Forge license module — capability-based license enforcement + hardware node-lock (grace-then-fail) with drift persistence. Wraps foundation-license.
| Tier | application |
| Role | unclassified (baselined) |
| Path | crates/application/license |
| Edition | 2024 |
| Targets | application_license |
| Public items | 11 across 2 modules |
| Tests | 1 |
What it is for
application-license — capability-based license enforcement for the Forge framework.
Wraps foundation-license. Supports signed license payloads, capability flags, and runtime enforcement. Foundation for any consumer app gating features behind paid tiers, evaluation limits, or commercial-license restrictions.
Capabilities
LicenseModule
application-license — capability-based license enforcement for the Forge framework.
| Item |
|---|
pub struct LicenseModule |
LicenseModule :: fn new() -> Self |
LicenseModule :: fn name(& self) -> & 'static str |
LicenseModule :: fn version(& self) -> & 'static str |
LicenseModule :: fn migrations(& self) -> Vec <MigrationSet> |
LicenseModule :: async fn migrate_pending(& self, pool : & PgPool) -> std::result::Result <u32, MigrationError> |
LicenseModule :: fn permission_codes(& self) -> Vec <String> |
repo (other)
Persistence for hardware-drift tracking (grace-then-fail, ADR 0018).
| Item |
|---|
async fn drift_since(pool : & PgPool, license_id : Uuid,) -> Result <Option <DateTime <Utc>>, sqlx::Error> |
async fn set_drift_if_absent(pool : & PgPool, license_id : Uuid, now : DateTime <Utc>,) -> Result <DateTime <Utc>, sqlx::Error> |
async fn clear_drift(pool : & PgPool, license_id : Uuid) -> Result <(), sqlx::Error> |
service (other)
License evaluation with hardware node-lock + grace-then-fail (ADR 0018).
| Item |
|---|
async fn evaluate_license(pool : & PgPool, signed : & SignedLicense, pubkey : & u8; 32, observed : Option <& BTreeMap <String, String>>, now : DateTime <Utc>,) -> Result <Entitlement, sqlx::Error> |
How to use it
No examples/ target and no doctest in this crate's rustdoc. The tests listed under Verification are the closest executable usage.
Module structure
application_license
reposervice
flowchart TD n_application_license["application_license"] n_application_license --> n_repo["repo"] n_application_license --> n_service["service"]
Public surface
`crate root`
| Item | What it is |
|---|---|
pub struct LicenseModule | — |
LicenseModule :: fn new() -> Self | — |
LicenseModule :: fn name(& self) -> & 'static str | — |
LicenseModule :: fn version(& self) -> & 'static str | — |
LicenseModule :: fn migrations(& self) -> Vec <MigrationSet> | — |
LicenseModule :: async fn migrate_pending(& self, pool : & PgPool) -> std::result::Result <u32, MigrationError> | — |
LicenseModule :: fn permission_codes(& self) -> Vec <String> | — |
`repo`
| Item | What it is |
|---|---|
async fn drift_since(pool : & PgPool, license_id : Uuid,) -> Result <Option <DateTime <Utc>>, sqlx::Error> | When a hardware mismatch was FIRST observed for license_id, or None if the hardware currently matches (no drift on record). |
async fn set_drift_if_absent(pool : & PgPool, license_id : Uuid, now : DateTime <Utc>,) -> Result <DateTime <Utc>, sqlx::Error> | Record a hardware drift starting at now if none is on record; return the effective drift-start (the existing one if already recorded — so the grace window doesn't reset on every boot). |
async fn clear_drift(pool : & PgPool, license_id : Uuid) -> Result <(), sqlx::Error> | Clear any recorded drift for license_id (the hardware matches again). |
`service`
| Item | What it is |
|---|---|
async fn evaluate_license(pool : & PgPool, signed : & SignedLicense, pubkey : & u8; 32, observed : Option <& BTreeMap <String, String>>, now : DateTime <Utc>,) -> Result <Entitlement, sqlx::Error> | Evaluate a signed license against the observed host fingerprint, persisting hardware drift so the grace window survives restarts |
Re-exports. Exported here, defined elsewhere.
| Export | Defined in |
|---|---|
evaluate_license | service::evaluate_license |
Boundary
Reaches into foundation.
