Skip to main content

Module query_remote

Module query_remote 

Source
Expand description

Versioned fail-closed wire envelopes for remote query execution.

One validated plan/result contract serves direct and server execution: the request carries the exact canonical plan bytes plus the invocation (operation, input rows, caller budgets), the exact executor advertisement, an absolute bounded expiry, and a caller nonce; the response binds that nonce and the whole request fingerprint so replayed or foreign evidence is rejected before any host object is constructed. Envelope formats are versioned independently of the plan format.

Structs§

RemoteCapabilities
One executor capability advertisement for pre-flight negotiation.
RemoteCapabilitiesFingerprint
The canonical fingerprint of one exact capability advertisement.
RemoteExecutorBinding
One logical executor identity and one concrete process/shared-store epoch.
RemoteLimits
Caller execution budgets carried with one remote invocation.
RemoteQueryFailure
One structured remote failure bound to its request.
RemoteQueryRequest
One complete remote invocation of a reusable validated plan.
RemoteQueryResponse
One successful remote execution bound to its request and plan.
RemoteReplyDecodeLimits
Caller limits checked before a typed remote outcome is allocated.
RemoteReplySignature
Exact Ed25519 signature carried by the authenticated outer reply.
RemoteReplySigningDigest
Domain-separated digest signed for one canonical unsigned outer reply.
RemoteRequestFingerprint
The canonical fingerprint of one complete request envelope.
RemoteSigningKeyId
Deterministic identity of one exact remote reply-signing public key.
RemoteSigningPublicKey
Exact Ed25519 public key trusted to authenticate replies from one executor.

Enums§

RemoteFieldValue
One typed field value of a remote fetched document.
RemoteOutcome
The typed terminal outcome of one remote invocation.
RemoteOutcomeShape
Expected authenticated success shape used for allocation-free budget scans.
RemoteReply
One decoded remote reply: a typed response or a request-bound failure.
RemoteValue
One typed value of a remote result row.

Constants§

DEFAULT_REMOTE_DEADLINE_MS
Default lifetime for a remote request with no explicit caller deadline.
MAX_REMOTE_CLOCK_SKEW_MS
Maximum positive client/server wall-clock skew admitted by remote preflight.
MAX_REMOTE_DEADLINE_MS
Longest caller deadline admitted by the first remote format: five minutes.
QUERY_REMOTE_CAPABILITIES_CANONICALIZATION
Canonicalization identifier for capability-advertisement fingerprints.
QUERY_REMOTE_CAPABILITIES_FINGERPRINT_DOMAIN
Fingerprint domain for exact executor capability advertisements.
QUERY_REMOTE_CAPABILITIES_FORMAT_V1
The exact wire discriminator for first-format capability advertisements.
QUERY_REMOTE_FAILURE_FORMAT_V1
The exact wire discriminator for first-format remote failures.
QUERY_REMOTE_REPLY_KEY_ID_DOMAIN
Domain separating deterministic reply-signing key identifiers.
QUERY_REMOTE_REPLY_SIGNATURE_DOMAIN
Domain separating Ed25519 reply signatures from every other signed value.
QUERY_REMOTE_REQUEST_CANONICALIZATION
Canonicalization identifier for whole remote request envelopes.
QUERY_REMOTE_REQUEST_FINGERPRINT_DOMAIN
Fingerprint domain for whole remote request envelopes.
QUERY_REMOTE_REQUEST_FORMAT_V1
The exact wire discriminator for first-format remote requests.
QUERY_REMOTE_RESPONSE_FORMAT_V1
The exact wire discriminator for first-format remote responses.
QUERY_REMOTE_SIGNED_REPLY_FORMAT_V1
The authenticated outer reply format used for both successes and failures.

Traits§

RemoteReplySigner
Binding-neutral signing operation used by the contract wire encoder.
RemoteReplyVerifier
Binding-neutral signature verifier used before any reply payload is decoded.

Functions§

checked_remote_deadline
Convert one optional caller-supplied deadline into the wire range.
checked_remote_limit
Convert one caller-supplied limit into the unsigned wire range.
decode_remote_reply
Decode one reply envelope of either kind and verify its request binding.
decode_signed_remote_failure
Authenticate and decode an uncorrelated remote failure.
remote_deadline_limit
Stable rejection for a deadline outside the supported monotonic range.
remote_limit_invalid
The stable rejection every out-of-range limit argument maps to.
remote_signature_invalid
Stable rejection for an unauthenticated or foreign remote reply.