Expand description
Typed participant lifecycle state and transitions.
The deviations here are mandated by docs/design/LP-EXTRACTION-GOAL.md:
detach cells retain a terminalized token after attach so the old binding
epoch remains producible, and cursor-progress facts are keyed per
participant rather than stored in the contract’s fixed occurrence array.
The array cannot represent two participants advancing over the same retained
suffix, so completion ordering is instead enforced by typed transitions and
tests.
Structs§
- Active
Binding - Active binding authority.
- Active
Identity Ranks - Sorted unique permanent indexes of current live members.
- Admission
Order - Stable admission ordering key for one lifecycle candidate.
- Aggregate
Operation Commit - Aggregate durability barrier pairing one selected shell event with the consumed typed operation commit.
- Aggregate
Operation Fault - Fail-loud invariant report: a consumed typed commit disagreed with itself.
- Aggregate
Operation Refusal - Refused aggregate decision retaining the unchanged shell and the intact consumed operation commit.
- Allocated
Participant Slot - Opaque, checked participant-slot allocation consumed by enrollment.
- Attach
Commit - Complete atomic result of a credential attach.
- Attach
Commit Parameters - Result allocation owned by one successful credential-attach transaction.
- Attach
Frontier Charges - Exact charges for a credential attach’s one or two retained rows.
- Attached
Lifecycle Record - Exact committed
Attachedlifecycle fact. - Attached
Operation - Durable facts of one committed credential attach, as recorded by the shell.
- Attached
Record Position - Assigned ordering and delivery position of one
Attachedlifecycle record. - Binding
Fate Measurement Refused - Refused measurement preserving every move-only input for serial retry.
- Binding
Fate Operation - Durable facts of one observed binding fate (crash/death), as recorded by the shell.
- Binding
Origin - Opaque durable origin of one current or last authoritative binding.
- Binding
Terminal Admit Refused - Admit refusal preserving the unchanged coupled owner.
- Binding
Terminal Candidate Charge - Canonical schema-v3 charge keyed to one sealed binding-terminal candidate.
- Binding
Terminal Commit - Successful committed terminal admission.
- Binding
Terminal Owner - Exact active binding-terminal claim authority.
- Binding
Terminal Pending - Successful observer-blocked pending terminal admission.
- Binding
Terminal Prepare Refused - Prepare refusal preserving the unchanged complete owner.
- Bound
Participant Cursor - One currently bound participant’s durable cumulative-cursor state.
- Candidate
Terminal Key - Sealed exact identity exposed to the canonical server encoder.
- Capacity
Counter - Validated occupancy bounded by one nonzero signed limit.
- Claim
Frontier Error - Deterministic claim-frontier restoration failure.
- Claim
Frontiers - Validated participant-keyed sequence and order claim authority.
- Claim
Frontiers Restore - Public persisted input for restoring both coupled claim frontiers.
- Closure
Accounting - Validated unchanged-prestate closure accounting.
- Closure
Debt - Nonzero componentwise closure debt.
- Committed
Binding Terminal Position - A durable binding-terminal record was appended in the fate transaction.
- Committed
Binding Terminal Restore - Raw durable fields for one committed binding terminal.
- Committed
Detach - Committed detach replay cell with its real Detached record sequence.
- Committed
Detach Transition - Atomic durable result of an immediately committed or drained detach.
- Committed
Detached Terminal - Appended
Detachedterminal with a cause valid for that record class. - Committed
Died Terminal - Appended
Diedterminal with a cause valid for that record class. - Committed
Ordinary Record - Ordinary record selected for one successful atomic transaction.
- Connection
Conversation Capacity Commit - Atomic successful result of semantic connection-capacity admission.
- Connection
Incarnation Allocation - Successful connection-incarnation allocation and resulting durable state.
- Connection
Incarnation Allocator - Validated monotonic connection-incarnation allocator state.
- Connection
Incarnation Allocator Restore - Raw durable connection-incarnation allocator header.
- Connection
Ordinal Exhaustion Commit - Atomic fixed-header update after a referenced terminal collision.
- Connection
Ordinal Exhaustion Replay - Idempotent refusal from an already terminal connection-ordinal header.
- Conversation
Commit - Ownership barrier between event selection and durable append.
- Conversation
Event - Opaque durable event emitted only by a protocol decision or canonical decode.
- Conversation
Genesis - Immutable genesis configuration for one participant conversation.
- Conversation
Refusal - Refused decision retaining the unchanged aggregate for continued use.
- Conversation
Replay Failure - Failed replay retaining the byte-for-byte unchanged pre-state.
- Credential
Attach Capacity Commit - Atomic successful credential-attach capacity reservation.
- Credential
Attach Capacity Counters - The five ordered receipt/provenance counters for credential attach.
