vsh-policy 0.3.0

Deterministic read-capability and transaction policy for VSH
Documentation

Deterministic capability and transaction policy for VSH.

The call policy runs before bytes or mutations reach [vsh_vfs::VirtualFs]. The transaction policy then evaluates the observed diff and any denied attempts. Both paths are pure, synchronous, and use only canonical VSH value types.