Skip to main content

ic_memory/runtime/
policy.rs

1use super::RuntimeBootstrapError;
2use crate::{
3    AllocationPolicy, MemoryManagerSlot, PolicyIdentity, PolicyIdentityError,
4    RuntimeBootstrapPolicy, StableKey, slot::IC_MEMORY_LEDGER_STABLE_KEY,
5};
6use std::convert::Infallible;
7
8pub(super) fn runtime_bootstrap_error_from_bootstrap<P>(
9    err: crate::BootstrapError<P>,
10) -> RuntimeBootstrapError<P> {
11    match err {
12        crate::BootstrapError::Ledger(err) => RuntimeBootstrapError::LedgerCommit(err),
13        crate::BootstrapError::Validation(err) => RuntimeBootstrapError::Validation(err),
14        crate::BootstrapError::Staging(err) => RuntimeBootstrapError::Staging(err),
15    }
16}
17
18// Resolution admits every external row under the host pool. This adapter only
19// keeps private governance outside application callbacks; it cannot accept raw
20// declarations from a public caller or supply a different allocation policy.
21pub(super) struct RuntimeMemoryManagerPolicy<'a, P> {
22    pub(super) custom_policy: &'a P,
23}
24
25impl<P: AllocationPolicy> AllocationPolicy for RuntimeMemoryManagerPolicy<'_, P> {
26    type Error = P::Error;
27
28    fn validate_key(&self, key: &StableKey) -> Result<(), Self::Error> {
29        if key.as_str() == IC_MEMORY_LEDGER_STABLE_KEY {
30            return Ok(());
31        }
32        self.custom_policy.validate_key(key)
33    }
34
35    fn validate_slot(&self, key: &StableKey, slot: &MemoryManagerSlot) -> Result<(), Self::Error> {
36        if key.as_str() == IC_MEMORY_LEDGER_STABLE_KEY {
37            return Ok(());
38        }
39        self.custom_policy.validate_slot(key, slot)
40    }
41
42    fn validate_reserved_slot(
43        &self,
44        key: &StableKey,
45        slot: &MemoryManagerSlot,
46    ) -> Result<(), Self::Error> {
47        if key.as_str() == IC_MEMORY_LEDGER_STABLE_KEY {
48            return Ok(());
49        }
50        self.custom_policy.validate_reserved_slot(key, slot)
51    }
52}
53
54///
55/// GenericAllocationPolicy
56///
57/// Built-in bootstrap policy for hosts needing no additional application checks.
58/// The runtime enforces host namespace grants, the common pool and governance;
59/// this policy adds no application-specific restrictions. Passing it directly
60/// to allocation validation outside the runtime does not enforce host pool admission.
61///
62/// Use with configured bootstrap when the host does not require a custom
63/// policy. It retains the built-in policy identity and does not authorize
64/// replacing a different policy already bound to the runtime.
65///
66pub struct GenericAllocationPolicy;
67
68impl AllocationPolicy for GenericAllocationPolicy {
69    type Error = Infallible;
70
71    fn validate_key(&self, _key: &StableKey) -> Result<(), Self::Error> {
72        Ok(())
73    }
74
75    fn validate_slot(
76        &self,
77        _key: &StableKey,
78        _slot: &MemoryManagerSlot,
79    ) -> Result<(), Self::Error> {
80        Ok(())
81    }
82
83    fn validate_reserved_slot(
84        &self,
85        _key: &StableKey,
86        _slot: &MemoryManagerSlot,
87    ) -> Result<(), Self::Error> {
88        Ok(())
89    }
90}
91
92impl RuntimeBootstrapPolicy for GenericAllocationPolicy {
93    fn runtime_bootstrap_identity(&self) -> Result<PolicyIdentity, PolicyIdentityError> {
94        PolicyIdentity::new("ic-memory.noop-policy", 1)
95    }
96}