pub fn build_wasi_ctx(grant: &CapabilityGrant, data_dir: &Path) -> WasiCtxExpand description
Build the [WasiCtx] enforcing grant for a plugin whose data dir is
data_dir. Only filesystem preopens are wired (see the module note);
sockets and subprocess spawning stay disabled at the WASI layer.
Graceful degradation: a granted prefix that cannot be opened (missing
dir, permission error) is skipped with a warn!, never a panic or a failed
load — the plugin runs with that one capability degraded (fragment §6). The
caller must have created data_dir before this runs (the host does).