Expand description
Executable admission and bounded execution of caller-selected Unix commands.
Consumers own pins, arguments, credentials, environment and trusted executable directories. Execution is not a sandbox or process-tree supervisor. Calls execute once, including on timeout or ambiguous completion; no retry occurs.
Structs§
- Admitted
Tool - An executable with a retained byte identity and an admitted exact version.
- Execution
Context - Explicit process context. The child’s inherited environment is cleared.
- Execution
Error - A failed invocation with bounded output and separately retained cleanup errors.
- Execution
Evidence - Bounded evidence from one invocation, including interrupted invocations.
- Output
Limits - Caller-selected stdout/stderr storage bounds and capture deadline.
- Tool
Spec - Exact executable and version authority selected by a consumer.
- Version
Spec - Exact version authority for a caller-trusted installed executable.
Enums§
- Execution
Failure - Why an invocation failed, independently of its retained output.
- Execution
Operation - Process or pipe operation that produced an IO failure.
- Invalid
Invocation - Invocation parameters rejected before dispatch or communication. An already spawned child remains owned and untouched by this validation.
- Output
Stream - A captured output stream.
- Resolution
Error - Executable selection failed before any admission or execution.
- Successful
Exit - Successful leader disposition during
communicate_child. - Tool
Error - Executable admission or execution failed.
Functions§
- capture_
command - Capture one caller-configured command without performing executable admission.
- capture_
group_ command - Capture one caller-configured command in a newly owned process group.
- communicate_
child - Communicate once with a caller-spawned child using its configured IO.
- resolve_
executable - Resolve one executable candidate without reading ambient PATH or running it.