Add capability-scoped module API (Workstream D)
ModuleManifest gains a structured [[permissions]] field (bread-shared's
new ModulePermission/PermissionKind, shared between bread-cli and breadd
so the two never drift on what a permission "type" string means).
breadd now gives every third-party module's Lua chunk a scoped _ENV
instead of the shared global table: load_scoped_lua_file builds a fresh
`bread` table containing only baseline bindings (event subscription,
timers, json, module/store, logging, and the pure-Lua sugar built on top
of those) plus whatever the manifest's permissions grant, with a
metatable __index falling back to the real globals for everything else
(stdlib, require/package - so require("bread.devices") keeps working,
since builtins load unscoped and their closures capture that environment
lexically regardless of the caller's). _G is explicitly rebound to the
scoped table itself to close the obvious escape hatch. A module with no
manifest, or a manifest with no permissions key, keeps full ambient
access unchanged (today's behavior) but is now tracked as `ungated` in
module status and surfaced by `bread doctor`. An explicit `permissions =
[]` is scoped for real but not flagged, since that's a deliberate
declaration.
Adds `bread modules audit <name>`: a best-effort text scan of a module's
.lua files suggesting a [[permissions]] block to paste into its manifest.
Converts examples/modules/cpu-temp-widget.lua into a directory module
with a worked bread.module.toml (fs.read + widget) as the reference
example. Documentation.md gets a new "Capability-scoped modules" section
covering the taxonomy, the require()/closure mechanism, and an explicit
note that path/bin scoping is recorded but not yet enforced per-call -
that's the out-of-process module sandboxing workstream this manifest
schema is laid down for. API_VERSION bumped 1.4.0 -> 1.5.0.
This commit is contained in:
parent
96639516b1
commit
6841163620
13 changed files with 1329 additions and 14 deletions
21
examples/modules/cpu-temp-widget/bread.module.toml
Normal file
21
examples/modules/cpu-temp-widget/bread.module.toml
Normal file
|
|
@ -0,0 +1,21 @@
|
|||
name = "cpu-temp-widget"
|
||||
version = "1.0.0"
|
||||
description = "Live CPU package temperature widget, read from hwmon sysfs"
|
||||
author = "bread"
|
||||
source = "local"
|
||||
installed_at = ""
|
||||
|
||||
# This module only ever calls bread.fs.read (never .write) and
|
||||
# bread.widget.register/update — declaring exactly that is what makes
|
||||
# bread.exec, bread.bluetooth, bread.hyprland, bread.machine, bread.notify,
|
||||
# and bread.state all genuinely absent (nil) from its `bread` table at
|
||||
# runtime, rather than merely unused. `source`/`installed_at` above get
|
||||
# overwritten by `bread modules install`; they're placeholders for the
|
||||
# drop-in/copy-paste path.
|
||||
|
||||
[[permissions]]
|
||||
type = "fs.read"
|
||||
path = "/sys/class/hwmon"
|
||||
|
||||
[[permissions]]
|
||||
type = "widget"
|
||||
Loading…
Add table
Add a link
Reference in a new issue