nomos_kernel_protocol library

Classes

Acknowledged
ActiveKernelWork
A call which is executing at the instant /health is observed. This is useful for a genuinely long replay or index rebuild; most calls complete between scrapes and are represented by the cumulative counters above.
AdoptApplicationModelRequest
AdoptWorkspacePlacement
AggregateCensusRequest
OPERATOR TELEMETRY, never law. How much state a workspace holds, and of what.
AggregateCensusResponse
AggregateTypeCount
ApplicationCompatibilityGuidance
The strongest next-step statement the local peer can prove. Fleet policy (including whether a client patch or workspace rollout is preferred) belongs to the tenant control plane and is not guessed from structural differences.
ApplicationCompatibilityPosture
Structural posture of this generated client against the law installed at the workspace's current local frontier. Partial is a useful operating mode: available members remain callable while only the exact unsafe members are refused before dispatch.
ApplicationDomainRequirement
Immutable requirements supplied while a generated application facade is composed. The shared Peer Office prepares them in declaration order.
ApplicationModelAdopted
ApplicationPrepared
ApplicationResultDelta
The rows of one declared query that changed between two kernel-issued read positions.
ApplyPackRequest
ApplyPackResponse
ArtifactsLatencyBucket
Cumulative wall-time histogram bucket, Prometheus model, fixed bounds.
ArtifactsRequestCounter
Cumulative counters for one (operation, outcome) pair of provider Git HTTP requests. operation: info-refs-upload | info-refs-receive | upload-pack | receive-pack | other outcome: 2xx | 3xx | 4xx | 5xx | timeout | transport Wall time runs until the response body is fully read or the request fails, so a slow pack download counts in full, not just its headers.
ArtifactsTransportSnapshot
AttachLocalFrontierRequest
AttachLocalFrontierResponse
AttestedRead
AuditCustodyRequest
One bounded slice of an OPT-IN audit: the canonical walk of the history under the workspace's main (architecture/lazy_history.md). Nothing schedules it. Each call does at most about budget_micros of work (one replay step always completes) and resumes where the last stopped. The walk needs the whole history present; a shallow custody must be deepened first.
AuditCustodyResponse
AuthenticationPostureQuery
Read-only postcondition for a bounded auth-recovery retry. The kernel checks the current local AuthProvider and signer relation; hosts and clients neither parse tokens nor infer readiness from time.
AuthenticationPostureResponse
AuthenticationReadiness
AuthenticationReadinessCriterion
AuthenticationReadinessOutcome
AuthoringOptions
AuthoringPreflightCause
AuthoringPreflightRequest
AuthoringPreflightResult
AuthorizationCheckRequest
AuthorizationCheckResponse
AuthorizationConditionContext
AuthorizationConsistency
AuthorizationDecisionBasis
AuthorizationExpandRequest
AuthorizationExpandResponse
AuthorizationExplanation
AuthorizationExplanation_Operation
AuthorizationObject
Zanzibar has its own explicit call algebra. These messages address the authorization graph compiled from the active typed USDA LawStage; they can constrain which custodied revision is acceptable but can never carry or replace the authorization model itself.
AuthorizationSubject
AwaitAuthenticationRequest
A desired kernel postcondition. Peer Office owns repeated local observations, deadline and backoff; Replica Follow independently owns any remote convergence which may make a later observation ready.
BindSessionRequest
Bind one ephemeral application interaction to a workspace identity. This performs no discovery, network request, Git mount, SQLite maintenance or replica-follow work. Placement is deliberately absent: each operation is routed by the Peer Office from the workspace's placement policy.
BirthCertificate
Signed authority evidence for one child birth. This is a kernel input, not tenant payload: generated clients cannot accidentally rename it, domain law cannot interpret it as business data, and the kernel converts it directly into its nominal Rust certificate before attaching it to USDA.
BirthEvidenceReadiness
BirthEvidenceStatus
BirthOutcome
BirthOutcomeStatus
BornCustody
BornCustodyRef
The custodian names the exact non-main frontiers to publish before birth is discoverable. Packs remain opaque physical custody, independently of their policy semantics.
BornWorkspace
ByIdQuery
ByTypeQuery
CallRequest
CallResponse
CapacityReserveRequest
CapacityReserveResponse
CapturedClock
CarriedWorkspaceOffer
A causal offer carried from another workspace. The peer transports these fields inside OfferRequest; the target kernel re-hashes the source proof, derives the source actor, and submits the sealed call through its one offer door. This is evidence for an offer, never a second effectful operation.
CheckInterfaceCompatibilityRequest
The Compatibility Desk transports one compiler-authored USDA matrix to the kernel. It does not duplicate the law schema in Protobuf and never parses or authors USDA itself.
CheckKernelContractsRequest
THE COARSE AXIS OF THE SAME JUDGEMENT: OSGi Contract Namespace requirements.
CheckpointAssurance
CheckpointCompression
CheckpointExportRequest
CheckpointExportResponse
CheckpointImportRequest
CheckpointImportResponse
CheckpointVerificationPolicy
CheckReferenceVersionsRequest
THE OFFICE STATES A REFERENCE'S VERSION STATUS; a client does not infer it.
ChildWorkspace
ChildWorkspaceLifecycleStatus
ChildWorkspaceList
ChildWorkspaceQuery
Structural lineage is framework custody, not an application-shaped row set. Give every host one exact generated result rather than teaching each runtime to parse NomosBirthRecord USDA independently.
ChildWorkspaceQueryRecord
ChildWorkspaceQueryResponse
ChildWorkspaceStatus
CloseRealmRequest
Transitional Protobuf close for string-frame shells. Component-native shells use peer-office.peer.close() directly. This duplicate disappears once every shell owns the WIT resource instead of simulating it through an invocation.
CompactionEquivalence
ConfigureProviderOriginsRequest
The host's configured discovery providers, by origin (scheme://host:port). Once configured, the Peer Office talks to these origins only: a retained or discovered placement naming any other origin is ignored on every network path, and the workspace is re-discovered through a configured provider.
ConflictSnapshot
ConsoleEnrolmentRoute
Where an enrolled principal's device key is enrolled (D22/D23): the application's console enroller, the console tenant and the enrolled provider scope declared in law. Application configuration, never law or authority: the kernel judges the resulting enrollDevice like any other intent.
