Expand description
capOS front-door SDK.
capos is the single crate a Rust author depends on to write a capOS
application against typed Cap’n Proto capability clients. The clients are
written once and run over a Transport seam:
- The default
ringfeature provides the in-system transport: an application running inside capOS reaches the kernel through its per-process capability ring (RingTransport). This isno_std. - The reserved
remotefeature is for a future host-side transport that reaches a capOS instance over the remote session connection. It is not implemented yet; seedocs/backlog/capos-sdk-dual-transport.md.
For the ring feature this crate is a thin facade: it re-exports the
capos_rt runtime, the typed capability clients, and the
entry_point! macro, and adds a prelude of the
items most applications use. Reach for the facade rather than depending on
capos-rt internals directly, so client code stays transport-agnostic.
Modules§
- alloc
- capos_
capnp - capset
- client
- entry
- prelude
- The items most in-system applications use: the runtime, the transport seam
(the
Transporttrait and itsRingTransportimplementation), theClienttrait, the common typed clients, and the call error types (ClientErrorand itsTransportErrorvariant payload). - ring
- syscall
- transport
- Transport seam shared by the typed capability clients.
Macros§
Structs§
- Account
Store Manager Client - Account
Store Reader Client - Answer
Id - Application
Exception - Audit
LogClient - Audit
Record - Authority
Broker Client - Authorized
KeyStore Client - Block
Device Client - Block
Device Info Result - Result of
BlockDevice.info: device geometry. - Block
Device Read Result - Result of
BlockDevice.readBlocks: the sector bytes returned by the kernel. - Boot
Package Client - Bootstrap
- CallId
- CapCqe
- Completion Queue Entry — 32 bytes.
- CapRing
Header - Ring header at the start of the shared page.
- CapSet
- CapSqe
- Submission Queue Entry — 64 bytes.
- Capability
- Capability
Info - Capability
Manager Client - Capability
Ref - Client
State - Completed
Call - Console
Bootstrap Policy - Console
Client - Console
Password Status - Console
Password Verify Result - Copy
Transfer - CpuIsolation
Accounting Target - CpuIsolation
Activation Preflight - CpuIsolation
Grant Minted - A successfully minted grant: the
CpuIsolationPoolGrantcap plus thegrant_idthat names it for a laterrevoke_grant. - CpuIsolation
Grant Minter Client - Client for a runtime
CpuIsolationGrantMinter: mints a freshCpuIsolationPoolGrantfor an operator-chosen(account, pool)at call time, bounded by the minter’s declared allowlist. - CpuIsolation
Grant Minter Info - CpuIsolation
Lease Client - CpuIsolation
Lease Create Response - CpuIsolation
Lease Create Result - CpuIsolation
Lease Identity - CpuIsolation
Lease Info - CpuIsolation
Lease Owner - CpuIsolation
Lease Renew Response - CpuIsolation
Lease Revoke Result - CpuIsolation
Lease Spec - CpuIsolation
Pool Grant Client - Client for a bootstrap
CpuIsolationPoolGrant: binds one authenticated account to one declared CPU-isolation pool.create_leasemints aCpuIsolationLeaseagainst the bound pool with the bound account stamped on, reusing theCpuIsolationLease.createresult shape. - CpuIsolation
Pool Grant Info - Create
Pipe Result - Result of
ProcessSpawner.createPipe: typed owned caps for both halves. Drop releases each half automatically; the parent typically passes one half into a child viaProcessSpawner.spawngrants before dropping its end. - Credential
