nomos_kernel_protocol
library
Classes
-
Acknowledged
-
-
ActiveKernelWork
-
A call which is executing at the instant /health is observed. This is useful
for a genuinely long replay or index rebuild; most calls complete between
scrapes and are represented by the cumulative counters above.
-
AdoptApplicationModelRequest
-
-
AdoptWorkspacePlacement
-
-
AggregateCensusRequest
-
OPERATOR TELEMETRY, never law. How much state a workspace holds, and of what.
-
AggregateCensusResponse
-
-
AggregateTypeCount
-
-
ApplicationCompatibilityGuidance
-
The strongest next-step statement the local peer can prove. Fleet policy
(including whether a client patch or workspace rollout is preferred) belongs
to the tenant control plane and is not guessed from structural differences.
-
ApplicationCompatibilityPosture
-
Structural posture of this generated client against the law installed at
the workspace's current local frontier. Partial is a useful operating mode:
available members remain callable while only the exact unsafe members are
refused before dispatch.
-
ApplicationDomainRequirement
-
Immutable requirements supplied while a generated application facade is
composed. The shared Peer Office prepares them in declaration order.
-
ApplicationModelAdopted
-
-
ApplicationPrepared
-
-
ApplicationResultDelta
-
The rows of one declared query that changed between two kernel-issued read positions.
-
ApplyPackRequest
-
-
ApplyPackResponse
-
-
ArtifactsLatencyBucket
-
Cumulative wall-time histogram bucket, Prometheus model, fixed bounds.
-
ArtifactsRequestCounter
-
Cumulative counters for one (operation, outcome) pair of provider Git HTTP requests.
operation: info-refs-upload | info-refs-receive | upload-pack | receive-pack | other
outcome: 2xx | 3xx | 4xx | 5xx | timeout | transport
Wall time runs until the response body is fully read or the request fails, so a slow pack
download counts in full, not just its headers.
-
ArtifactsTransportSnapshot
-
-
AttachLocalFrontierRequest
-
-
AttachLocalFrontierResponse
-
-
AttestedRead
-
-
AuditCustodyRequest
-
One bounded slice of an OPT-IN audit: the canonical walk of the history under the workspace's
main (architecture/lazy_history.md). Nothing schedules it. Each call does at most about
budget_micros of work (one replay step always completes) and resumes where the last stopped.
The walk needs the whole history present; a shallow custody must be deepened first.
-
AuditCustodyResponse
-
-
AuthenticationPostureQuery
-
Read-only postcondition for a bounded auth-recovery retry. The kernel checks the current local
AuthProvider and signer relation; hosts and clients neither parse tokens nor infer readiness from time.
-
AuthenticationPostureResponse
-
-
AuthenticationReadiness
-
-
AuthenticationReadinessCriterion
-
-
AuthenticationReadinessOutcome
-
-
AuthoringOptions
-
-
AuthoringPreflightCause
-
-
AuthoringPreflightRequest
-
-
AuthoringPreflightResult
-
-
AuthorizationCheckRequest
-
-
AuthorizationCheckResponse
-
-
AuthorizationConditionContext
-
-
AuthorizationConsistency
-
-
AuthorizationDecisionBasis
-
-
AuthorizationExpandRequest
-
-
AuthorizationExpandResponse
-
-
AuthorizationExplanation
-
-
AuthorizationExplanation_Operation
-
-
AuthorizationObject
-
Zanzibar has its own explicit call algebra. These messages address the authorization graph
compiled from the active typed USDA LawStage; they can constrain which custodied revision is
acceptable but can never carry or replace the authorization model itself.
-
AuthorizationSubject
-
-
AwaitAuthenticationRequest
-
A desired kernel postcondition. Peer Office owns repeated local
observations, deadline and backoff; Replica Follow independently owns any
remote convergence which may make a later observation ready.
-
BindSessionRequest
-
Bind one ephemeral application interaction to a workspace identity. This
performs no discovery, network request, Git mount, SQLite maintenance or
replica-follow work. Placement is deliberately absent: each operation is
routed by the Peer Office from the workspace's placement policy.
-
BirthCertificate
-
Signed authority evidence for one child birth. This is a kernel input, not tenant payload:
generated clients cannot accidentally rename it, domain law cannot interpret it as business data,
and the kernel converts it directly into its nominal Rust certificate before attaching it to USDA.
-
BirthEvidenceReadiness
-
-
BirthEvidenceStatus
-
-
BirthOutcome
-
-
BirthOutcomeStatus
-
-
BornCustody
-
-
BornCustodyRef
-
The custodian names the exact non-main frontiers to publish before birth is discoverable.
Packs remain opaque physical custody, independently of their policy semantics.
-
BornWorkspace
-
-
ByIdQuery
-
-
ByTypeQuery
-
-
CallRequest
-
-
CallResponse
-
-
CapacityReserveRequest
-
-
CapacityReserveResponse
-
-
CapturedClock
-
-
CarriedWorkspaceOffer
-
A causal offer carried from another workspace. The peer transports these
fields inside OfferRequest; the target kernel re-hashes the source proof,
derives the source actor, and submits the sealed call through its one offer
door. This is evidence for an offer, never a second effectful operation.
-
CheckInterfaceCompatibilityRequest
-
The Compatibility Desk transports one compiler-authored USDA matrix to the
kernel. It does not duplicate the law schema in Protobuf and never parses or
authors USDA itself.
-
CheckKernelContractsRequest
-
THE COARSE AXIS OF THE SAME JUDGEMENT: OSGi Contract Namespace requirements.
-
CheckpointAssurance
-
-
CheckpointCompression
-
-
CheckpointExportRequest
-
-
CheckpointExportResponse
-
-
CheckpointImportRequest
-
-
CheckpointImportResponse
-
-
CheckpointVerificationPolicy
-
-
CheckReferenceVersionsRequest
-
THE OFFICE STATES A REFERENCE'S VERSION STATUS; a client does not infer it.
-
ChildWorkspace
-
-
ChildWorkspaceLifecycleStatus
-
-
ChildWorkspaceList
-
-
ChildWorkspaceQuery
-
Structural lineage is framework custody, not an application-shaped row set.
Give every host one exact generated result rather than teaching each runtime
to parse NomosBirthRecord USDA independently.
-
ChildWorkspaceQueryRecord
-
-
ChildWorkspaceQueryResponse
-
-
ChildWorkspaceStatus
-
-
CloseRealmRequest
-
Transitional Protobuf close for string-frame shells. Component-native shells
use peer-office.peer.close() directly. This duplicate disappears once every
shell owns the WIT resource instead of simulating it through an invocation.
-
CompactionEquivalence
-
-
ConfigureProviderOriginsRequest
-
The host's configured discovery providers, by origin (scheme://host
:port). Once
configured, the Peer Office talks to these origins only: a retained or discovered
placement naming any other origin is ignored on every network path, and the
workspace is re-discovered through a configured provider.