ContinueCorrespondenceRequest
ContinueLocalReadRequest
A read has yielded while its local derived index catches up. The Peer Office retains the request and chooses the next quantum; shells only wait for this delay and return the opaque continuation. No index or retry policy lives there.
ConvergeReceivingGroupRequest
The convergence tail, run as correspondence work after the gate returned: posture, framework device recovery when the kernel says this key is not a seated signer, authentication readiness with birth evidence, then optional full verification. It never fails the gate. The desk hands this paper to the shell's background lane; shells only perform its typed physical effects.
CorrespondenceHold
One physical Peer Runtime host as the provider adapter sees it. One outbound letter — or a whole correspondent, when the route itself is down — that this host is holding back rather than delivering, with the last reason it could not settle.
CorrespondencePending
CorrespondenceRecovered
CorrespondenceRetryReason
Why a letter stayed in its source outbox. reason is a stable machine code: the failure code the target or transport returned, or one of nomos.correspondence.*. detail is human text, truncated, never payload bytes.
CredentialRefreshRequested
A background physical effect, equivalent to the foreground pending paper. The shell completes it with ContinueCorrespondenceRequest; it does not inspect a sync failure or choose a recovery procedure itself.
CredentialsRefreshed
CredentialUse
Ephemeral capability selection recorded on an application binding. Secret bytes live in the platform-shell WIT vault, not in workspace custody and not in the generated application protocol.
CustodianWarming
A typed "custodian warming up" posture for one workspace, carried from the workspace-opening answer (or the edge relay's opening reply) through the follow round to observers.
CustodyAdmission
CustodyAdmissionSpan
CustodyAdmissionTimings
CustodyAdvancedRequest
An exact custody frontier advanced through a write entrance which is not itself a RuntimeRequest (currently the HTTP custody-offer correspondence lane). This is only a demand signal for disposable acceleration: it grants no authority, changes no application state, and carries no host verdict.
CustodyBreak
CustodyBreakKind
CustodyBreakPolicy
Recovery preserves refused work and makes custody discontinuities explicit. It never rewrites business history silently.
CustodyCertificate
An admission-checkpoint signer's statement that head is the workspace's admitted custody.
CustodyChanged
CustodyChangeKind
CustodyDisagreement
CustodyInlineOffers
CustodyIntentAdmission
CustodyIntentAdmitted
CustodyIntentBlocked
CustodyIntentDeadLettered
CustodyIntentOffer
CustodyIntentQuarantined
CustodyIntentRefused
CustodyIntentSkipped
CustodyOfferAdmissionReceipt
CustodyOfferBatchRequest
CustodyOfferBatchResponse
HTTP custody admission still uses the same desk papers but has its own request identity and media type. It remains here only until the front-door envelope itself is split; the admission records live at correspondence.
CustodyOfferFailure
CustodyOfferReceipt
The interested peer retains the remote examiner's exact saga outcome without carrying the returned Git pack through the application boundary. Pack bytes are consumed mechanically by the peer office before this receipt is exposed.
CustodyOpening
The custody desk opens and inventories persistent Git custody. It has no application-session command: interaction binding lives in interaction_desk, while replica acquisition belongs exclusively to the background follow. A workspace custody open in progress: the one progress fact shared by host health, the shell's local-custody receipt and the office's answer to a paper that must wait for it. The workspace is named because an operator and a waiting peer must see which open it is.
CustodyPlacementExpectation
CustodyPlacementPolicy
CustodyPlacementRule
CustodyRemote
CustodyRequest
CustodyResponse
CustodyRetentionIntent
Peer-relative durable Git-custody intent, independent of whether the kernel keeps the workspace open in memory.
CustodySessionAdmission
CustodySessionCandidate
CustodySupersession
DeadLetterDiscard
DeadLetterEntry
DeadLetterList
DeadLetterRequest
DeadLetterResponse
DeadLetterRetry
DeclaredAuthenticationProvider
One law member (a command or read) and the provider it declares (authenticatesWith).
DeclaredAuthenticationProviderKind
DeclaredLawMemberKind
DeleteRefRequest
DeliverHttpObligationRequest
Execute one exact HTTPS obligation selected from the source kernel's outbox. This command exists separately from workspace delivery because an external provider response is transport acknowledgement, not Nomos admission.
DeliverWorkspaceEffectsRequest
DeriveSigningPublicKey
DetachedSignedChange
A prepared change returned with detached Ed25519 signatures from one signer key. The kernel decodes the change, re-derives the offer-token signing input at the target's CURRENT head and verifies it through the one JWT verifier, attaches the author attestation, and admits the result through the ordinary sealed-change door: the same admit, the same signer rule, the same checks as a change a kernel signed.
DetachedSigningInputs
The two statements a detached author signs, derived by the target kernel for one prepared intent and one signer key. author is the kernel's author_signed_bytes (domain tag, genesis binding, authored core); offer_token is the ASCII JWS signing input (base64url header "." base64url claims) of the D17 offer token nomos-offer+jwt { iss: binding, sub: key:<sha256(public_key)>, base: prepared_at_head, intents: intent_id }.
DeviceRecoveryAdmission
The exact, already signed request. Retransmission after a lost receipt must not create another authored change. Preparation itself has no admission.
DeviceRecoveryAdmissionStage
DeviceRecoveryRecord
PRIVATE device custody, never workspace history, diagnostics or telemetry. Persist before sending an admission or switching the active capability. A missing record is distinct from an unreadable record (a physical failure).
DeviceSignerStatus
A device credential is not the account. In particular, a revoked credential requires replacement under the declared recovery policy, never re-enrolment of the same key. UNSPECIFIED is an older kernel, not proof of absence.
DiagnosticAttribute
DirectiveAuthoringRequirementsQuery
Bounded metadata from the authenticated current law. The runtime combines this with exact Zanzibar checks; it never downloads or interprets law text.
DirectiveAuthoringRequirementsResponse
DirectiveCall
DiscardDeadLetterRequest
DiscoveredWorkspacePlacement
An availability description returned by a workspace discovery provider.
DiscoverWorkspacePlacement
Background inventory paper. Directory observations are routing hints, never admission authority; a subsequent Replica Follow retains the verified ref.
