Repository navigation
C1+C2: required-caps report + governed profile - #110
Merged
Merged
Conversation
Review C1 (P0.5): bytecode.RequiredCapabilities computes the union of opcode capabilities, store-URI requirements and lazy CALL (conservatively all capabilities, since generated code executes). Exposed without execution as `howlframe inspect --caps <artifact>` and legacy `-required-caps`, emitting compact deterministic JSON. Review C2 (P0.3): `check|build --profile=default|governed`. The governed profile rejects lazy_synthesize, ephemeral_circuit, neural_circuit, achieve, confidence, llm_generate, exec, spawn, db_connect/sql_query, include outside the root, and Go/JS targets, with the stable code PROFILE_FORBIDDEN_CONSTRUCT, before any output is written. Default behavior is unchanged. No HFBC wire change. Production -compile-bc is still AST bytecode, #90 stays Partial. Legacy -profile flag support is deferred. Tests: rule tables, seven-site AST scan, source conformance, corpus and hermetic execution soundness, profile drift, and CLI coverage. Co-authored-by: howlcipher <howlcipher@users.noreply.github.com>
howlcipher
commented
Oct 6, 2026
howlcipher
left a comment
Owner
Author
There was a problem hiding this comment.
Motoko COMMENT on head b7090de3eed7d0fdd0dcf26ea168e2da36b63a27 (base c6c7275d).
Verdict: merge-ready (CI build green). Diff matches claimed C1+C2 scope.
Checked
- C1:
bytecode.RequiredCapabilitiesis a deterministic, non-executing over-approx: opcode Registry caps ∪ store-URI requirements onSTORE_OPEN∪ all caps for lazy/unknownCALL. Sorted output. CLI:inspect --capsand-required-caps. - C2: governed allow-list rejects claimed constructs (plus
spawn_agent), outside-rootinclude/use, and Go/JS targets withPROFILE_FORBIDDEN_CONSTRUCTviahfir.VerifyProfilepre- and post-expansion, before any write. Default profile short-circuits unchanged. - Hard nos intact:
-compile-bcstillrunHFIRGate→bytecode.CompileToBytecode(no prod HFIR flip); #90 Partial; no tip-lock retake; no DOM; no HFBC wire/opcode change (HFBCFormatVersionstill"1"); no C4/C5/harness. - Tests cover unit caps/profile, seven-site VM conformance, hermetic execution incl. lazy synthesized FS write, CLI rejection-before-write, corpus soundness under exact grant.
Non-blockers
- Legacy bare
-profilestill deferred (onlycheck|build --profile) — as documented. - “Seven-site AST scan” wording is slightly off: seven sites live in VM conformance for
requireCapability; construct side is profile table +ScanProfile. - Caps report is program-wide conservative union, not path-sensitive (acknowledged).
Draft left draft. Okabe: undraft + squash-merge when ready.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What landed
bytecode.RequiredCapabilities= union of opcode capabilities + store-URI requirements + lazyCALL(conservatively reports all capabilities because generated code executes). Deterministic, compact JSON, no execution.governedrejectslazy_synthesize,ephemeral_circuit,neural_circuit,achieve,confidence,llm_generate,exec,spawn,db_connect/sql_query,includeoutside root, and Go/JS targets with stable codePROFILE_FORBIDDEN_CONSTRUCT, before any output is written. Checked pre- and post-include expansion.CLI surface
howlframe inspect --caps <artifact.hfbc>howlframe -required-caps <artifact>howlframe check --profile=default|governed <src.howl>howlframe build --profile=default|governed [--target=...] <src.howl>Tests
internal/bytecode: RequiredCapabilities rulesinternal/construct: profile tables + seven-site AST scaninternal/hfir: profile diagnostics / driftinternal/vm: source conformance + hermetic execution soundness (incl. lazy generated effects)TestCLIRequiredCapsAndGoverned,TestRequiredCapsFixtureSoundnessgofmt -l .empty,go vet ./...clean,go test ./... -count=1all green locally (incl. difftest, gogen, javascript, vm).Hard nos (respected)
-compile-bcstays AST bytecode; Write flagged http_server bytecode and stop #90 stays PartialDeferred
-profileflag support (onlycheck|build --profilefor now)Sandbox notes
An earlier Codex run hit sandbox-only failures (httptest listen EPERM, JS exec EPERM, difftest); in the final local run the full suite passed.
Journal:
docs/journals/2026-10-05_c1_c2_required_caps_governed_profile.md