diff --git a/dag/extdeps/access/posix_effective_principal_read_op.dag b/dag/extdeps/access/posix_effective_principal_read_op.dag index 6f2fc4be096..b78e708d723 100644 --- a/dag/extdeps/access/posix_effective_principal_read_op.dag +++ b/dag/extdeps/access/posix_effective_principal_read_op.dag @@ -39,6 +39,7 @@ fn effective_posix_principal_read( service access.PosixEffectivePrincipal { operation Read { + requires none input { read: EffectivePosixPrincipalRead } output { exit_code: Int from "exit_code" diff --git a/dag/extdeps/bmc/openbmc_fan_control.dag b/dag/extdeps/bmc/openbmc_fan_control.dag index 29f1277fb92..2d9382211d9 100644 --- a/dag/extdeps/bmc/openbmc_fan_control.dag +++ b/dag/extdeps/bmc/openbmc_fan_control.dag @@ -794,6 +794,7 @@ fn openbmc_execute( service openbmc.JsonProjection { operation ProjectFanConfig { + requires none input { desired_json: String path: NonEmptyStr diff --git a/dag/extdeps/browser/browser.dag b/dag/extdeps/browser/browser.dag index 8ab64899630..8e67745f855 100644 --- a/dag/extdeps/browser/browser.dag +++ b/dag/extdeps/browser/browser.dag @@ -37,12 +37,14 @@ type Element = String where brand("Element") service browser.Context { operation Launch { + requires Network input { headless: String = "false", profile_path: FilePath } output { context: BrowserContext from "stdout" } transport shell { argv: ["playwright-runner", "launch", "--headless", "{headless}", "--profile", "{profile_path}"] } } operation Close { + requires opaque input { context: BrowserContext } output {} transport shell { argv: ["playwright-runner", "close", "{context}"] } @@ -60,6 +62,7 @@ service browser.Page { } operation CurrentUrl { + requires Network input {} output { url: String from "stdout" } @@ -67,54 +70,63 @@ service browser.Page { } operation Title { + requires Network input {} output { title: String from "stdout" } transport shell { argv: ["playwright-runner", "title"] } } operation WaitForSelector { + requires opaque input { selector: String, timeout_ms: Int = 30000 } output { found: String from "stdout" } transport shell { argv: ["playwright-runner", "wait-for", "{selector}", "--timeout", "{timeout_ms}"] } } operation QueryAll { + requires opaque input { selector: String } output { count: String from "stdout" } transport shell { argv: ["playwright-runner", "query-all", "{selector}"] } } operation Click { + requires opaque input { selector: String } output {} transport shell { argv: ["playwright-runner", "click", "{selector}"] } } operation Fill { + requires opaque input { selector: String, text: String } output {} transport shell { argv: ["playwright-runner", "fill", "{selector}", "{text}"] } } operation Evaluate { + requires opaque input { expression: String } output { result: String from "stdout" } transport shell { argv: ["playwright-runner", "evaluate", "{expression}"] } } operation UploadFile { + requires opaque input { selector: String, path: FilePath } output {} transport shell { argv: ["playwright-runner", "upload", "{selector}", "{path}"] } } operation Screenshot { + requires opaque input { path: FilePath } output {} transport shell { argv: ["playwright-runner", "screenshot", "{path}"] } } operation Wait { + requires opaque input { ms: Int } output {} transport shell { argv: ["playwright-runner", "wait", "{ms}"] } @@ -124,18 +136,21 @@ service browser.Page { service browser.Element { operation IsVisible { + requires opaque input { selector: String } output { visible: String from "stdout" } transport shell { argv: ["playwright-runner", "is-visible", "{selector}"] } } operation InnerText { + requires opaque input { selector: String } output { text: String from "stdout" } transport shell { argv: ["playwright-runner", "inner-text", "{selector}"] } } operation EvaluateOn { + requires opaque input { selector: String, expression: String } output { result: String from "stdout" } transport shell { argv: ["playwright-runner", "evaluate-on", "{selector}", "{expression}"] } diff --git a/dag/extdeps/clock/clock.dag b/dag/extdeps/clock/clock.dag index 1700a067d40..70d6ac4d158 100644 --- a/dag/extdeps/clock/clock.dag +++ b/dag/extdeps/clock/clock.dag @@ -27,6 +27,7 @@ data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { service Clock { operation Now { + requires none input {} output { timestamp: Timestamp from "stdout" } readonly @@ -38,6 +39,7 @@ service Clock { } operation UnixMillis { + requires none input {} output { unix_millis: String from "stdout" } readonly @@ -49,6 +51,7 @@ service Clock { } operation UnixSecs { + requires none input {} output { unix_secs: String from "stdout" } readonly @@ -60,6 +63,7 @@ service Clock { } operation TimestampOffset { + requires none input { timestamp: Timestamp, offset: Nat } output { result: Timestamp from "stdout" } readonly @@ -71,6 +75,7 @@ service Clock { } operation TimestampAdd { + requires none input { timestamp: Timestamp, offset: Nat } output { result: Timestamp from "stdout" } readonly @@ -82,6 +87,7 @@ service Clock { } operation TimestampToUnixSecs { + requires none input { timestamp: Timestamp } output { unix_secs: String from "stdout" } readonly diff --git a/dag/extdeps/cron/cron.dag b/dag/extdeps/cron/cron.dag index 3d8952f92fd..aa5c151078a 100644 --- a/dag/extdeps/cron/cron.dag +++ b/dag/extdeps/cron/cron.dag @@ -14,6 +14,7 @@ data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { service cron.Tab { operation List { + requires none input {} output { entries: String from "stdout" } readonly @@ -25,6 +26,7 @@ service cron.Tab { } operation Replace { + requires none input { entries: String } output { success: Bool from "exit_success", stdout: String from "stdout", stderr: String from "stderr" } transport shell { diff --git a/dag/extdeps/crypto/hash.dag b/dag/extdeps/crypto/hash.dag index 32eb7b03ebd..748eb50856c 100644 --- a/dag/extdeps/crypto/hash.dag +++ b/dag/extdeps/crypto/hash.dag @@ -96,6 +96,7 @@ fn sha512_digest_content_hash(digest: Digest) -> ContentHash? { // transport row can be read from the operation itself. service crypto.Sha256Sum { operation File { + requires none input { path: String } output { line: String from "stdout" diff --git a/dag/extdeps/docker/container_inspect.dag b/dag/extdeps/docker/container_inspect.dag index 29fdb847885..1709350425c 100644 --- a/dag/extdeps/docker/container_inspect.dag +++ b/dag/extdeps/docker/container_inspect.dag @@ -7,6 +7,7 @@ import std.measure { ByteSize, byte_size, byte_size_count, Microsecond, microsec import extdeps.docker.endpoint { docker_default_endpoint } import extdeps.external_authority { ExternalAuthority } import extdeps.uri { Uri, Https } +import extdeps.ietf.http_semantics { GET } import extdeps.docker.container_inspect_contracts { container_state_wire_contract } import std.roster_frontier { FrontierRow, frontier_row_decl } import std.dissolution { unbound_dissolution } @@ -248,6 +249,7 @@ service docker.Container { } operation Inspect { + requires none input { container_id: String size: Bool = false diff --git a/dag/extdeps/docker/container_stats.dag b/dag/extdeps/docker/container_stats.dag index 63168277958..d231a526bde 100644 --- a/dag/extdeps/docker/container_stats.dag +++ b/dag/extdeps/docker/container_stats.dag @@ -7,6 +7,7 @@ import std.measure { ByteSize, byte_size, byte_size_count, Nanosecond, nanosecon import extdeps.docker.endpoint { docker_default_endpoint } import extdeps.external_authority { ExternalAuthority } import extdeps.uri { Uri, Https } +import extdeps.ietf.http_semantics { GET } import std.roster_frontier { FrontierRow, frontier_row_decl } import std.dissolution { unbound_dissolution } import std.decl_ref { decl_ref, decl_field_ref } @@ -91,6 +92,7 @@ service docker.ContainerStats { } operation GetStats { + requires none input { container_id: String stream: Bool = false diff --git a/dag/extdeps/entropy/entropy.dag b/dag/extdeps/entropy/entropy.dag index c59911c4782..1e1730954c1 100644 --- a/dag/extdeps/entropy/entropy.dag +++ b/dag/extdeps/entropy/entropy.dag @@ -80,6 +80,7 @@ data entropy_read_password_shell_emit_dissolution_trigger: DissolutionCondition data urandom_read_bytes_shell_emit_dissolution_trigger: DissolutionCondition = unbound_dissolution(description: "dissolve-on: Urandom.ReadBytes / Urandom.ReadPassword transport argv -- hand-authored shell program expanded as a string literal to capture the producing stage's exit status; this edits the failure arm of an EXISTING transport and adds no new emission site, per the gunbc.githooks_pre_push_emit precedent. DISSOLVES WHEN [C7 producer-status-pipeline] (an extdeps shell transport cannot declare a producer-then-consumer argv pair whose realization reports the PRODUCING stage's exit status; dash has no pipefail) lands and these operations declare that argv pair in place of an sh -c program.") service Urandom { operation ReadBytes { + requires none input { count: Int } output { octets_b64: String from "stdout" } readonly @@ -91,6 +92,7 @@ service Urandom { } operation ReadPassword { + requires none input { count: Int } output { password: String from "stdout" } readonly diff --git a/dag/extdeps/filesystem/filesystem_io.dag b/dag/extdeps/filesystem/filesystem_io.dag index fcb2d2a4c87..cca7a31eba9 100644 --- a/dag/extdeps/filesystem/filesystem_io.dag +++ b/dag/extdeps/filesystem/filesystem_io.dag @@ -685,6 +685,7 @@ data filesystem_absence_establishment_adoption_standing: String = "RUNG: structu service Filesystem { operation Write { + requires none input { path: String, content: String } output { success: Bool from "write_success" @@ -696,6 +697,7 @@ service Filesystem { } operation WriteOwnerOnly { + requires none input { path: String, content: String } output { success: Bool from "write_success" @@ -707,6 +709,7 @@ service Filesystem { } operation WriteCreateNew { + requires none input { path: String, content: String } output { success: Bool from "write_success" @@ -719,6 +722,7 @@ service Filesystem { } operation WriteCreateNewWithMode { + requires none input { path: String, content: String, mode: Int } output { success: Bool from "write_success" @@ -731,6 +735,7 @@ service Filesystem { } operation Read { + requires none input { path: String } output { content: String from "content" @@ -743,6 +748,7 @@ service Filesystem { } operation Delete { + requires none input { path: String } output { success: Bool from "delete_success" @@ -752,6 +758,7 @@ service Filesystem { } operation List { + requires none input { path: String } output { entries: String from "entries" diff --git a/dag/extdeps/git/git.dag b/dag/extdeps/git/git.dag index 18480c7a252..5654f51a9bf 100644 --- a/dag/extdeps/git/git.dag +++ b/dag/extdeps/git/git.dag @@ -1099,6 +1099,7 @@ fn git_observe_meta_shell_fragment() -> String { // whitespace (a patch ending in blank context lines). Read / with Filesystem.Read. service git.Core { operation CurrentBranch { + requires none input {} output { branch: String from "stdout" } readonly @@ -1110,6 +1111,7 @@ service git.Core { } operation RemoteBranches { + requires none input {} output { branches: List from "stdout_lines" } readonly @@ -1121,7 +1123,7 @@ service git.Core { } operation LsRemoteHeads { - requires Network + requires opaque input { remote: String } output { advertised: List from "stdout_lines" @@ -1133,6 +1135,7 @@ service git.Core { } operation RemoteUrlIn { + requires none input { repository_path: String, remote: String } output { url: String from "stdout" @@ -1144,6 +1147,7 @@ service git.Core { } operation ForEachRefIn { + requires none input { repository_path: String } output { raw: String from "stdout" @@ -1161,6 +1165,7 @@ service git.Core { } operation WorktreeListIn { + requires none input { repository_path: String } output { raw: String from "stdout" @@ -1174,6 +1179,7 @@ service git.Core { } operation WriteTreeInRepo { + requires opaque input { repository_path: String } output { tree: String from "stdout" @@ -1185,6 +1191,7 @@ service git.Core { } operation CommitTreeInRepo { + requires opaque input { repository_path: String, commit: GitRef } output { tree: String from "stdout" @@ -1196,6 +1203,7 @@ service git.Core { } operation TrackedWorktreeDiffFromInRepo { + requires opaque input { repository_path: String, treeish: GitRef } output { paths_nul: String from "stdout" @@ -1207,6 +1215,7 @@ service git.Core { } operation LsFiles { + requires opaque input {} output { files: List from "stdout_lines" } readonly @@ -1218,6 +1227,7 @@ service git.Core { } operation Diff { + requires opaque input { base: GitRef, head: GitRef = "HEAD" } output { diff: String from "stdout" } readonly @@ -1229,6 +1239,7 @@ service git.Core { } operation DiffNameOnly { + requires opaque input { base: GitRef, head: GitRef = "HEAD" } output { paths: List from "stdout_lines" @@ -1243,6 +1254,7 @@ service git.Core { } operation DiffNameOnlyNoRenames { + requires opaque input { base: GitRef, head: GitRef = "HEAD" } output { paths: List from "stdout_lines" @@ -1258,6 +1270,7 @@ service git.Core { } operation DiffNameOnlyMerge { + requires opaque input { base: GitRef, head: GitRef = "HEAD" } output { paths: List from "stdout_lines" @@ -1272,6 +1285,7 @@ service git.Core { } operation