Files
ww/test/wcc/835_nested_union_int_box.c
Hojun-Cho ce3a25a0b4 test: contain sepwork scratch per-driver tmpdir, fix /tmp+in-repo leak (#8)
The wcc test drivers ran `ww build <bare-/tmp src>` with no -o, so the
compiler's <stem>.sepwork scratch landed beside the source and was never
cleaned: unbounded /tmp growth (2195 stale dirs observed) that fills tmpfs
and fabricates phantom test failures + silent harness aborts, and for
in-repo fixture builds leaked .sepwork into the tracked tree.

Each leaking build now writes its source + output inside a per-invocation
tmpdir, passes -o <tmpdir>/<stem> so the .sepwork lands inside it, and
rm -rf's the tmpdir on every exit path -- including fopen-fail and the
expected-fail reject builds (scratch is mkdir'd before the build can fail).
`ww run` and explicit-`-o`/byte-id helpers are left as-is; the 990/993
byte-id comparison logic is byte-for-byte unchanged.

Two items filed separately (this commit holds the no-Makefile / no-main.c
rail):
- #13: a stale <src>.s byte-id readback (749) silently no-ops since
  separate-compile emits .s to <ostem>.sepwork/__root.s; documented inline.
- #14: build-system Makefile recipes build selfhost/cmd/*/main.ww with no
  -o and leak main.sepwork in-tree (bounded, gitignored; own commit).

One concern -- sepwork leak hygiene -- across 228 drivers; uniform
transform applied per-file and two-round reviewed. make test: all 402
passed, zero net-new /tmp scratch, zero test-driven in-repo .sepwork.
2026-06-22 23:29:39 +09:00

