Skip to main content

Crate wintercount

Crate wintercount 

Source
Expand description

wintercount — temporal policy provenance.

Named for the winter count: the buffalo robes on which Plains nations painted each year’s defining event — a permanent record of what happened and what governed then. This crate does the same for governed systems: pin the hash of the policy in force into every event, and “which rules governed this decision” stays answerable forever.

Extracted from Bad Apple’s audit ledger, where every line’s data payload carries policy_hash — SHA-256 of the exact policy bytes in force at write time, "builtin" when running on compiled-in defaults.

Structs§

Mark
One mark on the robe: an event and the policy hash in force when it happened.
PolicyDoc
A policy document registered so hashes resolve back to bytes.
PolicySet
Registry of known policy documents: hash → bytes, so an auditor can resolve a mark’s hash to the actual rules that governed.
WinterCount
The painted robe: an ordered sequence of marks. Built from any event stream that pins a policy hash per event.

Constants§

BUILTIN
The distinguished hash for “no policy file — compiled-in defaults”. Distinguishes “defaults in force” from “hash unavailable”.

Functions§

from_ledger
Extract a winter count from an NDJSON ledger whose lines carry data.policy_hash (Bad Apple’s format) — or a top-level policy_hash field. Lines without a parseable hash are skipped. Timestamps come from ts/timestamp (numeric epoch seconds) or data.ts; lines without timestamps are assigned their line index so ordering is still preserved.
policy_hash
SHA-256 (hex) of policy bytes — the “policy in force” fingerprint.