pub struct SkillCeilingGate { /* private fields */ }Expand description
An admission gate that caps a skill-driven proposal’s actions at the
skill’s persisted deployment_tier.
NOTE (neo review): this gate holds its OWN RiskClassifier, distinct
from the session PermissionGate’s. Both are RiskClassifier::new()
defaults today, so they classify identically — but if either side ever
installs custom rules, the two classification points can disagree on
an action’s tier. If custom rules land, thread ONE shared classifier
through both (Arc it) rather than configuring them separately.
Implementations§
Source§impl SkillCeilingGate
impl SkillCeilingGate
Sourcepub fn new(memgine: Arc<TokioMutex<MemgineEngine>>) -> Self
pub fn new(memgine: Arc<TokioMutex<MemgineEngine>>) -> Self
Build a gate that reads ceilings from memgine’s live skill graph.
Sourcepub fn with_classifier(self, classifier: RiskClassifier) -> Self
pub fn with_classifier(self, classifier: RiskClassifier) -> Self
Override the risk classifier (e.g. with project-specific escalation rules).
Trait Implementations§
Source§impl AdmissionGate for SkillCeilingGate
impl AdmissionGate for SkillCeilingGate
Source§fn name(&self) -> &str
fn name(&self) -> &str
Short stable identifier (e.g.
"information_flow", "concurrency")
recorded on the audit event so a denial is attributable to a gate.Source§fn check<'life0, 'life1, 'life2, 'life3, 'async_trait>(
&'life0 self,
proposal: &'life1 ActionProposal,
_ctx: &'life2 GateContext<'life3>,
) -> Pin<Box<dyn Future<Output = GateOutcome> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
'life2: 'async_trait,
'life3: 'async_trait,
fn check<'life0, 'life1, 'life2, 'life3, 'async_trait>(
&'life0 self,
proposal: &'life1 ActionProposal,
_ctx: &'life2 GateContext<'life3>,
) -> Pin<Box<dyn Future<Output = GateOutcome> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
'life2: 'async_trait,
'life3: 'async_trait,
Inspect a proposal and return a verdict. Must not mutate shared
state — admission runs before the execution snapshot is taken.
Auto Trait Implementations§
impl !RefUnwindSafe for SkillCeilingGate
impl !UnwindSafe for SkillCeilingGate
impl Freeze for SkillCeilingGate
impl Send for SkillCeilingGate
impl Sync for SkillCeilingGate
impl Unpin for SkillCeilingGate
impl UnsafeUnpin for SkillCeilingGate
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
impl<T> ErasedDestructor for Twhere
T: 'static,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
Converts
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
Converts
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more