pub fn build_sandboxed_plugin(
module: &[u8],
capabilities: &[Capability],
ctx: &SandboxContext,
) -> Result<Plugin, String>Expand description
Build a sandboxed plugin from module bytes, registering host functions
only for the granted capabilities. WASI is off and memory / fuel /
timeout are bounded (see the DEFAULT_* consts). Returns a user-facing
error if the module fails to compile, link, or instantiate — including the
case where it imports a host function whose capability wasn’t granted.
Duplicate host-function names are registered once (the first grant wins),
so a plugin with two detect:file:<path> grants links cleanly.