sigil-wasm · host
Source declarations, signatures and documentation for host.
Source: sigil/node/sigil-wasm/src/host.rs. SHA-256: c009efdf30d5d0019c0b66e0490db798645fd74d43be2d5c2392244040909c1d.
This reference follows declared source modules, retains conditional attributes, and includes public declarations and implementation methods. Private-module re-exports and trait resolution require the compiler; this is a source reference, not a claim that every listed item is a root import. Function bodies and constant values are omitted.
host::capability
The set of capabilities a contract may exercise during a call.
Read by the host adapter when the guest invokes a privileged host
function and either checked against ContractRecord.allowed_host_functions
in advance, or enforced by the backend before mutating any state.
pub mod capability;Source line: 23.
host::capability::STATE_GET
pub const STATE_GET: &str;Source line: 24.
host::capability::STATE_SET
pub const STATE_SET: &str;Source line: 25.
host::capability::STATE_DELETE
pub const STATE_DELETE: &str;Source line: 26.
host::capability::CALLER_DID
pub const CALLER_DID: &str;Source line: 27.
host::capability::BLOCK_HEIGHT
pub const BLOCK_HEIGHT: &str;Source line: 28.
host::capability::NATIVE_TRANSFER
pub const NATIVE_TRANSFER: &str;Source line: 29.
host::capability::LOG
pub const LOG: &str;Source line: 30.
host::capability::EMIT_EVENT
pub const EMIT_EVENT: &str;Source line: 31.
host::capability::RESOLVE_IDENTITY
pub const RESOLVE_IDENTITY: &str;Source line: 32.
host::capability::VERIFY_LINEAGE
pub const VERIFY_LINEAGE: &str;Source line: 33.
host::capability::SEND_ZONE_MESSAGE
pub const SEND_ZONE_MESSAGE: &str;Source line: 34.
host::capability::DISPATCH_COMPUTE
pub const DISPATCH_COMPUTE: &str;Source line: 35.
host::capability::RECORD_MANDATE_SPEND
pub const RECORD_MANDATE_SPEND: &str;Source line: 36.
host::capability::READ_COMPUTE_RECEIPT
pub const READ_COMPUTE_RECEIPT: &str;Source line: 37.
host::capability::READ_MACA_QUORUM_PROOF
pub const READ_MACA_QUORUM_PROOF: &str;Source line: 38.
host::HostLogLevel
Minimal log levels — match sigil_execution::anvil::LogLevel ordinal.
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
pub enum HostLogLevel {
Debug = 0,
Info = 1,
Warn = 2,
Error = 3,
}Source line: 43.
host::HostLogLevel::from_u32
Decode from the level integer that crosses the WASM boundary.
pub fn from_u32(v: u32) -> Self;Source line: 52.
host::HostBackend
Sigil chain backend exposed to a single contract invocation.
Each call gets its own HostBackend reference; implementors are
expected to provide commit/rollback semantics around the backend
(e.g. by writing into an overlay that is only flushed on success).
pub trait HostBackend: Send + Sync {
/// The DID of the contract currently executing. The runtime passes
/// this on every call so the backend can scope state, events, and
/// authorization checks per contract.
fn contract_did(&self) -> &str;
/// Returns `true` if `host_fn` is in the contract's allowlist.
/// Implementations should always check the live contract record;
/// this is consulted by the runtime as a defense-in-depth gate
/// before invoking the actual backend method.
fn allows_host_fn(&self, host_fn: &str) -> bool;
/// DID of the account/app that submitted the current contract call.
///
/// This is consensus input carried by the signed `CallContract`
/// transaction, not ambient process state.
fn caller_did(&self) -> &str ;
/// Current finalized block height visible to this contract call.
fn block_height(&self) -> Result<u64, HostError> ;
/// Transfer native micro-MINT from this contract's account to `recipient`.
