Files
AILang/examples/prelude.ail
T
Brummel 76b21c00eb feat(lang): eliminate the Implicit ownership default — totality + the drop-soundness it demasks (#55)
Deletes `ParamMode::Implicit`. `ParamMode` is now `{Own, Borrow}`:
every fn-type slot on every signature carries an explicit `own` or
`borrow`, no defaulted position survives anywhere (model 0008 §2,
spec 0062). The parser rejects a bare fn-type slot; `borrow-return`
and `borrow-over-value` reject at the signature; the corpus is
migrated to minimal-ownership modes (consumed ⇒ own, read-only-heap
⇒ borrow, value ⇒ trivial-own). The documented `Implicit`-ret-mode
leak is fixed: an owned heap return now drops exactly once (live=0,
acceptance criterion 5).

This was the easy half. Removing the default ACTIVATED a family of
drop paths that `Implicit` had silently skipped — the pre-cutover
language was leaking (and in places mis-dropping) here rather than
crashing, because an Implicit scrutinee turned the drop off. Making
the modes explicit (Own) turned those paths on and exposed two
latent-bug clusters, all fixed RED-first as part of this cutover:

Drop-soundness family (four legs):
  A. lit-sub-pattern double-free — the desugar re-matched the same
     owned scrutinee in the lit fall-through; fixed by grouping
     consecutive same-ctor arms into one match (bind fields once),
     in ailang-core desugar.
  B. Cons-husk leak on non-tail arm bodies — the lit-sub-pattern
     desugar rebound the owned scrutinee via `Let $mp = xs`, which
     bumped consume_count and suppressed the existing fn-return
     partial_drop. Fixed by not rebinding a bare-Var scrutinee
     (one husk-freeing mechanism, not two).
  C. polymorphic `drop_<T>` rc_dec'd monomorphised value fields —
     the per-ADT drop fn was emitted once from the polymorphic
     TypeDef, defaulting type-var fields to ptr and rc_dec'ing
     inline Ints (segfault). Fixed with per-monomorph drop
     functions (new ailang-codegen::dropmono): the drop set is
     collected from the lowered MIR, value-type fields are skipped,
     heap fields still freed once; monomorphic-concrete ADTs keep
     their byte-identical un-suffixed drop symbol.
  D. static Str literal passed to an `(own Str)` param — the
     literal lowers to a header-less rodata constant; the callee's
     now-active rc_dec read its length field as a refcount and
     freed a static address (segfault). Fixed with the missing
     fourth StrRep::Static→Heap promotion in lower_to_mir's App arm,
     gated on Own mode (borrow args stay static, no regression).

over-strict-mode lint over-fired: it suggested `(borrow V)` for
value-typed params (which `borrow-over-value` rejects — own is the
only legal mode there) and fired on `(intrinsic)` bodies (whose
consumption the linearity walk cannot observe). Tightened to skip
both; contract 0008 updated to the narrowed firing scope.

Irreversible step — canonical-form hash reset (model 0008 §6,
acceptance criterion 6). Every signature now carries explicit modes,
so the hashable canonical JSON changed for every module. RATIFY:
the corpus-wide hash-pin reset (hash_pin, prelude_module_hash_pin,
mono_hash_stability, eq_ord_e2e, embed_export_hash_stable, the
ct4/iter*/loop_recur schema-extension pins) and the list ir_snapshot
golden were regenerated once, deliberately, as the intended one-time
consequence of removing the mode elision from the canonical form —
not a regression. Each regenerated hash verified deterministic across
two runs.

Also fixes a pre-existing latent failure surfaced by the verification
gate, unrelated to this cutover: the `every_contract_names_a_resolvable_
ratifying_test` resolver (design_index_pin) could not resolve the
" + " dual-link ratifying-test form (`uniqueness.rs + linearity.rs`)
that the #57 audit-close (dfdc65f) introduced — it shipped red on that
commit. Resolver taught the dual-link form, mirroring its sibling.

Verification: cargo test --workspace = 731 passed, 0 failed (twice,
stable); e2e 102 passed, no binary exits non-zero (corpus crash-free);
grep-clean for Implicit/fn_implicit/mode_eq across crates; every drop
fix confirmed via emitted IR + AILANG_RC_STATS balance on the head==K,
head!=K, and Nil paths. Three BLOCKEDs en route (the unsound first
husk-dec attempt, the over-strict derivation premise, the leg-B fix
direction) were each treated as a real design/spec gap and rediagnosed,
not patched over.

