pub const TRUST_ANNOTATION: &str = "yah.trust";Expand description
Annotation key declaring how much this workload’s code is trusted, from
which admission derives the weakest isolation substrate it may run on
(R894-F1). See WorkloadSpec::trust and TrustLevel.
§Why a separate key from NATIVE_EXEC_ANNOTATION
yah.exec is a request: what the dispatcher wants. yah.trust is a
fact about the code: where it came from. Folding them together — a fourth
yah.exec value meaning “untrusted, so microvm” — would make the fact
unstateable whenever the request is stricter than the minimum, and would
silently discard it if a later ticket widened the substrate set. They are
two different questions and a workload answers both.
The pairing is checked, not merely recorded: cloud::config::admission_spec
refuses any spec whose declared trust exceeds what its requested substrate
provides, so a yah.trust = untrusted workload cannot reach a node on the
host kernel.