8376f56ab4
Adds native sandbox execution runtime, dynamic review middleware, and workspace file handling, with supporting stream events, prompt, and scope registry changes plus architecture docs.
29 lines
740 B
Python
29 lines
740 B
Python
"""Apply process resource limits before entering the native sandbox runtime."""
|
|
|
|
from __future__ import annotations
|
|
|
|
import os
|
|
import resource
|
|
import sys
|
|
|
|
|
|
def main() -> None:
|
|
if len(sys.argv) < 4 or sys.argv[2] != "--":
|
|
raise SystemExit("usage: sandbox_exec_helper.py FILE_SIZE -- COMMAND [ARG ...]")
|
|
|
|
try:
|
|
file_size = int(sys.argv[1])
|
|
except ValueError as exc:
|
|
raise SystemExit("FILE_SIZE must be an integer") from exc
|
|
if file_size < 1:
|
|
raise SystemExit("FILE_SIZE must be positive")
|
|
|
|
resource.setrlimit(resource.RLIMIT_FSIZE, (file_size, file_size))
|
|
os.umask(0o077)
|
|
command = sys.argv[3:]
|
|
os.execvpe(command[0], command, os.environ)
|
|
|
|
|
|
if __name__ == "__main__":
|
|
main()
|