Expand description
submilli:llm — gated model calls from inside a Submilli program.
Rust host functions registered directly under the package name. Each op runs
check_security before anything leaves the process; the one gated
capability is llm.call, cataloged in crate::stdlib::capabilities —
keep it in sync when adding or removing a gate (see AGENTS.md).
Dispatch is the embedder’s: StoreData::llm_provider holds the provider.
A runtime with none configured refuses every op rather than inventing a
completion, so a program never silently reasons over text no model produced
— the rule submilli:session follows for its store.
One capability, per-model filtering. call, batch, and models() are the
same grant, with prompt_count in the filter context rather than separate
names: enumerating the operator’s models is not a
distinct risk class from calling one. models() filters each candidate
through the same model filter that gates
calling, so a listing never offers a model the caller would be denied at
call time — the session.list / session.read shape.
No prompt or completion text crosses this boundary in metadata. Not in
the filter context, not in an error, not in a log. The context carries
model and prompt_count — the numbers, never the payload.
Re-exports§
pub use declaration::package_declaration;
Modules§
- declaration
- Type surface of
submilli:llm.
Constants§
- CAPABILITY
- The single capability gating every op in this package.
callandbatchare the same risk and the same grant as enumeration, discriminated by the filter context rather than by three capability names. - MODULE_
NAME - OPS
- The ops a request is recorded under,
callandbatch. The provider is not told which one a request came from.
Functions§
- install
- request_
digest - The digest the call log records for a request of this
op.