Skip to content

HowlFrame #90 Phase 2d: mediate fetch on Go and JavaScript - #57

Merged
howlcipher merged 1 commit into
mainfrom
cursor/phase2d-fetch-network-8e84
Sep 30, 2026
Merged

howlcipher merged 1 commit into
mainfrom
cursor/phase2d-fetch-network-8e84

Conversation

@howlcipher

Copy link
Copy Markdown
Owner

Summary

Phase 2d of #90 mediates (fetch url method [body]) on generated Go and JavaScript under the existing network grant. This follows the Phase 2a–2c HOWLFRAME_ALLOW_CAPS / CAPABILITY_DENIED pattern. #90 stays Partial. Production -compile-bc is unchanged.

  • howlFrameFetch checks network before http.NewRequest / http.DefaultClient.Do (Go) or fetch (JavaScript). An empty, missing, or non-network grant panics or throws CAPABILITY_DENIED: capability denied: network and does not open a connection. The denial text does not include the URL.
  • A network grant performs the request. Go try_let still binds (bytes, error). let and bytes_to_string use howlFrameFetchBytes. JavaScript returns the response text.
  • The interpreter sends the request only after its existing network check. The bytecode VM is unchanged: OpFetch is already network, and the gate runs before the request.
  • Conformance adds fetch_denied and fetch_granted on the interpreter, the bytecode VM, Go, and JavaScript. The fixture is (fetch "http://127.0.0.1:47653/howlframe-abi-v1-phase2d" "GET"). Denial records zero requests to that server.
  • write_file, mkdir, and other host effects are not mediated. No new capability, no new opcode, and no Wasm change.

Journal: docs/journals/2026-09-30_lowered_hfir_abi_phase2d_fetch.md.

How to test

gofmt -l .
go vet ./...
go test ./internal/backend/gogen/ ./internal/backend/javascript/ ./internal/vm/ ./tools/difftest/ -count=1

TestLoweredHFIRABIConformance serves phase2d-fetch-marker on 127.0.0.1:47653 and checks that fetch_denied makes no HTTP request while fetch_granted prints the marker on all four hosts.

Local evidence: gofmt -l . was clean, go vet ./... passed, and go test ./... passed.

Open in Web Open in Cursor 

Generated Go and JavaScript check the network grant in howlFrameFetch before any HTTP request. An empty, missing, or non-network HOWLFRAME_ALLOW_CAPS grant fails with CAPABILITY_DENIED and does not open a connection. Conformance covers fetch_denied and fetch_granted on the interpreter, bytecode VM, Go, and JavaScript. Production -compile-bc is unchanged. #90 stays Partial.

Co-authored-by: William Elias <wylelias.123@gmail.com>

@howlcipher howlcipher left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

COMMENT OK on head 32cd2e40 (CI build green).

Phase 2d scope check: Go+JS mediate (fetch) under existing network via HOWLFRAME_ALLOW_CAPS / howlFrameGrantHas; CAPABILITY_DENIED before http.NewRequest / fetch; denial text has no URL; denied cases record zero HTTP hits. Interpreter sends only after its existing network gate. Conformance fetch_denied / fetch_granted on interpreter / bytecode VM / Go / JS. write_file / mkdir untouched. -compile-bc still AST path. #90 stays Partial.

Hard nos clean: no half bytecode linker / HFIR module smuggle / VM module opcodes; no new caps or opcodes; don’t reopen #102–#105/#108; no path flip / Wasm as this item; no batch of remaining host effects.

Okabe: undraft + squash-merge when ready.

@howlcipher
howlcipher marked this pull request as ready for review September 30, 2026 04:33
@howlcipher
howlcipher merged commit 105cd26 into main Sep 30, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants