Expand description
Host policy — the optional loop-policy.json (proposal §6.2). It is the
only place auto-apply is granted, and it is host config (per-process,
never persisted in a memory file). All fields default-closed; the whole
struct rejects unknown keys, so a policy that tries to register an
executable (--analyzer-cmd) or touch a trust-floor field fails to load —
a stolen or committed policy file must be inert.
Precedence (enforced by the engine): engine ceilings > host CLI flags > this policy file > memory-file config. “The file selects and restricts; only the host grants.”
Structs§
- Auto
Apply Grant - One auto-apply grant: an analyzer family may auto-apply to these target
classes up to (and including)
max_severity. - Policy
- The parsed host policy. Everything default-closed.
Enums§
- Telemetry
Mode - Telemetry sidecar mode (host-only).