Define lowered-HFIR ABI v1 and core conformance suite (#90 phase 1) - #53
Merged
Merged
Conversation
Phase 1 records the contract and compares the interpreter, bytecode VM, Go, and JavaScript on a pure core plus capability denial. Production compilation stays on the AST. Co-authored-by: William Elias <wylelias.123@gmail.com>
howlcipher
commented
Sep 30, 2026
howlcipher
left a comment
Owner
Author
There was a problem hiding this comment.
COMMENT OK (approve-quality) — same-account; formal APPROVE unavailable.
Verdict: Ready to undraft + squash-merge when CI is green on 65d37cd.
What this gets right
- Honest Partial — Phase 1, not Done. Production stays AST →
runHFIRGate→ bytecode;-compile-hfir-bcremains experimental; emptyControlEdges/ non-executabledefun/call/whileare stated, not papered over. - Contract
lowered-hfir-abi/v1+tests/conformance/lowered_hfir_abi_v1.jsonviatools/difftestis the right Phase-1 shape: prove hosts that already run the core agree before flipping the graph. - Core cases cover arith/
if, #109 UTF-8map_keys(incl. non-BMP viastdout_keys→sort.Strings), #103 absence, #108TYPE_ERROR, #107 empty-grant purity, andenvdenial only on hosts that mediate (interp+VM). Go/JS absence from denial is correct and guarded. - Wasm: closed
WasmInfeasibleKindsonly; no collections/opcodes/imports. #73/#84 deferred to Phase 2.
Hard nos: clean — no linker / HFIR module smuggle / new feature opcodes / Factory under the ABI banner.
Nit (non-blocking): manifest stdout_keys for non-BMP are listed in fixture insertion order; harness re-sorts, so behavior is fine — sorting the JSON list would just read clearer.
CI: build still in progress at review time — merge only after green.
howlcipher
marked this pull request as ready for review
September 30, 2026 02:36
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Phase 1 of improvement #90. This does not move execution onto HFIR.
-compile-bcis stillrunHFIRGateand thenbytecode.CompileToBytecodeon the AST.-compile-hfir-bcstays the experimental lowerer.The contract is
docs/reference/lowered_hfir_abi_v1.md(lowered-hfir-abi/v1). It covers typed values, the call shape the hosts already share, the lack of a linear-memory import, error classes, pure effects versusenv, and Wasm feasibility. CFG/SSA is specified as the later shape.LowerASTstill leavesControlEdgesempty, anddefun,call, andwhilestill failLowerToBytecodewithHFIR_BYTECODE_UNSUPPORTED.The suite is
tests/conformance/lowered_hfir_abi_v1.json, run by the existingtools/difftestharness:if, under an empty grantmap_keys(including the #109 UTF-8 byte-order fixtures) andmap_getabsence (#103)map_keysTYPE_ERROR(#108)envdenial on the interpreter and the bytecode VM, andenvgranted on those hosts plus GoJavaScript runs the same
cli_appbody with the root rewritten toweb_app. Wasm is not executed. Its v1 rejection set is exactlyexec,spawn_agent, andhttp_server_start(HFIR_TARGET_INFEASIBLE), viahfir.WasmInfeasibleKinds. No new opcode, no module linker, no Wasm collection growth.Phase 2 (not this PR)
One lowered graph consumed by every host. That includes calls and
while, populated control edges, capability mediation on Go and JavaScript, one feasibility table for every target, and any Wasm growth (#73 / #84 stay behind that).Generated Go still calls
os.Getenvwith no grant check. JavaScript has noenv. Those hosts are intentionally absent from the denial case.Review notes for Motoko
improvements.mdis Partial — Phase 1, not Done.docs/journals/2026-09-30_lowered_hfir_abi_phase1.md.go test ./...passed, including./tools/difftestand./internal/hfir.Please comment. Do not merge.