pub struct MemoryValidator { /* private fields */ }Expand description
The memory validator — gates all memory writes.
Implements the containment paper’s proposed “memory integrity validator” by checking trust scores, content validity, source allowlists, and prompt injection patterns before allowing a write to LMDB.
Implementations§
Source§impl MemoryValidator
impl MemoryValidator
Sourcepub const fn new(config: ValidatorConfig) -> Self
pub const fn new(config: ValidatorConfig) -> Self
Create a new validator with the given config.
Sourcepub fn validate(&self, memory: &Memory) -> ValidationVerdict
pub fn validate(&self, memory: &Memory) -> ValidationVerdict
Validate a memory before writing.
Checks trust score, content validity, source allowlist, injection patterns, and provenance signature (if required).
Sourcepub fn sign(&self, memory: &Memory) -> Result<String>
pub fn sign(&self, memory: &Memory) -> Result<String>
Sign a memory’s provenance.
Uses Ed25519 (ed25519:<hex>) when an Ed25519 key is configured,
otherwise HMAC-SHA256 (bare hex). The signature is returned as a
string and should be stored alongside the memory (e.g. in a tag).
Sourcepub fn verify_signature(&self, memory: &Memory) -> bool
pub fn verify_signature(&self, memory: &Memory) -> bool
Verify a memory’s provenance signature.
Dispatches on the signature scheme: ed25519:<hex> verifies against
the configured Ed25519 public key; bare hex verifies as HMAC-SHA256
with a constant-time comparison. Returns false if the signature is
missing, malformed, or doesn’t match.
Sourcepub fn sign_memory(&self, memory: Memory) -> Result<Memory>
pub fn sign_memory(&self, memory: Memory) -> Result<Memory>
Sign a memory and return a new copy with the signature tag attached.
Sourcepub const fn config(&self) -> &ValidatorConfig
pub const fn config(&self) -> &ValidatorConfig
Get the validator configuration.
Auto Trait Implementations§
impl Freeze for MemoryValidator
impl RefUnwindSafe for MemoryValidator
impl Send for MemoryValidator
impl Sync for MemoryValidator
impl Unpin for MemoryValidator
impl UnsafeUnpin for MemoryValidator
impl UnwindSafe for MemoryValidator
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> Downcast for Twhere
T: Any,
impl<T> Downcast for Twhere
T: Any,
Source§fn into_any(self: Box<T>) -> Box<dyn Any>
fn into_any(self: Box<T>) -> Box<dyn Any>
Box<dyn Trait> (where Trait: Downcast) to Box<dyn Any>, which can then be
downcast into Box<dyn ConcreteType> where ConcreteType implements Trait.Source§fn into_any_rc(self: Rc<T>) -> Rc<dyn Any>
fn into_any_rc(self: Rc<T>) -> Rc<dyn Any>
Rc<Trait> (where Trait: Downcast) to Rc<Any>, which can then be further
downcast into Rc<ConcreteType> where ConcreteType implements Trait.Source§fn as_any(&self) -> &(dyn Any + 'static)
fn as_any(&self) -> &(dyn Any + 'static)
&Trait (where Trait: Downcast) to &Any. This is needed since Rust cannot
generate &Any’s vtable from &Trait’s.Source§fn as_any_mut(&mut self) -> &mut (dyn Any + 'static)
fn as_any_mut(&mut self) -> &mut (dyn Any + 'static)
&mut Trait (where Trait: Downcast) to &Any. This is needed since Rust cannot
generate &mut Any’s vtable from &mut Trait’s.Source§impl<T> DowncastSend for T
impl<T> DowncastSend for T
Source§impl<T> DowncastSync for T
impl<T> DowncastSync for T
impl<T> Fruit for T
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more