Commit Graph

949 Commits

Author SHA1 Message Date
Brummel f6a8607518 spec: 0064 harden ownership analysis part 2 (#57)
The #55 cutover (plan 0121, Task 4) is blocked: deleting
ParamMode::Implicit activates the strict linearity check universally,
but the migrated corpus does not pass cleanly. #56 (spec 0063) closed
two false-positive classes; universal activation surfaces three more
plus one genuine corpus over-consume. This spec is the "#56 part 2"
hardening, sibling to 0063, landing before the irreversible variant
deletion. It does NOT patch a fifth phase onto plan 0121 (project
rule: 2+ blocking classes = spec defect).

Four additive fixes, no schema/hash/codegen change, check stays
diagnostic-only:
- Type table teed from the typecheck pass (synth Let arm at lib.rs:3808
  computes the binder type then discards it) into (def,binder)->Type,
  threaded to linearity. The "stop discarding known information" fix,
  not a re-run of inference in the walk (ruled out by aaa70d4 / 0063).
- Class 3 (value-typed let-binder): is_value seeded from the table,
  extending 0063's per-binder flag to the let site it deferred.
- Class 1 (local function-typed binder): BinderState.fn_param_modes;
  callee_arg_modes consults local binders (params/lam from signature,
  let from the table) before the global table.
- Class 2 (let-alias of a borrowed value): an alias REDIRECT (not a
  state clone -- a clone would miss a real double-consume), root-
  resolved in use_var. Closes the contract 0008:340 carve-out.
- Class 4 (partition_eithers): genuine double-consume, body rewrite
  (destructure rest once); check unchanged, must-stay-RED fixture pins
  it.

Design call (user delegated): the binder->type table is the chosen
mechanism over local/shallow derivation -- the type is known and
discarded, and 0063's deferral of exactly this class is what produced
#57; a local-only patch re-creates the latent class. All five fenced
ail fixtures parse and reach the linearity stage with the recorded
exit codes (parse-every-block gate fired). Grounding-check PASS: every
load-bearing assumption ratified by a green in-source test or a live
RED trace.

refs #57
2026-06-01 17:26:18 +02:00
Brummel 39b674c1ec chore: throwaway mode-migration tool for the Implicit cutover (#55, 0121 task 3)
Adds `ail migrate-modes <file>` (a throwaway CLI subcommand) and the AST
walker `ailang_core::ast::for_each_fn_type_mut` it drives: parse a .ail,
map every bare/Implicit fn-type slot to Own, preserve explicit
Own/Borrow, print back. Semantically invisible today (PartialEq treats
Implicit == Own), but it materialises the modes so the post-cutover
parser — which will reject bare slots — accepts the migrated corpus.

Both are throwaway: removed in task 4 once ParamMode::Implicit is
deleted (the closure references Implicit and would not compile).
RED-first: migrate_modes.rs failed to compile (missing walker) before
for_each_fn_type_mut was added. Additive; full workspace suite green.

refs #55
2026-06-01 16:41:21 +02:00
Brummel e1c908912b feat(check): reject borrow-returns at the signature (#55, 0121 task 1)
`(ret (borrow T))` is now a check error (CheckError::BorrowReturnNotPermitted,
code `borrow-return-not-permitted`), fired on the fn signature before
body dataflow. Borrow-returns are refcount-invisible and can outlive
their source; re-enabling them needs the escape/liveness axis, which is
out of scope (spec 0062). The diagnostic names that gap as an honest
"not yet".

The check_fn signature destructure now also binds `ret_mode` (param_modes
stays under `..`; the borrow-over-value reject that reads it is folded
into the cutover, task 4). RED-first: examples/borrow_return_reject.ail
checked clean (exit 0) before the reject landed, exits 1 after. New
CLI-boundary E2E pin crates/ail/tests/mode_signature_rejects.rs, modelled
on raw_buf_new_type_arg_pin.rs. Additive — ParamMode::Implicit still
present; full workspace suite green, bench/check.py 0 regressed.

refs #55
2026-06-01 16:41:21 +02:00
Brummel 7dc21234f0 plan: re-stage 0121 — fold borrow-over-value into the cutover (mono collision)
First implementation contact surfaced a plan defect: the
borrow-over-value reject cannot land green as a standalone pre-cutover
task. The prelude's polymorphic comparison builtins are
`(params (borrow a) …)` (eq/compare/lt/…); the mono pass
(apply_subst_to_type, subst.rs:165) specialises `a := Int/Bool/Float`
into `compare__Int(borrow Int, …)` — the language's OWN generated code
in the forbidden `(borrow value-type)` shape. The standalone check
broke compare_{int,bool}_mono_symbol_emits_branch_ladder.

Spec 0062's "value types always own" rule is universal, so generated
code must honour it too: the principled fix is a mono-pass coercion
`(borrow value-type) -> (own value-type)` (a no-op — value types carry
no RC, so own vs borrow emits no inc/dec and the branch-ladder IR is
unchanged). The check and the coercion are a matched pair and now live
together in Task 4 (Steps B1-B2), which touches the mono path anyway.

Pre-cutover green tasks are now Task 1 (borrow-return reject) + Task 3
(throwaway migration tool). Task 1's check_def destructure binds only
ret_mode (param_modes stays under `..`); Task 4 Step B2 widens it.

Spec gap to record at the next 0062 brainstorm touch: the
borrow-over-value rule needs its mono-coercion clause spelled out — the
spec tested only the authored case.

refs #55
2026-06-01 16:33:58 +02:00
Brummel a84ba596cf plan: eliminate the Implicit ownership default (0121)
Executable projection of spec 0062 (#55) into four tasks: (1) the
borrow-return reject, (2) the borrow-over-value reject, (3) a throwaway
`ail migrate-modes` pass (parse -> Implicit->Own, keep explicit
own/borrow -> print explicit), (4) the atomic cutover (run the
migration over the corpus + hand-fix the read-only-heap params the
now-universal linearity check flags, delete the variant + all
compile sites compiler-driven, parser bare-slot reject, reset the hash
pins, flip the leak pin, update both contracts, drop the throwaway).
Placeholder-free; all seven surface fixtures parse-gated against HEAD.

Spec 0062 marked approved (user, 2026-06-01) and its soundness
re-validated against post-#56 HEAD: the three own-return-provenance /
regime-A fixtures still exit 1 under [consume-while-borrowed]; #56's
application-is-a-borrow change does not weaken them (none is an
application of a borrowed binder).

plan-recon folded four spec-enumeration corrections into the plan:
- kernel migration target is raw_buf/source.ail, not the retired
  kernel_stub/source.ail the spec cited;
- FIVE hash pins shift, not the two the spec named (embed_export_hash,
  eq_ord_e2e, mono_hash_stability are the missed twins);
- design/contracts/0002-data-model.md also documents the "implicit"
  JSON form and is drift-anchored -> updates alongside 0008;
- real counts are 261 fn-type fixtures (spec ~208) and 17 fn_implicit
  references (spec 16); the compiler is the authoritative enumerator.

refs #55
2026-06-01 16:19:07 +02:00
Brummel aaa70d4c35 feat(check): harden the ownership analysis for universal activation (0063)
The strict linearity check (use-after-consume / consume-while-borrowed,
linearity.rs) runs today only on the ~45 of 258 all-explicit-mode fns;
its activation gate skips any fn with a bare/Implicit param. Deleting
ParamMode::Implicit (#55) would turn it on universally and surface ~21%
false positives in two classes. This closes both, making the core
ownership analysis sharp across the whole codebase for the first time —
the precondition for #55. Diagnostic-only: no schema, no hash, no
codegen change; the two existing diagnostic codes simply fire on a
smaller, more correct set.

Fix 1 — value-type exemption. A new is_value_type predicate
(ailang-core::primitives) names the unboxed set {Int,Bool,Float,Unit};
BinderState gains an is_value flag seeded from the binder's locally
available type (param signatures, ctor field types for pattern binders,
lam typed-params), and use_var short-circuits the Consume arm for it. A
value type has no refcount and is never consumed, so multi-read is
always legal.

  Str is deliberately NOT in the value set, though is_primitive_name
  includes it: drop.rs:490-492 lowers only Int/Bool/Float/Unit to
  non-ptr; Str is a ptr, RC-dec'd, so a multi-consume of Str without
  clone is a real use-after-free. is_value_type is the Str-excluding
  subset of is_primitive_name, pinned by a unit test. is_heap_type and
  the over-strict-mode lint are left untouched (separate concern).

Fix 2 — application is a borrow. Term::App walks its callee in
Position::Borrow (was Consume). Applying a function value reads it; it
stays live for further applications. Global fn-refs are untracked
(no-op); a tracked function-typed binder (a HOF param) is no longer
consumed by application. This fixes both the own-f-param
use-after-consume and the borrow-f-param consume-while-borrowed in the
recursion-passing HOF shape (map_int f t). Passing a function value as
an arg is unchanged — it follows the callee param_modes.

Scope decision: value-typed let-binders stay conservatively tracked as
heap (their type is inferred, not annotated, and the linearity walk
does not re-run inference). This is soundness-safe — over-strict, never
unsound — and not a measured corpus shape; lifting it would need a full
binder->type table out of the type-checker.

Verification: all three false-positive classes reproduced today against
explicit-mode fns and shipped as RED->GREEN fixtures
(examples/fp_{value,hof,map}.ail); examples/real_consume.ail stays RED
(heap double-consume still fires) to prove the exemption is type-gated.
715 workspace tests green; bench/check.py 0/34 and bench/compile_check.py
0/24 regressed. merge_states carries is_value so the flag survives
branch merges. RED-first verified per task.

closes #56
2026-06-01 15:38:32 +02:00
Brummel 47fb328aca plan: harden ownership analysis — is_value_type + value exemption + app-borrow (0120)
Executable projection of spec 0063 into four tasks: (1) is_value_type
predicate in ailang-core::primitives; (2) application-is-a-borrow
(Term::App callee walked Position::Borrow); (3) value-type exemption
(BinderState.is_value seeded at param/pattern/lam sites, use_var
short-circuit); (4) on-disk RED->GREEN fixtures + workspace assertions.
Placeholder-free with exact code for every edit site. refs #56
2026-06-01 15:29:12 +02:00
Brummel 8cdac7ecef spec: harden the ownership analysis for universal activation (0063)
Precondition for #55 (eliminate ParamMode::Implicit, spec 0062). The
strict linearity check (use-after-consume / consume-while-borrowed)
runs today only on the ~45 of 258 all-explicit-mode fns; deleting
Implicit turns it on universally and surfaces ~21% false positives in
two classes — value-type params (Int/Bool/Float/Unit, never consumed)
and applied function params in HOFs (application is a borrow).

Two design questions settled against the live tool, not the model:
- Str is heap, NOT a value type for consume-tracking. drop.rs:490-492
  lowers only Int/Bool/Float/Unit to non-ptr; Str is a ptr, RC-dec'd,
  so a multi-consume of Str without clone is a real use-after-free. The
  value-type set is the unboxed {Int,Bool,Float,Unit}, narrower than
  is_primitive_name (which includes Str).
- Applying a function value is a borrow; passing it as an arg follows
  callee param_modes (unchanged). The recursion-passing HOF pattern is
  then consistent under a borrow f-param.

All three false-positive classes reproduced today against explicit-mode
fns (testable without #55) and recorded as RED fixtures; a heap
double-consume fixture stays RED to prove the exemption is type-gated.
grounding-check PASS. refs #56
2026-06-01 15:29:12 +02:00
Brummel 6c351af169 docs(claude): record the LLM-designed mandate and last-resort escalation
AILang is built primarily for LLMs; the corollary the owner stated
is that it is also meant to be designed by them. The human owner is
escalated to only as a last resort, and at that point the fix is most
likely a revert rather than a redesign. Records the design-authority
half of the identity that the opening section already stated for
authoring.
2026-06-01 15:01:21 +02:00
Brummel c8b765614d spec: eliminate the Implicit ownership default (0062)
Design spec for #55, superseding #54. Deletes ParamMode::Implicit in a
single cutover -> binary {Own, Borrow}; no defaulted ownership mode
survives on any fn-type slot, authored or compiler-synthesised.

The grounding pass corrected the central architecture claim. Both #55
and the first draft assumed a new return-provenance check was needed to
reject an own-return aliasing a borrowed binder, "silently accepted
today". Running the candidate fixtures through the live `ail check`
falsified that: consume-while-borrowed already rejects all three
provenance paths -- direct passthrough, let-indirection, and borrow
escaping into a returned constructor (regime A). Own-return soundness
and regime A are already-green properties. The cutover therefore adds
exactly one new check (borrow-return rejection) plus one signature-level
reject (borrow-over-value), not two new provenance analyses.

Scope decisions ratified: keyword stays verbal (own/borrow), ParamMode
keeps its name; totality is strict including value-type slots (every
slot moded, (own value) trivial, (borrow value) an error, bare slot a
parse error) so an LLM author needs no heap/value knowledge.

The leak fix (spec 0061 symptom) falls out of Implicit->Own at the
synthesis sites: the old typechecker made Implicit and Own
indistinguishable (mode_eq), so setting Own changes no typecheck
outcome -- it only flips the codegen dec gate from skip to emit.

