Skip to main content

Crate canwu_api

Crate canwu_api 

Source
Expand description

Public programmatic, query, semantic-agent, explanation, and debug interfaces.

Structs§

ActorKnowledge
ArchiveReachabilityManifest
Unified offline GC mark set for kernel-owned pages, evidence, decision blobs, and namespaced plugin archive objects.
ArchivedEvidenceLocator
ArchivedEvidenceReceipt
ArchivedPluginIngressProvenance
ArchivedSegmentHeader
Army
ArmyId
Stable numeric identifier for ArmyId.
ArmyKnowledge
ArtifactManifest
Stable identity for a scenario, ruleset, content pack, run policy, localization contract, or source ledger.
BookingAllocationV1
One booking’s allocation result, in allocation order.
BoundaryChange
BoundaryContext
BoundaryEmission
BoundaryEvaluationTrace
Committed rule-evaluation trace evidence in a boundary record, with its producing system. Entries follow system execution order: phase, then plugin and system name, then proposal order.
BoundaryId
Stable numeric identifier for BoundaryId.
BoundaryIngressGeneration
BoundaryKnowledgeChange
BoundaryPersonAvailabilityChange
Committed availability change evidence in a boundary record.
BoundaryPersonCreation
Committed person-creation evidence in a boundary record.
BoundaryProposal
BoundaryReceipt
BoundaryRecord
BoundaryRequest
BoundarySystemContract
Canwu
Main in-process API. All returned world values are detached snapshots.
CanwuError
CanwuViewer
Restricted player/agent/observer API. It deliberately exposes no raw snapshot, event, boundary, domain-record, or audit-origin access.
CapacityBooking
CapacityBookingAllocationEvidenceV1
Replayable evidence of one allocation decision.
CapacityBookingId
CapacityBookingRequestV1
One requested booking offered to a pool allocation pass, with the caller’s deterministic tie-break key and admission sequence.
CheckpointJournal
Portable full-save bundle built from a current-state checkpoint and journal segments.
CommandAttemptId
Stable numeric identifier for CommandAttemptId.
CommandAttemptRecord
CommandAuthority
CommandContext
CommandEnvelope
CommandId
Stable numeric identifier for CommandId.
CommandReceipt
CommandRecord
CommandRejection
CommandRequest
CommandRequestId
Stable numeric identifier for CommandRequestId.
CommitmentRoots
Canonical roots for independent authoritative state and evidence domains.
CompactedCanwu
Public API for a live runtime whose sealed evidence segments are stored by the caller.
CompactedSimulation
A live simulation whose sealed evidence prefixes are owned by the caller.
CreatedPerson
Receipt entry binding a creation correlation to its engine-allocated ID.
DecisionArchiveBlob
DecisionArchiveBucketPage
DecisionArchiveReceipt
DecisionAttemptRecord
DecisionContext
DecisionController
DecisionControllerBinding
DecisionError
DecisionExternalEvidence
DecisionFactorContribution
DecisionHistoryCursor
DecisionHistoryPage
DecisionHistoryQueryBudget
DecisionHotState
DecisionIngressRequest
DecisionLocatorScaleMetrics
DecisionOption
DecisionOptionEvaluation
DecisionOptionWeight
DecisionPolicyIdentity
DecisionRandomEvidence
DecisionRequestId
Stable numeric identifier for DecisionRequestId.
DecisionState
DecisionTicket
DecisionTicketDraft
DecisionTicketId
Stable numeric identifier for DecisionTicketId.
DecisionTrace
DecisionTraceId
Stable numeric identifier for DecisionTraceId.
DeliveryCompletionRequest
DeliverySaga
DemoIds
DepartureSlot
DomainRecord
DomainRecordChange
DomainRecordCommitmentRoots
Independent commitment roots for the Format-8 domain-record store.
DomainRecordDraft
DomainRecordKind
Stable application-defined record kind. Namespaces and names are validated by the simulation package registry before authoritative use.
DomainRecordPage
One deterministic trusted-host page of records from an authoritative read cut.
