crates/veilvoice-policy/src/policy.rs
veilvoice-policy · 984 lines · read the source here · or on GitHub
The policy itself: what can be required, and what requiring it does.
Every requirement tightens, and there is nowhere to write one that does not
Requirement has five variants and all five move VeilVoice in the same direction. There is no AllowPlaintext, no MaximumIntensity, no SkipMetadataCleaning. That is not an oversight to be filled in later; it is the property the whole crate rests on, and Posture::is_at_least_as_strict_as exists so a test can hold it.
Anybody adding a variant should read crate's documentation first. A loosening variant does not merely add a feature: it removes the reason the plain file can be read without a passphrase.
Format
Text, one requirement per line, for the same reason the tamper manifest is text: the point of the file is to be readable by the person it constrains.
VEILPOLICY1
note Set by the IT department. Ask before changing.
require encrypt-recordings
require clean-metadata
require minimum-intensity 80
The floor is a whole number of hundredths, not a decimal. A policy has to compare equal to its own sealed copy, and a value that reads back as 0.7999999 would make crate::verify report Differs for ever.
An unknown require keyword is an error, not a line to skip. A policy written by a newer build says something this one cannot honour, and quietly honouring the rest would leave the machine less restricted than the person who wrote it believes. Refusing says so.
In plain words
A way to say "these settings must always be on", so that they cannot be turned off later by accident.
Everything here only ever tightens. There is deliberately no way to write a rule that makes VeilVoice do less, because a settings file that could weaken the program would be the first thing worth attacking.
If a rule and a control disagree, the rule wins and the window shows you the value that will actually be used, rather than one that quietly changes when you press the button.
WHAT THIS FILE CONTAINS
984 lines defining 25 functions (23 public), 4 types and 3 constants. Everything below is read out of the source, so it cannot disagree with the code.
The types it owns.
enum Requirementline 69 · One thing a policy can insist on.struct Postureline 137 · The settings a policy can reach, as a front end holds them.struct Policyline 194 · A set of requirements, and an optional note from whoever wrote them.enum Verificationline 473 · What is known about the seal on a policy.
What happens when it runs. These are the ways in: public, and nothing else in this file calls them, so they are what an outside caller reaches first.
Requirement::keywordline 88 · The keyword this is written as.Requirement::describeline 103 · What this means, in the words a front end should show beside the control it has taken away.Posture::most_permissiveline 169 · The most permissive arrangement the controls can reach.Posture::is_at_least_as_strict_asline 183 · Whether self is at least as strict as other in every dimension.Policy::requireline 209 · Add a requirement.Policy::with_noteline 226 · Set the note shown beside every control the policy has fixed.Policy::noteline 243 · The note, if there is one.Policy::is_emptyline 248 · Whether anything at all is required.Policy::lenline 253 · How many requirements there are.Policy::requirementsline 258 · The requirements, in a stable order.Policy::constrainline 283 · Apply the policy to a posture.
reachesminimum_intensity,requiresPolicy::saveline 415 · Write the plain policy into dir, and the sealed copy beside it.
reachesseal,to_textVerification::describeline 493 · One line for a front end.Verification::wants_attentionline 518 · Whether this is a state somebody should look at.verifyline 530 · Check the plain policy in dir against its sealed copy.
reachesload,open_sealed,parse,new,requirement_from,default
WHAT CALLS WHAT
The functions this file defines, and the calls between them. An edge means the callee's name appears, called, inside the caller's body. This is a syntactic reading, not a type-resolved one. 22 of 24 functions are drawn; the diagram is bounded at 22 so it stays readable.
The same graph as Mermaid source
%%{init: {"theme":"base","themeVariables":{"background":"#1a1b26","primaryColor":"#1f2335","primaryTextColor":"#c0caf5","primaryBorderColor":"#7aa2f7","secondaryColor":"#16161e","tertiaryColor":"#16161e","lineColor":"#737aa2","textColor":"#c0caf5","mainBkg":"#1f2335","nodeBorder":"#7aa2f7","clusterBkg":"#16161e","clusterBorder":"#2f3549","fontFamily":"ui-monospace, SFMono-Regular, Consolas, monospace","fontSize":"14px"}}}%%
flowchart TD
n_keyword(["Requirement::keyword<br/>line 88"])
n_describe(["Requirement::describe<br/>line 103"])
n_default["Posture::default<br/>line 152"]
n_most_permissive(["Posture::most_permissive<br/>line 169"])
n_is_at_least_as_strict_as(["Posture::<br/>is_at_least_as_strict_as<br/>line 183"])
n_new["Policy::new<br/>line 204"]
n_require(["Policy::require<br/>line 209"])
n_with_note(["Policy::with_note<br/>line 226"])
n_note(["Policy::note<br/>line 243"])
n_is_empty(["Policy::is_empty<br/>line 248"])
n_len(["Policy::len<br/>line 253"])
n_requires["Policy::requires<br/>line 263"]
n_minimum_intensity["Policy::minimum_intensity<br/>line 268"]
n_constrain(["Policy::constrain<br/>line 283"])
n_to_text["Policy::to_text<br/>line 304"]
n_parse["Policy::parse<br/>line 330"]
n_seal["Policy::seal<br/>line 376"]
n_open_sealed["Policy::open_sealed<br/>line 398"]
n_save(["Policy::save<br/>line 415"])
n_load["Policy::load<br/>line 432"]
n_requirement_from["requirement_from<br/>line 441"]
n_verify(["verify<br/>line 530"])
n_constrain --> n_minimum_intensity
n_constrain --> n_requires
n_load --> n_parse
n_new --> n_default
n_open_sealed --> n_parse
