Skip to main content

Sandbox

Struct Sandbox 

Source
pub struct Sandbox { /* private fields */ }
Expand description

Approval-owning boundary around one execution backend.

Implementations§

Source§

impl Sandbox

Source

pub fn new(backend: Arc<dyn SandboxBackend>, policy: ApprovalPolicy) -> Self

Creates a sandbox with its initial approval policy.

Source

pub fn isolated_execution(&self) -> Result<Self>

Creates a child execution boundary with independent temporary files and workers.

§Errors

Returns an error if validation or an operation required by this function fails.

Source

pub fn attached_folders(self, primary: PathBuf, attached: Vec<PathBuf>) -> Self

Adds the primary workspace and attached folder paths to the model prompt.

Source

pub fn read<'a>( &'a self, path: &'a str, permissions: &'a ToolPermissions, ) -> BoxFuture<'a, Result<String>>

Reads a UTF-8 file.

Source

pub fn read_bytes<'a>( &'a self, path: &'a str, max_bytes: usize, permissions: &'a ToolPermissions, ) -> BoxFuture<'a, Result<Vec<u8>>>

Reads one bounded binary file.

Source

pub fn write<'a>( &'a self, path: &'a str, content: &'a str, permissions: &'a ToolPermissions, ) -> BoxFuture<'a, Result<()>>

Writes a UTF-8 file when this call has mutation authority.

Source

pub fn execute<'a>( &'a self, command: &'a str, permissions: &'a ToolPermissions, ) -> BoxFuture<'a, Result<CommandOutput>>

Runs a command when this call has mutation authority.

Source

pub async fn evaluate_worker( &self, command: &WorkerCommand, permissions: &ToolPermissions, request: &[u8], timeout: Duration, reset: bool, ) -> Result<Vec<u8>>

Evaluates one authorized request, preserving runtime state until explicit reset or loss.

§Errors

Returns an error if validation or an operation required by this function fails.

Source

pub async fn browser_page( &self, permissions: &ToolPermissions, ) -> Option<String>

The page a call’s chat may drive in a browser outside the sandbox, as a DevTools endpoint. That browser reaches the network from outside the sandbox, so only calls allowed network access are lent one.

Source

pub fn has_background_commands(&self, session_id: &str) -> Result<bool>

Reports whether one session still owns a background command result.

§Errors

Returns an error if validation or an operation required by this function fails.

Trait Implementations§

Source§

impl Middleware for Sandbox

Source§

fn name(&self) -> &'static str

Stable ID used to reject duplicate registrations.
Source§

fn frontend(&self) -> FrontendContribution

Declares commands and status data that any frontend may render.
Source§

fn prompt_section( &self, _runtime: &RuntimeContext, ) -> Result<Option<PromptSection>>

Contributes one immutable system-prompt section while the agent is created. Read more
Source§

fn render(&self, event: &EventMsg, _session_id: &str) -> Option<FrontendBlock>

Renders an event owned by this capability for the destination session. Read more
Source§

fn session_start<'a>( &'a self, context: &'a mut SessionStartContext<'_>, ) -> BoxFuture<'a, Result<()>>

Starts or re-enters a session lifecycle.
Source§

fn session_end<'a>( &'a self, runtime: &'a RuntimeContext, ) -> BoxFuture<'a, Result<()>>

Releases session-local state when the agent runtime stops.
Source§

fn incompatible_middleware(&self) -> &'static [&'static str]

Middleware IDs that cannot share a stack with this configured capability.
Source§

fn register( &self, _catalog: &mut Catalog, _runtime: &RuntimeContext, ) -> Result<()>

Adds tools to the catalog while the agent is created. Read more
Source§

fn command<'a>( &'a self, context: MiddlewareCommandContext<'a>, ) -> BoxFuture<'a, Result<MiddlewareCommandOutput>>

Handles a command declared by this middleware’s frontend contribution.
Source§

fn handles_messages(&self) -> bool

Reports whether this middleware is the session’s conversation-message preparer.
Source§

fn route_message( &self, _context: &mut MessageRouteContext<'_>, ) -> Result<SubmissionResult>

Validates and prepares one conversation message for its lifecycle boundary. Read more
Source§

fn message_boundary_events(&self, _submission_id: &str) -> Vec<EventMsg>

Produces capability UI cleanup when one queued message reaches its boundary.
Source§

fn message_submit<'a>( &'a self, _context: &'a mut MessageSubmitContext<'_>, ) -> BoxFuture<'a, Result<()>>

Intercepts a prepared conversation message at its delivery boundary.
Source§

fn active_command<'a>( &'a self, _context: &'a mut ActiveCommandContext<'_>, ) -> BoxFuture<'a, Result<Option<SubmissionResult>>>

Handles a capability command while a turn is active. Read more
Source§

fn pre_model<'a>( &'a self, _context: &'a mut ModelContext<'_>, ) -> BoxFuture<'a, Result<()>>

Mutates durable context before the next model request is assembled.
Source§

fn model_request<'a>( &'a self, _context: &'a mut ModelRequestContext<'_>, ) -> BoxFuture<'a, Result<()>>

Applies request-only context after every durable transform has completed.
Source§

fn tool_exposure<'a>( &'a self, _context: &'a mut ToolExposureContext<'_>, ) -> BoxFuture<'a, Result<()>>

Hides registered tools whose capability is unavailable at this boundary.
Source§

fn pre_tool_use<'a>( &'a self, _context: &'a mut PreToolUseContext<'_>, ) -> BoxFuture<'a, Result<()>>

Intercepts one normalized tool call before authorization and persistence.
Source§

fn permission_request<'a>( &'a self, _context: &'a mut PermissionRequestContext<'_>, ) -> BoxFuture<'a, Result<()>>

Decides whether an approval request should be deferred, allowed, or denied.
Source§

fn post_tool_use<'a>( &'a self, _context: &'a mut PostToolUseContext<'_>, ) -> BoxFuture<'a, Result<()>>

Transforms model-visible feedback after a tool has executed.
Source§

fn pre_compact<'a>( &'a self, _context: &'a mut CompactContext<'_>, ) -> BoxFuture<'a, Result<()>>

Intercepts context immediately before compaction and may stop the active turn.
Source§

fn prepare_compacted_input( &self, _original: &[Value], _compacted: &mut Vec<Value>, )

Repairs or discards capability-owned projections before compacted input is committed. The original input is read-only; changes are validated before the rewrite is saved.
Source§

fn post_compact<'a>( &'a self, _context: &'a mut CompactContext<'_>, ) -> BoxFuture<'a, Result<()>>

Intercepts the committed compacted context and may stop the active turn.
Source§

fn stop<'a>( &'a self, _context: &'a mut StopContext<'_>, ) -> BoxFuture<'a, Result<()>>

Decides whether a naturally stopped model should continue once more.
Source§

fn turn_end<'a>( &'a self, _context: &'a mut TurnEndContext<'_>, ) -> BoxFuture<'a, Result<()>>

Observes terminal bookkeeping for a completed or aborted turn.

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more