-
ConflictSnapshot
-
-
ConsoleEnrolmentRoute
-
Where an enrolled principal's device key is enrolled (D22/D23): the
application's console enroller, the console tenant and the enrolled provider
scope declared in law. Application configuration, never law or authority:
the kernel judges the resulting
enrollDevice like any other intent.
-
ContinueCorrespondenceRequest
-
-
ContinueLocalReadRequest
-
A read has yielded while its local derived index catches up. The Peer Office
retains the request and chooses the next quantum; shells only wait for this
delay and return the opaque continuation. No index or retry policy lives there.
-
ConvergeReceivingGroupRequest
-
The convergence tail, run as correspondence work after the gate returned:
posture, framework device recovery when the kernel says this key is not a
seated signer, authentication readiness with birth evidence, then optional
full verification. It never fails the gate. The desk hands this paper to the
shell's background lane; shells only perform its typed physical effects.
-
CorrespondenceHold
-
One physical Peer Runtime host as the provider adapter sees it.
One outbound letter — or a whole correspondent, when the route itself is down — that this
host is holding back rather than delivering, with the last reason it could not settle.
-
CorrespondencePending
-
-
CorrespondenceRecovered
-
-
CorrespondenceRetryReason
-
Why a letter stayed in its source outbox.
reason is a stable machine code: the failure code
the target or transport returned, or one of nomos.correspondence.*. detail is human text,
truncated, never payload bytes.
-
CredentialRefreshRequested
-
A background physical effect, equivalent to the foreground pending paper.
The shell completes it with ContinueCorrespondenceRequest; it does not
inspect a sync failure or choose a recovery procedure itself.
-
CredentialsRefreshed
-
-
CredentialUse
-
Ephemeral capability selection recorded on an application binding. Secret
bytes live in the platform-shell WIT vault, not in workspace custody and not
in the generated application protocol.
-
CustodianWarming
-
A typed "custodian warming up" posture for one workspace, carried from the workspace-opening
answer (or the edge relay's opening reply) through the follow round to observers.
-
CustodyAdmission
-
-
CustodyAdmissionSpan
-
-
CustodyAdmissionTimings
-
-
CustodyAdvancedRequest
-
An exact custody frontier advanced through a write entrance which is not
itself a RuntimeRequest (currently the HTTP custody-offer correspondence
lane). This is only a demand signal for disposable acceleration: it grants
no authority, changes no application state, and carries no host verdict.
-
CustodyBreak
-
-
CustodyBreakKind
-
-
CustodyBreakPolicy
-
Recovery preserves refused work and makes custody discontinuities explicit.
It never rewrites business history silently.
-
CustodyCertificate
-
An admission-checkpoint signer's statement that
head is the workspace's admitted custody.
-
CustodyChanged
-
-
CustodyChangeKind
-
-
CustodyDisagreement
-
-
CustodyInlineOffers
-
-
CustodyIntentAdmission
-
-
CustodyIntentAdmitted
-
-
CustodyIntentBlocked
-
-
CustodyIntentDeadLettered
-
-
CustodyIntentOffer
-
-
CustodyIntentQuarantined
-
-
CustodyIntentRefused
-
-
CustodyIntentSkipped
-
-
CustodyOfferAdmissionReceipt
-
-
CustodyOfferBatchRequest
-
-
CustodyOfferBatchResponse
-
HTTP custody admission still uses the same desk papers but has its own
request identity and media type. It remains here only until the front-door
envelope itself is split; the admission records live at correspondence.
-
CustodyOfferFailure
-
-
CustodyOfferReceipt
-
The interested peer retains the remote examiner's exact saga outcome without
carrying the returned Git pack through the application boundary. Pack bytes
are consumed mechanically by the peer office before this receipt is exposed.
-
CustodyOpening
-
The custody desk opens and inventories persistent Git custody. It has no
application-session command: interaction binding lives in interaction_desk,
while replica acquisition belongs exclusively to the background follow.
A workspace custody open in progress: the one progress fact shared by host health, the
shell's local-custody receipt and the office's answer to a paper that must wait for it.
The workspace is named because an operator and a waiting peer must see which open it is.
-
CustodyPlacementExpectation
-
-
CustodyPlacementPolicy
-
-
CustodyPlacementRule
-
-
CustodyRemote
-
-
CustodyRequest
-
-
CustodyResponse
-
-
CustodyRetentionIntent
-
Peer-relative durable Git-custody intent, independent of whether the kernel
keeps the workspace open in memory.
-
CustodySessionAdmission
-
-
CustodySessionCandidate
-
-
CustodySupersession
-
-
DeadLetterDiscard
-
-
DeadLetterEntry
-
-
DeadLetterList
-
-
DeadLetterRequest
-
-
DeadLetterResponse
-
-
DeadLetterRetry
-
-
DeclaredAuthenticationProvider
-
One law member (a command or read) and the provider it declares (
authenticatesWith).
-
DeclaredAuthenticationProviderKind
-
-
DeclaredLawMemberKind
-
-
DeleteRefRequest
-
-
DeliverHttpObligationRequest
-
Execute one exact HTTPS obligation selected from the source kernel's outbox.
This command exists separately from workspace delivery because an external
provider response is transport acknowledgement, not Nomos admission.
-
DeliverWorkspaceEffectsRequest
-
-
DeriveSigningPublicKey
-
-
DetachedSignedChange
-
A prepared change returned with detached Ed25519 signatures from one signer key. The kernel
decodes the change, re-derives the offer-token signing input at the target's CURRENT head and
verifies it through the one JWT verifier, attaches the author attestation, and admits the result
through the ordinary sealed-change door: the same admit, the same signer rule, the same checks
as a change a kernel signed.
-
DetachedSigningInputs
-
The two statements a detached author signs, derived by the target kernel for one prepared intent
and one signer key.
author is the kernel's author_signed_bytes (domain tag, genesis binding,
authored core); offer_token is the ASCII JWS signing input (base64url header "." base64url
claims) of the D17 offer token nomos-offer+jwt { iss: binding, sub: key:<sha256(public_key)>,
base: prepared_at_head, intents: intent_id }.
-
DeviceRecoveryAdmission
-
The exact, already signed request. Retransmission after a lost receipt must
not create another authored change. Preparation itself has no admission.
-
DeviceRecoveryAdmissionStage
-
-
DeviceRecoveryRecord
-
PRIVATE device custody, never workspace history, diagnostics or telemetry.
Persist before sending an admission or switching the active capability. A
missing record is distinct from an unreadable record (a physical failure).
-
DeviceSignerStatus
-
A device credential is not the account. In particular, a revoked credential
requires replacement under the declared recovery policy, never re-enrolment
of the same key. UNSPECIFIED is an older kernel, not proof of absence.
-
DiagnosticAttribute
-
-
DirectiveAuthoringRequirementsQuery
-
Bounded metadata from the authenticated current law. The runtime combines
this with exact Zanzibar checks; it never downloads or interprets law text.
-
DirectiveAuthoringRequirementsResponse
-
-
DirectiveCall
-
-
DiscardDeadLetterRequest
-
-
DiscoveredWorkspacePlacement
-
An availability description returned by a workspace discovery provider.
