nomos_kernel_protocol library

Classes

Acknowledged
AdoptGeneratedModelRequest
ApplicationCustodyEstablished
ApplyPackRequest
ApplyPackResponse
ApplyWorkspaceEffectRequest
Transport names only two custody locations plus the exact source commit/path exposed by the source kernel. The receiving kernel re-hashes that proof, derives the source workspace actor, opens the sealed nominal target call and runs target law; no host operation or payload exists.
ApplyWorkspaceEffectResponse
AttestedRead
AuthenticationPostureQuery
Read-only postcondition for a bounded auth-recovery retry. The kernel checks the current local AuthProvider and signer relation; hosts and clients neither parse tokens nor infer readiness from time.
AuthenticationPostureResponse
AuthoringOptions
AuthorizationCheckRequest
AuthorizationCheckResponse
AuthorizationConditionContext
AuthorizationConsistency
AuthorizationDecisionBasis
AuthorizationExpandRequest
AuthorizationExpandResponse
AuthorizationExplanation
AuthorizationExplanation_Operation
AuthorizationObject
Zanzibar has its own explicit call algebra. These messages address the authorization graph compiled from the active typed USDA LawStage; they can constrain which custodied revision is acceptable but can never carry or replace the authorization model itself.
AuthorizationSubject
AutoSyncStarted
AutoSyncStopped
BirthCertificate
Signed authority evidence for one child birth. This is a kernel input, not tenant payload: generated clients cannot accidentally rename it, domain law cannot interpret it as business data, and the kernel converts it directly into its nominal Rust certificate before attaching it to USDA.
BirthOutcome
BirthOutcomeStatus
BornCustody
BornWorkspace
ByIdQuery
ByTypeQuery
CallRequest
CallResponse
CapacityReserveRequest
CapacityReserveResponse
CapturedClock
CheckpointAssurance
CheckpointCompression
CheckpointExportRequest
CheckpointExportResponse
CheckpointImportRequest
CheckpointImportResponse
CheckpointVerificationPolicy
CloseRealmRequest
CompactionEquivalence
ConflictSnapshot
Connected
ConnectRequest
CustodyAdmission
CustodyAdmissionSpan
CustodyAdmissionTimings
CustodyBreak
CustodyBreakDecision
CustodyBreakKind
CustodyBreakPolicy
CustodyBreakResolved
CustodyChanged
CustodyChangeKind
CustodyInlineOffers
CustodyIntentAdmission
CustodyIntentAdmitted
CustodyIntentOffer
CustodyIntentRefused
CustodyIntentSkipped
CustodyOfferBatchRequest
The offline/client custody push lane carries kernel-authored OpenUSD bytes, never a host-shaped domain object. This dedicated binary envelope replaces the former JSON/base64 /intent-offers body while preserving the same authority boundary: the receiving kernel alone admits or refuses each offer.
CustodyOfferBatchResponse
CustodyRecovery
CustodyRequest
CustodyResponse
CustodySessionAdmission
CustodySessionCandidate
A lifecycle offer may carry additional authenticated Git objects. The client first publishes that kernel-built candidate ref, then names it here so the receiving custody plane performs the existing session admission sweep.
CustodySupersession
DeadLetterDiscard
DeadLetterEntry
DeadLetterList
DeadLetterRequest
Refused local work is host custody, not tenant domain state. Keep its three operator moves in one typed subsystem command rather than resurrecting the Runtime v1 operation enum and generic argument/result bags.
DeadLetterResponse
DeadLetterRetry
DeleteRefRequest
DiagnosticAttribute
DirectiveCall
DiscardDeadLetterRequest
DomainPrepared
EncodeRefusalVerdictRequest
EncodeRefusalVerdictResponse
EstablishApplicationCustodyRequest
Generated-application first custody is a framework lifecycle, not a generic command object. The application compiler supplies exact canonical calls; the runtime coordinates parent admission and child replay without exposing device keys, BigInt values or a JSON result object to the Dart host.
Failure
FoldFrontierAggregate
FoldFrontierFingerprint
FoldFrontierSnapshot
FrontierHlc
A prior-verification receipt is a typed cache of a kernel verdict. It is not authority by itself: only the separately supplied CheckpointVerificationPolicy decides whether an importer may accept it without recomputing the prefix. Unknown callers therefore verify by default.
