Skip to main content

Module host

Module host 

Source
Expand description

Host-function and prelude registration for the Submilli runtime.

Structs§

Denial
A denial the runtime threw that escaped the program, as the embedder sees it.
FatalHostError
A broken host invariant or exhausted host allocation must terminate the run, rather than becoming an exception that guest code can catch and ignore. Reaching the memory cap terminates it too, under its own name: see is_memory_exhausted.
HostAbi
Runtime handles host functions use to build real $Object-subtype structs (currently $string/$Array/$Uint8Array) on the host side instead of returning the raw payload array for a Wasm shim to re-wrap. The canonical StructType/ArrayType handles are declared directly via RecGroupBuilder (see [build_intrinsic_types]); the vtable value is read from the prelude instance per call.
PermissionDenied
Marker for a capability denial that should surface to the guest as the built-in PermissionDeniedError subclass, carrying the structured fields policy-aware recovery code reads (e.capability, e.caller, e.reason). Same contract as RangeError.
QuotaExceededError
Marker for a host failure that should surface to the guest as the built-in QuotaExceededError subclass rather than a base Error. Return Err(quota_exceeded_error(...)) from a host-fn body; the register_host_fn wrapper downcasts for it when converting the Err into a guest throw. The message is the guest-visible e.message.
RangeError
Marker for a host failure that should surface to the guest as the built-in RangeError subclass rather than a base Error. Return Err(range_error(...)) from a host-fn body; the register_host_fn wrapper downcasts for it when converting the Err into a guest throw. The message is the guest-visible e.message.
SyntaxError
Marker for a host failure that should surface to the guest as the built-in SyntaxError subclass — same contract as RangeError.
TypeError
Marker for a host failure that should surface to the guest as the built-in TypeError subclass — same contract as RangeError. Used for argument-boundary type mismatches (a null or wrong-typed value where the ABI promised another type) and for spec-TypeError conditions (invalid URL, fatal text decode, unsupported HTTP method).
UriError
Marker for a host failure that should surface to the guest as the built-in URIError subclass — same contract as RangeError.

Enums§

DenialSource
Which layer refused. Absent from the guest ABI: the guest sees caller/capability/reason as before. It selects the closing paragraph of the rendered message and, for a denial that escapes the program, the source the embedder reports.

Constants§

INTERNAL_MODULE_NAME
Not user-importable; __ prefix keeps it out of any stdlib namespace.
NUMBER_MODULE_NAME

Functions§

fatal_host_error
host_package_declarations
PackageDeclaration for host fns the consumer imports directly. console.log and number.toString are excluded — they’re wrapped by prelude exports and must not appear as free-function bindings in the user’s scope.
install_async
Install the full runtime: the store-less host fns (prelude + stdlib + MCP) followed by the store-bound prelude state. There are no runtime Wasm modules — every built-in surface is Rust host fns resolved straight from the linker.
install_async_for
install_async for an embedder that offers stdlib.
install_host_functions
install_host_functions_for
install_host_functions for an embedder that offers stdlib.
install_store_bound
The store-bound half of install_async, for embedders that keep a reusable base linker of host fns and only need the per-store state.
internal_host_package_declarations
Compiler-internal host fn definitions — wired into codegen but not visible in user scope.
permission_denied
A policy denial, thrown at the guest boundary as the built-in PermissionDeniedError.
permission_denied_invariant
A denial the policy never got to weigh in on, because the runtime refuses this caller/capability pair outright.
permission_denied_read_only
A write into a volume mounted read-only.
quota_exceeded_error
A host failure that throws the built-in QuotaExceededError at the guest boundary.
range_error
A host failure that throws the built-in RangeError at the guest boundary.
read_string_arg
read_string_array_arg
Read a real $Array<$string> into Vec<String>. Null slots → empty string.
register_host_fn
Register a host fn under mangled_name — the linker field codegen imports for it: mangle::host(module, name) for stdlib/host modules, or a prelude method’s dispatch key (e.g. submilli:prelude#String#repeat) so codegen’s method lookup resolves to it.
register_host_fn_async
Async sibling of register_host_fn: registers under mangled_name. The body returns a boxed future; the same Err → throw_error mapping applies once it resolves.
stdlib_package_declarations
syntax_error
A host failure that throws the built-in SyntaxError at the guest boundary.
throw_error
Raise a catchable Submilli Error from inside a host function.
type_error
A host failure that throws the built-in TypeError at the guest boundary.
uri_error
A host failure that throws the built-in URIError at the guest boundary.
write_submilli_array_struct
Build a real $Array (vtable + $rawArray backing) from already-built element object refs (e.g. $strings for a string[]). Each element Val must be a (ref null $Object) — a subtype ref or Val::AnyRef(None).
write_submilli_string
Encodes a Rust string as a Submilli packed-UTF-16 (array (mut i16)) — the bare $rawString payload, without the $string object wrapper.
write_submilli_string_struct
Build a real $string (vtable + packed-UTF-16 payload). Requires StoreData::host_abi, set once the prelude instantiates.
write_submilli_string_struct_units
Build a real $string directly from UTF-16 code units — the surrogate-faithful path for callers (e.g. String.fromCharCode) whose output may contain lone surrogates that a Rust String can’t carry. Requires StoreData::host_abi, set once the prelude instantiates.
write_submilli_uint8array_struct
Build a real $Uint8Array (vtable + packed-i8 payload). Mirror of write_submilli_string_struct. Requires StoreData::host_abi.