DiffUnified0 { + requires opaque input { base: GitRef, head: GitRef = "HEAD", range: GitDiffRange } output { diff: String from "stdout" @@ -1286,6 +1300,7 @@ service git.Core { } operation DiffNameStatus { + requires opaque input { base: GitRef, head: GitRef = "HEAD", range: GitDiffRange } output { raw: String from "stdout" @@ -1300,6 +1315,7 @@ service git.Core { } operation RevList { + requires opaque input { since: String } output { commits: List from "stdout_lines" } readonly @@ -1311,6 +1327,7 @@ service git.Core { } operation LogPathCommits { + requires Network input { path: FilePath } output { commits: List from "stdout_lines" } readonly @@ -1322,6 +1339,7 @@ service git.Core { } operation RevListBefore { + requires none input { before: String } output { base_ref: CommitSha from "stdout" } readonly @@ -1333,6 +1351,7 @@ service git.Core { } operation Show { + requires opaque input { ref: GitRef, path: FilePath } output { content: String from "stdout" @@ -1348,6 +1367,7 @@ service git.Core { } operation RestoreBlobTo { + requires opaque input { ref: GitRef, path: FilePath, work_tree: FilePath } output { success: Bool from "exit_success" @@ -1361,7 +1381,7 @@ service git.Core { } operation FetchNoTags { - requires Network + requires opaque input { remote: String, ref: String, stall_deadline_seconds: Seconds } output { success: Bool from "exit_success" @@ -1376,7 +1396,7 @@ service git.Core { } operation FetchPrune { - requires Network + requires opaque input { remote: String } output { success: Bool from "exit_success" @@ -1391,6 +1411,7 @@ service git.Core { } operation HeadCommitShort { + requires none input {} output { sha: String from "stdout" @@ -1405,6 +1426,7 @@ service git.Core { } operation ConfigLocalGet { + requires none input { key: String } output { success: Bool from "exit_success" @@ -1421,6 +1443,7 @@ service git.Core { } operation ConfigLocalSet { + requires none input { key: String, value: String } output { success: Bool from "exit_success" @@ -1434,6 +1457,7 @@ service git.Core { } operation ConfigLocalGetInRepo { + requires none input { repo: FilePath, key: String } output { success: Bool from "exit_success" @@ -1450,6 +1474,7 @@ service git.Core { } operation ConfigLocalSetInRepo { + requires none input { repo: FilePath, key: String, value: String } output { success: Bool from "exit_success" @@ -1463,6 +1488,7 @@ service git.Core { } operation InitInRepo { + requires none input { repo: FilePath } output { success: Bool from "exit_success" @@ -1476,6 +1502,7 @@ service git.Core { } operation AddAllInRepo { + requires opaque input { repo: FilePath } output { exit_code: Int from "exit_code" @@ -1485,6 +1512,7 @@ service git.Core { } operation CommitInRepo { + requires opaque input { repo: FilePath, message: String } output { exit_code: Int from "exit_code" @@ -1494,6 +1522,7 @@ service git.Core { } operation CheckoutNewBranchInRepo { + requires opaque input { repo: FilePath, branch: String } output { exit_code: Int from "exit_code" @@ -1503,6 +1532,7 @@ service git.Core { } operation CheckoutNewBranchAtInRepo { + requires opaque input { repo: FilePath, branch: String, start_point: GitRef } output { exit_code: Int from "exit_code" @@ -1512,6 +1542,7 @@ service git.Core { } operation CheckoutBranchInRepo { + requires opaque input { repo: FilePath, branch: String } output { exit_code: Int from "exit_code" @@ -1521,6 +1552,7 @@ service git.Core { } operation MergeNoEditInRepo { + requires opaque input { repo: FilePath, branch: String } output { exit_code: Int from "exit_code" @@ -1531,6 +1563,7 @@ service git.Core { } operation LsFilesUnmergedInRepo { + requires opaque input { repo: FilePath, path: String } output { entries: List from "stdout_lines" @@ -1542,6 +1575,7 @@ service git.Core { } operation LsFilesStageZPathspecInRepo { + requires opaque input { repo: FilePath, pathspec: String } output { raw: String from "stdout" @@ -1557,6 +1591,7 @@ service git.Core { } operation LsFilesStageZInRepo { + requires opaque input { repo: FilePath } output { raw: String from "stdout" @@ -1571,7 +1606,7 @@ service git.Core { } operation LsRemoteRefInRepo { - requires Network + requires opaque input { repo: FilePath, remote: String, ref_name: String } output { advertised: String from "stdout" @@ -1583,6 +1618,7 @@ service git.Core { } operation RevParseInRepo { + requires opaque input { repo: FilePath, target: GitRef } output { revision: String from "stdout" @@ -1594,7 +1630,7 @@ service git.Core { } operation FetchForcedRefInRepo { - requires Network + requires opaque input { repo: FilePath, remote: String, refspec: String } output { exit_code: Int from "exit_code" @@ -1605,7 +1641,7 @@ service git.Core { } operation FetchForcedRefInRepoTrustingSource { - requires Network + requires opaque input { repo: FilePath, remote: String, refspec: String, upload_pack: String } output { exit_code: Int from "exit_code" @@ -1616,7 +1652,7 @@ service git.Core { } operation PushForcedRefInRepo { - requires Network + requires opaque input { repo: FilePath, remote: String, refspec: String } output { exit_code: Int from "exit_code" @@ -1627,7 +1663,7 @@ service git.Core { } operation PushRefInRepo { - requires Network + requires opaque input { repo: FilePath, remote: String, refspec: String } output { exit_code: Int from "exit_code" @@ -1637,7 +1673,7 @@ service git.Core { transport shell { argv: ["git", "-C", "{repo}", "push", "--quiet", "{remote}", "{refspec}"] } } operation PushRefWithLeaseInRepo { - requires Network + requires opaque input { repo: FilePath, remote: String, refspec: String, lease: String } output { exit_code: Int from "exit_code" @@ -1648,6 +1684,7 @@ service git.Core { } operation CatFileBlobInRepo { + requires opaque input { repo: FilePath, oid: String } output { content: String from "stdout" @@ -1662,6 +1699,7 @@ service git.Core { } operation UpdateRefCompareAndSwapInRepo { + requires opaque input { repo: FilePath, ref: String, new_value: String, expected_old: String } output { exit_code: Int from "exit_code" @@ -1674,6 +1712,7 @@ service git.Core { } operation ReflogInRepo { + requires opaque input { repo: FilePath, ref: String } output { exit_code: Int from "exit_code" @@ -1687,6 +1726,7 @@ service git.Core { } operation ListUntrackedInRepo { + requires opaque input { repo: FilePath } output { exit_code: Int from "exit_code" @@ -1700,6 +1740,7 @@ service git.Core { } operation ResetHardInRepo { + requires opaque input { repo: FilePath, target: String } output { exit_code: Int from "exit_code" @@ -1818,6 +1859,7 @@ fn shape_git_rev_parse_argv(repo: FilePath, target: GitRef) -> List { service git.Worktree { operation Add { + requires opaque input { path: FilePath, branch: NonEmptyStr, remote_ref: GitRef } output { success: Bool from "exit_success" diff --git a/dag/extdeps/git/inspect.dag b/dag/extdeps/git/inspect.dag index ed3684f2c59..3ebd7114e09 100644 --- a/dag/extdeps/git/inspect.dag +++ b/dag/extdeps/git/inspect.dag @@ -171,6 +171,7 @@ data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { // every observer of that release and never removed (PR #10696). service git.Inspect { operation Toplevel { + requires none input {} output { path: FilePath from "stdout" } readonly @@ -185,6 +186,7 @@ service git.Inspect { } operation HeadCommit { + requires none input {} output { sha: CommitSha from "stdout" @@ -199,6 +201,7 @@ service git.Inspect { } operation WorkingTreeStatus { + requires opaque input { repository_path: String } output { entries_nul: String from "stdout" @@ -217,6 +220,7 @@ service git.Inspect { } operation HeadCommitIn { + requires none input { repository_path: String } output { sha: String from "stdout" @@ -235,6 +239,7 @@ service git.Inspect { } operation ReadTreeIntoIndex { + requires opaque input { repository_path: String, revision_hex: String, index_path: String } output { success: Bool from "exit_success" @@ -251,6 +256,7 @@ service git.Inspect { } operation StatusAgainstIndex { + requires opaque input { repository_path: String, index_path: String } output { entries_nul: String from "stdout" @@ -269,6 +275,7 @@ service git.Inspect { } operation IgnoredAgainstIndex { + requires opaque input { repository_path: String, index_path: String } output { paths_nul: String from "stdout" @@ -287,6 +294,7 @@ service git.Inspect { } operation IgnoredFiles { + requires opaque input {} output { paths_nul: String from "stdout" @@ -305,6 +313,7 @@ service git.Inspect { } operation MergeBase { + requires opaque input { repository_path: String, left: GitRef, right: GitRef } output { sha: CommitSha from "stdout" @@ -322,6 +331,7 @@ service git.Inspect { } operation ListTreePathsAtRevision { + requires opaque input { ref: GitRef } output { paths_nul: String from "stdout" @@ -337,6 +347,7 @@ service git.Inspect { } operation ListTreeEntriesAtRevision { + requires opaque input { ref: GitRef } output { entries_nul: String from "stdout" @@ -352,6 +363,7 @@ service git.Inspect { } operation GrepMatchesAtRevision { + requires opaque input { pattern: String, ref: GitRef, pathspec: String } output { matches: String from "stdout" @@ -368,6 +380,7 @@ service git.Inspect { } operation ResolveRefCommit { + requires opaque input { ref: GitRef } output { sha: CommitSha from "stdout" @@ -383,6 +396,7 @@ service git.Inspect { } operation GrepFixedAtRevision { + requires opaque input { pattern: String, ref: GitRef } output { paths: String from "stdout" @@ -399,6 +413,7 @@ service git.Inspect { } operation ShowTree { + requires opaque input { ref: GitRef } output { tree: String from "stdout" @@ -414,6 +429,7 @@ service git.Inspect { } operation ConfigGet { + requires none input { key: String } output { value: String from "stdout" @@ -430,6 +446,7 @@ service git.Inspect { } operation MergeTreeWriteTree { + requires opaque input { left: GitRef, right: GitRef } output { stdout: String from "stdout" diff --git a/dag/extdeps/git/plumbing.dag b/dag/extdeps/git/plumbing.dag index 7eb80de5e70..21b2ddc2bfa 100644 --- a/dag/extdeps/git/plumbing.dag +++ b/dag/extdeps/git/plumbing.dag @@ -139,6 +139,7 @@ fn git_commit_parents_argv(parents: GitCommitParents) -> List { // (gunbc.recurring_failure_mode identity_hashed_from_a_shared_mutable_path). service git.Plumbing { operation HashObjectWrite { + requires opaque input { address: GitRepositoryAddress, path: FilePath } output { oid: String from "stdout" @@ -149,6 +150,7 @@ service git.Plumbing { } operation HashObjectWriteStdin { + requires none input { address: GitRepositoryAddress, content: String } output { oid: String from "stdout" @@ -162,6 +164,7 @@ service git.Plumbing { } operation HashObjectStdinNoWrite { + requires none input { content: String } output { oid: String from "stdout" @@ -176,6 +179,7 @@ service git.Plumbing { } operation CatFileBlob { + requires opaque input { address: GitRepositoryAddress, object: String } output { content: String from "stdout" @@ -187,6 +191,7 @@ service git.Plumbing { } operation CatFileExists { + requires opaque input { address: GitRepositoryAddress, object: String } output { exit_code: Int from "exit_code" @@ -197,6 +202,7 @@ service git.Plumbing { } operation CatFileSize { + requires opaque input { address: GitRepositoryAddress, object: String } output { size: String from "stdout" @@ -208,6 +214,7 @@ service git.Plumbing { } operation UnpackObject { + requires opaque input { address: GitRepositoryAddress, object: String } output { path: String from "stdout" @@ -218,6 +225,7 @@ service git.Plumbing { } operation ReadTreeIntoIndex { + requires opaque input { address: GitRepositoryAddress, index: FilePath, treeish: String } output { exit_code: Int from "exit_code" @@ -227,6 +235,7 @@ service git.Plumbing { } operation ReadTreeIntoIndexPrefixed { + requires opaque input { address: GitRepositoryAddress, index: FilePath, prefix: String, treeish: String } output { exit_code: Int from "exit_code" @@ -236,6 +245,7 @@ service git.Plumbing { } operation AddAllIntoIndex { + requires opaque input { address: GitRepositoryAddress, index: FilePath } output { exit_code: Int from "exit_code" @@ -245,6 +255,7 @@ service git.Plumbing { } operation UpdateIndexCacheInfo { + requires opaque input { address: GitRepositoryAddress, index: FilePath, mode: String, oid: String, path: String } output { exit_code: Int from "exit_code" @@ -254,6 +265,7 @@ service git.Plumbing { } operation WriteTreeFromIndex { + requires opaque input { address: GitRepositoryAddress, index: FilePath } output { tree: String from "stdout" @@ -264,6 +276,7 @@ service git.Plumbing { } operation CheckoutIndexToPrefix { + requires opaque input { address: GitRepositoryAddress, index: FilePath, prefix: String } output { exit_code: Int from "exit_code" @@ -273,6 +286,7 @@ service git.Plumbing { } operation CommitTree { + requires opaque input { address: GitRepositoryAddress, tree: String, parents: GitCommitParents, message: String } output { commit: String from "stdout" @@ -283,6 +297,7 @@ service git.Plumbing { } operation InitAt { + requires none input { address: GitRepositoryAddress, path: FilePath } output { exit_code: Int from "exit_code" @@ -292,6 +307,7 @@ service