Expand description
submilli:embedding — remote text embeddings from inside a Submilli program.
Rust host functions registered directly under the package name. Each op runs
check_security_call before anything leaves the process; the one gated
capability is embedding.embed, cataloged in crate::stdlib::capabilities
— keep it in sync when adding or removing a gate (see AGENTS.md).
Dispatch is the embedder’s: StoreData::embedding_provider holds the
provider, and a runtime with none refuses every op rather than inventing a
vector — the rule submilli:llm follows.
One capability, per-alias filtering. embed and models() share the
grant, with input_count in the filter context. models() filters each
candidate through the same model filter that gates embed, so a listing
never offers an alias the caller would be denied at call time.
No input text or vector crosses this boundary in metadata. Not in the
filter context, not in an error, not in a log. The context carries model
and input_count.
Vectors stay compact, in the GC heap. A result is a backing struct whose
hidden field holds the vectors as a packed i8 array: little-endian f32
bytes, row-major, count × dimensions × 4 bytes — the storage a Uint8Array
uses. The array is allocated through the GC limiter, which collects inside
host calls, so a discarded result is reclaimed before the heap grows: the
vectors live in the GC heap, never in host memory the collector cannot see.
The field has no getter and its type is unreachable from the guest, so only
vector(i) and bytes(i) read it, copying one row out on demand; a
plain number[][] would cost about 60 bytes per number.
Re-exports§
pub use crate::runtime::EMBEDDING_MODULE_NAME as MODULE_NAME;pub use declaration::package_declaration;
Modules§
- declaration
- Type surface of
submilli:embedding.
Constants§
- CAPABILITY
- The single capability gating every op in this package.