harness-runtime
HarnessSpec v0.1 execution runtime — plane adapter traits, admission gate, loop strategies, no-amplification child spawning, and serde-stable run records (FINAL_SPEC §4)
HarnessSpec v0.1 execution runtime — plane adapter traits, admission gate, loop strategies, no-amplification child spawning, and serde-stable run records (FINAL_SPEC §4)
Package contract
| Field | Value |
|---|---|
| Language | rust |
| Source version | 0.1.0 |
| Manifest | forge-rs/harness-runtime/Cargo.toml |
| Source files | 29 |
| Evidence | Source reference; registry publication and runtime conformance are separate checks |
Import boundary
use harness_runtime;Use a source checkout or your verified private registry. Manifest coordinates identify the package; they do not establish that a public registry release exists.
Crate boundary
The following entries are taken from src/lib.rs. Feature conditions in the exact source still apply.
pub mod admission;
pub mod budget;
pub mod error;
pub mod planes;
pub mod record;
pub mod spawn;
pub mod spine;
pub mod strategy;
pub mod trace;
pub use admission::{
AdmissionRequest, AdmittedHarness, AdmittedParts, HarnessAdmission, RunContext,
};
pub use budget::BudgetLedger;
pub use error::{
AdmissionError, AmplificationRule, AmplificationViolation, BudgetError, PlaneError,
PlaneUnbound, RuntimeError, SpawnError, TraceContextError,
};
pub use planes::{
ApprovalDecision, ApprovalRequest, BudgetReservation, BudgetReservationRequest, ContextFrame,
ContextPlane, ContextRequest, EconomicsPlane, GateRequest, GateResult, HttpPlaneClient,
IdentityPlane, InferencePlane, InferenceRequest, InferenceResponse, InferenceUsage,
LineageVerification, LineageVerificationRequest, MediaArtifact, MemoryPlane, MemoryWrite,
ModelOutput, NoopPlanes, PerceptionPlane, PerceptionRecord, Placement, PlacementRequest, Plane,
PlaneKind, PlaneRegistry, PolicyDecision, PolicyPlane, PolicyRequest, SettlementRecord,
SettlementRequest, SubstratePlane, TelemetryEvent, TelemetryPlane, ToolInvocation, ToolOutput,
ToolsPlane, TranscriptEntry, TranscriptRole, VerificationPlane,
};
pub use record::{
AdmissionEvidence, HaltReason, PlaneDecision, RunOutcome, RunOutcomeKind, RunRecord,
SettlementEvidence, UsageTotals, RUN_RECORD_SCHEMA_VERSION,
};
pub use spawn::{spawn_child, SpawnedChild};
pub use spine::{
MapContextPlane, MapMemoryPlane, MapSpineClient, MapSpineConfig, SpineDispatchRecord,
SpineDispatchStatus,
};
pub use strategy::{
DagError, LoopStrategy, MicroDag, MicroDagNode, MicroDagStrategy, ReactLoop, RunPlan,
StrategyRegistry,
};
pub use trace::{TraceContext, TRACEPARENT_HEADER};Source reference
Download package reference JSON. Each original source file and generated declaration artifact has its own SHA-256 digest. Function bodies and constant values are omitted from downloads. These are source declaration inventories, not compiler-resolved rustdoc, TypeDoc, DocC, or Dokka output. Private modules can contain public declarations that are not reachable through the package boundary; consult the entry point before importing.
admission.rs
Read declaration text · 22 declaration entries
#[derive(Debug, Clone)]
pub struct RunContext {
/// Derivation depth (0 for a root harness; §4.5).
pub depth: u32,
/// Parent run id for spawned children.
pub parent_run_id: Option<String>,
/// The run's trace context, propagated to every provider call.
pub trace: TraceContext
}
pub fn root() -> Self;
pub fn child(
parent_run_id: impl Into<String>,
depth: u32,
parent_trace: &TraceContext,
) -> Self;
#[derive(Debug)]
pub struct AdmissionRequest {
/// The sealed manifest (already §5-validated by `harness-spec`).
pub manifest: ValidatedManifest,
/// The plane providers bound for this run.
pub planes: PlaneRegistry,
/// Where this run sits in the delegation tree.
pub run_context: RunContext
}
#[derive(Debug)]
pub struct AdmittedHarness {
}
pub fn run_id(&self) -> &str;
pub fn manifest(&self) -> &ValidatedManifest;
pub fn planes(&self) -> &PlaneRegistry;
pub fn budget(&self) -> &BudgetLedger;
pub fn budget_mut(&mut self) -> &mut BudgetLedger;
pub fn evidence(&self) -> &AdmissionEvidence;
pub fn context(&self) -> &RunContext;
pub fn started_at(&self) -> DateTime<Utc>;
pub async fn execute(
self,
strategies: &StrategyRegistry,
task: impl Into<String>,
) -> Result<RunRecord, RuntimeError>;
pub fn into_parts(self) -> AdmittedParts;
#[derive(Debug)]
pub struct AdmittedParts {
/// The run id minted at admission.
pub run_id: String,
/// The sealed manifest.
pub manifest: ValidatedManifest,
/// The bound planes.
pub planes: PlaneRegistry,
/// The run budget ledger.
pub budget: BudgetLedger,
/// Admission evidence.
pub evidence: AdmissionEvidence,
/// The run context.
pub context: RunContext,
/// Admission time.
pub started_at: DateTime<Utc>
}
#[derive(Debug, Clone)]
pub struct HarnessAdmission {
}
pub fn new(strategies: StrategyRegistry, context: ValidationContext) -> Self;
pub fn with_defaults() -> Self;
pub fn validation_context(&self) -> &ValidationContext;
pub async fn admit_toml(
&self,
source: &str,
planes: PlaneRegistry,
run_context: RunContext,
) -> Result<AdmittedHarness, AdmissionError>;
pub async fn admit(
&self,
request: AdmissionRequest,
) -> Result<AdmittedHarness, AdmissionError>;budget.rs
Read declaration text · 12 declaration entries
#[derive(Debug, Clone)]
pub struct BudgetLedger {
}
pub fn new(granted_usd: f64, granted_tokens: u64, on_exhausted: OnBudgetExhausted) -> Self;
pub fn remaining_usd(&self) -> f64;
pub fn remaining_tokens(&self) -> u64;
pub fn on_exhausted(&self) -> OnBudgetExhausted;
pub fn inference_calls(&self) -> u64;
pub fn is_exhausted(&self) -> bool;
pub fn check_can_spend(&self) -> Result<(), BudgetError>;
pub fn charge(&mut self, usage: &InferenceUsage);
pub fn record_tool_invocation(&mut self);
pub fn carve(&mut self, usd: f64, tokens: u64) -> Result<(), BudgetError>;
pub fn usage(&self) -> UsageTotals;error.rs
Read declaration text · 15 declaration entries
#[derive(Debug, Error)]
pub enum RuntimeError {
/// An operation reached a plane that is not bound to a provider.
#[error(transparent)]
PlaneUnbound(#[from] PlaneUnbound),
/// Admission denied the harness (§4.4: denied is a terminal state that
/// still settles and archives).
#[error(transparent)]
Admission(#[from] AdmissionError),
/// Child spawning violated the spawn policy or the no-amplification
/// invariant (§4.5).
