Skip to main content

ShellTool

Struct ShellTool 

Source
pub struct ShellTool { /* private fields */ }
Expand description

The confined shell tool.

Registers under "shell". Accepts either argv form (program + args) or a free-form cmd string parsed by the safe-subset engine. Leash refusals (out-of-scope exec/fs, a refused construct) are returned as a structured denied envelope (denied: true), not a hard error.

Implementations§

Source§

impl ShellTool

Source

pub fn new() -> ShellTool

Construct the tool with the real OS spawner, environment, and dir lister, and the default LimitsPolicy.

Source

pub fn with_config(limits: LimitsPolicy) -> ShellTool

Construct with the real seams and a caller-supplied LimitsPolicy — the configurability seam (agent-bridle#143): tune timeouts / output / glob caps.

Source

pub fn with_output_observer( self, observer: Arc<dyn ShellOutputObserver>, ) -> ShellTool

Attach a presentation-only observer for bounded stdout/stderr chunks.

The observer is queued only after leash admission. It receives at most the configured output cap per stream and cannot change authorization or the final result envelope. Delivery may finish asynchronously after the invocation returns; on_finish marks the queue-drained boundary.

Source

pub fn with_sandbox_policy(self, sandbox: SandboxPolicy) -> ShellTool

Set the sandbox mechanism policy (read/exec allow-lists, ABI floors) the L3 backend enforces (I5-B, #144). The default is today’s built-in allow-lists.

Source

pub fn with_private_hosts( self, hosts: impl IntoIterator<Item = String>, ) -> Result<ShellTool, Error>

Approve exact names for RFC1918/ULA resolution by the existing fenced egress proxy. The owning harness supplies explicit operator approvals; command text and remote metadata are not authority. The invocation’s ordinary network scope must independently allow every requested host.

Empty by default. This does not start a proxy where no kernel fence exists, permit forbidden address ranges, or change filesystem/exec scope.

Trait Implementations§

Source§

impl Clone for ShellTool

Source§

fn clone(&self) -> ShellTool

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for ShellTool

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result<(), Error>

Formats the value using the given formatter. Read more
Source§

impl Default for ShellTool

Source§

fn default() -> ShellTool

Returns the “default value” for a type. Read more
Source§

impl Tool for ShellTool

Source§

fn name(&self) -> &str

The dispatch name (the key in tools/list and in crate::Registry::dispatch).
Source§

fn schema(&self) -> Value

The MCP inputSchema (JSON Schema) for this tool’s arguments.
Source§

fn invoke<'life0, 'life1, 'async_trait>( &'life0 self, args: Value, cx: &'life1 ToolContext, ) -> Pin<Box<dyn Future<Output = Result<Value, ToolError>> + Send + 'async_trait>>
where 'life0: 'async_trait, 'life1: 'async_trait, ShellTool: 'async_trait,

Run the tool. The cx proves the leash was passed; the tool enforces per-operation policy by calling cx.check_exec, cx.check_path_*, etc.
Source§

fn required(&self) -> Caveats

The authority ceiling this tool promises to stay under. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<F, T> ConvertInto<T> for F
where T: ConvertFrom<F>,

Source§

fn convert_into(self) -> T

Infallibly converts a value of type Self to a value of type T.
Source§

impl<F, T> ConvertTryFrom<F> for T
where F: ConvertInto<T>,

Source§

type Error = !

The type of an error that can occur during a conversion. Read more
Source§

fn convert_try_from(value: F) -> Result<T, !>

Fallibly converts a value of type F to a value of type Self.
Source§

impl<F, T> ConvertTryInto<T> for F
where T: ConvertTryFrom<F>,

Source§

type Error = <T as ConvertTryFrom<F>>::Error

The type of an error that can occur during a conversion. Read more
Source§

fn convert_try_into(self) -> Result<T, <T as ConvertTryFrom<F>>::Error>

Fallibly converts a value of type Self to a value of type T.
Source§

impl<T> ErasedDestructor for T
where T: 'static,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> Pointable for T

Source§

const ALIGN: usize

The alignment of pointer.
Source§

type Init = T

The type for initializers.
Source§

unsafe fn init(init: <T as Pointable>::Init) -> usize

Initializes a with the given initializer. Read more
Source§

unsafe fn deref<'a>(ptr: usize) -> &'a T

Dereferences the given pointer. Read more
Source§

unsafe fn deref_mut<'a>(ptr: usize) -> &'a mut T

Mutably dereferences the given pointer. Read more
Source§

unsafe fn drop(ptr: usize)

Drops the object pointed to by the given pointer. Read more
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more