The manifest pinned `[build] runtime = "../../../runtime/wovm"`, a repo-only
relative path that overrides woc's runtime resolution — so `woc <copied-dir>`
failed off-repo (e.g. an installed toolchain on a test server) with "runtime
binary not found".
- Drop the [build] section: the project no longer hardcodes a machine path, so
an installed `woc` self-locates `wovm` beside its own binary.
- The module justfile's `build` recipe now sets WO_RUNTIME=<repo>/runtime/wovm
so the in-repo build still uses the freshly built VM.
- Acceptance is unaffected (it compiles via `woc --emit` + an explicit $WOVM,
never the manifest [build] key).
Verified: just log-watcher::build OK; just log-watcher 7/0; and building a
copied tree with the installed-layout woc from an unrelated cwd self-locates
the sibling wovm and produces a runnable binary.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Close the 3 gaps between "builds in the repo" and "installs from a tarball
like Go", so writeonce can ship to other developers.
- VERSION file at repo root single-sources the toolchain version (0.1.0).
- `woc version` -> "writeonce 0.1.0 linux/amd64"; `wovm --version` -> "wovm
0.1.0" (stamped by the Makefile from VERSION; --version handled only in the
plain-wovm path so a built app never shadows its own `version` arg).
- wo.toml `[runtime] wo = ">= X.Y"` is now ENFORCED: woc refuses a project
requiring a newer toolchain than itself (>= and bare version parsed;
unknown operators accepted forward-compatibly). Was parsed-and-ignored.
- woc self-locates wovm: --runtime > [build] runtime > $WO_RUNTIME > a `wovm`
beside the woc binary (Sys.executable_name) > runtime/wovm rel CWD. An
installed woc in <prefix>/bin finds its sibling wovm from any cwd.
- `just dist` (scripts/mkdist.sh) packages writeonce-<ver>-linux-amd64.tar.gz,
Go-shaped (archive root writeonce/, bin/{woc,wovm}, README, VERSION), with a
drift guard asserting VERSION == woc == wovm. dist/ gitignored.
- `just install-accept` (scripts/install-accept.sh) is the gate: extract, PATH,
version, build+run a project from an unrelated cwd, constraint refusal — 6/0.
Verified: install-accept 6/0; woc-test 565/0; wovm suites + cli_smoke;
log-watcher 7/0. Linux-amd64 only (a cross matrix is future work).
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Analyzed the full 131-file docs tree (4 parallel classifiers) against the
shipped woc/wovm toolchain. Removed 21 stale docs, kept all intentional
history (Rust-track plans/done, the runtime/database design series cited by
current specs, syscall/postgres/assembly/c-runtime studies, discarded/
learnings). Deleted:
- old-runtime "front door": writeonce-pl.md, runtime/wo-language.md
(pitched the Rust wo runtime -- REST/LiveView/SQL+Cypher -- as the current
language; contradicted the new README)
- v1 design set: 02-recovery, 03-data, 04-ui, 05-datalayer,
06-markdown-render, 07-ssl; runtime/database/05-go-sdk
- future-scope/ai-agents-content-management (unfinished old-runtime CMS)
- the ##ui/.htmlx LiveView frontend track (product decision to abandon):
9 plan/exploration/ui/*, plan/14-mvc-ui-implementation,
superpowers/plans/2026-08-01-ui-htmlx-live; 13d pricing-UI board row
Tree left link-clean: 46 dead links to the removed docs neutralized to plain
text or deleted as pure see-also bullets across 20 kept docs; whole-tree
link-resolving scan reports zero links to any deleted file. Removal recorded
in discarded.md; board Frontend section + project-structure tree updated.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
- README.md now IS the getting-started page (moved from
docs/writeonce.md; single source, no duplication): current
woc -> .wob -> wovm toolchain, system requirements, build, hello-
world, language + stdlib, embedded database, samples, roadmap
- deletes the old README's Rust `wo` runtime pitch (cargo run, axum
REST, Postgres mirror, blog/ecommerce) — that runtime is not
advancing and no longer the project's front door
- content unchanged from the verified doc (hello-world + switch
compiled live before the prior commit)
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
- docs/writeonce.md — external-developer front door for the current
woc -> .wob -> wovm toolchain (NOT the stale root README's old Rust
wo runtime): what writeonce is, system requirements, how to build
the toolchain, hello-world + the two build paths, language surface,
stdlib, the embedded database, project/manifest layout, samples
- shipped-only by decision: every feature described compiles and runs
today; hello-world + switch snippet verified live before commit;
employee/log-watcher cited as the working acceptance samples
- unshipped roadmap (aggregates, HTTP service, concurrency/fibers,
cross-program attach + keypair auth, blue-green, @derive) kept in a
clearly-separated Roadmap section, plus named current limits (net
TCP-only, proc.run no timeout, no stdin/stdout, no FFI)
- note: root README.md is stale (documents the older Rust axum/REST
runtime, no mention of woc/wovm); left untouched, flagged for the
developer
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
- frames a writeonce port of ~/projects/skillhost (C++ MCP host that
links libllama in-process, discovers filesystem skills, runs their
scripts confined) as the sample that drives host capabilities into
the open — the way log-watcher drove the systems stdlib
- names each gap as a candidate iteration (surveyed 2026-08-16 vs the
running compiler + skillhost source):
- Blocker A: in-process native-lib FFI (no FFI today) — fork:
FFI-as-language vs out-of-process model driver over proc/net+json
(llama-server, needs nothing new); leaning out-of-process
- Blocker B: stdio transport — no stdin/stdout builtins; port uses
a TCP socket meanwhile; io.stdin_read/stdout_write a candidate
- Blocker C: bounded/killable subprocess — proc.run has no timeout/
signal/process-group kill; smallest + most broadly useful, do 1st
- partials: recursive fs walk, exec-bit check, symlink-resolving
confinement (realpath) — one small fs-metadata iteration
- records what is already expressible (catalog via @table/9g skill-
catalog, discovery, frontmatter text-parse, config, single-thread
serve, context-gate arithmetic — no VRAM query needed)
- out of scope: in-process libllama/CUDA, VRAM introspection, exact
sampler chain / per-turn memory clear
- roadmap + board rows added
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
- method: an embedded-SQL app is a grammar corpus; catalogue what it
actually uses and add only that, translating its statements 1:1 as
the acceptance (the postgres/System.Linq reference pattern applied to
a whole application)
