Expand description
Decision records: what an embedder’s recorder sees of each capability decision.
The recorder is a SecurityCheck decorator (DecisionLog::install): it forwards
every call to the check it wraps, including audit, so the embedder’s own audit sees
exactly what it would without a recorder, and taps the same audit calls. Recording
never changes a decision, never fails a call, and never charges guest fuel.
Observation work (the source-line backtrace per call) is never charged to guest fuel;
see DecisionLogConfig::max_line_capture_frames for why and what bounds it. Lines stop
being captured when the decision cap is reached, when the byte budget cannot fit even a
bare record, after a record has been dropped whole for want of bytes, or when that frame
budget is exceeded. A later, smaller record may still be kept after such a drop, without
a line. Other truncation (a byte-budget payload drop, the pair cap) does not stop them.
Record buffers are charged against the recorder’s own byte budget, separate from the run’s memory limit so that recording never changes a run’s memory behavior, and a per-run decision cap; a run that reaches either is marked truncated rather than refused.
Structs§
- Call
Site - The call a decision belongs to and how it arrived.
- Call
Ticket - Identity of one host call, assigned when it begins.
- Decision
Explanation - The policy’s reasoning for one decision.
- Decision
Log - The per-run recorder.
- Decision
LogConfig - Decision
LogOutput - What a run recorded.
- Decision
Record - Failure
Record - One comparison that kept a rule’s filter from matching.
- Near
Miss Record - A rule that named the capability but whose filter rejected the call.
- Rule
Citation - A rule located by caller block and zero-based position.
- Source
Line - A position in the submitted program.
Enums§
- Decision
Action - What the policy decided.
AskHumanis a denial today (the approval flow is deferred), kept distinct so a record can say “deferred”. - Decision
Cause - Entry
Path - Which seam produced a decision.
- Failure
Reason Record
Traits§
- Decision
Recorder - The runtime’s side of a recorder: identity for each call. Record contents arrive through
SecurityCheck::audit. - Record
Observer - Sees records as they are made, for an embedder that streams a run while it executes.