pub struct Runtime { /* private fields */ }Expand description
Deterministic runtime that invokes only registered trusted capabilities.
Implementations§
Source§impl Runtime
impl Runtime
Sourcepub fn new(registry: CapabilityRegistry) -> Self
pub fn new(registry: CapabilityRegistry) -> Self
Creates a runtime from a host-controlled registry.
Sourcepub fn with_rule_summaries(self) -> Self
pub fn with_rule_summaries(self) -> Self
Reports per-rule counts and status (Report::rules): how many
objects each rule surely selected, how many it found or left not
evaluated, and whether it passed, failed, was not evaluated or
selected nothing. Off by default, and then reports are unchanged.
Needs the registry’s outcome refiner to count selections.
Sourcepub fn with_locations(self, policy: LocationPolicy) -> Self
pub fn with_locations(self, policy: LocationPolicy) -> Self
Locates every finding and not-evaluated outcome by storey and space
as policy says. Off by default, and then reports carry no
location. Needs the registry’s outcome refiner.
Sourcepub fn with_services(self, services: ServiceRegistry) -> Self
pub fn with_services(self, services: ServiceRegistry) -> Self
Adds adapter-provided host services to subsequent evaluations.
Sourcepub fn run(
&self,
project: &Project,
plan: ExecutionPlan,
) -> Result<Report, EngineError>
pub fn run( &self, project: &Project, plan: ExecutionPlan, ) -> Result<Report, EngineError>
Executes a plan and returns deterministically sorted findings.
Execution fails closed if the host registry no longer contains any capability that was present when the plan was compiled.
A bare project carries no source type-system declarations, so package
concepts bind to nothing and concept-based selection is reported as not
evaluated. Hosts that want concept binding run an EvidenceSession.
Sourcepub fn run_session(
&self,
session: &EvidenceSession,
plan: ExecutionPlan,
) -> Result<Report, EngineError>
pub fn run_session( &self, session: &EvidenceSession, plan: ExecutionPlan, ) -> Result<Report, EngineError>
Executes a plan against one immutable source/evidence snapshot.