Skip to main content

UserConstitution

Struct UserConstitution 

Source
pub struct UserConstitution {
    pub schema_version: u32,
    pub language: Option<String>,
    pub about: Option<String>,
    pub working_style: Vec<String>,
    pub priorities: Vec<String>,
    pub autonomy_preference: AutonomyPreference,
    pub notes: Option<String>,
    pub clauses: Vec<ConstitutionClause>,
    pub extra: BTreeMap<String, Value>,
}
Expand description

Structured user-global constitution. All content fields are optional so a minimal file still parses and a future schema stays forward-compatible.

Fields§

§schema_version: u32§language: Option<String>

Language the prose is authored in (BCP-47-ish tag, e.g. "en", "zh-Hans"). Localization metadata only.

§about: Option<String>

Short description of who the user is / their working context.

§working_style: Vec<String>

Preferred working style / communication preferences.

§priorities: Vec<String>

Standing priorities or values to weigh across projects.

§autonomy_preference: AutonomyPreference

Autonomy preference — model-facing guidance only.

§notes: Option<String>

Bounded free prose. Advisory; never parsed as enforceable policy.

§clauses: Vec<ConstitutionClause>

Individually addressable standing rules (schema v2). Only clauses with ClauseStatus::Accepted are rendered into the model-facing block.

§extra: BTreeMap<String, Value>

Unknown top-level fields, preserved verbatim across load/migrate/save so a newer Codewhale’s file survives a round-trip through an older one.

This map is cleared on the untrusted-draft path (UserConstitution::from_untrusted_json) and is outside cache_projection, so it can never reach the prompt or invalidate the prompt cache.

Implementations§

Source§

impl UserConstitution

Source

pub fn is_empty(&self) -> bool

True when the constitution carries no usable content (so callers can skip emitting an empty block and classify it as ConstitutionValidity::Empty).

Suggested clauses do not count: a file that only holds unratified model advice has no law in it yet, and must not be reported as configured.

Source

pub fn accepted_clauses(&self) -> impl Iterator<Item = &ConstitutionClause>

Accepted (ratified) clauses in stable id order. This is the only clause view the renderer and the cache projection may use.

Source

pub fn suggested_clauses(&self) -> impl Iterator<Item = &ConstitutionClause>

Clauses still awaiting ratification, in stable id order.

Source

pub fn validity(&self) -> ConstitutionValidity

Classify validity for the setup-state record.

Source

pub fn bounded(&self) -> Self

Return a bounded copy: list fields capped to MAX_LIST_ITEMS items of MAX_ITEM_LEN chars, prose capped to its limit, blank entries dropped. Free prose is never expanded into structure — it is only length-limited.

Source

pub fn render_body(&self) -> String

Deterministic, source-path-independent render of the constitution body. This is the canonical content hashed by preview_hash.

Envelope-tag sequences are neutralized here unconditionally, so even a hand-edited constitution.json that bypassed the untrusted-draft gate cannot forge or close the <codewhale_user_constitution> envelope at render time. Neutralization happens before hashing, so the preview hash still matches the rendered form byte-for-byte.

Source

pub fn render_block(&self, source: Option<&Path>) -> Option<String>

Render the full model-facing <codewhale_user_constitution> block.

source is included as an attribute for provenance but does not affect the body or the preview hash. Returns None when empty.

Source

pub fn preview_hash(&self) -> String

Stable content hash (FNV-1a 64-bit, hex) of the rendered body. Used for preview/version tracking in the setup-state record. Deterministic across platforms and independent of the home path.

Source

pub fn path() -> Result<PathBuf>

Path to the structured user-global constitution under $CODEWHALE_HOME.

Source

pub fn load() -> Result<UserConstitutionLoad>

Load the structured constitution from the home file, classifying the outcome so callers can record validity without re-reading the file.

Source

pub fn load_from(path: &Path) -> UserConstitutionLoad

Load from an explicit path (testable).

Source

pub fn save(&self) -> Result<()>

Atomically persist the bounded form to the home file. Callers invoke this only on accept — preview must never reach this path.

Source

pub fn save_to(&self, path: &Path) -> Result<()>

Atomically persist the bounded form to an explicit path (testable).

