Skip to main content

VerbRegistryBuilder

Struct VerbRegistryBuilder 

Source
pub struct VerbRegistryBuilder { /* private fields */ }
Expand description

Builder for constructing a VerbRegistry.

Packs are registered here; once .build() is called the registry is immutable and cheaply cloneable.

Implementations§

Source§

impl VerbRegistryBuilder

Source

pub fn new() -> Self

Create a builder with no packs, AllowAllGate, and the local namespace as default.

Source

pub fn with_visible_namespaces(&mut self, ns: Vec<Namespace>) -> &mut Self

Set the operator-configured read-visibility set (ADR-007 Rev 4 Rule 3b).

On the default (no explicit namespace= param) dispatch path, reads fan out over ['local'] ∪ ns. Writes remain pinned to 'local'. An explicit namespace= request parameter is a precise single-namespace escape and is not widened by this set. A cloud gate may also consult the list as policy input at its own layer.

Source

pub fn with_actor_id(&mut self, actor_id: Option<String>) -> &mut Self

Set the configured actor identity label (ADR-057).

When set, the dispatch path mints tokens carrying this actor so that comm.inbox applies the to_actor filter for directed delivery. When None (default), tokens carry ActorRef::anonymous() and inbox falls back to party-line behavior.

Source

pub fn register<P: Pack + PackRuntime + 'static>( &mut self, pack: P, ) -> &mut Self

Register a pack. The bound P: Pack + PackRuntime ensures the pack declares vocabulary via Pack consts alongside runtime dispatch.

This is the untrusted path: reachable from any external pack crate, so the pack registered here is never eligible for admission-degrade under VerbRegistry::admission_degrade_safe, regardless of what pack.name()/handler category it reports. Use register_boxed (composition root) or register_trusted (tests) for a pack the caller actually vouches for.

Source

pub fn register_mounted( &mut self, pack: Box<dyn PackRuntime>, ) -> Result<&mut Self, RuntimeError>

Register an owned mounted namespace without native-pack trust privileges.

Source

pub fn register_resolver( &mut self, name: impl Into<String>, resolver: Box<dyn PackByIdResolver>, ) -> &mut Self

Register a by-ID resolver for a pack that owns private SQL tables.

Packs that implement PackByIdResolver call this during their boot path so that get(id) and delete(id) can reach their records.

Source

pub fn with_gate(&mut self, gate: GateRef) -> &mut Self

Set the authorization gate consulted on every dispatch.

Defaults to AllowAllGate if not set. Deny is authoritative — a deny decision aborts dispatch with RuntimeError::PermissionDenied. Gate infrastructure errors abort dispatch with RuntimeError::GateUnavailable.

Source

pub fn with_default_namespace(&mut self, ns: impl Into<String>) -> &mut Self

Set the namespace surfaced to the gate when a verb does not carry an explicit namespace argument. Transports should plumb the runtime’s default_namespace so the gate’s input.namespace always reflects the operation’s true tenant.

Source

pub fn with_event_store(&mut self, store: Arc<dyn EventStore>) -> &mut Self

Set the EventStore used to persist audit events.

When configured, every gate check appends one Event (substrate = Event, outcome = Success on allow, Denied on deny, or Error on gate unavailability) in addition to the tracing::info! emission.

Callers that do not set this field continue to use tracing-only emission (the v0.2 default), except git.digest: its successful response carries a durable receipt and therefore fails safely when no store is configured.

Source

pub fn with_runtime_event_store( &mut self, runtime: &KhiveRuntime, ) -> Result<&mut Self, RuntimeError>

Configure the registry’s trusted audit sink from a runtime.

Registry audit constructors stamp namespace and actor directly from each resolved GateRequest, including per-request daemon identity overrides. This deliberately uses the runtime’s undecorated sink: the public token-scoped KhiveRuntime::events decorator would otherwise replace every per-request stamp with the single actor that happened to construct the registry.

The sink is resolved during Self::build using the final default namespace, so the order of namespace and sink configuration does not change its read scope. Sink initialization errors are returned by build: a serving registry never silently drops a configured runtime audit sink. Metadata builds and explicit replacement sinks do not open this sink.

Source

pub fn with_audit_batch_config(&mut self, config: AuditBatchConfig) -> &mut Self

Override the ADR-133 audit-batch seam’s tunables, applied when build() lazily constructs the batch from event_store. None (the default) uses AuditBatchConfig::default(). Exposed for tests that need to force a small max_pending_rows or a short admission_deadline to exercise admission-pressure paths deterministically (#2117, #2147, #2208, #2217).

Source

pub fn with_read_only_audit_store(&mut self) -> &mut Self

Mark audit persistence unavailable because its backend is read-only.

No EventStore is retained, so dispatch never attempts a write that is known to fail. Successful request entries expose a machine-readable advisory without changing their canonical verb result shape.

Source

pub fn with_dispatch_hook(&mut self, hook: Arc<dyn DispatchHook>) -> &mut Self

Register a post-dispatch hook.

When set, every successful pack dispatch calls hook.on_dispatch(view) with a synthetic EventView describing the verb outcome. Its observations vector is empty; callers that need persisted provenance must load it explicitly. The hook is opt-in: registries without a hook incur zero overhead on the dispatch hot path.

Brain pack uses this as a best-effort in-memory update path. Errors from on_dispatch are logged via tracing::warn! and never propagated.

Source

pub fn build(self) -> Result<VerbRegistry, RuntimeError>

Consume the builder and produce an immutable, cloneable registry.

Performs a topological sort of packs using Kahn’s algorithm. Returns an error if any declared dependency is missing from the loaded pack set, or if a circular dependency is detected.

Source

pub fn build_metadata(self) -> Result<PackMetadataRegistry, RuntimeError>

Inspect pack metadata without activating any registered pack. The result exposes no dispatch, preparation hooks, or serving-registry conversion.

Trait Implementations§

Source§

impl Default for VerbRegistryBuilder

Source§

fn default() -> Self

Returns the “default value” for a type. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more