pub struct Sandbox { /* private fields */ }Expand description
Approval-owning boundary around one execution backend.
Implementations§
Source§impl Sandbox
impl Sandbox
Sourcepub fn new(backend: Arc<dyn SandboxBackend>, policy: ApprovalPolicy) -> Self
pub fn new(backend: Arc<dyn SandboxBackend>, policy: ApprovalPolicy) -> Self
Creates a sandbox with its initial approval policy.
Sourcepub fn isolated_execution(&self) -> Result<Self>
pub fn isolated_execution(&self) -> Result<Self>
Creates a child execution boundary with independent temporary files and workers.
Sourcepub fn attached_folders(self, primary: PathBuf, attached: Vec<PathBuf>) -> Self
pub fn attached_folders(self, primary: PathBuf, attached: Vec<PathBuf>) -> Self
Adds the primary workspace and attached folder paths to the model prompt.
Sourcepub fn read_bytes<'a>(
&'a self,
path: &'a str,
max_bytes: usize,
) -> BoxFuture<'a, Result<Vec<u8>>>
pub fn read_bytes<'a>( &'a self, path: &'a str, max_bytes: usize, ) -> BoxFuture<'a, Result<Vec<u8>>>
Reads one bounded binary file.
Sourcepub fn write<'a>(
&'a self,
path: &'a str,
content: &'a str,
permissions: &'a ToolPermissions,
) -> BoxFuture<'a, Result<()>>
pub fn write<'a>( &'a self, path: &'a str, content: &'a str, permissions: &'a ToolPermissions, ) -> BoxFuture<'a, Result<()>>
Writes a UTF-8 file when this call has mutation authority.
Sourcepub fn execute<'a>(
&'a self,
command: &'a str,
permissions: &'a ToolPermissions,
) -> BoxFuture<'a, Result<CommandOutput>>
pub fn execute<'a>( &'a self, command: &'a str, permissions: &'a ToolPermissions, ) -> BoxFuture<'a, Result<CommandOutput>>
Runs a command when this call has mutation authority.
Sourcepub async fn evaluate_worker(
&self,
command: &WorkerCommand,
permissions: &ToolPermissions,
request: &[u8],
timeout: Duration,
reset: bool,
) -> Result<Vec<u8>>
pub async fn evaluate_worker( &self, command: &WorkerCommand, permissions: &ToolPermissions, request: &[u8], timeout: Duration, reset: bool, ) -> Result<Vec<u8>>
Evaluates one authorized request, preserving runtime state until explicit reset or loss.
Sourcepub fn has_background_commands(&self, session_id: &str) -> Result<bool>
pub fn has_background_commands(&self, session_id: &str) -> Result<bool>
Reports whether one session still owns a background command result.
Trait Implementations§
Source§impl Middleware for Sandbox
impl Middleware for Sandbox
Source§fn frontend(&self) -> FrontendContribution
fn frontend(&self) -> FrontendContribution
Declares commands and status data that any frontend may render.
Source§fn prompt_section(
&self,
_runtime: &RuntimeContext,
) -> Result<Option<PromptSection>>
fn prompt_section( &self, _runtime: &RuntimeContext, ) -> Result<Option<PromptSection>>
Contributes one immutable system-prompt section while the agent is created.
Source§fn render(&self, event: &EventMsg, _session_id: &str) -> Option<FrontendBlock>
fn render(&self, event: &EventMsg, _session_id: &str) -> Option<FrontendBlock>
Renders an event owned by this capability for the destination session. Read more
Source§fn session_start<'a>(
&'a self,
context: &'a mut SessionStartContext<'_>,
) -> BoxFuture<'a, Result<()>>
fn session_start<'a>( &'a self, context: &'a mut SessionStartContext<'_>, ) -> BoxFuture<'a, Result<()>>
Starts or re-enters a session lifecycle.
Source§fn session_end<'a>(
&'a self,
runtime: &'a RuntimeContext,
) -> BoxFuture<'a, Result<()>>
fn session_end<'a>( &'a self, runtime: &'a RuntimeContext, ) -> BoxFuture<'a, Result<()>>
Releases session-local state when the agent runtime stops.
Source§fn incompatible_middleware(&self) -> &'static [&'static str]
fn incompatible_middleware(&self) -> &'static [&'static str]
Middleware IDs that cannot share a stack with this configured capability.
Source§fn register(
&self,
_catalog: &mut Catalog,
_runtime: &RuntimeContext,
) -> Result<()>
fn register( &self, _catalog: &mut Catalog, _runtime: &RuntimeContext, ) -> Result<()>
Adds tools to the catalog while the agent is created.
Source§fn command<'a>(
&'a self,
context: MiddlewareCommandContext<'a>,
) -> BoxFuture<'a, Result<MiddlewareCommandOutput>>
fn command<'a>( &'a self, context: MiddlewareCommandContext<'a>, ) -> BoxFuture<'a, Result<MiddlewareCommandOutput>>
Handles a command declared by this middleware’s frontend contribution.
