[INFO] fetching crate apohara-agentguard 0.5.1...
[INFO] documenting apohara-agentguard-0.5.1 against 824336ad4127ce295849937a24c08a4aeff6ada7 for pr-162169
[INFO] extracting crate apohara-agentguard 0.5.1 into /workspace/builds/worker-6-tc1/source
[INFO] removed /workspace/builds/worker-6-tc1/source/rust-toolchain.toml
[INFO] started tweaking crates.io crate apohara-agentguard 0.5.1
[INFO] removed 0 missing tests
[INFO] finished tweaking crates.io crate apohara-agentguard 0.5.1
[INFO] tweaked toml for crates.io crate apohara-agentguard 0.5.1 written to /workspace/builds/worker-6-tc1/source/Cargo.toml
[INFO] validating manifest of crates.io crate apohara-agentguard 0.5.1 on toolchain 824336ad4127ce295849937a24c08a4aeff6ada7
[INFO] running `Command { std: CARGO_HOME="/workspace/cargo-home" RUSTUP_HOME="/workspace/rustup-home" "/workspace/cargo-home/bin/cargo" "+824336ad4127ce295849937a24c08a4aeff6ada7" "metadata" "--manifest-path" "Cargo.toml" "--no-deps", kill_on_drop: false }`
[INFO] crate crates.io crate apohara-agentguard 0.5.1 already has a lockfile, it will not be regenerated
[INFO] running `Command { std: CARGO_HOME="/workspace/cargo-home" RUSTUP_HOME="/workspace/rustup-home" "/workspace/cargo-home/bin/cargo" "+824336ad4127ce295849937a24c08a4aeff6ada7" "fetch" "--manifest-path" "Cargo.toml", kill_on_drop: false }`
[INFO] [stderr]     Blocking waiting for file lock on package cache
[INFO] [stderr]     Updating crates.io index
[INFO] [stderr]     Blocking waiting for file lock on package cache
[INFO] [stderr]  Downloading crates ...
[INFO] [stderr]   Downloaded landlock v0.4.5
[INFO] [stderr]   Downloaded bitflags v2.12.1
[INFO] [stderr]   Downloaded seccompiler v0.5.0
[INFO] running `Command { std: "docker" "create" "-v" "/var/lib/crater-agent-workspace/builds/worker-6-tc1/source:/opt/rustwide/workdir:ro,Z" "-v" "/var/lib/crater-agent-workspace/builds/worker-6-tc1/target:/opt/rustwide/target:rw,Z" "-v" "/var/lib/crater-agent-workspace/cargo-home:/opt/rustwide/cargo-home:ro,Z" "-v" "/var/lib/crater-agent-workspace/rustup-home:/opt/rustwide/rustup-home:ro,Z" "-m" "1610612736" "--network" "none" "ghcr.io/rust-lang/crates-build-env/linux@sha256:8683fc1fc2eb5c9ac98e0d076ab094b2ffac7f99da555d2b6a2e27f346de2ec7" "sleep" "infinity", kill_on_drop: false }`
[INFO] [stdout] 25b54269fc6877893a0f0b362b44eb79fedcc2b6fbb82cd9880be9b654d7b7ec
[INFO] running `Command { std: "docker" "start" "25b54269fc6877893a0f0b362b44eb79fedcc2b6fbb82cd9880be9b654d7b7ec", kill_on_drop: false }`
[INFO] running `Command { std: "docker" "inspect" "25b54269fc6877893a0f0b362b44eb79fedcc2b6fbb82cd9880be9b654d7b7ec", kill_on_drop: false }`
[INFO] running `Command { std: "docker" "exec" "-e" "SOURCE_DIR=/opt/rustwide/workdir" "-e" "CARGO_HOME=/opt/rustwide/cargo-home" "-e" "RUSTUP_HOME=/opt/rustwide/rustup-home" "-e" "CARGO_TARGET_DIR=/opt/rustwide/target" "-w" "/opt/rustwide/workdir" "--user" "0:0" "25b54269fc6877893a0f0b362b44eb79fedcc2b6fbb82cd9880be9b654d7b7ec" "/opt/rustwide/cargo-home/bin/cargo" "+824336ad4127ce295849937a24c08a4aeff6ada7" "metadata" "--no-deps" "--format-version=1", kill_on_drop: false }`
[INFO] running `Command { std: "docker" "inspect" "25b54269fc6877893a0f0b362b44eb79fedcc2b6fbb82cd9880be9b654d7b7ec", kill_on_drop: false }`
[INFO] running `Command { std: "docker" "exec" "-e" "SOURCE_DIR=/opt/rustwide/workdir" "-e" "CARGO_HOME=/opt/rustwide/cargo-home" "-e" "RUSTUP_HOME=/opt/rustwide/rustup-home" "-e" "CARGO_TARGET_DIR=/opt/rustwide/target" "-e" "CARGO_INCREMENTAL=0" "-e" "RUST_BACKTRACE=full" "-e" "RUSTFLAGS=--cap-lints=forbid" "-e" "RUSTDOCFLAGS=--cap-lints=forbid" "-w" "/opt/rustwide/workdir" "--user" "0:0" "25b54269fc6877893a0f0b362b44eb79fedcc2b6fbb82cd9880be9b654d7b7ec" "/opt/rustwide/cargo-home/bin/cargo" "+824336ad4127ce295849937a24c08a4aeff6ada7" "doc" "--frozen" "--no-deps" "--document-private-items" "--message-format=json", kill_on_drop: false }`
[INFO] [stderr]     Checking stable_deref_trait v1.2.1
[INFO] [stderr]    Compiling libc v0.2.186
[INFO] [stderr]    Compiling shlex v2.0.1
[INFO] [stderr]    Compiling find-msvc-tools v0.1.9
[INFO] [stderr]     Checking litemap v0.8.2
[INFO] [stderr]    Compiling serde_core v1.0.229
[INFO] [stderr]     Checking writeable v0.6.3
[INFO] [stderr]    Compiling icu_properties_data v2.2.0
[INFO] [stderr]    Compiling icu_normalizer_data v2.2.0
[INFO] [stderr]     Checking utf8_iter v1.0.4
[INFO] [stderr]     Checking zeroize v1.8.2
[INFO] [stderr]     Checking memchr v2.8.1
[INFO] [stderr]     Checking typenum v1.20.1
[INFO] [stderr]     Checking smallvec v1.15.1
[INFO] [stderr]     Checking utf8parse v0.2.2
[INFO] [stderr]    Compiling syn v2.0.117
[INFO] [stderr]    Compiling syn v3.0.3
[INFO] [stderr]     Checking untrusted v0.9.0
[INFO] [stderr]     Checking anstyle-parse v1.0.0
[INFO] [stderr]     Checking colorchoice v1.0.5
[INFO] [stderr]     Checking rustls-pki-types v1.14.1
[INFO] [stderr]     Checking anstyle v1.0.14
[INFO] [stderr]     Checking percent-encoding v2.3.2
[INFO] [stderr]    Compiling serde_json v1.0.150
[INFO] [stderr]     Checking is_terminal_polyfill v1.70.2
[INFO] [stderr]     Checking anstyle-query v1.1.5
[INFO] [stderr]    Compiling rustls v0.23.40
[INFO] [stderr]    Compiling nix v0.31.3
[INFO] [stderr]     Checking strsim v0.11.1
[INFO] [stderr]     Checking form_urlencoded v1.2.2
[INFO] [stderr]    Compiling cc v1.2.63
[INFO] [stderr]     Checking const-oid v0.10.2
[INFO] [stderr]     Checking anstream v1.0.0
[INFO] [stderr]     Checking subtle v2.6.1
[INFO] [stderr]     Checking winnow v1.0.3
[INFO] [stderr]     Checking regex-syntax v0.8.11
[INFO] [stderr]     Checking clap_lex v1.1.0
[INFO] [stderr]    Compiling anyhow v1.0.104
[INFO] [stderr]    Compiling heck v0.5.0
[INFO] [stderr]     Checking webpki-roots v1.0.7
[INFO] [stderr]     Checking log v0.4.32
[INFO] [stderr]     Checking bitflags v2.12.1
[INFO] [stderr]     Checking toml_parser v1.1.3+spec-1.1.0
[INFO] [stderr]     Checking clap_builder v4.6.6
