pub enum ApprovalThreshold {
Approvals(u32),
Unsatisfiable,
}Expand description
The approval bar an accepted ApprovalRequest must clear, as the mode
resolves it against the session’s bound policy.
Returned by QuorumMode::effective_threshold and, wrapped, by
QuorumMode::effective_threshold_for_session. Both variants are
reachable; “this session has no ApprovalRequest yet” is not a variant
here — that question is answered by the Option the session-level
accessor returns, so the two cannot be confused.
The policy’s own inert case (threshold.value <= 0, which includes the
schema default and therefore every session with no threshold rule at
all) is not a variant either: the mode’s documented fallback for it is
the ApprovalRequest’s own required_approvals, so it arrives here
already resolved as Approvals(required_approvals). Surfacing
macp_core::policy::rules::EffectiveThreshold::Inert instead would hand
the fallback rule back to the caller, which is the re-implementation this
accessor exists to delete (issue #146).
Deliberately not #[non_exhaustive], matching
macp_core::policy::rules::EffectiveThreshold and for the same reason:
a _ arm in a caller would silently reinterpret a future variant as one
of these, and silently mis-handling a governance bar is the defect class
issue #145 was. Adding a variant is a major cargo-semver-checks lint
(enum_variant_added) and release-plz.toml sets semver_check = true,
so it blocks the release PR rather than slipping out.
Variants§
Approvals(u32)
This many Approve ballots seal a positive commitment.
Never zero, and for a session whose ApprovalRequest the mode
accepted, never above the declared participant count: on_message
constrains both the payload field and any policy replacement for it to
1..=participants.
Unsatisfiable
The bound policy admits no positive commitment at any approval count.
Reached by an unrecognised threshold.type — including weighted,
which RFC-MACP-0012 1.2.0-draft removed from the vocabulary and
reserved — or by a percentage over an empty participant set — see
macp_core::policy::rules::EffectiveThreshold::Unsatisfiable.
RegisterPolicy refuses the first, so a session can only carry
such a policy if the PolicyDefinition was constructed directly (or
restored from a checkpoint that predates those checks). The second is
not catchable at registration — there is no participant count there —
and is blocked by QuorumMode::on_session_start rejecting an empty
participant set. The mode seals neither outcome on such a session,
positive or negative.