pub struct StoreData {Show 29 fields
pub blocking_work: BlockingWork,
pub git: Option<GitConfig>,
pub console: Box<dyn Write + Send>,
pub vfs: Vfs,
pub vfs_info: VfsInfo,
pub security_check: Arc<dyn SecurityCheck>,
pub fs_max_read_size: u64,
pub http_client: Arc<dyn HttpClient>,
pub http_max_response_size: u64,
pub http_max_download_timeout_ms: u64,
pub auth_proxy: Arc<dyn AuthProxy>,
pub secret_provider: Arc<dyn SecretProvider>,
pub mcp_transport: Option<Arc<dyn McpTransport>>,
pub llm_provider: Option<Arc<dyn LlmProvider>>,
pub llm_budget: Option<Arc<ExecutionTokenBudget>>,
pub embedding_provider: Option<Arc<dyn EmbeddingProvider>>,
pub embedding_budget: Option<Arc<EmbeddingTokenBudget>>,
pub session_kv: Option<Arc<dyn SessionKvStore>>,
pub agent_provider: Option<Arc<dyn AgentProvider>>,
pub skill_provider: Option<Arc<dyn SkillProvider>>,
pub metrics: Arc<dyn MetricsSink>,
pub tenant_limits: TenantLimits,
pub host_fuel: u64,
pub host_fuel_pending: u64,
pub host_fuel_applied_at: Option<u64>,
pub test_labels: RefCell<Vec<String>>,
pub host_abi: Option<HostAbi>,
pub type_info: BTreeMap<String, TypeInfoTable>,
pub vtable_walk_depth: u32,
/* private fields */
}Fields§
§blocking_work: BlockingWorkAfter cancelling a host call, the execution owner drains this before reusing or releasing the store. Blocking work may still be cleaning up.
git: Option<GitConfig>§console: Box<dyn Write + Send>§vfs: Vfs§vfs_info: VfsInfo§security_check: Arc<dyn SecurityCheck>§fs_max_read_size: u64§http_client: Arc<dyn HttpClient>§http_max_response_size: u64§http_max_download_timeout_ms: u64Operator ceiling for a download, including streaming its body.
auth_proxy: Arc<dyn AuthProxy>§secret_provider: Arc<dyn SecretProvider>§mcp_transport: Option<Arc<dyn McpTransport>>The outbound @mcp/<server> transport the submilli:mcp.call host fn
dispatches through, present when the embedder wires one. None in the
pure-interpreter path, where MCP calls throw “transport not configured”.
llm_provider: Option<Arc<dyn LlmProvider>>The model provider submilli:llm dispatches through, present only when
the embedder wires one. Left None the runtime has no model access at
all rather than silently completing against some default — the guest
surface reports that as a catchable configuration error
(LlmCallError::NotConfigured), the same rule session_kv follows.
llm_budget: Option<Arc<ExecutionTokenBudget>>This execution’s token budget, reserving against its own ceiling and the
server-wide one together. None in the pure-interpreter path, where
there is no aggregate to protect and nothing to charge against; the
prompt-count and prompt-size bounds still apply there, because they
bound pathological shapes rather than spend. The embedder installs one
per execution, and dropping it is what returns the reservation.
embedding_provider: Option<Arc<dyn EmbeddingProvider>>The provider submilli:embedding dispatches through, present only when
the embedder wires one. None means the guest sees a catchable
EmbeddingError::NotConfigured, never a silent default.
embedding_budget: Option<Arc<EmbeddingTokenBudget>>This execution’s embedding budget (tokens and outbound requests). None
in the pure-interpreter path; dropping it returns unspent reservation.
session_kv: Option<Arc<dyn SessionKvStore>>Session-scoped key-value storage, present only when the embedder wires a
provider. Left None the store stays absent rather than silently
becoming per-execution scratch state that no later execute can read —
the guest surface reports that as a configuration error.
agent_provider: Option<Arc<dyn AgentProvider>>The harness submilli:agents runs sub-agents through, present only when
the embedder wires one. None makes every call a catchable
AgentCallError::NotConfigured.
skill_provider: Option<Arc<dyn SkillProvider>>The harness submilli:skills reads skills through, present only when the
embedder wires one. None makes every call a catchable
SkillError::NotConfigured.
metrics: Arc<dyn MetricsSink>Embedder sink for host-operation metrics (HTTP transport latencies).
Defaults to NoopMetricsSink; the server installs a Sentry-backed one.
tenant_limits: TenantLimits§host_fuel: u64Fuel charged by host functions for their own work; the rest of the fuel
spent went to Wasm instructions. See fuel::charge_host_fuel.
host_fuel_pending: u64Host charges not yet applied to the engine’s fuel (see
fuel::HOST_FUEL_BATCH).
host_fuel_applied_at: Option<u64>The engine’s fuel right after the last application of pending host
charges; None before the first.
test_labels: RefCell<Vec<String>>Test-segment labels recorded by submilli:test.label, in call order.
Only the test runner installs that host fn; an ordinary run leaves this
empty. The runner reads it after main() returns to attribute the
pass/fail outcome to the segment that was open at the time.
host_abi: Option<HostAbi>Recovered runtime types + the prelude instance handle host functions use
to build real $string/$Array structs (vtable + payload) instead of
raw arrays. None until the prelude instantiates; set by
install_prelude_async. See crate::runtime::host::HostAbi.
type_info: BTreeMap<String, TypeInfoTable>Runtime type metadata keyed by package name.
vtable_walk_depth: u32Depth of the in-flight universal-vtable walk; see
[MAX_VTABLE_WALK_DEPTH].