ProtectedinitializedBacking flag for isInitialized.
Subclasses own this flag: set it in initialize and clear it in close.
Whether the environment has been initialized.
The absolute path to the environment's working directory.
ProtectedassertThrows if initialize has not been called.
Implementations should call this at the start of every operation that needs a live working directory.
Releases resources held by the environment.
The default implementation is a no-op. Subclasses must be idempotent and must clear initialized.
Executes a shell command in the working directory.
The shell command string to execute.
OptionaltimeoutSeconds: numberMaximum execution time in seconds. undefined means
no limit.
The exit code, stdout, stderr, and timeout status. A non-zero exit code is reported in the result, not thrown.
Initializes the environment (e.g. creates the working directory).
Called before first use. The default implementation is a no-op and leaves
isInitialized false. Subclasses must be idempotent and must set
initialized.
Reads a file from the working directory.
filePath is confined to the working directory by a lexical check on the
resolved path, which is not a sandbox.
Writes a file in the working directory, creating parent directories.
filePath is confined to the working directory by a lexical check on the
resolved path, which is not a sandbox. No newline translation is applied,
so explicit CRLF sequences are preserved.
Executes commands via local child processes, scoped to a working directory.
When
workingDiris not specified, a temporary directory is created on initialize and removed on close.WARNING: this class runs arbitrary shell strings on the host with no sandboxing and no sanitisation — the caller is responsible for trusting the command. It is a building block; tools built on top of it are responsible for gating execution behind an explicit user confirmation.
Further limitations, all shared with the adk-python reference implementation:
process.env, so any secret in the parent environment is visible to the command.SIGKILLto the spawned shell; processes it forked itself may survive, and anything they write after the kill is not captured. On Windows such a survivor also keeps the working directory locked, so a close following a timeout can fail to remove a temporary workspace.