Sigil documentation
ReferenceRust referencesigil-anomaly

sigil-anomaly · flag

Source declarations, signatures and documentation for flag.

Source: sigil/node/sigil-anomaly/src/flag.rs. SHA-256: 866b863e701fb01cf1d21fdef7d12a7d1cafdebfc464d51b36edea3e1ed105a4.

This reference follows declared source modules, retains conditional attributes, and includes public declarations and implementation methods. Private-module re-exports and trait resolution require the compiler; this is a source reference, not a claim that every listed item is a root import. Function bodies and constant values are omitted.

flag::FlagSeverity

Severity classification for an anomaly flag.

Severity drives sampling weight in the validator-agent runtime: higher severity flags are more likely to escalate to L2 small-model triage, and Critical flags are typically escalated to L3 immediately.

#[derive(Debug, Clone, Copy, PartialEq, Eq, Hash, Serialize, Deserialize)]
#[serde(rename_all = "lowercase")]
pub enum FlagSeverity {
    /// Heuristic match. Common; high false-positive rate. Sampled lightly.
    Info,
    /// Notable deviation from typical traffic shape.
    Low,
    /// Strong heuristic signal; warrants L2 attention.
    Medium,
    /// Pattern matches a known attack class. L2 + L3 attention.
    High,
    /// Severe deviation. Direct L3 escalation; possible L4 incident.
    Critical,
}

Source line: 18.

flag::Flag

A flag emitted by an anomaly rule.

Flags carry the rule's content-addressed id, the transaction hash that triggered the rule, severity, and an optional payload of rule-specific evidence. Payload format is opaque to the validator agent; downstream consumers (L2/L3) parse it according to the rule's declared schema.

#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
pub struct Flag {
/// Content-addressed id of the rule that emitted this flag.

pub rule_id: RuleId,
/// Transaction hash (BLAKE3-32) the rule evaluated against.

pub tx_hash: [u8; 32],
/// Severity of the flag.

pub severity: FlagSeverity,
/// Block height at which the snapshot view was taken. The rule did

/// not read live state; this is the explicit version label.

pub snapshot_height: u64,
/// Opaque rule-specific evidence payload. Canonical JSON.

pub evidence_json: String
}

Source line: 39.

flag::Flag::bare

Build a flag with empty evidence.

pub fn bare(
        rule_id: RuleId,
        tx_hash: [u8; 32],
        severity: FlagSeverity,
        snapshot_height: u64,
    ) -> Self;

Source line: 55.

flag::Flag::with_evidence

Build a flag with a JSON-serializable evidence payload.

pub fn with_evidence<E: Serialize>(
        rule_id: RuleId,
        tx_hash: [u8; 32],
        severity: FlagSeverity,
        snapshot_height: u64,
        evidence: &E,
    ) -> std::result::Result<Self, serde_json::Error>;

Source line: 71.

On this page