DomainPrepared
DomainRefusal
Ephemeral nominal value checked against the deciding law's invariant contract. No refusal event, outbox entry or durable record is required.
DropLocalCopyRequest
Authorize dropping exactly this local head and refetching the workspace from its current provider. Only this workspace's local custody and its projections, caches and indexes are replaced; device keys, credentials and other workspaces are not touched. The previous local head is preserved under a custody-preserved ref.
EffectExecutionCardinality
EffectExecutionPlacement
EncodeRefusalVerdictRequest
EncodeRefusalVerdictResponse
EncryptionIdentityRequest
EncryptionIdentityResponse
EnsureOwnedIdentityRequest
EnsureParentSignerEnrollmentRequest
EnsureParentSignerEnrollmentResult
EstimateWorkspaceTransferRequest
ExportLawProductsRequest
The products of every law closure selected at the workspace's main (derived from its Git custody).
ExportLawProductsResponse
ExportLiveOffersRequest
Failure
FetchWorkspaceRequest
Fetch this workspace now: the explicit form of what a read of a workspace this peer does not hold reaches (placement discovery, then the Replica Follow its placement retains, which mounts the provider's head alone). Nothing is read, bound or opened; the answer returns as soon as the follow exists, and the follow fetches on its own.
FoldFrontierAggregate
FoldFrontierFingerprint
FoldFrontierSnapshot
FollowObservation
FollowObservationPhase
FollowsSummary
Application-wide (no session): the replica follows this peer keeps up with in the background. settled follows have confirmed their exact local head; live ones also hold an open link to their upstream, so they are current now rather than as of their last round.
ForeignPlacementIgnored
Diagnostic: a placement naming an origin outside the configured providers was ignored.
FrameworkRequest
Transitional office envelope. Each document is defined by the desk which owns it; this file only preserves existing Runtime v2 field identities while callers move to desk-specific entry points.
FrameworkResponse
FrontierHlc
A prior-verification receipt is a typed cache of a kernel verdict. It is not authority by itself: only the separately supplied CheckpointVerificationPolicy decides whether an importer may accept it without recomputing the prefix. Unknown callers therefore verify by default.
FrontierRetained
FrontierTransitionDispositionMapEntry
FrontierTransitionDispositions
FrontierTransitionRequest
One real staged-law transition at the authenticated current frontier. This is deliberately a first-class protobuf contract rather than a NamedQuery/NomosStruct: field drift must fail every host build. COUNTERFACTUAL is a separate non-serving diagnostic and cannot authorize a lifecycle transition.
FrontierTransitionResponse
FrontierTransitionViolation
FullHistoryAuditQuery
Explicit diagnostic replay of retained history under each offer's historical law. Never an install prerequisite; does not reuse or replace verified-prefix caches, advance custody, or activate a candidate law.
FullHistoryAuditResponse
FullResultReason
Typed premise for answering a delta request with the complete result.
GenerateSigningKeyPair
GenesisOffer
Genesis selects the kernel's intrinsic bootstrap law. The controller USDZ, target and captured inputs are the ordinary OfferRequest fields. Keeping the intent empty prevents a host from manufacturing a privileged bootstrap call.
GitFetchRequest
GitFetchResult
GitReadLease
Short-lived, repository-scoped read capability for Git smart HTTP.
HistoricQueryRequest
The records desk provides typed, read-only inspection of custody and exact historic frontiers. It never moves the live frontier or invents authority.
HistoryAcquired
The Peer Runtime has satisfied the logical history capability. A caller may now replay the paper which received HistoryRequired; no physical acquisition detail crosses this boundary.
HistoryAcquisitionRecovery
Recovery paper carried by a durable effect executor. It cannot choose a physical depth or provider operation; it only lets the Peer Runtime restore its own logical acquisition after an ephemeral host has been replaced.
HistoryRequired
Kept at the end of the ABI declaration so introducing this typed failure detail does not renumber generated descriptor indexes for every existing kernel message.
HistorySummaryRequest
HistorySummaryResponse
HostHealth
HttpObligationDelivered
HttpsExecutionPolicy
HttpsOutboundRoute
IdentityProviderWitnessAdoption
Exact framework authoring request for the ordinary provider-witness adoption directive. The signed reads remain OfferRequest evidence; this message neither imports verifier material nor changes custody outside the destination workspace's normal offer gate.
IdentityProviderWitnessCertificate
IdentityProviderWitnessKey
IdentityProviderWitnessQuery
The root kernel serves the current typed provider publication from its own verified custody. It never fetches an external URL. Runtime v2 turns this result into a portable, peer-cached witness offer with source proof.
IdentityProviderWitnessRequired
IdentityProviderWitnessResponse
ImportLawProductsRequest
Install products for law closures selected at the workspace's main. A product for a closure the main does not select, or bytes that do not decode as that identity's layers, are refused.
ImportLawProductsResponse
InjectedKey
InspectChangeRequest
InspectChangeResponse
InspectCustodyPlacementRequest
InspectCustodyPlacementResponse
InspectDiscoveredWorkspacePlacement
InspectLawPackageRequest
Read-only inspection of one opaque compiler-produced law package. The Peer Office transports the bytes; only the kernel parses OpenUSD, composes the closure and derives its identity and domain surface.
InspectRefusalVerdictRequest
InspectRefusalVerdictResponse
InstalledLawClosureDeclarations
InstalledLawDeclarationsQuery
What the workspace's selected installed law declares about itself, read from authenticated custody at the exact head: each closure's unit set record (state/law-unit-sets) and each law member's declared authentication provider. Law is public; this carries no tenant data and needs no principal.
InstalledLawDeclarationsResponse
InstalledLawUnit
InstalledLawUnitSet
The record the unit lane keeps for a composed closure. A package-lane closure has none.
IntentRecord
IntentsAboveRequest
IntentsAboveResponse
IntentTransportRequirement
A sealed change is self-contained and may take the low-latency offer lane. A commit-tree requirement means the effect also introduced canonical custody (currently a typed USDA law closure), so sync must carry the authenticated Git tree rather than stripping it to change.usda. The kernel derives this from the commit-tree delta; hosts never infer it from domain/directive labels.
