Skip to content

sandbox-boundary

SandboxBindingInput = MyceliumJsonValue | undefined

JSON argument or the SDK’s explicit absence of an argument.


SandboxOperationBindings = Readonly<Record<string, Readonly<Record<string, (input) => Promise<MyceliumJsonValue>>>>>>>>>>

Host operation callbacks after decoding JSON or an absent RPC argument.

isSandboxFailure(cause): cause is SandboxFailure

Admit only errors constructed by the sandbox owner, using the maintained decoder.

unknown

cause is SandboxFailure


sandboxFailure(cause): SandboxFailure

Foreign throws stay private until an owner admits a diagnostic.

unknown

SandboxFailure


sandboxValueKind(value): string

Label a rejected JSON value without caller-owned reflection.

unknown

string


sandboxBindingInput(value): SandboxBindingInput

Decode the RPC argument before any capability callback observes it.

unknown

SandboxBindingInput


sandboxOperatorValue(cause): JSONType

Full operator representation, including nested errors, aggregates and cycles.

unknown

JSONType


sandboxGuestFailure(cause, bindings?): GuestThrew

Decode the engine’s guest-owned diagnostic once; renderers receive typed fields.

unknown

Readonly<Record<string, Readonly<Record<string, SandboxBinding>>>> = {}

GuestThrew


sandboxTransportMessage(failure, ref): string

Error.message is the SDK’s wire carrier; only this safe, bounded envelope crosses it.

SandboxFailure

string

string


recoverSandboxFailure(failure, failures): SandboxFailure

Recovery uses the decoded identity, never a match against diagnostic text.

SandboxFailure

ReadonlyMap<string, SandboxFailure>

SandboxFailure


sandboxExecutorFailure(cause, limitMs, elapsedMs): SandboxFailure

Decode Codemode’s documented error carrier before adapters choose a failure.

unknown

number

number

SandboxFailure


sandboxTransportErrno(cause): string | undefined

Decode a transport-owned errno without reflecting on a foreign throw in adapters.

unknown

string | undefined


sandboxSourceError(cause): Readonly<{ pos: number; }> | undefined

Admit Acorn’s documented offset from a syntax exception at this boundary.

unknown

Readonly<{ pos: number; }> | undefined


sandboxCapabilityFailure(cause, namespace, operation, admitted?): SandboxFailure

Capability owners supply an admission schema; decoding and foreign fallback stay here.

unknown

string

string

ZodType<Readonly<{ kind: "Files" | "Forage" | "InvalidInput" | "Unavailable" | "OperationFailed"; message: string; }>> = ...

SandboxFailure


sandboxBindingBoundary(bindings): Readonly<{ bindings: SandboxRequest["bindings"]; capture: (failure) => string; recover: (failure) => SandboxFailure; returnedFailure: (value) => SandboxFailure | undefined; }>

One boundary owns RPC decoding, safe transport and invocation-scoped recovery.

SandboxOperationBindings

Readonly<{ bindings: SandboxRequest["bindings"]; capture: (failure) => string; recover: (failure) => SandboxFailure; returnedFailure: (value) => SandboxFailure | undefined; }>