//! `everruns-sandbox-exec`: apply kernel containment, then become the shell.
//!
//! Not a user-facing command. A [`SandboxProvider`] spawns it with the fixed
//! argument list [`WorkerRequest::parse`] accepts, and it never returns on
//! success: it execs bash in place so the restrictions it installed are the
//! ones the shell and every descendant run under.
//!
//! [`SandboxProvider`]: everruns_core::host::containment::SandboxProvider
//! [`WorkerRequest::parse`]: everruns_core::host::containment::worker::WorkerRequest::parse