Public declaration syntax from forge-rs/harness-spec/src/manifest.rs Original source SHA-256: bbf9924ccc3f3d1cb52bb4dbeb076249b8124cf592bb644ded2f7b0414f9d068 Function bodies and constant values are omitted. This is not the complete implementation. Source line 29 #[derive(Debug, Clone, PartialEq, Serialize, Deserialize)] #[serde(deny_unknown_fields)] pub struct Manifest { /// Spec revision; must be `"0.1"` for this revision (§5.1). pub spec_version: String, /// Harness identity block (§5.3). pub harness: HarnessTable, /// Agent identity and lineage block (§5.3). pub identity: IdentityTable, /// Capability grants (§5.4). pub capabilities: CapabilitiesTable, /// Policy plane binding (§5.5). pub policy: PolicyTable, /// Context plane binding (§5.6). pub context: ContextTable, /// Optional perception ingress binding (§5.14). #[serde(default, skip_serializing_if = "Option::is_none")] pub perception: Option, /// Memory plane binding (§5.7). pub memory: MemoryTable, /// Inference plane binding (§5.8). pub inference: InferenceTable, /// Tool policy (§5.9). pub tools: ToolsTable, /// Verification gates (§5.10). pub verification: VerificationTable, /// Economics plane binding (§5.11). pub economics: EconomicsTable, /// Telemetry plane binding (§5.12). pub telemetry: TelemetryTable, /// Execution substrate class (§5.13). pub substrate: SubstrateTable, /// Loop strategy configuration (§5.13). pub r#loop: LoopTable, /// Child-harness spawn policy (§5.13). pub spawn: SpawnTable, /// Optional voice surface binding (§5.15). #[serde(default, skip_serializing_if = "Option::is_none")] pub voice: Option } Source line 74 pub fn from_toml(source: &str) -> Result; Source line 81 pub fn validate(&self) -> Result; Source line 87 pub fn validate_with( &self, context: &ValidationContext, ) -> Result; Source line 98 #[derive(Debug, Clone, PartialEq, Serialize, Deserialize)] #[serde(deny_unknown_fields)] pub struct HarnessTable { /// Stable harness URI (e.g. `harness://l1fe/one/brownfield-coder`). pub id: String, /// Human-readable name. pub name: String, /// Harness version (SemVer). pub version: String, /// Human-readable description. pub description: String, /// Accountable owner: an OAS DID of kind `hmr`, or an entity whose /// lineage terminates at one (lineage termination is verified at bind /// time, not by this crate). pub owner: String } Source line 116 #[derive(Debug, Clone, PartialEq, Serialize, Deserialize)] #[serde(deny_unknown_fields)] pub struct IdentityTable { /// The harness's OAS DID. pub did: String, /// Lineage proof reference; must resolve to a chain terminating at /// `[harness].owner`'s human root (resolution is a bind-time concern). pub lineage_proof: String, /// Maximum child derivation depth; must not exceed the runtime's /// configured maximum (ANVIL default 16). pub max_child_depth: u32 } Source line 132 #[derive(Debug, Clone, PartialEq, Serialize, Deserialize)] #[serde(deny_unknown_fields)] pub struct CapabilitiesTable { /// ACT grant URIs (e.g. `arsenal://act/one-coder/repo-rw`). Must be /// non-empty for any harness with a non-empty tool allowlist. pub act_refs: Vec } Source line 141 #[derive(Debug, Clone, PartialEq, Serialize, Deserialize)] #[serde(deny_unknown_fields)] pub struct PolicyTable { /// Policy engine provider. pub engine: PolicyEngine, /// Policy document references (e.g. `lanes://policy/source-code-private`). pub policy_refs: Vec, /// Allowed Cambium data classes; a subset of the frozen vocabulary. pub data_classes_allowed: Vec } Source line 153 #[derive(Debug, Clone, PartialEq, Serialize, Deserialize)] #[serde(deny_unknown_fields)] pub struct ContextTable { /// Context provider (`lanes` or `static`). pub provider: ContextProvider, /// Environment variable holding the provider