- Credential
Attach Live Receipt - Stored canonical credential-attach result while its secret-bearing receipt remains live.
- Credential
Attach Provenance - Non-secret credential-attach provenance retained after deleting the live verifier and secret body.
- Cursor
Episode Restore - Complete raw state for one participant-scoped nonzero-debt cursor episode.
- Cursor
Progress Continuous - Continuous cursor-progress witness with no delivered marker.
- Cursor
Progress Facts - Variable participant-scoped cursor facts; no fixed occurrence array exists.
- Cursor
Progress Key - Participant-scoped cursor progress key mandated by extraction Fix 2.
- Cursor
Progress Marker - Marker-backed cursor-progress witness.
- Debt
Completion - Validated completion restricted to clear, observer projection, or physical compaction.
- Detach
Lookup Context - Complete serialized context for exhaustive detach reference lookup.
- Detached
Credential Recovery - Detached fenced credential-recovery witness.
- Detached
Credential Recovery Restore - Marker-backed detached credential-recovery provenance.
- Detached
Cursor Release - Leave-only detached-cursor release witness.
- Detached
Marker Release - Leave-only undelivered-marker release witness.
- Detached
Marker Release Restore - Undelivered-marker release provenance.
- Detached
Operation - Durable facts of one committed clean detach, as recorded by the shell.
- Durable
Incarnation References - Complete bounded live and durable connection-incarnation references.
- Empty
Detach - Empty detach replay cell.
- Enrolled
Operation - Durable facts of one committed enrollment, as recorded by the shell.
- Enrollment
Capacity Commit - Atomic successful enrollment capacity reservation.
- Enrollment
Capacity Counters - All seven stage-8 counters for a fresh enrollment.
- Enrollment
Commit - Complete atomic enrollment result.
- Enrollment
Commit Parameters - Values allocated by one successful enrollment transaction.
- Enrollment
Fingerprint - Consuming-layer enrollment-token fingerprint with no protocol-invented width.
- Enrollment
Live Receipt - Stored secret-bearing enrollment receipt while its receipt deadline is live.
- Enrollment
Provenance - Non-secret enrollment provenance retained after the live receipt is deleted.
- Event
- Opaque typed completion event.
- Exit
Product Range - Validated compact
L_other x Eproduct range. - Exit
Product Range Restore - Persisted
L_other x Eproduct-range descriptor supplied during restoration. - Fenced
Attach Commit - Opaque proof that an exact marker-fenced attach committed.
- Fenced
Attach Commit Restore - Complete predecessor and event fields for a committed fenced attach.
- Fenced
Attach Verification Refusal - Fenced verification refusal that preserves both consumed authorities.
- Fenced
Marker Source Expectation - Exact protocol-recomputed marker facts a durable source row must match.
- Fenced
Marker Source Retention Refused - Refused source retention with the owner and recovery unchanged.
- Fresh
Participant Capacity Counter - Provably empty, nonzero per-participant capacity for fresh enrollment.
- Frontier
Participant - Participant-indexed membership fact used by claim validation and planning.
- Historical
Marker Delivery Fact Restore - Raw immutable fact that one retained marker was durably delivered to an exact historical binding epoch.
- Immutable
Order Candidate Major - Validated immutable candidate-major group.
- Immutable
Order Candidate Major Restore - Public persisted candidate-major group supplied during restoration.
- Initial
Enrollment Closure Input - Durable state and signed configuration required by initial enrollment.
- Initial
Enrollment Closure Projection - Fully derived, persistable initial-enrollment closure projection.
- Initial
Enrollment Commit Values - Values minted or deadline-derived only after every admission gate passes.
- Initial
Enrollment Frontier Commit - Atomic protocol-owned initial-enrollment frontier result.
- Initial
Enrollment Frontier Failure - Failed initial-frontier derivation retaining the speculative operation.
- Initial
Enrollment Operation Commit - Complete atomic initial-enrollment commit.
- Initial
Enrollment Operation Input - Persisted prestate read by one initial
EnrollmentRequestattempt. - Installed
Attach State - Operational attach state separated from occurrence authority exactly once.
- KClaim
Backed Detached Leave - Validated evidence for an exact-current K-backed detached Leave.
- Leave
Commit - One indivisible committed Leave state update.
- Leave
Commit Parameters - Allocation fields for settled bound or detached Leave.
- Leave
Committed Restore - Raw fields of the canonical permanent
LeaveCommittedresult. - Leave
Fingerprint - Consuming-layer canonical Leave-request fingerprint.
- Left
Operation - Durable facts of one permanent Leave, as recorded by the shell.
- Live
Frontier Commit - A typed lifecycle commit paired with its complete post-transition owner.
- Live
Frontier Failure - Failed live transition retaining the unchanged complete owner and operation.
