crates/veilvoice-policy/src/mandate.rs
veilvoice-policy · 539 lines · read the source here · or on GitHub
The two things VeilVoice insists on unless you say otherwise.
What this is
By default VeilVoice requires an app lock and encryption of every recording at rest. Both matter for the same reason: de-identification removes the voiceprint but keeps the words, so a veiled recording is still a recording of everything that was said, and an unlocked application sitting open is still a window into what you have processed.
So both are on, by default, without anybody choosing them. This module is how you stop insisting on one or both -- a deliberate, recorded choice rather than a setting that quietly drifts.
It is not the sealed policy, and the difference is the point
crate::Policy is the sealed, administrator-set policy that can only ever make VeilVoice stricter and cannot be weakened without the passphrase. This is the opposite tool for the opposite person: it is your own baseline, plainly stored, that you may relax. The two compose safely -- the effective requirement is this baseline OR whatever the sealed policy adds -- so an administrator can still force on something you turned off, and never the other way round.
Why it keeps a history
Turning off encryption or the app lock is exactly the kind of change someone should be able to see was made, when, and away from what. So every change is appended to a log with its timestamp and whether the value it left was the default. Nothing here is secret -- it is your own record of your own decisions -- so it is a plain file you can read.
In plain words
VeilVoice asks for a password for itself and encrypts your recordings, unless you deliberately turn one or both off. It remembers when you did, and what it was before, so the choice is never a mystery later.
WHAT THIS FILE CONTAINS
539 lines defining 24 functions (16 public), 3 types and 1 constant. Everything below is read out of the source, so it cannot disagree with the code.
The types it owns.
enum Fieldline 48 · Which requirement a change concerns.struct Changeline 81 · One recorded change.struct Mandateline 94 · The current requirements, and the log of how they got there.
What happens when it runs. These are the ways in: public, and nothing else in this file calls them, so they are what an outside caller reaches first.
Field::keyline 57 · The word used in the file and on the command line.Mandate::requires_app_lockline 127 · Whether an app lock is required.Mandate::requires_encryptionline 132 · Whether encryption of recordings at rest is required.Mandate::requiresline 137 · The value of one field.Mandate::is_defaultline 145 · Whether this is still the default: both required, nothing turned off.Mandate::historyline 150 · The change log, oldest first.Mandate::setline 159 · Set one requirement, recording the change if it is actually a change.
reachesnow,set_atMandate::resetline 189 · Return to the default (both required), recording the changes.
reachesnow,reset_at,set_atMandate::loadline 285 · Load from path, or the default if it is not there.
reachesdefault,parse,from_key,parse_boolMandate::saveline 294 · Write to path, owner-only.
reachesto_text,yesnodefault_pathline 304 · Where the mandate file lives: beside the app lock, under its own name.Change::describeline 336 · A whole sentence describing the change, for a log a person reads.
reacheswhen,utc,civil_from_days
WHAT CALLS WHAT
The functions this file defines, and the calls between them. An edge means the callee's name appears, called, inside the caller's body. This is a syntactic reading, not a type-resolved one. 22 of 24 functions are drawn; the diagram is bounded at 22 so it stays readable.
The same graph as Mermaid source
%%{init: {"theme":"base","themeVariables":{"background":"#1a1b26","primaryColor":"#1f2335","primaryTextColor":"#c0caf5","primaryBorderColor":"#7aa2f7","secondaryColor":"#16161e","tertiaryColor":"#16161e","lineColor":"#737aa2","textColor":"#c0caf5","mainBkg":"#1f2335","nodeBorder":"#7aa2f7","clusterBkg":"#16161e","clusterBorder":"#2f3549","fontFamily":"ui-monospace, SFMono-Regular, Consolas, monospace","fontSize":"14px"}}}%%
flowchart TD
n_key(["Field::key<br/>line 57"])
n_from_key["Field::from_key<br/>line 70"]
n_default["Mandate::default<br/>line 103"]
n_now["now<br/>line 118"]
n_requires_app_lock(["Mandate::requires_app_lock<br/>line 127"])
n_requires_encryption(["Mandate::requires_encryption<br/>line 132"])
n_requires(["Mandate::requires<br/>line 137"])
n_is_default(["Mandate::is_default<br/>line 145"])
n_set(["Mandate::set<br/>line 159"])
n_set_at["Mandate::set_at<br/>line 169"]
n_reset(["Mandate::reset<br/>line 189"])
n_reset_at["Mandate::reset_at<br/>line 198"]
n_parse["Mandate::parse<br/>line 205"]
n_to_text["Mandate::to_text<br/>line 255"]
n_load(["Mandate::load<br/>line 285"])
n_save(["Mandate::save<br/>line 294"])
n_parse_bool["parse_bool<br/>line 312"]
n_yesno["yesno<br/>line 321"]
n_when["Change::when<br/>line 331"]
n_describe(["Change::describe<br/>line 336"])
n_utc["utc<br/>line 359"]
n_civil_from_days["civil_from_days<br/>line 380"]
n_describe --> n_when
n_load --> n_default
n_load --> n_parse
n_parse --> n_from_key
n_parse --> n_parse_bool
n_reset --> n_now
n_reset --> n_reset_at
n_reset_at --> n_set_at
n_save --> n_to_text
n_set --> n_now
n_set --> n_set_at
n_to_text --> n_yesno