Shares tier application with 120 other crates: application-agreements, application-ai, application-analytics, application-approvals, application-assessments, application-audit-log, application-auth, application-billing, … (120 total).
_What this crate deliberately does NOT own is a judgment. No committed registry records one for it, so none is stated here._
Where it sits
| Tier (ontology) | application |
| Architectural role (taxonomy) | unclassified (baselined) |
| Location | crates/application/license |
| Vocabulary in force (lexicon) | current |
Tier flow. Which tiers this crate's own edges cross.
flowchart LR n_application["application"] --> n_foundation["foundation"]
Dependencies
Runtime, in this workspace.
| Crate | Tier | Optional | Only on |
|---|---|---|---|
| `application-core` | application | no | always |
| `foundation-license` | foundation | no | always |
Runtime, from outside the workspace.
| Crate | Requirement | Features | Optional | Only on |
|---|---|---|---|---|
async-trait | ^0.1 | — | no | always |
chrono | ^0.4 | serde, serde | no | always |
serde_json | ^1 | — | no | always |
sqlx | ^0.8 | runtime-tokio, postgres, chrono, uuid, json | no | always |
uuid | ^1 | v4, v7, serde, js, serde | no | always |
Development, from outside the workspace.
| Crate | Requirement | Features | Optional | Only on |
|---|---|---|---|---|
tokio | ^1 | full, macros, rt-multi-thread | no | always |
Build. None.
Depended on by. Nothing in this workspace.
Signal flow — what reaches this crate, and what it reaches.
flowchart LR SELF["application-license"] SELF -->|runtime| n_application_core["application-core"] SELF -->|runtime| n_foundation_license["foundation-license"] classDef self fill:#1f883d,stroke:#1f883d,color:#fff; class SELF self;
Feature flags
No Cargo features are defined: every capability is unconditional, so no consumer can receive a half-wired crate.
Targets
| Kind | Name | Source |
|---|---|---|
| lib | application_license | `src/lib.rs` |
Error model
No public error type was detected: no public item declares a type named *Error, and no public signature returns one.
Operational characteristics
| Property | Evidence |
|---|---|
| async public surface | yes |
| async runtime | none detected |
| database access | yes |
| network I/O | none detected |
| unsafe code | none detected |
| environment variables | yes |
No unsafe block, unsafe fn, unsafe impl or unsafe trait was found by the parser anywhere in this crate's source.
Configuration
| Variable | Read in |
|---|---|
CARGO_PKG_VERSION | src/lib.rs |
LICENSE_TEST_DB | src/service.rs |
Related capabilities
No workspace crate depends on this one.
Verification
| Kind | Count |
|---|---|
| Unit tests | 1 |
| Integration tests | 0 |
| Examples | 0 |
| Doctests | 0 |
Evidence by module. How often each public module is named by something executable.
| Module | Tests | Examples | Consumers |
|---|---|---|---|
crate root | 1 | 0 | 0 |
repo | 3 | 0 | 0 |
service | 1 | 0 | 0 |
What the tests establish, by name:
node_lock_grace_then_fail_over_db—src/service.rs
Documentation coverage
| Measure | Documented | Total |
|---|---|---|
| Public items with rustdoc | 4 | 11 |
Public modules with a //! block | 2 | 2 |
pie showData
title Public items with rustdoc
"Documented" : 4
"No rustdoc detected" : 7
Metrics
| Metric | Value |
|---|---|
| Rust source files | 3 |
| Source lines | 291 |
| Code lines | 226 |
| Public API items | 11 |
| Public modules | 2 |
| Tests | 1 |
| Examples | 0 |
| Cargo features | 0 |
| Direct runtime dependencies | 7 |
| Workspace reverse dependencies | 0 |
pie showData
title Public API by kind
"function" : 4
"method" : 6
"struct" : 1
pie showData
title Rust source composition
"Code" : 226
"Blank or comment" : 65
Generation
Rendered by tools-corpus corpus readme from repository evidence alone, renderer schema 2, lexicon current. No model, network service or database was consulted. Regenerate with tools-corpus corpus readme --write; verify with --check.