Documentation
¶
Index ¶
- Constants
- func CleanAbsPath(path string) string
- func CompletionDetail(item CompletionItem) string
- func DefaultStdinPath() string
- func DiagnosticsJSON(diags []Diagnostic) ([]byte, error)
- func DocsMarkdown(path, src string) string
- func HoverMarkdown(idx *WorkspaceIndex, path, src string, line, col int) string
- func KeywordMarkdown(name string) string
- func ModuleDirForPath(path string) string
- func PathToURI(path string) string
- func PrefixAt(src string, line, col int) string
- func RuneColumn(s string, byteOffset int) int
- func RuntimeDocMarkdown(name string) string
- func StdModuleMarkdown(name string) string
- func SymbolSummary(sym Symbol) string
- func URIToPath(uri string) string
- func WordAt(src string, line, col int) string
- type CompletionItem
- type Diagnostic
- type DiagnosticSeverity
- type EffectFinding
- type EffectUsage
- type EffectsReport
- type EvaluationOptions
- type EvaluationResult
- type ExecuteSPLFunc
- type HoverInfo
- type IndexedDocument
- type KeywordDoc
- type Location
- type PartialParseResult
- type ProjectConfig
- type Reference
- type Report
- type RuntimeDoc
- type StdModuleDoc
- type Symbol
- type WorkspaceIndex
- func (idx *WorkspaceIndex) AllSymbols() []Symbol
- func (idx *WorkspaceIndex) Definition(path, src string, line, col int) (Location, bool)
- func (idx *WorkspaceIndex) References(path, src string, line, col int) []Reference
- func (idx *WorkspaceIndex) Refresh()
- func (idx *WorkspaceIndex) Remove(path string)
- func (idx *WorkspaceIndex) Update(path, src string)
Constants ¶
const DynamicImportCapability = "dynamic-import"
DynamicImportCapability is the synthetic category used to report an import statement whose path is not a string literal (see security.SecurityPolicy.DenyDynamicImports / pkg/eval/eval.go's evalImportStatement for the runtime-enforced equivalent of this check).
Variables ¶
This section is empty.
Functions ¶
func CleanAbsPath ¶
func CompletionDetail ¶
func CompletionDetail(item CompletionItem) string
func DefaultStdinPath ¶
func DefaultStdinPath() string
func DiagnosticsJSON ¶
func DiagnosticsJSON(diags []Diagnostic) ([]byte, error)
func DocsMarkdown ¶
func HoverMarkdown ¶
func HoverMarkdown(idx *WorkspaceIndex, path, src string, line, col int) string
func KeywordMarkdown ¶
func ModuleDirForPath ¶
func RuneColumn ¶
func RuntimeDocMarkdown ¶
func StdModuleMarkdown ¶
func SymbolSummary ¶
Types ¶
type CompletionItem ¶
type CompletionItem struct {
Label string `json:"label"`
Kind string `json:"kind,omitempty"`
Detail string `json:"detail,omitempty"`
}
func CompletionItems ¶
func CompletionItems(path, src, prefix string) []CompletionItem
func WorkspaceCompletionItems ¶
func WorkspaceCompletionItems(idx *WorkspaceIndex, path, src, prefix string) []CompletionItem
type Diagnostic ¶
type Diagnostic struct {
Severity DiagnosticSeverity `json:"severity"`
Path string `json:"path,omitempty"`
Line int `json:"line,omitempty"`
Column int `json:"column,omitempty"`
Code string `json:"code,omitempty"`
Message string `json:"message"`
Hint string `json:"hint,omitempty"`
Snippet string `json:"snippet,omitempty"`
}
func StaticDiagnostics ¶
func StaticDiagnostics(path, src string, program *ast.Program) []Diagnostic
type DiagnosticSeverity ¶
type DiagnosticSeverity string
const ( SeverityError DiagnosticSeverity = "error" SeverityWarning DiagnosticSeverity = "warning" SeverityInfo DiagnosticSeverity = "info" )
type EffectFinding ¶
type EffectFinding struct {
Capability string `json:"capability"`
Usages []EffectUsage `json:"usages"`
}
EffectFinding groups every usage found for a single capability (or the synthetic "dynamic-import" category) in a script.
type EffectUsage ¶
type EffectUsage struct {
Builtin string `json:"builtin"`
Line int `json:"line,omitempty"`
Column int `json:"column,omitempty"`
}
EffectUsage is a single occurrence of a capability-relevant builtin call (or, for the "dynamic-import" category, a dynamic import statement) found while statically walking a script's AST.
type EffectsReport ¶
type EffectsReport struct {
Path string `json:"path,omitempty"`
OK bool `json:"ok"`
Capabilities []EffectFinding `json:"capabilities,omitempty"`
Diagnostics []Diagnostic `json:"diagnostics,omitempty"`
}
EffectsReport is the result of the static capability/effects analysis for one script: what it MIGHT do at runtime, without running it.
func AnalyzeEffects ¶
func AnalyzeEffects(path, src string) EffectsReport
AnalyzeEffects parses src and walks its AST to determine which security capabilities the script might exercise at runtime (network, filesystem read/write, exec, db, secrets, scheduler/async/server/watch/process-exit, ...), plus any dynamic (non-literal-path) imports, WITHOUT running the script. It is the data source for `spltool check --effects`.
