Skip to main content

DisplayPolicy

Enum DisplayPolicy 

Source
pub enum DisplayPolicy {
    WorkspaceAlias,
    BackendNative,
}
Expand description

How MountFs presents primary-workspace paths to the model, narration, prompts, and persisted output pointers.

§Why this is a policy seam and not a hardcoded rule

/workspace plays two independent roles in MountFs, and they must not be conflated:

  1. Routing / cwd — the model addresses files at /workspace/... and relative paths resolve there. This is a runtime mechanism: it is the same for every embedder (models are trained on cloud-agent layouts), so it stays hardcoded as WORKSPACE_MOUNT.
  2. Display presentation — the path string shown to the model, emitted in tool narration, and persisted in output pointers. This is policy, and it legitimately differs per embedder. That is what this enum selects.

§History (do not re-collapse these two roles)

  • PR #2776 made MountFs present /workspace unconditionally, deleting the old delegation to backend.display_path(...). The motivation was real: a mounted real-disk server session leaked the host checkout path (/private/var/.../checkout/src/lib.rs) to the model and into persisted, agent-visible output — a host-disclosure issue (threat model TM-FS). In a multi-tenant server the host is infrastructure the model must not see, so WorkspaceAlias is the correct, safe default.
  • But #2776 baked that policy into the mechanism, in shared everruns-core. That broke local single-user embedders (e.g. the yolop coding CLI, PR #258 “expose real workspace paths”), where the “host” is the user’s own machine. There, showing /Users/me/proj/src/lib.rs is not a disclosure — it is the desired behavior: paths are clickable and match what bash pwd prints. Such embedders still need MountFs for routing (relative resolution, the default cwd, extra mounts), so they cannot simply drop it; they need presentation to be overridable.

The resolution: keep the safe alias as the default so no server code changes and #2776’s security property is preserved, but expose BackendNative so a local embedder can opt back into its backend’s real identity. The runtime no longer hardcodes presentation — it defaults it, and lets the embedder decide. See specs/file-store.md (EVE-660, “Display policy”).

Variants§

§

WorkspaceAlias

Present primary paths under the stable, host-agnostic /workspace namespace, regardless of what the backend physically is. The default; required for multi-tenant/server hosts so host paths never reach the model or persisted output.

§

BackendNative

Delegate presentation of primary paths to the backend, exposing its native identity (real host paths for a real-disk store). For local, single-user embedders where the host is the user’s own machine and real paths are the intended, useful output.

Trait Implementations§

Source§

impl Clone for DisplayPolicy

Source§

fn clone(&self) -> DisplayPolicy

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Copy for DisplayPolicy

Source§

impl Debug for DisplayPolicy

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Default for DisplayPolicy

Source§

fn default() -> DisplayPolicy

Returns the “default value” for a type. Read more
Source§

impl Eq for DisplayPolicy

Source§

impl PartialEq for DisplayPolicy

Source§

fn eq(&self, other: &DisplayPolicy) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl StructuralPartialEq for DisplayPolicy

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> AsOut<T> for T
where T: Copy,

Source§

fn as_out(&mut self) -> Out<'_, T>

Returns an out reference to self.
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DynClone for T
where T: Clone,

Source§

fn __clone_box(&self, _: Private) -> *mut ()

Source§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

Source§

fn equivalent(&self, key: &K) -> bool

Compare self to key and return true if they are equal.
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> FromRef<T> for T
where T: Clone,

Source§

fn from_ref(input: &T) -> T

Converts to this type from a reference to the input type.
Source§

impl<T> FutureExt for T

Source§

fn with_context(self, otel_cx: Context) -> WithContext<Self>

Attaches the provided Context to this type, returning a WithContext wrapper. Read more
Source§

fn with_current_context(self) -> WithContext<Self>

Attaches the current Context to this type, returning a WithContext wrapper. Read more
Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self>

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> IntoRequest<T> for T

Source§

fn into_request(self) -> Request<T>

Wrap the input message T in a tonic::Request
Source§

impl<L> LayerExt<L> for L

Source§

fn named_layer<S>(&self, service: S) -> Layered<<L as Layer<S>>::Service, S>
where L: Layer<S>,

Applies the layer to a service and wraps it in Layered.
Source§

impl<T> ParallelSend for T

Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more