From 802af683ac9a29356e22bcc7f103eb141637f215 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=CE=A7=CE=B3=CF=86=CF=84=20Kompanion?= Date: Mon, 13 Oct 2025 00:07:13 +1300 Subject: [PATCH] docs: quickjs optional engine plan --- docs/JS-ENGINE.md | 11 +++++------ 1 file changed, 5 insertions(+), 6 deletions(-) diff --git a/docs/JS-ENGINE.md b/docs/JS-ENGINE.md index c6ba05b..470692f 100644 --- a/docs/JS-ENGINE.md +++ b/docs/JS-ENGINE.md @@ -1,6 +1,5 @@ -# JS Engine Integration (QuickJS) - -- Embed QuickJS for safe, deterministic, sandboxed transforms. -- No network, no filesystem by default; expose only Kompanion tool FFI shims. -- Use for text filters, parsers, light data munging; scripts under `~/.config/kompanion/js/`. -- FFI bridge: `js.callTool(name, args)` → JSON-RPC. +# Optional JavaScript Engine (QuickJS) +Goal: lightweight scripting for tools and creative transforms without pulling QtQml. +Design:\n- Link QuickJS as an optional component (BUILD_JS=ON).\n- Expose sandboxed functions: readText(path allowlist), writeJournal(text), httpFetch(allowlist).\n- Per-aspect capability gates via capabilities.json. +Security:\n- No require() to filesystem; no dynamic dlopen; memory/time limits per eval.\n- Network only via allowlisted httpFetch; inherits Tor proxy if set. +API sketch:\n- tools/js.eval {code, args} -> result or error; logs to ledger.