pub struct Runtime { /* private fields */ }Expand description
One native VSH engine instance with no process-global execution lock.
Implementations§
Source§impl Runtime
impl Runtime
Sourcepub fn open(config: RuntimeConfig) -> Result<Self, VshError>
pub fn open(config: RuntimeConfig) -> Result<Self, VshError>
Open one capability-rooted runtime and recover durable interrupted commits.
§Errors
Returns an error when blob storage, workspace capability setup, recovery, or fail-closed recovery conflict handling fails.
Examples found in repository?
More examples
29fn main() -> Result<(), Box<dyn Error>> {
30 let workspace = Workspace::new()?;
31 fs::create_dir(workspace.0.join("templates"))?;
32 fs::write(
33 workspace.0.join("templates/service.toml"),
34 b"channel = \"dev\"\n",
35 )?;
36 let runtime = Runtime::open(RuntimeConfig::new(&workspace.0))?;
37 let code = include_str!("staged_release.monty");
38 let preview = runtime.preview(RunRequest::new(code).with_detail(ReceiptDetail::Full))?;
39 assert!(matches!(
40 preview.decision,
41 RuntimeDecision::PendingApproval(_)
42 ));
43 assert_eq!(preview.changed_paths, 3);
44 assert!(!workspace.0.join("release").exists());
45 assert_eq!(
46 preview
47 .changes
48 .iter()
49 .map(|entry| entry.path.as_str())
50 .collect::<Vec<_>>(),
51 ["release", "release/README.txt", "release/app.toml"]
52 );
53 let now = u64::try_from(SystemTime::now().duration_since(UNIX_EPOCH)?.as_millis())?;
54 // A rename is a semantic risk even if it only rearranges generated files.
55 // Production code must authenticate a reviewer before this trusted call.
56 runtime.approve(
57 preview.transaction,
58 PrincipalId::digest_label("fixture-reviewer"),
59 now,
60 now + 30_000,
61 )?;
62 let committed = runtime.commit(preview.transaction, now)?;
63 assert_eq!(committed.transaction, preview.transaction);
64 assert!(committed.commit.is_some());
65 assert_eq!(
66 fs::read_to_string(workspace.0.join("release/app.toml"))?,
67 "channel = \"stable\"\n"
68 );
69 assert_eq!(
70 fs::read_to_string(workspace.0.join("release/README.txt"))?,
71 "channel=stable\n"
72 );
73 assert!(!workspace.0.join("release/service.toml").exists());
74 println!(
75 "Committed {} reviewed paths: {}",
76 committed.changed_paths, committed.transaction
77 );
78 Ok(())
79}Sourcepub const fn startup_recovery(&self) -> &RecoveryReport
pub const fn startup_recovery(&self) -> &RecoveryReport
Return the startup recovery work completed before accepting requests.
Sourcepub fn run(&self, request: RunRequest<'_>) -> Result<Receipt, VshError>
pub fn run(&self, request: RunRequest<'_>) -> Result<Receipt, VshError>
Execute, evaluate, and optionally auto-commit one exact transaction.
§Errors
Returns a typed error for snapshot, execution, diff, state, binding, reservation, revalidation, commit, or recovery failures. Deterministic policy denial is a successful receipt and never reaches the committer.
Sourcepub fn preview(&self, request: RunRequest<'_>) -> Result<Receipt, VshError>
pub fn preview(&self, request: RunRequest<'_>) -> Result<Receipt, VshError>
Force preview-only behavior regardless of the request’s mode field.
§Errors
Returns the same typed failures as Self::run.
Examples found in repository?
196fn sample(runtime: &Runtime, code: &str, intent: &str) -> Result<Sample, Box<dyn Error>> {
197 let started = Instant::now();
198 let receipt = runtime.preview(RunRequest::new(code).with_intent(intent))?;
199 let wall_ns = elapsed_ns(started);
200 if receipt.state == TransactionState::AutoApproved
201 && !runtime.discard_preview(receipt.transaction)?
