Expand description
Plugin host — the WASM Component Model extension substrate (Phase 7).
Design fragment: docs/dev/architecture/plugin-host.md. Slice plan:
docs/dev/operations/slice-plans/plugin-host.md. Spec: design.md §5.5.
PH7.1a — async runtime core. The host now runs the canonical async
ABI (design.md §5.5, fragment §3): the engine has async_support, so a
plugin’s lifecycle exports are async and a host call suspends the WASM
stack rather than pinning an OS thread. Each call runs under two hard
budgets — a fuel cap (total work) and an epoch deadline
(wall-clock) — and either, on exhaustion, traps cleanly: the offending
call returns a typed PluginHostError::Trap, the [Store] is untouched
by any other plugin, and the host stays live. A background epoch-ticker
thread bumps the engine epoch so the wall-clock deadline actually fires.
The lib owns no async runtime: methods are async fn, so the caller
(the editor’s multi-thread pool — never the current_thread actor)
drives them. Running two plugins on two tasks runs them on two cores.
PH7.1b — module cache + lazy instantiation. The AOT (Cranelift) compile
of a component is cached on disk (via wasmtime’s own cache, keyed on bytes +
compiler config + target + wasmtime version), so a second launch reuses the
cached module instead of recompiling. Lazy instantiation is structural
here, not a new type: PluginHost::compile loads/caches a Component
without instantiating it; the [Store] and instance are created only by an
explicit PluginHost::instantiate call. When the contribution model lands
(PH7.3+), that call is what a plugin’s first contribution invocation will
trigger.
PH7.2 — capability & security model. Each plugin now instantiates
under a CapabilityGrant computed from its PluginManifest and
TrustTier (fragment §6). The grant is enforced, not advisory: each
[Store]’s WASI view is built with exactly its granted filesystem preopens
plus a private per-plugin data dir, so a plugin without an fs:write grant
cannot reach a path outside its data dir at the WASI layer (WASI has no
ambient authority). net:http / proc:spawn ride the grant as metadata for
the capability-gated host-services seam (PH7.3+); they are deliberately
not wired into the raw WASI view (see capability). The host also
issues each plugin a monotonic PluginId and stamps
SourceLayer::Plugin provenance from its own ground truth — a plugin
cannot forge provenance (lattice_grammar::source has no public
SourceLocation setter). See manifest and capability.
The end-to-end “a guest attempts a write and WASI denies it” proof lands at
PH7.4 with the real wasm32-wasip2 fuzzy-finder (the guest toolchain PH7.0
deferred to that slice); PH7.2 proves the model at the host layer — grant
computation, the grant→preopen mapping, provenance issuance — with the
WASI-layer OS enforcement itself resting on wasmtime’s tested guarantee.
Still owned by later slices: every contribution seam (PH7.3+). The first
consumer of the plugin lifecycle world is the user’s init.rs; the no-op
component the tests instantiate is the degenerate init.rs.
Re-exports§
pub use crate::media_source::WasmMediaSource;pub use crate::scanned_excerpt_source::WasmScannedExcerptSource;pub use crate::scanned_excerpt_source::normalise_extensions;pub use crate::effect_authorizer::EffectAuthorizer;pub use boundary::WitBoundary;pub use capability::CapabilityGrant;pub use capability::FsGrant;pub use capability::GrantOutcome;pub use capability::PreopenSpec;pub use capability::TrustTier;pub use capability::build_wasi_ctx;pub use capability::grant;pub use completion_source::WasmCompletionSource;pub use completion_task::CompletionActor;pub use completion_task::CompletionClient;pub use context_source::WasmContextSource;pub use context_task::ContextActor;pub use context_task::ContextClient;pub use decoration_source::WasmDecorationSource;pub use decoration_task::DecorationActor;pub use decoration_task::DecorationClient;pub use manifest::Capability;pub use manifest::CapabilityParseError;pub use manifest::ManifestError;pub use manifest::PluginManifest;pub use manifest::PluginSeam;pub use picker_source::WasmPickerSource;pub use picker_task::PickerActor;pub use picker_task::PickerClient;pub use teardown::PluginTeardown;pub use teardown::TeardownRegistries;pub use teardown::TeardownReport;pub use trace::Direction;pub use trace::HotGate;pub use trace::PluginTracePushed;pub use trace::PluginTraceRecord;pub use trace::PluginTracer;pub use trace::PluginTracerHandle;pub use trace::TraceLevel;pub use trace::TraceOutcome;pub use transient_source::project_transient_context;pub use transient_source::spec_from_wit;pub use transient_source::transient_builder;pub use transient_task::TransientActor;pub use transient_task::TransientClient;pub use wake::Sleeper;pub use wake::SleeperHandle;
Modules§
- boundary
- The boundary adapter machinery (plugin-host.md §4).
