Skip to main content

BoundaryDirective

Enum BoundaryDirective 

Source
pub enum BoundaryDirective {
Show 13 variants SetComponent { state: StateKey, entity: EntityRef, component: String, value: Value, summary: String, }, MutateRecord { mutation: DomainRecordMutation, summary: String, }, Emit { event_type: String, summary: String, affected: Vec<EntityRef>, }, ScheduleIngress { after: SimDuration, packet_type: String, priority: i32, payload: Value, affected: Vec<EntityRef>, }, SchedulePluginIngress { target_plugin: String, after: SimDuration, packet_type: String, priority: i32, payload: Value, affected: Vec<EntityRef>, }, ResolveDecisionRandomly { resolution: RandomDecisionResolution, }, PublishKnowledge { holder: KnowledgeHolderRef, visibility: StateVisibility, producer_correlation: Option<String>, records: Vec<KnowledgeRecordDraft>, summary: String, }, SetPersonAvailability { person: PersonId, availability: PersonAvailability, summary: String, }, CreatePerson { draft: PersonDraft, correlation: String, summary: String, }, CancelPluginIngress { ingress_id: IngressId, reason: String, }, RecordEvaluationTrace { trace: EvaluationTraceRecord, }, RegisterTransitionManifest { manifest: TransitionManifest, }, StageTransitionWrite { manifest_id: TransitionManifestId, writes: Vec<BoundaryDirective>, },
}

Variants§

§

SetComponent

Fields

§state: StateKey
§entity: EntityRef
§component: String
§value: Value
§summary: String
§

MutateRecord

Fields

§summary: String
§

Emit

Fields

§event_type: String
§summary: String
§affected: Vec<EntityRef>
§

ScheduleIngress

Fields

§packet_type: String
§priority: i32
§payload: Value
§affected: Vec<EntityRef>
§

SchedulePluginIngress

Fields

§target_plugin: String
§packet_type: String
§priority: i32
§payload: Value
§affected: Vec<EntityRef>
§

ResolveDecisionRandomly

Resolves an open ticket with an operation-keyed random draw bound to the ticket and its version, either for a controller with random policy identity or as a guarded utility policy’s random tie-break. The boundary generates the Resolve decision ingress, admitted at the next boundary.

Before any draw is committed, the directive fails the boundary when the ticket’s person decision maker (crate::ErrorCode::DecisionMakerUnavailable) or its assigned controller’s authority person (crate::ErrorCode::IssuerUnavailable) is unavailable in the availability committed before this boundary. The authority person is the actor of an actor authority or the responsible actor of an institution authority. Because the end-of-boundary sweep and Open admission keep such tickets from staying open, this is a safeguard. Any availability change made in the same boundary does not fail the directive, because failing would roll the change back and repeat on every retry; the draw is then committed, the end-of-boundary sweep cancels the ticket (see BoundaryDirective::SetPersonAvailability), and the generated resolution is rejected at admission. To avoid that wasted draw, tie-break and random-policy systems should skip tickets whose decision maker or controller authority person is unavailable, read through crate::SimulationView::person_availability (which requires declaring StateKey::core_person_availability() in the contract’s reads).

Fields

§

PublishKnowledge

Fields

§visibility: StateVisibility
§producer_correlation: Option<String>
§summary: String
§

SetPersonAvailability

Replaces one person’s core life and custody state. Accepted from a phase-7 or phase-10 system that declares StateKey::core_person_availability() as a write; two writes for the same person in one boundary fail the boundary.

Making a person unavailable cancels, at the end of the same boundary and after the boundary’s random decisions are materialized, every open decision ticket whose decision maker is that person (crate::DECISION_MAKER_UNAVAILABLE_REASON) and then every remaining open ticket whose assigned controller’s authority person is that person (crate::CONTROLLER_AUTHORITY_UNAVAILABLE_REASON). The authority person is the actor of an actor authority or the responsible actor of an institution authority; council and no-responsible-actor authorities are never affected. A ticket that qualifies for both reasons carries the decision-maker reason. The cancelled IDs are recorded in ticket-ID order on the boundary’s crate::BoundaryPersonAvailabilityChange.

