ic_backup/ports/ic_observation/mod.rs
1//! Single reserved IC status/list observation contract; no installed provider.
2
3use crate::model::ic_observation::{IcObservationRequest, IcObservationResponse};
4use thiserror::Error;
5
6/// Integration-owned authenticated observation of an original pending mutation.
7///
8/// Retain original plan/mutation/observation bytes and durably reserve this exact
9/// observation before invocation. Qualify actual context, method-specific current
10/// read permission, original recovery chronology and exclusive command/dispatch
11/// custody proving this observation reservation was never dispatched. A reconstructed
12/// pending request proves none of these; a lost observation cannot be repeated.
13///
14/// Submit exactly one host replicated update using the original management receiver,
15/// effective target, method and Candid bytes. Status/list are semantic observations,
16/// still potentially paid. No query/proxy substitution, hidden retry, extra observations,
17/// funding or mutation is permitted. Additional calls need independent prior accounting.
18///
19/// Return exact retained raw reply and actual original authority/attempt/payload/context/
20/// target association. Integrations independently authenticate and qualify evidence,
21/// timing and exclusive attribution. Wire projections and inventory cardinality never
22/// automatically produce Applied/NotApplied/Uncertain receipts or fresh control/read
23/// authority. Failure/drop/death retain pending spent observation and mutation,
24/// obligations and source references; an absent reply is not settled uncertainty.
25/// Terminal replay invokes no provider. No default or implementation is installed.
26pub trait IcObservationProvider {
27 /// Observe once under the exact already reserved original observation.
28 /// # Errors
29 /// All failures retain pending original accounting; no implicit reissue or outcome.
30 fn observe(
31 &mut self,
32 request: &IcObservationRequest<'_>,
33 ) -> Result<IcObservationResponse, IcObservationProviderError>;
34}
35
36/// Redacted observation failure; no automatic receipt, refund or permission follows.
37#[derive(Clone, Copy, Debug, Eq, Error, PartialEq)]
38pub enum IcObservationProviderError {
39 /// No qualified provider; no dispatch.
40 #[error("IC observation provider unavailable")]
41 Unavailable,
42 /// This exact bounded original observation contract cannot be qualified.
43 #[error("IC observation contract unsupported")]
44 Unsupported,
45 /// Observation dispatch/reply/authentication is indeterminate, not settled Uncertain.
46 #[error("IC observation response indeterminate")]
47 Indeterminate,
48}