pub struct ChannelIngestCapability { /* private fields */ }Expand description
Factory for creating pack instances registered via inventory at link time.
Each pack crate submits a &'static dyn PackFactory wrapped in a
PackRegistration; the binary’s linker collects them all into a single
slice iterable at runtime.
Implementors must be Send + Sync + 'static because the registry is built
once and shared across async tasks.
Possession-bounded capability for the trusted channel-ingest note path.
Constructible only inside khive-runtime (the field is private), and
granted during pack registration exclusively to factories named in
CHANNEL_INGEST_CAPABLE_PACKS. Every call to
crate::KhiveRuntime::try_create_note_as_trusted_ingest must present a
reference to one, so the set of callers able to establish transport-owned
message properties is bounded by possession at the composition root, not
by a documentation prohibition. Two ways to obtain one: registering
through PackRegistry::register_packs/register_packs_with_runtimes
under the comm name (the allowlisted, automatic path), or a composition
root that builds packs directly calling
ChannelIngestCapability::grant_for_direct_composition and passing the
result to crate::PackRuntime::accept_channel_ingest_capability (or a
pack’s constructor variant that does so) itself. The residual trust
assumption is unchanged either way: whoever assembles the
VerbRegistryBuilder already decides which packs are wired in and already
holds a KhiveRuntime, so minting the grant explicitly carries no more
privilege than that composition already had by choosing to register comm
at all.
Implementations§
Source§impl ChannelIngestCapability
impl ChannelIngestCapability
Sourcepub fn grant_for_direct_composition() -> Self
pub fn grant_for_direct_composition() -> Self
Mint a capability for a composition root that constructs
channel-transport packs directly, bypassing
PackRegistry::register_packs (which grants this automatically).
See the type-level doc for the trust argument: this carries no more
privilege than the caller already has by virtue of holding a
KhiveRuntime and choosing to wire the pack in.
Auto Trait Implementations§
impl Freeze for ChannelIngestCapability
impl RefUnwindSafe for ChannelIngestCapability
impl Send for ChannelIngestCapability
impl Sync for ChannelIngestCapability
impl Unpin for ChannelIngestCapability
impl UnsafeUnpin for ChannelIngestCapability
impl UnwindSafe for ChannelIngestCapability
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more