Skip to main content

Standard Predicates

Predicates are the building blocks for governing-model transitions and contract rules. The local contract-log validator enforces the predicates below from replayable commit artifacts: the pending commit body, the pending commit signatures, and the already accepted contract state.

Current Local Evidence Matrix

These are the predicate and label facts currently used by the first-contract local validator path.

FactEvidence sourceCurrent-state rule
+POST, +MODEL, and other method labelsPending commit body methodsChecked on the pending commit
signed_by(/path.id)Pending commit signatures plus the public key string at /path.id in accepted stateReads previously committed state, not values written by the same commit
any_signed(/path)Pending commit signatures plus every accepted-state *.id file under /pathAt least one listed identity must sign
all_signed(/path)Pending commit signatures plus every accepted-state *.id file under /pathThe directory must contain at least one identity, and every listed identity must sign
threshold("n", /path)Pending commit signatures plus every accepted-state *.id file under /pathAt least n unique listed identities must sign
modifies(/path)Pending commit body pathsMatches /path itself or descendants such as /path/alice.id

Other reference predicates below describe the intended standard vocabulary. Treat them as requiring predicate-specific implementation and tests before using them in the local first-contract path.

Implementation Status

Use this table to distinguish the predicate vocabulary from the predicates currently enforced by the local first-contract validator.

Predicate familyLocal first-contract validatorNotes
Method labels such as +POST and +MODELEnforcedDerived from pending commit body methods
signed_by, any_signed, all_signed, threshold, modifiesEnforcedDerived from pending signatures, accepted state, and modified paths
before, after, state predicates, hash predicates, oracle_attests, and wasmNot first-contract-local yetIntended extension vocabulary; treat as external or future predicate checks unless a validator path explicitly documents support

Path Predicates

modifies

Checks if the commit writes to paths under a given prefix.

+modifies(/members)

Arguments:

  • path — Path prefix to check

Behavior:

  • Returns true if any path in the commit body starts with the given prefix
  • Used for path-based access control rules

Example:

// Only allow membership changes if all members sign
always(![+modifies(/members)] true | <+all_signed(/members)> true)

Signature Predicates

signed_by

Verifies the commit is signed by a specific ed25519 key.

+signed_by(/users/alice.id)

Arguments:

  • path — Path to the public key in contract state

Behavior:

  • Looks up the public key string at path in the accepted contract state
  • Passes if the pending commit includes a matching signature
  • Does not see identity files written by the same pending commit

any_signed

Verifies at least one member from a path has signed.

+any_signed(/members)

Arguments:

  • path — Path prefix containing member public keys

Behavior:

  • Enumerates all .id files under the path
  • Passes if ANY member has a valid signature
  • Used for "any member can act" patterns

all_signed

Verifies ALL members from a path have signed.

+all_signed(/members)

Arguments:

  • path — Path prefix containing member public keys

Behavior:

  • Enumerates all .id files under the path
  • Passes only if EVERY member has a valid signature
  • Fails when the path contains no .id members
  • Used for "unanimous consent" patterns like adding members

threshold

Verifies n-of-m signatures from the accepted identities under a path.

+threshold("2", /treasury/signers)

Arguments:

  • n — Minimum signatures required
  • signers_path — Path prefix containing signer public keys in *.id files

Behavior:

  • Enumerates all .id files under the path in accepted contract state
  • Counts each authorized public key at most once
  • Ignores commit signatures from keys that are not listed under the path
  • Passes when at least n unique listed identities signed the pending commit
  • Rejection output reports the authorized signature count, accepted member count, missing signature count, and any unauthorized signatures that were ignored

Time Predicates

before

Intended predicate for checking that current time is before a deadline.

before(/deadlines/expiry.datetime)

after

Intended predicate for checking that current time is after a timestamp.

after(/deadlines/start.datetime)

State Predicates

bool_true / bool_false

Intended predicates for checking boolean state values.

bool_true(/status/delivered.bool)
bool_false(/flags/cancelled.bool)

text_eq

Intended predicate for comparing text values.

text_eq(/status.text, "approved")

num_eq / num_gt / num_gte / num_lt / num_lte

Intended predicates for numeric comparisons.

num_gte(/balance.num, 100)
num_lt(/deposit.num, /limit.num)

Oracle Predicates

oracle_attests

Intended predicate for checking a signed attestation from a trusted oracle. This is external evidence vocabulary until a validator path documents the attestation format, freshness rule, replay binding, and signature check.

oracle_attests(/oracles/delivery.id, "delivered", "true")

Arguments:

  • oracle_path — Path to oracle's public key
  • claim — The claim type being attested
  • value — Expected value (optional)

Security features:

  • Should verify oracle signatures
  • Should enforce attestation freshness
  • Should bind attestations to a specific contract
  • Should prevent replay attacks

Hash Predicates

hash_matches

Intended predicate for checking a SHA256 hash commitment.

hash_matches(/commitments/secret.hash, /revealed/value.text)

Using Predicates in Rules

Predicates are combined with logical operators in rule formulas:

export default rule {
starting_at $PARENT
formula {
// All commits must be signed by alice OR bob
always(<+signed_by(/users/alice.id)> true | <+signed_by(/users/bob.id)> true)
}
}

export default rule {
starting_at $PARENT
formula {
// After deadline, only buyer can commit
always(!<+after(/deadlines/expiry.datetime)> true | <+signed_by(/users/buyer.id)> true)
}
}

Transition predicates use the same predicate names inside governing models:

pending -> executed [+threshold("2", /treasury/signers)]

Custom WASM Predicates

WASM predicates are intended custom predicate modules. They are not part of the current local first-contract validator evidence matrix.

modal predicate create --name my_predicate --output ./predicates/

Then reference in contracts:

wasm(/predicates/my_predicate.wasm, arg1, arg2)