Expand description
The host-services guest→host seam (plugin-host.md §5) — PH7.4b.
The first call direction into the host: a plugin asks the host to do
something on its behalf, capability-gated against the plugin’s
CapabilityGrant (PH7.2). This is
distinct from the guest’s WASI filesystem view: that view is sandboxed by the
Store’s preopens, so a guest cannot reach outside its grant even if it tries.
A host-services call, by contrast, runs host-side with full host authority
— the host process is not sandboxed — so the grant check is mandatory here,
not delegated to WASI. Enforcing it is the whole point of the seam.
PH7.4b lands one function, [walk_within_grant], the capability-gated
workspace enumeration the fuzzy-finder (PH7.4d) uses to replicate the native
files picker. It reuses the native walker’s policy so a plugin source and a
first-party source enumerate identically. The Host trait impl + linker
wiring live in lib.rs (next to PluginState, which carries the grant); this
module holds the gate + walk logic so it is unit-testable without a Store.
Functions§
- grant_
permits_ read - The same check for a FILE — on the file itself when it exists, on its parent only when it does not.
- grant_
permits_ write grant_permits_read, restricted to the plugin’s writable prefixes.