Out of scope: re-enabling borrow-returns (needs the escape/liveness
axis), multi-return, mode polymorphism.

grounding-check: PASS (7 assumptions ratified against named green tests;
all fenced ail blocks validated against the live tool).

refs #55
2026-06-01 14:21:26 +02:00
Brummel 657b24bfc9 docs(design): refine the ownership-totality model from design discussion (0008)
A design discussion on 0008 surfaced four refinements; this records them
in the exploratory model. Still design exploration, not a spec commitment.

- §3.4 (new): the keywords are adjectival, not verbal. `own`/`borrow`
  are acquisition verbs — native on a parameter (the callee acquires),
  backwards on a return (the callee disposes; §3.1's own text switches
  feet between the two readings). Naming the mode adjectivally
  (`owned`/`borrowed`) describes the value the receiver holds and is
  position-independent, strengthening §3's uniformity rather than
  breaking it. Carries a safety stake, not only readability: a wrong
  `own` is the double-free (§6), and the verb form is a mis-annotation
  pump pointed that way. Notes the corroborating `ret_mode: ParamMode`
  type-name smell (a return mode is a covariant promise, not a
  contravariant param demand).

- §4.4: "fixed modes suffice" is contingent on the point-free cut, not a
  standalone theorem. Adds the structural discriminator — today's HOFs
  control both ends of their seam, so the seam mode is determinate; only
  the wire-two-black-boxes kind (point-free) needs a mode variable.

- §5.1–5.3 (new): a tuple question exposed that `ret_mode` is flat but
  ownership is a tree over the type — a single top-level `Own` on a
  mixed Pair (owned field + borrowed field) decs borrowed data on drop.
  Resolved to regime A (borrows may not escape into an escaping heap
  structure → transitive ownership → flat `ret_mode` sound), not a
  per-field mode tree (regime B = lifetimes). For compound returns,
  verification is constitutive of the flat representation's meaning, not
  a separable phase — sharpening Q2 to "must" there. Multi-return is the
  ownership-honest return path (flat per-position modes, no reachability
  pass) but does not subsume the typed boxed aggregate; the boxing point
  is the ownership commit.

- §7: Q2 sharpened (compound returns force it), Q3 rewritten (adjectival
  keywords + the pre-cutover timing, since a post-cutover rename is a
  second irreversible hash reset), Q4 added (multi-return adoption);
  resolved-footer extended with regime A and multi-return≠tuple.

- §8 (new): relation to Rust. Concedes the primitive-level convergence
  (own/borrow ≈ move/borrow, regime A ≈ Rust's escape rule, unboxed
  product ≈ tuple, RC ≈ Rc/Arc), then names what AILang drops and why:
  no lifetime polymorphism (the point-free cut removes the pressure that
  makes Rust carry it), no `&mut`/shared-XOR-mutable (no shared mutable
  refs; mutation rides uniqueness, the Clean lineage), no elision (§2's
  no-defaults is the opposite of Rust's elision). Scoped to the
  totality-relevant divergences; the broader memory-model lineage is
  cross-referenced to 0004 rather than duplicated.
2026-06-01 12:20:20 +02:00
Brummel 768189abce docs(design): add the ownership-totality whitepaper (model 0008)
Exploratory model that converges the direction sparked by the
typed-MIR fieldtest Implicit-return leak (spec 0061). It is not
current state and not an approved milestone — the surface still
defaults ParamMode::Implicit; the file fixes a future shape before
committing it to specs.

The converged shape:

- Ownership is authored, never defaulted. Implicit is removed from
  the authorable surface; every parameter and return carries
  own/borrow. A default cannot be half-removed, so totality is the
  only coherent stopping point.
- Value types take trivial-own; borrow over a value type is an
  error. The surface stays uniform so the author needs no knowledge
  of which types are heap.
- No mode-polymorphism. A type-variable position is never a hole
  under fixed modes — it takes a concrete own/borrow. Mode variables
  would only remove duplication, and the reuse-across-modes need is
  confined to point-free combinators (cut by the language identity)
  and the consume-vs-preserve container duality (better expressed as
  two named functions). Structurally, AILang iterates via tail-app,
  not passed-function combinators, so the higher-order own/borrow
  clash does not arise. ParamMode stays binary {Own, Borrow}.

Left open: cutover shape, verification sequencing, glossary naming.
The one irreversible consequence — a corpus-wide module-hash reset
once Implicit stops eliding the mode fields from canonical JSON — is
named for deliberate sign-off.
2026-06-01 10:53:41 +02:00
Brummel 7a99c5dbfa docs(fieldtest): record the typed-MIR milestone-close fieldtest
Milestone-close fieldtest of the typed-MIR work, run by a downstream
LLM author exercising only the public interface. Four curated scenarios
plus a reduction-bisect set, derived top-down from the milestone promise
(heap-Str-across-recur, new-over-user-ADT, cross-module print__<UserType>,
combined render loop).

Three [working] findings ratified: new-over-user-ADT + Show + print
(#51/#53 class), cross-module synthesised print, and heap-Str-across-recur
value correctness all produced correct output first try.

One [bug] found and orchestrator-verified: returning an owned heap-Str
from a callee fn across the call boundary leaks exactly one RC slab
(live=1) — producer-independent (str_concat, int_to_str), loop-independent,
silent (output correct). It sits in the coverage gap the curated
*_no_leak_pin fixtures leave open (they keep the heap-Str expression inside
main). Distinct from #49 (loop-carried within one frame); this is the
function-return leg. Routed to debug RED-first; blocks the deliberate
milestone-close until GREEN.
2026-06-01 01:53:46 +02:00
Brummel bd62f2b9d0 docs(design): name the fn-value resolution carve-out in 0018
Audit follow-up (typed-MIR milestone-close drift review, clean). The
boundary contract said codegen does "no callee resolution"; that is true
for App callees — the only thing `Callee` totality claims over — but
`resolve_top_level_fn` still resolves a dotted fn used as a *value* via
`import_map` (the in-corpus-unreachable type-home residue the spec
blessed at mir.2), and ctor/const resolution stay codegen-side. Tighten
the prose to "no App-callee resolution" and name the value-position
carve-out, so the contract is precise and a future drift review does not
read the blanket claim as violated. Prose-only; no code, no test change.
2026-06-01 01:39:30 +02:00
Brummel a378dad0aa docs(design): ratify the check→codegen boundary (mir.5, typed-MIR close)
mir.5 is the typed-MIR milestone's closing iteration. Its CODE half had
already converged before the iteration began, so mir.5 ships no code —
it ratifies into the design/ ledger the boundary the code already holds.

Verified at iteration entry (empirically, not from the spec sketch):
  - all four named re-derivers grep-clean in codegen: synth_with_extras,
    synth_arg_type, type_home_module, the second infer_module_with_cross;
  - lower_workspace takes &MirWorkspace (codegen consumes MIR);
  - MTerm::New is unreachable!() — raw-buf.4 desugars Term::New to
    (app T.new …) before codegen, so there is no element-type
    re-derivation left to relocate;
  - #51 / #53 (the element-type / new-T codegen crashes) are closed;
    their residue was fixed by ee4107c / 420f75f plus the New-desugar,
    not by a separate raw-buf patch track.

Ledger work (the mir.5 deliverable):
  - NEW design/contracts/0018-check-codegen-boundary.md: the invariant
    "codegen re-derives nothing; MIR is total over what check proved;
    a codegen arm that recomputes a fact instead of reading MIR is
    drift." Ratifier: lower_to_mir_ty.rs::callee_classification_builtin_and_static.
  - 0013-typeclasses invariant 2 retracted: codegen no longer re-resolves
    cross-module names via an import_map fallback; lower_to_mir::classify_callee
    resolves the reference once into Callee::Static and codegen consumes it.
  - 0003-pipeline.md: the "lower to MIR" line names the real stage
    (elaborate_workspace → MirWorkspace → lower_workspace) and a new
    paragraph states the boundary, cross-referencing 0018.
  - INDEX.md: boundary contract row added; qualified-xref re-pointed at
    lower_to_mir + 0018.
  - codegen_import_map_fallback_pin.rs doc-comment made honest — it pins
    the post-mono AST precondition classify_callee relies on, not a
    codegen-side resolution that no longer exists. Assertions unchanged;
    the test stays green.
  - spec 0060 gains a mir.5 refinement note recording the early code
    convergence.

Acceptance criteria 1-7 of docs/specs/0060-typed-mir.md are all met.
Full workspace suite green (exit 0, 0 failed, 2 ignored); 708 passed
carried from mir.4 (no test added or removed).

Not done here (deliberately): the milestone #7 (raw-buf) subsumption
note is an external Gitea tracker write; the /boss auto-mode classifier
declined it as an unauthorised external write and it is surfaced to the
user rather than worked around. The end-to-end milestone fieldtest
remains the deliberate manual close-gate before the tracker milestone
is marked done.

refs #51 #53
2026-06-01 01:34:37 +02:00
Brummel c5fd16a4eb feat(codegen): StrRep loop-carried Str ⇒ Heap, close the #49 recur leak
mir.4 closes bug #49 (a heap-Str loop binder replaced across `recur`
leaks every superseded slab; the loop result leaks too) structurally,
by making every Str a loop binder holds OR a loop returns an owned heap
slab — then deleting the `!is_str` carve-out from BOTH codegen gates
that carried it. The leg-by-leg `!is_str` patches are gone.

Mechanism (the milestone thesis: representation in MIR, codegen reads
it). lower_to_mir sets rep = StrRep::Heap on every Str literal in a
loop-carried position; codegen's MTerm::Str arm promotes a Heap literal
via ailang_str_clone (a fresh ailang_rc_alloc slab, rc_header refcount
1). Three promotion positions, all in the Loop/Recur lowering:
  1. binder seed inits (is_str_ty on the binder type);
  2. recur args at Str-binder positions (read off the innermost
     loop_stack frame);
  3. exit-arm tail result literals (promote_tail_str_literals walks the
     loop body's tail positions when the loop returns Str).
With every loop-carried Str now owned-heap, both gates lose !is_str:
the recur superseded-value dec (lib.rs) frees each intermediate slab;
the loop-result trackability gate (drop.rs:493) lets the caller's
scope-close free the final slab.

Why both gates, and the planning-time error this corrects. The original
plan/spec scoped the deletion to the recur dec gate only, reasoning the
#49 loop result is "consumed by print". The implement-orchestrator
landed that scope (Tasks 1-2) clean and correctly BLOCKED: it took #49
from live=3 to live=1, the residual being the loop RESULT. I verified
the diagnosis empirically:
  - print BORROWS its arg (prelude: `(let s (show x) (do io/print_str
    s))`, the eob.1 heap-Str discipline), so `(print s)` does not free
    the loop result; the caller's let-binder does, via drop.rs:493.
    "consumed by print" != "freed by print" — that was the error.
  - Deleting drop.rs:493's !is_str takes #49 and the recur-literal
    fixture to live=0.
  - Deleting drop.rs:493 WITHOUT exit-arm promotion SIGSEGVs (exit 139)
    on a loop returning a static Str literal — hence the third
    promotion position and the static-exit witness.
The agent surfaced a real spec defect via an empirical BLOCK rather
than guessing; I corrected the spec refinement note (both gates, three
positions) and completed the loop-result leg inline, the context
already loaded from verifying the BLOCK (CLAUDE.md "already loaded
context" carve-out). drop.rs:493's Str carve-out is now sound to delete.

Boundary (asserted ill-typed, not constructible): a borrowed static-Str
Var seeded/recur'd into a consumed Str loop binder — rejected upstream
by uniqueness (a consumed binder position is owned).

Verification (orchestrator-run): all four leak fixtures reach live=0
under AILANG_RC_STATS — #49 (xyyy), recur-literal (reset), static-exit
(result), and the f488d31 boxed-ADT guard (2, no regression). The #49
#[ignore] is lifted. Full workspace: 708 passed / 0 failed / 2 ignored
(mir.3b baseline 702/0/3; +6 passed, -1 ignored = #49 lifted; the 2
remaining ignores are doctests). ir_snapshot: no drift (the Heap
promotion does not reach non-loop-carried literals — the
non_loop_str_literal_stays_static pin confirms at the unit level).
Neither CLAUDE.md lockstep pair touches Str representation.

New witness fixtures: examples/loop_str_recur_literal_no_leak_pin.ail
(recur-arg leg) and examples/loop_str_static_exit_no_leak_pin.ail
(loop-result leg / static-exit soundness). New pins: lower_to_mir_ty
exit-arm producer pin + the flipped seed/recur-arg pins; two runtime
leak pins alongside the lifted #49.

closes #49
2026-06-01 00:54:44 +02:00
Brummel 2536b5f535 plan(mir.4): StrRep loop-carried Str ⇒ Heap, delete the recur !is_str gate
mir.4 closes bug #49 (a heap-Str loop binder replaced across `recur`
leaks every superseded str_concat slab, live=3) structurally rather
than with a fourth leg-by-leg patch.

