Skip to main content

Runtime

Struct Runtime 

Source
pub struct Runtime { /* private fields */ }
Expand description

One native VSH engine instance with no process-global execution lock.

Implementations§

Source§

impl Runtime

Source

pub fn open(config: RuntimeConfig) -> Result<Self, VshError>

Open one capability-rooted runtime and recover durable interrupted commits.

§Errors

Returns an error when blob storage, workspace capability setup, recovery, or fail-closed recovery conflict handling fails.

Examples found in repository?
examples/native_benchmark.rs (lines 355-357)
354fn open_runtime(root: &Path, worker: &Path) -> Result<Runtime, Box<dyn Error>> {
355    Ok(Runtime::open(
356        RuntimeConfig::new(root).with_worker_path(worker),
357    )?)
358}
More examples
Hide additional examples
examples/staged_release.rs (line 36)
29fn main() -> Result<(), Box<dyn Error>> {
30    let workspace = Workspace::new()?;
31    fs::create_dir(workspace.0.join("templates"))?;
32    fs::write(
33        workspace.0.join("templates/service.toml"),
34        b"channel = \"dev\"\n",
35    )?;
36    let runtime = Runtime::open(RuntimeConfig::new(&workspace.0))?;
37    let code = include_str!("staged_release.monty");
38    let preview = runtime.preview(RunRequest::new(code).with_detail(ReceiptDetail::Full))?;
39    assert!(matches!(
40        preview.decision,
41        RuntimeDecision::PendingApproval(_)
42    ));
43    assert_eq!(preview.changed_paths, 3);
44    assert!(!workspace.0.join("release").exists());
45    assert_eq!(
46        preview
47            .changes
48            .iter()
49            .map(|entry| entry.path.as_str())
50            .collect::<Vec<_>>(),
51        ["release", "release/README.txt", "release/app.toml"]
52    );
53    let now = u64::try_from(SystemTime::now().duration_since(UNIX_EPOCH)?.as_millis())?;
54    // A rename is a semantic risk even if it only rearranges generated files.
55    // Production code must authenticate a reviewer before this trusted call.
56    runtime.approve(
57        preview.transaction,
58        PrincipalId::digest_label("fixture-reviewer"),
59        now,
60        now + 30_000,
61    )?;
62    let committed = runtime.commit(preview.transaction, now)?;
63    assert_eq!(committed.transaction, preview.transaction);
64    assert!(committed.commit.is_some());
65    assert_eq!(
66        fs::read_to_string(workspace.0.join("release/app.toml"))?,
67        "channel = \"stable\"\n"
68    );
69    assert_eq!(
70        fs::read_to_string(workspace.0.join("release/README.txt"))?,
71        "channel=stable\n"
72    );
73    assert!(!workspace.0.join("release/service.toml").exists());
74    println!(
75        "Committed {} reviewed paths: {}",
76        committed.changed_paths, committed.transaction
77    );
78    Ok(())
79}
Source

pub const fn startup_recovery(&self) -> &RecoveryReport

Return the startup recovery work completed before accepting requests.

Source

pub fn run(&self, request: RunRequest<'_>) -> Result<Receipt, VshError>

Execute, evaluate, and optionally auto-commit one exact transaction.

§Errors

Returns a typed error for snapshot, execution, diff, state, binding, reservation, revalidation, commit, or recovery failures. Deterministic policy denial is a successful receipt and never reaches the committer.

Source

pub fn preview(&self, request: RunRequest<'_>) -> Result<Receipt, VshError>

Force preview-only behavior regardless of the request’s mode field.

§Errors

Returns the same typed failures as Self::run.

