Summary: 683 instances, 465 unique

Text	Count
unsafe fn protect_workspace_subdir(cwd: &Path, psid: *mut c_void, subdir: &str) -> Result<bool> {	1
let queried = unsafe {	2
unsafe extern "system" {	3
let character = unsafe { key.uChar.UnicodeChar };	1
let handle = unsafe { OwnedHandle::from_raw_handle(handle.cast()) };	1
if unsafe { SetConsoleMode(handle, mode | requested) } == 0 {	1
let value_ref = unsafe {	1
let ok = unsafe { SetFileAttributesW(wide.as_ptr(), new_attrs) };	1
let handle = unsafe {	5
|| unsafe { libc::fcntl(fd.as_raw_fd(), libc::F_SETFL, flags | libc::O_NONBLOCK) } == -1	1
let mut sei: SHELLEXECUTEINFOW = unsafe { std::mem::zeroed() };	1
let _ = unsafe { libc::kevent(kq, &kev, 1, std::ptr::null_mut(), 0, std::ptr::null()) };	1
let null_read_fd = unsafe { libc::open(c"/dev/null".as_ptr(), libc::O_RDONLY) };	1
unsafe { std::slice::from_raw_parts(buf.as_ptr().cast(), buf.len()) }	1
let result = unsafe { FwpmFilterDeleteByKey0(engine, key) };	1
unsafe fn already_present(self, p_dacl: *mut ACL, psid: *mut c_void) -> bool {	1
let mut info: OSVERSIONINFOW = unsafe { mem::zeroed() };	1
pub unsafe fn protect_workspace_codex_dir(cwd: &Path, psid: *mut c_void) -> Result<bool> {	1
unsafe { libc::_exit(0) };	1
let attrs = unsafe { GetFileAttributesW(wide.as_ptr()) };	1
pub unsafe fn dacl_has_write_deny_for_sid(p_dacl: *mut ACL, psid: *mut c_void) -> bool {	1
let cancel_result = unsafe { CancelIoEx(handle, self.as_mut_ptr()) };	1
let ok = unsafe {	4
let result = unsafe { libc::fcntl(fd, libc::F_SETFD, flags | libc::FD_CLOEXEC) };	1
if cf_string_equals(&proxy_type, unsafe { kCFProxyTypeHTTP }) {	1
let count = unsafe {	1
let _ = unsafe { CloseHandle(handle) };	1
if unsafe { libc::fcntl(control.as_raw_fd(), libc::F_SETFD, flags | libc::FD_CLOEXEC) } < 0	1
let handle = unsafe { GetStdHandle(STD_INPUT_HANDLE) };	3
if unsafe { libc::getppid() } != parent_pid {	2
let err = unsafe { GetLastError() } as i32;	3
.and_then(|desktop| unsafe {	1
let _ = unsafe { libc::dup2(self.saved_stderr.as_raw_fd(), libc::STDERR_FILENO) };	1
if cf_string_equals(&proxy_type, unsafe { kCFProxyTypeAutoConfigurationURL })	1
unsafe fn ensure_allow_mask_aces_with_inheritance_impl(	1
unsafe { (stdout_stat.assume_init(), stderr_stat.assume_init()) };	1
let handle = unsafe { OpenProcess(PROCESS_SYNCHRONIZE, 0, pid) };	1
unsafe { NetApiBufferFree(buffer.cast()) };	1
let mode = unsafe { kCFRunLoopDefaultMode };	1
unsafe {	43
let applied_paths = unsafe { apply_deny_read_acls(desired_paths, psid) }?;	1
if unsafe { GetNumberOfConsoleInputEvents(self.handle, &mut pending) } == 0 {	1
let state = unsafe { &mut *client.cast::<PacRunLoopState>() };	1
unsafe fn dacl_allow_mask_needs_refresh(	1
if unsafe { libc::tcgetattr(fd.get_ref().as_raw_fd(), termios.as_mut_ptr()) }	1
|| cf_string_equals(&proxy_type, unsafe { kCFProxyTypeHTTPS })	1
let res = unsafe { GetProcessId(self.proc.lock().unwrap().as_raw_handle() as _) };	1
let key = unsafe { record.Event.KeyEvent };	1
unsafe { std::slice::from_raw_parts(out_blob.pbData, out_blob.cbData as usize) }.to_vec();	2
&& unsafe { TerminateProcess(*handle, 1) } == 0	1
let Some(host) = cf_string_value(proxy, unsafe { kCFProxyHostNameKey })	1
let (stdin_pair, stdout_pair, stderr_pair) = unsafe { setup_stdio_pipes()? };	1
let saved_stderr = unsafe { libc::dup(libc::STDERR_FILENO) };	1
let ok = unsafe { WinHttpGetIEProxyConfigForCurrentUser(&mut raw) };	1
Some(value) => unsafe { std::env::set_var("VISUAL", value) },	1
let result = unsafe { (CONPTY.ResizePseudoConsole)(self.con, size) };	1
