FIX.org, NEXT.md, DISCUSS.org, docs/DISCUSS.md and the session handoff at the root are one TODO.org now: 293 entries under seven subsystem headings, each carrying an org keyword that says where it stands. A DONE entry is a few lines saying what was decided and what that rules out; the reasoning that would not compress — the embedding spike and the four reports the hand-written x86 backend was built from — moved into docs/BUILT.md instead, and its entries point there in one line. Every entry was checked against the tree before it got a keyword, and the prose was wrong in both directions. Things the deleted files called open were built: the first-evaluation stall, main being redefinable, macro parameter lists, the type-limit constants, the array constructors, the byte fills, inc/dec, the discard's fontification, the Emacs buffers, rt_die's _exit, the backtrace surface, and the acceptance failure that could print and still exit zero. Things they called done were not: the backend reports' no-plan buckets had gone stale in the other direction, the value-dependent defvar was superseded rather than built, and macro-expansion source locations are on an unmerged lane, so that entry is NEXT and names the branch. Every comment that cited one of the five by name now cites a heading that exists, in TODO.org or in docs/BUILT.md. The session reports under docs/handoffs/ keep naming the files they worked on, because rewriting them would falsify what those sessions did; each carries a note saying where the content went.
46 lines
2.5 KiB
Plaintext
46 lines
2.5 KiB
Plaintext
;;;; Bounds checks, TODO.org, "An index out of range is a condition". One
|
|
;;;; program, one case per argument, so a trap is observable: the checked build
|
|
;;;; exits 134 with the source location on stderr.
|
|
;;;;
|
|
;;;; The unchecked build is not uniform, and the split is the point. An index
|
|
;;;; past the end runs off the end there and is not asserted on — that is what
|
|
;;;; --no-bounds-checks buys. Two of the cases below still trap: the reversed
|
|
;;;; range at n = 2 and the negative promise at n = -2, because neither is a
|
|
;;;; bounds check. Both are the claim that a slice's length word is a count,
|
|
;;;; and a build that drops them does not produce an unchecked slice, it
|
|
;;;; produces a value that is not one. See check_slice in lib/emit.ml.
|
|
;;;;
|
|
;;;; The selector is also the index wherever it can be, which is what keeps the
|
|
;;;; index dynamic — a literal would let the checker reject it outright one day
|
|
;;;; (that is a separate job) and lets LLVM fold the branch away here.
|
|
(defonce arr [3 i32])
|
|
|
|
(defn main [args [string]] i32
|
|
(let [n (i32 (bytes->i64 (bytes-view (at args 1))))
|
|
s (bytes-view "hello")] ; len 5
|
|
(cond
|
|
;; In bounds, including both edges: the last index, and a slice that
|
|
;; ends exactly at len. Neither may trap.
|
|
(= n 0) (do (print (at arr 2))
|
|
(print (slice s 1 5))
|
|
(print (slice s 5 5)) ; empty at len is legal
|
|
(println ""))
|
|
|
|
(= n 3) (print (at arr n)) ; past the end of a fixed array
|
|
(= n -1) (print (at arr n)) ; negative index
|
|
(= n 9) (print (at s n)) ; past the end of a slice
|
|
;; The write path lowers through place/Pindex rather than through At, so
|
|
;; it is checked separately even though the message is the same.
|
|
(= n 7) (set (at arr n) 1) ; write past the end
|
|
(= n 4) (print (slice s n 9)) ; hi past the end
|
|
(= n 2) (print (slice s n 1)) ; reversed range
|
|
;; (slice-from-ptr p n) has nothing to check n against — the caller's
|
|
;; number is the only length there is — so what it checks is that the
|
|
;; number is not absurd. Signed, deliberately: the comparisons the other
|
|
;; two checks use are unsigned, and a negative i32 sign-extended to i64
|
|
;; is a huge unsigned value that sails straight through them.
|
|
(= n -2) (print (length (slice-from-ptr (addr (at arr 0)) n)))
|
|
|
|
:else (println "?"))
|
|
0))
|