HowlFrame #90 Phase 2a: mediate env on Go and JavaScript - #54
Merged
Merged
Conversation
Empty HOWLFRAME_ALLOW_CAPS denies (env) with CAPABILITY_DENIED before the read. The environment grant returns the value. Production -compile-bc stays on the AST. Co-authored-by: William Elias <wylelias.123@gmail.com>
howlcipher
commented
Sep 30, 2026
howlcipher
left a comment
Owner
Author
There was a problem hiding this comment.
COMMENT OK (Motoko) on head d5524cb — Phase 2a only; #90 stays Partial.
Scope check
- Go + JS
(env)→howlFrameEnv; empty/missing/HOWLFRAME_ALLOW_CAPSwithoutenvironment→CAPABILITY_DENIEDbeforeos.Getenv/process.env[key]; grant returns value; no secret in stdout/stderr/crash. - Conformance:
env_denied/env_grantedon interp / VM / Go / JS (javascript_root: web_app); difftesthostGrantValue+commandEnv. - Production
-compile-bcunchanged; no linker / CFG / SSA / Wasm / path flip; no new cap kinds; #102–#105/#108 not reopened. - Docs/journal honest: Phase 2a Done, Phase 2 remaining; other generated host effects still unmediated.
Hard nos
Clean.
Non-blocking
CI build still in progress at review time — EM undraft + squash when green.
EM: clear to undraft + squash-merge when CI green. Do not mark #90 Done.
howlcipher
marked this pull request as ready for review
September 30, 2026 02:51
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Phase 2a only
This is the Motoko slice for improvement #90 Phase 2a: generated Go and JavaScript mediate
(env)the same way the interpreter and the bytecode VM already do. It is not the rest of Phase 2. Do not merge as a claim that #90 is Done.What changed
(env key)in generated Go and JavaScript goes throughhowlFrameEnv.HOWLFRAME_ALLOW_CAPS(comma-separated, the same names as-allow-caps).environmentisCAPABILITY_DENIEDbeforeos.Getenvorprocess.env[key]. The secret is not printed.environmentgrant returns the value.tests/conformance/lowered_hfir_abi_v1.jsoncovers denial and the granted case on the interpreter, the bytecode VM, Go, and JavaScript.docs/journals/2026-09-30_lowered_hfir_abi_phase2a_env.md.Explicitly not in this PR
-compile-bconto the HFIR lowerer.ControlEdges, CFG, or SSA.call/whileon the experimental lowerer.read_file,exec, and the rest) are still unmediated.Tests
gofmt -lis clean,go vet ./...is clean, andgo test ./...passes, including the ABI conformance cases for env denial and the granted read.