crates/veilvoice-cli/src/policy.rs
veilvoice-cli · 243 lines · read the source here · or on GitHub
veilvoice policy -- settings that can only be tightened.
The command-line front end to veilvoice_policy. That crate holds the logic and the honest account of what a sealed policy is worth; this file decides where the two files live and prints them.
Where the policy lives
<config>/veilvoice/policy/policy.txt read at every launch, no passphrase
<config>/veilvoice/policy/policy.sealed the same policy under a passphrase
Per-user, beside everything else this program keeps. Not a machine-wide location: writing to one would need administrator rights, and a policy this program applies to itself does not become enforcement by living somewhere only root can write. What it would become is a thing that looks like enforcement, which is worse than the honest version.
Why remove needs no passphrase
Because it could not meaningfully require one. Anybody who can run this command can delete the two files with the file manager, and a program that pretends otherwise is teaching its user something false. --yes is there so it is not done by accident, and the message says plainly what the passphrase is and is not for.
In plain words
The command line for settings that can only be tightened.
It shows what is currently required, and what a job would actually run with once those requirements are applied, so a value shown is a value used.
WHAT THIS FILE CONTAINS
243 lines defining 6 functions (5 public), 0 types and 0 constants. Everything below is read out of the source, so it cannot disagree with the code.
What happens when it runs. These are the ways in: public, and nothing else in this file calls them, so they are what an outside caller reaches first.
statusline 58 · What is in force, and what is known about the seal.
reachesdir,policy_dirsealline 105 · Write a policy and seal it.
reachesdir,policy_dirverifyline 162 · Check the plain policy against its sealed copy.
reachesdir,policy_dirremoveline 189 · Delete both files.
reachesdir,policy_dir
WHAT CALLS WHAT
The functions this file defines, and the calls between them. An edge means the callee's name appears, called, inside the caller's body. This is a syntactic reading, not a type-resolved one.
The same graph as Mermaid source
%%{init: {"theme":"base","themeVariables":{"background":"#1a1b26","primaryColor":"#1f2335","primaryTextColor":"#c0caf5","primaryBorderColor":"#7aa2f7","secondaryColor":"#16161e","tertiaryColor":"#16161e","lineColor":"#737aa2","textColor":"#c0caf5","mainBkg":"#1f2335","nodeBorder":"#7aa2f7","clusterBkg":"#16161e","clusterBorder":"#2f3549","fontFamily":"ui-monospace, SFMono-Regular, Consolas, monospace","fontSize":"14px"}}}%%
flowchart TD
n_policy_dir["policy_dir<br/>line 45"]
n_dir["dir<br/>line 49"]
n_status(["status<br/>line 58"])
n_seal(["seal<br/>line 105"])
n_verify(["verify<br/>line 162"])
n_remove(["remove<br/>line 189"])
n_dir --> n_policy_dir
n_remove --> n_dir
n_seal --> n_dir
n_status --> n_dir
n_verify --> n_dir
click n_policy_dir href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-cli/src/policy.rs#L45" "open the source"
click n_dir href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-cli/src/policy.rs#L49" "open the source"
click n_status href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-cli/src/policy.rs#L58" "open the source"
click n_seal href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-cli/src/policy.rs#L105" "open the source"
click n_verify href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-cli/src/policy.rs#L162" "open the source"
click n_remove href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-cli/src/policy.rs#L189" "open the source"
classDef entry fill:#1f2335,stroke:#7aa2f7,color:#c0caf5
class n_status,n_seal,n_verify,n_remove entry
classDef api fill:#1f2335,stroke:#7dcfff,color:#c0caf5
class n_policy_dir api
classDef helper fill:#1f2335,stroke:#bb9af7,color:#c0caf5
class n_dir helper
This site loads no third-party script, so it cannot run Mermaid; the diagram above is the same nodes and edges drawn by the generator instead. GitHub renders the source below directly.
ITEMS
| Item | Line | Documentation |
|---|---|---|
policy_dir pub fn | 45 | Where the policy files live. |
dir fn | 49 | |
status pub fn | 58 | What is in force, and what is known about the seal. |
seal pub fn | 105 | Write a policy and seal it. |
verify pub fn | 162 | Check the plain policy against its sealed copy. |
remove pub fn | 189 | Delete both files. |