- corpus #1 = ~/projects/skillhost (C++ MCP host, embedded SQLite skill
catalog): surveyed, entire SQL footprint is one file — 1 table, a
single-row parameterized INSERT, 4 SELECTs. 3 of 5 statements already
run on the 9b surface (insert, where name==?, order by name; PK ≈
@unique). Exactly 2 are the real gap:
- whole-query `count` (group-free; the degenerate aggregate, NOT
the parked group-by)
- correlated `not exists` subquery (skillhost's roots-of-the-tree)
- notable finding: skillhost's NOT EXISTS is naturally a `backlink`
emptiness in writeonce (children backlink + len==0), so the corpus
may be fully expressible once len(query) is confirmed — the iteration
may collapse to "confirm len(query) + add exists"; forks record this
- explicitly parks everything skillhost does NOT use (join/having/
offset/distinct/CTE/window/union/upsert/returning/json/fts/triggers)
and the full group-by; each enters only when a corpus demands it
- acceptance: docs/examples/skill-catalog mirroring skillhost's schema
+ its 5 catalog ops as writeonce translations
- roadmap + board rows added
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
- FK restrict: deleting a row a non-nullable `ref` still points at traps
WO_T_FK (11), catchable. The compiler now records a `ref` field's
target class in the class-table field_class metadata; the engine
(wo_row_has_referrers) scans referencing scalar columns before a
delete. Correctness-first full scan; the backlink-index optimization
is recorded for later
- docs/examples/employee now COMPILES AND RUNS all six modes against a
WAL-durable database: seed (+@unique trap across restart), report
(per-dept aggregates + payroll), staff (unique probe + backlink +
ref nav), raise (update-through-row), drop (FK restrict), and
persistence via replay
- group-by SYNTAX parked to a future iteration (user decision): the
report mode is hand-rolled from the shipped primitives meanwhile
(same numbers). "table relations and FK" is complete
- scripts/employee-accept.sh (8 checks) + a `just employee` module;
manifest parser tolerates iteration 9c's [share]/[[share.clients]]
sections so `woc .` builds the sample on this branch
- fixtures trap/db-fk-restrict (code 11) + run/db-fk-restrict-catch;
oop-e2e 79/0, woc-test 566/0, 15 runtime suites, log-watcher 7/0,
employee-accept 8/0
- 9b story + status board updated
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
- `e.field = v` where e is a table row lowers to DB_UPDATE_FIELD
(class, id, field, value) — the row's indexes maintained at the choke
point; heap-object field assignment still emits SETF unchanged
- `delete <row>` expression: DB_DELETE(class, id), yields the id so it
composes in `try delete x catch (e) nil` (restrict/trap surfaces
catchably); Delete AST node threaded through type/owner/dump/emit
- disassembly-caught bug fixed: in tail position dst == the builtin
window's first reg, so moving the id into dst clobbered the class id
— reserve dst past the window (the emit_ctor guard)
- run/db-update-delete fixture; oop-e2e up, woc-test 566/0,
log-watcher 7/0
- employee seed/list/staff/raise/drop now compile+run; only `report`
(group-by aggregation + projection record) remains
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
- `order by <field> [desc]` on whole-row queries: a selection sort over
the result multi, re-reading the key per element via the range var
(DB_GET_FIELD); O(n^2), KISS, no cost planner — the result sets are
small by design
- Text order keys use a new WO_B_STR_LT builtin (content compare, reusing
the WO_B_SORT elem_cmp); scalar keys use the LT opcode. The bug this
fixes: op_lt on two Text pointers compares ADDRESSES
- `take N`: clamp to count, slice [0,N). `take` is the KwTake keyword,
not an Ident — matched as the token
- two bugs found + fixed while testing: multi-line query clauses (skip
the separating newlines) and the key-kind read (must bind the range
var BEFORE ty_of_expr of the order key, or a Text key silently uses
op_lt); Index typechecks to the container's element type (`ds[0]`)
- fixture run/db-query-order; oop-e2e 75/0, woc-test 566/0, 15 runtime
suites, log-watcher 7/0
- employee `seed`/`list`/`staff` modes now compile and run; report
(group-by+projection), raise (update), drop (delete) remain
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
- `backlink C.f` field type: parsed, typed as `multi C`, and VIRTUAL —
filtered out of the stored row layout (no column, omittable in
ctor/insert), collected in clsrec.cr_backlinks
- reading a backlink (`d.staff`) lowers to DB_PROBE on the source
class's index for the backing column (backlink_target resolves the
(source class, index number); a backlink with no backing index has
no efficient read)
- `ref C` navigation (`e.dept.name`) chains: a ref value is the target
row's id, so a `Ref C` base navigates into C's fields exactly like a
table-class value, routing to DB_GET_FIELD both in typecheck and emit
- query navigation source `from s in d.staff`: emit_query evaluates the
nav expr to get its id-list instead of DB_SCAN; QNav typechecks with
the range var bound to the navigation's element class
- fixture run/db-query-relations proves both directions; oop-e2e 75/0,
woc-test 566/0, log-watcher 7/0
- still ahead for employee: order/take, group-by aggregates, projection
records, delete + update-through-row
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
- captures the toCSV/reflection thread: principle 13 forbids runtime
reflection, so a generic serializer can't be a user-written function;
Rust answers with derive macros (compile-time codegen), and
json.encode is already a single hand-built instance of exactly that
- iteration generalizes json.encode's mechanism into a reusable derive
facility: @derive(Json/Csv/Eq/Hash/Show) -> the compiler generates
per-type routines from the class-table metadata it already emits,
monomorphic, no runtime type tag, no dynamic dispatch
- closes the query-result-serialization gap
(csv.encode(from e in Employee ... select e)) that has no expression
today; acceptance requires json.encode retrofitted onto the framework
with byte-identical output, and disassembly proving no reflection
- four forks: request surface (lean @derive annotation), invocation
(lean compiler-recognized encode builtins, no UFCS/methods), Eq/Hash
sharing the engine's key comparison, static applicability checking
- out of scope: full trait/typeclass system, user proc-macros, general
generics, cross-channel derive -- a CLOSED compiler-known derivable
set, the pragmatic 80% without the type-system weight
- numbered 13 to echo the principle it lives inside; roadmap + board
rows added
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
