ArchitectureA supervised JVM-class runtime — OLTP on seven engines, OLAP on three. AI-native, MCP-native, observable as plain SQL.Read the architecture
Está viendo la edición Perú. Está viendo la edición Colombia. You're viewing the Pakistan edition. Cambiar a la edición global →Cambiar a la edición global →Switch to the global edition →

Script sandboxing: a host-access allow list and forbidden classes for GraalVM

Every script context comes from one factory with a sandbox policy. A generated allow list names the Java classes scripts may reach; file, network, thread, system and reflection classes are forbidden.

Server-side scripts are written by application developers and, increasingly, by agents. The language runtime must decide what they may reach. This release centralises that decision and makes it explicit.

One factory, one policy

  • Centralised creation Every script context comes from one factory that applies the sandbox policy, shares engines and sets host-access rules. The GraalVM edition is checked at startup.
  • A generated allow list The Java classes reachable from the platform's scripting library are enumerated into a file, and host access is limited to them.
  • Forbidden classes File and file-system classes, URLs, threads, system and runtime, reflection and the secure password utilities are refused outright.
  • Two profiles Restricted: no I/O and no native access. Permissive: I/O allowed, host class lookup still through the filter.

The language

  • ECMAScript 2024 is the baseline, and import statements work inside wrapped functions.

A year later this policy is what the MCP server's code-proof tools introspect to tell an agent which library members exist. The allow list is the contract.