pub struct InformationFlowGate { /* private fields */ }Expand description
An AdmissionGate that enforces information-flow safety: confidential
data must not reach an exfiltration sink, and forbidden tool orderings
are escalated to human approval.
Implementations§
Source§impl InformationFlowGate
impl InformationFlowGate
Sourcepub fn new(config: ToolLabelConfig) -> Self
pub fn new(config: ToolLabelConfig) -> Self
Build a gate from a resolved ToolLabelConfig.
Sourcepub fn with_builtin_labels() -> Self
pub fn with_builtin_labels() -> Self
Build a gate from the built-in defaults only.
Trait Implementations§
Source§impl AdmissionGate for InformationFlowGate
impl AdmissionGate for InformationFlowGate
Source§fn name(&self) -> &str
fn name(&self) -> &str
Short stable identifier (e.g.
"information_flow", "concurrency")
recorded on the audit event so a denial is attributable to a gate.Source§fn check<'life0, 'life1, 'life2, 'life3, 'async_trait>(
&'life0 self,
proposal: &'life1 ActionProposal,
_ctx: &'life2 GateContext<'life3>,
) -> Pin<Box<dyn Future<Output = GateOutcome> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
'life2: 'async_trait,
'life3: 'async_trait,
fn check<'life0, 'life1, 'life2, 'life3, 'async_trait>(
&'life0 self,
proposal: &'life1 ActionProposal,
_ctx: &'life2 GateContext<'life3>,
) -> Pin<Box<dyn Future<Output = GateOutcome> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
'life2: 'async_trait,
'life3: 'async_trait,
Inspect a proposal and return a verdict. Must not mutate shared
state — admission runs before the execution snapshot is taken.
Auto Trait Implementations§
impl Freeze for InformationFlowGate
impl RefUnwindSafe for InformationFlowGate
impl Send for InformationFlowGate
impl Sync for InformationFlowGate
impl Unpin for InformationFlowGate
impl UnsafeUnpin for InformationFlowGate
impl UnwindSafe for InformationFlowGate
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
impl<T> ErasedDestructor for Twhere
T: 'static,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
Converts
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
Converts
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more