pub struct CapabilityGrant {
pub fs: Vec<FsGrant>,
pub net_http: Vec<String>,
pub proc_spawn: bool,
pub state_write: bool,
pub grammar_chord: bool,
pub editor: CapabilitySet,
}Expand description
The effective capabilities a plugin is granted — the request filtered by its trust tier. This, not the manifest, is what the runtime enforces.
Fields§
§fs: Vec<FsGrant>Granted filesystem prefixes (enforced via WASI preopens).
net_http: Vec<String>Granted outbound-HTTP host allowlist (enforced at the host-services http seam, PH7.3+, not the WASI layer — see the module note).
proc_spawn: boolWhether the plugin may spawn subprocesses (enforced at the host-services proc seam, PH7.3+).
state_write: boolOR.1: whether the plugin may persist bytes in its own key/value store
(enforced at the host-services store-* seam — the store lives in the
plugin’s private data dir, which WASI already mounts, so this gate is
host-side like net:http rather than a preopen).
grammar_chord: boolCM.2: whether the plugin may bind an operator chord into the universal operator-pending grammar. Enforced at the loader’s grammar drain — a declared chord is skipped (and logged) without this, while the operator itself still registers and stays reachable by name.
editor: CapabilitySetThe editor capabilities a plugin-declared mode requires (enforced at mode activation, PH7.11).
Implementations§
Source§impl CapabilityGrant
impl CapabilityGrant
Sourcepub fn preopens(&self, data_dir: &Path) -> Vec<PreopenSpec>
pub fn preopens(&self, data_dir: &Path) -> Vec<PreopenSpec>
The full set of directory preopens for a plugin whose private data dir
is data_dir. The data dir is always mounted writable at
DATA_DIR_GUEST_MOUNT; each fs grant adds a preopen at a guest path
equal to its host path (so the guest opens the same absolute path it was
granted). A plugin with no fs grant reaches only its data dir.
The guest-path convention (fs prefix mounted at its own host path) is
provisional until fuzzy-finder exercises it (PH7.4, open question in
fragment §13).
Trait Implementations§
Source§impl Clone for CapabilityGrant
impl Clone for CapabilityGrant
Source§fn clone(&self) -> CapabilityGrant
fn clone(&self) -> CapabilityGrant
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreSource§impl Debug for CapabilityGrant
impl Debug for CapabilityGrant
Source§impl Default for CapabilityGrant
impl Default for CapabilityGrant
Source§fn default() -> CapabilityGrant
fn default() -> CapabilityGrant
impl Eq for CapabilityGrant
Source§impl PartialEq for CapabilityGrant
impl PartialEq for CapabilityGrant
impl StructuralPartialEq for CapabilityGrant
Auto Trait Implementations§
impl Freeze for CapabilityGrant
impl RefUnwindSafe for CapabilityGrant
impl Send for CapabilityGrant
impl Sync for CapabilityGrant
impl Unpin for CapabilityGrant
impl UnsafeUnpin for CapabilityGrant
impl UnwindSafe for CapabilityGrant
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
key and return true if they are equal.§impl<T> Instrument for T
impl<T> Instrument for T
§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more