git.Plumbing { } operation InitBareAt { + requires none input { address: GitRepositoryAddress, path: FilePath } output { exit_code: Int from "exit_code" @@ -301,6 +317,7 @@ service git.Plumbing { } operation ObserveRef { + requires opaque input { address: GitRepositoryAddress, ref_name: String } output { revision: String from "stdout" @@ -312,6 +329,7 @@ service git.Plumbing { } operation CreateRefIfAbsent { + requires opaque input { address: GitRepositoryAddress, ref_name: String, new: String } output { exit_code: Int from "exit_code" @@ -321,6 +339,7 @@ service git.Plumbing { } operation AdvanceRefIfExpected { + requires opaque input { address: GitRepositoryAddress, ref_name: String, new: String, expected_old: String } output { exit_code: Int from "exit_code" @@ -330,6 +349,7 @@ service git.Plumbing { } operation DeleteRefIfExpected { + requires opaque input { address: GitRepositoryAddress, ref_name: String, expected_old: String } output { exit_code: Int from "exit_code" diff --git a/dag/extdeps/git/publication_transport.dag b/dag/extdeps/git/publication_transport.dag index bb08bdc76e2..f0176782f85 100644 --- a/dag/extdeps/git/publication_transport.dag +++ b/dag/extdeps/git/publication_transport.dag @@ -138,7 +138,7 @@ fn git_remote_ref_cas_refspec(request: GitRemoteRefCasRequest) -> NonEmptyStr { // GitCommitRequest.allow_empty selects RecordEmptyCommit vs RecordCommit at transport bind — two operations, because shell argv templates cannot branch on Bool. service git.PublicationTransport { operation PushRefUpdate { - requires Network + requires opaque input { remote: NonEmptyStr refspec: NonEmptyStr @@ -156,7 +156,7 @@ service git.PublicationTransport { } operation PushRefUpdateWithLease { - requires Network + requires opaque input { remote: NonEmptyStr refspec: NonEmptyStr @@ -175,6 +175,7 @@ service git.PublicationTransport { } operation RecordCommit { + requires opaque input { message: NonEmptyStr } @@ -191,6 +192,7 @@ service git.PublicationTransport { } operation RecordEmptyCommit { + requires opaque input { message: NonEmptyStr } diff --git a/dag/extdeps/go/go.dag b/dag/extdeps/go/go.dag index 9132ac730cf..45f0c83545f 100644 --- a/dag/extdeps/go/go.dag +++ b/dag/extdeps/go/go.dag @@ -18,6 +18,7 @@ data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { // operation refuses rather than downloading a tarball and continuing). service go.Toolchain { operation RunFile { + requires opaque input { workdir: FilePath, script_path: FilePath, args: List = [] } output { success: Bool from "exit_success" diff --git a/dag/extdeps/gunbc/gunbc.dag b/dag/extdeps/gunbc/gunbc.dag index bef7fd9f9f9..bd68e2ad3de 100644 --- a/dag/extdeps/gunbc/gunbc.dag +++ b/dag/extdeps/gunbc/gunbc.dag @@ -94,6 +94,7 @@ data packages: List = [ service gunbc.WitnessBin { operation Run { + requires opaque input { workdir: FilePath bin_path: FilePath diff --git a/dag/extdeps/http/client.dag b/dag/extdeps/http/client.dag index 423a5ae002e..28e49df0748 100644 --- a/dag/extdeps/http/client.dag +++ b/dag/extdeps/http/client.dag @@ -214,6 +214,7 @@ service http.Client { } operation PostStdinWithinUnixSocket { + requires Network input { socket: NonEmptyStr, url: NonEmptyStr, request_body: String, connect_seconds: NonEmptyStr, max_seconds: NonEmptyStr } output { exit_code: Int from "exit_code" diff --git a/dag/extdeps/iproute2/ip_address.dag b/dag/extdeps/iproute2/ip_address.dag index 51af464f2e0..4e4e61a748a 100644 --- a/dag/extdeps/iproute2/ip_address.dag +++ b/dag/extdeps/iproute2/ip_address.dag @@ -44,6 +44,7 @@ data ip_binary_path: NonEmptyStr = "/usr/sbin/ip" // declared inputs, never assembled from a literal in the caller. service iproute2.IpAddress { operation ShowDevice { + requires none input { device: NonEmptyStr } output { body: String from "stdout", success: Bool from "exit_success" } readonly @@ -57,6 +58,7 @@ service iproute2.IpAddress { } operation AddSecondary { + requires none input { device: NonEmptyStr, cidr: NonEmptyStr } output { body: String from "stdout", transport_stderr: String from "stderr", success: Bool from "exit_success" } transport shell { @@ -69,6 +71,7 @@ service iproute2.IpAddress { } operation DeleteSecondary { + requires none input { device: NonEmptyStr, cidr: NonEmptyStr } output { body: String from "stdout", transport_stderr: String from "stderr", success: Bool from "exit_success" } transport shell { diff --git a/dag/extdeps/linux/cgroup_v2.dag b/dag/extdeps/linux/cgroup_v2.dag index d1a878ef903..8a27f4313df 100644 --- a/dag/extdeps/linux/cgroup_v2.dag +++ b/dag/extdeps/linux/cgroup_v2.dag @@ -62,6 +62,7 @@ data cgroup_v2_mount_point: NonEmptyStr = "/sys/fs/cgroup" // inhabitance claim over the real route needs to reach a positive verdict without a host. service linux.CgroupV2 { operation ListChildCgroups { + requires none input { cgroup_path: NonEmptyStr } output { value: String from "stdout" @@ -77,6 +78,7 @@ service linux.CgroupV2 { } operation ReadInterfaceFile { + requires none input { file_path: NonEmptyStr } output { value: String from "stdout" @@ -91,6 +93,7 @@ service linux.CgroupV2 { } } operation PathIsDirectory { + requires none input { path: NonEmptyStr } output { value: String from "stdout" @@ -109,6 +112,7 @@ service linux.CgroupV2 { } operation ReadEvents { + requires none input { events_path: NonEmptyStr } output { value: String from "stdout" diff --git a/dag/extdeps/linux/edac.dag b/dag/extdeps/linux/edac.dag index 6de9a125d3d..d5dd3b89023 100644 --- a/dag/extdeps/linux/edac.dag +++ b/dag/extdeps/linux/edac.dag @@ -43,6 +43,7 @@ data extdeps_model_scope: ExternalModelScope = ExternalModelScope { service diagnostic.edac.RasMcCtl { operation CorrectableCounts { + requires none input {} output { stdout: String from "stdout", success: Bool from "exit_success" } readonly diff --git a/dag/extdeps/linux/procfs.dag b/dag/extdeps/linux/procfs.dag index f8a5a9d8852..0aeda6612b3 100644 --- a/dag/extdeps/linux/procfs.dag +++ b/dag/extdeps/linux/procfs.dag @@ -119,6 +119,7 @@ data procfs_paths_read_by_this_repository: List = [ // not something this binding can supply. service linux.Procfs { operation ReadStat { + requires none input {} output { value: String from "stdout" @@ -136,6 +137,7 @@ service linux.Procfs { } operation ReadUptime { + requires none input {} output { value: String from "content" @@ -149,6 +151,7 @@ service linux.Procfs { } operation ReadMeminfo { + requires none input {} output { value: String from "stdout" @@ -166,6 +169,7 @@ service linux.Procfs { } operation ReadPidStat { + requires none input { pid: NonEmptyStr } output { value: String from "stdout" @@ -183,6 +187,7 @@ service linux.Procfs { } operation ReadNetTcp { + requires none input {} output { value: String from "stdout" @@ -200,6 +205,7 @@ service linux.Procfs { } operation ReadNetTcp6 { + requires none input {} output { value: String from "stdout" @@ -217,6 +223,7 @@ service linux.Procfs { } operation ReadPidCgroup { + requires none input { pid: NonEmptyStr } output { value: String from "stdout" diff --git a/dag/extdeps/llm/anthropic_rest.dag b/dag/extdeps/llm/anthropic_rest.dag index 953471eba22..684cdebbac7 100644 --- a/dag/extdeps/llm/anthropic_rest.dag +++ b/dag/extdeps/llm/anthropic_rest.dag @@ -67,7 +67,7 @@ service llm.Anthropic { } operation CliPrompt { - requires Network + requires opaque input { prompt: String model: String = "opus" diff --git a/dag/extdeps/llm/cli.dag b/dag/extdeps/llm/cli.dag index bce85837d35..8e973cdeabd 100644 --- a/dag/extdeps/llm/cli.dag +++ b/dag/extdeps/llm/cli.dag @@ -526,7 +526,7 @@ fn shape_codex_exec_argv( service llm.Codex { operation Review { - requires Network + requires opaque input { prompt: String cwd: String @@ -557,7 +557,7 @@ service llm.Codex { service claude.Invoke { operation Run { - requires Network + requires opaque input { session_id: String node_id: String diff --git a/dag/extdeps/llm/codex_app_server.dag b/dag/extdeps/llm/codex_app_server.dag index 5d832b446c8..54a53ad3654 100644 --- a/dag/extdeps/llm/codex_app_server.dag +++ b/dag/extdeps/llm/codex_app_server.dag @@ -72,6 +72,7 @@ type CodexAppServerExecutable { // module's method vocabulary was derived from, not a different product surface. service codex_app_server.Cli { operation GenerateJsonSchema { + requires opaque input { executable: CodexAppServerExecutable, output_dir: FilePath } output { success: Bool from "exit_success" diff --git a/dag/extdeps/node/node.dag b/dag/extdeps/node/node.dag index 57163a371cf..2211cfb5088 100644 --- a/dag/extdeps/node/node.dag +++ b/dag/extdeps/node/node.dag @@ -29,6 +29,7 @@ data extdeps_model_scope: ExternalModelScope = ExternalModelScope { // as a nonzero exit, so the caller receives success: false without a fallback. service node.Runtime { operation RunFile { + requires opaque input { workdir: FilePath, script_path: FilePath, args: List = [] } output { success: Bool from "exit_success" diff --git a/dag/extdeps/nvidia/system_management_interface.dag b/dag/extdeps/nvidia/system_management_interface.dag index 7a79e0a2299..7c8a41b5cd9 100644 --- a/dag/extdeps/nvidia/system_management_interface.dag +++ b/dag/extdeps/nvidia/system_management_interface.dag @@ -29,6 +29,7 @@ data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { // consumer must not read the presence of a process as weightless because its figure was withheld. service nvidia_smi.Smi { operation QueryComputeApps { + requires none input {} output { value: String from "stdout" diff --git a/dag/extdeps/package_managers/dpkg.dag b/dag/extdeps/package_managers/dpkg.dag index 322d0300d07..5e121276dbd 100644 --- a/dag/extdeps/package_managers/dpkg.dag +++ b/dag/extdeps/package_managers/dpkg.dag @@ -21,6 +21,7 @@ data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { // was all that held the fork together; equality is not single authority. service dpkg.Package { operation Status { + requires none input { package: NonEmptyStr } output { installed: Bool from "exit_success" } readonly diff --git a/dag/extdeps/posix/getconf.dag b/dag/extdeps/posix/getconf.dag index f47d4842d3c..51fbe70a58d 100644 --- a/dag/extdeps/posix/getconf.dag +++ b/dag/extdeps/posix/getconf.dag @@ -46,6 +46,7 @@ fn getconf_clock_ticks_command() -> ArgvCommand { service posix.Getconf { operation ClockTicksPerSecond { + requires none input {} output { value: String from "stdout" diff --git a/dag/extdeps/posix/signal.dag b/dag/extdeps/posix/signal.dag index b638c29042f..68ad9509ad7 100644 --- a/dag/extdeps/posix/signal.dag +++ b/dag/extdeps/posix/signal.dag @@ -32,6 +32,7 @@ data extdeps_model_scope: ExternalModelScope = ExternalModelScope { // everything the caller can reach". service posix.Signal { operation TerminateProcess { + requires none input { pid: NonEmptyStr } output { success: Bool from "exit_success" diff --git a/dag/extdeps/python/python.dag b/dag/extdeps/python/python.dag index cc02b089983..b9ab7fb267d 100644 --- a/dag/extdeps/python/python.dag +++ b/dag/extdeps/python/python.dag @@ -15,6 +15,7 @@ data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { service python.Interpreter { operation RunFile { + requires opaque input { workdir: FilePath, script_path: FilePath, args: List = [] } output { success: Bool from "exit_success" diff --git a/dag/extdeps/rust/cargo_build.dag b/dag/extdeps/rust/cargo_build.dag index b469a7e499e..0cb59780fab 100644 --- a/dag/extdeps/rust/cargo_build.dag +++ b/dag/extdeps/rust/cargo_build.dag @@ -58,7 +58,7 @@ data cargo_check_manifest_messages_note: String = "Cargo's structured check surf service cargo.Build { operation Build { - requires Network + requires opaque input { extra_args: List = [], env: Map = cargo_compile_env, build_jobs_args: List = [] } output { success: Bool from "exit_success" @@ -73,7 +73,7 @@ service cargo.Build { } operation BuildInheritEnv { - requires Network + requires opaque input { workdir: FilePath, extra_args: List = [] } output { success: Bool from "exit_success" @@ -88,7 +88,7 @@ service cargo.Build { } operation BuildManifest { - requires Network + requires opaque input { workdir: FilePath, manifest_path: FilePath, target_dir: FilePath, extra_args: List = [] } output { success: Bool from "exit_success" @@ -103,7 +103,7 @@ service cargo.Build { } operation BuildManifestMessages { - requires Network + requires opaque input { workdir: FilePath, manifest_path: FilePath, target_dir: FilePath, extra_args: List = [] } output { success: Bool from "exit_success" @@ -118,7 +118,7 @@ service cargo.Build { } operation CheckManifestMessages { - requires Network + requires opaque input { workdir: FilePath, manifest_path: FilePath, target_dir: FilePath, extra_args: List = [] } output { success: Bool from "exit_success" @@ -133,7 +133,7 @@ service cargo.Build { } operation Test { - requires Network + requires opaque input { extra_args: List = [] } output { success: Bool from "exit_success" @@ -149,7 +149,7 @@ service cargo.Build { } operation TestWithCwdEnv { - requires Network + requires opaque input { workdir: FilePath, cargo_bin: NonEmptyStr, env: List = [], extra_args: List = [] } output { success: Bool from "exit_success" @@ -166,7 +166,7 @@ service cargo.Build { } operation