Skip to main content

Crate canwu_sim

Crate canwu_sim 

Source
Expand description

Deterministic runtime, validated commands, scheduling, plugins, and snapshots.

Structs§

ActorKnowledge
ArchiveReachabilityManifest
Unified offline GC mark set for kernel-owned pages, evidence, decision blobs, and namespaced plugin archive objects.
ArchivedEvidenceLocator
ArchivedEvidenceReceipt
ArchivedPluginIngressProvenance
ArchivedSegmentHeader
Army
ArmyKnowledge
ArtifactManifest
Stable identity for a scenario, ruleset, content pack, run policy, localization contract, or source ledger.
BoundaryChange
BoundaryContext
BoundaryEmission
BoundaryIngressGeneration
BoundaryKnowledgeChange
BoundaryPersonAvailabilityChange
Committed availability change evidence in a boundary record.
BoundaryPersonCreation
Committed person-creation evidence in a boundary record.
BoundaryProposal
BoundaryReceipt
BoundaryRecord
BoundaryRequest
BoundarySystemContract
CanwuError
CheckpointJournal
Portable full-save bundle built from a current-state checkpoint and journal segments.
CommandAttemptRecord
CommandAuthority
CommandContext
CommandEnvelope
CommandReceipt
CommandRecord
CommandRejection
CommandRequest
CommitmentRoots
Canonical roots for independent authoritative state and evidence domains.
CompactedSimulation
A live simulation whose sealed evidence prefixes are owned by the caller.
CreatedPerson
Receipt entry binding a creation correlation to its engine-allocated ID.
DecisionArchiveBlob
DecisionArchiveBucketPage
DecisionArchivePageKey
DecisionArchiveReceipt
DecisionAttemptRecord
DecisionContext
DecisionController
DecisionControllerBinding
DecisionError
DecisionExternalEvidence
DecisionFactorContribution
DecisionHistoryCursor
DecisionHistoryPage
DecisionHistoryQueryBudget
DecisionHotState
DecisionIngressRequest
DecisionLocatorScaleMetrics
DecisionOption
DecisionOptionEvaluation
DecisionOptionWeight
DecisionPolicyIdentity
DecisionRandomEvidence
DecisionState
DecisionTicket
DecisionTicketDraft
DecisionTrace
DemoIds
DomainRecord
DomainRecordChange
DomainRecordCommitmentRoots
Independent commitment roots for the Format-8 domain-record store.
DomainRecordDraft
DomainRecordPage
One deterministic trusted-host page of records from an authoritative read cut.
DomainRecordPageRoots
DomainRecordSchema
DomainRecordVersionRef
Exact historical identity for an application-defined record version.
DomainReference
DomainReferenceSchema
EstimateRange
EventKind
Domain-neutral event identity and structured fields.
EvidenceArchiveIndex
EvidenceCursor
Monotonic cuts through every append-only evidence journal.
EvidenceDependency
EvidenceIndexEntry
EvidenceItemLocator
EvidenceJournalRoots
EvidenceJournalSegment
One contiguous append-only evidence range for incremental archival.
EvidenceSealToken
ExternalDecisionOption
ExternalDecisionRequest
ExternalDecisionResponse
Government
GuardedUtilityPolicy
A composite policy: ordered guards, then weighted utility over the options the guards left, then an optional bounded random tie-break.
HolderKnowledgeRecordId
Stable numeric identifier for HolderKnowledgeRecordId.
HumanDecisionResponse
IdentityEvidenceDependenciesV1
Authoritative identity-only evidence dependencies for a live domain record.
IngressReceipt
IngressRecord
KeyedDrawReservation
KnowledgeCursor
KnowledgeLimitsV1
KnowledgeOrigin
KnowledgeQuery
KnowledgeReadCut
KnowledgeRecord
KnowledgeRecordDraft
KnowledgeRecordId
Stable numeric identifier for KnowledgeRecordId.
KnowledgeRecordKind
