Skip to main content

DecisionMode

Struct DecisionMode 

Source
pub struct DecisionMode { /* private fields */ }

Implementations§

Source§

impl DecisionMode

Source

pub fn new(evaluator: Arc<dyn PolicyEvaluator>) -> Self

Construct the mode with an injected governance policy evaluator.

Trait Implementations§

Source§

impl Mode for DecisionMode

Source§

fn authorize_sender( &self, session: &Session, env: &Envelope, ) -> Result<(), MacpError>

Authorize the sender for decision mode messages.

Authority matrix (RFC-MACP-0004):

  • Proposal, Evaluation, Objection, Vote → declared participant only
  • Commitment → initiator or policy-delegated role
Source§

fn on_session_start( &self, _session: &Session, _env: &Envelope, ) -> Result<ModeResponse, MacpError>

Decision accepts an empty participants list.

RFC-MACP-0001 §7.1 requires participants only “when required by the Mode”, and RFC-MACP-0007 makes the initiator’s authority role-based rather than membership-based, so the roster and the authority model are independent here. A zero-participant Decision session is well-defined and inert: Self::authorize_sender routes Proposal, Evaluation, Objection and Vote through is_declared_participant, which is false over an empty list, so every such message is FORBIDDEN — the initiator’s included — and the session can only expire or be cancelled. Spec #99 removed minItems: 1 from the conformance fixture schema on that reasoning and added decision_zero_participants.json.

The roster rule is enforced in macp_core::session rather than here, so the carve-out is named in exactly one place and every other mode keeps the full canonical contract by default. The other four standards-track modes still re-reject an insufficient roster in their own on_session_start, which is where their mode-specific minima (Task’s “someone other than the initiator”, Handoff’s two parties) have to live anyway.

Source§

fn on_message( &self, session: &Session, env: &Envelope, ) -> Result<ModeResponse, MacpError>

Source§

fn on_message_at( &self, session: &Session, env: &Envelope, ctx: &MessageContext, ) -> Result<ModeResponse, MacpError>

Kernel entry point: on_message plus the runtime’s macp_core::mode::MessageContext (acceptance clock). Defaulted to plain on_message so most modes ignore it; modes that need a trustworthy time source (Handoff) override this instead of reading the forgeable Envelope.timestamp_unix_ms. The runtime and replay always call this, with the same clock value that the log entry records.
Source§

fn validate_client_envelope( &self, session: &Session, env: &Envelope, ) -> Result<(), MacpError>

The client boundary: validate an envelope that a client submitted on the live path, before it is dispatched. Read more
Source§

fn due_synthetic_envelope( &self, session: &Session, now_ms: i64, ) -> Option<Envelope>

The synthesis seam: given this session and this clock reading, the envelope (if any) that MUST enter accepted history before the message currently being processed. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more