Skip to content

RF symbols name architecture semantics. They are distinct from traversals, which read instance or verified saved-plan evidence at a specified language position.

Canonical symbol IDs

EBNF
symbol-id = owner, ".", kind, ".", name ;
kind = "concept" | "context" | "relation" | "rule" ;
local-reference = kind, ".", name ;
PartMeaningExample
ownerDialect owner or embedded rf owneraws
kindClosed semantic kindconcept
nameLowercase kebab-case identifierload-balancer

Examples of canonical IDs:

IDOwnerKindName
aws.rule.subnetawsrulesubnet
aws.relation.subscribes-toawsrelationsubscribes-to
google.concept.load-balancergoogleconceptload-balancer
rf.context.networkrfcontextnetwork

Slash-separated IDs and untyped free strings are not symbol references.

Reference syntax by position

PositionAccepted kindLocal syntaxQualified syntax
Rule asConceptconcept.applicationCurrent owner or rf
Context emission asContextcontext.runtimeCurrent owner or rf
Relation emission asRelationrelation.uses-networkCurrent owner only in 0.1.0
Emission toConcept or Ruleconcept.database, rule.databaseCurrent owner or allowed rf Concept
Policy target.conceptConceptNot acceptedAny linked qualified owner
Policy target.rules itemRuleNot acceptedAny linked qualified Dialect owner
contexts first argumentContextNot accepted in Policy sourceAny linked qualified owner
relations first argumentRelationNot accepted in Policy sourceAny linked qualified owner
Query target or contributorConcept or RuleNot accepted in Policy sourceAny linked qualified owner

RF Vocabulary currently contains Concepts and Contexts only. Therefore an rf.relation.* or rf.rule.* reference is invalid.

Dialect resolution

Inside a Dialect:

  1. kind.name resolves only against current Dialect.
  2. owner.kind.name may name current owner or rf.
  3. A local miss does not fall back to rf.
  4. A reference to another Dialect owner is rejected.
  5. There are no imports, aliases, wildcard references, or shadowing rules.
reference syntax RF
rule "subnet" {
match {
type = "example_subnet"
}
as = rf.concept.subnet
context {
as = rf.context.network
to = concept.virtual-network
via = source.network_id
on_null = "absent"
on_empty = "absent"
}
}

Here, concept.virtual-network means current Dialect's Concept. It does not mean rf.concept.virtual-network.

Policy Pack resolution

Every semantic reference in Policy source must be owner-qualified:

qualified Policy references RF
target {
concept = rf.concept.subnet
rules = [aws.rule.subnet]
}
assert = exists(contexts(rf.context.network, rf.concept.virtual-network))

Portable Policy Pack source carries references, not version pins. Compilation against a Form resolves each reference and derives exact semantic pins. Unknown owners or symbols fail linking.

Collection and duplicates

Dialect compilation has two passes. Compiler first collects definitions, then resolves references. A Rule may therefore reference a definition in a later file.

CaseResult
Same top-level Concept declared twiceDUPLICATE_ID
Same top-level Context declared twiceDUPLICATE_ID
Same top-level Relation declared twiceDUPLICATE_ID
Same Rule declared twiceDUPLICATE_ID
Same labeled context emission reused by several RulesOne shared local Context symbol
Same labeled relation emission reused by several RulesOne shared local Relation symbol
Top-level Context plus matching labeled context emissionsOne documented Context symbol
Top-level Relation plus matching labeled relation emissionsOne documented Relation symbol

Labeled emissions can introduce local Context or Relation symbols. Concepts are never introduced implicitly: every Concept must have an explicit top-level definition or come from RF Vocabulary.

Rejected syntax

invalid references RF
as = subnet
as = rf/subnet
as = other.concept.subnet

These fail because references are typed and dotted, and a Dialect cannot import a foreign owner. A Policy reference such as concept.subnet fails with POLICY_REFERENCE_UNQUALIFIED.