Skip to main content

Module plugins

Module plugins 

Source
Expand description

Local-only plugin API (#156): manifests, signatures, the installed-plugin registry, and the install/uninstall orchestration. See the staged plan in docs/developer/plugin-api-design.md.

A plugin is a signed bundle whose root is a manifest.json. The manifest declares one kind (content / detector / export). Code-bearing kinds reference a wasm module and list the host-function capabilities they import; each import is a permission request the user must grant. The signature binds the manifest and the module’s hash, so a tampered module fails verification even if the manifest is untouched.

This slice ships content providers end to end: a content plugin carries a typed content pack, merged into the active profile on install and removed exactly on uninstall (merge-and-track). Detector and export plugins parse and validate here but cannot yet be installed — they need the wasm runtime (a later slice).

Re-exports§

pub use eval::any_detector_suppresses;
pub use install::PreparedDetector;
pub use install::prepare_content_install;
pub use install::prepare_detector_install;
pub use install::prepare_export_install;
pub use registry::InstalledPlugin;
pub use registry::PluginRegistry;
pub use registry::PluginSummary;
pub use asset::validate_asset;
pub use asset::AssetKind;
pub use asset::AudioFormat;
pub use asset::ImageFormat;
pub use asset::ManifestAsset;
pub use asset::MAX_ASSETS;
pub use manifest::parse_manifest;
pub use manifest::validate_manifest;
pub use manifest::Capability;
pub use manifest::DetectConfig;
pub use manifest::ExportConfig;
pub use manifest::ExportFormat;
pub use manifest::ExportSink;
pub use manifest::Manifest;
pub use manifest::PluginKind;
pub use manifest::Signature;
pub use manifest::MANIFEST_VERSION;
pub use manifest::SUPPORTED_ABI_VERSION;
pub use signature::sha256;
pub use signature::signing_payload;
pub use signature::verify_signature;
pub use runtime::build_sandboxed_plugin;
pub use runtime::evaluate_detector;
pub use runtime::host_function_name;
pub use runtime::SandboxContext;
pub use runtime::DEFAULT_FUEL;
pub use runtime::DEFAULT_MEMORY_MAX_PAGES;
pub use runtime::DEFAULT_TIMEOUT;

Modules§

asset 🔒
Plugin image assets (#156): a content plugin may ship images and reference them from routine steps, so a guided break can show what a stretch looks like rather than only describing it.
detect 🔒
Local context probes a detector plugin can ask about, through the gated host functions in super::runtime (#156, slice 5).
eval 🔒
Aggregating installed detectors into a single suppress / don’t verdict (#156, slice 5b). The off-tick detector-eval task snapshots the installed detectors, loads each module, and asks any_detector_suppresses; the result feeds the 1Hz loop’s suppression chain via Scheduler::plugin_suppress.
install 🔒
Pure install-time validation. No I/O, no settings mutation — the command layer (scheduler::commands::plugins) handles the file read, the consent dialog, the content merge under lock, and persistence. Keeping the gate pure makes every rejection path unit-testable.
manifest 🔒
Plugin manifest types, parsing, and validation. Pure — no I/O.
registry 🔒
The installed-plugin registry: provenance for each installed plugin plus the merge-and-track record of exactly what content it added, so an uninstall can remove precisely those entries. Pure data + pure methods; the on-disk persistence is in crate::plugin_store.
runtime 🔒
The WASM capability sandbox (#156, slice 4).
signature 🔒
Manifest signature verification. Pure — no I/O.