sigil-anomaly · flag
Source declarations, signatures and documentation for flag.
Source: sigil/node/sigil-anomaly/src/flag.rs. SHA-256: 866b863e701fb01cf1d21fdef7d12a7d1cafdebfc464d51b36edea3e1ed105a4.
This reference follows declared source modules, retains conditional attributes, and includes public declarations and implementation methods. Private-module re-exports and trait resolution require the compiler; this is a source reference, not a claim that every listed item is a root import. Function bodies and constant values are omitted.
flag::FlagSeverity
Severity classification for an anomaly flag.
Severity drives sampling weight in the validator-agent runtime: higher
severity flags are more likely to escalate to L2 small-model triage,
and Critical flags are typically escalated to L3 immediately.
#[derive(Debug, Clone, Copy, PartialEq, Eq, Hash, Serialize, Deserialize)]
#[serde(rename_all = "lowercase")]
pub enum FlagSeverity {
/// Heuristic match. Common; high false-positive rate. Sampled lightly.
Info,
/// Notable deviation from typical traffic shape.
Low,
/// Strong heuristic signal; warrants L2 attention.
Medium,
/// Pattern matches a known attack class. L2 + L3 attention.
High,
/// Severe deviation. Direct L3 escalation; possible L4 incident.
Critical,
}Source line: 18.
flag::Flag
A flag emitted by an anomaly rule.
Flags carry the rule's content-addressed id, the transaction hash that triggered the rule, severity, and an optional payload of rule-specific evidence. Payload format is opaque to the validator agent; downstream consumers (L2/L3) parse it according to the rule's declared schema.
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
pub struct Flag {
/// Content-addressed id of the rule that emitted this flag.
pub rule_id: RuleId,
/// Transaction hash (BLAKE3-32) the rule evaluated against.
pub tx_hash: [u8; 32],
/// Severity of the flag.
pub severity: FlagSeverity,
/// Block height at which the snapshot view was taken. The rule did
/// not read live state; this is the explicit version label.
pub snapshot_height: u64,
/// Opaque rule-specific evidence payload. Canonical JSON.
pub evidence_json: String
}Source line: 39.
flag::Flag::bare
Build a flag with empty evidence.
pub fn bare(
rule_id: RuleId,
tx_hash: [u8; 32],
severity: FlagSeverity,
snapshot_height: u64,
) -> Self;Source line: 55.
flag::Flag::with_evidence
Build a flag with a JSON-serializable evidence payload.
pub fn with_evidence<E: Serialize>(
rule_id: RuleId,
tx_hash: [u8; 32],
severity: FlagSeverity,
snapshot_height: u64,
evidence: &E,
) -> std::result::Result<Self, serde_json::Error>;Source line: 71.