Skip to main content

GateOutcome

Struct GateOutcome 

Source
pub struct GateOutcome {
    pub violations: Vec<GateViolation>,
    pub withheld: Vec<Withheld>,
    pub zero_match: Vec<String>,
    pub multi_match: Vec<(String, Vec<String>)>,
}
Expand description

⟨0.24⟩ What gate returns: the violations it is SURE of, and the (rule, function) pairs it WITHHELD. Both halves travel, because the verdict is both (SPEC §3.1).

Fields§

§violations: Vec<GateViolation>

Sorted by (rule, detail).

§withheld: Vec<Withheld>

Sorted by (rule, func). Empty on every policy whose filters the signature can answer.

§zero_match: Vec<String>

⟨0.27⟩ SPEC §4 — the RAW TEXT of every rule whose SCOPE bound no function, sorted. A rule that bound nothing was evaluated and matched nothing, so it cannot have caught anything; scoring it as satisfied makes a one-character typo in a layer name a permanently green gate. This is a DISCLOSURE beside the verdict, never a new verdict: the caller prints it and MUST NOT let it change the exit code (a zero-match rule is legitimate when one policy is shared across repos).

§multi_match: Vec<(String, Vec<String>)>

SOUNDNESS R301 — every deny/pure rule whose scope names a BARE FUNCTION (no ::) and bound MORE THAN ONE, as (raw rule, the names it bound). Sorted, and a DISCLOSURE beside the verdict exactly like zero_match: the exit code must not move.

WHY. §6.2 scope matching is a PREFIX match, which is the documented behaviour and is not in question here. What is in question is that it is INVISIBLE: deny Fs either also binds either_ifelse and either_match, and deny Fs t_fish binds t_fish_both. An UNBOUND rule announces itself (matched NO function); an OVER-bound one announced nothing and looked exactly like a rule that bound the one function its author named. Both matrix agents on 2026-09-07 were caught by it, each noticing only because an unrelated control disagreed, and in every case the scoped column read exit 1 for a function that is actually SILENT — a cardinal sin hidden behind a neighbour’s name.

SCOPED TO BARE NAMES ON PURPOSE. A layer scope (handlers::) is MEANT to bind many, so announcing that would be noise on every real policy and the disclosure would be ignored. A scope with no :: is someone naming a function, and binding two is a surprise worth one line.

Trait Implementations§

Source§

impl Debug for GateOutcome

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Default for GateOutcome

Source§

fn default() -> GateOutcome

Returns the “default value” for a type. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.