[INFO] [stderr]     Checking webpki-roots v0.26.11
[INFO] [stderr]     Checking cpufeatures v0.3.0
[INFO] [stderr]     Checking toml_writer v1.1.2+spec-1.1.0
[INFO] [stderr]     Checking aho-corasick v1.1.4
[INFO] [stderr]     Checking hybrid-array v0.4.12
[INFO] [stderr]    Compiling ring v0.17.14
[INFO] [stderr]     Checking block-buffer v0.12.0
[INFO] [stderr]     Checking crypto-common v0.2.2
[INFO] [stderr]     Checking getrandom v0.2.17
[INFO] [stderr]     Checking regex-automata v0.4.18
[INFO] [stderr]     Checking digest v0.11.3
[INFO] [stderr]     Checking sha2 v0.11.0
[INFO] [stderr]    Compiling synstructure v0.13.2
[INFO] [stderr]    Compiling serde_derive v1.0.229
[INFO] [stderr]    Compiling clap_derive v4.6.4
[INFO] [stderr]     Checking toml_datetime v1.1.1+spec-1.1.0
[INFO] [stderr]     Checking serde_spanned v1.1.1
[INFO] [stderr]    Compiling zerovec-derive v0.11.3
[INFO] [stderr]    Compiling displaydoc v0.2.6
[INFO] [stderr]    Compiling thiserror-impl v2.0.18
[INFO] [stderr]    Compiling enumflags2_derive v0.7.12
[INFO] [stderr]     Checking toml v1.1.4+spec-1.1.0
[INFO] [stderr]    Compiling zerofrom-derive v0.1.7
[INFO] [stderr]    Compiling yoke-derive v0.8.2
[INFO] [stderr]     Checking enumflags2 v0.7.12
[INFO] [stderr]     Checking zerofrom v0.1.8
[INFO] [stderr]     Checking yoke v0.8.3
[INFO] [stderr]     Checking zerotrie v0.2.4
[INFO] [stderr]     Checking thiserror v2.0.18
[INFO] [stderr]     Checking zerovec v0.11.6
[INFO] [stderr]     Checking landlock v0.4.5
[INFO] [stderr]     Checking clap v4.6.6
[INFO] [stderr]     Checking regex v1.13.1
[INFO] [stderr]     Checking tinystr v0.8.3
[INFO] [stderr]     Checking potential_utf v0.1.5
[INFO] [stderr]     Checking icu_collections v2.2.0
[INFO] [stderr]     Checking icu_locale_core v2.2.0
[INFO] [stderr]     Checking rustls-webpki v0.103.13
[INFO] [stderr]     Checking icu_provider v2.2.0
[INFO] [stderr]     Checking icu_properties v2.2.0
[INFO] [stderr]     Checking icu_normalizer v2.2.0
[INFO] [stderr]     Checking idna_adapter v1.2.2
[INFO] [stderr]     Checking idna v1.1.0
[INFO] [stderr]     Checking url v2.5.8
[INFO] [stderr]     Checking serde v1.0.229
[INFO] [stderr]     Checking seccompiler v0.5.0
[INFO] [stderr]     Checking ureq v2.12.1
[INFO] [stderr]     Checking apohara-agentguard v0.5.1 (/opt/rustwide/workdir)
[INFO] [stderr]  Documenting apohara-agentguard v0.5.1 (/opt/rustwide/workdir)
[INFO] [stdout] warning: public documentation for `adapters` links to private item `format_decision_core`
[INFO] [stdout]   --> src/adapters/mod.rs:17:16
[INFO] [stdout]    |
[INFO] [stdout] 17 | //!   FIRST ([`format_decision_core`], Oracle U1 nit #5) — the single choke
[INFO] [stdout]    |                ^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout]    = note: `#[warn(rustdoc::private_intra_doc_links)]` on by default
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `claude` links to private item `format_decision_core`
[INFO] [stdout]  --> src/adapters/claude.rs:9:8
[INFO] [stdout]   |
[INFO] [stdout] 9 | //! ([`format_decision_core`]) with the Claude row of the capabilities matrix
[INFO] [stdout]   |        ^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]   |
[INFO] [stdout]   = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `CanonicalTool`
[INFO] [stdout]   --> src/adapters/claude.rs:24:23
[INFO] [stdout]    |
[INFO] [stdout] 24 | /// - `tool_name` → [`CanonicalTool`] (`Bash`/`Read`/`Edit`/`Write`/
[INFO] [stdout]    |                       ^^^^^^^^^^^^^ no item named `CanonicalTool` in scope
[INFO] [stdout]    |
[INFO] [stdout]    = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout]    = note: `#[warn(rustdoc::broken_intra_doc_links)]` on by default
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `CanonicalTool::Mcp`
[INFO] [stdout]   --> src/adapters/claude.rs:26:9
[INFO] [stdout]    |
[INFO] [stdout] 26 | ///   [`CanonicalTool::Mcp`]; anything else stays [`CanonicalTool::Unknown`]
[INFO] [stdout]    |         ^^^^^^^^^^^^^^^^^^ no item named `CanonicalTool` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `CanonicalTool::Unknown`
[INFO] [stdout]   --> src/adapters/claude.rs:26:53
[INFO] [stdout]    |
[INFO] [stdout] 26 | ///   [`CanonicalTool::Mcp`]; anything else stays [`CanonicalTool::Unknown`]
[INFO] [stdout]    |                                                     ^^^^^^^^^^^^^^^^^^^^^^ no item named `CanonicalTool` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `CanonicalTool::Unknown`
[INFO] [stdout]   --> src/adapters/codex.rs:12:43
[INFO] [stdout]    |
[INFO] [stdout] 12 | //! no canonical variant yet — it stays [`CanonicalTool::Unknown`] verbatim
[INFO] [stdout]    |                                           ^^^^^^^^^^^^^^^^^^^^^^ no item named `CanonicalTool` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `audit` links to private item `ChainHashInput`
[INFO] [stdout]   --> src/audit.rs:29:9
[INFO] [stdout]    |
[INFO] [stdout] 29 | //!   [`ChainHashInput`]; the struct's field order IS the canonical order and
[INFO] [stdout]    |         ^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `record` links to private item `RecordLine`
[INFO] [stdout]    --> src/audit.rs:148:57
[INFO] [stdout]     |
[INFO] [stdout] 148 | /// The record is serialized through a borrowed view ([`RecordLine`]) with the
[INFO] [stdout]     |                                                         ^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `anyhow::Err`
[INFO] [stdout]  --> src/config.rs:8:15
[INFO] [stdout]   |
[INFO] [stdout] 8 | //!   [`Err`](anyhow::Err) carrying the offending key/field name in the error
[INFO] [stdout]   |               ^^^^^^^^^^^ no item named `Err` in module `anyhow`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `enabled` links to private item `merge_tightening`
[INFO] [stdout]    --> src/config.rs:100:29
[INFO] [stdout]     |
[INFO] [stdout] 100 |     /// a loud error (see [`merge_tightening`]).
