C++ SCHX ยท rev 4
CAPABILITY CAGE

Declaring a capability does not grant it.

A privileged builtin executes only when the CAGE bytecode declares the capability and the host session policy grants it. The School-GIT Studio server grants isolated workspace file/database operations, but does not grant process-launch or unrestricted network capabilities to arbitrary editor code.

SCHX / FEATURE LAYER

Example declaration

cage๐Ÿ›ก๏ธ๐Ÿงฐ
  ๐Ÿ“๐Ÿ‘€๐Ÿ”ธ
  ๐Ÿ“โœ๏ธ๐Ÿ”ธ
  ๐Ÿ—ƒ๏ธ๐Ÿ‘€๐Ÿ”ธ
  ๐Ÿ—ƒ๏ธโœ๏ธ๐Ÿ”ธ
๐Ÿ”’
SCHX / FEATURE LAYER

Resource cage

  • Instruction budget prevents an infinite bytecode loop from running forever.
  • Wall-time budget is checked while the VM executes.
  • Memory is estimated against the program's configured cage.
  • Filesystem paths are canonicalized under the session workspace and cannot escape with .. paths.
  • Database keys are stored under a CAGE-owned workspace namespace.