FrontierTransitionDispositionMapEntry
FrontierTransitionDispositions
FrontierTransitionRequest
One real staged-law transition at the authenticated current frontier. This is deliberately a first-class protobuf contract rather than a NamedQuery/NomosStruct: field drift must fail every host build. HISTORY_PREFLIGHT remains an explicit counterfactual diagnostic and cannot authorize a lifecycle transition.
FrontierTransitionResponse
FrontierTransitionViolation
HistoricQueryRequest
Read one authenticated historic frontier without moving the live session. The runtime owns custody placement and temporary projection residency; the query itself is still the generated kernel contract and its domain-shaped result is still canonical OpenUSD.
HistorySummaryRequest
HistorySummaryResponse
HttpsOutboundRoute
InitializeWorkspaceRequest
The only root-genesis door. A host may supply an opaque lifecycle-controller package and captured execution inputs, but it cannot name a domain, directive, payload field or resulting law identity. The kernel validates the USDZ closure, derives its content identity and constructs the one legal bootstrap/installDomain call as a private nominal value.
InitializeWorkspaceResponse
InjectedKey
InspectChangeRequest
InspectChangeResponse
InspectRefusalVerdictRequest
InspectRefusalVerdictResponse
IntentRecord
IntentsAboveRequest
IntentsAboveResponse
IntentTransportRequirement
A sealed change is self-contained and may take the low-latency offer lane. A commit-tree requirement means the effect also introduced canonical custody (currently a typed USDA law closure), so sync must carry the authenticated Git tree rather than stripping it to change.usda. The kernel derives this from the commit-tree delta; hosts never infer it from domain/directive labels.
KernelCallRequest
KernelLawCapability
KernelLawHydrationStep
KernelProgressObserved
KernelProgressOperation
KernelProgressPhase
KernelProgressSnapshot
Ephemeral, authority-free progress from one long-running kernel operation.
KernelProgressUnit
KernelRefusal
KernelRefusalCode
This list mirrors nomos_executor::Reason. The Rust conversion is an exhaustive match, so adding a new gate refusal cannot silently degrade to prose.
KernelSpan
KernelSpanMetric
KernelSpans
LawChanged
LawClosureInfoRequest
LawClosureInfoResponse
LifecycleInstallIdentity
LifecycleInstallPhase
LinkChanged
LinkStatus
ListDeadLettersRequest
ListRefsRequest
ListRefsResponse
ListWorkspacesRequest
LocalCustodySnapshot
Opaque local custody cache. Git tree and checkpoint bytes remain kernel-owned; the host records only enough typed metadata to offer them back on next open. Field numbers deliberately match the historical runtime-v1 message so stored PB3 snapshots remain wire-compatible across this ownership correction.
LocalWorkRejected
LocalWorkRejectionSource
MetaFile
ModelDifference
ModelDifferenceKind
ModelLifecycleIntent
ModelLifecycleOperation
Exact framework lifecycle authoring. The candidate itself remains the opaque, content-addressed law_usdz package below; the kernel derives its identity and dependency closure after opening it. This intent exists so an installed controller can judge its successor using the controller's own nominal field identities. A client must never manufacture candidate-schema USDA for that transition.
ModelLifecycleRequest
Generated applications expose model evolution as one framework-owned lifecycle. The orchestration runtime may inspect its own kernel-authored preflight and author the fixed Nomos lifecycle directives, but the host boundary is exhaustive Protobuf: no verdict object, report map or stage string escapes into Dart.
ModelLifecycleResponse
ModelLifecycleStage
ModelReview
NamedQuery
Framework/introspection reads have fixed names in generated clients. arguments carries only their operation-specific data while migration replaces the remaining legacy query arms.
NominalCallIdentity
NomosKernelServiceApi
The host and kernel share one unary protocol. WASI transports the encoded messages through linear memory; native/cloud transports may expose the same messages through gRPC or Connect. This schema is an ABI only. Signed law and custody remain canonical typed USDA.