- Ast.Query node + parser: `from <v> in <src> where* [group..into] [order
by] [take] select <e>`, positional `from` trigger so it stays a usable
identifier; select stays grammar-owned (no DbStub conflict)
- typecheck: range var bound to the source table class; a table-class
value is its row id at runtime but TYPES as the class, so `e.field`
checks against the class fields; result is `multi <select-type>`;
group/order/take/navigation diagnosed WO-E250 not-yet (honest edge)
- emit: `from/where/select` lowers to a bytecode LOOP over DB_SCAN's
materialized id list — DB_GET_FIELD per column read, where-guards skip
the push, select projects, result is a fresh multi; no plan tree, no
SQL text (disassembly-provable)
- field access on a @table-class value routes to DB_GET_FIELD instead of
GETF (clsrec.cr_is_table + is_table_class); non-table classes unchanged
so log-watcher is unaffected
- the ASan-caught bug kept in a comment: a table-class query element is a
SCALAR id, not an OWNED pointer — tagging the result multi OWNED dropped
an id as a pointer (SEGV in wo_drop_obj)
- fixture run/db-query-scan (where-filter + select-whole + select-field);
oop-e2e 74/0, woc-test 566/0, log-watcher 7/0
- SLICE scope: group-by aggregation, order/take, and ref/backlink
navigation are the next chunk (employee report/staff/raise need them)
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
- DB_SCAN(64): class -> multi<Int> of every row id, materialized up
front (the 9b cursor-stability rule: the loop body point-reads, so a
row updated mid-loop cannot disturb iteration)
- DB_GET_FIELD(65): class,id,field -> the field decoded to a fresh VM
value (the out-gate copy); a table-class value IS its row id at
runtime, so this is how a compiled query reads a column, and a ref
field decodes to the target id for navigation
- DB_PROBE(66): class,index,key -> multi<Int> of ids whose first
indexed column equals key (backlink + indexed where)
- wo_val_decode_vm wrapper exposed; dispatch range 61..66, loader
arities, runner mirror updated
- 15 runtime suites green, oop-e2e 73/0
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
- 9e durability/throughput/scale: the measurement backbone -- run the
employee program, restart to prove persistence, benchmark read/write
through compiled .wo, ~1M-row mixed load with throughput floor + p99
ceiling + flat RSS; the gate every optimization signs (before/after
delta required, no measured delta = not accepted)
- 9f io_uring group-commit: replace fsync-per-commit with batched
io_uring durability overlapped on shard threads; same ack-after-
durable contract, crash battery unchanged, automatic fsync fallback
on kernels without it; deliberately LAST (needs 8's threads to
overlap and 9e's baseline to beat)
- wired the existing levers into the arc: iteration 8 (thread-per-core)
= "optimize multithreading", 7b (mark-sweep) = "implement GC" --
each now gated by re-running 9e and recording the delta
- explicit sequence recorded in 9e: 9b lands -> 9e baseline -> 7b
re-bench -> 8 re-bench -> 9f re-bench
- roadmap + board rows for 9e/9f; four forks each for the specs
(load generator, absolute vs relative budgets, what "1M" means,
durable vs RAM headline; ring model, liburing vs raw, batch
boundary, fallback testing)
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
- Task 6 note: db fixtures live in existing corpus kinds; crash battery
proven at unit level; select fixtures wait on 9b's read surface
- board row updated
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
- wo_row_update_field: encode new value, unique re-check against a
shadow BEFORE any mutation (violating update leaves the row
untouched, DB_ERR_UNIQUE), index entries moved old-hash -> new-hash,
old engine value freed; proven by test_table (unique refusal keeps
the row, released key becomes insertable)
- WAL UPDATE record: full-row re-log, replay = replace (remove +
re-create same id); prefix/suffix delta recorded as later
optimization; test_wal replays insert+update to the updated state
- builtins 62 DB_UPDATE_FIELD (cid,id,field,value) and 63 DB_DELETE
(cid,id), commit-before-ack like insert, WO_T_UNIQUE/WO_T_DB/WO_T_IO
mapping; dispatch range 61..63; loader arities; runner mirror
- plan Task 5 marked superseded-in-part with the recorded deviation:
the language surface (reads, queries, row views, delete statement)
is 9b's, where the comprehension design put it -- no interim brace-
select grammar to retire later
- gates: test_table 839/0, test_wal 102/0, 15 suites, oop-e2e 73/0
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
- .wob v3: class records carry an index tail (flags bit0 = unique,
col_cnt, columns) -- @table(index:[a,b]) entries plus one unique
single-column entry per @unique field; loader validates columns in
range and scalar/Text-kinded; emitter validates the declarations
(unknown column, un-indexable kind => diagnostic)
- engine: db_index hash multimap per table, built from the class
table at first touch, maintained ONLY inside wo_row_insert/
wo_row_remove; unique checks re-compare actual column values (a
hash is a hint); replay re-indexes via wo_row_raw_commit AFTER
slots are filled, so recovered tables carry their indexes
- WO_T_UNIQUE = 10; a violating insert is un-applied whole (bitmap,
hash, count, and the never-observable id reclaimed) and traps
catchably -- the employee SEED-DUP pattern
- wo_row_insert gains err_kind so db.c maps UNIQUE/OOM/other to the
right trap; test images and the runner's loader mirror speak v3
- fixtures: trap/db-unique-violation (code 10 exact) and
run/db-unique-catch (catchable dup, composite index accepts
duplicates, next id dense after a refusal)
- gates: oop-e2e 73/0, all 15 runtime suites, woc-test green,
log-watcher 7/0
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
- docs/examples/employee-list: attaches to the running employee
program; modes list / report (byte-identical to A's own) /
staff <dept> / probe-write (registered read-only, insert must trap
access-denied, exit 4, A unchanged)
- the manifests ARE the design, written as a pair: A's [share] gains
listen = unix socket beside WO_DATA plus [[share.clients]] naming
B's public-key fingerprint with rights = "read"; B's
[connect.employee] carries A's ipc string, A's PINNED fingerprint,
and project = ../employee for compile-time shapes -- the connect
section's name is the code's namespace (employee.Employee)
- fingerprints are PASTE-HERE placeholders by design: keys generate
into WO_DATA at first boot (9d), tomls carry fingerprints only,
printed by --identity
- sample-first: compiles after 9/9b/9c/9d; README maps each mode to
the acceptance line it exists for; 9c/9d stories now name this