[INFO] [stdout]     |                             ^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `load_default_locations` links to private item `merge_tightening`
[INFO] [stdout]    --> src/config.rs:254:16
[INFO] [stdout]     |
[INFO] [stdout] 254 |     /// (see [`merge_tightening`] for the per-field rules). Any violation is
[INFO] [stdout]     |                ^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `TighteningPresence::TRACKED_KEYS`
[INFO] [stdout]    --> src/config.rs:520:26
[INFO] [stdout]     |
[INFO] [stdout] 520 | /// 2. list its key in [`TighteningPresence::TRACKED_KEYS`],
[INFO] [stdout]     |                          ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ the struct `TighteningPresence` has no field or associated item named `TRACKED_KEYS`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `PROTECTION_CONFIG_FIELDS`
[INFO] [stdout]    --> src/config.rs:527:15
[INFO] [stdout]     |
[INFO] [stdout] 527 | /// against [`PROTECTION_CONFIG_FIELDS`].
[INFO] [stdout]     |               ^^^^^^^^^^^^^^^^^^^^^^^^ no item named `PROTECTION_CONFIG_FIELDS` in scope
[INFO] [stdout]     |
[INFO] [stdout]     = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `firewall` links to private item `djl`
[INFO] [stdout]  --> src/firewall/mod.rs:6:9
[INFO] [stdout]   |
[INFO] [stdout] 6 | //! - [`djl`]: 78 severity-scored rules (sev drives the tier).
[INFO] [stdout]   |         ^^^ this item is private
[INFO] [stdout]   |
[INFO] [stdout]   = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `firewall` links to private item `owasp`
[INFO] [stdout]  --> src/firewall/mod.rs:7:9
[INFO] [stdout]   |
[INFO] [stdout] 7 | //! - [`owasp`]: 24 OWASP ASI default-deny patterns (any match => Block).
[INFO] [stdout]   |         ^^^^^ this item is private
[INFO] [stdout]   |
[INFO] [stdout]   = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `firewall` links to private item `two_stage`
[INFO] [stdout]  --> src/firewall/mod.rs:8:9
[INFO] [stdout]   |
[INFO] [stdout] 8 | //! - [`two_stage`]: the 3 DJL rules whose lookaround patterns the Rust `regex`
[INFO] [stdout]   |         ^^^^^^^^^ this item is private
[INFO] [stdout]   |
[INFO] [stdout]   = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `firewall` links to private item `normalize`
[INFO] [stdout]   --> src/firewall/mod.rs:31:16
[INFO] [stdout]    |
[INFO] [stdout] 31 | //! NOTHING, [`normalize`] escalates through U1..U4 (escape strip → invisible
[INFO] [stdout]    |                ^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `firewall` links to private item `url_exfil::analyze`
[INFO] [stdout]   --> src/firewall/mod.rs:41:7
[INFO] [stdout]    |
[INFO] [stdout] 41 | //! [`url_exfil::analyze`]: `http(s)://` URLs whose query strings carry
[INFO] [stdout]    |       ^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `refetch` links to private item `UreqSource`
[INFO] [stdout]  --> src/firewall/refetch.rs:7:7
[INFO] [stdout]   |
[INFO] [stdout] 7 | //! [`UreqSource`]; tests inject a `MockSource` that returns canned content or a
[INFO] [stdout]   |       ^^^^^^^^^^ this item is private
[INFO] [stdout]   |
[INFO] [stdout]   = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `refetch` links to private item `UreqSource`
[INFO] [stdout]   --> src/firewall/refetch.rs:26:32
[INFO] [stdout]    |
[INFO] [stdout] 26 | //! exact search backend, so [`UreqSource`] performs a plain GET against the
[INFO] [stdout]    |                                ^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `ContentSource` links to private item `UreqSource`
[INFO] [stdout]    --> src/firewall/refetch.rs:109:33
[INFO] [stdout]     |
[INFO] [stdout] 109 | /// hermetic: production uses [`UreqSource`]; tests inject canned content.
[INFO] [stdout]     |                                 ^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `scan_output` links to private item `url_exfil`
[INFO] [stdout]    --> src/firewall/mod.rs:222:30
[INFO] [stdout]     |
[INFO] [stdout] 222 | /// exfiltration detector ([`url_exfil`]) on both passes.
[INFO] [stdout]     |                              ^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `gate` links to private item `resolve`
[INFO] [stdout]  --> src/gate/mod.rs:5:53
[INFO] [stdout]   |
[INFO] [stdout] 5 | //! 1. **Variable aliasing** (`x=rm; $x -rf ~`) — [`resolve`] substitutes
[INFO] [stdout]   |                                                     ^^^^^^^ this item is private
[INFO] [stdout]   |
[INFO] [stdout]   = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `gate` links to private item `decode`
[INFO] [stdout]  --> src/gate/mod.rs:7:61
[INFO] [stdout]   |
[INFO] [stdout] 7 | //! 2. **Base64 smuggling** (`echo … | base64 -d | sh`) — [`decode`] decodes the
[INFO] [stdout]   |                                                             ^^^^^^ this item is private
[INFO] [stdout]   |
[INFO] [stdout]   = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `gate` links to private item `taxonomy`
[INFO] [stdout]   --> src/gate/mod.rs:10:27
[INFO] [stdout]    |
[INFO] [stdout] 10 | //!    `curl … | sh`) — [`taxonomy`] matches per-leg rules plus a pre-split
[INFO] [stdout]    |                           ^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `normalize` links to private item `MAX_NORMALIZE_BYTES`
[INFO] [stdout]   --> src/gate/normalize.rs:22:33
[INFO] [stdout]    |
[INFO] [stdout] 22 | //! Three caps bound fan-out: [`MAX_NORMALIZE_BYTES`] (total size),
[INFO] [stdout]    |                                 ^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `normalize` links to private item `MAX_REWRITES`
[INFO] [stdout]   --> src/gate/normalize.rs:23:7
[INFO] [stdout]    |
[INFO] [stdout] 23 | //! [`MAX_REWRITES`] (number of splices across all passes), and a per-span
[INFO] [stdout]    |       ^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `active_rules`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           With `community_packs.enabled` empty (the default), [`active_rules`]
[INFO] [stdout]                                                                ^^^^^^^^^^^^^^
[INFO] [stdout]   = note: no item named `active_rules` in scope
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `hook` links to private item `dispatch`
[INFO] [stdout]  --> src/hook/mod.rs:7:9
[INFO] [stdout]   |
[INFO] [stdout] 7 | //! - [`dispatch`] — event routing: kill-switch checks, `PreToolUse` /
[INFO] [stdout]   |         ^^^^^^^^ this item is private
[INFO] [stdout]   |
[INFO] [stdout]   = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `hook` links to private item `canary_hook`
[INFO] [stdout]   --> src/hook/mod.rs:14:9
[INFO] [stdout]    |
[INFO] [stdout] 14 | //! - [`canary_hook`] — SessionStart sentinel seeding + PostToolUse canary scan.
[INFO] [stdout]    |         ^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `hook` links to private item `pathguard_hook`
[INFO] [stdout]   --> src/hook/mod.rs:15:9
[INFO] [stdout]    |
[INFO] [stdout] 15 | //! - [`pathguard_hook`] — Read/Write/Edit path-guard integration points.