-
DiscoverWorkspacePlacement
-
Background inventory paper. Directory observations are routing hints, never
admission authority; a subsequent Replica Follow retains the verified ref.
-
DomainPrepared
-
-
DomainRefusal
-
Ephemeral nominal value checked against the deciding law's invariant contract.
No refusal event, outbox entry or durable record is required.
-
DropLocalCopyRequest
-
Authorize dropping exactly this local head and refetching the workspace from its
current provider. Only this workspace's local custody and its projections, caches
and indexes are replaced; device keys, credentials and other workspaces are not
touched. The previous local head is preserved under a custody-preserved ref.
-
EffectExecutionCardinality
-
-
EffectExecutionPlacement
-
-
EncodeRefusalVerdictRequest
-
-
EncodeRefusalVerdictResponse
-
-
EncryptionIdentityRequest
-
-
EncryptionIdentityResponse
-
-
EnsureOwnedIdentityRequest
-
-
EnsureParentSignerEnrollmentRequest
-
-
EnsureParentSignerEnrollmentResult
-
-
EstimateWorkspaceTransferRequest
-
-
ExportLawProductsRequest
-
The products of every law closure selected at the workspace's main (derived from its Git custody).
-
ExportLawProductsResponse
-
-
ExportLiveOffersRequest
-
-
Failure
-
-
FetchWorkspaceRequest
-
Fetch this workspace now: the explicit form of what a read of a workspace this peer does not
hold reaches (placement discovery, then the Replica Follow its placement retains, which mounts
the provider's head alone). Nothing is read, bound or opened; the answer returns as soon as the
follow exists, and the follow fetches on its own.
-
FoldFrontierAggregate
-
-
FoldFrontierFingerprint
-
-
FoldFrontierSnapshot
-
-
FollowObservation
-
-
FollowObservationPhase
-
-
FollowsSummary
-
Application-wide (no session): the replica follows this peer keeps up with in the background.
settled follows have confirmed their exact local head; live ones also hold an open link to
their upstream, so they are current now rather than as of their last round.
-
ForeignPlacementIgnored
-
Diagnostic: a placement naming an origin outside the configured providers was ignored.
-
FrameworkRequest
-
Transitional office envelope. Each document is defined by the desk which
owns it; this file only preserves existing Runtime v2 field identities while
callers move to desk-specific entry points.
-
FrameworkResponse
-
-
FrontierHlc
-
A prior-verification receipt is a typed cache of a kernel verdict. It is not authority by
itself: only the separately supplied CheckpointVerificationPolicy decides whether an importer
may accept it without recomputing the prefix. Unknown callers therefore verify by default.
-
FrontierRetained
-
-
FrontierTransitionDispositionMapEntry
-
-
FrontierTransitionDispositions
-
-
FrontierTransitionRequest
-
One real staged-law transition at the authenticated current frontier. This is deliberately a
first-class protobuf contract rather than a NamedQuery/NomosStruct: field drift must fail every
host build. COUNTERFACTUAL is a separate non-serving diagnostic and cannot authorize a lifecycle
transition.
-
FrontierTransitionResponse
-
-
FrontierTransitionViolation
-
-
FullHistoryAuditQuery
-
Explicit diagnostic replay of retained history under each offer's historical
law. Never an install prerequisite; does not reuse or replace verified-prefix
caches, advance custody, or activate a candidate law.
-
FullHistoryAuditResponse
-
-
FullResultReason
-
Typed premise for answering a delta request with the complete result.
-
GenerateSigningKeyPair
-
-
GenesisOffer
-
Genesis selects the kernel's intrinsic bootstrap law. The controller USDZ,
target and captured inputs are the ordinary OfferRequest fields. Keeping the
intent empty prevents a host from manufacturing a privileged bootstrap call.
-
GitFetchRequest
-
-
GitFetchResult
-
-
GitReadLease
-
Short-lived, repository-scoped read capability for Git smart HTTP.
-
HistoricQueryRequest
-
The records desk provides typed, read-only inspection of custody and exact
historic frontiers. It never moves the live frontier or invents authority.
-
HistoryAcquired
-
The Peer Runtime has satisfied the logical history capability. A caller may
now replay the paper which received HistoryRequired; no physical acquisition
detail crosses this boundary.
-
HistoryAcquisitionRecovery
-
Recovery paper carried by a durable effect executor. It cannot choose a
physical depth or provider operation; it only lets the Peer Runtime restore
its own logical acquisition after an ephemeral host has been replaced.
-
HistoryRequired
-
Kept at the end of the ABI declaration so introducing this typed failure
detail does not renumber generated descriptor indexes for every existing
kernel message.
-
HistorySummaryRequest
-
-
HistorySummaryResponse
-
-
HostHealth
-
-
HttpObligationDelivered
-
-
HttpsExecutionPolicy
-
-
HttpsOutboundRoute
-
-
IdentityProviderWitnessAdoption
-
Exact framework authoring request for the ordinary provider-witness adoption directive. The
signed reads remain OfferRequest evidence; this message neither imports verifier material nor
changes custody outside the destination workspace's normal offer gate.
-
IdentityProviderWitnessCertificate
-
-
IdentityProviderWitnessKey
-
-
IdentityProviderWitnessQuery
-
The root kernel serves the current typed provider publication from its own
verified custody. It never fetches an external URL. Runtime v2 turns this
result into a portable, peer-cached witness offer with source proof.
-
IdentityProviderWitnessRequired
-
-
IdentityProviderWitnessResponse
-
-
ImportLawProductsRequest
-
Install products for law closures selected at the workspace's main. A product for a closure the
main does not select, or bytes that do not decode as that identity's layers, are refused.
-
ImportLawProductsResponse
-
-
InjectedKey
-
-
InspectChangeRequest
-
-
InspectChangeResponse
-
-
InspectCustodyPlacementRequest
-
-
InspectCustodyPlacementResponse
-
-
InspectDiscoveredWorkspacePlacement
-
-
InspectLawPackageRequest
-
Read-only inspection of one opaque compiler-produced law package. The Peer
Office transports the bytes; only the kernel parses OpenUSD, composes the
closure and derives its identity and domain surface.
-
InspectRefusalVerdictRequest
-
-
InspectRefusalVerdictResponse
-
-
InstalledLawClosureDeclarations
-
-
InstalledLawDeclarationsQuery
-
What the workspace's selected installed law declares about itself, read from authenticated custody
at the exact head: each closure's unit set record (
state/law-unit-sets) and each law member's
declared authentication provider. Law is public; this carries no tenant data and needs no principal.
-
InstalledLawDeclarationsResponse
-
-
InstalledLawUnit
-
-
InstalledLawUnitSet
-
The record the unit lane keeps for a composed closure. A package-lane closure has none.
-
IntentRecord
-
-
IntentsAboveRequest
-
-
IntentsAboveResponse
-
-
IntentTransportRequirement
-
A sealed change is self-contained and may take the low-latency offer lane. A commit-tree
requirement means the effect also introduced canonical custody (currently a typed USDA law
closure), so sync must carry the authenticated Git tree rather than stripping it to change.usda.