Supersedes #54 (return-position-only leak patch). Precondition #57
(linearity hardening) was already met. Spec docs/specs/0062, plan
docs/plans/0121.

closes #55
2026-06-02 00:03:46 +02:00

154 lines
8.2 KiB
Plaintext

(module prelude
(kernel)
(data Ordering
(doc "Result of a three-way comparison: LT (less than), EQ (equal), GT (greater than). Ships in milestone 23 as the codomain of Ord.compare.")
(ctor LT)
(ctor EQ)
(ctor GT))
(class Eq
(param a)
(doc "Structural equality. The class-method `eq` is the surface-level comparator; `==` as a surface name is not part of the language. Primitive instances Eq Int / Bool / Str / Unit are lowered via try_emit_primitive_instance_body in the codegen.")
(method eq
(type (fn-type (params (borrow a) (borrow a)) (ret (own (con Bool)))))))
(instance
(class Eq)
(type (con Int))
(doc "Eq Int. Compiler-supplied (intrinsic) body; codegen emits `icmp eq i64` with the alwaysinline attribute via the intercept registry.")
(method eq
(body (lam (params (typed x a) (typed y a)) (ret (con Bool)) (intrinsic)))))
(instance
(class Eq)
(type (con Bool))
(doc "Eq Bool. Compiler-supplied (intrinsic) body; codegen emits `icmp eq i1` with the alwaysinline attribute via the intercept registry.")
(method eq
(body (lam (params (typed x a) (typed y a)) (ret (con Bool)) (intrinsic)))))
(instance
(class Eq)
(type (con Str))
(doc "Eq Str. Compiler-supplied (intrinsic) body; codegen emits a call to `@ail_str_eq` with the alwaysinline attribute via the intercept registry.")
(method eq
(body (lam (params (typed x a) (typed y a)) (ret (con Bool)) (intrinsic)))))
(instance
(class Eq)
(type (con Unit))
(doc "Eq Unit. Unit is single-inhabitant so all values compare equal. Compiler-supplied (intrinsic) body; codegen emits `ret i1 1` via the intercept registry.")
(method eq
(body (lam (params (typed x a) (typed y a)) (ret (con Bool)) (intrinsic)))))
(class Ord
(param a)
(superclass (class Eq) (type a))
(doc "Total ordering. Ships in milestone 23 alongside Eq. `compare x y` returns LT, EQ, or GT (the three-ctor Ordering ADT also in the prelude). Decision 11's single-superclass closure requires `instance Eq T` for every `instance Ord T` — the three Ord instances below pair with the three Eq instances shipped in iter 23.2.3.")
(method compare
(type (fn-type (params (borrow a) (borrow a)) (ret (own (con Ordering)))))))
(instance
(class Ord)
(type (con Int))
(doc "Ord Int. Compiler-supplied (intrinsic) body; codegen emits a three-way `icmp slt` / `icmp eq` branch ladder constructing LT / EQ / GT via the intercept registry.")
(method compare
(body (lam (params (typed x a) (typed y a)) (ret (con Ordering)) (intrinsic)))))
(instance
(class Ord)
(type (con Bool))
(doc "Ord Bool. Compiler-supplied (intrinsic) body; codegen emits `icmp ult i1` LT-test, `icmp eq i1` EQ-test, GT default, via the intercept registry.")
(method compare
(body (lam (params (typed x a) (typed y a)) (ret (con Ordering)) (intrinsic)))))
(instance
(class Ord)
(type (con Str))
(doc "Ord Str. Compiler-supplied (intrinsic) body; codegen emits `call i32 @ail_str_compare(ptr, ptr)` then branches on slt-0 / eq-0 against the normalised {-1, 0, +1} return, via the intercept registry.")
(method compare
(body (lam (params (typed x a) (typed y a)) (ret (con Ordering)) (intrinsic)))))
(class Show
(param a)
(doc "Producer of a human-readable Str representation. Ships in milestone 24 with primitive instances for Int/Bool/Str/Float; user types declare their own instance.")
(method show
(type (fn-type (params (borrow a)) (ret (own (con Str)))))))
(instance
(class Show)
(type (con Int))
(method show
(body (lam (params (typed x (con Int))) (ret (con Str)) (body (app int_to_str x))))))
(instance
(class Show)
(type (con Bool))
(method show
(body (lam (params (typed x (con Bool))) (ret (con Str)) (body (app bool_to_str x))))))
(instance
(class Show)
(type (con Str))
(method show
(body (lam (params (typed x (con Str))) (ret (con Str)) (body (app str_clone x))))))
(instance
