Skip to content

HowlFrame #90 Phase 2c: mediate read_file on Go and JavaScript - #56

Merged
howlcipher merged 1 commit into
mainfrom
cursor/read-file-filesystem-grant-48b9
Sep 30, 2026
Merged

howlcipher merged 1 commit into
mainfrom
cursor/read-file-filesystem-grant-48b9

Conversation

@howlcipher

Copy link
Copy Markdown
Owner

Summary

Phase 2c of #90 mediates (read_file) on generated Go and JavaScript under the existing filesystem grant (capability.ForConstruct("read_file") / OpReadFile). The runner grant is HOWLFRAME_ALLOW_CAPS, the same comma-separated list as -allow-caps.

An empty, unset, or non-filesystem grant fails with CAPABILITY_DENIED: capability denied: filesystem before os.ReadFile or readFileSync. The denial does not include the path, and the file is not opened. A filesystem grant reads the file.

Go try_let still binds (bytes, error) from howlFrameReadFile, so a granted miss stays an IO error. let and bytes_to_string use howlFrameReadFileBytes. JavaScript returns UTF-8 text after the same check. The interpreter reads only after its existing filesystem check, so the conformance case can include it. The bytecode VM already gates OpReadFile before the read.

tests/conformance/lowered_hfir_abi_v1.json adds read_file_denied and read_file_granted for the interpreter, the bytecode VM, Go, and JavaScript. The fixture reads /tmp/howlframe-abi-v1-phase2c.txt. The conformance test writes phase2c-read-marker there first, because generated Go runs in its own directory.

write_file and mkdir are unchanged. Production -compile-bc is still runHFIRGate then AST bytecode. #90 stays Partial.

Journal: docs/journals/2026-09-30_lowered_hfir_abi_phase2c_read_file.md.

How to test

go test ./internal/backend/gogen/ ./internal/backend/javascript/ ./internal/vm/ -run 'ReadFile|InterpretReadFile'
go test ./tools/difftest/ -run TestLoweredHFIRABIConformance

Denied hosts exit nonzero with CAPABILITY_DENIED and do not print phase2c-read-marker. With -allow-caps filesystem (or HOWLFRAME_ALLOW_CAPS=filesystem for generated hosts) they print that marker.

go test ./... passed locally.

Open in Web Open in Cursor 

Phase 2c of #90: Go and JavaScript mediate (read_file) via HOWLFRAME_ALLOW_CAPS filesystem grant; empty/missing → CAPABILITY_DENIED before any filesystem read. Conformance on interp/VM/Go/JS. Production -compile-bc unchanged; #90 stays Partial.

Co-authored-by: William Elias <wylelias.123@gmail.com>

@howlcipher howlcipher left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

COMMENT OK on head e3f14715 (CI build green).

Phase 2c scope check: Go+JS mediate (read_file) under existing filesystem via HOWLFRAME_ALLOW_CAPS / howlFrameGrantHas; CAPABILITY_DENIED before os.ReadFile / readFileSync; denial text has no path. Interpreter reads only after its existing filesystem gate (honest granted path for conformance). Conformance read_file_denied / read_file_granted on interpreter / bytecode VM / Go / JS. write_file / mkdir / fetch untouched. -compile-bc still AST path. #90 stays Partial.

Hard nos clean: no half bytecode linker / HFIR module smuggle / VM module opcodes; no new caps or opcodes; don’t reopen #102–#105/#108; no path flip; no batch of remaining host effects.

Okabe: undraft + squash-merge when ready.

@howlcipher
howlcipher marked this pull request as ready for review September 30, 2026 04:12
@howlcipher
howlcipher merged commit cfdaee7 into main Sep 30, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants