Skip to main content

Module policy

Module policy 

Source
Expand description

Host policy — the optional loop-policy.json (proposal §6.2). It is the only place auto-apply is granted, and it is host config (per-process, never persisted in a memory file). All fields default-closed; the whole struct rejects unknown keys, so a policy that tries to register an executable (--analyzer-cmd) or touch a trust-floor field fails to load — a stolen or committed policy file must be inert.

Precedence (enforced by the engine): engine ceilings > host CLI flags > this policy file > memory-file config. “The file selects and restricts; only the host grants.”

Structs§

AutoApplyGrant
One auto-apply grant: an analyzer family may auto-apply to these target classes up to (and including) max_severity.
Cadence
When a loop pass is due — the loop’s cadence, as host policy.
CostBound
A cost bound beside the quality metric. The verdict on the quality field is unchanged; when quality held but field on the run after the apply exceeds max_increase_ratio × its value on the baseline run, the checkpoint records held_costlier and outcome_review emits an advisory Flag citing both runs — never a revert draft, because a cost/quality trade is a human decision. regressed dominates: one verdict per checkpoint. field is one of the promoted cost fields (effects, tokens, usd, wall_ms, cost_per_pass) or any integer key the harness writes; a run on which it is not measurable records no cost figures, and the quality verdict still records.
MinEffect
The Verify gate’s minimum effect size — a floor, not a significance test. A worsening of at most this much is held; no p-value, no interval, and the docs say so (docs/loop-proposal.md §18 forbids invented precision). Exactly one form:
OutcomeEvalset
The evalset every LLM-authored, applicable proposal is measured against after apply (docs/loop.md, “Evalset-backed outcomes”). An authored lesson carries no built-in recurrence metric — nothing errors when a lesson is merely useless — so without this the Verify gate has nothing to re-measure for exactly the proposals a human was least able to judge. The host names the evalset and the field; the engine takes the baseline from the newest run journaled BEFORE the proposal and reads the current value from runs journaled AFTER the apply. No baseline run → no metric, never a fabricated one.
PlanAuthoring
Whether, and how, DISCOVER may author a plan — a Workflow grain: named steps, edges with conditions in the runtime’s frozen grammar, validated before a reviewer sees it — beside the Skill that carries the prose.
PlanReplayPolicy
The pre-apply gate on a plan_revision: when the substrate can rehearse the candidate against the journaled runs of the live plan (SubstrateRead::plan_replay — areev run shadow --plan-file), refuse to stamp the revision applicable when the rehearsal says it is worse than the incumbent on the same runs, or when too many runs fall outside the journal’s support. Dream-RSI’s monotone selection (arXiv 2609.14858 §3) as a gate rather than an auto-deploy: applying stays human, with a BECAUSE. Default none — a revision is rehearsed when it can be and the report rides on the card, but nothing is refused.
Policy
The parsed host policy. Everything default-closed — the two fields whose closed state is not the zero value (skills, min_evidence) say so in their own Default.
SkillAuthoring
Whether, and how, DISCOVER may author a Skill — a reusable procedure with an applicability condition and ordered steps, derived from a trajectory that succeeded.

Enums§

BaselineKind
Which run journaled before the apply an evalset verdict compares against (docs/loop.md, “Evalset-backed outcomes”).
DiscoverObjective
What DISCOVER optimizes for (docs/loop-reflection.md §5.1). Host config like everything else here: it changes the scoring rule the proposer is given, never the gates — every draft still has to survive GROUND, VERIFY, the confidence floor and a human review with a BECAUSE.
EvidenceAttribution
How an Observation is attributed in the evidence bundle handed to the LLM (docs/loop.md). Named renders <observer> (a person) said of <subject>: <text>; Anonymous renders the bare text, which is what the engine did before 2026-09-04.
NearDuplicateMode
What DISCOVER does with a lesson that says, in other words, what a live lesson on the same entity already says. authored_dedup_key collapses the same text; a rewording is the reviewer’s call — so flag (default) lets it reach the queue carrying near_duplicate_of, and suppress drops it before the queue and counts it in the funnel as dropped_near_duplicate. Measured need (crates/areev-bench/ADBUY.md, seed 3): ten approved rules stated four facts, each approvable alone.
TelemetryMode
Telemetry sidecar mode (host-only).