LinuxUnshareBackend class final
The Linux backend: unshare argv generation plus command wrapping.
- Implemented types
Constructors
-
Creates the backend bound to a run's context. The spec drives the
mount/limit preamble and the
--netdecision; the defaults exist for bare display/backends-picked-outside-a-run.const
Properties
- enforces → bool
-
Whether this backend actually confines at the OS level.
falsemeans wrapCommand is a passthrough and kernel mode degrades to the Dart policy layers.no setteroverride -
envVars
→ Map<
String, String> -
The cube's injected environment variables (hidden vars excluded).
final
- hashCode → int
-
The hash code for this object.
no setterinherited
- runtimeType → Type
-
A representation of the runtime type of the object.
no setterinherited
- spec → CubeSpec
-
The cube spec whose mounts, limits and network policy apply.
final
- tmpdir → String
-
Writable scratch directory handed to the child as
TMPDIR.final - workspaceRoot → String
-
The real writable root (the env cwd) —
HOMEinside the sandbox.final
Methods
-
buildProfile(
CubeSpec spec, {required String workspaceRoot}) → String -
The profile content for
spec.workspaceRootis the real writable root (the env cwd); the cube's/workspaceis realized as that cwd.override -
Builds the
unshareargv forspec; the cube's command is appended after the trailing--at activation time.--netis included only when the spec allows no network at all. -
describe(
) → String -
override
-
noSuchMethod(
Invocation invocation) → dynamic -
Invoked when a nonexistent method or property is accessed.
inherited
-
toString(
) → String -
A string representation of this object.
inherited
-
wrapCommand(
String command, {required String profilePath, Map< String, String> env = const {}}) → String -
Wraps
commandso it runs inside the OS sandbox.profilePathnames the content-verified profile file staged by the shell (<home>/.fah/cube-profiles/); implementations that confine by other means may ignore it.envcarries the caller's per-exec environment (ShellExecOptions.env): kernel wrapping must thread it into the clean child environment or session vars and secrets are silently dropped — entries override the backend's cube-bound vars. Implementations that change nothing may ignore it too.override
Operators
-
operator ==(
Object other) → bool -
The equality operator.
inherited