pub struct Registry {
pub warnings: Vec<String>,
/* private fields */
}Expand description
The registry.
Fields§
§warnings: Vec<String>Non-fatal findings from the build (collisions, missing profile tools).
Implementations§
Source§impl Registry
impl Registry
Sourcepub fn build(
settings: &Settings,
servers: &[ServerTools],
) -> Result<Registry, Vec<String>>
pub fn build( settings: &Settings, servers: &[ServerTools], ) -> Result<Registry, Vec<String>>
Build from settings and the connected servers’ tool lists.
Every override is resolved here, at startup, so a misconfiguration fails to boot rather than failing on the call that needed the tool. The errors returned are: an override naming an unknown internal tool, a server that is not declared, a tool the server does not advertise, a mapping expression that does not compile, a tool that is both disabled and overridden, and disabling a tool that does not exist.
Sourcepub fn register_workflow_tools(
&mut self,
workflows: &[&Workflow],
) -> Vec<String>
pub fn register_workflow_tools( &mut self, workflows: &[&Workflow], ) -> Vec<String>
Register every workflow carrying a tool: block as a first-class
contract. Called ONCE, after the startup workflow load.
Startup-only is the whole safety argument. The registry is otherwise
built once from settings plus connected servers and validated
fail-closed; workflow tools would make it a mutable index if the model
could add to it, and workflow.create is root-callable — a root turn
could mint itself a new tool name, or shadow one, with no operator in
the loop. So workflow.create/update refuse a tool: block, and
this is the only door.
Tags are DERIVED, never declared. A workflow author writing
tags: [sensitive, egress] would make the one static instance-wide
security gate something the agent-editable half of the config asserts
about itself; instead a workflow tool inherits the union of the tags of
the tools its steps actually reach, so the trifecta fold sees the truth
about what the procedure can do.
pub fn get(&self, name: &str) -> Option<&ToolSpec>
pub fn names(&self) -> Vec<String>
pub fn servers(&self) -> &[String]
pub fn len(&self) -> usize
pub fn is_empty(&self) -> bool
pub fn iter(&self) -> impl Iterator<Item = &ToolSpec>
Sourcepub fn allowed(&self, caller: &Caller<'_>, name: &str) -> bool
pub fn allowed(&self, caller: &Caller<'_>, name: &str) -> bool
Whether caller may call name.
Fails closed at every step: an unknown tool, or one that is disabled or
still unmapped, is refused before any grant is consulted; an anonymous
A2A principal is refused outright; and a subagent carrying an explicit
allow list is held to it alone, so narrowing a child can only ever
remove reach, never restore it through a default.
Sourcepub fn defs_for(
&self,
caller: &Caller<'_>,
select: Option<&AgentTools>,
) -> Vec<ToolDef>
pub fn defs_for( &self, caller: &Caller<'_>, select: Option<&AgentTools>, ) -> Vec<ToolDef>
The LLM-facing definitions for a caller, filtered by the agent’s tool
selection (agent.tools.internal|mcp|code) when given.
Sourcepub fn validate_args(&self, name: &str, args: &Value) -> Result<(), String>
pub fn validate_args(&self, name: &str, args: &Value) -> Result<(), String>
Validate call arguments against the tool’s input schema.
Sourcepub fn validate_result(&self, name: &str, result: &Value) -> Result<(), String>
pub fn validate_result(&self, name: &str, result: &Value) -> Result<(), String>
Validate a result against the tool’s output schema (when it has one).
Sourcepub fn route(&self, name: &str) -> Option<Route<'_>>
pub fn route(&self, name: &str) -> Option<Route<'_>>
Where a call goes (None = unknown or unavailable).
Sourcepub fn map_args(m: &Mapping, args: &Value, ctx: &Value) -> Result<Value, String>
pub fn map_args(m: &Mapping, args: &Value, ctx: &Value) -> Result<Value, String>
Render a mapped tool’s MCP arguments from the internal call’s args
and the call context ({instance, run?, ctx?, principal?}). Without an
args template the internal args pass through unchanged.
Sourcepub fn map_result(m: &Mapping, result_ctx: &Value) -> Result<Value, String>
pub fn map_result(m: &Mapping, result_ctx: &Value) -> Result<Value, String>
Map an MCP CallToolResult (as the {"result": …} context the store
adapter also uses) back to the internal output. Without a result
template: structuredContent, else the text parsed as JSON, else the text.
The trifecta tags a set of tool names carries (for the gate).