Class TarSandboxedService
- Namespace
- Archiver.Core.Services
- Assembly
- Archiver.Core.dll
Extracts tar-family archives (tar, tar.gz, tar.bz2, tar.xz, tar.zst, tar.lzma, 7z, rar) via the system's tar.exe, launched inside a Windows AppContainer (no network capability) with a Job Object (ActiveProcessLimit = 1, RAM/CPU limits) — see TASKS.md's T-F52 entry for the full design and DECISIONS.md for the empirical trail. Never throws to callers — all errors are captured in ArchiveResult.Errors. Replaces the deleted TarProcessService.
public sealed class TarSandboxedService : ITarService
- Inheritance
-
TarSandboxedService
- Implements
- Inherited Members
Constructors
TarSandboxedService(GroupPolicyOptions)
Creates the service under the given Group Policy (T-F261: required, never defaulted).
public TarSandboxedService(GroupPolicyOptions policy)
Parameters
policyGroupPolicyOptions
Methods
CompressAsync(ArchiveOptions, IProgress<ProgressReport>?, CancellationToken)
Creates a tar-family archive (tar, tar.gz, tar.bz2, tar.xz, tar.zst, tar.lzma) from options.SourcePaths via tar.exe. Unlike ExtractAsync, this never runs the sandboxed AppContainer path — the input is trusted local files the user selected, not an untrusted archive being parsed, so T-F52's threat model (a hostile archive driving libarchive into misbehaving) does not apply here. Never throws — errors are captured in ArchiveResult.Errors. The one exception (T-F260): cancellation throws OperationCanceledException after cleanup.
public Task<ArchiveResult> CompressAsync(ArchiveOptions options, IProgress<ProgressReport>? progress = null, CancellationToken cancellationToken = default)
Parameters
optionsArchiveOptionsprogressIProgress<ProgressReport>cancellationTokenCancellationToken
Returns
DetectCapabilitiesAsync()
Detects which formats the system's tar.exe supports by probing its version output. Returns sensible all-false defaults if tar.exe is absent or the probe fails.
public Task<TarCapabilities> DetectCapabilitiesAsync()
Returns
Remarks
Under DisableTarExtraction the probe never runs and all-false defaults are returned.
ExtractAsync(ExtractOptions, IProgress<ProgressReport>?, CancellationToken)
Extracts one or more tar-family archives (tar, tar.gz, tar.bz2, tar.xz, tar.zst, tar.lzma, 7z, rar) via tar.exe. Never throws — errors are captured in ArchiveResult.Errors. IProgress<ProgressReport> (T-F142 — was IProgress<int>) to match IArchiveService.ExtractAsync's contract, since callers route through the same IExtractionRouter regardless of which service handles the format. Real BytesTransferred/TotalBytes/CurrentFile are only reported for a single-archive extraction (options.ArchivePaths.Count == 1) — matching ZipArchiveService.ExtractAsync's own singleArchive convention — a multi-archive selection still reports percent-only, BytesTransferred/TotalBytes = 0. The one exception to "never throws" (T-F260): cancellation throws OperationCanceledException after cleanup, whether it lands inside one archive or between two.
public Task<ArchiveResult> ExtractAsync(ExtractOptions options, IProgress<ProgressReport>? progress = null, CancellationToken cancellationToken = default)
Parameters
optionsExtractOptionsprogressIProgress<ProgressReport>cancellationTokenCancellationToken
Returns
ListEntriesAsync(string, CancellationToken)
Lists a tar-family archive's entries as a flat list, without extracting. Never throws — a failure (corrupted archive, tar.exe error) is reported via ArchiveListResult.Success/ErrorMessage. Does not run the whole-archive safety pre-scan ScanForUnsafeEntriesAsync performs before extraction — listing must never be gated on a safety check that only matters once bytes are about to be written to disk. Group Policy is a different matter (T-F250): IArchiveListingRouter refuses blocked formats, and this engine refuses to list at all under DisableTarExtraction.
public Task<ArchiveListResult> ListEntriesAsync(string archivePath, CancellationToken cancellationToken = default)
Parameters
archivePathstringcancellationTokenCancellationToken