selfhost+test: graduate structlookup same-module-first (#4b)
Class A silent miscompile, latent until two modules export the same struct leaf name. Wwstage's structlookup (selfhost/cmd/wcc/cgenutil.ww) walked c.structs head-first by sname, returning the FIRST match. cgdot's *struct field-load branch handed it inner.str (the bare leaf from a parsed N_TPTR whose inner is N_TNAME) and the head-pick silently emitted the wrong-module field offset — a displacement against BX that loaded whatever the colliding-module struct happened to align there. Cstage carries no sister bug: resolve_typename (cmd/wcc/check.c:65) already routes bare-leaf TY_STRUCT names through scope_lookup_prefer per c->cur_mod, and cgen.c reads fi.foff off the typed Sym — cs vs ws asm diverged on every bare- leaf collision but no in-tree corpus declares two same-leaf structs, so 995_self_rebuild stayed green (same surfacing pattern as #4a enumlookup post-strings). Fifth leaf of the trio leaf-name lookup graduation (after #27 aliaslookup, #28/#31 fnparams/fnretlookupmod, #4a enumlookup): structlookup grows a same-module-first walk before the head-walk fallback, mirroring aliaslookup's two-pass shape. No structlookupmod variant — pkg.S collapses at parse time (lib/ww/parse/parse.ww joindotted) into a single N_TNAME str routed through the existing embedded-dot smod==pkg branch, so there's no cgdot-style N_DOT consumer surface to add a *mod variant for (deferred per rob until one surfaces). No cstage symmetric fix needed for the same reason the bug doesn't surface there. 734_struct_modshadow pins the fix with 2 rows: row 1 bare-leaf in module M must fold against M's own S even with another module's same-leaf S at the head of c.structs (asserts the matching field- load disp inside the right TEXT sym + bad disp NOT-presence anti- check + byte-id between stages); row 2 pkg-qualified alpha.S from inside alpha is defensive coverage of the pre-existing embedded-dot smod==pkg branch — same path pre/post-fix (no sentinel-flip on this commit), pinned here so a future regression to the embedded-dot lookup is caught.
This commit is contained in:
5
Makefile
5
Makefile
@@ -263,6 +263,7 @@ TESTS = $(BIN)/test_smoke $(BIN)/test_lex $(BIN)/test_parse $(BIN)/test_check \
|
||||
$(BIN)/test_match_4arm_cross_module \
|
||||
$(BIN)/test_match_4arm_cross_module_run \
|
||||
$(BIN)/test_enum_modshadow \
|
||||
$(BIN)/test_struct_modshadow \
|
||||
$(BIN)/test_param_shadow_mod \
|
||||
$(BIN)/test_localoff_scope \
|
||||
$(BIN)/test_cast_enum_movl \
|
||||
@@ -613,6 +614,10 @@ $(BIN)/test_enum_modshadow: test/wcc/733_enum_modshadow.c \
|
||||
$(BIN)/w6c $(BIN)/w6c_ww | $(BIN)
|
||||
$(CC) $(CFLAGS) -o $@ $<
|
||||
|
||||
$(BIN)/test_struct_modshadow: test/wcc/734_struct_modshadow.c \
|
||||
$(BIN)/w6c $(BIN)/w6c_ww | $(BIN)
|
||||
$(CC) $(CFLAGS) -o $@ $<
|
||||
|
||||
$(BIN)/test_match_4arm_cross_module_run: test/wcc/929_match_4arm_cross_module_run.c \
|
||||
$(BIN)/ww $(BIN)/w6c $(BIN)/w6a $(BIN)/w6l \
|
||||
$(BIN)/ww_ww $(BIN)/w6c_ww $(BIN)/w6a_ww $(BIN)/w6l_ww \
|
||||
|
||||
@@ -8369,19 +8369,28 @@ export fn callsretsize(c: *cgen, n: *node) i32 = {
|
||||
};
|
||||
|
||||
fn structlookup(c: *cgen, name: str) *structinfo = {
|
||||
// Exact match first: bare-from-source struct names and already-
|
||||
// leafed lookups hit here directly.
|
||||
// Same-module first, then any. Trio-leaf graduation mirroring
|
||||
// aliaslookup (#27), fnret/fnparamslookupmod (#28/#31), and
|
||||
// enumlookup (#4a): without the prefer pass a bare-leaf struct
|
||||
// name in module M can collapse onto another module's same-leaf
|
||||
// struct prepended earlier in c.structs, silently picking the
|
||||
// wrong totsize / field offsets.
