Earlier quoted context omitted.
MV3 splits permissions into host permissions and classical permissions (tabs, storage, etc). Putting in your host permission list means that whatever the extension does, it can do it on all possible urls you may visit in the browser. In this sense, it's no different than in MV2. What's different is the classical permissions. Previously you could use the webRequest permission to execute custom JS functions in response…
It's a big difference between letting extension provide some rules and letting extension do whatever it wants with the request.
If you could implement a declarative language as powerful as an imperative one you could solve the halting problem.
So the switch from imperative to declarative is not free to make and Google has thrown the baby out with the bathwater. They just so happen to lose money every second that baby is alive. On the one hand, the decision to implement this specific declarative language is a malicious exertion of market force. On the other hand it's a stunning display of implementation incompetence. The language can't even reimplement the most popular existing extensions.