Expand description
A canonical, validated Candid Contract graph.
This crate deliberately delegates DID parsing and semantic checking to the
official candid_parser engine. It projects the checked result into a
host-neutral JSON model; it does not implement a second Candid parser or
codec.
§Feature surfaces
One package, four build surfaces. Every feature is enabled by default, so
an existing candid-core = "0.1" dependency is unchanged.
| Feature | Adds | Dependencies it pulls in |
|---|---|---|
(base) default-features = false | Contract, ContractDraft, RawContract, validation, canonicalization, the semantic Contract identities, detached artifact_id_with_limits, Limits/RuntimeContext, Diagnostic, ContractEnvelope | serde, serde_json, sha2, hex |
host-value | HostValue and graph-directed value validation | ic_principal |
compiler | compile_did, compile_with_resolver, Compilation, SourceId/SourceResolver/MemoryResolver, SourceInfo provenance | candid, candid_parser |
filesystem-compiler (implies compiler) | WorkspaceResolver, compile_did_file, source materialization, the candid-core binary | cap-std |
Items outside the enabled set are absent at compile time rather than present as failing stubs, so a build error names the feature to turn on.
§Targets
The compiler surface — self-contained sources through compile_did and
imported logical bundles through compile_with_resolver — needs no
filesystem and builds and runs on wasm32-unknown-unknown, which is where
browser WASM lands. filesystem-compiler items still compile there (the
cap-std capability is target-conditional), but WorkspaceResolver has no
directory to open on that target and its construction fails.
Bare wasm32-unknown-unknown has no clock. Cancellation and every
quantitative limit in Limits behave exactly as they do natively; an
explicit Limits::deadline_unix_ms cannot be measured there and therefore
fails closed with operation_deadline_exceeded instead of calling an
unsupported clock. No deadline configured stays unbounded, as it is
everywhere else. The crate takes no browser clock dependency to change
that.
Cargo unifies features across a dependency graph: if anything in a build
also depends on candid-core with defaults, the whole surface is compiled
once for every consumer in that build. Feature selection bounds what a
given dependency graph must contain, not what a mixed graph produces.
Structs§
- Cancellation
Token - A cheap, cloneable signal for cooperatively cancelling runtime work.
- Compilation
- Compile
Error - The compiler’s failure collection.
- Compile
Options - Contract
- The wire-semantics Contract consumed by host runtimes.
- Contract
Draft - A producer-side Contract draft: the parts an authoring tool supplies, and nothing it must not.
- Contract
Envelope - A strict semantic Contract plus namespaced, non-semantic ecosystem metadata.
- Contract
Identities - Contract
Method Ref - Contract
Type Ref - Contract
Validation Error - Declaration
- Diagnostic
- The one serializable failure item shared by every domain in this crate.
- Field
- Field
Label Provenance - Host
Field Value - One field of a
HostValuerecord, addressed by its authoritative Candid field ID. - Host
Value - A locally canonical tagged HostValue.
- Host
Value Validation Error - Limits
- Operational limits for work performed on untrusted Contracts, sources, and values.
- Limits
Config - The versioned, portable wire form of
Limits. - Limits
Config Error - A structured, stable rejection of a portable limits configuration.
- Memory
Resolver - Producer
Info - Untrusted, caller-supplied provenance about the tool that produced a Contract.
- RawContract
- Unvalidated Contract data decoded from an external artifact.
- RawSource
Info - Unvalidated source/provenance data.
- Related
Location - A secondary location attached to a
Diagnostic, in the order the underlying tool reported it after the primary location. - Resolve
Error - Resolved
Source - Resource
Limit Info - The
{resource, limit, observed}triple attached to everyresource_limit_exceededfailure. - Runtime
Context - Runtime policy and cooperative controls for one public operation.
- Service
Method - Source
Actor Info - Source
Declaration - Source
File Info - Source
Function Argument Info - Source
Id - Source
Import Info - Source
Info - Optional source/provenance data returned alongside, but never embedded in, the canonical Contract. It has no effect on Contract or interface identity.
- Source
Method Info - Source
Span - A logical source location.
- Workspace
Resolver - A resolver rooted at one explicitly authorized native directory.
Enums§
- Actor
- Artifact
Kind - The kind of serialized artifact an identity is computed over.
- Contract
Json Error - Diagnostic
Phase - Host
Value Json Error - Limits
Profile - A named, versioned set of default operational limit values.
- Method
Mode - Primitive
Type - Severity
- Source
Function Argument Direction - Source
Import Kind - Source
Label - Source spelling is intentionally separate from the semantic field ID.
positionaldifferentiates tuple syntax from an explicitly numeric label. - Source
Origin - Type
Node
Constants§
- CANONICALIZATION_
PROFILE - CONTRACT_
FORMAT - FORMAT_
VERSION - LIMITS_
CONFIG_ VERSION - The version of the portable limits configuration schema this build reads
and writes. See
LimitsConfig. - SEMANTICS_
PROFILE - SOURCE_
INFO_ VERSION
Traits§
Functions§
- artifact_
id_ with_ context artifact_id_with_limitsunder a fullRuntimeContext, so a caller’sCancellationTokenand deadline are observed while hashing.- artifact_
id_ with_ limits - Compute the detached artifact identity of
bytesunder caller-supplied limits. - compile_
did - compile_
did_ file - Compile a DID file through
candid_parser::check_file, including its official filesystem import-resolution path. - compile_
did_ file_ with_ context - compile_
did_ file_ with_ options - compile_
did_ with_ context - compile_
did_ with_ options - compile_
with_ resolver - Compile an immutable logical source bundle with no filesystem access.
- validate_
host_ value - validate_
host_ value_ with_ context
Type Aliases§
- Contract
Violation - Compatibility name for the shared diagnostic item in the Contract validation domain.
- Host
Value Violation - Compatibility name for the shared diagnostic item in the HostValue validation domain.
- TypeRef