pub struct SandboxCapabilities {
pub files: bool,
pub reconnect: bool,
pub preview: bool,
pub suspend_resume: bool,
pub snapshot: bool,
pub domain_egress_rules: bool,
pub egress_deny: bool,
pub enforced_limits: bool,
pub process_limit: bool,
pub session_lifetime: bool,
pub supervisor_pid_namespace: bool,
pub supervisor_isolation: bool,
}Expand description
What a platform’s sandbox backend can actually do.
Published so portable code can branch before calling rather than discovering a gap through an error. Every field here corresponds to a capability that at least one platform lacks; create, exec and terminate are the guaranteed floor and are therefore not listed.
Fields§
§files: boolFiles can be moved in and out of a session
reconnect: boolA later call can reach a session created by an earlier one
preview: boolAn authenticated, port-scoped capability to reach a service inside the sandbox
suspend_resume: boolSession state can be suspended and resumed
snapshot: boolA session’s full state can be captured and used to create another
domain_egress_rules: boolEgress can be restricted to a hostname allowlist
egress_deny: boolWhether a declared deny is actually enforced, rather than accepted and dropped
enforced_limits: boolThe platform enforces the declared cpu, memory and disk ceilings
process_limit: boolThe platform can cap how many processes a session runs
session_lifetime: boolThe platform terminates a session at a declared wall-clock deadline
supervisor_pid_namespace: boolA command runs in its own PID namespace and cannot see or signal the agent’s processes.
Only where an agent runs as root. Creating the namespace needs CAP_SYS_ADMIN, and the
Kubernetes sandbox pod drops every capability — which is also what denies ptrace by
construction, so granting it there would remove a lock to add one.
supervisor_isolation: boolThe process supervising a command is a different identity from the command.
False where a command runs as the agent’s own user: it can then read the supervisor’s
environment and signal it. Separate from supervisorPidNamespace, which is about
visibility rather than identity — a backend can have one without the other.
Implementations§
Source§impl SandboxCapabilities
impl SandboxCapabilities
Sourcepub fn for_platform(platform: Platform) -> Result<Self>
pub fn for_platform(platform: Platform) -> Result<Self>
Returns what the given platform’s sandbox backend supports.
Errors for platforms with no sandbox backend, rather than returning an all-false set — “every capability is missing” and “this platform has no sandboxes” are different conditions and an application should not have to tell them apart by inspection.
Sourcepub fn gcp_agent_platform() -> Self
pub fn gcp_agent_platform() -> Self
What the GCP Agent Platform sandbox backend supports; the body of the Platform::Gcp arm.
Trait Implementations§
Source§impl Clone for SandboxCapabilities
impl Clone for SandboxCapabilities
Source§fn clone(&self) -> SandboxCapabilities
fn clone(&self) -> SandboxCapabilities
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreimpl Copy for SandboxCapabilities
Source§impl Debug for SandboxCapabilities
impl Debug for SandboxCapabilities
Source§impl<'de> Deserialize<'de> for SandboxCapabilities
impl<'de> Deserialize<'de> for SandboxCapabilities
Source§fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
impl Eq for SandboxCapabilities
Source§impl PartialEq for SandboxCapabilities
impl PartialEq for SandboxCapabilities
Source§impl Serialize for SandboxCapabilities
impl Serialize for SandboxCapabilities
impl StructuralPartialEq for SandboxCapabilities
Auto Trait Implementations§
impl Freeze for SandboxCapabilities
impl RefUnwindSafe for SandboxCapabilities
impl Send for SandboxCapabilities
impl Sync for SandboxCapabilities
impl Unpin for SandboxCapabilities
impl UnsafeUnpin for SandboxCapabilities
impl UnwindSafe for SandboxCapabilities
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> DeserializeOwned for Twhere
T: for<'de> Deserialize<'de>,
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
key and return true if they are equal.