Design calls made in planning (folded into the spec as the mir.4
refinement note):

- Mechanism: producer-side representation, codegen reads it — the
  milestone thesis. lower_to_mir sets rep = StrRep::Heap on every
  MTerm::Str literal that flows into a Str loop-binder alloca (seed
  inits AND recur args at Str-binder positions); codegen's MTerm::Str
  arm gains a Heap leg that promotes the static literal via
  ailang_str_clone (fresh ailang_rc_alloc slab, rc_header refcount 1).
  No special-casing in the codegen Loop/Recur store arms — the clone is
  emitted automatically when the Str{Heap} node is lowered.

- Recur args are promoted too, not just seeds: `(recur "reset" …)` is
  well-typed (verified: `ail check` accepts it), and a seed-only
  promotion would leave a static literal under the now-unconditional
  dec — a constructible UB hole. Soundness over minimalism on the
  highest-risk RC/drop surface.

- Only the recur dec gate (lib.rs:2231) loses !is_str. The drop.rs
  loop-RESULT trackability gate (drop.rs:493) STAYS conservative:
  deleting it needs a broader "every Str a loop can return is
  owned-heap" guarantee (a static exit-arm literal breaks it) and is
  not required by the #49 acceptance (the #49 loop result is consumed
  by print). drop.rs is untouched.

- Boundary (out of scope, asserted ill-typed): a borrowed static-Str
  Var seeded/recur'd into a consumed Str loop binder is rejected
  upstream by uniqueness (a consumed binder position is owned), so it
  is not constructible.

Plan 0119 carries exact code per step: producer rep promotion + a
loop-frame-driven Str-binder mask for recur args (reusing the existing
ctx.loop_stack, no new ctx field), the codegen Heap leg, the gate
deletion, the #[ignore] lift on the #49 pin, a recur-literal witness
fixture + runtime pin proving the recur-arg leg, and the full-suite +
ir_snapshot verification. The existing lower_to_mir_ty Static-seed pin
flips to assert Heap.
2026-06-01 00:34:18 +02:00
Brummel eba1be8d9d feat(codegen): fill MArg.mode for App args, read the anon-temp drop gate off it, delete module_def_ail_types (mir.3b)
Second of two iterations delivering spec 0060's mir.3 row (plan
docs/plans/0118-mir.3b-marg-mode-and-table-delete.md). lower_to_mir's
Term::App arm fills each MArg.mode from the resolved callee's
param_modes (the sig = synth_pure(callee) it already holds); codegen's
emit_call anon-temp borrow-slot drop gate reads arg.mode instead of
re-looking-up the callee's param_modes from the module_def_ail_types
table; and — since that gate was the table's only reader — the
module_def_ail_types field plus all its construction and threading are
deleted.

Two refinements to the spec's mir.3b sketch, settled in planning from a
focused recon and recorded in spec 0060:

1. module_def_ail_types is deleted in mir.3b, not mir.5. A grep proved
   self.module_def_ail_types had exactly ONE reader (the anon-temp
   gate); the own-param drop reads param_modes from the def's own f.ty,
   not this table. Once the gate moves onto MArg.mode the table is dead,
   so it is removed now rather than carried as dead code to mir.5. The
   mir.5 row's "last re-derivation residue" shrinks to the
   element-type / Term::New (New.elem) work.

2. MArg.mode is filled for App args only; MTerm::Let.mode is not filled.
   Only App args have a real per-arg mode source (the callee
   Type::Fn.param_modes). Do args (EffectOpSig has no param modes), Ctor
   args (no per-field mode), and Recur args (loop binders carry no mode)
   stay Mode::Owned. Let.mode has no source (ast::Term::Let has no mode
   field) and no consumer (the let-drop gate reads consume, not
   Let.mode), so it stays Owned — filling it would invent a value
   nobody reads.

Safety property held: MArg.mode is filled from the same callee fn-type
the gate read from the table, so the drop fires identically. For
(app RawBuf.get (app RawBuf.set …) 0), RawBuf.get's param 0 is borrow,
so args[0].mode = Borrow — exactly the value module_def_ail_types
yielded. Confirmed by the anon-temp witness staying green.

ParamMode -> Mode conversion: Borrow -> Mode::Borrow; Own and Implicit
(the Implicit ≡ Own contract) -> Mode::Owned. The own-param drop keeps
reading ParamMode off f.ty (Type/ParamMode imports retained, live
readers at lib.rs:1356/1507).

Also retires three now-stale doc comments that named the deleted
module_def_ail_types field (ailang-check/src/lib.rs, uniqueness.rs, and
the codegen_import_map_fallback_pin test doc) — a direct consequence of
the deletion, reworded to the current architecture.

Verification (orchestrator, post-implement inspect): diff matches the
plan (App-arg m_args built before m_callee consumes sig — the benign
borrow-order deviation the plan's note flagged); module_def_ail_types
grep-clean across all of crates/; cargo build --workspace clean (no
unused/dead_code); cargo test --workspace 702 passed / 0 failed / 3
ignored (+1 = the new producer pin app_arg_carries_callee_borrow_mode;
no #[ignore] added). The anon-temp drop-correctness witness
raw_buf_owned_drop_balances_rc_stats stays live=0, now driven by
MArg.mode; the other RC-stats leak pins green; #49 stays #[ignore]
(mir.4); #51/#53 build guards green.

mir.3 is now complete (3a relocated consume_count + deleted the second
uniqueness run; 3b filled the mode annotation + deleted
module_def_ail_types). Remaining: mir.4 (#49 StrRep RED->GREEN),
mir.5 (element-type/Term::New + ledger).
2026-05-31 20:10:25 +02:00
Brummel 0bd7f47fad plan: mir.3b fill MArg.mode, switch the anon-temp gate onto it, delete module_def_ail_types
Executable plan for the second of two iterations delivering spec 0060's
mir.3 row. A focused recon (the anon-temp gate + the per-arg mode
sources) established two refinements to the spec sketch, both locked in
the plan:

1. module_def_ail_types is deleted in mir.3b, not mir.5. A grep proved
   self.module_def_ail_types has exactly ONE reader — the emit_call
   anon-temp borrow-slot drop gate. The own-param drop reads param_modes
   from the def's own f.ty, not this table. So switching that gate onto
   MArg.mode leaves the table dead; deleting it now is the clean move.
   mir.5's "last re-derivation residue" shrinks to element-type/Term::New.

2. MArg.mode is filled for App args only; MTerm::Let.mode is not filled.
   Only App args have a real per-arg mode source (the callee
   Type::Fn.param_modes). Do/Ctor/Recur args have no per-arg mode
   (EffectOpSig/Ctor.fields/loop-binders carry none) -> stay Owned
   default. Let.mode has no source (ast::Term::Let has no mode field)
   and no consumer (the let-drop gate reads consume, not Let.mode) ->
   stays Owned.

Safety property (recon-confirmed on the #43 anon-temp witness): MArg.mode
is filled from the same callee fn-type the gate read from the table, so
the drop fires identically. For (app RawBuf.get (app RawBuf.set …) 0),
RawBuf.get's param 0 is borrow -> args[0].mode = Borrow, exactly the
value module_def_ail_types yielded.

Four tasks: (1) producer fills App-arg MArg.mode via a param_mode_at
helper; (2) codegen gate reads arg.mode + delete module_def_ail_types
(field + construction + threading, compiler-completeness-checked);
(3) producer pin (App arg mode == Borrow) + the live=0 anon-temp
acceptance (raw_buf_owned_drop_balances_rc_stats); (4) record the
refinements in spec 0060. No new .ail fixture (reuses raw_buf_drop_min.ail).
2026-05-31 20:00:12 +02:00
Brummel 6bc0b501cb feat(codegen): relocate per-binder consume_count into MIR; delete codegen's second uniqueness run (mir.3a)
First of two iterations delivering spec 0060's mir.3 row (plan
docs/plans/0117-mir.3a-consume-count-relocation.md). The per-binder
consume_count — the only thing codegen read from its second
infer_module_with_cross run — now lives on a new binder-keyed
MirDef.consume: BTreeMap<String,u32>, filled once by lower_to_mir on the
post-mono body. Codegen builds its existing (def,binder)->consume_count
lookup from those maps and the three scope-close drop sites (own-param,
let-binder, match-arm) read it; the codegen uniqueness run, its
UniquenessTable field, and the import are deleted.

mir.3 is split into two iterations (recorded in spec 0060): the named
deletion depends ONLY on consume_count. All three drop sites read
consume_count from self.uniqueness, while the modes they also gate on
(param_modes for the own-param dec, scrutinee_is_owned for the match
dec) come from the type, not the uniqueness pass (UniquenessInfo carries
no mode). So mir.3a relocates consume_count and ships the deletion;
mir.3b (next) fills MArg.mode/MTerm::Let.mode and switches emit_call's
anon-temp gate onto MArg.mode. The split halves the change at the
codebase's highest-risk surface (RC/drop correctness, the raw-buf leak
saga) and makes each half independently verifiable against the live=0
leak pins.

Design: consume_count lands on MirDef (binder-keyed), NOT on MArg. The
drop sites key by (def, binder_name) — a per-binder aggregate — while the
spec-sketched MArg.consume_count is per-arg-position and never reaches
them; the per-def map matches the UniquenessTable's own keying and all
three binder kinds (param/let/pattern) uniformly. MArg.consume_count
stays a mir.1 default. Source = run check's infer_module_with_cross
inside lower_to_mir post-mono (the synth_pure single-engine-re-walked
pattern); retaining a check-time result is blocked (check's uniqueness
is pre-mono and runs on-demand-from-codegen, never in check_workspace,
so it would miss the mono specialisations). cross_module_types
(= codegen's module_def_ail_types) is rebuilt in elaborate_workspace
from the post-mono workspace.

Safety property held: this is a PURE RELOCATION of an identical
computation — infer_module_with_cross ran on the post-mono module in
codegen and now runs on the same post-mono module in lower_to_mir, so
drop placement is byte-identical. cross_module_types matches
module_def_ail_types exactly (both insert f.name->f.ty over post-mono
Def::Fn), confirmed by the leak pins staying green.

Verification (orchestrator, post-implement inspect): diff matches the
plan; codegen grep-clean for infer_module_with_cross + UniquenessTable
(now ailang-check-internal); cargo build --workspace clean (no errors,
no unused warnings — module_def_ail_types survives for emit_call's
anon-temp param_modes gate); cargo test --workspace 701 passed / 0
failed / 3 ignored (+1 = the new producer pin
mirdef_consume_is_populated_for_let_binder; no #[ignore] added). The
live=0 drop-correctness witnesses all green:
alloc_rc_loop_valued_rawbuf_binder_drops_at_scope_close (#43/#47),
alloc_rc_heap_loop_binder_replaced_by_recur_does_not_leak,
alloc_rc_print_int_does_not_leak_show_result_str. #49 stays #[ignore]
(mir.4); #51/#53 build guards green.
2026-05-31 19:48:57 +02:00
Brummel 69749fc3e1 plan: mir.3a relocate consume_count into MIR, delete codegen's second uniqueness run
Executable plan for the first of two iterations delivering spec 0060's
mir.3 row. Two plan-recon passes (mode/consume/drop-placement surface +
the uniqueness-pass signature) established that the named deletion (the
second infer_module_with_cross run) depends ONLY on consume_count: all
three codegen scope-close drop sites read consume_count from
self.uniqueness, while the modes they also gate on (param_modes for the
own-param dec, scrutinee_is_owned for the match-arm dec) come from the
type, not the uniqueness pass (UniquenessInfo carries no mode). So mir.3
splits:

- mir.3a (this plan): relocate consume_count; delete the second run.
- mir.3b (next): fill MArg.mode / MTerm::Let.mode from the type modes
  and switch emit_call's anon-temp borrow-slot gate onto MArg.mode.

The split halves the change at the codebase's highest-risk surface
(RC/drop correctness, where the raw-buf leak saga lived) and makes each
half independently verifiable against the live=0 leak pins.

Design decisions locked in the plan:

- consume_count lands on a new binder-keyed MirDef.consume:
  BTreeMap<String,u32>, NOT on MArg. The recon surfaced the central
  structural tension: the drop sites key consume_count by
  (def, binder_name) — a per-binder aggregate — while the spec-sketched
  MArg.consume_count is per-arg-position and never reaches them. The
  per-def binder map matches both the UniquenessTable's own keying and
  all three binder kinds (param/let/pattern) uniformly. MArg.consume_count
  stays a mir.1 default (no consumer). Spec 0060 is updated to record
  this (Task 5).

- Source = run check's infer_module_with_cross inside lower_to_mir on
  the post-mono module (the synth_pure single-engine-re-walked pattern).
  The alternative of retaining a check-time result is blocked: check's
  uniqueness runs pre-mono and on-demand-from-codegen, never during
  check_workspace, so a retained result would miss the mono
  specialisations. cross_module_types (= codegen's module_def_ail_types,
  module->def->Type) is rebuilt in elaborate_workspace from the post-mono
  workspace.

Key safety property carried in the plan: this is a PURE RELOCATION of an
identical computation. infer_module_with_cross ran on the post-mono
module in codegen and now runs on the same post-mono module in
lower_to_mir — same function, same input, same output — so drop
placement is byte-identical. The live=0 leak pins (raw_buf_loop_no_leak,
loop_recur_heap_binder, print_no_leak) are the value-correctness gate.

