Expand description
Native Gate4Agent node server and runtime.
Re-exports§
pub use gate4agent_node_protocol as protocol;
Structs§
- Bundle
Catalog - Bounded immutable lookup table for bundles installed before node startup.
- Managed
Worktree Profile - Native
History Config - Native
History Root - Network
Allowlist Catalog - Empty-default station network allowlist catalog.
- Network
Allowlist Entry - One node-local catalog entry. Wire / inventory still use
SpawnNetworkAllowlistId. - Network
Permit Sketch - dig2browser-spirit peer+protocol permit (node-local; non-secret).
- Node
Bundle - Immutable host-local bundle bytes and their public content receipt.
- Node
Bundle File - One immutable, normalized file captured from a validated bundle root.
- Node
Environment Profile - Immutable host-local binding from one public profile revision to native child-environment resolvers. Resolver values remain inside the native profiles and are never serialized or formatted for diagnostics.
- Node
Secret Reference - Node
Server - Node
Server Config - Node
Session Materialization Profile - Node
Session Path Binding - Node
Shutdown Handle - Provider
Native Network Sketch - Honest, partial provider-native network mapping (node-local).
- Spawn
Profile Registry - Workspace
Config
Enums§
- Bundle
Catalog Error - History
Source Layout - Network
Allowlist Catalog Error - Network
Permit Protocol - Allowed permit protocols (string form in JSON:
tcp/udp). - Node
Bundle Error - Node
Environment Profile Error - Node
Secret Resolve Error - Node
Secret Value - Node
Secret Value Error - Node
Server Error - Node
Session Environment Mutation - Node
Session File - Node
Session Materialization Profile Error - Node
Session Path Class - Spawn
Profile Registry Error - Worktree
Service Mode
Constants§
- CLAUDE_
STATION_ NETWORK_ SETTINGS_ FILE - Sidecar settings filename under ProviderHome (
CLAUDE_CONFIG_DIRhome/). - DEFAULT_
SPAWN_ PROFILE_ ID - MAX_
BUNDLE_ CATALOG_ ENTRIES - MAX_
BUNDLE_ FILES - MAX_
BUNDLE_ FILE_ BYTES - MAX_
BUNDLE_ PATH_ BYTES - MAX_
BUNDLE_ TOTAL_ BYTES - MAX_
NETWORK_ ALLOWLIST_ CATALOG_ ENTRIES - Soft bound on station network allowlist catalog membership (ids only). Soft bound on station network allowlist catalog ids exposed on launch inventory.
- MAX_
NETWORK_ PERMITS_ PER_ ENTRY - Soft bound on permit rows per catalog entry (dig2
MAX_NETWORK_PERMITSspirit). - MAX_
NODE_ ENVIRONMENT_ PROFILES - MAX_
NODE_ SECRET_ REFERENCE_ BYTES - MAX_
NODE_ SECRET_ VALUE_ BYTES - MAX_
SESSION_ ENVIRONMENT_ ENTRIES - MAX_
SESSION_ MATERIALIZATION_ FILES - MAX_
SESSION_ MATERIALIZATION_ FILE_ BYTES - MAX_
SESSION_ MATERIALIZATION_ RELATIVE_ PATH_ BYTES - MAX_
SPAWN_ PROFILES - NETWORK_
ALLOWLIST_ CATALOG_ ENV - Env path to an optional allowlist catalog file (absolute regular file). Unset → empty catalog (deny unknown at resolve). Never a secret store.
- NETWORK_
ALLOWLIST_ CATALOG_ SCHEMA_ VERSION - Structured catalog schema version (JSON v2).
Traits§
Functions§
- claude_
allowed_ domains_ from_ permits - Deduplicated Claude
allowedDomainsfrom catalog permits (stable order). - claude_
bash_ sandbox_ network_ os_ supported - Vendor Bash sandbox network overlay is macOS / Linux / WSL2 only. Native Windows (and WSL1 host without Linux node) has no vendor sandbox — refuse rather than silent no-op or invented argv.
- claude_
settings_ network_ overlay_ args - Documented Claude CLI argv:
--settings <absolute-path>. - claude_
station_ network_ settings_ json - Settings JSON fragment for Claude Bash sandbox network (vendor documented
sandbox.enabled+sandbox.network.allowedDomains). - codex_
network_ access_ config_ overlay - Codex
-coverlay for legacysandbox_workspace_write.network_access. - default_
node_ endpoint - default_
state_ path - load_
network_ allowlist_ catalog_ file - Load catalog from
path(absolute regular file). Dual format. - orca_
home_ roots - Pinned Orca-compatible roots beneath an explicitly supplied native home.
- parse_
network_ allowlist_ catalog_ text - Parse catalog text: JSON v2 when first non-comment content is
{, else v1 id-list (one id per line). - permit_
peer_ to_ allowed_ domain - Map catalog permit
peer→ Claudesandbox.network.allowedDomainshost. - provider_
native_ mapping_ supported - Whether
provider_nativeon a catalog entry can be honored forproviderat the resolvedApprovalLevel. - resolve_
network_ allowlist_ catalog - Resolve optional catalog from an explicit path, else from
NETWORK_ALLOWLIST_CATALOG_ENV, else empty. - resolve_
provider_ native_ launch_ overlay - Resolve provider-native launch overlay argv for a catalog entry, or refuse.