Skip to main content

check_toolset_action

Function check_toolset_action 

Source
pub fn check_toolset_action(
    action: &str,
    capabilities: &CapabilitySet,
    allowed_tools: &[String],
) -> Result<&'static str, ToolsetRuntimeError>
Expand description

Four-part enforcement check for a toolset action.

Returns the &'static str registry tool name T that the action resolves to when ALL four parts pass. The caller MUST route through the returned constant — NOT through any toolset-supplied string.

§Four-part logic

(a) The action name resolves — via a CLOSED lookup against the matrix — to a registry tool-name constant T (&'static str).

(b) T is in the grant set of some capability C.

(c) C is in the toolset’s declared CapabilitySet (from the pin).

(d) T is in the toolset’s allowed_tools (intersective narrowing — can only SUBTRACT from the capability grant, never add). When allowed_tools is empty the narrowing is vacuously satisfied.

SIGNING IS STRUCTURALLY EXCLUDED: the matrix contains no signing/key/policy tool, so even a toolset with all capabilities declared can never reach a signer via the ungated path.

The dispatch gate of the routed tool (dispatch_gate) runs AFTER this check — the toolset gate is ADDITIVE, never substitutive.

§Errors

Returns a distinct ToolsetRuntimeError variant for each failure mode: