diff --git a/Makefile b/Makefile index 359c0a68..fe37f54c 100644 --- a/Makefile +++ b/Makefile @@ -263,6 +263,7 @@ TESTS = $(BIN)/test_smoke $(BIN)/test_lex $(BIN)/test_parse $(BIN)/test_check \ $(BIN)/test_match_4arm_cross_module \ $(BIN)/test_match_4arm_cross_module_run \ $(BIN)/test_enum_modshadow \ + $(BIN)/test_struct_modshadow \ $(BIN)/test_param_shadow_mod \ $(BIN)/test_localoff_scope \ $(BIN)/test_cast_enum_movl \ @@ -613,6 +614,10 @@ $(BIN)/test_enum_modshadow: test/wcc/733_enum_modshadow.c \ $(BIN)/w6c $(BIN)/w6c_ww | $(BIN) $(CC) $(CFLAGS) -o $@ $< +$(BIN)/test_struct_modshadow: test/wcc/734_struct_modshadow.c \ + $(BIN)/w6c $(BIN)/w6c_ww | $(BIN) + $(CC) $(CFLAGS) -o $@ $< + $(BIN)/test_match_4arm_cross_module_run: test/wcc/929_match_4arm_cross_module_run.c \ $(BIN)/ww $(BIN)/w6c $(BIN)/w6a $(BIN)/w6l \ $(BIN)/ww_ww $(BIN)/w6c_ww $(BIN)/w6a_ww $(BIN)/w6l_ww \ diff --git a/selfhost/cmd/w6c/main.combined.ww b/selfhost/cmd/w6c/main.combined.ww index e96fcaab..bf4ea55f 100644 --- a/selfhost/cmd/w6c/main.combined.ww +++ b/selfhost/cmd/w6c/main.combined.ww @@ -8369,19 +8369,28 @@ export fn callsretsize(c: *cgen, n: *node) i32 = { }; fn structlookup(c: *cgen, name: str) *structinfo = { - // Exact match first: bare-from-source struct names and already- - // leafed lookups hit here directly. + // Same-module first, then any. Trio-leaf graduation mirroring + // aliaslookup (#27), fnret/fnparamslookupmod (#28/#31), and + // enumlookup (#4a): without the prefer pass a bare-leaf struct + // name in module M can collapse onto another module's same-leaf + // struct prepended earlier in c.structs, silently picking the + // wrong totsize / field offsets. let s: *structinfo = c.structs; + for (s != nil) { + if (streq(s.sname, name)) { + if (streq(s.smod, c.curmod)) { return s; }; + }; + s = s.sinext; + }; + s = c.structs; for (s != nil) { let sn: str = s.sname; if (streq(sn, name)) { return s; }; s = s.sinext; }; - // Module-qualified form: `pkg.S` → match the leaf scoped to its - // originating module. Mirrors aliaslookup's mod-filter; the - // `smod == pkg` guard is what prevents two modules with same- - // leaf-name structs from collapsing into whichever entry appears - // first in the chain. + // Module-qualified form embedded in name (`pkg.S`): scope the + // leaf to its originating module. The `smod == pkg` guard + // prevents same-leaf structs in two modules from collapsing. let i: i32 = name.len - 1; for (i >= 0) { if (name[i] == 46u8) { // '.' diff --git a/selfhost/cmd/wcc/cgenutil.ww b/selfhost/cmd/wcc/cgenutil.ww index 37597951..b6b9a2d9 100644 --- a/selfhost/cmd/wcc/cgenutil.ww +++ b/selfhost/cmd/wcc/cgenutil.ww @@ -1430,19 +1430,28 @@ export fn callsretsize(c: *cgen, n: *node) i32 = { }; fn structlookup(c: *cgen, name: str) *structinfo = { - // Exact match first: bare-from-source struct names and already- - // leafed lookups hit here directly. + // Same-module first, then any. Trio-leaf graduation mirroring + // aliaslookup (#27), fnret/fnparamslookupmod (#28/#31), and + // enumlookup (#4a): without the prefer pass a bare-leaf struct + // name in module M can collapse onto another module's same-leaf + // struct prepended earlier in c.structs, silently picking the + // wrong totsize / field offsets. let s: *structinfo = c.structs; + for (s != nil) { + if (streq(s.sname, name)) { + if (streq(s.smod, c.curmod)) { return s; }; + }; + s = s.sinext; + }; + s = c.structs; for (s != nil) { let sn: str = s.sname; if (streq(sn, name)) { return s; }; s = s.sinext; }; - // Module-qualified form: `pkg.S` → match the leaf scoped to its - // originating module. Mirrors aliaslookup's mod-filter; the - // `smod == pkg` guard is what prevents two modules with same- - // leaf-name structs from collapsing into whichever entry appears - // first in the chain. + // Module-qualified form embedded in name (`pkg.S`): scope the + // leaf to its originating module. The `smod == pkg` guard + // prevents same-leaf structs in two modules from collapsing. let i: i32 = name.len - 1; for (i >= 0) { if (name[i] == 46u8) { // '.' diff --git a/selfhost/cmd/wwdump/main.combined.ww b/selfhost/cmd/wwdump/main.combined.ww index f40ba114..e6de7536 100644 --- a/selfhost/cmd/wwdump/main.combined.ww +++ b/selfhost/cmd/wwdump/main.combined.ww @@ -8369,19 +8369,28 @@ export fn callsretsize(c: *cgen, n: *node) i32 = { }; fn structlookup(c: *cgen, name: str) *structinfo = { - // Exact match first: bare-from-source struct names and already- - // leafed lookups hit here directly. + // Same-module first, then any. Trio-leaf graduation mirroring + // aliaslookup (#27), fnret/fnparamslookupmod (#28/#31), and + // enumlookup (#4a): without the prefer pass a bare-leaf struct + // name in module M can collapse onto another module's same-leaf + // struct prepended earlier in c.structs, silently picking the + // wrong totsize / field offsets. let s: *structinfo = c.structs; + for (s != nil) { + if (streq(s.sname, name)) { + if (streq(s.smod, c.curmod)) { return s; }; + }; + s = s.sinext; + }; + s = c.structs; for (s != nil) { let sn: str = s.sname; if (streq(sn, name)) { return s; }; s = s.sinext; }; - // Module-qualified form: `pkg.S` → match the leaf scoped to its - // originating module. Mirrors aliaslookup's mod-filter; the - // `smod == pkg` guard is what prevents two modules with same- - // leaf-name structs from collapsing into whichever entry appears - // first in the chain. + // Module-qualified form embedded in name (`pkg.S`): scope the + // leaf to its originating module. The `smod == pkg` guard + // prevents same-leaf structs in two modules from collapsing. let i: i32 = name.len - 1; for (i >= 0) { if (name[i] == 46u8) { // '.' diff --git a/test/wcc/734_struct_modshadow.c b/test/wcc/734_struct_modshadow.c new file mode 100644 index 00000000..7e00cb96 --- /dev/null +++ b/test/wcc/734_struct_modshadow.c @@ -0,0 +1,247 @@ +/* + * 734_struct_modshadow — sentinel for the trio leaf-name pattern's + * 5th leaf: wwstage's structlookup. Pins bare-leaf `*S` field access + * to a same-module-first walk so the load picks the caller's own + * `S` (correct field offset / totsize) rather than another module's + * same-leaf-name `S` sitting at the head of c.structs. + * + * Pre-fix wwstage's `structlookup` (selfhost/cmd/wcc/cgenutil.ww) + * walked c.structs head-first by sname, returning the FIRST match. + * The cgdot `*struct` field-load branch handed it `inner.str` (the + * bare leaf from a parsed N_TPTR whose inner is N_TNAME) and the + * head-pick silently emitted the wrong-module field offset — a + * displacement against BX that loaded whatever the colliding-module + * struct happened to align there. Silent miscompile, not byte-id: + * cstage's resolve_typename uses scope_lookup_prefer(cur, cur_mod, + * leaf) so check.c already binds the correct Type, and cgen.c reads + * fi.foff off the typed Sym — cs vs ws asm diverged on every bare- + * leaf collision but no in-tree corpus declares two same-leaf + * structs, so 995 stayed green and the latent miscompile only + * surfaces once a stdlib port introduces the collision (same shape + * as #4a enumlookup surfacing post-strings). + * + * Trio's structural close per task #4 leaves: structlookup grows a + * same-module-first walk before the head-walk fallback, mirroring + * aliaslookup (#27), fnparamslookupmod (#28), fnretlookupmod (#31) + * and enumlookup (#4a). NO structlookupmod variant: the consumer + * surface for `pkg.S` is fully captured by the parser collapsing + * dotted N_TNAME into a single str with embedded `.