返回 DeepSeek-Reasonix
seatbelt_windows.go
根目录 / internal / sandbox / seatbelt_windows.go
1 //go:build windows
2
3 package sandbox
4
5 // Windows has no OS-level shell sandbox (see OSSandboxSupported), so every
6 // launch runs unwrapped as the current OS user.
7
8 // Command returns the shell invocation unwrapped.
9 func Command(_ Spec, sh Shell, command string) ([]string, bool) {
10 return sh.argv(command), false
11 }
12
13 // CommandArgs returns the raw argv unwrapped.
14 func CommandArgs(_ Spec, args []string) ([]string, bool) {
15 return args, false
16 }
17
18 // Available is always false on Windows.
19 func Available() bool { return false }
20
21 // writableDirsForSpec is empty: no Windows backend confines writes, so there
22 // is no boundary for Git metadata protection to sit inside.
23 func writableDirsForSpec(Spec) []string { return nil }
24
25 func gitMetadataRoots(spec Spec) []string { return spec.WriteRoots }
26
27 // HostWritableDirs is empty: Windows runs commands unjailed, so nothing here
28 // narrows where a command may write.
29 func HostWritableDirs() []string { return nil }
30
30 lines GO