Expand description
Public programmatic, query, semantic-agent, explanation, and debug interfaces.
Structs§
- Actor
Knowledge - Archive
Reachability Manifest - Unified offline GC mark set for kernel-owned pages, evidence, decision blobs, and namespaced plugin archive objects.
- Archived
Evidence Locator - Archived
Evidence Receipt - Archived
Plugin Ingress Provenance - Archived
Segment Header - Army
- ArmyId
- Stable numeric identifier for
ArmyId. - Army
Knowledge - Artifact
Manifest - Stable identity for a scenario, ruleset, content pack, run policy, localization contract, or source ledger.
- Boundary
Change - Boundary
Context - Boundary
Emission - Boundary
Id - Stable numeric identifier for
BoundaryId. - Boundary
Ingress Generation - Boundary
Knowledge Change - Boundary
Person Availability Change - Committed availability change evidence in a boundary record.
- Boundary
Person Creation - Committed person-creation evidence in a boundary record.
- Boundary
Proposal - Boundary
Receipt - Boundary
Record - Boundary
Request - Boundary
System Contract - Canwu
- Main in-process API. All returned world values are detached snapshots.
- Canwu
Error - Canwu
Viewer - Restricted player/agent/observer API. It deliberately exposes no raw snapshot, event, boundary, domain-record, or audit-origin access.
- Capacity
Booking - Capacity
Booking Id - Checkpoint
Journal - Portable full-save bundle built from a current-state checkpoint and journal segments.
- Command
Attempt Id - Stable numeric identifier for
CommandAttemptId. - Command
Attempt Record - Command
Authority - Command
Context - Command
Envelope - Command
Id - Stable numeric identifier for
CommandId. - Command
Receipt - Command
Record - Command
Rejection - Command
Request - Command
Request Id - Stable numeric identifier for
CommandRequestId. - Commitment
Roots - Canonical roots for independent authoritative state and evidence domains.
- Compacted
Canwu - Public API for a live runtime whose sealed evidence segments are stored by the caller.
- Compacted
Simulation - A live simulation whose sealed evidence prefixes are owned by the caller.
- Created
Person - Receipt entry binding a creation correlation to its engine-allocated ID.
- Decision
Archive Blob - Decision
Archive Bucket Page - Decision
Archive Receipt - Decision
Attempt Record - Decision
Context - Decision
Controller - Decision
Controller Binding - Decision
Error - Decision
External Evidence - Decision
Factor Contribution - Decision
History Cursor - Decision
History Page - Decision
History Query Budget - Decision
HotState - Decision
Ingress Request - Decision
Locator Scale Metrics - Decision
Option - Decision
Option Evaluation - Decision
Option Weight - Decision
Policy Identity - Decision
Random Evidence - Decision
Request Id - Stable numeric identifier for
DecisionRequestId. - Decision
State - Decision
Ticket - Decision
Ticket Draft - Decision
Ticket Id - Stable numeric identifier for
DecisionTicketId. - Decision
Trace - Decision
Trace Id - Stable numeric identifier for
DecisionTraceId. - Delivery
Completion Request - Delivery
Saga - DemoIds
- Departure
Slot - Domain
Record - Domain
Record Change - Domain
Record Commitment Roots - Independent commitment roots for the Format-8 domain-record store.
- Domain
Record Draft - Domain
Record Kind - Stable application-defined record kind. Namespaces and names are validated by the simulation package registry before authoritative use.
- Domain
Record Page - One deterministic trusted-host page of records from an authoritative read cut.
- Domain
Record Page Roots - Domain
Record Ref - Stable string identity for an application-defined entity or record.
- Domain
Record Schema - Domain
Record Version Ref - Exact historical identity for an application-defined record version.
- Domain
Reference - Domain
Reference Schema - Duration
Sample - Estimate
Range - EventId
- Stable numeric identifier for
EventId. - Event
Kind - Domain-neutral event identity and structured fields.
- Evidence
Archive Index - Evidence
Cursor - Monotonic cuts through every append-only evidence journal.
