The sandbox and its limits
Scripts run in Web Workers with work, time and size caps, so a script can never hang the chart.
Scripts run in a pool of Web Workers (one per spare CPU core, up to eight), not on the page. The page sends source, inputs and bars, and gets back columns, drawings, alerts and order intents. A script cannot touch the page, the network or a broker.
| Limit | Value | When hit |
|---|---|---|
| Operations per bar | 50,000,000 | Script stops with an error |
| Loop iterations per bar | 1,000,000 | Script stops with an error |
| Wall-clock per bar | 500 ms | Script stops with an error |
| Recursion depth | 200 | Script stops with an error |
| Full history run | 4 s | The run is abandoned |
| One live update | 250 ms | The run is abandoned |
| Array / matrix items | 100,000 | Script stops with an error |
| Map entries | 50,000 | Script stops with an error |
| Drawings per kind | 50 (up to 500) | Oldest removed |
| String length | 40,000 | Script stops with an error |
A worker that stops answering is terminated after its budget plus a short grace period, and the script is marked with the reason. The rest of the chart keeps running.