The backend this shell actually executes with: CubeBackendMode.kernel
when commands are OS-wrapped, CubeBackendMode.policy when only the
Dart policy layers run (a plain policy spec, or a kernel spec allowed
to degrade), null in passthrough mode or while a kernel spec is
refused (nothing executes at all). Hosts query this to display/audit
what actually ran.
Called when a backend: kernel spec degrades to policy mode because
no enforcing backend exists for the host — only when the spec opted
in via allowDegrade.
The single error shape every kernel failure surfaces — foreground
execs, the background startup probe and background-job refusals
(kernelStagingError consumers) all render their note through this,
so callers and tests match exactly one prefix.
The command a background job should start for command: unchanged in
policy mode, wrapped in the kernel backend in kernel mode (verifying
and if necessary restaging the profile first — null when staging
failed, see kernelStagingError; the caller must refuse to start the
job). env is the caller's per-exec environment —
threaded into the clean child env so jobs keep session vars and
secrets. The policy check stays with the caller.
One-shot capability probe for backend: kernel background jobs: a
job started through prepare only reports a wrapper failure inside
its job log, so startupFailure runs a wrapped no-op command once
per spec first and yields the clean failure note up front (null =
the wrapper works). Foreground execs skip this — exec maps the
failure from the result directly.
Swaps the enforced spec live; the next exec uses the new policies.
A backend: kernel spec with no enforcing backend for the host
refuses (every command denied, nothing runs) unless the spec opts in
via allowDegrade, in which case it degrades to policy mode and
fires onDegrade.