pub fn check_toolset_action(
action: &str,
capabilities: &CapabilitySet,
allowed_tools: &[String],
) -> Result<&'static str, ToolsetRuntimeError>Expand description
Four-part enforcement check for a toolset action.
Returns the &'static str registry tool name T that the action resolves
to when ALL four parts pass. The caller MUST route through the returned
constant — NOT through any toolset-supplied string.
§Four-part logic
(a) The action name resolves — via a CLOSED lookup against the matrix —
to a registry tool-name constant T (&'static str).
(b) T is in the grant set of some capability C.
(c) C is in the toolset’s declared CapabilitySet (from the pin).
(d) T is in the toolset’s allowed_tools (intersective narrowing — can
only SUBTRACT from the capability grant, never add). When
allowed_tools is empty the narrowing is vacuously satisfied.
SIGNING IS STRUCTURALLY EXCLUDED: the matrix contains no signing/key/policy tool, so even a toolset with all capabilities declared can never reach a signer via the ungated path.
The dispatch gate of the routed tool (dispatch_gate) runs AFTER this
check — the toolset gate is ADDITIVE, never substitutive.
§Errors
Returns a distinct ToolsetRuntimeError variant for each failure mode:
ToolsetRuntimeError::UnknownToolsetAction— part (a) failed.ToolsetRuntimeError::CapabilityNotDeclared— part (c) failed (the tool exists in the matrix but no granting capability is declared by this toolset).ToolsetRuntimeError::ToolNotAllowed— part (d) failed (allowed_toolsnarrowing excluded the tool).