docs(comments): rewrite comments across all crates to the guidelines
Sweep every first-party crate source (1956 .rs files) to the project comment guidelines: delete redundant restatements, decorative banners, change narration, and end-of-line comments; keep and tighten the crucial ones (invariants, bug rationale, SAFETY blocks, ported-source attribution). No functional code changed. Every edit is proven comment-only against the prior tree by a comment-stripping lexer (string/char/raw-string aware) plus a separate doctest-fence check. Where removing a comment made rustfmt or clippy want to re-lay-out adjacent code, the minimal triggering comment is restored so code tokens stay byte-identical. Gates green: cargo fmt --all --check (0 diffs), cargo check and cargo clippy --workspace --all-targets (0 warnings). Adds scripts/check_codegen_comment_guidelines.py — the enforcement gate for these guidelines (flags banners, end-of-line comments, change narration, and commented-out code).
This commit is contained in:
@@ -8,14 +8,14 @@
|
||||
use std::path::Path;
|
||||
use std::path::PathBuf;
|
||||
|
||||
// ── Kigi state directory ────────────────────────────────────────────────────
|
||||
// Kigi state directory
|
||||
|
||||
/// Kigi state directory — always writable (`$KIGI_SHARE_DIR` or `~/.kigi`).
|
||||
pub(crate) fn kigi_home() -> PathBuf {
|
||||
kigi_config::kigi_home()
|
||||
}
|
||||
|
||||
// ── Device files & directories ──────────────────────────────────────────────
|
||||
// Device files & directories
|
||||
|
||||
/// Device files that need write access for normal tool operation.
|
||||
///
|
||||
@@ -27,22 +27,30 @@ pub(crate) fn kigi_home() -> PathBuf {
|
||||
/// `/dev/pts` is a directory (PTY slaves on Linux) so it uses `allow_path`.
|
||||
#[cfg(all(feature = "enforce", unix))]
|
||||
pub(crate) const DEVICE_FILES: &[&str] = &[
|
||||
"/dev/null", // output sink — used by virtually every CLI tool
|
||||
"/dev/zero", // zero source — used by memory allocators
|
||||
"/dev/random", // entropy — used by crypto/TLS
|
||||
"/dev/urandom", // entropy — used by crypto/TLS
|
||||
"/dev/tty", // controlling terminal — used by git, ssh, gpg
|
||||
"/dev/ptmx", // PTY allocation — used by terminal spawning
|
||||
"/dev/fd", // file descriptor access (symlink to /proc/self/fd on Linux)
|
||||
// output sink — used by virtually every CLI tool
|
||||
"/dev/null",
|
||||
// zero source — used by memory allocators
|
||||
"/dev/zero",
|
||||
// entropy — used by crypto/TLS
|
||||
"/dev/random",
|
||||
// entropy — used by crypto/TLS
|
||||
"/dev/urandom",
|
||||
// controlling terminal — used by git, ssh, gpg
|
||||
"/dev/tty",
|
||||
// PTY allocation — used by terminal spawning
|
||||
"/dev/ptmx",
|
||||
// file descriptor access (symlink to /proc/self/fd on Linux)
|
||||
"/dev/fd",
|
||||
];
|
||||
|
||||
/// Device directories that need write access.
|
||||
#[cfg(all(feature = "enforce", unix))]
|
||||
pub(crate) const DEVICE_DIRS: &[&str] = &[
|
||||
"/dev/pts", // PTY slaves (Linux)
|
||||
// PTY slaves (Linux)
|
||||
"/dev/pts",
|
||||
];
|
||||
|
||||
// ── Temporary directories ───────────────────────────────────────────────────
|
||||
// Temporary directories
|
||||
|
||||
/// Temporary directories that need write access.
|
||||
///
|
||||
@@ -77,7 +85,7 @@ pub(crate) fn temp_writable_paths() -> Vec<PathBuf> {
|
||||
paths
|
||||
}
|
||||
|
||||
// ── Essential writable paths ────────────────────────────────────────────────
|
||||
// Essential writable paths
|
||||
|
||||
/// Writable directory paths for profiles that allow workspace writes (workspace, devbox, strict).
|
||||
/// Device files are handled separately via `allow_file` in `to_capability_set_with_config`.
|
||||
|
||||
Reference in New Issue
Block a user