-
-
Notifications
You must be signed in to change notification settings - Fork 3
Capability Modules
Permissions in the OS sense. A mod receives imports only for the modules it declared and the user granted; anything else is absent from its import object, so calling it is a link failure at load, not a runtime check that can be bypassed.
Users can revoke individual modules per mod in the mod menu's Advanced panel — so a mod must tolerate being granted less than it asked for.
| Module | Grants | Functions | Revocable | Status |
|---|---|---|---|---|
Core |
Logging, environment introspection, abort, fuel budget |
log, env, abort, fuel_budget
|
no | implemented |
GameState.Read |
Read the turn, countries, treasuries, provinces |
turn_number, country_count, country_at, country_name, country_treasury, country_province_count, province_population, province_owner
|
yes | implemented |
UI |
Register panels and draw inside them |
panel_register, draw_rect, draw_text, button
|
yes | implemented |
Assets |
Read your own data/ directory |
size, read
|
yes | implemented |
GameProcess |
Turn lifecycle hooks. Grants exports, not imports. | — | yes | implemented |
GameState.Write |
Mutate the world. Implies GameState.Read. |
set_country_treasury, add_country_treasury, set_province_owner, set_province_population
|
yes | implemented |
Neural |
Observe AI features and rewards (observe-only: no import writes to the model) |
feature_count, features, reward_count, reward_mean
|
yes | implemented |
Map |
Province geometry and adjacency |
width, height, province_count, province_at, province_name, province_center_x, province_center_y, province_is_land, province_neighbor_count, province_neighbor_at
|
yes | implemented |
Diplomacy |
Read and propose diplomatic actions |
at_war, allied, non_aggression, guaranteed, propose_war
|
yes | implemented |
Storage |
Persistent key-value store namespaced to your mod id |
get, set, remove
|
yes | implemented |
Audio |
Play and stop sounds from your own mod's assets |
play, stop, set_volume, is_playing
|
yes | implemented |
Net |
Send and receive messages between copies of YOUR OWN mod |
send, recv, peer_count, self_peer, is_host
|
yes | implemented |
WasiStub |
Minimal WASI shim so an interpreter-in-a-mod can boot. NOT a WASI implementation: no filesystem, deterministic randomness, no wall clock. |
fd_write, proc_exit, random_get, clock_time_get, environ_sizes_get, environ_get, args_sizes_get, args_get, fd_close, fd_fdstat_get, fd_prestat_get, fd_prestat_dir_name, fd_read, fd_seek, path_open, clock_res_get, sched_yield, fd_advise, fd_allocate, fd_datasync, fd_sync, fd_fdstat_set_flags, fd_filestat_get, fd_tell, fd_renumber, fd_filestat_set_size, fd_filestat_set_times, fd_pread, fd_pwrite, fd_readdir, path_create_directory, path_remove_directory, path_unlink_file, path_filestat_get, path_symlink, path_readlink, path_rename, path_link, path_filestat_set_times, poll_oneoff, sock_accept, sock_recv, sock_send, sock_shutdown
|
yes | implemented |
GameProcess grants no imports — it gates whether the host calls your
mod_pre_turn / mod_post_turn exports.
Deliberately absent: any filesystem, network, process, or clock-with-identity
capability. There is no module that grants them, so they cannot be requested.
WASI's fd_* and path_* imports are never linked into the runtime.
Requesting GameState.Write when you only read is not neutral — users see the
list before granting, and are right to be suspicious. Declare the least you
need.
The experimental AI Learning option mutates the trained model as you play.
A mod can change what the AI observes, so the two are mutually exclusive: you
will never observe a turn where both are active.