pub struct PeerCall { /* private fields */ }Expand description
One request to one peer.
Implementations§
Source§impl PeerCall
impl PeerCall
Sourcepub fn prepare(
registry: &PeerRegistry,
client: Arc<dyn PeerClient>,
caller: &Delegation,
peer: PeerId,
capability: impl Into<String>,
payload: Value,
) -> Result<Self, PeerError>
pub fn prepare( registry: &PeerRegistry, client: Arc<dyn PeerClient>, caller: &Delegation, peer: PeerId, capability: impl Into<String>, payload: Value, ) -> Result<Self, PeerError>
Prepare a hop, attenuating the caller’s authority onto the peer and presenting the credential the chain’s owner is owed.
§Errors
PeerError::Unknownif the peer is not registered — fail closed.PeerError::NotGrantedif the capability is outside the grant.PeerError::Delegationif the grant would widen the caller’s own authority, or if the chain is already at its depth limit.PeerError::WrongAudienceif the credential held is for someone else.
Sourcepub fn prepare_as_plane(
registry: &PeerRegistry,
client: Arc<dyn PeerClient>,
chain: &Delegation,
peer: PeerId,
capability: impl Into<String>,
payload: Value,
) -> Result<Self, PeerError>
pub fn prepare_as_plane( registry: &PeerRegistry, client: Arc<dyn PeerClient>, chain: &Delegation, peer: PeerId, capability: impl Into<String>, payload: Value, ) -> Result<Self, PeerError>
Prepare a hop for a run admitted as the plane, under the plane’s own chain.
The plane is the party that asked, so a peer told who asked is shown the plane’s own credential rather than one naming the chain’s owner as if a person had asked.
§Errors
As prepare, plus PeerError::NoPlaneCredential.
Sourcepub fn governed_by(self, safety: &ToolSafety) -> Self
pub fn governed_by(self, safety: &ToolSafety) -> Self
Hold this call to a manifest grant’s declaration.
A registry entry is operator wiring — where the peer is, what it is
granted, which credential reaches it. The reviewed tool://<peer>/<capability>
grant in the calling agent’s manifest is what says how the call may be
used, and it governs the same way it governs a tool: its protected
fields are checked at the sink, its ceiling bounds what may be sent, and
its mutates can only make the call more cautious than the wiring did.
Sourcepub const fn acting_as(&self) -> &Delegation
pub const fn acting_as(&self) -> &Delegation
The chain the peer will act under.
Trait Implementations§
Source§impl Effect for PeerCall
impl Effect for PeerCall
Source§fn sink_arguments(&self) -> Option<&Value>
fn sink_arguments(&self) -> Option<&Value>
The payload is what reaches the peer, so it is what the sink gate judges — the whole-value taint rule for a mutating grant, and the per-field rules a manifest declares.
Source§fn source(&self) -> SourceId
fn source(&self) -> SourceId
The reference a manifest grants this call under, so a source rule can
name this peer’s answer — tool://reviewer/audit.check — rather than
whichever peer an injected prompt reached first.
Source§fn trust(&self) -> Trust
fn trust(&self) -> Trust
A peer’s answer is another party’s data.
Stated rather than inherited because a peer feels more trusted than a tool — it is our agent, on our side. It is not: it runs somewhere else, under someone else’s control, and it may itself have read the internet.
