Expand description
Immutable, source-owned capability identity and scoped lifecycle kernel.
This module deliberately contains no package resolution, runtime
activation, or mutable latest-value registry. A capability source submits
one complete contribution, and CapabilitySet freezes the validated
descriptors behind an std::sync::Arc. Typed scopes add monotonic
ceilings, borrowed leases, reversible effects, and bounded structured
teardown. Closed runtime values and typestate transactions publish one
complete projected generation through a short catalog CAS.
Re-exports§
pub use crate::mcp::McpBinding;
Structs§
- Capability
Adapter Error - Bounded failure returned by a surface-owned capability projection adapter.
- Capability
Catalog - Session-local immutable capability publication catalog.
- Capability
Catalog Stamp - Exact local generation and identity digest used by catalog CAS publication.
- Capability
Ceiling - Complete immutable authority ceiling for one catalog generation.
- Capability
Cleanup Report - Bounded reverse-teardown result for retired or rolled-back effects.
- Capability
Commit Receipt - Successful all-or-nothing projection publication evidence.
- Capability
Contribution - Complete descriptor batch owned by one exact source generation.
- Capability
Descriptor - Serializable identity plane for one projected capability surface.
- Capability
Effect Error - Bounded failure returned by asynchronous capability teardown.
- Capability
Execution Ceiling - Numeric execution limits.
Noneis unbounded and is therefore the widest value for an optional duration ceiling. - Capability
Id - Stable source, category, and local-surface identity.
- Capability
Lease - Borrowed capability access tied to one typed scope owner.
- Capability
Projection - Immutable pairing of one identity set with exactly one typed runtime value for every descriptor.
- Capability
Projection Lease - Non-clone reader lease retaining one exact projected generation.
- Capability
Readiness Plan - Deterministic dependency-first ordering for one immutable capability set.
- Capability
Scope - Typed immutable catalog and monotonic governance scope.
- Capability
Scope Handle - Cloneable weak registration handle for one typed capability scope.
- Capability
Scope Id - Canonical hierarchical scope identity assigned by the Code host.
- Capability
Set - Canonically ordered immutable capability identity set.
- Capability
Source - Immutable identity and authority class for one complete contribution. Fields are private so untrusted package data cannot manufacture built-in precedence.
- Capability
Source Id - Stable identity of one trusted contribution source.
- Capability
Txn - Atomic capability contribution transaction guarded by Rust typestate.
- Code
Catalog Generation - Session-local immutable Code catalog generation.
- Flow
Binding - Immutable A3S Flow definition paired with the exact engine that can replay it.
- Governance
Capability Ceiling - Parent governance bindings that every child must retain.
- Knowledge
Surface Binding - Immutable multi-instance Knowledge readiness value accepted by the Code capability projection kernel.
- Knowledge
Surface Binding Spec - Host-reviewed, path-free readiness evidence for one Knowledge surface.
- Prepared
- Transaction state after every adapter prepared successfully.
- Prepared
Capability - One atomically returned runtime value and its reversible resources.
- Run
- RunCapability
Binding V1 - Serializable identity of the complete immutable capability generation and authority ceiling admitted for one Agent Run.
- RunUse
Capability Generation V1 - Diagnostic copy of the exact upstream A3S Use snapshot cursor retained by
the Run. The catalog digest already binds these fields; keeping them
explicit lets a recovery host request the correct generation without
resolving
latest. - Scope
Close Policy - Bounded close policy inherited by every child scope.
- Scope
Close Report - Deterministic, bounded outcome of one idempotent scope close.
- Session
- Session
Capability Batch - One complete next-generation Tool/Skill/Agent/Command/Hook/MCP/Flow/ Knowledge Surface/Knowledge/UI/Context projection for a Session.
- Session
Capability Run - Non-clone Run guard retaining one Code projection and one exact Use lease.
- Sha256
Digest - Canonical lowercase SHA-256 value used by capability identity contracts.
- Staged
- Transaction state before fallible runtime preparation.
