std/sandbox
Loads .trb files as sandboxed receiver closures - the mechanism behind project.trb and configuration scripts
(see "Receiver Scripts and the Sandbox" in CONCEPT.md, and docs/design/SCRIPTS.md).
A script runs in the VM, always: the step and time limits and the panic that does not end the caller are properties
of an interpreter (docs/design/SCRIPTS.md section 1). A program torb run runs in the VM loads one, from a path it
was compiled with or from any other, and so does a native binary torb build --embed-vm built, which embeds the VM.
A native binary torb build compiled loads one through the front end and the VM it embeds (slice 8): the script
is checked against Value and run in that VM, and the value crosses as text in both directions, through the
derived Encode and Decode of Value, every field included - so a receiver of such a program is
Encode & Decode, which a type of plain settings is by derivation.
Modules
std/sandbox/libLoads.trbfiles as sandboxed receiver closures - the mechanism behindproject.trband configuration scripts (see "Receiver Scripts and the Sandbox" in CONCEPT.md, and docs/design/SCRIPTS.md).
Everything
- extend
Int64The byte unit [SandboxCapabilities.limits] is written in. - type
SandboxSandboxes and type checks.trbfiles against a receiver type. - type
SandboxCapabilitiesWhat a script may do, granted at the call site ofSandbox.load- never in the script or its project file (a script that could grant itself capabilities would not be a sandbox). - type
SandboxErrorWhat went wrong loading a script: a syntax or type error against the receiver type, or a capability it does not have. - type
ScriptA loaded script, ready to run against aValueof the caller's own.