# Security Considerations for Runtime Types in Cloudflare Computer

> Discover security considerations for runtime types in Cloudflare Computer. Learn how capability-based isolation and strict RPC typing protect host resources from unauthorized access.

- Repository: [Cloudflare/computer](https://github.com/cloudflare/computer)
- Tags: security-considerations
- Published: 2026-08-15

---

**Runtime types in Cloudflare Computer enforce security through capability-based isolation, runtime-ID validation, resource confinement, and strict RPC typing that prevents unauthorized access to host resources.**

Cloudflare Computer isolates user code inside an on-demand **runtime** created for each execution request. The TypeScript types governing these runtimes—defined under `packages/computer/src/runtime/`—serve as the platform's primary security enforcement layer. This article examines how these runtime types address critical security concerns and prevent privilege escalation.

## Capability-Based Isolation via WorkspaceRuntime

All filesystem and network operations flow through the **`WorkspaceRuntime`** object. This design ensures the runtime only exposes capabilities deliberately granted by the platform.

In [`packages/computer/src/runtime/runtime.ts`](https://github.com/cloudflare/computer/blob/main/packages/computer/src/runtime/runtime.ts), the runtime implementation filters out any attempt to access the host's `process` or `globalThis` objects. The runtime never leaks these privileged globals, making direct host compromise impossible.

```typescript
// Runtime capabilities are gated through WorkspaceRuntime
import { Workspace } from "@cloudflare/computer";

async function runCommand(cmd: string) {
  const ws = new Workspace({ root: "/workspace" });
  // `ws.runtime.exec` validates the runtime ID internally
  const handle = await ws.runtime.exec(cmd);
  console.log(`Executed ${cmd} in runtime ${handle.runtimeId}`);
}

```

## Runtime-ID Validation Prevents Resource Hijacking

Every execution handle carries a **`runtimeId`**. Before any operation—`getExec`, `killExec`, or `disposeExec`—the code asserts that the supplied ID matches the stored execution record.

The `assertExecutionRuntime` function in [`packages/computer/src/workspace.ts`](https://github.com/cloudflare/computer/blob/main/packages/computer/src/workspace.ts) (lines 694-708) performs this validation. A malicious client attempting to hijack another execution's resources receives an assertion failure.

```typescript
// Explicit runtime-ID verification
async function getExec(ws: Workspace, execId: string, expectedRuntimeId: string) {
  const exec = await ws.runtime.getExec({ id: execId, runtimeId: expectedRuntimeId });
  // Mismatched IDs throw an assertion error (workspace.ts:L694)
  return exec;
}

```

## Resource Confinement Through ExecutionRuntimeTracker

The **`ExecutionRuntimeTracker`** type records CPU-time, memory, and I/O counters per runtime. Located in [`packages/computer/src/execution-runtime-tracker.ts`](https://github.com/cloudflare/computer/blob/main/packages/computer/src/execution-runtime-tracker.ts), this tracker provides immutable accounting data to the scheduler for quota enforcement and runaway execution aborts.

The type definitions make resource consumption explicit and tamper-resistant for callers.

## Disposable Stubs Eliminate Dangling Capabilities

Runtime-side RPC stubs are automatically disposed when executions finish. `WorkspaceRuntime` maintains a **weak-reference map** of active stubs and periodically flushes them via `runtime.flushDeferredDisposers`.

This mechanism in [`packages/computer/src/runtime/runtime.ts`](https://github.com/cloudflare/computer/blob/main/packages/computer/src/runtime/runtime.ts) (lines 150-165) prevents capability resurrection attacks where terminated executions might leave exploitable handles.

```typescript
// Safe runtime disposal clears all stubs
async function disposeRuntime(ws: Workspace, runtimeId: string) {
  await ws.runtime.disposeExec({ id: runtimeId });
  // Internal stub map is cleared, preventing reuse
}

```

## No Privileged Host Access

The runtime executes inside **Cloudflare Workers** (or a FUSE shim) without direct OS privileges. Types like `ExecLog` in [`packages/computer/src/exec/types.ts`](https://github.com/cloudflare/computer/blob/main/packages/computer/src/exec/types.ts) deliberately limit exposed data to what workers can safely provide—excluding environment variables and secret keys.