Store Client - Device
Mmio Brokered Nvme Admin Identify Result - Device
Mmio Brokered Nvme Admin OpRead Bytes Result - Result of
DeviceMmio.brokeredNvmeIoSyncReadBytes @22: the bounded status/echo fields plus the full read-back transfer asdata. The per-block match and block-distinctness are attested kernel-side in the release marker. - Device
Mmio Brokered Nvme Controller Enable Result - Device
Mmio Client - Device
Mmio Info - Device
Mmio MapAdmission - Device
Mmio Read32 Result - Device
Mmio Unmap Result - Device
Mmio Write32 Admission - DirEntry
- A single directory entry returned by
Directory.list. - Directory
Client - Directory
List Result - Result of
Directory.list: the entries in the directory. - DmaBuffer
Client - DmaBuffer
Complete Descriptor Admission - DmaBuffer
Free Buffer Result - DmaBuffer
Info - DmaBuffer
MapAdmission - DmaBuffer
Submit Descriptor Admission - DmaBuffer
Unmap Result - DmaPool
Allocate Buffer Rejection - DmaPool
Allocate Buffer Result - DmaPool
Client - DmaPool
Info - Entropy
Fill Result - Entropy
Source Client - File
Client - File
Read Result - Result of
File.read: the data returned by the kernel. - File
Stat Result - Result of
File.stat: size plus backend-provided metadata timestamps. Timestamp values are Unix epoch nanoseconds when supplied, or zero when the backend is unstamped/unsupported. - Hardware
Audit Drain - Hardware
Audit LogClient - Hardware
Audit Record - Hardware
Audit Snapshot - Interrupt
Acknowledge Admission - Interrupt
Client - Interrupt
Info - Interrupt
Mask Admission - Interrupt
Unmask Admission - Interrupt
Wait Admission - LogRead
Result - LogReader
Client - LogRecord
Entry - LogSink
Client - Manual
Build Info - The build/commit provenance returned by
buildInfo. - Manual
Client - Manual
Page - A manual page returned by
ManualClient::page_wait. - Manual
Page Ref - A
name(section)cross-reference returned byapropos. - Manual
Topic - One curated topic-index entry returned by
ManualClient::topics_wait. - Namespace
Client - Namespace
List Result - Network
Config - Network
Manager Client - NicClient
- Typed client for the
Niccapability: the Phase C userspace virtio-net driver’s frame round-trip surface. Frames cross the boundary as inlineData; the kernel copies them through the manager-owned bounce buffer, so no host-physical address or device-usable handle is exposed. - NicLink
Status Result Nic.linkStatusresult: the bound NIC’s link state plus the evidence triple.- NicMac
Address Result Nic.macAddressresult: the bound NIC’s MAC (six bytes inline) plus the evidence triple.- NicReceive
Poll Result Nic.receivePollresult: the next arrived Ethernet frame inline (whenframe_present), the observed EtherType, and the evidence triple. The sustained-receive pool stays armed across calls;frame_present = falseis the cheap “no frame yet” answer with no device reset.- NicReceive
Result Nic.receiveresult: one received Ethernet frame inline plus the observed EtherType and the evidence triple.- NicTransmit
Result Nic.transmitadmission: theresult/reason/sideEffectevidence triple.- Owned
Capability - Owned runtime handle for a local capability slot.
- Pipe
Client - Pipe
Read Result - Result of
Pipe.read: the bytes copied out plus the EOF flag the kernel returns when the writer half has been closed and the buffer is drained. - Process
Handle Client - Process
Spawner Client - Promise
Id - Resource
Profile Manager Client - Resource
Profile Reader Client - Restricted
Launcher Client - Restricted
