1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
//! The lifecycle record frames (S284; PRD 0025 section 6, ruling R-63):
//! the epoch protocol's declaration, confirmation, adoption report, seal
//! notice, and bootstrap lineage proof, joined by the arrival
//! endorsement (S346; PRD 0028 R7, the round's first wire spelling).
//! Each frame lives in its own version namespace under the standing
//! codec discipline (big-endian per R-58, canonical bijection, `O(1)`
//! impossible-count refusals, typed budgets and errors, an `encoded_len`
//! preflight per frame).
//!
//! # Decoded forms are report records (the S273 rule)
//!
//! No frame decodes into [`Adopted`](crate::metis::Adopted), a
//! [`SealedEpoch`], or a live [`Epochs`](crate::metis::Epochs): authority is
//! earned at the lifecycle doors. A decoded [`Declaration`] is the record
//! [`Epochs::deliver`](crate::metis::Epochs::deliver) consumes and
//! re-validates whole: roster, generation, risen, fresh. A decoded
//! [`SealRecord`] is a peer's *claim* of a seal. The live path compares that
//! claim against the receiver's own derived [`SealedEpoch`]. Only
//! [`Epochs::bootstrap`](crate::metis::Epochs::bootstrap) installs it, after
//! the caller's certificate decision, and it re-proves the machine invariants.
//! The codec itself never constructs lifecycle truth. Every embedded cut rides
//! as a canonical gap-free have-set (PRD 0016) whose gap-freedom the receiver
//! proves before the value enters any `Cut`-shaped role (the PRD 0025 section
//! 4 law); the decoded cut is a peer claim in witnessed shape, entering
//! through the honest [`Cut::floor_of`](crate::metis::Cut::floor_of) door.
//!
//! # The aggregate expanded-dot budget
//!
//! PRD 0025 section 4 composes budgets: one expanded-dot allowance across
//! every nested have-set in a frame, never restarted at a section
//! boundary. For this family the allowance is exactly zero, because every
//! embedded have-set must be gap-free. The first exception run of a gapped
//! embedding refuses as [`WireCutError::Gapped`] with its evidence.
pub use ;
pub use ;
pub use DeclarationDecodeError;
pub use ;
pub use WireCutError;
pub use ;
pub use ;