fn register_capability<'a>(
builder: PluginBuilder<'a>,
cap: &Capability,
ctx: &SandboxContext,
) -> PluginBuilder<'a>Expand description
Register the host function a single capability unlocks. All host functions
are () -> i64 booleans in this ABI; the data each one reads (the process
pattern, the granted file path) is captured from the grant + context, so a
module cannot influence what’s probed.