- Evidence
Index Entry - Evidence
Item Locator - Evidence
Journal Roots - Evidence
Journal Segment - One contiguous append-only evidence range for incremental archival.
- Evidence
Seal Token - Explanation
- Explanation
Step - External
Decision Option - External
Decision Request - External
Decision Response - Government
- Government
Id - Stable numeric identifier for
GovernmentId. - Guarded
Utility Policy - A composite policy: ordered guards, then weighted utility over the options the guards left, then an optional bounded random tie-break.
- Handoff
- Handoff
Id - Holder
Knowledge Record Id - Stable numeric identifier for
HolderKnowledgeRecordId. - Human
Decision Response - Identity
Evidence Dependencies V1 - Authoritative identity-only evidence dependencies for a live domain record.
- Ingress
Id - Stable numeric identifier for
IngressId. - Ingress
Receipt - Ingress
Record - Itinerary
Revision - Itinerary
Revision Id - Knowledge
Cursor - Knowledge
Limits V1 - Knowledge
Origin - Knowledge
Query - Knowledge
Query Result - Knowledge
Read Cut - Knowledge
Record - Knowledge
Record Draft - Knowledge
Record Id - Stable numeric identifier for
KnowledgeRecordId. - Knowledge
Record Kind - Stable namespace and kind for a holder-relative knowledge record.
- Knowledge
Record View - Knowledge
Schema Id - Exact version of one registered knowledge schema.
- Knowledge
Snapshot - Knowledge
Subject - Knowledge
Subject Schema - Knowledge
Write Grant - LegExecution
- LegExecution
Id - Letter
Cargo - Letter
Id - Stable numeric identifier for
LetterId. - LlmModel
Identity - Maintenance
Change Record - Maintenance
Dependency Resolver Descriptor - Declares that a plugin must participate when a target namespace is retired through owner-authorized maintenance. The declaration is persisted in the plugin descriptor, so replay and restore cannot silently omit a dependent owner.
- Maintenance
Rejection Receipt - MapPoint
- Movement
Order - Immutable, admitted intent shared by transport movement domains.
- Movement
Order Id - Stable identity for an admitted transport-domain movement intent.
- Movement
Subject - One typed identity in a movement manifest.
- Ordered
Rule Policy - Organization
Id - Stable numeric identifier for
OrganizationId. - Outbox
Entry - Durable, idempotent external-delivery identity derived from committed
boundary evidence. The engine creates one entry for every emission; a host
may deliver it at least once and use
delivery_idas its idempotency key. - Owner
Authorized Maintenance Draft - Owner
Authorized Maintenance Request - Owner
Authorized Mutation - Owner
Authorized Participant Draft - Owner
Authorized Participant Proposal - Owner
Authorized Record Expectation - Paged
Simulation Checkpoint - Patricia
Store Metrics - Payload
Property - Payload
Required Evidence Continuation V1 - Authoritative pending-continuation contract for rules that must inspect old payload bytes.
- Persistent
Domain Record Store - Person
- Person
Availability - Core life and custody state of one person.
- Person
Draft - Application-supplied content for a person created at a boundary.
- Person
Id - Stable numeric identifier for
PersonId. - Person
Transit State - Planning
Snapshot - Plugin
Action Descriptor - Plugin
Archive Retention - Plugin
Component Record - Plugin
Descriptor - Plugin
Ingress Descriptor - Plugin
Ingress Permit - Opaque capability issued only while a plugin registers a kernel-internal ingress type. Hosts can pass the capability back but cannot construct or alter it.
- Plugin
Ingress Request - Plugin
Ingress Target - Plugin
Knowledge Schema - Plugin
Registrar - Plugin
Registry - Policy
Decision - Portable
Paged Simulation Checkpoint - Prepared
Decision Archive - Prepared
Decision Ingress - Prepared
Evidence Seal - Prepared
Paged Simulation Checkpoint - Prepared
State Delta - Queued
External Policy - Queued
Human Policy - Queued
LlmPolicy - Random
Decision Resolution - Random
Draw Id - Stable numeric identifier for
RandomDrawId. - Random
Draw Record - Random
Operation Address V1 - Version-one stable entropy address for a future keyed random draw.