base URL. Required when /// `provider = "lanes"`; meaningless for `static`. #[serde(default, skip_serializing_if = "Option::is_none")] pub base_url_env: Option, /// Tenant scope for context requests. pub scope: ContextScope, /// Hard cap per packed frame, in tokens. Enforced at pack time. pub frame_budget_tokens: u64, /// Answer-vs-model-call routing decision owner. pub route_decision: RouteDecision, /// Cache classes the context plane may use. #[serde(default)] pub cache_classes: Vec } Source line 174 #[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)] #[serde(rename_all = "camelCase", deny_unknown_fields)] pub struct ContextScope { /// Platform identifier. pub platform_id: String, /// Organization identifier. pub organization_id: String, /// Project identifier. pub project_id: String } Source line 186 #[derive(Debug, Clone, PartialEq, Serialize, Deserialize)] #[serde(deny_unknown_fields)] pub struct PerceptionTable { /// Perception provider (`nous` in v0.1). pub provider: PerceptionProvider, /// Environment variable holding the provider base URL. pub base_url_env: String, /// Ingest modalities; a non-empty subset of the Nous ingest surfaces. pub modalities: Vec, /// Enrichment mode; `deterministic` only in v0.1 (`ml` is reserved for /// Ring 2 and rejected). pub enrichment: Enrichment, /// Fail-closed signed-IR requirement; must be `true` in v0.1. pub require_signed_ir: bool, /// Per-artifact media cap in bytes; finite, and never looser than the /// provider's own ingest cap (Nous ships 64 MiB). pub max_media_bytes: u64, /// Route derived IR/embeddings to the `[memory]` mind via the /// provider's MIND emission path. pub emit_to_memory: bool, /// Source-media retention discipline. pub retention: MediaRetention } Source line 211 #[derive(Debug, Clone, PartialEq, Serialize, Deserialize)] #[serde(deny_unknown_fields)] pub struct MemoryTable { /// Memory provider (e.g. `akasha`). pub provider: String, /// Mind URI (e.g. `akasha://minds/one-coder`). pub mind: String, /// Active memory types; a subset of the Akasha vocabulary. pub types: Vec, /// Write policy governing the memory plane. pub write_policy: WritePolicy } Source line 225 #[derive(Debug, Clone, PartialEq, Serialize, Deserialize)] #[serde(deny_unknown_fields)] pub struct InferenceTable { /// Inference provider (e.g. `foundry`). pub provider: String, /// Environment variable holding the provider base URL. pub base_url_env: String, /// Route policy: `catalog:live` (recommended) or a `model:` pin /// that fails closed when the route is no longer offered. pub route_policy: String, /// IAM permission required to invoke inference (frozen wire vocabulary). pub required_permission: String, /// Entitlement consumed by inference calls. pub entitlement: String, /// USD budget cap; present and finite. pub budget_usd: f64, /// Token budget cap; present and finite. pub budget_tokens: u64, /// Behavior on budget exhaustion (default `halt_and_settle`). #[serde(default)] pub on_budget_exhausted: OnBudgetExhausted } Source line 249 #[derive(Debug, Clone, PartialEq, Serialize, Deserialize)] #[serde(deny_unknown_fields)] pub struct ToolsTable { /// Must be present and `true` in v0.1: there is no allow-by-default /// harness. pub deny_default: bool, /// Allowlisted `/` tool identifiers, resolved against /// the host's interface/tool registry at validation. #[serde(default)] pub allow: Vec, /// Tools whose every invocation requires a human (or designated /// approver-harness) decision through the host's approval surface. #[serde(default)] pub approval_required: Vec } Source line 266 #[derive(Debug, Clone, PartialEq, Serialize, Deserialize)] #[serde(deny_unknown_fields)] pub struct VerificationTable { /// Binds the L1F-8 honesty policy: evidence refs