pub fn render_validation_report(
config: &ServerConfig,
hooks: &ToolkitHooks,
) -> Vec<ReportLine>Expand description
Render what this server actually enforces, as the lines
emit_validation_report logs (Phase 128, D-07).
Separate from the emission so a test can assert the exact line FORMATS without
installing a tracing subscriber — and so the documentation deliverable has one
authority for what an operator will see.
§It carries no request data, by construction
Every line is built from [server.validation], from
ServerConfig::validation_report (itself built from [[tools]] declarations),
and from which tool NAMES carry a registered validator. No argument value and no
credential can reach it, because none is in scope here. That is the property
that keeps the log from becoming the PHI channel SC-7 closed everywhere else.
§What it reports
In order: the effective [server.validation] policy; the always-on floor; one
line per tool naming its enforced rules; one WARN per ACTIVE opt-out, or one
INFO stating that none is active; the E1 policy registration state; and the E2
validator registrations, with a WARN for any registered under a tool name the
config does not declare.
An enforcement that is OFF is always stated. A log that listed only what is on would let an operator read silence as safety.