sample as their workload
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
- promotes 9c's identity fork to its own iteration: program identity
is a keypair (first-boot generated into WO_DATA, 0600, printable
fingerprint); A's [share] grants name PUBLIC KEYS, B pins A's key
in [connect.a]; mutual challenge-response, fresh nonces, transcript-
hash signing (protocol tag + fingerprints + nonces + channel)
- acceptance criteria: registered-key attach carries 9c rights
unchanged; unregistered key refused pre-statement with fingerprint
logged; same-uid-wrong-key refused (uid SUPERSEDED, not
supplemented); impostor on A's socket path aborted by B's pinned-key
check; handshake replay refused; rotation = manifest change
- four forks recorded: crypto provenance (lean: vendored compact
Ed25519 as the one sanctioned vendored component), keygen home
(lean: first-boot into WO_DATA), signed-transcript layout, uid
survival (lean: keys only, peer-cred demoted to log enrichment)
- out of scope: transport encryption, CA machinery, key escrow,
root-attacker protection
- plan folds into 9c's when specced (neither ships alone); 9c fork 3
marked superseded-as-end-state; roadmap + board rows added
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
- program B attaches to running program A's persistent database via an
IPC string in B's wo.toml [connect.<name>]; A registers clients by
name with read / read+write rights in its [share] manifest section;
unregistered = refused at connect, under-privileged = catchable trap
- doctrine preserved: A stays the single writer -- B's statements
execute inside A through the same choke-point row API, B never
touches A's WAL or slabs; typed statements checked by B's compiler
against A's table shapes, schema handshake at attach
- four forks recorded for the spec: channel carrier (lean: unix
socket + SO_PEERCRED), how B's compiler learns A's shapes (lean:
project reference + live handshake), grant granularity (lean:
whole-db rights, name+uid identity), blocking semantics (lean:
blocking round-trip, stop-flag rule applies)
- acceptance sketch: employee sample as A, a thin employee-report
client as B (read-only GroupBy over the wire) + audit-log writer
exercising the rights matrix
- slots after 9b (shares its typed surface), before 10 (HTTP is the
external face; this is the writeonce-native one); prior art:
04-client-api.md wire protocol + the WAL's value encoding
- roadmap + status board rows added
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
- compiler: `insert Class { ... }` is a typed Ast.Insert in statement
AND expression position, sharing the ctor literal's field grammar;
typechecked with the ctor's omittable rule; result = the row id (Int)
- owner pass: the engine copies at the row API, so an insert BORROWS
its field values -- no transfer, no E304; node is trap-capable and
carries a live-mask drop entry like DbStub did
- emit: builtin 61 window = class-id const + one slot per DECLARED
field in declaration order; omitted defaults emitted, omitted ?scalar
gets WO_NIL_SCALAR, other omitted optionals the zero word; fresh
argument values reaped after (the push/set copy semantics)
- runtime: database/src/db.c executes via the choke-point row API;
rt.db/rt.wal opaque handles on wo_rt; WO_DATA=<dir> = replay
<dir>/shard-0.wal at boot + commit-before-ack per statement (the
builtin's return IS the ack until iteration 8 ticks); failed commit
un-applies the row and traps WO_T_IO; loader validates the class-id
slot (variable window documented in wob.h + format doc)
- the promised diff: trap/pricing-set-price-db-stub is now
run/pricing-set-price-insert printing engine-allocated ids;
durability smoke prints 1,2 then 3,4 across two WO_DATA runs
- old "bare insert is an Ident" unit test rewritten to the new
contract; runner's loader mirror accepts id 61; goldens re-blessed
- gates: oop-accept ALL CRITERIA MET, oop-e2e 71/0, woc-test 566/0,
wovm-test green, log-watcher 7/0
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
- database/src/wal.{c,h}: framed records len|crc32|payload|mark
("WOL1" written last -- no mark, no record), typed-row payloads
walking the class-table kinds (nested records, containers, nil
encodings), little-endian like the loader
- commit order verbatim from the shipped phase-D pattern: RAM apply,
stage, ONE pwrite + ONE fdatasync for the batch, ack after -- group
commit is everything staged riding one sync
- replay decodes straight into engine-owned values (no VM at boot)
and re-enters rows through the choke-point row API, so Task 4's
indexes will rebuild for free; next_id advances past replayed ids
this shard owns (wo_row_create_raw)
- torn tail = short/CRC-fail/no-mark/zero-len: intact prefix applies,
tear dropped whole, wo_wal_open positions AT the tear so the next
commit overwrites it; CRC-valid-but-undecodable = corruption, loud
- wo_wal_check: offline oracle, no engine needed -- the crash
battery's verifier
- test_wal 90/0 ASan+UBSan incl. five crash-battery rounds (fork,
insert/commit/ack-over-pipe, SIGKILL mid-stream: zero acked-but-
missing, zero acked-but-wrong); all runtime suites green, oop-e2e
71/0; binding doc WAL section + CODE-LOGIC + plan Task 2 checked
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
- database/src/table.{c,h}: per-shard per-class slabs (256 rows,
malloc'd, never moved -- row addresses stable for 9b's row views),
occupancy bitmap, LIFO slot reuse, open-addressing id hash with
tombstones (ids never 0, never reused)
- field encoding walks the same .wob class-table kinds the VM walks:
scalars raw (WO_NIL_SCALAR passes through), Texts copied to db_text,
owned objects flattened recursively to db_rec, containers
element-wise; GCREF refused at encode (the GC bulkhead, defensively)
- two one-way copy gates: insert copies VM values in, read allocates
fresh VM values out -- no VM pointer in a slab, no slab pointer in
the VM, proven by mutating originals after insert
- id discipline: per table per shard, S+1 step N; owner = (id-1) % N;
N-parametric, runs at N=1 until iteration 8, tested at N=3
- choke points: wo_row_insert/wo_row_remove carry the INDEX HOOK
sites Task 4 attaches to; nothing else mutates storage
- runtime/Makefile links database/src into every wovm + test binary
- test_table 827/0 ASan+UBSan; oop-e2e 71/0; log-watcher 7/0;
binding doc docs/plan/oop-vm/04-db-binding.md; CODE-LOGIC.md beside
the code; plan Task 1 checked off
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
- 9b spec gains section 6 "Ownership, borrows, and GC across the
engine boundary": two one-way copy gates (no VM pointer enters a
row, everything a select returns is copied out), so the collector