DomainRecordPageRoots
DomainRecordRef
Stable string identity for an application-defined entity or record.
DomainRecordSchema
DomainRecordVersionRef
Exact historical identity for an application-defined record version.
DomainReference
DomainReferenceSchema
DurationSample
EstimateRange
EvaluationLimitsV1
Per-boundary bounds on rule-evaluation traces, declared in super::RunConfiguration::evaluation_limits.
EvaluationTerm
One named contribution to a rule evaluation, with the evidence it read.
EvaluationTermView
One term of an EvaluationTraceView.
EvaluationTraceRecord
Explains how one application rule produced one integer result for one subject at one boundary.
EvaluationTraceView
Holder-facing projection of one EvaluationTraceRecord, returned by CanwuViewer::evaluation_traces. It keeps the rule, subject, boundary, result, and each term’s contribution, and omits evidence identities.
EventId
Stable numeric identifier for EventId.
EventKind
Domain-neutral event identity and structured fields.
EvidenceArchiveIndex
EvidenceCursor
Monotonic cuts through every append-only evidence journal.
EvidenceIndexEntry
EvidenceItemLocator
EvidenceJournalRoots
EvidenceJournalSegment
One contiguous append-only evidence range for incremental archival.
EvidenceSealToken
Explanation
ExplanationStep
ExternalDecisionOption
ExternalDecisionRequest
ExternalDecisionResponse
Government
GovernmentId
Stable numeric identifier for GovernmentId.
GuardedUtilityPolicy
A composite policy: ordered guards, then weighted utility over the options the guards left, then an optional bounded random tie-break.
Handoff
HandoffId
HolderKnowledgeRecordId
Stable numeric identifier for HolderKnowledgeRecordId.
HumanDecisionResponse
IdentityEvidenceDependenciesV1
Authoritative identity-only evidence dependencies for a live domain record.
IngressId
Stable numeric identifier for IngressId.
IngressReceipt
IngressRecord
ItineraryRevision
ItineraryRevisionId
KnowledgeCursor
KnowledgeLimitsV1
KnowledgeOrigin
KnowledgeQuery
KnowledgeQueryResult
KnowledgeReadCut
KnowledgeRecord
KnowledgeRecordDraft
KnowledgeRecordId
Stable numeric identifier for KnowledgeRecordId.
KnowledgeRecordKind
Stable namespace and kind for a holder-relative knowledge record.
KnowledgeRecordView
KnowledgeSchemaId
Exact version of one registered knowledge schema.
KnowledgeSnapshot
KnowledgeSubject
KnowledgeSubjectSchema
KnowledgeWriteGrant
LegExecution
LegExecutionId
LetterCargo
LetterId
Stable numeric identifier for LetterId.
LlmModelIdentity
MaintenanceChangeRecord
MaintenanceDependencyResolverDescriptor
Declares that a plugin must participate when a target namespace is retired through owner-authorized maintenance. The declaration is persisted in the plugin descriptor, so replay and restore cannot silently omit a dependent owner.
MaintenanceRejectionReceipt
MapPoint
MovementOrder
Immutable, admitted intent shared by transport movement domains.
MovementOrderId
Stable identity for an admitted transport-domain movement intent.
MovementSubject
One typed identity in a movement manifest.
OrderedRulePolicy
OrganizationId
Stable numeric identifier for OrganizationId.
OutboxEntry
Durable, idempotent external-delivery identity derived from committed boundary evidence. The engine creates one entry for every emission; a host may deliver it at least once and use delivery_id as its idempotency key.
OwnerAuthorizedMaintenanceDraft
OwnerAuthorizedMaintenanceRequest
OwnerAuthorizedMutation
OwnerAuthorizedParticipantDraft
OwnerAuthorizedParticipantProposal
OwnerAuthorizedRecordExpectation
PagedSimulationCheckpoint
PatriciaStoreMetrics
PayloadProperty
PayloadRequiredEvidenceContinuationV1
Authoritative pending-continuation contract for rules that must inspect old payload bytes.
