Struct SecurityPolicy
pub struct SecurityPolicy {Show 26 fields
pub autonomy: AutonomyLevel,
pub risk_profile_name: String,
pub delegation_policy: DelegationPolicy,
pub workspace_dir: PathBuf,
pub config_path: Option<PathBuf>,
pub data_dir: Option<PathBuf>,
pub workspace_only: bool,
pub allowed_commands: Vec<String>,
pub forbidden_paths: Vec<String>,
pub allowed_roots: Vec<PathBuf>,
pub allowed_roots_read_only: Vec<PathBuf>,
pub allowed_roots_write_only: Vec<PathBuf>,
pub max_actions_per_hour: u32,
pub max_cost_per_day_cents: u32,
pub require_approval_for_medium_risk: bool,
pub block_high_risk_commands: bool,
pub shell_env_passthrough: Vec<String>,
pub shell_timeout_secs: u64,
pub allowed_tools: Option<Vec<String>>,
pub excluded_tools: Option<Vec<String>>,
pub auto_approve: Vec<String>,
pub always_ask: Vec<String>,
pub sandbox_enabled: Option<bool>,
pub sandbox_backend: Option<String>,
pub firejail_args: Vec<String>,
pub tracker: PerSenderTracker,
}Fields§
§autonomy: AutonomyLevel§risk_profile_name: StringName of the risk profile this policy was built from. Used to gate delegation: a Delegate may only target an agent sharing the caller’s risk profile. Empty when constructed outside the profile path.
delegation_policy: DelegationPolicyWhether and to which agents this profile may delegate.
workspace_dir: PathBuf§config_path: Option<PathBuf>§data_dir: Option<PathBuf>§workspace_only: bool§allowed_commands: Vec<String>§forbidden_paths: Vec<String>§allowed_roots: Vec<PathBuf>Directories the agent can read AND write under. Includes
RiskProfileConfig.allowed_roots plus any cross-agent
AccessMode::ReadWrite grants resolved from
agent.workspace.access at policy construction time.
allowed_roots_read_only: Vec<PathBuf>Directories the agent can read but NOT write under. Populated
from cross-agent AccessMode::Read grants at policy
construction time. Empty when no read-only cross-agent access
is configured.
allowed_roots_write_only: Vec<PathBuf>Directories the agent can write but NOT read under. Populated
from cross-agent AccessMode::Write grants; read-side tools
ignore this list.
max_actions_per_hour: u32§max_cost_per_day_cents: u32§require_approval_for_medium_risk: bool§block_high_risk_commands: bool§shell_env_passthrough: Vec<String>§shell_timeout_secs: u64§allowed_tools: Option<Vec<String>>Tool name allowlist. None is unrestricted (default for agents
without an explicit risk_profile.allowed_tools setting).
Some(vec![]) denies every tool. Some(list) admits only the
listed names. Enforced at the agent loop’s tool-dispatch site.
excluded_tools: Option<Vec<String>>Tool name denylist. Subtracts from the allowed set (whether the
allowed set comes from allowed_tools or from the unrestricted
default). None and Some(vec![]) both mean “exclude nothing”.
auto_approve: Vec<String>Tools that never require approval in this profile. Mirrors
RiskProfileConfig.auto_approve.
always_ask: Vec<String>Tools that always require approval in this profile. Mirrors
RiskProfileConfig.always_ask.
sandbox_enabled: Option<bool>Whether the sandbox is enabled for this profile. None
inherits the global default at the call site.
sandbox_backend: Option<String>Sandbox backend identifier (e.g. "firejail", "landlock").
None inherits the global default.
firejail_args: Vec<String>Extra arguments forwarded to firejail when sandbox_backend
resolves to "firejail".
tracker: PerSenderTrackerImplementations§
Source§impl SecurityPolicy
impl SecurityPolicy
Sourcepub fn is_tool_allowed(&self, name: &str) -> bool
pub fn is_tool_allowed(&self, name: &str) -> bool
True when name is admissible under the current policy.
allowed_tools = None is unrestricted; Some(list) is the
allowlist. excluded_tools always subtracts.
pub fn is_tool_excluded(&self, name: &str) -> bool
Source§impl SecurityPolicy
impl SecurityPolicy
Sourcepub fn command_risk_level(&self, command: &str) -> CommandRiskLevel
pub fn command_risk_level(&self, command: &str) -> CommandRiskLevel
Classify command risk. Any high-risk segment marks the whole command high.
