From 6b21ac8977982e837634669ccab217b80e68612f Mon Sep 17 00:00:00 2001 From: "google-labs-jules[bot]" <161369871+google-labs-jules[bot]@users.noreply.github.com> Date: Wed, 7 Oct 2026 13:18:18 +0000 Subject: [PATCH 1/2] Refactor std.compress to extract filesystem capability checks Extracts the inline closure logic for each compression utility (zip, unzip, tar, untar, gzip, gunzip) into discrete, named functions (`sys_zip`, `sys_unzip`, etc.) and extracts the duplicated filesystem capability check into a reusable `check_fs_capability` function. This declutters the registration flow and improves the maintainability and readability of `stdlib/src/compress.rs`. Co-authored-by: Tcode-Motion <188012755+Tcode-Motion@users.noreply.github.com> --- stdlib/src/compress.rs | 255 ++++++++++++++++++++--------------------- 1 file changed, 122 insertions(+), 133 deletions(-) diff --git a/stdlib/src/compress.rs b/stdlib/src/compress.rs index d1daf83b..fa2875dd 100644 --- a/stdlib/src/compress.rs +++ b/stdlib/src/compress.rs @@ -5,191 +5,180 @@ use std::io::{Read, Write}; use std::path::Path; use std::rc::Rc; use techscript_runtime::{ - context::Capability, error::RuntimeError, error::RuntimeErrorKind, value::RuntimeValue, + context::{Capability, RuntimeContext}, error::RuntimeError, error::RuntimeErrorKind, value::RuntimeValue, }; +fn check_fs_capability(ctx: &RuntimeContext) -> Result<(), RuntimeError> { + if !ctx.config.capabilities.contains(&Capability::FileSystem) { + return Err(RuntimeError::new( + RuntimeErrorKind::InvalidOperation( + "Security policy violation: FileSystem capability is denied".to_string(), + ), + None, + None, + )); + } + Ok(()) +} + impl StdlibRegistry { pub fn register_compress(&mut self) { let mut exports: HashMap> = HashMap::new(); + fn sys_zip( + ctx: &mut RuntimeContext, + args: Vec, + ) -> Result { + check_fs_capability(ctx)?; + let src_dir = args[0].try_into_string()?; + let archive_path = args[1].try_into_string()?; + zip_dir(&src_dir, &archive_path).map_err(|e| { + RuntimeError::new( + RuntimeErrorKind::InvalidOperation(format!("ZIP error: {}", e)), + None, + None, + ) + })?; + Ok(RuntimeValue::Null) + } + exports.insert( "zip".to_string(), Rc::new(StdFunction { name: "zip".to_string(), arity: 2, - callback: |ctx, args| { - if !ctx.config.capabilities.contains(&Capability::FileSystem) { - return Err(RuntimeError::new( - RuntimeErrorKind::InvalidOperation( - "Security policy violation: FileSystem capability is denied" - .to_string(), - ), - None, - None, - )); - } - let src_dir = args[0].try_into_string()?; - let archive_path = args[1].try_into_string()?; - zip_dir(&src_dir, &archive_path).map_err(|e| { - RuntimeError::new( - RuntimeErrorKind::InvalidOperation(format!("ZIP error: {}", e)), - None, - None, - ) - })?; - Ok(RuntimeValue::Null) - }, + callback: sys_zip, }), ); + fn sys_unzip( + ctx: &mut RuntimeContext, + args: Vec, + ) -> Result { + check_fs_capability(ctx)?; + let archive_path = args[0].try_into_string()?; + let dest_dir = args[1].try_into_string()?; + unzip_archive(&archive_path, &dest_dir).map_err(|e| { + RuntimeError::new( + RuntimeErrorKind::InvalidOperation(format!