Five tasks: (1) add MirDef.consume; (2) elaborate_workspace builds
cross_module_types + lower_module runs the pass and fills consume;
(3) codegen builds its (def,binder)->consume lookup from MIR, the three
drop sites read it, delete the run + field + import; (4) producer pin +
leak-pin acceptance + grep-clean; (5) record the split in spec 0060. No
new .ail fixture (producer pin reuses new_counter_user_adt.ail).
2026-05-31 19:40:54 +02:00
Brummel a6fd93adba feat(codegen): pre-resolve the App callee in MIR; delete is_static_callee + type_home_module (mir.2)
Second re-deriver removal of the typed-MIR milestone (spec
docs/specs/0060-typed-mir.md, plan docs/plans/0116-mir.2-callee-static.md).
Static-callee resolution moves out of codegen and into lower_to_mir:
every Term::App callee is classified once, mirroring check's own synth
Term::Var ladder (lib.rs:3409-3582), and emitted as a resolved Callee.
Codegen reads the callee identity off MIR and routes each kind to the
right lowering. The codegen re-derivers is_static_callee and
type_home_module are deleted, and the lower_app <-> is_static_callee
lockstep pair is struck from CLAUDE.md.

Callee reshape (beyond the spec's original {module, fn_name} sketch —
spec 0060's Concrete-code-shapes block is updated in this iteration):

  pub enum Callee {
      Static  { module, fn_name, sig: Type },  // user/prelude fn -> emit_call, module pre-resolved
      Builtin { name, sig: Type },             // operator/intrinsic -> inline opcode lowering
      Indirect(Box<MTerm>),                    // dynamic: fn-pointer / closure / shadowed name
  }

Two forced refinements, both settled in planning:

- sig:Type on each resolved variant. drop::synth_callee_ret_mode reads
  the callee ret_mode, today off Callee::Indirect(inner).ty(). A
  resolved callee has no sub-term, so the sig (= synth_pure(callee),
  mode-preserving) is the lossless replacement. This is NOT a mir.3
  pull-forward: the MArg param-mode / consume_count fields stay at their
  mir.1 defaults. Without it, every statically-resolved call would lose
  its drop signal and the RawBuf / int_to_str RC-stats pins mir.1b fixed
  would regress.

- Builtin variant. Operators and the str-num builtins (+, not,
  str_concat, ...) are lowered inline by name and have no module/fn_name;
  a separate variant is cleaner than a sentinel module. The classifier
  decides Builtin vs Static from CHECK'S OWN resolution (a name in
  env.globals with no owning module is a builtin), never a copy of
  codegen's old is_static_callee allowlist. The recon's divergence audit
  confirmed check's builtin set and codegen's inline-arm set match
  exactly, so the single-engine rule is mechanically satisfiable with no
  env threading gap.

type_home_module is fully deletable: a workspace-wide grep confirmed no
program references a type-scoped T.fn as a value, so its only other
consumer (resolve_top_level_fn) collapses to the module-name fallback
with no behaviour change. (The spec's "x3 mirrors" wording over-counted;
the live surface was the definition plus two call sites.)

Alternatives rejected during planning: sentinel module in Static
(ugly); builtins left as Indirect (breaks — no fn-pointer for an
operator); name-rewrite Static{name,sig} keeping lower_app's by-name
dispatch (blurs builtin/user and still needs sig). The mir.1b
re-synth-strictness trap (post-mono synth_pure re-unify surfacing
mode-strip / bare-vs-qualified / metavar leaks) did NOT fire under the
new producer path — qualify_local_types mode-preservation and the $u
wildcard normalisation from mir.1b held.

Verification (orchestrator, post-implement inspect): diff matches the
plan; grep-clean for is_static_callee + type_home_module across
ailang-codegen and ail; cargo build --workspace green; cargo test
--workspace 700 passed / 0 failed / 3 ignored (no #[ignore] added this
iteration — the 3 are the pre-existing #49 Str-leg pin + two doctests).
Acceptance witnesses green: #53 (mono_new_over_user_adt_builds_and_runs),
#51 (rawbuf_new_int_size_only_builds_and_runs still builds), show_print
cross-module (print_user_adt_runs_end_to_end), the new mir.2 pins
(mir2_resolved_callee_kinds_run_end_to_end, callee_classification_*,
strengthened new_over_user_adt_carries_node_types asserting Callee::Static).
#49 heap-Str loop binder stays #[ignore] (lifts at mir.4).

Two new examples/ fixtures back the new pins (classify_pin.ail for the
producer classification pin, mir2_callee_kinds.ail for the E2E),
ail-parse / round-trip clean.

Forward note (cycle-close architect): crates/ail/tests/codegen_import_map_fallback_pin.rs:14-15
doc prose names lower_app's cross-module arm and synth_with_extras as
failure-mode targets — both now deleted (mir.2 / mir.1b). The pin's
protected invariant is still valid and green; the prose is stale and
wants a doc-honesty reword, left out of this iteration's footprint.
2026-05-31 19:27:56 +02:00
Brummel d81ea93de6 plan: mir.2 Callee::Static pre-resolved, codegen stops re-deriving the callee
Executable plan for spec 0060's mir.2 iteration: relocate static-callee
resolution from codegen into lower_to_mir. Two plan-recon passes (codegen
consumer surface + check-side producer surface) mapped the resolution
frontend; this plan locks three design decisions made during planning,
ahead of the tasks:

1. The Callee bridge enum is reshaped beyond the spec sketch: a third
   variant Builtin{name,sig} (operators / str-num intrinsics have no
   module/fn_name and are lowered inline by name), and a sig:Type on each
   resolved variant. The sig is the lossless replacement for the pre-mir.2
   Callee::Indirect(inner).ty() read that drop's synth_callee_ret_mode
   depends on; it is synth_pure(callee), mode-preserving. NOT a mir.3
   pull-forward — the MArg param-modes stay at mir.1 defaults. Spec
   0060's Concrete-code-shapes Callee block is updated as part of the
   iteration (Task 5).

2. Classification mirrors check's own synth Term::Var ladder
   (lib.rs:3409-3582), never copies codegen's is_static_callee allowlist.
   The recon's divergence audit confirmed check's builtin set and
   codegen's inline-arm set match exactly, so the single-engine rule is
   mechanically satisfiable with no env threading gap.

3. type_home_module is fully deletable: a workspace-wide grep confirmed no
   program references a type-scoped T.fn as a value, so its second
   consumer (resolve_top_level_fn) collapses to the module-name fallback
   with no behaviour change. The spec's "grep-clean" acceptance holds; the
   spec's "x3 mirrors" wording over-counts (def + 2 live sites).

Five tasks: (1) reshape Callee; (2) lower_to_mir classify_callee +
App arm; (3) the atomic codegen consumer switch (App arm/drop/lower_app
split/delete is_static_callee+type_home_module/resolve_top_level_fn);
(4) pins (strengthen #53 to assert Callee::Static, add a three-way
classification pin) + workspace suite; (5) strike the lower_app <->
is_static_callee lockstep row from CLAUDE.md, update spec 0060, clean
stale comment references. The classify_pin fixture is ail-parse-gated
(exit 0).
2026-05-31 19:10:37 +02:00
Brummel 895ba846e8 feat(codegen): switch the lowering walk from &Term to typed &MTerm (mir.1b)
Atomic completion of spec iteration mir.1 (docs/specs/0060-typed-mir.md):
codegen now consumes the typed MIR produced by `lower_to_mir` instead of
re-deriving types from the bare `ast::Term`. Every codegen helper that
took `&Term` (lower_term, lower_app, drop.rs, match_lower.rs) takes
`&MTerm` and reads each node's checker-proved type off `MTerm::ty()`.
The build path is `Workspace -> elaborate_workspace -> MirWorkspace ->
lower_workspace`; the public `lower_workspace*` entry points and their 18
call sites thread `&MirWorkspace`. The codegen-side type re-derivers
`synth_with_extras` + `synth_arg_type` (and the `builtin_ail_type` /
`builtin_effect_op_ret` mirror tables) are deleted — grep-clean. The
three re-derivers the spec keeps until mir.2/mir.3 (`type_home_module`,
`is_static_callee`, the second `infer_module_with_cross`) stay.

The mechanical Term->MTerm match-arm conversion was straightforward and
compiler-enforced. The substance was a set of producer-side correctness
gaps that only surface once codegen reads `MTerm::ty()` and once the
build path re-synthesises the post-mono AST through the canonical
`synth` (which, unlike the old codegen, fully re-unifies). Each was
root-caused against a failing e2e fixture:

1. `qualify_local_types` stripped fn-type modes (rebuilt `Type::Fn` with
   empty `param_modes` / `Implicit` `ret_mode`), so a monomorphised
   polymorphic intrinsic (`RawBuf.set`) lost its `Own` ret-mode and the
   owned temporary leaked at the call site. Made mode-preserving, like
   its sister `qualify_workspace_types` and `Subst::apply` (449df13).

2. `lower_to_mir::synth_pure` synthesises each node in isolation, so a
   nullary polymorphic ctor (`Nil : List<a>`) left its element type an
   unbound `$m` metavar that the canonical synth never pins. Codegen's
   mono unifier (`unify_for_subst`) already has a wildcard for exactly
   this — `$u`, the spelling the now-deleted codegen synth used — so the
   typed-MIR boundary normalises every residual `$m` to `$u` once
   (`wildcard_residual_metavars`), rather than teaching each consumer to
   tolerate a raw metavar.

3. The class-method mono arm (`synthesise_mono_fn`) substituted the
   registry-canonical *qualified* instance type into a method appended to
   the instance's own module, minting a `show_user_adt.IntBox` param
   against a bare-`IntBox` body. Localised to bare before substitution,
   symmetric to the free-fn arm (600565d).

4. Monomorphisation synthesises *downward* class-dispatch references —
   prelude's `print__<IntBox>` names the instance module `show_user_adt`
   that prelude never imports. The post-mono re-synth in `lower_module`
   seeds every workspace module name as an identity import (excluding the
   current module, to keep own types bare) so the qualified-var path
   resolves these; the canonical `synth` used by `check_workspace` stays
   strict.

5. Post-mono, a cross-module callee can name the consumer's *own* ADT
   qualified (`show_user_adt.IntBox`) where the consumer synthesises it
   bare — a spelling split that cannot exist pre-mono (the param is
   polymorphic there). synth's App arm strips the current module's own
   qualifier from both sides before unifying (`strip_own_module_qual`),
   a no-op pre-mono.

Acceptance: whole workspace suite green (698 tests); `e2e` 98/98 and
`show_print_e2e` 3/3; `synth_with_extras`/`synth_arg_type` grep-clean in
codegen; #51/#53 fixtures build and run; lower_to_mir_ty pins green. The
#49 heap-Str loop-binder leak remains ignored (lifts at mir.4).

Builds on the standalone producer fix (600565d, free-fn own-ADT
localisation) and the two standalone mode-preservation fixes
(449df13 Subst::apply); those landed separately as they are
independently correct and inert on the old codegen.
2026-05-31 18:29:36 +02:00
Brummel 449df13c9c fix(check): preserve fn-type modes through Subst::apply
`Subst::apply` rebuilt every `Type::Fn` with `param_modes: vec![]`
and `ret_mode: Implicit`, discarding the modes the surrounding type
carried. That was harmless while nothing downstream of inference read
fn-type modes — but it is a latent under-specification: substitution
is meant to be type-preserving, and a fn type's modes are part of its
identity (an `(own T) -> (own U)` contract is not the same contract as
its borrow-returning sibling). Modes are positional over `params`, and
substitution remaps each param type element-wise without changing the
arity, so the mode lists stay aligned — preserving them is a clone, not
a re-derivation.

The typed-MIR boundary (milestone 0060) makes this load-bearing: a node
type synthesised by `lower_to_mir::synth_pure` ends with `subst.apply`,
and the codegen drop path reads `ret_mode == Own` off a call's callee
node to decide RC trackability. With the modes stripped here, an
Own-returning call read back `Implicit`, nothing was trackable, and a
heap-allocated binder leaked at scope close. Preserving the modes
restores that signal at the source rather than re-deriving it in codegen
(which is exactly the re-derivation the milestone exists to delete).

Safe by construction: `unify`'s Fn arm destructures modes with `..` and
compares only params/ret/effects, so carrying modes through `apply`
cannot change unification; and `Type`'s custom `PartialEq` already
treats `Implicit` and `Own` as interchangeable (only `Borrow` is
distinct), so equality outcomes are unaffected except where preserving
a `Borrow` is the more correct answer anyway. Whole `ailang-check`
suite stays green.

RED pin: crates/ailang-check/tests/subst_preserves_modes.rs.
2026-05-31 18:01:24 +02:00
Brummel 600565d356 fix(check): localize own-ADT type-args in free-fn mono; complete the lower_to_mir producer
Additive producer-side work for the typed-MIR milestone (spec
docs/specs/0060-typed-mir.md), surfaced while building the mir.1b
codegen-consumption switch. Nothing here consumes MIR — codegen is
untouched; the whole existing suite stays green and one new RED pin
goes green. The mir.1b codegen switch itself stays in the working tree.

