pub struct LuaRuntime {
source: String,
modules_path: Option<PathBuf>,
timeout_ms: u64,
}Expand description
Holds a validated Lua script and executes it against a Context.
A fresh Lua VM is created for every execution, so scripts cannot leak state between requests; only the source text is retained between calls.
Fields§
§source: StringThe full script source, re-loaded into a fresh VM per execution.
modules_path: Option<PathBuf>Directory the sandboxed require resolves modules from; None
disables require.
timeout_ms: u64Wall-clock budget for one execution, covering both loading the
source and the execute(ctx) call. Enforced by a Luau VM interrupt;
0 disables enforcement.
Implementations§
Source§impl LuaRuntime
impl LuaRuntime
Sourcepub fn new(
source: &str,
timeout_ms: u64,
modules_path: Option<PathBuf>,
) -> Result<Self, String>
pub fn new( source: &str, timeout_ms: u64, modules_path: Option<PathBuf>, ) -> Result<Self, String>
Compiles and validates the script in a throwaway VM, failing early if
the source has syntax errors, its top level errors on load, or it does
not define a global execute function. This runs once at
policy-compile time, not per request.
Sourcepub fn execute(
&self,
ctx: Context,
) -> Result<(Context, Option<&'static str>), PluginExecutionError>
pub fn execute( &self, ctx: Context, ) -> Result<(Context, Option<&'static str>), PluginExecutionError>
Runs the script’s execute(ctx) against the given context in a fresh
VM and returns the context rebuilt from the table the script returned,
and the port the script named, if any ("respond" or the implicit
success).
Every failure mode (load, marshalling either way, missing execute,
a runtime error raised by the script, or an unrecognized second
return value) returns a PluginExecutionError carrying the original
context, with a distinguishing error code (LUA_LOAD_ERROR,
LUA_MARSHAL_ERROR, LUA_MISSING_EXECUTE, LUA_EXECUTION_ERROR,
LUA_UNMARSHAL_ERROR, LUA_BAD_PORT, and LUA_TIMEOUT when the
script outran timeout_ms), so the graph engine routes through the
error port exactly like a native plugin failure.
timeout_ms is a single budget covering both loading the source and
the execute(ctx) call.
Shares the load/marshal/call core with execute_without_port
via call_execute; only the judgment of the
second return value differs between the two.
Sourcepub fn execute_without_port(
&self,
ctx: Context,
) -> Result<Context, PluginExecutionError>
pub fn execute_without_port( &self, ctx: Context, ) -> Result<Context, PluginExecutionError>
execute for node types that declare no outcome port: any named port
other than "success" is a LUA_BAD_PORT failure with the ORIGINAL
context, and the message says so without pointing at respond.
Used by serverless-pre-function/serverless-post-function, which
share this Lua runtime with script but have no respond port (or
any outcome port) to leave on — a function that names one anyway is
rejected here, at the point the original ctx is still in hand,
rather than one layer up with a serverless-specific message.
Sourcefn call_execute(
&self,
lua: &Lua,
timed_out: &Arc<AtomicBool>,
ctx: Context,
) -> Result<(Context, LuaTable, Option<LuaValue>), PluginExecutionError>
fn call_execute( &self, lua: &Lua, timed_out: &Arc<AtomicBool>, ctx: Context, ) -> Result<(Context, LuaTable, Option<LuaValue>), PluginExecutionError>
Shared core of execute and
execute_without_port: loads the
script, marshals ctx, calls execute(ctx), and returns the table it
returned together with the raw second return value, still unjudged,
and the original ctx — untouched, since it was only ever borrowed
to build the Lua table. This lets a caller that rejects the second
value still hand back the pristine original context, never the one
rebuilt from what the script returned.
Takes lua and timed_out by reference rather than creating them
itself: the returned LuaTable/LuaValue are only valid as long as
the Lua instance that produced them is alive, so it must live in
the caller’s stack frame, not be dropped when this function returns.
Sourcefn finish_unmarshal(
&self,
ctx: Context,
result_table: &LuaTable,
) -> Result<Context, PluginExecutionError>
fn finish_unmarshal( &self, ctx: Context, result_table: &LuaTable, ) -> Result<Context, PluginExecutionError>
Rebuilds the Context from result_table, carrying over the fields
scripts never see (the wire protocol and the errors accumulated by
earlier nodes) from ctx. On failure the ORIGINAL ctx travels with
the error, not a partially-rebuilt one.
Auto Trait Implementations§
impl Freeze for LuaRuntime
impl RefUnwindSafe for LuaRuntime
impl Send for LuaRuntime
impl Sync for LuaRuntime
impl Unpin for LuaRuntime
impl UnsafeUnpin for LuaRuntime
impl UnwindSafe for LuaRuntime
Blanket Implementations§
§impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
§impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
§impl<T> Instrument for T
impl<T> Instrument for T
§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more