Sigil documentation
ReferenceRust referencesigil-wasm

sigil-wasm · host

Source declarations, signatures and documentation for host.

Source: sigil/node/sigil-wasm/src/host.rs. SHA-256: c009efdf30d5d0019c0b66e0490db798645fd74d43be2d5c2392244040909c1d.

This reference follows declared source modules, retains conditional attributes, and includes public declarations and implementation methods. Private-module re-exports and trait resolution require the compiler; this is a source reference, not a claim that every listed item is a root import. Function bodies and constant values are omitted.

host::capability

The set of capabilities a contract may exercise during a call.

Read by the host adapter when the guest invokes a privileged host function and either checked against ContractRecord.allowed_host_functions in advance, or enforced by the backend before mutating any state.

pub mod capability;

Source line: 23.

host::capability::STATE_GET

pub const STATE_GET: &str;

Source line: 24.

host::capability::STATE_SET

pub const STATE_SET: &str;

Source line: 25.

host::capability::STATE_DELETE

pub const STATE_DELETE: &str;

Source line: 26.

host::capability::CALLER_DID

pub const CALLER_DID: &str;

Source line: 27.

host::capability::BLOCK_HEIGHT

pub const BLOCK_HEIGHT: &str;

Source line: 28.

host::capability::NATIVE_TRANSFER

pub const NATIVE_TRANSFER: &str;

Source line: 29.

host::capability::LOG

pub const LOG: &str;

Source line: 30.

host::capability::EMIT_EVENT

pub const EMIT_EVENT: &str;

Source line: 31.

host::capability::RESOLVE_IDENTITY

pub const RESOLVE_IDENTITY: &str;

Source line: 32.

host::capability::VERIFY_LINEAGE

pub const VERIFY_LINEAGE: &str;

Source line: 33.

host::capability::SEND_ZONE_MESSAGE

pub const SEND_ZONE_MESSAGE: &str;

Source line: 34.

host::capability::DISPATCH_COMPUTE

pub const DISPATCH_COMPUTE: &str;

Source line: 35.

host::capability::RECORD_MANDATE_SPEND

pub const RECORD_MANDATE_SPEND: &str;

Source line: 36.

host::capability::READ_COMPUTE_RECEIPT

pub const READ_COMPUTE_RECEIPT: &str;

Source line: 37.

host::capability::READ_MACA_QUORUM_PROOF

pub const READ_MACA_QUORUM_PROOF: &str;

Source line: 38.

host::HostLogLevel

Minimal log levels — match sigil_execution::anvil::LogLevel ordinal.

#[derive(Debug, Clone, Copy, PartialEq, Eq)]
pub enum HostLogLevel {
    Debug = 0,
    Info = 1,
    Warn = 2,
    Error = 3,
}

Source line: 43.

host::HostLogLevel::from_u32

Decode from the level integer that crosses the WASM boundary.

pub fn from_u32(v: u32) -> Self;

Source line: 52.

host::HostBackend

Sigil chain backend exposed to a single contract invocation.

Each call gets its own HostBackend reference; implementors are expected to provide commit/rollback semantics around the backend (e.g. by writing into an overlay that is only flushed on success).

pub trait HostBackend: Send + Sync {
    /// The DID of the contract currently executing. The runtime passes
    /// this on every call so the backend can scope state, events, and
    /// authorization checks per contract.
    fn contract_did(&self) -> &str;

    /// Returns `true` if `host_fn` is in the contract's allowlist.
    /// Implementations should always check the live contract record;
    /// this is consulted by the runtime as a defense-in-depth gate
    /// before invoking the actual backend method.
    fn allows_host_fn(&self, host_fn: &str) -> bool;

    /// DID of the account/app that submitted the current contract call.
    ///
    /// This is consensus input carried by the signed `CallContract`
    /// transaction, not ambient process state.
    fn caller_did(&self) -> &str ;

    /// Current finalized block height visible to this contract call.
    fn block_height(&self) -> Result<u64, HostError> ;

    /// Transfer native micro-MINT from this contract's account to `recipient`.
    ///
    /// Backends must stage the debit/credit and commit it only if the enclosing
    /// WASM call succeeds.
    fn native_transfer(&mut self, _recipient: &str, _amount: u64) -> Result<(), HostError> ;