let mut previous_action: libc::sigaction = unsafe { std::mem::zeroed() };	1
let ret_code = unsafe { libc::setrlimit(libc::RLIMIT_CORE, &rlim) };	1
let (h_token, readonly_sid, readonly_sid_str, write_root_sids) = unsafe {	1
let result = unsafe { FwpmFilterAdd0(engine, &filter, null_mut(), &mut filter_id) };	1
unsafe { std::ptr::read_unaligned(self.buffer.as_ptr() as *const TOKEN_USER) };	1
unsafe {	6
let previous_error_mode = unsafe { SetErrorMode(RUNNER_ERROR_MODE_FLAGS) };	1
let url = unsafe {	1
let mut read_end = unsafe { std::fs::File::from_raw_fd(fds[0]) };	2
let mut si: STARTUPINFOEXW = unsafe { mem::zeroed() };	1
unsafe extern "C" fn(*mut c_void, CFArrayRef, CFErrorRef);	1
let flags = unsafe { libc::fcntl(route.control_fd, libc::F_GETFD) };	1
let result = unsafe { libc::kill(raw_pid, libc::SIGKILL) };	1
let mut addr_req = unsafe { std::mem::zeroed::<libc::ifreq>() };	1
assert_ne!(unsafe { libc::fcntl(socket_fd, libc::F_GETFD) }, -1);	1
unsafe impl async_io::IoSafe for WindowsUnixStream {}	1
let url = match cf_i32_value(proxy, unsafe { kCFProxyPortNumberKey }) {	1
let handshake_client = unsafe { AsyncDatagramSocket::from_raw_fd(dup_socket_fd) }?;	1
let child_sid = unsafe { libc::getsid(child_pid) };	1
unsafe { std::mem::MaybeUninit::zeroed().assume_init() };	1
if cf_string_equals(&proxy_type, unsafe {	1
let mut pi: PROCESS_INFORMATION = unsafe { std::mem::zeroed() };	2
let result = unsafe { libc::kill(-raw_pid, libc::SIGKILL) };	1
let process_handle = unsafe { OpenProcess(PROCESS_QUERY_LIMITED_INFORMATION, 0, process_id) };	1
let res = unsafe { libc::poll(&mut poll_fd, 1, 10) };	1
pub unsafe fn ensure_allow_mask_aces_with_inheritance(	1
unsafe { OpenProcess(PROCESS_QUERY_LIMITED_INFORMATION, FALSE, server_process_id) };	1
let cmsg_data_len = usize::try_from(unsafe { (*cmsg).cmsg_len })	1
let flags = unsafe { libc::fcntl(fd, libc::F_GETFD) };	1
let parent_pid = unsafe { libc::getpid() };	4
let fd = unsafe { libc::socket(libc::AF_INET, libc::SOCK_DGRAM | libc::SOCK_CLOEXEC, 0) };	1
let err = unsafe { GetLastError() };	1
let mut addr = unsafe { std::mem::zeroed::<libc::sockaddr_un>() };	1
let opened = unsafe {	1
pipe_write: unsafe { File::from_raw_handle(h_pipe_in as _) },	1
fds.push(unsafe { OwnedFd::from_raw_fd(fd) });	1
unsafe fn enable_single_privilege(h_token: HANDLE, name: &str) -> Result<()> {	1
unsafe { libc::fcntl(file.as_raw_fd(), libc::F_SETFD, flags | libc::FD_CLOEXEC) };	1
let status = unsafe {	1
let ok = unsafe { OpenProcessToken(GetCurrentProcess(), desired, &mut h) };	1
if requested_mode != mode && unsafe { SetConsoleMode(handle, requested_mode) } == 0 {	3
unsafe { std::env::set_var(&key, &value) };	1
let result = unsafe { libc::kill(raw_pid, libc::SIGTERM) };	1
unsafe { GetLastError() }	1
unsafe { GetFileType(file.as_raw_handle() as HANDLE) == FILE_TYPE_DISK }	1
if unsafe { libc::statvfs(path.as_ptr(), stats.as_mut_ptr()) } != 0 {	1
if unsafe { libc::dup2(file.as_raw_fd(), libc::STDERR_FILENO) } == -1 {	1
pub unsafe fn create_workspace_write_token_with_caps_from(	1
pub unsafe fn create_readonly_token_with_caps_from(	1
return Err(anyhow!("CryptProtectData failed: {}", unsafe {	1
let mut blocked: libc::sigset_t = unsafe { std::mem::zeroed() };	1
unsafe {	1
None => unsafe { env::remove_var(key) },	1
let fd = unsafe { libc::socket(libc::AF_UNIX, libc::SOCK_STREAM, 0) };	1
pub unsafe fn create_readonly_token_with_cap(	1
Ok(unsafe { AsyncDatagramSocket::from_raw_fd(client_fd) }?)	1