Shell Launcher Client - Ring
Client - Runtime
- Runtime
Ring Client - Scheduling
Context Bind Result - Scheduling
Context Binding - Scheduling
Context Client - Scheduling
Context Create Response - Scheduling
Context Create Result - Scheduling
Context Identity - Scheduling
Context Info - Scheduling
Context Notification Slot - Scheduling
Context Notification Snapshot - Scheduling
Context Revoke Result - Scheduling
Context Spec - Scheduling
Policy Client - Scheduling
Policy Snapshot - Session
Audit Context - Session
Info - Session
Manager Client - Session
Start Result - Shell
Bundle Endpoint - Shell
Bundle Result - Spawn
Grant - Spawn
Result - SshAuthorized
KeyDecision - SshHost
KeyClient - SshHost
KeyPublic Key - StdIO
Client - Prototype client for the shell-serviced
StdIOendpoint facet. - StdIO
Read Request - StdIO
Read Result - Store
Client - Store
GetResult - Store
PutResult - System
Info Client - TcpAccept
Result - TcpListen
Authority Client - TcpListen
Result - TcpListener
Client - TcpSocket
Client - Terminal
Read Result - Terminal
Session Client - Thread
Control Client - Thread
Exit Code - Thread
Handle Client - Thread
Spawner Client - Timer
Client - Timer
Now - UdpRecv
From Result - UdpSocket
Client - User
Session Client - Virtual
Memory Call Scratch - Virtual
Memory Client - Wall
Clock Client - Wall
Clock Time - Worker
Spawn Result
Enums§
- Account
Store Manager - Account
Store Reader - Audit
Event Type - Audit
Log - Audit
Reason Class - Audit
Result Class - Auth
Strength - Authority
Broker - Authorized
KeyStore - Block
Device - Boot
Package - CapSet
Error - Capability
Manager - Client
Error - Clock
Provenance - Runtime mirror of the schema
ClockProvenanceenum. - Console
- CpuIsolation
Accounting Target Kind - CpuIsolation
Grant Mint Outcome - Outcome of a
mintGrant: on success the mintedCpuIsolationPoolGrantcap and itsgrant_id, otherwise the typed rejection reason with no cap. - CpuIsolation
Grant Mint Result - Outcome of
CpuIsolationGrantMinter.mintGrant(capos-rt mirror of the schemaCpuIsolationGrantMintResultenum). - CpuIsolation
Grant Minter - CpuIsolation
Grant Revoke Result - Outcome of
CpuIsolationGrantMinter.revokeGrant(capos-rt mirror of the schemaCpuIsolationGrantRevokeResultenum). - CpuIsolation
Lease - CpuIsolation
Lease Create Outcome - CpuIsolation
Lease Operation Result - CpuIsolation
Lease Renew Result - CpuIsolation
Lease State - CpuIsolation
Mode - CpuIsolation
Named Ring - CpuIsolation
Owner Kind - CpuIsolation
Pool Grant - Credential
Check Status - Credential
Store - Device
Mmio - Directory
- DmaBuffer
- DmaPool
- DmaPool
Allocate Buffer Outcome - Endpoint
- Entropy
Source - Entropy
Status - Exception
Decode Error - Exception
Type - File
- Hardware
Audit CapTag - Hardware
Audit Event - Hardware
Audit Log - Interrupt
- IpAddress
Family - Address family reported by
NetworkConfigand carried by the socket-addressDatacontract (schema/capos.capnp,IpAddressFamily): a 4-byte value isIpv4, a 16-byte value isIpv6, and an empty value isUnspecified. - Kernel
CapSource - Latency
Class - Line
Echo - Line
Status - LogReader
- LogSeverity
- Runtime mirror of the schema
LogLevelenum used by the log surface so callers need not import the generated capnp types. Severity ordering isdebug < info < warn < error. - LogSink
- Manual
- Manual
Source - How a
ManualPagebody was produced, mirroring the schemaSourceenum. - Memory
Object - Namespace
- Network
Manager - Nic
- Overrun
Policy - Park
Space - Pipe
- Principal
