Skip to main content

Module decision

Module decision 

Source
Expand description

Decision records: what an embedder’s recorder sees of each capability decision.

The recorder is a SecurityCheck decorator (DecisionLog::install): it forwards every call to the check it wraps, including audit, so the embedder’s own audit sees exactly what it would without a recorder, and taps the same audit calls. Recording never changes a decision, never fails a call, and never charges guest fuel.

Observation work (the source-line backtrace per call) is never charged to guest fuel; see DecisionLogConfig::max_line_capture_frames for why and what bounds it. Lines stop being captured when the decision cap is reached, when the byte budget cannot fit even a bare record, after a record has been dropped whole for want of bytes, or when that frame budget is exceeded. A later, smaller record may still be kept after such a drop, without a line. Other truncation (a byte-budget payload drop, the pair cap) does not stop them.

Record buffers are charged against the recorder’s own byte budget, separate from the run’s memory limit so that recording never changes a run’s memory behavior, and a per-run decision cap; a run that reaches either is marked truncated rather than refused.

Structs§

CallSite
The call a decision belongs to and how it arrived.
CallTicket
Identity of one host call, assigned when it begins.
DecisionExplanation
The policy’s reasoning for one decision.
DecisionLog
The per-run recorder.
DecisionLogConfig
DecisionLogOutput
What a run recorded.
DecisionRecord
FailureRecord
One comparison that kept a rule’s filter from matching.
NearMissRecord
A rule that named the capability but whose filter rejected the call.
RuleCitation
A rule located by caller block and zero-based position.
SourceLine
A position in the submitted program.

Enums§

DecisionAction
What the policy decided. AskHuman is a denial today (the approval flow is deferred), kept distinct so a record can say “deferred”.
DecisionCause
EntryPath
Which seam produced a decision.
FailureReasonRecord

Traits§

DecisionRecorder
The runtime’s side of a recorder: identity for each call. Record contents arrive through SecurityCheck::audit.
RecordObserver
Sees records as they are made, for an embedder that streams a run while it executes.