CubeSpec class final
A parsed cube manifest: identity plus the five policy sections.
Constructors
- CubeSpec({required String name, String? description, CubeBackendMode backend = CubeBackendMode.policy, bool allowDegrade = false, CubeToolPolicy tools = const CubeToolPolicy(), CubeNetworkPolicy network = const CubeNetworkPolicy(), CubeFsPolicy filesystem = const CubeFsPolicy(), CubeEnvPolicy env = const CubeEnvPolicy(), CubeResourceLimits resources = const CubeResourceLimits(), CubeCachePolicy cache = const CubeCachePolicy()})
-
Creates a spec; policies default to their safe values.
const
- CubeSpec.fromYaml(Object? node, {String sourcePath = 'cube'})
-
Parses a whole cube yaml document.
sourcePathnames the document in error messages (default'cube').factory
Properties
- allowDegrade → bool
-
Whether an unavailable
backend: kernelmay degrade to policy mode. Requested isolation is a contract: without this opt-in a kernel spec on a platform without an enforcing backend is REFUSED (zero commands run); with it the shell degrades loudly (onDegrade) and reports the effective backend for audit.final - backend → CubeBackendMode
-
How commands are confined — Dart policy layers only, or wrapped in
the host platform's kernel sandbox.
final
- cache → CubeCachePolicy
-
Cache behavior.
final
- description → String?
-
Optional human-readable description.
final
- env → CubeEnvPolicy
-
Which environment variables the run sees.
final
- filesystem → CubeFsPolicy
-
Which paths may be read or written.
final
- hashCode → int
-
The hash code for this object.
no setterinherited
- name → String
-
Cube name,
^[a-z][a-z0-9-]*$(enforced at parse).final - network → CubeNetworkPolicy
-
Which hosts/ports may be reached.
final
- resources → CubeResourceLimits
-
Resource caps and timeout.
final
- runtimeType → Type
-
A representation of the runtime type of the object.
no setterinherited
- tools → CubeToolPolicy
-
Which command words may run.
final
Methods
-
noSuchMethod(
Invocation invocation) → dynamic -
Invoked when a nonexistent method or property is accessed.
inherited
-
toCanonicalMap(
) → Map< String, Object?> -
A stable, JSON-encodable canonical form of the whole spec: keys sorted
at every level, lists sorted (semantically orderless), durations as
seconds,
nullfields omitted. Two specs that parse to the same policy always produce an equal map — this is the content-addressed cache key input. -
toString(
) → String -
A string representation of this object.
inherited
-
withAllowDegrade(
{bool allowDegrade = true}) → CubeSpec -
A copy of this spec with
allowDegradeset — the/cube use --allow-degradeopt-in path (SEC-05: degrade only via explicit opt-in, never silently).
Operators
-
operator ==(
Object other) → bool -
The equality operator.
inherited