let duplicated = unsafe { libc::dup(fd) };	1
let usage = unsafe {	1
let event = unsafe { CreateEventW(ptr::null(), TRUE, FALSE, ptr::null()) };	1
let res = unsafe { libc::close(fd) };	1
let ty = unsafe { (*cmsg).cmsg_type };	1
let null_write_fd = unsafe { libc::open(c"/dev/null".as_ptr(), libc::O_WRONLY) };	1
Some(Ok(unsafe { ProxyArray::wrap_under_get_rule(proxies) }))	1
let result = unsafe {	13
let proxy_type = cf_string_value(&proxy, unsafe { kCFProxyTypeKey })?;	1
let close_res = unsafe { libc::close(fd) };	1
let mut pi: PROCESS_INFORMATION = unsafe { mem::zeroed() };	1
let ok = unsafe {	2
pub unsafe fn sync_persistent_deny_read_acls(	1
let mut ifreq = unsafe { std::mem::zeroed::<libc::ifreq>() };	1
let configured = unsafe {	1
let result = unsafe { libc::flock(file.as_raw_fd(), libc::LOCK_EX | libc::LOCK_NB) };	2
if cf_string_equals(&proxy_type, unsafe { kCFProxyTypeHTTPS }) {	1
if unsafe { libc::getrlimit(libc::RLIMIT_NOFILE, &raw mut limit) } == 0 {	1
let result = unsafe { libc::fcntl(fd, libc::F_SETFD, flags | libc::FD_CLOEXEC) };	2
let fd = unsafe { OwnedFd::from_raw_fd(fd) };	1
let spawn_result = unsafe {	1
pub unsafe fn revoke_ace(path: &Path, psid: *mut c_void) {	1
pipe_read: unsafe { File::from_raw_handle(h_pipe_out as _) },	1
let count = unsafe {	1
unsafe {	23
unsafe fn update(	2
let mut action: libc::sigaction = unsafe { std::mem::zeroed() };	1
return Err(io::Error::from_raw_os_error(unsafe {	3
let result = unsafe { FwpmSubLayerAdd0(engine, &sublayer, null_mut()) };	1
unsafe fn dacl_mask_allows_with_scope(	1
let status = unsafe { NtResumeProcess(process.as_raw_handle().cast()) };	1
Some(val) => unsafe { env::set_var(key, val) },	1
pub unsafe fn world_sid() -> Result<Vec<u8>> {	1
if unsafe { libc::prctl(libc::PR_SET_PDEATHSIG, libc::SIGTERM) } == -1 {	1
let handle = unsafe { GetStdHandle(kind) };	1
let mut limits: JOBOBJECT_EXTENDED_LIMIT_INFORMATION = unsafe { std::mem::zeroed() };	1
unsafe extern "C" {	4
let result = unsafe { libc::setpgid(0, 0) };	1
let fd_status = unsafe { libc::fcntl(received_fds[0].as_raw_fd(), libc::F_GETFD) };	1
let mut control = unsafe { UnixStream::from_raw_fd(route.control_fd) };	1
while unsafe { *ptr.add(len) } != 0 {	1
Ok(unsafe { (File::from_raw_fd(master), File::from_raw_fd(slave)) })	1
let flags = unsafe { libc::fcntl(fd.as_raw_fd(), libc::F_GETFL) };	1
let saved_stderr = unsafe { OwnedFd::from_raw_fd(saved_stderr) };	1
pub unsafe fn dacl_mask_allows(	1
if queried != 0 || unsafe { GetLastError() } != ERROR_INSUFFICIENT_BUFFER {	1
None => unsafe { env::remove_var(name) },	1
unsafe { BorrowedSocket::borrow_raw(self.as_raw_socket()) }	2
Ok(unsafe { OwnedHandle::from_raw_handle(handle as RawHandle) })	2
unsafe { DeleteProcThreadAttributeList(self.as_mut_ptr()) };	1
let stderr_handle = unsafe { GetStdHandle(STD_ERROR_HANDLE) };	1
let assigned = unsafe {	1
let preserved_fd = unsafe { std::fs::File::from_raw_fd(fds[1]) };	1
unsafe { libc::ioctl(fd, libc::SIOCSIFFLAGS as libc::Ioctl, &ifreq) };	1
unsafe { v8__V8__IsSandboxEnabled() }	1
if unsafe { libc::pipe(pipe_fds.as_mut_ptr()) } == -1 {	1
Some(unsafe { CFURL::wrap_under_get_rule(value.as_CFTypeRef() as CFURLRef) })	1
let value = unsafe { CFString::wrap_under_create_rule(value_ref as _) }.to_string();	1
Ok(unsafe { File::from_raw_fd(duplicated) })	1
let watch = unsafe { libc::inotify_add_watch(fd, parent_cstr.as_ptr(), mask) };	1
let kq = unsafe { libc::kqueue() };	1
if peer_uid != unsafe { libc::getuid() } {	1
pub unsafe fn ensure_allow_mask_aces(	1
