Walk every fetch(url) / http.get(url) / net.connect(host, port) / WebSocket(url) / https.request(...) call site where the URL/host is a string literal (or computed from compile-time constants). Cross-reference against the host's perry.allowedHosts allowlist. Refuse to compile if a literal host isn't permitted.
For non-literal arguments (URL computed at runtime from variables), default-deny — require explicit perry.allowDynamicHosts: true in the host package.json, or per-call-site annotation. The static guarantee: grep-ing the binary's egress is reliable.
Mechanism
HIR walk identifies all egress call sites; literal-or-foldable args checked against the allowlist; non-literal args fail unless explicitly allowed. Zero runtime cost — compile-time analysis only.
Combined with the per-package capability net:<host> token (separate issue), gives static egress control at two granularities: per-package and per-host.
Acceptance
Part of the supply-chain hardening series. Host-app-controlled. Zero runtime cost (compile-time HIR walk only).
Walk every
fetch(url)/http.get(url)/net.connect(host, port)/WebSocket(url)/https.request(...)call site where the URL/host is a string literal (or computed from compile-time constants). Cross-reference against the host'sperry.allowedHostsallowlist. Refuse to compile if a literal host isn't permitted.For non-literal arguments (URL computed at runtime from variables), default-deny — require explicit
perry.allowDynamicHosts: truein the host package.json, or per-call-site annotation. The static guarantee:grep-ing the binary's egress is reliable.Mechanism
HIR walk identifies all egress call sites; literal-or-foldable args checked against the allowlist; non-literal args fail unless explicitly allowed. Zero runtime cost — compile-time analysis only.
Combined with the per-package capability
net:<host>token (separate issue), gives static egress control at two granularities: per-package and per-host.Acceptance
package.jsonperry.allowedHosts: ["api.example.com", "*.cdn.example.com", "https://api.acme.com/v1/*"]fetch/http.get/https.request/net.connect/WebSocketcall sites analyzedperry.allowDynamicHosts: trueperry auditlists every literal egress in the build for reviewPart of the supply-chain hardening series. Host-app-controlled. Zero runtime cost (compile-time HIR walk only).