Expand description
Trust tiers, grant computation, and the per-plugin WASI view.
Design fragment: docs/dev/architecture/plugin-host.md §6. Slice: PH7.2.
The pipeline is: manifest (request) + trust tier → grant (effective) →
WASI view (enforcement). The manifest (crate::manifest) is what a
plugin asks for; the CapabilityGrant is what it gets after the trust
tier filters the request; the [wasmtime_wasi::WasiCtx] is how the grant is
enforced — a plugin’s Store is built with exactly its granted
filesystem preopens, so a path outside the grant is unreachable at the WASI
layer (WASI has no ambient authority: only preopened dirs exist). That is
the “denied at the WASI layer, not by discipline” property the PH7.2 exit
names.
Scope of WASI enforcement at PH7.2 = filesystem only. net:http and
proc:spawn are carried on the grant as metadata but are not wired into
the WASI view here: raw WASI sockets/subprocess would be a broader grant
than intended. Network and process access are serviced by capability-gated
host-services calls (PH7.3+), which check the grant’s allowlist — so the
grant is the single source of truth both layers read. Enabling raw TCP for
a net:http grant would leak authority the host-services check exists to
contain, so build_wasi_ctx deliberately leaves sockets disabled.
Structs§
- Capability
Grant - The effective capabilities a plugin is granted — the request filtered by its trust tier. This, not the manifest, is what the runtime enforces.
- FsGrant
- A single granted filesystem prefix and its write bit.
- Grant
Outcome - The result of computing a grant: the effective
CapabilityGrantplus the requested capabilities that were denied by the trust tier, so the host can surface a “loaded with reduced function” notification (fragment §6 UX; the four-artefact graceful-error clause). - Preopen
Spec - A resolved directory preopen: which host dir maps to which guest path, and
whether it is writable. The mapping between a
CapabilityGrantand the WASI view, exposed as data so it is unit-testable without a live guest (PH7.2 proves enforcement at this layer; the guest-level end-to-end proof lands at PH7.4 with the realwasm32-wasip2fuzzy-finder).
Enums§
- Trust
Tier - How much the editor trusts a plugin — decides which requested capabilities become grants. A plugin cannot self-declare this (it is not a manifest field); the host determines it from install provenance.
Constants§
- DATA_
DIR_ GUEST_ MOUNT - The guest path the per-plugin data dir is mounted at. A plugin always has a
private, writable scratch dir here regardless of any
fs:*grant.
Functions§
- build_
wasi_ ctx - Build the [
WasiCtx] enforcinggrantfor a plugin whose data dir isdata_dir. Only filesystem preopens are wired (see the module note); sockets and subprocess spawning stay disabled at the WASI layer. - grant
- Compute the effective grant for
manifestundertier.