Source

pub fn from_untrusted_json(raw: &str) -> UntrustedDraftParse

Parse an untrusted draft (e.g. model output) into a bounded, sanitized constitution.

This is the single ingestion gate for text CodeWhale did not author:

  • Extracts balanced JSON objects in order until one parses, so fenced or prose-wrapped output still parses — including prose that itself contains braces before the real draft. Anything without a parseable object is Invalid, and every drop is logged loudly (#5169).
  • Unknown keys are ignored by serde, so a draft cannot smuggle runtime-policy fields (approval_policy, sandbox_mode, …) into the persisted file — the schema simply has nowhere to put them.
  • Every text field is stripped of control characters and of <codewhale_user_constitution tag sequences, so a draft cannot forge or close the prompt-injection envelope.
  • The result is bounded before it is returned, so oversized drafts are truncated before preview/save, and the preview hash of what the user ratifies matches what is persisted.
Source

pub fn cache_projection(&self) -> CacheProjection

The exact bytes this constitution contributes to the cache-stable prompt prefix, plus their digest and measures (#4782, #3928).

Byte-stability contract, relied on by the prompt-cache accounting:

  • it is a pure function of the accepted content only;
  • recording a suggestion, preserving an unknown field, or bumping the schema version does not change a single byte;
  • it is independent of the home path and of field/clause file order.
Source

pub fn migrate_raw(raw: &str) -> MigrationOutcome

Deterministically migrate raw constitution bytes to the current schema.

Pure: no I/O, no clock, no home lookup. Same bytes in, same outcome out.

Source

pub fn migrate_file(path: &Path) -> Result<MigrationOutcome>

Migrate the file at path in place, writing a rollback backup first.

A rejection writes nothing at all: the original file is left byte-identical so the user can inspect it, and the receipt says exactly why.

Source

pub fn rollback_file(path: &Path) -> Result<PathBuf>

Restore the pre-migration bytes written by Self::migrate_file.

Fails loudly when no backup exists rather than leaving the caller to believe a rollback happened.

Source

pub fn with_recommendation( &self, recommendation: &ConstitutionRecommendation, ) -> Self

Record model advice as suggestions only.

The returned constitution has byte-identical accepted content — asserted by the equal cache digest — so calling this can never change what the model reads next turn. This is the whole “never silently apply model advice” contract in one function (#3930).

Source

pub fn ratify( &self, reviewed_digest: &str, clause_ids: &[String], note: Option<&str>, ) -> Result<Ratification, RatificationError>

Ratify specific suggested clauses, failing closed on stale input.

reviewed_digest is the CacheProjection::digest of the base the human actually reviewed. If the live base has moved since — another save, a migration, a concurrent edit — this returns RatificationError::StaleBase and accepts nothing, because the human approved a document that no longer exists.

Trait Implementations§

Source§

impl Clone for UserConstitution

Source§

fn clone(&self) -> UserConstitution

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for UserConstitution

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Default for UserConstitution

Source§

fn default() -> Self

Returns the “default value” for a type. Read more
Source§

impl<'de> Deserialize<'de> for UserConstitution

Source§

fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>
where __D: Deserializer<'de>,

Deserialize this value from the given Serde deserializer. Read more
Source§

impl Eq for UserConstitution

Eq is asserted by hand rather than derived, because the preserved-unknown map holds serde_json::Value, which is only PartialEq.

The one value that would break reflexivity is a JSON float NaN — and JSON cannot express one: serde_json refuses to parse or emit NaN, so no constitution file can contain a value that is unequal to itself. Downstream types (UserConstitutionLoad, setup state, TUI drafts) keep their derived Eq as a result.

Source§

impl PartialEq for UserConstitution

Source§

fn eq(&self, other: &UserConstitution) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl Serialize for UserConstitution

Source§

fn serialize<__S>(&self, __serializer: __S) -> Result<__S::Ok, __S::Error>
where __S: Serializer,

Serialize this value into the given Serde serializer. Read more
Source§

impl StructuralPartialEq for UserConstitution

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DeserializeOwned for T
where T: for<'de> Deserialize<'de>,

Source§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

Source§

fn equivalent(&self, key: &K) -> bool

Checks if this value is equivalent to the given key. Read more
Source§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

Source§

fn equivalent(&self, key: &K) -> bool

Compare self to key and return true if they are equal.
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more