InterfaceCompatibilityQuery
InterfaceCompatibilityReason
InterfaceCompatibilityResponse
InterfaceCompatibilityStatus
InterfaceCompatibilityVerdict
The desk's complete answer: the kernel's per-member examination, plus the one correspondence fact a client would otherwise be tempted to infer.
InterfaceMemberKind
VINTF-inspired compatibility algebra over Nomos's canonical OpenUSD law. The application matrix is USDA; Protobuf carries only the closed request and typed verdict across the kernel ABI.
InterfaceMemberVerdict
InvocationTarget
KernelCallRequest
The application counter accepts only compiler-generated calls and reads. Domain values remain canonical OpenUSD; this desk never receives generic maps, custody paths, placement policy or provider credentials.
KernelConfigurationRequest
Immutable process configuration supplied once by the Peer Office before it opens any workspace custody. This is not law, an offer or a test backdoor: it selects the external trust universe in which this kernel instance will verify lineage. Repeating the same configuration is idempotent; changing it after configuration is refused.
KernelConfigurationResponse
KernelContractRequirement
KernelContractVerdict
KernelLawCapability
KernelLawHydrationStep
KernelProgressObserved
KernelProgressOperation
KernelProgressPhase
KernelProgressSnapshot
Ephemeral, authority-free progress from one long-running kernel operation.
KernelProgressUnit
KernelRefreshOutcome
Outcome of asking a shell to reconcile to the provider-selected kernel in place.
KernelRefusal
KernelRefusalCode
This list mirrors nomos_executor::Reason. The Rust conversion is an exhaustive match, so adding a new gate refusal cannot silently degrade to prose.
KernelResidencyIntent
Peer-relative kernel-memory intent. This does not promise durable Git custody or offline availability; CustodyRetentionIntent governs that separately.
KernelSpan
KernelSpanMetric
KernelSpans
KernelWorkCounter
One exclusive top-level class of kernel ABI work. Counters are cumulative for the installed kernel in this process; Prometheus treats a process/kernel swap as an ordinary counter reset. family is the bounded dashboard vocabulary, while operation is the exact generated oneof path (also bounded by the ABI). Neither field contains a workspace, law identity, intent or tenant value.
KernelWorkCpuBucket
Cumulative histogram bucket for one KernelWorkCounter. The bounds are fixed by the peer runtime and cumulative, matching the Prometheus histogram model.
KernelWorkSnapshot
Operator telemetry only. Top-level families are mutually exclusive so their CPU totals form one honest 100% partition. Kernel-owned nested phase timings remain separate drill-down evidence and must never be added to these totals.
KeyedBirthName
birth.keyed({ namespace, key }) — <namespace>-<sha256(namespace + US + key)[:40]>.
LawChanged
LawClosureInfoRequest
LawClosureInfoResponse
LawPackageInspection
LawProducts
The kernel's derived law products for one law closure (architecture/lazy_history.md): its read and command projection layers, each a pure function of the law identity. A provider serves them with the custody over HTTPS, and a device mounts them instead of composing the law. The device's own re-derivation is the opt-in audit.
LawUnit
One law unit exactly as the compiler emits it under build/<pkg>.units/<key>-<hash>/: every file at its logical path, unit.usda among them. Typed entries rather than an archive: the kernel already treats a unit as a git tree of (path, blob) entries, so each entry maps to one tree entry with no archive parser, member-name normalisation or second transport format (architecture/law_units_format.md, "Why there is no .tar.gz per unit").
LawUnitFile
LifecycleInstallIdentity
LifecycleInstallPhase
LinkChanged
LinkStatus
ListChildWorkspacesRequest
ListDeadLettersRequest
ListRefsRequest
ListRefsResponse
ListWorkspaceMomentsRequest
ListWorkspacesRequest
LiveAdmission
The custodian's admission of one live batch: the same CustodyAdmission the HTTP offer lane returns (main, sealed main, per-intent outcomes), keyed by the batch's request id. Sent to every live peer of the workspace. A failed or blocked batch sends none; the sender's follow falls back.
LiveFrontier
LiveLinkClosure
One closed live connection, correlated with what that connection had carried (CAP-683). The runtime keeps a bounded record of recent closes; nothing here costs a history walk or a network call, and none of it is on the write path.
LiveLinkRole
Which side of the live link a connection served.
LiveOfferFrame
A live link carries proposals and, from the custodian only, the admission it judged for them. A peer advances its tracked base from an admission only when the sealed main is already in its own verified history; anything else falls back to the ordinary HTTP/Git convergence lane.
LocalCopyDropPreview
LocalCopyDropScheduled
LocalCustodySnapshot
Opaque local custody cache. Git tree and checkpoint bytes remain kernel-owned; the host records only enough typed metadata to offer them back on next open. Field numbers deliberately match the historical runtime-v1 message so stored PB3 snapshots remain wire-compatible across this ownership correction.
LocalHistoryPosture
LocalLawCurrency
WHETHER MISSING LAW MIGHT STILL ARRIVE IS THE OFFICE'S TO STATE.
LocalReadPending
LocalWorkRejected
LocalWorkRejectionSource
MaintenancePhase
MaintenanceQuantumQuery
MaintenanceQuantumResponse
MaintenanceScheduled
MaintenanceTicked
MaintenanceTickRequest
One explicit, bounded turn of Peer Office maintenance. The platform shell merely wakes this procedure; it cannot select a workspace, interpret a frontier, or loop until completion.
MetaFile
MintTypedIdRequest
Pure kernel producers have exact generated frames. They do not impersonate workspace queries and no host serializes their keys, identifiers or ciphertext into a command map.
MintTypedIdResponse
ModelAdoptionOutcome
ModelAdoptionPhase
ModelAdoptionProgress
Emitted as a RuntimeEvent to every session bound to the workspace while the desk runs, and once more with the terminal outcome.
ModelLifecycleIntent
ModelLifecycleOperation
Exact framework lifecycle authoring. The candidate itself remains the opaque, content-addressed law_usdz package below; the kernel derives its identity and dependency closure after opening it. This intent exists so an installed controller can judge its successor using the controller's own nominal field identities. A client must never manufacture candidate-schema USDA for that transition.
