pub struct SimulationView<'a> { /* private fields */ }Implementations§
Source§impl SimulationView<'_>
impl SimulationView<'_>
Sourcepub fn plugin_archive_object(
&self,
namespace: &str,
object_id: &str,
) -> Result<Option<Vec<u8>>, CanwuError>
pub fn plugin_archive_object( &self, namespace: &str, object_id: &str, ) -> Result<Option<Vec<u8>>, CanwuError>
Loads a package-owned cold object through the host provider attached to this runtime. Package code remains responsible for authenticating the bytes against its committed archive root before using them.
pub const fn time(&self) -> SimTime
pub fn army(&self, id: ArmyId) -> Result<Option<&Army>, CanwuError>
pub fn person(&self, id: PersonId) -> Result<Option<&Person>, CanwuError>
Sourcepub fn person_availability(
&self,
id: PersonId,
) -> Result<Option<&PersonAvailability>, CanwuError>
pub fn person_availability( &self, id: PersonId, ) -> Result<Option<&PersonAvailability>, CanwuError>
Returns committed core availability for a person after an explicit
canwu.core.person_availability read. None means alive and free.
Sourcepub fn persons_created_by_correlation(
&self,
plugin: &str,
correlation: &str,
) -> Result<Vec<CreatedPerson>, CanwuError>
pub fn persons_created_by_correlation( &self, plugin: &str, correlation: &str, ) -> Result<Vec<CreatedPerson>, CanwuError>
Finds committed person creations produced by one plugin with an exact correlation, so the proposing system can bind engine-allocated IDs at a later boundary. The lookup reads the persisted created-person registry, so it does not depend on retained evidence.
pub fn government( &self, id: GovernmentId, ) -> Result<Option<&Government>, CanwuError>
pub fn territory( &self, id: TerritoryId, ) -> Result<Option<&Territory>, CanwuError>
pub fn route(&self, id: RouteId) -> Result<Option<&Route>, CanwuError>
pub fn actor_knowledge( &self, actor: PersonId, ) -> Result<Option<&ActorKnowledge>, CanwuError>
Sourcepub fn knowledge_record_count_in_namespace(
&self,
namespace: &str,
) -> Result<usize, CanwuError>
pub fn knowledge_record_count_in_namespace( &self, namespace: &str, ) -> Result<usize, CanwuError>
Counts records in a knowledge namespace at the current proposal-visible cut.
Sourcepub fn knowledge_records(
&self,
holder: KnowledgeHolderRef,
query: &KnowledgeQuery,
) -> Result<KnowledgeQueryResult, CanwuError>
pub fn knowledge_records( &self, holder: KnowledgeHolderRef, query: &KnowledgeQuery, ) -> Result<KnowledgeQueryResult, CanwuError>
Queries holder-relative records for an omniscient plugin system.
This enforces the declared canwu.core.knowledge read and returns an
owned projection. It is not an actor-facing authorization API.
Sourcepub fn command(
&self,
id: CommandId,
) -> Result<Option<&CommandRecord>, CanwuError>
pub fn command( &self, id: CommandId, ) -> Result<Option<&CommandRecord>, CanwuError>
Resolves an exact command ID from the retained runtime journal in O(1).
An archived command remains valid identity evidence, but its payload is
no longer available through this view: lookup returns
ErrorCode::EvidenceContentUnavailable. None means the ID has
neither retained content nor a committed archive receipt.
Sourcepub fn event(&self, id: EventId) -> Result<Option<&SimEvent>, CanwuError>
pub fn event(&self, id: EventId) -> Result<Option<&SimEvent>, CanwuError>
Resolves an exact event ID from the retained runtime journal in O(1).
An archived event remains valid identity evidence, but its payload is
no longer available through this view: lookup returns
ErrorCode::EvidenceContentUnavailable. None means the ID has
neither retained content nor a committed archive receipt.
pub fn ingress( &self, id: IngressId, ) -> Result<Option<&IngressRecord>, CanwuError>
Sourcepub fn cancellable_plugin_ingress(
&self,
) -> Result<Vec<&IngressRecord>, CanwuError>
pub fn cancellable_plugin_ingress( &self, ) -> Result<Vec<&IngressRecord>, CanwuError>
Lists the still-pending plugin ingress that this boundary system’s own
plugin scheduled inside the engine and may withdraw with
crate::BoundaryDirective::CancelPluginIngress, in ingress-ID order.
Only items due strictly after the view time are listed. Items that a boundary directive scheduled earlier in the current boundary appear from the next boundary; items generated by this plugin’s commands are listed as soon as they are queued. Views that are not bound to a boundary system list nothing.
Sourcepub fn transition_manifests(
&self,
) -> Result<Vec<&PendingTransitionManifest>, CanwuError>
pub fn transition_manifests( &self, ) -> Result<Vec<&PendingTransitionManifest>, CanwuError>
Lists the pending transition manifests that this boundary system’s
plugin coordinates or participates in, in manifest-ID order, after an
explicit canwu.core.transitions read.
