A11 (C++ runtime)
Native C++ implementation of the A11 streaming action runtime
Loading...
Searching...
No Matches
main.cc File Reference

a11-flow-run – runs a .flow file as a program. More...

#include <cstdio>
#include <cstdlib>
#include <iostream>
#include <memory>
#include <optional>
#include <string>
#include <string_view>
#include <vector>
#include <absl/status/status.h>
#include <absl/status/status_macros.h>
#include <absl/status/statusor.h>
#include <absl/strings/match.h>
#include <absl/strings/numbers.h>
#include <absl/strings/str_cat.h>
#include <absl/strings/str_join.h>
#include <absl/time/time.h>
#include "a11/flow/diagnostic.h"
#include "a11/flow/interpreter/interpreter.h"
#include "sdk/flow/actions/flow_actions.h"
#include "sdk/flow/actions/options.h"
#include "sdk/flow/actions/policy.h"

Namespaces

namespace  a11
 
namespace  a11::flow
 
namespace  a11::flow::interpreter
 

Functions

int main (int argc, char **argv)
 

Detailed Description

a11-flow-run – runs a .flow file as a program.

Flow was a way to describe how deployed actions connect. With the standard library beside it – files, a clock, processes, this process's own standard streams – a file can also just be a program, and this is what runs one:

a11-flow-run wc.flow < some-file
a11-flow-run greet.flow -- Helena

The file says which of it is the program by declaring a flow with no name:

flow {
describe "What this program does."
...
}

and everything else in the file – named flows, structs – is what that one uses. argc and argv arrive as ports nobody declared, argv[0] being the program's own name as in C.

What a program may expect to be bound

Everything in a11::sdk::flow, plus the standard streams. That is the contract this interpreter offers and the reason a file can be written against it: a program that reads read_stdin and writes write_stdout will find them, and one that reads a file will find read_file – inside whatever roots this run allows, which is the working directory unless told otherwise.

Policy limits

There is no way to widen the policy from inside the file. --allow-write, --root, --allow-run and --allow-net are arguments to this program, because a capability a script could grant itself is not a capability anybody granted. A file handed to this interpreter can therefore be read for what it will do, and the command line is where what it may do is written.

The exit code

Zero when the entry flow finished, and non-zero when it failed – with the failure on standard error as a diagnostic, positioned in the source where the language could say where. A flow that wants to choose its own exit code puts one on an out exit_code: integer port.

Function Documentation

◆ main()

int main ( int  argc,
char **  argv 
)

Variable Documentation

◆ arguments

std::vector<std::string> arguments

argv for the program, [0] = path.

◆ check_only

bool check_only = false

◆ environment

std::vector<std::string> environment

◆ may_reach_local_network

bool may_reach_local_network = false

◆ may_reach_network

bool may_reach_network = false

◆ may_run

bool may_run = false

◆ path

std::string path

◆ print_plan

bool print_plan = false

◆ roots

std::vector<std::string> roots

◆ timeout

std::optional<absl::Duration> timeout

◆ unrestricted

bool unrestricted = false

◆ writable

bool writable = false