Skip to main content

PrefixView

Struct PrefixView 

Source
pub struct PrefixView<'a, S: OmsSubstrate> { /* private fields */ }
Expand description

A read-only, prefix-bounded view of a substrate. Every grain created after until_ms is invisible, and every write is refused — the two properties a rehearsal needs to be exact and harmless, both enforced by the type rather than promised.

Implementations§

Source§

impl<'a, S: OmsSubstrate> PrefixView<'a, S>

Source

pub fn new(inner: &'a S, until_ms: i64) -> Self

Trait Implementations§

Source§

impl<S: OmsSubstrate> OmsSubstrate for PrefixView<'_, S>

Source§

fn put_grain(&mut self, _spec: &GrainSpec) -> Result<String>

Append a new grain; returns its content address.
Source§

fn supersede( &mut self, _target_hash: &str, _spec: &GrainSpec, _justification: &str, ) -> Result<String>

Supersede target_hash with a new grain carrying justification; returns the new grain’s address. Atomic and distinct from put (OMS §28.4).
Source§

fn retract(&mut self, _hash: &str, _reason: &str) -> Result<()>

Index-layer retraction (verification_status = retracted) — the inverse of an applied ADD, used by rollback. Not destructive (the grain stays content-addressed; only the index marks it retracted). The default reports it unsupported so substrates opt in.
Source§

fn put_blob(&mut self, _bytes: &[u8]) -> Result<String>

Store an opaque blob (candidate tool CODE, evalset payloads) in the substrate’s CAS, returning its address. §7.4’s blob seam — CAPABILITY-GATED: the default refuses, so a loop can only carry code on substrates that explicitly opt in. Code enters the substrate only through this seam or an authored add — never from a git mirror.
Source§

fn execute_cal(&mut self, _cal: &str) -> Result<Vec<Value>>

Execute CAL text, returning result rows as JSON. Used to regenerate evidence sets (evidence_query) and to apply proposal_cal. A substrate MAY reject CAL it cannot run with Error::CalUnsupported.
Source§

fn validate_cal(&self, cal: &str) -> Result<()>

Validate a CAL batch without executing it (statement classification, destructive-op detection). Delegated to the substrate — the engine contains a CAL writer, never a parser.
Source§

fn definition_inverse(&self, statement: &str) -> Result<Option<String>>

The CAL that would restore the CURRENT definition named by a DEFINE QUERY / DEFINE TEMPLATE statement — the rollback inverse, captured before the definition is replaced. Read more
Source§

fn load_state(&self) -> Result<Value>

Load the persisted loop state blob (config + watermarks/cooldowns). Returns Value::Null when nothing has been stored yet.
Source§

fn store_state(&mut self, _state: &Value) -> Result<()>

Persist the loop state blob (a file-truth, so it travels with the file on sync).
Source§

fn get_blob(&mut self, address: &str) -> Result<Vec<u8>>

Fetch a blob by the address put_blob returned. Same capability gate.
Source§

impl<S: OmsSubstrate> SubstrateRead for PrefixView<'_, S>

Source§

fn capabilities(&self) -> Capabilities

Declared optional capabilities.
Source§

fn grains_of_type( &self, grain_type: &str, namespace: Option<&str>, opts: ReadOpts, ) -> Result<Vec<GrainRecord>>

Curated read: all grains of one OMS type, optionally namespace-scoped and watermark/liveness filtered.
Source§

fn grain(&self, hash: &str) -> Result<Option<GrainRecord>>

Fetch one grain by content address.
Source§

fn heads(&self, namespace: Option<&str>) -> Result<Vec<HeadGroup>>

Entities with more than one live head. Requires the forks capability; the default impl reports it missing so non-fork substrates degrade cleanly rather than pretend.
Source§

fn telemetry(&self, namespace: Option<&str>) -> Result<Option<TelemetryView>>

A snapshot of the recall-telemetry rollups (§8). Requires the telemetry capability; the default returns None so substrates without a sidecar degrade cleanly. namespace scopes the snapshot when set.
Source§

fn validate_plan(&self, workflow: &Value) -> Result<()>

Structurally validate a candidate Workflow grain body — the same checks the runtime would run before executing it (unique and reachable nodes, conditions parse, every cycle bounded). The engine calls this before it will stamp a plan_revision as executable, so a proposal that would produce an unrunnable plan never reaches a reviewer as something they could apply. Read more
Source§

fn tool_evalset(&self, tool: &str) -> Result<Option<String>>

The evalset a code revision of tool must be gated against (Rule E1’s pin). Returns Ok(None) when the tool declares none, which makes a code_revision for it advisory — an unpinnable revision is one no gating run could ever satisfy. Read more
Source§

fn embed(&self, text: &str) -> Result<Option<Vec<f32>>>

Embed one text through the substrate’s installed embedder — the T1 leg of “is this the same instruction in different words”. Ok(None) when no embedder is installed (the embeddings capability is off), so the caller falls back to a lexical measure rather than guessing. The default reports none; substrates opt in.
Source§

fn address_of(&self, spec: &GrainSpec) -> Result<Option<String>>

The content address put_grain(spec) WOULD assign, computed without writing — what lets a rehearsal name the exact grain a live pass would have stored. Ok(None) when the substrate cannot say (the default); a replay then reports findings by dedup key and summary.
Source§

fn plan_replay( &self, _incumbent_plan_hash: &str, _candidate: &Value, ) -> Result<Option<Value>>

Rehearse a candidate Workflow body against the journaled runs of the live plan at incumbent_plan_hash — re-driven through the runtime’s pure scheduler with every effect answered from the journal, nothing dispatched, nothing written (areev run shadow --plan-file). The report is the runtime’s ShadowPlanReport as JSON; the engine reads totals.runs, no_worse, out_of_support_fraction and the per-run rows. Ok(None) when the substrate has no runtime or no journaled runs of that plan — the proposal is then simply unrehearsed, never refused for it. The default reports none.

Auto Trait Implementations§

§

impl<'a, S> Freeze for PrefixView<'a, S>
where &'a S: Freeze,

§

impl<'a, S> RefUnwindSafe for PrefixView<'a, S>

§

impl<'a, S> Send for PrefixView<'a, S>
where &'a S: Send,

§

impl<'a, S> Sync for PrefixView<'a, S>
where &'a S: Sync,

§

impl<'a, S> Unpin for PrefixView<'a, S>
where &'a S: Unpin,

§

impl<'a, S> UnsafeUnpin for PrefixView<'a, S>

§

impl<'a, S> UnwindSafe for PrefixView<'a, S>

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.