- Random
Sample - Random
Stream Key - Random
Stream State - Replay
Journal - Complete recorded environment and input journal for exact replay.
- Reservation
Allocation - Reservation
Offer - Reservation
Offer Record - Reservation
Pool Key - Reservation
Ref - Reservation
Request - Reservation
Request Record - Resource
Id - Stable numeric identifier for
ResourceId. - Route
- Route
Cost - RouteId
- Stable numeric identifier for
RouteId. - Route
Leg - Route
Plan - Routing
Cache - Routing
Connection - Routing
Connection Ref - Routing
Endpoint - Routing
Network - Routing
Node Ref - Routing
Policy - Routing
Request - RunConfiguration
- Scenario
- Schema
Registry - Seat
Binding - SimDuration
- SimEvent
- SimTime
- Simulation
Checkpoint - Current authoritative state plus the journal cut required to validate it.
- Simulation
Snapshot - Simulation
View - State
Key - State
Page Blob - State
Page Retention Handle - State
Page Retention Ledger - Persistable host-side mark/sweep interlock for content-addressed state pages. Preparing, verifying, or durably enqueueing a root protects every declared reachable page across process restart. A committed root takes over that lease atomically before the transient handle may disappear.
- System
Contract - Territory
- Territory
Id - Stable numeric identifier for
TerritoryId. - Transit
State - Transport
Execution - Transport
Execution Id - Type
Schema - Typed
Domain Record Ref - Typed façade over a stable application-defined record identity.
- Utility
Profile - Verified
Decision Archive Commit - Provider-verified, replay-safe archive transition. Blob bytes remain in the host archive; canonical ingress carries only the exact hot-state source root, token, and compact receipts needed to revalidate the transition.
- Verified
Owner Authorized Maintenance Commit - Viewer
Context - Visible
Change - Weighted
Utility Evaluator - Weighted
Utility Policy - World
Snapshot
Enums§
- Archive
Store Outcome - Boundary
Directive - Boundary
Emission Kind - Boundary
Phase - Capacity
Booking Status - Cause
Ref - Command
- Command
Attempt Outcome - Command
Ingress - Command
Outcome - Command
Policy Context - Command-relevant policy deliberately omits run purpose, observation, and trace so authoritative handlers cannot branch on presentation-only inputs.
- Controller
Decision - Controller
Policy - Core
Entity Kind - Custody
State - Whether a person is free to act. Absent availability means
CustodyState::Free. - Decision
Action - Decision
Archive Record - Decision
Archive Store Outcome - Decision
Attempt Error Code - Decision
Attempt Outcome - Decision
Authority - Decision
Error Code - Decision
Evaluation - Decision
History Key - Typed identity for decision history. A scalar ID is not enough because tickets, caller-selected requests, and engine-issued traces have different uniqueness and retention rules.
- Decision
History Location - Decision
Mutation - Decision
Origin - Decision
Outcome - Decision
Policy Kind - Decision
Stage - The stage of a composite policy that produced a decision. Decisions from single-stage policies, and every historical trace, carry no stage.
- Decision
Ticket State - Domain
Entity Kind Class - Type-level class for domain kinds whose instances are entity identities.
- Domain
Record Class - Domain
Record Lifecycle - Domain
Record Mutation - Domain
Record Mutation Policy - Domain
Record Operation - Domain
Record Version Source - Persisted identity of the operation that established one domain-record version. Version zero is reserved and rejected by runtime validation.
- Domain
Reference Target - Domain
Reference Target Kind - Domain
Value Kind Class - Type-level class for domain kinds whose instances are non-entity records.
- Entity
Ref - Serializable entity reference used by events, queries, and generic tools.
- Error
Code - Event
Audience - Declarative audience for a persisted event projection.
- Event
Kind Error - Evidence
Journal Kind - Evidence
Nested Locator - Evidence
Ref - Shared persisted-evidence identity used by knowledge, decisions, random operations, replay, and compact archive receipts.
- Explanation
Request - Handoff
Kind - How custody changed hands between two legs.
- Ingress
Cancellation Authority - Authority that withdrew a queued plugin ingress item.
