Skip to main content

cinrs_core/
parse.rs

1//! A recursive-descent parser for the whole C99 grammar.
2//!
3//! # The lexer hack
4//!
5//! C cannot be parsed without knowing which identifiers are `typedef` names:
6//! `T * x;` is a declaration when `T` names a type and a multiplication
7//! otherwise, and `(T)-1` is a cast rather than a subtraction. The parser
8//! therefore keeps a stack of scopes recording, for every
9//! identifier it declares, whether it was introduced by `typedef` or as an
10//! ordinary object. Lookups walk the stack from the innermost scope out, so an
11//! ordinary declaration properly shadows an outer `typedef`.
12//!
13//! # Declarator resolution
14//!
15//! Declarators are turned into a [`Type`] tree as they are parsed, using the
16//! classic "parse the suffixes first, then recurse into the parenthesised
17//! declarator" trick. That is what makes `int (*fp[3])(void)` come out as
18//! *array of 3 pointer to function(void) returning int* rather than as an
19//! opaque chain that sema would have to interpret again.
20//!
21//! # Standards
22//!
23//! The grammar is C23's, and the [`Standard`] the unit was compiled with
24//! gates the parts of it a block's own revision does not have. Which way a
25//! construct is gated
26//! depends on how C spelled it: the C11 keywords all start with an
27//! underscore, which C99 reserves, so the lexer recognises them everywhere
28//! and the parser reports "'_Static_assert' requires C11 or later" instead of
29//! a syntax error; the C23 keywords are ordinary identifiers before C23 — the
30//! bundled `<stdbool.h>` writes `#define bool _Bool` — so they are gated
31//! where the *name* turns out not to mean anything, here and in
32//! [sema](crate::sema).
33//!
34//! # Error recovery
35//!
36//! A syntax error aborts the current external declaration (`Err(Bail)`
37//! unwinds to the top level), which then synchronises on the next `;` or `}`
38//! at nesting depth zero and keeps going. That way one compilation reports one
39//! error per broken declaration instead of stopping at the first.
40
41use std::collections::HashMap;
42
43use crate::ast::*;
44use crate::capture::SourceRange;
45use crate::diag::{Diagnostic, Diagnostics};
46use crate::gnu;
47use crate::ir::{INT128_TYPEDEF_NAMES, VA_LIST_NAMES};
48use crate::lex::{Keyword, Punct, StrKind, StrLit, TokenKind};
49use crate::pp::{Origin, PackMap, Token};
50use crate::{Gating, Options, Standard};
51
52/// The spelling of `_Noreturn` that every standard accepts.
53///
54/// `_Noreturn` itself is a C11 keyword, and a `c99!` block that includes the
55/// bundled `<stdlib.h>` must not be told that its `exit` declaration needs a
56/// newer standard. The headers therefore write this name, which is a
57/// declaration specifier in every mode and means exactly what `_Noreturn`
58/// means.
59pub const NORETURN_BUILTIN: &str = "__cinrs_noreturn";
60
61/// An integer constant expression the parser synthesises.
62fn int_expr(value: u128, range: SourceRange) -> Expr {
63    Expr {
64        kind: ExprKind::Int(crate::lex::IntLit {
65            value,
66            base: crate::lex::NumBase::Decimal,
67            unsigned: false,
68            long: crate::lex::LongKind::None,
69            text: value.to_string(),
70        }),
71        range,
72    }
73}
74
75/// Signals that the current external declaration cannot be parsed further.
76#[derive(Debug)]
77#[must_use]
78pub struct Bail;
79
80type PResult<T> = Result<T, Bail>;
81
82/// Whether an identifier names a type or an object.
83#[derive(Clone, Copy, PartialEq, Eq, Debug)]
84enum SymKind {
85    Typedef,
86    Ordinary,
87}
88
89/// One lexical scope's contribution to the lexer hack.
90#[derive(Default)]
91struct Scope {
92    syms: HashMap<String, SymKind>,
93}
94
95/// Parses a token list into a [`TranslationUnit`].
