pub struct UserConstitution {
pub schema_version: u32,
pub language: Option<String>,
pub about: Option<String>,
pub working_style: Vec<String>,
pub priorities: Vec<String>,
pub autonomy_preference: AutonomyPreference,
pub notes: Option<String>,
}Expand description
Structured user-global constitution. All content fields are optional so a minimal file still parses and a future schema stays forward-compatible.
Fields§
§schema_version: u32§language: Option<String>Language the prose is authored in (BCP-47-ish tag, e.g. "en",
"zh-Hans"). Localization metadata only.
about: Option<String>Short description of who the user is / their working context.
working_style: Vec<String>Preferred working style / communication preferences.
priorities: Vec<String>Standing priorities or values to weigh across projects.
autonomy_preference: AutonomyPreferenceAutonomy preference — model-facing guidance only.
notes: Option<String>Bounded free prose. Advisory; never parsed as enforceable policy.
Implementations§
Source§impl UserConstitution
impl UserConstitution
Sourcepub fn is_empty(&self) -> bool
pub fn is_empty(&self) -> bool
True when the constitution carries no usable content (so callers can skip
emitting an empty block and classify it as ConstitutionValidity::Empty).
Sourcepub fn validity(&self) -> ConstitutionValidity
pub fn validity(&self) -> ConstitutionValidity
Classify validity for the setup-state record.
Sourcepub fn bounded(&self) -> Self
pub fn bounded(&self) -> Self
Return a bounded copy: list fields capped to MAX_LIST_ITEMS items of
MAX_ITEM_LEN chars, prose capped to its limit, blank entries dropped.
Free prose is never expanded into structure — it is only length-limited.
Sourcepub fn render_body(&self) -> String
pub fn render_body(&self) -> String
Deterministic, source-path-independent render of the constitution body.
This is the canonical content hashed by preview_hash.
Envelope-tag sequences are neutralized here unconditionally, so even a
hand-edited constitution.json that bypassed the untrusted-draft gate
cannot forge or close the <codewhale_user_constitution> envelope at
render time. Neutralization happens before hashing, so the preview hash
still matches the rendered form byte-for-byte.
Sourcepub fn render_block(&self, source: Option<&Path>) -> Option<String>
pub fn render_block(&self, source: Option<&Path>) -> Option<String>
Render the full model-facing <codewhale_user_constitution> block.
source is included as an attribute for provenance but does not affect
the body or the preview hash. Returns None when empty.
Sourcepub fn preview_hash(&self) -> String
pub fn preview_hash(&self) -> String
Stable content hash (FNV-1a 64-bit, hex) of the rendered body. Used for preview/version tracking in the setup-state record. Deterministic across platforms and independent of the home path.
Sourcepub fn path() -> Result<PathBuf>
pub fn path() -> Result<PathBuf>
Path to the structured user-global constitution under $CODEWHALE_HOME.
Sourcepub fn load() -> Result<UserConstitutionLoad>
pub fn load() -> Result<UserConstitutionLoad>
Load the structured constitution from the home file, classifying the outcome so callers can record validity without re-reading the file.
Sourcepub fn load_from(path: &Path) -> UserConstitutionLoad
pub fn load_from(path: &Path) -> UserConstitutionLoad
Load from an explicit path (testable).
Sourcepub fn save(&self) -> Result<()>
pub fn save(&self) -> Result<()>
Atomically persist the bounded form to the home file. Callers invoke this only on accept — preview must never reach this path.
Sourcepub fn save_to(&self, path: &Path) -> Result<()>
pub fn save_to(&self, path: &Path) -> Result<()>
Atomically persist the bounded form to an explicit path (testable).
Sourcepub fn from_untrusted_json(raw: &str) -> UntrustedDraftParse
pub fn from_untrusted_json(raw: &str) -> UntrustedDraftParse
Parse an untrusted draft (e.g. model output) into a bounded, sanitized constitution.
This is the single ingestion gate for text CodeWhale did not author:
- Extracts the first JSON object, so fenced or prose-wrapped output
still parses; anything without one is
Invalid. - Unknown keys are ignored by serde, so a draft cannot smuggle
runtime-policy fields (
approval_policy,sandbox_mode, …) into the persisted file — the schema simply has nowhere to put them. - Every text field is stripped of control characters and of
<codewhale_user_constitutiontag sequences, so a draft cannot forge or close the prompt-injection envelope. - The result is
boundedbefore it is returned, so oversized drafts are truncated before preview/save, and the preview hash of what the user ratifies matches what is persisted.
Trait Implementations§
Source§impl Clone for UserConstitution
impl Clone for UserConstitution
Source§fn clone(&self) -> UserConstitution
fn clone(&self) -> UserConstitution
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreSource§impl Debug for UserConstitution
impl Debug for UserConstitution
Source§impl Default for UserConstitution
impl Default for UserConstitution
Source§impl<'de> Deserialize<'de> for UserConstitution
impl<'de> Deserialize<'de> for UserConstitution
Source§fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
impl Eq for UserConstitution
Source§impl PartialEq for UserConstitution
impl PartialEq for UserConstitution
Source§impl Serialize for UserConstitution
impl Serialize for UserConstitution
impl StructuralPartialEq for UserConstitution
Auto Trait Implementations§
impl Freeze for UserConstitution
impl RefUnwindSafe for UserConstitution
impl Send for UserConstitution
impl Sync for UserConstitution
impl Unpin for UserConstitution
impl UnsafeUnpin for UserConstitution
impl UnwindSafe for UserConstitution
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> DeserializeOwned for Twhere
T: for<'de> Deserialize<'de>,
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
key and return true if they are equal.