LinuxUnshareBackend class final

The Linux backend: unshare argv generation plus command wrapping.

Implemented types

Constructors

LinuxUnshareBackend({CubeSpec spec = const CubeSpec(name: 'host'), String workspaceRoot = '/workspace', String tmpdir = '/tmp', Map<String, String> envVars = const {}})
Creates the backend bound to a run's context. The spec drives the mount/limit preamble and the --net decision; the defaults exist for bare display/backends-picked-outside-a-run.
const

Properties

enforces → bool
Whether this backend actually confines at the OS level. false means wrapCommand is a passthrough and kernel mode degrades to the Dart policy layers.
no setteroverride
envVars → Map<String, String>
The cube's injected environment variables (hidden vars excluded).
final
hashCode → int
The hash code for this object.
no setterinherited
runtimeType → Type
A representation of the runtime type of the object.
no setterinherited
spec → CubeSpec
The cube spec whose mounts, limits and network policy apply.
final
tmpdir → String
Writable scratch directory handed to the child as TMPDIR.
final
workspaceRoot → String
The real writable root (the env cwd) — HOME inside the sandbox.
final

Methods

buildProfile(CubeSpec spec, {required String workspaceRoot}) → String
The profile content for spec. workspaceRoot is the real writable root (the env cwd); the cube's /workspace is realized as that cwd.
override
buildUnshareArgv(CubeSpec spec, {String? workspaceRoot}) → List<String>
Builds the unshare argv for spec; the cube's command is appended after the trailing -- at activation time. --net is included only when the spec allows no network at all.
describe() → String
override
noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
toString() → String
A string representation of this object.
inherited
wrapCommand(String command, {required String profilePath, Map<String, String> env = const {}}) → String
Wraps command so it runs inside the OS sandbox. profilePath names the content-verified profile file staged by the shell (<home>/.fah/cube-profiles/); implementations that confine by other means may ignore it. env carries the caller's per-exec environment (ShellExecOptions.env): kernel wrapping must thread it into the clean child environment or session vars and secrets are silently dropped — entries override the backend's cube-bound vars. Implementations that change nothing may ignore it too.
override

Operators

operator ==(Object other) → bool
The equality operator.
inherited