pub struct ToolContext {
pub local: Arc<dyn LocalBackend>,
pub redactor: Redactor,
pub max_result_bytes: usize,
pub identity: Identity,
pub cli_version: Option<Version>,
pub paths: PathPolicy,
pub devices: DeviceCache,
pub max_tier: Tier,
/* private fields */
}Expand description
Everything a handler may reach.
Fields§
§local: Arc<dyn LocalBackend>The local node. Present even when the local surface is disabled, in which case it is a backend that reports the binary as missing.
redactor: RedactorRemoves secrets from anything on its way out.
max_result_bytes: usizeThe size above which a result is refused rather than truncated.
identity: IdentityWho we are on the tailnet, when we could find out.
cli_version: Option<Version>The version the local CLI reports, when it could be read.
paths: PathPolicyWhere the tools that take a path are allowed to write.
devices: DeviceCacheThe tailnet’s device list, cached for a few seconds.
The only mutable state a session holds. It exists because two features ask the same question repeatedly — which device did you mean, and which could you have meant — and neither should cost a request each time.
max_tier: TierThe most dangerous tier this session permits.
The gate is what normally applies this, before a handler is reached, so no typed tool has to look at it. The passthrough does: its row carries a floor rather than its real tier, so it is the one tool that has to make the same decision the gate makes, against the command it was given.
Implementations§
Source§impl ToolContext
impl ToolContext
Sourcepub async fn tailnet_devices(&self) -> ToolResult<Arc<[Device]>>
pub async fn tailnet_devices(&self) -> ToolResult<Arc<[Device]>>
The tailnet’s devices, from the cache when it is warm enough.
The error is the one the caller would have got anyway: without a credential this is the missing-credential sentence, and a control-plane failure is reported as itself rather than as an absent device.
Sourcepub async fn names_us(&self, target: &str) -> bool
pub async fn names_us(&self, target: &str) -> bool
Whether target names the node this server runs on.
Two sources, because the control plane accepts two identifiers for the same device and the local node only knows one of them. Status gives the node id, the addresses and the name, and is re-read as it ages. The numeric id has to be asked of the control plane — and is, only when the answer could turn on it: a target that is not all digits is not a numeric id, so the overwhelming majority of calls cost nothing extra, and the one that does costs one request per process (Q87).
Sourcepub fn tailnet(&self) -> ToolResult<&Client>
pub fn tailnet(&self) -> ToolResult<&Client>
The control plane, or the reason there is none.