Nextest { - requires Network + requires opaque input { extra_args: List = [], build_jobs_args: List = [] } output { success: Bool from "exit_success" @@ -182,7 +182,7 @@ service cargo.Build { } operation Clippy { - requires Network + requires opaque input { extra_args: List = [] lint_args: List = [] @@ -200,6 +200,7 @@ service cargo.Build { } operation Fmt { + requires opaque input { extra_args: List = [] } output { success: Bool from "exit_success" @@ -214,7 +215,7 @@ service cargo.Build { } operation Check { - requires Network + requires opaque input { extra_args: List = [] } output { success: Bool from "exit_success" @@ -229,7 +230,7 @@ service cargo.Build { } operation Doc { - requires Network + requires opaque input { extra_args: List = [] } output { success: Bool from "exit_success" @@ -245,7 +246,7 @@ service cargo.Build { } operation Run { - requires Network + requires opaque input { package: String, bin: String, args: List } output { success: Bool from "exit_success" @@ -271,6 +272,7 @@ service cargo.Build { // separately versioned, and a toolchain can carry a cargo that a rustc release line does not name. service cargo.Identity { operation Version { + requires none input {} output { success: Bool from "exit_success" diff --git a/dag/extdeps/rust/rustc.dag b/dag/extdeps/rust/rustc.dag index 0d8ec741ca5..e46e6d29cbb 100644 --- a/dag/extdeps/rust/rustc.dag +++ b/dag/extdeps/rust/rustc.dag @@ -52,6 +52,7 @@ data extdeps_model_scope: ExternalModelScope = ExternalModelScope { service rustc.Check { operation CheckSourceText { + requires none input { source: String, edition: String = "2021" } output { success: Bool from "exit_success" @@ -81,6 +82,7 @@ service rustc.Check { // repository-specific identity string: which fields a consumer joins on is the consumer's fact. service rustc.Identity { operation VersionVerbose { + requires none input {} output { success: Bool from "exit_success" diff --git a/dag/extdeps/shell.dag b/dag/extdeps/shell.dag index 812c9d70fad..40ead0f46a5 100644 --- a/dag/extdeps/shell.dag +++ b/dag/extdeps/shell.dag @@ -56,6 +56,7 @@ data find_pipe_shell_emit_dissolution_trigger: DissolutionCondition = unbound_di service shell.Find { operation ListDirs { + requires none input { path: FilePath, max_depth: Int = 1, min_depth: Int = 1 } output { dirs: List from "stdout_lines" } readonly @@ -67,6 +68,7 @@ service shell.Find { } operation FilesAndSymlinksWithMode { + requires none input { root: FilePath } output { success: Bool from "exit_success" @@ -88,6 +90,7 @@ service shell.Find { } operation Files { + requires none input { workdir: FilePath, root: FilePath, name_glob: String } output { success: Bool from "exit_success" @@ -103,6 +106,7 @@ service shell.Find { } operation SocketInodeHolders { + requires none input { inode: NonEmptyStr } output { success: Bool from "exit_success" @@ -120,6 +124,7 @@ service shell.Find { } operation FilesByNameSorted { + requires none input { root: FilePath, name_glob: NonEmptyStr } output { success: Bool from "exit_success" @@ -143,6 +148,7 @@ service shell.Find { service shell.Env { operation Get { + requires none input { name: NonEmptyStr } output { value: String? from "stdout" } readonly @@ -181,6 +187,7 @@ service shell.Env { service shell.PosixCommandV { operation Check { + requires none input { command: NonEmptyStr } output { exists: Bool from "exit_success", path: FilePath? from "stdout" } readonly @@ -204,6 +211,7 @@ fn posix_command_v_check_argv(command: NonEmptyStr) -> List { // mode digits and gets its own operation rather than being parsed out of them. service shell.Test { operation IsExecutable { + requires none input { path: FilePath } output { executable: Bool from "exit_success" } readonly @@ -215,6 +223,7 @@ service shell.Test { } operation IsNonEmpty { + requires none input { path: FilePath } output { nonempty: Bool from "exit_success" } readonly @@ -226,6 +235,7 @@ service shell.Test { } operation IsFile { + requires none input { path: FilePath } output { is_file: Bool from "exit_success" } readonly @@ -237,6 +247,7 @@ service shell.Test { } operation IsDirectory { + requires none input { path: FilePath } output { is_directory: Bool from "exit_success" } readonly @@ -248,6 +259,7 @@ service shell.Test { } operation IsSticky { + requires none input { path: FilePath } output { is_sticky: Bool from "exit_success" } readonly @@ -259,6 +271,7 @@ service shell.Test { } operation IsWritable { + requires none input { path: FilePath } output { writable: Bool from "exit_success" } readonly @@ -283,6 +296,7 @@ fn shell_test_is_executable_argv(path: FilePath) -> List { // that the location it named is the location it got. service shell.Path { operation Canonical { + requires none input { path: FilePath } output { success: Bool from "exit_success" @@ -300,6 +314,7 @@ service shell.Path { service shell.Id { operation UserId { + requires none input {} output { success: Bool from "exit_success" @@ -315,6 +330,7 @@ service shell.Id { } operation UserName { + requires none input {} output { success: Bool from "exit_success" @@ -332,6 +348,7 @@ service shell.Id { service shell.Uname { operation KernelName { + requires none input {} output { name: String from "stdout", success: Bool from "exit_success" } transport shell { argv: ["uname", "-s"] } @@ -342,6 +359,7 @@ service shell.Uname { } operation Machine { + requires none input {} output { machine: String from "stdout", success: Bool from "exit_success" } transport shell { argv: ["uname", "-m"] } @@ -354,6 +372,7 @@ service shell.Uname { service shell.Mktemp { operation FileInDirectory { + requires none input { dir: FilePath } output { path: FilePath from "stdout", success: Bool from "exit_success" } transport shell { argv: ["mktemp", "-p", "{dir}"] } @@ -364,6 +383,7 @@ service shell.Mktemp { } operation Dir { + requires none input {} output { path: FilePath from "stdout", success: Bool from "exit_success" } transport shell { argv: ["mktemp", "-d"] } @@ -374,6 +394,7 @@ service shell.Mktemp { } operation DirWithTemplate { + requires none input { template: FilePath } output { path: FilePath from "stdout", success: Bool from "exit_success" } transport shell { argv: ["mktemp", "-d", "{template}"] } @@ -392,6 +413,7 @@ service shell.Mktemp { // name never exists at a wider one and no second pathname operation is needed to narrow it. service shell.Mkdir { operation NewOwnerOnly { + requires none input { path: FilePath } output { success: Bool from "exit_success" } transport shell { argv: ["mkdir", "-m", "0700", "--", "{path}"] } @@ -402,6 +424,7 @@ service shell.Mkdir { } operation Parents { + requires none input { path: FilePath } output { success: Bool from "exit_success" } transport shell { argv: ["mkdir", "-p", "{path}"] } @@ -414,6 +437,7 @@ service shell.Mkdir { service shell.Link { operation Hard { + requires none input { source: FilePath, destination: FilePath } output { success: Bool from "exit_success" } transport shell { argv: ["ln", "{source}", "{destination}"] } @@ -426,6 +450,7 @@ service shell.Link { service shell.Remove { operation FileForce { + requires none input { path: FilePath } output { success: Bool from "exit_success" } transport shell { argv: ["rm", "-f", "{path}"] } @@ -436,6 +461,7 @@ service shell.Remove { } operation RecursiveForce { + requires none input { path: FilePath } output { success: Bool from "exit_success" } transport shell { argv: ["rm", "-rf", "{path}"] } @@ -446,6 +472,7 @@ service shell.Remove { } operation EmptyDirectory { + requires none input { path: FilePath } output { success: Bool from "exit_success" } transport shell { argv: ["rmdir", "{path}"] } @@ -472,6 +499,7 @@ service shell.Remove { // comparison was available. service shell.Stat { operation ModeOf { + requires none input { path: FilePath } output { success: Bool from "exit_success" @@ -487,6 +515,7 @@ service shell.Stat { } operation OwnerOf { + requires none input { path: FilePath } output { success: Bool from "exit_success" @@ -504,6 +533,7 @@ service shell.Stat { service shell.Move { operation File { + requires none input { source: FilePath, destination: FilePath } output { success: Bool from "exit_success" } transport shell { argv: ["mv", "{source}", "{destination}"] } @@ -514,6 +544,7 @@ service shell.Move { } operation NoReplaceDirectory { + requires none input { source: FilePath, destination: FilePath } output { success: Bool from "exit_success" } transport shell { argv: ["mv", "-T", "{source}", "{destination}"] } @@ -526,6 +557,7 @@ service shell.Move { service shell.Chmod { operation OwnerOnlyDirectory { + requires none input { path: FilePath } output { success: Bool from "exit_success" } transport shell { argv: ["chmod", "0700", "{path}"] } @@ -536,6 +568,7 @@ service shell.Chmod { } operation WorldWritableDirectory { + requires none input { path: FilePath } output { success: Bool from "exit_success" } transport shell { argv: ["chmod", "0777", "{path}"] } @@ -546,6 +579,7 @@ service shell.Chmod { } operation OwnerReadWriteFile { + requires none input { path: FilePath } output { success: Bool from "exit_success" } transport shell { argv: ["chmod", "0600", "{path}"] } @@ -556,6 +590,7 @@ service shell.Chmod { } operation RecursiveWritable { + requires none input { path: FilePath } output { success: Bool from "exit_success" } transport shell { argv: ["chmod", "-R", "u+w", "{path}"] } @@ -566,6 +601,7 @@ service shell.Chmod { } operation RecursiveReadOnly { + requires none input { path: FilePath } output { success: Bool from "exit_success" } transport shell { argv: ["chmod", "-R", "a-w", "{path}"] } @@ -578,6 +614,7 @@ service shell.Chmod { service shell.Copy { operation File { + requires none input { source: FilePath, destination: FilePath } output { success: Bool from "exit_success" } transport shell { argv: ["cp", "{source}", "{destination}"] } @@ -588,6 +625,7 @@ service shell.Copy { } operation Recursive { + requires none input { source: FilePath, destination: FilePath } output { success: Bool from "exit_success" } transport shell { argv: ["cp", "-r", "{source}", "{destination}"] } diff --git a/dag/extdeps/shell/exec.dag b/dag/extdeps/shell/exec.dag index 13c939bd262..7f0ef43e4af 100644 --- a/dag/extdeps/shell/exec.dag +++ b/dag/extdeps/shell/exec.dag @@ -132,6 +132,7 @@ data shell_exec_transport_ceiling_authority: ByteSize = host_exec_arg_max_strlen service shell.Exec { operation Run { + requires opaque input { script: TransportScript } output { @@ -152,6 +153,7 @@ service shell.Exec { } operation RunArgv { + requires opaque input { program: NonEmptyStr, arguments: ProcessArgvExpansion } output { @@ -170,6 +172,7 @@ service shell.Exec { } } operation RunArgvStdin { + requires opaque input { program: NonEmptyStr, arguments: ProcessArgvExpansion, stdin_payload: String } output { @@ -190,6 +193,7 @@ service shell.Exec { } operation RunArgvOutcome { + requires opaque input { program: NonEmptyStr, arguments: ProcessArgvExpansion } output { @@ -210,6 +214,7 @@ service shell.Exec { } operation Check { + requires opaque input { command: TransportScript } output { exists: Bool from "exit_success" } readonly diff --git a/dag/extdeps/sudo/nopasswd_execute_probe_check_op.dag b/dag/extdeps/sudo/nopasswd_execute_probe_check_op.dag index e3e26ef99c3..4a0aaab6482 100644 --- a/dag/extdeps/sudo/nopasswd_execute_probe_check_op.dag +++ b/dag/extdeps/sudo/nopasswd_execute_probe_check_op.dag @@ -110,6 +110,7 @@ fn sudo_nopasswd_grant_list_shell_condition(probe: SudoNopasswdGrantListProbeSha service sudo.NopasswdExecuteProbe { operation Check { + requires opaque input { probe: SudoNopasswdExecuteProbeShape } output { success: Bool from "exit_success" } readonly @@ -129,6 +130,7 @@ service sudo.NopasswdExecuteProbe { service sudo.NopasswdGrantList { operation Read { + requires none input {} output { exit_code: Int from "exit_code" diff --git a/dag/extdeps/systemd/journalctl.dag b/dag/extdeps/systemd/journalctl.dag index 2929f03432f..f22af633ba5 100644 --- a/dag/extdeps/systemd/journalctl.dag +++ b/dag/extdeps/systemd/journalctl.dag @@ -45,6 +45,7 @@ data extdeps_model_scope: ExternalModelScope = ExternalModelScope { // journal daemon adds, not one the logging process can set. (man7.org, read 2026-09-23.) service systemd.Journalctl { operation UnitLog { + requires none input { unit: NonEmptyStr } output { stdout: String from "stdout" @@ -65,6 +66,7 @@ service systemd.Journalctl { } operation UnitInvocationLog { + requires none input { unit: NonEmptyStr, invocation_id: NonEmptyStr } output { stdout: String from "stdout" diff --git a/dag/extdeps/systemd/oomd.dag b/dag/extdeps/systemd/oomd.dag index 4573ef54444..166a13b80ce 100644 --- a/dag/extdeps/systemd/oomd.dag +++ b/dag/extdeps/systemd/oomd.dag @@ -90,6 +90,7 @@ type OomdDropIn { service systemd.Oomctl { operation Dump { + requires none input {} output { stdout: String from "stdout" diff --git a/dag/extdeps/systemd/systemctl.dag b/dag/extdeps/systemd/systemctl.dag index 506a7fc40ba..f6fadace03a 100644 --- a/dag/extdeps/systemd/systemctl.dag +++ b/dag/extdeps/systemd/systemctl.dag @@ -445,6 +445,7 @@ type UnitFileState // service systemd.Systemctl { operation Enable { + requires Network input { unit: NonEmptyStr } output { success: Bool from "exit_success" @@ -459,6 +460,7 @@ service systemd.Systemctl { } operation Restart { + requires Network input { unit: NonEmptyStr } output { success: Bool from "exit_success" @@ -473,6 +475,7 @@ service systemd.Systemctl { } operation DisableNow { + requires Network input { unit: NonEmptyStr } output { success: Bool from "exit_success" @@ -487,6 +490,7 @@ service systemd.Systemctl { } operation Start { + requires Network input { unit: NonEmptyStr } output { success: Bool from "exit_success" @@ -501,6 +505,7 @@ service systemd.Systemctl { } operation Stop { + requires Network input { unit: NonEmptyStr } output { success: Bool from "exit_success" @@ -518,6 +523,7 @@ service systemd.Systemctl { } operation ResetFailedUnit { + requires Network input { unit: NonEmptyStr } output { success: Bool from "exit_success" @@ -534,6 +540,7 @@ service systemd.Systemctl { } operation KillUnitTerm { + requires Network input { unit: NonEmptyStr } output { success: Bool from "exit_success" @@ -550,6 +557,7 @@ service systemd.Systemctl { } operation MaskNow { + requires Network input { unit: NonEmptyStr } output { success: Bool from "exit_success" @@ -567,6 +575,7 @@ service systemd.Systemctl { } operation SetProperty { + requires Network input { unit: NonEmptyStr, property: NonEmptyStr, value: NonEmptyStr } output { success: Bool from "exit_success" @@ -583,6 +592,7 @@ service systemd.Systemctl { } operation RevertMemoryCaps { + requires Network input { unit: NonEmptyStr } output { success: Bool from "exit_success" @@ -599,6 +609,7 @@ service systemd.Systemctl { } operation DaemonReload { + requires none input {} output { success: Bool from "exit_success" @@ -612,6 +623,7 @@ service systemd.Systemctl { } operation IsActive { + requires Network input { unit: NonEmptyStr } output { state: String from "stdout" @@ -630,6 +642,7 @@ service systemd.Systemctl { } operation ShowProperty { + requires Network input { unit: NonEmptyStr, property: NonEmptyStr } output { value: String from "stdout" @@ -647,6 +660,7 @@ service systemd.Systemctl { } operation ShowUserProperty { + requires Network input { unit: NonEmptyStr, property: NonEmptyStr } output { outcome: ShellOutcome @@ -665,6 +679,7 @@ service systemd.Systemctl { } operation ShowLoadState { + requires Network input { unit: NonEmptyStr } output { value: String from "stdout" @@ -682,6 +697,7 @@ service systemd.Systemctl { } operation ListUnits { + requires Network input { pattern: NonEmptyStr, unit_type: String = "service", @@ -716,6 +732,7 @@ service systemd.Systemctl { } operation ListUnitsAllLoaded { + requires Network input { pattern: NonEmptyStr, unit_type: String = "service", @@ -749,6 +766,7 @@ service systemd.Systemctl { } operation Status { + requires Network input { unit: NonEmptyStr } output { stdout: String from "stdout" diff --git a/dag/extdeps/systemd/systemd_run.dag b/dag/extdeps/systemd/systemd_run.dag index 53dc795e7fc..f0888848d51 100644 --- a/dag/extdeps/systemd/systemd_run.dag +++ b/dag/extdeps/systemd/systemd_run.dag @@ -220,6 +220,7 @@ fn systemd_run_transient_wait_unit_argv(unit: NonEmptyStr, properties: List, command_argv: List } output { success: Bool from "exit_success" @@ -238,6 +239,7 @@ service systemd.SystemdRun { operation RunTransientRetained { + requires opaque input { unit: NonEmptyStr, property_argv: List, command_argv: List } output { success: Bool from "exit_success" @@ -255,6 +257,7 @@ service systemd.SystemdRun { } operation RunTransientAndWait { + requires opaque input { unit: NonEmptyStr, property_argv: List, command_argv: List } output { exit_code: Int from "exit_code" diff --git a/dag/extdeps/tailscale/serve.dag b/dag/extdeps/tailscale/serve.dag index dc013282858..8d99fbc7d17 100644 --- a/dag/extdeps/tailscale/serve.dag +++ b/dag/extdeps/tailscale/serve.dag @@ -402,6 +402,7 @@ data tailscale_serve_resource_relation: KeyedResourceRelation List { service tmux.Session { operation New { + requires opaque input { session_name: String, working_dir: String, inner_argv: List } output { success: Bool from "exit_success" @@ -630,6 +631,7 @@ service tmux.Session { } operation List { + requires none input {} output { sessions: String from "stdout" } readonly @@ -641,6 +643,7 @@ service tmux.Session { } operation Kill { + requires none input { session_name: String } output { success: Bool from "exit_success" diff --git a/dag/extdeps/tools/coreutils_stat.dag b/dag/extdeps/tools/coreutils_stat.dag index 6bc7566410d..22665d21521 100644 --- a/dag/extdeps/tools/coreutils_stat.dag +++ b/dag/extdeps/tools/coreutils_stat.dag @@ -47,6 +47,7 @@ data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { // spelling. service coreutils.Stat { operation PathOwnership { + requires none input { path: NonEmptyStr } output { line: String from "stdout" @@ -61,6 +62,7 @@ service coreutils.Stat { } operation PathSize { + requires none input { path: NonEmptyStr } output { size_text: String from "stdout" @@ -75,6 +77,7 @@ service coreutils.Stat { } operation PathMode { + requires none input { path: NonEmptyStr } output { mode_text: String from "stdout" diff --git a/dag/extdeps/tools/diffutils.dag b/dag/extdeps/tools/diffutils.dag index 8eb1308502b..232afb8dcc9 100644 --- a/dag/extdeps/tools/diffutils.dag +++ b/dag/extdeps/tools/diffutils.dag @@ -20,6 +20,7 @@ data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { service shell.Diff { operation Recursive { + requires none input { left: FilePath, right: FilePath } output { identical: Bool from "exit_success", exit_code: Int from "exit_code" } readonly diff --git a/dag/extdeps/tools/grep.dag b/dag/extdeps/tools/grep.dag index 5cceb6b3fe3..c43876547d0 100644 --- a/dag/extdeps/tools/grep.dag +++ b/dag/extdeps/tools/grep.dag @@ -24,6 +24,7 @@ data grep_cli_tool: CliTool = CliTool { service grep.Grep { operation MatchesFixedString { + requires none input { pattern: NonEmptyStr, path: NonEmptyStr } output { matches: Bool from "exit_success" } readonly diff --git a/dag/extdeps/tools/gzip.dag b/dag/extdeps/tools/gzip.dag index 69a461d08c4..7ba2761b7b0 100644 --- a/dag/extdeps/tools/gzip.dag +++ b/dag/extdeps/tools/gzip.dag @@ -43,6 +43,7 @@ data extdeps_model_scope: ExternalModelScope = ExternalModelScope { // disk is never modified (--stdout). service gzip.Gzip { operation DecodeToStdout { + requires none input { path: NonEmptyStr } output { text: String from "stdout" diff --git a/dag/extdeps/tools/hostname.dag b/dag/extdeps/tools/hostname.dag index 0dbbc841da3..3966619f8d8 100644 --- a/dag/extdeps/tools/hostname.dag +++ b/dag/extdeps/tools/hostname.dag @@ -45,6 +45,7 @@ fn hostname_short_read_argv() -> List { service os.Hostname { operation ReadShort { + requires none input {} output { value: String from "stdout" @@ -200,6 +201,7 @@ fn hostname_set_surface_words(surface: CliSurface) -> List { // carried no readonly marker. The process handler is a realization, not an observation. service hostnamectl.Process { operation Run { + requires Network input { arguments: ProcessArgvExpansion } output { exit_code: Int from "exit_code" diff --git a/dag/extdeps/tools/id.dag b/dag/extdeps/tools/id.dag index 70fada17f63..f7945dd1bc4 100644 --- a/dag/extdeps/tools/id.dag +++ b/dag/extdeps/tools/id.dag @@ -53,6 +53,7 @@ fn id_uid_of_command(user: NonEmptyStr) -> ArgvCommand { service os.Id { operation Uid { + requires none input {} output { value: String from "stdout" @@ -70,6 +71,7 @@ service os.Id { } operation Gid { + requires none input {} output { value: String from "stdout" @@ -87,6 +89,7 @@ service os.Id { } operation Lookup { + requires none input { user: NonEmptyStr } output { stdout: String from "stdout" diff --git a/dag/extdeps/tools/jq.dag b/dag/extdeps/tools/jq.dag index a7870d99289..0ba297bab2a 100644 --- a/dag/extdeps/tools/jq.dag +++ b/dag/extdeps/tools/jq.dag @@ -76,6 +76,7 @@ data jq_cli_tool: CliTool = CliTool { // reachable by every future caller. service jq.Process { operation RunWithStdin { + requires none input { arguments: ProcessArgvExpansion, stdin_payload: String } output { exit_code: Int from "exit_code" @@ -94,6 +95,7 @@ service jq.Process { } operation RunWithoutStdin { + requires none input { arguments: ProcessArgvExpansion } output { exit_code: Int from "exit_code" diff --git a/dag/extdeps/tools/node.dag b/dag/extdeps/tools/node.dag index a6c9abe46b6..17da4190a64 100644 --- a/dag/extdeps/tools/node.dag +++ b/dag/extdeps/tools/node.dag @@ -33,6 +33,7 @@ data node_cli_tool: CliTool = CliTool { service nodejs.Cli { operation Version { + requires none input {} output { version: String from "stdout" diff --git a/dag/extdeps/tools/npm.dag b/dag/extdeps/tools/npm.dag index 62c5a5257e5..7a2954b36d7 100644 --- a/dag/extdeps/tools/npm.dag +++ b/dag/extdeps/tools/npm.dag @@ -31,6 +31,7 @@ data npm_cli_tool: CliTool = CliTool { service npm.Cli { operation Version { + requires none input {} output { version: String from "stdout" @@ -88,7 +89,7 @@ service npm.Cache { service npm.Ci { operation IgnoreScripts { - requires Network + requires opaque input { workdir: FilePath } output { success: Bool from "exit_success" @@ -105,6 +106,7 @@ service npm.Ci { } operation IgnoreScriptsOffline { + requires opaque input { workdir: FilePath, cache: FilePath } output { success: Bool from "exit_success" diff --git a/dag/extdeps/tools/openssl.dag b/dag/extdeps/tools/openssl.dag index 61e40267f71..f8224a37f60 100644 --- a/dag/extdeps/tools/openssl.dag +++ b/dag/extdeps/tools/openssl.dag @@ -39,6 +39,7 @@ data openssl_cli_tool: CliTool = CliTool { // through a String is a lossy decode the caller could not detect; hex round-trips exactly. service openssl.Dgst { operation SignSha256Hex { + requires none input { key_file: NonEmptyStr, signing_input: NonEmptyStr } output { exit_code: Int from "exit_code" diff --git a/dag/extdeps/tools/rustfmt.dag b/dag/extdeps/tools/rustfmt.dag index 29e1af98cfb..2a5cc9b791c 100644 --- a/dag/extdeps/tools/rustfmt.dag +++ b/dag/extdeps/tools/rustfmt.dag @@ -27,6 +27,7 @@ data rustfmt_parse_files_note: String = "--emit stdout makes this a parse observ service rustfmt.Parse { operation Files { + requires opaque input { workdir: FilePath, edition: String, files: List } output { success: Bool from "exit_success" diff --git a/dag/extdeps/tools/sed.dag b/dag/extdeps/tools/sed.dag index efbd0012df8..4364421e2be 100644 --- a/dag/extdeps/tools/sed.dag +++ b/dag/extdeps/tools/sed.dag @@ -39,6 +39,7 @@ data sed_cli_tool: CliTool = CliTool { // string, which is the failure this operation's first consumer exists to catch. service sed.Sed { operation InPlaceSubstitute { + requires opaque input { expression: NonEmptyStr, path: NonEmptyStr } output { success: Bool from "exit_success" } transport shell { argv: ["sed", "-i", "{expression}", "{path}"] } @@ -49,6 +50,7 @@ service sed.Sed { } operation ScriptsSuppressAutoPrint { + requires opaque input { arguments: List, path: NonEmptyStr } output { lines: List from "stdout_lines" diff --git a/dag/extdeps/tools/sha256sum.dag b/dag/extdeps/tools/sha256sum.dag index 33f04ec1092..3553ebf957f 100644 --- a/dag/extdeps/tools/sha256sum.dag +++ b/dag/extdeps/tools/sha256sum.dag @@ -51,6 +51,7 @@ data sha256sum_cli_tool: CliTool = CliTool { // DigestStdin uses the no-file-operand mode to digest the supplied content. service sha256sum.Sha256 { operation DigestFile { + requires none input { path: NonEmptyStr } output { line: String from "stdout" @@ -65,6 +66,7 @@ service sha256sum.Sha256 { } operation DigestStdin { + requires none input { content: String } output { line: String from "stdout" @@ -82,6 +84,7 @@ service sha256sum.Sha256 { } operation CheckFile { + requires none input { checksum_file: NonEmptyStr } output { matches: Bool from "exit_success" } readonly diff --git a/dag/extdeps/tools/sha512sum.dag b/dag/extdeps/tools/sha512sum.dag index c5bbcd76bf5..1ede31086b4 100644 --- a/dag/extdeps/tools/sha512sum.dag +++ b/dag/extdeps/tools/sha512sum.dag @@ -56,6 +56,7 @@ data extdeps_model_scope: ExternalModelScope = ExternalModelScope { service sha512sum.Sha512 { operation DigestFile { + requires none input { path: FilePath } output { stdout: String from "stdout" diff --git a/dag/extdeps/tools/sleep.dag b/dag/extdeps/tools/sleep.dag index df51049b29d..bc31745a486 100644 --- a/dag/extdeps/tools/sleep.dag +++ b/dag/extdeps/tools/sleep.dag @@ -69,6 +69,7 @@ fn sleep_seconds_argv(duration: Second) -> SleepArgvRendering { service sleep.Delay { operation Seconds { + requires none input { seconds: NonEmptyStr } output { success: Bool from "exit_success" } transport shell { argv: ["sleep", "{seconds}"] } diff --git a/dag/extdeps/tools/stat.dag b/dag/extdeps/tools/stat.dag index 3630c268af5..f4f02fcb319 100644 --- a/dag/extdeps/tools/stat.dag +++ b/dag/extdeps/tools/stat.dag @@ -168,6 +168,7 @@ fn stat_allocated_blocks_command(path: String) -> ArgvCommand { // -L. The default is relied on here deliberately and is part of the cited GNU authority. service stat.File { operation FileType { + requires none input { path: String } output { file_type: String from "stdout" diff --git a/dag/extdeps/tools/wc.dag