Skip to main content

prepare_detector_install

Function prepare_detector_install 

Source
pub fn prepare_detector_install(
    manifest_json: &str,
    registry: &PluginRegistry,
) -> Result<PreparedDetector, String>
Expand description

Validate an incoming detector-plugin manifest end to end and return it with its decoded module, ready to persist. Runs, in order: parse, schema validation, the detector-only gate, base64-decode of the embedded module (size-capped), signature verification (binding the manifest and the module hash), the not-already-installed check, and — critically — an install-time link check: the module is instantiated in the sandbox with exactly the granted capabilities, which fails if it imports a host function whose capability wasn’t granted. That’s the bidirectional half of the import↔grant model and proves the module actually loads before we keep it.