Expand description
Digest/version admission and bounded execution of explicit Unix host tools.
Consumers own pins, arguments, credentials, environment and trusted executable directories. Execution is not a sandbox or process-tree supervisor. Calls execute once, including on timeout or ambiguous completion; no retry occurs.
Structs§
- Admitted
Tool - An executable whose exact bytes and version were admitted by a consumer.
- Execution
Context - Explicit process context. The child’s inherited environment is cleared.
- Execution
Error - A failed invocation with bounded output and direct-child cleanup evidence.
- Execution
Evidence - Bounded evidence from one invocation, including interrupted invocations.
- Output
Limits - Caller-selected stdout/stderr storage bounds and capture deadline.
- Tool
Spec - Exact executable and version authority selected by a consumer.
Enums§
- Execution
Failure - Why an invocation failed, independently of its retained output.
- Execution
Operation - Process or pipe operation that produced an IO failure.
- Invalid
Invocation - An invalid invocation was rejected before a child was spawned.
- Output
Stream - A captured output stream.
- Resolution
Error - Executable selection failed before any admission or execution.
- Tool
Error - Executable admission or execution failed.
Functions§
- resolve_
executable - Resolve one executable candidate without reading ambient PATH or running it.