- `woc` now emits `.wob` that `wovm` runs: emit.ml lowers the typed, owner-annotated AST (scope-stack registers with a >64 WO-E401 diagnostic, Lua-style call windows, ICALL by slot, dedup const pool, drop maps, line tables, implicit terminators); disasm.ml backs `--dump-bc` goldens. - Ownership lowering consumes the four owner tables verbatim; RESIDUAL is the only source of borrow ops, coalesced per operand. Review caught the emitter consuming only 2 of owner.ml's 4 residual producers — an assignment-anchored aliasing violation ran to exit 0 instead of trapping; fixed, plus a backstop raising WO-E404 for any residual region left unconsumed. - Conformance harness `scripts/oop-e2e.sh` (`just oop-e2e`): four fixture kinds with exact outcomes — byte-exact stdout, one WO-E### anchored on `error CODE:`, numeric trap code, gc trace. 25 fixtures incl. pricing-demo logic, the ownership suite, and DB_STUB's parse-but-trap. `tests/` un-ignored so the corpus is actually tracked. - `woc build` produces a self-contained binary: wovm copy + appended image + 20-byte trailer, self-exec via /proc/self/exe. Verified relocated outside the repo, argless, and against adversarial trailer corruption. - Milestone 1's five spec criteria all MET (`just oop-accept`). Criterion 3 closed by WO-E405 — the entry must return `Int`, since program mode already says its return value is the exit code — which deletes the leak class without adding return-type metadata to the format. `gc/held-cycle` retired: an externally-held cycle is not expressible in a post-exit pump. - New spec: inferred GC + incremental per-shard tri-color mark-sweep, retiring `@gc` and reference counting. Story gains iterations 7b (that work) and 9b (`@table`, relations, compiler-checked query); `.dev/reference` gains a sparse System.Linq checkout. Priority: 5→6→7 (log-watcher) then 7b, 8, 9, 9b.
64 lines
2 KiB
Text
64 lines
2 KiB
Text
-- The other half of the borrow story: where static proof fails, and only
|
|
-- there, the emitter wraps the region in runtime borrow ops.
|
|
--
|
|
-- `pair` takes two exclusive borrows of elements reached through runtime
|
|
-- indices, so `i == j` is unprovable (the canonical residual case from
|
|
-- the spec's section 4). One BORROW_X / RELEASE_X pair per operand —
|
|
-- coalesced per operand, never one pair per residual-table entry.
|
|
-- `fixed` is the control: literal indices are provably distinct, so it
|
|
-- gets no guards at all.
|
|
class Item {
|
|
n: Int
|
|
}
|
|
|
|
class Bag {
|
|
items: multi Item
|
|
}
|
|
|
|
fn touch(mut a: Item, mut b: Item) -> Int {
|
|
return a.n + b.n
|
|
}
|
|
|
|
fn pair(mut bag: Bag, i: Int, j: Int) -> Int {
|
|
return touch(bag.items[i], bag.items[j])
|
|
}
|
|
|
|
fn fixed(mut bag: Bag) -> Int {
|
|
return touch(bag.items[0], bag.items[1])
|
|
}
|
|
|
|
-- Three exclusive aliases in one region: the pairwise check produces
|
|
-- THREE residual entries (a-b, a-c, b-c) over THREE distinct operands.
|
|
-- Per-operand coalescing must emit 3 guard pairs; a regression to one
|
|
-- pair per table entry would emit 6 and self-trap by asking for two
|
|
-- exclusive borrows of the same object. `pair` above cannot tell those
|
|
-- two apart (one entry, two operands, 2 guards either way) — this can.
|
|
fn touch3(mut a: Item, mut b: Item, mut c: Item) -> Int {
|
|
return a.n + b.n + c.n
|
|
}
|
|
|
|
fn triple(mut bag: Bag, i: Int, j: Int, k: Int) -> Int {
|
|
return touch3(bag.items[i], bag.items[j], bag.items[k])
|
|
}
|
|
|
|
-- An assignment is its own region: owner.ml anchors the residual sites
|
|
-- it produces on the statement, not on a call. `s.n = 5` writes through
|
|
-- one alias while another is live over a runtime index, so the SETF
|
|
-- itself must be guarded.
|
|
fn write_through(mut bag: Bag, i: Int, j: Int) -> Int {
|
|
let r = bag.items[i]
|
|
let s = bag.items[j]
|
|
s.n = 5
|
|
return r.n
|
|
}
|
|
|
|
fn main() {
|
|
let bag = Bag { items: multi_new() }
|
|
push(bag.items, Item { n: 1 })
|
|
push(bag.items, Item { n: 2 })
|
|
push(bag.items, Item { n: 3 })
|
|
print_int(pair(bag, 0, 1))
|
|
print_int(fixed(bag))
|
|
print_int(triple(bag, 0, 1, 2))
|
|
print_int(write_through(bag, 0, 1))
|
|
}
|