wintercount 0.1.0

Temporal policy provenance: pin the policy hash in force at every event, then answer 'what rules governed at time T' forever — named for the painted buffalo robes that recorded each year's defining event
Documentation

wintercount

Temporal policy provenance. Named for the winter count — the buffalo robes on which Plains nations painted each year's defining event, a permanent record of what happened and what governed then.

Extracted from Bad Apple's audit ledger, where every line pins policy_hash — the SHA-256 of the exact policy bytes in force at write time.

The question it answers

"What rules governed this decision?" — not today's rules, not last week's. The rules in force at the moment it happened. Forever.

How it works

  • policy_hash(bytes) — SHA-256 of the canonical policy document. Even a rejected policy gets its hash pinned, so the record can prove which bytes were refused.
  • WinterCount — the painted robe: an ordered sequence of marks (ts, policy_hash).
  • policy_at(ts) — the hash governing at time T.
  • transitions() — every point where governance changed hands.
  • governed_range(hash) / census() — how long and how much each policy ruled.
  • foreign_marks(known) — events under a policy that isn't in your registry: rejected, removed, or foreign rules.
  • from_ledger(lines) — extract the count straight from a Bad Apple-format NDJSON ledger.

Usage

use wintercount::{WinterCount, PolicySet, policy_hash};

let mut wc = WinterCount::new();
wc.mark(1_700_000_000, policy_hash(b"allow: read"));
wc.mark(1_700_000_100, policy_hash(b"allow: none"));

assert_eq!(wc.policy_at(1_700_000_050), Some(old_hash));

Why it matters

Governance that can't say which rules were in force when a decision was made is governance that can't be audited. The winter count makes the temporal claim verifiable — the robe keeps the record even after the policy is gone.

License

MIT