Headline fix — own-ADT type-arg localization in free-fn mono:

  monomorphise_workspace's free-fn arm normalises every observed
  type-arg through Registry::normalize_type_for_lookup. That
  normalisation is load-bearing for cross-module dedup and a stable
  specialisation symbol name, but it qualifies a *defining-module-own*
  ADT to `<module>.<T>`. synthesise_mono_fn_for_free_fn then substitutes
  those qualified type-args into the polymorphic source signature and
  body, which are in the module's own *bare* convention (the qualify
  pre-pass deliberately leaves own-module type-cons bare — lib.rs:4358,
  "the current module sees its own types bare"). The result is a
  self-inconsistent specialisation: e.g. fold_left specialised with
  accumulator b := List<Int> minted
    ((std_list.List<Int>, Int) -> std_list.List<Int>,
     std_list.List<Int>, List<Int>) -> std_list.List<Int>
  — a qualified accumulator parameter against a bare list argument and a
  bare Lam body. check_workspace never hits this (it synths the pre-mono
  bodies, bare throughout); the old codegen tolerated it via the
  now-deleted synth_arg_type's loose type-tracking. The post-mono synth
  re-entry in lower_to_mir does full unification and correctly rejects
  it: `expected std_list.List<Int>, got List<Int>`.

  Fix: localize_own_types (mono.rs) strips the `<defining_module>.`
  prefix back to bare for the module's own ADTs, applied to the type-args
  before they are substituted, so the synthesised signature and body stay
  uniformly bare-own. The *stored* type_args remain normalised, so the
  symbol name and the Phase-3 rewrite-cursor key on the same canonical
  form — the byte-identity invariant between synthesis and rewrite is
  untouched. The ClassMethod arm needs no analogue: it already
  substitutes the un-normalised target.type_ (mono.rs:841).

  Alternatives rejected: (a) drop the normalisation in the shared
  apply_subst_and_normalize helper — breaks cross-module dedup, mints
  duplicate specialisations under divergent names. (b) Make
  lower_to_mir's synth treat `<owner>.T` and bare `T` as equal during
  unification — papers over the producer inconsistency in the consumer
  and contradicts the established own-types-stay-bare invariant the rest
  of check relies on. (c) Qualify the whole synthesised def own->qualified
  — fights lib.rs:4358 and would require the lower path to also flip,
  cascading the convention change through synth.

Producer completeness (additive, mirrors existing guards):

  - lower_module skips Type::Forall defs (lower_to_mir.rs), mirroring
    emit_module's guard. Polymorphic defs are stale source kept for
    round-trip; their bodies carry mono-rewritten call names for
    specialisations that were never synthesised, so a synth re-entry
    would hit UnknownIdentifier.
  - lower_module lowers non-literal const bodies to typed MTerm, carried
    in MirModule.consts (+ MirConst in ailang-mir). A non-literal const
    (e.g. a List ctor expression) needs a typed body once the consumer
    walk takes &MTerm; literal consts emit a global and need no body.
  - MirModule gains `ast: Module`, populated by lower_module — forward
    scaffolding the mir.1b codegen consumption reads for module
    structure. Populated here, consumed by the in-tree switch.

Verification: full `cargo test --workspace` green (697 passed, 0 failed)
with the codegen-consumption switch stashed out, including the new pin
crates/ailang-check/tests/lower_to_mir_ty.rs::poly_free_fn_accumulating_into_own_adt_elaborates
(RED before the localize fix with the exact mismatch above, GREEN after)
and the full e2e corpus (the own-ADT-poly demos elaborate clean and run
through the old codegen). This proves the producer fix is
regression-free and the remaining 22 e2e reds in the working tree are
codegen-consumption defects, not producer defects.
2026-05-31 17:41:05 +02:00
Brummel 5b4eb766c3 glossary: bootstrap AILang nomenclature ledger
Add design/glossary.md (25 entries) and wire it in via the
paths.glossary profile slot, making it standing reading for every
skill and agent role.

Built by the glossary skill's bootstrap procedure: five read-only
glossary-extractor agents swept the prose surface (design/contracts,
design/models, design/INDEX.md, docs/PROSE_ROUNDTRIP.md, and the 60
docs/specs in three blocks), reporting recurring domain-concept terms
and their competing synonyms with frequencies. docs/plans was
excluded as a derived execution artefact that mirrors spec/contract
vocabulary rather than originating it.

Three apparently-contested clusters were resolved by record-reality
against the authoritative current docs (CLAUDE.md + design/): the
retired .ailx extension yields to .ail; Form-A wins over "Form A"
(13:2); round-trip wins over roundtrip (15:10). The one genuine
nomenclature choice -- the canonical term for the structured hashable
form -- was decided by the user: JSON-AST is canonical, .ail.json is
its on-disk file. The local conformance check caught and removed a
Form-B / JSON-AST Avoid-list collision before write.
2026-05-31 17:10:46 +02:00
Brummel 1a1a68df8b plan: mir.1b — codegen consumes MIR (the atomic switch)
Second half of spec iteration mir.1, planned against the landed mir.1a
infrastructure (135f4ce). This is the project's largest single
mechanical change and it is atomic: codegen's entire lowering walk
flips from &Term to &MTerm with no compiling intermediate (dual-path is
spec-forbidden). plan-recon proved the blast radius with a compile stub
(flipping only lower_term's signature → 58 cascading errors across
lib.rs/drop.rs/match_lower.rs/escape.rs/lambda.rs, baseline restored
green). The plan gives a Term→MTerm correspondence rule for the
mechanical arm renames (the build gate is the totality checker), exact
before→after for the judgement sites (the 9 synth_arg_type reads → ty(),
the dual-source Emitter, escape pointer-identity, entry-point
signatures, CLI diagnostics), and a satisfiable gate per task.

Four recon open-questions resolved by orchestrator judgement (within
the approved spec's intent; the spec's MirModule sketch is illustrative
and exact shape is the planner's):
- OQ1: MirModule gains `ast: Module` — codegen reads structural data
  (Type/Const/ctor/intrinsic markers/symbol tables) from .ast, typed fn
  bodies from .defs. MirWorkspace stays the single artefact (it now
  contains the post-mono AST); structural reads were never a
  re-derivation, so this does not reintroduce one. Also resolves the
  intrinsic-fn gap (lower_module skips intrinsic bodies; codegen
  iterates ast.defs and looks up MirDef bodies by name).
- OQ2: emit_fn borrows mir_def.body:&MTerm once and shares it between
  escape::analyze_fn_body and lower_term (pointer identity is only
  stable within one borrowed tree); casts flip to *const MTerm.
- OQ3: MTerm::New's codegen arm stays unreachable! — New is desugared
  away before codegen (RawBuf→payload, monomorphic user-ADT new→dotted
  App), exactly as Term::New is today; #51 builds unchanged.
- OQ4: the CLI build/emit-ir paths drop their separate check_workspace
  call and let elaborate_workspace's Err drive diagnostics (one check,
  not two); `ail check` stays on check_workspace.
- emit_ir keeps &Module, calls elaborate_workspace internally,
  converts Err(diags)→CodegenError; its builtin-only in-source tests
  check clean without a prelude.

Task structure: Task 1 (additive) extends MirModule + populates ast +
adds codegen's ailang-mir dep, gate cargo test --workspace. Task 2 (the
atomic flip) converts the whole codegen crate including its tests, gate
cargo test -p ailang-codegen (deliberately excludes crates/ail so the
not-yet-threaded external callers don't fail this gate). Task 3 threads
the crates/ail callers (CLI build/emit-ir/staticlib + 6 e2e callers),
gate cargo test --workspace == 102 ok (the mir.1a baseline), #51/#53
build+run, synth_with_extras/synth_arg_type grep-clean.

refs #49
2026-05-31 14:23:26 +02:00
Brummel 135f4ceed7 feat(check): mir.1a — typed-MIR types + post-mono lower_to_mir + elaborate_workspace (additive)
First half of spec iteration mir.1 (docs/specs/0060-typed-mir.md,
plan docs/plans/0114-mir.1a-mir-infrastructure.md). Purely additive: a
new leaf crate plus a post-mono lowering walk plus the front-end entry.
Nothing consumes MIR yet — codegen and the CLI are untouched — so the
whole existing suite stays green (102 test-result-ok lines, 0 failed;
the one ignored is the #49 pin, which lifts at mir.4). mir.1b flips
codegen to consume MIR and deletes the synth_with_extras mirror.

What lands:
- `ailang-mir` (new leaf crate, depends only on ailang-core): MTerm /
  MArg / MArm / MLoopBinder / MNewArg / Callee / Mode / StrRep / MirDef
  / MirModule / MirWorkspace, structurally complete over all 17 Term
  variants plus the dedicated Str split (MTerm::Str{lit,rep}). Every
  later-iteration annotation field exists now at a mir.1 default
  (App.callee = Indirect, MArg.mode/consume_count = Owned/1, Str.rep =
  Static, New.elem = None); the struct shape will not change across
  mir.2–mir.5, only the values. MTerm::ty() reads the carried type.
- `ailang-check::lower_to_mir`: the post-mono walk. Carries no second
  type engine — it calls the canonical `synth` per node with fresh
  throwaway inference scaffolding (subst/counter/residuals/…), applies
  the substitution, and threads only the lexical locals/loop_stack,
  maintained by the same push/pop rules synth uses (Let, Loop, Lam,
  LetRec, and Match via synth's own type_check_pattern). This is the
  "one engine, not two" property the milestone buys, on the producer
  side.
- `ailang-check::elaborate_workspace`: the single front-end entry —
  check (diagnostics gate) → desugar+lift → monomorphise → lower_to_mir
  — transcribed from the CLI build path. check_workspace stays for the
  diagnostics-only callers.
- Three ty-fill pins (crates/ailang-check/tests/lower_to_mir_ty.rs)
  load the #51/#53/#49 witnesses as fixtures and elaborate the whole
  workspace, so lower_to_mir is exercised over the full prelude+kernel,
  not just the tiny witness. Two new witness fixtures
  (examples/new_{rawbuf_size_only,counter_user_adt}.ail); #49 reuses the
  existing loop_recur_str_binder_no_leak_pin.ail.

Deviations from the plan, all forced by ground truth and verified
against the live code before commit:
- FnDef.export is Option<String>, not bool — dropped from MirDef (the
  plan's note allowed this fallback). Codegen reads FnDef.export
  directly, unaffected.
- fn_param_types did not exist — lifted the param-type extraction into
  a shared pub(crate) fn and rewired both mono.rs sites
  (collect_mono_targets, collect_rewrite_targets) to it, so the
  param-type source cannot drift between mono and lower_to_mir. The
  helper unwraps a top-level Forall then reads Type::Fn.params —
  identical to the inner_ty extraction it replaces; the early-return
  non-fn guard is preserved at both sites. Behaviour-preserving (whole
  suite green; this is the only edit to existing mono behaviour).
- lower_module mirrors two more mono.rs scaffolding rules the plan
  under-transcribed: skip intrinsic-bodied fns (they are
  signature-only; lowering them would hit synth's Term::Intrinsic
  guard) and seed env.current_module + env.globals + env.imports per
  module so synth's Var lookup resolves post-mono specialisations
  (e.g. compare__Int) in the prelude.
- The #53 pin asserts the lowered (new Counter 42) init carries ty
  Counter, not that it is an MTerm::New: a monomorphic `new` over a
  user ADT is desugared to a dotted call `(app Counter.new 42)` before
  lower_to_mir runs (desugar.rs:1078-1098), so it lowers to MTerm::App.
  MTerm::New survives only for a polymorphic `new` carrying a written
  NewArg::Type (the #51 RawBuf path, covered by the rawbuf pin). The
  pin's intent — ty-fill correctness — is preserved; the structural
  variant is mir.2/mir.5 territory.
- ailang-mir uses workspace-inherited Cargo fields for consistency with
  the existing crates (added it to [workspace.dependencies]).

refs #49
2026-05-31 14:04:03 +02:00
Brummel 438a009b83 plan: mir.1a — typed-MIR infrastructure (additive half of spec mir.1)
First of two plans for spec iteration mir.1 (docs/specs/0060-typed-mir.md).
mir.1 is the project's largest iteration — a full codegen frontend
switch from walking &Term to walking &MTerm — and it does not fit one
bite-sized plan, because the switch is atomic: there is no compiling
intermediate between "all Term" and "all MTerm" (dual-path is
spec-forbidden). The MIR *producer* side, by contrast, compiles and
tests in isolation. So mir.1 is sequenced across two plans:

- mir.1a (this plan): the additive producer — new leaf crate
  ailang-mir (MTerm/MArg/Callee/Mode/StrRep, structurally complete over
  all 17 Term variants plus the Str split), ailang-check::lower_to_mir
  (post-mono walk that calls canonical synth per node and maintains
  locals/loop_stack exactly as synth does — no second type engine), and
  ailang-check::elaborate_workspace (check → desugar+lift → mono →
  lower_to_mir). Nothing consumes MIR yet; codegen untouched; whole
  suite stays green; three ty-fill pins load the #51/#53/#49 witnesses
  as fixtures and elaborate the full workspace (prelude included).

