Skip to main content

AdmittedTool

Struct AdmittedTool 

Source
pub struct AdmittedTool { /* private fields */ }
Expand description

An executable with a retained byte identity and an admitted exact version.

Self::admit requires a consumer-supplied digest. Self::admit_version records the installed identity without authenticating it against a pin. Every execution rechecks digest/permission before spawning. Consumers must exclude concurrent writers to the executable and its parent directories: filesystem checks and exec are separate operations. This is not a file capability or verification of dynamic libraries, interpreters, or descendants.

Implementations§

Source§

impl AdmittedTool

Source

pub fn admit( spec: &ToolSpec<'_>, context: &ExecutionContext<'_>, limits: OutputLimits, ) -> Result<Self, ToolError>

Admit exact executable bytes before invoking the selected version command.

§Errors

Rejects invalid inputs, non-executable files, digest/size mismatch, process failures, non-UTF-8 stdout, and a different successful version identity.

Source

pub fn admit_version( spec: &VersionSpec<'_>, context: &ExecutionContext<'_>, limits: OutputLimits, ) -> Result<Self, ToolError>

Admit an exact version and record the caller-trusted installed bytes.

For tools built locally, no portable published digest may exist. This entry hashes the executable within the supplied budget before running the version command. The resulting Self::identity is an observation, not a trusted published pin. All later runs reject changed bytes using the same verification and capture engine as Self::admit.

The caller must trust the installation before admission: the version command executes those bytes. Exact version output does not establish authenticity. No version ranges, tool installation or PATH search occur. The caller must exclude concurrent executable/directory writers.

§Errors

Rejects invalid inputs, non-executable or oversized files, process failures, non-UTF-8 stdout and a different successful version identity.

Source

pub fn path(&self) -> &Path

Canonical absolute path selected during admission.

Source

pub const fn identity(&self) -> ArtifactIdentity

Retained raw executable identity.

With Self::admit_version, this is an observed identity, not proof of a published binary pin or trusted installation provenance.

Source

pub fn version_identity(&self) -> &str

Successfully observed, trimmed version identity.

Source

pub fn run( &self, arguments: &[OsString], context: &ExecutionContext<'_>, limits: OutputLimits, ) -> Result<ExecutionEvidence, ToolError>

Run once with a cleared, explicitly supplied environment and null stdin.

Stdout/stderr are drained fairly through nonblocking pipes without reader threads. On overflow/deadline the direct child is killed and reaped; pipe handles are closed without waiting for descendants to close their copies. Descendant processes remain caller-owned. This must not be interpreted as a rollback or safe automatic retry of a command with external effects.

§Errors

Returns invalid-input or identity failures before execution, or an execution failure retaining bounded prefixes and cleanup outcomes.

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.