Skip to main content

entracte_lib/plugins/
mod.rs

1//! Local-only plugin API (#156): manifests, signatures, the installed-plugin
2//! registry, and the install/uninstall orchestration. See the staged plan in
3//! `docs/developer/plugin-api-design.md`.
4//!
5//! A plugin is a signed bundle whose root is a `manifest.json`. The manifest
6//! declares one `kind` (content / detector / export). Code-bearing kinds
7//! reference a wasm `module` and list the host-function capabilities they
8//! `import`; each import is a permission request the user must grant. The
9//! signature binds the manifest **and** the module's hash, so a tampered
10//! module fails verification even if the manifest is untouched.
11//!
12//! This slice ships **content providers** end to end: a content plugin
13//! carries a typed content pack, merged into the active profile on install
14//! and removed exactly on uninstall (merge-and-track). Detector and export
15//! plugins parse and validate here but cannot yet be installed — they need
16//! the wasm runtime (a later slice).
17
18pub(crate) mod asset;
19mod detect;
20mod eval;
21mod install;
22mod manifest;
23pub(crate) mod registry;
24mod runtime;
25mod signature;
26
27pub use eval::any_detector_suppresses;
28
29#[allow(unused_imports)]
30pub use install::PreparedDetector;
31pub use install::{prepare_content_install, prepare_detector_install, prepare_export_install};
32pub use registry::{InstalledPlugin, PluginRegistry, PluginSummary};
33
34// The full manifest/signature API surface. Some items are consumed by the
35// command layer and tests now; others (the ABI version, module hashing, the
36// raw parse/validate/verify entry points) by the wasm-runtime slice. Marked
37// allow(unused_imports) so the public API can live in one place ahead of all
38// its consumers.
39#[allow(unused_imports)]
40pub use asset::{validate_asset, AssetKind, AudioFormat, ImageFormat, ManifestAsset, MAX_ASSETS};
41#[allow(unused_imports)]
42pub use manifest::{
43    parse_manifest, validate_manifest, Capability, DetectConfig, ExportConfig, ExportFormat,
44    ExportSink, Manifest, PluginKind, Signature, MANIFEST_VERSION, SUPPORTED_ABI_VERSION,
45};
46#[allow(unused_imports)]
47pub use signature::{sha256, signing_payload, verify_signature};
48
49// The sandbox API. No in-crate caller yet — the detector and export slices
50// consume it. Marked allow so the foundational runtime can land and be
51// tested ahead of its consumers (the wat-driven tests exercise it directly).
52#[allow(unused_imports)]
53pub use runtime::{
54    build_sandboxed_plugin, evaluate_detector, host_function_name, SandboxContext, DEFAULT_FUEL,
55    DEFAULT_MEMORY_MAX_PAGES, DEFAULT_TIMEOUT,
56};