Expand description
Declaration-driven gate for capability-scoped operations.
The gate contains no domain policy: callers provide a manifest declaration,
exact approval verifier/use adapters, a record sink, and the performer. The
journal-backed OperationLifecycle adds bounded fenced leases, durable
dispatch, independent postcondition observation, and truthful reconciliation.
Structs§
- Approval
- Approval presented for a reviewed operation.
- Dispatch
Id - Identity of a dispatch durably recorded before a performer is called.
- Evidence
SetId - Identity of the evidence carried by one observation.
- Fenced
Dispatch - Durable performer handoff bound to an exact grant, attempt, and fenced lease.
- Fenced
Dispatch Id - Identity of one lease-bound durable dispatch.
- Gate
Context - Dependencies used to guard one operation.
- Gate
Record - Audit record emitted after successful first performance.
- Lease
Window - Explicit holder and monotonic bounds for one operation lease acquisition.
- Lifecycle
Receipt - Raw performer acknowledgement bound to one fenced dispatch.
- Lifecycle
Receipt Id - Identity of one raw lifecycle performer receipt.
- Operation
Attempt - One caller-selected attempt ordinal for a stable operation.
- Operation
Attempt Id - Identity of one attempt record, kept separate from the operation id.
- Operation
Declaration - Canonical operation declaration supplied by a domain manifest.
- Operation
Dispatch - Exact durable handoff to an injected performer.
- Operation
Grant - Exact authority presented for one operation.
- Operation
Grant Id - Identity of one separately recorded least-authority grant.
- Operation
Id - Stable identity derived only from canonical immutable operation intent.
- Operation
Intent - Canonical semantic intent whose identity survives grants, attempts, and leases.
- Operation
Lease - Bounded effect authority tied to the journal writer fence that recorded it.
- Operation
Lease Id - Identity of one bounded, fenced operation lease.
- Operation
Lifecycle - Journal-backed M5 coordinator for fenced dispatch and independent reconciliation.
- Operation
Lifecycle Record - Complete verified lifecycle history reconstructed only from the journal.
- Operation
Observation - Durable independent observation of one operation postcondition.
- Operation
Observation Id - Identity of one independent postcondition observation.
- Operation
Outcome Id - Identity of one durable reconciliation outcome.
- Operation
Record - Complete verified durable record for one operation.
- Operation
Service - Journal-backed owner of durable operation intent, dispatch, and raw receipts.
- Performer
Receipt - Raw performer acknowledgement bound to one durable dispatch.
- Performer
Receipt Id - Identity of a raw performer acknowledgement.
- Postcondition
Request - Request passed to an independent observer without performer authority.
Enums§
- Approval
Decision - Explicit approval decision.
- Durable
Operation State - The three durable states delivered by the operation-log phase.
- Execution
Mode - Policy label for an operation. None implies reversibility.
- Lifecycle
Performer Response - Result of calling a lifecycle performer after durable dispatch.
- Operation
Error - Typed refusal from durable operation construction, replay, or publication.
- Operation
Outcome - Reconciled semantic operation result.
- Operation
Step - Last durable lifecycle boundary available to reconciliation.
- Performer
Response - Result of one injected performer call.
- Postcondition
Response - Typed result from a postcondition observer.
- Replay
Policy - Replay rule bound into immutable operation intent.
- Sink
Failure Policy - Policy for a record-sink failure after the operation performed.
Traits§
- Approval
Use - Atomically consumes a verified approval once.
- Approval
Verifier - Validates approval authenticity and validity without consuming it.
- Gate
Record Sink - Receives gate records.
- Lifecycle
Performer - Effect authority invoked only after a matching fenced dispatch is durable.
- Operation
Performer - Effect boundary used only after a matching dispatch is durable.
- Postcondition
Observer - Effect-free identity plus independently performed postcondition observation.
Functions§
- guard_
operation - Guard and resolve an effect, returning the kernel’s result reference directly.
Type Aliases§
- Operation
Intent Id - Identity of canonical operation intent.