This repository was archived by the owner on Feb 18, 2026. It is now read-only.
Kernel filesystem change#663
Open
ShaleXIONG wants to merge 36 commits into
Open
Conversation
033fe1f to
32bd148
Compare
82c0019 to
52284d4
Compare
b6ee90c to
b48ac99
Compare
cb7ba2b to
c02e6e0
Compare
- Update the wasmtime to the newer version, that provide infra for WASI. such infrastructure assumes and uses the underline POSIX. - Remove WASMI since there is no need. - Rework on how to specify the permission in policy file, using the access control "rwx" now.
minor: - remove libveracruz.
The policy needs to specify the service and the mounting directory. While the engine will load the service based on the service name.
c02e6e0 to
dbea580
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Rework entirely on the execution engines and modify the policy accordingly.
input, under the mounted directory, specified in the policy file. Any caller of this service should readoutputunder the mounted directory.Execution, which requires two methods,namereturning the name of this execution, andexecuteexecuting a path to a file, or a directory. The later case is useful for service, which is mounted in a directory.rwx. Remove the oldcapabilityparameter, but combine the permission with entity by=>symbol, for example "<CLIENT_CERT> => output:r, input:w".Minor:
clapby using thederivefeatures.