Skip to main content

Module tool

Module tool 

Source
Expand description

Executable admission and bounded execution of caller-selected Unix commands.

Consumers own pins, arguments, credentials, environment and trusted executable directories. Execution is not a sandbox or process-tree supervisor. Calls execute once, including on timeout or ambiguous completion; no retry occurs.

Structs§

AdmittedTool
An executable with a retained byte identity and an admitted exact version.
ExecutionContext
Explicit process context. The child’s inherited environment is cleared.
ExecutionError
A failed invocation with bounded output and separately retained cleanup errors.
ExecutionEvidence
Bounded evidence from one invocation, including interrupted invocations.
OutputLimits
Caller-selected stdout/stderr storage bounds and capture deadline.
ToolSpec
Exact executable and version authority selected by a consumer.
VersionSpec
Exact version authority for a caller-trusted installed executable.

Enums§

ExecutionFailure
Why an invocation failed, independently of its retained output.
ExecutionOperation
Process or pipe operation that produced an IO failure.
InvalidInvocation
Invocation parameters rejected before dispatch or communication. An already spawned child remains owned and untouched by this validation.
OutputStream
A captured output stream.
ResolutionError
Executable selection failed before any admission or execution.
SuccessfulExit
Successful leader disposition during communicate_child.
ToolError
Executable admission or execution failed.

Functions§

capture_command
Capture one caller-configured command without performing executable admission.
capture_group_command
Capture one caller-configured command in a newly owned process group.
communicate_child
Communicate once with a caller-spawned child using its configured IO.
communicate_child_with_observer
Communicate with an owned child while observing retained output bytes live.
resolve_executable
Resolve one executable candidate without reading ambient PATH or running it.