ecluse
Safe HaskellNone
LanguageGHC2021

Ecluse.Composition.Vet

Description

The boot validation pass: one role-parameterised applicative that accumulates every refusal and every advisory a configuration earns.

A rule whose severity varies by RegistryRole reaches its outcome only through rule, so it cannot be fatal on one boot path and absent from another: a role that tolerates a finding says so in the rule. An outcome settled outside the pass, such as a refusal keyed on the mirror-pipeline half a process runs, joins it through decided. Advisories ride the success path, so a check that passes can still advise.

Synopsis

The accumulating pass

data Vet a Source #

A boot check awaiting its role: the advisories it logs, beside either every refusal it earned or the value it vetted.

Instances

Instances details
Applicative Vet Source # 
Instance details

Defined in Ecluse.Composition.Vet

Methods

pure :: a -> Vet a #

(<*>) :: Vet (a -> b) -> Vet a -> Vet b #

liftA2 :: (a -> b -> c) -> Vet a -> Vet b -> Vet c #

(*>) :: Vet a -> Vet b -> Vet b #

(<*) :: Vet a -> Vet b -> Vet a #

Functor Vet Source # 
Instance details

Defined in Ecluse.Composition.Vet

Methods

fmap :: (a -> b) -> Vet a -> Vet b #

(<$) :: a -> Vet b -> Vet a #

runVet :: RegistryRole -> Vet a -> ([Advisory], Either [BootError] a) Source #

Run a pass for one role: every advisory it logs, and either every refusal or the vetted value.

withRole :: (RegistryRole -> Vet a) -> Vet a Source #

Continue a pass with the role it runs for, which is how a witness one role alone may hold is built. The role is no finding, so selecting a check by it hides none.

decided :: Either [BootError] a -> Vet a Source #

Carry an outcome a producer decided for itself into the pass, so its refusals join the rest. rule cannot express one already settled, or one whose severity turns on more than RegistryRole.

Rules and their severity

data Severity finding Source #

What one role does about a finding a rule detected.

Constructors

Refuse (finding -> BootError)

Refuse to boot, reporting this refusal.

Advise (finding -> Advisory)

Boot, and log this advisory.

Ignore

Boot, and log nothing: only another role acts on the finding, and ecluse check-config names that role for it.

rule :: (RegistryRole -> Severity finding) -> (input -> Maybe finding) -> input -> Vet () Source #

One rule: its severity per role, the condition it detects in an input, and that input. One detection feeds both the refusal and the advisory, so the two cannot describe different rules.

byStoreRole :: Severity finding -> Severity finding -> RegistryRole -> Severity finding Source #

The severity split the store roles share, so the preview arm cannot be spelled apart from the deleting one and drift: the store-role severity first, then the writing role's.