- `woc` now emits `.wob` that `wovm` runs: emit.ml lowers the typed, owner-annotated AST (scope-stack registers with a >64 WO-E401 diagnostic, Lua-style call windows, ICALL by slot, dedup const pool, drop maps, line tables, implicit terminators); disasm.ml backs `--dump-bc` goldens. - Ownership lowering consumes the four owner tables verbatim; RESIDUAL is the only source of borrow ops, coalesced per operand. Review caught the emitter consuming only 2 of owner.ml's 4 residual producers — an assignment-anchored aliasing violation ran to exit 0 instead of trapping; fixed, plus a backstop raising WO-E404 for any residual region left unconsumed. - Conformance harness `scripts/oop-e2e.sh` (`just oop-e2e`): four fixture kinds with exact outcomes — byte-exact stdout, one WO-E### anchored on `error CODE:`, numeric trap code, gc trace. 25 fixtures incl. pricing-demo logic, the ownership suite, and DB_STUB's parse-but-trap. `tests/` un-ignored so the corpus is actually tracked. - `woc build` produces a self-contained binary: wovm copy + appended image + 20-byte trailer, self-exec via /proc/self/exe. Verified relocated outside the repo, argless, and against adversarial trailer corruption. - Milestone 1's five spec criteria all MET (`just oop-accept`). Criterion 3 closed by WO-E405 — the entry must return `Int`, since program mode already says its return value is the exit code — which deletes the leak class without adding return-type metadata to the format. `gc/held-cycle` retired: an externally-held cycle is not expressible in a post-exit pump. - New spec: inferred GC + incremental per-shard tri-color mark-sweep, retiring `@gc` and reference counting. Story gains iterations 7b (that work) and 9b (`@table`, relations, compiler-checked query); `.dev/reference` gains a sparse System.Linq checkout. Priority: 5→6→7 (log-watcher) then 7b, 8, 9, 9b.
32 lines
845 B
Text
32 lines
845 B
Text
-- The zero-cost-when-provable promise, as a pinned dump.
|
|
--
|
|
-- `proven` aliases a @gc reference out of a field and hands it to a
|
|
-- function that only reads it. The owner pass proves the acquire and its
|
|
-- release balanced inside one scope (compiler/test/golden/owner/rc.wo
|
|
-- pins that as ELIDED), and nothing about the access is unprovable, so
|
|
-- the emitted body must contain NO borrow op and NO rc op at all — the
|
|
-- disassembly below is the evidence. `main` is the contrast: an escape
|
|
-- into a field is a KEPT acquire, so RC_INC does appear there.
|
|
@gc
|
|
class Cache {
|
|
hits: Int
|
|
}
|
|
|
|
class Holder {
|
|
cache: Cache
|
|
}
|
|
|
|
fn read(c: Cache) -> Int {
|
|
return c.hits
|
|
}
|
|
|
|
fn proven(h: Holder) -> Int {
|
|
let c = h.cache
|
|
return read(c)
|
|
}
|
|
|
|
fn main() {
|
|
let cache = Cache { hits: 41 }
|
|
let h = Holder { cache: cache }
|
|
print_int(proven(h) + 1)
|
|
}
|