iter remove-mut-var-assign.1: atomic removal of mut/var/assign

mut/var/assign removed from AILang entirely and atomically. Deleted:
Term::Mut/Term::Assign/struct MutVar; the three Form-A keywords +
parse_mut/parse_assign + grammar EBNF; the 4 mut CheckError variants;
the mut_scope_stack synth threading (param dropped from synth + every
internal/external/test caller); the two lower_term arms; and every
exhaustive no-_ Term::Mut/Term::Assign match arm across 17 source
files — cut in lockstep with DESIGN.md, fixtures, the drift trio,
carve-out and roadmap so the schema is honest at every commit. No
catch-all wildcard introduced (verified). loop/recur + let/if are
the surviving forms.

The shared codegen alloca machinery survives (loop reuses it):
mut_var_allocas renamed binder_allocas (representation-only, loop
codegen byte-identical) and the shared Term::Lam escape guard
simplified to !loop_stack.is_empty() with the loop half
(LoopBinderCapturedByLambda) byte-equivalent. Feature-acceptance
applied inverted: the removed feature fails clause 2 (redundant)
and clause 3 (IS the iterated-mutable-state bug class).

Behaviour preservation is executable: mut_counter/mut_sum_floats
still print 55 after the faithful let/if rewrite. The removal is
made executable by the new mut_removed_pin.rs (4 must-fail pins).
Independent verification: cargo test --workspace 605/0, zero
residual mut symbols in any crate source, loop/recur non-regression
all green (55 / 500000500000 / infinite-compiles / the
lambda_capturing_loop_binder pin), roundtrip_cli PASS.

One DONE_WITH_CONCERNS: a 4th recurrence of the recon-undercount
class (in-source mod tests + a drift-pin fn + 5 orphaned mut
.ail.json carve-outs + a non-enumerated E0599); all resolved within
implementer remit, no behaviour change. Milestone-close audit then
fieldtest remain.

