| 1 | package plugin |
| 2 | |
| 3 | import ( |
| 4 | "fmt" |
| 5 | |
| 6 | "reasonix/internal/sandbox" |
| 7 | ) |
| 8 | |
| 9 | // wrapConfinedCommand applies the OS command sandbox for a confined MCP |
| 10 | // process and fails closed when the backend is unavailable: a confined |
| 11 | // process must never run unsandboxed. commandArgs is injectable for tests. |
| 12 | func wrapConfinedCommand(name string, spec sandbox.Spec, launchArgs []string, commandArgs func(sandbox.Spec, []string) ([]string, bool)) ([]string, error) { |
| 13 | argv, wrapped := commandArgs(spec, launchArgs) |
| 14 | if spec.Enforce() && !wrapped { |
| 15 | return nil, fmt.Errorf("stdio plugin %q: confined process requires an available sandbox backend", name) |
| 16 | } |
| 17 | return argv, nil |
| 18 | } |
| 19 |