pub struct AdmittedTool { /* private fields */ }Expand description
An executable with a retained byte identity and an admitted exact version.
Self::admit requires a consumer-supplied digest. Self::admit_version
records the installed identity without authenticating it against a pin.
Every execution rechecks digest/permission before spawning. Consumers must
exclude concurrent writers to the executable and its parent directories:
filesystem checks and exec are separate operations. This is not a file
capability or verification of dynamic libraries, interpreters, or descendants.
Implementations§
Source§impl AdmittedTool
impl AdmittedTool
Sourcepub fn admit(
spec: &ToolSpec<'_>,
context: &ExecutionContext<'_>,
limits: OutputLimits,
) -> Result<Self, ToolError>
pub fn admit( spec: &ToolSpec<'_>, context: &ExecutionContext<'_>, limits: OutputLimits, ) -> Result<Self, ToolError>
Admit exact executable bytes before invoking the selected version command.
§Errors
Rejects invalid inputs, non-executable files, digest/size mismatch, process failures, non-UTF-8 stdout, and a different successful version identity.
Sourcepub fn admit_version(
spec: &VersionSpec<'_>,
context: &ExecutionContext<'_>,
limits: OutputLimits,
) -> Result<Self, ToolError>
pub fn admit_version( spec: &VersionSpec<'_>, context: &ExecutionContext<'_>, limits: OutputLimits, ) -> Result<Self, ToolError>
Admit an exact version and record the caller-trusted installed bytes.
For tools built locally, no portable published digest may exist. This
entry hashes the executable within the supplied budget before running
the version command. The resulting Self::identity is an observation,
not a trusted published pin. All later runs reject changed bytes using
the same verification and capture engine as Self::admit.
The caller must trust the installation before admission: the version command executes those bytes. Exact version output does not establish authenticity. No version ranges, tool installation or PATH search occur. The caller must exclude concurrent executable/directory writers.
§Errors
Rejects invalid inputs, non-executable or oversized files, process failures, non-UTF-8 stdout and a different successful version identity.
Sourcepub const fn identity(&self) -> ArtifactIdentity
pub const fn identity(&self) -> ArtifactIdentity
Retained raw executable identity.
With Self::admit_version, this is an observed identity, not proof of
a published binary pin or trusted installation provenance.
Sourcepub fn version_identity(&self) -> &str
pub fn version_identity(&self) -> &str
Successfully observed, trimmed version identity.
Sourcepub fn run(
&self,
arguments: &[OsString],
context: &ExecutionContext<'_>,
limits: OutputLimits,
) -> Result<ExecutionEvidence, ToolError>
pub fn run( &self, arguments: &[OsString], context: &ExecutionContext<'_>, limits: OutputLimits, ) -> Result<ExecutionEvidence, ToolError>
Run once with a cleared, explicitly supplied environment and null stdin.
Stdout/stderr are drained fairly through nonblocking pipes without reader threads. On overflow/deadline the direct child is killed and reaped; pipe handles are closed without waiting for descendants to close their copies. Descendant processes remain caller-owned. This must not be interpreted as a rollback or safe automatic retry of a command with external effects.
§Errors
Returns invalid-input or identity failures before execution, or an execution failure retaining bounded prefixes and cleanup outcomes.