#[error(transparent)]
Spawn(#[from] SpawnError),
/// The manifest selected a loop strategy the runtime has no driver
/// for (§5.13: `loop.strategy` must name a registered strategy).
#[error("loop strategy {strategy:?} has no registered driver in this runtime")]
StrategyUnavailable {
/// The strategy named by `loop.strategy`.
strategy: String,
},
}
#[derive(Debug, Clone, PartialEq, Eq, Error)]
#[error("plane {plane} is unbound: cannot perform {operation}")]
pub struct PlaneUnbound {
/// The unbound plane.
pub plane: PlaneKind,
/// The operation that was attempted.
pub operation: &'static str
}
pub fn new(plane: PlaneKind, operation: &'static str) -> Self;
#[derive(Debug, Clone, PartialEq, Error)]
pub enum PlaneError {
/// The plane has no provider bound (noop fail-closed path).
#[error(transparent)]
Unbound(#[from] PlaneUnbound),
/// The provider is unreachable or unavailable. Per §4.6, availability
/// is never disguised as success: admission denies, execution halts.
#[error("provider unavailable: {message}")]
Unavailable {
/// Human-readable detail.
message: String,
},
/// The provider actively denied the request (e.g. policy miss,
/// insufficient entitlement).
#[error("provider denied the request: {message}")]
Denied {
/// Human-readable detail.
message: String,
},
/// The provider did not answer within the configured timeout.
#[error("provider timed out after {timeout_ms} ms: {message}")]
Timeout {
/// The configured timeout in milliseconds.
timeout_ms: u64,
/// Human-readable detail.
message: String,
},
/// The provider answered with a response that could not be decoded or
/// fails the plane's contract.
#[error("invalid provider response: {message}")]
InvalidResponse {
/// Human-readable detail.
message: String,
},
/// Any other provider failure, with an optional upstream status code.
#[error("provider error{status_suffix}: {message}")]
Provider {
/// Upstream status code when the provider is HTTP-backed.
status: Option<u16>,
/// Human-readable detail.
message: String,
/// Pre-rendered status suffix for the Display impl.
status_suffix: String,
},
}
pub fn unavailable(message: impl Into<String>) -> Self;
pub fn denied(message: impl Into<String>) -> Self;
pub fn invalid_response(message: impl Into<String>) -> Self;
pub fn provider(status: Option<u16>, message: impl Into<String>) -> Self;
#[derive(Debug, Error)]
pub enum AdmissionError {
/// The manifest failed §5 validation when admission was invoked with
/// raw TOML (§5.16: a conforming runtime must refuse to execute a
/// manifest that fails validation).
#[error("manifest validation failed: {0}")]
ValidationFailed(#[from] SpecError),
/// A plane the manifest requires is not bound to a provider.
#[error("admission requires the {0}")]
PlaneUnbound(#[from] PlaneUnbound),
/// The identity plane rejected the lineage: the harness DID does not
/// chain to the declared human root, or the provider could not verify
/// it (§5.3, §4.6).
#[error("identity verification failed for {did}: {reason}")]
IdentityRejected {
/// The harness agent DID.
did: String,
/// Why verification failed.
reason: String,
},
/// The policy plane denied the inference permission/entitlement the
/// manifest requires (§5.8, §4.6: a policy engine miss denies
/// in-contract).
#[error("policy denied {permission}: {reason}")]
PolicyDenied {
/// The permission that was checked.
permission: String,
/// Why the policy plane denied it.
reason: String,
},
/// The economics plane refused or could not complete the budget
/// reservation (§4.4 step 3: metering failure is denial).
#[error("budget reservation failed: {0}")]
ReservationFailed(#[source] PlaneError),
/// The identity plane verified the lineage but returned no durable
/// evidence reference (§4.4 step 3: an admission allow without a
/// durable `evidenceRef` must not exist).
#[error("identity verification returned no evidence reference")]
MissingEvidenceRef,
/// The manifest's `loop.strategy` has no registered driver in this
/// runtime (§5.13: `loop.strategy` must name a registered strategy).
#[error("loop strategy {strategy:?} has no registered driver in this runtime")]
StrategyUnavailable {
/// The strategy named by `loop.strategy`.
strategy: String,
},
}
#[derive(Debug, Error)]
pub enum SpawnError {
/// The parent manifest declares `spawn.allowed = false`.
#[error("harness {harness_id:?} does not permit child spawning ([spawn].allowed = false)")]
SpawningDisabled {
/// The parent harness id.
harness_id: String,
},
/// The child would sit deeper than the manifest bound or the runtime
/// maximum derivation depth (§4.5, §5.3).
#[error("child depth {child_depth} exceeds the maximum derivation depth {max}")]
DepthLimitExceeded {
/// The depth the child would occupy.
child_depth: u32,
/// The effective maximum (min of manifest bound, runtime bound).
max: u32,
},
/// The child manifest failed §5 validation on its own terms.
#[error("child manifest invalid: {0}")]
InvalidChildManifest(#[from] SpecError),
/// The child would widen authority relative to its parent — the
/// no-amplification invariant (§4.5).
#[error("no-amplification violation: {0}")]
Amplification(#[from] AmplificationViolation),
/// The child's declared budgets could not be carved out of the
/// parent's remaining budget (§4.5: sibling budgets must not overlap).
#[error("budget carve failed: {0}")]
BudgetCarve(#[from] BudgetError),
}
#[derive(Debug, Clone, PartialEq, Error)]
#[error("[{rule}] {path}: {message}")]
pub struct AmplificationViolation {
/// Machine-checkable rule code.
pub rule: AmplificationRule,
/// Dotted manifest path of the offending child value.
pub path: String,
/// Human-readable explanation citing the governing spec section.
pub message: String
}
pub fn new(
rule: AmplificationRule,
path: impl Into<String>,
message: impl Into<String>,
) -> Self;
#[derive(Debug, Clone, Copy, PartialEq, Eq, Hash)]
pub enum AmplificationRule {
/// `tools.allow` is not a subset of the parent's (§4.5).
ToolSuperset,
/// `capabilities.act_refs` is not a subset of the parent's (§4.5).
CapabilitySuperset,
/// `policy.data_classes_allowed` is not a subset of the parent's
/// (§4.5).
DataClassSuperset,
/// A declared budget exceeds `spawn.child_budget_fraction_max` of the
/// parent's remaining budget (§4.5, §5.13).
BudgetFractionExceeded,
/// `memory.types` is not a subset of the parent's (§4.5: effective
/// authority of any subtree node is bounded by the root's).
MemoryTypeSuperset,
/// The parent is text-only (no `[perception]`) but the child declares
/// one (§4.7: perception is authority, narrowed on spawn).
PerceptionIntroduced,
/// `perception.modalities` is not a subset of the parent's (§4.7.5).
ModalitySuperset,
/// `perception.max_media_bytes` exceeds the parent's cap (§4.5:
/// budgets and caps narrow, they never loosen).
MediaCapLoosened,
/// `identity.max_child_depth` exceeds the parent's bound (§4.5:
/// derivation depth respects the manifest bound).
ChildDepthSuperset,
/// A parent-required tool approval was dropped by the child for a tool
/// it keeps (§5.9: dropping a HITL gate widens effective authority).
