diff --git a/README.md b/README.md index f7f554d..a17b640 100644 --- a/README.md +++ b/README.md @@ -56,10 +56,12 @@ this repository's `store-sqlite/` directory. The `store-sqlite-plugin` crate is deliberately tiny: the logic crate also holds its one door (`door::door`, the store v3 table over `SqliteStore` through `busbar_contract::store_door!`; its `open` slot adapts the operator's settings -into a `SqliteStore`), and the plugin crate exports that door as the image's one -symbol, `busbar_plugin_door` (`export_door!`), so the cdylib answers the loader +into a `SqliteStore`), and the plugin crate exports that door as +`busbar_plugin_door` (`export_door!`), so the cdylib answers the loader through the same door a busbar build that LINKS `busbar-store-sqlite` -registers — one source, both doors. +registers — one source, both doors. The plugin crate also registers the store +on the cold store lane (`export_store_plugin!`) that the busbar kernel at the +pin boots a configured `store:` through. - The **default durable store** for busbar's governance data: virtual diff --git a/store-sqlite-plugin/src/lib.rs b/store-sqlite-plugin/src/lib.rs index 631bbc3..d576fd8 100644 --- a/store-sqlite-plugin/src/lib.rs +++ b/store-sqlite-plugin/src/lib.rs @@ -8,18 +8,38 @@ //! All the store lives in the `busbar-store-sqlite` crate, including its one door //! (`busbar_store_sqlite::door::door`, the store v3 table). This crate re-exports the logic crate, //! so the library it builds carries exactly the code a busbar build links, and exports that door as -//! the image's ONE symbol, `busbar_plugin_door` (`export_door!`, unconditionally) — one source, -//! both doors (DECISIONS #2 rule (1)). +//! `busbar_plugin_door` (`export_door!`, unconditionally) — one source, both doors (DECISIONS #2 +//! rule (1)). It also registers the store on the cold store lane the busbar kernel at the pin boots +//! a configured store through (`cold`, `export_store_plugin!`). //! -//! This crate is `deny`, not `forbid`: the export macro's `#[unsafe(no_mangle)]` is the one reviewed -//! exemption (a `forbid` cannot be lifted for it). No other `unsafe` exists here. +//! This crate is `deny`, not `forbid`: the two export macros (`#[unsafe(no_mangle)]`, the cold +//! boundary's `unsafe extern` functions) are the reviewed exemptions (a `forbid` cannot be lifted +//! for them). No other `unsafe` exists here. #![deny(unsafe_code)] pub use busbar_store_sqlite::*; -/// The exported door: the macro's `#[no_mangle]` symbol is the one exemption. +/// The exported door: the macro's `#[no_mangle]` symbol is an exemption. #[allow(unsafe_code)] mod exported { busbar_contract::export_door!(busbar_store_sqlite::door::door); } + +/// The store a busbar at the pin BOOTS. Its kernel opens a configured dropped-in store through the +/// cold store lane (`PluginRegistry::open_store` -> `load_store_image`: `busbar_abi`, +/// `busbar_plugin_kind`, `busbar_open`, ...), not through the door; an image that exports only +/// `busbar_plugin_door` answers `busbar_plugin_kind` with NULL there and the boot is refused +/// (BUSBAR-9007 "returned a null kind string"). This registration answers that lane over the same +/// [`SqliteStore`], opened by the door's own settings parser ([`door::open`]). +fn open_cold(cfg: &str) -> Result { + door::open(cfg).map(|s| Box::new(s) as busbar_contract::abi::sdk::StoreHandle) +} + +/// THE COLD LANE's registration (`export_store_plugin!`): the contract SDK's frozen symbols answer +/// through it. The macro's boundary functions are `unsafe extern "C-unwind"` by the cold ABI's own +/// definition, and it registers through a load-time initializer section — the other exemption. +#[allow(unsafe_code)] +mod cold { + busbar_contract::abi::sdk::export_store_plugin!(super::open_cold); +}