Files
scriptc/scripts/sandbox-command.mjs
Chris Tate 8227a5ad9c Fix Sandbox command transport and pinned native setup (#295)
Build the Linux LLVM helper and runtime pack before running both test lanes, and align native cache contracts with the current target policy. Full managed Sandbox gate passed.
2026-09-12 15:59:01 -05:00

23 lines
869 B
JavaScript

export const MAX_INLINE_SANDBOX_COMMAND_BYTES = 768;
export const shellQuote = (value) => `'${value.replaceAll("'", `'"'"'`)}'`;
/** Keep long shell programs out of the local CLI's argument vector. The
* same script records the remote exit status for either transport. */
export function sandboxCommand(command, args, exitMarker) {
const statusPath = `/tmp/${exitMarker}.status`;
const script =
`${[command, ...args].map(shellQuote).join(" ")}; scriptc_status=$?; ` +
`printf '%s\\n' "$scriptc_status" > ${shellQuote(statusPath)}; ` +
`printf '\\n${exitMarker}%s\\n' "$scriptc_status"`;
const scriptPath = `/tmp/${exitMarker}.sh`;
const file = Buffer.byteLength(script, "utf8") > MAX_INLINE_SANDBOX_COMMAND_BYTES;
return {
script,
scriptPath,
statusPath,
file,
argv: file ? ["sh", scriptPath] : ["sh", "-c", script],
};
}