Stable namespace and kind for a holder-relative knowledge record.
KnowledgeRecordView
KnowledgeSchemaId
Exact version of one registered knowledge schema.
KnowledgeSnapshot
KnowledgeSubject
KnowledgeSubjectSchema
KnowledgeWriteGrant
LetterCargo
LlmModelIdentity
MaintenanceChangeRecord
MaintenanceDependencyResolverDescriptor
Declares that a plugin must participate when a target namespace is retired through owner-authorized maintenance. The declaration is persisted in the plugin descriptor, so replay and restore cannot silently omit a dependent owner.
MaintenanceRejectionReceipt
MapPoint
OrderedRulePolicy
OutboxEntry
Durable, idempotent external-delivery identity derived from committed boundary evidence. The engine creates one entry for every emission; a host may deliver it at least once and use delivery_id as its idempotency key.
OwnerAuthorizedMaintenanceDraft
OwnerAuthorizedMaintenanceRequest
OwnerAuthorizedMutation
OwnerAuthorizedParticipantDraft
OwnerAuthorizedParticipantProposal
OwnerAuthorizedRecordExpectation
PagedCheckpointScaleMetrics
PagedSimulationCheckpoint
PatriciaStoreMetrics
PayloadProperty
PayloadRequiredEvidenceContinuationV1
Authoritative pending-continuation contract for rules that must inspect old payload bytes.
PersistentDecisionLog
Structurally shared append-only decision log.
PersistentDomainRecordStore
Person
PersonAvailability
Core life and custody state of one person.
PersonDraft
Application-supplied content for a person created at a boundary.
PersonTransitState
PluginActionDescriptor
PluginArchiveRetention
PluginComponentRecord
PluginDescriptor
PluginIngressDescriptor
PluginIngressPermit
Opaque capability issued only while a plugin registers a kernel-internal ingress type. Hosts can pass the capability back but cannot construct or alter it.
PluginIngressRequest
PluginIngressTarget
PluginKnowledgeSchema
PluginRegistrar
PluginRegistry
PolicyDecision
PortablePagedSimulationCheckpoint
PreparedDecisionArchive
PreparedDecisionIngress
PreparedEvidenceSeal
PreparedPagedSimulationCheckpoint
PreparedStateDelta
QueuedExternalPolicy
QueuedHumanPolicy
QueuedLlmPolicy
RandomDecisionResolution
RandomDrawRecord
RandomOperationAddressV1
Version-one stable entropy address for a future keyed random draw.
RandomSample
RandomStreamKey
RandomStreamState
ReplayJournal
Complete recorded environment and input journal for exact replay.
ReservationAllocation
ReservationOffer
ReservationOfferRecord
ReservationPoolKey
ReservationRef
ReservationRequest
ReservationRequestRecord
Route
RunConfiguration
Scenario
SeatBinding
SimEvent
Simulation
SimulationCheckpoint
Current authoritative state plus the journal cut required to validate it.
SimulationSnapshot
SimulationView
StateKey
StatePageBlob
StatePageRetentionHandle
StatePageRetentionLedger
Persistable host-side mark/sweep interlock for content-addressed state pages. Preparing, verifying, or durably enqueueing a root protects every declared reachable page across process restart. A committed root takes over that lease atomically before the transient handle may disappear.
SystemContract
Territory
TraceLocatorScaleMetrics
TransitState
UtilityProfile
VerifiedDecisionArchiveCommit
Provider-verified, replay-safe archive transition. Blob bytes remain in the host archive; canonical ingress carries only the exact hot-state source root, token, and compact receipts needed to revalidate the transition.
VerifiedOwnerAuthorizedMaintenanceCommit
WeightedUtilityEvaluator
WeightedUtilityPolicy
WorldSnapshot