- Ingress
Class - Ingress
Payload - Interaction
Policy - Issuer
- Itinerary
Revision Reason - Knowledge
History View - Knowledge
Holder Policy - Whether a domain entity schema may receive holder-relative knowledge.
- Knowledge
Holder Ref - Stable holder identity shared by people and eligible institutional entities.
- Knowledge
Query Error - Knowledge
Source - Knowledge
Subject Target - Knowledge
Subject Target Kind - LegExecution
Status - Letter
Status - Life
State - Whether a person is alive. Absent availability means
LifeState::Alive. - Maintenance
Disposition - Maintenance
Ingress Request - Movement
Initiative - Who initiated a movement intent. The runtime must derive this from the admitted authority and never trust an unvalidated caller-supplied label.
- Movement
Order Error - Movement
Subject Role - The physical role of a subject in a movement manifest.
- Observation
Policy - Observation
Principal - An observation identity authorized by the run’s persisted observation
policy. This type is intentionally constructed through
Canwu::viewer_contextso an observation request cannot self-escalate. - Owner
Authorized Participant Role - Payload
Schema - Payload
Value Type - Random
Algorithm - Random
Draw Address - Persisted address of a random draw.
- Random
Draw Outcome - Random
Draw Producer - Random
Operation Target - Stable application target for an operation-addressed random draw.
- Reconciliation
Outcome - Result of reconciling the information-system delivery attempt.
- Reservation
Disposition - Routing
Algorithm - Routing
Endpoint Kind - Routing
Error - Rule
Choice - RunConfiguration
Snapshot - RunManifest
- The exact non-executable environment bound to a simulation run.
- RunPurpose
- Saga
State - Schema
Registry Error - Error returned when a schema registration would replace an existing type.
- Seat
Policy - Simulation
Granularity - Generic simulation granularity used by host applications to map aggregate, group, and individual actors onto the same authoritative engine.
- State
Page Retention Phase - State
Visibility - System
Cadence - System
Directive - Trace
Policy - Transfer
Mode - Transport
Error - Transport
Execution State - Traversal
Model
Constants§
- ADMISSION_
CURSOR_ FORMAT_ VERSION - Version of persisted monotonic boundary-admission cursors.
- CHECKPOINT_
JOURNAL_ FORMAT_ VERSION - Version of current-state checkpoints plus append-only evidence segments.
- COMMITMENT_
FORMAT_ VERSION - Version of the domain-separated checkpoint commitment contract.
- CONTROLLER_
AUTHORITY_ UNAVAILABLE_ REASON - Cancellation reason recorded on an open ticket whose assigned controller’s authority person became unavailable.
- DECISION_
ARCHIVE_ BUCKET_ PAGE_ FORMAT_ VERSION - DECISION_
ARCHIVE_ FORMAT_ VERSION - DECISION_
MAKER_ UNAVAILABLE_ REASON - Cancellation reason recorded on an open ticket whose person decision maker became unavailable.
- DECISION_
REQUEST_ COMMITMENT_ DOMAIN - ENGINE_
VERSION - IDENTITY_
EVIDENCE_ DEPENDENCIES_ FIELD - Reserved domain-record payload field declaring retained identity proofs.
- IDENTITY_
EVIDENCE_ DEPENDENCIES_ FORMAT_ VERSION - Current wire version of
IdentityEvidenceDependenciesV1. - MAX_
DECISION_ ARCHIVE_ BATCH_ ENTRIES - MAX_
DECISION_ HISTORY_ PAGE_ BYTES - MAX_
DECISION_ HISTORY_ PAGE_ SIZE - MAX_
INGRESS_ CANCELLATION_ REASON_ BYTES - Maximum UTF-8 byte length of a plugin ingress cancellation reason.
- MAX_
KNOWLEDGE_ PAGE_ SIZE - MAX_
OWNER_ AUTHORIZED_ MUTATIONS - MAX_
OWNER_ AUTHORIZED_ PARTICIPANTS - MAX_
STATE_ DELTA_ PAGES - Hard predecode cap for one initial or incremental Format-8 page graph.
