pub struct ShieldDefinition {Show 24 fields
pub name: String,
pub scan: Vec<String>,
pub strategy: String,
pub on_breach: String,
pub severity: String,
pub quarantine: String,
pub max_retries: Option<i64>,
pub confidence_threshold: Option<f64>,
pub allow_tools: Vec<String>,
pub deny_tools: Vec<String>,
pub sandbox: Option<bool>,
pub redact: Vec<String>,
pub declassifies: Vec<String>,
pub suppress: Vec<String>,
pub generalise: Vec<String>,
pub log: String,
pub deflect_message: String,
pub taint: String,
pub compliance: Vec<String>,
pub sign: String,
pub unknown_fields: Vec<(String, Loc)>,
pub loc: Loc,
pub leading_trivia: Vec<Trivia>,
pub trailing_trivia: Vec<Trivia>,
}Fields§
§name: String§scan: Vec<String>§strategy: String§on_breach: String§severity: String§quarantine: String§max_retries: Option<i64>§confidence_threshold: Option<f64>§allow_tools: Vec<String>§deny_tools: Vec<String>§sandbox: Option<bool>§redact: Vec<String>§declassifies: Vec<String>v4.5.0 — the regulatory classes this shield is authorised to RETIRE.
Empty for almost every shield, and that is the point: scanning is not declassifying. A control that can end a regulatory obligation says so.
suppress: Vec<String>v4.5.0 — the identifier KINDS this control removes entirely.
Kinds, not field names, deliberately. A control that named
[mrn, ssn] would be welded to one type’s spelling and useless on the
next; a control that names [medical_record_number, ssn] describes
what it does to DATA and is reusable wherever that data appears. It is
also the only form the catalogue can check: field names are prose.
generalise: Vec<String>v4.5.0 — the identifier kinds this control REDUCES rather than removes.
The shield names the kind; the regime says how. Safe Harbor reduces a
date to its year and a postal code to three digits, and those
operations come from HIPAA_SAFE_HARBOR rather than being restated
here — an author who could restate them could restate them wrong, and
the regulation is the source.
log: String§deflect_message: String§taint: String§compliance: Vec<String>ESK — regulatory coverage (HIPAA, PCI_DSS, GDPR, …).
sign: Stringv2.34.0 — egress signing algorithm (closed catalog: hmac_sha256,
axon-T846). Empty = the shield does not sign. A shield with sign:
is an EGRESS shield: publish <Channel> within <Shield> marks the
channel for signed external delivery (v2.34.0).
unknown_fields: Vec<(String, Loc)>v2.34.0 (axon-W010) — block fields the parser did not recognize,
with their source locations. Pre-77 the parser silently discarded
these (_ => skip_value()), so a typo or an unsupported field passed
axon check unremarked (Kivi brief #51 B.3). The parser still skips
the VALUE (leniency preserved — existing programs keep compiling) but
records the NAME so the type checker can warn honestly.
loc: Loc§leading_trivia: Vec<Trivia>v1.5.2 — leading comment trivia attached to this declaration (comments preceding the declaration’s first token, since the previous declaration or file start). Empty by default.
trailing_trivia: Vec<Trivia>v1.5.2 — trailing comment trivia (same line as the declaration’s last effective token). Empty by default.