b/dag/extdeps/tools/wc.dag index ffd4c42d9e3..97c37aef1ff 100644 --- a/dag/extdeps/tools/wc.dag +++ b/dag/extdeps/tools/wc.dag @@ -40,6 +40,7 @@ data extdeps_model_scope: ExternalModelScope = ExternalModelScope { service wc.ByteCount { operation File { + requires none input { path: FilePath } output { stdout: String from "stdout" diff --git a/dag/extdeps/tools/xorriso.dag b/dag/extdeps/tools/xorriso.dag index 7349d51732e..9090329066d 100644 --- a/dag/extdeps/tools/xorriso.dag +++ b/dag/extdeps/tools/xorriso.dag @@ -30,6 +30,7 @@ data xorriso_cli_tool: CliTool = CliTool { service xorriso.Iso { operation BuildIso { + requires none input { volume_id: NonEmptyStr, output_path: NonEmptyStr, source_dir: NonEmptyStr } output { success: Bool from "exit_success" } transport shell { diff --git a/dag/extdeps/typescript/typescript.dag b/dag/extdeps/typescript/typescript.dag index b22f7999632..4a05719da7c 100644 --- a/dag/extdeps/typescript/typescript.dag +++ b/dag/extdeps/typescript/typescript.dag @@ -33,7 +33,7 @@ data extdeps_model_scope: ExternalModelScope = ExternalModelScope { // success describes the exit, never the existence or absence of emitted files. service typescript.Compiler { operation Compile { - requires Network + requires opaque input { workdir: FilePath, source_path: FilePath, out_dir: FilePath, target: String, module: String } output { success: Bool from "exit_success" diff --git a/dag/gunbc/runner/runner_microvm_boot_probe.dag b/dag/gunbc/runner/runner_microvm_boot_probe.dag index 0588834d76b..057ab32fa58 100644 --- a/dag/gunbc/runner/runner_microvm_boot_probe.dag +++ b/dag/gunbc/runner/runner_microvm_boot_probe.dag @@ -7,6 +7,7 @@ import std.process { ProcessExit, ExitSuccess, exit_failure } import std.disposition { ConstructionMechanism, SingleAuthority } import extdeps.shell import extdeps.exec.command { ArgvCommand } +import extdeps.filesystem.filesystem_io { Filesystem } import extdeps.tools.mkdir { mkdir_parents_command } import extdeps.tools.gnu_coreutils { cp_command, rm_force_command, timeout_command, coreutils_timeout_expired_exit_code } import extdeps.virtualization.firecracker { diff --git a/docs/plans/d13-network-audit.md b/docs/plans/d13-network-audit.md index 1f4aeeb2c26..acf37e7a9c4 100644 --- a/docs/plans/d13-network-audit.md +++ b/docs/plans/d13-network-audit.md @@ -14,7 +14,25 @@ A `requires` clause states what a sandbox must GRANT, so the fail-closed directi - A fetch that depends on cache state is Network: cargo without `--offline`, `npm ci`, `npm cache add`, `npx -y`, `apt-get install`, `gcloud auth print-access-token`. - `arping` is Network: it uses the network interface. - A runtime-program parameter is **OpaqueDemand**: `shell.exec` Run*, `systemd-run` with `command_argv`, the sudo probe `Check`, `gunbc.WitnessBin` `Run`, and the node/python/go `RunFile` runners. The argv is runtime data, so step (b) yields DemandUndecided for their callers instead of an empty demand. + - **Runtime program in an argument** (ruling 2026-10-02): an argument that carries a program the invoked tool executes is **OpaqueDemand** -- scripts, expressions, inner argv, executing templates, and a caller-supplied program path in argv[0] (`codex_app_server` `GenerateJsonSchema`). This includes an unrefined string in option position that the tool accepts as a program-executing option (`git grep -O`). A runtime program whose language has no network or exec primitive (a jq filter; Rust source that rustc only compiles) does not raise the demand above its host program's. + - **Remote-selecting option in an unrefined string** (ruling 2026-10-02): if an unrefined string sits where the tool parses options, and the tool has an option that selects a remote host or URL (`systemctl -H/--host=`, `hostnamectl -H`, curl `-K`/`-x`), the operation is **Network**. That holds unless the argv structurally prevents it, e.g. the string follows `--` or is the value of a preceding option. - Everything else is a local program on local paths: NotNetwork. + - **Live browser page** (ruling 2026-10-02): an interaction with a running browser is **Network**. A click can navigate, page scripts run during any call, and browser startup can fetch. A program whose option surface cannot be verified (`playwright-runner` is not in this repository) is **OpaqueDemand** for every runtime positional it receives; it is never assumed none. + - **Partial clone** (ruling 2026-10-02): a git read that needs blob or tree objects is **Network**, because in a partial clone git lazily fetches missing objects from the promisor remote, and whether a repository is a partial clone belongs to the repository the operation is pointed at, i.e. its input. Reads of commits, refs, the index or config only are not affected. +- **Repository-selected executable** (ruling 2026-10-02): if the invoked command executes a program selected by the input repository or its configuration, the operation is **OpaqueDemand**, unless the operation structurally disables that surface. This covers hooks, clean/smudge/process filters, diff/merge drivers, textconv, the credential helper, the fsmonitor hook, `core.sshCommand`, `remote.*.uploadpack`, a cargo build script or proc macro, `.cargo/config` aliases and runners, the `.npmrc` `git` executable, and agent hooks in a settings argument. Upstream surfaces, all git per git-scm.com/docs: + - githooks(5): `pre-commit`, `prepare-commit-msg` (not suppressed by `--no-verify`), `commit-msg`, `post-commit`, `post-checkout` (checkout, worktree add), `pre-merge-commit`/`post-merge`, `pre-push`, `reference-transaction` (every ref update, including `update-ref`), `post-index-change` (every index write: add, read-tree, update-index, write-tree). + - gitattributes(5): clean on add/status/diff-against-worktree/`hash-object` with a path; smudge on checkout/restore/reset/checkout-index/merge; diff drivers and textconv on patch output; merge drivers on merge and merge-tree. + - git-config(1): `core.fsmonitor` on index refresh (status, add, commit, untracked scans); `credential.helper`, `core.sshCommand`, `remote..uploadpack`/`receivepack` on every transport (fetch, push, ls-remote). + - Cargo: build scripts and proc macros (doc.rust-lang.org/cargo/reference/build-scripts.html), and user aliases that shadow external subcommands such as `fmt` (doc.rust-lang.org/cargo/reference/config.html#alias). + - npm: the `git` config key (docs.npmjs.com/cli/using-npm/config#git) for git dependencies. + - Claude Code: hooks in `--settings` (docs.anthropic.com/claude-code/hooks). + - Agent CLIs (`codex exec`, and `claude -p` with a runtime permission mode) execute model-chosen commands, which makes them runtime programs. + + - Index reads (ruling 2026-10-02, no special case): any git command that reads the index can run the `core.fsmonitor` hook on the first index load (read-cache `tweak_fsmonitor`). That covers plain `ls-files`, and also every unrefined revision argument, because a revision may be spelled `:` or `::`, which reads the index (gitrevisions(7)). So rev-parse/show/cat-file/ls-tree/merge-base/reflog/rev-list/commit-tree/diff with a runtime revision are opaque. + - Toolchain proxies in an input directory (ruling 2026-10-02): rustup selects the toolchain from `rust-toolchain.toml` in the working directory (rust-lang.github.io/rustup/overrides.html). npx reads the project `.npmrc` (e.g. `node-options`). So an operation that runs these in a cwd or repository it takes as input is opaque. The same programs run with an ambient cwd (`cargo --version`, `rustc --version`) fall under the host-environment boundary. + + Git operations that reach none of these surfaces keep their transport verdict. They have fixed revisions and no index read: rev-parse of `HEAD`/`--show-toplevel`, `rev-list --before=… HEAD`, `for-each-ref`, `worktree list`, `branch -r`, `config`, `init`, `hash-object --stdin`, and `log -- {path}` (Network: partial clone). Paging is not reached because stdout is captured, not a TTY. +- **Boundary — host environment is not demand** (ruling 2026-10-02): host-wide configuration (global/system git config, `~/.ssh/config`, rustup toolchain selection from an ambient cwd) and host-wide resolver configuration (NSS, which can route `id`/`whoami`/`stat %U` to LDAP; DNS) is the sandbox's environment, not an operation's demand, and does not raise a clause. ## Citations by class @@ -25,7 +43,7 @@ A `requires` clause states what a sandbox must GRANT, so the fail-closed directi | Network → `requires Network` | GitHub REST API docs (docs.github.com/rest), base https://api.github.com | `extdeps.github.actions_jit_runner`, `extdeps.github.app`, `extdeps.github.checks`, `extdeps.github.code_search`, `extdeps.github.commits`, `extdeps.github.gists`, `extdeps.github.git_database`, `extdeps.github.issues`, `extdeps.github.org_actions`, `extdeps.github.pulls`, `extdeps.github.repository_contents`, `extdeps.github.rulesets`, `extdeps.github.users`, `extdeps.github.workflow_runs`, `extdeps.github.workflows` | | Network → `requires Network` | Google Drive API v3 reference (developers.google.com/drive/api/reference/rest/v3) | `extdeps.google.drive` | | Network → `requires Network` | Google Sheets API v4 reference (developers.google.com/sheets/api/reference/rest) | `extdeps.google.sheets` | -| Network → `requires Network` | PARAM remote: git-fetch(1)/git-push(1)/git-ls-remote(1) use the remote's transport (gitprotocol-v2(5)); a {remote} may be a local path (file transport) or a URL | `extdeps.git`, `extdeps.git.publication_transport` | +| Network → `requires Network` | PARAM remote: git-fetch(1)/git-push(1)/git-ls-remote(1) use the remote's transport (gitprotocol-v2(5)); a {remote} may be a local path (file transport) or a URL; operations run in a repository are now opaque (repository-selected credential helper/sshCommand/uploadpack/pre-push/reference-transaction); the Network clause remains only where none of those surfaces is reached | `extdeps.git`, `extdeps.git.publication_transport` | | Network → `requires Network` | PARAM request_url: endpoint is the runtime ACTIONS_ID_TOKEN_REQUEST_URL (docs.github.com/actions/reference/security/oidc); declaration fixes no host | `extdeps.cloud.gcp.sts` | | Network → `requires Network` | PARAM tarball: npm cache add (docs.npmjs.com/cli/commands/npm-cache) accepts a path or a URL | `extdeps.tools.npm` | | Network → `requires Network` | PARAM url: Playwright page.goto (playwright.dev/docs/api/class-page#page-goto) navigates to a runtime URL | `extdeps.browser` | @@ -34,9 +52,9 @@ A `requires` clause states what a sandbox must GRANT, so the fail-closed directi | Network → `requires Network` | SEC EDGAR APIs (sec.gov/search-filings/edgar-application-programming-interfaces) | `extdeps.sec.edgar_rest` | | Network → `requires Network` | STATE credential cache: gcloud auth print-access-token (cloud.google.com/sdk/gcloud/reference/auth/print-access-token) refreshes over oauth2.googleapis.com only when the cached token is expired | `extdeps.shell` | | Network → `requires Network` | STATE package cache: apt-get(8) install downloads .debs from sources.list unless already installed/cached; PARAM package | `extdeps.apt` | -| Network → `requires Network` | STATE package cache: npm ci (docs.npmjs.com/cli/commands/npm-ci) fetches from the registry unless every tarball is cached | `extdeps.tools.npm` | +| Network → `requires Network` | STATE package cache: npm ci (docs.npmjs.com/cli/commands/npm-ci) fetches from the registry unless every tarball is cached; superseded for `npm.Ci` by the repository-selected executable rule (`.npmrc` `git`): opaque | `extdeps.tools.npm` | | Network → `requires Network` | STATE package cache: npx -y -p (docs.npmjs.com/cli/commands/npx) installs the package from the registry unless already cached | `extdeps.typescript` | -| Network → `requires Network` | STATE registry cache: cargo build/check/test (doc.rust-lang.org/cargo/commands/cargo-build.html, --offline/--frozen) fetch the index/crates only when Cargo.lock deps are not already downloaded; argv does not pass --offline | `extdeps.cargo_build` | +| Network → `requires Network` | STATE registry cache: cargo build/check/test (doc.rust-lang.org/cargo/commands/cargo-build.html, --offline/--frozen) fetch the index/crates only when Cargo.lock deps are not already downloaded; argv does not pass --offline; superseded for `cargo.Build` by the repository-selected executable rule (build scripts, proc macros): opaque | `extdeps.cargo_build` | | Network → `requires Network` | TCGplayer API (docs.tcgplayer.com), base https://api.tcgplayer.com | `extdeps.tcgplayer.catalog`, `extdeps.tcgplayer.pricing`, `extdeps.tcgplayer.store`, `extdeps.tcgplayer.tcgplayer` | | Network → `requires Network` | curl(1) to fixed https://api.github.com (GitHub Apps REST docs.github.com/rest/apps) | `extdeps.github.app` | | Network → `requires Network` | curl(1) to https://{bmc_host}: DMTF Redfish DSP0266 / MegaRAC web API over HTTPS — argv fixes the https scheme to a BMC host | `extdeps.bmc.http`, `extdeps.bmc.megarac` | @@ -56,67 +74,96 @@ A `requires` clause states what a sandbox must GRANT, so