`, which routes + * through structlookup's existing smod==pkg embedded-dot branch. + * Cstage carries no sister bug — resolve_typename already routes + * the bare-leaf TY_STRUCT name through scope_lookup_prefer per + * c->cur_mod (cmd/wcc/check.c:60). + * + * Asserts the post-fix field-offset land inside the matching TEXT + * sym on BOTH stages and that cs vs ws stay byte-identical on each + * row. Row 1 sentinel-flips this commit's new same-module-first + * walk (revert the structlookup change → row 1 fails on wwstage + * + cs-vs-ws diff). Row 2 exercises the pre-existing embedded-dot + * smod==pkg branch (unchanged here) — defensive coverage that + * guards the second structlookup path against future regression; + * does not sentinel-flip on this commit's change. + */ +#include +#include +#include +#include +#include + +static int +runwait(const char *cmd) +{ + int rc = system(cmd); + if (rc == -1) return -1; + if (WIFEXITED(rc)) return WEXITSTATUS(rc); + return -1; +} + +struct row { + const char *label; + const char *src; + const char *textsym; /* TEXT sym containing the load */ + const char *want_imm; /* the displacement that MUST appear */ + const char *bad_imm; /* the displacement that MUST NOT appear */ +}; + +/* Field layout (registerstruct: 8B alignment for >=8B, 4B for >=4). + * Offsets chosen so neither digit-string is a substring of the + * other (12 vs 32) — strstr-based needle matching would otherwise + * spuriously hit "4(BX)," inside "24(BX),". + * beta.S = { tag1, tag2, tag3, mark: i32 } → mark foff = 12, totsize = 16 + * alpha.S = { p1, p2, p3, p4: i64, mark: i32 } + * → mark foff = 32, totsize = 40 + * + * Source orderings pick which module's S sits at the head of + * c.structs after collectstructs' head-prepend walk. The LAST `type + * S = struct ...` in source order ends at the head — that's the + * leaf-collision the same-module-first walk must beat. */ +static const struct row rows[] = { + { "bare_leaf_same_module", + "// MODULE: gamma\n" + "use alpha;\n" + "use beta;\n" + "export fn main() i32 = { return 0; };\n" + "// MODULE: beta\n" + "type S = struct { tag1: i32, tag2: i32, tag3: i32, mark: i32, };\n" + "export fn readbetamark(s: *S) i32 = { return s.mark; };\n" + "// MODULE: alpha\n" + "type S = struct { p1: i64, p2: i64, p3: i64, p4: i64, mark: i32, };\n", + "TEXT beta.readbetamark", "12(BX),", "32(BX)," }, + /* `alpha.S` collapses into a single N_TNAME str at parse time + * (lib/ww/parse/parse.ww joindotted), so structlookup is called + * with "alpha.S" and falls through the new same-module-first + * walk (no s.sname == "alpha.S") + head walk into the existing + * embedded-dot branch (leaf="S", pkg="alpha", filter smod==pkg). + * Pre/post-fix both pick alpha — row 2 sentinel-flips ONLY if + * the smod==pkg filter regresses, pinning the second lookup + * path independent of row 1's same-module-first walk. */ + { "dot_qualified_explicit_module", + "// MODULE: gamma\n" + "use alpha;\n" + "use beta;\n" + "export fn main() i32 = { return 0; };\n" + "// MODULE: alpha\n" + "type S = struct { p1: i64, p2: i64, p3: i64, p4: i64, mark: i32, };\n" + "export fn readalphamark(s: *alpha.S) i32 = { return s.mark; };\n" + "// MODULE: beta\n" + "type S = struct { tag1: i32, tag2: i32, tag3: