CubeSpec class final

A parsed cube manifest: identity plus the five policy sections.

Constructors

CubeSpec({required String name, String? description, CubeBackendMode backend = CubeBackendMode.policy, bool allowDegrade = false, CubeToolPolicy tools = const CubeToolPolicy(), CubeNetworkPolicy network = const CubeNetworkPolicy(), CubeFsPolicy filesystem = const CubeFsPolicy(), CubeEnvPolicy env = const CubeEnvPolicy(), CubeResourceLimits resources = const CubeResourceLimits(), CubeCachePolicy cache = const CubeCachePolicy()})
Creates a spec; policies default to their safe values.
const
CubeSpec.fromYaml(Object? node, {String sourcePath = 'cube'})
Parses a whole cube yaml document. sourcePath names the document in error messages (default 'cube').
factory

Properties

allowDegrade → bool
Whether an unavailable backend: kernel may degrade to policy mode. Requested isolation is a contract: without this opt-in a kernel spec on a platform without an enforcing backend is REFUSED (zero commands run); with it the shell degrades loudly (onDegrade) and reports the effective backend for audit.
final
backend → CubeBackendMode
How commands are confined — Dart policy layers only, or wrapped in the host platform's kernel sandbox.
final
cache → CubeCachePolicy
Cache behavior.
final
description → String?
Optional human-readable description.
final
env → CubeEnvPolicy
Which environment variables the run sees.
final
filesystem → CubeFsPolicy
Which paths may be read or written.
final
hashCode → int
The hash code for this object.
no setterinherited
name → String
Cube name, ^[a-z][a-z0-9-]*$ (enforced at parse).
final
network → CubeNetworkPolicy
Which hosts/ports may be reached.
final
resources → CubeResourceLimits
Resource caps and timeout.
final
runtimeType → Type
A representation of the runtime type of the object.
no setterinherited
tools → CubeToolPolicy
Which command words may run.
final

Methods

noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
toCanonicalMap() → Map<String, Object?>
A stable, JSON-encodable canonical form of the whole spec: keys sorted at every level, lists sorted (semantically orderless), durations as seconds, null fields omitted. Two specs that parse to the same policy always produce an equal map — this is the content-addressed cache key input.
toString() → String
A string representation of this object.
inherited
withAllowDegrade({bool allowDegrade = true}) → CubeSpec
A copy of this spec with allowDegrade set — the /cube use --allow-degrade opt-in path (SEC-05: degrade only via explicit opt-in, never silently).

Operators

operator ==(Object other) → bool
The equality operator.
inherited