Examples found in repository?
examples/native_benchmark.rs (line 198)
196fn sample(runtime: &Runtime, code: &str, intent: &str) -> Result<Sample, Box<dyn Error>> {
197    let started = Instant::now();
198    let receipt = runtime.preview(RunRequest::new(code).with_intent(intent))?;
199    let wall_ns = elapsed_ns(started);
200    if receipt.state == TransactionState::AutoApproved
201        && !runtime.discard_preview(receipt.transaction)?
202    {
203        return Err(io::Error::other("runtime did not retain its auto-approved preview").into());
204    }
205    Ok(Sample {
206        wall_ns,
207        internal_ns: receipt.timings.total_ns,
208        stages: receipt.timings.into(),
209        state: receipt.state,
210        changed_paths: u64::try_from(receipt.changed_paths).unwrap_or(u64::MAX),
211    })
212}
More examples
Hide additional examples
examples/staged_release.rs (line 38)
29fn main() -> Result<(), Box<dyn Error>> {
30    let workspace = Workspace::new()?;
31    fs::create_dir(workspace.0.join("templates"))?;
32    fs::write(
33        workspace.0.join("templates/service.toml"),
34        b"channel = \"dev\"\n",
35    )?;
36    let runtime = Runtime::open(RuntimeConfig::new(&workspace.0))?;
37    let code = include_str!("staged_release.monty");
38    let preview = runtime.preview(RunRequest::new(code).with_detail(ReceiptDetail::Full))?;
39    assert!(matches!(
40        preview.decision,
41        RuntimeDecision::PendingApproval(_)
42    ));
43    assert_eq!(preview.changed_paths, 3);
44    assert!(!workspace.0.join("release").exists());
45    assert_eq!(
46        preview
47            .changes
48            .iter()
49            .map(|entry| entry.path.as_str())
50            .collect::<Vec<_>>(),
51        ["release", "release/README.txt", "release/app.toml"]
52    );
53    let now = u64::try_from(SystemTime::now().duration_since(UNIX_EPOCH)?.as_millis())?;
54    // A rename is a semantic risk even if it only rearranges generated files.
55    // Production code must authenticate a reviewer before this trusted call.
56    runtime.approve(
57        preview.transaction,
58        PrincipalId::digest_label("fixture-reviewer"),
59        now,
60        now + 30_000,
61    )?;
62    let committed = runtime.commit(preview.transaction, now)?;
63    assert_eq!(committed.transaction, preview.transaction);
64    assert!(committed.commit.is_some());
65    assert_eq!(
66        fs::read_to_string(workspace.0.join("release/app.toml"))?,
67        "channel = \"stable\"\n"
68    );
69    assert_eq!(
70        fs::read_to_string(workspace.0.join("release/README.txt"))?,
71        "channel=stable\n"
72    );
73    assert!(!workspace.0.join("release/service.toml").exists());
74    println!(
75        "Committed {} reviewed paths: {}",
76        committed.changed_paths, committed.transaction
77    );
78    Ok(())
79}
Source

pub fn discard_preview( &self, transaction: TransactionId, ) -> Result<bool, VshError>

Forget one process-local auto-approved preview without mutating the host.

Durable approval-required artifacts are never removed by this method. false means this runtime did not retain the supplied preview.

§Errors

Returns an error only when the bounded pending-artifact lock was poisoned.

Examples found in repository?
examples/native_benchmark.rs (line 201)
196fn sample(runtime: &Runtime, code: &str, intent: &str) -> Result<Sample, Box<dyn Error>> {
197    let started = Instant::now();
198    let receipt = runtime.preview(RunRequest::new(code).with_intent(intent))?;
199    let wall_ns = elapsed_ns(started);
200    if receipt.state == TransactionState::AutoApproved
201        && !runtime.discard_preview(receipt.transaction)?
202    {
203        return Err(io::Error::other("runtime did not retain its auto-approved preview").into());
204    }
205    Ok(Sample {
206        wall_ns,
207        internal_ns: receipt.timings.total_ns,
208        stages: receipt.timings.into(),
209        state: receipt.state,
210        changed_paths: u64::try_from(receipt.changed_paths).unwrap_or(u64::MAX),
211    })
212}
Source

pub fn approve( &self, transaction: TransactionId, principal: PrincipalId, issued_at_unix_ms: u64, expires_at_unix_ms: u64, ) -> Result<TransactionRecord, VshError>

Bind an independent, expiring approval to one exact pending transaction.

§Errors

Returns an error for an invalid time window, missing transaction, mismatched binding, wrong state, or internal artifact-state mismatch.

Examples found in repository?
examples/staged_release.rs (lines 56-61)
29fn main() -> Result<(), Box<dyn Error>> {
30    let workspace = Workspace::new()?;
31    fs::create_dir(workspace.0.join("templates"))?;
32    fs::write(
33        workspace.0.join("templates/service.toml"),
34        b"channel = \"dev\"\n",
35    )?;
36    let runtime = Runtime::open(RuntimeConfig::new(&workspace.0))?;
37    let code = include_str!("staged_release.monty");
38    let preview = runtime.preview(RunRequest::new(code).with_detail(ReceiptDetail::Full))?;
39    assert!(matches!(
40        preview.decision,
41        RuntimeDecision::PendingApproval(_)
42    ));
43    assert_eq!(preview.changed_paths, 3);
44    assert!(!workspace.0.join("release").exists());
45    assert_eq!(
46        preview
47            .changes
48            .iter()
49            .map(|entry| entry.path.as_str())
50            .collect::<Vec<_>>(),
51        ["release", "release/README.txt", "release/app.toml"]
52    );
53    let now = u64::try_from(SystemTime::now().duration_since(UNIX_EPOCH)?.as_millis())?;
54    // A rename is a semantic risk even if it only rearranges generated files.
55    // Production code must authenticate a reviewer before this trusted call.
56    runtime.approve(
57        preview.transaction,
58        PrincipalId::digest_label("fixture-reviewer"),
59        now,
60        now + 30_000,
61    )?;
62    let committed = runtime.commit(preview.transaction, now)?;
63    assert_eq!(committed.transaction, preview.transaction);
64    assert!(committed.commit.is_some());
65    assert_eq!(
66        fs::read_to_string(workspace.0.join("release/app.toml"))?,
67        "channel = \"stable\"\n"
68    );
69    assert_eq!(
70        fs::read_to_string(workspace.0.join("release/README.txt"))?,
71        "channel=stable\n"
72    );
73    assert!(!workspace.0.join("release/service.toml").exists());
74    println!(
75        "Committed {} reviewed paths: {}",
76        committed.changed_paths, committed.transaction
77    );
78    Ok(())
79}
Source