- boundary_
app_ effect WitBoundarymirror forAppEffect(plugin-host.md §4.4, PH7.3b2).- boundary_
config - TC.3 — the config schema / value boundary: arena on the wire, tree in the host.
- boundary_
context - The sticky-context boundary conversions (treesitter-context.md, TC.2).
- boundary_
decoration - The decoration/ui boundary conversions (plugin-host.md §5
decorations/ui, PH7.9a). - boundary_
effect WitBoundarymirrors for theEffectpayload types (plugin-host.md §4.4).- boundary_
event - The event/hook boundary conversions (plugin-host.md §5
events, PH7.8a). - boundary_
grammar - The grammar-extension boundary conversions (plugin-host.md §4.1, PH7.7a).
- boundary_
picker - The picker-source boundary mirrors (plugin-host.md §4.2 / §5
picker-source). - buffer
- The
documentresource backing + thebuffer-snapshotprojection (plugin-host.md §4.2 / §9.6, PH7.3c). - capability
- Trust tiers, grant computation, and the per-plugin WASI view.
- completion_
host - The completion-source guest world (PH7.6).
- completion_
source - PH7.6 — the
WasmCompletionSourceadapter (the async-produce path). - completion_
task - PH7.6 — the per-plugin actor bridge for completion sources.
- config_
host - The
configguest→host option-declaration seam (PH7.10). - context_
host - The context-provider guest world (TC.2).
- context_
source - TC.2 — the
WasmContextSourceadapter (the async-produce path). - context_
task - TC.2 — the per-plugin actor bridge for sticky-context providers.
- dashboard_
host - CR.4: the
dashboardguest→host section seam. Thedashboardguest→host section seam (CR.4). - decoration_
host - The decoration-provider guest world (PH7.9b).
- decoration_
source - PH7.9c — the
WasmDecorationSourceadapter (the async-produce path). - decoration_
task - PH7.9b — the per-plugin actor bridge for decoration providers.
- effect_
authorizer - XF.4 — authorising a guest-returned effect’s file paths.
- error_
parser_ host - CM.6: the host side of the plugin-contributed compilation-parser seam.
- event_
task - PH7.8c — the per-plugin event-delivery actor + bus wiring.
- events_
host - The event/hook guest world (PH7.8b).
- grammar_
host - The grammar-extension guest world (PH7.7b).
- grammar_
trampoline - The sync grammar trampoline + registry wiring (plugin-host.md §4.1, PH7.7c).
- help_
host - CR.3: the
helpguest→host topic-registration seam. Thehelpguest→host topic-registration seam (CR.3). - host_
services - The
host-servicesguest→host seam (plugin-host.md §5) — PH7.4b. - keymap_
host - The
keymapguest→host binding-registration seam (PL8.D.1). - language_
host - The
languageguest→host registration seam (LG.3c). - lattice
- manifest
- The plugin manifest — a plugin’s declared capability request.
- media_
host - IM.6b — the inline-media provider guest world.
- media_
source - IM.6b — the
WasmMediaSourceadapter. - media_
task - IM.6b — the per-plugin actor bridge for inline-media providers.
- mode_
host - The
modesguest→host mode-declaration seam (PH7.11a). - multibuffer_
view_ host - MV.1 — the multibuffer-view guest world.
- multibuffer_
view_ task - MV.1 — the per-plugin actor bridge for multibuffer-view sources.
- picker_
host - The picker-source guest world (PH7.4c.1a).
- picker_
source - PH7.4c.2 — the
WasmPickerSourcehost adapter (the create path). - picker_
task - PH7.4c.1b — the per-plugin actor task + call protocol (the bridge).
- plugin_
manager_ host - PM.7: the host side of the
requireseam. - plugin_
store - OR.1 — durable, plugin-scoped key/value storage for guests.
- scan_
cache - OT.3b — agenda scan results, remembered across restarts.
- scan_
host - OM.A1 — the scanned-excerpt-source guest world.
- scan_
task - OM.A1 — the per-plugin actor bridge for scanned-excerpt-source providers.
- scanned_
excerpt_ source - OM.A1 — the
WasmScannedExcerptSourceadapter. - sign_
host - The
signsguest→host sign-declaration seam (SG.3a). - teardown
- Plugin teardown — reversing every contribution a plugin made (PH7.12b.3).