n_utc --> n_civil_from_days
n_when --> n_utc
click n_key href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/mandate.rs#L57" "open the source"
click n_from_key href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/mandate.rs#L70" "open the source"
click n_default href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/mandate.rs#L103" "open the source"
click n_now href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/mandate.rs#L118" "open the source"
click n_requires_app_lock href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/mandate.rs#L127" "open the source"
click n_requires_encryption href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/mandate.rs#L132" "open the source"
click n_requires href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/mandate.rs#L137" "open the source"
click n_is_default href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/mandate.rs#L145" "open the source"
click n_set href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/mandate.rs#L159" "open the source"
click n_set_at href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/mandate.rs#L169" "open the source"
click n_reset href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/mandate.rs#L189" "open the source"
click n_reset_at href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/mandate.rs#L198" "open the source"
click n_parse href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/mandate.rs#L205" "open the source"
click n_to_text href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/mandate.rs#L255" "open the source"
click n_load href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/mandate.rs#L285" "open the source"
click n_save href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/mandate.rs#L294" "open the source"
click n_parse_bool href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/mandate.rs#L312" "open the source"
click n_yesno href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/mandate.rs#L321" "open the source"
click n_when href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/mandate.rs#L331" "open the source"
click n_describe href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/mandate.rs#L336" "open the source"
click n_utc href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/mandate.rs#L359" "open the source"
click n_civil_from_days href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/mandate.rs#L380" "open the source"
classDef entry fill:#1f2335,stroke:#7aa2f7,color:#c0caf5
class n_key,n_requires_app_lock,n_requires_encryption,n_requires,n_is_default,n_set,n_reset,n_load,n_save,n_describe entry
classDef api fill:#1f2335,stroke:#7dcfff,color:#c0caf5
class n_parse,n_to_text,n_when,n_utc api
classDef helper fill:#1f2335,stroke:#bb9af7,color:#c0caf5
class n_from_key,n_default,n_now,n_set_at,n_reset_at,n_parse_bool,n_yesno,n_civil_from_days helper
This site loads no third-party script, so it cannot run Mermaid; the diagram above is the same nodes and edges drawn by the generator instead. GitHub renders the source below directly.
ITEMS
| Item | Line | Documentation |
|---|---|---|
MAGIC const | 44 | The magic on the first line, so a stray file is not mistaken for this one. |
Field pub enum | 48 | Which requirement a change concerns. |
Field::key pub fn | 57 | The word used in the file and on the command line. |
Field::from_key fn | 70 | The field a key in the file names, or None for one this version does not know. |
Change pub struct | 81 | One recorded change. |
Mandate pub struct | 94 | The current requirements, and the log of how they got there. |
Mandate::default fn | 103 | Both required. |
now fn | 118 | The clock as seconds since the epoch, without panicking on a clock set before it. |
Mandate::requires_app_lock pub fn | 127 | Whether an app lock is required. |
Mandate::requires_encryption pub fn | 132 | Whether encryption of recordings at rest is required. |
Mandate::requires pub fn | 137 | The value of one field. |
Mandate::is_default pub fn | 145 | Whether this is still the default: both required, nothing turned off. |
Mandate::history pub fn | 150 | The change log, oldest first. |
Mandate::set pub fn | 159 | Set one requirement, recording the change if it is actually a change. |
Mandate::set_at fn | 169 | Set one field as of at, answering whether anything actually changed. |
Mandate::reset pub fn | 189 | Return to the default (both required), recording the changes. |
Mandate::reset_at fn | 198 | Turn every requirement on as of at, answering whether anything changed. |
Mandate::parse pub fn | 205 | Parse the file format. |
Mandate::to_text pub fn | 255 | Render the file format. |
Mandate::load pub fn | 285 | Load from path, or the default if it is not there. |
Mandate::save pub fn | 294 | Write to path, owner-only. |
default_path pub fn | 304 | Where the mandate file lives: beside the app lock, under its own name. |
parse_bool fn | 312 | A yes or no in any of the spellings a person might write, or None. |
yesno fn | 321 | A boolean in the spelling this file is written in. |
Change::when pub fn | 331 | When the change was made, as a UTC civil timestamp. |
Change::describe pub fn | 336 | A whole sentence describing the change, for a log a person reads. |
utc pub fn | 359 | Unix seconds as YYYY-MM-DD HH:MM:SS UTC. |
civil_from_days fn | 380 | Days since 1970-01-01 to a civil year, month and day. |