Skip to main content

Module runtime

Module runtime 

Source
Expand description

Wasmtime engine configuration for Submilli.

Re-exports§

pub use agents::AGENTS_MODULE_NAME;
pub use agents::AgentCallError;
pub use agents::AgentInfo;
pub use agents::AgentOutcome;
pub use agents::AgentProvider;
pub use agents::AgentRequest;
pub use agents::AgentUsage;
pub use call_log::BodyCopy;
pub use call_log::CallOutcome;
pub use call_log::CallRecord;
pub use call_log::ModelUsage;
pub use call_log::PayloadRecord;
pub use decision::CallSite;
pub use decision::CallTicket;
pub use decision::DecisionAction;
pub use decision::DecisionCause;
pub use decision::DecisionExplanation;
pub use decision::DecisionLog;
pub use decision::DecisionLogConfig;
pub use decision::DecisionLogOutput;
pub use decision::DecisionRecord;
pub use decision::DecisionRecorder;
pub use decision::EntryPath;
pub use decision::FailureReasonRecord;
pub use decision::FailureRecord;
pub use decision::NearMissRecord;
pub use decision::RecordObserver;
pub use decision::RuleCitation;
pub use decision::SourceLine;
pub use disk_quota::DiskQuota;
pub use disk_quota::Holder;
pub use disk_quota::OpenFileGuard;
pub use disk_quota::QuotaCharge;
pub use disk_quota::QuotaExceeded;
pub use embedding::DEFAULT_MAX_EMBEDDING_REQUESTS;
pub use embedding::DEFAULT_MAX_EXECUTION_EMBEDDING_TOKENS;
pub use embedding::EMBEDDING_MODULE_NAME;
pub use embedding::EmbeddingBatch;
pub use embedding::EmbeddingBoundKind;
pub use embedding::EmbeddingError;
pub use embedding::EmbeddingFailureReason;
pub use embedding::EmbeddingLimitKind;
pub use embedding::EmbeddingLimits;
pub use embedding::EmbeddingMalformedReason;
pub use embedding::EmbeddingModel;
pub use embedding::EmbeddingProvider;
pub use embedding::EmbeddingShapeError;
pub use embedding::EmbeddingTokenBudget;
pub use embedding::Purpose;
pub use embedding::SubBatchSettlement;
pub use embedding::estimate_embedding_tokens;
pub use exec::RunResult;
pub use exec::dispatch_main_async;
pub use exec::instantiate_program_async;
pub use host::INTERNAL_MODULE_NAME;
pub use host::NUMBER_MODULE_NAME;
pub use host::host_package_declarations;
pub use host::install_async as install_runtime_async;
pub use host::install_async_for as install_runtime_async_for;
pub use host::install_host_functions as install_runtime_host_functions;
pub use host::install_host_functions_for as install_runtime_host_functions_for;
pub use host::install_store_bound as install_runtime_store_bound;
pub use host::internal_host_package_declarations;
pub use host::stdlib_package_declarations;
pub use json::JSON_MODULE_NAME;
pub use limits::DEFAULT_MAX_STORE_BYTES;
pub use limits::MemoryCapExceeded;
pub use limits::MemoryExhausted;
pub use limits::TenantLimits;
pub use limits::install_tenant_limits;
pub use limits::is_memory_exhausted;
pub use llm::DEFAULT_MAX_ALL_EXECUTIONS_TOKENS;
pub use llm::DEFAULT_MAX_EXECUTION_TOKENS;
pub use llm::ExecutionTokenBudget;
pub use llm::FailureReason;
pub use llm::LLM_MODULE_NAME;
pub use llm::LlmCallError;
pub use llm::LlmFailure;
pub use llm::LlmLimitKind;
pub use llm::LlmLimits;
pub use llm::LlmModel;
pub use llm::LlmOutcome;
pub use llm::LlmProvider;
pub use llm::PromptBoundKind;
pub use llm::SharedTokenBudget;
pub use mcp::MCP_MODULE_NAME;
pub use mcp::McpCallError;
pub use mcp::McpOutcome;
pub use mcp::McpResponse;
pub use mcp::McpTransport;
pub use mcp::install_mcp_async;
pub use mcp::mcp_call_package_declaration;
pub use metrics::HttpMetric;
pub use metrics::MetricsSink;
pub use metrics::NoopMetricsSink;
pub use secrets::NoopSecretProvider;
pub use secrets::SecretProvider;
pub use security::AllowAllCheck;
pub use security::AuditDecision;
pub use security::CheckOutcome;
pub use security::SecurityCheck;
pub use session_kv::InMemorySessionKv;
pub use session_kv::SessionKvEntry;
pub use session_kv::SessionKvError;
pub use session_kv::SessionKvLimitKind;
pub use session_kv::SessionKvLimits;
pub use session_kv::SessionKvPage;
pub use session_kv::SessionKvStore;
pub use session_kv::SharedKvBudget;
pub use skills::SKILLS_MODULE_NAME;
pub use skills::Skill;
pub use skills::SkillError;
pub use skills::SkillInfo;
pub use skills::SkillProvider;
pub use vfs::Access;
pub use vfs::CopyDirError;
pub use vfs::MAX_MEASURED_DEPTH;
pub use vfs::MountError;
pub use vfs::MountSpec;
pub use vfs::Vfs;
pub use vfs::VfsMode;
pub use vfs::copy_host_dir;
pub use vfs::copy_host_subdir;
pub use vfs::measure_dir;
pub use vfs::measure_host_dir;
pub use vfs::measure_host_dir_skipping_vanished;
pub use vfs::measure_host_subdir_skipping_vanished;
pub use vfs::open_host_subdir;
pub use vfs::regular_files;
pub use watchdog::Watchdog;
pub use crate::stdlib::http::AuthProxy;
pub use crate::stdlib::http::AuthProxyError;
pub use crate::stdlib::http::HttpClient;
pub use crate::stdlib::http::HttpError;
pub use crate::stdlib::http::HttpRequest;
pub use crate::stdlib::http::HttpResponse;
pub use crate::stdlib::http::NetworkPolicy;
pub use crate::stdlib::http::NoopAuthProxy;
pub use crate::stdlib::http::ReqwestHttpClient;