[INFO] [stdout]    |         ^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `hook` links to private item `canary`
[INFO] [stdout]   --> src/hook/mod.rs:16:9
[INFO] [stdout]    |
[INFO] [stdout] 16 | //! - [`canary`] — the canary token primitive (generate/persist/read).
[INFO] [stdout]    |         ^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `harness` links to private item `crate::contract::cap_reason`
[INFO] [stdout]   --> src/hook/harness.rs:22:9
[INFO] [stdout]    |
[INFO] [stdout] 22 | //!   [`crate::contract::cap_reason`] (display-layer neutralization + cap) —
[INFO] [stdout]    |         ^^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `run_with_source` links to private item `UreqSource`
[INFO] [stdout]   --> src/hook/dispatch.rs:56:61
[INFO] [stdout]    |
[INFO] [stdout] 56 | /// exercised without real network access; [`run`] passes [`UreqSource`].
[INFO] [stdout]    |                                                             ^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `neutralize_reason` links to private item `neutralize`
[INFO] [stdout]    --> src/neutralize.rs:103:44
[INFO] [stdout]     |
[INFO] [stdout] 103 | /// [`crate::verdict::Verdict::reason`] ([`neutralize`], always-owned result).
[INFO] [stdout]     |                                            ^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `Verdict`
[INFO] [stdout]  --> src/policy/mod.rs:4:57
[INFO] [stdout]   |
[INFO] [stdout] 4 | //! existing `toml` crate is the parser) and produces [`Verdict`]s that
[INFO] [stdout]   |                                                         ^^^^^^^ no item named `Verdict` in scope
[INFO] [stdout]   |
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `crate::hook::dispatch::max_verdict`
[INFO] [stdout]  --> src/policy/mod.rs:6:7
[INFO] [stdout]   |
[INFO] [stdout] 6 | //! [`crate::hook::dispatch::max_verdict`] in the hook dispatch.
[INFO] [stdout]   |       ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ no item named `dispatch` in module `hook`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `policy` links to private item `matcher`
[INFO] [stdout]   --> src/policy/mod.rs:12:9
[INFO] [stdout]    |
[INFO] [stdout] 12 | //! - [`matcher`]: the glob/pattern helper. The same `*`-substring semantics
[INFO] [stdout]    |         ^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `PolicyError`
[INFO] [stdout]   --> src/policy/mod.rs:18:40
[INFO] [stdout]    |
[INFO] [stdout] 18 | //!   code-frame renderer that every [`PolicyError`] Display carries (Story
[INFO] [stdout]    |                                        ^^^^^^^^^^^ no item named `PolicyError` in scope
[INFO] [stdout]    |
[INFO] [stdout]    = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `PolicySet`
[INFO] [stdout]   --> src/policy/mod.rs:20:25
[INFO] [stdout]    |
[INFO] [stdout] 20 | //! - [`engine`]: the [`PolicySet`] type. Loads, evaluates, and tracks
[INFO] [stdout]    |                         ^^^^^^^^^ no item named `PolicySet` in scope
[INFO] [stdout]    |
[INFO] [stdout]    = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `PolicySet::load`
[INFO] [stdout]   --> src/policy/mod.rs:25:7
[INFO] [stdout]    |
[INFO] [stdout] 25 | //! [`PolicySet::load`] returns [`PolicyError`] on any IO/parse/schema
[INFO] [stdout]    |       ^^^^^^^^^^^^^^^ no item named `PolicySet` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `PolicyError`
[INFO] [stdout]   --> src/policy/mod.rs:25:35
[INFO] [stdout]    |
[INFO] [stdout] 25 | //! [`PolicySet::load`] returns [`PolicyError`] on any IO/parse/schema
[INFO] [stdout]    |                                   ^^^^^^^^^^^ no item named `PolicyError` in scope
[INFO] [stdout]    |
[INFO] [stdout]    = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `Verdict::block`
[INFO] [stdout]   --> src/policy/mod.rs:27:7
[INFO] [stdout]    |
[INFO] [stdout] 27 | //! [`Verdict::block`] so a misconfigured policy is a hard refusal, never a
[INFO] [stdout]    |       ^^^^^^^^^^^^^^ no item named `Verdict` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `PolicySet::default`
[INFO] [stdout]   --> src/policy/mod.rs:32:35
[INFO] [stdout]    |
[INFO] [stdout] 32 | //! With no policy file loaded, [`PolicySet::default()`] is a no-op combine
[INFO] [stdout]    |                                   ^^^^^^^^^^^^^^^^^^^^ no item named `PolicySet` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `crate::hook::tier_rank`
[INFO] [stdout]   --> src/policy/engine.rs:22:10
[INFO] [stdout]    |
[INFO] [stdout] 22 | //!    [`crate::hook::tier_rank`]. If ANY rule produced a non-Allow
[INFO] [stdout]    |          ^^^^^^^^^^^^^^^^^^^^^^ no item named `tier_rank` in module `hook`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `PolicyError` links to private item `super::spans::render_code_frame`
[INFO] [stdout]   --> src/policy/engine.rs:59:23
[INFO] [stdout]    |
[INFO] [stdout] 59 | /// code frame (see [`super::spans::render_code_frame`]) so the Display of any
[INFO] [stdout]    |                       ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `SchemaVersion` links to private item `CURRENT_SCHEMA_VERSION`
[INFO] [stdout]   --> src/policy/engine.rs:98:35
[INFO] [stdout]    |
[INFO] [stdout] 98 |     /// `schema_version` is not [`CURRENT_SCHEMA_VERSION`]. Located
[INFO] [stdout]    |                                   ^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `load` links to private item `canonical_fingerprint`
[INFO] [stdout]    --> src/policy/engine.rs:200:11
[INFO] [stdout]     |
[INFO] [stdout] 200 |     /// [`canonical_fingerprint`]).
[INFO] [stdout]     |           ^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `crate::hook::dispatch::max_verdict`
[INFO] [stdout]    --> src/policy/engine.rs:543:20
[INFO] [stdout]     |
[INFO] [stdout] 543 | /// identical to [`crate::hook::dispatch::max_verdict`] (Block > Ask > Warn > Allow;
[INFO] [stdout]     |                    ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ no item named `dispatch` in module `hook`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `crate::hook::tier_rank`
[INFO] [stdout]    --> src/policy/engine.rs:545:7
[INFO] [stdout]     |
[INFO] [stdout] 545 | /// [`crate::hook::tier_rank`] is `pub(crate)`; using the canonical
[INFO] [stdout]     |       ^^^^^^^^^^^^^^^^^^^^^^ no item named `tier_rank` in module `hook`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `schema` links to private item `super::matcher`
[INFO] [stdout]  --> src/policy/schema.rs:5:10
[INFO] [stdout]   |
[INFO] [stdout] 5 | //! in [`super::matcher`]. This module is `pub` so the test suite can build
[INFO] [stdout]   |          ^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]   |
[INFO] [stdout]   = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `pattern` links to private item `super::matcher`
[INFO] [stdout]   --> src/policy/schema.rs:89:29
[INFO] [stdout]    |
[INFO] [stdout] 89 |     /// Glob pattern (see [`super::matcher`]). A non-`*` pattern is a literal
[INFO] [stdout]    |                             ^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `schema_version` links to private item `CURRENT_SCHEMA_VERSION`
[INFO] [stdout]    --> src/policy/schema.rs:162:22
[INFO] [stdout]     |
[INFO] [stdout] 162 |     /// Must equal [`CURRENT_SCHEMA_VERSION`]; otherwise the load is
[INFO] [stdout]     |                      ^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `spans` links to private item `render_code_frame`
[INFO] [stdout]   --> src/policy/spans.rs:21:7
[INFO] [stdout]    |
[INFO] [stdout] 21 | //! [`render_code_frame`] turns `(source, location)` into a rustc-style frame:
[INFO] [stdout]    |       ^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `spans` links to private item `MAX_LINE_DISPLAY_CHARS`
[INFO] [stdout]   --> src/policy/spans.rs:31:40
[INFO] [stdout]    |
[INFO] [stdout] 31 | //! starting line; lines longer than [`MAX_LINE_DISPLAY_CHARS`] are shown as a
[INFO] [stdout]    |                                        ^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `gate::evaluate`
[INFO] [stdout]   --> src/proxy/gate.rs:25:24
[INFO] [stdout]    |
[INFO] [stdout] 25 | //!      anti-bypass [`gate::evaluate`] pipeline; a gate `Block` propagates.
