pub struct Provenance {
pub run: RunId,
pub case: Option<CaseId>,
pub effect: EffectKey,
pub dispatch: Option<EffectKey>,
pub agent: String,
pub signature: Option<KeySignature>,
}Expand description
Who is calling, on whose behalf, for which piece of work.
Fields§
§run: RunId§case: Option<CaseId>§effect: EffectKeyWhich effect within the run — unique per run and per attempt.
dispatch: Option<EffectKey>The logical dispatch, stable across retries of the same call.
effect hashes the attempt number, and it must: without
it a retry would collide with the recorded failure of the attempt before
it, and replay would read back the failure instead of the retry.
That makes it the wrong thing to hand a callee for duplicate detection, which is the opposite question — “have I already done this work?” — and must answer yes for a retry. A peer given the effect key sees two unrelated messages and may act twice, which is precisely the outcome deduplication exists to prevent.
agent: StringThe agent, as the deployment names it.
signature: Option<KeySignature>The signature over payload, if the plane has a signer.
None is honest rather than convenient: a plane with no workload
identity cannot attest, and a self-signed block would look attested and
prove nothing — the same reasoning that keeps unsigned journal records
unsigned rather than self-signed.
Implementations§
Source§impl Provenance
impl Provenance
pub fn new(run: RunId, effect: EffectKey, agent: impl Into<String>) -> Self
Sourcepub const fn dispatching(self, dispatch: EffectKey) -> Self
pub const fn dispatching(self, dispatch: EffectKey) -> Self
Name the logical dispatch this call belongs to.
See Provenance::dispatch for why it is not the effect key.
Sourcepub fn dedupe_key(&self) -> EffectKey
pub fn dedupe_key(&self) -> EffectKey
The identity a callee should deduplicate on.
Falls back to the effect key when no dispatch id was supplied, which is wrong across retries and right for everything else — and is what a transport gets if the runtime did not set one.
pub const fn in_case(self, case: Option<CaseId>) -> Self
Sourcepub fn payload(&self, target: &str, arguments: &Value) -> Digest
pub fn payload(&self, target: &str, arguments: &Value) -> Digest
The bytes a signature covers.
Canonical — the same map always hashes the same way — because the callee
recomputes this from the wire form and the two must agree byte for byte.
Uses this crate’s own canonical writer rather than serde_json’s
ordering, for the reason recorded against core::canon: map order is not
something to inherit from a dependency’s feature flags.
target and arguments are what bind the signature to this call.
Sourcepub fn seal(self, signer: &dyn Signer, target: &str, arguments: &Value) -> Self
pub fn seal(self, signer: &dyn Signer, target: &str, arguments: &Value) -> Self
Sign this block for one specific call.
Sourcepub fn verify(
&self,
verifier: &dyn Verifier,
target: &str,
arguments: &Value,
) -> bool
pub fn verify( &self, verifier: &dyn Verifier, target: &str, arguments: &Value, ) -> bool
Whether this block was signed for exactly this call.
The callee’s side. Returns false for an unsigned block, an unknown key,
and a signature made for a different call alike — they are the same
answer to the only question being asked, which is may I act on this.
Trait Implementations§
Source§impl Clone for Provenance
impl Clone for Provenance
Source§impl Debug for Provenance
impl Debug for Provenance
Source§impl<'de> Deserialize<'de> for Provenance
impl<'de> Deserialize<'de> for Provenance
Source§fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
impl Eq for Provenance
Source§impl PartialEq for Provenance
impl PartialEq for Provenance
Source§impl Serialize for Provenance
impl Serialize for Provenance
impl StructuralPartialEq for Provenance
Auto Trait Implementations§
impl Freeze for Provenance
impl RefUnwindSafe for Provenance
impl Send for Provenance
impl Sync for Provenance
impl Unpin for Provenance
impl UnsafeUnpin for Provenance
impl UnwindSafe for Provenance
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> DeserializeOwned for Twhere
T: for<'de> Deserialize<'de>,
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
key and return true if they are equal.Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more