lock.rs

crates/veilvoice-cli/src/lock.rs

veilvoice-cli · 347 lines · read the source here · or on GitHub

veilvoice lock manages the application lock from the command line.

The lock guards the desktop app: with one set, VeilVoice asks for a password before it will show anything or start a live scramble. Managing it from here exists because a headless machine still has a config directory, and because anything the GUI can do to a file on disk should be inspectable without the GUI.

Every path through this module prints veilvoice_crypto::lock::SCOPE, for one reason: a lock the user believes is stronger than it is has made them less safe, not more.

In plain words

Sets, changes and clears the passphrase that opens the desktop application, from a terminal.

It is the same lock the window uses and the same file, so the two cannot get out of step. What it is worth is printed with it: it stops somebody who picks up your unlocked computer, and it does not stop somebody holding your disk.

WHAT THIS FILE CONTAINS

347 lines defining 12 functions (2 public), 2 types and 0 constants. Everything below is read out of the source, so it cannot disagree with the code.

The types it owns.

  • enum Action line 30
  • enum Site line 50 · Where the lock is kept for this invocation.

What happens when it runs. These are the ways in: public, and nothing else in this file calls them, so they are what an outside caller reaches first.

  • run line 135 · Dispatch veilvoice lock to the subcommand that was asked for.
    reaches change, remove, resolve, set, status, open_or_explain, print_scope, wrap

WHAT CALLS WHAT

Site::resolve line 58 Site::describe line 74 Site::open line 85 Site::create line 96 print_scope line 107 wrap line 116 run line 135 status line 152 set line 209 change line 252 remove line 265 open_or_explain line 277 entry: a way in: public, and nothing in this file calls it api: public, and also used inside this file helper: private to this file dashed: a call that goes back up, or across a wrapped rank The functions this file defines, and the calls between them. An edge means the callee's name appears, called, inside the caller's body. This is a syntactic reading, not a type-resolved one.

The functions this file defines, and the calls between them. An edge means the callee's name appears, called, inside the caller's body. This is a syntactic reading, not a type-resolved one.

The same graph as Mermaid source
%%{init: {"theme":"base","themeVariables":{"background":"#1a1b26","primaryColor":"#1f2335","primaryTextColor":"#c0caf5","primaryBorderColor":"#7aa2f7","secondaryColor":"#16161e","tertiaryColor":"#16161e","lineColor":"#737aa2","textColor":"#c0caf5","mainBkg":"#1f2335","nodeBorder":"#7aa2f7","clusterBkg":"#16161e","clusterBorder":"#2f3549","fontFamily":"ui-monospace, SFMono-Regular, Consolas, monospace","fontSize":"14px"}}}%%
flowchart TD
    n_resolve["Site::resolve<br/>line 58"]
    n_describe["Site::describe<br/>line 74"]
    n_open["Site::open<br/>line 85"]
    n_create["Site::create<br/>line 96"]
    n_print_scope["print_scope<br/>line 107"]
    n_wrap["wrap<br/>line 116"]
    n_run(["run<br/>line 135"])
    n_status["status<br/>line 152"]
    n_set["set<br/>line 209"]
    n_change["change<br/>line 252"]
    n_remove["remove<br/>line 265"]
    n_open_or_explain["open_or_explain<br/>line 277"]
    n_change --> n_open_or_explain
    n_print_scope --> n_wrap
    n_remove --> n_open_or_explain
    n_run --> n_change
    n_run --> n_remove
    n_run --> n_resolve
    n_run --> n_set
    n_run --> n_status
    n_set --> n_print_scope
    n_status --> n_print_scope
    click n_resolve href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-cli/src/lock.rs#L58" "open the source"
    click n_describe href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-cli/src/lock.rs#L74" "open the source"
    click n_open href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-cli/src/lock.rs#L85" "open the source"
    click n_create href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-cli/src/lock.rs#L96" "open the source"
    click n_print_scope href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-cli/src/lock.rs#L107" "open the source"
    click n_wrap href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-cli/src/lock.rs#L116" "open the source"
    click n_run href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-cli/src/lock.rs#L135" "open the source"
    click n_status href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-cli/src/lock.rs#L152" "open the source"
    click n_set href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-cli/src/lock.rs#L209" "open the source"
    click n_change href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-cli/src/lock.rs#L252" "open the source"
    click n_remove href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-cli/src/lock.rs#L265" "open the source"
    click n_open_or_explain href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-cli/src/lock.rs#L277" "open the source"
    classDef entry fill:#1f2335,stroke:#7aa2f7,color:#c0caf5
    class n_run entry
    classDef api fill:#1f2335,stroke:#7dcfff,color:#c0caf5
    class n_wrap api
    classDef helper fill:#1f2335,stroke:#bb9af7,color:#c0caf5
    class n_resolve,n_describe,n_open,n_create,n_print_scope,n_status,n_set,n_change,n_remove,n_open_or_explain helper

This site loads no third-party script, so it cannot run Mermaid; the diagram above is the same nodes and edges drawn by the generator instead. GitHub renders the source below directly.

ITEMS

ItemLineDocumentation
Action pub enum30
Site enum50Where the lock is kept for this invocation.
Site::resolve fn58Where the lock is kept: the path given on the command line, or the platform default.
Site::describe fn74What to print as the location.
Site::open fn85Open the lock, and say whether a missing copy had to be rebuilt.
Site::create fn96Make a lock here for the first time, deriving the verifier from password.
print_scope fn107Print the honest scope note, wrapped for a terminal.
wrap pub fn116Greedy word wrap.
run pub fn135Dispatch veilvoice lock to the subcommand that was asked for.
status fn152veilvoice lock status: whether a lock is set, and where it lives.
set fn209veilvoice lock set: make a lock, asking for the passphrase twice.
change fn252veilvoice lock change: replace the passphrase, after proving the old one.
remove fn265veilvoice lock remove: take the lock off, after proving the passphrase.
open_or_explain fn277The lock store, or a message saying what to do rather than a bare error.