The kernel derives this from the commit-tree delta; hosts never infer it from domain/directive labels.
-
InterfaceCompatibilityQuery
-
-
InterfaceCompatibilityReason
-
-
InterfaceCompatibilityResponse
-
-
InterfaceCompatibilityStatus
-
-
InterfaceCompatibilityVerdict
-
The desk's complete answer: the kernel's per-member examination, plus the one
correspondence fact a client would otherwise be tempted to infer.
-
InterfaceMemberKind
-
VINTF-inspired compatibility algebra over Nomos's canonical OpenUSD law.
The application matrix is USDA; Protobuf carries only the closed request and
typed verdict across the kernel ABI.
-
InterfaceMemberVerdict
-
-
InvocationTarget
-
-
KernelCallRequest
-
The application counter accepts only compiler-generated calls and reads.
Domain values remain canonical OpenUSD; this desk never receives generic
maps, custody paths, placement policy or provider credentials.
-
KernelConfigurationRequest
-
Immutable process configuration supplied once by the Peer Office before it
opens any workspace custody. This is not law, an offer or a test backdoor:
it selects the external trust universe in which this kernel instance will
verify lineage. Repeating the same configuration is idempotent; changing it
after configuration is refused.
-
KernelConfigurationResponse
-
-
KernelContractRequirement
-
-
KernelContractVerdict
-
-
KernelLawCapability
-
-
KernelLawHydrationStep
-
-
KernelProgressObserved
-
-
KernelProgressOperation
-
-
KernelProgressPhase
-
-
KernelProgressSnapshot
-
Ephemeral, authority-free progress from one long-running kernel operation.
-
KernelProgressUnit
-
-
KernelRefreshOutcome
-
Outcome of asking a shell to reconcile to the provider-selected kernel in place.
-
KernelRefusal
-
-
KernelRefusalCode
-
This list mirrors nomos_executor::Reason. The Rust conversion is an exhaustive
match, so adding a new gate refusal cannot silently degrade to prose.
-
KernelResidencyIntent
-
Peer-relative kernel-memory intent. This does not promise durable Git custody
or offline availability; CustodyRetentionIntent governs that separately.
-
KernelSpan
-
-
KernelSpanMetric
-
-
KernelSpans
-
-
KernelWorkCounter
-
One exclusive top-level class of kernel ABI work. Counters are cumulative for
the installed kernel in this process; Prometheus treats a process/kernel swap
as an ordinary counter reset.
family is the bounded dashboard vocabulary,
while operation is the exact generated oneof path (also bounded by the ABI).
Neither field contains a workspace, law identity, intent or tenant value.
-
KernelWorkCpuBucket
-
Cumulative histogram bucket for one KernelWorkCounter. The bounds are fixed
by the peer runtime and cumulative, matching the Prometheus histogram model.
-
KernelWorkSnapshot
-
Operator telemetry only. Top-level families are mutually exclusive so their
CPU totals form one honest 100% partition. Kernel-owned nested phase timings
remain separate drill-down evidence and must never be added to these totals.
-
KeyedBirthName
-
birth.keyed({ namespace, key }) — <namespace>-<sha256(namespace + US + key)[:40]>.
-
LawChanged
-
-
LawClosureInfoRequest
-
-
LawClosureInfoResponse
-
-
LawPackageInspection
-
-
LawProducts
-
The kernel's derived law products for one law closure (architecture/lazy_history.md): its read and
command projection layers, each a pure function of the law identity. A provider serves them
with the custody over HTTPS, and a device mounts them instead of composing the law. The
device's own re-derivation is the opt-in audit.
-
LawUnit
-
One law unit exactly as the compiler emits it under
build/<pkg>.units/<key>-<hash>/: every
file at its logical path, unit.usda among them. Typed entries rather than an archive: the
kernel already treats a unit as a git tree of (path, blob) entries, so each entry maps to one
tree entry with no archive parser, member-name normalisation or second transport format
(architecture/law_units_format.md, "Why there is no .tar.gz per unit").
-
LawUnitFile
-
-
LifecycleInstallIdentity
-
-
LifecycleInstallPhase
-
-
LinkChanged
-
-
LinkStatus
-
-
ListChildWorkspacesRequest
-
-
ListDeadLettersRequest
-
-
ListRefsRequest
-
-
ListRefsResponse
-
-
ListWorkspaceMomentsRequest
-
-
ListWorkspacesRequest
-
-
LiveAdmission
-
The custodian's admission of one live batch: the same CustodyAdmission the HTTP offer lane
returns (main, sealed main, per-intent outcomes), keyed by the batch's request id. Sent to every
live peer of the workspace. A failed or blocked batch sends none; the sender's follow falls back.
-
LiveFrontier
-
-
LiveLinkClosure
-
One closed live connection, correlated with what that connection had carried (CAP-683). The
runtime keeps a bounded record of recent closes; nothing here costs a history walk or a network
call, and none of it is on the write path.
-
LiveLinkRole
-
Which side of the live link a connection served.
-
LiveOfferFrame
-
A live link carries proposals and, from the custodian only, the admission it judged for them.
A peer advances its tracked base from an admission only when the sealed main is already in its
own verified history; anything else falls back to the ordinary HTTP/Git convergence lane.
-
LocalCopyDropPreview
-
-
LocalCopyDropScheduled
-
-
LocalCustodySnapshot
-
Opaque local custody cache. Git tree and checkpoint bytes remain kernel-owned;
the host records only enough typed metadata to offer them back on next open.
Field numbers deliberately match the historical runtime-v1 message so stored
PB3 snapshots remain wire-compatible across this ownership correction.
-
LocalHistoryPosture
-
-
LocalLawCurrency
-
WHETHER MISSING LAW MIGHT STILL ARRIVE IS THE OFFICE'S TO STATE.
-
LocalReadPending
-
-
LocalWorkRejected
-
-
LocalWorkRejectionSource
-
-
MaintenancePhase
-
-
MaintenanceQuantumQuery
-
-
MaintenanceQuantumResponse
-
-
MaintenanceScheduled
-
-
MaintenanceTicked
-
-
MaintenanceTickRequest
-
One explicit, bounded turn of Peer Office maintenance. The platform shell
merely wakes this procedure; it cannot select a workspace, interpret a
frontier, or loop until completion.
-
MetaFile
-
-
MintTypedIdRequest
-
Pure kernel producers have exact generated frames. They do not impersonate
workspace queries and no host serializes their keys, identifiers or
ciphertext into a command map.
-
MintTypedIdResponse
-
-
ModelAdoptionOutcome
-
-
ModelAdoptionPhase
-
-
ModelAdoptionProgress
-
Emitted as a RuntimeEvent to every session bound to the workspace while the
desk runs, and once more with the terminal outcome.
-
ModelLifecycleIntent
-
-
ModelLifecycleOperation
-
Exact framework lifecycle authoring. The candidate itself remains the opaque, content-addressed
law_usdz package below; the kernel derives its identity and dependency closure after opening it.