PendingTransitionManifest
A registered manifest awaiting its ready boundary, and the registration evidence recorded on the boundary that admitted it.
PersistentDomainRecordStore
Person
PersonAvailability
Core life and custody state of one person.
PersonDraft
Application-supplied content for a person created at a boundary.
PersonId
Stable numeric identifier for PersonId.
PersonTransitState
PlanningSnapshot
PluginActionDescriptor
PluginArchiveRetention
PluginComponentRecord
PluginDescriptor
PluginIngressDescriptor
PluginIngressPermit
Opaque capability issued only while a plugin registers a kernel-internal ingress type. Hosts can pass the capability back but cannot construct or alter it.
PluginIngressRequest
PluginIngressTarget
PluginKnowledgeSchema
PluginRegistrar
PluginRegistry
PolicyDecision
PortablePagedSimulationCheckpoint
PreparedDecisionArchive
PreparedDecisionIngress
PreparedEvidenceSeal
PreparedPagedSimulationCheckpoint
PreparedStateDelta
QueuedExternalPolicy
QueuedHumanPolicy
QueuedLlmPolicy
RandomDecisionResolution
RandomDrawId
Stable numeric identifier for RandomDrawId.
RandomDrawRecord
RandomOperationAddressV1
Version-one stable entropy address for a future keyed random draw.
RandomSample
RandomStreamKey
RandomStreamState
ReplayJournal
Complete recorded environment and input journal for exact replay.
ReservationAllocation
ReservationOffer
ReservationOfferRecord
ReservationPoolKey
ReservationRef
ReservationRequest
ReservationRequestRecord
ResourceId
Stable numeric identifier for ResourceId.
Route
RouteCost
RouteId
Stable numeric identifier for RouteId.
RouteLeg
RoutePlan
RoutingCache
RoutingConnection
RoutingConnectionRef
RoutingEndpoint
RoutingNetwork
RoutingNodeRef
RoutingPolicy
RoutingRequest
RunConfiguration
Scenario
SchemaRegistry
SeatBinding
SimDuration
SimEvent
SimTime
SimulationCheckpoint
Current authoritative state plus the journal cut required to validate it.
SimulationSnapshot
SimulationView
StateKey
StatePageBlob
StatePageRetentionHandle
StatePageRetentionLedger
Persistable host-side mark/sweep interlock for content-addressed state pages. Preparing, verifying, or durably enqueueing a root protects every declared reachable page across process restart. A committed root takes over that lease atomically before the transient handle may disappear.
SystemContract
Territory
TerritoryId
Stable numeric identifier for TerritoryId.
TransitState
TransitionAuditRecord
Read-only audit evidence for one manifest settled at its ready boundary.
TransitionManifest
Declaration of the participants of one multi-owner transition and the single boundary in which all of their writes stage and commit.
TransitionManifestId
Stable identity of a registered manifest. The coordinator is the registering plugin, recorded by the kernel rather than claimed by content.
TransitionParticipant
One plugin whose writes a transition requires.
TransitionParticipantAudit
How many writes one participant staged for a manifest.
TransitionRecordVersion
A record version a participant expects the transition to produce.
TransportCapacityPoolV1
A windowed pool of interchangeable transport capacity, such as ferry crossings, carriage places, or relay mounts for one period.
TransportExecution
TransportExecutionId
TypeSchema
TypedDomainRecordRef
Typed façade over a stable application-defined record identity.
UtilityProfile
VerifiedDecisionArchiveCommit
Provider-verified, replay-safe archive transition. Blob bytes remain in the host archive; canonical ingress carries only the exact hot-state source root, token, and compact receipts needed to revalidate the transition.
VerifiedOwnerAuthorizedMaintenanceCommit
ViewerContext
VisibleChange
WeightedUtilityEvaluator
WeightedUtilityPolicy
WorldSnapshot