Sourcepub fn validate_command_execution(
&self,
command: &str,
approved: bool,
) -> Result<CommandRiskLevel, String>
pub fn validate_command_execution( &self, command: &str, approved: bool, ) -> Result<CommandRiskLevel, String>
Validate full command execution policy (allowlist + risk gate).
pub fn is_command_allowed(&self, command: &str) -> bool
Sourcepub fn forbidden_path_argument(&self, command: &str) -> Option<String>
pub fn forbidden_path_argument(&self, command: &str) -> Option<String>
Return the first path-like argument blocked by path policy. This is best-effort token parsing for shell commands and is intended as a safety gate before command execution.
Sourcepub fn is_path_allowed(&self, path: &str) -> bool
pub fn is_path_allowed(&self, path: &str) -> bool
Check if a file path is allowed (no path traversal, within workspace)
pub fn is_resolved_path_readable(&self, resolved: &Path) -> bool
pub fn is_resolved_path_allowed(&self, resolved: &Path) -> bool
pub fn is_runtime_config_path(&self, resolved: &Path) -> bool
pub fn runtime_config_violation_message(&self, resolved: &Path) -> String
pub fn resolved_path_violation_message(&self, resolved: &Path) -> String
Sourcepub fn enforce_tool_operation(
&self,
operation: ToolOperation,
operation_name: &str,
) -> Result<(), String>
pub fn enforce_tool_operation( &self, operation: ToolOperation, operation_name: &str, ) -> Result<(), String>
Enforce policy for a tool operation. Read operations are always allowed by autonomy/rate gates. Act operations require non-readonly autonomy and available action budget.
Sourcepub fn record_action(&self) -> bool
pub fn record_action(&self) -> bool
Record an action for the current sender and check if rate-limited.
Returns true if allowed, false if budget exhausted.
Sourcepub fn is_rate_limited(&self) -> bool
pub fn is_rate_limited(&self) -> bool
Check if the current sender would be rate-limited without recording.
pub fn resolve_tool_path(&self, path: &str) -> PathBuf
pub fn is_under_allowed_root(&self, path: &str) -> bool
pub fn is_under_read_only_allowed_root(&self, path: &str) -> bool
Sourcepub fn is_under_any_allowed_root(&self, path: &str) -> bool
pub fn is_under_any_allowed_root(&self, path: &str) -> bool
Union of all three root tiers; directionality is enforced later by the resolved-path checks.
pub fn ensure_no_escalation_beyond( &self, parent: &SecurityPolicy, ) -> Result<(), EscalationViolation>
pub fn from_risk_profile( risk_profile: &RiskProfileConfig, workspace_dir: &Path, ) -> Self
pub fn from_profiles( risk_profile: &RiskProfileConfig, runtime_profile: Option<&RuntimeProfileConfig>, workspace_dir: &Path, ) -> Self
pub fn for_agent(config: &Config, agent_alias: &str) -> Result<Self>
pub fn prompt_summary(&self) -> String
Trait Implementations§
Source§impl Clone for SecurityPolicy
impl Clone for SecurityPolicy
Source§fn clone(&self) -> SecurityPolicy
fn clone(&self) -> SecurityPolicy
1.0.0 (const: unstable) · §fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreSource§impl Debug for SecurityPolicy
impl Debug for SecurityPolicy
Auto Trait Implementations§
impl Freeze for SecurityPolicy
impl !RefUnwindSafe for SecurityPolicy
impl Send for SecurityPolicy
impl Sync for SecurityPolicy
impl Unpin for SecurityPolicy
impl UnsafeUnpin for SecurityPolicy
impl !UnwindSafe for SecurityPolicy
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
§impl<T> Instrument for T
impl<T> Instrument for T
§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more