pub fn capture_command(
command: &mut Command,
limits: OutputLimits,
) -> Result<ExecutionEvidence, ToolError>Expand description
Capture one caller-configured command without performing executable admission.
The caller owns the program, arguments, working directory, environment and
platform setup. Their Command settings are used unchanged except that
stdin is set to null and stdout/stderr to pipes. Ambient environment or PATH
search remains enabled if the caller’s command enables it. No digest/version
check, credential selection, command reconstruction or retry is performed.
Use AdmittedTool when exact executable-byte/version admission is required.
Shares the admitted-tool execution engine: stdout/stderr are drained fairly with bounded storage, and the deadline starts immediately before spawning and extends through pipe EOF. On failure, pipes are closed and the direct child is terminated/reaped, retaining the original failure and cleanup evidence. Descendants, platform setup hooks and inherited descriptor lifetimes remain caller-owned. Spawning, setup hooks and kill/reap are synchronous and may exceed the deadline. This does not supervise a process group, roll back an external effect or make an uncertain command safe to repeat.
§Errors
Rejects an invalid deadline before touching or spawning the command. Spawn, capture, nonzero exit, overflow and deadline failures retain bounded evidence.