let dup_server_stream_fd = unsafe { libc::dup(server_stream_guard.as_raw_fd()) };	1
let result = unsafe { libc::killpg(pgid, signal) };	1
None => unsafe {	1
details.push(format!("console input code page: {}", unsafe {	1
let h = unsafe {	1
pub unsafe fn get_logon_sid_bytes(h_token: HANDLE) -> Result<Vec<u8>> {	1
cmsg = unsafe { libc::CMSG_NXTHDR(&hdr, cmsg) };	1
let result = unsafe { libc::tcflush(libc::STDIN_FILENO, libc::TCIFLUSH) };	1
let result = unsafe { GetNamedPipeServerProcessId(pipe_handle, &mut server_process_id) };	1
cf_string_value(proxy, unsafe { kCFProxyAutoConfigurationJavaScriptKey })	1
return Err(io::Error::from_raw_os_error(unsafe {	3
unsafe fn grant_desktop_access(handle: isize, logs_base_dir: Option<&Path>) -> Result<()> {	1
let spawn_res = unsafe {	1
let after_count = unsafe { buf.as_ptr().add(std::mem::size_of::<u32>()) } as usize;	1
let write_end = unsafe { std::fs::File::from_raw_fd(fds[1]) };	4
let res = unsafe { WaitForSingleObject(process, wait_ms) };	1
let status = unsafe {	2
let flags = unsafe { libc::fcntl(num, libc::F_GETFD) };	1
let sid_len = unsafe { GetLengthSid(psid) };	1
if unsafe { libc::flock(lock_file.as_raw_fd(), libc::LOCK_UN) } < 0 {	1
let nev = unsafe {	1
pub unsafe fn create_workspace_write_token_with_caps_and_user_from(	1
|| unsafe { libc::fcntl(fd, libc::F_SETFL, flags | libc::O_NONBLOCK) } < 0	1
let error = unsafe { GetLastError() };	1
pub unsafe fn convert_string_sid_to_sid(s: &str) -> Option<*mut c_void> {	1
let ret_code = unsafe { libc::prctl(libc::PR_SET_DUMPABLE, 0, 0, 0, 0) };	2
let process = unsafe { OwnedHandle::from_raw_handle(process as _) };	1
let stdout_handle = unsafe { GetStdHandle(STD_OUTPUT_HANDLE) };	1
let _ = unsafe { libc::close(kq) };	1
let err = unsafe { GetLastError() } as i32;	3
let descriptor_table_bytes = unsafe {	1
unsafe { std::ptr::write_volatile(byte, 0) };	1
details.push(console_mode_detail("stderr console mode", unsafe {	1
execute_pac(|callback, context| unsafe {	1
let ok = unsafe { ShellExecuteExW(&mut sei) };	1
if unsafe { GetConsoleMode(handle, &mut mode) } == 0 {	1
Some(value) => unsafe { env::set_var(name, value) },	1
let result = unsafe { libc::kill(pid, 0) };	3
let original_flags = unsafe { libc::fcntl(fd, libc::F_GETFL) };	1
let count = unsafe {	2
let result = unsafe {	1
let result = unsafe { FwpmProviderAdd0(engine, &provider, null_mut()) };	1
let mut read_file = unsafe { File::from_raw_fd(read_fd) };	1
unsafe impl Send for PsuedoCon {}	1
let eof = unsafe { termios.assume_init() }.c_cc[libc::VEOF];	1
Some(unsafe { CFURL::wrap_under_create_rule(url) })	1
pub unsafe fn add_deny_read_ace(path: &Path, psid: *mut c_void) -> Result<bool> {	1
let current_process = unsafe { GetCurrentProcess() };	1
let result = unsafe {	1
let ok = unsafe { ConvertStringSidToSidW(to_wide(s).as_ptr(), &mut psid) };	1
let saved_stderr = unsafe { libc::dup(libc::STDERR_FILENO) };	1
match unsafe { WaitForSingleObject(self.event.raw(), remaining_timeout_ms(deadline)) } {	1
if unsafe { libc::flock(lock_file.as_raw_fd(), libc::LOCK_EX) } < 0 {	1
let current_token = open_process_token(unsafe { GetCurrentProcess() })?;	1
unsafe fn ensure_inheritable_stdio(si: &mut STARTUPINFOW) -> Result<()> {	1
let level = unsafe { (*cmsg).cmsg_level };	1
if unsafe { ConvertStringSidToSidW(sid_w.as_ptr(), &mut psid) } == 0 {	1
if unsafe { libc::fcntl(libc::STDIN_FILENO, libc::F_GETFD) } < 0 {	1
if cf_string_equals(&proxy_type, unsafe { kCFProxyTypeAutoConfigurationURL }) {	1
unsafe { GetLastError() }	1
