Skip to main content

Module scope

Module scope 

Source
Expand description

Scope records: owned identity records the daemon holds for sessions.

A scope is identified by (owner, ref). The owner is the module whose own registered connection synced it, never a value in the request, and the ref is an opaque string unique within that owner only. The design is docs/designs/daemon-scopes.md; the wire shapes here are the owner-facing half of it (scope.sync, scope.describe).

Every record type refuses unknown fields. A field this daemon does not know may be one that narrows authority in a later version (a carrier’s target list, say), and silently dropping it would widen what the scope grants, so an owner sending one is told its body is malformed instead.

Structs§

ScopeAttributes
The attributes the daemon stamps without interpreting. Both grant authority, so only an owner listed in the daemon’s scope_authority_owners may set either.
ScopeCarrier
Who, besides the owner, may open routes under a scope.
ScopeEnded
A scope of the syncing owner that the sync ended, by removal or by a higher epoch for the same ref.
ScopeParent
A link from a scope to another scope, pinned to that scope’s session by its epoch.
ScopeRecord
One scope as its owner registers it in scope.sync.
ScopeRecordResult
The per-record result in a scope.sync reply, in request order.
ScopeSelector
The scope a route.open asks to be admitted under.
ScopeStamp
The fields the daemon stamps for a live scope.

Enums§

ParentState
The state of a scope’s parent link.
ScopeKind
What a scope stands for. Closed, and fixed for the life of one scope_epoch: a different kind needs a new epoch, which ends the old scope.
ScopeRecordOutcome
What a scope.sync did with one record.
ScopeStatus
scope.describe’s answer about one (owner, ref).

Constants§

CAP_SCOPES_V1
The server.describe capability a daemon advertises when it admits routes under scopes. A carrier that needs a scoped route and does not see it fails the call (scope_unsupported) instead of opening an unscoped route.
MAX_CARRIER_TARGETS
Most modules one targeted carrier entry may list.
MAX_LIVE_SCOPES_PER_OWNER
Most live scopes one owner may hold. A sync naming more is refused whole.
MAX_SCOPE_ATTRIBUTE_BYTES
Most bytes one scope’s attributes may take, measured as compact JSON. A sync carrying a larger record is refused whole.
MAX_SCOPE_TOMBSTONES_PER_OWNER
Most ended scopes the daemon remembers per owner. The oldest is forgotten first, and reaching the bound never refuses a sync.
SCOPE_DESCRIBE_OP
Module-to-subc op that reads one scope’s current state.
SCOPE_SYNC_OP
Module-to-subc op that registers an owner’s full scope set.