Kind - Process
Handle - Process
Spawner - Resource
Profile Manager - Resource
Profile Reader - Restricted
Launcher - Restricted
Shell Launcher - Result
CapError - Ring
Client Error - Scheduling
Context - Scheduling
Context Bind State - Scheduling
Context Create Outcome - Scheduling
Context Dispatch Effect - Scheduling
Context Notification Kind - Scheduling
Context Notification Lifecycle Event - Scheduling
Context Notification Observer Result - Scheduling
Context Operation Result - Scheduling
Context State - Scheduling
Policy Cap - Session
Manager - Shared
Park Space - Spawn
Grant Mode - Spawn
Grant Source - SshGateway
- SshHost
Key - SshTerminal
Factory - StdIO
- StdIO
Read Mode - StdIO
Stream - Store
- System
Info - TcpListen
Authority - TcpListener
- TcpSocket
- Terminal
Session - Thread
Control - Thread
Handle - Thread
Spawner - Timer
- Transport
Error - UdpSocket
- User
Session - Virtual
Memory - Wall
Clock
Constants§
- ACCOUNT_
STORE_ MANAGER_ INTERFACE_ ID - ACCOUNT_
STORE_ READER_ INTERFACE_ ID - AUDIT_
LOG_ INTERFACE_ ID - AUTHORITY_
BROKER_ INTERFACE_ ID - AUTHORIZED_
KEY_ STORE_ INTERFACE_ ID - BLOCKDEVICE_
INTERFACE_ ID - BOOT_
PACKAGE_ INTERFACE_ ID - CAPABILITY_
MANAGER_ INTERFACE_ ID - CONSOLE_
INTERFACE_ ID - CPU_
ISOLATION_ GRANT_ MINTER_ INTERFACE_ ID - CPU_
ISOLATION_ LEASE_ INTERFACE_ ID - CPU_
ISOLATION_ POOL_ GRANT_ INTERFACE_ ID - CREDENTIAL_
STORE_ INTERFACE_ ID - DEVICEMMIO_
INTERFACE_ ID - DIRECTORY_
INTERFACE_ ID - DMABUFFER_
INTERFACE_ ID - DMAPOOL_
INTERFACE_ ID - ENDPOINT_
INTERFACE_ ID - ENTROPY_
SOURCE_ INTERFACE_ ID - FILE_
INTERFACE_ ID - FRAME_
ALLOCATOR_ INTERFACE_ ID - HARDWARE_
AUDIT_ LOG_ INTERFACE_ ID - HARDWARE_
AUDIT_ READER_ INTERFACE_ ID - INTERRUPT_
INTERFACE_ ID - LOG_
READER_ INTERFACE_ ID - LOG_
SINK_ INTERFACE_ ID - MANUAL_
INTERFACE_ ID - MEMORY_
OBJECT_ INTERFACE_ ID - NAMESPACE_
INTERFACE_ ID - NETWORK_
MANAGER_ INTERFACE_ ID - NIC_
INTERFACE_ ID - PARK_
SPACE_ INTERFACE_ ID - PIPE_
INTERFACE_ ID - PRESERVE_
CLIENT_ ENDPOINT_ BADGE - PROCESS_
HANDLE_ INTERFACE_ ID - PROCESS_
SPAWNER_ INTERFACE_ ID - RESOURCE_
PROFILE_ MANAGER_ INTERFACE_ ID - RESOURCE_
PROFILE_ READER_ INTERFACE_ ID - RESTRICTED_
LAUNCHER_ INTERFACE_ ID - RESTRICTED_
SHELL_ LAUNCHER_ INTERFACE_ ID - SCHEDULING_
CONTEXT_ INTERFACE_ ID - SCHEDULING_
POLICY_ CAP_ INTERFACE_ ID - SESSION_
MANAGER_ INTERFACE_ ID - SHARED_
PARK_ SPACE_ INTERFACE_ ID - SSH_
GATEWAY_ INTERFACE_ ID - SSH_
HOST_ KEY_ INTERFACE_ ID - SSH_
TERMINAL_ FACTORY_ INTERFACE_ ID - STDIO_
INTERFACE_ ID - STORE_
INTERFACE_ ID - SYSTEM_
INFO_ INTERFACE_ ID - TCP_
LISTENER_ INTERFACE_ ID - TCP_
LISTEN_ AUTHORITY_ INTERFACE_ ID - TCP_
SOCKET_ INTERFACE_ ID - TERMINAL_
SESSION_ INTERFACE_ ID - THREAD_
CONTROL_ INTERFACE_ ID - THREAD_
HANDLE_ INTERFACE_ ID - THREAD_
SPAWNER_ INTERFACE_ ID - TIMER_
INTERFACE_ ID - UDP_
SOCKET_ INTERFACE_ ID - USER_
SESSION_ INTERFACE_ ID - VIRTUAL_
MEMORY_ INTERFACE_ ID - VIRTUAL_
MEMORY_ MESSAGE_ SCRATCH_ BYTES - VIRTUAL_
MEMORY_ PARAMS_ BUFFER_ BYTES - VIRTUAL_
MEMORY_ RESULT_ BUFFER_ BYTES - VM_
PROT_ EXEC - VM_
PROT_ NONE - VM_
PROT_ READ - VM_
PROT_ WRITE - WALL_
CLOCK_ INTERFACE_ ID
Traits§
- Capability
Type - Client
- Transport
- Client-side capability invocation seam over a single-owner connection.
Functions§
- decode_
completed_ call - decode_
stdio_ read_ params - decode_
stdio_ write_ params - default_
reader_ options - encode_
stdio_ read_ result
Type Aliases§
- Ring
Transport - The in-system ring transport.