202 {
203 return Err(io::Error::other("runtime did not retain its auto-approved preview").into());
204 }
205 Ok(Sample {
206 wall_ns,
207 internal_ns: receipt.timings.total_ns,
208 stages: receipt.timings.into(),
209 state: receipt.state,
210 changed_paths: u64::try_from(receipt.changed_paths).unwrap_or(u64::MAX),
211 })
212}More examples
29fn main() -> Result<(), Box<dyn Error>> {
30 let workspace = Workspace::new()?;
31 fs::create_dir(workspace.0.join("templates"))?;
32 fs::write(
33 workspace.0.join("templates/service.toml"),
34 b"channel = \"dev\"\n",
35 )?;
36 let runtime = Runtime::open(RuntimeConfig::new(&workspace.0))?;
37 let code = include_str!("staged_release.monty");
38 let preview = runtime.preview(RunRequest::new(code).with_detail(ReceiptDetail::Full))?;
39 assert!(matches!(
40 preview.decision,
41 RuntimeDecision::PendingApproval(_)
42 ));
43 assert_eq!(preview.changed_paths, 3);
44 assert!(!workspace.0.join("release").exists());
45 assert_eq!(
46 preview
47 .changes
48 .iter()
49 .map(|entry| entry.path.as_str())
50 .collect::<Vec<_>>(),
51 ["release", "release/README.txt", "release/app.toml"]
52 );
53 let now = u64::try_from(SystemTime::now().duration_since(UNIX_EPOCH)?.as_millis())?;
54 // A rename is a semantic risk even if it only rearranges generated files.
55 // Production code must authenticate a reviewer before this trusted call.
56 runtime.approve(
57 preview.transaction,
58 PrincipalId::digest_label("fixture-reviewer"),
59 now,
60 now + 30_000,
61 )?;
62 let committed = runtime.commit(preview.transaction, now)?;
63 assert_eq!(committed.transaction, preview.transaction);
64 assert!(committed.commit.is_some());
65 assert_eq!(
66 fs::read_to_string(workspace.0.join("release/app.toml"))?,
67 "channel = \"stable\"\n"
68 );
69 assert_eq!(
70 fs::read_to_string(workspace.0.join("release/README.txt"))?,
71 "channel=stable\n"
72 );
73 assert!(!workspace.0.join("release/service.toml").exists());
74 println!(
75 "Committed {} reviewed paths: {}",
76 committed.changed_paths, committed.transaction
77 );
78 Ok(())
79}Sourcepub fn discard_preview(
&self,
transaction: TransactionId,
) -> Result<bool, VshError>
pub fn discard_preview( &self, transaction: TransactionId, ) -> Result<bool, VshError>
Forget one process-local auto-approved preview without mutating the host.
Durable approval-required artifacts are never removed by this method. false
means this runtime did not retain the supplied preview.
§Errors
Returns an error only when the bounded pending-artifact lock was poisoned.
Examples found in repository?
196fn sample(runtime: &Runtime, code: &str, intent: &str) -> Result<Sample, Box<dyn Error>> {
197 let started = Instant::now();
198 let receipt = runtime.preview(RunRequest::new(code).with_intent(intent))?;
199 let wall_ns = elapsed_ns(started);
200 if receipt.state == TransactionState::AutoApproved
201 && !runtime.discard_preview(receipt.transaction)?
202 {
203 return Err(io::Error::other("runtime did not retain its auto-approved preview").into());
204 }
205 Ok(Sample {
206 wall_ns,
207 internal_ns: receipt.timings.total_ns,
208 stages: receipt.timings.into(),
209 state: receipt.state,
210 changed_paths: u64::try_from(receipt.changed_paths).unwrap_or(u64::MAX),
211 })
212}Sourcepub fn approve(
&self,
transaction: TransactionId,
principal: PrincipalId,
issued_at_unix_ms: u64,
expires_at_unix_ms: u64,
) -> Result<TransactionRecord, VshError>
pub fn approve( &self, transaction: TransactionId, principal: PrincipalId, issued_at_unix_ms: u64, expires_at_unix_ms: u64, ) -> Result<TransactionRecord, VshError>
Bind an independent, expiring approval to one exact pending transaction.
