pub struct SynthDefinition {
pub name: String,
pub target: String,
pub risk: String,
pub language: String,
pub sandbox: String,
pub review: String,
pub max_lines: Option<i64>,
pub loc: Loc,
pub leading_trivia: Vec<Trivia>,
pub trailing_trivia: Vec<Trivia>,
}Expand description
v2.42.0 — synth <Name> { target:, risk:, language:, sandbox:, review:, max_lines: } — a dynamic tool-synthesis policy.
A savant that hits an epistemic gap it has no tool for can, under such a
policy, deduce + write a tool (a Coder sub-agent, a Reviewer sub-agent — a
par with an agreement condition), compile it to wasm32-wasi, and run it
in an Extism zero-trust sandbox, feeding stdout back as empirical evidence
(paper section 6). The policy declares the SAFETY ENVELOPE; the runtime enforces it.
Deny-by-default (D87.d): OSS parses + statically disciplines this policy
but ships a SynthBackend reference that REFUSES to execute — running
untrusted synthesised code needs the enterprise Extism/gVisor isolation
(v2.42.0). The checker therefore requires sandbox: wasm (T882): a synth
policy that would run code outside a sandbox can never compile.
Unknown fields are a hard parse error: a synth policy governs arbitrary-code execution — the highest-stakes surface in the language.
Fields§
§name: String§target: Stringtarget: "…" — what the synthesised tools are for (the capability scope).
Required (v2.42.0 axon-T879).
risk: Stringrisk: low | medium | high | critical — the ceiling risk class the
policy admits; governs review + isolation strictness. Required
(v2.42.0 axon-T880).
language: Stringlanguage: rust | c | python — the allowed synthesis source language
(all compiled to wasm32-wasi). Empty ⇒ any admitted language
(v2.42.0 axon-T881 validates when present).
sandbox: Stringsandbox: wasm — the isolation tier. MUST be wasm (v2.42.0 axon-T882
deny-by-default): synthesised code may only run in a zero-trust WASM
sandbox. Empty ⇒ error (never a silent “no sandbox”).
review: Stringreview: required | none — the Coder/Reviewer consensus requirement.
Empty ⇒ required (the safe default). none is FORBIDDEN for
high/critical risk (v2.42.0 axon-T883).
max_lines: Option<i64>max_lines: <int> — an optional hard cap on synthesised source length
(a smaller attack + review surface). None ⇒ engine default.
loc: Loc§leading_trivia: Vec<Trivia>v1.5.2 — leading comment trivia.
trailing_trivia: Vec<Trivia>v1.5.2 — trailing comment trivia.