A one-million-entry non-collision Patricia map can contain
2N - 1logical node pages; this leaves bounded room for its manifest and compact decision buckets without making the count unbounded. - MAX_
STATE_ PAGE_ BYTES - OWNER_
AUTHORIZED_ MAINTENANCE_ FORMAT_ VERSION - PAGED_
CHECKPOINT_ FORMAT_ VERSION - PAYLOAD_
REQUIRED_ EVIDENCE_ CONTINUATION_ FIELD - Reserved domain-record payload field declaring a payload-reading continuation.
- PAYLOAD_
REQUIRED_ EVIDENCE_ CONTINUATION_ FORMAT_ VERSION - Current wire version of
PayloadRequiredEvidenceContinuationV1. - PLUGIN_
DESCRIPTOR_ FORMAT_ VERSION - ROUTING_
ALGORITHM_ VERSION - RUN_
CONFIGURATION_ FORMAT_ VERSION - RUN_
MANIFEST_ FORMAT_ VERSION - SNAPSHOT_
FORMAT_ VERSION - Format 8 binds every decision attempt to its complete ingress request and activates content-addressed state-page persistence. Older snapshots, journals, and sub-contract versions are rejected before any mutable runtime state is constructed.
- STATE_
PAGE_ CODEC - STATE_
PAGE_ FORMAT_ VERSION - STATE_
REVISION_ FORMAT_ VERSION - Version of the authoritative revision commitment.
- TRANSPORT_
SEMANTIC_ VERSION
Traits§
- Archive
Provider - Archive
Store - Decision
Archive Provider - Decision
Archive Store - Decision
Policy - Decision
Rule - Domain
Entity Type - Marker implemented automatically for entity-class domain record types.
- Domain
Kind Class - Sealed type-level classification for application-defined record kinds.
- Domain
Record Type - Compile-time identity for one namespaced application-defined record kind.
- Domain
Value Type - Marker implemented automatically for non-entity domain record types.
- External
Policy - Human
Policy - LlmPolicy
- Plugin
Archive Object Provider - Namespace-aware host access used only by offline archive mark/sweep. Plugin callbacks decode and authenticate their own object formats; the kernel never needs to depend on downstream archive crates.
- Rule
Policy - Simulation
Plugin - A stateless executable package whose persisted identity must change whenever its authoritative behavior changes.
- State
Page Provider - State
Page Store - Utility
Evaluator - Utility
Policy
Functions§
- canonical_
byte_ hash - Computes a domain-separated BLAKE3 commitment over an already canonical byte payload.
- canonical_
hash - Computes the engine’s canonical JSON commitment for plugin-owned data.
- delivery_
completion_ operation_ key - format8_
decision_ locator_ scale_ probe - Runs the production decision archive lifecycle and reports its bounded locator metrics without exposing the scale fixture.
- format8_
patricia_ scale_ probe - Builds the actual Format-8 domain-record store, including the HAMT, ordered key pages, primary Patricia tree, reverse-reference tree, and successor/predecessor trees. The returned metrics describe every production Patricia index plus the materialized HAMT/key-page cardinalities.
- identity_
evidence_ dependencies_ property_ v1 - Returns the reserved property a domain-record schema must declare to
authoritatively produce
IdentityOnlydependencies. - payload_
required_ evidence_ continuation_ property_ v1 - Returns the reserved property a domain-record schema must declare to
authoritatively produce
PayloadRequireddependencies. - plan_
route - prepare_
state_ delta - state_
page_ id - verify_
state_ delta
Type Aliases§
- Boundary
System Handler - Owner
Authorized Maintenance Participant - Plugin-owned callback used by the kernel maintenance coordinator. The callback receives a read-scoped immutable view and must author the exact proposal for its own schemas; callers never supply participant mutations.
- Plugin
Archive Reachability Participant - Plugin-owned extension of the unified archive reachability manifest. The callback is registered with the plugin descriptor, so a restored runtime cannot silently omit a plugin archive from GC marking.
- Plugin
Command Handler - Simulation
System Handler - Compatibility-only synchronous event reactor.