For AI agents: the complete documentation index is available at /tc39-atlas/en/llms.txt, the full documentation bundle is available at /tc39-atlas/en/llms-full.txt, and this page is available as Markdown at /tc39-atlas/en/proposals/year/pending/proposal-limited-arraybuffer.md.
  • English
  • Limited ArrayBuffer S1

    Proposal details
    Proposal overview

    This proposal addresses the lack of read-only and range-limited views for ArrayBuffer, which prevents enforcing minimal permission/information principles. It proposes freezing ArrayBuffer to make it and its views read-only, and optionally creating range-limited views.

    Note

    The README below comes from the upstream repository and may contain outdated stage or status metadata. Use the proposal details above as the current source of truth.

    Limited ArrayBuffer

    Status

    Champion(s): Jack Works

    Author(s): Jack Works

    Stage: 1

    Presentations

    Problem to be resolved

    All of the following are helpful to archive the minimal permission/information principle.

    1. Cannot make an ArrayBuffer read-only.
    2. Cannot give others a read-only view to the ArrayBuffer and keep the read-write permission internally.
    3. Cannot give others a view that range limited (only a small area of the whole buffer is visible).

    Design goal

    1. Freeze the ArrayBuffer.
      1. Like Object.freeze, there is no way back once frozen.
      2. Any TypedArray/DataView to the freezed ArrayBuffer is read-only too.
      3. [Optional] Keep frozen when sent across Realm (HTML intergration).
    2. Read-only TypedArray/DataView to a read-write ArrayBuffer.
      1. Must not be able to construct a read-write view from a read-only view.
    3. [Optional] Range-limited TypedArray/DataView to a read-write ArrayBuffer (CrimsonCodes0's use case on WebAssembly).
      1. Must not be able to construct a bigger view range from a smaller view range.
    4. Not adding too much complexity to the implementor.

    Pros

    1. Minimal permission/information principle works on ArrayBuffer.
    2. Embedded JS engines can represent ROMs as read-only ArrayBuffer.

    API design

    See design.md