26fb3459d8
The runtime print path now writes exactly the bytes of its
argument with no implicit trailing newline. `io/print_str` is
byte-faithful; authors who want a newline emit `(do io/print_str
"\n")` themselves.
## Codegen
`crates/ailang-codegen/src/lib.rs`:
- Module preamble: `@puts(ptr)` → `@fputs(ptr, ptr)` plus
`@stdout = external global ptr` (libc's `FILE *stdout`).
- Effect-op lowering for `io/print_str`: emit
`getelementptr +8` then `load ptr, ptr @stdout` then
`call/tail call i32 @fputs(ptr bytes, ptr fp)`. Identical
bytes-pointer GEP, distinct sink.
- The pinned IR-shape test renames from
`print_str_calls_puts_with_bytes_pointer` to
`print_str_calls_fputs_with_bytes_pointer_and_stdout` and now
asserts: bytes-GEP present, stdout-load present, both module-
preamble declarations present, and no `@puts(` call anywhere
in the emitted IR.
## Why this shape, and not the alternatives
- *Rename `io/print_str` to `io/println_str` (issue #29 option 2)*
— kept the auto-newline, just relabelled it. AILang's design
bias is explicit-over-implicit (CLAUDE.md: implicit conversions
cut). Auto-newline is a hidden runtime augmentation; the rename
would have preserved it. Rejected.
- *Append `\n` inside the polymorphic `print` (Show-mediated)
function in `examples/prelude.ail`* — would have been a one-line
fix. Rejected: `print` is the Show-mediated formatter, not a
newline emitter; baking a newline into it would have re-imposed
the same implicit-augmentation problem one layer up, breaking
callers that legitimately want pure-bytes output.
## Fixture / test sweep
30 `.ail` fixtures whose owning tests asserted line-separated
stdout now emit explicit `(do io/print_str "\n")` after each
print. Tests that asserted on multi-line stdout (`show_print_e2e`,
`floats_e2e`, `str_concat_e2e`, `eq_ord_e2e`, several `print_*`
smoke tests) had their fixtures sweetened the same way; assertions
themselves remain the canonical observable output. Fixtures that
never relied on the newline (no test ever read the absence of one)
were left untouched.
## Migrated metadata
- `crates/ailang-core/tests/hash_pin.rs`: the `ordering_match::main`
canonical hash is refreshed (`b65a7f834703ffb4` →
`8ed47b4062ce00f5`). The comment now names both successive
corpus migrations honestly: the per-type-print-retirement (which
moved `(do io/print_int x)` to `(app print x)`) AND this
fputs swap (which wrapped that with `(seq ... (do io/print_str
"\n"))`).
- `design/contracts/str-abi.md`: the consumer-ABI table now lists
`@fputs` as the print sink. A prose paragraph documents the
byte-faithful semantics and references this issue.
- `examples/ordering_match.prose.txt`: regenerated from the
updated `ordering_match.ail`.
- `crates/ail/tests/snapshots/{hello,sum,max3,list,ws_main}.ll`:
IR snapshots regenerated via `UPDATE_SNAPSHOTS=1`.
- Stale `@puts` comments in `runtime/str.c`,
`crates/ail/tests/{e2e,show_print_e2e,print_no_leak_pin}.rs`
replaced with `@fputs`.
## Verification
- `cargo test -p ail --test print_str_no_auto_newline_e2e` — both
RED tests from commit c8ecfa3 now pass.
- `cargo test --workspace` — 90 test groups GREEN, 0 failures.
- `cargo build --workspace` — GREEN.
- No new clippy lints (24 warnings pre-existing in
`crates/ailang-core/src/lib.rs:129`).
- Stats: `bench/orchestrator-stats/2026-05-21-iter-bugfix-print-
str-fputs.json` — 1/1 tasks, 0 re-loops, 0 review loops.
## Empirical evidence cited
Caught in the 2026-05-21 Qwen3-Coder naming-A/B run
(`experiments/2026-05-21-naming-ab/runs/r1/`): every cohort wrote
`(do io/print_str "...\n")` with explicit `\n` and got doubled
newlines, failing the `t3_main_prints` stdout match across all
three cohorts. The empirical LLM-natural form already assumes the
new (post-this-commit) semantics — confirming the
feature-acceptance test in CLAUDE.md.
closes #29
120 lines
4.8 KiB
Rust
120 lines
4.8 KiB
Rust
//! RED-pin for the 2026-05-14 Cat-A heap-Str leak in `print`
|
|
//! (uncovered during the per-type-print-op retirement).
|
|
//!
|
|
//! Property protected: under `--alloc=rc`, evaluating the trivial
|
|
//! program `(body (app print 42))` does NOT leak the heap-Str
|
|
//! allocated inside `print`'s body. `print`'s body is the explicit-
|
|
//! let `let s = show x in do io/print_str s` (see iter 24.3, pinned
|
|
//! structurally by `print_mono_body_shape.rs`); `show` at primitive
|
|
//! type calls `int_to_str` which returns a fresh heap-Str (slab in
|
|
//! `runtime/str.c`). `io/print_str` borrows the Str. At let-scope-
|
|
//! close, the binder `s` is the only owner — codegen must emit
|
|
//! `ailang_rc_dec(s)`. The runtime stats line at exit must report
|
|
//! `live == 0` (equivalently `allocs == frees`).
