pub enum EnvPolicy {
InheritExcept {
deny: Vec<String>,
},
ClearExcept {
allow: Vec<String>,
},
}Expand description
How the child’s environment is derived from ours.
Variants§
InheritExcept
Inherit the parent environment, minus deny.
The default for the pre-existing seams. A blanket env_clear would be
stricter but would break every deployed --llm-cmd or --embed-cmd
that legitimately reads an API key out of the environment — so the
non-breaking fix is to remove the variables Areev knows hold secrets.
It knows them by name because the operator names them: --passphrase-env VAR and --token-env VAR pass the variable name, not the value.
ClearExcept
Clear the environment, passing through only allow (plus the per-call
extras, which are always set).
Strictly better, and the default for surfaces introduced in 1.3, which carry no backward-compatibility burden.
Implementations§
Source§impl EnvPolicy
impl EnvPolicy
Sourcepub fn minimal_allow() -> Vec<String>
pub fn minimal_allow() -> Vec<String>
Variables worth keeping under EnvPolicy::ClearExcept for a command
to be able to run at all. PATH is load-bearing — without it a bare
command name resolves to nothing.