//! Round-trip gate for the form-(A) projection. //! //! Two complementary checks over `examples/*.ail`, each gathering //! fixtures dynamically via `read_dir` (no hardcoded lists). The //! tests are pure readers — they do not write into the working //! tree. //! //! 1. `parse_is_deterministic_over_every_ail_fixture`: for every //! well-formed `.ail` text `t`, `parse(t)` produces the same //! canonical bytes every invocation. The parser is a pure //! function of input — no randomness, no time dependence, no //! environment leak. Hashing `canonical::to_bytes(parse(t))` is //! therefore well-defined for any `.ail` source. //! //! 2. `parse_then_print_then_parse_is_idempotent_on_every_ail_fixture`: //! Direction 2 of the Roundtrip Invariant (DESIGN.md §"Roundtrip //! Invariant"). For every well-formed `.ail` text `t`, asserts //! `canonical_bytes(parse(t))` equals //! `canonical_bytes(parse(print(parse(t))))`. The printer is a //! left-inverse of the parser modulo canonical form. //! //! Retired iter form-a.1 T9: `print_then_parse_round_trips_every_fixture` //! (corpus shrunk to 8 carve-outs post-iter) and //! `every_ail_fixture_matches_its_json_counterpart` (no longer //! expressible: only one form is hand-authored post-iter). use std::path::PathBuf; fn examples_dir() -> PathBuf { // `CARGO_MANIFEST_DIR` is the surface crate root; examples live two // levels up. let crate_dir = PathBuf::from(env!("CARGO_MANIFEST_DIR")); crate_dir.parent().unwrap().parent().unwrap().join("examples") } // Retired iter form-a.1 T9: // - `list_json_fixtures` helper (walked `.ail.json` for the two retired tests below). // - `print_then_parse_round_trips_every_fixture`: corpus shrunk to 8 carve-outs // post-iter; property subsumed by `parse_is_deterministic_over_every_ail_fixture` // plus the surviving `parse_then_print_then_parse_is_idempotent_on_every_ail_fixture`. // - `round_trip_one` helper (only consumer was the retired test above). // - `every_ail_fixture_matches_its_json_counterpart`: no longer expressible — // only one form is hand-authored post-iter; counterparts are derived in-process // via `ail parse`. fn list_ail_fixtures() -> Vec { let dir = examples_dir(); let mut paths: Vec = std::fs::read_dir(&dir) .unwrap_or_else(|e| panic!("read_dir({}): {e}", dir.display())) .filter_map(|entry| entry.ok()) .map(|e| e.path()) .filter(|p| { p.file_name() .and_then(|n| n.to_str()) .map(|n| n.ends_with(".ail")) .unwrap_or(false) }) .collect(); paths.sort(); paths } /// Direction 2 of the Roundtrip Invariant (DESIGN.md §"Roundtrip /// Invariant"): for every well-formed `.ail` text `t`, the /// composition `parse → print → parse` is idempotent on the AST. /// /// For the 57 `.ail` fixtures that have a JSON counterpart this /// follows logically from `print_then_parse_round_trips_every_fixture` /// + `every_ail_fixture_matches_its_json_counterpart`. This test /// asserts the property directly so it stays robust for future /// `.ail` fixtures without a JSON counterpart, and so the spec's /// Direction-2 claim has a dedicated enforcement point. #[test] fn parse_then_print_then_parse_is_idempotent_on_every_ail_fixture() { let fixtures = list_ail_fixtures(); assert!( !fixtures.is_empty(), "no .ail fixtures found under {}", examples_dir().display() ); let mut failures = Vec::::new(); let mut passed = 0usize; for path in &fixtures { let text = match std::fs::read_to_string(path) { Ok(t) => t, Err(e) => { failures.push(format!("{}: read failed: {e}", path.display())); continue; } }; let parsed_once = match ailang_surface::parse(&text) { Ok(m) => m, Err(e) => { failures.push(format!("{}: parse(t) failed: {e}", path.display())); continue; } }; let printed = ailang_surface::print(&parsed_once); let parsed_twice = match ailang_surface::parse(&printed) { Ok(m) => m, Err(e) => { failures.push(format!( "{}: parse(print(parse(t))) failed: {e}\n--- printed ---\n{printed}", path.display() )); continue; } }; let bytes_a = ailang_core::canonical::to_bytes(&parsed_once); let bytes_b = ailang_core::canonical::to_bytes(&parsed_twice); if bytes_a != bytes_b { let s_a = String::from_utf8_lossy(&bytes_a).into_owned(); let s_b = String::from_utf8_lossy(&bytes_b).into_owned(); failures.push(format!( "{}: parse → print → parse is NOT idempotent.\nparse(t): {s_a}\nparse(print(parse(t))): {s_b}", path.display() )); continue; } passed += 1; } if !failures.is_empty() { panic!( "{} of {} .ail fixture(s) failed idempotency check (passed: {}):\n{}", failures.len(), fixtures.len(), passed, failures.join("\n\n") ); } eprintln!("parse→print→parse idempotency ok for {passed} .ail fixtures"); } /// Parse-determinism (post-form-a-default-authoring §C3): for every /// well-formed `.ail` text `t`, `parse(t)` produces the same canonical /// bytes every invocation. Loader is a pure function of input — no /// randomness, no time dependence, no environment leak. #[test] fn parse_is_deterministic_over_every_ail_fixture() { let mut checked = 0usize; for ail_path in list_ail_fixtures() { let text = std::fs::read_to_string(&ail_path) .unwrap_or_else(|e| panic!("read {ail_path:?}: {e}")); let m1 = ailang_surface::parse(&text) .unwrap_or_else(|e| panic!("parse {ail_path:?}: {e:?}")); let m2 = ailang_surface::parse(&text) .unwrap_or_else(|e| panic!("parse {ail_path:?} (2nd): {e:?}")); let b1 = ailang_core::canonical::to_bytes(&m1); let b2 = ailang_core::canonical::to_bytes(&m2); assert_eq!( b1, b2, "parse non-determinism on {ail_path:?}", ); checked += 1; } assert!(checked > 0, "no .ail fixtures found"); }