Fields

§person: PersonId
§availability: PersonAvailability
§summary: String
§

CreatePerson

Creates a person with an engine-allocated ID. Accepted from a phase-7 system that declares StateKey::core_people() as a write. The person is committed at the end of the boundary and becomes visible to systems at the next boundary; correlation is unique per plugin, system, and boundary and binds the receipt’s allocated ID.

Fields

§correlation: String
§summary: String
§

CancelPluginIngress

Withdraws one still-pending plugin ingress item that this system’s plugin scheduled inside the engine (through ScheduleIngress, SchedulePluginIngress, or a plugin command), strictly before the item’s due time. The boundary records a terminal crate::IngressPayload::PluginCancellation entry among its generated ingress; the withdrawn item is never admitted.

Take targets from crate::SimulationView::cancellable_plugin_ingress in the same boundary. A target that is foreign, already due, admitted, or cancelled, or that another proposal already cancels in this boundary, fails the whole boundary deterministically.

Fields

§ingress_id: IngressId
§reason: String
§

RecordEvaluationTrace

Records how an application rule produced one result for one subject. Accepted from any phase-7 or phase-12 system without a contract declaration. The trace must name this boundary, its subject identity must exist, and every term’s evidence must be committed evidence visible to the proposal.

The trace is recorded, with its producing system, in crate::BoundaryRecord::evaluation_traces as hash-chained boundary evidence. It is never state: it changes nothing, no system can read it back, and it is sealed and archived with its boundary record. The run configuration’s crate::EvaluationLimitsV1 bound the traces of the whole boundary and the terms of each trace; a proposal set that exceeds either bound fails the boundary with crate::ErrorCode::EvaluationTraceLimitExceeded.

§

RegisterTransitionManifest

Registers a transition manifest coordinated by this system’s plugin. Accepted from a phase-7, phase-10, or phase-12 system that declares StateKey::core_transitions() as a write.

A manifest registered in phase 7 may be ready in the same boundary; one registered in phase 10 or 12 must name a later boundary, and none may be ready more than crate::MAX_TRANSITION_READY_HORIZON boundaries ahead. Every participant must be a registered plugin with a phase-10 system that declares the same write, and every expected record must be of a registered kind. One coordinator may have one pending manifest per lineage and at most crate::MAX_PENDING_TRANSITION_MANIFESTS_PER_COORDINATOR pending manifests, within crate::MAX_PENDING_TRANSITION_MANIFESTS overall. The registration becomes visible to the coordinator and participants from the next phase through crate::SimulationView::transition_manifests and is recorded in BoundaryRecord::transition_manifests.

Fields

§

StageTransitionWrite

Stages ordinary directives as this plugin’s part of a transition manifest that is ready at this boundary. Accepted only from a phase-10 system of a listed participant that declares StateKey::core_transitions() as a write; another plugin’s staging fails the boundary with crate::ErrorCode::InvalidAuthority.

Each staged write must be a directive this system could propose directly: its declared writes, ownership, and phase rules apply, and it commits with the system’s visibility. An empty writes list records the participant’s presence without writing. Before phase 11 commits, the kernel audits every ready manifest: when some, but not all, participants staged (crate::ErrorCode::TransitionParticipantMissing) or an expected version differs (crate::ErrorCode::TransitionVersionMismatch), the whole boundary fails closed; when none staged, the manifest expires, so a single-participant manifest cannot fail for omission. The audit is recorded in BoundaryRecord::transition_audits and readable through crate::SimulationView::transition_audits.

Trait Implementations§

Source§

impl Clone for BoundaryDirective

Source§

fn clone(&self) -> Self

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for BoundaryDirective

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl<'de> Deserialize<'de> for BoundaryDirective

Source§

fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>
where __D: Deserializer<'de>,

Deserialize this value from the given Serde deserializer. Read more
Source§

impl PartialEq for BoundaryDirective

Source§

fn eq(&self, other: &Self) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl Serialize for BoundaryDirective

Source§

fn serialize<__S>(&self, __serializer: __S) -> Result<__S::Ok, __S::Error>
where __S: Serializer,

Serialize this value into the given Serde serializer. Read more
Source§

impl StructuralPartialEq for BoundaryDirective

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DeserializeOwned for T
where T: for<'de> Deserialize<'de>,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.