Skip to main content

Module policy

Module policy 

Source
Expand description

Host policy — the optional loop-policy.json (proposal §6.2). It is the only place auto-apply is granted, and it is host config (per-process, never persisted in a memory file). All fields default-closed; the whole struct rejects unknown keys, so a policy that tries to register an executable (--analyzer-cmd) or touch a trust-floor field fails to load — a stolen or committed policy file must be inert.

Precedence (enforced by the engine): engine ceilings > host CLI flags > this policy file > memory-file config. “The file selects and restricts; only the host grants.”

Structs§

AutoApplyGrant
One auto-apply grant: an analyzer family may auto-apply to these target classes up to (and including) max_severity.
Policy
The parsed host policy. Everything default-closed.

Enums§

TelemetryMode
Telemetry sidecar mode (host-only).