← → to step · Space to play / pause
ONE MAP, DIFFERENT PATHS
Where does my code go?
Caller ≠ guest
The caller is the program that submits the RPC. The guest is the untrusted code that plimsoll runs. A model can write that code without being either end of the network connection.
A pipe ≠ a permission
The adapter, a provider’s own channel between the guest and the broker, only carries an API call. The shared broker checks whether the call is allowed and makes the outgoing HTTP request. The API then applies its own authorization.
A result ≠ a guarantee
Guest code that failed still comes back in a successful RPC response. The isolation tier is evidence the daemon reports. If the client’s own check finds the reported tier missing or weaker than it demanded, the code may already have run.