pub enum ConsumeOutcome<R> {
Handled(TrustTask<R>),
Rejected(TrustTask<ErrorPayload>),
Suppressed,
Duplicate {
prior_response: Option<Value>,
in_flight: bool,
},
}Expand description
Possible outcomes of consume_inbound.
Variants§
Handled(TrustTask<R>)
The document passed every framework check and the caller’s handler produced a success response. The caller emits the response over the same transport that delivered the request.
Rejected(TrustTask<ErrorPayload>)
A framework check failed and the rejection has a routable
recipient, OR the caller’s handler returned an
ErrorResponse of its own. Either way the document is
already addressed per SPEC.md §8.1 — the caller emits it over
the transport.
Suppressed
SPEC.md §8.1 routing rule for identity_mismatch: the in-band
issuer is by definition the contested identity, and the
transport authenticated no sender, so the consumer SHOULD NOT
emit any response (doing so would constitute an oracle).
Callers SHOULD log this case for audit — silent suppression is the spec rule but invisible suppression is an ops footgun.
Duplicate
SPEC.md §7.2 item 11: a document with this id and this content was
already accepted for execution. The handler was not called, and the
consequential effect did not happen a second time. This is the §8.4
retry being absorbed, which is the outcome that makes retrying safe.
This is not an error. §7.2 (Disposition of a duplicate): “In no
case is a duplicate reported as taskFailed; the task did not fail, it
already happened.” A caller that folded this into
Rejected would report a failure that did not occur,
and would tell the producer to investigate a working system.
What to emit:
prior_responsepresent — emit it. It is the response document the first execution produced (a success response, or a non-retryable error response; tell them apart by itstype), which §7.2 says the consumer SHOULD return.prior_responseabsent,in_flight == false— the specification defines no success response (§4.4.1’s fire-and-forget case) or the guard retains none. Emit nothing: “there is nothing to return: the consumer declines to execute again and that silence is the correct disposition, not an error.”in_flight == true— the original execution has not finished. §7.2: “the consumer SHOULD return or expose the existing execution state rather than begin another.”
Trait Implementations§
Auto Trait Implementations§
impl<R> Freeze for ConsumeOutcome<R>
impl<R> RefUnwindSafe for ConsumeOutcome<R>where
TrustTask<R>: RefUnwindSafe,
impl<R> Send for ConsumeOutcome<R>
impl<R> Sync for ConsumeOutcome<R>
impl<R> Unpin for ConsumeOutcome<R>
impl<R> UnsafeUnpin for ConsumeOutcome<R>where
TrustTask<R>: UnsafeUnpin,
impl<R> UnwindSafe for ConsumeOutcome<R>where
TrustTask<R>: UnwindSafe,
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> BorrowUnordered for T
impl<T> BorrowUnordered for T
fn as_unordered(&self) -> &Unordered<T>
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoRequest<T> for T
impl<T> IntoRequest<T> for T
Source§fn into_request(self) -> Request<T>
fn into_request(self) -> Request<T>
T in a tonic::RequestSource§impl<T, U, C> IntoWithContext<U, C> for Twhere
U: FromWithContext<T, C>,
impl<T, U, C> IntoWithContext<U, C> for Twhere
U: FromWithContext<T, C>,
Source§impl<T> Pointable for T
impl<T> Pointable for T
Source§impl<T> PolicyExt for Twhere
T: ?Sized,
impl<T> PolicyExt for Twhere
T: ?Sized,
impl<T> Read<Exclusive, BecauseExclusive> for Twhere
T: ?Sized,
Source§impl<T> ResourceProvider<()> for T
impl<T> ResourceProvider<()> for T
Source§fn get_resource(&self) -> &()
fn get_resource(&self) -> &()
T.