) -> R, ) -> R
§fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
self, then passes self.as_ref() into the pipe function.§fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
self, then passes self.as_mut() into the pipe
function.§fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
self, then passes self.deref() into the pipe function.§impl<T> Pointable for T
impl<T> Pointable for T
§impl<T> PolicyExt for Twhere
T: ?Sized,
impl<T> PolicyExt for Twhere
T: ?Sized,
§fn and<P, B, E>(self, other: P) -> And<T, P>
fn and<P, B, E>(self, other: P) -> And<T, P>
Policy that returns Action::Follow only if self and other return
Action::Follow. Read more§impl<T, U> RamaTryFrom<T> for Uwhere
U: TryFrom<T>,
impl<T, U> RamaTryFrom<T> for Uwhere
U: TryFrom<T>,
type Error = <U as TryFrom<T>>::Error
fn rama_try_from(value: T) -> Result<U, <U as RamaTryFrom<T>>::Error>
§impl<T, U, CrateMarker> RamaTryInto<U, CrateMarker> for Twhere
U: RamaTryFrom<T, CrateMarker>,
impl<T, U, CrateMarker> RamaTryInto<U, CrateMarker> for Twhere
U: RamaTryFrom<T, CrateMarker>,
type Error = <U as RamaTryFrom<T, CrateMarker>>::Error
fn rama_try_into(self) -> Result<U, <U as RamaTryFrom<T, CrateMarker>>::Error>
impl<T> Read<Exclusive, BecauseExclusive> for Twhere
T: ?Sized,
§impl<T> Tap for T
impl<T> Tap for T
§fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
Borrow<B> of a value. Read more§fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
BorrowMut<B> of a value. Read more§fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
AsRef<R> view of a value. Read more§fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
AsMut<R> view of a value. Read more§fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
Deref::Target of a value. Read more§fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
Deref::Target of a value. Read more§fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self
fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self
.tap() only in debug builds, and is erased in release builds.§fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self
fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self
.tap_mut() only in debug builds, and is erased in release
builds.§fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
.tap_borrow() only in debug builds, and is erased in release
builds.§fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
.tap_borrow_mut() only in debug builds, and is erased in release
builds.§fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
.tap_ref() only in debug builds, and is erased in release
builds.§fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
.tap_ref_mut() only in debug builds, and is erased in release
builds.§fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
.tap_deref() only in debug builds, and is erased in release
builds.