pub enum BoundaryDirective {
Show 13 variants
SetComponent {
state: StateKey,
entity: EntityRef,
component: String,
value: Value,
summary: String,
},
MutateRecord {
mutation: DomainRecordMutation,
summary: String,
},
Emit {
event_type: String,
summary: String,
affected: Vec<EntityRef>,
},
ScheduleIngress {
after: SimDuration,
packet_type: String,
priority: i32,
payload: Value,
affected: Vec<EntityRef>,
},
SchedulePluginIngress {
target_plugin: String,
after: SimDuration,
packet_type: String,
priority: i32,
payload: Value,
affected: Vec<EntityRef>,
},
ResolveDecisionRandomly {
resolution: RandomDecisionResolution,
},
PublishKnowledge {
holder: KnowledgeHolderRef,
visibility: StateVisibility,
producer_correlation: Option<String>,
records: Vec<KnowledgeRecordDraft>,
summary: String,
},
SetPersonAvailability {
person: PersonId,
availability: PersonAvailability,
summary: String,
},
CreatePerson {
draft: PersonDraft,
correlation: String,
summary: String,
},
CancelPluginIngress {
ingress_id: IngressId,
reason: String,
},
RecordEvaluationTrace {
trace: EvaluationTraceRecord,
},
RegisterTransitionManifest {
manifest: TransitionManifest,
},
StageTransitionWrite {
manifest_id: TransitionManifestId,
writes: Vec<BoundaryDirective>,
},
}Variants§
SetComponent
MutateRecord
Emit
ScheduleIngress
SchedulePluginIngress
Fields
after: SimDurationResolveDecisionRandomly
Resolves an open ticket with an operation-keyed random draw bound to
the ticket and its version, either for a controller with random policy
identity or as a guarded utility policy’s random tie-break. The
boundary generates the Resolve decision ingress, admitted at the next
boundary.
Before any draw is committed, the directive fails the boundary when
the ticket’s person decision maker
(crate::ErrorCode::DecisionMakerUnavailable) or its assigned
controller’s authority person (crate::ErrorCode::IssuerUnavailable)
is unavailable in the availability committed before this boundary. The
authority person is the actor of an actor authority or the responsible
actor of an institution authority. Because the end-of-boundary sweep
and Open admission keep such tickets from staying open, this is a
safeguard. Any availability change made in the same boundary does not
fail the directive, because failing would roll the change back and
repeat on every retry; the draw is then committed, the end-of-boundary
sweep cancels the ticket (see
BoundaryDirective::SetPersonAvailability), and the generated
resolution is rejected at admission. To avoid that wasted draw,
tie-break and random-policy systems should skip tickets whose decision
maker or controller authority person is unavailable, read through
crate::SimulationView::person_availability (which requires
declaring StateKey::core_person_availability() in the contract’s
reads).
Fields
resolution: RandomDecisionResolutionPublishKnowledge
SetPersonAvailability
Replaces one person’s core life and custody state. Accepted from a
phase-7 or phase-10 system that declares
StateKey::core_person_availability() as a write; two writes for the
same person in one boundary fail the boundary.
Making a person unavailable cancels, at the end of the same boundary
and after the boundary’s random decisions are materialized, every open
decision ticket whose decision maker is that person
(crate::DECISION_MAKER_UNAVAILABLE_REASON) and then every remaining
open ticket whose assigned controller’s authority person is that
person (crate::CONTROLLER_AUTHORITY_UNAVAILABLE_REASON). The
authority person is the actor of an actor authority or the responsible
actor of an institution authority; council and no-responsible-actor
authorities are never affected. A ticket that qualifies for both
reasons carries the decision-maker reason. The cancelled IDs are
recorded in ticket-ID order on the boundary’s
crate::BoundaryPersonAvailabilityChange.
CreatePerson
Creates a person with an engine-allocated ID. Accepted from a phase-7
system that declares StateKey::core_people() as a write. The person
is committed at the end of the boundary and becomes visible to systems
at the next boundary; correlation is unique per plugin, system, and
boundary and binds the receipt’s allocated ID.
CancelPluginIngress
Withdraws one still-pending plugin ingress item that this system’s
plugin scheduled inside the engine (through ScheduleIngress,
SchedulePluginIngress, or a plugin command), strictly before the
item’s due time. The boundary records a terminal
crate::IngressPayload::PluginCancellation entry among its generated
ingress; the withdrawn item is never admitted.
Take targets from crate::SimulationView::cancellable_plugin_ingress
in the same boundary. A target that is foreign, already due, admitted,
or cancelled, or that another proposal already cancels in this
boundary, fails the whole boundary deterministically.
RecordEvaluationTrace
Records how an application rule produced one result for one subject. Accepted from any phase-7 or phase-12 system without a contract declaration. The trace must name this boundary, its subject identity must exist, and every term’s evidence must be committed evidence visible to the proposal.
The trace is recorded, with its producing system, in
crate::BoundaryRecord::evaluation_traces as hash-chained boundary
evidence. It is never state: it changes nothing, no system can read it
back, and it is sealed and archived with its boundary record. The run
configuration’s crate::EvaluationLimitsV1 bound the traces of the
whole boundary and the terms of each trace; a proposal set that
exceeds either bound fails the boundary with
crate::ErrorCode::EvaluationTraceLimitExceeded.
Fields
trace: EvaluationTraceRecordRegisterTransitionManifest
Registers a transition manifest coordinated by this system’s plugin.
Accepted from a phase-7, phase-10, or phase-12 system that declares
StateKey::core_transitions() as a write.
A manifest registered in phase 7 may be ready in the same boundary;
one registered in phase 10 or 12 must name a later boundary, and none
may be ready more than crate::MAX_TRANSITION_READY_HORIZON
boundaries ahead. Every participant must be a registered plugin with a
phase-10 system that declares the same write, and every expected record
must be of a registered kind. One coordinator may have one pending
manifest per lineage and at most
crate::MAX_PENDING_TRANSITION_MANIFESTS_PER_COORDINATOR pending
manifests, within crate::MAX_PENDING_TRANSITION_MANIFESTS overall.
The registration becomes visible to the coordinator and participants
from the next phase through
crate::SimulationView::transition_manifests and is recorded in
BoundaryRecord::transition_manifests.
Fields
manifest: TransitionManifestStageTransitionWrite
Stages ordinary directives as this plugin’s part of a transition
manifest that is ready at this boundary. Accepted only from a phase-10
system of a listed participant that declares
StateKey::core_transitions() as a write; another plugin’s staging
fails the boundary with crate::ErrorCode::InvalidAuthority.
Each staged write must be a directive this system could propose
directly: its declared writes, ownership, and phase rules apply, and it
commits with the system’s visibility. An empty writes list records
the participant’s presence without writing. Before phase 11 commits,
the kernel audits every ready manifest: when some, but not all,
participants staged (crate::ErrorCode::TransitionParticipantMissing)
or an expected version differs
(crate::ErrorCode::TransitionVersionMismatch), the whole boundary
fails closed; when none staged, the manifest expires, so a
single-participant manifest cannot fail for omission. The audit is
recorded in BoundaryRecord::transition_audits and readable through
crate::SimulationView::transition_audits.
Trait Implementations§
Source§impl Clone for BoundaryDirective
impl Clone for BoundaryDirective
Source§fn clone(&self) -> BoundaryDirective
fn clone(&self) -> BoundaryDirective
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read more