unsafe { CFRunLoopSourceInvalidate(source.as_concrete_TypeRef()) };	1
let result = unsafe { libc::killpg(pgid, libc::SIGKILL) };	1
let res = unsafe { libc::prctl(libc::PR_SET_PDEATHSIG, libc::SIGTERM) };	2
let passwd = unsafe { passwd.assume_init_ref() };	1
let status = unsafe { NtResumeProcess(process_handle.cast()) };	1
if unsafe { CloseHandle(self.handle) } == 0 {	1
let result = unsafe { libc::getpeereid(stream.as_raw_fd(), &mut peer_uid, &mut peer_gid) };	1
pub unsafe fn create_readonly_token_with_cap_from(	1
unsafe fn path_has_world_write_allow(path: &Path) -> Result<bool> {	1
let result = unsafe { libc::fcntl(fd, libc::F_SETFD, cleared_flags) };	1
unsafe extern "C" fn pac_result_callback(	1
unsafe { v8__V8__IsSandboxEnabled() },	1
let Some(pac_url) = cf_url_value(proxy, unsafe { kCFProxyAutoConfigurationURLKey }) else {	1
let flags = unsafe { libc::fcntl(fd, libc::F_GETFD) };	3
let thread_wait = unsafe { WaitForSingleObject(thread_handle, 0) };	1
let status = unsafe { (ntdll.RtlGetVersion)(&mut info) };	1
let read_end = unsafe { std::fs::File::from_raw_fd(fds[0]) };	3
let read = unsafe { libc::read(self.fd, buf.as_mut_ptr().cast(), buf.len()) };	1
Ok(unsafe { OwnedFd::from_raw_fd(relocated_fd) })	1
cf_string_equals(&proxy_type, unsafe { kCFProxyTypeNone })	1
let current_flags = unsafe { ifreq.ifr_ifru.ifru_flags };	1
Ok(unsafe { std::os::windows::io::OwnedHandle::from_raw_handle(handle.cast()) })	1
pub unsafe fn dacl_has_write_allow_for_sid(p_dacl: *mut ACL, psid: *mut c_void) -> bool {	1
if unsafe { libc::pipe2(pipe.as_mut_ptr(), libc::O_CLOEXEC) } < 0 {	1
let err = unsafe { GetLastError() };	5
if unsafe { GetNumberOfConsoleInputEvents(handle, &mut pending) } == 0 {	1
retain: Option<unsafe extern "C" fn(*mut c_void) -> *mut c_void>,	1
pub unsafe fn add_deny_write_ace(path: &Path, psid: *mut c_void) -> Result<bool> {	1
let terminated = unsafe {	2
let pipe_res = unsafe { libc::pipe2(pipe_fds.as_mut_ptr(), libc::O_CLOEXEC) };	1
if unsafe { PowerSetRequest(handle, request_type) } == 0 {	1
let uid = unsafe { libc::getuid() };	3
let source = unsafe { CFRunLoopSource::wrap_under_create_rule(source) };	1
unsafe impl async_io::IoSafe for WindowsUnixListener {}	1
if unsafe { GetVolumePathNameW(path.as_ptr(), volume.as_mut_ptr(), volume.len() as u32) } == 0 {	1
let result = unsafe { libc::setsid() };	1
pub unsafe fn get_current_token_for_restriction() -> Result<HANDLE> {	1
|| cf_string_equals(&proxy_type, unsafe {	1
let _ = unsafe { mlock(start as *const c_void, size) };	1
if unsafe { libc::close(target_fd) } == -1 {	1
unsafe { std::env::set_var("VISUAL", "editor") };	1
let group_count = unsafe { std::ptr::read_unaligned(buffer.as_ptr().cast::<u32>()) } as usize;	1
let fd = unsafe { data_ptr.add(i).read() };	1
if unsafe { libc::dup2(null_read_fd, libc::STDIN_FILENO) } < 0 {	1
unsafe fn scan_token_groups_for_logon(h: HANDLE) -> Option<Vec<u8>> {	1
let mut previous: libc::sigset_t = unsafe { std::mem::zeroed() };	1
let row_count = unsafe { std::ptr::read_unaligned(buffer.as_ptr().cast::<u32>()) } as usize;	1
unsafe fn create_token_with_caps_from(	1
let reaped_pid = unsafe { libc::waitpid(-1, &mut status, 0) };	1
let wait_res = unsafe { libc::waitpid(pid, &mut status as *mut libc::c_int, 0) };	1
pub(crate) unsafe fn get_user_sid_bytes(h_token: HANDLE) -> Result<Vec<u8>> {	1
let mut access: EXPLICIT_ACCESS_W = unsafe { zeroed() };	1
unsafe extern "C" {}	1
if unsafe { GetConsoleScreenBufferInfoEx(output, &mut info) } == 0 {	1
Ok(unsafe { std::fs::File::from_raw_handle(duplicated as _) })	1