///
/// Backends must stage the debit/credit and commit it only if the enclosing
/// WASM call succeeds.
fn native_transfer(&mut self, _recipient: &str, _amount: u64) -> Result<(), HostError> ;
// --- State (always permitted; gated by allowlist anyway) -------
fn state_get(&mut self, key: &[u8]) -> Result<Option<Vec<u8>>, HostError>;
fn state_set(&mut self, key: &[u8], value: &[u8]) -> Result<(), HostError>;
fn state_delete(&mut self, key: &[u8]) -> Result<(), HostError>;
// --- Logging + events -----------------------------------------
fn log(&mut self, level: HostLogLevel, message: &str);
fn emit_event(
&mut self,
topic: &str,
indexed: &[(String, Vec<u8>)],
data: &[u8],
) -> Result<(), HostError>;
// --- Identity (read-only) -------------------------------------
/// Resolve the OAS identity document for `did`. `None` if not
/// registered. Consensus-deterministic implementations must read
/// from on-chain identity storage, not from off-chain resolvers.
fn resolve_identity(&self, did: &str) -> Result<Option<Vec<u8>>, HostError>;
/// Verify that `did` has a valid lineage chain back to a registered
/// human root. Returns `true` if the chain validates against
/// on-chain identity storage. Pure read-only.
fn verify_lineage(&self, did: &str) -> Result<bool, HostError>;
// --- Cross-zone messaging -------------------------------------
/// Queue a message for `target_zone`. Must NOT execute the target
/// inline — message delivery is a separate consensus step.
fn send_zone_message(
&mut self,
target_zone: &str,
target_module: Option<&str>,
payload: &[u8],
) -> Result<(), HostError>;
// --- Compute marketplace (privileged) -------------------------
/// Dispatch a compute job into the marketplace. The backend must
/// verify that:
/// - the contract has an active mandate / budget
/// - the requested verification tier is supported by at least one
/// registered provider
/// - the call site holds the `dispatch_compute` capability
///
/// Returns the assigned `job_id` on success.
fn dispatch_compute(&mut self, request: &ComputeDispatchRequest) -> Result<String, HostError>;
/// Charge the contract's mandate by `amount` micro-MINT. Used by
/// non-compute spend paths (e.g. paying a service contract).
fn record_mandate_spend(
&mut self,
mandate_id: &str,
amount: u64,
memo: Option<&str>,
) -> Result<(), HostError>;
// --- Verified read paths --------------------------------------
/// Return the receipt record for `receipt_id`, or `None`. The
/// backend MUST only return receipts that are settled and within
/// the chain's challenge window (or already past it).
fn read_compute_receipt(&self, receipt_id: &str) -> Result<Option<ReceiptView>, HostError>;
/// Return a MACA quorum proof for a (epoch_id, work_id) tuple, or
/// `None`. The backend MUST only return finalised quorum proofs.
fn read_maca_quorum_proof(
&self,
epoch_id: u64,
work_id: &SigilHash,
) -> Result<Option<MacaQuorumProofView>, HostError>;
}Source line: 67.
host::ReceiptView
Minimal view of a settled compute receipt exposed to contract code.
Avoids dragging the full ComputeReceipt (with private fields like
signatures) into the WASM ABI.
#[derive(Debug, Clone, PartialEq, Eq, serde::Serialize, serde::Deserialize)]
pub struct ReceiptView {
pub receipt_id: String,
pub job_id: String,
pub provider_did: String,
pub consumer_did: String,
pub model_id: String,
pub output_commitment: SigilHash,
pub input_commitment: SigilHash,
pub model_commitment: Option<SigilHash>,
pub verification_tier: String,
pub cost_micro_mint: u64,
pub settled: bool
}Source line: 184.
host::MacaQuorumProofView
Minimal view of a MACA quorum proof exposed to contract code.
#[derive(Debug, Clone, PartialEq, Eq, serde::Serialize, serde::Deserialize)]
pub struct MacaQuorumProofView {
pub epoch_id: u64,
pub work_id: SigilHash,
pub agreeing: u32,
pub total_validators: u32,
pub finalised: bool
}Source line: 200.
host::ComputeDispatchRequest
Compute job request issued by a contract via dispatch_compute.
#[derive(Debug, Clone, PartialEq, Eq, serde::Serialize, serde::Deserialize)]
pub struct ComputeDispatchRequest {
pub model_id: String,
pub input_commitment: SigilHash,
pub code_commitment: Option<SigilHash>,
pub model_commitment: Option<SigilHash>,
pub max_cost_micro_mint: u64,
pub verification_tier: String,
pub mandate_id: String
}Source line: 210.