Every remaining item is now traced to a measurement on the sample; anything the sample does not exercise is deferred by name with the measurement that says so. - new plan docs/plan/compiler/2026-08-14-logwatcher-executable.md — six tasks between "it runs" and "you can leave it running": the ownership pass learning stdlib return types (>1 MB leaked in 8s of `run` mode, one fs.read_all result), dropping a projected temporary (`for e in parse_dir(d).entries` leaks the shell per rescan), the runtime's own argv container (128 B every run), honouring the stop signal in blocking calls (a server in accept ignores SIGTERM), closing accepted connections (net.close exists, unused), and a soak that would have caught all of it. Opens with the measured starting point and closes with an explicit out-of-scope list - story 7 (log-watcher proof): status banner separating the met compile-and-run half from the executable half, plus a new Given/When/Then — clean SIGTERM exit, zero leaks, flat RSS and descriptors across a soak - story 5: grammar half landed, strictness half deliberately deferred - story 6: landed for the surface the workload uses, with the two lifetime defects it exposed pointed at the new plan - story 7b: recorded as off this workload's path, measured — the sample has no @gc class, 0 RC_INC/RC_DEC against 78 DROPs - 00-status.md: NEXT PLAN is the executable list; story table and in-progress row point at the new plan; deferrals carry their evidence - plan 8 (haxe-parity): banner now says on hold behind the executable plan, and its task states are corrected — Task 5 shipped, Tasks 6 and 7 are half done Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
66 lines
3 KiB
Markdown
66 lines
3 KiB
Markdown
# Iteration 6 — program mode + systems stdlib
|
||
|
||
> Format: fiberloom `product/story-iteration-template`. Part of
|
||
> [Story — one language, one runtime, one database, one binary](00-story.md).
|
||
|
||
|
||
> **Status (2026-08-14):** ✅ landed for the surface the driving workload uses —
|
||
> program mode (`fn main(args: multi Text) -> Int`, argv from the runtime, the
|
||
> return value as the exit code), the text/container builtins, and the OS half
|
||
> (`fs`, `time`, `env`, `net`, `proc`) with predeclared `Stat`/`TimeParts`/
|
||
> `Proc` records, plus `json` encode/decode over `.wob` v2 class metadata.
|
||
> What the workload never calls was not written. Two lifetime defects found
|
||
> here are being fixed as part of
|
||
> [`plan/compiler/2026-08-14-logwatcher-executable.md`](../../plan/compiler/2026-08-14-logwatcher-executable.md):
|
||
> the runtime's own argv container is never freed, and blocking `accept`/`read`
|
||
> ignore the stop signal.
|
||
|
||
## Goals
|
||
|
||
- writeonce stops being server-only: a project with a free
|
||
`fn main(args) -> Int` compiles as a CLI program with exit codes — the
|
||
daemon/tool shape log-watcher represents.
|
||
- Five typed builtin modules — `fs`, `proc`, `net`, `time`, `json` — give
|
||
programs system access with no FFI hole: bounded reads, args-array-only
|
||
process runs, TCP listen/accept, monotonic time, typed JSON decode.
|
||
- Every handle is an owned object whose drop closes it: RAII from the
|
||
ownership model, leaked fds impossible by construction.
|
||
|
||
## Acceptance Criteria
|
||
|
||
- What to achieve?
|
||
- **Given** a program with `fn main`,
|
||
- **when** `wo run` executes it and `woc build` packages it,
|
||
- **then** the return value propagates as the process exit code in both
|
||
forms, and SIGTERM flips `env.stopping()` without any callback
|
||
machinery.
|
||
- What to achieve?
|
||
- **Given** the stdlib corpus against real resources (tempdir files,
|
||
rename-simulated rotation, spawned trivial processes, loopback
|
||
sockets),
|
||
- **when** the suite runs under ASan,
|
||
- **then** all fixtures pass, and the fd-battery fixture (open many
|
||
handles in a loop) shows no fd-count growth.
|
||
- What to achieve?
|
||
- **Given** a JSON document missing optional fields or shaped wrongly,
|
||
- **when** `json.decode … as Record` runs,
|
||
- **then** missing optionals decode as nil, shape mismatches yield nil
|
||
overall, and no trap fires — expected absence is data, not error.
|
||
|
||
## Out Of Scope
|
||
|
||
- The log-watcher sample itself (iteration 7 proves this slice).
|
||
- UDP/TLS, fs mutation beyond append, signal callbacks, worker threads.
|
||
|
||
## Info
|
||
|
||
- One API, two disciplines: the same stdlib calls are blocking in program
|
||
mode and loop-integrated on server shards — no `async` keyword exists.
|
||
- Spec: `docs/superpowers/specs/2026-08-01-systems-track-design.md` Parts 2–3.
|
||
|
||
## Proposed Solution
|
||
|
||
- Execute the existing plan: `docs/superpowers/plans/2026-08-01-program-mode-stdlib.md`
|
||
(program entry + env module, time, fs with inode stat + bounded
|
||
`read_at`, proc.run with capped capture, net RAII handles, typed json,
|
||
sys corpus battery in the `oop-accept` gate).
|