6c92f85d10
Bring the Nexus/Praxis/Hexis integration in line with MAVEN_ECOSYSTEM_ARCHITECTURE.md: - Praxis over HTTP: drop the in-process praxis.db open (praxisstore/ praxistools) and call praxisd's /api/v1/tools/* API via a new praxisClient. Honors the "no component reads another's DB" invariant (AC#12). PraxisConfig.DBPath -> URL. - Hexis confirmation gate: mutating capabilities (ReadOnly=false) now park a bound pendingHexis confirmation and require a spoken "да" before executing; read-only run immediately (AC#7, no auto attention->action). - Capability safety: >1 verb match is ambiguous -> ask instead of firing the first; ambiguous Nexus resolution asks for clarification (AC#2). - Correlation IDs on Hexis execute, recorded in the cross-service trace. - Bug: importance arrives as JSON float64 over HTTP, not int. - Tests: confirm-gate, decline, read-only, and ambiguity paths. Build: vendor/ bakes in the hexis client (replace-directed at a sibling repo outside the Docker context); Dockerfile builds from vendor and no longer `go mod download`s the unreachable replace paths. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
52 lines
1.2 KiB
Go
52 lines
1.2 KiB
Go
// Copyright 2018 The Go Authors. All rights reserved.
|
|
// Use of this source code is governed by a BSD-style
|
|
// license that can be found in the LICENSE file.
|
|
|
|
package unix
|
|
|
|
import "fmt"
|
|
|
|
// Unveil implements the unveil syscall.
|
|
// For more information see unveil(2).
|
|
// Note that the special case of blocking further
|
|
// unveil calls is handled by UnveilBlock.
|
|
func Unveil(path string, flags string) error {
|
|
if err := supportsUnveil(); err != nil {
|
|
return err
|
|
}
|
|
pathPtr, err := BytePtrFromString(path)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
flagsPtr, err := BytePtrFromString(flags)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
return unveil(pathPtr, flagsPtr)
|
|
}
|
|
|
|
// UnveilBlock blocks future unveil calls.
|
|
// For more information see unveil(2).
|
|
func UnveilBlock() error {
|
|
if err := supportsUnveil(); err != nil {
|
|
return err
|
|
}
|
|
return unveil(nil, nil)
|
|
}
|
|
|
|
// supportsUnveil checks for availability of the unveil(2) system call based
|
|
// on the running OpenBSD version.
|
|
func supportsUnveil() error {
|
|
maj, min, err := majmin()
|
|
if err != nil {
|
|
return err
|
|
}
|
|
|
|
// unveil is not available before 6.4
|
|
if maj < 6 || (maj == 6 && min <= 3) {
|
|
return fmt.Errorf("cannot call Unveil on OpenBSD %d.%d", maj, min)
|
|
}
|
|
|
|
return nil
|
|
}
|