284 lines
9.6 KiB
C

/*
* 835_nested_union_int_box — two reject-align fixes in the nested-union /
* widen-subset family. Both close SILENT wwstage miscompiles by aligning
* ww DOWN to cstage's existing loud.
*
* #23 (drew spec .ai/drew-23-spec.md) — a bare untyped-int return/assign
* into a tagged union with NO DIRECT variant able to hold an int (the int
* is reachable only via a NESTED union, or no slot exists at all). ww's
* isuntypedint tagged sub-loop fell through to a permissive `*confident=
* false; return true;` so the caller never flagged it — ww silently built
* a tag=0/payload box with no inner-tag wrapper (malformed). The fix:
* confident-reject when no direct variant is numeric-or-enum (mirror
* cstage type.c:343 `return 0`), routing through errnotassign. An ENUM
* variant is kept ACCEPTED (new N_TENUM check, mirrors cstage type_isnum
* (enum)=true) — A3 is the trap: dropping it would flip an enum-variant
* union to reject while cstage accepts. wwstage-ONLY; check.c unchanged.
*
* S1 / #35 (ken census .ai/miscompile-census.md) — a widen-SUBSET cast in
* a tagged construct: `return true: inner` where inner=(int|bool) boxed
* into outer=(int|bool|str). The cast target is a TAGGED union that is NOT
* dst, and the inner-variant tag is never remapped to dst's index, so ww
* cgen's scalar arm emitted tag=0 — running the int arm on a bool value
* (census S1 returned 70, expected 11). cstage loud-stops at cgen.c:2721-
* 2723 (#35). wwstage gains the twin in cgwidentaggedstorebp (cgenutil.ww).
* A 2ND-VARIANT value (bool) is mandatory: `5:inner` is benign (int is
* variant 0 in both, tag 0 coincidentally right). Faithful inner->outer
* tag remap = the #23/#40 widen-subset feature, deferred post-CSP.
*
* neg row | shape | gate
* -------------+------------------------------------------------+------
* R1_nested | inner=(int|bool); outer=(inner|str); ret 5 | FAIL
* R2_noslot | u=(str|bool); ret 5 | FAIL
* R3_struct | A=struct{v:int}; u=(A|str); ret 5 | FAIL
* S1_subcast | return true: inner (inner=(int|bool)->outer) | FAIL
*
* pos row | shape | want
* -------------+------------------------------------------------+------
* A1_direct | u=(int|str); ret 5; match int -> n | 5
* A2_aliased | myint=int; u=(myint|str); ret 5 | 0
* A3_enum | col=enum{RED,GREEN}; u=(col|str); ret 5 [trap] | 0
* A4_unionsrc | outer=(inner|str); mk(x:inner) outer = x | 0
* A5_subset | sub=(int|uint); sup=(int|uint|str); ret x | 0
*
* Diagnostic TEXT is byte-id-blind (#23 routes through errnotassign "not
* assignable"; S1 emits the #35 line); both stages REJECT and emit no asm.
* selfhost has no such construct, so 990-997 byte-id is untouched.
*/
#include <stdio.h>
#include <stdlib.h>
#include <unistd.h>
#include <sys/stat.h>
#include <sys/wait.h>
static int
runwait(const char *cmd)
{
int rc = system(cmd);
if (rc == -1) return -1;
if (WIFEXITED(rc)) return WEXITSTATUS(rc);
return -1;
}
struct row { const char *label; const char *src; int want; };
static const struct row rows[] = {
/* A1 — direct numeric variant; live runtime proof the accept path
* still builds a correct box (match int -> return 5). */
{ "A1_direct",
"package main;\n"
"type u = (int | str);\n"
"fn mk() u = { return 5; };\n"
"export fn main() i32 = {\n"
"\tlet v = mk();\n"
"\tmatch (v) {\n"
"\tcase let n: int => return n: i32;\n"
"\tcase str => return 1;\n"
"\t};\n"
"\treturn 9;\n"
"};\n",
5 },
/* A2 — aliased numeric variant (resolvealias -> int). Compile-only:
* main returns 0; the accept is proven by the build succeeding. */
{ "A2_aliased",
"package main;\n"
"type myint = int;\n"
"type u = (myint | str);\n"
"fn mk() u = { return 5; };\n"
"export fn main() i32 = { return 0; };\n",
0 },
/* A3 — enum variant (the trap): the N_TENUM accept keeps this legal,
* mirroring cstage type_isnum(enum). Compile-only. */
{ "A3_enum",
"package main;\n"
"type col = enum { RED, GREEN };\n"
"type u = (col | str);\n"
"fn mk() u = { return 5; };\n"
"export fn main() i32 = { return 0; };\n",
0 },
/* A4 — src is a UNION (inner), not an untyped int -> never enters the
* int arm; tagged->tagged direct-variant accept. Compile-only. */
{ "A4_unionsrc",
"package main;\n"
"type inner = (int | bool);\n"
"type outer = (inner | str);\n"
"fn mk(x: inner) outer = { return x; };\n"
"export fn main() i32 = { return 0; };\n",
0 },
/* A5 — proper-subset union widen, src union. Compile-only. */
{ "A5_subset",
"package main;\n"
"type sub = (int | uint);\n"
"type sup = (int | uint | str);\n"
"fn w(x: sub) sup = { return x; };\n"
"export fn main() i32 = { return 0; };\n",
