a4be1e58a3
Iteration-discipline milestone, 2 of 3. Strictly additive (nothing tail-related removed; that is it.3). New whole-body pass verify_structural_recursion sibling of verify_tail_positions (DD-1): smaller-set algorithm with implicit candidate inference + unconstrained accumulators (DD-2, foldl=structural), self/mutual via inline ADT-family union-find (DD-3), it.2-only tail==false grandfather. CheckError::NonStructuralRecursion. term_contains_loop (stops at Term::Lam, DD-4) injects Diverge so existing UndeclaredEffect enforces it, no new variant; lam-arrow + LetRec sub-effect sites wired. DESIGN.md Decision 3 synced. Four it.1 loop fixtures gained !Diverge. Two spec-premise boundary defects surfaced + resolved within the additive invariant (corpus clean, check not weakened), recorded as corrected it.3 corpus-migration scope: (1) the "21 tail-app fixtures" grandfather premise under-counts the corpus — no-ADT-candidate counter recursions have no structural position to verify, deferred to it.3; (2) two RC-regression fixtures joined the spec's transitional tail-app grandfather as the other 20 do (RC==GC guards verified still green). cargo test --workspace 622/0; 9 acceptance pins non-vacuous. Specfda9b78, planbc9f512.
64 lines
2.1 KiB
Plaintext
64 lines
2.1 KiB
Plaintext
; Iter 18d.4 regression fixture: under --alloc=rc, codegen's
|
|
; "pattern-binder dec at arm close" (Iter A) was firing on
|
|
; pattern-bound pointer fields whose enclosing fn is Implicit-
|
|
; mode. Result: a free of memory the caller still references.
|
|
;
|
|
; Symptom under --alloc=rc before the fix:
|
|
; - Implicit-mode pin/loop: refcount underflow at runtime.
|
|
; - Same code under --alloc=gc: clean exit, prints `0`.
|
|
;
|
|
; Pattern shape: a heap-allocated value `t` shared between a
|
|
; callee that pattern-destructures it (pin) and a recursive
|
|
; call that re-passes it (loop). Pattern arm binds the children
|
|
; (l, r) without consuming them — pre-fix, codegen emitted a
|
|
; drop on each, freeing memory still referenced via the outer
|
|
; let-binder `t`.
|
|
|
|
(module rc_pin_recurse_implicit
|
|
|
|
(data Tree
|
|
(ctor TLeaf)
|
|
(ctor TNode (con Int) (con Tree) (con Tree)))
|
|
|
|
(fn build
|
|
(type (fn-type (params (con Int)) (ret (con Tree))))
|
|
(params d)
|
|
(body
|
|
(if (app == d 0)
|
|
(term-ctor Tree TLeaf)
|
|
(term-ctor Tree TNode 1
|
|
(app build (app - d 1))
|
|
(app build (app - d 1))))))
|
|
|
|
(fn pin
|
|
(type (fn-type (params (con Tree)) (ret (con Int))))
|
|
(params t)
|
|
(body
|
|
(match t
|
|
(case (pat-ctor TLeaf) 0)
|
|
(case (pat-ctor TNode v l r) 1))))
|
|
|
|
; Iter it.2: this is integer-counter recursion holding the ADT
|
|
; param `t` constant — non-structural by the it.2 guardedness
|
|
; check (D2). The recursive call is in tail position, so it joins
|
|
; the transitional `tail-app` grandfather (spec it.2 "Transitional
|
|
; grandfather") exactly as the rest of the corpus does until it.3
|
|
; migrates such recursions to `(loop …)`. The 18d.4 regression this
|
|
; fixture guards lives in `pin`'s match arm-close, unaffected by
|
|
; this tail marking.
|
|
(fn loop
|
|
(type (fn-type (params (con Int) (con Tree)) (ret (con Int))))
|
|
(params n t)
|
|
(body
|
|
(if (app == n 0)
|
|
0
|
|
(let _v (app pin t)
|
|
(tail-app loop (app - n 1) t)))))
|
|
|
|
(fn main
|
|
(type (fn-type (params) (ret (con Unit)) (effects IO)))
|
|
(params)
|
|
(body
|
|
(let t (app build 2)
|
|
(app print (app loop 3 t))))))
|