Expand description
Local-only plugin API (#156): manifests, signatures, the installed-plugin
registry, and the install/uninstall orchestration. See the staged plan in
docs/developer/plugin-api-design.md.
A plugin is a signed bundle whose root is a manifest.json. The manifest
declares one kind (content / detector / export). Code-bearing kinds
reference a wasm module and list the host-function capabilities they
import; each import is a permission request the user must grant. The
signature binds the manifest and the module’s hash, so a tampered
module fails verification even if the manifest is untouched.
This slice ships content providers end to end: a content plugin carries a typed content pack, merged into the active profile on install and removed exactly on uninstall (merge-and-track). Detector and export plugins parse and validate here but cannot yet be installed — they need the wasm runtime (a later slice).
Re-exports§
pub use eval::any_detector_suppresses;pub use install::PreparedDetector;pub use install::prepare_content_install;pub use install::prepare_detector_install;pub use install::prepare_export_install;pub use registry::InstalledPlugin;pub use registry::PluginRegistry;pub use registry::PluginSummary;pub use asset::validate_asset;pub use asset::AssetKind;pub use asset::AudioFormat;pub use asset::ImageFormat;pub use asset::ManifestAsset;pub use asset::MAX_ASSETS;pub use manifest::parse_manifest;pub use manifest::validate_manifest;pub use manifest::Capability;pub use manifest::DetectConfig;pub use manifest::ExportConfig;pub use manifest::ExportFormat;pub use manifest::ExportSink;pub use manifest::Manifest;pub use manifest::PluginKind;pub use manifest::Signature;pub use manifest::MANIFEST_VERSION;pub use manifest::SUPPORTED_ABI_VERSION;pub use signature::sha256;pub use signature::signing_payload;pub use signature::verify_signature;pub use runtime::build_sandboxed_plugin;pub use runtime::evaluate_detector;pub use runtime::host_function_name;pub use runtime::SandboxContext;pub use runtime::DEFAULT_FUEL;pub use runtime::DEFAULT_MEMORY_MAX_PAGES;pub use runtime::DEFAULT_TIMEOUT;
Modules§
- asset 🔒
- Plugin image assets (#156): a content plugin may ship images and reference them from routine steps, so a guided break can show what a stretch looks like rather than only describing it.
- detect 🔒
- Local context probes a detector plugin can ask about, through the gated
host functions in
super::runtime(#156, slice 5). - eval 🔒
- Aggregating installed detectors into a single suppress / don’t verdict
(#156, slice 5b). The off-tick detector-eval task snapshots the installed
detectors, loads each module, and asks
any_detector_suppresses; the result feeds the 1Hz loop’s suppression chain viaScheduler::plugin_suppress. - install 🔒
- Pure install-time validation. No I/O, no settings mutation — the command
layer (
scheduler::commands::plugins) handles the file read, the consent dialog, the content merge under lock, and persistence. Keeping the gate pure makes every rejection path unit-testable. - manifest 🔒
- Plugin manifest types, parsing, and validation. Pure — no I/O.
- registry 🔒
- The installed-plugin registry: provenance for each installed plugin plus
the merge-and-track record of exactly what content it added, so an
uninstall can remove precisely those entries. Pure data + pure methods;
the on-disk persistence is in
crate::plugin_store. - runtime 🔒
- The WASM capability sandbox (#156, slice 4).
- signature 🔒
- Manifest signature verification. Pure — no I/O.