mandate.rs

crates/veilvoice-policy/src/mandate.rs

veilvoice-policy · 539 lines · read the source here · or on GitHub

The two things VeilVoice insists on unless you say otherwise.

What this is

By default VeilVoice requires an app lock and encryption of every recording at rest. Both matter for the same reason: de-identification removes the voiceprint but keeps the words, so a veiled recording is still a recording of everything that was said, and an unlocked application sitting open is still a window into what you have processed.

So both are on, by default, without anybody choosing them. This module is how you stop insisting on one or both -- a deliberate, recorded choice rather than a setting that quietly drifts.

It is not the sealed policy, and the difference is the point

crate::Policy is the sealed, administrator-set policy that can only ever make VeilVoice stricter and cannot be weakened without the passphrase. This is the opposite tool for the opposite person: it is your own baseline, plainly stored, that you may relax. The two compose safely -- the effective requirement is this baseline OR whatever the sealed policy adds -- so an administrator can still force on something you turned off, and never the other way round.

Why it keeps a history

Turning off encryption or the app lock is exactly the kind of change someone should be able to see was made, when, and away from what. So every change is appended to a log with its timestamp and whether the value it left was the default. Nothing here is secret -- it is your own record of your own decisions -- so it is a plain file you can read.

In plain words

VeilVoice asks for a password for itself and encrypts your recordings, unless you deliberately turn one or both off. It remembers when you did, and what it was before, so the choice is never a mystery later.

WHAT THIS FILE CONTAINS

539 lines defining 24 functions (16 public), 3 types and 1 constant. Everything below is read out of the source, so it cannot disagree with the code.

The types it owns.

  • enum Field line 48 · Which requirement a change concerns.
  • struct Change line 81 · One recorded change.
  • struct Mandate line 94 · The current requirements, and the log of how they got there.

What happens when it runs. These are the ways in: public, and nothing else in this file calls them, so they are what an outside caller reaches first.

  • Field::key line 57 · The word used in the file and on the command line.
  • Mandate::requires_app_lock line 127 · Whether an app lock is required.
  • Mandate::requires_encryption line 132 · Whether encryption of recordings at rest is required.
  • Mandate::requires line 137 · The value of one field.
  • Mandate::is_default line 145 · Whether this is still the default: both required, nothing turned off.
  • Mandate::history line 150 · The change log, oldest first.
  • Mandate::set line 159 · Set one requirement, recording the change if it is actually a change.
    reaches now, set_at
  • Mandate::reset line 189 · Return to the default (both required), recording the changes.
    reaches now, reset_at, set_at
  • Mandate::load line 285 · Load from path, or the default if it is not there.
    reaches default, parse, from_key, parse_bool
  • Mandate::save line 294 · Write to path, owner-only.
    reaches to_text, yesno
  • default_path line 304 · Where the mandate file lives: beside the app lock, under its own name.
  • Change::describe line 336 · A whole sentence describing the change, for a log a person reads.
    reaches when, utc, civil_from_days

WHAT CALLS WHAT

Field::key line 57 Field::from_key line 70 Mandate::default line 103 now line 118 Mandate::requires_app_lock line 127 Mandate::requires_encryption line 132 Mandate::requires line 137 Mandate::is_default line 145 Mandate::set line 159 Mandate::set_at line 169 Mandate::reset line 189 Mandate::reset_at line 198 Mandate::parse line 205 Mandate::to_text line 255 Mandate::load line 285 Mandate::save line 294 parse_bool line 312 yesno line 321 Change::when line 331 Change::describe line 336 utc line 359 civil_from_days line 380 entry: a way in: public, and nothing in this file calls it api: public, and also used inside this file helper: private to this file dashed: a call that goes back up, or across a wrapped rank The functions this file defines, and the calls between them. An edge means the callee's name appears, called, inside the caller's body. This is a syntactic reading, not a type-resolved one. 22 of 24 functions are drawn; the diagram is bounded at 22 so it stays readable.

The functions this file defines, and the calls between them. An edge means the callee's name appears, called, inside the caller's body. This is a syntactic reading, not a type-resolved one. 22 of 24 functions are drawn; the diagram is bounded at 22 so it stays readable.

