Skip to main content

capture_command

Function capture_command 

Source
pub fn capture_command(
    command: &mut Command,
    limits: OutputLimits,
) -> Result<ExecutionEvidence, ToolError>
Expand description

Capture one caller-configured command without performing executable admission.

The caller owns the program, arguments, working directory, environment and platform setup. Their Command settings are used unchanged except that stdin is set to null and stdout/stderr to pipes. Ambient environment or PATH search remains enabled if the caller’s command enables it. No digest/version check, credential selection, command reconstruction or retry is performed. Use AdmittedTool when exact executable-byte/version admission is required.

Shares the admitted-tool execution engine: stdout/stderr are drained fairly with bounded storage, and the deadline starts immediately before spawning and extends through pipe EOF. On failure, pipes are closed and the direct child is terminated/reaped, retaining the original failure and cleanup evidence. Descendants, platform setup hooks and inherited descriptor lifetimes remain caller-owned. Spawning, setup hooks and kill/reap are synchronous and may exceed the deadline. This does not supervise a process group, roll back an external effect or make an uncertain command safe to repeat.

§Errors

Rejects an invalid deadline before touching or spawning the command. Spawn, capture, nonzero exit, overflow and deadline failures retain bounded evidence.