|
||||
let s: *structinfo = c.structs;
|
||||
for (s != nil) {
|
||||
if (streq(s.sname, name)) {
|
||||
if (streq(s.smod, c.curmod)) { return s; };
|
||||
};
|
||||
s = s.sinext;
|
||||
};
|
||||
s = c.structs;
|
||||
for (s != nil) {
|
||||
let sn: str = s.sname;
|
||||
if (streq(sn, name)) { return s; };
|
||||
s = s.sinext;
|
||||
};
|
||||
// Module-qualified form: `pkg.S` → match the leaf scoped to its
|
||||
// originating module. Mirrors aliaslookup's mod-filter; the
|
||||
// `smod == pkg` guard is what prevents two modules with same-
|
||||
// leaf-name structs from collapsing into whichever entry appears
|
||||
// first in the chain.
|
||||
// Module-qualified form embedded in name (`pkg.S`): scope the
|
||||
// leaf to its originating module. The `smod == pkg` guard
|
||||
// prevents same-leaf structs in two modules from collapsing.
|
||||
let i: i32 = name.len - 1;
|
||||
for (i >= 0) {
|
||||
if (name[i] == 46u8) { // '.'
|
||||
|
||||
@@ -1430,19 +1430,28 @@ export fn callsretsize(c: *cgen, n: *node) i32 = {
|
||||
};
|
||||
|
||||
fn structlookup(c: *cgen, name: str) *structinfo = {
|
||||
// Exact match first: bare-from-source struct names and already-
|
||||
// leafed lookups hit here directly.
|
||||
// Same-module first, then any. Trio-leaf graduation mirroring
|
||||
// aliaslookup (#27), fnret/fnparamslookupmod (#28/#31), and
|
||||
// enumlookup (#4a): without the prefer pass a bare-leaf struct
|
||||
// name in module M can collapse onto another module's same-leaf
|
||||
// struct prepended earlier in c.structs, silently picking the
|
||||
// wrong totsize / field offsets.
|
||||
let s: *structinfo = c.structs;
|
||||
for (s != nil) {
|
||||
if (streq(s.sname, name)) {
|
||||
if (streq(s.smod, c.curmod)) { return s; };
|
||||
};
|
||||
s = s.sinext;
|
||||
};
|
||||
s = c.structs;
|
||||
for (s != nil) {
|
||||
let sn: str = s.sname;
|
||||
if (streq(sn, name)) { return s; };
|
||||
s = s.sinext;
|
||||
};
|
||||
// Module-qualified form: `pkg.S` → match the leaf scoped to its
|
||||
// originating module. Mirrors aliaslookup's mod-filter; the
|
||||
// `smod == pkg` guard is what prevents two modules with same-
|
||||
// leaf-name structs from collapsing into whichever entry appears
|
||||
// first in the chain.
|
||||
// Module-qualified form embedded in name (`pkg.S`): scope the
|
||||
// leaf to its originating module. The `smod == pkg` guard
|
||||
// prevents same-leaf structs in two modules from collapsing.
|
||||
let i: i32 = name.len - 1;
|
||||
for (i >= 0) {
|
||||
if (name[i] == 46u8) { // '.'
|
||||
|
||||
@@ -8369,19 +8369,28 @@ export fn callsretsize(c: *cgen, n: *node) i32 = {
|
||||
};
|
||||
|
||||
fn structlookup(c: *cgen, name: str) *structinfo = {
|
||||
// Exact match first: bare-from-source struct names and already-
|
||||
// leafed lookups hit here directly.
|
||||
// Same-module first, then any. Trio-leaf graduation mirroring
|
||||
// aliaslookup (#27), fnret/fnparamslookupmod (#28/#31), and
|
||||
// enumlookup (#4a): without the prefer pass a bare-leaf struct
|
||||
// name in module M can collapse onto another module's same-leaf
|
||||
// struct prepended earlier in c.structs, silently picking the
|
||||
// wrong totsize / field offsets.
|
||||
let s: *structinfo = c.structs;
|
||||
for (s != nil) {
|
||||
if (streq(s.sname, name)) {
|
||||
if (streq(s.smod, c.curmod)) { return s; };
|
||||
};
|
||||
s = s.sinext;
|
||||
};
|
||||
s = c.structs;
|
||||
for (s != nil) {
|
||||
let sn: str = s.sname;
|
||||
if (streq(sn, name)) { return s; };
|
||||
s = s.sinext;
|
||||
};
|
||||
// Module-qualified form: `pkg.S` → match the leaf scoped to its
|
||||
// originating module. Mirrors aliaslookup's mod-filter; the
|
||||
// `smod == pkg` guard is what prevents two modules with same-
|
||||
// leaf-name structs from collapsing into whichever entry appears
|
||||
// first in the chain.