The same graph as Mermaid source
%%{init: {"theme":"base","themeVariables":{"background":"#1a1b26","primaryColor":"#1f2335","primaryTextColor":"#c0caf5","primaryBorderColor":"#7aa2f7","secondaryColor":"#16161e","tertiaryColor":"#16161e","lineColor":"#737aa2","textColor":"#c0caf5","mainBkg":"#1f2335","nodeBorder":"#7aa2f7","clusterBkg":"#16161e","clusterBorder":"#2f3549","fontFamily":"ui-monospace, SFMono-Regular, Consolas, monospace","fontSize":"14px"}}}%%
flowchart TD
    n_key(["Field::key<br/>line 57"])
    n_from_key["Field::from_key<br/>line 70"]
    n_default["Mandate::default<br/>line 103"]
    n_now["now<br/>line 118"]
    n_requires_app_lock(["Mandate::requires_app_lock<br/>line 127"])
    n_requires_encryption(["Mandate::requires_encryption<br/>line 132"])
    n_requires(["Mandate::requires<br/>line 137"])
    n_is_default(["Mandate::is_default<br/>line 145"])
    n_set(["Mandate::set<br/>line 159"])
    n_set_at["Mandate::set_at<br/>line 169"]
    n_reset(["Mandate::reset<br/>line 189"])
    n_reset_at["Mandate::reset_at<br/>line 198"]
    n_parse["Mandate::parse<br/>line 205"]
    n_to_text["Mandate::to_text<br/>line 255"]
    n_load(["Mandate::load<br/>line 285"])
    n_save(["Mandate::save<br/>line 294"])
    n_parse_bool["parse_bool<br/>line 312"]
    n_yesno["yesno<br/>line 321"]
    n_when["Change::when<br/>line 331"]
    n_describe(["Change::describe<br/>line 336"])
    n_utc["utc<br/>line 359"]
    n_civil_from_days["civil_from_days<br/>line 380"]
    n_describe --> n_when
    n_load --> n_default
    n_load --> n_parse
    n_parse --> n_from_key
    n_parse --> n_parse_bool
    n_reset --> n_now
    n_reset --> n_reset_at
    n_reset_at --> n_set_at
    n_save --> n_to_text
    n_set --> n_now
    n_set --> n_set_at
    n_to_text --> n_yesno
    n_utc --> n_civil_from_days
    n_when --> n_utc
    click n_key href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/mandate.rs#L57" "open the source"
    click n_from_key href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/mandate.rs#L70" "open the source"
    click n_default href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/mandate.rs#L103" "open the source"
    click n_now href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/mandate.rs#L118" "open the source"
    click n_requires_app_lock href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/mandate.rs#L127" "open the source"
    click n_requires_encryption href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/mandate.rs#L132" "open the source"
    click n_requires href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/mandate.rs#L137" "open the source"
    click n_is_default href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/mandate.rs#L145" "open the source"
    click n_set href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/mandate.rs#L159" "open the source"
    click n_set_at href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/mandate.rs#L169" "open the source"
    click n_reset href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/mandate.rs#L189" "open the source"
    click n_reset_at href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/mandate.rs#L198" "open the source"
    click n_parse href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/mandate.rs#L205" "open the source"
    click n_to_text href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/mandate.rs#L255" "open the source"
    click n_load href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/mandate.rs#L285" "open the source"
    click n_save href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/mandate.rs#L294" "open the source"
    click n_parse_bool href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/mandate.rs#L312" "open the source"
    click n_yesno href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/mandate.rs#L321" "open the source"
    click n_when href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/mandate.rs#L331" "open the source"
    click n_describe href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/mandate.rs#L336" "open the source"
    click n_utc href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/mandate.rs#L359" "open the source"
    click n_civil_from_days href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/mandate.rs#L380" "open the source"
    classDef entry fill:#1f2335,stroke:#7aa2f7,color:#c0caf5
    class n_key,n_requires_app_lock,n_requires_encryption,n_requires,n_is_default,n_set,n_reset,n_load,n_save,n_describe entry
    classDef api fill:#1f2335,stroke:#7dcfff,color:#c0caf5
    class n_parse,n_to_text,n_when,n_utc api
    classDef helper fill:#1f2335,stroke:#bb9af7,color:#c0caf5
    class n_from_key,n_default,n_now,n_set_at,n_reset_at,n_parse_bool,n_yesno,n_civil_from_days helper

This site loads no third-party script, so it cannot run Mermaid; the diagram above is the same nodes and edges drawn by the generator instead. GitHub renders the source below directly.

ITEMS

ItemLineDocumentation
MAGIC const44The magic on the first line, so a stray file is not mistaken for this one.
Field pub enum48Which requirement a change concerns.
Field::key pub fn57The word used in the file and on the command line.
Field::from_key fn70The field a key in the file names, or None for one this version does not know.
Change pub struct81One recorded change.
Mandate pub struct94The current requirements, and the log of how they got there.
Mandate::default fn103Both required.
now fn118The clock as seconds since the epoch, without panicking on a clock set before it.
Mandate::requires_app_lock pub fn127Whether an app lock is required.
Mandate::requires_encryption pub fn132Whether encryption of recordings at rest is required.
Mandate::requires pub fn137The value of one field.
Mandate::is_default pub fn145Whether this is still the default: both required, nothing turned off.
Mandate::history pub fn150The change log, oldest first.
Mandate::set pub fn159Set one requirement, recording the change if it is actually a change.
Mandate::set_at fn169Set one field as of at, answering whether anything actually changed.
Mandate::reset pub fn189Return to the default (both required), recording the changes.
Mandate::reset_at fn198Turn every requirement on as of at, answering whether anything changed.
Mandate::parse pub fn205Parse the file format.
Mandate::to_text pub fn255Render the file format.
Mandate::load pub fn285Load from path, or the default if it is not there.
Mandate::save pub fn294Write to path, owner-only.
default_path pub fn304Where the mandate file lives: beside the app lock, under its own name.
parse_bool fn312A yes or no in any of the spellings a person might write, or None.
yesno fn321A boolean in the spelling this file is written in.
Change::when pub fn331When the change was made, as a UTC civil timestamp.
Change::describe pub fn336A whole sentence describing the change, for a log a person reads.
utc pub fn359Unix seconds as YYYY-MM-DD HH:MM:SS UTC.
civil_from_days fn380Days since 1970-01-01 to a civil year, month and day.