Expand description
wintercount — temporal policy provenance.
Named for the winter count: the buffalo robes on which Plains nations painted each year’s defining event — a permanent record of what happened and what governed then. This crate does the same for governed systems: pin the hash of the policy in force into every event, and “which rules governed this decision” stays answerable forever.
Extracted from Bad Apple’s audit ledger, where every line’s data
payload carries policy_hash — SHA-256 of the exact policy bytes
in force at write time, "builtin" when running on compiled-in
defaults.
Structs§
- Mark
- One mark on the robe: an event and the policy hash in force when it happened.
- Policy
Doc - A policy document registered so hashes resolve back to bytes.
- Policy
Set - Registry of known policy documents: hash → bytes, so an auditor can resolve a mark’s hash to the actual rules that governed.
- Winter
Count - The painted robe: an ordered sequence of marks. Built from any event stream that pins a policy hash per event.
Constants§
- BUILTIN
- The distinguished hash for “no policy file — compiled-in defaults”. Distinguishes “defaults in force” from “hash unavailable”.
Functions§
- from_
ledger - Extract a winter count from an NDJSON ledger whose lines carry
data.policy_hash(Bad Apple’s format) — or a top-levelpolicy_hashfield. Lines without a parseable hash are skipped. Timestamps come fromts/timestamp(numeric epoch seconds) ordata.ts; lines without timestamps are assigned their line index so ordering is still preserved. - policy_
hash - SHA-256 (hex) of policy bytes — the “policy in force” fingerprint.