/** * The agent's hands: ONE bash session over one caller's workspace, in this * process, with no machine anywhere. * * The disk is the caller's own `WorkspaceFs` — the store, wearing just-bash's * `IFileSystem` (build contract §3.2) — so a script reads and writes exactly the * files that person already has, under exactly the mounts §3.1 froze * (`/user`, `/orgs/` rw, `/host` ro). There is no path argument to escape * with and no host disk to reach: a write outside the mounts is `EACCES` from * the filesystem itself, not from a check bolted on here. */ import { type IFileSystem } from "@vendoai/core"; /** One `bash` call's ceilings. Both map onto just-bash's own execution limits; * everything else keeps just-bash's `normal` profile. */ export interface ShellLimits { /** Wall clock for ONE call, in milliseconds. */ maxExecutionTimeMs?: number; /** Total stdout + stderr bytes one call may produce. */ maxOutputBytes?: number; } /** What a turn holds: a shell that keeps its filesystem between calls. */ export interface ShellSession { exec(command: string): Promise<{ stdout: string; stderr: string; exitCode: number; }>; } /** A turn is a person waiting, so the default is the length of a person's * patience rather than just-bash's compatibility-oriented hour. */ export declare const DEFAULT_MAX_EXECUTION_TIME_MS = 30000; /** Generous next to the 32 000-char tool-output cap the bridge applies, because * a script may legitimately produce a lot and pipe it into `tail`; the cap is * what the MODEL sees, this is what the SHELL may make. */ export declare const DEFAULT_MAX_OUTPUT_BYTES = 1000000; /** * One session, one workspace. The interpreter boots on the FIRST call and is * kept: booting it costs a module load, and a turn that runs three commands * should pay that once. */ export declare function createShellSession(opts: { workspace: IFileSystem; limits?: ShellLimits; javascript?: boolean; }): ShellSession; //# sourceMappingURL=engine.d.ts.map