    // --- State (always permitted; gated by allowlist anyway) -------

    fn state_get(&mut self, key: &[u8]) -> Result<Option<Vec<u8>>, HostError>;
    fn state_set(&mut self, key: &[u8], value: &[u8]) -> Result<(), HostError>;
    fn state_delete(&mut self, key: &[u8]) -> Result<(), HostError>;

    // --- Logging + events -----------------------------------------

    fn log(&mut self, level: HostLogLevel, message: &str);
    fn emit_event(
        &mut self,
        topic: &str,
        indexed: &[(String, Vec<u8>)],
        data: &[u8],
    ) -> Result<(), HostError>;

    // --- Identity (read-only) -------------------------------------

    /// Resolve the OAS identity document for `did`. `None` if not
    /// registered. Consensus-deterministic implementations must read
    /// from on-chain identity storage, not from off-chain resolvers.
    fn resolve_identity(&self, did: &str) -> Result<Option<Vec<u8>>, HostError>;

    /// Verify that `did` has a valid lineage chain back to a registered
    /// human root. Returns `true` if the chain validates against
    /// on-chain identity storage. Pure read-only.
    fn verify_lineage(&self, did: &str) -> Result<bool, HostError>;

    // --- Cross-zone messaging -------------------------------------

    /// Queue a message for `target_zone`. Must NOT execute the target
    /// inline — message delivery is a separate consensus step.
    fn send_zone_message(
        &mut self,
        target_zone: &str,
        target_module: Option<&str>,
        payload: &[u8],
    ) -> Result<(), HostError>;

    // --- Compute marketplace (privileged) -------------------------

    /// Dispatch a compute job into the marketplace. The backend must
    /// verify that:
    ///   - the contract has an active mandate / budget
    ///   - the requested verification tier is supported by at least one
    ///     registered provider
    ///   - the call site holds the `dispatch_compute` capability
    ///
    /// Returns the assigned `job_id` on success.
    fn dispatch_compute(&mut self, request: &ComputeDispatchRequest) -> Result<String, HostError>;

    /// Charge the contract's mandate by `amount` micro-MINT. Used by
    /// non-compute spend paths (e.g. paying a service contract).
    fn record_mandate_spend(
        &mut self,
        mandate_id: &str,
        amount: u64,
        memo: Option<&str>,
    ) -> Result<(), HostError>;

    // --- Verified read paths --------------------------------------

    /// Return the receipt record for `receipt_id`, or `None`. The
    /// backend MUST only return receipts that are settled and within
    /// the chain's challenge window (or already past it).
    fn read_compute_receipt(&self, receipt_id: &str) -> Result<Option<ReceiptView>, HostError>;

    /// Return a MACA quorum proof for a (epoch_id, work_id) tuple, or
    /// `None`. The backend MUST only return finalised quorum proofs.
    fn read_maca_quorum_proof(
        &self,
        epoch_id: u64,
        work_id: &SigilHash,
    ) -> Result<Option<MacaQuorumProofView>, HostError>;
}

Source line: 67.

host::ReceiptView

Minimal view of a settled compute receipt exposed to contract code. Avoids dragging the full ComputeReceipt (with private fields like signatures) into the WASM ABI.

#[derive(Debug, Clone, PartialEq, Eq, serde::Serialize, serde::Deserialize)]
pub struct ReceiptView {
pub receipt_id: String,
pub job_id: String,
pub provider_did: String,
pub consumer_did: String,
pub model_id: String,
pub output_commitment: SigilHash,
pub input_commitment: SigilHash,
pub model_commitment: Option<SigilHash>,
pub verification_tier: String,
pub cost_micro_mint: u64,
pub settled: bool
}

Source line: 184.

host::MacaQuorumProofView

Minimal view of a MACA quorum proof exposed to contract code.

#[derive(Debug, Clone, PartialEq, Eq, serde::Serialize, serde::Deserialize)]
pub struct MacaQuorumProofView {
pub epoch_id: u64,
pub work_id: SigilHash,
pub agreeing: u32,
pub total_validators: u32,
pub finalised: bool
}

Source line: 200.

host::ComputeDispatchRequest

Compute job request issued by a contract via dispatch_compute.

#[derive(Debug, Clone, PartialEq, Eq, serde::Serialize, serde::Deserialize)]
pub struct ComputeDispatchRequest {
pub model_id: String,
pub input_commitment: SigilHash,
pub code_commitment: Option<SigilHash>,
pub model_commitment: Option<SigilHash>,
pub max_cost_micro_mint: u64,
pub verification_tier: String,
pub mandate_id: String
}

Source line: 210.

On this page