|
|
//!
|
|
//! As of commit 301cbc3 this test fails: stderr reports
|
|
//! `ailang_rc_stats: allocs=1 frees=0 live=1`. The IR for the post-
|
|
//! mono `ail_prelude_print__Int` body contains a `call ptr
|
|
//! @ail_prelude_show__Int(...)` followed by `getelementptr +8` +
|
|
//! `@fputs` + `ret i8 0` — there is no `ailang_rc_dec` on the
|
|
//! show-result before return. Root cause sits at codegen's
|
|
//! `is_rc_heap_allocated` App-arm: it reads the callee's
|
|
//! `Type::Fn.ret_mode` via `synth_callee_ret_mode` and requires
|
|
//! `Own`. The mono'ed `show__Int` inherits its `Type::Fn` from the
|
|
//! `Show` class method declaration in `examples/prelude.ail.json`,
|
|
//! whose `methods[0].type` omits the `ret_mode` key — `serde` defaults
|
|
//! the missing field to `ParamMode::Implicit`. So
|
|
//! `synth_callee_ret_mode(show__Int) == Implicit`, the let-binder is
|
|
//! not flagged trackable, and `drop_symbol_for_binder` is never
|
|
//! called for it.
|
|
//!
|
|
//! Once the underlying issue is fixed (the canonical move is to
|
|
//! recognise that any class-method whose declared `ret` is `Str` /
|
|
//! any pointer-typed user type should round-trip as Own through
|
|
//! mono, OR to install the Show class declaration with explicit
|
|
//! `ret_mode: "own"`, OR to widen `is_rc_heap_allocated`'s App-arm
|
|
//! to also consult the callee's ret type-via-Str-carve-out), this
|
|
//! test must flip GREEN without weakening the assertion.
|
|
|
|
use std::path::Path;
|
|
use std::process::Command;
|
|
|
|
fn ail_bin() -> &'static str {
|
|
env!("CARGO_BIN_EXE_ail")
|
|
}
|
|
|
|
#[test]
|
|
fn alloc_rc_print_int_does_not_leak_show_result_str() {
|
|
let manifest_dir = env!("CARGO_MANIFEST_DIR");
|
|
let workspace = Path::new(manifest_dir).parent().unwrap().parent().unwrap();
|
|
let src = workspace
|
|
.join("examples")
|
|
.join("print_int_no_leak_pin.ail");
|
|
let tmp = std::env::temp_dir().join(format!(
|
|
"ailang_print_no_leak_pin_{}",
|
|
std::process::id()
|
|
));
|
|
std::fs::create_dir_all(&tmp).unwrap();
|
|
let out = tmp.join("bin");
|
|
let status = Command::new(ail_bin())
|
|
.args([
|
|
"build",
|
|
src.to_str().unwrap(),
|
|
"--alloc=rc",
|
|
"-o",
|
|
])
|
|
.arg(&out)
|
|
.status()
|
|
.expect("ail build failed to run");
|
|
assert!(
|
|
status.success(),
|
|
"ail build --alloc=rc failed for print_int_no_leak_pin.ail"
|
|
);
|
|
let output = Command::new(&out)
|
|
.env("AILANG_RC_STATS", "1")
|
|
.output()
|
|
.expect("execute binary");
|
|
assert!(
|
|
output.status.success(),
|
|
"binary exited non-zero: status {:?}",
|
|
output.status
|
|
);
|
|
let stderr = String::from_utf8(output.stderr).expect("stderr utf8");
|
|
let stats_line = stderr
|
|
.lines()
|
|
.find(|l| l.starts_with("ailang_rc_stats:"))
|
|
.unwrap_or_else(|| {
|
|
panic!(
|
|
"missing ailang_rc_stats line in stderr; stderr was:\n{stderr}"
|
|
)
|
|
});
|
|
let mut allocs: Option<u64> = None;
|
|
let mut frees: Option<u64> = None;
|
|
let mut live: Option<i64> = None;
|
|
for tok in stats_line.split_whitespace() {
|
|
if let Some(v) = tok.strip_prefix("allocs=") {
|
|
allocs = v.parse().ok();
|
|
} else if let Some(v) = tok.strip_prefix("frees=") {
|
|
frees = v.parse().ok();
|
|
} else if let Some(v) = tok.strip_prefix("live=") {
|
|
live = v.parse().ok();
|
|
}
|
|
}
|
|
let allocs = allocs.expect("missing allocs= field");
|
|
let frees = frees.expect("missing frees= field");
|
|
let live = live.expect("missing live= field");
|
|
assert_eq!(
|
|
live, 0,
|
|
"`(app print 42)` under --alloc=rc leaks {live} heap-Str cell(s) \
|
|
(allocs={allocs} frees={frees}); print's let-binder for the \
|
|
show-result must drop at let-scope-close. Show class method \
|
|
`show` in prelude.ail.json omits `ret_mode`, so mono-synthesised \
|
|
`show__Int` inherits ret_mode=Implicit and `is_rc_heap_allocated` \
|
|
declines to track the let-binder."
|
|
);
|
|
assert_eq!(
|
|
allocs, frees,
|
|
"alloc/free mismatch (allocs={allocs} frees={frees} live={live})"
|
|
);
|
|
}
|