Enums§

ArchiveStoreOutcome
BoundaryDirective
BoundaryEmissionKind
BoundaryPhase
CauseRef
Command
CommandAttemptOutcome
CommandIngress
CommandOutcome
CommandPolicyContext
Command-relevant policy deliberately omits run purpose, observation, and trace so authoritative handlers cannot branch on presentation-only inputs.
ControllerDecision
ControllerPolicy
CustodyState
Whether a person is free to act. Absent availability means CustodyState::Free.
DecisionAction
DecisionArchiveRecord
DecisionArchiveStoreOutcome
DecisionAttemptErrorCode
DecisionAttemptOutcome
DecisionAuthority
DecisionErrorCode
DecisionEvaluation
DecisionHistoryKey
Typed identity for decision history. A scalar ID is not enough because tickets, caller-selected requests, and engine-issued traces have different uniqueness and retention rules.
DecisionHistoryLocation
DecisionMutation
DecisionOrigin
DecisionOutcome
DecisionPolicyKind
DecisionStage
The stage of a composite policy that produced a decision. Decisions from single-stage policies, and every historical trace, carry no stage.
DecisionTicketState
DomainRecordClass
DomainRecordLifecycle
DomainRecordMutation
DomainRecordMutationPolicy
DomainRecordOperation
DomainRecordVersionSource
Persisted identity of the operation that established one domain-record version. Version zero is reserved and rejected by runtime validation.
DomainReferenceTarget
DomainReferenceTargetKind
ErrorCode
EventAudience
Declarative audience for a persisted event projection.
EvidenceJournalKind
EvidenceNestedLocator
EvidenceRef
Shared persisted-evidence identity used by knowledge, decisions, random operations, replay, and compact archive receipts.
EvidenceRequirement
IngressCancellationAuthority
Authority that withdrew a queued plugin ingress item.
IngressClass
IngressPayload
InteractionPolicy
Issuer
KnowledgeHistoryView
KnowledgeHolderPolicy
Whether a domain entity schema may receive holder-relative knowledge.
KnowledgeHolderRef
Stable holder identity shared by people and eligible institutional entities.
KnowledgeSource
KnowledgeSubjectTarget
KnowledgeSubjectTargetKind
LetterStatus
LifeState
Whether a person is alive. Absent availability means LifeState::Alive.
MaintenanceDisposition
MaintenanceIngressRequest
ObservationPolicy
OwnerAuthorizedParticipantRole
PayloadSchema
PayloadValueType
RandomAlgorithm
RandomDrawAddress
Persisted address of a random draw.
RandomDrawOutcome
RandomDrawProducer
RandomOperationTarget
Stable application target for an operation-addressed random draw.
ReservationDisposition
RuleChoice
RunConfigurationSnapshot
RunManifest
The exact non-executable environment bound to a simulation run.
RunPurpose
SeatPolicy
StatePageRetentionPhase
StateVisibility
SystemCadence
SystemDirective
TracePolicy

Constants§

ADMISSION_CURSOR_FORMAT_VERSION
Version of persisted monotonic boundary-admission cursors.
CHECKPOINT_JOURNAL_FORMAT_VERSION
Version of current-state checkpoints plus append-only evidence segments.
COMMITMENT_FORMAT_VERSION
Version of the domain-separated checkpoint commitment contract.
CONTROLLER_AUTHORITY_UNAVAILABLE_REASON
Cancellation reason recorded on an open ticket whose assigned controller’s authority person became unavailable.
DECISION_ARCHIVE_BUCKET_PAGE_FORMAT_VERSION
DECISION_ARCHIVE_FORMAT_VERSION
DECISION_MAKER_UNAVAILABLE_REASON
Cancellation reason recorded on an open ticket whose person decision maker became unavailable.
DECISION_REQUEST_COMMITMENT_DOMAIN
ENGINE_VERSION
IDENTITY_EVIDENCE_DEPENDENCIES_FIELD
Reserved domain-record payload field declaring retained identity proofs.
IDENTITY_EVIDENCE_DEPENDENCIES_FORMAT_VERSION
Current wire version of IdentityEvidenceDependenciesV1.
MAX_DECISION_ARCHIVE_BATCH_ENTRIES
MAX_DECISION_HISTORY_PAGE_BYTES
MAX_DECISION_HISTORY_PAGE_SIZE
MAX_INGRESS_CANCELLATION_REASON_BYTES
Maximum UTF-8 byte length of a plugin ingress cancellation reason.
MAX_OWNER_AUTHORIZED_MUTATIONS
MAX_OWNER_AUTHORIZED_PARTICIPANTS
MAX_STATE_DELTA_PAGES
Hard predecode cap for one initial or incremental Format-8 page graph. A one-million-entry non-collision Patricia map can contain 2N - 1 logical node pages; this leaves bounded room for its manifest and compact decision buckets without making the count unbounded.
MAX_STATE_PAGE_BYTES
MAX_SYNCHRONOUS_REACTION_DEPTH
Maximum nested depth of the compatibility synchronous event-reactor path.
OWNER_AUTHORIZED_MAINTENANCE_FORMAT_VERSION
PAGED_CHECKPOINT_FORMAT_VERSION
PAYLOAD_REQUIRED_EVIDENCE_CONTINUATION_FIELD
Reserved domain-record payload field declaring a payload-reading continuation.
PAYLOAD_REQUIRED_EVIDENCE_CONTINUATION_FORMAT_VERSION
Current wire version of PayloadRequiredEvidenceContinuationV1.
PLUGIN_DESCRIPTOR_FORMAT_VERSION
RUN_CONFIGURATION_FORMAT_VERSION
RUN_MANIFEST_FORMAT_VERSION
SNAPSHOT_FORMAT_VERSION
Format 8 binds every decision attempt to its complete ingress request and activates content-addressed state-page persistence. Older snapshots, journals, and sub-contract versions are rejected before any mutable runtime state is constructed.
STATE_PAGE_CODEC
STATE_PAGE_FORMAT_VERSION
STATE_PAGE_RETENTION_FORMAT_VERSION
STATE_REVISION_FORMAT_VERSION
Version of the authoritative revision commitment.

