- docs/examples/employee-list: attaches to the running employee program; modes list / report (byte-identical to A's own) / staff <dept> / probe-write (registered read-only, insert must trap access-denied, exit 4, A unchanged) - the manifests ARE the design, written as a pair: A's [share] gains listen = unix socket beside WO_DATA plus [[share.clients]] naming B's public-key fingerprint with rights = "read"; B's [connect.employee] carries A's ipc string, A's PINNED fingerprint, and project = ../employee for compile-time shapes -- the connect section's name is the code's namespace (employee.Employee) - fingerprints are PASTE-HERE placeholders by design: keys generate into WO_DATA at first boot (9d), tomls carry fingerprints only, printed by --identity - sample-first: compiles after 9/9b/9c/9d; README maps each mode to the acceptance line it exists for; 9c/9d stories now name this sample as their workload Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
28 lines
1.2 KiB
TOML
28 lines
1.2 KiB
TOML
name = "employee"
|
|
version = "0.1.0"
|
|
description = "Employee management — iteration 9/9b acceptance workload: @table storage, ref/backlink relations, compiler-checked GroupBy queries"
|
|
|
|
[runtime]
|
|
wo = ">= 0.1"
|
|
|
|
# `woc .` builds target/employee once iterations 9 (engine) and 9b (query
|
|
# surface) land; until then this sample is the target the plans compile
|
|
# toward, sample-first like log-watcher was.
|
|
[build]
|
|
runtime = "../../../runtime/wovm"
|
|
|
|
# Iteration 9c/9d surface (target): this program OWNS its database and
|
|
# shares it. The runtime listens on `listen` beside WO_DATA; every client
|
|
# below is a grant — no registration, no attach, same uid included.
|
|
[share]
|
|
listen = "unix:target/data/employee.sock"
|
|
|
|
# Program B (docs/examples/employee-list), granted read-only. Identity is
|
|
# B's public-key fingerprint (9d): printed by `employee-list --identity`
|
|
# after B's first boot; paste it here. Rights: "read" or "rw" — B's
|
|
# probe-write mode exists to prove "read" refuses. Rotation and revocation
|
|
# are edits to this table plus a restart, never an API.
|
|
[[share.clients]]
|
|
name = "employee-list"
|
|
public_key = "ed25519:PASTE-EMPLOYEE-LIST-FINGERPRINT-HERE"
|
|
rights = "read"
|