pub enum KernelRequest {
Show 20 variants
BeginCapsuleInstallBatch {
target_principal: Option<PrincipalId>,
members: Vec<CapsuleInstallBatchMember>,
},
InstallCapsule {
source: String,
workspace: bool,
target_principal: Option<PrincipalId>,
provenance: Option<CapsuleInstallProvenance>,
authority: CapsuleInstallAuthority,
env: Vec<CapsuleInstallEnv>,
expected_generation: Option<InstalledCapsuleGeneration>,
batch: Option<CapsuleInstallBatchContext>,
},
FinishCapsuleInstallBatch {
batch_id: CapsuleInstallBatchId,
target_principal: Option<PrincipalId>,
},
GetInstalledCapsuleIdentity {
id: String,
},
GetCapsuleInstallResumeReceipt {
id: String,
},
PutCapsuleInstallResumeReceipt {
receipt: CapsuleInstallResumeReceipt,
},
ApproveCapability {
request_id: String,
signature: String,
},
ListCapsules,
ReloadCapsules,
ReloadCapsule {
id: String,
},
UnloadCapsule {
id: String,
},
RemoveCapsule {
id: String,
force: bool,
purge: bool,
},
PromoteWorkspace {
id: String,
},
RollbackWorkspace {
id: String,
},
GetCommands,
GetCapsuleMetadata,
GetCapsuleMetadataForPrincipal {
target_principal: PrincipalId,
},
Shutdown {
reason: Option<String>,
},
GetStatus,
GetAgentReadiness,
}Expand description
Management API requests directed at the core daemon.
Variants§
BeginCapsuleInstallBatch
Open a short lease for an exact set of local capsule archives.
Fields
target_principal: Option<PrincipalId>Optional durable principal target. Absent means the caller.
members: Vec<CapsuleInstallBatchMember>Fixed capsule identities admitted by this lease.
InstallCapsule
Request to install a capsule from a local or remote path.
Fields
target_principal: Option<PrincipalId>Optional durable principal target. Absent means the caller; selecting another requires the global capsule-install capability.
provenance: Option<CapsuleInstallProvenance>Bounded distro/source provenance; never widens install authority.
Authenticated one-install authority decision. The kernel binds it to the source digest it computes before publication.
env: Vec<CapsuleInstallEnv>Typed owner-scoped values staged by the daemon before lifecycle. Values are redacted from audit payloads and are bounded by the kernel’s environment limits.
expected_generation: Option<InstalledCapsuleGeneration>Observed package generation; filtered refresh fail-closes on mismatch.
batch: Option<CapsuleInstallBatchContext>Optional bounded request-frequency lease; never grants authority.
FinishCapsuleInstallBatch
Close a batch after every declared member is durably complete.
Fields
batch_id: CapsuleInstallBatchIdKernel-issued lease identifier.
target_principal: Option<PrincipalId>Optional lease target; absent means the caller.
GetInstalledCapsuleIdentity
Read the authenticated caller’s complete durable package identity.
The kernel resolves the owner from the authenticated request context; this request never accepts a principal or target selector.
GetCapsuleInstallResumeReceipt
Read the authenticated caller’s durable capsule-install resume receipt.
PutCapsuleInstallResumeReceipt
Replace the authenticated caller’s durable capsule-install resume receipt.
Fields
receipt: CapsuleInstallResumeReceiptComplete receipt to store under its capsule identifier.
ApproveCapability
Request to approve a capability grant (usually following an ApprovalNeeded response).
Fields
ListCapsules
Request the list of currently loaded capsules.
ReloadCapsules
Reload all capsules from the file system.
ReloadCapsule
Reload a single capsule by id without a daemon restart: hot-swap it if
already loaded (picking up the new on-disk bytes a reinstall wrote), or
load it if not yet registered. Lets a fresh astrid capsule install /
update make the capsule usable without restarting the daemon.
UnloadCapsule
Unload a single capsule by id without a daemon restart: unregister it
from the running daemon so it stops receiving events and its tools leave
the surface. Lets a fresh astrid capsule remove take effect live. The
on-disk removal is authoritative and dependency-checked by the CLI; this
only mirrors that into the running registry.
RemoveCapsule
Remove one capsule package from the authenticated owner’s durable registry and unload its live runtime. The daemon is the sole writer; clients never delete install paths directly.
Fields
PromoteWorkspace
Promote a capsule’s OS-level copy-on-write workspace changes into the
pristine workspace — the gate’s “approve” (Fix #2). For a non-git
workspace, capsule writes and spawned-process output land in a
copy-on-write merged tree; this commits them to the real workspace. A
no-op (not_applicable) for a git-managed or No-CoW workspace.
RollbackWorkspace
Discard a capsule’s OS-level copy-on-write workspace changes — the
gate’s “reject” (Fix #2). Restores the merged tree to the pristine
contents. A no-op (not_applicable) for a git-managed or No-CoW
workspace.
GetCommands
Request the list of globally registered slash commands.
GetCapsuleMetadata
Request metadata about loaded capsules (manifests, providers, interceptors).
The kernel’s equivalent of /proc — exposing process table info.
GetCapsuleMetadataForPrincipal
Request metadata for one explicitly selected principal.
Selecting another principal requires global capsule:list authority;
the authenticated caller remains the audited actor.
Fields
target_principal: PrincipalIdPrincipal whose durable and live capsule registry is inspected.
Shutdown
Request the daemon to shut down gracefully.
GetStatus
Request daemon status information.
GetAgentReadiness
Request agent-loop readiness: whether the loaded capsule set can serve
an agent chat turn. Read-only, name-agnostic — see AgentLoopReadiness.
Trait Implementations§
Source§impl Clone for KernelRequest
impl Clone for KernelRequest
Source§fn clone(&self) -> KernelRequest
fn clone(&self) -> KernelRequest
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read more