Skip to main content

Module install

Module install 

Source
Expand description

Pure install-time validation. No I/O, no settings mutation — the command layer (scheduler::commands::plugins) handles the file read, the consent dialog, the content merge under lock, and persistence. Keeping the gate pure makes every rejection path unit-testable.

Structs§

PreparedDetector
A detector validated and ready to install: the manifest plus its decoded, signature-verified, sandbox-linkable wasm module.

Constants§

MAX_MODULE_BYTES 🔒
Cap on a decoded wasm module. Generous for a real detector/export module while bounding a hostile base64 blob.

Functions§

prepare_content_install
Validate an incoming content-plugin manifest end to end and return it ready to merge. Runs, in order: JSON parse, schema validation, the content-only gate, signature verification, and the not-already-installed check. Detector/export plugins validate but are rejected here — they need the wasm runtime that a later slice adds.
prepare_detector_install
Validate an incoming detector-plugin manifest end to end and return it with its decoded module, ready to persist. Runs, in order: parse, schema validation, the detector-only gate, base64-decode of the embedded module (size-capped), signature verification (binding the manifest and the module hash), the not-already-installed check, and — critically — an install-time link check: the module is instantiated in the sandbox with exactly the granted capabilities, which fails if it imports a host function whose capability wasn’t granted. That’s the bidirectional half of the import↔grant model and proves the module actually loads before we keep it.
prepare_export_install
Validate an incoming export-plugin manifest end to end and return it ready to register. Like content, an export adapter is declarative (no wasm), so the signature is verified over the manifest alone. Runs: parse → schema validation (which checks the export config) → export-only gate → signature → not-already-installed.