|
||||
// Module-qualified form embedded in name (`pkg.S`): scope the
|
||||
// leaf to its originating module. The `smod == pkg` guard
|
||||
// prevents same-leaf structs in two modules from collapsing.
|
||||
let i: i32 = name.len - 1;
|
||||
for (i >= 0) {
|
||||
if (name[i] == 46u8) { // '.'
|
||||
|
||||
247
test/wcc/734_struct_modshadow.c
Normal file
247
test/wcc/734_struct_modshadow.c
Normal file
@@ -0,0 +1,247 @@
|
||||
/*
|
||||
* 734_struct_modshadow — sentinel for the trio leaf-name pattern's
|
||||
* 5th leaf: wwstage's structlookup. Pins bare-leaf `*S` field access
|
||||
* to a same-module-first walk so the load picks the caller's own
|
||||
* `S` (correct field offset / totsize) rather than another module's
|
||||
* same-leaf-name `S` sitting at the head of c.structs.
|
||||
*
|
||||
* Pre-fix wwstage's `structlookup` (selfhost/cmd/wcc/cgenutil.ww)
|
||||
* walked c.structs head-first by sname, returning the FIRST match.
|
||||
* The cgdot `*struct` field-load branch handed it `inner.str` (the
|
||||
* bare leaf from a parsed N_TPTR whose inner is N_TNAME) and the
|
||||
* head-pick silently emitted the wrong-module field offset — a
|
||||
* displacement against BX that loaded whatever the colliding-module
|
||||
* struct happened to align there. Silent miscompile, not byte-id:
|
||||
* cstage's resolve_typename uses scope_lookup_prefer(cur, cur_mod,
|
||||
* leaf) so check.c already binds the correct Type, and cgen.c reads
|
||||
* fi.foff off the typed Sym — cs vs ws asm diverged on every bare-
|
||||
* leaf collision but no in-tree corpus declares two same-leaf
|
||||
* structs, so 995 stayed green and the latent miscompile only
|
||||
* surfaces once a stdlib port introduces the collision (same shape
|
||||
* as #4a enumlookup surfacing post-strings).
|
||||
*
|
||||
* Trio's structural close per task #4 leaves: structlookup grows a
|
||||
* same-module-first walk before the head-walk fallback, mirroring
|
||||
* aliaslookup (#27), fnparamslookupmod (#28), fnretlookupmod (#31)
|
||||
* and enumlookup (#4a). NO structlookupmod variant: the consumer
|
||||
* surface for `pkg.S` is fully captured by the parser collapsing
|
||||
* dotted N_TNAME into a single str with embedded `.`, which routes
|
||||
* through structlookup's existing smod==pkg embedded-dot branch.
|
||||
* Cstage carries no sister bug — resolve_typename already routes
|
||||
* the bare-leaf TY_STRUCT name through scope_lookup_prefer per
|
||||
* c->cur_mod (cmd/wcc/check.c:60).
|
||||
*
|
||||
* Asserts the post-fix field-offset land inside the matching TEXT
|
||||
* sym on BOTH stages and that cs vs ws stay byte-identical on each
|
||||
* row. Row 1 sentinel-flips this commit's new same-module-first
|
||||
* walk (revert the structlookup change → row 1 fails on wwstage
|
||||
* + cs-vs-ws diff). Row 2 exercises the pre-existing embedded-dot
|
||||
* smod==pkg branch (unchanged here) — defensive coverage that
|
||||
* guards the second structlookup path against future regression;
|
||||
* does not sentinel-flip on this commit's change.
|
||||
*/
|
||||
#include <stdio.h>
|
||||
#include <stdlib.h>
|
||||
#include <string.h>
|
||||
#include <unistd.h>
|
||||
#include <sys/wait.h>
|
||||
|
||||
static int
|
||||
runwait(const char *cmd)
|
||||
{
|
||||
int rc = system(cmd);
|
||||
if (rc == -1) return -1;
|
||||
if (WIFEXITED(rc)) return WEXITSTATUS(rc);
|
||||
return -1;
|
||||
}
|
||||
|
||||
struct row {
|
||||
const char *label;
|
||||
const char *src;
|
||||
const char *textsym; /* TEXT sym containing the load */
|
||||
const char *want_imm; /* the displacement that MUST appear */
|
||||
const char *bad_imm; /* the displacement that MUST NOT appear */
|
||||
};
|
||||
|
||||
/* Field layout (registerstruct: 8B alignment for >=8B, 4B for >=4).
