;; A match arm's binding is a binding, and the escape check has to see it. ;; ;; Reading the payload by hand is a case-field read, which is suspect: a copy ;; of a function value carries whatever environment the original did. Binding ;; it to a name in an arm is the same read, and the store that fills the arm's ;; slot is inside the branch rather than in any form the walk reads as a ;; binding — so without the arm's slots being taken as suspect too, the Vec, ;; slice, struct and pointer spellings of this were all refused while the one ;; that goes through Option and a name was not. (defn leak [o (Option (Fn [] i32))] (Fn [] i32) (match o (Some f) f None (fn [] 0))) (defn main [] i32 0)