writeonce/compiler
shoney.arickathil 09047b26fb fix: copy-on-push closes the container double-free; line-buffer program output
The unsoundness is closed. All four MCP tools now answer correctly over HTTP
(get_running_crons, list_logs, tail_log -> ["info two","error three"],
search_log -> its match) where `tail_log` used to return
{"isError":true,"text":"tool failed: not a text value"}. corpus 71/0,
woc 565/0, wovm gates green, ASan clean on the container fixtures.

- builtin.c: multi_push, map_set (key AND value) and multi_set COPY a TEXT
  element into the container. The container's declared kinds already make it
  the owner of what it holds, so storing a caller-owned pointer gave one
  string two owners — `push(res, e.log_path)` freed a record's field out from
  under it. OWNED/GCREF elements still move (not copyable; the @gc escape
  keeps their counting), so `set`'s @gc gap is untouched and still recorded
- emit.ml: `drop_fresh_text` — after push/set and the `m[k] = v` / `m[i] = v`
  sugar, a value that was freshly BUILT (call result, `..` chain,
  interpolation) is dropped here, while a value read out of a place is left to
  its owner. That asymmetry is the point: before the copy the borrowed case
  double freed and the fresh case leaked
- obj.c: the runtime's output stream is line-buffered. A long-running program
  writing progress with `print` was invisible when stdout was a file or a pipe
  (full buffering), and a killed one lost its log entirely; byte-exact
  fixtures are unaffected
- scripts/log-watcher-accept.sh + `just log-watcher`: the acceptance test for
  the sample — compile, watch (alert), run (schedule), and three MCP checks.
  Hardened after it lied to me: a per-run port (a stale server on a fixed port
  answered for it), a connect-probe that fails loudly when OUR server did not
  come up, replies read by Content-Length rather than to EOF (the sample never
  closes), and kill -9 on teardown
- docs: the copy rule is in the builtin surface; the status board records the
  gap as closed and adds the new one — a blocking accept/read swallows SIGTERM,
  which belongs to the shard-actor runtime's event loop, not to a patch here

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-14 18:50:18 +02:00
..
bin feat(compiler): richer field defaults + cross-file consts 2026-08-14 16:56:55 +02:00
src fix: copy-on-push closes the container double-free; line-buffer program output 2026-08-14 18:50:18 +02:00
test feat: json encode/decode + as, .wob v2 class metadata — log-watcher compiles 2026-08-14 17:08:46 +02:00
dune-project feat(compiler): Tasks 1-4 — scaffold, diagnostics, lexer, declaration parser 2026-08-10 09:00:08 +02:00
README.md feat: milestone 1 complete — .wob emitter, conformance corpus, single binary; GC redesign specced 2026-08-11 19:31:26 +02:00

compiler/ — the OCaml woc compiler

Lexer → parser → typechecker → ownership pass → bytecode emitter, for .wo. OCaml stdlib only (no Menhir, no ppx); dune is the build runner. Sibling of the C wovm bytecode VM (runtime/) — the two halves of the OOP track's spec (docs/superpowers/specs/2026-08-01-oop-compiler-vm-design.md) meet at plan 3, where woc's emitted .wob runs on wovm.

Stage: plan 3 (docs/plan/compiler/2026-08-01-wob-emit-e2e-single-binary.md) complete, Tasks 1–6 + 8 (Task 7, a parity harness against the Rust runtime, was deferred by explicit decision — the two stacks now diverge by design). .wo source compiles to .wob bytecode (--emit) and to a single self-contained executable (build) that runs wovm with no arguments and no repo-relative dependency. Milestone 1's acceptance gate — compile-time budget, the full conformance corpus under ASan, the single-binary smoke, both unit suites — is just oop-accept. Plan 2 (lexer through ownership pass) shipped first and is unchanged.

Requirements

OCaml 4.14.1, dune 3.14.0 — Ubuntu 24.04 apt packages (sudo apt install ocaml dune), the version floor. Confirm with ocaml -version / dune --version. No opam packages, no Menhir, no ppx — stdlib only.

Build, test

cd compiler && dune build     # -> _build/default/bin/woc
cd compiler && dune runtest   # test_diag unit checks + runner golden/CLI-smoke suite

just woc-build   # same, from the repo root
just woc-test    # same, from the repo root

WOC_BLESS=1 dune runtest (from compiler/) rewrites golden .expected files to match current output — use it once, by hand, to seed or intentionally update a fixture.

Running woc

woc <path>                       # compile (lex, parse, typecheck, ownership-check); nothing prints on success
woc --dump-tokens <path>         # stdout: one line per lexed token
woc --dump-ast <path>            # stdout: the declaration + body AST, indented
woc --dump-owner <path>          # stdout: the ownership pass's four tables (moves, drops, rc, residual)
woc --dump-bc <path>             # stdout: disassembled bytecode for every emitted method
woc --emit <path> -o <out.wob>   # compile through to a .wob bytecode module, runnable by wovm
woc build <dir> -o <app> [--runtime <path>]
                                  # compile + append the .wob image to a copy of wovm (default
                                  # runtime/wovm, or --runtime) into one self-contained <app>

<path> is a single .wo file or a directory. A directory is discovered recursively for every .wo file under it — same contract as wo run (crates/rt/src/lib.rs::discover): dot-prefixed entries and target/data/node_modules are skipped, results are sorted by path. Every discovered file compiles as one program (declarations in one file resolve for bodies in another, regardless of discovery order); diagnostics from every file and every stage print sorted by (file, line, col). For multi-file --dump-* output, each file's dump is preceded by a === path === header line (compiler/src/dump.ml's file_header) — a single-file run never prints one.

Diagnostics render as file:line:col: severity CODE: message plus a source excerpt with a caret; every shipped code is cataloged in docs/plan/oop-vm/01-error-catalog.md. Exit codes: 0 clean compile, 1 diagnostics reported, 2 usage/IO failure.

Layout

  • src/ — one module per stage: diag (diagnostics, collector, exit-code decision), token/lexer, ast/parser, types (typechecker), owner (MVS ownership pass), emit (bytecode emitter, consumes owner's four tables), disasm (bytecode disassembler, backs --dump-bc), dump (stable text dumps for all of the above)
  • bin/ — the woc executable: CLI parsing, file discovery, the multi-file/cross-file driver, --emit/build output
  • test/ — runner.ml (golden runner + CLI smoke) and test_diag.ml (diag.ml unit checks); test/golden/<stage>/ holds one-file-per-fixture goldens (tokens, ast, owner, owner-err, bc); test/fixtures/driver/ holds the multi-file CLI-smoke fixtures (directory discovery, cross-file symbols, diagnostic ordering) that don't fit the one-.wo-file-per-fixture golden shape

Governing docs (all under docs/, not here — this file stays an orientation README): spec docs/superpowers/specs/2026-08-01-oop-compiler-vm-design.md; plans docs/plan/compiler/2026-08-01-woc-compiler-front.md and 2026-08-01-wob-emit-e2e-single-binary.md (+ architecture.md, nullable-types-implementation.md, 2026-08-01-haxe-parity-language.md in the same directory). Format contract: docs/plan/oop-vm/00-wob-format.md. Error catalog: docs/plan/oop-vm/01-error-catalog.md. Conformance corpus contract (fixture layout woc's golden output feeds into): docs/plan/oop-vm/02-corpus.md; source-language builtin surface woc accepts: docs/plan/oop-vm/08-builtin-surface.md. Runtime sibling: runtime/README.md.