ApprovalGateDropped,
}
#[derive(Debug, Clone, PartialEq, Error)]
pub enum BudgetError {
/// A carve or charge exceeded the remaining budget.
#[error(
"insufficient budget: requested {requested_usd} USD / {requested_tokens} tokens, \
remaining {remaining_usd} USD / {remaining_tokens} tokens"
)]
Insufficient {
/// Requested USD.
requested_usd: f64,
/// Requested tokens.
requested_tokens: u64,
/// Remaining USD.
remaining_usd: f64,
/// Remaining tokens.
remaining_tokens: u64,
},
/// The budget is exhausted; the configured `on_budget_exhausted`
/// policy now applies (§5.8).
#[error("budget exhausted ({remaining_usd} USD / {remaining_tokens} tokens remaining)")]
Exhausted {
/// Remaining USD (may be zero or negative after the final charge).
remaining_usd: f64,
/// Remaining tokens.
remaining_tokens: u64,
},
}
#[derive(Debug, Clone, PartialEq, Eq, Error)]
#[error("invalid W3C traceparent value {value:?}: {reason}")]
pub struct TraceContextError {
/// The offending header value.
pub value: String,
/// Why it is invalid.
pub reason: String
}lib.rs
Read declaration text · 18 declaration entries
pub mod admission;
pub mod budget;
pub mod error;
pub mod planes;
pub mod record;
pub mod spawn;
pub mod spine;
pub mod strategy;
pub mod trace;
pub use admission::{
AdmissionRequest, AdmittedHarness, AdmittedParts, HarnessAdmission, RunContext,
};
pub use budget::BudgetLedger;
pub use error::{
AdmissionError, AmplificationRule, AmplificationViolation, BudgetError, PlaneError,
PlaneUnbound, RuntimeError, SpawnError, TraceContextError,
};
pub use planes::{
ApprovalDecision, ApprovalRequest, BudgetReservation, BudgetReservationRequest, ContextFrame,
ContextPlane, ContextRequest, EconomicsPlane, GateRequest, GateResult, HttpPlaneClient,
IdentityPlane, InferencePlane, InferenceRequest, InferenceResponse, InferenceUsage,
LineageVerification, LineageVerificationRequest, MediaArtifact, MemoryPlane, MemoryWrite,
ModelOutput, NoopPlanes, PerceptionPlane, PerceptionRecord, Placement, PlacementRequest, Plane,
PlaneKind, PlaneRegistry, PolicyDecision, PolicyPlane, PolicyRequest, SettlementRecord,
SettlementRequest, SubstratePlane, TelemetryEvent, TelemetryPlane, ToolInvocation, ToolOutput,
ToolsPlane, TranscriptEntry, TranscriptRole, VerificationPlane,
};
pub use record::{
AdmissionEvidence, HaltReason, PlaneDecision, RunOutcome, RunOutcomeKind, RunRecord,
SettlementEvidence, UsageTotals, RUN_RECORD_SCHEMA_VERSION,
};
pub use spawn::{spawn_child, SpawnedChild};
pub use spine::{
MapContextPlane, MapMemoryPlane, MapSpineClient, MapSpineConfig, SpineDispatchRecord,
SpineDispatchStatus,
};
pub use strategy::{
DagError, LoopStrategy, MicroDag, MicroDagNode, MicroDagStrategy, ReactLoop, RunPlan,
StrategyRegistry,
};
pub use trace::{TraceContext, TRACEPARENT_HEADER};planes/context.rs
Read declaration text · 3 declaration entries
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
pub struct ContextRequest {
/// Tenant scope from `[context].scope`.
pub scope: ContextScope,
/// The task text the frame is packed around.
pub task: String,
/// Hard cap for the packed frame, from `[context].frame_budget_tokens`.
pub frame_budget_tokens: u64
}
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
pub struct ContextFrame {
/// The packed frame content delivered to the inference plane.
pub packed: String,
/// Actual frame size in tokens. The runtime rejects the frame when
/// this exceeds the declared cap (§5.6).
pub tokens: u64
}
#[async_trait]
pub trait ContextPlane: Plane {
/// Pack the governed context frame for one run.
async fn pack_frame(&self, request: ContextRequest) -> Result<ContextFrame, PlaneError>;
}planes/economics.rs
Read declaration text · 5 declaration entries
#[derive(Debug, Clone, PartialEq, Serialize, Deserialize)]
pub struct BudgetReservationRequest {
/// The run id this reservation is tied to.
pub run_id: String,
/// BLAKE3 manifest hash (hex) identifying the harness contract.
pub manifest_hash: String,
/// Requested USD cap (`[inference].budget_usd`).
pub budget_usd: f64,
/// Requested token cap (`[inference].budget_tokens`).
pub budget_tokens: u64,
/// Declared meter map (`[economics].meters`, Garden two-segment keys).
pub meters: BTreeMap<String, String>,
/// Idempotency key per `[economics].idempotency` discipline.
pub idempotency_key: String
}
#[derive(Debug, Clone, PartialEq, Serialize, Deserialize)]
pub struct BudgetReservation {
/// Provider-side reservation id, echoed back at settlement.
pub reservation_id: String,
/// Granted USD cap.
pub granted_usd: f64,
/// Granted token cap.
pub granted_tokens: u64,
/// Durable evidence reference for the reservation.
pub evidence_ref: Option<String>
}
#[derive(Debug, Clone, PartialEq, Serialize, Deserialize)]
pub struct SettlementRequest {
/// The run id.
pub run_id: String,
/// The reservation being settled.
pub reservation_id: String,
/// Terminal usage totals.
pub usage: UsageTotals,
/// Terminal outcome kind.
pub outcome: RunOutcomeKind,
/// Idempotency key (same discipline as the reservation).
pub idempotency_key: String
}
#[derive(Debug, Clone, PartialEq, Serialize, Deserialize)]
pub struct SettlementRecord {
/// Provider-side settlement id.
pub settlement_id: String,
/// Settled USD.
pub settled_usd: f64,
/// Settled tokens.
pub settled_tokens: u64,
/// Durable evidence reference for the settlement.
pub evidence_ref: Option<String>
}
#[async_trait]
pub trait EconomicsPlane: Plane {
/// Reserve the run budget at admission. Failure is denial (§4.4,
/// §4.6): the harness must not execute.
async fn reserve_budget(
&self,
request: BudgetReservationRequest,
) -> Result<BudgetReservation, PlaneError>;
/// Settle the run exactly once, on every terminal state — verified,
/// failed, halted, denied all still settle (§4.4).
async fn settle(&self, request: SettlementRequest) -> Result<SettlementRecord, PlaneError>;
}planes/http.rs
Read declaration text · 10 declaration entries
#[derive(Debug, Error)]
pub enum HttpClientError {
/// The base URL is not a valid absolute http(s) URL.
#[error("invalid plane base URL {url:?}: {reason}")]
InvalidBaseUrl {
/// The offending URL.
url: String,
/// Why it is invalid.
reason: String,
},
/// The underlying HTTP client could not be built.