- Live
Frontier Owner - Complete executable frontier, closure-accounting, and keyed-retention owner.
- Live
Identity Restore - Raw durable fields for the latest committed terminal retained by membership.
- Live
Leave Commit - Complete move-only settled Leave result: tombstone and executable owner.
- Live
Member - Live participant membership plus permanent enrollment and terminal history.
- Live
Member Restore - Complete persistence input for restoring one live member.
- Marker
AckCommit - Atomic zero-debt marker-ack commit.
- Marker
Candidate Authority - Complete immutable marker candidate authority.
- Marker
Cursor Progress Restore - Marker-backed cursor provenance retaining its exact delivery predecessor.
- Marker
Delivery - Exact marker-delivery witness.
- Marker
Delivery Projection - Move-only typed wire projection of one protocol-selected compaction marker.
- Marker
Delivery Restore - Raw predecessor fields proving exact marker delivery.
- Marker
Drain Commit - Complete atomic marker-drain commit.
- Marker
Proof Permit - Opaque authority for an exact delivered marker and originating operation.
- Marker
Proof State - Durable participant facts read by the total marker-proof selector.
- Mint
Fenced Attach Refused - Failed one-use fenced proof mint with unchanged retry authority and inputs.
- Minted
Fenced Attach - Successful one-use fenced proof mint.
- Movable
Order Claim - One exact movable transaction-order claim.
- Movable
Sequence Claim - One exact movable direct sequence claim.
- Nonzero
Debt AckOperation - Durable facts of one nonzero-debt participant cursor acknowledgement, as recorded by the shell.
- Nonzero
Debt Cursor Episode - Participant-scoped cursor accounting for one provably nonzero-debt episode.
- Nonzero
Participant AckCommit - Atomic nonzero-debt participant-ack commit.
- Observer
Floor Permit - Opaque proof that one protocol-computed candidate floor passed stage 11.
- Observer
Progress Advance Transaction - Ownership barrier between a validated progress advance and its durable append.
- Observer
Progress Projection - Move-only exact observer-progress projection emitted by a committed source.
- Observer
Progress Track Transaction - Ownership barrier between a validated registration and its durable append.
- Observer
Projection - Observer-projection witness.
- Observer
Recovery Aggregate - Exclusively owned observer-recovery aggregate: per-conversation hard observer progress plus every installed equal-epoch arm, as ONE owned unit.
- Observer
Recovery Arm - One equal observer epoch that must be armed by an accepted recovery batch.
- Observer
Recovery Commit - Whole-batch observer-recovery commit selected after exhaustive validation.
- Observer
Recovery Transaction - Ownership barrier between arm selection and atomic arm installation.
- Order
Allocation - Successful allocation of one unreserved transaction-order major.
- Order
Claim Frontier - Validated exact transaction-order claim frontier.
- Order
Claim Frontier Restore - Public persisted input for transaction-order-frontier restoration.
- Order
Claims - Movable unmaterialized transaction-order claims.
- Order
Ledger - Validated transaction-order high watermark and reserved claims.
- Ordinary
Binding Authority - Opaque authority for the current epoch produced by an ordinary attach.
- Ordinary
Binding Authority Restore - Raw predecessor fields for an ordinary-attach binding authority.
- Ordinary
Binding Fate - Exact no-marker fate derived from an ordinary attach and its durable death.
- Ordinary
Binding Fate Restore - Exact ordinary-binding fate provenance for cursor release.
- Ordinary
Detached Attach Admission - Opaque proof that ordinary detached attach entered from a legal closure state.
- Ordinary
Projection Limits - Signed closure limits used by one ordinary fixed-point projection.
- Ordinary
Record Drain First - Sealed globally earlier candidate paired with its unchanged frontier state.
- Ordinary
Record Projection Failure - Recoverable noncommit from the consuming ordinary projection.
- Ordinary
Record Projection Input - External facts and signed limits for one consuming ordinary projection.
- Participant
AckCommit - Atomic zero-debt participant-ack commit.
- Participant
Conversation - Event-sourced participant conversation.
- Participant
Conversation Restore - Complete raw participant-conversation snapshot for public cold restore.
- Participant
Conversation State - Fully validated whole-conversation participant state.
- Pending
Binding Terminal Position - A binding fate was durably accepted but its terminal append remains pending.
- Pending
Detach - Pending detach replay cell whose terminal record is observer-blocked.
- Pending
Detach Transition - Atomic durable result of accepting an observer-blocked detach.
- Pending
Detached Finalization - Pending
Detachedterminal with no possibleDied-only cause. - Pending
Died Finalization - Pending
Diedterminal with no possibleDetached-only cause. - Pending
Died Ordinary Finalizer - Floor authority measured before a Pending-Died enclosing finalizer commits.
- Pending
Finalization Restore - Raw durable fields for one pending binding terminal.