- mir.1b (next plan, against the landed types): flip codegen's walk to
  &MTerm, delete synth_with_extras + synth_arg_type (9 call sites across
  lib.rs/drop.rs/match_lower.rs), thread the 18 lower_workspace* callers,
  switch the CLI build path to elaborate_workspace.

Both together satisfy the spec's mir.1 row. The split is plan
granularity, not a spec change — the spec's mir.1 deliverable is
unchanged.

Orchestrator design calls baked in (planner judgement, no user fork):
dedicated MTerm::Str{lit,rep} variant (Str-split installs the mir.4
hook at the #49 loop seed); emit_ir keeps &Module (builds MIR
internally — minimal blast radius); lower_to_mir scaffolding mirrors
mono.rs:771-816; Match-arm binding reuses synth's own type_check_pattern.

Recon (plan-recon) mapped the full deletion blast radius for mir.1b
(9 synth_arg_type sites, not the 3 the focus-hint assumed; 18
lower_workspace* callers). The two new witness fixtures
(new_rawbuf_size_only, new_counter_user_adt) were verified ail
check-clean during planning.
2026-05-31 13:51:33 +02:00
Brummel 8bc2972594 spec: typed-mir — place lower_to_mir post-mono, correct one-engine framing
plan-recon flagged that monomorphise_workspace runs between check and
codegen, and codegen lowers the post-mono workspace. The first draft of
this spec placed lower_to_mir as the final phase of check_workspace
(pre-mono) and claimed "nothing re-walks the AST". That is wrong on
both counts:

- Built pre-mono, MIR would not carry the monomorphic specialisations
  monomorphise_workspace appends — exactly the post-mono bodies codegen
  emits today — reintroducing the check↔codegen gap this milestone
  exists to close.
- synth is a pure `&Term → Type` function and the authoring AST carries
  no node-ids, so MIR cannot be a side-table read off a check pass; it
  is built inline by a walk. The honest property is therefore not "no
  second walk" but "no second *engine*": codegen's synth_with_extras is
  a hand-copied mirror of synth that drifts (every raw-buf bug is a
  drift point). The milestone replaces the mirror with a single
  post-mono call to canonical synth, materialised as MIR.

Corrections: architecture diagram and data flow now run
check → lift → monomorphise → lower_to_mir; lower_to_mir is wrapped by
a new front-end entry elaborate_workspace that subsumes the lift+mono
orchestration the CLI does today; check_workspace stays for the
diagnostics-only path (`ail check`). Node count fixed 27 → 17 Term
variants (ast.rs:436).

Re-dispatched grounding-check after the edit (post-PASS edit
invalidates the prior report) — PASS, all load-bearing post-mono
assumptions ratified against live code (main.rs build order,
mono.rs synth use, 17-variant Term, no node-ids).
2026-05-31 13:24:08 +02:00
Brummel 207c63649f spec: typed-mir check→codegen boundary contract
Open a new milestone introducing a typed mid-level IR (`ailang-mir`) as
the single artefact crossing the check → codegen boundary, so codegen
re-derives nothing.

Root cause (architect drift review): the boundary today carries no typed
artefact. `crates/ail/src/main.rs:2293` calls `check_workspace`, discards
the result, and hands `lower_workspace` the raw `Workspace`.
`CheckedModule` (ailang-check/src/lib.rs:1283) carries only top-level
(Type, hash). Codegen therefore re-runs four independent derivations of
what check already proved — type synthesis (`synth_with_extras`), callee
resolution (`type_home_module` ×3 + `is_static_callee`), uniqueness/mode
(`infer_module_with_cross`, second run), and Str representation (`!is_str`
recur gate). Every raw-buf bug (#43/#46/#47/#49/#51/#53, all "check-clean,
build-divergent") is a point where one of those re-derivations disagreed
with check and got patched one leg at a time.

Honest framing: this is removal of a re-derivation architecture, not a
RED→GREEN of crashing programs. #51 and #53 build today (patched by
ee4107c / 420703d) and are regression guards — they must keep building as
the codegen mirrors that hold them green are deleted. #49 is the one open
leg (builds, leaks live=3, test #[ignore]'d) and is the single RED→GREEN.

Five iterations, each adding one MIR annotation class and deleting the
matching codegen re-deriver: mir.1 structural MIR + `ty`; mir.2
`Callee::Static`; mir.3 `Mode`/`consume_count`; mir.4 `StrRep` (#49
live=0); mir.5 element-type residue + ledger (new boundary contract,
retract 0013:106-120, fix 0003-pipeline model, INDEX, close #51/#53,
reset milestone #7 to not-met).

Forward rewrite, not revert (the prior raw-buf milestone close was wrong;
the language infrastructure is healthy and survives — only the codegen
re-derivation is the disease). Approach B: a separate typed MIR carrier,
authoring AST unchanged.

Gates: parse-every-block clean (all three .ail witnesses `ail check`-clean,
exit 0); grounding-check PASS (13 load-bearing assumptions ratified against
green tests / verified code facts).
2026-05-31 12:45:52 +02:00
Brummel 02775b58ca test(codegen): mark the #49 Str-leg RED pin #[ignore] pending the representation spec
The Str-leg pin (committed 04f75c8) is RED on main: a heap-Str loop
binder replaced by `recur` leaks every superseded slab (live=3). Closing
it turned out NOT to be a mechanical fix. The "clone the static seed"
approach only covers the common accumulator shape (a fresh `str_concat`
result each iteration); it does not cover a `recur` arg or loop result
that is itself static, nor a phi-join of (static, heap) Str whose runtime
value may be static — and `ailang_rc_dec` on a static-Str pointer is UB
(no rc_header; rc.c has no runtime guard, per
design/contracts/0011-str-abi.md). A correct fix needs the deliberate
"every Str in loop-carried state is heap" representation decision that
commit f488d31 flagged as pending — routed through brainstorm.

This `#[ignore]` keeps `main`'s `cargo test --workspace` green while that
design cycle runs. The assertion body — the live=0 contract — is
unchanged; the GREEN implementation removes the `#[ignore]`. The ADT-leg
guard stays an active green test. Forward-fix only; main HEAD untouched.

refs #49
2026-05-31 11:21:52 +02:00
Brummel 04f75c8b71 test(codegen): RED-pin #49 Str leg — heap-Str loop binder must not leak across recur
A heap-Str accumulator threaded through a `(loop …)`/`recur` as a loop
binder leaks: each iteration's superseded `str_concat` slab is never
RC-dec'd, even when the loop's final result is consumed. The fixture
reports `allocs=4 frees=1 live=3` under AILANG_RC_STATS (stdout `xyyy`
is correct).

Root (data-flow traced): the `Term::Recur` arm in
crates/ailang-codegen/src/lib.rs (~2131) gates its superseded-value dec
behind `!is_str`. That exclusion exists because a `Str` loop seed may be
a static-literal Str — a constexpr GEP into a packed-struct global with
no rc_header (lib.rs:1612) — and `ailang_rc_dec` on a static pointer
reads garbage at `payload-8` and aborts on underflow (rc.c:221, no
runtime guard, per design/contracts/0011-str-abi.md). So the Str binder's
prior heap slab is overwritten by a plain `store` with no dec.

Distinct from the loop-RESULT scope-close drop (8bcdae1, which also
excluded Str) and from the ADT leg already fixed in f488d31 — this is
the per-iteration leak of the *intermediate* Str binder values, which
f488d31 explicitly left open pending a representation decision.

RED test crates/ail/tests/loop_recur_str_binder_no_leak_pin.rs with
fixture examples/loop_recur_str_binder_no_leak_pin.ail: the Str leg
asserts live=0 (RED at HEAD, live=3); the ADT leg (f488d31) is re-pinned
as a green guard so a regression on the shared Term::Recur dec path is
caught with it.

GREEN side (chosen direction): promote a static-literal Str seed to heap
via str_clone at loop entry so every Str binder slot holds a heap Str
with a valid rc_header, then lift the `!is_str` recur-dec exclusion. This
UPHOLDS the 0011-str-abi codegen-proof invariant (extends "static Str
never reaches dec" to the loop case) rather than adding a runtime guard.

refs #49
2026-05-31 04:09:44 +02:00
Brummel 420703d321 fix(codegen): resolve the dotted T.new user-ADT callee, symmetric to check
A monomorphic `(new Counter 42)` over a user-defined ADT that declares a
`new` fn passed `ail check` but crashed `ail build --alloc=rc` with
`unknown variable: Counter.new` (RED-pinned in 1eff055).

Root: the `Term::New` desugar lowers a no-type-arg monomorphic
`(new Counter 42)` to `(app Counter.new 42)` — a type-scoped `Var`
callee `Counter.new`. The checker resolves that dotted callee via its
TypeDef-first ladder (so check is clean), but codegen had no equivalent
resolution: the name was absent from the import map and the current
module's def list, so it fell through to `CodegenError::UnknownVar`. The
user `new` fn body IS codegen'd — only the dotted call-site failed to
resolve. The error surfaced first in the arg-type pre-pass
(`synth_with_extras`'s dotted-Var branch), which `lower_term`'s
`Term::Let` arm runs before lowering the call.

Fix (crates/ailang-codegen/src/lib.rs, all `// #53`):
- New `Emitter::type_home_module(type_name)`: returns the module
  declaring the named TypeDef (current module first, then any import
  target) by scanning `module_ctor_index` for a matching
  `CtorRef.type_name`. This mirrors the checker's TypeDef-first ladder.
- A dotted `T.def` fallback (resolve via the type's home module) added
  to the three sites that needed it: `resolve_top_level_fn` (the
  fn-pointer / lower_app resolution path), `is_static_callee` (its
  lockstep partner), and the `synth_with_extras` dotted-Var branch (the
  path that actually fired for this fixture).

Lockstep (CLAUDE.md `lower_app` ↔ `is_static_callee`): `is_static_callee`
now returns true for a dotted `T.def` whose `T` is a user ADT declared
in this or an imported module, exactly matching `resolve_top_level_fn`'s
new fallback — so no name is claimed static without being lowerable.

Distinct root from #51 (the polymorphic `(new T <elem> …)` type-arg
drop, ee4107c) — that fix deliberately left the monomorphic
app-lowering path unchanged; this completes it.

Verification: the #53 pin (crates/ail/tests/user_adt_new_mono_pin.rs)
is green; the original 3-module reproducer
examples/fieldtest/kem_2_counter_new.ail builds, runs, prints 42;
ailang-codegen/check/core suites, the intercepts bijection, and both
hash-pins are green; full workspace green.

closes #53
2026-05-31 03:52:23 +02:00
Brummel 1eff055a0e test(codegen): RED-pin #53 — monomorphic (new T args) over a user ADT must build
A monomorphic `(new Counter 42)` over a user-defined ADT that declares a
`new` fn passes `ail check` but crashes `ail build --alloc=rc` with
`unknown variable: Counter.new`. Distinct root from #51 (the polymorphic
type-arg drop, fixed by ee4107c) — the #51 fix deliberately left the
monomorphic app-lowering path unchanged.

Root (data-flow traced): the `Term::New` desugar
(crates/ailang-core/src/desugar.rs ~1091) lowers the no-type-arg
monomorphic `(new Counter 42)` to `Term::App { callee:
Var("Counter.new") }`. The checker's TypeDef-first ladder resolves that
dotted callee, so `ail check` is clean; codegen's call-lowering
(`lower_app` / `is_static_callee` in crates/ailang-codegen/src/lib.rs)
does not recognise the dotted `Counter.new` user-ADT constructor callee,
so the `Term::Var` arm falls through to `CodegenError::UnknownVar`
(lib.rs:1712). The documented `lower_app`↔`is_static_callee` lockstep
pair — a check↔codegen disagreement on whether `Counter.new` resolves.
The user `new` fn body IS codegen'd; only the dotted call-site is
unrecognised.

The RED test is minimal and autonomous: a single inline module (user
ADT + `new` fn + a `main` calling `(new Counter 42)`), minimised from
the 3-module 35-symbol kem_2_counter_new.ail reproducer — the
match/print scaffolding is dropped because the crash is at the
call-site lowering, independent of how the result is consumed. Asserts
check passes, build succeeds, the binary runs and prints `ok`. RED at
HEAD (fails at build with the exact symptom). GREEN side resolves the
dotted T.new user-ADT callee at codegen, symmetric to the checker.

refs #53
2026-05-31 03:33:03 +02:00
Brummel ee4107c721 fix(check): honour the written element type-arg on polymorphic (new T …)
A `(new RawBuf (con Int) 3)` whose buffer is never observed by a later
get/set passed `ail check` but crashed `ail build` with
`RawBuf_new__Unit has no registered intercept`, and a forbidden
`(new RawBuf (con Unit) 3)` was wrongly accepted at check. Both legs
share one root: the `Term::New` desugar discarded the author's written
`NewArg::Type` before anything could use it.

This was never an inference problem. The element type is EXPLICITLY
known — the author wrote `(con Int)`. The defect was that the desugar
threw that known type away and relied on re-discovering it from
downstream use; with no use (size-only), `RawBuf.new`'s result-only
forall var stayed unpinned, mono Unit-defaulted it, and codegen aborted
on the unregistered `RawBuf_new__Unit` intercept. The fix USES the
written type instead of inferring it.