#[error("http client build failed: {0}")]
BuildFailed(String),
}
#[derive(Debug, Clone)]
pub struct HttpPlaneClient {
}
pub fn new(
plane: PlaneKind,
base_url: impl Into<String>,
timeout: Duration,
) -> Result<Self, HttpClientError>;
pub fn with_default_header(mut self, name: &str, value: impl Into<String>) -> Self;
pub fn plane(&self) -> PlaneKind;
pub fn base_url(&self) -> &str;
pub fn timeout(&self) -> Duration;
pub fn url(&self, path: &str) -> String;
pub async fn post_json<B, T>(
&self,
path: &str,
body: &B,
trace: &TraceContext,
) -> Result<T, PlaneError>
where
B: Serialize + Sync,
T: DeserializeOwned,;
pub async fn get_json<T>(&self, path: &str, trace: &TraceContext) -> Result<T, PlaneError>
where
T: DeserializeOwned,;planes/identity.rs
Read declaration text · 3 declaration entries
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
pub struct LineageVerificationRequest {
/// The harness agent DID (`[identity].did`).
pub did: String,
/// The lineage proof reference (`[identity].lineage_proof`).
pub lineage_proof: String,
/// The accountable owner the chain must terminate at
/// (`[harness].owner`).
pub expected_owner: String,
/// Derivation depth of this run (0 for a root harness).
pub depth: u32
}
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
pub struct LineageVerification {
/// True when the chain resolves and terminates at the expected human
/// root.
pub verified: bool,
/// The human root the chain terminates at, when resolved.
pub human_root: Option<String>,
/// Durable evidence reference for the verification (§4.4 step 3: an
/// admission allow without a durable `evidenceRef` must not exist).
pub evidence_ref: Option<String>
}
#[async_trait]
pub trait IdentityPlane: Plane {
/// Verify that `request.did` chains to `request.expected_owner`'s
/// human root. Provider unavailability is a typed
/// [`PlaneError::Unavailable`], never a silent pass (§4.6).
async fn verify_lineage(
&self,
request: LineageVerificationRequest,
) -> Result<LineageVerification, PlaneError>;
}planes/inference.rs
Read declaration text · 8 declaration entries
#[derive(Debug, Clone, PartialEq, Serialize, Deserialize)]
pub struct InferenceRequest {
/// The task (or packed context frame) the call is grounded in.
pub task: String,
/// The loop transcript so far (actions and observations, oldest
/// first).
pub transcript: Vec<TranscriptEntry>,
/// Optional output-token cap for this call.
pub max_output_tokens: Option<u64>
}
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
pub struct TranscriptEntry {
/// Whether this entry is an action the loop took or an observation it
/// received back.
pub role: TranscriptRole,
/// Entry content.
pub content: String
}
#[derive(Debug, Clone, Copy, PartialEq, Eq, Serialize, Deserialize)]
#[serde(rename_all = "snake_case")]
pub enum TranscriptRole {
/// Something the loop did (a tool call, an answer attempt).
Action,
/// What came back (tool output, denials, errors).
Observation,
}
#[derive(Debug, Clone, PartialEq, Serialize, Deserialize)]
#[serde(tag = "kind", rename_all = "snake_case")]
pub enum ModelOutput {
/// A text completion (the loop's final answer candidate).
Completion {
/// The completion text.
text: String,
},
/// A request to invoke a tool.
ToolCall {
/// The `<interface>/<action>` tool identifier.
tool: String,
/// Opaque tool input (plane-defined encoding).
input: String,
},
}
#[derive(Debug, Clone, Copy, PartialEq, Serialize, Deserialize)]
pub struct InferenceUsage {
/// Prompt/input tokens.
pub input_tokens: u64,
/// Completion/output tokens.
pub output_tokens: u64,
/// USD cost of this call.
pub cost_usd: f64
}
pub fn total_tokens(&self) -> u64;
#[derive(Debug, Clone, PartialEq, Serialize, Deserialize)]
pub struct InferenceResponse {
/// Structured model output.
pub output: ModelOutput,
/// Metered usage for the call.
pub usage: InferenceUsage
}
#[async_trait]
pub trait InferencePlane: Plane {
/// Run one model call through the binding. Routes resolve per
/// `[inference].route_policy` (§5.8: live catalog by default; pins
/// fail closed when no longer offered).
async fn complete(&self, request: InferenceRequest) -> Result<InferenceResponse, PlaneError>;
}planes/memory.rs
Read declaration text · 2 declaration entries
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
pub struct MemoryWrite {
/// Which memory type the write targets.
pub kind: MemoryType,
/// Application-defined key.
pub key: String,
/// The content to store.
pub content: String
}
#[async_trait]
pub trait MemoryPlane: Plane {
/// Write into the bound mind. Returns the provider's evidence
/// reference for the write, when it produces one.
async fn write(&self, write: MemoryWrite) -> Result<Option<String>, PlaneError>;
/// Consolidate the run's task-scoped writes into durable memory.
/// The runtime invokes this only for `verified` runs (§5.7:
/// consolidation must not occur for runs that end `failed`, `halted`,
/// or `denied`). Returns the consolidation evidence reference, when
/// the provider produces one.
async fn consolidate(&self, mind: String) -> Result<Option<String>, PlaneError>;
}planes/mod.rs
Read declaration text · 40 declaration entries
pub use context::{ContextFrame, ContextPlane, ContextRequest};
pub use economics::{
BudgetReservation, BudgetReservationRequest, EconomicsPlane, SettlementRecord,
SettlementRequest,
};
pub use http::HttpPlaneClient;
pub use identity::{IdentityPlane, LineageVerification, LineageVerificationRequest};
pub use inference::{
InferencePlane, InferenceRequest, InferenceResponse, InferenceUsage, ModelOutput,
TranscriptEntry, TranscriptRole,
};
pub use memory::{MemoryPlane, MemoryWrite};
pub use noop::NoopPlanes;
pub use perception::{MediaArtifact, PerceptionPlane, PerceptionRecord};
pub use policy::{PolicyDecision, PolicyPlane, PolicyRequest};
pub use substrate::{Placement, PlacementRequest, SubstratePlane};
pub use telemetry::{TelemetryEvent, TelemetryPlane};
pub use tools::{ApprovalDecision, ApprovalRequest, ToolInvocation, ToolOutput, ToolsPlane};
pub use verification::{GateRequest, GateResult, VerificationPlane};
#[derive(Debug, Clone, Copy, PartialEq, Eq, Hash, PartialOrd, Ord, Serialize, Deserialize)]
#[serde(rename_all = "snake_case")]
pub enum PlaneKind {
/// Identity plane (OAS DID lineage).
Identity,
/// Policy plane (information-flow / capability authorization).
Policy,
/// Context plane (packed governed frames).
Context,
/// Memory plane (episodic/procedural/resource/vault).
Memory,
/// Inference plane (model calls through the binding).
Inference,
/// Tools plane (allowlisted invocation + approvals).
Tools,
/// Verification plane (declared gates).
Verification,
/// Economics plane (reservation, metering, settlement).
Economics,
/// Telemetry plane (event emission).
Telemetry,
/// Substrate plane (execution placement).
Substrate,
/// Perception ingress (signed, typed SemanticIR — optional binding,
/// §4.7).