This intent exists so an installed controller can judge its successor using the controller's own
nominal field identities. A client must never manufacture candidate-schema USDA for that transition.
-
NamedQuery
-
Framework/introspection reads have fixed names in generated clients.
arguments carries only
their operation-specific data while migration replaces the remaining legacy query arms.
-
NominalCallIdentity
-
-
NomosKernelServiceApi
-
The host and kernel share one unary protocol. WASI transports the encoded messages through
linear memory; native/cloud transports may expose the same messages through gRPC or Connect.
This schema is an ABI only. Signed law and custody remain canonical typed USDA.
-
NomosList
-
-
NomosRef
-
-
NomosStruct
-
-
NomosValue
-
Nomos' dynamic tenant value is deliberately not google.protobuf.Value: that standard helper
stores every number as double and cannot represent the exact i64/u64 values used by HLCs,
replica ids, counters and custody metadata.
-
Null
-
-
OfferAdmitted
-
The kernel owns the shape of an admitted offer. Keep every framework consequence explicit so
generated Rust, TypeScript and Dart clients fail to compile when this contract changes. Tenant
business values remain canonical USDA; they never acquire a parallel protobuf domain model.
-
OfferAggregateRef
-
-
OfferBlockedOnDependency
-
-
OfferDeadLettered
-
-
OfferPreparationChallenge
-
-
OfferPrepared
-
A target holon's non-effectful authored result. The target kernel alone runs its installed law and
captures its exact inputs; a sovereign client kernel may then add the device signature without cloning
the target's custody. Admission still re-runs the ordinary offer gate against the target's current head.
-
OfferQuarantined
-
-
OfferRefused
-
-
OfferRequest
-
-
OfferResponse
-
An offer is adjudicated data, not a generic RPC success followed by a stringly
outcome field. Every kernel-owned admission state is exhaustive in generated clients.
-
OfferStateChange
-
The aggregates one admitted offer changed, by the type a read resolves for each (its
__type,
else its id), between the head it was admitted on and the head it produced. Exact or wider,
never narrower: every aggregate whose state differs between the two heads is counted.
-
OpenApiDescriptionResponse
-
OpenAPI is already a JSON document, not a tenant value or a recursive NomosValue tree.
Intermediate runtimes forward it without parsing/reconstructing every schema property.
-
OpenGitStateRequest
-
-
OpenGitStateResponse
-
-
OpenReceivingGroupRequest
-
One local-open/birth procedure. Reception transports this paper once; the
shared desk opens mounted local custody immediately. Remote presence or a
successful birth returns typed LOCAL_REPLICA_NOT_READY while Replica Follow
independently establishes local custody.
-
OpenRequest
-
-
OpenResponse
-
Application operations have distinct envelopes even where their tenant-defined body remains a
NomosValue. This keeps operation identity in the generated type system instead of rebuilding a
stringly
mode discriminator above a generic success object.
-
OsgiAttribute
-
-
OsgiCapability
-
-
OsgiDirective
-
-
OsgiRequirement
-
-
OsgiResourceResponse
-
-
OutboundOffer
-
A kernel-authored outbound offer. The host switches exhaustively on
route solely to transport
the opaque sealed bytes; every semantic field remains inside sealed_offer. custody_path and
delivery_ref are opaque transport cursors chosen by the kernel, never reconstructed by a host.
-
OutboxEntry
-
Routing inventory is deliberately not a transport envelope: no history walk or evidence pack.
-
OutboxRequest
-
-
OutboxResponse
-
-
OutboxSummary
-
The cheap fleet read over one workspace's durable outbox: inventory only,
no preparation, no history walk.
-
OutboxTargetCount
-
-
OwnedBirthScopeKeyRequest
-
-
OwnedDeviceRequestQuery
-
Fixed framework crypto has an exact generated ABI. The signed request and encrypted custody
values remain canonical USDA documents; Protobuf identifies the operation and frames those
semantic values without rebuilding their schema as a generic struct.
-
OwnedDeviceRequestResponse
-
-
OwnedIdentityEnsured
-
-
OwnedIdentityProtection
-
-
OwnedKeyWrap
-
-
OwnedPrepareApprovalQuery
-
-
OwnedPrepareApprovalResponse
-
-
OwnedRecordAction
-
-
OwnedRecordPreparation
-
-
OwnedRecordRef
-
-
OwnedScopeKey
-
-
OwnedScopeKeyList
-
-
OwnedScopeKeyRequest
-
-
OwnedScopeKeysRequest
-
-
OwnedSharePreparation
-
-
OwnedTransferPreparation
-
-
OwnedUnsharePreparation
-
-
PackDeltaRequest
-
-
PackDeltaResponse
-
-
PageQuery
-
-
ParentSignerEnrollment
-
-
ParentSignerEnrollmentRequest
-
-
PeerConsoleEnrolled
-
The console's record of the enrolled device (HTTP 201).
-
PeerConsoleEnrolmentEffect
-
D22/D23: enrol this device's key with the application's console enroller.
The shell asks its credential provider for a FRESH plain identity token
(no device challenge, never a cached one: the console spends each token
once), signs the console's enrolment request with the device secret it holds
under
device_identity, and POSTs
<console>/v1/tenants/<tenant>/providers/<scope>/enrolments. The token goes
only to the console, over transport; it never re-enters Peer Office, an
intent or a ledger. Peer Office decides when to ask and how to retry.
-
PeerConsoleEnrolmentRefused
-
The console answered, but not with an enrolment.
-
PeerCredentialRefreshed
-
Ephemeral platform receipt, never workspace custody. Empty material means
this shell has no usable refresh provider for the requested capability.
-
PeerCredentialRefreshEffect
-
Invoke the platform's provider for this opaque device capability. Choosing
when to ask (a refusal, or renewal ahead of the proof's expiry), and whether
an operation may retry, belongs to Peer Office.
-
PeerDeviceIdentity
-
Absent secret on a load means this device holds no identity under that
name yet; on a save it is simply the acknowledgement.
-
PeerDeviceIdentityEffect
-
The shell owns durable device-identity persistence (a 0600 file today, the
OS keychain/keystore when implemented). Peer Office asks it to load or save
exactly one identity's secret; the loaded secret lives in the runtime's
credential vault under the session's capability and never re-enters a
shell-built kernel request. A shell that cannot persist identity answers
with a typed failure receipt; it never fabricates or substitutes a secret.
-
PeerDeviceIdentityLoad
-
-
PeerDeviceIdentitySave
-
-
PeerDeviceRecoveryLoad
-
-
PeerDeviceRecoverySave
-
-
PeerEffectFailure
-
-
PeerEffectFailureReason
-
-
PeerEffectReceipt
-
-
PeerGitFetchEffect
-
-
PeerGitFetchResponse
-
-
PeerGitPushEffect
-
An auxiliary commit tree is parked on an inert session ref before its
ordinary custody offer is submitted. This effect moves kernel-produced Git
bytes only: it cannot advance main and carries no admission verdict.
