mandate.rs

crates/veilvoice-cli/src/mandate.rs

veilvoice-cli · 339 lines · read the source here · or on GitHub

veilvoice mandate -- the two things VeilVoice insists on, and how to stop.

The command-line front end to veilvoice_policy::Mandate. That module holds the data and the history; this file decides what is printed, and makes relaxing a requirement a deliberate act rather than a flag somebody typed once.

This is the opposite tool to veilvoice policy

A sealed policy can only ever make VeilVoice stricter, and is meant for somebody setting rules for somebody else. The mandate is your own baseline for your own machine, and it is the only thing here that can be relaxed.

The two compose in one direction only: the effective requirement is the mandate or whatever the sealed policy adds. So relaxing the mandate cannot switch off something an administrator has fixed, and status says so when that is what is happening, rather than reporting "not required" at somebody who will then find it is still required.

Why relaxing asks twice

Turning off encryption at rest means every recording VeilVoice writes from then on is a plain file of everything that was said. De-identification took the voiceprint out; it did not take the words out. That is a real choice somebody may have real reasons to make, so it is offered, but it is not offered casually, and it is written down with the date.

In plain words

VeilVoice asks for a password for itself and encrypts your recordings unless you tell it not to. This is where you tell it not to, and where you can see when you did.

WHAT THIS FILE CONTAINS

339 lines defining 11 functions (5 public), 0 types and 0 constants. Everything below is read out of the source, so it cannot disagree with the code.

What happens when it runs. These are the ways in: public, and nothing else in this file calls them, so they are what an outside caller reaches first.

  • status line 84 · What is required now, and how it got that way.
    reaches describe, load, sealed_also_requires, path
  • history line 124 · The log of every change, oldest first.
    reaches load, path
  • relax line 152 · Stop insisting on one or both requirements.
    reaches change, describe, load, sealed_also_requires, wanted, path
  • insist line 157 · Insist on one or both requirements again.
    reaches change, describe, load, sealed_also_requires, wanted, path
  • reset line 277 · Back to insisting on both.
    reaches load, path

WHAT CALLS WHAT

path line 41 load line 51 sealed_also_requires line 64 describe line 76 status line 84 history line 124 relax line 152 insist line 157 wanted line 166 change line 181 reset line 277 entry: a way in: public, and nothing in this file calls it helper: private to this file dashed: a call that goes back up, or across a wrapped rank The functions this file defines, and the calls between them. An edge means the callee's name appears, called, inside the caller's body. This is a syntactic reading, not a type-resolved one.

The functions this file defines, and the calls between them. An edge means the callee's name appears, called, inside the caller's body. This is a syntactic reading, not a type-resolved one.

The same graph as Mermaid source
%%{init: {"theme":"base","themeVariables":{"background":"#1a1b26","primaryColor":"#1f2335","primaryTextColor":"#c0caf5","primaryBorderColor":"#7aa2f7","secondaryColor":"#16161e","tertiaryColor":"#16161e","lineColor":"#737aa2","textColor":"#c0caf5","mainBkg":"#1f2335","nodeBorder":"#7aa2f7","clusterBkg":"#16161e","clusterBorder":"#2f3549","fontFamily":"ui-monospace, SFMono-Regular, Consolas, monospace","fontSize":"14px"}}}%%
flowchart TD
    n_path["path<br/>line 41"]
    n_load["load<br/>line 51"]
    n_sealed_also_requires["sealed_also_requires<br/>line 64"]
    n_describe["describe<br/>line 76"]
    n_status(["status<br/>line 84"])
    n_history(["history<br/>line 124"])
    n_relax(["relax<br/>line 152"])
    n_insist(["insist<br/>line 157"])
    n_wanted["wanted<br/>line 166"]
    n_change["change<br/>line 181"]
    n_reset(["reset<br/>line 277"])
    n_change --> n_describe
    n_change --> n_load
    n_change --> n_sealed_also_requires
    n_change --> n_wanted
    n_history --> n_load
    n_insist --> n_change
    n_load --> n_path
    n_relax --> n_change
    n_reset --> n_load
    n_status --> n_describe
    n_status --> n_load
    n_status --> n_sealed_also_requires
    click n_path href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-cli/src/mandate.rs#L41" "open the source"
    click n_load href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-cli/src/mandate.rs#L51" "open the source"
    click n_sealed_also_requires href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-cli/src/mandate.rs#L64" "open the source"
    click n_describe href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-cli/src/mandate.rs#L76" "open the source"
    click n_status href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-cli/src/mandate.rs#L84" "open the source"
    click n_history href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-cli/src/mandate.rs#L124" "open the source"
    click n_relax href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-cli/src/mandate.rs#L152" "open the source"
    click n_insist href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-cli/src/mandate.rs#L157" "open the source"
    click n_wanted href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-cli/src/mandate.rs#L166" "open the source"
    click n_change href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-cli/src/mandate.rs#L181" "open the source"
    click n_reset href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-cli/src/mandate.rs#L277" "open the source"
    classDef entry fill:#1f2335,stroke:#7aa2f7,color:#c0caf5
    class n_status,n_history,n_relax,n_insist,n_reset entry
    classDef helper fill:#1f2335,stroke:#bb9af7,color:#c0caf5
    class n_path,n_load,n_sealed_also_requires,n_describe,n_wanted,n_change helper

This site loads no third-party script, so it cannot run Mermaid; the diagram above is the same nodes and edges drawn by the generator instead. GitHub renders the source below directly.

ITEMS

ItemLineDocumentation
path fn41Where the mandate file lives.
load fn51The sealed policy and where it was read from, so an error can name the file.
sealed_also_requires fn64Whether the sealed policy independently fixes this requirement on.
describe fn76One requirement in the words a person would use for it, not the field name.
status pub fn84What is required now, and how it got that way.
history pub fn124The log of every change, oldest first.
relax pub fn152Stop insisting on one or both requirements.
insist pub fn157Insist on one or both requirements again.
wanted fn166The fields the flags name, refusing when they name none.
change fn181Tighten or release the sealed policy, after saying what that means.
reset pub fn277Back to insisting on both.