never traces engine memory and the engine never touches refcounts
- row views are borrows WITHOUT a runtime net: rows share the VM's
field encoding but not its header, so no borrow word backs them --
the compile-time escape rule is load-bearing alone
- cursor stability settled: scans materialize their id list before
the body, row updates through the view stay legal (raise mode
updates an indexed column mid-scan and is the proving fixture),
insert/delete on a table with an open cursor is a new WO-E5xx
- GC-pause interaction recorded: collector runs between statements,
a long scan delays slices -- accepted, documented
- iteration-7b ordering constraint: GC inference must classify before
table-field validation, diagnostic names the inference reason --
noted in 7b story, iteration-9 plan constraints, 9b plan tasks
- stories 09/09b Info sections point at the analysis; 9b plan Tasks
3/5 carry the enforceable checkboxes (ASan boundary assertion)
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
- docs/examples/employee: Department/Employee @table classes with
@unique, [dept] and [dept, salary] indexes, ref/backlink pair;
modes seed/report/staff/raise/drop per the 9b spec section 6 —
written AHEAD of the features (sample-first, like log-watcher);
README states it does not compile on today's toolchain and links
the plans that compile toward it
- report mode is the GroupBy showcase: group-and-reduce projection
{headcount, avg, min, max} ordered by avg desc, whole-query sum
for payroll; staff proves both navigation directions + index probe;
drop proves delete restrict (trap asserted)
- engine directory decision (user, 2026-08-15): database/ is its own
top-level dir, statically linked into wovm — file structures updated
in the iteration-9 plan and the 9b plan
- gap found by writing the sample: iteration 9's subset lacks a
`delete` statement and restrict needs one — added to 9b plan Task 3
- 9b plan Task 6 notes the sample is pre-authored and authoritative
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
- spec settles 9b's three forks: SQL/Cypher layer superseded as the
program surface (design history + wo-db engine-semantics reference);
comprehension syntax desugared at compile time (no function values);
System.Linq = operator vocabulary + edge cases, PostgreSQL = execution
+ integrity vocabulary (both references surveyed 2026-08-15)
- aggregate semantics normative: count/sum total 0 on empty, avg/min/max
are ?T with nil (empty is data, not a fault); nil skipped; sum wraps
like language arithmetic; GroupBy lowers as group-and-reduce
(AggregateBy shape), transition/finalize ABI from nodeAgg
- relations: ref = FK with direct-index-probe check (nil passes,
unchanged-key skips), backlink = secondary-index scan, delete is
restrict-only; nil never joins, nil is a legal group key
- lowering: the compiler is the planner — queries become bytecode loops
over cursor/group builtins, longest-prefix index selection, no plan
tree, no SQL text in the image (disassembly-provable)
- plan: 6 tasks gated by a new docs/examples/employee sample
(Department/Employee, @unique, composite index, ref/backlink,
GroupBy report mode) with its own acceptance script + crash step;
blocked on iteration 9's engine plan
- story 09b + status board updated; 02-wo-language.md carries the
supersession note
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
- docs/examples/{agent-loop,blog,ecommerce,hello,mcp-think,pricing}
removed; every deleted tree is preserved on branch
cleanup/non-logwatcher-examples (snapshot of this branch pre-delete)
- justfile: hello/pricing/pricing-demo/pricing-pg-demo/hello-demo
recipes removed with the examples they served (Rust-runtime demos);
rt-c-* prototype recipes and every gate recipe stay
- crates/rt parser test article_debug: the blog fixture it read from
disk now lives inline, same shape, so cargo test needs no example
- gates after cleanup: cargo test -p rt 69/0, oop-e2e 71/0, woc-test
green, log-watcher 7/0
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
- docs/examples/log-watcher/justfile carries build/accept/soak; the
root mounts it with `mod log-watcher`, so `just log-watcher` still
runs the acceptance (default recipe) and every doc reference stays
valid; `just log-watcher::build` / `::soak 60` reach the rest, and
plain `just build` works from inside the directory
- ROOT is source_directory()-based: inside a `mod`,
justfile_directory() names the ROOT justfile's directory and every
path would miss
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
- log-watcher-build: `woc <dir>` manifest build, output at
docs/examples/log-watcher/target/log-watcher
- log-watcher-soak [DURATION=30]: the acceptance script's opt-in soak
- log-watcher's comment now names the stop check it grew in Task 4
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
- a directory carrying wo.toml is a PROJECT: `woc .` inside it (or
`woc path/to/project` from anywhere) reads the manifest and produces
<target>/<name>, exactly what `woc build <dir> -o ...` produces
- schema is the one the sample already carried -- top-level name/
version/description, [runtime] wo (accepted, not yet enforced) --
plus a new [build] section: runtime (wovm to prepend) and target
(output dir, default "target"), both relative to the manifest's own
directory so the build is invocation-point independent
- unknown keys and sections are hard errors: a typo'd key silently
ignored would build the wrong thing
- directories WITHOUT wo.toml keep check-only semantics -- the corpus
is full of those; oop-e2e 71/0, woc-test 565/0, log-watcher 7/0
- sample's wo.toml gains the [build] section; target/ gitignored
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
- Task 5: net.close on every path out of a serve iteration (400
included) and the listener on stop; measured 4 -> 54 fds over 50
requests before, 4 -> 4 over 200 after. The loop's comment claimed
the iteration-end drop IS the close -- wrong twice (net.Conn is a
scalar, and a drop would not close an fd); it now says what is true
- Task 6: LW_SOAK=<seconds> in the acceptance script -- each mode under
load, resident+descriptor deltas against a WARMED baseline (warm-up
includes load: cold-to-high-water is not growth), 256 KiB / zero
tolerance; LW_ACCEPT_WOVM soaks another build
- the soak caught ~1.6 MiB/min of in-arena leaks ASan cannot see (the
arena is one allocation to LeakSanitizer); an arena size-class
census + pointer trace attributed five bugs:
- jparse_string sized every decoded string at "rest of the input"
and relabeled len after -- blocks filed on free lists their next
allocation never reads (fs.read_all's mis-size, again); copy out
