Skip to main content

TrustLevel

Enum TrustLevel 

Source
pub enum TrustLevel {
    Trusted,
    Untrusted,
}
Expand description

How far a workload’s code is trusted — the declared input from which admission derives a minimum ExecSubstrate (R894).

§Absent means trusted, and that is only safe because of where it is stamped

The default direction is the trap this axis exists to close, so it is worth stating exactly. Every WorkloadSpec in the tree today is built by operator code — a reconciler, an appliance builder, a qed dispatcher — and none of them declares trust. Making the absent key mean untrusted would refuse the entire fleet on the day this lands; making it mean trusted is correct for exactly that population and wrong for any other.

So the rule is not “absent means trusted”. It is: the single choke point that ingests code the operator did not write stamps TRUST_UNTRUSTED_VALUE as it builds the spec (WorkloadSpec::stamp_untrusted), and a spec that reaches admission without having passed through operator-authored construction cannot exist. A tenant does not hand yah a WorkloadSpec; it hands yah an image and an argv, which yah’s own code puts into a spec. That is why the marker is not self-attestable: the untrusted party never holds the pen.

R823 (untrusted camp vending on microVMs) is the first such choke point. If a second one appears, it stamps too — and the rule to apply is that any constructor taking third-party bytes calls stamp_untrusted in the same function that takes them, not in a caller that might be forgotten.

Variants§

§

Trusted

Operator-authored code. No substrate floor.

§

Untrusted

Third-party code. Must not share a kernel with the fleet.

Implementations§

Source§

impl TrustLevel

Source

pub fn minimum_substrate(self) -> ExecSubstrate

The weakest substrate this trust level may run on.

TrustLevel::Untrusted maps to ExecSubstrate::MicroVm because a container shares the node’s kernel, and “untrusted code never shares a kernel with the fleet” is the rule this axis makes checkable. W344’s isolation table says “containerd or microVM” for higher-risk code; the 2026-09-11 operator call resolved that disjunction to the strict side for code the operator did not write.

TrustLevel::Trusted maps to ExecSubstrate::Native, the bottom of the ordering — i.e. no constraint, which is what every workload running today has.

Source

pub fn as_str(self) -> &'static str

The annotation value spelling this level.

Trait Implementations§

Source§

impl Clone for TrustLevel

Source§

fn clone(&self) -> Self

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Copy for TrustLevel

Source§

impl Debug for TrustLevel

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Default for TrustLevel

Source§

fn default() -> Self

Returns the “default value” for a type. Read more
Source§

impl Eq for TrustLevel

Source§

impl Hash for TrustLevel

Source§

fn hash<__H: Hasher>(&self, state: &mut __H)

Feeds this value into the given Hasher. Read more
1.3.0 · Source§

fn hash_slice<H>(data: &[Self], state: &mut H)
where H: Hasher, Self: Sized,

Feeds a slice of this type into the given Hasher. Read more
Source§

impl Ord for TrustLevel

Source§

fn cmp(&self, other: &Self) -> Ordering

This method returns an Ordering between self and other. Read more
1.21.0 (const: unstable) · Source§

fn max(self, other: Self) -> Self
where Self: Sized,

Compares and returns the maximum of two values. Read more
1.21.0 (const: unstable) · Source§

fn min(self, other: Self) -> Self
where Self: Sized,

Compares and returns the minimum of two values. Read more
1.50.0 (const: unstable) · Source§

fn clamp(self, min: Self, max: Self) -> Self
where Self: Sized,

Restrict a value to a certain interval. Read more
Source§

fn clamp_to<R>(self, range: R) -> Self
where Self: Sized, R: ClampBounds<Self>,

🔬This is a nightly-only experimental API. (clamp_to)
Restrict a value to a certain range. Read more
Source§

impl PartialEq for TrustLevel

Source§

fn eq(&self, other: &Self) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl PartialOrd for TrustLevel

Source§

fn partial_cmp(&self, other: &Self) -> Option<Ordering>

This method returns an ordering between self and other values if one exists. Read more
1.0.0 (const: unstable) · Source§

fn lt(&self, other: &Rhs) -> bool

Tests less than (for self and other) and is used by the < operator. Read more
1.0.0 (const: unstable) · Source§

fn le(&self, other: &Rhs) -> bool

Tests less than or equal to (for self and other) and is used by the <= operator. Read more
1.0.0 (const: unstable) · Source§

fn gt(&self, other: &Rhs) -> bool

Tests greater than (for self and other) and is used by the > operator. Read more
1.0.0 (const: unstable) · Source§

fn ge(&self, other: &Rhs) -> bool

Tests greater than or equal to (for self and other) and is used by the >= operator. Read more
Source§

impl StructuralPartialEq for TrustLevel

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<Q, K> Comparable<K> for Q
where Q: Ord + ?Sized, K: Borrow<Q> + ?Sized,

Source§

fn compare(&self, key: &K) -> Ordering

Compare self to key and return their ordering.
Source§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

Source§

fn equivalent(&self, key: &K) -> bool

Checks if this value is equivalent to the given key. Read more
Source§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

Source§

fn equivalent(&self, key: &K) -> bool

Compare self to key and return true if they are equal.
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.