Perception,
}
pub trait Plane: Send + Sync {
/// Which plane this adapter serves.
fn kind(&self) -> PlaneKind;
/// Stable provider identifier for records and logs (e.g. `foundry`,
/// `lanes`, `noop`).
fn provider_id(&self) -> &str;
/// True when a real provider is bound. Noop adapters return false.
fn is_bound(&self) -> bool ;
}
#[derive(Clone, Default)]
pub struct PlaneRegistry {
}
pub fn new() -> Self;
pub fn noop_filled() -> Self;
pub fn with_identity(mut self, plane: Arc<dyn IdentityPlane>) -> Self;
pub fn with_policy(mut self, plane: Arc<dyn PolicyPlane>) -> Self;
pub fn with_context(mut self, plane: Arc<dyn ContextPlane>) -> Self;
pub fn with_memory(mut self, plane: Arc<dyn MemoryPlane>) -> Self;
pub fn with_inference(mut self, plane: Arc<dyn InferencePlane>) -> Self;
pub fn with_tools(mut self, plane: Arc<dyn ToolsPlane>) -> Self;
pub fn with_verification(mut self, plane: Arc<dyn VerificationPlane>) -> Self;
pub fn with_economics(mut self, plane: Arc<dyn EconomicsPlane>) -> Self;
pub fn with_telemetry(mut self, plane: Arc<dyn TelemetryPlane>) -> Self;
pub fn with_substrate(mut self, plane: Arc<dyn SubstratePlane>) -> Self;
pub fn with_perception(mut self, plane: Arc<dyn PerceptionPlane>) -> Self;
pub fn bound_identity(&self) -> Result<&Arc<dyn IdentityPlane>, PlaneUnbound>;
pub fn bound_policy(&self) -> Result<&Arc<dyn PolicyPlane>, PlaneUnbound>;
pub fn bound_context(&self) -> Result<&Arc<dyn ContextPlane>, PlaneUnbound>;
pub fn bound_memory(&self) -> Result<&Arc<dyn MemoryPlane>, PlaneUnbound>;
pub fn bound_inference(&self) -> Result<&Arc<dyn InferencePlane>, PlaneUnbound>;
pub fn bound_tools(&self) -> Result<&Arc<dyn ToolsPlane>, PlaneUnbound>;
pub fn bound_verification(&self) -> Result<&Arc<dyn VerificationPlane>, PlaneUnbound>;
pub fn bound_economics(&self) -> Result<&Arc<dyn EconomicsPlane>, PlaneUnbound>;
pub fn bound_telemetry(&self) -> Result<&Arc<dyn TelemetryPlane>, PlaneUnbound>;
pub fn bound_substrate(&self) -> Result<&Arc<dyn SubstratePlane>, PlaneUnbound>;
pub fn bound_perception(&self) -> Result<&Arc<dyn PerceptionPlane>, PlaneUnbound>;planes/noop.rs
Read declaration text · 2 declaration entries
pub struct NoopPlanes;
pub fn registry() -> PlaneRegistry;planes/perception.rs
Read declaration text · 3 declaration entries
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
pub struct MediaArtifact {
/// Declared modality; must be within `[perception].modalities`.
pub modality: Modality,
/// Raw source bytes (bounded by `[perception].max_media_bytes`).
pub bytes: Vec<u8>,
/// MIME media type hint.
pub media_type: String
}
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
pub struct PerceptionRecord {
/// Provider perception id; downstream consumers reference this, never
/// the raw bytes.
pub perception_id: String,
/// True when the IR is signed per the provider's signing model
/// (`require_signed_ir = true` makes unsigned records inadmissible).
pub signed: bool,
/// Content-addressed reference to the typed SemanticIR.
pub ir_ref: String,
/// Modalities actually perceived.
pub modalities: Vec<Modality>
}
#[async_trait]
pub trait PerceptionPlane: Plane {
/// Ingest one media artifact, yielding a signed, typed record.
/// §4.7.3: fail-closed — unsigned, unresolvable, or unverifiable
/// artifacts are rejected, never delivered best-effort.
async fn ingest(&self, artifact: MediaArtifact) -> Result<PerceptionRecord, PlaneError>;
}planes/policy.rs
Read declaration text · 3 declaration entries
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
pub struct PolicyRequest {
/// The harness agent DID requesting the action.
pub subject_did: String,
/// The permission being checked (`[inference].required_permission`).
pub permission: String,
/// The entitlement consumed (`[inference].entitlement`).
pub entitlement: String,
/// Policy document references from `[policy].policy_refs`.
pub policy_refs: Vec<String>
}
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
pub struct PolicyDecision {
/// True when the action is permitted.
pub allowed: bool,
/// Why the decision was made (denials MUST carry a reason).
pub reason: String
}
#[async_trait]
pub trait PolicyPlane: Plane {
/// Authorize the requested permission/entitlement for the subject.
async fn authorize(&self, request: PolicyRequest) -> Result<PolicyDecision, PlaneError>;
}planes/substrate.rs
Read declaration text · 3 declaration entries
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
pub struct PlacementRequest {
/// The run id.
pub run_id: String,
/// Substrate class (`[substrate].class`).
pub class: SubstrateClass,
/// Isolation class (`[substrate].isolation`).
pub isolation: Isolation
}
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
pub struct Placement {
/// Provider-side placement id.
pub placement_id: String,
/// Durable evidence reference for the placement, when produced.
pub evidence_ref: Option<String>
}
#[async_trait]
pub trait SubstratePlane: Plane {
/// Prepare the execution placement for a run.
async fn prepare(&self, request: PlacementRequest) -> Result<Placement, PlaneError>;
}planes/telemetry.rs
Read declaration text · 2 declaration entries
#[derive(Debug, Clone, PartialEq, Serialize, Deserialize)]
pub struct TelemetryEvent {
/// Full event type (`<event_prefix>.<declared-subject>`).
pub event_type: String,
/// Event subject (the run id).
pub subject: String,
/// Event payload.
pub data: serde_json::Value,
/// Emission time.
pub time: DateTime<Utc>
}
#[async_trait]
pub trait TelemetryPlane: Plane {
/// Emit one event. Returns the provider's event receipt reference,
/// when it produces one.
async fn emit(&self, event: TelemetryEvent) -> Result<Option<String>, PlaneError>;
}planes/tools.rs
Read declaration text · 5 declaration entries
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
pub struct ToolInvocation {
/// The run id the invocation belongs to.
pub run_id: String,
/// The `<interface>/<action>` tool identifier.
pub tool: String,
/// Opaque tool input (plane-defined encoding).
pub input: String,
/// Capability grants offered for authorization
/// (`[capabilities].act_refs`).
pub act_refs: Vec<String>
}
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
pub struct ToolOutput {
/// The tool's result content.
pub content: String,
/// Provider evidence reference for the invocation, when produced.
pub evidence_ref: Option<String>
}
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
pub struct ApprovalRequest {
/// The run id.
pub run_id: String,
/// The tool awaiting approval.
pub tool: String,
/// The input awaiting approval.
pub input: String
}
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
#[serde(tag = "decision", rename_all = "snake_case")]
pub enum ApprovalDecision {
/// Approved; the invocation may proceed.
Approved {
/// Who approved (human principal or approver-harness DID).
approver: String,
},
/// Denied; the loop receives the denial as an observation.
