flan/lib/tast.ml
Joseph Ferano 008165335d break crosses only sometimes, so the refusal is relative now
return is refused inside handler-bind and restart-case blanketly, and rightly:
a return always crosses the frames they pushed. A break does not. A loop
written wholly inside a restart-case body has a perfectly good local break, so
the rule is a barrier on the loop stack rather than a flag — a jump is refused
exactly when a barrier stands between it and the loop it names, and the message
says which construct. handler-bind and restart-case bodies are barriers, so is
a restart clause, so are a defer's forms; a handler clause is lifted into its
own function and needs no rule at all. in_frames is untouched: a return is the
special case where the target is always outside every barrier.

continue wanted the other blocker. check_dotimes folded its step onto the end
of the body, which a continue would jump past, so the counter would never
advance and the loop would hang. Tast.While carries a latch now — condition,
body, latch — the step goes there, and emit_while emits four blocks. A while's
latch is empty and folds away.

Labels are Odin's, in the head position: (while :outer c ...) and (break
:outer). A keyword there is unambiguous because a loop condition is never one,
so one label function serves while, until, dotimes, break and continue. It is
not a goto — the checker resolves a label against the loops the form is
lexically inside, so control can only leave a loop it is already in.

Break and Continue carry a relative depth rather than a name, because that is
what a backend already has: emit keeps one entry per While the way it keeps
one pad per frame, and indexes it.

Nothing in the prelude wants either. Every early exit there is a return from
the function, which break cannot replace; the sentinel-flag loop break exists
to remove does not appear in it. The two the compiler emits are that shape and
are the one place it cannot help — their sentinel is set inside a restart-case.

reach.ml and render.ml take the While arity change and nothing else.
2026-09-12 21:58:53 +07:00