-
PeerGitPushResponse
-
-
PeerHistoryAcquisitionEffect
-
Peer Runtime requests one bounded physical advance toward locally available
authenticated history. The platform chooses no depth and owns no loop; it
performs one provider-appropriate step and reports whether acquisition has
completed.
-
PeerHistoryAcquisitionReceipt
-
-
PeerHttpEffect
-
-
PeerHttpMethod
-
A peer-office job may need a platform shell to move an exact protobuf paper
over HTTP. The shell receives no workspace lifecycle command and returns no
semantic verdict: it performs this mechanical effect and returns the bytes
and status it observed. The peer office retains the state machine and the
target kernel remains the only examiner.
-
PeerHttpResponse
-
-
PeerLawPackage
-
-
PeerLawPackageEffect
-
The exact compiled law package the application was released with, by its
kernel-derived identity. The office asks for it only when a workspace must
stage that package (the kernel demands the opaque USDZ bytes on stage/install;
the parent-current-law selector is admitted in genesis recipes only). The
shell answers from the capability the application supplied (a bundled asset,
a file) or with a typed failure; it never fetches, substitutes or inspects it.
-
PeerLocalCustodyEffect
-
Make already retained Git bytes accessible at the kernel's physical mount.
This operation must not discover or download absent custody.
-
PeerLocalCustodyReceipt
-
-
PeerSocketCloseInitiator
-
Who ended a live socket.
-
PeerSocketClosure
-
How a live socket ended. Bounded: the reason is at most 123 bytes (RFC 6455's close reason).
-
PeerSocketEffect
-
Runtime-owned socket lifecycle; shells only operate the identified socket.
-
PeerSocketObserved
-
-
PeerSocketReceipt
-
-
PeerStatusReport
-
The deploy canary's view of one workspace: its Peer Office custody status beside the
physical health of the host currently serving it (GET /v2/workspaces/
-
PeerWakeEffect
-
A mechanical wake requested by a runtime-owned procedure. The platform
applies this delay exactly; it does not select backoff or readiness policy.
-
PeerWoken
-
-
PeerWorkspaceDiscoveryEffect
-
The platform chooses its configured external directory. It returns the
directory's typed observation; only the Peer Office selects the next step.
-
PendingConflictsQuery
-
The maintained conflict index is framework-owned, while each competing
value remains typed by the application's composed law. Both operations
therefore have exact request fields and return canonical USDA.
-
PendingConflictSummaryQuery
-
-
PersistBornCustodyEffect
-
A kernel birth initially exists in the peer's physical Git working area.
The peer office, not a platform shell, decides that those exact bytes must
become durable custody. A shell may only perform this closed byte-moving
effect and return the per-workspace physical receipt.
-
PersistBornCustodyReceipt
-
-
PersistedBornCustody
-
-
PhysicalClosureCheck
-
-
PhysicalRefFile
-
-
PlacementAdopted
-
-
PlacementOffer
-
-
PrepareApplicationRequest
-
One application-readiness procedure. Reception only transports this paper;
it does not sequence domain preparation or interpret compatibility.
-
PrepareDomainRequest
-
Law package readiness is peer maintenance. Installing, adopting and
restoring law are ordinary generated offers judged by the kernel and are
deliberately not a second peer-office lifecycle.
-
PrepareOutboundOffer
-
-
PrepareOwnedRecordActionRequest
-
-
PrepareRemoteOfferRequest
-
The first half of remote authoring proves possession of an enrolled device key BEFORE the
target evaluates a privileged plan. The client signs the exact serialized OfferRequest bytes;
the target kernel verifies those same bytes against its own signer relation, then prepares the
USDA transition. The second, existing SignPreparedOffer proof binds the resulting transition.
-
PrepareRemoteOfferResponse
-
-
PreservedLocalCopy
-
A local copy replaced by a refetch and kept aside, not merged. Recorded when the
replacement happens, from Git alone, so it stays visible after main moved on.
-
PreviewLocalCopyDropRequest
-
What dropping this peer's local copy of a workspace would discard. Local-only
observation: no network, no mutation. A device replica is a droppable cache of
the provider's custody; these counts are the work that cache holds which the
provider has not admitted.
-
ProtectOwnedIdentityRequest
-
-
ProveCompactionEquivalenceRequest
-
-
ProveCompactionEquivalenceResponse
-
-
ProvideLawProductsRequest
-
A provider serving a workspace's derived law products (architecture/lazy_history.md): the
products of every closure selected at its main, as the kernel exports them from custody.
-
ProviderOriginsConfigured
-
-
ProviderTokenVerificationStatus
-
-
QuarantinedBinding
-
Diagnostic: a persisted peer-desk binding was NOT created by this office, so it is
quarantined — preserved byte-for-byte under the quarantine namespace, never loaded,
followed, exported or delivered from. A copied state directory (peer-desk.sqlite and
custody) carries every secret in it, so keys cannot tell a copy from the original: the
office seat (the host's declared identity and the origins it serves) can.
-
QueryAuthority
-
Claims and opaque proofs supplied to a read. The kernel alone resolves them against active law;
this message cannot assert a verified principal.
-
QueryOperation
-
-
QueryRequest
-
-
QueryResponse
-
-
QueryResultFormat
-
-
ReadAccessPreparation
-
Transient observation: a session read was refused only because this device is
not yet an active signer of a principal who holds the read there, and the office
is enrolling it through the application's console route before asking again.
The read itself still ends typed: rows, CREDENTIAL_UNAVAILABLE or a refusal.
-
ReadAttestation
-
The closed Protobuf projection of the canonical USDA read-attestation
evidence. It is carried on an OfferRequest and has no mutation semantics of
its own. The kernel verifies it before a plan may consume the read.
-
ReadBlobRequest
-
-
ReadBlobResponse
-
-
ReadCustodyPlacementRequest
-
-
ReadCustodyPlacementResponse
-
-
ReadDependencies
-
The state a declared rows result reads, from the installed read law. A state change touching none
of it leaves the next delta from this result's position empty. Exact or wider, never narrower.
-
ReadIndexPending
-
One bounded turn of disposable read/custody/command acceleration. The
request is closed and typed so a host cannot smuggle a second maintenance
language through a generic map. The kernel remains the sole owner of every
frontier and of the work selected for this turn.
-
ReadMaintenanceCause
-
Disposable acceleration is demand-driven by changes to verified custody.
These causes explain why the Peer Office scheduled work; they never become
application facts or authority.
-
ReadMaintenanceProgress
-
-
ReadProjectionStorageKind
-
-
ReadWorkspaceGenesisRequest
-
-
ReadWorkspacePlacement
-
-
RealmClosed
-
-
ReceivingGroupConvergence
-
Emitted as a RuntimeEvent to every session bound to the workspace, and
returned as the tail paper's own outcome.
-
ReceivingGroupConvergenceOutcome
-
-
ReceivingGroupConvergencePhase
-
-
ReceivingGroupName
-
The framework's identity anchor —
nomos-rg-<sha256(principal)[:40]>.