[INFO] [stdout]    |                        ^^^^^^^^^^^^^^ no item named `gate` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `gate` links to private item `high_confidence_destructive`
[INFO] [stdout]   --> src/proxy/gate.rs:29:34
[INFO] [stdout]    |
[INFO] [stdout] 29 | //!      structural detectors ([`high_confidence_destructive`]: fetch-piped-
[INFO] [stdout]    |                                  ^^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `pinning` links to private item `PinLock`
[INFO] [stdout]   --> src/proxy/pinning.rs:40:10
[INFO] [stdout]    |
[INFO] [stdout] 40 | //! in [`PinLock`]), and the store is RE-READ inside the critical section, so
[INFO] [stdout]    |          ^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `pinning` links to private item `PinStore::load`
[INFO] [stdout]   --> src/proxy/pinning.rs:47:31
[INFO] [stdout]    |
[INFO] [stdout] 47 | //! torn/corrupt file makes [`PinStore::load`] fail LOUDLY (quarantine-grade),
[INFO] [stdout]    |                               ^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `Matched`
[INFO] [stdout]    --> src/proxy/pinning.rs:488:49
[INFO] [stdout]     |
[INFO] [stdout] 488 |     /// 2. **Store lookup**: matching entry ⇒ [`Matched`] (with
[INFO] [stdout]     |                                                 ^^^^^^^ no item named `Matched` in scope
[INFO] [stdout]     |
[INFO] [stdout]     = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `Mismatch`
[INFO] [stdout]    --> src/proxy/pinning.rs:489:60
[INFO] [stdout]     |
[INFO] [stdout] 489 |     ///    `last_verified` refreshed); differing entry ⇒ [`Mismatch`] (store
[INFO] [stdout]     |                                                            ^^^^^^^^ no item named `Mismatch` in scope
[INFO] [stdout]     |
[INFO] [stdout]     = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `Recorded`
[INFO] [stdout]    --> src/proxy/pinning.rs:490:46
[INFO] [stdout]     |
[INFO] [stdout] 490 |     ///    untouched); no entry ⇒ record ⇒ [`Recorded`].
[INFO] [stdout]     |                                              ^^^^^^^^ no item named `Recorded` in scope
[INFO] [stdout]     |
[INFO] [stdout]     = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `descriptor_hash` links to private item `canonical_tool_descriptor`
[INFO] [stdout]    --> src/proxy/pinning.rs:784:39
[INFO] [stdout]     |
[INFO] [stdout] 784 | /// SHA-256 of one tool's canonical [`canonical_tool_descriptor`].
[INFO] [stdout]     |                                       ^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `fallback`
[INFO] [stdout]   --> src/sandbox/mod.rs:10:42
[INFO] [stdout]    |
[INFO] [stdout] 10 | //! [`SandboxError::Unavailable`] (see [`fallback`]).
[INFO] [stdout]    |                                          ^^^^^^^^ no item named `fallback` in scope
[INFO] [stdout]    |
[INFO] [stdout]    = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `crate::hook::dispatch::max_verdict`
[INFO] [stdout]   --> src/verdict.rs:12:45
[INFO] [stdout]    |
[INFO] [stdout] 12 | /// Precedence (most-severe wins, used by [`crate::hook::dispatch::max_verdict`]):
[INFO] [stdout]    |                                             ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ no item named `dispatch` in module `hook`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `neutralize_reason` links to private item `neutralize`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           transform the MCP surface applies). See [`neutralize`].
[INFO] [stdout]                                                    ^^^^^^^^^^^^
[INFO] [stdout]   = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `neutralize_reason` links to private item `neutralize`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           [`crate::verdict::Verdict::reason`] ([`neutralize`], always-owned result).
[INFO] [stdout]                                                 ^^^^^^^^^^^^
[INFO] [stdout]   = note: this link resolves only because you passed `--document-private-items`, but will break without
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stderr]     Finished `dev` profile [unoptimized + debuginfo] target(s) in 47.91s
[INFO] [stderr] warning: the following packages contain code that will be rejected by a future version of Rust: nix v0.31.3
[INFO] [stderr] note: to see what the problems were, use the option `--future-incompat-report`, or run `cargo report future-incompatibilities --id 3`
[INFO] [stderr]    Generated /opt/rustwide/target/doc/apohara_agentguard/index.html and 1 other file
[INFO] running `Command { std: "docker" "inspect" "25b54269fc6877893a0f0b362b44eb79fedcc2b6fbb82cd9880be9b654d7b7ec", kill_on_drop: false }`
[INFO] running `Command { std: "docker" "exec" "-e" "SOURCE_DIR=/opt/rustwide/workdir" "-e" "CARGO_HOME=/opt/rustwide/cargo-home" "-e" "RUSTUP_HOME=/opt/rustwide/rustup-home" "-e" "CARGO_TARGET_DIR=/opt/rustwide/target" "-e" "CARGO_INCREMENTAL=0" "-e" "RUST_BACKTRACE=full" "-e" "RUSTFLAGS=--cap-lints=forbid" "-e" "RUSTDOCFLAGS=--cap-lints=forbid" "-e" "DOCS_RS=1" "-e" "RUSTC_BOOTSTRAP=1" "-w" "/opt/rustwide/workdir" "--user" "0:0" "25b54269fc6877893a0f0b362b44eb79fedcc2b6fbb82cd9880be9b654d7b7ec" "/opt/rustwide/cargo-home/bin/cargo" "+824336ad4127ce295849937a24c08a4aeff6ada7" "rustdoc" "--lib" "-Zrustdoc-map" "--config" "build.rustdocflags=[\"--cfg\", \"docsrs\", \"-Z\", \"unstable-options\", \"--document-private-items\"]" "--frozen" "--message-format=json", kill_on_drop: false }`
[INFO] [stderr]  Documenting apohara-agentguard v0.5.1 (/opt/rustwide/workdir)
[INFO] [stdout] warning: public documentation for `adapters` links to private item `format_decision_core`
[INFO] [stdout]   --> src/adapters/mod.rs:17:16
[INFO] [stdout]    |
[INFO] [stdout] 17 | //!   FIRST ([`format_decision_core`], Oracle U1 nit #5) — the single choke
[INFO] [stdout]    |                ^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout]    = note: `#[warn(rustdoc::private_intra_doc_links)]` on by default
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `claude` links to private item `format_decision_core`
[INFO] [stdout]  --> src/adapters/claude.rs:9:8
[INFO] [stdout]   |