310 lines
16 KiB
OCaml
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

(** The typed IR: what the checker produces and what every backend consumes.
Three backends share this — the tree-walking interpreter, dev redefinition
and the release AOT build (plan.org, Compilation) — so everything a backend
would otherwise have to re-derive is resolved here and nowhere else:
- names are gone. A local is a slot index into the frame, a global is a
name, and a call names its callee directly. No environment lookup.
- field access is an index, not a string, and any auto-deref the source
relied on is an explicit [Deref] node.
- literals have a machine type. There is no untyped 1 past this point.
- a struct literal lists every field in declaration order, with the omitted
ones filled in as [Zero] — ZII is settled here rather than at runtime.
- sugar is already gone from the AST; what is left is the small set below. *)
type prim =
(* arithmetic and comparison, per machine type — the operands carry their own
kind at runtime, so one constructor covers every width *)
| Add | Sub | Mul | Div | Rem
| Eq | Ne | Lt | Le | Gt | Ge
| Not
(* bitwise, integers only. [Shr] is arithmetic on a signed type and logical
on an unsigned one, which is what the operand's own kind already says. *)
| BitAnd | BitOr | BitXor | Shl | Shr
(* containers: fixed arrays and slices only at milestone 2 *)
| Len | At | Slice
(* the milestone-2 host primitives, plan.org. The four conversions are
*text*: bytes->f64 parses "12.5", f64->bytes renders it — that is what
calc-me's tokenizer and the prelude's printers each need. *)
| Bytes | BytesToF64 | BytesToI64 | F64ToBytes | I64ToBytes
(* (string b): the other direction of [Bytes], and the same non-instruction.
See check.ml's "string" case for why it is unchecked. *)
| StrOfBytes
(* No surface name: the structural printer is the only thing that builds
these. U64ToBytes because u64 is not i64 with a flag, EscapeBytes for a
string nested inside a printed structure. *)
| U64ToBytes | EscapeBytes
| WriteStdout | Exit | Argv
(* A call into the runtime's C, named by symbol. The argument and result
LLVM types come off the expression nodes themselves, so one constructor
covers every entry point the allocator and container runtime has and the
backend grows one arm rather than one per operation — which matters
because spec-memory.md's runtime is type-erased and therefore *is* a list
of C entry points. A string or slice argument crosses as ptr+len, the
same rule as every other shim here. No transfer guard follows one: a
transfer cannot cross a C frame. *)
| Rt of string
(* spec-memory.md, "Alignment": a property of the type, computed at the call
site, passed as a parameter to the type-erased allocator — all three, and
they are not alternatives. The checker builds these at the site where the
concrete element type is known and the backend fills in the number from
the same layout calculator DWARF uses. *)
| SizeOf of Types.t
| AlignOf of Types.t
(* The address of any expression, not only of a place: the element a [push]
copies may be a computed value, and the runtime takes it by pointer
because it is type-erased. The backend already spills a non-place to a
temporary for exactly this. *)
| AddrOf
| Cast of Types.t
type expr = { e : expr_kind; ty : Types.t; loc : Loc.t }
and expr_kind =
| Int of int64 * Types.ikind
| Float of float * Types.fkind
| Bool of bool
| Str of string
| Unit
| Zero of Types.t (* ZII: all-bytes-zero of this type *)
| Uninit of Types.t (* the explicit opt-out *)
| Local of int (* slot index into the frame *)
| Global of string
| Prim of prim * expr list
| Call of string * expr list (* direct call; no first-class fns yet *)
(* The address of a function the compiler emitted, by symbol. Not a function
*value*: nothing in the surface language can produce one, name its type or
call through it, and its only consumers are runtime entry points that take
a procedure the way spec-memory.md's type-erased allocator does. The Map's
hash and equality pair is what wanted it — Odin's [Map_Info] is two
contextless [proc] fields reached exactly this way — and a handler-bind
clause is the same arrangement with the symbol carried on [hframe]
instead. Its Flan type is [Alloc]: an opaque pointer-width value with no
user-writable constructor, which is all any backend needs to know. *)
| FnAddr of fnref
| Do of expr list
| Let of (int * expr) list * expr list
| If of expr * expr * expr
(* condition, body, and the *latch*: forms that run after the body and before
the condition is tested again. [dotimes] folds its increment in there
rather than onto the end of the body, because a [continue] branches to the
latch and a step written in the body would be skipped — the loop would
never advance and would hang. A [while] has an empty latch. *)
| While of expr * expr list * expr list
| Return of expr option
(* Leaving a loop, and jumping to its latch. The int is how many loops out
the target is, innermost first: 0 is the loop this is directly inside.
A *relative* depth rather than a name or an id because it is exactly what
each backend already has — [emit] keeps one entry per [While] it is inside
and indexes it. The invariant that makes it sound: the checker mints these
only from its own loop stack, and both stacks are pushed once per [While].
A [While] the checker *invents* (alloc_guard, the file-failure retry) is
built directly and never contains one of these, so the entry it pushes in
[emit] matches nothing and is harmless — keep it that way. *)
| Break of int
| Continue of int
| Set of place * expr
| Field of expr * int (* target is already a struct value *)
| Addr of place
| Deref of expr
| Make of string * expr list (* struct literal, every field, in order *)
(* A union value: the union's name, the case's name, and every field of that
case in declaration order with the omitted ones filled in as [Zero] — the
same ZII rule [Make] carries, and settled here for the same reason. It is
its own node rather than a [Make] over a synthesised struct because the
value's *type* is the union and its payload is a byte blob the case is
reinterpreted into; a backend that saw only [Make] would have to rederive
which of the two it was looking at. *)
| MakeCase of string * string * expr list
(* One field of one case of a union value, by index. The case name is on the
node because the payload is untyped bytes: [Field]'s index alone cannot
say which case struct the blob is being read as. [match] is the only thing
that proves the case, so this is only ever built under an arm that
checked the tag — and by [Render], which reads a field only after the same
comparison. One node, so the payload layout is known in exactly one place
in each backend rather than once per reader. *)
| CaseField of expr * string * int
| Arr of expr list (* fixed-array literal *)
| Some_ of expr
| None_
| Match of expr * arm list
(* (some x): unwrap Some, else early-return None from the enclosing function.
An early return, not an expression that can fail — hence its own node. *)
| UnwrapSome of expr
(* Conditions, spec-conditions.md. [Signal] walks the handler stack and
returns Unit whatever it finds — with nothing matching it is a no-op, so
nothing here alters control flow. [HandlerBind] pushes one frame per
clause, runs its body, and pops them; each clause was lifted into its own
function by the checker, so what is left is the frame and the call. *)