NamedQuery
Framework/introspection reads have fixed names in generated clients. arguments carries only their operation-specific data while migration replaces the remaining legacy query arms.
NominalCallIdentity
NomosKernelServiceApi
The host and kernel share one unary protocol. WASI transports the encoded messages through linear memory; native/cloud transports may expose the same messages through gRPC or Connect. This schema is an ABI only. Signed law and custody remain canonical typed USDA.
NomosList
NomosRef
NomosStruct
NomosValue
Nomos' dynamic tenant value is deliberately not google.protobuf.Value: that standard helper stores every number as double and cannot represent the exact i64/u64 values used by HLCs, replica ids, counters and custody metadata.
Null
OfferAdmitted
The kernel owns the shape of an admitted offer. Keep every framework consequence explicit so generated Rust, TypeScript and Dart clients fail to compile when this contract changes. Tenant business values remain canonical USDA; they never acquire a parallel protobuf domain model.
OfferAggregateRef
OfferBlockedOnDependency
OfferDeadLettered
OfferPreparationChallenge
OfferPrepared
A target holon's non-effectful authored result. The target kernel alone runs its installed law and captures its exact inputs; a sovereign client kernel may then add the device signature without cloning the target's custody. Admission still re-runs the ordinary offer gate against the target's current head.
OfferQuarantined
OfferRefused
OfferRequest
OfferResponse
An offer is adjudicated data, not a generic RPC success followed by a stringly outcome field. Every kernel-owned admission state is exhaustive in generated clients.
OfferStateChange
The aggregates one admitted offer changed, by the type a read resolves for each (its __type, else its id), between the head it was admitted on and the head it produced. Exact or wider, never narrower: every aggregate whose state differs between the two heads is counted.
OpenApiDescriptionResponse
OpenAPI is already a JSON document, not a tenant value or a recursive NomosValue tree. Intermediate runtimes forward it without parsing/reconstructing every schema property.
OpenGitStateRequest
OpenGitStateResponse
OpenReceivingGroupRequest
One local-open/birth procedure. Reception transports this paper once; the shared desk opens mounted local custody immediately. Remote presence or a successful birth returns typed LOCAL_REPLICA_NOT_READY while Replica Follow independently establishes local custody.
OpenRequest
OpenResponse
Application operations have distinct envelopes even where their tenant-defined body remains a NomosValue. This keeps operation identity in the generated type system instead of rebuilding a stringly mode discriminator above a generic success object.
OsgiAttribute
OsgiCapability
OsgiDirective
OsgiRequirement
OsgiResourceResponse
OutboundOffer
A kernel-authored outbound offer. The host switches exhaustively on route solely to transport the opaque sealed bytes; every semantic field remains inside sealed_offer. custody_path and delivery_ref are opaque transport cursors chosen by the kernel, never reconstructed by a host.
OutboxEntry
Routing inventory is deliberately not a transport envelope: no history walk or evidence pack.
OutboxRequest
OutboxResponse
OutboxSummary
The cheap fleet read over one workspace's durable outbox: inventory only, no preparation, no history walk.
OutboxTargetCount
OwnedBirthScopeKeyRequest
OwnedDeviceRequestQuery
Fixed framework crypto has an exact generated ABI. The signed request and encrypted custody values remain canonical USDA documents; Protobuf identifies the operation and frames those semantic values without rebuilding their schema as a generic struct.
OwnedDeviceRequestResponse
OwnedIdentityEnsured
OwnedIdentityProtection
OwnedKeyWrap
OwnedPrepareApprovalQuery
OwnedPrepareApprovalResponse
OwnedRecordAction
OwnedRecordPreparation
OwnedRecordRef
OwnedScopeKey
OwnedScopeKeyList
OwnedScopeKeyRequest
OwnedScopeKeysRequest
OwnedSharePreparation
OwnedTransferPreparation
OwnedUnsharePreparation
PackDeltaRequest
PackDeltaResponse
PageQuery
ParentSignerEnrollment
ParentSignerEnrollmentRequest
PeerConsoleEnrolled
The console's record of the enrolled device (HTTP 201).
PeerConsoleEnrolmentEffect
D22/D23: enrol this device's key with the application's console enroller. The shell asks its credential provider for a FRESH plain identity token (no device challenge, never a cached one: the console spends each token once), signs the console's enrolment request with the device secret it holds under device_identity, and POSTs <console>/v1/tenants/<tenant>/providers/<scope>/enrolments. The token goes only to the console, over transport; it never re-enters Peer Office, an intent or a ledger. Peer Office decides when to ask and how to retry.
PeerConsoleEnrolmentRefused
The console answered, but not with an enrolment.
PeerCredentialRefreshed
Ephemeral platform receipt, never workspace custody. Empty material means this shell has no usable refresh provider for the requested capability.
PeerCredentialRefreshEffect
Invoke the platform's provider for this opaque device capability. Choosing when to ask (a refusal, or renewal ahead of the proof's expiry), and whether an operation may retry, belongs to Peer Office.
PeerDeviceIdentity
Absent secret on a load means this device holds no identity under that name yet; on a save it is simply the acknowledgement.
PeerDeviceIdentityEffect
The shell owns durable device-identity persistence (a 0600 file today, the OS keychain/keystore when implemented). Peer Office asks it to load or save exactly one identity's secret; the loaded secret lives in the runtime's credential vault under the session's capability and never re-enters a shell-built kernel request. A shell that cannot persist identity answers with a typed failure receipt; it never fabricates or substitutes a secret.
PeerDeviceIdentityLoad
PeerDeviceIdentitySave
PeerDeviceRecoveryLoad
PeerDeviceRecoverySave
PeerEffectFailure
PeerEffectFailureReason
PeerEffectReceipt
PeerGitFetchEffect
PeerGitFetchResponse
PeerGitPushEffect
An auxiliary commit tree is parked on an inert session ref before its ordinary custody offer is submitted. This effect moves kernel-produced Git bytes only: it cannot advance main and carries no admission verdict.
PeerGitPushResponse
PeerHistoryAcquisitionEffect
Peer Runtime requests one bounded physical advance toward locally available authenticated history. The platform chooses no depth and owns no loop; it performs one provider-appropriate step and reports whether acquisition has completed.