Mechanism:
- desugar.rs: a polymorphic `(new T <elem> …)` (carrying a written
  `NewArg::Type`) now SURVIVES into check instead of being lowered to
  `(app T.new …)`. A monomorphic `(new Counter 42)` (no type-arg) keeps
  the raw-buf.4 app-lowering unchanged.
- lib.rs synth `Term::New` arm: (a) validates the written element type
  against the constructed type's `param_in` set via
  `check_type_well_formed`, firing `ParamNotInRestrictedSet` naming the
  forbidden element (leg 2) — synth is the correct site because it has
  Env/registry access, unlike `pre_desugar_validation`; (b) binds the
  result-only forall var DIRECTLY to the written type (`?a := Int`, a
  trivial binding, no inference channel) by pushing a `FreeFnCall` whose
  metas are the written concrete types, so mono mints
  `RawBuf_new__<elem>` and never `__Unit`.
- mono.rs: `rewrite_mono_calls` and `interleave_slots` gain matching
  `Term::New` arms that each consume exactly one free-fn slot at a
  type-arg-bearing `Term::New` (mirroring synth's single observation,
  pushed before the value-args), and `rewrite_mono_calls` reduces the
  node to `(app <mangled> <value-args>)` so codegen never sees
  `Term::New` and the lib.rs:2200 `unreachable!` stays valid. The two
  walkers stay in lockstep.

The Unit-default policy in mono stays correct for genuinely-unobservable
vars (`is_empty(Nil)` etc.); only the case with a written `NewArg::Type`
is changed.

Alternatives rejected: an additive `type_args` field on `Term::App`
(~100 construction sites across 7 crates — a detour that builds a new
transport slot only to copy the already-known type into it); a runtime
type-witness parameter on `RawBuf.new` (invents a runtime value for a
pure type property); an identity-lambda wrapper carrying the element in
its param-type (hides a semantic property in a runtime construct). The
written type belongs where the author put it, carried to the one point
that consumes it.

Verification: both RED legs (committed 61b9d3f) now green; full
check/codegen/core/surface suites green; intercepts bijection and
hash-pin tests green; existing raw-buf int/float/bool fixtures still
build and run leak-clean (live=0).

Out of scope (pre-existing at HEAD, separate issue): a monomorphic
`(new Counter 42)` over a user ADT fails with `unknown variable:
Counter.new` — unrelated to the type-arg drop fixed here.

closes #51
2026-05-31 03:03:14 +02:00
Brummel 61b9d3f513 test(raw-buf): RED-pin #51 — (new T <elem> …) must honour the element type-arg
Two failing E2E tests pinning the two legs of the #51 codegen crash,
both rooted in the `Term::New` desugar dropping `NewArg::Type`
(crates/ailang-core/src/desugar.rs:1053):

- Leg 1 (legitimate): `(new RawBuf (con Int) 3)` used only via
  `RawBuf.size` — never observed by get/set, so the dropped `(con Int)`
  is the sole element-type carrier. The unpinned forall var defaults to
  Unit in mono and `ail build --alloc=rc` aborts on the unregistered
  `RawBuf_new__Unit` intercept. Pins build+run printing `3`.

- Leg 2 (forbidden): `(new RawBuf (con Unit) 3)` — Unit is outside the
  param-in set {Int, Float, Bool}, but the dropped type-arg never reaches
  param-in enforcement, so `ail check` wrongly passes. Pins a
  `param-not-in-restricted-set` rejection naming Unit at check time.

Both RED at HEAD. GREEN side carries the explicit element type from
Term::New through to monomorphisation (must not mint __Unit) and adds the
leg-2 reject pre-desugar per the Term::New/desugar lockstep.

refs #51
2026-05-31 02:05:02 +02:00
Brummel 1b2d23ec42 fieldtest: raw-buf comprehensive — 4 examples, 8 findings (refs #7)
Comprehensive usability re-test of the RawBuf kernel extension in
natural LLM-author decompositions the prior field test (0058) did not
exercise: a Float RawBuf in a user ADT read through two borrow helpers,
a Bool flag buffer filled with a computed value, an Int fib buffer whose
fill reads its own writes plus two composed borrow summaries, and a
forbidden core-primitive element. All three working fixtures build, run
to expected values, and report live=0 across Float/Bool/Int widths —
the core RawBuf surface (borrow-helper composition, fill loops,
RawBuf-in-ADT, element widths) genuinely holds together.

Orchestrator triage corrected the fieldtester's run, which executed a
stale target/release/ail (built before the #50 fix). Every outcome was
re-verified against a fresh build:

- F2 (bare RawBuf ADT field unresolved) — RETRACTED: a stale-binary
  false positive. On a fresh build the bare name resolves in every
  configuration (ctor name == or != type name; builds/runs live=0). The
  #50 fix is correct and general.
- F7 (NEW, issue #51) — a `check`-clean program crashes `build`: a
  buffer whose element type is never observed by a later get/set
  defaults its element to Unit in monomorphisation and hits an
  unregistered `RawBuf_new__Unit` intercept. Affects a legitimate
  `RawBuf<Int>` used only for its size AND a forbidden locally-
  constructed element. Root: the `(new T ...)` desugar drops the
  explicit element annotation; honouring it reverses the milestone's
  § Term::New desugar decision, so it routes through brainstorm.
- F8 (process) — the field test ran stale; the fieldtester agent now
  builds from the current tree before running (plugin fix).

F1 (spec_gap) resolved here: the design ledger's §Series substrate ctor
wrote the storage field `(own (RawBuf a))`, which does not parse (`own`
is fn-param/ret only). Rewritten to the verified-authorable `(con RawBuf
a)`. The rest of the §Series listing is illustrative and its element-
less `(new RawBuf lookback)` construction is entangled with #51; a full
compile-verification of that listing belongs with the Series-substrate
work.

F5 (param-in rejects a forbidden core primitive, message names the set)
and F4/F3 (borrow composition; substrate composite) carry on. F6
(param-in set rendered as a Rust-debug list) filed as #52.

refs #7
2026-05-30 18:29:00 +02:00
Brummel f488d314e8 fix(codegen): dec superseded heap loop-binder values across recur (ADT leg)
A heap value threaded through a `(loop ...)`/`recur` as a loop binder
leaked: the `Term::Recur` arm stored each new arg into the binder's
loop-carried alloca with a plain `store` and never RC-dec'd the heap
value already in that slot, so every iteration's superseded value was
lost. The scope-close drop path (drop.rs, commit 8bcdae1) only ever
sees the loop's FINAL result, never the intermediates.

The recur store now decs the prior value before overwriting it, gated
by the SAME predicate the scope-close path uses — RC-heap AND lowers
to `ptr` AND not `Str`. The binder slot tuple is widened to carry the
binder's AILang type so the gate and the typed drop-symbol lookup
(`field_drop_call`) are available at the store. A same-pointer guard
(`icmp eq prior, new`) skips the dec when a `recur` threads the
identical pointer back — the own->own case (RawBuf fill loops, where
`RawBuf.set` mutates in place), so a retained buffer is never freed.

Scope: the boxed-ADT leg only. Every ADT value is heap-allocated, so
dec'ing a superseded ADT binder is unambiguously UB-free. A `Str`
accumulator is deliberately NOT covered: `Str` literals lower to
constexpr-GEPs into static globals (no rc_header), so a `Str` loop
seed may be static and dec'ing it would be UB. That is the same
static-vs-heap-`Str` obstacle behind 8bcdae1's deliberate `Str`
exclusion; the `Str` accumulator leak remains open in #49 pending a
runtime representation decision.

RED test in crates/ail/tests/loop_recur_heap_binder_no_leak_pin.rs
threads a boxed `Cell` through three recurs: pre-fix allocs=5 frees=2
live=3, post-fix live=0, stdout 2. Verified: zero-recur ADT control
live=0 (no spurious dec), Int loops (isqrt/collatz/gcd) live=0
(non-ptr, no dec), RawBuf fill loops live=0 out 35/16 (same-pointer
guard), Str accumulator unchanged (live=3, no crash).

refs #49
2026-05-30 17:48:51 +02:00
Brummel a92bcaf969 fix(check): qualify cross-module kernel type-cons in user ADT fields
A consumer module's ADT field could reference a kernel-tier
auto-imported type by its bare name in op/value positions
(`(new RawBuf ...)`, `RawBuf.get`) but NOT in the type-constructor
position of the field declaration: `(con RawBuf (con Int))` stayed
the unqualified `RawBuf<Int>` and failed to unify with the
constructor argument's `raw_buf.RawBuf<Int>`, so a RawBuf could not
be stored in a user ADT field without spelling the qualified
`raw_buf.RawBuf`.

`qualify_workspace_module` skipped `Def::Type` entirely, and the
`Term::Ctor` arm only qualified field types of cross-module *owning*
types — a *local* type carrying a cross-module field was the
uncovered case. The fix qualifies each ctor field type in the
`Def::Type` arm via the existing `qualify_workspace_types`, which
upgrades only genuinely cross-module type-cons (skips
`own_local_types` and primitives), so a purely-local field is never
spuriously rewritten. This is a check-side workspace transform, not
the on-disk canonical form, so no module hash drifts (both hash-pin
tests stay green).

RED test `rawbuf_in_user_adt_field_resolves_bare_name` in
crates/ailang-check/tests/workspace.rs, with the bare-name fixture
(now checks/builds/runs -> 42, live=0, the ADT drop cascade frees
the buffer slab) and the qualified control twin.

This is the Series-substrate shape (a RawBuf wrapped in a user ADT),
so the inconsistency would have bitten the pending series milestone.

closes #50
2026-05-30 17:48:34 +02:00
Brummel 43e3b21080 audit: raw-buf usability repair — cycle tidy (refs #7)
Close-out audit for the raw-buf usability repair (range 8e9f0f0..HEAD:
B1 #46, B2 #47, B3 #48, B5 loop-result drop, docs).

Architect drift review (against design/INDEX.md + the kernel-extensions
model): all three lockstep-invariant pairs undisturbed (INTERCEPTS ↔
intrinsic markers, lower_app ↔ is_static_callee, Pattern::Lit ↔
pre_desugar_validation — none touched; the edits sit in linearity,
synth_with_extras, and drop.rs). Every fix shipped a property-protecting
RED test. B3 brings the diagnostic into conformance with the model's
pre-existing §4 promise rather than opening a gap.

One drift item raised and fixed here: the B4 ratification paragraph in
design/models/0007 §RawBuf overstated the set non-enforcement as
unconditional. Verified: a double-consume of an own-param RawBuf inside a
fn with explicit modes fires [use-after-consume]; it slips through only
where the linearity activation gate skips the fn (paramless main, or
implicit-mode params). The paragraph now states the enforcement is gated,
names the gate, and gives both the caught and the uncaught case.

Regression (commands.regression, verbatim):
- bench/check.py        EXIT 0 — 34 metrics; 0 regressed, 34 stable
- bench/compile_check.py EXIT 0 — 24 metrics; 0 regressed, 24 stable
- bench/cross_lang.py   EXIT 0 — 25 metrics; 0 regressed, 25 stable
No baseline moved; carry-on.

Two forward-queue items filed during the repair, both out of scope here:
- #49 per-iteration leak of superseded heap loop-binder values across
  recur (a Str accumulator leaks; RawBuf does not — set is in-place).
- #50 bare RawBuf not auto-imported in type-constructor positions (a
  RawBuf in a user ADT field needs the qualified raw_buf.RawBuf); the
  RawBuf-in-ADT substrate itself works (builds, runs, drop cascades
  leak-clean) with the qualified name.

cycle raw-buf-usability tidy (clean).
2026-05-30 17:23:29 +02:00
Brummel d5cc6e96b6 docs(raw-buf): refresh fixture outcomes; ratify set non-enforcement (refs #7)
- rawbuf_1_score_table / rawbuf_2_running_max: the header OUTCOME blocks
  described the pre-fix breakage (does-not-check / unknown-variable).
  Those defects are fixed (B1 #46, B2 #47, B5); update the comments to
  the current state — both check, build, run to their expected values
  and are leak-clean under AILANG_RC_STATS. The files now serve as
  positive regression examples, not bug repros.

- design/models/0007 §RawBuf: ratify the fieldtest's B4 spec_gap. The
  `own -> own` signature of RawBuf.set is a threading discipline, not
  runtime-enforced single-use; a double-consume of the same owned buffer
  aliases one slab (consistent with every owned value in the language).
  State that single-use is the author's responsibility and full linear
  enforcement is Issue #22 territory.

Surfaced by the raw-buf fieldtest (docs/specs/0058).
2026-05-30 17:14:39 +02:00
Brummel 8bcdae1b53 fix(codegen): drop a let-bound owned loop result at scope close
An owned heap value whose `let`-binding value is a `(loop ...)` result,
afterwards only borrow-read (or unused), was never dropped at scope close
— a memory leak (AILANG_RC_STATS live=1). Newly observable once #47 made
fill-loops build: rawbuf_2_running_max leaked one buffer per run.

Root cause: is_rc_heap_allocated — the predicate the let-lowering uses to
decide a scope-close `dec` — matched only Term::Ctor, Term::Lam and
Own-returning Term::App. A Term::Loop-valued binder fell through to false,
so it was never registered for drop. (Sibling of the #47 synth gap: the
Term::Loop arm under-handled in yet another pass.)