Denied {
/// Why the invocation was denied.
reason: String,
},
}
#[async_trait]
pub trait ToolsPlane: Plane {
/// Invoke an allowlisted tool against a covering capability grant.
async fn invoke(&self, invocation: ToolInvocation) -> Result<ToolOutput, PlaneError>;
/// Request approval for a gated invocation. Called only for tools in
/// `[tools].approval_required`; the runtime records the decision
/// either way (§5.9).
async fn request_approval(
&self,
request: ApprovalRequest,
) -> Result<ApprovalDecision, PlaneError>;
}planes/verification.rs
Read declaration text · 4 declaration entries
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
pub struct GateRequest {
/// The run id.
pub run_id: String,
/// The gate as declared in `[verification].gates`.
pub gate: Gate
}
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
pub struct GateResult {
/// The gate that was attempted.
pub gate: Gate,
/// Whether the gate actually executed. `passed` is meaningless —
/// and MUST be ignored — when this is false.
pub executed: bool,
/// Whether the executed gate passed.
pub passed: bool,
/// Exit code for command gates, when executed.
pub exit_code: Option<i32>,
/// Provider evidence reference, passed through verbatim or absent —
/// never synthesized (§5.10).
pub evidence_ref: Option<String>,
/// Human-readable detail (captured output summary, error).
pub detail: String
}
pub fn counts_as_pass(&self) -> bool;
#[async_trait]
pub trait VerificationPlane: Plane {
/// Execute one declared gate and return its machine-checkable result.
async fn run_gate(&self, request: GateRequest) -> Result<GateResult, PlaneError>;
}record.rs
Read declaration text · 10 declaration entries
pub const RUN_RECORD_SCHEMA_VERSION: &str;
#[derive(Debug, Clone, Copy, PartialEq, Serialize, Deserialize)]
pub struct UsageTotals {
/// Total input tokens across all inference calls.
pub input_tokens: u64,
/// Total output tokens across all inference calls.
pub output_tokens: u64,
/// `input_tokens + output_tokens`.
pub total_tokens: u64,
/// Total USD charged.
pub cost_usd: f64,
/// Number of inference calls made.
pub inference_calls: u64,
/// Number of tool invocations executed.
pub tool_invocations: u64
}
#[derive(Debug, Clone, Copy, PartialEq, Eq, Serialize, Deserialize)]
#[serde(rename_all = "snake_case")]
pub enum RunOutcomeKind {
/// All declared gates executed and passed.
Verified,
/// Execution finished but a gate failed, or a gate could not run.
Failed,
/// The run stopped early (budget, step limit, plane failure).
Halted,
/// Admission refused the run.
Denied,
}
#[derive(Debug, Clone, PartialEq, Serialize, Deserialize)]
#[serde(tag = "reason", rename_all = "snake_case")]
pub enum HaltReason {
/// The inference budget was exhausted (§5.8 `halt_and_settle`).
BudgetExhausted,
/// The budget was exhausted and the manifest's policy is
/// `request_approval` (§5.8): an extension approval was requested and
/// the run halted pending it — extension mints a new budget epoch, it
/// never edits the exhausted one.
BudgetExhaustedApprovalRequested,
/// `[loop].max_steps` was reached without a final answer.
StepLimitExceeded,
/// A plane call failed in-run (§4.4: any failure lands in a terminal
/// state with settlement — never silent continuation).
PlaneFailure {
/// The plane that failed.
plane: PlaneKind,
/// What happened.
detail: String,
},
}
#[derive(Debug, Clone, PartialEq, Serialize, Deserialize)]
#[serde(tag = "state", rename_all = "snake_case")]
pub enum RunOutcome {
/// All declared gates executed and passed.
Verified {
/// The final answer, when the loop produced one.
answer: Option<String>,
},
/// Execution finished but verification failed (§4.6: `failed` is
/// terminal with evidence; still settles).
Failed {
/// Why the run failed.
reason: String,
},
/// The run halted before completion.
Halted {
/// Why it halted.
cause: HaltReason,
},
/// Admission denied the run (§4.4: denied still settles and archives).
Denied {
/// Why admission denied the run.
reason: String,
},
}
pub fn kind(&self) -> RunOutcomeKind;
#[derive(Debug, Clone, PartialEq, Serialize, Deserialize)]
pub struct PlaneDecision {
/// The plane that made the decision.
pub plane: PlaneKind,
/// The operation decided (e.g. `tool.invoke`, `inference.complete`).
pub operation: String,
/// Whether the operation was allowed to proceed.
pub allowed: bool,
/// Why / what happened (tool id, denial reason, budget state).
pub detail: String
}
#[derive(Debug, Clone, PartialEq, Serialize, Deserialize)]
pub struct AdmissionEvidence {
/// The durable admission evidence reference.
pub evidence_ref: String,
/// The identity plane's lineage verification evidence, when produced.
pub lineage_evidence_ref: Option<String>,
/// The economics plane's reservation id.
pub reservation_id: String,
/// The reservation's evidence reference, when produced.
pub reservation_evidence_ref: Option<String>,
/// Granted USD budget.
pub granted_usd: f64,
/// Granted token budget.
pub granted_tokens: u64
}
#[derive(Debug, Clone, PartialEq, Serialize, Deserialize)]
pub struct SettlementEvidence {
/// The provider's settlement id.
pub settlement_id: String,
/// Settled USD.
pub settled_usd: f64,
/// Settled tokens.
pub settled_tokens: u64,
/// The settlement evidence reference, when produced.
pub evidence_ref: Option<String>
}
#[derive(Debug, Clone, PartialEq, Serialize, Deserialize)]
pub struct RunRecord {
/// Schema version ([`RUN_RECORD_SCHEMA_VERSION`]).
pub schema_version: String,
/// The run id minted at admission.
pub run_id: String,
/// BLAKE3 manifest hash (hex) identifying the harness contract.
pub manifest_hash: String,
/// Parent run id for spawned children (§4.5).
pub parent_run_id: Option<String>,
/// Derivation depth of this run (0 for a root harness).
pub depth: u32,
/// The harness id (`[harness].id`).
pub harness_id: String,
/// The agent DID (`[identity].did`).
pub agent_did: String,
/// The loop strategy that executed (`[loop].strategy`).
pub loop_strategy: String,
/// Admission evidence.
pub admission: AdmissionEvidence,
/// Ordered plane decisions.
pub decisions: Vec<PlaneDecision>,
/// Declared gate results, in manifest order.
pub gate_results: Vec<GateResult>,
/// Terminal usage totals.
pub usage: UsageTotals,
/// Terminal outcome.
pub outcome: RunOutcome,
/// Settlement evidence; present on every terminal state (§4.4: all
/// still settle). Absent only when settlement itself failed — which is
/// itself recorded in `telemetry_failures`.
pub settlement: Option<SettlementEvidence>,
/// Telemetry/consolidation failures observed during the run. Recording
/// them here keeps observability honest without silently dropping
/// events or rewriting the terminal outcome.
pub telemetry_failures: Vec<String>,
/// The run's W3C trace id (32 hex chars) propagated to providers.
pub trace_id: String,
/// When the run started (admission time).
pub started_at: DateTime<Utc>,
/// When the run reached its terminal state.