PeerHistoryAcquisitionReceipt
PeerHttpEffect
PeerHttpMethod
A peer-office job may need a platform shell to move an exact protobuf paper over HTTP. The shell receives no workspace lifecycle command and returns no semantic verdict: it performs this mechanical effect and returns the bytes and status it observed. The peer office retains the state machine and the target kernel remains the only examiner.
PeerHttpResponse
PeerLawPackage
PeerLawPackageEffect
The exact compiled law package the application was released with, by its kernel-derived identity. The office asks for it only when a workspace must stage that package (the kernel demands the opaque USDZ bytes on stage/install; the parent-current-law selector is admitted in genesis recipes only). The shell answers from the capability the application supplied (a bundled asset, a file) or with a typed failure; it never fetches, substitutes or inspects it.
PeerLocalCustodyEffect
Make already retained Git bytes accessible at the kernel's physical mount. This operation must not discover or download absent custody.
PeerLocalCustodyReceipt
PeerSocketCloseInitiator
Who ended a live socket.
PeerSocketClosure
How a live socket ended. Bounded: the reason is at most 123 bytes (RFC 6455's close reason).
PeerSocketEffect
Runtime-owned socket lifecycle; shells only operate the identified socket.
PeerSocketObserved
PeerSocketReceipt
PeerStatusReport
The deploy canary's view of one workspace: its Peer Office custody status beside the physical health of the host currently serving it (GET /v2/workspaces/
PeerWakeEffect
A mechanical wake requested by a runtime-owned procedure. The platform applies this delay exactly; it does not select backoff or readiness policy.
PeerWoken
PeerWorkspaceDiscoveryEffect
The platform chooses its configured external directory. It returns the directory's typed observation; only the Peer Office selects the next step.
PendingConflictsQuery
The maintained conflict index is framework-owned, while each competing value remains typed by the application's composed law. Both operations therefore have exact request fields and return canonical USDA.
PendingConflictSummaryQuery
PersistBornCustodyEffect
A kernel birth initially exists in the peer's physical Git working area. The peer office, not a platform shell, decides that those exact bytes must become durable custody. A shell may only perform this closed byte-moving effect and return the per-workspace physical receipt.
PersistBornCustodyReceipt
PersistedBornCustody
PhysicalClosureCheck
PhysicalRefFile
PlacementAdopted
PlacementOffer
PrepareApplicationRequest
One application-readiness procedure. Reception only transports this paper; it does not sequence domain preparation or interpret compatibility.
PrepareDomainRequest
Law package readiness is peer maintenance. Installing, adopting and restoring law are ordinary generated offers judged by the kernel and are deliberately not a second peer-office lifecycle.
PrepareOutboundOffer
PrepareOwnedRecordActionRequest
PrepareRemoteOfferRequest
The first half of remote authoring proves possession of an enrolled device key BEFORE the target evaluates a privileged plan. The client signs the exact serialized OfferRequest bytes; the target kernel verifies those same bytes against its own signer relation, then prepares the USDA transition. The second, existing SignPreparedOffer proof binds the resulting transition.
PrepareRemoteOfferResponse
PreservedLocalCopy
A local copy replaced by a refetch and kept aside, not merged. Recorded when the replacement happens, from Git alone, so it stays visible after main moved on.
PreviewLocalCopyDropRequest
What dropping this peer's local copy of a workspace would discard. Local-only observation: no network, no mutation. A device replica is a droppable cache of the provider's custody; these counts are the work that cache holds which the provider has not admitted.
ProtectOwnedIdentityRequest
ProveCompactionEquivalenceRequest
ProveCompactionEquivalenceResponse
ProvideLawProductsRequest
A provider serving a workspace's derived law products (architecture/lazy_history.md): the products of every closure selected at its main, as the kernel exports them from custody.
ProviderOriginsConfigured
ProviderTokenVerificationStatus
QuarantinedBinding
Diagnostic: a persisted peer-desk binding was NOT created by this office, so it is quarantined — preserved byte-for-byte under the quarantine namespace, never loaded, followed, exported or delivered from. A copied state directory (peer-desk.sqlite and custody) carries every secret in it, so keys cannot tell a copy from the original: the office seat (the host's declared identity and the origins it serves) can.
QueryAuthority
Claims and opaque proofs supplied to a read. The kernel alone resolves them against active law; this message cannot assert a verified principal.
QueryOperation
QueryRequest
QueryResponse
QueryResultFormat
ReadAccessPreparation
Transient observation: a session read was refused only because this device is not yet an active signer of a principal who holds the read there, and the office is enrolling it through the application's console route before asking again. The read itself still ends typed: rows, CREDENTIAL_UNAVAILABLE or a refusal.
ReadAttestation
The closed Protobuf projection of the canonical USDA read-attestation evidence. It is carried on an OfferRequest and has no mutation semantics of its own. The kernel verifies it before a plan may consume the read.
ReadBlobRequest
ReadBlobResponse
ReadCustodyPlacementRequest
ReadCustodyPlacementResponse
ReadDependencies
The state a declared rows result reads, from the installed read law. A state change touching none of it leaves the next delta from this result's position empty. Exact or wider, never narrower.
ReadIndexPending
One bounded turn of disposable read/custody/command acceleration. The request is closed and typed so a host cannot smuggle a second maintenance language through a generic map. The kernel remains the sole owner of every frontier and of the work selected for this turn.
ReadMaintenanceCause
Disposable acceleration is demand-driven by changes to verified custody. These causes explain why the Peer Office scheduled work; they never become application facts or authority.
ReadMaintenanceProgress
ReadProjectionStorageKind
ReadWorkspaceGenesisRequest
ReadWorkspacePlacement
RealmClosed
ReceivingGroupConvergence
Emitted as a RuntimeEvent to every session bound to the workspace, and returned as the tail paper's own outcome.
ReceivingGroupConvergenceOutcome
ReceivingGroupConvergencePhase
ReceivingGroupName
The framework's identity anchor — nomos-rg-<sha256(principal)[:40]>.
ReceivingGroupOpened
RecordedWorkspaceEffectOutcome
RecordWorkspaceEffectOutcomeRequest
A source's record of the recipient custodian's judgment. It is correspondence metadata; it never supplies a business event or changes main. The source kernel binds it to its own immutable outbound offer and refuses to record a deferral as completion.