[INFO] [stdout] 9 | //! ([`format_decision_core`]) with the Claude row of the capabilities matrix
[INFO] [stdout]   |        ^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]   |
[INFO] [stdout]   = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `CanonicalTool`
[INFO] [stdout]   --> src/adapters/claude.rs:24:23
[INFO] [stdout]    |
[INFO] [stdout] 24 | /// - `tool_name` → [`CanonicalTool`] (`Bash`/`Read`/`Edit`/`Write`/
[INFO] [stdout]    |                       ^^^^^^^^^^^^^ no item named `CanonicalTool` in scope
[INFO] [stdout]    |
[INFO] [stdout]    = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout]    = note: `#[warn(rustdoc::broken_intra_doc_links)]` on by default
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `CanonicalTool::Mcp`
[INFO] [stdout]   --> src/adapters/claude.rs:26:9
[INFO] [stdout]    |
[INFO] [stdout] 26 | ///   [`CanonicalTool::Mcp`]; anything else stays [`CanonicalTool::Unknown`]
[INFO] [stdout]    |         ^^^^^^^^^^^^^^^^^^ no item named `CanonicalTool` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `CanonicalTool::Unknown`
[INFO] [stdout]   --> src/adapters/claude.rs:26:53
[INFO] [stdout]    |
[INFO] [stdout] 26 | ///   [`CanonicalTool::Mcp`]; anything else stays [`CanonicalTool::Unknown`]
[INFO] [stdout]    |                                                     ^^^^^^^^^^^^^^^^^^^^^^ no item named `CanonicalTool` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `CanonicalTool::Unknown`
[INFO] [stdout]   --> src/adapters/codex.rs:12:43
[INFO] [stdout]    |
[INFO] [stdout] 12 | //! no canonical variant yet — it stays [`CanonicalTool::Unknown`] verbatim
[INFO] [stdout]    |                                           ^^^^^^^^^^^^^^^^^^^^^^ no item named `CanonicalTool` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `audit` links to private item `ChainHashInput`
[INFO] [stdout]   --> src/audit.rs:29:9
[INFO] [stdout]    |
[INFO] [stdout] 29 | //!   [`ChainHashInput`]; the struct's field order IS the canonical order and
[INFO] [stdout]    |         ^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `record` links to private item `RecordLine`
[INFO] [stdout]    --> src/audit.rs:148:57
[INFO] [stdout]     |
[INFO] [stdout] 148 | /// The record is serialized through a borrowed view ([`RecordLine`]) with the
[INFO] [stdout]     |                                                         ^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `anyhow::Err`
[INFO] [stdout]  --> src/config.rs:8:15
[INFO] [stdout]   |
[INFO] [stdout] 8 | //!   [`Err`](anyhow::Err) carrying the offending key/field name in the error
[INFO] [stdout]   |               ^^^^^^^^^^^ no item named `Err` in module `anyhow`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `enabled` links to private item `merge_tightening`
[INFO] [stdout]    --> src/config.rs:100:29
[INFO] [stdout]     |
[INFO] [stdout] 100 |     /// a loud error (see [`merge_tightening`]).
[INFO] [stdout]     |                             ^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `load_default_locations` links to private item `merge_tightening`
[INFO] [stdout]    --> src/config.rs:254:16
[INFO] [stdout]     |
[INFO] [stdout] 254 |     /// (see [`merge_tightening`] for the per-field rules). Any violation is
[INFO] [stdout]     |                ^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `firewall` links to private item `djl`
[INFO] [stdout]  --> src/firewall/mod.rs:6:9
[INFO] [stdout]   |
[INFO] [stdout] 6 | //! - [`djl`]: 78 severity-scored rules (sev drives the tier).
[INFO] [stdout]   |         ^^^ this item is private
[INFO] [stdout]   |
[INFO] [stdout]   = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `firewall` links to private item `owasp`
[INFO] [stdout]  --> src/firewall/mod.rs:7:9
[INFO] [stdout]   |
[INFO] [stdout] 7 | //! - [`owasp`]: 24 OWASP ASI default-deny patterns (any match => Block).
[INFO] [stdout]   |         ^^^^^ this item is private
[INFO] [stdout]   |
[INFO] [stdout]   = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `firewall` links to private item `two_stage`
[INFO] [stdout]  --> src/firewall/mod.rs:8:9
[INFO] [stdout]   |
[INFO] [stdout] 8 | //! - [`two_stage`]: the 3 DJL rules whose lookaround patterns the Rust `regex`
[INFO] [stdout]   |         ^^^^^^^^^ this item is private
[INFO] [stdout]   |
[INFO] [stdout]   = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `firewall` links to private item `normalize`
[INFO] [stdout]   --> src/firewall/mod.rs:31:16
[INFO] [stdout]    |
[INFO] [stdout] 31 | //! NOTHING, [`normalize`] escalates through U1..U4 (escape strip → invisible
[INFO] [stdout]    |                ^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `firewall` links to private item `url_exfil::analyze`
[INFO] [stdout]   --> src/firewall/mod.rs:41:7
[INFO] [stdout]    |
[INFO] [stdout] 41 | //! [`url_exfil::analyze`]: `http(s)://` URLs whose query strings carry
[INFO] [stdout]    |       ^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `refetch` links to private item `UreqSource`
[INFO] [stdout]  --> src/firewall/refetch.rs:7:7
[INFO] [stdout]   |
[INFO] [stdout] 7 | //! [`UreqSource`]; tests inject a `MockSource` that returns canned content or a
[INFO] [stdout]   |       ^^^^^^^^^^ this item is private
[INFO] [stdout]   |
[INFO] [stdout]   = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `refetch` links to private item `UreqSource`
[INFO] [stdout]   --> src/firewall/refetch.rs:26:32
[INFO] [stdout]    |
[INFO] [stdout] 26 | //! exact search backend, so [`UreqSource`] performs a plain GET against the
[INFO] [stdout]    |                                ^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `ContentSource` links to private item `UreqSource`
[INFO] [stdout]    --> src/firewall/refetch.rs:109:33
[INFO] [stdout]     |
[INFO] [stdout] 109 | /// hermetic: production uses [`UreqSource`]; tests inject canned content.
[INFO] [stdout]     |                                 ^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `scan_output` links to private item `url_exfil`
[INFO] [stdout]    --> src/firewall/mod.rs:222:30
[INFO] [stdout]     |
[INFO] [stdout] 222 | /// exfiltration detector ([`url_exfil`]) on both passes.