| Signal of sigkind * int * expr (* how, the type id, the condition *)
| Handled of hframe list * expr list
(* The transfer, spec-conditions.md §3§6. [RestartCase] pushes one frame per
clause, runs its body, and pops them; if a transfer arrives naming one of
*its* frames it runs that clause instead, and the whole form yields either
way. [InvokeRestart] looks the name up on the restart stack, writes the
frame it found into the transfer channel and leaves — it has type Never,
so nothing follows it.
[InvokeRestart]'s arguments are already evaluated: the checker binds each
to a slot and wraps the node in a [Let], so what is left here is a list of
locals to copy into the frame. Two reasons, and both matter. An argument
that transfers on its own must be guarded before this one aims the
channel; and a call written in an argument has to be on the walk [Reach]
and [Load] already do, which a list hanging off a node they treat as a
leaf would not be. [rsig] is the argument types as written, and [rsig_id]
their hash — §3's run-time check, since the name is resolved on a stack
nothing static can see. *)
| RestartCase of rclause list * expr
(* (with-allocator A BODY...) — spec-memory.md. It rebinds the current
allocator for its dynamic extent and releases nothing. Its own node
because the restore has to happen on the *transfer* path too: a body that
errors, or a restart taken from inside it, must not leave the context
allocator pointing at a region the handler knows nothing about. *)
| WithAlloc of expr * expr list
(* name id, name, arguments, their spelling, its hash, where *)
| InvokeRestart of int * string * expr list * string * int * Loc.t
(* [Serror] is §2's diverging variant: the same lookup, type Never, and with
nothing transferring the program stops rather than carrying on. *)
(* Which symbol table the address comes out of. [Flanfn] is a function this
compiler emitted and is therefore name-mangled and reachability-tracked;
[Rtfn] is a C entry point in flan_rt.c, spelled as written. The two are
interchangeable at the call site because a Flan function's emitted signature
is its parameters followed by the transfer channel, and the runtime's
matching typedef spells that last pointer out. *)
and fnref = Flanfn of string | Rtfn of string
and sigkind = Ssignal | Serror
and place =
| Plocal of int
| Pglobal of string
| Pfield of expr * int
| Pindex of expr * expr list
| Pderef of expr
(* A pushed handler: which condition type it matches, and the lifted function
that runs when one is signalled. *)
and hframe = { htype : int; hfn : string }
(* A restart clause. [rname_id] is what [invoke-restart] matches by name; the
body is a branch in the function that wrote it, because unlike a handler a
clause runs at the restart-case, which is where it was written.
[rparams] are the slots §3's parameters are bound to, in order, with their
types; the invoker stores into a buffer this frame owns and the clause loads
them from it. [rsig] is how those types are spelled and [rsig_id] its hash:
what the two ends compare, since neither can see the other. *)
and rclause =
{ rname_id : int; rname : string; rparams : (int * Types.t) list;
rsig : string; rsig_id : int; rbody : expr list }
(* [binds] are the slots the pattern's fields are bound to, in field order. *)
and arm = { acase : string option; binds : int list; abody : expr list }
type field = { fname : string; fty : Types.t }
type structure = { sname : string; fields : field list }
type variant = { vname : string; vfields : field list }
type union = { uname : string; cases : variant list }
type fn = {
name : string;
params : Types.t list; (* bound to slots 0 .. n-1, in order *)
slots : Types.t array; (* the frame: one entry per slot *)
(* What the source called each slot, parallel to [slots]. [None] is a slot
the compiler made up and no one wrote a name for -- [dotimes]'s hidden
bound, the pair (min) and (max) evaluate their operands into, the slot a
tail expression goes through. Names are otherwise gone from this IR (see
the header); this is the one exception, and it exists so a debug build can
emit a [!DILocalVariable] that says [lo] where the source said [lo]. A
backend is free to ignore it entirely -- nothing is *resolved* through it,
and a slot is still only ever referred to by index. *)
snames : string option array;
ret : Types.t;
body : expr list;
(* The defers again, innermost first. [body] already has them spliced onto
the normal exit path; this is the same list for the *transfer* exit path,
which leaves through a landing block the backend builds and no form in
[body] can reach. spec-conditions.md §5: they run, and errdefer does not. *)
fdefers : expr list;
(* Set on a function the checker made up rather than one anyone wrote: a
handler-bind clause, lifted out of the function named here. It is reached
by address from that function's body and from nowhere else, so it needs no
cell and no registry slot, and a redefinition of the parent carries its
own copy. *)
fparent : string option;
floc : Loc.t;
}
(* [gfolded] is the difference between a constant whose value the *checker*
consumed — an array length, decided before any type resolves — and one that
is only ever read at run time. The first is in the program's shape and can
never be reloaded; the second is just bytes in memory and can. Nothing else
can tell them apart afterwards, so it is recorded here. *)
type global = {
gname : string;
gty : Types.t;
ginit : expr;
gconst : bool;
gfolded : bool;
}
(* A foreign function: no body, and [esym] is the symbol the linker sees. The
aggregate calling convention is not modelled here — a C shim flattens every
struct that crosses the boundary, so clang classifies it per target and
nothing in the backend has to know x86-64 from arm64 from wasm32. *)
type extern = {
ename : string; (* the Flan name, e.g. rl/init-window *)
esym : string; (* the C symbol *)
eparams : Types.t list;
eret : Types.t;
}
type program = {
structs : structure list;
unions : union list;
globals : global list; (* in declaration order *)
externs : extern list;
fns : fn list;
(* The C the program's own (declare-c ...) forms generated, if any: one
translation unit, compiled into the build like a package's hand-written
.c file. It is on the program rather than beside it so that every driver
— the CLI, the REPL, the acceptance table — carries it without knowing
it exists. See [Shim]. *)
(* The generated FFI shim, in parts keyed by the declaration each serves,
with "" for the shared preamble. Parts rather than one string so that
[Reach.link] can drop a wrapper whose binding nothing reachable calls. *)
cshim : (string * string) list;
}
(* The declared position of a case, which is its tag, and the case itself. Tags
are declaration order from zero, so an all-bytes-zero union is the first
case with a zeroed payload — the same rule that makes an [Option]'s zero a
[None], and the reason case order is part of a union's contract. *)
let case_index (u : union) name =
let rec go i = function
| [] -> None
| (c : variant) :: rest ->
if String.equal c.vname name then Some (i, c) else go (i + 1) rest
in
go 0 u.cases
let vfield_index (c : variant) name =
let rec go i = function
| [] -> None
| (f : field) :: rest ->
if String.equal f.fname name then Some i else go (i + 1) rest
in
go 0 c.vfields
let field_index (s : structure) name =
let rec go i = function
| [] -> None
| f :: rest -> if String.equal f.fname name then Some i else go (i + 1) rest
in
go 0 s.fields