A manifest’s expected versions name other plugins’ records, so the
list is relative to the reading plugin; other plugins’ manifests and
views not bound to a boundary system list nothing. Inside a boundary,
a manifest registered by an earlier phase is listed from the next phase
on, and a manifest that settled at phase 11 is no longer listed. A
participant stages for the manifests whose ready_at is the current
boundary and that list its plugin.
Sourcepub fn transition_audits(
&self,
) -> Result<Vec<&TransitionAuditRecord>, CanwuError>
pub fn transition_audits( &self, ) -> Result<Vec<&TransitionAuditRecord>, CanwuError>
Returns the audits of the transition manifests that settled at phase 11
of the current boundary and that this boundary system’s plugin
coordinates or participates in, in manifest-ID order, after an
explicit canwu.core.transitions read.
A failed audit fails the boundary instead of leaving a record, so every
outcome is crate::TransitionAuditOutcome::Committed or
crate::TransitionAuditOutcome::Expired. Earlier phases and views
not bound to a boundary system see no audits; hosts read settled
audits from crate::BoundaryRecord::transition_audits and
crate::BoundaryReceipt::transition_audits.
Sourcepub fn plugin_ingress_matches(
&self,
id: IngressId,
plugin: &str,
packet_type: &str,
) -> Result<bool, CanwuError>
pub fn plugin_ingress_matches( &self, id: IngressId, plugin: &str, packet_type: &str, ) -> Result<bool, CanwuError>
Matches retained, plugin-generated ingress provenance without exposing its payload.
Durable evidence may cite ingress admitted at an earlier boundary, but a generated record still waiting in the scheduler is not yet admissible. Format-7 archive receipts retain a Merkle-bound compact producer proof, so archived payload bytes do not need to return to the hot path.
Sourcepub fn plugin_ingress_payload_matches(
&self,
id: IngressId,
plugin: &str,
packet_type: &str,
occurred_at: SimTime,
expected_payload: &Value,
) -> Result<bool, CanwuError>
pub fn plugin_ingress_payload_matches( &self, id: IngressId, plugin: &str, packet_type: &str, occurred_at: SimTime, expected_payload: &Value, ) -> Result<bool, CanwuError>
Matches a retained plugin ingress to an exact provider payload and delivery time. Payload inspection is deliberately limited to retained records: archived receipts prove producer identity, but cannot safely be reused to authorize a different legal proposal without the original bytes.
Sourcepub fn decision_attempt(
&self,
request_id: DecisionRequestId,
) -> Result<Option<&DecisionAttemptRecord>, CanwuError>
pub fn decision_attempt( &self, request_id: DecisionRequestId, ) -> Result<Option<&DecisionAttemptRecord>, CanwuError>
Returns the retained outcome for one exact decision request.
Sourcepub fn decision_controller(
&self,
id: &str,
) -> Result<Option<&DecisionControllerBinding>, CanwuError>
pub fn decision_controller( &self, id: &str, ) -> Result<Option<&DecisionControllerBinding>, CanwuError>
Returns one current decision-controller binding after an explicit core read.
Sourcepub fn decision_ticket(
&self,
id: DecisionTicketId,
) -> Result<Option<&DecisionTicket>, CanwuError>
pub fn decision_ticket( &self, id: DecisionTicketId, ) -> Result<Option<&DecisionTicket>, CanwuError>
Returns one current decision ticket after an explicit core read.
pub fn domain_record( &self, reference: &DomainRecordRef, ) -> Result<Option<&DomainRecord>, CanwuError>
pub fn typed_domain_record<T: DomainRecordType>( &self, reference: &TypedDomainRecordRef<T>, ) -> Result<Option<&DomainRecord>, CanwuError>
pub fn proposed_domain_record( &self, reference: &DomainRecordRef, ) -> Result<Option<&DomainRecord>, CanwuError>
pub fn proposed_typed_domain_record<T: DomainRecordType>( &self, reference: &TypedDomainRecordRef<T>, ) -> Result<Option<&DomainRecord>, CanwuError>
Sourcepub fn proposed_domain_record_version(
&self,
reference: &DomainRecordRef,
) -> Result<Option<DomainRecordVersionRef>, CanwuError>
pub fn proposed_domain_record_version( &self, reference: &DomainRecordRef, ) -> Result<Option<DomainRecordVersionRef>, CanwuError>
Returns the exact evidence reference assigned to a domain-record version proposed earlier in the current boundary.
Sourcepub fn current_domain_record_version(
&self,
reference: &DomainRecordRef,
) -> Result<Option<DomainRecordVersionRef>, CanwuError>
pub fn current_domain_record_version( &self, reference: &DomainRecordRef, ) -> Result<Option<DomainRecordVersionRef>, CanwuError>
Returns the exact evidence reference for the currently visible version
of a domain record. Strategic aggregation runs after atomic commit,
therefore it cannot use Self::proposed_domain_record_version.