NomosList
NomosRef
NomosRuntimeServiceApi
The application-runtime boundary is deliberately smaller than the public Nomos client API. Generated clients lower domain work to CallRequest. This protocol owns only realm lifecycle, transport scheduling and subscriptions. Tenant values remain canonical OpenUSD and never become an open protobuf map.
NomosStruct
NomosValue
Nomos' dynamic tenant value is deliberately not google.protobuf.Value: that standard helper stores every number as double and cannot represent the exact i64/u64 values used by HLCs, replica ids, counters and custody metadata.
Null
OfferAdmitted
The kernel owns the shape of an admitted offer. Keep every framework consequence explicit so generated Rust, TypeScript and Dart clients fail to compile when this contract changes. Tenant business values remain canonical USDA; they never acquire a parallel protobuf domain model.
OfferAggregateRef
OfferBlockedOnDependency
OfferDeadLettered
OfferPreparationChallenge
OfferPrepared
A target holon's non-effectful authored result. The target kernel alone runs its installed law and captures its exact inputs; a sovereign client kernel may then add the device signature without cloning the target's custody. Admission still re-runs the ordinary offer gate against the target's current head.
OfferQuarantined
OfferRefused
OfferRequest
OfferResponse
An offer is adjudicated data, not a generic RPC success followed by a stringly outcome field. Every kernel-owned admission state is exhaustive in generated clients.
OpenRequest
OpenResponse
Application operations have distinct envelopes even where their tenant-defined body remains a NomosValue. This keeps operation identity in the generated type system instead of rebuilding a stringly mode discriminator above a generic success object.
OsgiAttribute
OsgiCapability
OsgiDirective
OsgiRequirement
OsgiResourceResponse
OutboundOffer
A kernel-authored outbound offer. The host switches exhaustively on route solely to transport the opaque sealed bytes; every semantic field remains inside sealed_offer. custody_path and delivery_ref are opaque transport cursors chosen by the kernel, never reconstructed by a host.
OutboxRequest
OutboxResponse
OwnedDeviceRequestQuery
Fixed framework crypto has an exact generated ABI. The signed request and encrypted custody values remain canonical USDA documents; Protobuf identifies the operation and frames those semantic values without rebuilding their schema as a generic struct.
OwnedDeviceRequestResponse
OwnedPrepareApprovalQuery
OwnedPrepareApprovalResponse
PackDeltaRequest
PackDeltaResponse
PageQuery
PendingConflictsQuery
The maintained conflict index is framework-owned, while each competing value remains typed by the application's composed law. Both operations therefore have exact request fields and return canonical USDA.
PendingConflictSummaryQuery
PrepareDomainRequest
PrepareRemoteOfferRequest
The first half of remote authoring proves possession of an enrolled device key BEFORE the target evaluates a privileged plan. The client signs the exact serialized OfferRequest bytes; the target kernel verifies those same bytes against its own signer relation, then prepares the USDA transition. The second, existing SignPreparedOffer proof binds the resulting transition.
PrepareRemoteOfferResponse
ProveCompactionEquivalenceRequest
ProveCompactionEquivalenceResponse
ProviderTokenVerificationStatus
QueryAuthority
Claims and opaque proofs supplied to a read. The kernel alone resolves them against active law; this message cannot assert a verified principal.
QueryOperation
QueryRequest
QueryResponse
QueryResultFormat
ReadBlobRequest
ReadBlobResponse
RealmClosed
ReferenceVersionCheck
ReferenceVersionsQuery
RefRecord
RefusalVerdict
RejectedLocalIntent
RelationshipTupleAddress
RelationshipTupleEvidence
RemoteOfferAdmission
Container-to-control-plane handoff for a remote sealed offer. This is an internal host obligation, not tenant data: the container has made custody durable and the control plane must persist any kernel-produced child packs before returning the generated OfferResponse to the caller.
RepoStatsRequest
RepoStatsResponse
ResidentComponent
ResidentComponentKind
ResidentFootprint
ResidentFootprintRequest
OPERATOR TELEMETRY, never law. What each resident workspace costs this kernel in memory, so the host can see WHY a container is full instead of guessing from a process-wide RSS number. Cheap by construction: the read model's size is page_count × page_size, two SQLite pragmas, so this is safe to poll. Reports only what is ALREADY resident — it never mounts, folds, or touches custody. deep walks each resident's documents, indexes and fold images by reference (no clone, no serialize). That is the only way to see the ~70% of a workspace that is NOT SQLite pages, but it costs real time, so it is opt-in and the response reports what the measurement itself cost.
