From 14a8e04bc4e35965e7e5195e9eb83c1e4881c1a5 Mon Sep 17 00:00:00 2001 From: "google-labs-jules[bot]" <161369871+google-labs-jules[bot]@users.noreply.github.com> Date: Tue, 6 Oct 2026 08:05:45 +0000 Subject: [PATCH 1/2] Refactor sys.rs by extracting inline closures to standalone functions Co-authored-by: Tcode-Motion <188012755+Tcode-Motion@users.noreply.github.com> --- stdlib/src/sys.rs | 161 ++++++++++++++++++++++++++-------------------- 1 file changed, 92 insertions(+), 69 deletions(-) diff --git a/stdlib/src/sys.rs b/stdlib/src/sys.rs index 42d264b3..5f2a1e1e 100644 --- a/stdlib/src/sys.rs +++ b/stdlib/src/sys.rs @@ -7,8 +7,95 @@ use techscript_runtime::{ context::Capability, error::{RuntimeError, RuntimeErrorKind}, value::RuntimeValue, + RuntimeContext, }; +fn read_file_fn( + ctx: &mut RuntimeContext, + args: Vec, +) -> Result { + if !ctx.config.capabilities.contains(&Capability::FileSystem) { + return Err(RuntimeError::new( + RuntimeErrorKind::InvalidOperation( + "Security policy violation: FileSystem capability is denied".to_string(), + ), + None, + None, + )); + } + let path = args[0].try_into_string()?; + let content = std::fs::read_to_string(path).map_err(|e| { + RuntimeError::new( + RuntimeErrorKind::InvalidOperation(format!("IO error: {}", e)), + None, + None, + ) + })?; + Ok(RuntimeValue::Str(content)) +} + +fn write_file_fn( + ctx: &mut RuntimeContext, + args: Vec, +) -> Result { + if !ctx.config.capabilities.contains(&Capability::FileSystem) { + return Err(RuntimeError::new( + RuntimeErrorKind::InvalidOperation( + "Security policy violation: FileSystem capability is denied".to_string(), + ), + None, + None, + )); + } + let path = args[0].try_into_string()?; + let content = args[1].try_into_string()?; + std::fs::write(path, content).map_err(|e| { + RuntimeError::new( + RuntimeErrorKind::InvalidOperation(format!("IO error: {}", e)), + None, + None, + ) + })?; + Ok(RuntimeValue::Null) +} + +fn exists_fn( + ctx: &mut RuntimeContext, + args: Vec, +) -> Result { + if !ctx.config.capabilities.contains(&Capability::FileSystem) { + return Err(RuntimeError::new( + RuntimeErrorKind::InvalidOperation( + "Security policy violation: FileSystem capability is denied".to_string(), + ), + None, + None, + )); + } + let path = args[0].try_into_string()?; + Ok(RuntimeValue::Bool(std::path::Path::new(&path).exists())) +} + +fn time_now_fn( + _ctx: &mut RuntimeContext, + _args: Vec, +) -> Result { + let start = std::time::SystemTime::now(); + let since_the_epoch = start + .duration_since(std::time::UNIX_EPOCH) + .unwrap_or_default(); + Ok(RuntimeValue::Float(since_the_epoch.as_secs_f64())) +} + +fn time_sleep_fn( + _ctx: &mut RuntimeContext, + args: Vec, +) -> Result { + let ms = args[0].try_into_int()?; + std::thread::sleep(std::time::Duration::from_millis(ms as u64)); + Ok(RuntimeValue::Null) +} + impl StdlibRegistry { pub fn register_sys(&mut self) { let mut exports: HashMap> = @@ -19,27 +106,7 @@ impl StdlibRegistry { Rc::new(StdFunction { name: "read_file".to_string(), arity: 1, - callback: |ctx, args| { - if !ctx.config.capabilities.contains(&Capability::FileSystem) { - return Err(RuntimeError::new( - RuntimeErrorKind::InvalidOperation( - "Security policy violation: FileSystem capability is denied" - .to_string(), - ), - None, - None, - )); - } - let path = args[0].try_into_string()?; - let content = std::fs::read_to_string(path).map_err(|e| { - RuntimeError::new( - RuntimeErrorKind::InvalidOperation(format!("IO error: {}", e)), - None, - None, - ) - })?; - Ok(RuntimeValue::Str(content)) - }, + callback: read_file_fn, }), ); @@ -48,28 +115,7 @@ impl StdlibRegistry { Rc::new(StdFunction { name: "write_file".to_string(), arity: 2, - callback: |ctx, args| { - if !ctx.config.capabilities.contains(&Capability::FileSystem) { - return Err(RuntimeError::new( - RuntimeErrorKind::InvalidOperation( - "Security policy violation: FileSystem capability is denied" - .to_string(), - ), - None, - None, - )); - } - let path = args[0].try_into_string()?; - let content = args[1].try_into_string()?; - std::fs::write(path, content).map_err(|e| { - RuntimeError::new( - RuntimeErrorKind::InvalidOperation(format!("IO error: {}", e)), - None, - None, - ) - })?; - Ok(RuntimeValue::Null) - }, + callback: write_file_fn, }), ); @@ -78,20 +124,7 @@ impl StdlibRegistry { Rc::new(StdFunction { name: "exists".to_string(), arity: 1, - callback: |ctx, args| { - if !ctx.config.capabilities.contains(&Capability::FileSystem) { - return Err(RuntimeError::new( - RuntimeErrorKind::InvalidOperation( - "Security policy violation: FileSystem capability is denied" - .to_string(), - ), - None, - None, - )); - } - let path = args[0].try_into_string()?; - Ok(RuntimeValue::Bool(std::path::Path::new(&path).exists())) - }, + callback: exists_fn, }), ); @@ -112,13 +145,7 @@ impl StdlibRegistry { Rc::new(StdFunction { name: "now".to_string(), arity: 0, - callback: |_ctx, _args| { - let start = std::time::SystemTime::now(); - let since_the_epoch = start - .duration_since(std::time::UNIX_EPOCH) - .unwrap_or_default(); - Ok(RuntimeValue::Float(since_the_epoch.as_secs_f64())) - }, + callback: time_now_fn, }), ); @@ -127,11 +154,7 @@ impl StdlibRegistry { Rc::new(StdFunction { name: "sleep".to_string(), arity: 1, - callback: |_ctx, args| { - let ms = args[0].try_into_int()?; - std::thread::sleep(std::time::Duration::from_millis(ms as u64)); - Ok(RuntimeValue::Null) - }, + callback: time_sleep_fn, }), ); From d5da57de11da232c3bbb6a7c4abf7ec453876e50 Mon Sep 17 00:00:00 2001 From: "google-labs-jules[bot]" <161369871+google-labs-jules[bot]@users.noreply.github.com> Date: Tue, 6 Oct 2026 08:16:00 +0000 Subject: [PATCH 2/2] Fix auto-merge failure by ignoring missing protection rules Co-authored-by: Tcode-Motion <188012755+Tcode-Motion@users.noreply.github.com>