pub struct RunCommandRequest {
pub command: String,
pub args: Vec<String>,
pub cwd: Option<String>,
pub env: BTreeMap<String, String>,
pub timeout: Duration,
}Expand description
A command to run inside a sandbox.
Fields§
§command: StringThe program to run
args: Vec<String>Arguments handed to the program, each as one argument — nothing re-parses their text
cwd: Option<String>Working directory inside the sandbox
env: BTreeMap<String, String>Environment overlaid on the sandbox’s own
timeout: DurationHow long this command may run. Required — a defaulted timeout is a hang waiting for a slow day.
CreateSandboxRequest::timeout_ms is an outer bound this timeout cannot see. Neither
shortens the other, but on AWS and GCP the platform reaps the sandbox at its lifetime
whatever is running inside: a command still going is cut off mid-flight and reports
SANDBOX_OUTCOME_UNKNOWN, never timeoutExceeded, because nothing survived to say what it
did. A lifetime has to leave room for the longest command it must cover.
It bounds the command, not the call, and the call lands just after it. Where the agent
supervises the process it kills the process group; where the data plane has no timeout of
its own the command runs under timeout inside the sandbox. Either way the sandbox stays
usable. Only a sandbox that cannot run timeout is ended instead, and that call returns
once the sandbox is gone.
On every backend timeoutExceeded is reported only once the command has verifiably
stopped — the agent waits for its kill, and where there is no agent the sandbox kills the
command itself and says so. It is never reported on a stop that was merely requested: a
timeout that leaves untrusted code running is not a timeout.
What stops is the command and its process group. A descendant that detaches itself into a session of its own is beyond any signal sent from inside, on every backend; it is bounded by the sandbox, which ends on terminate or at its own lifetime ceiling.
Implementations§
Trait Implementations§
Source§impl Clone for RunCommandRequest
impl Clone for RunCommandRequest
Source§fn clone(&self) -> RunCommandRequest
fn clone(&self) -> RunCommandRequest
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreSource§impl Debug for RunCommandRequest
impl Debug for RunCommandRequest
Source§impl<'de> Deserialize<'de> for RunCommandRequest
impl<'de> Deserialize<'de> for RunCommandRequest
Source§fn deserialize<__D>(
__deserializer: __D,
) -> Result<RunCommandRequest, <__D as Deserializer<'de>>::Error>where
__D: Deserializer<'de>,
fn deserialize<__D>(
__deserializer: __D,
) -> Result<RunCommandRequest, <__D as Deserializer<'de>>::Error>where
__D: Deserializer<'de>,
impl Eq for RunCommandRequest
Source§impl PartialEq for RunCommandRequest
impl PartialEq for RunCommandRequest
Source§impl Serialize for RunCommandRequest
impl Serialize for RunCommandRequest
Source§fn serialize<__S>(
&self,
__serializer: __S,
) -> Result<<__S as Serializer>::Ok, <__S as Serializer>::Error>where
__S: Serializer,
fn serialize<__S>(
&self,
__serializer: __S,
) -> Result<<__S as Serializer>::Ok, <__S as Serializer>::Error>where
__S: Serializer,
impl StructuralPartialEq for RunCommandRequest
Auto Trait Implementations§
impl Freeze for RunCommandRequest
impl RefUnwindSafe for RunCommandRequest
impl Send for RunCommandRequest
impl Sync for RunCommandRequest
impl Unpin for RunCommandRequest
impl UnsafeUnpin for RunCommandRequest
impl UnwindSafe for RunCommandRequest
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> DeserializeOwned for Twhere
T: for<'de> Deserialize<'de>,
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
key and return true if they are equal.Source§impl<K, Q> Equivalent<Q> for K
impl<K, Q> Equivalent<Q> for K
Source§fn equivalent(&self, key: &Q) -> bool
fn equivalent(&self, key: &Q) -> bool
key and return true if they are equal.impl<T> ErasedDestructor for Twhere
T: 'static,
Source§impl<T> FromBase64 for Twhere
T: for<'de> Deserialize<'de>,
impl<T> FromBase64 for Twhere
T: for<'de> Deserialize<'de>,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more