## Strict RPC Contract Typing

The **capnproto-based RPC contract** ([`docs/08_capnweb_interface.md`](https://github.com/cloudflare/computer/blob/main/docs/08_capnweb_interface.md)) compiles to TypeScript interfaces in [`packages/rpc/src/interface.ts`](https://github.com/cloudflare/computer/blob/main/packages/rpc/src/interface.ts). Strong typing rejects malformed or malicious messages before they reach runtime logic, providing protocol-level security.

## Key Security Files in Cloudflare Computer

| File | Security Function |
|:---|:---|
| [`packages/computer/src/runtime/runtime.ts`](https://github.com/cloudflare/computer/blob/main/packages/computer/src/runtime/runtime.ts) | Core `WorkspaceRuntime` implementation; capability checks and stub disposal |
| [`packages/computer/src/workspace.ts`](https://github.com/cloudflare/computer/blob/main/packages/computer/src/workspace.ts) | `runtimeId` validation via `assertExecutionRuntime` |
| [`packages/computer/src/execution-runtime-tracker.ts`](https://github.com/cloudflare/computer/blob/main/packages/computer/src/execution-runtime-tracker.ts) | Immutable resource accounting for quota enforcement |
| [`packages/computer/src/exec/types.ts`](https://github.com/cloudflare/computer/blob/main/packages/computer/src/exec/types.ts) | Minimal safe shapes for cross-runtime data |
| [`packages/rpc/src/interface.ts`](https://github.com/cloudflare/computer/blob/main/packages/rpc/src/interface.ts) | Strongly-typed RPC contract preventing malformed messages |
| [`docs/08_capnweb_interface.md`](https://github.com/cloudflare/computer/blob/main/docs/08_capnweb_interface.md) | Capnproto RPC specification |

## Summary

- **Capability-based isolation**: `WorkspaceRuntime` gates all operations and hides host globals
- **Runtime-ID validation**: Every operation verifies the execution belongs to the claimed runtime
- **Resource confinement**: `ExecutionRuntimeTracker` enforces immutable quota accounting
- **Automatic disposal**: Weak-reference stub maps prevent capability leakage post-execution
- **Strict typing**: Capnproto-to-TypeScript compilation rejects malicious RPC payloads

## Frequently Asked Questions

### How does Cloudflare Computer prevent one execution from accessing another execution's resources?

Each execution receives a unique `runtimeId` that must be provided with every operation. The `assertExecutionRuntime` function in [`workspace.ts`](https://github.com/cloudflare/computer/blob/main/workspace.ts) validates this ID against stored records, throwing an error on mismatch. This design prevents resource hijacking even if an attacker obtains another execution's handle.

### What prevents user code from accessing the host operating system?

The runtime executes inside Cloudflare Workers or a FUSE shim without direct OS privileges. The `WorkspaceRuntime` implementation explicitly filters access to `process` and `globalThis`, and type definitions like `ExecLog` exclude sensitive data such as environment variables from cross-boundary messages.

### How does Cloudflare Computer handle resource exhaustion attacks?

The `ExecutionRuntimeTracker` type maintains immutable counters for CPU time, memory, and I/O per runtime. The scheduler consults these counters to enforce quotas and forcibly terminate runaway executions before they impact other tenants or platform stability.

### Why are RPC stubs disposed automatically rather than manually?

`WorkspaceRuntime` maintains active stubs in a weak-reference map with periodic flushing via `flushDeferredDisposers`. Automatic disposal eliminates human error in cleanup and prevents "dangling capability" attacks where forgotten stubs could be resurrected to access terminated execution contexts.