pub struct GateOutcome {
pub violations: Vec<GateViolation>,
pub withheld: Vec<Withheld>,
pub zero_match: Vec<String>,
pub multi_match: Vec<(String, Vec<String>)>,
}Expand description
⟨0.24⟩ What gate returns: the violations it is SURE of, and the (rule, function) pairs it
WITHHELD. Both halves travel, because the verdict is both (SPEC §3.1).
Fields§
§violations: Vec<GateViolation>Sorted by (rule, detail).
withheld: Vec<Withheld>Sorted by (rule, func). Empty on every policy whose filters the signature can answer.
zero_match: Vec<String>⟨0.27⟩ SPEC §4 — the RAW TEXT of every rule whose SCOPE bound no function, sorted. A rule that bound nothing was evaluated and matched nothing, so it cannot have caught anything; scoring it as satisfied makes a one-character typo in a layer name a permanently green gate. This is a DISCLOSURE beside the verdict, never a new verdict: the caller prints it and MUST NOT let it change the exit code (a zero-match rule is legitimate when one policy is shared across repos).
multi_match: Vec<(String, Vec<String>)>SOUNDNESS R301 — every deny/pure rule whose scope names a BARE FUNCTION (no ::) and bound
MORE THAN ONE, as (raw rule, the names it bound). Sorted, and a DISCLOSURE beside the verdict
exactly like zero_match: the exit code must not move.
WHY. §6.2 scope matching is a PREFIX match, which is the documented behaviour and is not in
question here. What is in question is that it is INVISIBLE: deny Fs either also binds
either_ifelse and either_match, and deny Fs t_fish binds t_fish_both. An UNBOUND rule
announces itself (matched NO function); an OVER-bound one announced nothing and looked exactly
like a rule that bound the one function its author named. Both matrix agents on 2026-09-07 were
caught by it, each noticing only because an unrelated control disagreed, and in every case the
scoped column read exit 1 for a function that is actually SILENT — a cardinal sin hidden behind
a neighbour’s name.
SCOPED TO BARE NAMES ON PURPOSE. A layer scope (handlers::) is MEANT to bind many, so
announcing that would be noise on every real policy and the disclosure would be ignored. A scope
with no :: is someone naming a function, and binding two is a surprise worth one line.