("UNZIP error: {}", e)), + None, + None, + ) + })?; + Ok(RuntimeValue::Null) + } + exports.insert( "unzip".to_string(), Rc::new(StdFunction { name: "unzip".to_string(), arity: 2, - callback: |ctx, args| { - if !ctx.config.capabilities.contains(&Capability::FileSystem) { - return Err(RuntimeError::new( - RuntimeErrorKind::InvalidOperation( - "Security policy violation: FileSystem capability is denied" - .to_string(), - ), - None, - None, - )); - } - let archive_path = args[0].try_into_string()?; - let dest_dir = args[1].try_into_string()?; - unzip_archive(&archive_path, &dest_dir).map_err(|e| { - RuntimeError::new( - RuntimeErrorKind::InvalidOperation(format!("UNZIP error: {}", e)), - None, - None, - ) - })?; - Ok(RuntimeValue::Null) - }, + callback: sys_unzip, }), ); + fn sys_tar( + ctx: &mut RuntimeContext, + args: Vec, + ) -> Result { + check_fs_capability(ctx)?; + let src_dir = args[0].try_into_string()?; + let archive_path = args[1].try_into_string()?; + tar_dir(&src_dir, &archive_path).map_err(|e| { + RuntimeError::new( + RuntimeErrorKind::InvalidOperation(format!("TAR error: {}", e)), + None, + None, + ) + })?; + Ok(RuntimeValue::Null) + } + exports.insert( "tar".to_string(), Rc::new(StdFunction { name: "tar".to_string(), arity: 2, - callback: |ctx, args| { - if !ctx.config.capabilities.contains(&Capability::FileSystem) { - return Err(RuntimeError::new( - RuntimeErrorKind::InvalidOperation( - "Security policy violation: FileSystem capability is denied" - .to_string(), - ), - None, - None, - )); - } - let src_dir = args[0].try_into_string()?; - let archive_path = args[1].try_into_string()?; - tar_dir(&src_dir, &archive_path).map_err(|e| { - RuntimeError::new( - RuntimeErrorKind::InvalidOperation(format!("TAR error: {}", e)), - None, - None, - ) - })?; - Ok(RuntimeValue::Null) - }, + callback: sys_tar, }), ); + fn sys_untar( + ctx: &mut RuntimeContext, + args: Vec, + ) -> Result { + check_fs_capability(ctx)?; + let archive_path = args[0].try_into_string()?; + let dest_dir = args[1].try_into_string()?; + untar_archive(&archive_path, &dest_dir).map_err(|e| { + RuntimeError::new( + RuntimeErrorKind::InvalidOperation(format!("UNTAR error: {}", e)), + None, + None, + ) + })?; + Ok(RuntimeValue::Null) + } + exports.insert( "untar".to_string(), Rc::new(StdFunction { name: "untar".to_string(), arity: 2, - callback: |ctx, args| { - if !ctx.config.capabilities.contains(&Capability::FileSystem) { - return Err(RuntimeError::new( - RuntimeErrorKind::InvalidOperation( - "Security policy violation: FileSystem capability is denied" - .to_string(), - ), - None, - None, - )); - } - let archive_path = args[0].try_into_string()?; - let dest_dir = args[1].try_into_string()?; - untar_archive(&archive_path, &dest_dir).map_err(|e| { - RuntimeError::new( - RuntimeErrorKind::InvalidOperation(format!("UNTAR error: {}", e)), - None, - None, - ) - })?; - Ok(RuntimeValue::Null) - }, + callback: sys_untar, }), ); + fn sys_gzip( + ctx: &mut RuntimeContext, + args: Vec, + ) -> Result { + check_fs_capability(ctx)?; + let src_file = args[0].try_into_string()?; + let archive_path = args[1].try_into_string()?; + gzip_file(&src_file, &archive_path).map_err(|e| { + RuntimeError::new( + RuntimeErrorKind::InvalidOperation(format!