pub struct IntentGate { /* private fields */ }Expand description
The admission gate. Cheap and side-effect-free per the seam contract: the cores are pure and the config is captured at construction.
Implementations§
Source§impl IntentGate
impl IntentGate
Sourcepub fn new(config: IntentGateConfig) -> Self
pub fn new(config: IntentGateConfig) -> Self
A gate with no runtime provenance: taint is derived from the tool names and the proposal’s own DAG only.
Sourcepub fn with_taint(config: IntentGateConfig, ledger: Arc<TaintLedger>) -> Self
pub fn with_taint(config: IntentGateConfig, ledger: Arc<TaintLedger>) -> Self
A gate backed by the runtime’s TaintLedger, so a result the
executor observed as tainted marks the actions that READ it — even
when their own tool is trusted, and even when the tainting action
belongs to an earlier proposal (the replan case). See
crate::taint.
Trait Implementations§
Source§impl AdmissionGate for IntentGate
impl AdmissionGate for IntentGate
Source§fn name(&self) -> &str
fn name(&self) -> &str
Short stable identifier (e.g.
"information_flow", "concurrency")
recorded on the audit event so a denial is attributable to a gate.Source§fn check<'life0, 'life1, 'life2, 'life3, 'async_trait>(
&'life0 self,
proposal: &'life1 ActionProposal,
ctx: &'life2 GateContext<'life3>,
) -> Pin<Box<dyn Future<Output = GateOutcome> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
'life2: 'async_trait,
'life3: 'async_trait,
fn check<'life0, 'life1, 'life2, 'life3, 'async_trait>(
&'life0 self,
proposal: &'life1 ActionProposal,
ctx: &'life2 GateContext<'life3>,
) -> Pin<Box<dyn Future<Output = GateOutcome> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
'life2: 'async_trait,
'life3: 'async_trait,
Inspect a proposal and return a verdict. Must not mutate shared
state — admission runs before the execution snapshot is taken.
Auto Trait Implementations§
impl !RefUnwindSafe for IntentGate
impl !UnwindSafe for IntentGate
impl Freeze for IntentGate
impl Send for IntentGate
impl Sync for IntentGate
impl Unpin for IntentGate
impl UnsafeUnpin for IntentGate
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
impl<T> ErasedDestructor for Twhere
T: 'static,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
Converts
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
Converts
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more