-
ReceivingGroupOpened
-
-
RecordedWorkspaceEffectOutcome
-
-
RecordWorkspaceEffectOutcomeRequest
-
A source's record of the recipient custodian's judgment. It is correspondence metadata;
it never supplies a business event or changes main. The source kernel binds it to its
own immutable outbound offer and refuses to record a deferral as completion.
-
RecoverCorrespondenceRequest
-
A durable platform wake resumes the source office after process loss. The
office selects its committed work and the exact custody frontier to retain.
-
ReferenceVersionCheck
-
-
ReferenceVersionOutcome
-
-
ReferenceVersionReport
-
One outcome per requested check, in the order asked.
-
ReferenceVersionsQuery
-
-
ReferenceVersionStatus
-
-
RefRecord
-
-
RefreshCredentialsRequest
-
Transitional shell-to-office update. This disappears when every platform
writes the WIT credential vault directly; application clients never call it.
-
RefreshReplicaCredentialRequest
-
Internal background paper. The workspace-keyed Replica Follow resolves its
own durable capability locator; no interaction session is manufactured.
-
RefusalVerdict
-
-
RejectedLocalIntent
-
-
RelationshipTupleAddress
-
-
RelationshipTupleEvidence
-
-
ReleaseWorkspaceStateRequest
-
-
ReleaseWorkspaceStateResponse
-
-
RemoteGeneratedOfferAccepted
-
-
RemoteGeneratedOfferRequest
-
-
RemoteOfferAdmission
-
-
RepoStatsRequest
-
-
RepoStatsResponse
-
-
ResidencyHost
-
-
ResidencyPressureRelieved
-
-
ResidencyPressureRequest
-
A platform shell reports physical memory pressure; it never chooses which
workspace to evict. The peer office applies the shared warm-lease policy and
preserves Git custody while releasing only kernel residency.
-
ResidencyReport
-
-
ResidentAggregateCensus
-
The frontier's authenticated aggregate count, and the most numerous types from the resident
read accelerator.
top_types describe the head's state only when types_state_root equals
state_root; otherwise they describe the (named) older state the accelerator is bound to.
-
ResidentComponent
-
-
ResidentComponentKind
-
-
-
OPERATOR TELEMETRY, never law. What each resident workspace costs this kernel in memory, so the
host can see WHY a container is full instead of guessing from a process-wide RSS number. Cheap by
construction: the read model's size is
page_count × page_size, two SQLite pragmas, so this is
safe to poll. Reports only what is ALREADY resident — it never mounts, folds, or touches custody.
deep walks each resident's documents, indexes and fold images by reference (no clone, no
serialize). That is the only way to see the ~70% of a workspace that is NOT SQLite pages, but it
costs real time, so it is opt-in and the response reports what the measurement itself cost.
-
-
ResidentOutbox
-
Undelivered outbound commitments at the last outbox inspection. Inventory only: the durable
outbox in Git is the work; this is the host's latest look at it.
-
ResidentPlacement
-
Operator view of one workspace's custody placement. Remote and mailbox URLs are deliberately
reduced to names and a presence bit: this report is served unauthenticated.
-
ResidentPlacementRule
-
One peer-class rule of a declared placement policy. A class whose custody retention is NONE
holds no replica: it reaches the workspace through the named remotes only.
-
ResidentWorkspaceDetail
-
── Physical host telemetry ───────────────────────────────────────────────────
A platform-shell process describes itself. This is operator telemetry with no
authority: nothing here admits an effect, selects a kernel or moves custody.
It is the ONE contract for a host's /health and /kernel/refresh answers,
the edge's /v1/ops/residency aggregate, placement headroom, peer restarts and the
kernel-release swap proof. Until 2026-09-07 each of those hand-rolled its own
JSON and a renamed field (pid/booted → replica) silently broke kernel releases.
Physical detail about ONE resident workspace, keyed by a name in
HostHealth.resident_workspaces. Telemetry only: it ranks candidates for an operator or a
shedding policy and admits nothing.
-
ResidentWorkspaceReadiness
-
-
ResolvedWorkspaceName
-
-
ResolveRefRequest
-
-
ResolveRefResponse
-
-
ResolveRefsQuery
-
-
ResolveStatePositionRequest
-
Ask the kernel whether one replica-local custody hint resolves to the same canonical USDA state
on this authenticated main. Hosts may use the answer for placement only; offer admission reopens
and rederives the foreign read independently.
-
ResolveStatePositionResponse
-
-
ResolveWorkspaceNameRequest
-
THE ONE PLACE A WORKSPACE NAME IS DERIVED FOR A CLIENT.
-
RestartedHost
-
A host restart (POST /v1/ops/restart-peers): every selected Peer Runtime host restarted.
-
RestartError
-
-
RestartReport
-
-
RestoreMainRequest
-
Establish an absent live frontier from already-imported custody. Foreign custody is exposed only
under an internal quarantine ref, verified as a complete semantic chain, and promoted atomically.
Operator custody may instead authenticate and open the exact current-state frontier that previously
entered that custody through admission; historical objects remain available on demand or for audit.
Replacement requires an explicit expected local head; it preserves that head and still
verifies foreign custody through canonical admission before atomic promotion.
-
RestoreMainResponse
-
-
RestoreMainSpans
-
One typed breakdown of custody admission. Zero means that phase was not needed
(for example, an already-mounted frontier only performs the live-ref lookup).
-
RetainedRef
-
One custody ref at the exact object the Peer Runtime requires a durable copy to hold.
-
RetainFrontierEffect
-
Peer Runtime requests retention of one exact frontier. The platform may
move bytes and report the result; it cannot select the workspace, head or refs.
-
RetainFrontierRequest
-
Internal Peer Runtime paper used by its background scheduler. The shell
never authors this request; it only executes the resulting physical effect.
-
RetentionOutcomeCounter
-
outcome: retained | superseded | failed
-
RetryDeadLetterRequest
-
-
RowsQuery
-
-
RuntimeBlocked
-
A request can wait for physical office work without confusing that wait with
a law refusal. Custody and kernel residency remain distinct obligations.
-
RuntimeEvent
-
-
RuntimeFailure
-
-
RuntimeFailureKind
-
A runtime defect, malformed paper or violated integrity invariant. Expected
environmental absence and lawful refusal have their own response arms; a
client must never inspect
code or message to tell those cases apart.
-
RuntimeReady
-
-
RuntimeRefusal
-
-
RuntimeRefusalReason
-
A known authority or policy decision. Tenant-domain offer refusals remain in
the kernel's typed OfferResponse; this arm is for the runtime boundary itself.
-
RuntimeRequest
-
Transitional numbered envelope at the peer office's front door. The actual
papers are owned by the imported desk files; this file must not regain their
fields or procedures. Tenant values remain canonical OpenUSD and never
become an open protobuf map.
-
RuntimeResponse
-
-
RuntimeSpan
-
-
RuntimeTransportFailure
-
-
RuntimeUnavailable
-
-
RuntimeUnavailableReason
-
The operation could be valid, but the physical facts needed to execute it
are not available now. These are presentation-safe control values, not log
messages. In particular REMOTE_ONLY_OFFLINE says that placement provided no
local read route and the required remote reception could not be reached.