- Subtask
- Supervised
Task Id - Opaque identity of one task owned by a capability scope supervisor.
- Turn
- UiAsset
- A bounded, path-free UTF-8 asset with a content-derived identity.
- UiBinding
- Immutable UI value accepted by the Code capability projection kernel.
- UiBinding
Spec - Renderer-neutral metadata and exact static document selected by a host.
- UiDocument
- Exact path-free document bytes selected for one UI generation.
- UseCapability
Generation - Exact immutable A3S Use capability publication identity.
- UseGeneration
Lease Error - Bounded failure returned while retaining one exact A3S Use generation.
- UsePackage
Generation - Exact immutable A3S Use package lifecycle generation identity.
- Validated
- Transaction state after the complete value projection passed validation.
- Workspace
Capability Ceiling - Workspace operations a scope may expose. A child may only turn flags off.
Enums§
- Capability
Kind - Closed product capability categories. Implementations inside a category remain open; arbitrary runtime categories do not enter the set.
- Capability
Projection Error - Failure that leaves the currently published projection unchanged.
- Capability
Runtime Error - Session-host failure that cannot expose a partial capability generation.
- Capability
Scope Error - Failure to construct, narrow, admit, or operate a capability scope.
- Capability
Scope Kind - Closed scope hierarchy used by the capability lifecycle kernel.
- Capability
SetError - Validation failure that prevents an immutable capability set from being constructed.
- Capability
Source Class - Trusted precedence class assigned by the host adapter, never by package content.
- Capability
Value - Closed runtime value categories accepted by the Code projection kernel.
- Knowledge
Surface Binding Error - RunCapability
Binding Error - Stable validation and comparison failures for a persisted Run capability identity.
- UiAsset
Kind - Closed static asset roles accepted by the renderer-neutral UI contract.
- UiBinding
Error
Constants§
- CAPABILITY_
CEILING_ DIGEST_ DOMAIN - CAPABILITY_
CEILING_ SCHEMA - CAPABILITY_
READINESS_ PLAN_ SCHEMA - CAPABILITY_
SET_ DIGEST_ DOMAIN - CAPABILITY_
SET_ SCHEMA - DEFAULT_
SCOPE_ CLOSE_ TIMEOUT - KNOWLEDGE_
SURFACE_ BINDING_ SCHEMA - MAX_
CAPABILITIES - MAX_
CAPABILITY_ CANONICAL_ BYTES - MAX_
CAPABILITY_ DEPENDENCIES - MAX_
CAPABILITY_ DEPENDENCY_ EDGES - MAX_
CAPABILITY_ IDENTIFIER_ BYTES - MAX_
CAPABILITY_ READINESS_ WAVES - MAX_
CAPABILITY_ SOURCES - MAX_
CAPABILITY_ TRANSACTION_ EFFECTS - MAX_
KNOWLEDGE_ SURFACE_ PROJECTIONS - MAX_
SCOPE_ CHILDREN - MAX_
SCOPE_ CLOSE_ TIMEOUT - MAX_
SCOPE_ EFFECTS - MAX_
SCOPE_ TASKS - MAX_
UI_ ASSETS_ PER_ KIND - MAX_
UI_ ASSET_ BYTES - MAX_
UI_ DOCUMENT_ BYTES - RUN_
CAPABILITY_ BINDING_ SCHEMA - UI_
BINDING_ SCHEMA - UI_
DOCUMENT_ SCHEMA - USE_
CAPABILITY_ SNAPSHOT_ CURSOR_ SCHEMA
Traits§
- Capability
Effect - One reversible resource owned by exactly one capability scope.
- Capability
Projection Adapter - Surface-owned fallible preparation boundary.
- Retained
UseGeneration - Host adapter for the exact non-clone lease returned by A3S Use.
- Scope
Kind - Sealed marker implemented only by the four supported scope levels.
- UseGeneration
Lease Provider - Generation-bound host seam for the real non-clone A3S Use snapshot lease.