("GZIP error: {}", e)), + None, + None, + ) + })?; + Ok(RuntimeValue::Null) + } + exports.insert( "gzip".to_string(), Rc::new(StdFunction { name: "gzip".to_string(), arity: 2, - callback: |ctx, args| { - if !ctx.config.capabilities.contains(&Capability::FileSystem) { - return Err(RuntimeError::new( - RuntimeErrorKind::InvalidOperation( - "Security policy violation: FileSystem capability is denied" - .to_string(), - ), - None, - None, - )); - } - let src_file = args[0].try_into_string()?; - let archive_path = args[1].try_into_string()?; - gzip_file(&src_file, &archive_path).map_err(|e| { - RuntimeError::new( - RuntimeErrorKind::InvalidOperation(format!("GZIP error: {}", e)), - None, - None, - ) - })?; - Ok(RuntimeValue::Null) - }, + callback: sys_gzip, }), ); + fn sys_gunzip( + ctx: &mut RuntimeContext, + args: Vec, + ) -> Result { + check_fs_capability(ctx)?; + let archive_path = args[0].try_into_string()?; + let dest_file = args[1].try_into_string()?; + gunzip_archive(&archive_path, &dest_file).map_err(|e| { + RuntimeError::new( + RuntimeErrorKind::InvalidOperation(format!("GUNZIP error: {}", e)), + None, + None, + ) + })?; + Ok(RuntimeValue::Null) + } + exports.insert( "gunzip".to_string(), Rc::new(StdFunction { name: "gunzip".to_string(), arity: 2, - callback: |ctx, args| { - if !ctx.config.capabilities.contains(&Capability::FileSystem) { - return Err(RuntimeError::new( - RuntimeErrorKind::InvalidOperation( - "Security policy violation: FileSystem capability is denied" - .to_string(), - ), - None, - None, - )); - } - let archive_path = args[0].try_into_string()?; - let dest_file = args[1].try_into_string()?; - gunzip_archive(&archive_path, &dest_file).map_err(|e| { - RuntimeError::new( - RuntimeErrorKind::InvalidOperation(format!("GUNZIP error: {}", e)), - None, - None, - ) - })?; - Ok(RuntimeValue::Null) - }, + callback: sys_gunzip, }), ); From 514b43cd7de9482f49bc245b92c76a681ca31d5d Mon Sep 17 00:00:00 2001 From: "google-labs-jules[bot]" <161369871+google-labs-jules[bot]@users.noreply.github.com> Date: Wed, 7 Oct 2026 13:38:03 +0000 Subject: [PATCH 2/2] Refactor std.compress to extract filesystem capability checks Extracts the inline closure logic for each compression utility (zip, unzip, tar, untar, gzip, gunzip) into discrete, named functions (`sys_zip`, `sys_unzip`, etc.) and extracts the duplicated filesystem capability check into a reusable `check_fs_capability` function. This declutters the registration flow and improves the maintainability and readability of `stdlib/src/compress.rs`. Co-authored-by: Tcode-Motion <188012755+Tcode-Motion@users.noreply.github.com> --- stdlib/src/compress.rs | 209 ++++++++++++++++++----------------- stdlib/tests/stdlib_tests.rs | 8 +- 2 files changed, 112 insertions(+), 105 deletions(-) diff --git a/stdlib/src/compress.rs b/stdlib/src/compress.rs index fa2875dd..455bda97 100644 --- a/stdlib/src/compress.rs +++ b/stdlib/src/compress.rs @@ -5,7 +5,10 @@ use std::io::{Read, Write}; use std::path::Path; use std::rc::Rc; use techscript_runtime::{ - context::{Capability, RuntimeContext}, error::RuntimeError, error::RuntimeErrorKind, value::RuntimeValue, + context::{Capability, RuntimeContext}, + error::RuntimeError, + error::RuntimeErrorKind, + value::RuntimeValue, }; fn check_fs_capability(ctx: &RuntimeContext) -> Result<(), RuntimeError> { @@ -21,28 +24,113 @@ fn check_fs_capability(ctx: &RuntimeContext) -> Result<(), RuntimeError> { Ok(()) } +fn sys_zip( + ctx: &mut RuntimeContext, + args: Vec, +) -> Result { + check_fs_capability(ctx)?; + let src_dir = args[0].try_into_string()?; + let archive_path = args[1].try_into_string()?; + zip_dir(&src_dir, &archive_path).map_err(|e| { + RuntimeError::new( + RuntimeErrorKind::InvalidOperation(format!