-
SealFieldRequest
-
The sealing desk prepares cryptographic material without interpreting the
application action. The kernel remains the authority over admission.
-
SealFieldResult
-
-
SessionBound
-
-
ShareWorkspaceOutcome
-
-
ShareWorkspaceRequest
-
The correspondence desk prepares typed documents exchanged with another
workspace. It transports claims; the receiving kernel remains the examiner.
-
ShareWorkspaceResult
-
-
SiblingResidenciesRequired
-
-
SiblingResidencyRequired
-
-
SignalChanged
-
-
SignAuthorityAttestationRequest
-
A participant signs the exact authority edge it is disclosing. Every peer
derives these bytes in the kernel from the same typed fields; no host may
invent a serialization of the signed statement.
-
SignAuthorityAttestationResponse
-
-
SignBirthCertificateRequest
-
Pure local signing for the same typed certificate that OfferRequest carries. The client-held secret
enters one kernel call and is never retained; the response is the generated certificate message, not a
second document representation of it. A non-empty input signature is refused so callers cannot confuse
signing a body with accepting a previously signed certificate. The certificate parent_key authorizes the
signer of the next link down the chain, so it need not match signer_secret. When omitted, the kernel derives
it from signer_secret for the self-signed/keyless lane.
-
SignBirthCertificateResponse
-
-
SigningIdentityRequest
-
The kernel is the one implementation of the peer's Ed25519 signing machine. Platform shells
provide neither randomness formats nor key derivation code: they carry this generated message
and retain the returned secret in their secure credential store.
-
SigningIdentityResponse
-
-
SigningKeyPair
-
-
SigningPublicKey
-
-
SignOfferPreparationRequest
-
-
SignOfferPreparationResponse
-
-
SignPreparedOfferRequest
-
Pure client-side signing of a target-kernel-prepared USDA transition. The secret enters only the local
kernel invocation; neither the host nor the target workspace receives it.
-
SignPreparedOfferResponse
-
-
SpatialQuery
-
-
StoredCheckpointManifest
-
Typed manifest for a checkpoint's Git meta-commit. This is cache/transport structure, not
application state; semantic aggregate content remains canonical USDA.
-
SyncAdmittedIntent
-
-
SyncCompleted
-
-
SyncPhaseTimings
-
-
SyncRefusal
-
-
SyncRefusedIntent
-
-
SyncReplayedIntent
-
-
SyncRequest
-
-
SyncResponse
-
Closed convergence verdict. Sync used to return a NomosStruct assembled via
serde_json, forcing every host to maintain a second interpretation of this
kernel-owned procedure. These records are framework protocol, not tenant
values, so they remain ordinary generated Protobuf messages end to end.
-
SyncWorkspaceRequest
-
Internal background convergence paper. A retained follow is addressed by
workspace; it never borrows an application session as replica identity.
-
SyncWorkspaceResponse
-
-
TallyQuery
-
-
TraceContext
-
Observations and mechanical socket effects from the peer office. None is an
admission verdict; only the receiving kernel may admit an application offer.
-
TransferKind
-
-
TransferProgress
-
-
UnwatchRequest
-
-
UnwrapScopeKeyRequest
-
-
UnwrapScopeKeyResponse
-
-
VerifiedFrontierReceipt
-
-
VerifyChainDiagnostics
-
-
VerifyChainEngineTiming
-
-
VerifyChainHistory
-
What a verification on partly materialised history did walk.
-
VerifyChainLawHydrationTiming
-
-
VerifyChainStepPhases
-
Kernel-owned phase timings for one replayed intent. These remain typed all the way to the
framework observability edge so diagnostics cannot become another semantic JSON carrier.
-
VerifyChainStepSpan
-
-
VerifyChainWalk
-
-
VerifyWorkspaceChainRequest
-
-
VerifyWorkspaceChainResult
-
-
WarmProgressResponse
-
One bounded kernel-maintenance quantum. This is runtime procedure state,
not an application value, so every host receives the same closed shape.
-
WatchChanged
-
-
WatchKind
-
-
WatchRequest
-
-
WatchStarted
-
-
WatchStopped
-
-
WorkspaceCandidateCustodyRequired
-
The Peer Office has the workspace's main custody but needs one exact
transport branch before it can judge the offered commits. The platform may
fetch bytes for this ref; it may not inspect or admit them.
-
WorkspaceCustodyRequired
-
-
WorkspaceEffectDeferred
-
Durable mailbox append acknowledgement. Recipient judgment runs independently
of the request, including when the target is already resident. The courier
continues observation until the mailbox returns a completed recipient judgment.
Repeated admission returns the canonical receipt with already_applied set.
-
WorkspaceEffectIdentity
-
-
WorkspaceEffectJudgmentSignature
-
-
WorkspaceEffectReceiptQuery
-
Completion is a kernel observation of the target's admitted main history. An
unavailable history fails the query; it must never be represented as absence.
-
WorkspaceEffectReceiptResponse
-
-
WorkspaceEffectsDelivered
-
-
WorkspaceEffectStatusRequest
-
Workspace Mailbox Service observation. It never submits an offer or changes main.
-
WorkspaceEffectStatusResponse
-
-
WorkspaceFetch
-
-
WorkspaceGenesis
-
-
WorkspaceKernelResidencyRequired
-
-
WorkspaceList
-
-
WorkspaceMoment
-
-
WorkspaceMomentList
-
-
WorkspaceOpening
-
The answer to a paper whose workspace is still being opened. The paper was not executed:
resend it after retry_after_millis. Opening continues regardless of who waits.
-
WorkspaceOutboundRoute
-
-
WorkspacePlacementRequest
-
Desired placement is an independently governed operational frontier owned
by the workspace's retained-replica lifecycle. It is addressed by workspace,
never by an ephemeral interaction session.
-
WorkspacePlacementState
-
-
WorkspaceRebirth
-
Local custody belongs to a different genesis than the one the provider serves.
-
WorkspaceResidencyRequirement
-
A custody dependency the kernel decoded from a sealed intent's typed captured-read envelope.
This is a compute-readiness hint, never authority: the receiving kernel still reopens the named
workspace at source_head and proves the carried result before admission.
-
WorkspaceStatus
-
Observation only: querying status must not acquire custody, connect a session,
or open a workspace. An absent local head says nothing about remote custody.
-
WorkspaceStatusRequest
-
-
WorkspaceSummary
-
The peer's local physical inventory: the union of kernel-resident workspaces
and the replica follows this peer keeps. Observation only: listing never
acquires custody, mounts, fetches, or reads history; its cost is bounded by
the inventory's size.
-
WorkspaceTarget
-
-
WorkspaceTransferEstimate
-
-
WorkspaceTransferKind
-
-
WrapScopeKeyRequest
-
-
WrapScopeKeyResponse
-
-
WriteMetaCommitRequest
-
-
WriteMetaCommitResponse
-
-
WritePreparation
-
Transient observation for one refused, not-yet-admitted generated call. The
office owns recovery; observing this event is never required for correctness.
-
WriteRefRequest
-