[INFO] [stdout]     |                              ^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `gate` links to private item `resolve`
[INFO] [stdout]  --> src/gate/mod.rs:5:53
[INFO] [stdout]   |
[INFO] [stdout] 5 | //! 1. **Variable aliasing** (`x=rm; $x -rf ~`) — [`resolve`] substitutes
[INFO] [stdout]   |                                                     ^^^^^^^ this item is private
[INFO] [stdout]   |
[INFO] [stdout]   = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `gate` links to private item `decode`
[INFO] [stdout]  --> src/gate/mod.rs:7:61
[INFO] [stdout]   |
[INFO] [stdout] 7 | //! 2. **Base64 smuggling** (`echo … | base64 -d | sh`) — [`decode`] decodes the
[INFO] [stdout]   |                                                             ^^^^^^ this item is private
[INFO] [stdout]   |
[INFO] [stdout]   = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `gate` links to private item `taxonomy`
[INFO] [stdout]   --> src/gate/mod.rs:10:27
[INFO] [stdout]    |
[INFO] [stdout] 10 | //!    `curl … | sh`) — [`taxonomy`] matches per-leg rules plus a pre-split
[INFO] [stdout]    |                           ^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `normalize` links to private item `MAX_NORMALIZE_BYTES`
[INFO] [stdout]   --> src/gate/normalize.rs:22:33
[INFO] [stdout]    |
[INFO] [stdout] 22 | //! Three caps bound fan-out: [`MAX_NORMALIZE_BYTES`] (total size),
[INFO] [stdout]    |                                 ^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `normalize` links to private item `MAX_REWRITES`
[INFO] [stdout]   --> src/gate/normalize.rs:23:7
[INFO] [stdout]    |
[INFO] [stdout] 23 | //! [`MAX_REWRITES`] (number of splices across all passes), and a per-span
[INFO] [stdout]    |       ^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `hook` links to private item `dispatch`
[INFO] [stdout]  --> src/hook/mod.rs:7:9
[INFO] [stdout]   |
[INFO] [stdout] 7 | //! - [`dispatch`] — event routing: kill-switch checks, `PreToolUse` /
[INFO] [stdout]   |         ^^^^^^^^ this item is private
[INFO] [stdout]   |
[INFO] [stdout]   = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `hook` links to private item `canary_hook`
[INFO] [stdout]   --> src/hook/mod.rs:14:9
[INFO] [stdout]    |
[INFO] [stdout] 14 | //! - [`canary_hook`] — SessionStart sentinel seeding + PostToolUse canary scan.
[INFO] [stdout]    |         ^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `hook` links to private item `pathguard_hook`
[INFO] [stdout]   --> src/hook/mod.rs:15:9
[INFO] [stdout]    |
[INFO] [stdout] 15 | //! - [`pathguard_hook`] — Read/Write/Edit path-guard integration points.
[INFO] [stdout]    |         ^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `hook` links to private item `canary`
[INFO] [stdout]   --> src/hook/mod.rs:16:9
[INFO] [stdout]    |
[INFO] [stdout] 16 | //! - [`canary`] — the canary token primitive (generate/persist/read).
[INFO] [stdout]    |         ^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `harness` links to private item `crate::contract::cap_reason`
[INFO] [stdout]   --> src/hook/harness.rs:22:9
[INFO] [stdout]    |
[INFO] [stdout] 22 | //!   [`crate::contract::cap_reason`] (display-layer neutralization + cap) —
[INFO] [stdout]    |         ^^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `run_with_source` links to private item `UreqSource`
[INFO] [stdout]   --> src/hook/dispatch.rs:56:61
[INFO] [stdout]    |
[INFO] [stdout] 56 | /// exercised without real network access; [`run`] passes [`UreqSource`].
[INFO] [stdout]    |                                                             ^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `neutralize_reason` links to private item `neutralize`
[INFO] [stdout]    --> src/neutralize.rs:103:44
[INFO] [stdout]     |
[INFO] [stdout] 103 | /// [`crate::verdict::Verdict::reason`] ([`neutralize`], always-owned result).
[INFO] [stdout]     |                                            ^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `Verdict`
[INFO] [stdout]  --> src/policy/mod.rs:4:57
[INFO] [stdout]   |
[INFO] [stdout] 4 | //! existing `toml` crate is the parser) and produces [`Verdict`]s that
[INFO] [stdout]   |                                                         ^^^^^^^ no item named `Verdict` in scope
[INFO] [stdout]   |
[INFO] [stdout]   = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `crate::hook::dispatch::max_verdict`
[INFO] [stdout]  --> src/policy/mod.rs:6:7
[INFO] [stdout]   |
[INFO] [stdout] 6 | //! [`crate::hook::dispatch::max_verdict`] in the hook dispatch.
[INFO] [stdout]   |       ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ no item named `dispatch` in module `hook`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `policy` links to private item `matcher`
[INFO] [stdout]   --> src/policy/mod.rs:12:9
[INFO] [stdout]    |
[INFO] [stdout] 12 | //! - [`matcher`]: the glob/pattern helper. The same `*`-substring semantics
[INFO] [stdout]    |         ^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `PolicyError`
[INFO] [stdout]   --> src/policy/mod.rs:18:40
[INFO] [stdout]    |
[INFO] [stdout] 18 | //!   code-frame renderer that every [`PolicyError`] Display carries (Story
[INFO] [stdout]    |                                        ^^^^^^^^^^^ no item named `PolicyError` in scope
[INFO] [stdout]    |
[INFO] [stdout]    = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `PolicySet`
[INFO] [stdout]   --> src/policy/mod.rs:20:25
[INFO] [stdout]    |
[INFO] [stdout] 20 | //! - [`engine`]: the [`PolicySet`] type. Loads, evaluates, and tracks
[INFO] [stdout]    |                         ^^^^^^^^^ no item named `PolicySet` in scope
[INFO] [stdout]    |
[INFO] [stdout]    = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `PolicySet::load`
[INFO] [stdout]   --> src/policy/mod.rs:25:7
[INFO] [stdout]    |
[INFO] [stdout] 25 | //! [`PolicySet::load`] returns [`PolicyError`] on any IO/parse/schema
[INFO] [stdout]    |       ^^^^^^^^^^^^^^^ no item named `PolicySet` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `PolicyError`
[INFO] [stdout]   --> src/policy/mod.rs:25:35
[INFO] [stdout]    |
[INFO] [stdout] 25 | //! [`PolicySet::load`] returns [`PolicyError`] on any IO/parse/schema
[INFO] [stdout]    |                                   ^^^^^^^^^^^ no item named `PolicyError` in scope
[INFO] [stdout]    |
[INFO] [stdout]    = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `Verdict::block`
[INFO] [stdout]   --> src/policy/mod.rs:27:7
[INFO] [stdout]    |
[INFO] [stdout] 27 | //! [`Verdict::block`] so a misconfigured policy is a hard refusal, never a
[INFO] [stdout]    |       ^^^^^^^^^^^^^^ no item named `Verdict` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `PolicySet::default`
[INFO] [stdout]   --> src/policy/mod.rs:32:35
[INFO] [stdout]    |
[INFO] [stdout] 32 | //! With no policy file loaded, [`PolicySet::default()`] is a no-op combine
[INFO] [stdout]    |                                   ^^^^^^^^^^^^^^^^^^^^ no item named `PolicySet` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `crate::hook::tier_rank`
[INFO] [stdout]   --> src/policy/engine.rs:22:10
[INFO] [stdout]    |
[INFO] [stdout] 22 | //!    [`crate::hook::tier_rank`]. If ANY rule produced a non-Allow
[INFO] [stdout]    |          ^^^^^^^^^^^^^^^^^^^^^^ no item named `tier_rank` in module `hook`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `PolicyError` links to private item `super::spans::render_code_frame`
[INFO] [stdout]   --> src/policy/engine.rs:59:23
[INFO] [stdout]    |
[INFO] [stdout] 59 | /// code frame (see [`super::spans::render_code_frame`]) so the Display of any
[INFO] [stdout]    |                       ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `SchemaVersion` links to private item `CURRENT_SCHEMA_VERSION`
[INFO] [stdout]   --> src/policy/engine.rs:98:35
[INFO] [stdout]    |
[INFO] [stdout] 98 |     /// `schema_version` is not [`CURRENT_SCHEMA_VERSION`]. Located
[INFO] [stdout]    |                                   ^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `load` links to private item `canonical_fingerprint`
[INFO] [stdout]    --> src/policy/engine.rs:200:11
[INFO] [stdout]     |
[INFO] [stdout] 200 |     /// [`canonical_fingerprint`]).
