Skip to main content

Sandbox & Limits

Resource scripts do not get the full standard library of their language. Anything that reaches outside the game, or that could take the server or a player's game down with it, is either missing or capped. This page lists what is actually there.

Runaway Scripts​

A single script call (one thread step, one event handler, one exported function) may run for at most 5 seconds and the VM may use at most 256 MiB of memory. A script that goes over either one is stopped with an error, and the whole resource is shut down: a script that ran away once does it again on the next tick.

caution

This safety net covers Lua and JavaScript. In a Squirrel script an endless loop that never calls Thread.Pause will freeze the server, or the game of every player who loaded the resource, and nothing will step in.

tip

The 5 seconds are per call, not per resource. Long work belongs in a thread that calls Thread.Pause(0) in its loop: each tick is its own call and gets its own 5 seconds.

Lua​

Available:

Library
base, table, string, math, utf8fully available
oswithout execute, exit, remove, rename, setlocale, tmpname, getenv
debugread-only part only: traceback and getinfo work, anything that changes state does not
ioServer only

Not available:

  • coroutine, superseded by the Thread API, which is built on it
  • package and require. There is no module loader; list every script in the meta file instead
  • dofile and loadfile

JavaScript​

The engine is a small embedded one, not a browser and not Node.js. The language itself is complete and current (ES2025: classes, async/await, Map and Set with the set methods, iterator helpers, typed arrays, Date, RegExp, JSON and so on; Temporal is not there), but the host objects of those environments are not:

  • No import, export or require. Every <script> of the resource runs as a plain script in one shared global scope; list the files in the meta file in the order they depend on each other.
  • No setTimeout, setInterval or fetch. Use the Timer and HTTP functions, which are the same in every language.
  • No file system, no processes, no network beyond the HTTP functions.
  • console.log, console.info, console.warn, console.error and print write to the server/client log, like Console.Log. Objects are printed as JSON.

Numbers are converted on the way into the API: a whole number becomes a 32-bit int, anything with a fraction a single-precision float, see Event Arguments. A number too large for an int therefore loses precision; send large IDs as strings.

The call stack is limited. Recursion that goes a few thousand levels deep ends in a RangeError that you can catch, not in a crash.

Squirrel​

deprecated

Available:

Library
string, mathfully available
io, systemServer only
timeClient only

The blob library is not registered.

Always-Present Globals​

Two globals are set up before your scripts run and are part of the API rather than of your resource:

  • Exports (Lua and Squirrel also accept the old name exports)
  • Timer
warning

Do not assign to Exports or Timer. They are ordinary globals, so overwriting one breaks it for every script in the resource.