("ZIP error: {}", e)), + None, + None, + ) + })?; + Ok(RuntimeValue::Null) +} + +fn sys_unzip( + ctx: &mut RuntimeContext, + args: Vec, +) -> Result { + check_fs_capability(ctx)?; + let archive_path = args[0].try_into_string()?; + let dest_dir = args[1].try_into_string()?; + unzip_archive(&archive_path, &dest_dir).map_err(|e| { + RuntimeError::new( + RuntimeErrorKind::InvalidOperation(format!("UNZIP error: {}", e)), + None, + None, + ) + })?; + Ok(RuntimeValue::Null) +} + +fn sys_tar( + ctx: &mut RuntimeContext, + args: Vec, +) -> Result { + check_fs_capability(ctx)?; + let src_dir = args[0].try_into_string()?; + let archive_path = args[1].try_into_string()?; + tar_dir(&src_dir, &archive_path).map_err(|e| { + RuntimeError::new( + RuntimeErrorKind::InvalidOperation(format!("TAR error: {}", e)), + None, + None, + ) + })?; + Ok(RuntimeValue::Null) +} + +fn sys_untar( + ctx: &mut RuntimeContext, + args: Vec, +) -> Result { + check_fs_capability(ctx)?; + let archive_path = args[0].try_into_string()?; + let dest_dir = args[1].try_into_string()?; + untar_archive(&archive_path, &dest_dir).map_err(|e| { + RuntimeError::new( + RuntimeErrorKind::InvalidOperation(format!("UNTAR error: {}", e)), + None, + None, + ) + })?; + Ok(RuntimeValue::Null) +} + +fn sys_gzip( + ctx: &mut RuntimeContext, + args: Vec, +) -> Result { + check_fs_capability(ctx)?; + let src_file = args[0].try_into_string()?; + let archive_path = args[1].try_into_string()?; + gzip_file(&src_file, &archive_path).map_err(|e| { + RuntimeError::new( + RuntimeErrorKind::InvalidOperation(format!("GZIP error: {}", e)), + None, + None, + ) + })?; + Ok(RuntimeValue::Null) +} + +fn sys_gunzip( + ctx: &mut RuntimeContext, + args: Vec, +) -> Result { + check_fs_capability(ctx)?; + let archive_path = args[0].try_into_string()?; + let dest_file = args[1].try_into_string()?; + gunzip_archive(&archive_path, &dest_file).map_err(|e| { + RuntimeError::new( + RuntimeErrorKind::InvalidOperation(format!("GUNZIP error: {}", e)), + None, + None, + ) + })?; + Ok(RuntimeValue::Null) +} + impl StdlibRegistry { pub fn register_compress(&mut self) { let mut exports: HashMap> = HashMap::new(); - fn sys_zip( - ctx: &mut RuntimeContext, - args: Vec, - ) -> Result { - check_fs_capability(ctx)?; - let src_dir = args[0].try_into_string()?; - let archive_path = args[1].try_into_string()?; - zip_dir(&src_dir, &archive_path).map_err(|e| { - RuntimeError::new( - RuntimeErrorKind::InvalidOperation(format!("ZIP error: {}", e)), - None, - None, - ) - })?; - Ok(RuntimeValue::Null) - } - exports.insert( "zip".to_string(), Rc::new(StdFunction { @@ -52,23 +140,6 @@ impl StdlibRegistry { }), ); - fn sys_unzip( - ctx: &mut RuntimeContext, - args: Vec, - ) -> Result { - check_fs_capability(ctx)?; - let archive_path = args[0].try_into_string()?; - let dest_dir = args[1].try_into_string()?; - unzip_archive(&archive_path, &dest_dir).map_err(|e| { - RuntimeError::new( - RuntimeErrorKind::InvalidOperation(format!