sandboxExecOptions function

ShellExecOptions sandboxExecOptions(
  1. CubeSpec spec,
  2. ShellExecOptions? options
)

A Shell whose commands are gated by a cube's policies. Builds the forwarded options for a permitted command under spec: the timeout clamped to the cube's CubeResourceLimits.timeout (the smaller of caller and cube wins; a null caller inherits the cube's), plus the cube's injected env vars.

The env merge is additive only — ShellExecOptions.env cannot strip variables the process already inherited; full environment cleanliness is kernel-backend territory (Phase 2+).

Implementation

/// Builds the forwarded options for a permitted command under [spec]:
/// the timeout clamped to the cube's [CubeResourceLimits.timeout] (the
/// smaller of caller and cube wins; a null caller inherits the cube's),
/// plus the cube's injected env vars.
///
/// The env merge is additive only — [ShellExecOptions.env] cannot strip
/// variables the process already inherited; full environment cleanliness
/// is kernel-backend territory (Phase 2+).
ShellExecOptions sandboxExecOptions(CubeSpec spec, ShellExecOptions? options) {
  var timeout = options?.timeout;
  final cubeTimeout = spec.resources.timeout;
  if (cubeTimeout != null && (timeout == null || cubeTimeout < timeout)) {
    timeout = cubeTimeout;
  }
  final injected = spec.env.isEmpty
      ? const <String, String>{}
      : spec.env.apply(const {});
  final unchanged = injected.isEmpty && timeout == options?.timeout;
  if (unchanged) return options ?? const ShellExecOptions();
  return ShellExecOptions(
    cwd: options?.cwd,
    env: injected.isEmpty ? options?.env : {...injected, ...?options?.env},
    timeout: timeout,
    cancelToken: options?.cancelToken,
    onStdout: options?.onStdout,
    onStderr: options?.onStderr,
    stdinData: options?.stdinData,
    jobLogMaxBytes: options?.jobLogMaxBytes,
    onJobLogWarning: options?.onJobLogWarning,
    jobLogRedactor: options?.jobLogRedactor,
  );
}