pub enum EventBody {
SessionStart {
agent: String,
harness: String,
model: Option<String>,
trace_format: Option<String>,
},
SessionEnd {
outcome: SessionOutcome,
},
Resume {
last_seq_seen: u64,
},
TurnStart,
TurnEnd,
PromptAssembled {
budget_tokens: u32,
declared_total_tokens: u64,
composition_digest: Option<String>,
frames: Vec<RenderedFrame>,
},
ModelResponse {
tool_calls: Vec<String>,
},
ToolCall {
call_id: String,
tool: String,
},
ToolResult {
call_id: String,
status: ToolStatus,
},
VerifyObserved {
frame: FrameId,
verdict: Verdict,
},
SideEffect {
effect_id: String,
kind: String,
call_id: Option<String>,
},
}Expand description
The event bodies. Serialized internally tagged on event and flattened
into the TraceEvent envelope, so a journal line reads
{"seq":5,…,"event":"tool_call","call_id":"call_1",…}.
Variants§
SessionStart
The recording opens: which agent, under which harness, is being traced.
Fields
trace_format: Option<String>The trace vocabulary this journal is written to — see
TRACE_FORMAT.
SessionEnd
The session tore down deliberately. A journal without one records a crash.
Fields
outcome: SessionOutcomeResume
The harness came back after a crash. last_seq_seen is the highest
seq the resumed harness actually recovered — the journal knows what
it recorded, so the delta between the two is quantified work loss.
A resume implicitly closes any open turn and orphans any unresolved
tool calls; resumed work starts a new turn.
TurnStart
A turn opens. The envelope turn names it.
TurnEnd
The open turn closes. The envelope turn must match.
PromptAssembled
The harness composed a prompt and sent it. Recording assembly as the model request is deliberate: the journal claims what was sent is what was assembled, and every context guarantee is checked at this moment — the point of use.
Fields
budget_tokens: u32The context budget the harness announced for this prompt, in
budget tokens (SPEC.md §7).
declared_total_tokens: u64The harness’s own total of the rendered frame costs — checked against the per-frame declarations, so the arithmetic can’t drift from the itemization.
composition_digest: Option<String>Digest of the composed context section (algorithm
recorder-declared, e.g. sha256:<hex>). Optional; when present,
an unchanged frame set MUST reproduce it byte-identically
(docs/context-reuse.md §1 prefix stability, finally checkable).
frames: Vec<RenderedFrame>The frames rendered into this prompt, in composition order.
ModelResponse
The model answered, requesting zero or more tool calls by id. The ids
are the loop’s contract: each must be resolved exactly once before the
next prompt_assembled.
ToolCall
The harness began executing a model-requested call. Executing a call the model never requested is the phantom-execution defect.
ToolResult
A requested call was resolved — executed to completion, errored, or
declined (ToolStatus::Rejected).
VerifyObserved
The host observed a context/verify answer for a frame it holds
(docs/context-reuse.md §4). Rendering the same identity after a
stale/gone verdict is the citing-dead-evidence defect.
SideEffect
The harness performed an externally visible action (file write,
network call, command). effect_id names an intended-once effect: a
deliberate re-execution is a new id, so the same id twice is the
crash-replay bug by construction.