|
||||
* Offsets chosen so neither digit-string is a substring of the
|
||||
* other (12 vs 32) — strstr-based needle matching would otherwise
|
||||
* spuriously hit "4(BX)," inside "24(BX),".
|
||||
* beta.S = { tag1, tag2, tag3, mark: i32 } → mark foff = 12, totsize = 16
|
||||
* alpha.S = { p1, p2, p3, p4: i64, mark: i32 }
|
||||
* → mark foff = 32, totsize = 40
|
||||
*
|
||||
* Source orderings pick which module's S sits at the head of
|
||||
* c.structs after collectstructs' head-prepend walk. The LAST `type
|
||||
* S = struct ...` in source order ends at the head — that's the
|
||||
* leaf-collision the same-module-first walk must beat. */
|
||||
static const struct row rows[] = {
|
||||
{ "bare_leaf_same_module",
|
||||
"// MODULE: gamma\n"
|
||||
"use alpha;\n"
|
||||
"use beta;\n"
|
||||
"export fn main() i32 = { return 0; };\n"
|
||||
"// MODULE: beta\n"
|
||||
"type S = struct { tag1: i32, tag2: i32, tag3: i32, mark: i32, };\n"
|
||||
"export fn readbetamark(s: *S) i32 = { return s.mark; };\n"
|
||||
"// MODULE: alpha\n"
|
||||
"type S = struct { p1: i64, p2: i64, p3: i64, p4: i64, mark: i32, };\n",
|
||||
"TEXT beta.readbetamark", "12(BX),", "32(BX)," },
|
||||
/* `alpha.S` collapses into a single N_TNAME str at parse time
|
||||
* (lib/ww/parse/parse.ww joindotted), so structlookup is called
|
||||
* with "alpha.S" and falls through the new same-module-first
|
||||
* walk (no s.sname == "alpha.S") + head walk into the existing
|
||||
* embedded-dot branch (leaf="S", pkg="alpha", filter smod==pkg).
|
||||
* Pre/post-fix both pick alpha — row 2 sentinel-flips ONLY if
|
||||
* the smod==pkg filter regresses, pinning the second lookup
|
||||
* path independent of row 1's same-module-first walk. */
|
||||
{ "dot_qualified_explicit_module",
|
||||
"// MODULE: gamma\n"
|
||||
"use alpha;\n"
|
||||
"use beta;\n"
|
||||
"export fn main() i32 = { return 0; };\n"
|
||||
"// MODULE: alpha\n"
|
||||
"type S = struct { p1: i64, p2: i64, p3: i64, p4: i64, mark: i32, };\n"
|
||||
"export fn readalphamark(s: *alpha.S) i32 = { return s.mark; };\n"
|
||||
"// MODULE: beta\n"
|
||||
"type S = struct { tag1: i32, tag2: i32, tag3: i32, mark: i32, };\n",
|
||||
"TEXT alpha.readalphamark", "32(BX),", "12(BX)," },
|
||||
};
|
||||
|
||||
static int
|
||||
slurp(const char *path, char *buf, size_t cap)
|
||||
{
|
||||
FILE *f = fopen(path, "rb");
|
||||
if (!f) return -1;
|
||||
size_t n = fread(buf, 1, cap - 1, f);
|
||||
fclose(f);
|
||||
buf[n] = '\0';
|
||||
return (int)n;
|
||||
}
|
||||
|
||||
static int
|
||||
emit_s(const char *w6c, const struct row *r, int i, char *out_s, size_t cap)
|
||||
{
|
||||
char src[64], cmd[1024];
|
||||
snprintf(src, sizeof src, "/tmp/sms_%d_%d.ww", getpid(), i);
|
||||
snprintf(out_s, cap, "/tmp/sms_%d_%d_%s.s",
|
||||
getpid(), i, w6c[strlen(w6c) - 1] == 'w' ? "ww" : "c");
|
||||
|
||||
FILE *f = fopen(src, "wb");
|
||||
if (!f) return -1;
|
||||
fputs(r->src, f);
|
||||
fclose(f);
|
||||
|
||||
snprintf(cmd, sizeof cmd, "%s -o %s %s 2>/dev/null", w6c, out_s, src);
|
||||
int rc = runwait(cmd);
|
||||
unlink(src);
|
||||
return rc;
|
||||
}
|
||||
|
||||
/* Inside the named TEXT sym, before its first RET, the want_imm
|
||||
* MUST appear and the bad_imm MUST NOT. bad_imm flags pre-fix