§Errors
Returns an error for an invalid time window, missing transaction, mismatched binding, wrong state, or internal artifact-state mismatch.
Examples found in repository?
29fn main() -> Result<(), Box<dyn Error>> {
30 let workspace = Workspace::new()?;
31 fs::create_dir(workspace.0.join("templates"))?;
32 fs::write(
33 workspace.0.join("templates/service.toml"),
34 b"channel = \"dev\"\n",
35 )?;
36 let runtime = Runtime::open(RuntimeConfig::new(&workspace.0))?;
37 let code = include_str!("staged_release.monty");
38 let preview = runtime.preview(RunRequest::new(code).with_detail(ReceiptDetail::Full))?;
39 assert!(matches!(
40 preview.decision,
41 RuntimeDecision::PendingApproval(_)
42 ));
43 assert_eq!(preview.changed_paths, 3);
44 assert!(!workspace.0.join("release").exists());
45 assert_eq!(
46 preview
47 .changes
48 .iter()
49 .map(|entry| entry.path.as_str())
50 .collect::<Vec<_>>(),
51 ["release", "release/README.txt", "release/app.toml"]
52 );
53 let now = u64::try_from(SystemTime::now().duration_since(UNIX_EPOCH)?.as_millis())?;
54 // A rename is a semantic risk even if it only rearranges generated files.
55 // Production code must authenticate a reviewer before this trusted call.
56 runtime.approve(
57 preview.transaction,
58 PrincipalId::digest_label("fixture-reviewer"),
59 now,
60 now + 30_000,
61 )?;
62 let committed = runtime.commit(preview.transaction, now)?;
63 assert_eq!(committed.transaction, preview.transaction);
64 assert!(committed.commit.is_some());
65 assert_eq!(
66 fs::read_to_string(workspace.0.join("release/app.toml"))?,
67 "channel = \"stable\"\n"
68 );
69 assert_eq!(
70 fs::read_to_string(workspace.0.join("release/README.txt"))?,
71 "channel=stable\n"
72 );
73 assert!(!workspace.0.join("release/service.toml").exists());
74 println!(
75 "Committed {} reviewed paths: {}",
76 committed.changed_paths, committed.transaction
77 );
78 Ok(())
79}Sourcepub fn commit(
&self,
transaction: TransactionId,
now_unix_ms: u64,
) -> Result<Receipt, VshError>
pub fn commit( &self, transaction: TransactionId, now_unix_ms: u64, ) -> Result<Receipt, VshError>
Consume the single-use reservation and commit one previewed transaction.
§Errors
Returns an error for missing artifacts, expired approval, replay, stale host dependencies, commit/recovery failures, or internal binding mismatch.
Examples found in repository?
29fn main() -> Result<(), Box<dyn Error>> {
30 let workspace = Workspace::new()?;
31 fs::create_dir(workspace.0.join("templates"))?;
32 fs::write(
33 workspace.0.join("templates/service.toml"),
34 b"channel = \"dev\"\n",
35 )?;
36 let runtime = Runtime::open(RuntimeConfig::new(&workspace.0))?;
37 let code = include_str!("staged_release.monty");
38 let preview = runtime.preview(RunRequest::new(code).with_detail(ReceiptDetail::Full))?;
39 assert!(matches!(
40 preview.decision,
41 RuntimeDecision::PendingApproval(_)
42 ));
43 assert_eq!(preview.changed_paths, 3);
44 assert!(!workspace.0.join("release").exists());
45 assert_eq!(
46 preview
47 .changes
48 .iter()
49 .map(|entry| entry.path.as_str())
50 .collect::<Vec<_>>(),
51 ["release", "release/README.txt", "release/app.toml"]
52 );
53 let now = u64::try_from(SystemTime::now().duration_since(UNIX_EPOCH)?.as_millis())?;
54 // A rename is a semantic risk even if it only rearranges generated files.
