astrid-runtime/sdk-rust
68.6
Adequate · 30 September 2026
7k
lines of production code
Rust
primary language
2
measurements over time
What this system is
This system is a Rust SDK for developing WebAssembly capsules that execute within the Astrid runtime kernel. It provides a typed, component-model-based interface for core capabilities including filesystem access, HTTP networking, identity resolution, and persistent storage, replacing previous raw FFI bindings with structured WIT contracts. The SDK also manages capsule lifecycle events, security approvals, and interactive user prompts through dedicated modules, ensuring type safety and synchronization with the host environment.
Features
Added bundled WIT contracts for Astrid SDK interfaces
The SDK now includes a pre-generated \astrid-contracts.wit\ file that bundles core interface definitions (types, agent, approval, client, context) for immediate use. This file is auto-generated from the canonical \astrid-runtime/wit\ submodule, ensuring the SDK surface stays in sync with the runtime's contract definitions without requiring manual regeneration by users.
astrid-sdk/wit · high confidence
Added test-capsule example with WIT event definitions
The examples directory now includes a new test-capsule project that demonstrates the use of WIT (WebAssembly Interface Types) for defining events. This example introduces a WIT interface specifying a test-event record (containing an ID, count, optional label, and tags) and a severity enum, providing a concrete reference for how event schemas are structured in the system.
examples · high confidence
Automated synchronization of WIT contract definitions
A new script, scripts/sync-contracts-wit.sh, has been added to automatically generate the bundled WIT file (astrid-sdk/wit/astrid-contracts.wit) from the canonical source files in the contracts/interfaces directory. This tool consolidates multiple per-package WIT definitions into a single package format required by the wit\_events! macro, ensuring that the SDK's interface definitions remain in sync with the runtime's canonical source of truth and preventing drift through CI checks.
scripts · high confidence
Initial release of Astrid system WIT interfaces
This change introduces the complete set of WebAssembly Interface Types (WIT) definitions for the Astrid system, establishing the host-guest contracts for capsule development. The diff adds new interface packages for core capabilities: \astrid:approval\ for human-in-the-loop security approvals, \astrid:elicit\ for interactive user input during lifecycle hooks, \astrid:fs\ for sandboxed filesystem operations with VFS support, \astrid:guest\ defining the lifecycle and interceptor export worlds, \astrid:http\ (v1.0.0) for HTTP client operations with SSRF protection, \astrid:identity\ for multi-platform identity resolution, \astrid:io\ for foundation I/O primitives, \astrid:ipc\ for the inter-process communication event bus, \astrid:kv\ for persistent key-value storage, and \astrid:net\ for networking including TCP, UDP, and DNS. These files define the typed error codes, request/response records, and resource handles that capsules will import to interact with the Astrid kernel.
astrid-sys/wit-staging · high confidence
New test capsule example for SDK validation
Added a new \test-capsule\ example that serves as a minimal integration test for the SDK's Component Model target (\wasm32-wasip2\). This example demonstrates the usage of the \\#\[capsule\]\ macro, defines tools (\increment\, \get\_counter\, \emit\_event\), implements an event interceptor, and exercises lifecycle hooks including install, upgrade, and a \before\_tool\_call\ hook that can veto tool execution. It also validates host imports for logging, IPC publishing, and WIT event generation.
examples/test-capsule · high confidence
SDK surface expanded with typed modules for filesystem, HTTP, identity, and lifecycle hooks
The SDK now exposes a comprehensive set of typed modules for core capsule capabilities. The new \fs\ module provides a \std::fs\-mirrored virtual filesystem with RAII file handles and metadata. The \http\ module adds an HTTP client backed by \astrid:http@1.1.0\, featuring per-request controls (timeouts, redirect policies, SSRF protection) and streaming responses. The \identity\ module enables platform user identity resolution and linking. Lifecycle management is handled by the \hook\ module, which allows capsules to subscribe to and respond to kernel events (e.g., tool calls, session start/end) via a read-then-optionally-reply model. Additionally, the \elicit\ module supports interactive user prompts for secrets and text, while \interceptors\ provides introspection for kernel-managed subscriptions. The previous \types\ module has been removed, with its contents re-exported under \sdk::types\.
astrid-sdk/src · high confidence
WIT type generation and capsule state detection improvements
The \astrid-sdk-macros\ crate now includes a new \wit\_events!\ procedural macro that reads \.wit\ files (single files or directories) and generates corresponding Rust structs and enums with serde serialization support, enabling developers to easily consume WebAssembly Interface Types. Additionally, the \\#\[capsule\]\ macro has been enhanced to automatically detect stateful capsules by checking for \&mut self\ method signatures, removing the need for explicit state annotations in many cases, and now extracts doc comments from methods and impl blocks to provide descriptions for tools and commands.
astrid-sdk-macros · high confidence
Architecture
SDK repository restructured with externalized contract submodule
The SDK repository has been reorganized to externalize the WIT contract definitions into a standalone \contracts\ submodule pointing to the canonical \astrid-runtime/wit\ repository. This change updates the submodule configuration (\.gitmodules\) and the repository's \README.md\ to reflect the new canonical URL for the Astrid runtime. For users, this ensures that the Rust SDK's generated types and host ABI bindings remain synchronized with the authoritative contract source, preventing drift between the SDK and the runtime kernel.