Fix: add a Term::Loop arm that tracks the binder iff the loop's static
result type lowers to llvm `ptr` (boxed/heap) AND is not Str — and widen
drop_symbol_for_binder's App arm to cover Term::Loop so it resolves the
per-type drop symbol. Two load-bearing safety gates:
  - the `ptr` gate excludes unboxed primitives (Int/Bool/Float/Unit), so
    an Int-returning loop is not handed to a drop fn;
  - Str is excluded because a loop can return a *static* Str (a seed
    literal threaded unchanged) and ailang_rc_dec on a static-Str pointer
    is UB; an Own-App can never return a static Str, which is why the App
    arm may track Str but the Loop arm must not.
The loop's seed binders are consumed (moved in), so nothing else tracks
the result; linearity guarantees no alias, so the new drop is single.

Verified leak-clean and double-free-free across the fieldtest RawBuf set,
the consumed case, the Int-gate case, and the escape case (a fn returning
a loop-built owned RawBuf to its caller).

The separate per-iteration leak of superseded heap loop-binder values
(e.g. a Str accumulator threaded through recur) is a distinct, broader
pre-existing bug, filed separately — not addressed here.

RED-first: raw_buf_loop_no_leak_pin.
2026-05-30 17:14:28 +02:00
Brummel db710b1a73 fix(codegen): replay loop binders in synth_with_extras (closes #47)
A `let`-bound `loop` whose body references one of its own loop binders on
the non-recur exit passed `ail check` but failed `ail build` with
`unknown variable`. The fieldtest surfaced this with an owned RawBuf loop
binder, but the trigger is element-type-independent.

Root cause: the Term::Loop arm of synth_with_extras (the type-replay walk
the let-lowering runs via synth_arg_type on every let value) descended
into the loop body WITHOUT adding the loop binders to `extras`, unlike the
Term::Let arm which pushes its binder. A loop binder referenced on the
non-recur exit then resolved to UnknownVar during the type replay.

Fix: clone `extras`, push each loop binder's (name, ty), and thread the
augmented extras into the recursive synth of the body — mirroring the
Term::Let arm exactly. General fix; a plain Int let-bound loop that
references its binder also builds now.

This restores check<->codegen agreement for the natural fill-loop (thread
an owned buffer of runtime length through a loop/recur, one RawBuf.set per
iteration) — the way to populate a buffer whose length is not a fixed set
of literal indices.

Surfaced by the raw-buf fieldtest (finding B2, docs/specs/0058).
RED-first: loop_let_bound_binder_reference_builds.
2026-05-30 17:14:07 +02:00
Brummel 744ad41e47 fix(check): resolve type-scoped borrow-receiver ops in linearity (closes #46)
A function whose parameter is `borrow (RawBuf a)` and which calls
RawBuf.get or RawBuf.size on that parameter even once was rejected at
`ail check` with [consume-while-borrowed] — the exact borrow-receiver
use the ledger advertises for get/size. The diagnostic also misnamed the
cause: the receiver is read, not consumed.

Root cause: the linearity walk's callee_arg_modes looked up the callee
under its spelled name. A type-scoped polymorphic op is spelled
`RawBuf.get` at the call site, but check_module_with_visible registers
the kernel raw_buf ops under their bare def names (get/size). The lookup
missed, the receiver arg defaulted to Consume, and consuming a binder
whose borrow_count==1 (the Borrow param) fired the false positive. The
kernel signatures themselves are correct (receiver slot is `borrow`); the
only defect was the name-resolution gap in the linearity globals lookup.

Fix: on a direct-lookup miss, fall back to the bare method name via the
existing parse_method_qualifier + qualifier_is_class_shape resolvers,
gated on a class/type-shaped qualifier so lowercase cross-module-fn
qualifiers (std_list.length) are excluded. This is how the rest of the
checker already treats type-scoped polymorphic ops; the fix is general,
not RawBuf-specific.

This unblocks the natural borrow-helper decomposition (a shared
read-only buffer behind a helper fn) — the shape the downstream series
milestone's Series.at / Series.total_count need.

Surfaced by the raw-buf fieldtest (finding B1, docs/specs/0058).
RED-first: rawbuf_borrow_receiver_read_is_linearity_clean.
2026-05-30 17:13:56 +02:00
Brummel 75109f171d fix(check): param-not-in-restricted-set names the allowed set (closes #48)
The ParamNotInRestrictedSet diagnostic named the offending type, the
type-variable and the home type, but not the allowed set {Int, Float,
Bool} that design/models/0007 §4 promises it names. A downstream author
was told what is wrong but not what is right, and the kernel source that
carries the set is not available to a downstream consumer.

The allowed set already travels on the error struct (it flows into the
JSON `details.allowed`); only the human-readable `#[error]` render
dropped it. Append it to the Display string. JSON details unchanged.

Surfaced by the raw-buf fieldtest (finding B3, docs/specs/0058).
RED-first: param_in_reject_message_names_allowed_set pins the message
content before the one-line render fix.
2026-05-30 17:13:40 +02:00
Brummel 8e9f0f06a6 fieldtest: raw-buf — 4 examples, 6 findings (refs #7)
Downstream field test of the raw-buf surface as a consumer with only
the public interface (design ledger + `ail` CLI; no crate source).
Four fixtures under examples/fieldtest/, spec at
docs/specs/0058-fieldtest-raw-buf.md. Every recorded outcome
reproduced independently before commit.

Findings (3 bug, 1 spec_gap, 2 working):

- B1 [bug] `borrow (RawBuf a)` receiver is unusable. A fn taking
  `borrow (RawBuf Int)` that calls RawBuf.get/.size on the parameter
  even once is rejected `consume-while-borrowed` — the diagnostic
  names the wrong cause (the receiver is not consumed). The ledger
  advertises get/size as borrow-receiver ops, so the documented use
  is unreachable from any helper-function decomposition. This blocks
  Series (#8) — the milestone's own downstream raison d'être —
  whose at/total_count read through a `borrow (Series a)`.

- B2 [bug] An owned RawBuf threaded through a `loop` binder passes
  check but panics codegen `unknown variable: b` at build. A plain
  Int loop binder builds fine, so the fault is specific to an owned
  RawBuf loop binder. Breaks the check↔codegen agreement.

- B3 [bug] `param-not-in-restricted-set` omits the allowed set.
  design/models/0007 §4 promises the diagnostic "names the offending
  type and the allowed set"; the shipped message names the type, the
  type-var, and the home type but not `{Int, Float, Bool}`. A
  downstream author is told what is wrong but not what is right.

- B4 [spec_gap] RawBuf.set receiver double-consume is not enforced;
  two set calls on the same owned buffer silently alias the slab.
  Not raw-buf-specific (owned Str/ADT behave identically) — a
  pre-existing linearity-non-enforcement property. Recorded because
  RawBuf's own→own mutation is the first place a silent alias yields
  a mutated-in-place surprise. Ratify in the ledger or open a backlog
  item for full linear enforcement.

- W1 [working] `(new …)` sugar + inference-from-use across
  Int/Float/Bool builds and runs first try (sensor_pair prints 5.0);
  the Bool i1/i8 packing edge round-trips. The milestone's cleanest win.

- W2 [working] param-in reject fires for both Str and a user TypeDef.

Net: B1+B2 mean the only RawBuf programs that build today are
straight-line owned let-threading with literal indices — the
shipped-fixture shape. Helper decomposition (B1) and runtime-length
loop fill (B2) both fail. fieldtest does not self-resolve; routing
is the orchestrator's call.
2026-05-30 16:26:48 +02:00
Brummel f37bd959d4 audit: raw-buf milestone close — tidy (clean) (refs #7)
Cycle-close drift review for the raw-buf milestone (raw-buf.1-.6 +
the #42/#43 drop-leak bug-fixes), range a163c8c..HEAD. raw-buf.6
(13e590c) retired kernel_stub; raw_buf is now the sole kernel-tier
base extension, ailang-kernel its family-crate home.

Architect (range a163c8c..HEAD, focus raw-buf.6 removal): clean, no
drift.
- Lockstep pair 3 (INTERCEPTS <-> (intrinsic) markers) intact:
  answer + StubT_peek__{Int,Float} entries left with the deleted
  kernel_stub source; the 12 surviving RawBuf entries (4 ops x
  {Int,Float,Bool}) bijection cleanly with the 12 markers
  parse_raw_buf() generates; intercepts_bijection_with_intrinsic_markers
  green. No orphan entry, no orphan marker.
- Design ledger present-state: INDEX.md + models/0007 name raw_buf
  as the sole live ratifier, raw-buf shipped, series pending. No
  stale "ratified by the stub", no aspirational retirement framing.
- Dangling-reference sweep clean: only residual is the intentional
  self-contained inline serde_json check-layer fixtures in
  ailang-check/src/lib.rs. Kernel crate is lib.rs + raw_buf/ only;
  count pins re-baselined 5->4.
- Lockstep pairs 1 (Pattern::Lit <-> pre_desugar_validation) and 2
  (lower_app <-> is_static_callee) saw no raw-buf-range arms needing
  a mirror. All five architect sweeps exit 0.

Regression (all green, no baseline move):
- compile_check.py: exit 0, 24/24 stable (uniform downward check_ms
  within tol -- stub no longer parsed per compile; within the 20%
  band, no re-ratify warranted).
- check.py: exit 0, 34/34 stable.
- cross_lang.py: exit 0, 25/25 stable.

Resolution: carry-on. No fix iteration, no baseline ratify. Hygiene:
removed untracked git-ignored *.ll.actual scratch files carrying
pre-removal stub IR (never shipped).
2026-05-30 16:10:42 +02:00
Brummel 13e590cb46 iter raw-buf.6 kernel-stub-retirement (DONE 5/5): retire the stub, raw_buf is the sole base extension (refs #7)
Closes the raw-buf milestone. raw_buf (shipped raw-buf.1-.5; the
owned-drop resolution landed under bug #42/#43) has subsumed every
ratification role kernel_stub held -- Term::New end-to-end, the
param-in reject, kernel-tier auto-import, the monomorphic intrinsic
path, and the type-scoped polymorphic intrinsic mechanism (RawBuf's
four ops). The stub is now redundant; this iteration removes it.

Pure removal (-636/+49 across 22 files, 7 deleted):
- Rust surface: drop `mod kernel_stub` + `STUB_AIL` re-export
  (ailang-kernel), `parse_kernel_stub` + its workspace injection
  (ailang-surface), the `answer` + two `StubT_peek__{Int,Float}`
  INTERCEPTS entries + their three emit fns (ailang-codegen). The
  (intrinsic) markers leave with the deleted source, so the
  marker<->entry bijection holds in lockstep.
- Source + tests: delete crates/ailang-kernel/src/kernel_stub/,
  kernel_stub_module_round_trips, the two stub-consumer e2e tests,
  and mono_scoped_symbol.rs (its scope-qualified-mono mechanism is
  now pinned by RawBuf's ops + the intercepts bijection).
- Fixtures: delete kernel_answer.ail, new_stubt_smoke.ail,
  peek_mono_pin_smoke.ail, and fieldtest kem_3_stub_consumer.ail
  (referenced the deleted StubT; documented a since-fixed bug).
- Pins: re-baseline both workspace-count content-pins 5 -> 4
  (workspace_pin.rs + the e2e.rs twin) and regenerate all five IR
  snapshots (400 stub-IR lines removed; no user IR changed -- the
  stub auto-injected into every build).
- Ledger: design/INDEX.md + design/models/0007 to present-state
  (raw_buf is the live ratifier; raw-buf milestone shipped, series
  pending), plus architecture-comment sweep across workspace.rs,
  mono.rs, check/codegen lib.rs, workspace_kernel.rs.

Scope decisions (orchestrator, pre-plan): the self-contained inline
serde_json check-layer fixtures in ailang-check/src/lib.rs keep their
incidental StubT/kernel_stub sample names (they construct what they
reference; not stub-ratification) -- the one permitted residual.
kem_4 fieldtest kept (uses a user NumBox ADT, comment-only edit).
hash.rs `name: "answer"` left (generic serde doc example).

Plan-gap caught at implement: the planner's verbatim edit list
under-enumerated four honesty sites; one (mono.rs:562) carried a
literal `StubT_peek__Int` -- a hard-gate symbol the verbatim list
missed, which would have failed Task 4's removal gate. Filled
(comment-only, no behaviour). Confirms the planner self-review
filter-completeness risk; the implement gate caught it.

Verification: full workspace suite green (0 failed); hard symbol gate
(STUB_AIL|parse_kernel_stub|emit_answer|emit_stubt_peek|StubT_peek__)
zero matches across crates/ examples/ design/; soft gate residual only
the kept inline fixtures; kernel crate is lib.rs + raw_buf/ only.
Regression: compile_check 24/24 stable (exit 0; uniform downward
check_ms within tol -- stub no longer parsed per compile), cross_lang
25/25, check 34/34 stable (exit 0; an earlier exit-1 on
rc_over_bump was machine-load ratio noise -- denominator bump_s got
faster, rc_s also improved -- confirmed green on re-run, not
baselined).
2026-05-30 16:07:29 +02:00