PUBLIC MODULE · lib/sandbox.js

Sandbox

Sandbox — process ownership primitives. Dispatch owns scope teardown and cancellation policy; tools only spawn through their supplied scope. Worker descendants inherit the worker group so one kill reaches the command tree.

class Sandbox class

Sandbox façade for scoped child processes; dispatch owns teardown.

static osAvailable() method

Is OS write-sandbox enforcement in effect (own mechanism or a detected outer jail)? Probed once per process; no opt-out.

static osKind() method

The OS write-sandbox mechanism in effect: "seatbelt", "bwrap", "delegated" (an outer jail already confines this process; the wrap is a passthrough), or null (no enforcement; Agent forces safe mode).

static osWrap(file, args, cwd, workingDirectory) method

Wrap a program invocation in the OS write sandbox: the [file, argv] to spawn (unchanged when no mechanism applies).

static processStop(child, options) method

Stop a process/group and await closure; safe to call repeatedly.

static scope() method

Create a process scope owned and closed by one tool dispatch.

static spawn(file, args, options) method

Spawn a process using the same ownership policy as scoped calls.