parse: enforce strict-package — reject package-less files (#24a)

Flip the soft-default to a hard "missing package clause" error symmetrically in
both stages (cmd/wcc/parse.c + lib/ww/syntax/parse.ww): the first real decl of a
primary section with empty pathmod/resetmod and no seen clause is now rejected.
Closes the documented soft-default divergence (the 63-wrapper carve-out).

The gate flip can't be split from the migration it breaks, so this is one atomic
commit: ~80 test/wcc wrappers gain `package main;` via a shared wwtestpkg.h
helper, 6 data fixtures plus 17 asm-grep assertions update for the bare->main.<leaf>
root-helper mangle shift, and rt/ declares `package rt;` with @symbol pinning the
bare rt_ensure/rt_malloc linker names.

Root mangling narrows: the executable entry `main` stays bare (existing
carve-out), but root helper symbols become main.X. The #84 cluster is rewritten
to assert main.run distinct from aa.run/test.run; its cgen fix and bare machinery
are retained — still load-bearing for package-less module-reset deps. New
table-driven test 782_strict_package.c (6 rows, both stages).

Retiring //ww:module-reset is deferred to #24b: it is load-bearing (clears the
.wwi pathmod so the body's package clause asserts), not a vestige; fusing its
removal here would be a silent mismatch.

All byte-id gates green; full make test reports "all 335 tests passed".
This commit is contained in:
2026-06-29 03:55:26 +09:00
parent d34c90d932
commit 7b9488706b
95 changed files with 579 additions and 223 deletions

View File

@@ -1,6 +1,8 @@
// rt/malloc.ww — bump allocator over 2MiB chunks. Archived into
// libwwrt.a, compiled standalone (no `module`) with bare symbols, like
// rt/ensure.ww.
// libwwrt.a, compiled standalone with bare symbols, like rt/ensure.ww.
// Under strict-package (#24a) it declares `package rt;` (matching its
// directory); the export's link name stays bare via its own
// @symbol("rt_malloc").
//
// WHY bump, replacing the page-per-call mmap (rt_segmalloc, ex-rt_malloc):
// the old rt_malloc page-rounded every request, so a 32-72B node cost a
@@ -15,6 +17,7 @@
// Zero-init is preserved: every byte handed out is fresh from
// MAP_ANONYMOUS (kernel-zeroed) and never reused, so alloc(T{})'s
// zero-fill still holds. Lazy first chunk falls out of cur=rem=0.
package rt;
def CHUNKSZ: u64 = 2097152u64; // 1<<21, ref/hare/rt/malloc.ha:24
def ALIGN: u64 = 16u64; // ref/hare/rt/malloc.ha:14