Enums§

ArchiveStoreOutcome
BoundaryDirective
BoundaryEmissionKind
BoundaryPhase
CapacityAllocationFailureV1
Why an allocation pass failed a booking request.
CapacityBookingStatus
CauseRef
Command
CommandAttemptOutcome
CommandIngress
CommandOutcome
CommandPolicyContext
Command-relevant policy deliberately omits run purpose, observation, and trace so authoritative handlers cannot branch on presentation-only inputs.
ControllerDecision
ControllerPolicy
CoreEntityKind
CustodyState
Whether a person is free to act. Absent availability means CustodyState::Free.
DecisionAction
DecisionArchiveRecord
DecisionArchiveStoreOutcome
DecisionAttemptErrorCode
DecisionAttemptOutcome
DecisionAuthority
DecisionErrorCode
DecisionEvaluation
DecisionHistoryKey
Typed identity for decision history. A scalar ID is not enough because tickets, caller-selected requests, and engine-issued traces have different uniqueness and retention rules.
DecisionHistoryLocation
DecisionMutation
DecisionOrigin
DecisionOutcome
DecisionPolicyKind
DecisionStage
The stage of a composite policy that produced a decision. Decisions from single-stage policies, and every historical trace, carry no stage.
DecisionTicketState
DomainEntityKindClass
Type-level class for domain kinds whose instances are entity identities.
DomainRecordClass
DomainRecordLifecycle
DomainRecordMutation
DomainRecordMutationPolicy
DomainRecordOperation
DomainRecordVersionSource
Persisted identity of the operation that established one domain-record version. Version zero is reserved and rejected by runtime validation.
DomainReferenceTarget
DomainReferenceTargetKind
DomainValueKindClass
Type-level class for domain kinds whose instances are non-entity records.
EntityRef
Serializable entity reference used by events, queries, and generic tools.
ErrorCode
EventAudience
Declarative audience for a persisted event projection.
EventKindError
EvidenceJournalKind
EvidenceNestedLocator
EvidenceRef
Shared persisted-evidence identity used by knowledge, decisions, random operations, replay, and compact archive receipts.
ExplanationRequest
HandoffKind
How custody changed hands between two legs.
IngressCancellationAuthority
Authority that withdrew a queued plugin ingress item.
IngressClass
IngressPayload
InteractionPolicy
Issuer
ItineraryRevisionReason
KnowledgeHistoryView
KnowledgeHolderPolicy
Whether a domain entity schema may receive holder-relative knowledge.
KnowledgeHolderRef
Stable holder identity shared by people and eligible institutional entities.
KnowledgeQueryError
KnowledgeSource
KnowledgeSubjectTarget
KnowledgeSubjectTargetKind
LegExecutionStatus
LetterStatus
LifeState
Whether a person is alive. Absent availability means LifeState::Alive.
MaintenanceDisposition
MaintenanceIngressRequest
MovementInitiative
Who initiated a movement intent. The runtime must derive this from the admitted authority and never trust an unvalidated caller-supplied label.
MovementOrderError
MovementSubjectRole
The physical role of a subject in a movement manifest.
ObservationPolicy
ObservationPrincipal
An observation identity authorized by the run’s persisted observation policy. This type is intentionally constructed through Canwu::viewer_context so an observation request cannot self-escalate.
OwnerAuthorizedParticipantRole
PayloadSchema
PayloadValueType
RandomAlgorithm
RandomDrawAddress
Persisted address of a random draw.
RandomDrawOutcome
RandomDrawProducer
RandomOperationTarget
Stable application target for an operation-addressed random draw.
ReconciliationOutcome
Result of reconciling the information-system delivery attempt.
ReservationDisposition
RoutingAlgorithm
RoutingEndpointKind
RoutingError
RuleChoice
RunConfigurationSnapshot
RunManifest
The exact non-executable environment bound to a simulation run.
RunPurpose
SagaState
SchemaRegistryError
Error returned when a schema registration would replace an existing type.
SeatPolicy
SimulationGranularity
Generic simulation granularity used by host applications to map aggregate, group, and individual actors onto the same authoritative engine.
StatePageRetentionPhase
StateVisibility
SystemCadence
SystemDirective
TracePolicy
TransferMode
TransitionAuditOutcome
Terminal outcome of a manifest at its ready boundary. Failed checks leave no record: they fail the boundary instead.
TransportError
TransportExecutionState
TraversalModel

