Encoded transfer and in-path interception
The scenario
Section titled “The scenario”A sender posts an encoded message to one recipient. The relay carrying it copies the message on the way, reads the whole copy, and fails to decode it with the key it has. The recipient receives the original, has a delegate with the right key decode it, and shares the decoded result with one reviewer.
The question the example answers: how do you keep “holds a copy”, “read it”, and “understood it” apart, and record a decode done on someone else’s behalf so that replay reuses the recorded result?
All holders, times, and content codes are synthetic test values.
What this example shows
Section titled “What this example shows”canwu-information, the information domain extension, and its plannerInformationLifecycle::plan.- A same-content copy: a second
RepresentationwithContentRelation::SameContentand a parent edge to the original. Interpretationrecords withInterpretationStatus::FailedandSucceeded, each bound to the access and representation it read.- Delegated interpretation:
InterpretationAuthority::Delegatedcites a persisted command that carries aDelegationClaimV1. - Knowledge publications, each addressed to one holder
(holder-relative knowledge), plus snapshot
restore, exact replay, and compact checkpoint
restore through
InformationPlugin.
Run it
Section titled “Run it”cargo run -p canwu-information --example encoded_interceptionThe program prints one line once every check has passed; a failed check stops it earlier:
encoded_interception: in-transit copy, failed access interpretation, delegated decode, restricted review release, authoritative save/load, exact replay without external decoding, and compact reconstruction verifiedEach phrase names a group of checks in the source; the last three come from
verify_authoritative_operation_roundtrip in examples/support/mod.rs, run
for the delegated interpretation and for the review release.
How the message moves
Section titled “How the message moves”View diagram source
sequenceDiagram
participant S as Sender H-601
participant R as Relay H-603
participant P as Recipient H-602
participant D as Delegate H-604
participant V as Reviewer H-605
S->>R: dispatch to H-602, attempt InTransit (minutes 2-4)
Note over R: SameContent copy (minute 5)
R->>R: read the copy, decode_k1 fails (minutes 6-7)
R->>P: attempt Delivered, recipient reads (minutes 12-13)
Note over P,D: delegation claim for decode_k2
D-->>P: Succeeded, result content (minutes 14-15)
P->>V: review release Active (minutes 17-19)
Walkthrough
Section titled “Walkthrough”The scenario is in
encoded_interception.rs;
shared helpers are in
support/mod.rs.
Records are planned one request at a time against a detached ledger, as in
Confidential copy and targeted release.
| Holder | Role |
|---|---|
H-601 |
sender |
H-602 |
addressed recipient; commissions the decode and publishes the review release |
H-603 |
relay; copies the message and tries to decode it |
H-604 |
delegate who decodes for H-602 |
H-605 |
reviewer |
1. Encode and send (minutes 0–4)
Section titled “1. Encode and send (minutes 0–4)”The original representation names the capability needed to read it:
payload: RepresentationPayload { format: "grouped_symbols_v1".to_owned(), created_at: minute(1), operation: "encode_k2".to_owned(), content_relation: ContentRelation::SameContent, sources: Vec::new(), claimed_source: None, interpretation_capability: Some("decode_k2".to_owned()),},An addressed Dispatch to H-602 becomes Active. Its DeliveryAttempt
names H-603 under the relay role and moves to InTransit.
2. The relay copies the message (minute 5)
Section titled “2. The relay copies the message (minute 5)”The relay creates a second representation of the same content:
content_relation: ContentRelation::SameContent,sources: vec![RepresentationSourceEdge { parent: encoded.clone(), completeness_per_mille: 1_000, fidelity_per_mille: 1_000,}],SameContent requires the copy to reference the same Content record as its
parent (validate_representation_lineage). The relay also gets its own
Instance of the copy.
3. The relay reads the copy and fails to decode it (minutes 6–7)
Section titled “3. The relay reads the copy and fails to decode it (minutes 6–7)”The relay’s access cites the captured instance and reads the whole copy
(extent_per_mille: 1_000). Its interpretation:
payload: InterpretationPayload { interpreted_at: minute(7), status: InterpretationStatus::Failed, capability: "decode_k1".to_owned(), confidence_per_mille: 0, authenticity: None,},authority: InterpretationAuthority::HolderSelf,The Failed outcome comes from the example. The extension stores capability
and interpretation_capability as labels, and your application decides
whether a decode works. What the extension checks is how the outcome is
recorded (validate_interpretation in
lifecycle.rs):
- every interpretation has
input_access,input_representation,performed_by, andperformed_forreferences, and each input representation is one that an input access read; - a
Failedinterpretation has noresult_content, and aPartialorSucceededone must have it; - with
HolderSelf, the performer and the holder it serves are the same.
The example checks the second rule directly: a Succeeded request without
result_content must fail.
assert!(ledger.plan(&invalid_success_without_result).is_err());4. The original arrives (minutes 12–13)
Section titled “4. The original arrives (minutes 12–13)”The delivery attempt moves to Delivered, which publishes
RepresentationAvailable to H-602. The recipient’s access cites the
delivery_attempt, the dispatch, and the original representation. The
relay’s access cites the captured instance, so the two reads rest on separate
evidence.