the fail-closed directi | Network → `requires Network` | gh(1) manual (cli.github.com/manual): `gh api`/`gh pr`/`gh run` call api.github.com | `extdeps.github.actions_runs`, `extdeps.github.ci_runner`, `extdeps.github.org_actions`, `extdeps.github.organizations`, `extdeps.github.pulls` | | Network → `requires Network` | ipmitool(1) INTERFACES: -I lanplus = IPMI v2.0 RMCP+ over UDP/623 to -H {bmc_host} | `extdeps.bmc.ipmi` | | Network → `requires Network` | ssh(1)/scp(1) (+sshpass(1)): opens TCP/22 session to the host named in argv | `extdeps.bmc.openbmc_password_ssh_transport`, `extdeps.ssh.password_session`, `extdeps.ssh.session` | -| Network → `requires Network` | vendor CLI prompt mode calls the hosted model API (Claude Code docs.anthropic.com/claude-code/cli-reference; Codex CLI `exec` github.com/openai/codex; Gemini CLI github.com/google-gemini/gemini-cli) | `extdeps.llm.anthropic_rest`, `extdeps.llm.cli` | -| NotNetwork → `requires none` (pending #12960) | /usr/bin/stat: local coreutils/POSIX utility (man stat(1)); argv names only local paths/values | `extdeps.tools.stat` | -| NotNetwork → `requires none` (pending #12960) | Docker Engine API (docs.docker.com/reference/api/engine): default endpoint unix:///var/run/docker.sock (extdeps.docker.endpoint docker_default_endpoint), a unix socket | `extdeps.docker.container_inspect`, `extdeps.docker.container_stats` | -| NotNetwork → `requires none` (pending #12960) | Playwright Page/BrowserContext API (playwright.dev/docs/api/class-page): acts on an already-loaded local browser page | `extdeps.browser` | -| NotNetwork → `requires none` (pending #12960) | cargo(1) --version / cargo-fmt: no registry access (doc.rust-lang.org/cargo/commands) | `extdeps.cargo_build` | -| NotNetwork → `requires none` (pending #12960) | cat: local coreutils/POSIX utility (man cat(1)); argv names only local paths/values | `extdeps.linux.cgroup_v2`, `extdeps.linux.procfs` | -| NotNetwork → `requires none` (pending #12960) | chmod: local coreutils/POSIX utility (man chmod(1)); argv names only local paths/values | `extdeps.shell` | -| NotNetwork → `requires none` (pending #12960) | codex app-server generate-json-schema (github.com/openai/codex app-server README): writes schema files locally | `extdeps.llm.codex_app_server` | -| NotNetwork → `requires none` (pending #12960) | cp: local coreutils/POSIX utility (man cp(1)); argv names only local paths/values | `extdeps.shell` | -| NotNetwork → `requires none` (pending #12960) | crontab(1): local spool | `extdeps.cron` | -| NotNetwork → `requires none` (pending #12960) | curl(1) --unix-socket: connects to a local unix socket, not TCP | `extdeps.http.client` | -| NotNetwork → `requires none` (pending #12960) | date: local coreutils/POSIX utility (man date(1)); argv names only local paths/values | `extdeps.clock` | -| NotNetwork → `requires none` (pending #12960) | diff: local coreutils/POSIX utility (man diff(1)); argv names only local paths/values | `extdeps.tools.diffutils` | -| NotNetwork → `requires none` (pending #12960) | dpkg(1): local status database | `extdeps.dpkg` | -| NotNetwork → `requires none` (pending #12960) | find: local coreutils/POSIX utility (man find(1)); argv names only local paths/values | `extdeps.linux.cgroup_v2`, `extdeps.shell` | -| NotNetwork → `requires none` (pending #12960) | getconf: local coreutils/POSIX utility (man getconf(1)); argv names only local paths/values | `extdeps.posix.getconf` | -| NotNetwork → `requires none` (pending #12960) | git(1); local subcommand per git-scm.com/docs (no transport; only fetch/push/ls-remote/clone/pull use git transfer protocols, gitprotocol-v2(5)) | `extdeps.git`, `extdeps.git.inspect`, `extdeps.git.plumbing`, `extdeps.git.publication_transport` | -| NotNetwork → `requires none` (pending #12960) | grep: local coreutils/POSIX utility (man grep(1)); argv names only local paths/values | `extdeps.tools.grep` | -| NotNetwork → `requires none` (pending #12960) | gunbc file transport: local filesystem read/write (POSIX open(2), read(2)) | `extdeps.filesystem.filesystem_io`, `extdeps.linux.procfs` | -| NotNetwork → `requires none` (pending #12960) | gzip: local coreutils/POSIX utility (man gzip(1)); argv names only local paths/values | `extdeps.tools.gzip` | -| NotNetwork → `requires none` (pending #12960) | hostname: local coreutils/POSIX utility (man hostname(1)); argv names only local paths/values | `extdeps.tools.hostname` | -| NotNetwork → `requires none` (pending #12960) | hostnamectl(1): D-Bus to local systemd-hostnamed | `extdeps.tools.hostname` | -| NotNetwork → `requires none` (pending #12960) | id: local coreutils/POSIX utility (man id(1)); argv names only local paths/values | `extdeps.shell`, `extdeps.tools.id` | -| NotNetwork → `requires none` (pending #12960) | ip-address(8): rtnetlink to the local kernel | `extdeps.iproute2.ip_address` | -| NotNetwork → `requires none` (pending #12960) | journalctl(1): reads the local journal | `extdeps.systemd.journalctl` | -| NotNetwork → `requires none` (pending #12960) | jq(1) manual: filter over stdin/args | `extdeps.bmc.openbmc_fan_control`, `extdeps.tools.jq` | -| NotNetwork → `requires none` (pending #12960) | kill: local coreutils/POSIX utility (man kill(1)); argv names only local paths/values | `extdeps.posix.signal` | -| NotNetwork → `requires none` (pending #12960) | ln: local coreutils/POSIX utility (man ln(1)); argv names only local paths/values | `extdeps.shell` | -| NotNetwork → `requires none` (pending #12960) | mkdir: local coreutils/POSIX utility (man mkdir(1)); argv names only local paths/values | `extdeps.shell` | -| NotNetwork → `requires none` (pending #12960) | mktemp: local coreutils/POSIX utility (man mktemp(1)); argv names only local paths/values | `extdeps.shell` | -| NotNetwork → `requires none` (pending #12960) | mv: local coreutils/POSIX utility (man mv(1)); argv names only local paths/values | `extdeps.shell` | -| NotNetwork → `requires none` (pending #12960) | node: local coreutils/POSIX utility (man node(1)); argv names only local paths/values | `extdeps.tools.node` | -| NotNetwork → `requires none` (pending #12960) | npm --version (docs.npmjs.com/cli/commands/npm) | `extdeps.tools.npm` | -| NotNetwork → `requires none` (pending #12960) | npm ci --offline (docs.npmjs.com/cli/using-npm/config#offline): forces cache-only, no network | `extdeps.tools.npm` | -| NotNetwork → `requires none` (pending #12960) | nvidia-smi(1): local NVML | `extdeps.nvidia.system_management_interface` | -| NotNetwork → `requires none` (pending #12960) | oomctl(1): local systemd-oomd | `extdeps.systemd.oomd` | -| NotNetwork → `requires none` (pending #12960) | openssl-dgst(1): local signing | `extdeps.tools.openssl` | -| NotNetwork → `requires none` (pending #12960) | printenv: local coreutils/POSIX utility (man printenv(1)); argv names only local paths/values | `extdeps.shell` | -| NotNetwork → `requires none` (pending #12960) | ras-mc-ctl(8): local EDAC sysfs/rasdaemon DB | `extdeps.linux.edac` | -| NotNetwork → `requires none` (pending #12960) | realpath: local coreutils/POSIX utility (man realpath(1)); argv names only local paths/values | `extdeps.shell` | -| NotNetwork → `requires none` (pending #12960) | rm: local coreutils/POSIX utility (man rm(1)); argv names only local paths/values | `extdeps.shell` | -| NotNetwork → `requires none` (pending #12960) | rmdir: local coreutils/POSIX utility (man rmdir(1)); argv names only local paths/values | `extdeps.shell` | -| NotNetwork → `requires none` (pending #12960) | rustc --version / local compilation (doc.rust-lang.org/rustc) | `extdeps.rustc` | -| NotNetwork → `requires none` (pending #12960) | rustfmt: local coreutils/POSIX utility (man rustfmt(1)); argv names only local paths/values | `extdeps.tools.rustfmt` | -| NotNetwork → `requires none` (pending #12960) | sed: local coreutils/POSIX utility (man sed(1)); argv names only local paths/values | `extdeps.tools.sed` | -| NotNetwork → `requires none` (pending #12960) | sh -c script authored in the declaration uses only local programs (mktemp(1), find(1), sort(1), head(1)/tr(1) over /dev/urandom, rustc --emit=metadata, command -v) | `extdeps.entropy`, `extdeps.rustc`, `extdeps.shell` | -| NotNetwork → `requires none` (pending #12960) | sha256sum: local coreutils/POSIX utility (man sha256sum(1)); argv names only local paths/values | `extdeps.crypto.hash`, `extdeps.tools.sha256sum` | -| NotNetwork → `requires none` (pending #12960) | sha512sum: local coreutils/POSIX utility (man sha512sum(1)); argv names only local paths/values | `extdeps.tools.sha512sum` | -| NotNetwork → `requires none` (pending #12960) | sleep: local coreutils/POSIX utility (man sleep(1)); argv names only local paths/values | `extdeps.tools.sleep` | -| NotNetwork → `requires none` (pending #12960) | stat: local coreutils/POSIX utility (man stat(1)); argv names only local paths/values | `extdeps.shell`, `extdeps.tools.coreutils_stat` | -| NotNetwork → `requires none` (pending #12960) | sudo(8) -l: local policy | `extdeps.sudo.nopasswd_execute_probe_check_op` | -| NotNetwork → `requires none` (pending #12960) | systemctl(1): talks to the local systemd manager over D-Bus/private socket | `extdeps.systemd.systemctl` | -| NotNetwork → `requires none` (pending #12960) | tailscale CLI `serve status` reads the local tailscaled LocalAPI socket (tailscale.com/kb/1242/tailscale-serve) | `extdeps.tailscale.serve` | -| NotNetwork → `requires none` (pending #12960) | test: local coreutils/POSIX utility (man test(1)); argv names only local paths/values | `extdeps.linux.cgroup_v2`, `extdeps.shell` | -| NotNetwork → `requires none` (pending #12960) | tmux(1): local server socket | `extdeps.tmux` | -| NotNetwork → `requires none` (pending #12960) | uname: local coreutils/POSIX utility (man uname(1)); argv names only local paths/values | `extdeps.shell` | -| NotNetwork → `requires none` (pending #12960) | wc: local coreutils/POSIX utility (man wc(1)); argv names only local paths/values | `extdeps.tools.wc` | -| NotNetwork → `requires none` (pending #12960) | whoami: local coreutils/POSIX utility (man whoami(1)); argv names only local paths/values | `extdeps.access.posix_effective_principal_read_op` | -| NotNetwork → `requires none` (pending #12960) | xorriso: local coreutils/POSIX utility (man xorriso(1)); argv names only local paths/values | `extdeps.tools.xorriso` | -| OpaqueDemand → `requires opaque` (pending #12960) | PARAM bin_path: program is runtime | `extdeps.gunbc` | -| OpaqueDemand → `requires opaque` (pending #12960) | PARAM command_argv: systemd-run(1) itself is local; the transient unit runs a runtime command | `extdeps.systemd.systemd_run` | -| OpaqueDemand → `requires opaque` (pending #12960) | PARAM probe.command_path: sudo(8) runs a runtime program | `extdeps.sudo.nopasswd_execute_probe_check_op` | -| OpaqueDemand → `requires opaque` (pending #12960) | PARAM program/command body: argv supplied at runtime | `extdeps.shell.exec` | -| OpaqueDemand → `requires opaque` (pending #12960) | PARAM script_path: behaviour is the runtime script | `extdeps.go`, `extdeps.node`, `extdeps.python` | +| Network → `requires Network` | vendor CLI prompt mode calls the hosted model API (Claude Code docs.anthropic.com/claude-code/cli-reference; Codex CLI `exec` github.com/openai/codex; Gemini CLI github.com/google-gemini/gemini-cli); `claude.Invoke.Run` (hooks in `--settings`), `llm.Anthropic.CliPrompt` (runtime permission mode) and `llm.Codex.Review` (agent exec in `-C {cwd}`) are opaque | `extdeps.llm.anthropic_rest`, `extdeps.llm.cli` | +| NotNetwork → `requires none` | /usr/bin/stat: local coreutils/POSIX utility (man stat(1)); argv names only local paths/values | `extdeps.tools.stat` | +| NotNetwork → `requires none` | Docker Engine API (docs.docker.com/reference/api/engine): default endpoint unix:///var/run/docker.sock (extdeps.docker.endpoint docker_default_endpoint), a unix socket | `extdeps.docker.container_inspect`, `extdeps.docker.container_stats` | +| Network → `requires Network` | RULING live page: Playwright Page/BrowserContext API (playwright.dev/docs/api/class-page); a running page and browser startup may fetch (`Launch`, `CurrentUrl`, `Title`) | `extdeps.browser` | +| OpaqueDemand → `requires opaque` | RULING unverifiable surface: `playwright-runner` is not in this repository, so a runtime positional (selector, text, path, ms, context) may reach an unknown option | `extdeps.browser` | +| OpaqueDemand → `requires opaque` | RULING runtime program: Playwright page.evaluate / locator.evaluate (playwright.dev/docs/evaluating) run runtime JavaScript in the page, which can call fetch | `extdeps.browser` | +| NotNetwork → `requires none` | cargo(1) --version / cargo-fmt: no registry access (doc.rust-lang.org/cargo/commands); `cargo fmt` is now opaque (a workspace alias can shadow the external subcommand); `--version` stays none | `extdeps.cargo_build` | +| NotNetwork → `requires none` | cat: local coreutils/POSIX utility (man cat(1)); argv names only local paths/values | `extdeps.linux.cgroup_v2`, `extdeps.linux.procfs` | +| NotNetwork → `requires none` | chmod: