Expand description
Verification boundary for supplemental invocation quotas.
The kernel treats supplemental authorization artifacts as opaque bytes. A trusted verifier installed by the runtime composition root parses and verifies those bytes, then returns a request-bound claim. The kernel checks every request binding again before exposing a quota owner or maximum.
Structs§
- Canonical
Revocation Set - The exact sorted revocation identifiers bound into an admission operation.
- Supplemental
Quota Verification Context - Request facts supplied by the kernel, never by the supplemental artifact.
- Supplemental
Quota Verifier Binding - Runtime evidence identifying the installed supplemental verifier.
- Supplemental
Quota Verifier Error - Error returned by an installed supplemental verifier.
- Verified
Supplemental Quota Claim - A claim returned by an installed trusted supplemental verifier.
Enums§
Constants§
- BROKER_
CAPABILITY_ EXECUTION_ PROFILE - The only supplemental invocation-quota profile supported by v1.
- MAX_
ADMISSION_ REVOCATION_ IDS - MAX_
SUPPLEMENTAL_ AUTHORIZATION_ BYTES - MAX_
SUPPLEMENTAL_ CLAIM_ FIELD_ BYTES - MAX_
SUPPLEMENTAL_ CONTEXT_ FIELD_ BYTES - MAX_
SUPPLEMENTAL_ NEGOTIATED_ FEATURES - MAX_
SUPPLEMENTAL_ REVOCATION_ IDS - MAX_
SUPPLEMENTAL_ REVOCATION_ ID_ BYTES
Traits§
- Supplemental
Quota Verifier - Trusted extension point installed by the runtime composition root.
Functions§
- supplemental_
authorization_ artifact_ digest - Hash the opaque authorization artifact exactly as received by the kernel.
- supplemental_
request_ binding_ hash - Compute the request binding that a trusted verifier must return.