spec docs/specs/2026-05-18-remove-mut-var-assign.md (grounding PASS)
plan docs/plans/remove-mut-var-assign.1.md
This commit is contained in:
2026-05-18 11:06:17 +02:00
parent f355899fdf
commit 07f080256c
48 changed files with 331 additions and 2523 deletions
+2 -23
View File
@@ -1,17 +1,4 @@
; Fieldtest mut-local #1 — factorial 5! via straight-line mut updates.
;
; Task: print 5! (= 120) using a `mut` block that names a running
; product and unrolls five multiplications as straight-line statements.
; This is the most direct possible use of mut-local: no helper fn, no
; iteration, just a sequence of in-block updates terminated by reading
; the var. The LLM-author's mental model of "I want a local accumulator"
; maps 1:1 onto the surface here.
;
; Why this fits mut-local's scope: the milestone supplies only sealed
; lexically-scoped mutables, with no `while` or `for`. Straight-line
; unroll is the *only* shape inside one mut block that needs no helper.
;
; Expected stdout: 120
; Print 5! (= 120) via a let-threaded running product.
(module mut-local_1_factorial
@@ -19,12 +6,4 @@
(type (fn-type (params) (ret (con Unit)) (effects IO)))
(params)
(body
(app print
(mut
(var prod (con Int) 1)
(assign prod (app * prod 1))
(assign prod (app * prod 2))
(assign prod (app * prod 3))
(assign prod (app * prod 4))
(assign prod (app * prod 5))
prod)))))
(app print (let prod 1 (let prod (app * prod 1) (let prod (app * prod 2) (let prod (app * prod 3) (let prod (app * prod 4) (let prod (app * prod 5) prod))))))))))
@@ -1,20 +1,5 @@
; Fieldtest mut-local #2 — classify a temperature into a band using
; nested if-branches that each update a mut-Int "category code".
;
; Task: given a temperature value, set a category-code mut-var to
; 0 (freezing), 1 (cold), 2 (warm), 3 (hot) by walking through a
; cascade of if-branches. Print the resulting code.
;
; Why this fits mut-local's scope: this exercises mut composed with
; `if` — each branch contains a single `(assign ...)`. The seal-by-
; construction promise says the if-branch can write to the var, and
; the var's value flows out of the branch as the latest store. This is
; a use of mut that *replaces* what a chain of let-rebinds would
; otherwise do, and a chain of let-rebinds is the AILang author's
; usual workaround for "set this variable conditionally" — so the
; mut form should be measurably cleaner here.
;
; Expected stdout: 2 (room temperature 22 = "warm")
; Classify a temperature into a 0..3 band via a let-bound code.
; classify 22 = 2 ("warm"). Expected stdout: 2
(module mut-local_2_classify_temp
@@ -22,17 +7,7 @@
(doc "Return category code 0..3 for temperature t in degrees C.")
(type (fn-type (params (con Int)) (ret (con Int))))
(params t)
(body
(mut
(var code (con Int) 0)
(if (app < t 0)
(assign code 0)
(if (app < t 15)
(assign code 1)
(if (app < t 28)
(assign code 2)
(assign code 3))))
code)))
(body (let code 0 (let code (if (app < t 0) 0 (if (app < t 15) 1 (if (app < t 28) 2 3))) code))))
(fn main
(type (fn-type (params) (ret (con Unit)) (effects IO)))
+3 -27
View File
@@ -1,23 +1,5 @@
; Fieldtest mut-local #3 — evaluate the polynomial
; p(x) = 2 x^3 - 3 x^2 + 5 x - 7
; at x = 2.5 by Horner's method, using a Float mut-var as the running
; accumulator and unrolling the four Horner steps as straight-line
; assigns.
;
; Why this fits mut-local's scope: the accumulator is a Float, the
; updates are straight-line (no iteration), and the mut form removes
; the four nested let-rebinds an LLM-author would otherwise write
; ("p1 = ..., p2 = p1*x + ..., p3 = p2*x + ...") — each rebind needing
; a fresh name. Reusing one name for the running accumulator is the
; natural shape, and mut supplies it.
;
; Hand-check (Horner): start with leading coeff 2.0, then for each
; lower coefficient do acc = acc * x + c:
; 2.0 * 2.5 + (-3) = 5.0 - 3 = 2.0
; 2.0 * 2.5 + 5 = 5.0 + 5 = 10.0
; 10.0 * 2.5 + (-7) = 25.0 - 7 = 18.0
; Expected stdout: 18 (Float 18.0 via %g; print drops the trailing
; ".0" the same way it does for the Float fixture mut_sum_floats.ail.)
; Evaluate p(x) = 2x^3 - 3x^2 + 5x - 7 at x = 2.5 by Horner's method
; via a let-threaded Float accumulator. Expected stdout: 18
(module mut-local_3_horner
@@ -25,10 +7,4 @@
(type (fn-type (params) (ret (con Unit)) (effects IO)))
(params)
(body
(app print
(mut
(var acc (con Float) 2.0)
(assign acc (app - (app * acc 2.5) 3.0))
(assign acc (app + (app * acc 2.5) 5.0))
(assign acc (app - (app * acc 2.5) 7.0))
acc)))))
(app print (let acc 2.0 (let acc (app - (app * acc 2.5) 3.0) (let acc (app + (app * acc 2.5) 5.0) (let acc (app - (app * acc 2.5) 7.0) acc))))))))
@@ -1,17 +1,5 @@
; Fieldtest mut-local #4 — Bool mut-var "found-a-factor" flag.
;
; Task: probe whether n has a small prime factor (2, 3, 5, or 7) by
; running four straight-line checks; if any check matches, set a Bool
; mut-var to true. Print the flag at the end.
;
; The straight-line form here is the natural shape: an LLM-author asked
; to "test these four conditions and OR the results" would otherwise
; write a chain of `||` operators (no such operator in AILang surface)
; or a nested chain of `(if ... (if ... ))`. The mut form replaces both
; with a flat sequence whose intent ("set this flag if any of these
; matches") reads top-to-bottom.
;
; Test against n = 91 = 7 * 13 — only the divisible-by-7 check fires.
; Probe whether n has a small prime factor (2, 3, 5, 7) via a
; let-threaded Bool flag. has_small_factor 91 = true (91 = 7 * 13).
; Expected stdout: true
(module mut-local_4_has_small_factor
@@ -19,14 +7,7 @@
(fn has_small_factor
(type (fn-type (params (con Int)) (ret (con Bool))))
(params n)
(body
(mut
(var found (con Bool) false)
(if (app == (app % n 2) 0) (assign found true) (lit-unit))
(if (app == (app % n 3) 0) (assign found true) (lit-unit))
(if (app == (app % n 5) 0) (assign found true) (lit-unit))
(if (app == (app % n 7) 0) (assign found true) (lit-unit))
found)))
(body (let found false (let found (if (app == (app % n 2) 0) true found) (let found (if (app == (app % n 3) 0) true found) (let found (if (app == (app % n 5) 0) true found) (let found (if (app == (app % n 7) 0) true found) found)))))))
(fn main
(type (fn-type (params) (ret (con Unit)) (effects IO)))
@@ -1,39 +0,0 @@
; Fieldtest mut-local #5 — deliberate probe of the seal-by-construction
; promise: try to lift a mut-var into a lambda closure.
;
; Spec §"Out of scope": "Lambda capture of a mut-var. A lambda body
; whose free vars include a mut-var of an enclosing Term::Mut is
; rejected at typecheck with CheckError::MutVarCapturedByLambda."
;
; This file is EXPECTED TO FAIL at `ail check` with the
; `mut-var-captured-by-lambda` diagnostic. The purpose is to probe:
; - that the diagnostic actually fires
; - that its rendered text is actionable
; - that it points at the lambda site, not somewhere else
;
; The shape: a mut block declares `count`, builds a closure that would
; close over `count`, and tries to return the closure. An LLM-author
; might write this naïvely thinking "I just need a small callback that
; updates the running count" — exactly the shape the seal forbids.
(module mut-local_5_lambda_capture_probe
(fn make_bumper
(type
(fn-type
(params (con Int))
(ret (fn-type (params (con Int)) (ret (con Int))))))
(params seed)
(body
(mut
(var count (con Int) 0)
(assign count seed)
(lam (params (typed n (con Int)))
(ret (con Int))
(body (app + n count))))))
(fn main
(type (fn-type (params) (ret (con Unit)) (effects IO)))
(params)
(body
(app print (app (app make_bumper 10) 5)))))
@@ -1,18 +0,0 @@
; Fieldtest mut-local #6 — deliberate diagnostic probe. EXPECTED TO
; FAIL at `ail check`.
;
; Probes `mut-var-unsupported-type` — declaring a Str mut-var.
; (A sibling fixture used to probe `assign-type-mismatch` by assigning
; 1.5 to an Int var; on the same surface the diagnostic also fires
; with the same double-bracket-prefix shape.)
(module mut-local_6_diag_probe
(fn main
(type (fn-type (params) (ret (con Unit)) (effects IO)))
(params)
(body
(app print
(mut
(var s (con Str) "hello")
s)))))