Documentation
¶
Overview ¶
Package cli implements the bounded, one-shot notify command, without global initialization.
Index ¶
Constants ¶
const ( RawLimit = 64 << 10 DecodedLimit = 16 << 10 ContextLimit = 16 << 10 ExitSuccess = 0 ExitRejected = 1 ExitInvalid = 2 ExitUnknown = 3 )
Variables ¶
This section is empty.
Functions ¶
func ReadSecureContext ¶
ReadSecureContext pins every path component without following symlinks. The final regular file must be owned by the effective user, private (0400 or 0600), singly linked and bounded. Lstat/Fstat identity and post-read metadata are checked. These checks establish safe local reading, never trusted provenance.
func Run ¶
func Run(ctx context.Context, args []string, input io.ReadCloser, output, diagnostics io.Writer, o Options) (code int)
Run accepts arguments AFTER "notify". Stdin is one JSON document framed by EOF; it owns input, whose Close MUST unblock Read, and closes it exactly once. Output and diagnostics are borrowed writers that must return promptly (or be cancellation-aware); Run never closes them. Errors never include input or paths. Help does not read stdin, context, clock, or backend. No argument is content.
Types ¶
type Backend ¶
type Backend interface {
Notify(context.Context, agentnotify.Payload, origin.Context, notification.Deadline) agentnotify.Receipt
}
Backend is borrowed from composition. Notify must honor cancellation and the original boot-continuous deadline. Run calls it at most once and never closes it.
type Options ¶
type Options struct {
Backend Backend
Clock agentnotify.Clock
// ReadContext is a test/composition seam, not caller input. Nil uses the secure
// platform reader. Overrides must honor cancellation and return promptly.
ReadContext func(context.Context, string) ([]byte, error)
// CloseResources releases only resources exclusively transferred to this Run.
// It runs exactly once, after input and all adapter work have joined, even on help.
// Do not use it to close a shared backend.
CloseResources func() error
}