Module: SecurityBox::Runtime

Defined in:
lib/security_box/runtime.rb

Overview

Registry of heavyweight artifacts shared across sandboxes:

  • Engine (one per runtime configuration; owns the epoch timer)
  • Compiled Module (one per engine+image)

Module compilation is slow (~15s the first time per process); the compiled artifact is persisted via ModuleCache so later processes deserialize it from disk instead of recompiling.

Constant Summary collapse

MUTEX =
Mutex.new

Class Method Summary collapse

Class Method Details

.build_shareable(image_path:, epoch_interval_ms:) ⇒ Object

Builds a dedicated (not memoized) Engine + Module pair prepared for use across Ractors: the epoch timer is started and the precompile key is touched BEFORE freezing, then both artifacts are made Ractor-shareable (stage-3 Q2 "Plan C"). The pair is not stored in the class memos — freezing shared artifacts would affect every Sandbox — so each RactorPool pays one module deserialize (~0.5s via the disk cache). Callers must treat the returned pair as immutable.



51
52
53
54
55
56
57
58
59
# File 'lib/security_box/runtime.rb', line 51

def build_shareable(image_path:, epoch_interval_ms:)
  engine = build_engine(epoch_interval_ms)
  module_ = ModuleCache.load_module(engine, image_path) ||
            ModuleCache.compile_and_store(engine, image_path)
  engine.precompile_compatibility_key # touch before make_shareable
  Ractor.make_shareable(engine)
  Ractor.make_shareable(module_)
  [engine, module_]
end

.clear! ⇒ Object



37
38
39
40
41
42
# File 'lib/security_box/runtime.rb', line 37

def clear!
  MUTEX.synchronize do
    @engines.clear
    @modules.clear
  end
end

.engine(epoch_interval_ms:) ⇒ Object



22
23
24
25
26
# File 'lib/security_box/runtime.rb', line 22

def engine(epoch_interval_ms:)
  MUTEX.synchronize do
    @engines[epoch_interval_ms] ||= build_engine(epoch_interval_ms)
  end
end

.module_for(engine, image_path) ⇒ Object



28
29
30
31
32
33
34
35
# File 'lib/security_box/runtime.rb', line 28

def module_for(engine, image_path)
  MUTEX.synchronize do
    @modules[[engine.object_id, image_path]] ||= begin
      ModuleCache.load_module(engine, image_path) ||
        ModuleCache.compile_and_store(engine, image_path)
    end
  end
end