ResidentFootprintResponse
ResolveCustodyBreakRequest
ResolveRefRequest
ResolveRefResponse
ResolveRefsQuery
ResolveStatePositionRequest
Ask the kernel whether one replica-local custody hint resolves to the same canonical USDA state on this authenticated main. Hosts may use the answer for placement only; offer admission reopens and rederives the foreign read independently.
ResolveStatePositionResponse
RestoreGeneratedModelRequest
RestoreMainRequest
Establish an absent live frontier from already-imported custody. The kernel first exposes the candidate only under an internal quarantine ref, verifies its complete semantic chain, and promotes it atomically. A host cannot use this operation to advance or replace an existing main.
RestoreMainResponse
RestoreMainSpans
One typed breakdown of custody admission. Zero means that phase was not needed (for example, an already-mounted frontier only performs the live-ref lookup).
RetryDeadLetterRequest
RowsQuery
RuntimeBlocked
A host may need custody to become resident before the exact same generated request can enter the kernel. Make that scheduling fact exhaustive and typed; it is neither tenant data nor an unstructured diagnostic attribute.
RuntimeEvent
RuntimeFailure
RuntimeReady
RuntimeRequest
RuntimeResponse
RuntimeSpan
RuntimeTransportFailure
SetTestRootRequest
SiblingResidenciesRequired
SiblingResidencyRequired
SignalChanged
SignBirthCertificateRequest
Pure local signing for the same typed certificate that OfferRequest carries. The client-held secret enters one kernel call and is never retained; the response is the generated certificate message, not a second document representation of it. A non-empty input signature is refused so callers cannot confuse signing a body with accepting a previously signed certificate. The certificate parent_key authorizes the signer of the next link down the chain, so it need not match signer_secret. When omitted, the kernel derives it from signer_secret for the self-signed/keyless lane.
SignBirthCertificateResponse
SignOfferPreparationRequest
SignOfferPreparationResponse
SignPreparedOfferRequest
Pure client-side signing of a target-kernel-prepared USDA transition. The secret enters only the local kernel invocation; neither the host nor the target workspace receives it.
SignPreparedOfferResponse
SnapshotWorkspaceRequest
SpatialQuery
StageGeneratedModelRequest
StartAutoSyncRequest
StopAutoSyncRequest
StoredCheckpointManifest
Typed manifest for a checkpoint's Git meta-commit. This is cache/transport structure, not application state; semantic aggregate content remains canonical USDA.
SyncCompleted
SyncPhaseTimings
SyncRequest
SyncResponse
SyncWorkspaceRequest
SyncWorkspaceResponse
TallyQuery
TestRequest
Harness-only controls. Production kernels compile these operations out and fail closed if asked.
TestResponse
TraceContext
TransferKind
TransferProgress
UnwatchRequest
VerifiedFrontierReceipt
VerifyChainDiagnostics
VerifyChainEngineTiming
VerifyChainLawHydrationTiming
VerifyChainStepPhases
Kernel-owned phase timings for one replayed intent. These remain typed all the way to the framework observability edge so diagnostics cannot become another semantic JSON carrier.
VerifyChainStepSpan
VerifyChainWalk
WatchChanged
WatchKind
WatchRequest
WatchStarted
WatchStopped
WorkspaceList
WorkspaceOutboundRoute
WorkspaceResidency
WorkspaceResidencyRequired
WorkspaceResidencyRequirement
A custody dependency the kernel decoded from a sealed intent's typed captured-read envelope. This is a compute-readiness hint, never authority: the receiving kernel still reopens the named workspace at source_head and proves the carried result before admission.
WorkspaceSnapshot
WorkspaceSummary
WorkspaceSyncPosture
WorkspaceTarget
WriteMetaCommitRequest
WriteMetaCommitResponse
WriteRefRequest

Extensions

GeneratedMessageGenericExtensions on T
Extensions on GeneratedMessages.