local coreutils/POSIX utility (man chmod(1)); argv names only local paths/values | `extdeps.shell` | +| OpaqueDemand → `requires opaque` | RULING runtime program: argv[0] is the caller-supplied `CodexAppServerExecutable.path`, so the executed program is runtime-selected (codex app-server generate-json-schema itself writes schema files locally, per the github.com/openai/codex app-server README) | `extdeps.llm.codex_app_server` | +| NotNetwork → `requires none` | cp: local coreutils/POSIX utility (man cp(1)); argv names only local paths/values | `extdeps.shell` | +| NotNetwork → `requires none` | crontab(1): local spool | `extdeps.cron` | +| Network → `requires Network` | RULING remote option: curl(1) --unix-socket, but the `{url}` positional is unrefined and not after `--`, so it can carry curl options (`-K`, `-x`) that retarget the connection | `extdeps.http.client` | +| NotNetwork → `requires none` | date: local coreutils/POSIX utility (man date(1)); argv names only local paths/values | `extdeps.clock` | +| NotNetwork → `requires none` | diff: local coreutils/POSIX utility (man diff(1)); argv names only local paths/values | `extdeps.tools.diffutils` | +| NotNetwork → `requires none` | dpkg(1): local status database | `extdeps.dpkg` | +| NotNetwork → `requires none` | find: local coreutils/POSIX utility (man find(1)); argv names only local paths/values | `extdeps.linux.cgroup_v2`, `extdeps.shell` | +| NotNetwork → `requires none` | getconf: local coreutils/POSIX utility (man getconf(1)); argv names only local paths/values | `extdeps.posix.getconf` | +| NotNetwork → `requires none` | git(1); local subcommand per git-scm.com/docs reading only commits, refs, the index or config (no transport; only fetch/push/ls-remote/clone/pull use git transfer protocols, gitprotocol-v2(5)), and running no hook, filter, driver or fsmonitor surface | `extdeps.git`, `extdeps.git.inspect`, `extdeps.git.plumbing`, `extdeps.git.publication_transport` | +| Network → `requires Network` | RULING partial clone: git-partial-clone (git-scm.com/docs/partial-clone) lazily fetches missing blobs/trees from the promisor remote; diff, show, cat-file, ls-tree, log -- path, read-tree, checkout-index, unpack-file, merge, merge-tree, checkout, restore, reset --hard, worktree add; any of these that also runs a repository-selected executable is opaque instead | `extdeps.git`, `extdeps.git.inspect`, `extdeps.git.plumbing` | +| OpaqueDemand → `requires opaque` | RULING runtime program: git-grep(1) `-O` opens matches with a runtime program; `{pattern}` and `{ref}` (GitRef is only non-empty) sit in option position | `extdeps.git.inspect` | +| NotNetwork → `requires none` | grep: local coreutils/POSIX utility (man grep(1)); argv names only local paths/values | `extdeps.tools.grep` | +| NotNetwork → `requires none` | gunbc file transport: local filesystem read/write (POSIX open(2), read(2)) | `extdeps.filesystem.filesystem_io`, `extdeps.linux.procfs` | +| NotNetwork → `requires none` | gzip: local coreutils/POSIX utility (man gzip(1)); argv names only local paths/values | `extdeps.tools.gzip` | +| NotNetwork → `requires none` | hostname: local coreutils/POSIX utility (man hostname(1)); argv names only local paths/values | `extdeps.tools.hostname` | +| Network → `requires Network` | RULING remote option: hostnamectl(1) `-H/--host=` runs over SSH; `Process.Run` forwards an unrestricted ProcessArgvExpansion | `extdeps.tools.hostname` | +| NotNetwork → `requires none` | id: local coreutils/POSIX utility (man id(1)); argv names only local paths/values | `extdeps.shell`, `extdeps.tools.id` | +| NotNetwork → `requires none` | ip-address(8): rtnetlink to the local kernel | `extdeps.iproute2.ip_address` | +| NotNetwork → `requires none` | journalctl(1): reads the local journal | `extdeps.systemd.journalctl` | +| NotNetwork → `requires none` | jq(1) manual: filter over stdin/args | `extdeps.bmc.openbmc_fan_control`, `extdeps.tools.jq` | +| NotNetwork → `requires none` | kill: local coreutils/POSIX utility (man kill(1)); argv names only local paths/values | `extdeps.posix.signal` | +| NotNetwork → `requires none` | ln: local coreutils/POSIX utility (man ln(1)); argv names only local paths/values | `extdeps.shell` | +| NotNetwork → `requires none` | mkdir: local coreutils/POSIX utility (man mkdir(1)); argv names only local paths/values | `extdeps.shell` | +| NotNetwork → `requires none` | mktemp: local coreutils/POSIX utility (man mktemp(1)); argv names only local paths/values | `extdeps.shell` | +| NotNetwork → `requires none` | mv: local coreutils/POSIX utility (man mv(1)); argv names only local paths/values | `extdeps.shell` | +| NotNetwork → `requires none` | node: local coreutils/POSIX utility (man node(1)); argv names only local paths/values | `extdeps.tools.node` | +| NotNetwork → `requires none` | npm --version (docs.npmjs.com/cli/commands/npm) | `extdeps.tools.npm` | +| NotNetwork → `requires none` | npm ci --offline (docs.npmjs.com/cli/using-npm/config#offline): forces cache-only, no network; superseded by the repository-selected executable rule: opaque | `extdeps.tools.npm` | +| NotNetwork → `requires none` | nvidia-smi(1): local NVML | `extdeps.nvidia.system_management_interface` | +| NotNetwork → `requires none` | oomctl(1): local systemd-oomd | `extdeps.systemd.oomd` | +| NotNetwork → `requires none` | openssl-dgst(1): local signing | `extdeps.tools.openssl` | +| NotNetwork → `requires none` | printenv: local coreutils/POSIX utility (man printenv(1)); argv names only local paths/values | `extdeps.shell` | +| NotNetwork → `requires none` | ras-mc-ctl(8): local EDAC sysfs/rasdaemon DB | `extdeps.linux.edac` | +| NotNetwork → `requires none` | realpath: local coreutils/POSIX utility (man realpath(1)); argv names only local paths/values | `extdeps.shell` | +| NotNetwork → `requires none` | rm: local coreutils/POSIX utility (man rm(1)); argv names only local paths/values | `extdeps.shell` | +| NotNetwork → `requires none` | rmdir: local coreutils/POSIX utility (man rmdir(1)); argv names only local paths/values | `extdeps.shell` | +| NotNetwork → `requires none` | rustc --version / local compilation (doc.rust-lang.org/rustc) | `extdeps.rustc` | +| NotNetwork → `requires none` | rustfmt: local coreutils/POSIX utility (man rustfmt(1)); argv names only local paths/values | `extdeps.tools.rustfmt` | +| OpaqueDemand → `requires opaque` | RULING runtime program: GNU sed's `e` command and `s///e` execute shell commands; the operations take a runtime sed program without `--sandbox` | `extdeps.tools.sed` | +| NotNetwork → `requires none` | sh -c script authored in the declaration uses only local programs (mktemp(1), find(1), sort(1), head(1)/tr(1) over /dev/urandom, rustc --emit=metadata, command -v) | `extdeps.entropy`, `extdeps.rustc`, `extdeps.shell` | +| NotNetwork → `requires none` | sha256sum: local coreutils/POSIX utility (man sha256sum(1)); argv names only local paths/values | `extdeps.crypto.hash`, `extdeps.tools.sha256sum` | +| NotNetwork → `requires none` | sha512sum: local coreutils/POSIX utility (man sha512sum(1)); argv names only local paths/values | `extdeps.tools.sha512sum` | +| NotNetwork → `requires none` | sleep: local coreutils/POSIX utility (man sleep(1)); argv names only local paths/values | `extdeps.tools.sleep` | +| NotNetwork → `requires none` | stat: local coreutils/POSIX utility (man stat(1)); argv names only local paths/values | `extdeps.shell`, `extdeps.tools.coreutils_stat` | +| NotNetwork → `requires none` | sudo(8) -l: local policy | `extdeps.sudo.nopasswd_execute_probe_check_op` | +| NotNetwork → `requires none` | systemctl(1): talks to the local systemd manager over D-Bus/private socket; only operations with no unrefined positional string (`DaemonReload`) | `extdeps.systemd.systemctl` | +| Network → `requires Network` | RULING remote option: systemctl(1) `-H/--host=` runs over SSH; the unit/pattern positional is an unrefined NonEmptyStr with no `--` before it | `extdeps.systemd.systemctl` | +| NotNetwork → `requires none` | tailscale CLI `serve status` reads the local tailscaled LocalAPI socket (tailscale.com/kb/1242/tailscale-serve) | `extdeps.tailscale.serve` | +| NotNetwork → `requires none` | test: local coreutils/POSIX utility (man test(1)); argv names only local paths/values | `extdeps.linux.cgroup_v2`, `extdeps.shell` | +| NotNetwork → `requires none` | tmux(1): local server socket (`List`, `Kill`) | `extdeps.tmux` | +| OpaqueDemand → `requires opaque` | RULING runtime program: tmux new-session runs `inner_argv`, a runtime command | `extdeps.tmux` | +| NotNetwork → `requires none` | uname: local coreutils/POSIX utility (man uname(1)); argv names only local paths/values | `extdeps.shell` | +| NotNetwork → `requires none` | wc: local coreutils/POSIX utility (man wc(1)); argv names only local paths/values | `extdeps.tools.wc` | +| NotNetwork → `requires none` | whoami: local coreutils/POSIX utility (man whoami(1)); argv names only local paths/values | `extdeps.access.posix_effective_principal_read_op` | +| NotNetwork → `requires none` | xorriso: local coreutils/POSIX utility (man xorriso(1)); argv names only local paths/values | `extdeps.tools.xorriso` | +| OpaqueDemand → `requires opaque` | PARAM bin_path: program is runtime | `extdeps.gunbc` | +| OpaqueDemand → `requires opaque` | PARAM command_argv: systemd-run(1) itself is local; the transient unit runs a runtime command | `extdeps.systemd.systemd_run` | +| OpaqueDemand → `requires opaque` | PARAM probe.command_path: sudo(8) runs a runtime program | `extdeps.sudo.nopasswd_execute_probe_check_op` | +| OpaqueDemand → `requires opaque` | PARAM program/command body: argv supplied at runtime | `extdeps.shell.exec` | +| OpaqueDemand → `requires opaque` | PARAM script_path: behaviour is the runtime script | `extdeps.go`, `extdeps.node`, `extdeps.python` | + +## Follow-ups (better modeling than the clauses above; not done here) + +- Repository-selected executables in git, by structural disabling. Each item has its citation, and each would move the affected operations back to their transport verdict: + - `-c core.hooksPath=/dev/null` disables every hook, including `prepare-commit-msg` and `reference-transaction` (git-config `core.hooksPath`; githooks(5)). `--no-verify` alone is insufficient. + - `-c core.fsmonitor=false` (git-config `core.fsmonitor`) disables the fsmonitor hook on every index read. `--no-optional-locks` does not: it only skips the opportunistic index write (git(1)). + - Revision arguments: a refined revision type that excludes the `:` index forms, or `--end-of-options` plus a full object id, removes the index read from rev-parse/show/cat-file/ls-tree/merge-base/rev-list. + - Toolchain proxies: pin the toolchain explicitly (`cargo +`, `RUSTUP_TOOLCHAIN`) and run npx with `--userconfig`/an isolated cwd, or the operation stays opaque. + - `--no-textconv --no-ext-diff` on diff (git-diff(1)). + - `hash-object --no-filters` (git-hash-object(1)). + - Overriding the filter and merge-driver surfaces needs per-driver `-c filter..*`/`merge..driver` overrides, which are unknown in advance. A typed attribute-free checkout realization is the structural route; otherwise those operations stay opaque. + - On transports, `-c credential.helper=` (an empty value resets the helper list; gitcredentials(7)), `-c core.sshCommand=ssh`, and dropping `--upload-pack`. +- Cargo: no flag disables build scripts or proc macros, so those operations stay opaque until the workspace's build-time programs are modeled. +- npm ci: `--git=false`-style suppression is not documented. Pin the lockfile to registry-only sources and refuse git dependencies. + +- `systemd.Systemctl` and `hostnamectl.Process`: terminate options before the unit/pattern positional (`--`), or refine the input to a unit-name type. Either move those operations back to `requires none`. +- `sed.Sed`: a typed non-executing sed subset, or `--sandbox` in the argv, would move both operations to `requires none`. +- `tmux.Session.New`: an inner-command carrier whose program demand is declared. +- `browser.Page.Evaluate` / `browser.Element.EvaluateOn`: a structurally non-network expression vocabulary. +- `git.Inspect` grep operations: `-e {pattern}` plus `--` before the revision, or a refined GitRef, would remove the `-O` route. +- git object reads: add `git --no-lazy-fetch` (git 2.44+) to the read operations, then move them to `requires none`. +- `extdeps.browser`: bring the runner's CLI into the repository (or cite its option surface) and terminate options before positionals; the selector operations then fall to the live-page Network rule. +- `http.Client.PostStdinWithinUnixSocket`: put `--` before `{url}` and type the url to the socket's authority. diff --git a/src/v2/workflow/floor_unimported_bare_provider_debt_roster.dag b/src/v2/workflow/floor_unimported_bare_provider_debt_roster.dag index b47a5b15ec9..f2e18bcc0dd 100644 --- a/src/v2/workflow/floor_unimported_bare_provider_debt_roster.dag +++ b/src/v2/workflow/floor_unimported_bare_provider_debt_roster.dag @@ -331,12 +331,12 @@ data unimported_bare_provider_dispositions: List