Modules§

agents
The embedder-supplied seam for submilli:agents: a program hands work to a sub-agent and gets its result back.
blocking
Blocking work whose cleanup belongs to an execution, not its request.
call_log
Call records: each host call a program made, when it ran, and, for a call that reaches outside the program, what it sent and what came back.
decision
Decision records: what an embedder’s recorder sees of each capability decision.
disk_quota
The blueprint’s size_limit: a byte budget for the files in one VFS.
embedding
The embedder-supplied seam for submilli:embedding — batches of text embedded by a remote provider from inside a Submilli program.
exec
Program instantiation, main invocation and JSON-encoded result capture.
fs
VFS path resolver for the submilli:fs host module.
fuel
Fuel for work done by host functions. Wasm instructions burn fuel on their own; a host function charges for its work here, from the same budget, so that fuel bounds the CPU a program spends wherever it spends it.
gc_singleton
Helpers that declare one struct/array/func type as its own singleton rec group via wasmtime’s RecGroupBuilder. WasmGC structural canonicalization makes the returned handle share the engine type-index a module emitting the same bytes uses, so a host-built type flows into a guest slot of that type without trapping.
host
Host-function and prelude registration for the Submilli runtime.
intrinsic_types
Host-side declaration of the canonical intrinsic WasmGC rec group.
json
Host side of the JSON.parse compiler intrinsic.
limits
Per-store ResourceLimiter enforcing a single aggregate cap on GC heap, linear memory, and host-attached bytes (e.g. compiled regexes). host_attached_bytes is Arc<AtomicU64> so externref Drop impls can decrement it without a &mut TenantLimits borrow.
llm
The embedder-supplied seam for submilli:llm — gated model calls from inside a Submilli program.
mcp
Outbound @mcp/<server> transport dispatch.
metrics
Embedder hook for runtime observability. The interpreter times host-side operations (currently HTTP transport) and hands each one to a MetricsSink the embedder installs on StoreData. The default sink discards everything, so the pure-interpreter path stays dependency-free — the binary crates (CLI, server) are the only place a real metrics backend (Sentry) is wired in.
number
JavaScript-compatible number parsers and formatters.
prelude
The prelude’s implementation: every built-in method, static, constant, and vtable as Rust host fns, registered under submilli:prelude.
secrets
Runtime-side provider for submilli:secrets.
security
Embedder-supplied security policy trait.
session_kv
Session-scoped key-value store: the trait an embedder implements and a bounded in-memory implementation.
skills
The embedder-supplied seam for submilli:skills: a program reads the skills the harness offers, their instructions and the files bundled with them.
token_ledger
The token accounting both submilli:llm and submilli:embedding budget against: a per-execution reservation that also charges a server-wide aggregate, with held reserve for spend a provider never reported.
vfs
VFS root directory plumbing.
watchdog
Wall-clock watchdog that drives wasmtime’s epoch-based interruption.

Structs§

LinkedPackageModule
RuntimeConfig
StoreData
VfsInfo
Filesystem metadata surfaced to scripts via submilli:fs.info(): the active mode and the byte cap the VFS enforces, so the script — and the LLM — can branch on the sandbox shape. Never exposes the host path.

Constants§

BIGINT_MODULE_NAME
DEFAULT_FS_MAX_READ_SIZE
DEFAULT_HTTP_MAX_RESPONSE_SIZE
TEMPORAL_MODULE_NAME

Functions§

install_package_modules_async