Skip to main content

meerkat_runtime/
traits.rs

1//! §23 Runtime traits — RuntimeDriver and RuntimeControlPlane.
2//!
3//! These define the interface between surfaces and the runtime control-plane.
4
5use meerkat_core::lifecycle::{InputId, RunId};
6use serde::{Deserialize, Serialize};
7
8use crate::accept::AcceptOutcome;
9use crate::identifiers::LogicalRuntimeId;
10use crate::input::Input;
11use crate::input_state::{InputLifecycleState, InputState, StoredInputState};
12use crate::runtime_event::RuntimeEventEnvelope;
13use crate::runtime_state::RuntimeState;
14
15/// Errors from RuntimeDriver operations.
16#[derive(Debug, Clone, thiserror::Error)]
17#[non_exhaustive]
18pub enum RuntimeDriverError {
19    /// The runtime is not in a state that can accept this operation.
20    #[error("Runtime not ready: {state}")]
21    NotReady { state: RuntimeState },
22
23    /// The runtime was never registered / does not exist.
24    ///
25    /// Distinct from [`RuntimeDriverError::Destroyed`] and
26    /// [`RuntimeDriverError::NotReady`] with a `Destroyed` state: absence means
27    /// the runtime id was never admitted, not that it once existed and was torn
28    /// down.
29    #[error("Runtime not found: {runtime_id}")]
30    NotFound { runtime_id: LogicalRuntimeId },
31
32    /// Input validation failed.
33    #[error("Input validation failed: {reason}")]
34    ValidationFailed { reason: String },
35
36    /// The runtime has been destroyed.
37    #[error("Runtime destroyed")]
38    Destroyed,
39
40    /// Durable recovery state could not be replayed through canonical runtime authority.
41    #[error("Recovery corruption: {reason}")]
42    RecoveryCorruption { reason: String },
43
44    /// Internal error.
45    #[error("Internal error: {0}")]
46    Internal(String),
47}
48
49/// Errors from RuntimeControlPlane operations.
50#[derive(Debug, Clone, thiserror::Error)]
51#[non_exhaustive]
52pub enum RuntimeControlPlaneError {
53    /// Runtime not found.
54    #[error("Runtime not found: {0}")]
55    NotFound(LogicalRuntimeId),
56
57    /// Invalid state for this operation.
58    #[error("Invalid state for operation: {state}")]
59    InvalidState { state: RuntimeState },
60
61    /// Store error.
62    #[error("Store error: {0}")]
63    StoreError(String),
64
65    /// Internal error.
66    #[error("Internal error: {0}")]
67    Internal(String),
68}
69
70/// Report from a recovery operation.
71#[derive(Debug, Clone, Serialize, Deserialize)]
72pub struct RecoveryReport {
73    /// How many inputs were recovered.
74    pub inputs_recovered: usize,
75    /// How many inputs were abandoned during recovery.
76    pub inputs_abandoned: usize,
77    /// How many inputs were re-queued.
78    pub inputs_requeued: usize,
79    /// Details of recovery actions.
80    #[serde(default, skip_serializing_if = "Vec::is_empty")]
81    pub details: Vec<String>,
82}
83
84/// Report from a retire operation.
85#[derive(Debug, Clone, Serialize, Deserialize)]
86pub struct RetireReport {
87    /// How many non-terminal inputs were abandoned.
88    pub inputs_abandoned: usize,
89    /// How many inputs are pending drain (will be processed before stopping).
90    #[serde(default)]
91    pub inputs_pending_drain: usize,
92}
93
94/// Report from a reset operation.
95#[derive(Debug, Clone, Serialize, Deserialize)]
96pub struct ResetReport {
97    /// How many non-terminal inputs were abandoned.
98    pub inputs_abandoned: usize,
99}
100
101/// Report from a recycle operation (reset driver and recover state).
102#[derive(Debug, Clone, Serialize, Deserialize)]
103pub struct RecycleReport {
104    /// How many inputs were transferred to the new instance.
105    pub inputs_transferred: usize,
106}
107
108/// Report from a destroy operation.
109#[derive(Debug, Clone, Serialize, Deserialize)]
110pub struct DestroyReport {
111    /// How many non-terminal inputs were abandoned.
112    pub inputs_abandoned: usize,
113}
114
115/// The runtime driver — per-session interface for input acceptance and lifecycle.
116///
117/// Each session gets its own RuntimeDriver instance. The driver manages the
118/// InputState ledger, policy resolution, and input queue for that session.
119#[cfg_attr(not(target_arch = "wasm32"), async_trait::async_trait)]
120#[cfg_attr(target_arch = "wasm32", async_trait::async_trait(?Send))]
121pub trait RuntimeDriver: Send + Sync {
122    /// Accept an input into the runtime.
123    async fn accept_input(&mut self, input: Input) -> Result<AcceptOutcome, RuntimeDriverError>;
124
125    /// Handle a runtime event (from the event bus).
126    async fn on_runtime_event(
127        &mut self,
128        event: RuntimeEventEnvelope,
129    ) -> Result<(), RuntimeDriverError>;
130
131    /// Recover from a crash/restart.
132    async fn recover(&mut self) -> Result<RecoveryReport, RuntimeDriverError>;
133
134    /// Get the current runtime state.
