Expose guarded Datalog relation queries#317
Merged
Merged
Conversation
Expose a bounded relation-atom query path so stored facts can be read through the same guarded daemon, client, and CLI boundary that ingests them. Constraint: Public surfaces must not expose storage paths, internal relation names, arbitrary programs, or tracker metadata. Rejected: General Datalog program upload | unsafe without evaluator budgets and reviewable rule packaging. Rejected: Direct fact-store reads in wyctl | bypasses daemon authorization and audit boundaries. Confidence: medium Scope-risk: moderate Directive: Keep query input as a parsed allowlisted atom until cancellation and recursion budgets exist. Tested: full fact-enabled test suite; full default test suite Not-tested: Audit-enabled fact query build; current local fact build has audit disabled. Co-authored-by: OmX <omx@oh-my-codex.dev>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Validation