pub ended_at: DateTime<Utc>
}spawn.rs
Read declaration text · 7 declaration entries
#[derive(Debug)]
pub struct SpawnedChild {
}
pub fn manifest(&self) -> &ValidatedManifest;
pub fn depth(&self) -> u32;
pub fn carved_usd(&self) -> f64;
pub fn carved_tokens(&self) -> u64;
pub fn inherited_planes(&self) -> &[PlaneName];
pub fn spawn_child(
parent: &mut AdmittedHarness,
child_source: &str,
context: &ValidationContext,
) -> Result<SpawnedChild, SpawnError>;spine/client.rs
Read declaration text · 27 declaration entries
pub const MAP_BASE_URL_ENV: &str;
pub const MAP_AUTH_TYPE_ENV: &str;
pub const MAP_TENANT_ID_ENV: &str;
pub const MAP_AGENT_DID_ENV: &str;
pub const MAP_SCOPES_ENV: &str;
pub const MAP_TIMEOUT_MS_ENV: &str;
pub const MAP_MAX_RETRIES_ENV: &str;
pub const MAP_BEARER_TOKEN_ENV: &str;
pub const MIM_VERSION: &str;
pub const DEFAULT_MODULE_VERSION: &str;
pub const DEFAULT_TIMEOUT: Duration;
pub const DEFAULT_MAX_RETRIES: u32;
pub const RETRY_BACKOFF: Duration;
#[derive(Clone, Debug)]
pub struct MapSpineConfig {
/// MAP daemon base URL (no trailing slash).
pub base_url: String,
/// `x-l1fe-auth-type` header value.
pub auth_type: String,
/// `x-l1fe-tenant-id` header value; omitted when unset.
pub tenant_id: Option<String>,
/// Sender DID (`x-l1fe-agent-did` + envelope sender).
pub agent_did: String,
/// Scopes sent on every dispatch.
pub scopes: Vec<String>,
/// Per-attempt HTTP timeout.
pub timeout: Duration,
/// Retries after the first attempt.
pub max_retries: u32,
/// Protocol module version requested on dispatch.
pub module_version: String,
/// Optional bearer token for daemons in local development auth mode
/// (`MAP_BEARER_TOKEN`). Wire-only; never logged or recorded.
pub bearer_token: Option<String>
}
pub fn from_env() -> Option<Self>;
pub fn for_base_url(base_url: impl Into<String>) -> Self;
#[derive(Debug, Clone, PartialEq, Eq, Serialize)]
#[serde(rename_all = "snake_case")]
pub enum SpineDispatchStatus {
/// The spine answered 2xx with a contract-shaped body.
Ok,
/// The spine answered a non-success status (a real answer, believed).
RemoteStatus,
/// The dispatch never reached a MAP answer after retries.
Transport,
/// A 2xx body broke the response contract.
InvalidResponse,
}
#[derive(Debug, Clone, PartialEq, Serialize)]
pub struct SpineDispatchRecord {
/// Protocol dispatched to (e.g. `MIND`).
pub protocol: String,
/// Operation dispatched (e.g. `store_memory`).
pub operation: String,
/// The HTTP path the envelope was projected onto.
pub endpoint: String,
/// Local correlation id (the request envelope's id).
pub correlation_id: String,
/// The daemon's `requestId`, when it returned one.
pub remote_request_id: Option<String>,
/// The W3C `traceparent` sent on the wire.
pub traceparent: String,
/// Attempts made (1 + retries).
pub attempts: u32,
/// Terminal outcome of the dispatch.
pub status: SpineDispatchStatus,
/// Upstream HTTP status, when the spine answered.
pub http_status: Option<u16>
}
#[derive(Debug, Clone)]
pub struct SpineDispatch {
/// The protocol module's response payload, passed through verbatim.
pub output: Value,
/// The exact MAP envelope message sent (`{ header, payload }`,
/// mirroring the `map.json` schema) — the auditable request record,
/// kept for evidence bundles the way ONE's client keeps
/// `request_envelope`.
pub request_envelope: Value,
/// The audit record for this dispatch (also appended to the client's
/// dispatch log).
pub record: SpineDispatchRecord
}
#[derive(Clone)]
pub struct MapSpineClient {
}
pub fn new(config: MapSpineConfig) -> Result<Self, PlaneError>;
pub fn from_env() -> Option<Self>;
pub fn is_configured() -> bool;
pub fn config(&self) -> &MapSpineConfig;
pub fn dispatch_log(&self) -> Vec<SpineDispatchRecord>;
pub async fn health_check(&self) -> bool;
#[instrument(skip(self, input))]
pub async fn invoke(
&self,
protocol: &str,
operation: &str,
input: Value,
) -> Result<SpineDispatch, PlaneError>;spine/context.rs
Read declaration text · 6 declaration entries
#[derive(Debug, Clone, PartialEq, Eq)]
pub struct RecallHit {
/// The memory's id.
pub memory_id: String,
/// The memory's content (possibly capped at [`RECALL_CONTENT_CAP`]).
pub content: String
}
#[derive(Clone)]
pub struct MapContextPlane {
}
pub fn new(client: MapSpineClient, recall_scope: impl Into<String>) -> Self;
pub fn with_recall_limit(mut self, limit: usize) -> Self;
pub fn with_marc_decomposition(mut self) -> Self;
pub fn client(&self) -> &MapSpineClient;spine/memory.rs
Read declaration text · 3 declaration entries
#[derive(Clone)]
pub struct MapMemoryPlane {
}
pub fn new(client: MapSpineClient, mind: impl Into<String>) -> Self;
pub fn client(&self) -> &MapSpineClient;spine/mod.rs
Read declaration text · 4 declaration entries
pub use client::{
MapSpineClient, MapSpineConfig, SpineDispatchRecord, SpineDispatchStatus, MAP_AUTH_TYPE_ENV,
MAP_BASE_URL_ENV,
};
pub use context::{MapContextPlane, RecallHit};
pub use memory::MapMemoryPlane;
pub use payloads::{
MarcReasoningTask, MarcTaskResult, MindMemoryMetadata, MindMemoryObject, MindMemoryQuery,
MindQueryResult, MindStorageResult, MindSymbolicFilter,
};spine/payloads.rs
Read declaration text · 9 declaration entries
#[derive(Debug, Clone, PartialEq, Serialize, Deserialize)]
#[serde(rename_all = "camelCase")]
pub struct MindMemoryObject {
/// MIND protocol version the object conforms to.
pub mind_version: String,
/// UUID identifying the memory.
pub memory_id: String,
/// Core textual content.
pub content: String,
/// Provenance chain entries (opaque to the runtime).
#[serde(default)]
pub provenance_chain: Vec<Value>,
/// Access control rules (opaque to the runtime).
#[serde(default)]
pub access_control_list: Vec<Value>,
/// Annotations (opaque to the runtime).
#[serde(default)]
pub annotations: Vec<Value>,
/// Triggers (opaque to the runtime).
#[serde(default)]
pub triggers: Vec<Value>,
/// Object metadata (timestamp, source DID, tags).
pub metadata: MindMemoryMetadata
}
#[derive(Debug, Clone, PartialEq, Serialize, Deserialize)]
#[serde(rename_all = "camelCase")]
pub struct MindMemoryMetadata {
/// RFC 3339 timestamp of the write.
pub timestamp: String,
/// DID of the agent the memory is attributed to.
pub source_agent_did: String,
/// Free-form tags.
