Skip to main content

BashSandbox

Trait BashSandbox 

Source
pub trait BashSandbox: Send + Sync {
    // Required methods
    fn exec_command<'life0, 'life1, 'life2, 'async_trait>(
        &'life0 self,
        command: &'life1 str,
        guest_workspace: &'life2 str,
    ) -> Pin<Box<dyn Future<Output = Result<SandboxOutput>> + Send + 'async_trait>>
       where Self: 'async_trait,
             'life0: 'async_trait,
             'life1: 'async_trait,
             'life2: 'async_trait;
    fn shutdown<'life0, 'async_trait>(
        &'life0 self,
    ) -> Pin<Box<dyn Future<Output = ()> + Send + 'async_trait>>
       where Self: 'async_trait,
             'life0: 'async_trait;

    // Provided methods
    fn exec<'life0, 'async_trait>(
        &'life0 self,
        request: SandboxCommandRequest,
    ) -> Pin<Box<dyn Future<Output = Result<SandboxExecutionOutput>> + Send + 'async_trait>>
       where Self: 'async_trait,
             'life0: 'async_trait { ... }
    fn policy_digest(&self) -> Option<String> { ... }
    fn apply_network_grant(
        &self,
        _grant: NetworkGrant,
        _expected_base_digest: &str,
    ) -> Result<String> { ... }
}
Expand description

Abstraction over sandbox bash execution used by the bash built-in tool.

Implement this trait to replace the native sandbox with a custom backend. The host application constructs the implementation and passes it to the session via crate::SessionOptions::with_sandbox_handle.

Required Methods§

Source

fn exec_command<'life0, 'life1, 'life2, 'async_trait>( &'life0 self, command: &'life1 str, guest_workspace: &'life2 str, ) -> Pin<Box<dyn Future<Output = Result<SandboxOutput>> + Send + 'async_trait>>
where Self: 'async_trait, 'life0: 'async_trait, 'life1: 'async_trait, 'life2: 'async_trait,

Execute a shell command inside the sandbox.

  • command — the shell command string (passed as bash -c <command>).
  • guest_workspace — the workspace path expected by a custom guest backend (for example, "/workspace"). The A3S native backend uses its canonical host workspace instead.
Source

fn shutdown<'life0, 'async_trait>( &'life0 self, ) -> Pin<Box<dyn Future<Output = ()> + Send + 'async_trait>>
where Self: 'async_trait, 'life0: 'async_trait,

Shut down the sandbox (best-effort, infallible from caller’s perspective).

Provided Methods§

Source

fn exec<'life0, 'async_trait>( &'life0 self, request: SandboxCommandRequest, ) -> Pin<Box<dyn Future<Output = Result<SandboxExecutionOutput>> + Send + 'async_trait>>
where Self: 'async_trait, 'life0: 'async_trait,

Execute a command with the complete host tool contract.

Existing implementations inherit a compatibility adapter that delegates to Self::exec_command. Sandboxes that spawn a real process should override this method so timeout and output-stream semantics are not silently lost. The built-in bash tool also enforces timeout_ms by dropping this future at the deadline, so implementations must terminate or otherwise contain child processes when their execution future is cancelled.

Source

fn policy_digest(&self) -> Option<String>

Snapshot of the active policy digest for grant lineage, when the backend supports host-approved grants.

Source

fn apply_network_grant( &self, _grant: NetworkGrant, _expected_base_digest: &str, ) -> Result<String>

Apply a host-approved network grant: the only sanctioned broadening path. expected_base_digest pins the approval to the exact policy the user confirmed against. The default refuses: custom backends opt in explicitly.

Dyn Compatibility§

This trait is dyn compatible.

In older versions of Rust, dyn compatibility was called "object safety".

Implementors§