/** * Shared types and constants for the pi-sandbox extension. */ /** Filesystem layout inside the sandbox container. */ export const FS = { /** Host project mounted read-only. */ workspace: "/workspace", /** Writable ephemeral export boundary. */ output: "/output", /** Unprivileged sandbox user. */ user: "sandbox", /** Default shell. */ shell: "/bin/sh", } as const; /** Default sandbox image tag. */ export const IMAGE_TAG = "pi-sandbox:debian-slim"; /** Default execution timeout in seconds. */ export const DEFAULT_TIMEOUT_SECONDS = 120; /** Upper bound the caller may request for timeout_seconds. */ export const MAX_TIMEOUT_SECONDS = 3600; /** Resource limits passed to the container. */ export const RESOURCE_LIMITS = { /** Memory limit (bytes). */ memoryBytes: 2 * 1024 * 1024 * 1024, // 2 GiB /** CPU limit (shares, 0 = default). */ cpus: 2, /** Max number of processes (pids). */ pids: 512, } as const; /** Maximum total artifact bytes copied out of /output in one run. */ export const MAX_ARTIFACT_BYTES = 50 * 1024 * 1024; // 50 MiB /** Maximum number of artifacts accepted in one run. */ export const MAX_ARTIFACTS = 20; /** Shell-mode parameter key. */ export const COMMAND_KEY = "command"; /** Argv-mode executable key. */ export const EXECUTABLE_KEY = "executable"; /** A single artifact destination (host path after export). */ export interface ExportedArtifact { /** Relative path under /output the caller requested (normalized). */ requested: string; /** Absolute guest path it was copied from. */ guestPath: string; /** Absolute host path where the artifact was written. */ hostPath: string; /** Size in bytes. */ bytes: number; } /** Result details returned by the sandbox_run tool. */ export interface SandboxRunDetails { /** Exit code of the command (null if killed). */ exitCode: number | null; /** True if the run was terminated by the timeout. */ timedOut: boolean; /** True if the run was cancelled via the AbortSignal. */ cancelled: boolean; /** Wall-clock duration in milliseconds. */ durationMs: number; /** Container id that executed the run. */ containerId: string; /** Whether networking was enabled for this run. */ networkEnabled: boolean; /** Whether a privileged setup phase ran. */ setupRan: boolean; /** True if stdout was truncated before returning. */ stdoutTruncated: boolean; /** True if stderr was truncated before returning. */ stderrTruncated: boolean; /** Host path of the full stdout file, if stdout was truncated. */ stdoutPath?: string; /** Host path of the full stderr file, if stderr was truncated. */ stderrPath?: string; /** Artifacts exported from /output, if any. */ artifacts: ExportedArtifact[]; }