#[serde(default)]
pub tags: Vec<String>,
/// Ontology references.
#[serde(default)]
pub ontology_references: Vec<String>
}
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
#[serde(rename_all = "camelCase")]
pub struct MindSymbolicFilter {
/// Subject pattern.
#[serde(skip_serializing_if = "Option::is_none")]
pub subject: Option<String>,
/// Predicate pattern.
#[serde(skip_serializing_if = "Option::is_none")]
pub predicate: Option<String>,
/// Object pattern.
#[serde(skip_serializing_if = "Option::is_none")]
pub object: Option<String>
}
#[derive(Debug, Clone, PartialEq, Serialize, Deserialize)]
#[serde(rename_all = "camelCase")]
pub struct MindMemoryQuery {
/// Caller-minted query id.
pub query_id: String,
/// Symbolic triple filter.
#[serde(skip_serializing_if = "Option::is_none")]
pub symbolic_filter: Option<MindSymbolicFilter>,
/// DID of the agent requesting recall (the spine tenant principal).
pub requesting_agent_did: String,
/// Result cap.
#[serde(skip_serializing_if = "Option::is_none")]
pub limit: Option<usize>
}
#[derive(Debug, Clone, PartialEq, Serialize, Deserialize)]
#[serde(rename_all = "camelCase")]
pub struct MindStorageResult {
/// The stored memory's id.
pub memory_id: String,
/// Store timestamp (provider-rendered).
pub stored_at: String,
/// Backend that stored the object (`LOCAL` | `AKASHA`).
pub backend: String,
/// Stored version.
pub version: u64
}
#[derive(Debug, Clone, PartialEq, Serialize, Deserialize)]
#[serde(rename_all = "camelCase")]
pub struct MindQueryResult {
/// Echo of the query id.
pub query_id: String,
/// The recalled memory objects.
pub results: Vec<MindMemoryObject>,
/// Provider-measured execution time.
pub execution_time_ms: u64,
/// Provider message (may be empty).
pub message: String
}
#[derive(Debug, Clone, PartialEq, Serialize)]
pub struct MarcReasoningTask {
/// Caller-minted task id.
pub task_id: String,
/// Reasoning type (`"deductive"` for the context-plane projection).
pub reasoning_type: String,
/// Reasoning mode; the spine projection is always Monolithic.
pub mode: Value,
/// Premise statements. MARC's deductive engine rejects an empty
/// premise list (`InsufficientPremises`) — callers must supply at
/// least one real premise (recalled memory contents or the task
/// text); a fabricated premise would poison the trace.
pub premises: Vec<String>,
/// The query the engine evaluates.
pub query: String,
/// Optional context string.
#[serde(skip_serializing_if = "Option::is_none")]
pub context: Option<String>,
/// Engine parameters (provenance markers ride here).
pub engine_params: Value
}
pub fn deductive(
task_id: impl Into<String>,
premises: Vec<String>,
query: impl Into<String>,
context: Option<String>,
) -> Self;
#[derive(Debug, Clone, PartialEq, Deserialize)]
pub struct MarcTaskResult {
/// Echo of the task id.
pub task_id: String,
/// The engine's result value.
pub result: Value,
/// Engine-reported confidence in `[0, 1]`.
pub confidence: f64,
/// The reasoning trace (steps, totals, timing).
pub reasoning_trace: Value,
/// Synthesis details, when the mode produced them.
#[serde(default)]
pub synthesis_details: Option<Value>,
/// Issues raised by the engine.
#[serde(default)]
pub issues: Vec<Value>
}strategy/microdag.rs
Read declaration text · 7 declaration entries
#[derive(Debug, Clone, PartialEq, Eq, Error)]
pub enum DagError {
/// Two nodes share an id.
#[error("duplicate node id {0:?}")]
DuplicateNode(String),
/// A `depends_on` edge names a node that does not exist.
#[error("node {node:?} depends on unknown node {dependency:?}")]
UnknownDependency {
/// The node carrying the edge.
node: String,
/// The missing dependency.
dependency: String,
},
/// The graph contains a dependency cycle.
#[error("dependency cycle involving {0:?}")]
Cycle(Vec<String>),
}
#[derive(Debug, Clone, PartialEq, Eq)]
pub struct MicroDagNode {
/// Unique step id.
pub id: String,
/// Ids of steps that must complete before this one starts.
pub depends_on: Vec<String>
}
#[derive(Debug, Clone, PartialEq, Eq)]
pub struct MicroDag {
}
pub fn new(nodes: Vec<MicroDagNode>) -> Result<Self, DagError>;
pub fn nodes(&self) -> &[MicroDagNode];
pub fn layers(&self) -> Result<Vec<Vec<String>>, DagError>;
pub trait MicroDagStrategy: LoopStrategy {
/// Compile a task and admitted manifest into an executable MicroDAG.
fn compile(&self, task: &str) -> Result<MicroDag, DagError>;
}strategy/mod.rs
Read declaration text · 10 declaration entries
pub use microdag::{DagError, MicroDag, MicroDagNode, MicroDagStrategy};
pub use react::ReactLoop;
#[derive(Debug)]
pub struct RunPlan {
/// The admitted harness (contract sealed, planes bound, budget
/// reserved).
pub admitted: AdmittedHarness,
/// The task to accomplish.
pub task: String
}
#[async_trait]
pub trait LoopStrategy: Send + Sync {
/// The registered strategy name (`loop.strategy` in the manifest).
fn name(&self) -> &'static str;
/// Drive one run to its terminal state.
async fn run(&self, plan: RunPlan) -> Result<RunRecord, RuntimeError>;
}
#[derive(Clone, Default)]
pub struct StrategyRegistry {
}
pub fn new() -> Self;
pub fn with_builtins() -> Self;
pub fn register(&mut self, strategy: Arc<dyn LoopStrategy>);
pub fn get(&self, name: &str) -> Option<&Arc<dyn LoopStrategy>>;
pub fn names(&self) -> Vec<&'static str>;strategy/react.rs
Read declaration text · 2 declaration entries
#[derive(Debug, Default)]
pub struct ReactLoop;
pub fn new() -> Self;trace.rs
Read declaration text · 9 declaration entries
pub const TRACEPARENT_HEADER: &str;
#[derive(Debug, Clone, Copy, PartialEq, Eq, Hash)]
pub struct TraceContext {
}
pub fn root() -> Self;
pub fn child(&self) -> Self;
pub fn trace_id_hex(&self) -> String;
pub fn span_id_hex(&self) -> String;
pub fn sampled(&self) -> bool;
pub fn traceparent(&self) -> String;
pub fn from_traceparent(value: &str) -> Result<Self, TraceContextError>;Continue
harness-apd
APD benchmark driver — binds harness-runtime (HarnessSpec v0.1) to an OpenAI-compatible inference route, local dev planes, and the MAP spine when MAP_BASE_URL is set (WS-11)
harness-sdk-forge
Forge ↔ Harness bridge — implements harness-sdk's AgentAdapter for forge-rs agents and re-exports the full forge SDK so harness apps get every Forge primitive in one import.