pub struct WritePolicy {
pub allows: &'static [WriteRange],
pub parametric: &'static [ParametricWriteRange],
pub lamports: LamportPolicy,
}Expand description
Declared write-set for one instruction.
Intended to be a static built at macro-expansion time from the
context’s mut / mut(seg, ...) declarations and installed via
Context::set_write_policy.
An empty set is a valid policy: it denies every Context-mediated
write, turning the instruction into a machine-checked read-only
contract.
The optional lamports dimension extends the set
from data bytes to lamport balances; see LamportPolicy.
Fields§
§allows: &'static [WriteRange]Allowed write ranges. Scanned linearly; contexts declare a handful of ranges, so a bounded scan beats any lookup structure at Solana scale.
parametric: &'static [ParametricWriteRange]Invocation-parametric rules that narrow selected static envelopes.
lamports: LamportPolicyDeclared lamport-write permission set. See
LamportPolicy for the exact semantics of each variant.
Implementations§
Source§impl WritePolicy
impl WritePolicy
Sourcepub const fn new(allows: &'static [WriteRange]) -> Self
pub const fn new(allows: &'static [WriteRange]) -> Self
Wrap a const slice of allowed ranges as a policy.
The lamport dimension is left LamportPolicy::Undeclared, which
preserves the behavior without a mutation-completeness contract: lamport mutation is
ungoverned and the policy is not mutation-complete.
Sourcepub const fn with_lamports(
allows: &'static [WriteRange],
lamport_accounts: &'static [u8],
) -> Self
pub const fn with_lamports( allows: &'static [WriteRange], lamport_accounts: &'static [u8], ) -> Self
Build a policy that declares both dimensions: data ranges and the account indices allowed to have their lamports mutated.
Sourcepub const fn with_parametric(
allows: &'static [WriteRange],
parametric: &'static [ParametricWriteRange],
) -> Self
pub const fn with_parametric( allows: &'static [WriteRange], parametric: &'static [ParametricWriteRange], ) -> Self
Build a data policy with invocation-parametric cell narrowing.
Sourcepub const fn with_parametric_and_lamports(
allows: &'static [WriteRange],
parametric: &'static [ParametricWriteRange],
lamport_accounts: &'static [u8],
) -> Self
pub const fn with_parametric_and_lamports( allows: &'static [WriteRange], parametric: &'static [ParametricWriteRange], lamport_accounts: &'static [u8], ) -> Self
Build a mutation-complete policy with parametric cell narrowing.
Sourcepub const fn lamports_declared(&self) -> bool
pub const fn lamports_declared(&self) -> bool
Whether the lamport dimension was declared (making the policy a
mutation-complete write-set when installed by a strict_writes
context).
Sourcepub fn allows_lamport_mutation(&self, account_index: u8) -> bool
pub fn allows_lamport_mutation(&self, account_index: u8) -> bool
Whether the policy permits mutating account_index’s lamports.
LamportPolicy::Undeclared permits everything (the dimension
carries no authority); a declared set permits only its members.
Sourcepub fn allows_whole_account_write(&self, account_index: u8) -> bool
pub fn allows_whole_account_write(&self, account_index: u8) -> bool
Whether a declared range grants whole-account data writes on
account_index (what a plain mut / lifecycle declaration
compiles to). Used by the CPI writable-meta gate: handing an
account writable to a callee is unbounded data delegation, so it
requires a whole-account grant, not just field ranges.
Sourcepub fn allows_any_account_write(&self, account_index: u8) -> bool
pub fn allows_any_account_write(&self, account_index: u8) -> bool
Whether this policy grants any data-write authority on
account_index.
Length/presence transitions cannot be represented as an ordinary byte range because the affected bytes may not exist yet. The ambient gate therefore treats a declared data range as the account-level authority required to resize that account, while still requiring a whole-account grant for raw full-buffer writes and writable CPI delegation.
Sourcepub fn check_write(
&self,
account_index: u8,
offset: u32,
size: u32,
) -> Result<(), ProgramError>
pub fn check_write( &self, account_index: u8, offset: u32, size: u32, ) -> Result<(), ProgramError>
Ok(()) iff [offset, offset + size) on account_index is
fully contained in a single declared range. Adjacent declared
ranges are not coalesced at check time; the macro emits ranges
exactly as declared, so a request straddling two declarations is
refused (declare a covering range if that access is intended).
Sourcepub fn check_write_with_args(
&self,
account_index: u8,
offset: u32,
size: u32,
args: &[u32],
) -> Result<(), ProgramError>
pub fn check_write_with_args( &self, account_index: u8, offset: u32, size: u32, args: &[u32], ) -> Result<(), ProgramError>
Parametric form of check_write. A request that
touches a governed column must fit the invocation-selected cell; other
requests fall back to the ordinary static policy.
Return the first byte in a recorded write touch that is not authorized by this invocation’s effective policy.
Unlike check_write_with_args, this
method checks the union of authorized ranges. The distinction is
intentional: a write acquire must fit one declaration, but the touch
ledger may coalesce adjacent, independently authorized acquires into a
single record. Static ranges authorize bytes outside parametric
envelopes; inside an envelope, only the invocation-selected cell is
authorized. Missing or out-of-range selector values therefore fail
closed at the first governed byte.
Sourcepub fn allows_write(&self, account_index: u8, offset: u32, size: u32) -> bool
pub fn allows_write(&self, account_index: u8, offset: u32, size: u32) -> bool
Non-erroring form of check_write.