RecoverCorrespondenceRequest
A durable platform wake resumes the source office after process loss. The office selects its committed work and the exact custody frontier to retain.
ReferenceVersionCheck
ReferenceVersionOutcome
ReferenceVersionReport
One outcome per requested check, in the order asked.
ReferenceVersionsQuery
ReferenceVersionStatus
RefRecord
RefreshCredentialsRequest
Transitional shell-to-office update. This disappears when every platform writes the WIT credential vault directly; application clients never call it.
RefreshReplicaCredentialRequest
Internal background paper. The workspace-keyed Replica Follow resolves its own durable capability locator; no interaction session is manufactured.
RefusalVerdict
RejectedLocalIntent
RelationshipTupleAddress
RelationshipTupleEvidence
ReleaseWorkspaceStateRequest
ReleaseWorkspaceStateResponse
RemoteGeneratedOfferAccepted
RemoteGeneratedOfferRequest
RemoteOfferAdmission
RepoStatsRequest
RepoStatsResponse
ResidencyHost
ResidencyPressureRelieved
ResidencyPressureRequest
A platform shell reports physical memory pressure; it never chooses which workspace to evict. The peer office applies the shared warm-lease policy and preserves Git custody while releasing only kernel residency.
ResidencyReport
ResidentAggregateCensus
The frontier's authenticated aggregate count, and the most numerous types from the resident read accelerator. top_types describe the head's state only when types_state_root equals state_root; otherwise they describe the (named) older state the accelerator is bound to.
ResidentComponent
ResidentComponentKind
ResidentFootprint
ResidentFootprintRequest
OPERATOR TELEMETRY, never law. What each resident workspace costs this kernel in memory, so the host can see WHY a container is full instead of guessing from a process-wide RSS number. Cheap by construction: the read model's size is page_count × page_size, two SQLite pragmas, so this is safe to poll. Reports only what is ALREADY resident — it never mounts, folds, or touches custody. deep walks each resident's documents, indexes and fold images by reference (no clone, no serialize). That is the only way to see the ~70% of a workspace that is NOT SQLite pages, but it costs real time, so it is opt-in and the response reports what the measurement itself cost.
ResidentFootprintResponse
ResidentOutbox
Undelivered outbound commitments at the last outbox inspection. Inventory only: the durable outbox in Git is the work; this is the host's latest look at it.
ResidentPlacement
Operator view of one workspace's custody placement. Remote and mailbox URLs are deliberately reduced to names and a presence bit: this report is served unauthenticated.
ResidentPlacementRule
One peer-class rule of a declared placement policy. A class whose custody retention is NONE holds no replica: it reaches the workspace through the named remotes only.
ResidentWorkspaceDetail
── Physical host telemetry ─────────────────────────────────────────────────── A platform-shell process describes itself. This is operator telemetry with no authority: nothing here admits an effect, selects a kernel or moves custody. It is the ONE contract for a host's /health and /kernel/refresh answers, the edge's /v1/ops/residency aggregate, placement headroom, peer restarts and the kernel-release swap proof. Until 2026-09-07 each of those hand-rolled its own JSON and a renamed field (pid/booted → replica) silently broke kernel releases. Physical detail about ONE resident workspace, keyed by a name in HostHealth.resident_workspaces. Telemetry only: it ranks candidates for an operator or a shedding policy and admits nothing.
ResidentWorkspaceReadiness
ResolvedWorkspaceName
ResolveRefRequest
ResolveRefResponse
ResolveRefsQuery
ResolveStatePositionRequest
Ask the kernel whether one replica-local custody hint resolves to the same canonical USDA state on this authenticated main. Hosts may use the answer for placement only; offer admission reopens and rederives the foreign read independently.
ResolveStatePositionResponse
ResolveWorkspaceNameRequest
THE ONE PLACE A WORKSPACE NAME IS DERIVED FOR A CLIENT.
RestartedHost
A host restart (POST /v1/ops/restart-peers): every selected Peer Runtime host restarted.
RestartError
RestartReport
RestoreMainRequest
Establish an absent live frontier from already-imported custody. Foreign custody is exposed only under an internal quarantine ref, verified as a complete semantic chain, and promoted atomically. Operator custody may instead authenticate and open the exact current-state frontier that previously entered that custody through admission; historical objects remain available on demand or for audit. Replacement requires an explicit expected local head; it preserves that head and still verifies foreign custody through canonical admission before atomic promotion.
RestoreMainResponse
RestoreMainSpans
One typed breakdown of custody admission. Zero means that phase was not needed (for example, an already-mounted frontier only performs the live-ref lookup).
RetainedRef
One custody ref at the exact object the Peer Runtime requires a durable copy to hold.
RetainFrontierEffect
Peer Runtime requests retention of one exact frontier. The platform may move bytes and report the result; it cannot select the workspace, head or refs.
RetainFrontierRequest
Internal Peer Runtime paper used by its background scheduler. The shell never authors this request; it only executes the resulting physical effect.
RetentionOutcomeCounter
outcome: retained | superseded | failed
RetryDeadLetterRequest
RowsQuery
RuntimeBlocked
A request can wait for physical office work without confusing that wait with a law refusal. Custody and kernel residency remain distinct obligations.
RuntimeEvent
RuntimeFailure
RuntimeFailureKind
A runtime defect, malformed paper or violated integrity invariant. Expected environmental absence and lawful refusal have their own response arms; a client must never inspect code or message to tell those cases apart.
RuntimeReady
RuntimeRefusal
RuntimeRefusalReason
A known authority or policy decision. Tenant-domain offer refusals remain in the kernel's typed OfferResponse; this arm is for the runtime boundary itself.
RuntimeRequest
Transitional numbered envelope at the peer office's front door. The actual papers are owned by the imported desk files; this file must not regain their fields or procedures. Tenant values remain canonical OpenUSD and never become an open protobuf map.
RuntimeResponse
RuntimeSpan
RuntimeTransportFailure
RuntimeUnavailable
RuntimeUnavailableReason
The operation could be valid, but the physical facts needed to execute it are not available now. These are presentation-safe control values, not log messages. In particular REMOTE_ONLY_OFFLINE says that placement provided no local read route and the required remote reception could not be reached.