("UNZIP error: {}", e)), - None, - None, - ) - })?; - Ok(RuntimeValue::Null) - } - exports.insert( "unzip".to_string(), Rc::new(StdFunction { @@ -78,23 +149,6 @@ impl StdlibRegistry { }), ); - fn sys_tar( - ctx: &mut RuntimeContext, - args: Vec, - ) -> Result { - check_fs_capability(ctx)?; - let src_dir = args[0].try_into_string()?; - let archive_path = args[1].try_into_string()?; - tar_dir(&src_dir, &archive_path).map_err(|e| { - RuntimeError::new( - RuntimeErrorKind::InvalidOperation(format!("TAR error: {}", e)), - None, - None, - ) - })?; - Ok(RuntimeValue::Null) - } - exports.insert( "tar".to_string(), Rc::new(StdFunction { @@ -104,23 +158,6 @@ impl StdlibRegistry { }), ); - fn sys_untar( - ctx: &mut RuntimeContext, - args: Vec, - ) -> Result { - check_fs_capability(ctx)?; - let archive_path = args[0].try_into_string()?; - let dest_dir = args[1].try_into_string()?; - untar_archive(&archive_path, &dest_dir).map_err(|e| { - RuntimeError::new( - RuntimeErrorKind::InvalidOperation(format!("UNTAR error: {}", e)), - None, - None, - ) - })?; - Ok(RuntimeValue::Null) - } - exports.insert( "untar".to_string(), Rc::new(StdFunction { @@ -130,23 +167,6 @@ impl StdlibRegistry { }), ); - fn sys_gzip( - ctx: &mut RuntimeContext, - args: Vec, - ) -> Result { - check_fs_capability(ctx)?; - let src_file = args[0].try_into_string()?; - let archive_path = args[1].try_into_string()?; - gzip_file(&src_file, &archive_path).map_err(|e| { - RuntimeError::new( - RuntimeErrorKind::InvalidOperation(format!("GZIP error: {}", e)), - None, - None, - ) - })?; - Ok(RuntimeValue::Null) - } - exports.insert( "gzip".to_string(), Rc::new(StdFunction { @@ -156,23 +176,6 @@ impl StdlibRegistry { }), ); - fn sys_gunzip( - ctx: &mut RuntimeContext, - args: Vec, - ) -> Result { - check_fs_capability(ctx)?; - let archive_path = args[0].try_into_string()?; - let dest_file = args[1].try_into_string()?; - gunzip_archive(&archive_path, &dest_file).map_err(|e| { - RuntimeError::new( - RuntimeErrorKind::InvalidOperation(format!("GUNZIP error: {}", e)), - None, - None, - ) - })?; - Ok(RuntimeValue::Null) - } - exports.insert( "gunzip".to_string(), Rc::new(StdFunction { diff --git a/stdlib/tests/stdlib_tests.rs b/stdlib/tests/stdlib_tests.rs index ce296064..50a54c49 100644 --- a/stdlib/tests/stdlib_tests.rs +++ b/stdlib/tests/stdlib_tests.rs @@ -540,7 +540,9 @@ fn test_http_module() { &mut ctx_unprivileged, vec![RuntimeValue::Str(format!("http://127.0.0.1:{}", port))], ); - assert!(matches!(res_get, Err(techscript_runtime::RuntimeError { kind: techscript_runtime::RuntimeErrorKind::InvalidOperation(msg), .. }) if msg.contains("Security policy violation"))); + assert!( + matches!(res_get, Err(techscript_runtime::RuntimeError { kind: techscript_runtime::RuntimeErrorKind::InvalidOperation(msg), .. }) if msg.contains("Security policy violation")) + ); let post = http.exports.get("post").unwrap(); let res_post = post.call( @@ -550,7 +552,9 @@ fn test_http_module() { RuntimeValue::Str("body".to_string()), ], ); - assert!(matches!(res_post, Err(techscript_runtime::RuntimeError { kind: techscript_runtime::RuntimeErrorKind::InvalidOperation(msg), .. }) if msg.contains("Security policy violation"))); + assert!( + matches!(res_post, Err(techscript_runtime::RuntimeError { kind: techscript_runtime::RuntimeErrorKind::InvalidOperation(msg), .. }) if msg.contains("Security policy violation")) + ); // Test with Network capability let mut caps = HashSet::new();