32 lines
1.5 KiB
Plaintext
32 lines
1.5 KiB
Plaintext
;;;; Bounds checks, NEXT.md item 2. One program, one case per argument, so a
|
|
;;;; trap is observable: the checked build exits 134 with the source location
|
|
;;;; on stderr, the unchecked one runs off the end and is not asserted on.
|
|
;;;;
|
|
;;;; The selector is also the index wherever it can be, which is what keeps the
|
|
;;;; index dynamic — a literal would let the checker reject it outright one day
|
|
;;;; (that is a separate job) and lets LLVM fold the branch away here.
|
|
(defvar arr [3 i32])
|
|
|
|
(defn main [args [string]] i32
|
|
(let [n (i32 (bytes->i64 (bytes (at args 1))))
|
|
s (bytes "hello")] ; len 5
|
|
(cond
|
|
;; In bounds, including both edges: the last index, and a slice that
|
|
;; ends exactly at len. Neither may trap.
|
|
(= n 0) (do (print-i64 (i64 (at arr 2)))
|
|
(print-bytes (slice s 1 5))
|
|
(print-bytes (slice s 5 5)) ; empty at len is legal
|
|
(newline))
|
|
|
|
(= n 3) (print-i64 (i64 (at arr n))) ; past the end of a fixed array
|
|
(= n -1) (print-i64 (i64 (at arr n))) ; negative index
|
|
(= n 9) (print-i64 (i64 (at s n))) ; past the end of a slice
|
|
;; The write path lowers through place/Pindex rather than through At, so
|
|
;; it is checked separately even though the message is the same.
|
|
(= n 7) (set (at arr n) 1) ; write past the end
|
|
(= n 4) (print-bytes (slice s n 9)) ; hi past the end
|
|
(= n 2) (print-bytes (slice s n 1)) ; reversed range
|
|
|
|
:else (print-line "?"))
|
|
0))
|