Traits§

ArchiveProvider
ArchiveStore
DecisionArchiveProvider
DecisionArchiveStore
DecisionPolicy
DecisionRule
ExternalPolicy
HumanPolicy
LlmPolicy
PluginArchiveObjectProvider
Namespace-aware host access used only by offline archive mark/sweep. Plugin callbacks decode and authenticate their own object formats; the kernel never needs to depend on downstream archive crates.
RulePolicy
SimulationPlugin
A stateless executable package whose persisted identity must change whenever its authoritative behavior changes.
StatePageProvider
StatePageStore
UtilityEvaluator
UtilityPolicy

Functions§

canonical_byte_hash
Computes a domain-separated BLAKE3 commitment over an already canonical byte payload.
canonical_hash
Computes the engine’s canonical JSON commitment for plugin-owned data.
demo_scenario
format8_decision_locator_scale_probe
Runs the production decision archive lifecycle and reports its bounded locator metrics without exposing the scale fixture.
format8_paged_checkpoint_scale_probe
Runs the real Simulation paged-checkpoint boundary over a decision locator fixture, including storage, authenticated restore, empty-suffix replay, exact provider-backed lookups, and a zero-page repeat delta.
format8_patricia_scale_probe
Builds the actual Format-8 domain-record store, including the HAMT, ordered key pages, primary Patricia tree, reverse-reference tree, and successor/predecessor trees. The returned metrics describe every production Patricia index plus the materialized HAMT/key-page cardinalities.
format8_trace_locator_scale_probe
Exercises the trace locator and archive-commit path with a large retained hot trace log. The target is the final ordinal, which made the former linear scan hit its worst case.
identity_evidence_dependencies_property_v1
Returns the reserved property a domain-record schema must declare to authoritatively produce IdentityOnly dependencies.
payload_required_evidence_continuation_property_v1
Returns the reserved property a domain-record schema must declare to authoritatively produce PayloadRequired dependencies.
prepare_state_delta
state_page_id
verify_state_delta

Type Aliases§

BoundarySystemHandler
OwnerAuthorizedMaintenanceParticipant
Plugin-owned callback used by the kernel maintenance coordinator. The callback receives a read-scoped immutable view and must author the exact proposal for its own schemas; callers never supply participant mutations.
PluginArchiveReachabilityParticipant
Plugin-owned extension of the unified archive reachability manifest. The callback is registered with the plugin descriptor, so a restored runtime cannot silently omit a plugin archive from GC marking.
PluginCommandHandler
SimulationSystemHandler
Compatibility-only synchronous event reactor.