pub fn commit( &self, transaction: TransactionId, now_unix_ms: u64, ) -> Result<Receipt, VshError>

Consume the single-use reservation and commit one previewed transaction.

§Errors

Returns an error for missing artifacts, expired approval, replay, stale host dependencies, commit/recovery failures, or internal binding mismatch.

Examples found in repository?
examples/staged_release.rs (line 62)
29fn main() -> Result<(), Box<dyn Error>> {
30    let workspace = Workspace::new()?;
31    fs::create_dir(workspace.0.join("templates"))?;
32    fs::write(
33        workspace.0.join("templates/service.toml"),
34        b"channel = \"dev\"\n",
35    )?;
36    let runtime = Runtime::open(RuntimeConfig::new(&workspace.0))?;
37    let code = include_str!("staged_release.monty");
38    let preview = runtime.preview(RunRequest::new(code).with_detail(ReceiptDetail::Full))?;
39    assert!(matches!(
40        preview.decision,
41        RuntimeDecision::PendingApproval(_)
42    ));
43    assert_eq!(preview.changed_paths, 3);
44    assert!(!workspace.0.join("release").exists());
45    assert_eq!(
46        preview
47            .changes
48            .iter()
49            .map(|entry| entry.path.as_str())
50            .collect::<Vec<_>>(),
51        ["release", "release/README.txt", "release/app.toml"]
52    );
53    let now = u64::try_from(SystemTime::now().duration_since(UNIX_EPOCH)?.as_millis())?;
54    // A rename is a semantic risk even if it only rearranges generated files.
55    // Production code must authenticate a reviewer before this trusted call.
56    runtime.approve(
57        preview.transaction,
58        PrincipalId::digest_label("fixture-reviewer"),
59        now,
60        now + 30_000,
61    )?;
62    let committed = runtime.commit(preview.transaction, now)?;
63    assert_eq!(committed.transaction, preview.transaction);
64    assert!(committed.commit.is_some());
65    assert_eq!(
66        fs::read_to_string(workspace.0.join("release/app.toml"))?,
67        "channel = \"stable\"\n"
68    );
69    assert_eq!(
70        fs::read_to_string(workspace.0.join("release/README.txt"))?,
71        "channel=stable\n"
72    );
73    assert!(!workspace.0.join("release/service.toml").exists());
74    println!(
75        "Committed {} reviewed paths: {}",
76        committed.changed_paths, committed.transaction
77    );
78    Ok(())
79}
Source

pub fn recover(&self) -> Result<RecoveryReport, VshError>

Recover all durable commit artifacts under this runtime’s capability root.

§Errors

Returns a typed commit/recovery error for corrupt or unsafe journals.

Source

pub fn transaction( &self, transaction: TransactionId, ) -> Result<TransactionRecord, VshError>

Return one persisted lifecycle record.

§Errors

Returns VshError::Store when the transaction does not exist.

