Sigil documentation
ReferenceRust referencesigil-anomaly

sigil-anomaly · rule

Source declarations, signatures and documentation for rule.

Source: sigil/node/sigil-anomaly/src/rule.rs. SHA-256: 102aea2a060c3ff2ceff53e276010f922d63c5b0d5a9a78121b028a4cb4b9286.

This reference follows declared source modules, retains conditional attributes, and includes public declarations and implementation methods. Private-module re-exports and trait resolution require the compiler; this is a source reference, not a claim that every listed item is a root import. Function bodies and constant values are omitted.

rule::RuleId

Content-addressed rule identifier.

A rule's id is the BLAKE3 hash of its canonical serialized definition. Two rules with the same logic but different configurations have different ids. This makes rule sets auditable and reproducible.

#[derive(Debug, Clone, Copy, PartialEq, Eq, PartialOrd, Ord, Hash, Serialize, Deserialize)]
pub struct RuleId([u8; 32]);

Source line: 21.

rule::RuleId::from_blake3

pub fn from_blake3(hash: [u8; 32]) -> Self;

Source line: 24.

rule::RuleId::as_bytes

pub fn as_bytes(&self) -> &[u8; 32];

Source line: 28.

rule::RuleId::to_hex

pub fn to_hex(&self) -> String;

Source line: 32.

rule::RuleMetadata

Metadata supplied at rule registration.

#[derive(Debug, Clone, Serialize, Deserialize)]
pub struct RuleMetadata {
/// Human-readable name. Not consensus-binding.

pub name: String,
/// Description of what the rule detects.

pub description: String,
/// Schema version of the rule's evidence payload.

pub evidence_schema_version: u32,
/// Snapshot view keys the rule requires. Used by `RuleSet::evaluate`

/// to fail fast if the supplied view is missing required keys.

pub required_snapshot_keys: Vec<String>
}

Source line: 51.

rule::AnomalyRule

The core rule trait.

Implementors are pure functions: given a transaction (read-only) and a snapshot view (read-only, explicitly versioned), they return zero or more flags or an error.

**Implementation contract:

  • evaluate must be deterministic: the same (tx, view) always produces the same output.
  • evaluate must not perform I/O, read clocks, sample randomness, or maintain hidden state across calls.
  • evaluate must complete in bounded time. The validator-agent runtime budgets <1ms per rule per transaction; rules that exceed this are sampling candidates for de-registration.
  • id() must return the BLAKE3 hash of the rule's canonical serialized definition. Two registrations with the same id are rejected.
pub trait AnomalyRule: Send + Sync {
    /// Stable, content-addressed identifier.
    fn id(&self) -> RuleId;

    /// Metadata describing the rule.
    fn metadata(&self) -> &RuleMetadata;

    /// Evaluate the rule against a transaction and snapshot view.
    ///
    /// The transaction is referenced by its canonical wire form
    /// (serialized bytes) plus its BLAKE3 hash. Rules that need to
    /// inspect transaction structure should parse the bytes themselves
    /// using `sigil-core`'s schema; the trait stays decoupled from
    /// `sigil-core`'s evolving type surface.
    fn evaluate(
        &self,
        tx_bytes: &[u8],
        tx_hash: &[u8; 32],
        view: &SnapshotView,
    ) -> Result<Vec<Flag>>;
}

Source line: 81.

On this page