SealFieldRequest
The sealing desk prepares cryptographic material without interpreting the application action. The kernel remains the authority over admission.
SealFieldResult
SessionBound
ShareWorkspaceOutcome
ShareWorkspaceRequest
The correspondence desk prepares typed documents exchanged with another workspace. It transports claims; the receiving kernel remains the examiner.
ShareWorkspaceResult
SiblingResidenciesRequired
SiblingResidencyRequired
SignalChanged
SignAuthorityAttestationRequest
A participant signs the exact authority edge it is disclosing. Every peer derives these bytes in the kernel from the same typed fields; no host may invent a serialization of the signed statement.
SignAuthorityAttestationResponse
SignBirthCertificateRequest
Pure local signing for the same typed certificate that OfferRequest carries. The client-held secret enters one kernel call and is never retained; the response is the generated certificate message, not a second document representation of it. A non-empty input signature is refused so callers cannot confuse signing a body with accepting a previously signed certificate. The certificate parent_key authorizes the signer of the next link down the chain, so it need not match signer_secret. When omitted, the kernel derives it from signer_secret for the self-signed/keyless lane.
SignBirthCertificateResponse
SigningIdentityRequest
The kernel is the one implementation of the peer's Ed25519 signing machine. Platform shells provide neither randomness formats nor key derivation code: they carry this generated message and retain the returned secret in their secure credential store.
SigningIdentityResponse
SigningKeyPair
SigningPublicKey
SignOfferPreparationRequest
SignOfferPreparationResponse
SignPreparedOfferRequest
Pure client-side signing of a target-kernel-prepared USDA transition. The secret enters only the local kernel invocation; neither the host nor the target workspace receives it.
SignPreparedOfferResponse
SpatialQuery
StoredCheckpointManifest
Typed manifest for a checkpoint's Git meta-commit. This is cache/transport structure, not application state; semantic aggregate content remains canonical USDA.
SyncAdmittedIntent
SyncCompleted
SyncPhaseTimings
SyncRefusal
SyncRefusedIntent
SyncReplayedIntent
SyncRequest
SyncResponse
Closed convergence verdict. Sync used to return a NomosStruct assembled via serde_json, forcing every host to maintain a second interpretation of this kernel-owned procedure. These records are framework protocol, not tenant values, so they remain ordinary generated Protobuf messages end to end.
SyncWorkspaceRequest
Internal background convergence paper. A retained follow is addressed by workspace; it never borrows an application session as replica identity.
SyncWorkspaceResponse
TallyQuery
TraceContext
Observations and mechanical socket effects from the peer office. None is an admission verdict; only the receiving kernel may admit an application offer.
TransferKind
TransferProgress
UnwatchRequest
UnwrapScopeKeyRequest
UnwrapScopeKeyResponse
VerifiedFrontierReceipt
VerifyChainDiagnostics
VerifyChainEngineTiming
VerifyChainHistory
What a verification on partly materialised history did walk.
VerifyChainLawHydrationTiming
VerifyChainStepPhases
Kernel-owned phase timings for one replayed intent. These remain typed all the way to the framework observability edge so diagnostics cannot become another semantic JSON carrier.
VerifyChainStepSpan
VerifyChainWalk
VerifyWorkspaceChainRequest
VerifyWorkspaceChainResult
WarmProgressResponse
One bounded kernel-maintenance quantum. This is runtime procedure state, not an application value, so every host receives the same closed shape.
WatchChanged
WatchKind
WatchRequest
WatchStarted
WatchStopped
WorkspaceCandidateCustodyRequired
The Peer Office has the workspace's main custody but needs one exact transport branch before it can judge the offered commits. The platform may fetch bytes for this ref; it may not inspect or admit them.
WorkspaceCustodyRequired
WorkspaceEffectDeferred
Durable mailbox append acknowledgement. Recipient judgment runs independently of the request, including when the target is already resident. The courier continues observation until the mailbox returns a completed recipient judgment. Repeated admission returns the canonical receipt with already_applied set.
WorkspaceEffectIdentity
WorkspaceEffectJudgmentSignature
WorkspaceEffectReceiptQuery
Completion is a kernel observation of the target's admitted main history. An unavailable history fails the query; it must never be represented as absence.
WorkspaceEffectReceiptResponse
WorkspaceEffectsDelivered
WorkspaceEffectStatusRequest
Workspace Mailbox Service observation. It never submits an offer or changes main.
WorkspaceEffectStatusResponse
WorkspaceFetch
WorkspaceGenesis
WorkspaceKernelResidencyRequired
WorkspaceList
WorkspaceMoment
WorkspaceMomentList
WorkspaceOpening
The answer to a paper whose workspace is still being opened. The paper was not executed: resend it after retry_after_millis. Opening continues regardless of who waits.
WorkspaceOutboundRoute
WorkspacePlacementRequest
Desired placement is an independently governed operational frontier owned by the workspace's retained-replica lifecycle. It is addressed by workspace, never by an ephemeral interaction session.
WorkspacePlacementState
WorkspaceRebirth
Local custody belongs to a different genesis than the one the provider serves.
WorkspaceResidencyRequirement
A custody dependency the kernel decoded from a sealed intent's typed captured-read envelope. This is a compute-readiness hint, never authority: the receiving kernel still reopens the named workspace at source_head and proves the carried result before admission.
WorkspaceStatus
Observation only: querying status must not acquire custody, connect a session, or open a workspace. An absent local head says nothing about remote custody.
WorkspaceStatusRequest
WorkspaceSummary
The peer's local physical inventory: the union of kernel-resident workspaces and the replica follows this peer keeps. Observation only: listing never acquires custody, mounts, fetches, or reads history; its cost is bounded by the inventory's size.
WorkspaceTarget
WorkspaceTransferEstimate
WorkspaceTransferKind
WrapScopeKeyRequest
WrapScopeKeyResponse
WriteMetaCommitRequest
WriteMetaCommitResponse
WritePreparation
Transient observation for one refused, not-yet-admitted generated call. The office owns recovery; observing this event is never required for correctness.
WriteRefRequest

Extensions

GeneratedMessageGenericExtensions on T
Extensions on GeneratedMessages.