Constants§

ADMISSION_CURSOR_FORMAT_VERSION
Version of persisted monotonic boundary-admission cursors.
CAPACITY_BOOKING_ALLOCATION_DIGEST_DOMAIN
Hash domain of CapacityBookingAllocationEvidenceV1::semantic_digest.
CHECKPOINT_JOURNAL_FORMAT_VERSION
Version of current-state checkpoints plus append-only evidence segments.
COMMITMENT_FORMAT_VERSION
Version of the domain-separated checkpoint commitment contract.
CONTROLLER_AUTHORITY_UNAVAILABLE_REASON
Cancellation reason recorded on an open ticket whose assigned controller’s authority person became unavailable.
DECISION_ARCHIVE_BUCKET_PAGE_FORMAT_VERSION
DECISION_ARCHIVE_FORMAT_VERSION
DECISION_MAKER_UNAVAILABLE_REASON
Cancellation reason recorded on an open ticket whose person decision maker became unavailable.
DECISION_REQUEST_COMMITMENT_DOMAIN
ENGINE_VERSION
IDENTITY_EVIDENCE_DEPENDENCIES_FIELD
Reserved domain-record payload field declaring retained identity proofs.
IDENTITY_EVIDENCE_DEPENDENCIES_FORMAT_VERSION
Current wire version of IdentityEvidenceDependenciesV1.
MAX_DECISION_ARCHIVE_BATCH_ENTRIES
MAX_DECISION_HISTORY_PAGE_BYTES
MAX_DECISION_HISTORY_PAGE_SIZE
MAX_INGRESS_CANCELLATION_REASON_BYTES
Maximum UTF-8 byte length of a plugin ingress cancellation reason.
MAX_KNOWLEDGE_PAGE_SIZE
MAX_OWNER_AUTHORIZED_MUTATIONS
MAX_OWNER_AUTHORIZED_PARTICIPANTS
MAX_PENDING_TRANSITION_MANIFESTS
Maximum number of registered manifests awaiting their ready boundary, across all coordinators. Manifests that settle in a boundary still count until its phase 11.
MAX_PENDING_TRANSITION_MANIFESTS_PER_COORDINATOR
Maximum number of pending manifests one coordinator may hold, so a single coordinator cannot exhaust MAX_PENDING_TRANSITION_MANIFESTS.
MAX_STATE_DELTA_PAGES
Hard predecode cap for one initial or incremental Format-8 page graph. A one-million-entry non-collision Patricia map can contain 2N - 1 logical node pages; this leaves bounded room for its manifest and compact decision buckets without making the count unbounded.
MAX_STATE_PAGE_BYTES
MAX_TRANSITION_EXPECTED_VERSIONS
Maximum number of expected_pre and expected_post entries, together, across all participants of one manifest. With the pending bounds, this bounds the number of entries in the pending set; each record reference names a registered record kind and follows the ordinary record-ID rules.
MAX_TRANSITION_LINEAGE_ID_BYTES
Maximum byte length of a manifest lineage ID.
MAX_TRANSITION_PARTICIPANTS
Maximum number of participants one manifest may list.
MAX_TRANSITION_READY_HORIZON
Maximum number of boundaries between a registration and its ready_at boundary, so every pending manifest settles within a bounded number of boundaries and no lineage stays locked indefinitely.
OWNER_AUTHORIZED_MAINTENANCE_FORMAT_VERSION
PAGED_CHECKPOINT_FORMAT_VERSION
PAYLOAD_REQUIRED_EVIDENCE_CONTINUATION_FIELD
Reserved domain-record payload field declaring a payload-reading continuation.
PAYLOAD_REQUIRED_EVIDENCE_CONTINUATION_FORMAT_VERSION
Current wire version of PayloadRequiredEvidenceContinuationV1.
PLUGIN_DESCRIPTOR_FORMAT_VERSION
ROUTING_ALGORITHM_VERSION
RUN_CONFIGURATION_FORMAT_VERSION
RUN_MANIFEST_FORMAT_VERSION
SNAPSHOT_FORMAT_VERSION
Format 8 binds every decision attempt to its complete ingress request and activates content-addressed state-page persistence. Older snapshots, journals, and sub-contract versions are rejected before any mutable runtime state is constructed.
STATE_PAGE_CODEC
STATE_PAGE_FORMAT_VERSION
STATE_REVISION_FORMAT_VERSION
Version of the authoritative revision commitment.
TRANSPORT_SEMANTIC_VERSION
Semantic identity of the transport record and transition contract.

