pub struct Engine { /* private fields */ }Expand description
The engine holds the registered analyzers, the host policy, and an optional LLM enrichment backend (§9).
Implementations§
Source§impl Engine
impl Engine
Sourcepub fn with_builtins() -> Self
pub fn with_builtins() -> Self
An engine with the default built-ins and a default (fully closed) policy — nothing auto-applies, no LLM.
Sourcepub fn with_policy(self, policy: Policy) -> Self
pub fn with_policy(self, policy: Policy) -> Self
Install a host policy (the only place auto-apply is granted).
Sourcepub fn with_llm(self, backend: Box<dyn LlmBackend>) -> Self
pub fn with_llm(self, backend: Box<dyn LlmBackend>) -> Self
Attach an optional LLM enrichment backend (§9). Only ever adds cited
draft recommendations (stamped origin = llm, never auto-applied) and
whitelisted guidance notes — it can never gate or rewrite deterministic
output.
Sourcepub fn with_ground_llm(self, backend: Box<dyn LlmBackend>) -> Self
pub fn with_ground_llm(self, backend: Box<dyn LlmBackend>) -> Self
Attach a separate backend for the GROUND stage (§5.2). Without this,
grounding uses the with_llm backend. Independent of the proposer so an
operator can run entailment on a cheaper/specialized model.
pub fn policy(&self) -> &Policy
Sourcepub fn register(&mut self, analyzer: Box<dyn Analyzer>)
pub fn register(&mut self, analyzer: Box<dyn Analyzer>)
Register an additional analyzer (the linked-Rust seam).
pub fn analyzers(&self) -> &[Box<dyn Analyzer>]
Sourcepub fn analyze_only<S: OmsSubstrate>(
&self,
sub: &S,
opts: &RunOptions,
overrides: &BTreeMap<String, Map<String, Value>>,
now_ms: i64,
) -> Result<Vec<Recommendation>>
pub fn analyze_only<S: OmsSubstrate>( &self, sub: &S, opts: &RunOptions, overrides: &BTreeMap<String, Map<String, Value>>, now_ms: i64, ) -> Result<Vec<Recommendation>>
Run the exact production analysis/validation path without Phase 0 measurement or Phase 3 persistence. The immutable substrate borrow is the replay safety boundary: recommendations, audit grains, state, cooldowns, outcomes, and the op-log cannot be changed here.
overrides is keyed by full analyzer id and overlays the file’s stored
parameter map. Unknown keys fail closed through resolve_params and
surface as an analyzer skip, exactly as in a production run.
Sourcepub fn run<S: OmsSubstrate>(
&self,
sub: &mut S,
opts: &RunOptions,
now_ms: i64,
) -> Result<RunResult>
pub fn run<S: OmsSubstrate>( &self, sub: &mut S, opts: &RunOptions, now_ms: i64, ) -> Result<RunResult>
Run one analysis pass. Idempotent under dedup_key; the watermark is
advanced at the end, so a crashed run simply re-runs.
Sourcepub fn review<S: OmsSubstrate>(
&self,
sub: &mut S,
rec_hash: &str,
decision: Decision,
actor: &str,
observer: ObserverType,
scopes: &ScopeSet,
because: &str,
now_ms: i64,
) -> Result<()>
pub fn review<S: OmsSubstrate>( &self, sub: &mut S, rec_hash: &str, decision: Decision, actor: &str, observer: ObserverType, scopes: &ScopeSet, because: &str, now_ms: i64, ) -> Result<()>
Approve or reject a pending recommendation. Requires the review scope,
a mandatory BECAUSE, and blocks self-approval against the creating actor.
Sourcepub fn preflight_apply<S: OmsSubstrate>(
&self,
sub: &S,
rec_hash: &str,
scopes: &ScopeSet,
allow_destructive: bool,
) -> Result<()>
pub fn preflight_apply<S: OmsSubstrate>( &self, sub: &S, rec_hash: &str, scopes: &ScopeSet, allow_destructive: bool, ) -> Result<()>
Check everything apply would refuse on, without writing
anything.
This exists for the fused approve-and-apply callers (the bindings’
apply_recommendation). Recording the approval first and then hitting
the destructive gate strands the recommendation in approved, which has
no exit but applied or expired — approved → rejected is not a
legal transition — so a refused apply left the reviewer unable to
dismiss it. Ask first, then approve.
Deliberately does not check the lifecycle transition: the caller is about to make it legal by approving.
