1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
//! The Policy Decision Point (PDP).
//!
//! A maintainer-side Rego engine that decides the disposition of a Trust Task
//! before it is dispatched: `allow`, `deny`, `requireStepUp`, or
//! `requireConsent`. It replaces the inline "default allow" the vault handlers
//! carried, and generalises the vault-only policy of the 0.2 schema to any task
//! via `policy/_shared/0.3`.
//!
//! ## Design invariants
//!
//! - **Code decides, registry describes.** The authoritative `sideEffects` /
//! `exposure` classification fed into [`types::PolicyInput`] comes from the
//! compiled dispatch table (the trust-task dispatch table), NOT from the published
//! registry. Whoever controls the registry must not be able to lower the
//! consent bar. (SPEC §7.3 items 13–14.)
//! - **Fail closed.** Every path that cannot produce an explicit `allow` — no
//! policy fired, an evaluation error, a resource-budget abort, an
//! unclassifiable input — resolves to `deny`. See [`decide`].
//! - **Priority-ordered, first-opinion-wins.** Policies run highest-priority
//! first; the first whose `decision` rule fires is authoritative. A policy
//! whose rule is undefined abstains rather than denying, so a narrow
//! high-priority override can sit above a broad default.
//!
//! ## Layering
//!
//! - [`engine`] — the thin `regorus` wrapper (compile + evaluate one module).
//! - [`types`] — the Rust mirror of `policy/_shared/0.3`.
//! - [`decide`] — orchestration across the active policy set (this module).
//!
//! Persistence (the `policy:` keyspace), the `policy/*` Trust Task handlers,
//! per-request [`types::PolicyInput`] construction, and boot-installed default
//! policies land alongside this in the same PR series.
pub use ;
pub use ;
pub use build_policy_input;
pub use load_active_for_context;
pub use ;
/// Decide a task's disposition across the priority-ordered active policy set.
///
/// Each entry is `(priority, compiled)`. Higher priority evaluates first; the
/// first policy whose `decision` rule fires wins. If every policy abstains — or
/// any evaluation errors or aborts — the result is a fail-closed `deny`.
///
/// This is the single choke point the vault call sites (and, later, every
/// dispatched task) route through, so the deny-by-default guarantee lives in
/// exactly one place.