1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
// Copyright The OpenTelemetry Authors
// SPDX-License-Identifier: Apache-2.0
//! Component inventory: link-time metadata for security-relevant components.
//!
//! This module implements the runtime surface of [RFC 0001: Component
//! Inventory][rfc]. Components annotated with the
//! [`#[component_inventory]`][macro] attribute macro (in
//! `otel-arrow-dfe-engine-macros`) emit one [`ComponentMeta`] entry into the
//! [`COMPONENT_INVENTORY`] distributed slice at link time. Offline tooling
//! (`cargo xtask component-inventory`, added in a later phase) reads the slice
//! to detect new/removed components for threat-model drift detection,
//! documentation coverage, and security review.
//!
//! This mirrors the existing `#[capability]` -> `KNOWN_CAPABILITIES` mechanism
//! (`crate::capability`). The data is read only by offline tooling and never at
//! runtime, so the mechanism is zero-cost.
//!
//! [rfc]: https://github.com/open-telemetry/otel-arrow/blob/main/rust/otap-dataflow/rfcs/0001-component-inventory.md
//! [macro]: otel_arrow_dfe_engine_macros::component_inventory
/// Component category (RFC 0001).
///
/// Re-exported from the leaf `otel-arrow-dfe-component-inventory-syntax` crate, which is
/// the single source of truth shared by the runtime type (here), the
/// `#[component_inventory]` proc macro, and the `cargo xtask component-inventory`
/// scanner. Defining it once there (rather than duplicating a string table in
/// each consumer) means adding a variant updates every consumer through the
/// type system and the three cannot drift.
///
/// The `#[component_inventory]` macro accepts a bare identifier (e.g.
/// `Receiver`) and rejects unknown variants at compile time, preventing
/// misspellings like `Reciever` from silently corrupting the inventory. For
/// factory components the macro also validates the category against the URN's
/// middle segment (e.g. `urn:otel:`**`receiver`**`:otlp`).
///
/// See [`Category`] for the full list of variants and their intended meanings.
pub use Category;
/// Well-known attribute keys (RFC 0001, "Option A": free-form map + key
/// constants). Contributors are encouraged to use these constants for the
/// security-relevant attributes so keys stay consistent across components.
///
/// The `attributes` map is intentionally free-form (`&[(&str, &str)]`) so any
/// component can express any property; these constants only standardize the
/// common keys. Value validation for security-relevant keys (RFC "Option C")
/// is intentionally not implemented in Phase 1.
//
// TODO(stability): a component "stability" attribute was considered but
// intentionally omitted. Stability is not modeled per-signal: many components
// have no signal type, or handle multiple signal types, so a single per-signal
// stability field does not fit. Revisit with the SIG if a component-level
// stability key is wanted later.
/// Inventory metadata for one security-relevant component.
///
/// Collected at link time via the [`COMPONENT_INVENTORY`] distributed slice;
/// extracted by `cargo xtask component-inventory`. Identity and category are
/// the fixed fields; all domain-specific properties live in the free-form
/// [`attributes`](ComponentMeta::attributes) slice so the struct is not biased
/// toward any one access pattern (network, filesystem, cloud, ...).
///
/// Note: this struct is deliberately **not** `#[non_exhaustive]` -- the
/// `#[component_inventory]` macro constructs it directly with a struct literal
/// from other crates, which `#[non_exhaustive]` would forbid. New fields must
/// therefore be added in lockstep with the macro's emission.
/// Link-time registry of all components annotated with `#[component_inventory]`
/// compiled into the binary.
///
/// Populated by the `#[component_inventory]` proc macro. Read only by offline
/// tooling (`cargo xtask component-inventory`); never at runtime.
//
// `linkme::distributed_slice` requires a `pub static`; `#[doc(hidden)]`
// excludes it from generated rustdoc so external crates don't see it in the
// public API surface. `#[allow(unsafe_code)]` is required because
// `linkme::distributed_slice` emits a static with `#[link_section = "..."]`,
// which the engine crate's `-D unsafe-code` lint would otherwise reject.
pub static COMPONENT_INVENTORY: = ;
/// Iterate over every component registered in the [`COMPONENT_INVENTORY`]
/// distributed slice.
///
/// Mirrors the iteration pattern used for `KNOWN_CAPABILITIES`.