1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
//! Project-root detection and the lazy-write safety guard.
//!
//! Why: project-root detection is asked by five crates, so the walk itself
//! moved to `trusty_common::palace_resolve` (#5811) and this module keeps only
//! trusty-memory's own concerns — the `personal` sentinel and the guard that
//! decides where a pin file may be created.
//! What: re-exports `find_project_root`, `PROJECT_MARKERS` and
//! `TRUSTY_TOOLS_DIR` from the shared resolver; defines `PERSONAL_PALACE` and
//! `is_unsafe_pin_location`.
//! Test: `project_slug_finds_git_root`, `project_slug_returns_none_without_markers`,
//! `project_slug_uses_first_ancestor_marker`, `trusty_tools_dir_is_project_marker`.
use Path;
// #5811: the walk and the marker list are shared — trusty-mpm, trusty-code,
// trusty-agents and trusty-common's catch-up all need the same answer for
// "where does this project begin?", so a second copy here would be a second
// answer.
pub use ;
/// Sentinel palace name that is always valid regardless of project context.
///
/// Why: users operating outside any project root (global notes, exploratory
/// sessions, personal task lists) need a stable palace that can receive
/// memories without failing the project-enforcement gate. The name `personal`
/// is the single reserved identifier for this purpose.
/// What: a `&str` constant that the enforcement logic tests against before
/// applying project-slug validation.
/// Test: `validate_palace_name_accepts_personal`.
pub const PERSONAL_PALACE: &str = "personal";
/// Return `true` when `root` is an unsafe location for a lazily-written pin.
///
/// Why (product guard): when the walk finds no real project marker it can fall
/// through to the system temp dir, the user's home directory, or the filesystem
/// root. Writing a pin file there silently poisons every future invocation from
/// any subdirectory of that path — including every `tempfile::tempdir()` in the
/// test suite. The guard intercepts this before the write so only genuine
/// project roots ever receive a pin file.
/// What: canonicalises `root` and compares it against `std::env::temp_dir()`,
/// `dirs::home_dir()`, and `/`. A path that cannot be canonicalised is treated
/// as unsafe.
/// Test: `lazy_write_skipped_for_temp_dir_root`.
pub