pass through verbatim /// or are absent — never synthesized. pub evidence_required: bool, /// Verification gates; must be non-empty for any harness that can /// mutate state outside its own memory plane. pub gates: Vec } Source line 278 #[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)] #[serde(deny_unknown_fields)] pub struct Gate { /// Gate kind (`command` in v0.1). pub kind: GateKind, /// The command to execute; exit code plus captured output ref are the /// minimum machine-checkable evidence. pub run: String } Source line 289 #[derive(Debug, Clone, PartialEq, Serialize, Deserialize)] #[serde(deny_unknown_fields)] pub struct EconomicsTable { /// Settlement provider (`garden` in v0.1). pub settlement: Settlement, /// Meter map; every value must satisfy the Garden v4 two-segment /// meter-key rule (`.`). pub meters: BTreeMap, /// Idempotency key discipline for replay-safe usage events. pub idempotency: String } Source line 302 #[derive(Debug, Clone, PartialEq, Serialize, Deserialize)] #[serde(deny_unknown_fields)] pub struct TelemetryTable { /// Telemetry provider (e.g. `cambium`). pub provider: String, /// Stream binding; the stream id is derived server-side. pub stream: TelemetryStream, /// Event type prefix; must conform to the Cambium v1 grammar /// (`ai.cambium..`) and must not request a /// privileged prefix. pub event_prefix: String, /// Event subjects emitted under the prefix (`.`). pub emit: Vec } Source line 318 #[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)] #[serde(deny_unknown_fields)] pub struct TelemetryStream { /// Stream kind (`run` in v0.1). pub kind: StreamKind } Source line 329 #[derive(Debug, Clone, PartialEq, Serialize, Deserialize)] #[serde(deny_unknown_fields)] pub struct SubstrateTable { /// Substrate class. pub class: SubstrateClass, /// Isolation class. pub isolation: Isolation } Source line 339 #[derive(Debug, Clone, PartialEq, Serialize, Deserialize)] #[serde(deny_unknown_fields)] pub struct LoopTable { /// A registered loop strategy (`react`, `microdag`, `plan_execute`, or /// one registered with the validation context). Strategies receive /// plane handles already bound and narrowed; they cannot widen /// authority. pub strategy: String, /// Maximum loop steps. pub max_steps: u64, /// Human Interjection Protocol toggle. pub interjection: Interjection } Source line 354 #[derive(Debug, Clone, PartialEq, Serialize, Deserialize)] #[serde(deny_unknown_fields)] pub struct SpawnTable { /// Whether this harness may spawn children. pub allowed: bool, /// Narrowing mode; `strict` in v0.1 (child authority ⊆ parent). pub narrowing: Narrowing, /// Maximum fraction of the parent's remaining budget any child may /// receive; enforced by the economics plane, not by strategy code. pub child_budget_fraction_max: f64, /// Planes whose bindings children inherit. #[serde(default)] pub inherit: Vec } Source line 374 #[derive(Debug, Clone, PartialEq, Serialize, Deserialize)] #[serde(deny_unknown_fields)] pub struct VoiceTable { /// ASR route class, resolved via the `[inference]` live catalog. pub asr_route_class: AsrRouteClass, /// TTS route class, resolved via the `[inference]` live catalog. pub tts_route_class: TtsRouteClass, /// Acknowledgment track policy. pub ack_policy: AckPolicy, /// Barge-in behavior; `interrupt` is the only v0.1 value. pub barge_in: BargeIn, /// Spoken-register paraphrase constraint; must be `true` in v0.1. pub constrained_verbalization: bool, /// Fraction of TTS utterances round-tripped and semantically diffed; /// must lie in `[0, 1]`. pub faithfulness_sampling: f64, /// Maximum utterance length in seconds; finite. pub max_utterance_seconds: u64, /// Voice meter map; values follow the Garden two-segment rule (§5.11). pub meters: BTreeMap }