Source§type Output = Value
type Output = Value
Source§fn descriptor(&self) -> EffectDescriptor
fn descriptor(&self) -> EffectDescriptor
Source§fn recovery(&self) -> Recovery
fn recovery(&self) -> Recovery
InDoubt failure. The two are the
same situation reached from different directions.Source§fn retry(&self) -> RetryPolicy
fn retry(&self) -> RetryPolicy
Source§fn max_sensitivity(&self) -> Sensitivity
fn max_sensitivity(&self) -> Sensitivity
Source§fn delegation_depth(&self) -> Option<usize>
fn delegation_depth(&self) -> Option<usize>
Source§fn protected_fields(&self) -> &[ProtectedField]
fn protected_fields(&self) -> &[ProtectedField]
Source§fn output_sensitivity(&self) -> Sensitivity
fn output_sensitivity(&self) -> Sensitivity
Source§fn attach(&mut self, provenance: &Provenance)
fn attach(&mut self, provenance: &Provenance)
Source§fn credential_binding(&self) -> Option<CredentialBinding>
fn credential_binding(&self) -> Option<CredentialBinding>
Source§fn perform<'life0, 'async_trait>(
&'life0 self,
) -> Pin<Box<dyn Future<Output = Result<Value, EffectError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
fn perform<'life0, 'async_trait>(
&'life0 self,
) -> Pin<Box<dyn Future<Output = Result<Value, EffectError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
Source§fn gen_ai_operation(&self) -> Option<&'static str>
fn gen_ai_operation(&self) -> Option<&'static str>
Source§fn gen_ai_request(&self) -> Option<GenAiRequest>
fn gen_ai_request(&self) -> Option<GenAiRequest>
GenAI
span attributes. Read moreSource§fn gen_ai_response(&self, output: &Self::Output) -> Option<GenAiResponse>
fn gen_ai_response(&self, output: &Self::Output) -> Option<GenAiResponse>
Source§fn retries_landed(&self) -> bool
fn retries_landed(&self) -> bool
Source§fn rebind(&mut self, _arguments: Value) -> bool
fn rebind(&mut self, _arguments: Value) -> bool
arguments in place of the ones this effect was built over,
where it can — what a declared redaction at a sink needs. Read moreSource§fn outbound_bytes(&self) -> u64
fn outbound_bytes(&self) -> u64
Auto Trait Implementations§
impl !RefUnwindSafe for PeerCall
impl !UnwindSafe for PeerCall
impl Freeze for PeerCall
impl Send for PeerCall
impl Sync for PeerCall
impl Unpin for PeerCall
impl UnsafeUnpin for PeerCall
Blanket Implementations§
Source§impl<E> AnyEffect for Ewhere
E: Effect,
impl<E> AnyEffect for Ewhere
E: Effect,
Source§fn spend_erased(&self, output: &Value) -> Spend
fn spend_erased(&self, output: &Value) -> Spend
Round-trips the output to ask the typed effect what it cost.
A type that cannot be deserialized from its own serialization is already
broken for replay — Effect::Output requires the round-trip, and the
journal reconstructs every output that way. Charging zero here is the
same answer replay would reach, and the defect surfaces where it belongs.
Source§fn gen_ai_response_erased(&self, output: &Value) -> Option<GenAiResponse>
fn gen_ai_response_erased(&self, output: &Value) -> Option<GenAiResponse>
Round-trips the output, for the reason
spend_erased does.
fn descriptor(&self) -> EffectDescriptor
fn attach_erased(&mut self, provenance: &Provenance)
fn gen_ai_operation(&self) -> Option<&'static str>
fn mutates(&self) -> bool
fn recovery(&self) -> Recovery
fn retry(&self) -> RetryPolicy
fn retries_landed(&self) -> bool
fn max_sensitivity(&self) -> Sensitivity
fn sink_arguments(&self) -> Option<&Value>
fn rebind_erased(&mut self, arguments: Value) -> bool
fn outbound_bytes(&self) -> u64
fn credential_binding(&self) -> Option<CredentialBinding>
fn protected_fields(&self) -> &[ProtectedField]
fn delegation_depth(&self) -> Option<usize>
fn source(&self) -> SourceId
fn trust(&self) -> Trust
fn output_sensitivity(&self) -> Sensitivity
fn gen_ai_request(&self) -> Option<GenAiRequest>
fn perform_erased<'life0, 'async_trait>(
&'life0 self,
) -> Pin<Box<dyn Future<Output = Result<Value, EffectError>> + Send + 'async_trait>>where
'life0: 'async_trait,
E: 'async_trait,
fn reconcile_erased<'life0, 'async_trait>(
&'life0 self,
) -> Pin<Box<dyn Future<Output = Result<Reconciliation<Value>, EffectError>> + Send + 'async_trait>>where
'life0: 'async_trait,
E: 'async_trait,
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<E> BuildsEffect<E> for Ewhere
E: Effect,
impl<E> BuildsEffect<E> for Ewhere
E: Effect,
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more