policy.rs

crates/veilvoice-cli/src/policy.rs

veilvoice-cli · 243 lines · read the source here · or on GitHub

veilvoice policy -- settings that can only be tightened.

The command-line front end to veilvoice_policy. That crate holds the logic and the honest account of what a sealed policy is worth; this file decides where the two files live and prints them.

Where the policy lives

<config>/veilvoice/policy/policy.txt     read at every launch, no passphrase
<config>/veilvoice/policy/policy.sealed  the same policy under a passphrase

Per-user, beside everything else this program keeps. Not a machine-wide location: writing to one would need administrator rights, and a policy this program applies to itself does not become enforcement by living somewhere only root can write. What it would become is a thing that looks like enforcement, which is worse than the honest version.

Why remove needs no passphrase

Because it could not meaningfully require one. Anybody who can run this command can delete the two files with the file manager, and a program that pretends otherwise is teaching its user something false. --yes is there so it is not done by accident, and the message says plainly what the passphrase is and is not for.

In plain words

The command line for settings that can only be tightened.

It shows what is currently required, and what a job would actually run with once those requirements are applied, so a value shown is a value used.

WHAT THIS FILE CONTAINS

243 lines defining 6 functions (5 public), 0 types and 0 constants. Everything below is read out of the source, so it cannot disagree with the code.

What happens when it runs. These are the ways in: public, and nothing else in this file calls them, so they are what an outside caller reaches first.

  • status line 58 · What is in force, and what is known about the seal.
    reaches dir, policy_dir
  • seal line 105 · Write a policy and seal it.
    reaches dir, policy_dir
  • verify line 162 · Check the plain policy against its sealed copy.
    reaches dir, policy_dir
  • remove line 189 · Delete both files.
    reaches dir, policy_dir

WHAT CALLS WHAT

policy_dir line 45 dir line 49 status line 58 seal line 105 verify line 162 remove line 189 entry: a way in: public, and nothing in this file calls it api: public, and also used inside this file helper: private to this file dashed: a call that goes back up, or across a wrapped rank The functions this file defines, and the calls between them. An edge means the callee's name appears, called, inside the caller's body. This is a syntactic reading, not a type-resolved one.

The functions this file defines, and the calls between them. An edge means the callee's name appears, called, inside the caller's body. This is a syntactic reading, not a type-resolved one.

The same graph as Mermaid source
%%{init: {"theme":"base","themeVariables":{"background":"#1a1b26","primaryColor":"#1f2335","primaryTextColor":"#c0caf5","primaryBorderColor":"#7aa2f7","secondaryColor":"#16161e","tertiaryColor":"#16161e","lineColor":"#737aa2","textColor":"#c0caf5","mainBkg":"#1f2335","nodeBorder":"#7aa2f7","clusterBkg":"#16161e","clusterBorder":"#2f3549","fontFamily":"ui-monospace, SFMono-Regular, Consolas, monospace","fontSize":"14px"}}}%%
flowchart TD
    n_policy_dir["policy_dir<br/>line 45"]
    n_dir["dir<br/>line 49"]
    n_status(["status<br/>line 58"])
    n_seal(["seal<br/>line 105"])
    n_verify(["verify<br/>line 162"])
    n_remove(["remove<br/>line 189"])
    n_dir --> n_policy_dir
    n_remove --> n_dir
    n_seal --> n_dir
    n_status --> n_dir
    n_verify --> n_dir
    click n_policy_dir href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-cli/src/policy.rs#L45" "open the source"
    click n_dir href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-cli/src/policy.rs#L49" "open the source"
    click n_status href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-cli/src/policy.rs#L58" "open the source"
    click n_seal href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-cli/src/policy.rs#L105" "open the source"
    click n_verify href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-cli/src/policy.rs#L162" "open the source"
    click n_remove href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-cli/src/policy.rs#L189" "open the source"
    classDef entry fill:#1f2335,stroke:#7aa2f7,color:#c0caf5
    class n_status,n_seal,n_verify,n_remove entry
    classDef api fill:#1f2335,stroke:#7dcfff,color:#c0caf5
    class n_policy_dir api
    classDef helper fill:#1f2335,stroke:#bb9af7,color:#c0caf5
    class n_dir helper

This site loads no third-party script, so it cannot run Mermaid; the diagram above is the same nodes and edges drawn by the generator instead. GitHub renders the source below directly.

ITEMS

ItemLineDocumentation
policy_dir pub fn45Where the policy files live.
dir fn49
status pub fn58What is in force, and what is known about the seal.
seal pub fn105Write a policy and seal it.
verify pub fn162Check the plain policy against its sealed copy.
remove pub fn189Delete both files.