- Pending
Leave Commit Parameters - Allocation and ordering proof for positional pending-terminal Leave.
- Pending
Recovered Cursor Release - Latent cursor-release suffix while an earlier OP/PC witness remains stored.
- Pending
Recovered Cursor Release Restore - Durable latent cursor-release suffix while an OP/PC predecessor remains stored.
- Pending
Replay Request - Verified command that forces pending replay through the progress/drain rule.
- Physical
Compaction - Physical-compaction range witness.
- Planned
Enrollment Marker - Planned marker owned by a newly overtaken enrollment participant.
- Prepared
Binding Fate - Successful protocol measurement retaining the coupled frontier owner.
- Prepared
Binding Terminal - Non-mutating prepared terminal admission with its sealed canonical key.
- Prepared
Leave Authority - Linear order-lane authority for one exact settled or positional Leave.
- Prepared
Pending Died Ordinary Finalizer - Ordinary fate and unchanged owner prepared for an enclosing finalizer.
- Projected
Ordinary Record - Sealed ordinary fixed-point poststate for one atomic durable transaction.
- Projection
Compaction Successor - Strict/later successor authority for OP, PC, and greater cumulative ack.
- Receipt
Deadlines - Checked receipt and provenance deadlines derived from one admitted clock read.
- Recipient
AckObligations - Validated durable delivery obligations for one participant ack frontier.
- Record
Admission Commit - Atomic ordinary-record commit selected by every shared admission gate.
- Record
Admission Drain First - Earlier immutable candidate paired with the unchanged replayable aggregate.
- Record
Admission Failure - Internal fault paired with the unchanged replayable aggregate.
- Record
Admission Persistence Parts - Exact successful record-admission parts for one atomic persistence commit.
- Record
Admission Prestate - Complete unchanged durable prestate consumed by ordinary admission.
- Record
Admission Refusal - Exact wire response paired with the unchanged replayable aggregate.
- Record
Size Permit - Successful static ordinary-record size preflight.
- Recovered
Binding Fate - Exact recovered-binding fate authority derived from a fenced attach.
- Recovered
Binding Fate Restore - Complete fenced-attach predecessor for a recovered binding-fate authority.
- Recovered
Cursor Release - Exact released state when binding fate covers storage immediately.
- Recovery
Claim Provenance - Sealed recovery-claim provenance derived from one exact stored edge.
- Recovery
Fence Permit - Successful stage-7 proof that no recovery fence applies.
- Recovery
Order Active Binding Restore - Optional leading
Amember of a persisted DCR order interval. - Recovery
Order Block - Validated indivisible DCR order interval.
- Recovery
Order Block Restore - Public persisted shape of the sole DCR order interval.
- Recovery
Sequence Block - Validated indivisible DCR sequence interval.
- Recovery
Sequence Block Restore - Public persisted shape of the sole DCR sequence interval.
- Recovery
Sequence Terminal Restore - Optional leading
Tmember of a persisted DCR sequence interval. - Remaining
Closure Permit - Successful remaining closure gate.
- Replacement
Terminal Product Range - Validated compact
L x RTproduct range. - Replacement
Terminal Product Range Restore - Persisted
L x RTproduct-range descriptor supplied during restoration. - Required
Capacity Plan - Componentwise maximum required capacity across a finite successor plan.
- Resulting
Enrollment Capacity Counters - All seven post-enrollment identity and receipt/provenance counters.
- Retained
Causal Record - One typed retained record fact used for candidate-key and provenance checks.
- Retained
Fenced Marker Source - Move-only owner/recovery pair held across one bounded durable source read.
- Retained
Record Charge - Exact durable charge keyed to one validated retained causal row.
- Retired
Identity - Permanent retired identity tombstone.
- Retired
Identity Restore - Complete raw durable tombstone fields.
- Sealed
Binding Fate Token - One move-only binding-fate authority emitted by an attach commit.
- Sequence
Admission - Successful sequence-reserve admission.
- Sequence
Claim Frontier - Validated exact sequence claim frontier.
- Sequence
Claim Frontier Restore - Public persisted input for sequence-frontier restoration.
- Sequence
Claims - Primitive participant-lifecycle claims from which the sequence reserve is derived.
- Sequence
Ledger - Validated delivery-sequence watermark and all unmaterialized claims.
- Sequence
Product Ranges - Validated O(I) product descriptors for the sequence frontier.
- Sequence
Product Ranges Restore - Compact persisted product descriptors supplied during restoration.
- Server
Incarnation Exhaustion - State-preserving terminal server-incarnation refusal.
- Server
Incarnation Fsync Intent - Checked startup write which must be fsynced before participant mode starts.
- Terminal
Product Range - Validated compact
L x Tproduct range. - Terminal
Product Range Restore - Persisted
L x Tproduct-range descriptor supplied during restoration. - Terminalized
Detach - Terminalized detach replay cell retained after a successful attach.
- Unchanged
Record Admission - Complete unchanged operation state returned by every noncommit decision.
- Verified
Attach Commit - Successful attach proof; fields are private so only mode verification mints it.
- Verified
Committed Detach - Exact verified view of a committed detach cell.
- Verified
Detach Request - Detach request proven to match one active binding.
- Verified
Leave Request - Exact Leave request authority proven against one live member.
- Verified
Pending Detach - Exact verified view of a pending detach cell.
- Verified
Terminalized Detach - Exact verified view whose receiver is the sole state-derived constructor for
TerminalizedDetachCell.
Enums§
- Aggregate
Operation Decision - Total aggregate decision for one lifecycle operation.
- Aggregate
Operation Fault Reason - Reason a consumed typed commit could not repeat itself as an event body.
- Attach
Commit Error - Failure while atomically applying a previously verified attach.
- Attach
Secret Proof - Secret-verifier result supplied by the consuming cryptographic layer for credential attach lookup.
- Attach
Transition - Binding-terminal effect selected by one successful attach.
- Attach
Verification Error - Failure while proving credential-attach authority before commit.
- Binding
Fate Measurement Error - Typed reason protocol-owned binding-fate measurement refused.
- Binding
Fate Terminal - Closed terminal input accepted by protocol-owned binding-fate measurement.
- Binding
Fate Terminal Restore - Durable binding-fate terminal provenance, whether appended or still pending.
- Binding
Required Lookup Result - Total shared lookup result for ack, marker-ack, and ordinary admission.
- Binding
Slot Decision - Stage-6 participant binding-slot result, bound to the requesting operation’s response authority.
- Binding
Slot Occupancy - Current participant occupancy of one connection/conversation binding slot.
- Binding
State - Binding-slot state; pending finalization carries no live authority.
- Binding
State Restore - Durable binding-slot representation with raw pending-terminal fields.
- Binding
Terminal Admission - Exhaustive terminal-admission result.
- Binding
Terminal Admit Error - Typed reason the keyed candidate could not be admitted.
- Binding
Terminal Cause Class - Closed terminal row class selected before canonical encoding.
- Binding
Terminal Disposition - Durable placement selected by an unrefusable binding-fate transaction.
- Binding
Terminal Encoding - Canonical durability encoding required for one binding-terminal candidate.
- Binding
Terminal Kind - Binding-terminal lifecycle record kind, derived from cause-partitioned state.
- Binding
Terminal Prepare Error - Typed reason the non-mutating prepare stage refused authority or positions.
- Capacity
Counter Invariant Error - Invalid persisted occupancy for one signed nonzero capacity.
- Claim
Frontier Counter - Counter whose frontier failed restoration.
- Claim
Frontier Invalid Reason - Structural reason for a claim-frontier failure.
- Closure
Accounting Error - Invalid durable closure-accounting state.
- Closure
State - Closure state makes a clear edge with nonzero debt unconstructible.
- Closure
State Restore - Raw closure state; a stored edge always carries a raw nonzero debt vector.
- Committed
Binding Terminal - Cause-partitioned durable binding-terminal record.
- Connection
Conversation Tracking - Whether a semantic request’s conversation already owns a connection slot.
- Connection
Incarnation Allocation Decision - Connection-ordinal allocation decision.
- Connection
Incarnation Allocator Restore Error - Invalid durable connection-incarnation allocator header.
- Connection
Ordinal Exhaustion - Exact ordinal-exhaustion transition.
- Conversation
Decision - Protocol decision that either owns one pending durable commit or refuses it.
- Conversation
Event Decode Error - Stable canonical event-decode failure.
- Conversation
Operation - One of the six lifecycle operations recordable by the conversation shell.
- Conversation
Refusal Reason - Reason a protocol decision emitted no durable event.
- Conversation
Replay Error - Semantic durable-replay failure for a structurally decoded event.
- Conversation
State Restore Error - Failure while jointly restoring claim frontiers and their current closure edge.
- Credential
Attach Capacity Decision - Exhaustive stage-8 credential-attach runtime-capacity result.
- Credential
Attach Lookup Result - Total credential-attach lookup result through authority phase 3.
- Credential
Attach Token Phase - Phase selected by credential-attach token lookup.
- Cumulative
AckAuthorization Error - Authority failure before a cumulative-ack transition.
- Cumulative
AckOutcome - Exhaustive outcome of an authority-checked normal cumulative ack.
- Cursor
Episode Build Error - Construction failure for a participant-scoped nonzero-debt episode.
- Cursor
Fact Encode Error - Deterministic cursor-fact serialization failure.
