pub struct DecisionLog { /* private fields */ }Expand description
The per-run recorder.
Implementations§
Source§impl DecisionLog
impl DecisionLog
Sourcepub fn install(data: &mut StoreData, config: DecisionLogConfig) -> Arc<Self> ⓘ
pub fn install(data: &mut StoreData, config: DecisionLogConfig) -> Arc<Self> ⓘ
Wraps the store’s security check in a recording decorator. Returns the log to read results from.
Install it outermost: after any embedder wrapper of the check (such as the server’s
audit decorator). Other wrappers do not forward SecurityCheck::recorder, so a
recorder installed beneath one is invisible to the host functions that begin calls.
Sourcepub fn install_observed(
data: &mut StoreData,
config: DecisionLogConfig,
observer: Option<Arc<dyn RecordObserver>>,
) -> Arc<Self> ⓘ
pub fn install_observed( data: &mut StoreData, config: DecisionLogConfig, observer: Option<Arc<dyn RecordObserver>>, ) -> Arc<Self> ⓘ
install, with an observer that sees each record as it is made.
Sourcepub fn new(
config: DecisionLogConfig,
observer: Option<Arc<dyn RecordObserver>>,
) -> Arc<Self> ⓘ
pub fn new( config: DecisionLogConfig, observer: Option<Arc<dyn RecordObserver>>, ) -> Arc<Self> ⓘ
A log not yet attached to a run; wrap a check to record through it.
The clock starts now.
Sourcepub fn wrap(
self: &Arc<Self>,
inner: Arc<dyn SecurityCheck>,
) -> Arc<dyn SecurityCheck> ⓘ
pub fn wrap( self: &Arc<Self>, inner: Arc<dyn SecurityCheck>, ) -> Arc<dyn SecurityCheck> ⓘ
inner, with every decision it audits also recorded here. For a check made outside
a program run, such as a server’s file tool; a run uses install.
Sourcepub fn finish(&self) -> DecisionLogOutput
pub fn finish(&self) -> DecisionLogOutput
Takes the run’s records and releases their byte charge. Call once, when the run ends: the truncation flags, drop count, and call numbering describe the whole run, so a later call would not describe only its own records.
Trait Implementations§
Source§impl DecisionRecorder for DecisionLog
impl DecisionRecorder for DecisionLog
Source§fn begin_call(
&self,
caller: &str,
capability: &str,
line: Option<SourceLine>,
) -> CallTicket
fn begin_call( &self, caller: &str, capability: &str, line: Option<SourceLine>, ) -> CallTicket
line is the program line that led to it, when known.Source§fn enter_host_call(&self) -> u64
fn enter_host_call(&self) -> u64
exit_host_call passes back.Source§fn exit_host_call(&self, marker: u64, returned: bool)
fn exit_host_call(&self, marker: u64, returned: bool)
returned) or failed. Ends every call begun since
marker that is still open; a nested host function has ended its own already.Source§fn wants_payload(&self, call_index: u64) -> bool
fn wants_payload(&self, call_index: u64) -> bool
call_index would be kept: the call is open and the
payload budget is not spent. Callers check it before building a payload. The
default asks for every payload.