(repo-wide) · high confidence
Behavioural changes
Migrate system API bindings from Extism FFI to Wasmtime Component Model
The \astrid-sys\ crate has replaced its raw Extism FFI bindings with generated typed guest bindings based on the Wasmtime Component Model. Instead of exposing low-level \Vec\<u8\>\ functions for file system, IPC, network, and other OS operations, the crate now imports typed host functions from per-domain WIT packages (e.g., \astrid:fs\, \astrid:ipc\, \astrid:http\). This change introduces a \Guest\ trait for capsule exports, an \export!\ macro for wiring, and generated Rust structs for WIT types, providing a more structured and type-safe interface for capsule authors compared to the previous raw byte-based ABI.
astrid-sys/src · high confidence
Support for multiple frozen WIT versions via staged build script
The \astrid-sys\ crate now includes a \build.rs\ script that stages WebAssembly Interface Types (WIT) from the \contracts/host\ submodule into a \wit-staging\ directory, enabling \wit-bindgen\ to resolve them. This change allows the system to ship multiple frozen versions of the same package (e.g., \http@1.0.0\ and \http@1.1.0\) side-by-side by keying each version in its own dependency directory, ensuring that capsules pinned to older interfaces remain compatible while new code can use updated ones. The build process also handles published crates by skipping staging if the submodule is absent, relying on the committed \wit-staging\ copy instead.
astrid-sys · high confidence
Test coverage
Added compile-time smoke tests for users contract types
Added a new test file that verifies the \astrid:users@1.0.0\ WIT contract types (such as \AstridUser\, \ContextIdentity\, and various request/response structs) are correctly exported and implement the \Send\ trait, ensuring that contract drift is caught at compile time.
astrid-sdk/tests · high confidence
Dependencies
Astrid SDK v0.7.2: Migration to Wasmtime Component Model and WASI-free Targeting
The Rust SDK has been upgraded to version 0.7.2, marking a significant architectural shift from the Extism PDK to the Wasmtime Component Model. This change updates the build target to \wasm32-unknown-unknown\, removing dependencies on WASI interfaces (such as \wasi:random\) in favor of custom runtime bindings provided by \astrid-sys\. Key dependency updates include replacing \extism-pdk\ with \wit-bindgen\ and \wit-parser\, introducing \astrid-types\ for shared definitions, and configuring \getrandom\ with a custom backend to handle random number generation without WASI. The workspace also adds \chrono\ (with \default-features = false\) to support time handling via the SDK's own \astrid\_sdk::time\ module, ensuring capsules remain compatible with the new component-based execution environment.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 68 → 69 (+1.0)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 93 → 93 (+0.0)
- Architecture 100 → 97 (-2.8)
- Maturity 65 → 66 (+0.3)
- Readiness 64 → 63 (-1.4)
- Security 61 → 71 (+9.7)
Resolved (1)
- Hotspot: astrid-sdk-macros/src/lib.rs (astrid-sdk-macros/src/lib.rs)
New (6)
- Ambiguous return type for fs.read. It is unclear if fs.read returns bytes or a string. Given fs.read_to_string exists, fs.read likely returns bytes, but the naming convention is inconsistent with standard libraries (e.g., Rust's std::fs::read returns bytes, but read_to_string is explicit). If fs.read returns bytes, it should be named read_bytes or similar to match read_to_string's explicitness, or read_to_string should be read_string.
- Dependency hygiene PARTLY measured — Cargo dependencies read, no committed lock to grade for currency
- Duplicate spawning mechanisms. There are two ways to spawn processes: the builder pattern via Command and the direct module-level functions process.spawn and process.spawn_background. This creates confusion about which API to use. The module-level functions are essentially thin wrappers around Command, adding unnecessary complexity.
- Inconsistent optional handling. Some getters have an _opt suffix (e.g., get_bytes_opt), while others do not (e.g., get_borsh, get_versioned). It is unclear if get_borsh returns an Option or a Result with a specific error type for 'not found'. This inconsistency makes it difficult to predict how to handle missing keys.
- Misuse of SystemTime for non-time fields. ResolvedUser.display_name is a string, not a time. ExitInfo.exit_code and signal are integers. ResourceLimits fields are numeric limits. ProcessInfo.os_pid is an integer. KeyPage.next_cursor is likely a string or opaque cursor. Using SystemTime for these fields is a severe type error and indicates a copy-paste error or misunderstanding of types.
- Redundant existence check. fs.exists is a common convenience method, but fs.metadata and fs.symlink_metadata already provide the necessary information to determine existence (by checking for errors). Having a dedicated exists method duplicates the intent of checking if a path is valid, leading to API bloat.
Changes since last survey
- 3 commits — 3 feature/other, 0 fixes
By area
- (root) — 2 commits
- astrid-sdk/src — 1 commit
Notable commits
- change: chore(release): prepare SDK 0.7.2 (#69)
- change: feat(net): expose authenticated connection ownership (#68)
- change: feat(net): expose authenticated connection principals (#70)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
astrid-runtime/sdk-rust was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 30 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 238b9797c1e28086ba9cefdd483bec0fe958bb8f — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-cb25ca4feafa.