Hare's canonical runtime allocator is rt::malloc with linker symbol
rt.malloc (ref/hare/rt/malloc.ha:27,78). ww kept the dot→underscore
Plan 9 convention (CLAUDE.md rule 4) so the linker symbol becomes
rt_malloc; the lib/rt exported function name becomes malloc; ww
callers say rt.malloc(...).
The language builtin keyword stays `alloc(T)!` — unchanged from Hare
(ref/hare/hare/lex/token.ha:21 ltok::ALLOC, parse/expr.ha:398
builtin()). The rename only touches the lowered linker symbol and the
exported function name behind it; the user-facing syntax for
heap-allocation is identical to Hare.
Surface:
- rt/alloc.s: TEXT rt_alloc → TEXT rt_malloc, labels updated
- lib/rt/malloc.ww: @symbol("rt_malloc") fn malloc(...) (was rt_alloc/alloc)
- rt/ensure.ww: local FFI decl + call site updated to malloc; `!` dropped
on the direct FFI call (rt_malloc returns *void, not a tagged union)
- 18 .ww callers: rt.alloc(...) → rt.malloc(...)
- cstage cmd/wcc/check.c + wwstage selfhost/cmd/wcc/check.ww
alloc-builtin suppression gate routes through ffi_resolve("malloc")
for the lowering; the user-shadow check still keys on the BUILTIN
KEYWORD "alloc" since that is what `alloc(...)` parses as. Adding
"malloc" to the user-shadow check was unnecessary and was reverted
during pre-commit review.
- cstage cmd/w6c/cgen.c: 2× ffi_resolve("alloc") → ffi_resolve("malloc")
- wwstage cgenexpr/cgenstmt: 2× ffiresolve(c, "alloc") → ffiresolve(c, "malloc")
- Test fixtures (700_e2e, 758_cgalloc_str_field, 990_selfhost, 992_w6l_ww,
selfhost/test/tagged_ptr_ret.ww): updated inline ww sources to the new
decl + call form
This is commit 2 of 3 in the lib/rt extraction (#38). Commit 3 closes
the OOM contract — return type becomes nullable *void and the builtin
lowering null-checks + propagates nomem.
Verified 132/132 + 995_self_rebuild byte-identity (5 wwstage tools
round-trip identical) + make clean cold rebuild.
23 lines
1.2 KiB
Plaintext
23 lines
1.2 KiB
Plaintext
// rt — runtime primitives exposed to ww programs.
|
|
// Mirrors Hare's rt:: module placement (ref/hare/rt/).
|
|
|
|
package rt;
|
|
|
|
// malloc — mmap-backed page allocator. Untyped: `malloc(n)` returns a
|
|
// `*void`; callers cast to the target type. Diverges from Hare: Hare
|
|
// exposes `alloc` / `free` as typed language builtins that the
|
|
// compiler lowers to rt::malloc/rt::free; ww has no such builtins,
|
|
// so the rt-symbol surface is exposed directly. Stdlib callers that
|
|
// need a typed allocation pattern wrap this with a cast plus a stored
|
|
// capacity (see [[strings.dup]], [[memio.dynamic]]).
|
|
//
|
|
// OOM: rt_malloc is a bare mmap(MAP_ANON|MAP_PRIVATE) wrapper with no
|
|
// error path. The raw Linux mmap syscall returns a negative errno cast
|
|
// to `*void` on failure (e.g. `(void*)-12` for ENOMEM); the
|
|
// `MAP_FAILED` (`(void*)-1`) value is a libc-wrapper convention that
|
|
// rt_malloc doesn't apply. Neither `== nil` nor `== (void*)-1` catches
|
|
// it; any deref of such a return faults. Today the stdlib does not
|
|
// check; OOM faults on first dereference. A typed fallible variant is
|
|
// a future task (task #39). ref/hare/rt/malloc.ha:27.
|
|
@symbol("rt_malloc") export fn malloc(n: u64) *void;
|