0 },
};
/* Each neg must FAIL the build on both stages (loud reject). */
static const char *neg[] = {
/* R1 — #23 canonical: int reachable only via a NESTED union. */
"package main;\n"
"type inner = (int | bool);\n"
"type outer = (inner | str);\n"
"fn mk() outer = { return 5; };\n"
"export fn main() i32 = { return 0; };\n",
/* R2 — no slot for an int at all (same fallthrough). */
"package main;\n"
"type u = (str | bool);\n"
"fn mk() u = { return 5; };\n"
"export fn main() i32 = { return 0; };\n",
/* R3 — int fits no variant (struct | str). */
"package main;\n"
"type A = struct { v: int };\n"
"type u = (A | str);\n"
"fn mk() u = { return 5; };\n"
"export fn main() i32 = { return 0; };\n",
/* S1 / #35 — widen-SUBSET cast in a RETURN, 2nd-variant (bool) value
* (census sx4). ww cgen's cgreturn formerly skipped the widener for an
* N_CAST-tagged source (needswiden=false) -> plain cgexpr -> tag=0
* SILENT (ran the int arm -> 70, want 11). Now the genuine-widening
* (ru!=fnret) needswiden arm routes it through cgwidentaggedstore ->
* the #35 widen-subset loud-stop. Both stages reject. */
"package main;\n"
"type inner = (int | bool);\n"
"type outer = (int | bool | str);\n"
"fn mk() outer = { return true: inner; };\n"
"export fn main() i32 = {\n"
"\tlet v = mk();\n"
"\tmatch (v) {\n"
"\tcase let n: int => return 70;\n"
"\tcase let b: bool => return 11;\n"
"\tcase let s: str => return 22;\n"
"\t};\n"
"\treturn 99;\n"
"};\n",
};
static int
run_driver(const char *driver, const struct row *r, int i)
{
char tmpdir[64], src[128], outbin[128], rmcmd[160], cmd[1024];
snprintf(tmpdir, sizeof tmpdir, "/tmp/nui_%d_d_%d", getpid(), i);
mkdir(tmpdir, 0755);
snprintf(src, sizeof src, "%s/nui_%d_%d.ww", tmpdir, getpid(), i);
snprintf(outbin, sizeof outbin, "%s/nui_%d_%d", tmpdir, getpid(), i);
snprintf(rmcmd, sizeof rmcmd, "rm -rf %s", tmpdir);
FILE *f = fopen(src, "wb");
if (!f) { runwait(rmcmd); return -1; }
fputs(r->src, f);
fclose(f);
snprintf(cmd, sizeof cmd, "%s build -o %s %s 2>/dev/null",
driver, outbin, src);
if (runwait(cmd) != 0) {
fprintf(stderr, "row[%s]: build via %s failed\n",
r->label, driver);
runwait(rmcmd);
return -1;
}
int got = runwait(outbin);
runwait(rmcmd);
return got;
}
/* build_should_fail — the construct must error on `driver`; returns 0 when
* the build correctly FAILS, non-zero when it wrongly succeeded. */
static int
build_should_fail(const char *driver, const char *src, int i)
{
char tmpdir[64], s[128], outbin[128], rmcmd[160], cmd[1024];
snprintf(tmpdir, sizeof tmpdir, "/tmp/nuin_%d_d_%d", getpid(), i);
mkdir(tmpdir, 0755);
snprintf(s, sizeof s, "%s/nuin_%d_%d.ww", tmpdir, getpid(), i);
snprintf(outbin, sizeof outbin, "%s/nuin_%d_%d", tmpdir, getpid(), i);
snprintf(rmcmd, sizeof rmcmd, "rm -rf %s", tmpdir);
FILE *f = fopen(s, "wb");
if (!f) { runwait(rmcmd); return -1; }
fputs(src, f);
fclose(f);
snprintf(cmd, sizeof cmd, "%s build -o %s %s 2>/dev/null",
driver, outbin, s);
int rc = runwait(cmd);
runwait(rmcmd);
return rc == 0 ? -1 : 0; /* build must NOT succeed */
}
int
main(void)
{
const char *bin = getenv("BIN");
if (!bin) bin = "out/bin";
char absbin[1024];
if (bin[0] != '/') {
char cwd[1024];
if (getcwd(cwd, sizeof cwd) == NULL) return 1;
snprintf(absbin, sizeof absbin, "%s/%s", cwd, bin);
bin = absbin;
}
char cdrv[1024];
snprintf(cdrv, sizeof cdrv, "%s/ww", bin);
char wdrv[1024];
snprintf(wdrv, sizeof wdrv, "%s/ww_ww", bin);
struct { const char *name; const char *path; int gated_on_existence; }
drivers[] = {
{ "cstage", cdrv, 0 },
{ "wwstage", wdrv, 1 },
{ NULL, NULL, 0 },
};
int n = (int)(sizeof rows / sizeof rows[0]);
int nn = (int)(sizeof neg / sizeof neg[0]);
int total = 0, fail = 0;
for (int d = 0; drivers[d].name; d++) {
if (drivers[d].gated_on_existence
&& access(drivers[d].path, X_OK) != 0) {
fprintf(stderr, "nested_union_int_box: skip %s (no %s)\n",
drivers[d].name, drivers[d].path);
continue;
}
for (int i = 0; i < n; i++) {
int got = run_driver(drivers[d].path, &rows[i], i);
total++;
if (got != rows[i].want) {
fprintf(stderr,
"nested_union_int_box[%s][%s]: exit=%d want=%d\n",
drivers[d].name, rows[i].label,
got, rows[i].want);
fail++;
}
}
for (int i = 0; i < nn; i++) {
total++;
if (build_should_fail(drivers[d].path, neg[i],
100 + i) != 0) {
fprintf(stderr,
"nested_union_int_box[%s][neg%d]: built ok, "
"expected a loud reject\n",
drivers[d].name, i);
fail++;
}
}
}
if (fail) {
fprintf(stderr,
"nested_union_int_box: %d/%d fixtures failed\n", fail, total);
return 1;
}
printf("nested_union_int_box: %d/%d ok\n", total, total);
return 0;
}