pub struct VerbRegistryBuilder { /* private fields */ }Expand description
Builder for constructing a VerbRegistry.
Packs are registered here; once .build() is called the registry is
immutable and cheaply cloneable.
Implementations§
Source§impl VerbRegistryBuilder
impl VerbRegistryBuilder
Sourcepub fn new() -> Self
pub fn new() -> Self
Create a builder with no packs, AllowAllGate, and the local namespace as default.
Sourcepub fn with_visible_namespaces(&mut self, ns: Vec<Namespace>) -> &mut Self
pub fn with_visible_namespaces(&mut self, ns: Vec<Namespace>) -> &mut Self
Set the operator-configured read-visibility set (ADR-007 Rev 4 Rule 3b).
On the default (no explicit namespace= param) dispatch path, reads fan
out over ['local'] ∪ ns. Writes remain pinned to 'local'. An explicit
namespace= request parameter is a precise single-namespace escape and
is not widened by this set. A cloud gate may also consult the list as
policy input at its own layer.
Sourcepub fn with_actor_id(&mut self, actor_id: Option<String>) -> &mut Self
pub fn with_actor_id(&mut self, actor_id: Option<String>) -> &mut Self
Set the configured actor identity label (ADR-057).
When set, the dispatch path mints tokens carrying this actor so that
comm.inbox applies the to_actor filter for directed delivery.
When None (default), tokens carry ActorRef::anonymous() and inbox
falls back to party-line behavior.
Sourcepub fn register<P: Pack + PackRuntime + 'static>(
&mut self,
pack: P,
) -> &mut Self
pub fn register<P: Pack + PackRuntime + 'static>( &mut self, pack: P, ) -> &mut Self
Register a pack. The bound P: Pack + PackRuntime ensures the pack
declares vocabulary via Pack consts alongside runtime dispatch.
This is the untrusted path: reachable from any external pack crate,
so the pack registered here is never eligible for admission-degrade
under VerbRegistry::admission_degrade_safe, regardless of what
pack.name()/handler category it reports. Use register_boxed
(composition root) or register_trusted (tests) for a pack the
caller actually vouches for.
Sourcepub fn register_mounted(
&mut self,
pack: Box<dyn PackRuntime>,
) -> Result<&mut Self, RuntimeError>
pub fn register_mounted( &mut self, pack: Box<dyn PackRuntime>, ) -> Result<&mut Self, RuntimeError>
Register an owned mounted namespace without native-pack trust privileges.
Sourcepub fn register_resolver(
&mut self,
name: impl Into<String>,
resolver: Box<dyn PackByIdResolver>,
) -> &mut Self
pub fn register_resolver( &mut self, name: impl Into<String>, resolver: Box<dyn PackByIdResolver>, ) -> &mut Self
Register a by-ID resolver for a pack that owns private SQL tables.
Packs that implement PackByIdResolver call this during their boot path
so that get(id) and delete(id) can reach their records.
Sourcepub fn with_gate(&mut self, gate: GateRef) -> &mut Self
pub fn with_gate(&mut self, gate: GateRef) -> &mut Self
Set the authorization gate consulted on every dispatch.
Defaults to AllowAllGate if not set. Deny is authoritative — a deny
decision aborts dispatch with RuntimeError::PermissionDenied. Gate
infrastructure errors abort dispatch with RuntimeError::GateUnavailable.
Sourcepub fn with_default_namespace(&mut self, ns: impl Into<String>) -> &mut Self
pub fn with_default_namespace(&mut self, ns: impl Into<String>) -> &mut Self
Set the namespace surfaced to the gate when a verb does not carry an
explicit namespace argument. Transports should plumb the runtime’s
default_namespace so the gate’s input.namespace always reflects
the operation’s true tenant.
Sourcepub fn with_event_store(&mut self, store: Arc<dyn EventStore>) -> &mut Self
pub fn with_event_store(&mut self, store: Arc<dyn EventStore>) -> &mut Self
Set the EventStore used to persist audit events.