Source§fn handles_messages(&self) -> bool
fn handles_messages(&self) -> bool
Reports whether this middleware is the session’s conversation-message preparer.
Source§fn route_message(
&self,
_context: &mut MessageRouteContext<'_>,
) -> Result<SubmissionResult>
fn route_message( &self, _context: &mut MessageRouteContext<'_>, ) -> Result<SubmissionResult>
Validates and prepares one conversation message for its lifecycle boundary.
Source§fn message_boundary_events(&self, _submission_id: &str) -> Vec<EventMsg>
fn message_boundary_events(&self, _submission_id: &str) -> Vec<EventMsg>
Produces capability UI cleanup when one queued message reaches its boundary.
Source§fn message_submit<'a>(
&'a self,
_context: &'a mut MessageSubmitContext<'_>,
) -> BoxFuture<'a, Result<()>>
fn message_submit<'a>( &'a self, _context: &'a mut MessageSubmitContext<'_>, ) -> BoxFuture<'a, Result<()>>
Intercepts a prepared conversation message at its delivery boundary.
Source§fn active_command<'a>(
&'a self,
_context: &'a mut ActiveCommandContext<'_>,
) -> BoxFuture<'a, Result<Option<SubmissionResult>>>
fn active_command<'a>( &'a self, _context: &'a mut ActiveCommandContext<'_>, ) -> BoxFuture<'a, Result<Option<SubmissionResult>>>
Handles a capability command while a turn is active. Read more
Source§fn pre_model<'a>(
&'a self,
_context: &'a mut ModelContext<'_>,
) -> BoxFuture<'a, Result<()>>
fn pre_model<'a>( &'a self, _context: &'a mut ModelContext<'_>, ) -> BoxFuture<'a, Result<()>>
Mutates durable context before the next model request is assembled.
Source§fn model_request<'a>(
&'a self,
_context: &'a mut ModelRequestContext<'_>,
) -> BoxFuture<'a, Result<()>>
fn model_request<'a>( &'a self, _context: &'a mut ModelRequestContext<'_>, ) -> BoxFuture<'a, Result<()>>
Applies request-only context after every durable transform has completed.
Source§fn tool_exposure<'a>(
&'a self,
_context: &'a mut ToolExposureContext<'_>,
) -> BoxFuture<'a, Result<()>>
fn tool_exposure<'a>( &'a self, _context: &'a mut ToolExposureContext<'_>, ) -> BoxFuture<'a, Result<()>>
Hides registered tools whose capability is unavailable at this boundary.
Source§fn pre_tool_use<'a>(
&'a self,
_context: &'a mut PreToolUseContext<'_>,
) -> BoxFuture<'a, Result<()>>
fn pre_tool_use<'a>( &'a self, _context: &'a mut PreToolUseContext<'_>, ) -> BoxFuture<'a, Result<()>>
Intercepts one normalized tool call before authorization and persistence.
Source§fn permission_request<'a>(
&'a self,
_context: &'a mut PermissionRequestContext<'_>,
) -> BoxFuture<'a, Result<()>>
fn permission_request<'a>( &'a self, _context: &'a mut PermissionRequestContext<'_>, ) -> BoxFuture<'a, Result<()>>
Decides whether an approval request should be deferred, allowed, or denied.
Source§fn post_tool_use<'a>(
&'a self,
_context: &'a mut PostToolUseContext<'_>,
) -> BoxFuture<'a, Result<()>>
fn post_tool_use<'a>( &'a self, _context: &'a mut PostToolUseContext<'_>, ) -> BoxFuture<'a, Result<()>>
Transforms model-visible feedback after a tool has executed.
Source§fn pre_compact<'a>(
&'a self,
_context: &'a mut CompactContext<'_>,
) -> BoxFuture<'a, Result<()>>
fn pre_compact<'a>( &'a self, _context: &'a mut CompactContext<'_>, ) -> BoxFuture<'a, Result<()>>
Intercepts context immediately before compaction and may stop the active turn.
Source§fn retain_compacted_input(&self, _item: &Value) -> bool
fn retain_compacted_input(&self, _item: &Value) -> bool
Keeps one compacted context item before it is committed or observed by hooks.
Capability-owned projections may be discarded even when a later hook stops or fails.
Source§fn post_compact<'a>(
&'a self,
_context: &'a mut CompactContext<'_>,
) -> BoxFuture<'a, Result<()>>
fn post_compact<'a>( &'a self, _context: &'a mut CompactContext<'_>, ) -> BoxFuture<'a, Result<()>>
Intercepts the committed compacted context and may stop the active turn.
Auto Trait Implementations§
impl !Freeze for Sandbox
impl !RefUnwindSafe for Sandbox
impl !UnwindSafe for Sandbox
impl Send for Sandbox
impl Sync for Sandbox
impl Unpin for Sandbox
impl UnsafeUnpin for Sandbox
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more