Expand description
Call records: each host call a program made, when it ran, and, for a call that reaches outside the program, what it sent and what came back.
The DecisionLog keeps these beside its decisions. Every gated
host call is a call: it starts at its gate and ends when the host function returns,
so its timing and outcome need nothing from the host function itself. A host function
whose call fetches or sends something also hands the recorder its request and
response ([record_payload]): a capped copy, a digest of the full
payload, and its full size.
What is never kept: a secret’s value (a secrets.get call keeps its timing only),
and the values of credential-bearing headers, which are masked before the copy and the
digest are taken (see mask_headers). Matching known secret values inside bodies is
the embedder’s job when it stores a record; the runtime does not know them all.
Hashing a payload walks bytes the program already paid fuel to send or receive, so the
digest adds no unbounded work of its own; like the rest of the recorder it is not
charged to guest fuel (see DecisionLogConfig::max_line_capture_frames).
Structs§
- Call
Record - One host call. Times are microseconds measured from the recorder’s start.
- Model
Usage - Token counts a model provider reported for one call. Absent when not reported.
- Payload
- What a host function hands the recorder for one side of a call.
- Payload
Record - One side of a call: what it sent, or what came back.
Enums§
- Body
Copy - A copy of a payload body, kept as text when it is UTF-8.
- Call
Outcome - How a call ended.
- Side
- Which side of a call a payload belongs to.
Constants§
- MASKED
- The value a masked header carries in a record.
Functions§
- is_
sensitive_ header - Whether a header’s value is a credential:
Authorization,Proxy-Authorization,Cookie,Set-Cookie, and any name containingkey,token,secret,auth,password,passwd,signature, orcredential. - mask_
headers - Headers as a recordable JSON array of
[name, value]pairs with credential values masked, and the names that were masked. - mask_
url - A URL as a record keeps it: the userinfo and the values of credential-named query parameters masked, and the fragment dropped. A URL that does not parse keeps nothing of its authority, path, or query, so a credential in it cannot survive.