(class Show)
(type (con Float))
(method show
(body (lam (params (typed x (con Float))) (ret (con Str)) (body (app float_to_str x))))))
(fn ne
(doc "Polymorphic disequality. `ne x y` ≡ not (eq x y). Ships in milestone 23 as the Eq-class free helper.")
(type (forall (vars a) (constraints (constraint Eq a)) (fn-type (params (borrow a) (borrow a)) (ret (own (con Bool))))))
(params x y)
(body (app not (app eq x y))))
(fn lt
(doc "Polymorphic strict-less-than. `lt x y` ≡ case compare x y of LT -> True; _ -> False. Ships in milestone 23 as the Ord-class free helper.")
(type (forall (vars a) (constraints (constraint Ord a)) (fn-type (params (borrow a) (borrow a)) (ret (own (con Bool))))))
(params x y)
(body (match (app compare x y)
(case (pat-ctor LT) true)
(case _ false))))
(fn le
(doc "Polymorphic less-than-or-equal. `le x y` ≡ case compare x y of GT -> False; _ -> True. Ships in milestone 23 as the Ord-class free helper.")
(type (forall (vars a) (constraints (constraint Ord a)) (fn-type (params (borrow a) (borrow a)) (ret (own (con Bool))))))
(params x y)
(body (match (app compare x y)
(case (pat-ctor GT) false)
(case _ true))))
(fn gt
(doc "Polymorphic strict-greater-than. `gt x y` ≡ case compare x y of GT -> True; _ -> False. Ships in milestone 23 as the Ord-class free helper.")
(type (forall (vars a) (constraints (constraint Ord a)) (fn-type (params (borrow a) (borrow a)) (ret (own (con Bool))))))
(params x y)
(body (match (app compare x y)
(case (pat-ctor GT) true)
(case _ false))))
(fn ge
(doc "Polymorphic greater-than-or-equal. `ge x y` ≡ case compare x y of LT -> False; _ -> True. Ships in milestone 23 as the Ord-class free helper.")
(type (forall (vars a) (constraints (constraint Ord a)) (fn-type (params (borrow a) (borrow a)) (ret (own (con Bool))))))
(params x y)
(body (match (app compare x y)
(case (pat-ctor LT) false)
(case _ true))))
(fn print
(doc "Polymorphic console-print helper. `print x` ≡ `do io/print_str (show x)` with an explicit let-binder around `show x` for heap-Str RC discipline per eob.1 Str carve-out. Ships in milestone 24 as the second half of the Show prelude.")
(type (forall (vars a) (constraints (constraint Show a)) (fn-type (params (borrow a)) (ret (own (con Unit))) (effects IO))))
(params x)
(body (let s (app show x) (do io/print_str s))))
(fn float_eq
(doc "IEEE Float equality. `float_eq x y` returns true iff both operands are non-NaN and bit-equal. Compiler-supplied (intrinsic) body; codegen emits `fcmp oeq double` with alwaysinline via the intercept registry. Replaces the milestone-deleted polymorphic `==` on Float.")
(type (fn-type (params (own (con Float)) (own (con Float))) (ret (own (con Bool)))))
(params x y)
(intrinsic))
(fn float_ne
(doc "IEEE Float disequality. `float_ne nan nan` returns true (unordered-or-not-equal per IEEE-754). Compiler-supplied (intrinsic) body; codegen emits `fcmp une double`.")
(type (fn-type (params (own (con Float)) (own (con Float))) (ret (own (con Bool)))))
(params x y)
(intrinsic))
(fn float_lt
(doc "IEEE Float strict less-than. `float_lt nan x` returns false for any x (unordered). Compiler-supplied (intrinsic) body; codegen emits `fcmp olt double`.")
(type (fn-type (params (own (con Float)) (own (con Float))) (ret (own (con Bool)))))
(params x y)
(intrinsic))
(fn float_le
(doc "IEEE Float less-than-or-equal. Compiler-supplied (intrinsic) body; codegen emits `fcmp ole double`.")
(type (fn-type (params (own (con Float)) (own (con Float))) (ret (own (con Bool)))))
(params x y)
(intrinsic))
(fn float_gt
(doc "IEEE Float strict greater-than. Compiler-supplied (intrinsic) body; codegen emits `fcmp ogt double`.")
(type (fn-type (params (own (con Float)) (own (con Float))) (ret (own (con Bool)))))
(params x y)
(intrinsic))
(fn float_ge
(doc "IEEE Float greater-than-or-equal. Compiler-supplied (intrinsic) body; codegen emits `fcmp oge double`.")
(type (fn-type (params (own (con Float)) (own (con Float))) (ret (own (con Bool)))))
(params x y)
(intrinsic)))