pub struct DecisionMode { /* private fields */ }Implementations§
Source§impl DecisionMode
impl DecisionMode
Sourcepub fn new(evaluator: Arc<dyn PolicyEvaluator>) -> Self
pub fn new(evaluator: Arc<dyn PolicyEvaluator>) -> Self
Construct the mode with an injected governance policy evaluator.
Trait Implementations§
Source§impl Mode for DecisionMode
impl Mode for DecisionMode
Authorize the sender for decision mode messages.
Authority matrix (RFC-MACP-0004):
- Proposal, Evaluation, Objection, Vote → declared participant only
- Commitment → initiator or policy-delegated role
Source§fn on_session_start(
&self,
_session: &Session,
_env: &Envelope,
) -> Result<ModeResponse, MacpError>
fn on_session_start( &self, _session: &Session, _env: &Envelope, ) -> Result<ModeResponse, MacpError>
Decision accepts an empty participants list.
RFC-MACP-0001 §7.1 requires participants only “when required by the
Mode”, and RFC-MACP-0007 makes the initiator’s authority role-based
rather than membership-based, so the roster and the authority model are
independent here. A zero-participant Decision session is well-defined
and inert: Self::authorize_sender routes Proposal, Evaluation,
Objection and Vote through is_declared_participant, which is
false over an empty list, so every such message is FORBIDDEN
— the initiator’s included — and the session can only expire or be
cancelled. Spec #99 removed minItems: 1 from the conformance fixture
schema on that reasoning and added decision_zero_participants.json.
The roster rule is enforced in macp_core::session rather than here, so
the carve-out is named in exactly one place and every other mode keeps
the full canonical contract by default. The other four standards-track
modes still re-reject an insufficient roster in their own
on_session_start, which is where their mode-specific minima
(Task’s “someone other than the initiator”, Handoff’s two parties) have
to live anyway.
fn on_message( &self, session: &Session, env: &Envelope, ) -> Result<ModeResponse, MacpError>
Source§fn on_message_at(
&self,
session: &Session,
env: &Envelope,
ctx: &MessageContext,
) -> Result<ModeResponse, MacpError>
fn on_message_at( &self, session: &Session, env: &Envelope, ctx: &MessageContext, ) -> Result<ModeResponse, MacpError>
on_message plus the runtime’s
macp_core::mode::MessageContext (acceptance clock). Defaulted to plain
on_message so most modes ignore it; modes that need a trustworthy
time source (Handoff) override this instead of reading the forgeable
Envelope.timestamp_unix_ms. The runtime and replay always call this,
with the same clock value that the log entry records.