Expand description
Declaration-driven gate for capability-scoped operations.
The gate contains no domain policy: callers provide a manifest declaration, exact approval verifier/use adapters, a record sink, and the performer.
Structs§
- Approval
- Approval presented for a reviewed operation.
- Dispatch
Id - Identity of a dispatch durably recorded before a performer is called.
- Gate
Context - Dependencies used to guard one operation.
- Gate
Record - Audit record emitted after successful first performance.
- Operation
Attempt - One caller-selected attempt ordinal for a stable operation.
- Operation
Attempt Id - Identity of one attempt record, kept separate from the operation id.
- Operation
Declaration - Canonical operation declaration supplied by a domain manifest.
- Operation
Dispatch - Exact durable handoff to an injected performer.
- Operation
Grant - Exact authority presented for one operation.
- Operation
Grant Id - Identity of one separately recorded least-authority grant.
- Operation
Id - Stable identity derived only from canonical immutable operation intent.
- Operation
Intent - Canonical semantic intent whose identity survives grants, attempts, and leases.
- Operation
Record - Complete verified durable record for one operation.
- Operation
Service - Journal-backed owner of durable operation intent, dispatch, and raw receipts.
- Performer
Receipt - Raw performer acknowledgement bound to one durable dispatch.
- Performer
Receipt Id - Identity of a raw performer acknowledgement.
Enums§
- Approval
Decision - Explicit approval decision.
- Durable
Operation State - The three durable states delivered by the operation-log phase.
- Execution
Mode - Policy label for an operation. None implies reversibility.
- Operation
Error - Typed refusal from durable operation construction, replay, or publication.
- Performer
Response - Result of one injected performer call.
- Replay
Policy - Replay rule bound into immutable operation intent.
- Sink
Failure Policy - Policy for a record-sink failure after the operation performed.
Traits§
- Approval
Use - Atomically consumes a verified approval once.
- Approval
Verifier - Validates approval authenticity and validity without consuming it.
- Gate
Record Sink - Receives gate records.
- Operation
Performer - Effect boundary used only after a matching dispatch is durable.
Functions§
- guard_
operation - Guard and resolve an effect, returning the kernel’s result reference directly.
Type Aliases§
- Operation
Intent Id - Identity of canonical operation intent.