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> Conv for T

Source§

fn conv<T>(self) -> T
where Self: Into<T>,

Converts self into T using Into<T>. Read more
Source§

impl<T> FmtForward for T

Source§

fn fmt_binary(self) -> FmtBinary<Self>
where Self: Binary,

Causes self to use its Binary implementation when Debug-formatted.
Source§

fn fmt_display(self) -> FmtDisplay<Self>
where Self: Display,

Causes self to use its Display implementation when Debug-formatted.
Source§

fn fmt_lower_exp(self) -> FmtLowerExp<Self>
where Self: LowerExp,

Causes self to use its LowerExp implementation when Debug-formatted.
Source§

fn fmt_lower_hex(self) -> FmtLowerHex<Self>
where Self: LowerHex,

Causes self to use its LowerHex implementation when Debug-formatted.
Source§

fn fmt_octal(self) -> FmtOctal<Self>
where Self: Octal,

Causes self to use its Octal implementation when Debug-formatted.
Source§

fn fmt_pointer(self) -> FmtPointer<Self>
where Self: Pointer,

Causes self to use its Pointer implementation when Debug-formatted.
Source§

fn fmt_upper_exp(self) -> FmtUpperExp<Self>
where Self: UpperExp,

Causes self to use its UpperExp implementation when Debug-formatted.
Source§

fn fmt_upper_hex(self) -> FmtUpperHex<Self>
where Self: UpperHex,

Causes self to use its UpperHex implementation when Debug-formatted.
Source§

fn fmt_list(self) -> FmtList<Self>
where &'a Self: for<'a> IntoIterator,

Formats each item in a sequence. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> Pipe for T
where T: ?Sized,

Source§

fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> R
where Self: Sized,

Pipes by value. This is generally the method you want to use. Read more
Source§

fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> R
where R: 'a,

Borrows self and passes that borrow into the pipe function. Read more
Source§

fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> R
where R: 'a,

Mutably borrows self and passes that borrow into the pipe function. Read more
Source§

fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
where Self: Borrow<B>, B: 'a + ?Sized, R: 'a,

Borrows self, then passes self.borrow() into the pipe function. Read more
Source§

fn pipe_borrow_mut<'a, B, R>( &'a mut self, func: impl FnOnce(&'a mut B) -> R, ) -> R
where Self: BorrowMut<B>, B: 'a + ?Sized, R: 'a,

Mutably borrows self, then passes self.borrow_mut() into the pipe function. Read more
Source§

fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
where Self: AsRef<U>, U: 'a + ?Sized, R: 'a,

Borrows self, then passes self.as_ref() into the pipe function.
Source§

fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
where Self: AsMut<U>, U: 'a + ?Sized, R: 'a,

Mutably borrows self, then passes self.as_mut() into the pipe function.
Source§

fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
where Self: Deref<Target = T>, T: 'a + ?Sized, R: 'a,

Borrows self, then passes self.deref() into the pipe function.
Source§

fn pipe_deref_mut<'a, T, R>( &'a mut self, func: impl FnOnce(&'a mut T) -> R, ) -> R
where Self: DerefMut<Target = T> + Deref, T: 'a + ?Sized, R: 'a,

Mutably borrows self, then passes self.deref_mut() into the pipe function.
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Tap for T

Source§

fn tap(self, func: impl FnOnce(&Self)) -> Self

Immutable access to a value. Read more
Source§

fn tap_mut(self, func: impl FnOnce(&mut Self)) -> Self

Mutable access to a value. Read more
Source§

fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
where Self: Borrow<B>, B: ?Sized,

Immutable access to the Borrow<B> of a value. Read more
Source§

fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
where Self: BorrowMut<B>, B: ?Sized,

Mutable access to the BorrowMut<B> of a value. Read more
Source§

fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
where Self: AsRef<R>, R: ?Sized,

Immutable access to the AsRef<R> view of a value. Read more
Source§

fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
where Self: AsMut<R>, R: ?Sized,

Mutable access to the AsMut<R> view of a value. Read more
Source§

fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
where Self: Deref<Target = T>, T: ?Sized,

Immutable access to the Deref::Target of a value. Read more
Source§

fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
where Self: DerefMut<Target = T> + Deref, T: ?Sized,

Mutable access to the Deref::Target of a value. Read more
Source§

fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self

Calls .tap() only in debug builds, and is erased in release builds.
Source§

fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self

Calls .tap_mut() only in debug builds, and is erased in release builds.
Source§

fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
where Self: Borrow<B>, B: ?Sized,

Calls .tap_borrow() only in debug builds, and is erased in release builds.
Source§

fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
where Self: BorrowMut<B>, B: ?Sized,

Calls .tap_borrow_mut() only in debug builds, and is erased in release builds.
Source§

fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
where Self: AsRef<R>, R: ?Sized,

Calls .tap_ref() only in debug builds, and is erased in release builds.
Source§

fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
where Self: AsMut<R>, R: ?Sized,

Calls .tap_ref_mut() only in debug builds, and is erased in release builds.
Source§

fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
where Self: Deref<Target = T>, T: ?Sized,

Calls .tap_deref() only in debug builds, and is erased in release builds.
Source§

fn tap_deref_mut_dbg<T>(self, func: impl FnOnce(&mut T)) -> Self
where Self: DerefMut<Target = T> + Deref, T: ?Sized,

Calls .tap_deref_mut() only in debug builds, and is erased in release builds.
Source§

impl<T> TryConv for T

Source§

fn try_conv<T>(self) -> Result<T, Self::Error>
where Self: TryInto<T>,

Attempts to convert self into T using TryInto<T>. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.