Skip to main content

ApprovalLedger

Struct ApprovalLedger 

Source
pub struct ApprovalLedger { /* private fields */ }
Expand description

An append-only ledger of human-in-the-loop decisions, keyed by fingerprint (last decision wins). Optionally persisted as JSONL so the approval state survives restarts — HITL decisions are durable harness state, not transient prompts.

Concurrency: a single writer per journal file is assumed. The stateless FFI opens a fresh ledger per call, so a product that drives approvals from multiple processes against one journal must serialize those writes itself (e.g. route them through the daemon). Reads tolerate the writer appending concurrently; a torn final line is skipped on load and counted in ApprovalLedger::skipped_on_load.

Implementations§

Source§

impl ApprovalLedger

Source

pub fn new() -> ApprovalLedger

Source

pub fn with_journal(path: impl Into<PathBuf>) -> Result<ApprovalLedger, Error>

Create a ledger backed by a JSONL journal at path, loading any existing decisions. Each line is one ApprovalRecord; the last line for a fingerprint wins, so a later rejection overrides an earlier approval.

Source

pub fn skipped_on_load(&self) -> usize

Number of unparseable lines skipped during the load. Nonzero means the journal is corrupt or was torn by a concurrent writer.

Source

pub fn record( &mut self, record: ApprovalRecord, ) -> Result<&ApprovalRecord, Error>

Record a decision, persisting it to the journal when configured. Returns the stored record.

A journal write failure is an error, not best-effort (review A7): callers emit ApprovalRecorded audit events on the strength of this call, so a decision that only landed in memory must not be reported as durable. On Err the decision is NOT stored (memory and journal stay consistent — both lack it) and the caller must surface the failure. An in-memory ledger (no journal) cannot fail.

Source

pub fn lookup(&self, fingerprint: &str) -> Option<&ApprovalRecord>

The current decision for a fingerprint, if any.

Source

pub fn all(&self) -> impl Iterator<Item = &ApprovalRecord>

Source

pub fn record_decision( &mut self, fingerprint: &str, required_tier: PermissionTier, decision: ApprovalDecision, reviewer: &str, reason: &str, evidence: Option<String>, ) -> Result<ApprovalRecord, Error>

Build and record a decision against an explicit fingerprint — the ledger-level twin of PermissionGate::record_for_fingerprint, for callers that share ONE ledger across many gates/sessions (e.g. the daemon’s shared approval substrate) and so must not route the write through any single session’s gate. Errs when the journal write fails (the decision is then NOT recorded — see Self::record).

Trait Implementations§

Source§

impl Debug for ApprovalLedger

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result<(), Error>

Formats the value using the given formatter. Read more
Source§

impl Default for ApprovalLedger

Source§

fn default() -> ApprovalLedger

Returns the “default value” for a type. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> ErasedDestructor for T
where T: 'static,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self>

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> Pointable for T

Source§

const ALIGN: usize

The alignment of pointer.
Source§

type Init = T

The type for initializers.
Source§

unsafe fn init(init: <T as Pointable>::Init) -> usize

Initializes a with the given initializer. Read more
Source§

unsafe fn deref<'a>(ptr: usize) -> &'a T

Dereferences the given pointer. Read more
Source§

unsafe fn deref_mut<'a>(ptr: usize) -> &'a mut T

Mutably dereferences the given pointer. Read more
Source§

unsafe fn drop(ptr: usize)

Drops the object pointed to by the given pointer. Read more
Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more