The 3020-line docs/DESIGN.md is replaced by the design/ ledger:
design/INDEX.md (sole addressable spine, typed Contracts+Models tables,
polymorphic links — prose file OR authoritative source //!), 14
design/contracts/*.md test-linked invariants + 3 source-link-only
contracts (mangling/env-construction/qualified-xref, no prose file —
code is SoT), 5 design/models/*.md whitepapers, and
docs/journals/2026-05-19-design-decision-records.md (the
relitigation-guard archive — every why/rejected/does-not-do/rollback/
empirical ### moved out at ###-granularity). Clean cut: git rm
docs/DESIGN.md, no stub.
RED-first crates/ailang-core/tests/design_index_pin.rs — the 4-clause
anti-regrowth spine (DESIGN.md-gone / every-INDEX-link-resolves /
every-contract-names-a-resolvable-ratifier /
contracts-carry-no-decision-record-prose) — demonstrably RED before,
GREEN after. Build-atomic by task ordering: design_schema_drift.rs's
include_str! (the only compile-time consumer) retargeted to
design/contracts/data-model.md BEFORE the deletion; its
## Data model/## Pipeline slicer dropped (a simplification the split
enables). 2 NoInstance diagnostics + 2 lockstep E2Es retargeted to
design/contracts/{float-semantics,typeclasses}.md. ~12 agent reading
lists + 5 SKILL bodies + CLAUDE.md + skills/README.md + ~25
code/C/.ail/spec comment xrefs retargeted; OQ7 dangling 'Iter 13b'
cite deleted (no forward target — a pointer would be fiction).
honesty-rule.md rewritten so the rule names the new home
(rationale->journals), resolving the recon-found internal
contradiction; the two docs_honesty_pin.rs:70,72 pinned phrases kept
verbatim+contiguous.
Boss-verified independently: cargo test --workspace 646 passed /
0 failed; design_index_pin 4/4; acceptance grep CLEAN of live
DESIGN.md refs (residuals = only the spec-mandated clause-4
deletion-enforcer). 2 DONE_WITH_CONCERNS routed to the mandatory
milestone-close audit: (a) str-abi.md:23 '(iter str-concat,
2026-05-13)' provenance stamp trips advisory architect_sweeps Sweep-1
— Boss-confirmed byte-identical to DESIGN.md@deeffb1:2062-2065, a
faithfully-migrated PRE-EXISTING anchor (regexes verbatim, only path
retargeted), NOT split-introduced — RATIFY-or-tidy at audit; (b) a
now stale-direction intra-prose 'see Str ABI below' cross-ref in
float-semantics.md — audit-adjudication candidate. Plan defect noted:
Task 9 Step 4's verbatim acceptance grep used a ^./ anchor not
matching the system's grep -rIn output; substance re-verified CLEAN.
Spec grounding-check PASS x2. Journals INDEX + decision-records
pointer appended (Boss-only).
2.2 KiB
Frozen value layout (M3 — one-way commitment)
Frozen value layout (M3 — one-way commitment)
For a single-constructor data T whose n fields are each Int
or Float, a value of T crossing the embedding C boundary is a
bare payload pointer p:
| bytes | content |
|---|---|
p - 8 .. p |
uint64_t refcount header (HEADER_SIZE = 8) |
p + 0 .. p + 8 |
int64_t constructor tag (written; 0 for the single ctor — no elision) |
p + 8 + i*8 |
field i, declaration order: int64_t for Int, IEEE-754 double bit-pattern for Float |
Total box payload size = 8 + n*8. This is the same layout
lower_ctor (match_lower.rs) emits internally; for an exported
type the host encodes and decodes these exact offsets itself, so
they are frozen — a compiler change MUST NOT move them for an
exported type, which permanently constrains codegen's freedom to
repack exported records.
Construction (host → kernel input). The host MUST obtain an
input record's storage from ailang_rc_alloc(8 + n*8) (returns the
payload pointer with the refcount header pre-set to 1, payload
zeroed), then write the tag (0) and the scalar fields at the
offsets above. A raw malloc is a contract violation:
own-consume and ailang_rc_dec both require the runtime's 8-byte
header at p - 8 initialised to 1.
Ownership follows the declared mode (the §"Mode metadata is
load-bearing for codegen" contract, as the C ABI): a (own (con T)) parameter transfers ownership in — the kernel consumes it
(Iter-B drop-at-return); the host MUST NOT touch or dec it after
the call. A (borrow (con T)) parameter is retained by the host —
the kernel does not consume it; the host frees it. The return value
is always owned by the host.
Free (host side). ailang_rc_dec(payload). Leak-free for an M3
record because every field is a scalar — ailang_rc_dec is
header-only and an M3 record has no boxed children. A record with
boxed fields (Str/List/nested record) is not an M3
embedding type — the export gate rejects it, so the boundary
never crosses a value that would need a recursive typed-free. The
freeze covers exactly the all-scalar single-constructor record.
Ratified by: crates/ailang-codegen/tests/embed_record_layout_pin.rs.