- Cursor
Fate Successor - Closed cursor-fate result taxonomy retained for API compatibility.
- Cursor
Progress Fact - Durable cursor-progress fact state.
- Debt
Completion Restore - Raw durable successor class accepted by detached Leave or fenced attach.
- Detach
Cell - Exact four-variant detach cell mandated by the extraction brief.
- Detach
Cell Restore - Exact four-state durable detach replay cell.
- Detach
Commit Error - Invalid previous-cell state for accepting a new detach.
- Detach
Lookup Result - Total result of detach participant/token/binding lookup.
- Detach
Replay Error - Exact-token replay verification failure.
- Detach
Token Resolution - Exact-token resolution state for the identity-slot detach cell.
- Detach
Verification Error - Authority mismatch between an active binding and detach request.
- Detached
Attach Refusal - Exact refusal selected by a detached edge or charged retarget check.
- Detached
Binding Transition - Result of a fate that records a
Detachedlifecycle terminal. - Detached
Cursor Release Provenance Restore - Provenance alternatives capable of constructing
DetachedCursorRelease. - Died
Binding Transition - Result of a fate that records a
Diedlifecycle terminal. - Durable
Incarnation References Error - Error constructing a bounded complete durable-reference collection.
- Enrollment
Capacity Decision - Exhaustive stage-8 enrollment runtime-capacity result.
- Enrollment
Commit Error - Failure while committing a previously allocated enrollment.
- Enrollment
Lookup Result - Total enrollment-token lookup result through phase 0c.
- Enrollment
Token Phase - Phase-specific enrollment-token lookup state after the lifetime token index has run.
- Fenced
Attach Mint Refusal Reason - Exact reason the owner could not mint a fenced attach proof.
- Fresh
Participant Capacity Counter Invariant Error - Invalid restored occupancy for a participant that has not yet been minted.
- Frontier
Binding - Exact live participant binding state used by marker planning.
- Historical
Causal Fact Restore - Raw durable facts for one compacted causal lifecycle record.
- Identity
State - Present participant identity state; absence is represented outside this enum.
- Immutable
Sequence Candidate - Immutable assigned candidate above the current sequence high watermark.
- Initial
Enrollment Closure Error - Malformed durable/configuration input for initial enrollment projection.
- Initial
Enrollment Frontier Error - An admitted initial enrollment disagreed with its typed frontier projection.
- Initial
Enrollment Operation Decision - Exhaustive initial-enrollment operation result.
- Initial
Enrollment Operation Fault - Internal invariant fault separated from every wire-visible outcome.
- Leave
Commit Error - Failure while applying an already-authorized Leave transaction.
- Leave
Lookup Result - Total result of Leave participant/token/binding lookup.
- Leave
Secret Proof - Result of the permanent Leave-token verifier supplied by the consuming cryptographic layer.
- Leave
Verification Error - Failure while proving a live member’s exact Leave request authority.
- Live
Frontier Error - Failure selected while coupling a sealed lifecycle commit to live ownership.
- Live
Leave Error - Typed failure of the protocol-owned settled Leave live transition.
- Marker
AckCommit Error - Failure while applying an already-selected marker-ack commit.
- Marker
AckDecision - Total zero-debt marker-ack decision.
- Marker
Drain Error - Exact invariant fault selected by mandatory marker drain.
- Marker
Proof Decision - Exhaustive result of marker-proof selection after common authority.
- Marker
Proof Input - Operation-specific marker-proof input after common authority validation.
- Marker
Provenance - Immutable origin of one planned or appended marker value.
- Marker
Sequence Owner - Current logical owner of one marker-provenance value.
- Measured
Binding Fate - Protocol-produced binding fate after measuring the post-release floor.
- Membership
Invariant Error - Invalid durable membership/history combination.
- Mint
Fenced Attach Result - Complete result of the sole production fenced proof mint.
- Nonzero
AckEpisode Position - Durable episode position supplied while applying an aggregate ack commit.
- Nonzero
Participant AckCommit Error - Failure while applying an already-selected nonzero-debt ack commit.
- Nonzero
Participant AckDecision - Total nonzero-debt participant-ack decision.
- Nonzero
Participant AckInvariant Error - Durable aggregate mismatch found after common request authority succeeded.
- Observer
Checked Operation - Operations whose candidate floor is checked against hard observer retention.
- Observer
Floor Decision - Stage-11 observer hard-retention decision.
- Observer
Progress Advance Decision - Total transactional progress-advance decision against the owned aggregate.
- Observer
Progress Advance Error - Failure while advancing hard observer progress.
- Observer
Progress Track Decision - Total transactional registration decision against the owned aggregate.
- Observer
Progress Track Error - Failure while registering a newly tracked conversation.
- Observer
Recovery Aggregate Restore Error - Restore-time validation failure for the owned observer-recovery aggregate.
