cleanup, docs
This commit is contained in:
@@ -16,9 +16,6 @@ of hostcall names. Names may be given bare (`shell_exec`) or fully qualified
|
||||
(`uce_host_shell_exec`); whitespace is ignored. Empty (the default) blocks
|
||||
nothing.
|
||||
|
||||
```
|
||||
UCE_HOSTCALL_BLOCKLIST=shell_exec, shell_spawn, http_request, http_request_async, mysql
|
||||
```
|
||||
|
||||
Changes take effect on **restart** (`systemctl restart uce`). There is no hot
|
||||
reload — the list is parsed once per worker process into a fast lookup, so an
|
||||
@@ -58,3 +55,6 @@ listed, so a deployment cannot be bricked by an over-broad blocklist:
|
||||
- Pure-compute library functions that are NOT hostcalls (string ops, `DValue`
|
||||
methods, hashing helpers like `gen_noise`, etc.) are not OS capabilities and
|
||||
cannot be blocked this way — only `uce_host_*` membrane calls are gateable.
|
||||
|
||||
:example
|
||||
print("Blocked functions documents a UCE concept.\n");
|
||||
|
||||
Reference in New Issue
Block a user