[INFO] [stdout]     |           ^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `schema` links to private item `super::matcher`
[INFO] [stdout]  --> src/policy/schema.rs:5:10
[INFO] [stdout]   |
[INFO] [stdout] 5 | //! in [`super::matcher`]. This module is `pub` so the test suite can build
[INFO] [stdout]   |          ^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]   |
[INFO] [stdout]   = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `pattern` links to private item `super::matcher`
[INFO] [stdout]   --> src/policy/schema.rs:89:29
[INFO] [stdout]    |
[INFO] [stdout] 89 |     /// Glob pattern (see [`super::matcher`]). A non-`*` pattern is a literal
[INFO] [stdout]    |                             ^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `schema_version` links to private item `CURRENT_SCHEMA_VERSION`
[INFO] [stdout]    --> src/policy/schema.rs:162:22
[INFO] [stdout]     |
[INFO] [stdout] 162 |     /// Must equal [`CURRENT_SCHEMA_VERSION`]; otherwise the load is
[INFO] [stdout]     |                      ^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `spans` links to private item `render_code_frame`
[INFO] [stdout]   --> src/policy/spans.rs:21:7
[INFO] [stdout]    |
[INFO] [stdout] 21 | //! [`render_code_frame`] turns `(source, location)` into a rustc-style frame:
[INFO] [stdout]    |       ^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `spans` links to private item `MAX_LINE_DISPLAY_CHARS`
[INFO] [stdout]   --> src/policy/spans.rs:31:40
[INFO] [stdout]    |
[INFO] [stdout] 31 | //! starting line; lines longer than [`MAX_LINE_DISPLAY_CHARS`] are shown as a
[INFO] [stdout]    |                                        ^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `gate::evaluate`
[INFO] [stdout]   --> src/proxy/gate.rs:25:24
[INFO] [stdout]    |
[INFO] [stdout] 25 | //!      anti-bypass [`gate::evaluate`] pipeline; a gate `Block` propagates.
[INFO] [stdout]    |                        ^^^^^^^^^^^^^^ no item named `gate` in scope
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `gate` links to private item `high_confidence_destructive`
[INFO] [stdout]   --> src/proxy/gate.rs:29:34
[INFO] [stdout]    |
[INFO] [stdout] 29 | //!      structural detectors ([`high_confidence_destructive`]: fetch-piped-
[INFO] [stdout]    |                                  ^^^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `pinning` links to private item `PinLock`
[INFO] [stdout]   --> src/proxy/pinning.rs:40:10
[INFO] [stdout]    |
[INFO] [stdout] 40 | //! in [`PinLock`]), and the store is RE-READ inside the critical section, so
[INFO] [stdout]    |          ^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `pinning` links to private item `PinStore::load`
[INFO] [stdout]   --> src/proxy/pinning.rs:47:31
[INFO] [stdout]    |
[INFO] [stdout] 47 | //! torn/corrupt file makes [`PinStore::load`] fail LOUDLY (quarantine-grade),
[INFO] [stdout]    |                               ^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]    |
[INFO] [stdout]    = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `Matched`
[INFO] [stdout]    --> src/proxy/pinning.rs:488:49
[INFO] [stdout]     |
[INFO] [stdout] 488 |     /// 2. **Store lookup**: matching entry ⇒ [`Matched`] (with
[INFO] [stdout]     |                                                 ^^^^^^^ no item named `Matched` in scope
[INFO] [stdout]     |
[INFO] [stdout]     = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `Mismatch`
[INFO] [stdout]    --> src/proxy/pinning.rs:489:60
[INFO] [stdout]     |
[INFO] [stdout] 489 |     ///    `last_verified` refreshed); differing entry ⇒ [`Mismatch`] (store
[INFO] [stdout]     |                                                            ^^^^^^^^ no item named `Mismatch` in scope
[INFO] [stdout]     |
[INFO] [stdout]     = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `Recorded`
[INFO] [stdout]    --> src/proxy/pinning.rs:490:46
[INFO] [stdout]     |
[INFO] [stdout] 490 |     ///    untouched); no entry ⇒ record ⇒ [`Recorded`].
[INFO] [stdout]     |                                              ^^^^^^^^ no item named `Recorded` in scope
[INFO] [stdout]     |
[INFO] [stdout]     = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `descriptor_hash` links to private item `canonical_tool_descriptor`
[INFO] [stdout]    --> src/proxy/pinning.rs:784:39
[INFO] [stdout]     |
[INFO] [stdout] 784 | /// SHA-256 of one tool's canonical [`canonical_tool_descriptor`].
[INFO] [stdout]     |                                       ^^^^^^^^^^^^^^^^^^^^^^^^^ this item is private
[INFO] [stdout]     |
[INFO] [stdout]     = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `fallback`
[INFO] [stdout]   --> src/sandbox/mod.rs:10:42
[INFO] [stdout]    |
[INFO] [stdout] 10 | //! [`SandboxError::Unavailable`] (see [`fallback`]).
[INFO] [stdout]    |                                          ^^^^^^^^ no item named `fallback` in scope
[INFO] [stdout]    |
[INFO] [stdout]    = help: to escape `[` and `]` characters, add '\' before them like `\[` or `\]`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: unresolved link to `crate::hook::dispatch::max_verdict`
[INFO] [stdout]   --> src/verdict.rs:12:45
[INFO] [stdout]    |
[INFO] [stdout] 12 | /// Precedence (most-severe wins, used by [`crate::hook::dispatch::max_verdict`]):
[INFO] [stdout]    |                                             ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ no item named `dispatch` in module `hook`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `neutralize_reason` links to private item `neutralize`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           transform the MCP surface applies). See [`neutralize`].
[INFO] [stdout]                                                    ^^^^^^^^^^^^
[INFO] [stdout]   = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stdout] warning: public documentation for `neutralize_reason` links to private item `neutralize`
[INFO] [stdout]   |
[INFO] [stdout]   = note: the link appears in this line:
[INFO] [stdout]           
[INFO] [stdout]           [`crate::verdict::Verdict::reason`] ([`neutralize`], always-owned result).
[INFO] [stdout]                                                 ^^^^^^^^^^^^
[INFO] [stdout]   = note: this link will resolve properly if you pass `--document-private-items`
[INFO] [stdout] 
[INFO] [stdout] 
[INFO] [stderr]     Finished `dev` profile [unoptimized + debuginfo] target(s) in 1.85s
[INFO] [stderr] warning: the following packages contain code that will be rejected by a future version of Rust: nix v0.31.3
[INFO] [stderr] note: to see what the problems were, use the option `--future-incompat-report`, or run `cargo report future-incompatibilities --id 3`
[INFO] [stderr]    Generated /opt/rustwide/target/doc/apohara_agentguard/index.html
[INFO] running `Command { std: "docker" "inspect" "25b54269fc6877893a0f0b362b44eb79fedcc2b6fbb82cd9880be9b654d7b7ec", kill_on_drop: false }`
[INFO] running `Command { std: "docker" "rm" "-f" "25b54269fc6877893a0f0b362b44eb79fedcc2b6fbb82cd9880be9b654d7b7ec", kill_on_drop: false }`
[INFO] [stdout] 25b54269fc6877893a0f0b362b44eb79fedcc2b6fbb82cd9880be9b654d7b7ec
