pub struct DecisionMode { /* private fields */ }Implementations§
Source§impl DecisionMode
impl DecisionMode
Sourcepub fn new(evaluator: Arc<dyn PolicyEvaluator>) -> DecisionMode
pub fn new(evaluator: Arc<dyn PolicyEvaluator>) -> DecisionMode
Construct the mode with an injected governance policy evaluator.
Trait Implementations§
Source§impl Mode for DecisionMode
impl Mode for DecisionMode
Authorize the sender for decision mode messages.
Authority matrix (RFC-MACP-0004):
- Proposal, Evaluation, Objection, Vote → declared participant only
- Commitment → initiator or policy-delegated role
Source§fn on_session_start(
&self,
_session: &Session,
_env: &Envelope,
) -> Result<ModeResponse, MacpError>
fn on_session_start( &self, _session: &Session, _env: &Envelope, ) -> Result<ModeResponse, MacpError>
Decision accepts an empty participants list.
RFC-MACP-0001 §7.1 requires participants only “when required by the
Mode”, and RFC-MACP-0007 makes the initiator’s authority role-based
rather than membership-based, so the roster and the authority model are
independent here. A zero-participant Decision session is well-defined
and inert: Self::authorize_sender routes Proposal, Evaluation,
Objection and Vote through is_declared_participant, which is
false over an empty list, so every such message is FORBIDDEN
— the initiator’s included — and the session can only expire or be
cancelled. Spec #99 removed minItems: 1 from the conformance fixture
schema on that reasoning and added decision_zero_participants.json.
The roster rule is enforced in macp_core::session rather than here, so
the carve-out is named in exactly one place and every other mode keeps
the full canonical contract by default. The other four standards-track
modes still re-reject an insufficient roster in their own
on_session_start, which is where their mode-specific minima
(Task’s “someone other than the initiator”, Handoff’s two parties) have
to live anyway.
fn on_message( &self, session: &Session, env: &Envelope, ) -> Result<ModeResponse, MacpError>
Source§fn on_message_at(
&self,
session: &Session,
env: &Envelope,
ctx: &MessageContext,
) -> Result<ModeResponse, MacpError>
fn on_message_at( &self, session: &Session, env: &Envelope, ctx: &MessageContext, ) -> Result<ModeResponse, MacpError>
on_message plus the runtime’s
macp_core::mode::MessageContext (acceptance clock). Defaulted to plain
on_message so most modes ignore it; modes that need a trustworthy
time source (Handoff) override this instead of reading the forgeable
Envelope.timestamp_unix_ms. The runtime and replay always call this,
with the same clock value that the log entry records.Auto Trait Implementations§
impl !RefUnwindSafe for DecisionMode
impl !UnwindSafe for DecisionMode
impl Freeze for DecisionMode
impl Send for DecisionMode
impl Sync for DecisionMode
impl Unpin for DecisionMode
impl UnsafeUnpin for DecisionMode
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoRequest<T> for T
impl<T> IntoRequest<T> for T
Source§fn into_request(self) -> Request<T>
fn into_request(self) -> Request<T>
T in a tonic::Request