Skip to content

Safety Model

darkstar edited this page Oct 3, 2026 · 2 revisions

Safety Model

Important

Diagnostics may explain and propose. Mutation must be explicit, structured, validated, and reject uncertainty.

Rendering never modifies source files. Automatic remediation is limited to structured edits that:

  1. are marked MachineApplicable;
  2. still match the expected source contents;
  3. use valid UTF-8 boundaries;
  4. don't overlap;
  5. satisfy declared preconditions.

🧱 Safeguards

  • stale-edit rejection and guarded insertion requirements
  • transaction-wide validation, recovery state before writes, rollback on observed write failures
  • optional post-fix verification, with rollback when it fails
  • trusted-root requirements for hydrated compiler edits
  • fail-closed documentation version resolution (ambiguous package versions don't guess)
  • revision-aware rendering that fails closed when source identity no longer matches
  • suggested shell commands are never executed automatically

🔐 Privacy

  • Diagnostic history is privacy-light: no messages, source text, arbitrary attributes or remediation payloads.
  • Capsules and exports are privacy-aware; bridge attachments are private unless explicitly opted in.
  • Forensic output separates evidence from causation; causal claims stay not established unless explicitly recorded.

🔒 Reporting a vulnerability

Email security@cybercoretech.net and please don't open a public issue.

← 🧾 Schemas & Specs  ·  🎨 Themes & Documentation →

🩺 diagprint

⚡ Start

🧱 Build

📤 Ship

🔧 Fix

🔬 Investigate

🛠️ Project


🌐 Site · 📖 docs.rs · 📦 crates.io

Clone this wiki locally