pub fn silo_enter_sandbox() -> Result<usize>
Seal current context into sandboxed mode (no return to broader rights).