Expand description
Plugin manifest types, parsing, and validation. Pure — no I/O.
The manifest is versioned (MANIFEST_VERSION) like the content-pack
format. Validation is first-error-wins with user-facing messages, the
same shape as content_pack::validate_pack. The load-time half of the
capability model lives here: a code-bearing plugin’s declared imports
must all be valid capabilities, and a content plugin must declare none.
The runtime half (checking the module’s actual wasm import section
against this list, and per-call scope enforcement) lands with the
runtime slice.
Structs§
- Detect
Config - Detector configuration: the parameters the host matches against when it
computes a detector’s gated booleans. Only meaningful for a detector
plugin. The
detect:file:<path>scope lives in the capability itself, so only the process pattern needs declaring here. - Export
Config - A declarative export adapter: on the named events, the host renders its
own break stats in
formatand delivers them todestinationviasink. No wasm — the plugin runs no code; the destination is fixed here (and shown in the consent dialog), so the plugin can never redirect the data. - Manifest
- A parsed plugin manifest. A content plugin carries a typed
ContentPackpayload (validated viacontent_pack::validate_pack); code-bearing kinds carry a wasmmoduleand declaredimportsinstead. - Signature
- The detached signature over
canonical(manifest-without-signature)plus the module hash. ed25519; keys and signature are base64.
Enums§
- Capability
- A host-function capability a module imports. Serialised as the
colon-delimited string form used in the manifest’s
importsarray and shown verbatim in the consent dialog. Scoped variants carry the exact path / origin the grant is bound to. - Export
Format - The serialisation the host renders break stats in before delivery.
- Export
Sink - Where a declarative export adapter delivers break stats.
- Plugin
Kind - Which extension point a plugin provides. Exactly one per manifest.
Constants§
- MANIFEST_
VERSION - Manifest schema version this build reads and writes. Bumped only on a breaking change to the manifest shape.
- MAX_
ID_ 🔒LEN - MAX_
IMPORTS 🔒 - MAX_
SCOPE_ 🔒LEN - MAX_
STRING_ 🔒LEN - Defensive caps so a malformed or hostile manifest can’t bloat state or stall the UI. Generous relative to any hand-authored plugin.
- SUPPORTED_
ABI_ VERSION - Host-function ABI version this build exposes to wasm modules. A module built against a different ABI is refused rather than mis-bound.
Functions§
- check_
string 🔒 - parse_
manifest - Parse a manifest from JSON, mapping serde errors to a user-facing string.
Does not validate beyond shape — call
validate_manifestnext. - validate_
assets 🔒 - Validate a manifest’s assets and the routine references to them. Only
content plugins may carry assets; each must be a sound, in-cap image or
audio file (see
validate_asset) with a unique id. Everystep.assetmust resolve to an image asset, and everystep.sound/ breath phase cue to an audio asset. First-error-wins, like the rest of the file. - validate_
export_ 🔒config - Validate a declarative export config: a non-empty, length-capped
destination (an
http(s)://URL for the http sink), and at least one trigger event. - validate_
id 🔒 - A reverse-DNS-ish id: non-empty, lowercase
[a-z0-9.-], at least one dot, length-capped. Kept pragmatic — it’s a uniqueness key, not a security boundary. - validate_
manifest - Validate a parsed manifest: supported versions, well-formed id and name,
kind/module/imports consistency, and that every import is a capability
valid for the kind. The signature is verified separately
(
super::verify_signature). Returns a clear, user-facing error on the first problem.