pub enum Capability {
FsRead(PathBuf),
FsWrite(PathBuf),
NetHttp(String),
ProcSpawn,
StateWrite,
GrammarChord,
}Expand description
An OS-level capability a plugin requests in its manifest. Distinct from
CapabilitySet (editor/buffer capabilities); these gate the plugin’s
WASI view (filesystem / network / process).
Wire form (manifest + [Display]): fs:read:<prefix>, fs:write:<prefix>,
net:http:<host>, proc:spawn, state:write. The <prefix> may itself
contain : (paths, host:port); only the first two segments are the
discriminator.
Variants§
FsRead(PathBuf)
Read access to a host path prefix (fs:read:<prefix>).
FsWrite(PathBuf)
Read + write access to a host path prefix (fs:write:<prefix>).
NetHttp(String)
Outbound HTTP to one host-allowlist entry (net:http:<host>).
ProcSpawn
Permission to spawn subprocesses (proc:spawn). Bundled-only in v1
(dropped from a user-installed plugin’s grant — fragment §6).
StateWrite
OR.1: permission to persist bytes in the plugin’s own key/value store
(state:write, the host-services store-* calls).
Its own capability rather than a corollary of fs:write, because the
two answer different questions. fs:write:<prefix> is reach — which
of the user’s files a plugin may alter — and a plugin that persists an
index needs none of that. Folding the store into fs:write would make
“remember something between restarts” require a grant over the user’s
documents, which is the wrong trade in the direction that matters.
GrammarChord
CM.2: permission to bind an operator’s chord into the universal
operator-pending grammar (gc{motion}, gcc, Visual gc).
A capability rather than a free contribution because it is the most
user-visible power a plugin can take: it claims keys in the grammar
every buffer shares, and a chord the user did not expect is worse than
a feature they did not get. Declaring it puts the claim in
plugin.toml, in the grant :plugins displays, and in the denial list
when a tier withholds it.
Granted at BOTH tiers, unlike proc:spawn. The chord lands in the
plugin’s own MinorMode layer rather than Builtin, it is visible in
:plugins, and unload reverses it by provenance — so the blast radius
is the plugin’s own modes. Withholding it from user-installed plugins
would make contributing an operator a bundled-only feature, which is
precisely the “adding new operators is first-class” claim (paramount
#3) that the plugin API exists to honour.
Withheld is NOT a load failure: the operator still registers and stays
reachable by name. A plugin never silently mis-binds
(register-binding’s contract), and a refused chord is a decision
rather than a broken wire.
Trait Implementations§
Source§impl Clone for Capability
impl Clone for Capability
Source§fn clone(&self) -> Capability
fn clone(&self) -> Capability
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreSource§impl Debug for Capability
impl Debug for Capability
Source§impl Display for Capability
impl Display for Capability
impl Eq for Capability
Source§impl FromStr for Capability
impl FromStr for Capability
Source§impl PartialEq for Capability
impl PartialEq for Capability
impl StructuralPartialEq for Capability
Auto Trait Implementations§
impl Freeze for Capability
impl RefUnwindSafe for Capability
impl Send for Capability
impl Sync for Capability
impl Unpin for Capability
impl UnsafeUnpin for Capability
impl UnwindSafe for Capability
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
key and return true if they are equal.§impl<T> Instrument for T
impl<T> Instrument for T
§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more