let _ = unsafe { libc::close(kq) };	1
unsafe { libc::proc_pidpath(pid, buffer.as_mut_ptr().cast(), buffer.len() as u32) };	1
let process = unsafe { OpenProcess(PROCESS_DUP_HANDLE, 0, process_id) };	1
let saved_stderr = unsafe { OwnedFd::from_raw_fd(saved_stderr) };	1
Some(value) => unsafe {	1
let fd = unsafe { libc::inotify_init1(libc::IN_NONBLOCK | libc::IN_CLOEXEC) };	1
unsafe { data.set_len(bytes_required) };	1
let ok = unsafe {	1
let dup_socket_fd = unsafe { libc::dup(socket_fd) };	1
let flags = unsafe { libc::fcntl(descriptor, libc::F_GETFD) };	1
if unsafe { EqualSid(server_user.sid()?, current_user.sid()?) } == 0 {	1
let read_end = unsafe { std::os::fd::OwnedFd::from_raw_fd(pipe_fds[0]) };	1
unsafe fn setup_stdio_pipes() -> io::Result<PipeHandles> {	1
let res = unsafe {	3
let mut session: FWPM_SESSION0 = unsafe { zeroed() };	1
unsafe extern "C" {	3
let result = unsafe {	14
Anonymous: unsafe { zeroed() },	1
pub unsafe fn create_readonly_token_with_caps_and_user_from(	1
let result = unsafe { FwpmTransactionCommit0(self.engine.handle) };	1
pub unsafe fn add_allow_ace(path: &Path, psid: *mut c_void) -> Result<bool> {	1
let result = unsafe { WaitForSingleObject(process.as_raw_handle() as _, timeout_ms) };	1
unsafe { libc::waitpid(child_pid, std::ptr::null_mut(), libc::WNOHANG) };	1
let last_error = unsafe { GetLastError() };	1
unsafe extern "system" {	2
let process = unsafe {	1
pub unsafe fn ensure_allow_write_aces(path: &Path, sids: &[*mut c_void]) -> Result<bool> {	1
Ok(unsafe { OwnedHandle::from_raw_handle(handle as _) })	1
let counters = unsafe {	1
let code = unsafe { RtlNtStatusToDosError(status) };	1
&format!("capture failed to terminate root process: {}", unsafe {	1
let suggested_buffer_len = unsafe { libc::sysconf(libc::_SC_GETPW_R_SIZE_MAX) };	1
let data_ptr = unsafe { libc::CMSG_DATA(cmsg).cast::<RawFd>() };	1
|path, sid| unsafe { add_deny_write_ace(path, sid) },	1
if unsafe { GetNumberOfConsoleInputEvents(self.handle, &mut pending) } == 0 {	1
unsafe { GetLastError() }	1
pub unsafe fn protect_workspace_agents_dir(cwd: &Path, psid: *mut c_void) -> Result<bool> {	1
unsafe { CFEqual(value.as_CFTypeRef(), expected as CFTypeRef) != 0 }	1
pub unsafe fn apply_deny_read_acls(paths: &[PathBuf], psid: *mut c_void) -> Result<Vec<PathBuf>> {	1
unsafe { &*(buf as *const [MaybeUninit<T>; N] as *const [T; N]) }	1
let shell_path = unsafe { CStr::from_ptr(passwd.pw_shell) }	1
unsafe fn wide_ptr_to_string(ptr: PWSTR) -> String {	1
pub unsafe fn dacl_has_read_deny_for_sid(p_dacl: *mut ACL, psid: *mut c_void) -> bool {	1
anyhow::bail!("OpenDesktopW failed: {}", unsafe { GetLastError() });	1
let result = unsafe { libc::poll(&mut poll_fd, 1, remaining_timeout_ms(deadline)?) };	1
let page_size = u64::try_from(unsafe { libc::sysconf(libc::_SC_PAGESIZE) })	1
let handle = unsafe {	1
unsafe fn set_default_dacl(h_token: HANDLE, sids: &[*mut c_void]) -> Result<()> {	1
unsafe { libc::ioctl(fd, libc::SIOCGIFFLAGS as libc::Ioctl, &mut ifreq) };	1
let mut cmsg = unsafe { libc::CMSG_FIRSTHDR(&hdr) as *const libc::cmsghdr };	1
if unsafe { CFGetTypeID(value.as_CFTypeRef()) == CFURLGetTypeID() } {	1
unsafe { self.update(PROC_THREAD_ATTRIBUTE_HANDLE_LIST, value, size) }	1
let ok = unsafe { CopySid(sid_len, out.as_mut_ptr() as *mut std::ffi::c_void, psid) };	1
if unsafe { libc::dup2(devnull.as_raw_fd(), libc::STDERR_FILENO) } == -1 {	1
let res = unsafe { libc::kill(pid as libc::pid_t, 0) };	1
let wait_res = unsafe { WaitForSingleObject(pi.hProcess, timeout) };	1