Sourcepub fn apply<S: OmsSubstrate>(
&self,
sub: &mut S,
rec_hash: &str,
actor: &str,
observer: ObserverType,
scopes: &ScopeSet,
because: &str,
allow_destructive: bool,
now_ms: i64,
) -> Result<AppliedRecord>
pub fn apply<S: OmsSubstrate>( &self, sub: &mut S, rec_hash: &str, actor: &str, observer: ObserverType, scopes: &ScopeSet, because: &str, allow_destructive: bool, now_ms: i64, ) -> Result<AppliedRecord>
Apply an approved recommendation. Requires apply; destructive payloads
additionally require admin + allow_destructive. Records the applied
info (inverse plan) for rollback.
Sourcepub fn apply_gated<S: OmsSubstrate>(
&self,
sub: &mut S,
rec_hash: &str,
actor: &str,
observer: ObserverType,
scopes: &ScopeSet,
because: &str,
allow_destructive: bool,
gating: &GatingEvidence,
now_ms: i64,
) -> Result<AppliedRecord>
pub fn apply_gated<S: OmsSubstrate>( &self, sub: &mut S, rec_hash: &str, actor: &str, observer: ObserverType, scopes: &ScopeSet, because: &str, allow_destructive: bool, gating: &GatingEvidence, now_ms: i64, ) -> Result<AppliedRecord>
Apply WITH the §7.4 evalset-run edge — the only path that can apply a
code_revision. The evidence is validated against the
recommendation’s pin and recorded on the audit Observation.
Sourcepub fn rollback<S: OmsSubstrate>(
&self,
sub: &mut S,
rec_hash: &str,
actor: &str,
observer: ObserverType,
scopes: &ScopeSet,
because: &str,
now_ms: i64,
) -> Result<()>
pub fn rollback<S: OmsSubstrate>( &self, sub: &mut S, rec_hash: &str, actor: &str, observer: ObserverType, scopes: &ScopeSet, because: &str, now_ms: i64, ) -> Result<()>
Roll back an applied recommendation by retracting the grains it created. Fails for non-rollbackable applies (e.g. FORGET).
Sourcepub fn recommendations<S: OmsSubstrate>(
&self,
sub: &S,
status_filter: Option<RecStatus>,
) -> Result<Vec<Recommendation>>
pub fn recommendations<S: OmsSubstrate>( &self, sub: &S, status_filter: Option<RecStatus>, ) -> Result<Vec<Recommendation>>
List stored recommendations, optionally filtered by status. Status comes from the rebuildable index, not the immutable grain body. Ordered for review triage — highest severity first, then oldest first — and stable across runs for identical input.
Sourcepub fn analyzer_settings<S: OmsSubstrate>(
&self,
sub: &S,
) -> Result<Vec<AnalyzerSetting>>
pub fn analyzer_settings<S: OmsSubstrate>( &self, sub: &S, ) -> Result<Vec<AnalyzerSetting>>
Per-analyzer effective settings for the Setup view: the manifest facts merged with the file-config (override or manifest default). Read-only.
Sourcepub fn set_analyzer_config<S: OmsSubstrate>(
&self,
sub: &mut S,
analyzer_id: &str,
update: AnalyzerConfigUpdate,
scopes: &ScopeSet,
) -> Result<AnalyzerConfig>
pub fn set_analyzer_config<S: OmsSubstrate>( &self, sub: &mut S, analyzer_id: &str, update: AnalyzerConfigUpdate, scopes: &ScopeSet, ) -> Result<AnalyzerConfig>
Update one analyzer’s file-config (enable/disable, severity floor, param
overrides, namespace scoping). Requires Admin. Params are validated
against the analyzer’s manifest first (unknown keys rejected, fail-closed),
and the analyzer must exist. Returns the merged config as stored. This is
the only write into persisted.config — the config layer, never a grain.
Sourcepub fn outcomes<S: OmsSubstrate>(&self, sub: &S) -> Result<Vec<OutcomeResult>>
pub fn outcomes<S: OmsSubstrate>(&self, sub: &S) -> Result<Vec<OutcomeResult>>
The measured outcome time series (the Verify gate’s history) across all recommendations, ordered by when each checkpoint was measured.
Sourcepub fn health<S: OmsSubstrate>(&self, sub: &S, now_ms: i64) -> Result<Health>
pub fn health<S: OmsSubstrate>(&self, sub: &S, now_ms: i64) -> Result<Health>
A health snapshot — when the loop last ran, how much is un-analyzed since, and the queue counts. Lets a host surface “the loop may be stale” so a forgotten SessionEnd hook / cron doesn’t silently kill it.
Sourcepub fn llm_metrics<S: OmsSubstrate>(&self, sub: &S) -> Result<LlmMetrics>
pub fn llm_metrics<S: OmsSubstrate>(&self, sub: &S) -> Result<LlmMetrics>
Approval-rate metric for origin = llm recommendations (reflection
design §6b) — the live field-quality signal that accrues off the audit
chain: what fraction of the model’s surfaced proposals a reviewer
accepts. Complements the offline Effective-Reliability eval.