exact, free at the taken size
- `!=` never dropped fresh operands (headers["authorization"] !=
"Bearer ${key}" leaked both sides per request); Ne now reaps as Eq
- an Int interpolation segment is a fresh int_to_text, not a borrow;
is_borrowed_value_t asks the segment's type
- json.encode(Ctor{...}) had no owner -- record + both field copies
leaked per tool call; its bespoke lowering now drops the argument
- a discarded expression statement owns its result: `pop(lines);`
leaked the popped element; reader builtins excluded
- after: arena live bytes flat per request on every handler; release
soak 30 s per mode watch 0 / run 0 / mcp +20 KiB, descriptors flat;
ASan build flat at 14600 KiB across 601686 requests in 90 s past its
~1200-request quarantine warm-up
- gates: oop-accept ALL CRITERIA MET, oop-e2e 71/0, woc-test 565/0,
wovm-test green, log-watcher 7/0 (soak opt-in, fast path <1 min)
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
- blocking stdlib calls that PARK (net.accept, socket read/write,
time.sleep, a child wait) no longer restart the syscall when the
stop flag is set on an interruption: a server sitting in accept
ignored SIGTERM and only `kill -9` ended it
- a stop is NOT a trap -- builtin.h's WO_SYS_STOPPED carries no error
record and no catch handler sees it (`try` must not swallow
SIGTERM); the VM unwinds the whole stack through the same drop
machinery an uncaught trap uses, so nothing leaks on the way out
- wo_vm_call gained a third outcome (1 = stopped); the CLI maps it to
the status the program's own `return 0` would have given, and a
regular-file read keeps its plain EINTR retry -- it does not park
- an ASSIGNMENT was not an ownership boundary: `api_key =
j.mcp.apiKey` moved the field pointer into the local, so the local
aliased the record and the first unwind freed the same string twice
(SIGSEGV in class_free). `let` copied a Text place, assignment now
does too -- the same double free was latent on the normal exit path,
hidden by the order the compiler happens to emit drops in
- log-watcher-accept is 7 checks: the seventh is the stop itself, with
the hard kill demoted to a fallback whose use is the failure
- measured under ASan: mcp parked, mcp after traffic, watch and run
all exit rc 0 with zero leaks; SIGINT behaves as SIGTERM
- gates: oop-accept ALL CRITERIA MET, oop-e2e 71/0, woc-test 565/0,
wovm-test green, log-watcher 7/0
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
- program mode built the entry's `multi Text` of arguments and never
freed it: the entry only BORROWS a parameter (never a `take`, and
the drop tables never drop one), so the runtime that built the
container owns it
- dropped after the entry returns and after a trap alike -- the
container outlives the unwind; `multi_free` recurses, so the
argument strings go with it
- one site covers both invocation shapes: `self_rc` picks the argv
offset, it does not build a second container
- measured: watch, run and the full MCP mix now report ZERO leaks
under ASan -- the clean baseline the soak (Task 6) reads against
- gates: oop-accept ALL CRITERIA MET, oop-e2e 71/0, wovm-test green,
log-watcher 6/0
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
- the drop tables track bindings only, so six shapes had no owner: a
comparison operand (`if parse_expr(s) == nil` abandoned a schedule
record and its five containers per cron line), a borrowed call
argument (a 1 KB string per MCP request), a container read's copy,
a loop's iterable, a projected record, and any of those escaped by
a `return` from inside the statement that built them
- `c[i]` is the one place expression whose register holds a COPY:
no second copy at a boundary (`let u = tokens[0]` copied twice and
abandoned the first), and a drop where every other place is left be
- never drop an argument register after a CALL — the callee's frame
overlaps it; the reap moved into call_window's pre-call stash
- a statement-owned temporary is parked in a LOCAL slot: a loop
reclaims every temp for its body, and the end-of-statement DROP was
releasing the loop counter instead of the record
- reader builtins (get/latest/key_at/val_at) keep arg0 alive — their
result points into it — but their key argument is ordinary
- measured: run 2 112 B -> 64 B, flat 8 s to 20 s; MCP mix 21 312 B /
63 -> 64 B / 1; every handler flat from 2 to 6 requests; the 64 B
left is Task 3's argv container
- gates: oop-e2e 71/0, woc-test 565/0, wovm-test green, log-watcher 6/0
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Measured on the workload's supervisor mode, eight seconds, clean SIGTERM exit:
run 1 051 040 B in 24 allocations -> 2 112 B in 19; watch 128 B in 2 -> 64 B in
1. corpus 71/0, woc runtest 565/0, wovm unit gates green, just log-watcher 6/0.
- owner.ml: `oclass_of` called `Text` a builtin scalar, so it was Copy and NO
Text local was ever dropped — that, not the missing stdlib table, was the
leak. Text is now Owned, which forces an answer for what it does at an
ownership boundary, and the answer is uniform: it is COPIED. Into a
container (push/set/`m[i] = v`, already true), into a field (SETF), out of a
function (return), into a binding (`let s = other`), and into a loop cursor.
The source keeps its value; a freshly built Text stays the caller's and is
dropped at the site
- owner.ml: resolve_callee answers for three shapes it never knew — reserved
stdlib members, builtins, and a class's `static` members — so their results
get a type, an owner and a drop
- vm/builtin: WO_B_TEXT_COPY, the one new builtin the rule needs; SETF copies a
TEXT field in; emit copies a Text read out of a container, bound from a
place, returned from a place, or loaded into a cursor, and drops a freshly
built one after a copying store
- sysio.c: fs.read_all/net.read allocated their cap then relabelled the buffer
with the short length — but wo_str_free sizes a block by its len (no size
headers, obj.h), so a 1 MiB buffer wearing a 30-byte length went onto a
32-byte free list and never came back. They copy out at the true size now
- two regressions the corpus caught, fixed in the same pass: a @gc value read
out of a container is a plain borrow, not an rc-counted alias; and push's @gc
escape is keyed on "push is not a user-declared fn" rather than "the callee
did not resolve", which stopped being true once builtins resolved
- docs: Task 1 closed in the executable plan with its before/after numbers, and
the status board's item 1 records the deeper root cause
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Every remaining item is now traced to a measurement on the sample; anything the
sample does not exercise is deferred by name with the measurement that says so.