original_fd: unsafe { std::os::fd::OwnedFd::from_raw_fd(original_fd) },	1
let ok = unsafe {	5
let result = unsafe { FwpmTransactionBegin0(self.handle, 0) };	1
Some(unsafe { ProxyArray::wrap_under_create_rule(proxies) })	1
unsafe { libc::_exit(1) };	1
pub unsafe fn from_raw_fd(fd: RawFd) -> std::io::Result<Self> {	1
let res = unsafe { libc::kevent(kq, &kev, 1, std::ptr::null_mut(), 0, std::ptr::null()) };	2
let string = unsafe { wide_ptr_to_string(self.0) };	1
let original_fd = unsafe { libc::dup(target_fd) };	1
let result = unsafe { libc::fcntl(fd, libc::F_SETFL, flags | libc::O_NONBLOCK) };	1
let rows = unsafe {	1
let server_stream_fd = unsafe { std::os::fd::OwnedFd::from_raw_fd(dup_server_stream_fd) };	1
pub unsafe fn allow_null_device(psid: *mut c_void) {	1
None => unsafe { std::env::remove_var("VISUAL") },	1
if unsafe { libc::fcntl(fd, libc::F_SETFL, original_flags | libc::O_NONBLOCK) } == -1 {	1
let ok = unsafe { InitializeProcThreadAttributeList(list, attr_count, 0, &mut size) };	1
let exit_code = unsafe { bwrap_main(cstrings.len() as libc::c_int, argv_ptrs.as_ptr()) };	1
let cancel_ok = unsafe { CancelSynchronousIo(thread_handle) };	1
let slice = unsafe { std::slice::from_raw_parts(ptr, len) };	1
unsafe extern "C" {	1
let groups = unsafe {	1
let mut si: STARTUPINFOW = unsafe { std::mem::zeroed() };	1
- unsafe { libc::CMSG_LEN(0) as usize };	1
let read = unsafe { libc::read(read_fd, byte.as_mut_ptr().cast(), byte.len()) };	1
[unsafe { std::mem::zeroed::<INPUT_RECORD>() }; WINDOWS_PROBE_READ_RECORDS];	1
let sandbox_sid = unsafe { get_user_sid_bytes(security.h_token)? };	1
if unsafe { libc::dup2(saved_stderr.as_raw_fd(), libc::STDERR_FILENO) } == -1 {	1
let psid = unsafe { convert_string_sid_to_sid(sid) }	1
let result = unsafe { OpenProcessToken(process, TOKEN_QUERY, &mut token) };	1
let value = unsafe {	1
let owner_user_sid = unsafe {	1
let res = unsafe { GetExitCodeProcess(proc.as_raw_handle() as _, &mut status) };	2
if unsafe { GetConsoleMode(handle, &mut mode) } == 0 {	2
Self::new(unsafe { Socket::from_raw_fd(fd) })	1
let res = unsafe { WaitForSingleObject(process, timeout) };	1
if unsafe { PowerClearRequest(self.handle, self.request_type) } == 0 {	1
Ok(unsafe { std::os::unix::net::UnixStream::from_raw_fd(fd.into_raw_fd()) })	1
release: Option<unsafe extern "C" fn(*mut c_void)>,	1
let hr = unsafe {	1
let rc = unsafe { libc::kill(pid, 0) };	1
let handle = unsafe { OpenProcess(PROCESS_QUERY_LIMITED_INFORMATION, 0, pid) };	1
let _ = unsafe { libc::kill(bg_pid, libc::SIGKILL) };	1
let result = unsafe { libc::ioctl(raw_fd, libc::TIOCSWINSZ, &mut winsize) };	1
copy_description: Option<unsafe extern "C" fn(*mut c_void) -> CFStringRef>,	1
let err = unsafe {	1
} else if unsafe { libc::getppid() } != expected_parent_pid {	1
None => unsafe { env::remove_var(self.name) },	1
assert_ne!(unsafe { libc::fcntl(original_fd, libc::F_GETFD) }, -1);	1
let ok = unsafe { GetNamedPipeClientProcessId(h, &mut client_pid) };	1
match unsafe { path_has_world_write_allow(path) } {	1
let set_addr_result = unsafe { libc::ioctl(fd, libc::SIOCSIFADDR as libc::Ioctl, &addr_req) };	1
let path = unsafe {	1
let setpgid_res = unsafe { libc::setpgid(0, 0) };	1
match unsafe {	1
execute_pac(|callback, context| unsafe {	1
} else if cf_string_equals(&proxy_type, unsafe { kCFProxyTypeHTTP })	1
pub unsafe fn fetch_dacl_handle(path: &Path) -> Result<(*mut ACL, *mut c_void)> {	1
let status = unsafe {	2
let proxies = unsafe {	1
let result = unsafe { FlushConsoleInputBuffer(handle) };	1