The current boundary overlay/proposal is preferred, followed by the runtime’s verified current-record provenance index. The index is maintained at commit time and rebuilt from canonical evidence on restore, so lookup does not scan retained or archived history.
Sourcepub fn domain_record_version_evidence_exists(
&self,
reference: &DomainRecordVersionRef,
) -> Result<bool, CanwuError>
pub fn domain_record_version_evidence_exists( &self, reference: &DomainRecordVersionRef, ) -> Result<bool, CanwuError>
Returns whether an exact domain-record version reference is valid at this proposal-visible cut.
This validates both the record identity/version and its establishment source. Earlier same-boundary proposals are considered before retained or archived runtime evidence. Either the exact record-kind read or the administrative domain-record read grants access.
Sourcepub fn domain_record_version_is_current(
&self,
reference: &DomainRecordVersionRef,
) -> Result<bool, CanwuError>
pub fn domain_record_version_is_current( &self, reference: &DomainRecordVersionRef, ) -> Result<bool, CanwuError>
Checks that an exact domain-record version is both valid evidence and current.
Sourcepub fn evidence_exists(
&self,
reference: &EvidenceRef,
) -> Result<bool, CanwuError>
pub fn evidence_exists( &self, reference: &EvidenceRef, ) -> Result<bool, CanwuError>
Returns whether a generic evidence identity is retained or archived.
Domain-record versions proposed earlier in this boundary are visible. Archived identities count as existing even when their bodies are no longer retained.
Sourcepub fn evidence_time(
&self,
reference: &EvidenceRef,
) -> Result<Option<SimTime>, CanwuError>
pub fn evidence_time( &self, reference: &EvidenceRef, ) -> Result<Option<SimTime>, CanwuError>
Returns when retained or earlier same-boundary evidence first became authoritative at this proposal-visible cut.
Archived identity receipts do not retain a precise semantic time, so
they return None and callers that require temporal ordering must fail
closed or load the archived evidence body.
Sourcepub fn domain_record_version(
&self,
reference: &DomainRecordVersionRef,
) -> Result<Option<DomainRecord>, CanwuError>
pub fn domain_record_version( &self, reference: &DomainRecordVersionRef, ) -> Result<Option<DomainRecord>, CanwuError>
Resolves the retained record body for one exact domain-record version.
Archived receipts prove that a version existed but do not contain its
body, so this returns None when the corresponding evidence segment is
not live in the runtime.
Sourcepub fn domain_records_of_kind(
&self,
kind: &DomainRecordKind,
limit: usize,
) -> Result<Vec<DomainRecord>, CanwuError>
pub fn domain_records_of_kind( &self, kind: &DomainRecordKind, limit: usize, ) -> Result<Vec<DomainRecord>, CanwuError>
Returns a bounded, deterministic projection of records of one kind.
Same-boundary overlays take precedence over current state. Records are ordered by their canonical reference, so result order is replay stable.
Sourcepub fn domain_records_of_kind_after(
&self,
kind: &DomainRecordKind,
after: Option<&DomainRecordRef>,
limit: usize,
) -> Result<Vec<DomainRecord>, CanwuError>
pub fn domain_records_of_kind_after( &self, kind: &DomainRecordKind, after: Option<&DomainRecordRef>, limit: usize, ) -> Result<Vec<DomainRecord>, CanwuError>
Returns one bounded deterministic page of records after a canonical record-reference cursor.
The cursor is exclusive and must name the same kind. This keeps plugin
scans bounded without imposing a 10,000-record lifetime ceiling on a
domain kind. Same-boundary overlays retain the same precedence as
Self::domain_records_of_kind.
Sourcepub fn knowledge_changes_by_correlation(
&self,
plugin: &str,
producer_correlation: &str,
) -> Result<Vec<BoundaryKnowledgeChange>, CanwuError>
pub fn knowledge_changes_by_correlation( &self, plugin: &str, producer_correlation: &str, ) -> Result<Vec<BoundaryKnowledgeChange>, CanwuError>
Finds committed knowledge changes produced with an exact correlation.
This supports next-boundary operation finalization without granting a plugin unrestricted access to unrelated knowledge payloads.
Sourcepub fn knowledge_changes_by_correlation_prefix(
&self,
plugin: &str,
producer_correlation_prefix: &str,
) -> Result<Vec<BoundaryKnowledgeChange>, CanwuError>
pub fn knowledge_changes_by_correlation_prefix( &self, plugin: &str, producer_correlation_prefix: &str, ) -> Result<Vec<BoundaryKnowledgeChange>, CanwuError>
Finds committed knowledge changes whose producer correlation begins with a deterministic operation prefix.
The prefix remains plugin-scoped. This is intended for bounded multi-holder operation finalization where every holder batch must keep a unique full correlation value.