Files
ww/lib/memio/memio.ww
Hojun-Cho 47918d3ced lib: drop _unsafe convention; rename fromutf8_unsafe → frombytes; strings α-batch (concat/join/lpad/rpad)
CLAUDE.md rule 9 amended with the explicit carve-out: ww is C/Plan-9-
lineage — no GC, no "safe" baseline to be unsafe relative to — so the
Hare `_unsafe` suffix flags an axis ww doesn't have. The convention
is dropped wholesale in lib/.

Concrete changes:
- lib/strings: `fromutf8_unsafe` → `frombytes` (pure reinterpret). The
  validating sibling `fromutf8` is deleted entirely (28 lines, plus its
  84-line fromutf8_cases test). Callers that need validation write the
  two lines inline at the IO source: `utf8.validate(b)?;
  let s = strings.frombytes(b);`. `fromutf8` name reserved for a future
  true validating helper.
- lib/strings α-batch: concat/join/lpad/rpad migrate from
  `rt.malloc(N): *u8` to `alloc([], N)!` + `buf.len = N;` +
  `return frombytes(buf);`. Same dup-pilot pattern (4c07ef0). Task #41.
- lib/memio header comment trimmed: drops a stale reference to
  "lib has no fromutf8 today"; cites the rule-9 carve-out instead.
- Caller renames across selfhost combined.ww files (auto-regen) +
  cgenutil.ww comment ref.

Rule-11 disclosure on the bundle: the rename and the α-batch are
nominally separable concerns (symbol-naming policy vs amalloc→
alloc-slice migration), but they touch the same 4 functions in
lib/strings/strings.ww — the α-batch's first emission of `frombytes`
postdates the rename. The α-batch was applied on top of the rename
sweep mid-flight by the pre-commit reviewer; splitting them back
out is fiddly text surgery for marginal bisect value. The rename is
the primary concern; α-batch is one entry in #8's sized-slice
migration.

Verified: make test 132/132, 995_self_rebuild byte-identity holds.
Closes #42; advances #41.
2026-05-21 00:35:14 +09:00