Traits§

ArchiveProvider
ArchiveStore
DecisionArchiveProvider
DecisionArchiveStore
DecisionPolicy
DecisionRule
DomainEntityType
Marker implemented automatically for entity-class domain record types.
DomainKindClass
Sealed type-level classification for application-defined record kinds.
DomainRecordType
Compile-time identity for one namespaced application-defined record kind.
DomainValueType
Marker implemented automatically for non-entity domain record types.
ExternalPolicy
HumanPolicy
LlmPolicy
PluginArchiveObjectProvider
Namespace-aware host access used only by offline archive mark/sweep. Plugin callbacks decode and authenticate their own object formats; the kernel never needs to depend on downstream archive crates.
RulePolicy
SimulationPlugin
A stateless executable package whose persisted identity must change whenever its authoritative behavior changes.
StatePageProvider
StatePageStore
UtilityEvaluator
UtilityPolicy

Functions§

allocate_capacity_bookings
Allocates requested bookings against one pool revision, all or nothing per booking.
canonical_byte_hash
Computes a domain-separated BLAKE3 commitment over an already canonical byte payload.
canonical_hash
Computes the engine’s canonical JSON commitment for plugin-owned data.
capacity_booking_allocation_operation_key
Stable operation key of one booking’s allocation at one pool revision.
delivery_completion_operation_key
format8_decision_locator_scale_probe
Runs the production decision archive lifecycle and reports its bounded locator metrics without exposing the scale fixture.
format8_patricia_scale_probe
Builds the actual Format-8 domain-record store, including the HAMT, ordered key pages, primary Patricia tree, reverse-reference tree, and successor/predecessor trees. The returned metrics describe every production Patricia index plus the materialized HAMT/key-page cardinalities.
identity_evidence_dependencies_property_v1
Returns the reserved property a domain-record schema must declare to authoritatively produce IdentityOnly dependencies.
payload_required_evidence_continuation_property_v1
Returns the reserved property a domain-record schema must declare to authoritatively produce PayloadRequired dependencies.
plan_route
prepare_state_delta
state_page_id
verify_state_delta

Type Aliases§

BoundarySystemHandler
OwnerAuthorizedMaintenanceParticipant
Plugin-owned callback used by the kernel maintenance coordinator. The callback receives a read-scoped immutable view and must author the exact proposal for its own schemas; callers never supply participant mutations.
PluginArchiveReachabilityParticipant
Plugin-owned extension of the unified archive reachability manifest. The callback is registered with the plugin descriptor, so a restored runtime cannot silently omit a plugin archive from GC marking.
PluginCommandHandler
SimulationSystemHandler
Compatibility-only synchronous event reactor.