96///
97/// The tokens are the [preprocessor](crate::pp)'s, so there are no directives
98/// left to see and every range already points where a diagnostic should land —
99/// at the invocation, for a token a macro produced.
100///
101/// `unit_range` is the range the whole translation unit covers — normally
102/// [`crate::Source::root_range`]. The token list must end with
103/// [`TokenKind::Eof`].
104/// Diagnostics are pushed into `diags`; the returned tree is a best effort and
105/// may contain [`TypeKind::Error`]/[`StmtKind::Error`] placeholders.
106pub fn parse(
107    tokens: &[Token],
108    unit_range: SourceRange,
109    packing: &PackMap,
110    options: &Options,
111    diags: &mut Diagnostics,
112) -> TranslationUnit {
113    // The preprocessor always ends its output with EOF, but the parser indexes
114    // on that promise, so make it true rather than trust it.
115    let patched: Vec<Token>;
116    let tokens: &[Token] = if tokens.last().is_some_and(Token::is_eof) {
117        tokens
118    } else {
119        patched = tokens
120            .iter()
121            .cloned()
122            .chain(std::iter::once(Token {
123                kind: TokenKind::Eof,
124                range: SourceRange::at(unit_range.end),
125                origin: Origin::Source,
126            }))
127            .collect();
128        &patched
129    };
130    let last_range = tokens.first().map_or(unit_range, |t| t.range);
131    // `__builtin_va_list` names a type wherever it appears, which the parser
132    // has to know before it can tell `__builtin_va_list *p;` from a
133    // multiplication. It is the one name the compiler owns; `va_list` itself
134    // is an ordinary identifier that the bundled `<stdarg.h>` `typedef`s to
135    // it, exactly as GCC's own header does.
136    let mut builtins = Scope::default();
137    for name in VA_LIST_NAMES {
138        builtins.syms.insert((*name).to_owned(), SymKind::Typedef);
139    }
140    // `__int128_t` and `__uint128_t` are the compiler's own names for the two
141    // 128-bit types, exactly as they are in GCC; `__int128` itself is a
142    // keyword the preprocessor hands over.
143    for (name, _) in INT128_TYPEDEF_NAMES {
144        builtins.syms.insert((*name).to_owned(), SymKind::Typedef);
145    }
146    let mut parser = Parser {
147        tokens,
148        pos: 0,
149        diags,
150        scopes: vec![builtins],
151        standard: options.standard,
152        gating: options.gating(),
153        in_extension: false,
154        packing,
155        last_range,
156        depth: 0,
157        records: Vec::new(),
158        enums: Vec::new(),
159        typeofs: Vec::new(),
160        label_addrs: 0,
161    };
162    parser.parse_translation_unit(unit_range)
163}
164
165/// How deeply one construct may nest before the parser gives up.
166///
167/// Recursive descent turns nesting in the input into stack frames, and a
168/// procedural macro that overflows the stack takes the whole compiler down
169/// with no useful message. Pathologically nested input becomes a diagnostic
170/// instead.
171///
172/// What it bounds is the *nesting* of the tree and never the length of
173/// anything. `a + b + c + …`, `a, b, c, …` and `a && b && …` are
174/// left-associative, so each operand is a sibling rather than a level, and
175/// the parser, [`crate::sema`] and [`crate::codegen`] all walk such a chain
176/// iteratively: its length is bounded by memory alone, which is what lets a
177/// logical source line hold the 4095 characters C23 5.2.5.2p1 asks for. Three
178/// constructs are the other way round and *are* charged here, because each
179/// operator is one more level of a tree every pass has to walk:
180///
181/// * the right-associative `a ? b : c ? d : e` and `a = b = c`
182///   ([`Parser::parse_conditional_expr`],
183///   [`Parser::parse_assignment_expr`]);
184/// * a run of postfix operators, `p->a->b->c` and `a[i][j][k]`
185///   ([`Parser::parse_postfix_suffixes`]), where each one is a place inside
186///   the last.
