CubePolicyEngine class final

Evaluates a shell command line against a cube's tool and network policies.

The engine splits the line on shell operators (|, ||, &&, ;, &, newlines), extracts $( ... ) and backtick subshell segments, strips leading VAR=value assignments, and checks every resulting command against CubeSpec.tools. Commands that invoke curl or wget — and gh api <abs-url> — get an additional CubeSpec.network check on the URLs they reference.

Global destruction (rm -rf /) is deliberately not special-cased: the tool allowlist is the mechanism — a cube that does not list rm never runs it.

Constructors

CubePolicyEngine(CubeSpec spec, {String? homeDir, String? workspaceRoot, CubeFsProbe? pathProbe})
Creates an engine evaluating commands against spec.
const

Properties

hashCode → int
The hash code for this object.
no setterinherited
homeDir → String?
The host home directory, resolving ~ redirection targets.
final
pathProbe → CubeFsProbe?
The symlink probe for redirect-target checks; null keeps the lexical traversal check (web hosts, tests without a filesystem).
final
runtimeType → Type
A representation of the runtime type of the object.
no setterinherited
spec → CubeSpec
The cube specification whose policies are enforced.
final
workspaceRoot → String?
The real workspace root, resolving relative redirection targets.
final

Methods

checkCommand(String commandLine) → CubePolicyDecision
Checks every command the commandLine would run.
noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
toString() → String
A string representation of this object.
inherited

Operators

operator ==(Object other) → bool
The equality operator.
inherited