n_parse --> n_new
n_parse --> n_requirement_from
n_save --> n_seal
n_save --> n_to_text
n_seal --> n_to_text
n_verify --> n_load
n_verify --> n_open_sealed
click n_keyword href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/policy.rs#L88" "open the source"
click n_describe href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/policy.rs#L103" "open the source"
click n_default href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/policy.rs#L152" "open the source"
click n_most_permissive href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/policy.rs#L169" "open the source"
click n_is_at_least_as_strict_as href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/policy.rs#L183" "open the source"
click n_new href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/policy.rs#L204" "open the source"
click n_require href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/policy.rs#L209" "open the source"
click n_with_note href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/policy.rs#L226" "open the source"
click n_note href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/policy.rs#L243" "open the source"
click n_is_empty href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/policy.rs#L248" "open the source"
click n_len href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/policy.rs#L253" "open the source"
click n_requires href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/policy.rs#L263" "open the source"
click n_minimum_intensity href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/policy.rs#L268" "open the source"
click n_constrain href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/policy.rs#L283" "open the source"
click n_to_text href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/policy.rs#L304" "open the source"
click n_parse href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/policy.rs#L330" "open the source"
click n_seal href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/policy.rs#L376" "open the source"
click n_open_sealed href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/policy.rs#L398" "open the source"
click n_save href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/policy.rs#L415" "open the source"
click n_load href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/policy.rs#L432" "open the source"
click n_requirement_from href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/policy.rs#L441" "open the source"
click n_verify href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-policy/src/policy.rs#L530" "open the source"
classDef entry fill:#1f2335,stroke:#7aa2f7,color:#c0caf5
class n_keyword,n_describe,n_most_permissive,n_is_at_least_as_strict_as,n_require,n_with_note,n_note,n_is_empty,n_len,n_constrain,n_save,n_verify entry
classDef api fill:#1f2335,stroke:#7dcfff,color:#c0caf5
class n_new,n_requires,n_minimum_intensity,n_to_text,n_parse,n_seal,n_open_sealed,n_load api
classDef helper fill:#1f2335,stroke:#bb9af7,color:#c0caf5
class n_default,n_requirement_from helper
This site loads no third-party script, so it cannot run Mermaid; the diagram above is the same nodes and edges drawn by the generator instead. GitHub renders the source below directly.
ITEMS
| Item | Line | Documentation |
|---|---|---|
MAGIC const | 56 | Magic first line. |
PLAIN_FILE pub const | 59 | The plain policy, read at every launch and needing no passphrase. |
SEALED_FILE pub const | 63 | The same policy sealed under a passphrase, for proving the plain one is what was written. |
Requirement pub enum | 69 | One thing a policy can insist on. |
Requirement::keyword pub fn | 88 | The keyword this is written as. |
Requirement::describe pub fn | 103 | What this means, in the words a front end should show beside the control it has taken away. |
Posture pub struct | 137 | The settings a policy can reach, as a front end holds them. |
Posture::default fn | 152 | VeilVoice's own defaults, which are the strict ones. |
Posture::most_permissive pub fn | 169 | The most permissive arrangement the controls can reach. |
Posture::is_at_least_as_strict_as pub fn | 183 | Whether self is at least as strict as other in every dimension. |
Policy pub struct | 194 | A set of requirements, and an optional note from whoever wrote them. |
Policy::new pub fn | 204 | A policy that requires nothing. |
Policy::require pub fn | 209 | Add a requirement. |
Policy::with_note pub fn | 226 | Set the note shown beside every control the policy has fixed. |
Policy::note pub fn | 243 | The note, if there is one. |
Policy::is_empty pub fn | 248 | Whether anything at all is required. |
Policy::len pub fn | 253 | How many requirements there are. |
Policy::requirements pub fn | 258 | The requirements, in a stable order. |
Policy::requires pub fn | 263 | Whether a particular requirement is in force. |
Policy::minimum_intensity pub fn | 268 | The intensity floor, or 0.0 when none is set. |
Policy::constrain pub fn | 283 | Apply the policy to a posture. |
Policy::to_text pub fn | 304 | Serialise to the text format described at the top of this module. |
Policy::parse pub fn | 330 | Parse the text format. |
Policy::seal pub fn | 376 | Seal the policy under a passphrase. |
Policy::open_sealed pub fn | 398 | Open a policy sealed by Policy::seal. |
Policy::save pub fn | 415 | Write the plain policy into dir, and the sealed copy beside it. |
Policy::load pub fn | 432 | Read the plain policy from dir. |
requirement_from fn | 441 | |
Verification pub enum | 473 | What is known about the seal on a policy. |
Verification::describe pub fn | 493 | One line for a front end. |
Verification::wants_attention pub fn | 518 | Whether this is a state somebody should look at. |
verify pub fn | 530 | Check the plain policy in dir against its sealed copy. |