pub struct Label {
pub provenance: BTreeSet<SourceId>,
pub trust: Trust,
pub sensitivity: Sensitivity,
}Expand description
A value’s position in the information-flow lattice.
A pure product of three joins — provenance unions, trust degrades,
sensitivity escalates. Release marks are deliberately not part of a
label: a mark is scoped to the one value a release was granted over, while
a label flows through every join a derived value is built from, so a mark
stored here would ride any bare join onto data it never covered unless
every call site remembered to strip it. Marks live on Tainted instead,
where the operations that can prove value lineage — projection, assembly,
transformation — are the only ways to move one.
Fields§
§provenance: BTreeSet<SourceId>§trust: Trust§sensitivity: SensitivityImplementations§
Source§impl Label
impl Label
Sourcepub fn untrusted(source: SourceId) -> Self
pub fn untrusted(source: SourceId) -> Self
A value that crossed a trust boundary — every tool result, every retrieval, every peer response, including from first-party services. A compromised internal service is exactly what this exists for.
pub fn with_sensitivity(self, s: Sensitivity) -> Self
Sourcepub fn join(&self, other: &Self) -> Self
pub fn join(&self, other: &Self) -> Self
Bounded join-semilattice: trust degrades, sensitivity escalates, provenance accumulates.
Nothing else rides a join. In particular a join can never transport a
release: marks live on Tainted, not here, so combining labels —
however a caller does it — cannot extend a grant to data the release
never covered.
pub fn is_untrusted(&self) -> bool
Trait Implementations§
Source§impl<'de> Deserialize<'de> for Label
impl<'de> Deserialize<'de> for Label
Source§fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
impl Eq for Label
impl StructuralPartialEq for Label
Auto Trait Implementations§
impl Freeze for Label
impl RefUnwindSafe for Label
impl Send for Label
impl Sync for Label
impl Unpin for Label
impl UnsafeUnpin for Label
impl UnwindSafe for Label
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> DeserializeOwned for Twhere
T: for<'de> Deserialize<'de>,
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
key and return true if they are equal.Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more