Skip to main content

WritePolicy

Struct WritePolicy 

Source
pub struct WritePolicy {
    pub allows: &'static [WriteRange],
    pub parametric: &'static [ParametricWriteRange],
    pub lamports: LamportPolicy,
}
Expand description

Declared write-set for one instruction.

Intended to be a static built at macro-expansion time from the context’s mut / mut(seg, ...) declarations and installed via Context::set_write_policy. An empty set is a valid policy: it denies every Context-mediated write, turning the instruction into a machine-checked read-only contract.

The optional lamports dimension extends the set from data bytes to lamport balances; see LamportPolicy.

Fields§

§allows: &'static [WriteRange]

Allowed write ranges. Scanned linearly; contexts declare a handful of ranges, so a bounded scan beats any lookup structure at Solana scale.

§parametric: &'static [ParametricWriteRange]

Invocation-parametric rules that narrow selected static envelopes.

§lamports: LamportPolicy

Declared lamport-write permission set. See LamportPolicy for the exact semantics of each variant.

Implementations§

Source§

impl WritePolicy

Source

pub const fn new(allows: &'static [WriteRange]) -> Self

Wrap a const slice of allowed ranges as a policy.

The lamport dimension is left LamportPolicy::Undeclared, which preserves the behavior without a mutation-completeness contract: lamport mutation is ungoverned and the policy is not mutation-complete.

Source

pub const fn with_lamports( allows: &'static [WriteRange], lamport_accounts: &'static [u8], ) -> Self

Build a policy that declares both dimensions: data ranges and the account indices allowed to have their lamports mutated.

Source

pub const fn with_parametric( allows: &'static [WriteRange], parametric: &'static [ParametricWriteRange], ) -> Self

Build a data policy with invocation-parametric cell narrowing.

Source

pub const fn with_parametric_and_lamports( allows: &'static [WriteRange], parametric: &'static [ParametricWriteRange], lamport_accounts: &'static [u8], ) -> Self

Build a mutation-complete policy with parametric cell narrowing.

Source

pub const fn lamports_declared(&self) -> bool

Whether the lamport dimension was declared (making the policy a mutation-complete write-set when installed by a strict_writes context).

Source

pub fn allows_lamport_mutation(&self, account_index: u8) -> bool

Whether the policy permits mutating account_index’s lamports.

LamportPolicy::Undeclared permits everything (the dimension carries no authority); a declared set permits only its members.

Source

pub fn allows_whole_account_write(&self, account_index: u8) -> bool

Whether a declared range grants whole-account data writes on account_index (what a plain mut / lifecycle declaration compiles to). Used by the CPI writable-meta gate: handing an account writable to a callee is unbounded data delegation, so it requires a whole-account grant, not just field ranges.

Source

pub fn allows_any_account_write(&self, account_index: u8) -> bool

Whether this policy grants any data-write authority on account_index.

Length/presence transitions cannot be represented as an ordinary byte range because the affected bytes may not exist yet. The ambient gate therefore treats a declared data range as the account-level authority required to resize that account, while still requiring a whole-account grant for raw full-buffer writes and writable CPI delegation.

Source

pub fn check_write( &self, account_index: u8, offset: u32, size: u32, ) -> Result<(), ProgramError>

Ok(()) iff [offset, offset + size) on account_index is fully contained in a single declared range. Adjacent declared ranges are not coalesced at check time; the macro emits ranges exactly as declared, so a request straddling two declarations is refused (declare a covering range if that access is intended).

Source

pub fn check_write_with_args( &self, account_index: u8, offset: u32, size: u32, args: &[u32], ) -> Result<(), ProgramError>

Parametric form of check_write. A request that touches a governed column must fit the invocation-selected cell; other requests fall back to the ordinary static policy.

Source

pub fn first_unauthorized_byte_with_args( &self, account_index: u8, offset: u32, size: u32, args: &[u32], ) -> Option<u64>

Return the first byte in a recorded write touch that is not authorized by this invocation’s effective policy.

Unlike check_write_with_args, this method checks the union of authorized ranges. The distinction is intentional: a write acquire must fit one declaration, but the touch ledger may coalesce adjacent, independently authorized acquires into a single record. Static ranges authorize bytes outside parametric envelopes; inside an envelope, only the invocation-selected cell is authorized. Missing or out-of-range selector values therefore fail closed at the first governed byte.

Source

pub fn allows_write(&self, account_index: u8, offset: u32, size: u32) -> bool

Non-erroring form of check_write.

Trait Implementations§

Source§

impl Debug for WritePolicy

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.