Skip to main content

Module call_log

Module call_log 

Source
Expand description

Call records: each host call a program made, when it ran, and, for a call that reaches outside the program, what it sent and what came back.

The DecisionLog keeps these beside its decisions. Every gated host call is a call: it starts at its gate and ends when the host function returns, so its timing and outcome need nothing from the host function itself. A host function whose call fetches or sends something also hands the recorder its request and response ([record_payload]): a capped copy, a digest of the full payload, and its full size.

What is never kept: a secret’s value (a secrets.get call keeps its timing only), and the values of credential-bearing headers, which are masked before the copy and the digest are taken (see mask_headers). Matching known secret values inside bodies is the embedder’s job when it stores a record; the runtime does not know them all.

Hashing a payload walks bytes the program already paid fuel to send or receive, so the digest adds no unbounded work of its own; like the rest of the recorder it is not charged to guest fuel (see DecisionLogConfig::max_line_capture_frames).

Structs§

CallRecord
One host call. Times are microseconds measured from the recorder’s start.
ModelUsage
Token counts a model provider reported for one call. Absent when not reported.
Payload
What a host function hands the recorder for one side of a call.
PayloadRecord
One side of a call: what it sent, or what came back.

Enums§

BodyCopy
A copy of a payload body, kept as text when it is UTF-8.
CallOutcome
How a call ended.
Side
Which side of a call a payload belongs to.

Constants§

MASKED
The value a masked header carries in a record.

Functions§

is_sensitive_header
Whether a header’s value is a credential: Authorization, Proxy-Authorization, Cookie, Set-Cookie, and any name containing key, token, secret, auth, password, passwd, signature, or credential.
mask_headers
Headers as a recordable JSON array of [name, value] pairs with credential values masked, and the names that were masked.
mask_url
A URL as a record keeps it: the userinfo and the values of credential-named query parameters masked, and the fragment dropped. A URL that does not parse keeps nothing of its authority, path, or query, so a credential in it cannot survive.