Skip to main content

Module manifest

Module manifest 

Source
Expand description

Plugin manifest types, parsing, and validation. Pure — no I/O.

The manifest is versioned (MANIFEST_VERSION) like the content-pack format. Validation is first-error-wins with user-facing messages, the same shape as content_pack::validate_pack. The load-time half of the capability model lives here: a code-bearing plugin’s declared imports must all be valid capabilities, and a content plugin must declare none. The runtime half (checking the module’s actual wasm import section against this list, and per-call scope enforcement) lands with the runtime slice.

Structs§

DetectConfig
Detector configuration: the parameters the host matches against when it computes a detector’s gated booleans. Only meaningful for a detector plugin. The detect:file:<path> scope lives in the capability itself, so only the process pattern needs declaring here.
ExportConfig
A declarative export adapter: on the named events, the host renders its own break stats in format and delivers them to destination via sink. No wasm — the plugin runs no code; the destination is fixed here (and shown in the consent dialog), so the plugin can never redirect the data.
Manifest
A parsed plugin manifest. A content plugin carries a typed ContentPack payload (validated via content_pack::validate_pack); code-bearing kinds carry a wasm module and declared imports instead.
Signature
The detached signature over canonical(manifest-without-signature) plus the module hash. ed25519; keys and signature are base64.

Enums§

Capability
A host-function capability a module imports. Serialised as the colon-delimited string form used in the manifest’s imports array and shown verbatim in the consent dialog. Scoped variants carry the exact path / origin the grant is bound to.
ExportFormat
The serialisation the host renders break stats in before delivery.
ExportSink
Where a declarative export adapter delivers break stats.
PluginKind
Which extension point a plugin provides. Exactly one per manifest.

Constants§

MANIFEST_VERSION
Manifest schema version this build reads and writes. Bumped only on a breaking change to the manifest shape.
MAX_ID_LEN 🔒
MAX_IMPORTS 🔒
MAX_SCOPE_LEN 🔒
MAX_STRING_LEN 🔒
Defensive caps so a malformed or hostile manifest can’t bloat state or stall the UI. Generous relative to any hand-authored plugin.
SUPPORTED_ABI_VERSION
Host-function ABI version this build exposes to wasm modules. A module built against a different ABI is refused rather than mis-bound.

Functions§

check_string 🔒
parse_manifest
Parse a manifest from JSON, mapping serde errors to a user-facing string. Does not validate beyond shape — call validate_manifest next.
validate_assets 🔒
Validate a manifest’s assets and the routine references to them. Only content plugins may carry assets; each must be a sound, in-cap image or audio file (see validate_asset) with a unique id. Every step.asset must resolve to an image asset, and every step.sound / breath phase cue to an audio asset. First-error-wins, like the rest of the file.
validate_export_config 🔒
Validate a declarative export config: a non-empty, length-capped destination (an http(s):// URL for the http sink), and at least one trigger event.
validate_id 🔒
A reverse-DNS-ish id: non-empty, lowercase [a-z0-9.-], at least one dot, length-capped. Kept pragmatic — it’s a uniqueness key, not a security boundary.
validate_manifest
Validate a parsed manifest: supported versions, well-formed id and name, kind/module/imports consistency, and that every import is a capability valid for the kind. The signature is verified separately (super::verify_signature). Returns a clear, user-facing error on the first problem.