Limited ArrayBuffer S1
Proposal details
- Stage: Stage 1
- Status: Active
- ECMAScript edition: —
- Synchronized: Aug 28, 2026
- 中文译文 · Source repository
Proposal overview
This proposal addresses the lack of read-only and range-limited views for ArrayBuffer, which prevents enforcing minimal permission/information principles. It proposes freezing ArrayBuffer to make it and its views read-only, and optionally creating range-limited views.
Note
The README below comes from the upstream repository and may contain outdated stage or status metadata. Use the proposal details above as the current source of truth.
Limited ArrayBuffer
Status
Champion(s): Jack Works
Author(s): Jack Works
Stage: 1
Presentations
Problem to be resolved
All of the following are helpful to archive the minimal permission/information principle.
- Cannot make an
ArrayBufferread-only. - Cannot give others a read-only view to the
ArrayBufferand keep the read-write permission internally. - Cannot give others a view that range limited (only a small area of the whole buffer is visible).
Design goal
- Freeze the
ArrayBuffer.- Like
Object.freeze, there is no way back once frozen. - Any
TypedArray/DataViewto the freezedArrayBufferis read-only too. - [Optional] Keep frozen when sent across Realm (HTML intergration).
- Like
- Read-only
TypedArray/DataViewto a read-writeArrayBuffer.- Must not be able to construct a read-write view from a read-only view.
- [Optional] Range-limited
TypedArray/DataViewto a read-writeArrayBuffer(CrimsonCodes0's use case on WebAssembly).- Must not be able to construct a bigger view range from a smaller view range.
- Not adding too much complexity to the implementor.
Pros
- Minimal permission/information principle works on
ArrayBuffer. - Embedded JS engines can represent ROMs as read-only
ArrayBuffer.
API design
See design.md