- Observer
Recovery Decision - Total observer-recovery decision.
- Observer
Recovery Transaction Decision - Total transactional observer-recovery decision against the owned aggregate.
- Order
Admission Error - Order admission refusal or impossible simulated state.
- Order
Claims Invariant Error - Invalid primitive order-claim state.
- Order
Direct Owner - Direct movable transaction-order owner stored in a bounded identity slot.
- Order
High - Persisted transaction-order high-watermark state.
- Order
Ledger Invariant Error - Invalid persisted order ledger.
- Ordinary
Projection Error - Invalid or noncommitting ordinary fixed-point snapshot.
- Ordinary
Record Projection Decision - Consuming fixed-point result for one optional ordinary record.
- Participant
AckCommit Error - Failure while applying an already-selected participant-ack commit.
- Participant
AckDecision - Total zero-debt participant-ack decision.
- Participant
Binding Request - Binding-required participant request families that share lookup phases 1 through 5.
- Participant
Cursor Progress - Cursor progress split into typestates rather than an optional marker bag.
- Participant
Lifecycle Restore - Complete event-replayed participant state, with tombstone precedence in the type.
- Participant
Slot Allocation Error - Invalid participant-slot allocation proof.
- Pending
Drain Decision - Result of the mandatory ordered drain attempt on advanced observer progress.
- Pending
Finalization - Binding authority ended, but its terminal record awaits durable append.
- Pending
Replay - Atomic durable result of exact-token pending replay.
- Pending
Replay Error - Invalid pending replay input or paired state.
- Prepare
Leave Authority Error - Failure to consume the exact order authority for a Leave transaction.
- Presented
Identity - Result of resolving the presented participant key before operation-specific authority checks.
- Receipt
Deadline Error - Failure to derive the frozen receipt/provenance deadline pair.
- Recipient
AckObligations Context Error - The testimony belongs to another participant or durable ack prestate.
- Recipient
AckObligations Error - Malformed durable recipient-obligation testimony.
- Record
Admission Decision - Exhaustive ordinary-record operation result.
- Record
Admission Fault - Internal durable/configuration fault, distinct from every wire outcome.
- Record
Size Decision - Static ordinary-record size decision in entry-before-byte order.
- Recovered
Binding Fate Transition - Preserve-or-cover result for cursor-releasing binding fate against OP/PC.
- Recovered
Storage Completion Restore - Exact completion event consuming a latent OP/PC predecessor.
- Recovery
Fence Decision - Stage-7 recovery-fence decision.
- Recovery
Quartet Status - Whether one enrollment projection endows the sole recovery quartet.
- Recovery
Sequence Reserve - Edge-owned recovery sequence claims.
- Remaining
Closure Decision - Stage-12 closure decision after observer admission.
- Required
Capacity Plan Error - Invalid required-capacity simulation.
- Resolved
Identity - Identity reached through an exact token index before the presented-key identity lookup runs.
- Restored
Binding Fate Terminal - Validated binding-fate terminal provenance.
- Restored
Participant Lifecycle - Validated runtime participant state restored from durable data.
- Retained
Causal Record Kind - Exact typed body class for one retained causal record.
- Retirement
Error - Mismatch between a live member and proposed stored Leave result.
- Sealed
Binding Fate Intent - Closed persistence shape carried by one sealed binding-fate token.
- Semantic
Connection Capacity Decision - Stage-6 semantic connection-capacity result.
- Sequence
Admission Error - Sequence admission refusal.
- Sequence
Direct Owner - Direct sequence-claim owner stored in an identity slot.
- Sequence
Ledger Invariant Error - Invalid persisted sequence ledger.
- Sequence
Product Class - Product class that may own a value before its causal transaction fires.
- Server
Incarnation Startup Decision - Startup decision for the checked server-incarnation increment.
- Storage
Restore Error - A durable lifecycle capsule failed a protocol invariant.
- Stored
Edge - Exact seven non-clear stored edge kinds.
- Stored
Edge Restore - Exact seven-kind stored-edge representation with provenance where required.
- Terminal
Product Source - Terminal source retained by immutable marker provenance.
Traits§
- Leave
Only Edge - Sealed intended-dead-end contract for DMR and
DCursor. - Participant
Slot Allocator Proof - Consuming allocator proof for one permanent participant reservation slot.
Functions§
- allocate_
connection_ incarnation - Allocates one checked connection ordinal, skipping every exact collision.
- apply_
attach_ frontier - Applies credential attach to the complete live owner.
- apply_
detach_ frontier - Applies a committed detach terminal to the complete live owner.
- apply_
enrollment_ frontier - Applies a subsequent enrollment to the complete live owner.
- apply_
initial_ enrollment - Applies frozen stages 2, 6, and 8-13 to initial enrollment.
- apply_
marker_ ack - Applies the complete zero-debt marker-ack selector.
- apply_
marker_ ack_ frontier - Applies a zero-debt marker acknowledgement cursor transition.
- apply_
nonzero_ participant_ ack - Applies the complete nonzero-debt normal-ack selector.
- apply_
nonzero_ participant_ ack_ frontier - Applies a nonzero-debt participant acknowledgement cursor transition.
- apply_
nonzero_ participant_ ack_ with_ obligations - Applies the nonzero-debt selector with durable recipient obligations.
- apply_
participant_ ack - Applies the complete zero-debt participant-ack selector.
- apply_
participant_ ack_ frontier - Applies a zero-debt participant acknowledgement cursor transition.
- apply_
participant_ ack_ with_ obligations - Applies the Unit 2 durable-obligation endpoint rule after shared lookup.
- apply_
record_ admission - Applies frozen stages 4-12 and constructs the exact phase-13 record commit.
- check_
observer_ floor - Applies the observer hard-retention selector to a protocol-computed floor.
- check_
record_ size - Applies the frozen stage-8
RecordTooLargeselector. - check_
recovery_ fence - Applies the stage-7 recovery-fence predicate before numeric admission.
- check_
remaining_ closure - Applies the remaining closure order: delivered marker, churn, then capacity.
- classify_
record_ admission_ binding - Classifies one ordinary record admission through the shared binding-required lookup WITHOUT consuming any claim-frontier authority.
- commit_
attach - Atomically commits a verified attach and applies Fix 1’s detach-cell rule.
- commit_
detach - Commits an immediate detach atomically with binding release.
- commit_
enrollment - Atomically creates membership, binding,
Attached, and canonical receipt. - commit_
leave - Commits bound or already-detached Leave, deriving all optional result fields.
- commit_
pending_ leave - Positionally commits one pending binding terminal immediately before
Left. - commit_
pending_ leave_ frontier - Commits a pending binding terminal immediately before Leave through one complete live owner.
- commit_
settled_ leave_ frontier - Commits settled bound or detached Leave through one complete live owner.
- complete_
pending_ detach - Completes one paired pending finalization and detach replay cell.
- decide_
attached_ operation - Selects the aggregate
Attachedevent for one consumed attach commit. - decide_
detached_ operation - Selects the aggregate
Detachedevent for one consumed detach transition. - decide_
enrolled_ operation - Selects the aggregate
Enrolledevent for one consumed enrollment commit. - decide_
left_ operation - Selects the aggregate
Leftevent for one consumed leave commit. - decide_
nonzero_ debt_ ack_ operation - Selects the aggregate
NonzeroDebtAckevent for one consumed ack commit. - decide_
ordinary_ binding_ fate_ operation - Selects the aggregate
BindingFateevent for one consumed ordinary fate. - decide_
recovered_ binding_ fate_ operation - Selects the aggregate
BindingFateevent for one consumed recovered fate. - drain_
next_ marker - Consumes the globally first marker candidate into one atomic durable commit.
- lookup_
binding_ required - Applies the common tombstone, unknown, generation, and exact-binding order for participant ack, marker ack, and ordinary admission.
- lookup_
credential_ attach - Applies credential-attach token lookup, tombstone precedence, verifier order, and ordinary live-authority checks.
- lookup_
detach - Applies the total participant lookup and detach-cell precedence.
- lookup_
enrollment - Applies token-to-identity tombstone precedence and enrollment’s three live token phases.
- lookup_
leave - Applies the committed-Leave exception, tombstone precedence, and live Leave authority/binding order.
- prepare_
server_ incarnation_ startup - Produces the checked startup fsync intent or exact server exhaustion.
- project_
initial_ enrollment_ closure - Projects the complete initial-enrollment closure transition.
- select_
credential_ attach_ binding_ slot - Selects credential-attach binding occupancy, permitting only an empty slot or rotation of the same presented participant.
- select_
credential_ attach_ capacity - Applies credential attach’s exact five-scope runtime-capacity order.
- select_
enrollment_ binding_ slot - Selects enrollment binding-slot occupancy without revealing its occupant.
- select_
enrollment_ capacity - Applies the fixed enrollment runtime-capacity order atomically.
- select_
marker_ proof - Applies the frozen total marker-proof selector in its exact precedence order.
- select_
semantic_ connection_ capacity - Applies semantic connection-conversation capacity before participant mutation.
- start_
blocked_ detach - Starts an observer-blocked detach with terminal authority already ended.
Type Aliases§
- Aggregate
Operation Result - Total aggregate decision, or the fail-loud pairing fault for the two producers whose event bodies revalidate their consumed commit.
- Live
Frontier Result - Result of coupling any typed lifecycle commit to live frontier ownership.