specification for module-level isolation in Tor

I've got to write up a document explaining how we'd like to get module-level isolation working in the Tor program.