- new plan docs/plan/compiler/2026-08-14-logwatcher-executable.md — six tasks
between "it runs" and "you can leave it running": the ownership pass learning
stdlib return types (>1 MB leaked in 8s of `run` mode, one fs.read_all
result), dropping a projected temporary (`for e in parse_dir(d).entries`
leaks the shell per rescan), the runtime's own argv container (128 B every
run), honouring the stop signal in blocking calls (a server in accept ignores
SIGTERM), closing accepted connections (net.close exists, unused), and a soak
that would have caught all of it. Opens with the measured starting point and
closes with an explicit out-of-scope list
- story 7 (log-watcher proof): status banner separating the met compile-and-run
half from the executable half, plus a new Given/When/Then — clean SIGTERM
exit, zero leaks, flat RSS and descriptors across a soak
- story 5: grammar half landed, strictness half deliberately deferred
- story 6: landed for the surface the workload uses, with the two lifetime
defects it exposed pointed at the new plan
- story 7b: recorded as off this workload's path, measured — the sample has no
@gc class, 0 RC_INC/RC_DEC against 78 DROPs
- 00-status.md: NEXT PLAN is the executable list; story table and in-progress
row point at the new plan; deferrals carry their evidence
- plan 8 (haxe-parity): banner now says on hold behind the executable plan, and
its task states are corrected — Task 5 shipped, Tasks 6 and 7 are half done
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
- 08-builtin-surface.md: containers copy a TEXT element/key/value; a freshly
built Text is the caller's to drop, a value read out of a place keeps its
owner; OWNED/GCREF still move and set's @gc retention gap stays open
- 00-status.md: the borrowed-Text double free is struck through as closed by
copy-on-push, with the concrete failure it fixed; new gap recorded — a
blocking accept/read swallows SIGTERM, which belongs to iteration 8's event
loop rather than a patch to the blocking calls
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The unsoundness is closed. All four MCP tools now answer correctly over HTTP
(get_running_crons, list_logs, tail_log -> ["info two","error three"],
search_log -> its match) where `tail_log` used to return
{"isError":true,"text":"tool failed: not a text value"}. corpus 71/0,
woc 565/0, wovm gates green, ASan clean on the container fixtures.
- builtin.c: multi_push, map_set (key AND value) and multi_set COPY a TEXT
element into the container. The container's declared kinds already make it
the owner of what it holds, so storing a caller-owned pointer gave one
string two owners — `push(res, e.log_path)` freed a record's field out from
under it. OWNED/GCREF elements still move (not copyable; the @gc escape
keeps their counting), so `set`'s @gc gap is untouched and still recorded
- emit.ml: `drop_fresh_text` — after push/set and the `m[k] = v` / `m[i] = v`
sugar, a value that was freshly BUILT (call result, `..` chain,
interpolation) is dropped here, while a value read out of a place is left to
its owner. That asymmetry is the point: before the copy the borrowed case
double freed and the fresh case leaked
- obj.c: the runtime's output stream is line-buffered. A long-running program
writing progress with `print` was invisible when stdout was a file or a pipe
(full buffering), and a killed one lost its log entirely; byte-exact
fixtures are unaffected
- scripts/log-watcher-accept.sh + `just log-watcher`: the acceptance test for
the sample — compile, watch (alert), run (schedule), and three MCP checks.
Hardened after it lied to me: a per-run port (a stale server on a fixed port
answered for it), a connect-probe that fails loudly when OUR server did not
come up, replies read by Content-Length rather than to EOF (the sample never
closes), and kill -9 on teardown
- docs: the copy rule is in the builtin surface; the status board records the
gap as closed and adds the new one — a blocking accept/read swallows SIGTERM,
which belongs to the shard-actor runtime's event loop, not to a patch here
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Found by driving the compiled log-watcher's third path — the MCP server. It now
answers real JSON-RPC over HTTP: initialize returns protocolVersion/serverInfo,
tools/list returns the full tool list (1049 bytes of generated JSON), and an
unauthorized request gets 401 {"error":"unauthorized"}. corpus 71/0, woc 565/0,
wovm gates green.
- lexer: `\r` and `\0` escapes. Without `\r` a program cannot write CRLF at
all — the server's `index_of(buf, "\r\n\r\n")` was searching for a literal
backslash-r, so it never found a header terminator and hung on every request
- parser: an interpolated sub-expression now mints node ids from the OUTER id
space. A fresh sub-parser started at 1, so `${...}` nodes collided with the
file's own nodes — and every side table (drops, moves, rc, masks, f_decl) is
keyed by node id. Surfaced as WO-E404 "ownership table names `headers`,
which has no register"; silent misattribution otherwise
- types.ml: `net.Conn` is a reserved SCALAR type (a file descriptor). It was
falling through as "some user class", i.e. WO_K_OWNED, so the frame would
DROP an integer at scope end
- types.ml: confident_typ knows `..` yields Text. Interpolation desugars to a
Concat chain, so without it every interpolated value looked underivable —
which is why the `+`-on-Text check missed two live sites in the workload
- `m[k]` on a map is now the OPTIONAL read (nil for a missing key), while
`get(m, k)` stays the asserting one that traps KEY. That is what makes
`let v = m[k]; if v != nil` — the workload's header lookup — work.
trap/missing-map-key now pins `get(...)`, and the surface doc records the
split
- json.encode of a `json.Value` emits it verbatim (kind 255): an echoed id was
coming back as "1" instead of 1
- disasm: TRY/ENDTRY render instead of ?OP32/?OP33
- status board: the push-of-a-borrowed-Text gap is now recorded with the
concrete failure it produces (tools/call tail_log), plus the leaked
temporary-record shell found in the same disassembly
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Found by running the compiled log-watcher, not by reading code: the supervisor
rejected every cron line ("malformed schedule: * * * * *") because a `*` field
expands to 0 and `?Int`'s nil was also 0, so `a == nil` was true for a real
value. Both log-watcher subcommands now behave: `watch` alerts on a live file,
`run` reports SCHEDULE /var/log/backup.log: * * * * *. corpus 71/0, woc 565/0,
wovm gates green.
- a nullable SCALAR (?Int/?Bool/?Timestamp/?Id) spells nil as WO_NIL_SCALAR
(-2^62), not the zero word. Heap-shaped optionals keep 0 — a null pointer is
unambiguous. The value is -2^62 and NOT INT64_MIN on purpose: the compiler's
integers are OCaml's 63-bit natives, so INT64_MIN is not expressible there
(and `min_int * 2` silently wraps to 0 — the first attempt did exactly that)
- the class table marks such fields (WOB_FIELD_NIL_SCALAR in field_class), so
the runtime writes the right absence where it produces absence itself:
json.decode leaving a key absent or seeing `null`, and parse_int on
unparseable input (so parse_int("0") is now distinguishable from a failure).
