Skip to main content

LocalCommandExecutor

Struct LocalCommandExecutor 

Source
pub struct LocalCommandExecutor<W> { /* private fields */ }
Expand description

Local non-PTY, one-shot command executor backed by host process spawning.

This executor resolves CommandRequest::cwd through the Workspace, starts argv directly without implicit shell parsing, applies EnvPolicy, requires a timeout, captures stdout/stderr separately, and reports output truncation.

This executor is not an OS sandbox. It does not technically enforce SandboxPolicy, NetworkPolicy, network isolation, process-tree cleanup, or resource limits. Its capability report marks sandbox, network, and process cleanup as advisory, and resource limits as unsupported.

By default, command execution fails closed when the requested policy requires technical enforcement that this local process backend cannot provide. LocalCommandExecutor::with_advisory_policy and LocalCommandExecutor::with_policy_capability_mode can explicitly allow such execution to continue with advisory enforcement reports. That mode is intended for tests, local prototypes, and reference CLI dogfooding; production coding-agent hosts should inject a CommandExecutor backed by a container, VM, platform sandbox, or remote isolated worker that can enforce the requested policy.

Implementations§

Source§

impl<W> LocalCommandExecutor<W>

Source

pub fn new(workspace: W) -> LocalCommandExecutor<W>

Constructs a local command executor for a workspace.

Source

pub fn with_advisory_policy(self, allow: bool) -> LocalCommandExecutor<W>

Allows policy requirements that cannot be technically enforced locally to be reported as advisory instead of failing closed.

Passing true does not enable sandboxing, network isolation, process-tree cleanup, or resource limits. It only permits execution to continue while recording the downgrade in the returned policy enforcement report.

Source

pub fn with_policy_capability_mode( self, mode: PolicyCapabilityMode, ) -> LocalCommandExecutor<W>

Sets how this executor handles policy/capability mismatches.

PolicyCapabilityMode::RequireEnforced is the conservative default. PolicyCapabilityMode::AllowAdvisory allows local execution to proceed without technical enforcement and requires reports to say so explicitly.

Trait Implementations§

Source§

impl<W> Clone for LocalCommandExecutor<W>
where W: Clone,

Source§

fn clone(&self) -> LocalCommandExecutor<W>

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl<W> CommandExecutor for LocalCommandExecutor<W>
where W: Workspace,

Source§

fn capabilities(&self) -> CommandExecutorCapabilities

Returns executor capabilities.
Source§

fn execute<'life0, 'life1, 'life2, 'async_trait>( &'life0 self, request: CommandRequest, policy: &'life1 ExecutionPolicy, context: &'life2 RunContext, ) -> Pin<Box<dyn Future<Output = Result<CommandOutput, CommandError>> + Send + 'async_trait>>
where 'life0: 'async_trait, 'life1: 'async_trait, 'life2: 'async_trait, LocalCommandExecutor<W>: 'async_trait,

Executes a command under a harness execution policy.
Source§

impl<W> Debug for LocalCommandExecutor<W>
where W: Debug,

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result<(), Error>

Formats the value using the given formatter. Read more

Auto Trait Implementations§

§

impl<W> Freeze for LocalCommandExecutor<W>
where W: Freeze,

§

impl<W> RefUnwindSafe for LocalCommandExecutor<W>
where W: RefUnwindSafe,

§

impl<W> Send for LocalCommandExecutor<W>
where W: Send,

§

impl<W> Sync for LocalCommandExecutor<W>
where W: Sync,

§

impl<W> Unpin for LocalCommandExecutor<W>
where W: Unpin,

§

impl<W> UnsafeUnpin for LocalCommandExecutor<W>
where W: UnsafeUnpin,

§

impl<W> UnwindSafe for LocalCommandExecutor<W>
where W: UnwindSafe,

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DynClone for T
where T: Clone,

Source§

fn __clone_box(&self, _: Private) -> *mut ()

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more