i32, mark: i32, };\n", + "TEXT alpha.readalphamark", "32(BX),", "12(BX)," }, +}; + +static int +slurp(const char *path, char *buf, size_t cap) +{ + FILE *f = fopen(path, "rb"); + if (!f) return -1; + size_t n = fread(buf, 1, cap - 1, f); + fclose(f); + buf[n] = '\0'; + return (int)n; +} + +static int +emit_s(const char *w6c, const struct row *r, int i, char *out_s, size_t cap) +{ + char src[64], cmd[1024]; + snprintf(src, sizeof src, "/tmp/sms_%d_%d.ww", getpid(), i); + snprintf(out_s, cap, "/tmp/sms_%d_%d_%s.s", + getpid(), i, w6c[strlen(w6c) - 1] == 'w' ? "ww" : "c"); + + FILE *f = fopen(src, "wb"); + if (!f) return -1; + fputs(r->src, f); + fclose(f); + + snprintf(cmd, sizeof cmd, "%s -o %s %s 2>/dev/null", w6c, out_s, src); + int rc = runwait(cmd); + unlink(src); + return rc; +} + +/* Inside the named TEXT sym, before its first RET, the want_imm + * MUST appear and the bad_imm MUST NOT. bad_imm flags pre-fix + * head-walk picking the wrong-module S's field offset. */ +static int +check_imm(const char *spath, const struct row *r, const char *stage) +{ + char buf[1 << 14]; + if (slurp(spath, buf, sizeof buf) < 0) { + fprintf(stderr, "row[%s][%s]: cannot read %s\n", + r->label, stage, spath); + return -1; + } + const char *fn = strstr(buf, r->textsym); + if (!fn) { + fprintf(stderr, "row[%s][%s]: no %s in %s\n", + r->label, stage, r->textsym, spath); + return -1; + } + const char *ret = strstr(fn, "\tRET"); + if (!ret) { + fprintf(stderr, "row[%s][%s]: no RET inside %s\n", + r->label, stage, r->textsym); + return -1; + } + const char *good = strstr(fn, r->want_imm); + if (!good || good >= ret) { + fprintf(stderr, + "row[%s][%s]: want_imm %s missing inside %s\n", + r->label, stage, r->want_imm, r->textsym); + return -1; + } + const char *bad = strstr(fn, r->bad_imm); + if (bad && bad < ret) { + fprintf(stderr, + "row[%s][%s]: bad_imm %s present inside %s — wrong-module S\n", + r->label, stage, r->bad_imm, r->textsym); + return -1; + } + return 0; +} + +int +main(void) +{ + const char *bin = getenv("BIN"); + if (!bin) bin = "out/bin"; + char absbin[512]; + if (bin[0] != '/') { + char cwd[256]; + if (getcwd(cwd, sizeof cwd) == NULL) return 1; + snprintf(absbin, sizeof absbin, "%s/%s", cwd, bin); + bin = absbin; + } + + char w6c[640], w6c_ww[640]; + snprintf(w6c, sizeof w6c, "%s/w6c", bin); + snprintf(w6c_ww, sizeof w6c_ww, "%s/w6c_ww", bin); + + int have_ww = (access(w6c_ww, X_OK) == 0); + int n = (int)(sizeof rows / sizeof rows[0]); + int total = 0, fail = 0; + + for (int i = 0; i < n; i++) { + char cs_path[128], ws_path[128]; + + if (emit_s(w6c, &rows[i], i, cs_path, sizeof cs_path) != 0) { + fprintf(stderr, + "struct_modshadow[cstage][%s]: w6c failed\n", + rows[i].label); + fail++; total++; continue; + } + total++; + if (check_imm(cs_path, &rows[i], "cstage") != 0) fail++; + + if (!have_ww) { unlink(cs_path); continue; } + + if (emit_s(w6c_ww, &rows[i], i, ws_path, sizeof ws_path) != 0) { + fprintf(stderr, + "struct_modshadow[wwstage][%s]: w6c_ww failed\n", + rows[i].label); + fail++; total++; + unlink(cs_path); continue; + } + total++; + if (check_imm(ws_path, &rows[i], "wwstage") != 0) fail++; + + total++; + char cmd[512]; + snprintf(cmd, sizeof cmd, "cmp -s %s %s", cs_path, ws_path); + if (runwait(cmd) != 0) { + fprintf(stderr, + "struct_modshadow[%s]: cstage vs wwstage asm differs\n", + rows[i].label); + fail++; + } + + unlink(cs_path); unlink(ws_path); + } + + if (fail) { + fprintf(stderr, + "struct_modshadow: %d/%d fixtures failed\n", fail, total); + return 1; + } + printf("struct_modshadow: %d/%d ok\n", total, total); + return 0; +}