CubePolicyEngine class final
Evaluates a shell command line against a cube's tool and network policies.
The engine splits the line on shell operators (|, ||, &&, ;, &,
newlines), extracts $( ... ) and backtick subshell segments, strips
leading VAR=value assignments, and checks every resulting command
against CubeSpec.tools. Commands that invoke curl or wget — and
gh api <abs-url> — get an additional CubeSpec.network check on the
URLs they reference.
Global destruction (rm -rf /) is deliberately not special-cased: the
tool allowlist is the mechanism — a cube that does not list rm never
runs it.
Constructors
- CubePolicyEngine(CubeSpec spec, {String? homeDir, String? workspaceRoot, CubeFsProbe? pathProbe})
-
Creates an engine evaluating commands against
spec.const
Properties
- hashCode → int
-
The hash code for this object.
no setterinherited
- homeDir → String?
-
The host home directory, resolving
~redirection targets.final - pathProbe → CubeFsProbe?
-
The symlink probe for redirect-target checks;
nullkeeps the lexical traversal check (web hosts, tests without a filesystem).final - runtimeType → Type
-
A representation of the runtime type of the object.
no setterinherited
- spec → CubeSpec
-
The cube specification whose policies are enforced.
final
- workspaceRoot → String?
-
The real workspace root, resolving relative redirection targets.
final
Methods
-
checkCommand(
String commandLine) → CubePolicyDecision -
Checks every command the
commandLinewould run. -
noSuchMethod(
Invocation invocation) → dynamic -
Invoked when a nonexistent method or property is accessed.
inherited
-
toString(
) → String -
A string representation of this object.
inherited
Operators
-
operator ==(
Object other) → bool -
The equality operator.
inherited