55 // Production code must authenticate a reviewer before this trusted call.
56 runtime.approve(
57 preview.transaction,
58 PrincipalId::digest_label("fixture-reviewer"),
59 now,
60 now + 30_000,
61 )?;
62 let committed = runtime.commit(preview.transaction, now)?;
63 assert_eq!(committed.transaction, preview.transaction);
64 assert!(committed.commit.is_some());
65 assert_eq!(
66 fs::read_to_string(workspace.0.join("release/app.toml"))?,
67 "channel = \"stable\"\n"
68 );
69 assert_eq!(
70 fs::read_to_string(workspace.0.join("release/README.txt"))?,
71 "channel=stable\n"
72 );
73 assert!(!workspace.0.join("release/service.toml").exists());
74 println!(
75 "Committed {} reviewed paths: {}",
76 committed.changed_paths, committed.transaction
77 );
78 Ok(())
79}Sourcepub fn prepare_commit(
&self,
transaction: TransactionId,
) -> Result<CommitPreparation, VshError>
pub fn prepare_commit( &self, transaction: TransactionId, ) -> Result<CommitPreparation, VshError>
Freeze one exact commit candidate before invoking an external handler.
No handler code runs in this method. Process-local auto-approved previews are made durable before an event is returned, so a crash can regenerate the same event from the exact transaction artifact.
§Errors
Returns a typed store, artifact, configuration, or evidence error.
Sourcepub fn resolve_commit(
&self,
preparation: &CommitPreparation,
decision: &HookDecision,
now_unix_ms: u64,
) -> Result<CommitResolution, VshError>
pub fn resolve_commit( &self, preparation: &CommitPreparation, decision: &HookDecision, now_unix_ms: u64, ) -> Result<CommitResolution, VshError>
Apply one hook decision to the exact prepared transaction.
The preparation is revalidated against durable state and regenerated evidence, so callers cannot substitute a transaction or event after the handler returns.
§Errors
Returns a typed event-binding, state, approval, store, or commit error. The exact preparation is checked again before any decision changes host files.
Sourcepub fn fail_hook(&self, preparation: &CommitPreparation) -> Result<(), VshError>
pub fn fail_hook(&self, preparation: &CommitPreparation) -> Result<(), VshError>
Apply fail-closed state after a handler exception, timeout, or cancellation.
§Errors
Returns a typed store or artifact error if automatic approval cannot be moved into the existing pending-approval state.
Sourcepub fn recover(&self) -> Result<RecoveryReport, VshError>
pub fn recover(&self) -> Result<RecoveryReport, VshError>
Recover all durable commit artifacts under this runtime’s capability root.
§Errors
Returns a typed commit/recovery error for corrupt or unsafe journals.
Sourcepub fn transaction(
&self,
transaction: TransactionId,
) -> Result<TransactionRecord, VshError>
pub fn transaction( &self, transaction: TransactionId, ) -> Result<TransactionRecord, VshError>
Return one persisted lifecycle record.
§Errors
Returns VshError::Store when the transaction does not exist.
