1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
//! `dabin` (binary `da`) — classify a bash command as approve/defer/deny
//! under an explicitly-named set of policies.
//!
//! The library is the engine; the binary is a thin CLI wrapper. Embedders
//! who want to compose their own classification pipeline depend on this
//! crate directly and use [`classify`] with whichever [`Policy`] values
//! they like (built-ins from [`policies`] or their own).
pub use classify;
pub use ;
use Path;
/// What a single [`Policy`] says about a single segment.
/// The engine's final answer for a whole command.
/// A single policy. Atomic: each value covers exactly one capability.
/// Adding a new capability is one new value with its own [`verify`] fn —
/// no central registry to update.
///
/// [`verify`]: Policy::verify