Skip to main content

Crate candid_core

Crate candid_core 

Source
Expand description

A canonical, validated Candid Contract graph.

This crate deliberately delegates DID parsing and semantic checking to the official candid_parser engine. It projects the checked result into a host-neutral JSON model; it does not implement a second Candid parser or codec.

§Feature surfaces

One package, four build surfaces. Every feature is enabled by default, so an existing candid-core = "0.1" dependency is unchanged.

FeatureAddsDependencies it pulls in
(base) default-features = falseContract, ContractDraft, RawContract, validation, canonicalization, the semantic Contract identities, detached artifact_id_with_limits, Limits/RuntimeContext, Diagnostic, ContractEnvelopeserde, serde_json, sha2, hex
host-valueHostValue and graph-directed value validationic_principal
compilercompile_did, compile_with_resolver, Compilation, SourceId/SourceResolver/MemoryResolver, SourceInfo provenancecandid, candid_parser
filesystem-compiler (implies compiler)WorkspaceResolver, compile_did_file, source materialization, the candid-core binarycap-std

Items outside the enabled set are absent at compile time rather than present as failing stubs, so a build error names the feature to turn on.

§Targets

The compiler surface — self-contained sources through compile_did and imported logical bundles through compile_with_resolver — needs no filesystem and builds and runs on wasm32-unknown-unknown, which is where browser WASM lands. filesystem-compiler items still compile there (the cap-std capability is target-conditional), but WorkspaceResolver has no directory to open on that target and its construction fails.

Bare wasm32-unknown-unknown has no clock. Cancellation and every quantitative limit in Limits behave exactly as they do natively; an explicit Limits::deadline_unix_ms cannot be measured there and therefore fails closed with operation_deadline_exceeded instead of calling an unsupported clock. No deadline configured stays unbounded, as it is everywhere else. The crate takes no browser clock dependency to change that.

Cargo unifies features across a dependency graph: if anything in a build also depends on candid-core with defaults, the whole surface is compiled once for every consumer in that build. Feature selection bounds what a given dependency graph must contain, not what a mixed graph produces.

Structs§

CancellationToken
A cheap, cloneable signal for cooperatively cancelling runtime work.
Compilation
CompileError
The compiler’s failure collection.
CompileOptions
Contract
The wire-semantics Contract consumed by host runtimes.
ContractDraft
A producer-side Contract draft: the parts an authoring tool supplies, and nothing it must not.
ContractEnvelope
A strict semantic Contract plus namespaced, non-semantic ecosystem metadata.
ContractIdentities
ContractMethodRef
ContractTypeRef
ContractValidationError
Declaration
Diagnostic
The one serializable failure item shared by every domain in this crate.
Field
FieldLabelProvenance
HostFieldValue
One field of a HostValue record, addressed by its authoritative Candid field ID.
HostValue
A locally canonical tagged HostValue.
HostValueValidationError
Limits
Operational limits for work performed on untrusted Contracts, sources, and values.
LimitsConfig
The versioned, portable wire form of Limits.
LimitsConfigError
A structured, stable rejection of a portable limits configuration.
MemoryResolver
ProducerInfo
Untrusted, caller-supplied provenance about the tool that produced a Contract.
RawContract
Unvalidated Contract data decoded from an external artifact.
RawSourceInfo
Unvalidated source/provenance data.
RelatedLocation
A secondary location attached to a Diagnostic, in the order the underlying tool reported it after the primary location.
ResolveError
ResolvedSource
ResourceLimitInfo
The {resource, limit, observed} triple attached to every resource_limit_exceeded failure.
RuntimeContext
Runtime policy and cooperative controls for one public operation.
ServiceMethod
SourceActorInfo
SourceDeclaration
SourceFileInfo
SourceFunctionArgumentInfo
SourceId
SourceImportInfo
SourceInfo
Optional source/provenance data returned alongside, but never embedded in, the canonical Contract. It has no effect on Contract or interface identity.
SourceMethodInfo
SourceSpan
A logical source location.
WorkspaceResolver
A resolver rooted at one explicitly authorized native directory.

Enums§

Actor
ArtifactKind
The kind of serialized artifact an identity is computed over.
ContractJsonError
DiagnosticPhase
HostValueJsonError
LimitsProfile
A named, versioned set of default operational limit values.
MethodMode
PrimitiveType
Severity
SourceFunctionArgumentDirection
SourceImportKind
SourceLabel
Source spelling is intentionally separate from the semantic field ID. positional differentiates tuple syntax from an explicitly numeric label.
SourceOrigin
TypeNode

Constants§

CANONICALIZATION_PROFILE
CONTRACT_FORMAT
FORMAT_VERSION
LIMITS_CONFIG_VERSION
The version of the portable limits configuration schema this build reads and writes. See LimitsConfig.
SEMANTICS_PROFILE
SOURCE_INFO_VERSION

Traits§

SourceResolver

Functions§

artifact_id_with_context
artifact_id_with_limits under a full RuntimeContext, so a caller’s CancellationToken and deadline are observed while hashing.
artifact_id_with_limits
Compute the detached artifact identity of bytes under caller-supplied limits.
compile_did
compile_did_file
Compile a DID file through candid_parser::check_file, including its official filesystem import-resolution path.
compile_did_file_with_context
compile_did_file_with_options
compile_did_with_context
compile_did_with_options
compile_with_resolver
Compile an immutable logical source bundle with no filesystem access.
validate_host_value
validate_host_value_with_context

Type Aliases§

ContractViolation
Compatibility name for the shared diagnostic item in the Contract validation domain.
HostValueViolation
Compatibility name for the shared diagnostic item in the HostValue validation domain.
TypeRef