Skip to main content

ResolvedDestination

Struct ResolvedDestination 

pub struct ResolvedDestination { /* private fields */ }
Expand description

A normalized host and the exact address set that passed network policy.

Callers must dial Self::addresses directly. Resolving Self::host again would reopen the DNS-rebinding window this type closes, so the type deliberately offers no way to get from a value back to a fresh resolution.

Implementations§

Source§

impl ResolvedDestination

Source

pub fn new( host: &str, port: u16, addresses: impl IntoIterator<Item = SocketAddr>, private_access: PrivateNetworkAccess, nat64_prefixes: &[Nat64Prefix], ) -> Result<Self, NetworkGuardError>

Validate one DNS result and retain the exact addresses to dial.

nat64_prefixes is the deployment’s security.nat64_prefixes, parsed once by the caller at construction. Passing an empty slice states that the host runs no network-specific translator; it does not skip the well-known 64:ff9b::/96 form, which the address predicates decode unconditionally.

Three things happen here that a bare validator call does not do:

  1. Cloud metadata is refused for both access modes, so an operator opt-in for private destinations never re-opens it.
  2. A mixed public/private answer set is refused even when private access is authorized. Otherwise resolver ordering or connection fallback silently decides which trust zone the connection lands in.
  3. The surviving addresses are retained, which is the pin.
§Errors

Returns NetworkGuardError for a malformed host or port, an empty or mismatched answer set, a metadata endpoint, an unauthorized private address, or an answer spanning both address classes.

Source

pub fn host(&self) -> &str

Canonical lowercase host, without IPv6 brackets or a trailing DNS dot. Use this for SNI and certificate verification, never for a second resolution.

Source

pub fn port(&self) -> u16

Authorized destination port.

Source

pub fn addresses(&self) -> &[SocketAddr]

Exact validated socket addresses. Dial these instead of resolving again.

Trait Implementations§

Source§

impl Clone for ResolvedDestination

Source§

fn clone(&self) -> ResolvedDestination

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · §

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for ResolvedDestination

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Eq for ResolvedDestination

Source§

impl PartialEq for ResolvedDestination

Source§

fn eq(&self, other: &ResolvedDestination) -> bool

Tests for self and other values to be equal, and is used by ==.
1.0.0 (const: unstable) · §

fn ne(&self, other: &Rhs) -> bool

Tests for !=. The default implementation is almost always sufficient, and should not be overridden without very good reason.
Source§

impl StructuralPartialEq for ResolvedDestination

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

§

fn equivalent(&self, key: &K) -> bool

Checks if this value is equivalent to the given key. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

§

impl<T> Instrument for T

§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided [Span], returning an Instrumented wrapper. Read more
§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
§

impl<T> WithSubscriber for T

§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a [WithDispatch] wrapper. Read more
§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a [WithDispatch] wrapper. Read more