- theme_
host - The
themeguest→host element-declaration seam (TC.4). - trace
- PO.1 — the plugin boundary-trace substrate (Layer 1 of the observability
stack, design fragment
docs/dev/architecture/plugin-observability.md). - trampoline
- The §4.1 trampoline + §4.3 result-carrier (plugin-host.md, PH7.3d).
- transient_
host - TR.2b — the transient-source guest world.
- transient_
source - TR.2b — the
WasmTransientSourceadapter (boundary + registry builder). - transient_
task - TR.2b — the per-plugin actor bridge for transient-source providers.
- tree_
resource - TS.1 host backing for the
tree-snapshot/nodeWIT resources (plugin-treesitter-seam.md §3). The host owns the parse tree; a plugin gets read-only handles and calls back for the structure it needs — the tree never crosses the boundary (thedocument-handle model, applied to structure). - ui_host
- The
uiguest→host contribution seam (OC.3 / ML.6) — a plugin-owned modeline element. - wake
- OC.2 — the periodic wake seam:
wake-every/cancel-wake/on-wake.
Structs§
- Component
- The compiled component — the return type of
PluginHost::compile, re-exported so callers (the plugin loader) can name it without a directwasmtimedependency. A compiled WebAssembly Component. - Loaded
Plugin - A live plugin instance: its
Store(holding the scoped WASI view), the lifecycle bindings, the per-call budget, its host-issued identity and effective grant. Dropping it tears theStoredown (the reload/teardown seam PH7.12 formalises). - Plugin
- Auto-generated bindings for an instance a component which
implements the world
plugin. - Plugin
Budget - Per-call resource budget. Both limits are hard: whichever is hit first traps the call cleanly.
- Plugin
Host - The wasmtime engine, the (import-free) component linker, the on-disk module cache, and the epoch ticker. One host per editor process; construct it once (the engine owns Cranelift).
- Plugin
Id - A host-issued plugin identity. Monotonic, allocated by the
PluginHostat instantiation — never supplied by the guest. It is theu32insideSourceLayer::Plugin, so every contribution a plugin registers (PH7.3+) traces back to a provenance the guest cannot forge. - Plugin
Indices - Auto-generated bindings for index of the exports of
plugin. - Plugin
Pre - Auto-generated bindings for a pre-instantiated version of a
component which implements the world
plugin.
Enums§
- Plugin
Host Error - Typed error surface for the plugin host. No host path panics — every
failure mode is a value here (the four-artefact graceful-error clause).
anyhow::Erroris wasmtime’s error type; each variant carries it as#[source]. - Trap
Kind - Why a lifecycle call trapped. Fuel/epoch are the expected runaway-guard
outcomes;
Otheris any genuine wasm trap (unreachable, OOB, a guest panic).
Functions§
- data_
dir_ base_ from - The pure resolver behind [
default_data_dir_base], split out so the layout is testable without touching the process environment. - legacy_
data_ dir_ base - The pre-2026-09-22 data-dir base,
dirs::data_dir()/lattice/plugins/. Read once at boot bymigrate_plugin_data; nothing else should use it. - migrate_
cache_ dirs - Carry the module cache under the config home, once. Returns whether anything moved. A cache that cannot be moved is simply rebuilt.
- migrate_
plugin_ data - Move each
<old>/<name>/datadirectory to<new>/<name>/data, returning how many moved. Idempotent, and safe to call whenolddoes not exist.
Type Aliases§
- Active
Buffer Snapshot - Annotation
- AppEffect
- Applied
Edit - ArgDefault
- ArgKind
- ArgSpec
- ArgValue
- Args
- Buffer
Entry - Buffer
Snapshot - Candidate
Data - Candidate
Kind - Decoration
Context - Echo
Level - Edit
- Edit
Delta - Edit
Kind - Effect
- Event
- Event
Filter - Event
Kind - Gutter
Decoration - Gutter
Diff Kind - Gutter
Severity Level - Hscroll
- KeyChord
- KeyKind
- LspRequest
- Modal
State - Open
Target - Pane
Direction - Picker
Accept Outcome - Picker
Context - Picker
Source Spec - Position
- Position
Entry - Position
Source - Quit
Scope - Range
- RawCandidate
- Register
- Routing
Payload - Scroll
Pos - Search
Direction - Selection
- Selection
Set - Special
Key - Substitute
Scope - Transient
Context - Transient
Spec - UiNotification
- UiZone
- Utf16
Pos - Viewport
Pos - Visual
Kind - Visual
Mode - Yank
Kind