- `woc` now emits `.wob` that `wovm` runs: emit.ml lowers the typed, owner-annotated AST (scope-stack registers with a >64 WO-E401 diagnostic, Lua-style call windows, ICALL by slot, dedup const pool, drop maps, line tables, implicit terminators); disasm.ml backs `--dump-bc` goldens. - Ownership lowering consumes the four owner tables verbatim; RESIDUAL is the only source of borrow ops, coalesced per operand. Review caught the emitter consuming only 2 of owner.ml's 4 residual producers — an assignment-anchored aliasing violation ran to exit 0 instead of trapping; fixed, plus a backstop raising WO-E404 for any residual region left unconsumed. - Conformance harness `scripts/oop-e2e.sh` (`just oop-e2e`): four fixture kinds with exact outcomes — byte-exact stdout, one WO-E### anchored on `error CODE:`, numeric trap code, gc trace. 25 fixtures incl. pricing-demo logic, the ownership suite, and DB_STUB's parse-but-trap. `tests/` un-ignored so the corpus is actually tracked. - `woc build` produces a self-contained binary: wovm copy + appended image + 20-byte trailer, self-exec via /proc/self/exe. Verified relocated outside the repo, argless, and against adversarial trailer corruption. - Milestone 1's five spec criteria all MET (`just oop-accept`). Criterion 3 closed by WO-E405 — the entry must return `Int`, since program mode already says its return value is the exit code — which deletes the leak class without adding return-type metadata to the format. `gc/held-cycle` retired: an externally-held cycle is not expressible in a post-exit pump. - New spec: inferred GC + incremental per-shard tri-color mark-sweep, retiring `@gc` and reference counting. Story gains iterations 7b (that work) and 9b (`@table`, relations, compiler-checked query); `.dev/reference` gains a sparse System.Linq checkout. Priority: 5→6→7 (log-watcher) then 7b, 8, 9, 9b.
26 lines
874 B
Text
26 lines
874 B
Text
-- Ownership suite (plan 2), as an end-user program: `bag.items[0]` passed
|
|
-- twice as a `mut` parameter in the same call is a *provable* alias --
|
|
-- same runtime index, same call -- so it fails at compile time. Contrast
|
|
-- with tests/corpus/trap/exclusive-borrow-alias, the same shape with a
|
|
-- runtime-variable index (i == j): the analysis can't prove that one
|
|
-- either way, so it becomes a residual check the VM traps BORROW on
|
|
-- instead. This is the hybrid boundary: provable violations fail here;
|
|
-- unprovable ones trap there. Mirrors the `same_index` case of
|
|
-- compiler/test/golden/owner-err/double-mut.wo.
|
|
class Item {
|
|
n: Int
|
|
}
|
|
|
|
class Bag {
|
|
items: multi Item
|
|
}
|
|
|
|
fn swap(mut a: Item, mut b: Item) -> Int {
|
|
return a.n + b.n
|
|
}
|
|
|
|
fn main() {
|
|
let bag = Bag { items: multi_new() }
|
|
push(bag.items, Item { n: 1 })
|
|
print_int(swap(bag.items[0], bag.items[0]))
|
|
}
|