135    fn runtime_state(&self) -> RuntimeState;
136
137    /// Get the state of a specific input.
138    fn input_state(&self, input_id: &InputId) -> Option<&InputState>;
139
140    /// Get the current DSL-owned lifecycle phase of a specific input.
141    fn input_phase(&self, input_id: &InputId) -> Option<InputLifecycleState>;
142
143    /// Get the current DSL-owned last run association for a specific input.
144    fn input_last_run_id(&self, input_id: &InputId) -> Option<RunId>;
145
146    /// Get the current DSL-owned last boundary sequence for a specific input.
147    fn input_last_boundary_sequence(&self, input_id: &InputId) -> Option<u64>;
148
149    /// Get the persisted shell+seed bundle for a specific input.
150    fn stored_input_state(&self, input_id: &InputId) -> Option<StoredInputState>;
151
152    /// Resolve the machine-owned idempotency-key binding to its input id.
153    ///
154    /// Read-only reconciliation mirror of the generated admission map — it
155    /// decides nothing and never registers a binding (the accept-path
156    /// admission resolution stays the only mutator).
157    fn input_id_for_idempotency_key(&self, idempotency_key: &str) -> Option<InputId>;
158
159    /// List all non-terminal input IDs.
160    fn active_input_ids(&self) -> Vec<InputId>;
161}
162
163/// The runtime control plane — manages multiple runtime instances.
164#[cfg_attr(not(target_arch = "wasm32"), async_trait::async_trait)]
165#[cfg_attr(target_arch = "wasm32", async_trait::async_trait(?Send))]
166pub trait RuntimeControlPlane: Send + Sync {
167    /// Ingest an input into a specific runtime.
168    async fn ingest(
169        &self,
170        runtime_id: &LogicalRuntimeId,
171        input: Input,
172    ) -> Result<AcceptOutcome, RuntimeControlPlaneError>;
173
174    /// Publish a runtime event.
175    async fn publish_event(
176        &self,
177        event: RuntimeEventEnvelope,
178    ) -> Result<(), RuntimeControlPlaneError>;
179
180    /// Retire a runtime (no new input, drain existing).
181    async fn retire(
182        &self,
183        runtime_id: &LogicalRuntimeId,
184    ) -> Result<RetireReport, RuntimeControlPlaneError>;
185
186    /// Recycle a runtime (reset driver and recover state).
187    async fn recycle(
188        &self,
189        runtime_id: &LogicalRuntimeId,
190    ) -> Result<RecycleReport, RuntimeControlPlaneError>;
191
192    /// Reset a runtime (abandon all pending input).
193    async fn reset(
194        &self,
195        runtime_id: &LogicalRuntimeId,
196    ) -> Result<ResetReport, RuntimeControlPlaneError>;
197
198    /// Recover a runtime from crash.
199    async fn recover(
200        &self,
201        runtime_id: &LogicalRuntimeId,
202    ) -> Result<RecoveryReport, RuntimeControlPlaneError>;
203
204    /// Get the state of a runtime.
205    async fn runtime_state(
206        &self,
207        runtime_id: &LogicalRuntimeId,
208    ) -> Result<RuntimeState, RuntimeControlPlaneError>;
209
210    /// Destroy a runtime (terminal state, no recovery possible).
211    async fn destroy(
212        &self,
213        runtime_id: &LogicalRuntimeId,
214    ) -> Result<DestroyReport, RuntimeControlPlaneError>;
215
216    /// Load a boundary receipt for verification.
217    async fn load_boundary_receipt(
218        &self,
219        runtime_id: &LogicalRuntimeId,
220        run_id: &RunId,
221        sequence: u64,
222    ) -> Result<Option<meerkat_core::lifecycle::RunBoundaryReceipt>, RuntimeControlPlaneError>;
223}
224
225#[cfg(test)]
226#[allow(clippy::unwrap_used)]
227mod tests {
228    use super::*;
229
230    // Verify traits are object-safe
231    fn _assert_driver_object_safe(_: &dyn RuntimeDriver) {}
232    fn _assert_control_plane_object_safe(_: &dyn RuntimeControlPlane) {}
233
234    #[test]
235    fn runtime_driver_error_display() {
236        let err = RuntimeDriverError::NotReady {
237            state: RuntimeState::Initializing,
238        };
239        assert!(err.to_string().contains("initializing"));
240
241        let err = RuntimeDriverError::ValidationFailed {
242            reason: "bad input".into(),
243        };
244        assert!(err.to_string().contains("bad input"));
245    }
246
247    #[test]
248    fn runtime_control_plane_error_display() {
249        let err = RuntimeControlPlaneError::NotFound(LogicalRuntimeId::new("missing"));
250        assert!(err.to_string().contains("missing"));
251    }
252
253    #[test]
254    fn recovery_report_serde() {
255        let report = RecoveryReport {
256            inputs_recovered: 5,
257            inputs_abandoned: 1,
258            inputs_requeued: 3,
259            details: vec!["requeued 3 staged inputs".into()],
260        };
261        let json = serde_json::to_value(&report).unwrap();
262        let parsed: RecoveryReport = serde_json::from_value(json).unwrap();
263        assert_eq!(parsed.inputs_recovered, 5);
264    }
265}