let file = unsafe { File::from_raw_fd(descriptor) };	1
let mut overlapped = unsafe { std::mem::zeroed::<OVERLAPPED>() };	1
let ok = unsafe { ConnectNamedPipe(h, ptr::null_mut()) };	1
assert_ne!(unsafe { libc::fcntl(socket_fd, libc::F_GETFD) }, -1);	1
Some(unsafe { (*(buffer as *const USER_INFO_23)).usri23_flags })	1
let result = unsafe { libc::pipe(fds.as_mut_ptr()) };	5
let mut info = unsafe { std::mem::zeroed::<CONSOLE_SCREEN_BUFFER_INFOEX>() };	1
let mut credentials = unsafe { std::mem::zeroed::<libc::ucred>() };	1
let root_result = unsafe {	1
unsafe fn add_deny_ace(path: &Path, psid: *mut c_void, kind: DenyAceKind) -> Result<bool> {	1
Some(value) => unsafe { env::set_var(self.name, value) },	1
let fd = unsafe { BorrowedFd::borrow_raw(master_fd) }.try_clone_to_owned()?;	1
let stats = unsafe { stats.assume_init() };	1
let proc = unsafe { OwnedHandle::from_raw_handle(pi.hProcess as _) };	1
let _ = unsafe { libc::kill(child_pid, libc::SIGKILL) };	1
let Some(proxy_type) = cf_string_value(proxy, unsafe { kCFProxyTypeKey }) else {	1
unsafe { libc::fcntl(self.reader.as_raw_fd(), libc::F_SETFL, self.original_flags) };	1
let mut hdr: libc::msghdr = unsafe { std::mem::zeroed() };	1
let ret_code = unsafe { libc::ptrace(libc::PT_DENY_ATTACH, 0, std::ptr::null_mut(), 0) };	1
let result = unsafe { libc::prctl(libc::PR_SET_NO_NEW_PRIVS, 1, 0, 0, 0) };	1
let mut write_end = unsafe { std::fs::File::from_raw_fd(pipe_fds[1]) };	1
unsafe {	41
let handle = unsafe { CreateJobObjectW(std::ptr::null_mut(), std::ptr::null()) };	1
let _main_thread = unsafe { OwnedHandle::from_raw_handle(pi.hThread as _) };	1
let flags = unsafe { libc::fcntl(fd, libc::F_GETFL) };	1
unsafe fn create_token_with_caps_user_and_additional_restrictions_from(	1
let command_pid = unsafe { libc::fork() };	1
unsafe { std::env::remove_var(REMOTE_CONTROL_DISABLED_ENV_VAR) };	1
let pid = unsafe { libc::fork() };	3
let page_size = unsafe { sysconf(_SC_PAGESIZE) };	1
unsafe { GetLastError() }	2
let mut si: STARTUPINFOEXW = unsafe { std::mem::zeroed() };	1
let relocated_fd = unsafe {	1
unsafe impl Sync for PsuedoCon {}	1
if unsafe { libc::dup2(source_fd, stream_fd) } < 0 {	2
if unsafe { libc::kill(pid, signal) } == -1 {	1
if unsafe {	5
unsafe { self.update(PROC_THREAD_ATTRIBUTE_JOB_LIST, value, size) }	2
if unsafe { ConvertSidToStringSidW(sid, &mut string_sid) } == 0 {	1
let process = unsafe { OwnedHandle::from_raw_handle(handle as _) };	1
let parent_sid = unsafe { libc::getsid(0) };	1
return Err(anyhow!("CryptUnprotectData failed: {}", unsafe {	1
unsafe { (CONPTY.ClosePseudoConsole)(self.con) };	1
let process = unsafe { OwnedHandle::from_raw_handle(process.cast()) };	1
let duplicate_ok = unsafe {	1
details.push(format!("console output code page: {}", unsafe {	1
details.push(console_mode_detail("stdout console mode", unsafe {	1
let bytes = unsafe {	1
let flags = unsafe { libc::fcntl(fd, libc::F_GETFL) };	1
if cf_string_equals(&proxy_type, unsafe { kCFProxyTypeNone }) {	1
if cf_string_equals(&proxy_type, unsafe { kCFProxyTypeSOCKS }) {	1
unsafe { libc::CMSG_SPACE((count * size_of::<RawFd>()) as _) as usize }	1
let current_group_id = unsafe { libc::getpgid(process_id) };	1
let handle = unsafe { PowerCreateRequest(&context) };	1
pub unsafe fn create_process_as_user(	1
let pgid = unsafe { libc::getpgid(pid) };	1
let effective_uid = unsafe { libc::geteuid() };	1
unsafe { libc::waitpid(raw_pid, std::ptr::null_mut(), libc::WNOHANG) };	1
match unsafe { GetDriveTypeW(volume.as_ptr()) } {	1