json.encode renders a nil scalar as JSON null
- emit.ml: `nil` takes its word from its destination (annotation, field,
return type); a comparison against `nil` emits the literal with the other
operand's type, so ?scalar compares against the sentinel and ?heap against 0
- vm.c: EQS accepts a nil operand — two `?Text` values compare with it, and the
answer is "both absent is equal, one absent is not". Trapping there made
`a != b` on optionals unusable (it was trapping BOUNDS "null text" in the
supervisor's rescan). A non-nil operand must still be a real Text
- docs: both normative docs now state the heap-vs-scalar nil split and the EQS
rule; the stale duplicate vm_unwind comment is gone
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
- docs/00-status.md: NEXT PLAN is now iteration 5's strictness half (?T forced
handling, pub(read) writes, using, #if) plus an ASan run over the workload;
iterations 6 and 7 marked landed; a "Landed 2026-08-14" section records what
actually shipped, and a new known-gaps block records what did not — lenient
optionals, unenforced pub(read), the borrowed-Text-into-container hazard,
json's Bool/float limits, net fd lifetime, no ASan over the workload, and no
corpus fixtures for the new surface (by direction: the sample is the test)
- runtime/src/CODE-LOGIC.md: file map, the loader-is-the-only-validator and
traps-never-leak invariants, the catch stack, records the VM fills but cannot
name, class metadata + json, program mode, and where to look when it breaks
- compiler/src/CODE-LOGIC.md: the pipeline, why there are two type derivers and
the stay-silent-when-underivable rule, how contextual values get a
destination, the node-id/label contract between owner.ml and emit.ml, the
four kinds of qualified call, predeclared records, the constant-interning
trap, register discipline, and how to verify a change
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
docs/examples/log-watcher now COMPILES AND RUNS: `wovm lw.wob watch app.log 2 1`
tails a live file, classifies levels and fires its alert
("last entry is error, quiet for 2s"). corpus 71/0, woc 565/0, wovm gates green.
- program mode: the entry is `fn main` taking nothing or one `multi Text`;
runtime/src/main.c builds that list from the program's own arguments (not
the program name, not the image path) and the entry's return value is the
process exit code (low byte); the loader accepts a 0- or 1-arg free-fn entry
- `+` on Text is now WO-E201 pointing at `..`. This was a memory-safety hole,
not a style nit: the emitter lowered it to ADD on two heap pointers, and the
workload's own `out = out + char_of(c)` produced a wild pointer that
segfaulted the VM inside starts_with. Reported off confident types only
- `x == nil` / `x != nil` lower to EQ (a word compare), never EQS: nil is the
zero word and EQS dereferences its operands, so a nil guard would trap
instead of answering
- docs/examples/log-watcher: seven `+`-on-Text sites corrected to `..`
(logtail sanitize, mcp header/body/carry assembly, supervisor detections
line) — the sample was carrying the Haxe habit, and the language reserves
`+` for arithmetic by doctrine
- wovm CLI takes arguments after the image path (`wovm <file.wob> [args...]`)
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
docs/examples/log-watcher (1285 lines, 7 files) now compiles clean: 0
diagnostics, a 35KB .wob written. corpus 71/0, woc runtest 565/0, every wovm
unit gate green (both dispatch flavors).
- .wob v2: each class row gains three u32 per-field arrays — the field's NAME
constant, the CLASS it refers to (or the json-raw marker), and a container
field's ELEMENT kinds. json is then a runtime service driven by metadata
instead of per-type generated code. loader/emitter/disassembler/test
assembler all read and write v2; field-name constants are interned with the
rest of the pool (interning during serialization silently loses them)
- runtime/src/json.c (new): encode by static kind + object headers + class
table (nested records need no static knowledge); decode parses and BINDS
straight into the target class — keys matched to field names, nested objects
built as the field's class, arrays as a multi of the field's element kind,
unknown keys skipped, absent keys nil. Malformed input is nil, never a trap
- `as`: `json.decode(text) as T` is the one cast this language has (WO-E403
for any other `as`, and for a bare json.decode with no target type). Its
result is `?T`, which is why the decode and the target are one instruction
- json.Value: a reserved type name for a value the source does not inspect —
the raw JSON slice, kind TEXT, re-emitted verbatim by encode
- docs: 00-wob-format.md is now the v2 reference (class metadata, TRY/ENDTRY,
the whole builtin surface, WO_T_IO); 08-builtin-surface.md documents the
text/container builtins, the OS modules with their predeclared records, and
json's two documented limits (Bool encodes 0/1, floats truncate)
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
log-watcher diagnostics 55 -> 48 (all json-rooted now). corpus 71/0, woc 565/0.
- emit.ml: a field default may now be `nil`, `{}` (a fresh empty container of
the field's declared type) or `Rec {}` (a record built from its own field
defaults) — the workload's `st: TailState = TailState {}` and
`scheduled: map<Text, CronWatch> = {}` shapes
- parser.ml/main.ml: a top-level `const` is visible to every file of its
module, not just its own file — files in a directory are one module by the
discovery contract, and the workload reads logtail.wo's `const CHUNK` from
mcp.wo. A file's own const still wins on a name collision
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
log-watcher diagnostics 129 -> 55 (json is what is left: 13 encode sites,
3 `as` parses and their cascade). corpus 71/0, woc 565/0, wovm gates green.
- runtime/src/sysio.c (new): 17 builtins behind the reserved module names —
fs.exists/list/stat/read_all/read_at/append, time.sleep/local/iso,
env.get/stopping, net.listen/accept/read/write/close, proc.run. Thin
blocking libc calls; a failed syscall traps the new WO_T_IO with errno's
own message, which `try ... catch` is how a program handles
- record-returning members (fs.stat, time.local, proc.run) take their
result record's CLASS ID as the last argument, so the VM allocates what
it fills without knowing any source type name (the err_fill pattern)
- absence is the zero word: a missing path from fs.stat and an unset
env.get are nil, not traps
- env.stopping installs SIGTERM/SIGINT handlers on first use only
- types.ml: predeclared Stat/TimeParts/Proc records (field order is the
contract with sysio.c) + the stdlib member table (arity, builtin id,
return type, result record) + stdlib return types in confident_typ
- emit.ml: stdlib member calls lower to their builtin with the record class
id appended; WO-E406 now means "no such member", not "not linked";
predeclared records enter the class table only when a program needs them
- emit.ml: fstate carries the method's declared return type, so a tail
`return []` / `return {}` gets its element kinds; a non-empty list literal
falls back to its own element type when there is no declared destination
- types.ml: confident_typ chases a container read (`c[i]`), which is what
makes a switch over a value pulled out of a map resolve; a void `try` arm
no longer demands its catch arm agree
- corpus: lang-use-stdlib-not-linked now pins WO-E406 for an unknown MEMBER
(fs.slurp) — the "not linked" premise is gone now that fs is linked
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>