210 lines
5.7 KiB
Plaintext

// memio — in-memory io stream.
//
// Hare's memio:: surface, drop underscores. Two flavours behind a
// single [[io.stream]]:
//
// fixed caller owns the buffer, writes stop when full.
// dynamic memio owns the buffer, writes grow it; close frees.
//
// Call shape divergence from Hare: the caller supplies both the
// memio `state` and the `io.stream` slot, by pointer. ww cgen does
// not yet implement &x.field or 32B-struct return-by-value, so the
// Hare `let s = memio::fixed(buf)` shape isn't reachable; collapse
// to a single returned struct when those land (lib/CLAUDE.md
// "graduate in one go").
//
// let mem: memio.state;
// let s: io.stream;
// memio.fixed(&mem, &s, buf);
// io.write(&s, bytes);
//
// Subset of Hare's surface: io.stream's variants are {eof, closed},
// so memio drops Hare's NONBLOCK flag (would need an `again` variant
// in lib/io). string()'s utf8-validating constructor is omitted per
// CLAUDE.md rule 9 carve-out. Hare's seek / copy callbacks are
// likewise absent: lib/io's stream vtable has only read/write/close
// slots, so memio can't wire a seeker or copier even if we wanted
// to. All three come back when their dependencies do.
package memio;
import io;
import os;
import rt;
// state — memio's per-stream bookkeeping. The caller owns the slot
// and passes its address into a constructor. `ptr/len/cap` are the
// slice fields kept flat to dodge a chained-dot write through the
// state pointer (cgen doesn't store into `m.buf.ptr` reliably).
export type state = struct {
ptr: *u8,
len: i32,
cap: i32,
pos: i32,
};
// fixed — wire `s` over a caller-supplied buffer. Writes never grow;
// they return 0 once `pos` reaches the end of the buffer.
export fn fixed(m: *state, s: *io.stream, buf: []u8) void = {
m.ptr = buf.ptr;
m.len = buf.len;
m.cap = buf.len;
m.pos = 0;
s.ctx = m: *void;
s.read = readfn;
s.write = fixedwrite;
s.close = closenoop;
};
// dynamic — wire `s` with no initial buffer. Writes grow the backing
// allocation; [[io.close]] frees it.
export fn dynamic(m: *state, s: *io.stream) void = {
m.ptr = nil;
m.len = 0;
m.cap = 0;
m.pos = 0;
s.ctx = m: *void;
s.read = readfn;
s.write = dynamicwrite;
s.close = dynamicclose;
};
// dynamicfrom — like [[dynamic]] but seeded with an existing slice.
// Ownership of the slice transfers to the stream; [[io.close]] frees
// it. The slice must come from the runtime allocator: close calls
// [[os.free]] with `m.cap` bytes, which is taken from `buf.cap` (the
// slice's allocated capacity), not its logical length. Passing a
// half-filled append slice (len < cap) and using only `buf.len` here
// would under-free on close.
export fn dynamicfrom(m: *state, s: *io.stream, buf: []u8) void = {
m.ptr = buf.ptr;
m.len = buf.len;
m.cap = buf.cap;
m.pos = 0;
s.ctx = m: *void;
s.read = readfn;
s.write = dynamicwrite;
s.close = dynamicclose;
};
// buffer — borrowed view of bytes written so far (buf[..pos]).
// Seek to the end before calling if the full buffer is wanted.
export fn buffer(m: *state) []u8 = {
let r: []u8;
r.ptr = m.ptr;
r.len = m.pos;
return r;
};
// string — bytes written so far, as a str view. Hare returns
// (str | utf8::invalid); ww doesn't ship utf8 validation yet, so
// this returns the unchecked view.
export fn string(m: *state) str = {
let r: str;
r.ptr = m.ptr;
r.len = m.pos;
return r;
};
// reset — rewind the cursor and truncate the logical content to 0.
// Backing storage is preserved; subsequent writes (dynamic) re-fill
// from the start without reallocation.
export fn reset(m: *state) void = {
m.pos = 0;
m.len = 0;
};
// borrowedread — return an `amt`-byte view starting at `pos` without
// copying, advancing the cursor. eof if fewer bytes are available.
export fn borrowedread(m: *state, amt: i32) ([]u8 | io.eof) = {
if (m.len - m.pos < amt) {
let e: io.eof;
return e;
};
let r: []u8;
r.ptr = m.ptr + (m.pos: u64);
r.len = amt;
m.pos += amt;
return r;
};
// ---- vtable callbacks ------------------------------------------------
fn readfn(s: *io.stream, buf: []u8) (i32 | io.eof | io.closed) = {
let m: *state = s.ctx: *state;
if (m.pos >= m.len) {
let e: io.eof;
return e;
};
let avail: i32 = m.len - m.pos;
let n: i32 = buf.len;
if (avail < n) { n = avail; };
let i: i32 = 0;
for (i < n) {
buf[i] = m.ptr[m.pos + i];
i += 1;
};
m.pos += n;
return n;
};
fn fixedwrite(s: *io.stream, buf: []u8) (i32 | io.closed) = {
let m: *state = s.ctx: *state;
if (m.pos >= m.len) { return 0; };
let space: i32 = m.len - m.pos;
let n: i32 = buf.len;
if (space < n) { n = space; };
let i: i32 = 0;
for (i < n) {
m.ptr[m.pos + i] = buf[i];
i += 1;
};
m.pos += n;
return n;
};
fn dynamicwrite(s: *io.stream, buf: []u8) (i32 | io.closed) = {
let m: *state = s.ctx: *state;
let need: i32 = m.pos + buf.len;
if (need > m.cap) { grow(m, need); };
let i: i32 = 0;
for (i < buf.len) {
m.ptr[m.pos + i] = buf[i];
i += 1;
};
m.pos += buf.len;
if (m.pos > m.len) { m.len = m.pos; };
return buf.len;
};
fn dynamicclose(s: *io.stream) (void | io.closed) = {
let m: *state = s.ctx: *state;
if (m.cap > 0) { os.free(m.ptr: *void, m.cap: u64); };
m.ptr = nil;
m.len = 0;
m.cap = 0;
m.pos = 0;
return;
};
fn closenoop(s: *io.stream) (void | io.closed) = {
return;
};
// Double-and-copy growth. Initial bump from 0 lands at 8 to amortise
// small write bursts without a tail of reallocs.
fn grow(m: *state, need: i32) void = {
let newcap: i32 = m.cap;
if (newcap < 8) { newcap = 8; };
for (newcap < need) { newcap *= 2; };
let nbuf: *u8 = rt.malloc(newcap: u64): *u8;
let i: i32 = 0;
for (i < m.len) {
nbuf[i] = m.ptr[i];
i += 1;
};
if (m.cap > 0) { os.free(m.ptr: *void, m.cap: u64); };
m.ptr = nbuf;
m.cap = newcap;
};