|
||||
* head-walk picking the wrong-module S's field offset. */
|
||||
static int
|
||||
check_imm(const char *spath, const struct row *r, const char *stage)
|
||||
{
|
||||
char buf[1 << 14];
|
||||
if (slurp(spath, buf, sizeof buf) < 0) {
|
||||
fprintf(stderr, "row[%s][%s]: cannot read %s\n",
|
||||
r->label, stage, spath);
|
||||
return -1;
|
||||
}
|
||||
const char *fn = strstr(buf, r->textsym);
|
||||
if (!fn) {
|
||||
fprintf(stderr, "row[%s][%s]: no %s in %s\n",
|
||||
r->label, stage, r->textsym, spath);
|
||||
return -1;
|
||||
}
|
||||
const char *ret = strstr(fn, "\tRET");
|
||||
if (!ret) {
|
||||
fprintf(stderr, "row[%s][%s]: no RET inside %s\n",
|
||||
r->label, stage, r->textsym);
|
||||
return -1;
|
||||
}
|
||||
const char *good = strstr(fn, r->want_imm);
|
||||
if (!good || good >= ret) {
|
||||
fprintf(stderr,
|
||||
"row[%s][%s]: want_imm %s missing inside %s\n",
|
||||
r->label, stage, r->want_imm, r->textsym);
|
||||
return -1;
|
||||
}
|
||||
const char *bad = strstr(fn, r->bad_imm);
|
||||
if (bad && bad < ret) {
|
||||
fprintf(stderr,
|
||||
"row[%s][%s]: bad_imm %s present inside %s — wrong-module S\n",
|
||||
r->label, stage, r->bad_imm, r->textsym);
|
||||
return -1;
|
||||
}
|
||||
return 0;
|
||||
}
|
||||
|
||||
int
|
||||
main(void)
|
||||
{
|
||||
const char *bin = getenv("BIN");
|
||||
if (!bin) bin = "out/bin";
|
||||
char absbin[512];
|
||||
if (bin[0] != '/') {
|
||||
char cwd[256];
|
||||
if (getcwd(cwd, sizeof cwd) == NULL) return 1;
|
||||
snprintf(absbin, sizeof absbin, "%s/%s", cwd, bin);
|
||||
bin = absbin;
|
||||
}
|
||||
|
||||
char w6c[640], w6c_ww[640];
|
||||
snprintf(w6c, sizeof w6c, "%s/w6c", bin);
|
||||
snprintf(w6c_ww, sizeof w6c_ww, "%s/w6c_ww", bin);
|
||||
|
||||
int have_ww = (access(w6c_ww, X_OK) == 0);
|
||||
int n = (int)(sizeof rows / sizeof rows[0]);
|
||||
int total = 0, fail = 0;
|
||||
|
||||
for (int i = 0; i < n; i++) {
|
||||
char cs_path[128], ws_path[128];
|
||||
|
||||
if (emit_s(w6c, &rows[i], i, cs_path, sizeof cs_path) != 0) {
|
||||
fprintf(stderr,
|
||||
"struct_modshadow[cstage][%s]: w6c failed\n",
|
||||
rows[i].label);
|
||||
fail++; total++; continue;
|
||||
}
|
||||
total++;
|
||||
if (check_imm(cs_path, &rows[i], "cstage") != 0) fail++;
|
||||
|
||||
if (!have_ww) { unlink(cs_path); continue; }
|
||||
|
||||
if (emit_s(w6c_ww, &rows[i], i, ws_path, sizeof ws_path) != 0) {
|
||||
fprintf(stderr,
|
||||
"struct_modshadow[wwstage][%s]: w6c_ww failed\n",
|
||||
rows[i].label);
|
||||
fail++; total++;
|
||||
unlink(cs_path); continue;
|
||||
}
|
||||
total++;
|
||||
if (check_imm(ws_path, &rows[i], "wwstage") != 0) fail++;
|
||||
|
||||
total++;
|
||||
char cmd[512];
|
||||
snprintf(cmd, sizeof cmd, "cmp -s %s %s", cs_path, ws_path);
|
||||
if (runwait(cmd) != 0) {
|
||||
fprintf(stderr,
|
||||
"struct_modshadow[%s]: cstage vs wwstage asm differs\n",
|
||||
rows[i].label);
|
||||
fail++;
|
||||
}
|
||||
|
||||
unlink(cs_path); unlink(ws_path);
|
||||
}
|
||||
|
||||
if (fail) {
|
||||
fprintf(stderr,
|
||||
"struct_modshadow: %d/%d fixtures failed\n", fail, total);
|
||||
return 1;
|
||||
}
|
||||
printf("struct_modshadow: %d/%d ok\n", total, total);
|
||||
return 0;
|
||||
}
|
||||
Reference in New Issue
Block a user