type EvaluationOptions ¶
type EvaluationOptions struct {
Profile string `json:"profile,omitempty"`
TimeoutMS int64 `json:"timeoutMs,omitempty"`
MaxOutputBytes int64 `json:"maxOutputBytes,omitempty"`
MaxExecOutputBytes int64 `json:"maxExecOutputBytes,omitempty"`
MaxSteps int64 `json:"maxSteps,omitempty"`
MaxDepth int `json:"maxDepth,omitempty"`
AllowedCapabilities []string `json:"allowedCapabilities,omitempty"`
AllowedExecCommands []string `json:"allowedExecCommands,omitempty"`
AllowedNativeModules []string `json:"allowedNativeModules,omitempty"`
DeniedNativeModules []string `json:"deniedNativeModules,omitempty"`
AllowedFileReadPaths []string `json:"allowedFileReadPaths,omitempty"`
AllowedFileWritePaths []string `json:"allowedFileWritePaths,omitempty"`
}
type EvaluationResult ¶
type EvaluationResult struct {
OK bool `json:"ok"`
Path string `json:"path,omitempty"`
Result string `json:"result,omitempty"`
Output string `json:"output,omitempty"`
Error string `json:"error,omitempty"`
Duration int64 `json:"durationMs"`
Diagnostics []string `json:"diagnostics,omitempty"`
Metrics map[string]any `json:"metrics,omitempty"`
Artifacts []map[string]any `json:"artifacts,omitempty"`
Events []map[string]any `json:"events,omitempty"`
}
func EvaluateSPL ¶
func EvaluateSPL(path, src string, opts EvaluationOptions) EvaluationResult
type ExecuteSPLFunc ¶
type ExecuteSPLFunc func(path, src string, opts EvaluationOptions, output io.Writer) (result string, err error)
var ExecuteSPLFn ExecuteSPLFunc
type HoverInfo ¶
type IndexedDocument ¶
type KeywordDoc ¶
type PartialParseResult ¶
type PartialParseResult struct {
Path string `json:"path,omitempty"`
Complete bool `json:"complete"`
Diagnostics []Diagnostic `json:"diagnostics,omitempty"`
Program *ast.Program `json:"-"`
}
func ParsePartial ¶
func ParsePartial(path, src string) PartialParseResult
type ProjectConfig ¶
type ProjectConfig struct {
Runtime struct {
MaxDepth int `json:"max_depth,omitempty"`
MaxSteps int64 `json:"max_steps,omitempty"`
MaxHeapMB int64 `json:"max_heap_mb,omitempty"`
TimeoutMS int64 `json:"timeout_ms,omitempty"`
MaxOutputBytes int64 `json:"max_output_bytes,omitempty"`
MaxHTTPBodyBytes int64 `json:"max_http_body_bytes,omitempty"`
MaxExecOutputBytes int64 `json:"max_exec_output_bytes,omitempty"`
} `json:"runtime,omitempty"`
Security struct {
Profile string `json:"profile,omitempty"`
AllowedCapabilities []string `json:"allowed_capabilities,omitempty"`
DeniedCapabilities []string `json:"denied_capabilities,omitempty"`
AllowedExecCommands []string `json:"allowed_exec_commands,omitempty"`
AllowedNetworkHosts []string `json:"allowed_network_hosts,omitempty"`
AllowedDBDrivers []string `json:"allowed_db_drivers,omitempty"`
AllowedFileReadPaths []string `json:"allowed_file_read_paths,omitempty"`
AllowedFileWritePaths []string `json:"allowed_file_write_paths,omitempty"`
} `json:"security,omitempty"`
Tooling struct {
UndefinedVariables bool `json:"undefined_variables,omitempty"`
Shadowing bool `json:"shadowing,omitempty"`
Unreachable bool `json:"unreachable,omitempty"`
DeprecatedBuiltins []string `json:"deprecated_builtins,omitempty"`
} `json:"tooling,omitempty"`
Test struct {
Patterns []string `json:"patterns,omitempty"`
TimeoutMS int64 `json:"timeout_ms,omitempty"`
} `json:"test,omitempty"`
REPL struct {
Profile string `json:"profile,omitempty"`
} `json:"repl,omitempty"`
}
func DefaultProjectConfig ¶
func DefaultProjectConfig() ProjectConfig
func LoadProjectConfig ¶
func LoadProjectConfig(start string) (ProjectConfig, string, error)
type Report ¶
type Report struct {
Path string `json:"path,omitempty"`
OK bool `json:"ok"`
Changed bool `json:"changed,omitempty"`
Formatted string `json:"formatted,omitempty"`
Diagnostics []Diagnostic `json:"diagnostics,omitempty"`
Symbols []Symbol `json:"symbols,omitempty"`
}
func CheckSource ¶
func FormatSource ¶
type RuntimeDoc ¶
type StdModuleDoc ¶
type Symbol ¶
type Symbol struct {
Name string `json:"name"`
Kind string `json:"kind"`
Path string `json:"path,omitempty"`
Line int `json:"line,omitempty"`
Column int `json:"column,omitempty"`
Detail string `json:"detail,omitempty"`
}
func SymbolsForSource ¶
func VisibleSymbolsForSource ¶
type WorkspaceIndex ¶
type WorkspaceIndex struct {
Root string
Documents map[string]IndexedDocument
}
func NewWorkspaceIndex ¶
func NewWorkspaceIndex(root string) *WorkspaceIndex
func (*WorkspaceIndex) AllSymbols ¶
func (idx *WorkspaceIndex) AllSymbols() []Symbol
func (*WorkspaceIndex) Definition ¶
func (idx *WorkspaceIndex) Definition(path, src string, line, col int) (Location, bool)
func (*WorkspaceIndex) References ¶
func (idx *WorkspaceIndex) References(path, src string, line, col int) []Reference
func (*WorkspaceIndex) Refresh ¶
func (idx *WorkspaceIndex) Refresh()
func (*WorkspaceIndex) Remove ¶
func (idx *WorkspaceIndex) Remove(path string)
func (*WorkspaceIndex) Update ¶
func (idx *WorkspaceIndex) Update(path, src string)