Skip to main content

ProviderRuntimePolicy

Struct ProviderRuntimePolicy 

Source
pub struct ProviderRuntimePolicy {
    pub raw_pty_lifecycle: bool,
    pub semantic_readiness: bool,
    pub structured_prompt: bool,
    pub provider_session_identity: bool,
    pub semantic_resume: bool,
    pub hook_semantics: bool,
}

Fields§

§raw_pty_lifecycle: bool§semantic_readiness: bool§structured_prompt: bool§provider_session_identity: bool§semantic_resume: bool§hook_semantics: bool

Whether this session’s provider-event ingestion may come from a declared hook adapter – a native hooks contract the provider CLI itself calls over the authenticated loopback ingress route, with the node’s own adapter normalizing the payload before it ever reaches the engine.

This is deliberately NOT semantic_readiness, and granting one must never imply the other. semantic_readiness (and the structured_ prompt/provider_session_identity/semantic_resume capabilities chained off it) authorize INFERRING provider semantics by parsing PTY terminal text – that inference is only sound for a CLI version this build has a verified vendor terminal contract for (see gate4agent-runtime-native’s VERIFIED_PROFILES). A hook event is not an inference: the CLI is asserting it directly over a route this node authenticated, and the node’s hook adapter – not a terminal screen scanner – turns it into a ProviderEvent. None of the terminal-behaviour verification a vendor contract encodes is relevant to that trust story, so hook_semantics is derived purely from “does the catalog declare a hook adapter for this provider” and never from a vendor version probe. Conflating the two would let a provider that merely declares a hook adapter silently unlock PTY-parsing semantics it was never verified for, or – the bug this field fixes – let a verified-semantic gate silently swallow every hook event a provider with no verified profile at all (grok, codex, kimi) sends over a route that is otherwise working end to end.

Implementations§

Source§

impl ProviderRuntimePolicy

Source

pub fn new( raw_pty_lifecycle: bool, semantic_readiness: bool, structured_prompt: bool, provider_session_identity: bool, semantic_resume: bool, hook_semantics: bool, ) -> Result<Self, ProviderRuntimePolicyError>

Source

pub const fn raw_pty() -> Self

Source

pub const fn none() -> Self

The all-false policy: no capability admitted at all. This is the correct shape for a transport that has no PTY and whose catalog entry declares no contract this build can grant a semantic capability from – e.g. a Pipe-transport provider with no declared Pipe contract. Unlike raw_pty(), this does NOT claim a PTY lifecycle exists.

Source

pub fn validate(self) -> Result<(), ProviderRuntimePolicyError>

Only semantic_resume and hook_semantics require the raw PTY lifecycle. semantic_readiness, structured_prompt, and provider_session_identity do NOT, on their own – an ACP transport has no PTY at all, yet session/prompt and session/update are MANDATORY surface of the ACP protocol itself, and session/new MUST return a sessionId under that same specification, none of it an inference this build makes by parsing PTY terminal text the way it does for a verified PTY vendor contract. provider_session_identity in particular is not a bare protocol formality here: both shipped ACP adapters map that mandatory sessionId to the provider’s own durable session id (claude-agent-acp’s is the Claude Code session id and on-disk transcript filename; codex-acp’s is the Codex thread id), and the ACP spawn path publishes it as a SessionId-keyed ProviderEvent::SessionIdentityObserved, which is what carries a newly-created record from IdentityPending to Live. An agent whose adapter never emits that event – because it returns no sessionId, violating the ACP contract this grant relies on – correctly stays IdentityPending rather than being treated as identity-less; that is the refusal-by-name this policy is meant to produce for such an agent, not a defect in the grant. Granting semantic_readiness/ structured_prompt/provider_session_identity with raw_pty_lifecycle: false is therefore a legitimate policy shape (see gate4agent_node::provider_runtime::policy_for_transport’s TransportKind::Acp arm), not a defect this validation should catch.

semantic_resume/hook_semantics keep the old, stricter rule: today nothing derives either of the two for a transport other than a verified PTY vendor contract – ACP’s spec gives no resume guarantee analogous to session/new’s sessionId, and the engine separately refuses ACP resume outright – so granting one without raw_pty_lifecycle remains a construction defect rather than a legitimate non-PTY policy shape.

Source

pub const fn admits(self, capability: ProviderRuntimeCapability) -> bool

Trait Implementations§

Source§

impl Clone for ProviderRuntimePolicy

Source§

fn clone(&self) -> Self

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Copy for ProviderRuntimePolicy

Source§

impl Debug for ProviderRuntimePolicy

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl<'de> Deserialize<'de> for ProviderRuntimePolicy

Source§

fn deserialize<D>(deserializer: D) -> Result<Self, D::Error>
where D: Deserializer<'de>,

Deserialize this value from the given Serde deserializer. Read more
Source§

impl Eq for ProviderRuntimePolicy

Source§

impl PartialEq for ProviderRuntimePolicy

Source§

fn eq(&self, other: &Self) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl Serialize for ProviderRuntimePolicy

Source§

fn serialize<__S>(&self, __serializer: __S) -> Result<__S::Ok, __S::Error>
where __S: Serializer,

Serialize this value into the given Serde serializer. Read more
Source§

impl StructuralPartialEq for ProviderRuntimePolicy

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DeserializeOwned for T
where T: for<'de> Deserialize<'de>,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.