When configured, every gate check appends one Event (substrate =
Event, outcome = Success on allow, Denied on deny, or Error on
gate unavailability) in addition to the tracing::info! emission.
Callers that do not set this field continue to use tracing-only emission
(the v0.2 default), except git.digest: its successful response carries
a durable receipt and therefore fails safely when no store is configured.
Sourcepub fn with_runtime_event_store(
&mut self,
runtime: &KhiveRuntime,
) -> Result<&mut Self, RuntimeError>
pub fn with_runtime_event_store( &mut self, runtime: &KhiveRuntime, ) -> Result<&mut Self, RuntimeError>
Configure the registry’s trusted audit sink from a runtime.
Registry audit constructors stamp namespace and actor directly from
each resolved GateRequest, including per-request daemon identity
overrides. This deliberately uses the runtime’s undecorated sink: the
public token-scoped KhiveRuntime::events decorator would otherwise
replace every per-request stamp with the single actor that happened to
construct the registry.
The sink is resolved during Self::build using the final default
namespace, so the order of namespace and sink configuration does not
change its read scope. Sink initialization errors are returned by build:
a serving registry never silently drops a configured runtime audit sink.
Metadata builds and explicit replacement sinks do not open this sink.
Sourcepub fn with_audit_batch_config(&mut self, config: AuditBatchConfig) -> &mut Self
pub fn with_audit_batch_config(&mut self, config: AuditBatchConfig) -> &mut Self
Override the ADR-133 audit-batch seam’s tunables, applied when
build() lazily constructs the batch from event_store.
None (the default) uses AuditBatchConfig::default(). Exposed for
tests that need to force a small max_pending_rows or a short
admission_deadline to exercise admission-pressure paths
deterministically (#2117, #2147, #2208, #2217).
Sourcepub fn with_read_only_audit_store(&mut self) -> &mut Self
pub fn with_read_only_audit_store(&mut self) -> &mut Self
Mark audit persistence unavailable because its backend is read-only.
No EventStore is retained, so dispatch never attempts a write that is
known to fail. Successful request entries expose a machine-readable
advisory without changing their canonical verb result shape.
Sourcepub fn with_dispatch_hook(&mut self, hook: Arc<dyn DispatchHook>) -> &mut Self
pub fn with_dispatch_hook(&mut self, hook: Arc<dyn DispatchHook>) -> &mut Self
Register a post-dispatch hook.
When set, every successful pack dispatch calls hook.on_dispatch(view)
with a synthetic EventView describing the verb outcome. Its
observations vector is empty; callers that need persisted provenance
must load it explicitly. The hook is opt-in: registries without a hook
incur zero overhead on the dispatch hot path.
Brain pack uses this as a best-effort in-memory update path. Errors from
on_dispatch are logged via tracing::warn! and never propagated.
Sourcepub fn build(self) -> Result<VerbRegistry, RuntimeError>
pub fn build(self) -> Result<VerbRegistry, RuntimeError>
Consume the builder and produce an immutable, cloneable registry.
Performs a topological sort of packs using Kahn’s algorithm. Returns an error if any declared dependency is missing from the loaded pack set, or if a circular dependency is detected.
Sourcepub fn build_metadata(self) -> Result<PackMetadataRegistry, RuntimeError>
pub fn build_metadata(self) -> Result<PackMetadataRegistry, RuntimeError>
Inspect pack metadata without activating any registered pack. The result exposes no dispatch, preparation hooks, or serving-registry conversion.
Trait Implementations§
Auto Trait Implementations§
impl !RefUnwindSafe for VerbRegistryBuilder
impl !UnwindSafe for VerbRegistryBuilder
impl Freeze for VerbRegistryBuilder
impl Send for VerbRegistryBuilder
impl Sync for VerbRegistryBuilder
impl Unpin for VerbRegistryBuilder
impl UnsafeUnpin for VerbRegistryBuilder
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more