pub struct StaticVerificationGate { /* private fields */ }Expand description
An admission gate that statically verifies a proposal before any action runs.
Holds a handle to the runtime’s tool registry rather than a back-reference to
the Runtime itself — gates are stored on the runtime, so an Arc<Runtime>
here would be a cycle. The registry is already Arc-shared, so cloning it is
both cheap and always current: tools registered after this gate is built are
visible to it.
Implementations§
Source§impl StaticVerificationGate
impl StaticVerificationGate
Sourcepub fn new(tools: Arc<TokioRwLock<HashMap<String, ToolSchema>>>) -> Self
pub fn new(tools: Arc<TokioRwLock<HashMap<String, ToolSchema>>>) -> Self
Build a gate reading tool schemas from the runtime’s live registry.
Sourcepub fn with_max_actions(self, max_actions: usize) -> Self
pub fn with_max_actions(self, max_actions: usize) -> Self
Override the action ceiling (proposals longer than this are not walked).
Trait Implementations§
Source§impl AdmissionGate for StaticVerificationGate
impl AdmissionGate for StaticVerificationGate
Source§fn name(&self) -> &str
fn name(&self) -> &str
Short stable identifier (e.g.
"information_flow", "concurrency")
recorded on the audit event so a denial is attributable to a gate.Source§fn check<'life0, 'life1, 'life2, 'life3, 'async_trait>(
&'life0 self,
proposal: &'life1 ActionProposal,
ctx: &'life2 GateContext<'life3>,
) -> Pin<Box<dyn Future<Output = GateOutcome> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
'life2: 'async_trait,
'life3: 'async_trait,
fn check<'life0, 'life1, 'life2, 'life3, 'async_trait>(
&'life0 self,
proposal: &'life1 ActionProposal,
ctx: &'life2 GateContext<'life3>,
) -> Pin<Box<dyn Future<Output = GateOutcome> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
'life2: 'async_trait,
'life3: 'async_trait,
Inspect a proposal and return a verdict. Must not mutate shared
state — admission runs before the execution snapshot is taken.
Auto Trait Implementations§
impl !RefUnwindSafe for StaticVerificationGate
impl !UnwindSafe for StaticVerificationGate
impl Freeze for StaticVerificationGate
impl Send for StaticVerificationGate
impl Sync for StaticVerificationGate
impl Unpin for StaticVerificationGate
impl UnsafeUnpin for StaticVerificationGate
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
impl<T> ErasedDestructor for Twhere
T: 'static,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
Converts
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
Converts
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more