Auto Trait Implementations§
impl !Freeze for Runtime
impl RefUnwindSafe for Runtime
impl Send for Runtime
impl Sync for Runtime
impl Unpin for Runtime
impl UnsafeUnpin for Runtime
impl UnwindSafe for Runtime
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> FmtForward for T
impl<T> FmtForward for T
Source§fn fmt_binary(self) -> FmtBinary<Self>where
Self: Binary,
fn fmt_binary(self) -> FmtBinary<Self>where
Self: Binary,
self to use its Binary implementation when Debug-formatted.Source§fn fmt_display(self) -> FmtDisplay<Self>where
Self: Display,
fn fmt_display(self) -> FmtDisplay<Self>where
Self: Display,
self to use its Display implementation when
Debug-formatted.Source§fn fmt_lower_exp(self) -> FmtLowerExp<Self>where
Self: LowerExp,
fn fmt_lower_exp(self) -> FmtLowerExp<Self>where
Self: LowerExp,
self to use its LowerExp implementation when
Debug-formatted.Source§fn fmt_lower_hex(self) -> FmtLowerHex<Self>where
Self: LowerHex,
fn fmt_lower_hex(self) -> FmtLowerHex<Self>where
Self: LowerHex,
self to use its LowerHex implementation when
Debug-formatted.Source§fn fmt_octal(self) -> FmtOctal<Self>where
Self: Octal,
fn fmt_octal(self) -> FmtOctal<Self>where
Self: Octal,
self to use its Octal implementation when Debug-formatted.Source§fn fmt_pointer(self) -> FmtPointer<Self>where
Self: Pointer,
fn fmt_pointer(self) -> FmtPointer<Self>where
Self: Pointer,
self to use its Pointer implementation when
Debug-formatted.Source§fn fmt_upper_exp(self) -> FmtUpperExp<Self>where
Self: UpperExp,
fn fmt_upper_exp(self) -> FmtUpperExp<Self>where
Self: UpperExp,
self to use its UpperExp implementation when
Debug-formatted.Source§fn fmt_upper_hex(self) -> FmtUpperHex<Self>where
Self: UpperHex,
fn fmt_upper_hex(self) -> FmtUpperHex<Self>where
Self: UpperHex,
self to use its UpperHex implementation when
Debug-formatted.Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§impl<T> Pipe for Twhere
T: ?Sized,
impl<T> Pipe for Twhere
T: ?Sized,
Source§fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> Rwhere
Self: Sized,
fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> Rwhere
Self: Sized,
Source§fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> Rwhere
R: 'a,
fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> Rwhere
R: 'a,
self and passes that borrow into the pipe function. Read moreSource§fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> Rwhere
R: 'a,
fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> Rwhere
R: 'a,
self and passes that borrow into the pipe function. Read moreSource§fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
Source§fn pipe_borrow_mut<'a, B, R>(
&'a mut self,
func: impl FnOnce(&'a mut B) -> R,
) -> R
fn pipe_borrow_mut<'a, B, R>( &'a mut self, func: impl FnOnce(&'a mut B) -> R, ) -> R
Source§fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
self, then passes self.as_ref() into the pipe function.Source§fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
self, then passes self.as_mut() into the pipe
function.Source§fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
self, then passes self.deref() into the pipe function.impl<T> Read<Exclusive, BecauseExclusive> for Twhere
T: ?Sized,
Source§impl<T> Tap for T
impl<T> Tap for T
Source§fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
Borrow<B> of a value. Read moreSource§fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
BorrowMut<B> of a value. Read moreSource§fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
AsRef<R> view of a value. Read moreSource§fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
AsMut<R> view of a value. Read moreSource§fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
Deref::Target of a value. Read moreSource§fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
Deref::Target of a value. Read moreSource§fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self
fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self
.tap() only in debug builds, and is erased in release builds.Source§fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self
fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self
.tap_mut() only in debug builds, and is erased in release
builds.Source§fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
.tap_borrow() only in debug builds, and is erased in release
builds.Source§fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
.tap_borrow_mut() only in debug builds, and is erased in release
builds.Source§fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
.tap_ref() only in debug builds, and is erased in release
builds.Source§fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
.tap_ref_mut() only in debug builds, and is erased in release
builds.Source§fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
.tap_deref() only in debug builds, and is erased in release
builds.