Expand description
Versioned fail-closed wire envelopes for remote query execution.
One validated plan/result contract serves direct and server execution: the request carries the exact canonical plan bytes plus the invocation (operation, input rows, caller budgets), the exact executor advertisement, an absolute bounded expiry, and a caller nonce; the response binds that nonce and the whole request fingerprint so replayed or foreign evidence is rejected before any host object is constructed. Envelope formats are versioned independently of the plan format.
Structs§
- Remote
Capabilities - One executor capability advertisement for pre-flight negotiation.
- Remote
Capabilities Fingerprint - The canonical fingerprint of one exact capability advertisement.
- Remote
Executor Binding - One logical executor identity and one concrete process/shared-store epoch.
- Remote
Limits - Caller execution budgets carried with one remote invocation.
- Remote
Query Failure - One structured remote failure bound to its request.
- Remote
Query Request - One complete remote invocation of a reusable validated plan.
- Remote
Query Response - One successful remote execution bound to its request and plan.
- Remote
Reply Decode Limits - Caller limits checked before a typed remote outcome is allocated.
- Remote
Reply Signature - Exact Ed25519 signature carried by the authenticated outer reply.
- Remote
Reply Signing Digest - Domain-separated digest signed for one canonical unsigned outer reply.
- Remote
Request Fingerprint - The canonical fingerprint of one complete request envelope.
- Remote
Signing KeyId - Deterministic identity of one exact remote reply-signing public key.
- Remote
Signing Public Key - Exact Ed25519 public key trusted to authenticate replies from one executor.
Enums§
- Remote
Field Value - One typed field value of a remote fetched document.
- Remote
Outcome - The typed terminal outcome of one remote invocation.
- Remote
Outcome Shape - Expected authenticated success shape used for allocation-free budget scans.
- Remote
Reply - One decoded remote reply: a typed response or a request-bound failure.
- Remote
Value - One typed value of a remote result row.
Constants§
- DEFAULT_
REMOTE_ DEADLINE_ MS - Default lifetime for a remote request with no explicit caller deadline.
- MAX_
REMOTE_ CLOCK_ SKEW_ MS - Maximum positive client/server wall-clock skew admitted by remote preflight.
- MAX_
REMOTE_ DEADLINE_ MS - Longest caller deadline admitted by the first remote format: five minutes.
- QUERY_
REMOTE_ CAPABILITIES_ CANONICALIZATION - Canonicalization identifier for capability-advertisement fingerprints.
- QUERY_
REMOTE_ CAPABILITIES_ FINGERPRINT_ DOMAIN - Fingerprint domain for exact executor capability advertisements.
- QUERY_
REMOTE_ CAPABILITIES_ FORMAT_ V1 - The exact wire discriminator for first-format capability advertisements.
- QUERY_
REMOTE_ FAILURE_ FORMAT_ V1 - The exact wire discriminator for first-format remote failures.
- QUERY_
REMOTE_ REPLY_ KEY_ ID_ DOMAIN - Domain separating deterministic reply-signing key identifiers.
- QUERY_
REMOTE_ REPLY_ SIGNATURE_ DOMAIN - Domain separating Ed25519 reply signatures from every other signed value.
- QUERY_
REMOTE_ REQUEST_ CANONICALIZATION - Canonicalization identifier for whole remote request envelopes.
- QUERY_
REMOTE_ REQUEST_ FINGERPRINT_ DOMAIN - Fingerprint domain for whole remote request envelopes.
- QUERY_
REMOTE_ REQUEST_ FORMAT_ V1 - The exact wire discriminator for first-format remote requests.
- QUERY_
REMOTE_ RESPONSE_ FORMAT_ V1 - The exact wire discriminator for first-format remote responses.
- QUERY_
REMOTE_ SIGNED_ REPLY_ FORMAT_ V1 - The authenticated outer reply format used for both successes and failures.
Traits§
- Remote
Reply Signer - Binding-neutral signing operation used by the contract wire encoder.
- Remote
Reply Verifier - Binding-neutral signature verifier used before any reply payload is decoded.
Functions§
- checked_
remote_ deadline - Convert one optional caller-supplied deadline into the wire range.
- checked_
remote_ limit - Convert one caller-supplied limit into the unsigned wire range.
- decode_
remote_ reply - Decode one reply envelope of either kind and verify its request binding.
- decode_
signed_ remote_ failure - Authenticate and decode an uncorrelated remote failure.
- remote_
deadline_ limit - Stable rejection for a deadline outside the supported monotonic range.
- remote_
limit_ invalid - The stable rejection every out-of-range limit argument maps to.
- remote_
signature_ invalid - Stable rejection for an unauthenticated or foreign remote reply.