5. A delegate decodes for the recipient (minutes 14–15)
Section titled “5. A delegate decodes for the recipient (minutes 14–15)”The decoded result is new content derived from the original, with code
SYN-E8-42-R. The successful interpretation names H-604 as performer,
H-602 as the holder it serves, and binds the result:
holder_reference("performed_by", &performer_holder),holder_reference("performed_for", &destination_holder),DomainReference::from_typed("result_content", decoded_content.clone()),Its authority is delegated:
authority: InterpretationAuthority::Delegated { evidence: EvidenceRef::Command(CommandId::new(1)), authority_grant: DELEGATED_AUTHORITY_GRANT.to_owned(),},The grant DELEGATED_AUTHORITY_GRANT (interpret_for_holder) tells
InformationPlugin to read the claim from the claim key of a
delegate_interpretation_v1 plugin command addressed to canwu-authority. In
the example, CaseAuthorityPlugin in support/mod.rs registers that command,
and the first command of the authoritative run carries this claim:
Some(DelegationClaimV1 { format_version: 1, performed_by: EntityRef::Person(PersonId::new(604)), performed_for: destination_holder.clone(), capabilities: vec!["decode_k2".to_owned()], not_before: Some(SimTime::EPOCH), expires_at: None,}),When it applies the interpretation, the plugin checks that the claim names
this performer, this holder, and this capability, and that the interpretation
time falls in [not_before, expires_at). A claim that fails the check gets
the operation rejected with invalid_authority.
After the authoritative run, only the recipient holds a new fact:
assert_authoritative_knowledge( canwu, &destination_holder, &["interpretation_recorded"],)?;assert_authoritative_knowledge(canwu, &review_holder, &[])?;assert_authoritative_knowledge(canwu, &source_holder, &[])?;assert_authoritative_knowledge(canwu, &performer_holder, &[])For replay, the helper registers PersistedResultReplayPlugin in place of
CaseAuthorityPlugin. Its handler for the same command fails with
ReplayMismatch unless the payload already carries the recorded result, so a
passing replay shows the result came from the journal.
6. Share the result with a reviewer (minutes 16–19)
Section titled “6. Share the result with a reviewer (minutes 16–19)”The delegate renders the result as a review_text_v1 representation. H-602
then creates an explicit audience of H-602 and H-605 and an audience
release of that representation. Activation also runs in Canwu:
assert_authoritative_knowledge(canwu, &destination_holder, &["release_available"])?;assert_authoritative_knowledge(canwu, &review_holder, &["release_available"])?;assert_authoritative_knowledge(canwu, &source_holder, &[])?;assert_authoritative_knowledge(canwu, &performer_holder, &[])What to notice
Section titled “What to notice”- Copy, access, and interpretation are three separate records. The relay holds a full copy and a full read, and still has no decoded content.
- The decode outcome is application input. The extension decides how an outcome must be recorded, including the result binding.
- A delegated decode publishes to the holder it serves. The delegate receives no fact from it.
- The delegation claim lives in a persisted command, so replay checks authority from the journal.
Try changing
Section titled “Try changing”- Add
DomainReference::from_typed("result_content", content.clone())to the relay’s failed interpretation. Planning fails withfailed interpretation cannot have result content. - In the relay’s interpretation, set
performed_fortodestination_holderand keepHolderSelf. Planning fails withself interpretation authority requires performer and holder equality. - In the
DelegationClaimV1, changecapabilitiestovec!["decode_k1".to_owned()]. The detached plan still succeeds, butInformationPluginrejects the operation withinvalid_authority, and the example stops withauthoritative case operation did not complete: Rejected.
Beyond the example
Section titled “Beyond the example”Judging a claimed source
Section titled “Judging a claimed source”A representation can name the source it claims in
RepresentationPayload::claimed_source, and an interpretation of it can record
an authenticity finding (AuthenticityFinding)
in InterpretationPayload::authenticity: whether the claimed source is
accepted, a short basis such as "seal_mismatch", and a confidence. The
finding must cite the current version of a representation that the
interpretation reads and that carries a claimed_source; otherwise
InformationPlugin rejects the operation with invalid_lifecycle. A forged
letter can therefore be recorded as decoded while its claimed sender is
rejected. How likely a holder is to spot a forgery is an application draw (see
Model ownership); this example leaves
authenticity as None, and the
authenticity finding test builds one.
Authority from an assigned role
Section titled “Authority from an assigned role”InterpretationAuthority::InstitutionalRole works like the delegated form,
but reads the claim from an exact version of an AuthorityAssignment record
under the grant interpret_as_assigned_role.
Source
Section titled “Source”Open the runnable example
Read the shared example helpers
Read the interpretation authority tests
Read the authenticity finding test