187///
188/// 200 is three times the 63 levels of nesting C23 5.2.5.2p1 asks for and
189/// close to Clang's own `-fbracket-depth` default of 256. Measured on an
190/// unoptimised build against the 8 MiB `rustc` gives macro expansion, code
191/// generation survives about 5000 levels of a conditional chain and about 450
192/// of a `->` chain, which is the tightest of them; the margin is therefore
193/// twofold at worst and twentyfold at best.
194const MAX_RECURSION_DEPTH: u32 = 200;
195
196/// How many labels one statement may carry.
197///
198/// A label chain is parsed iteratively, so it costs the parser nothing — but
199/// each label is still a level of the tree that sema, the CFG lowering and
200/// code generation walk recursively, and something has to bound that. C23
201/// 5.2.5.2p1 asks for 1023 `case` labels in one `switch`; this is four times
202/// that, and a chain longer than it is a diagnostic rather than a crash.
203const MAX_LABEL_CHAIN: usize = 4096;
204
205/// One label of a chain, held while the statement it labels is parsed.
206enum PendingLabel {
207    /// `name:`
208    Ident { label: Ident },
209    /// `case value:`, and GNU's `case low ... high:`.
210    Case { value: Expr, upper: Option<Expr> },
211    /// `default:`
212    Default,
213}
214
215struct Parser<'a> {
216    tokens: &'a [Token],
217    pos: usize,
218    diags: &'a mut Diagnostics,
219    scopes: Vec<Scope>,
220    /// Which revision's grammar to accept; see [`Parser::require_standard`].
221    standard: Standard,
222    /// How that revision gates a newer one's features.
223    gating: Gating,
224    /// Whether `__extension__` has switched the gates off for the declaration
225    /// being parsed; see [`Parser::require_standard`].
226    in_extension: bool,
227    /// What `#pragma pack` was asking for, by token position.
228    packing: &'a PackMap,
229    /// Range of the most recently consumed token, used to close node ranges.
230    last_range: SourceRange,
231    /// Current recursion depth; reset at every external declaration.
232    depth: u32,
233    /// The `struct`/`union` specifiers seen so far; see [`RecordSpecId`].
234    records: Vec<RecordSpec>,
235    /// The `enum` specifiers seen so far.
236    enums: Vec<EnumSpec>,
237    /// The `typeof` operands seen so far.
238    typeofs: Vec<TypeofOperand>,
239    /// How many `&&label` operands have been parsed.
240    ///
241    /// A function that takes a label's address has to be lowered through a
242    /// [control-flow graph](crate::cfg), because the value of `&&label` *is*
243    /// the state number the label stands for. That decision is made from the
244    /// statements of the body ([`crate::sema::Sema::needs_cfg`]), and
245    /// `&&label` is an expression — it can sit in an initialiser, a call
246    /// argument or a `static` table — so the one place that sees all of them
247    /// is here. Counting rather than flagging is what lets a nested function
248    /// definition put the count back where it found it, so that its own
249    /// `&&label` says nothing about the function it was written in.
250    label_addrs: u32,
251}
252
253// ---------------------------------------------------------------------------
254// token helpers
255// ---------------------------------------------------------------------------
256
257impl Parser<'_> {
258    fn peek(&self) -> &Token {
259        &self.tokens[self.pos]
260    }
261
262    fn nth(&self, n: usize) -> &Token {
263        let i = (self.pos + n).min(self.tokens.len() - 1);
264        &self.tokens[i]
265    }
266
267    fn cur_range(&self) -> SourceRange {
268        self.peek().range
269    }
270
271    fn describe_cur(&self) -> String {
272        self.peek().kind.describe()
273    }
274
275    fn at_eof(&self) -> bool {
276        self.peek().is_eof()
277    }
278
279    fn at_punct(&self, p: Punct) -> bool {
280        self.peek().is_punct(p)
281    }
282
283    fn at_keyword(&self, k: Keyword) -> bool {
284        self.peek().is_keyword(k)
285    }
286
287    fn advance(&mut self) {
288        self.last_range = self.tokens[self.pos].range;
289        if self.pos + 1 < self.tokens.len() {
290            self.pos += 1;
291        }
292    }
293
294    fn bump_range(&mut self) -> SourceRange {
295        let range = self.cur_range();
296        self.advance();
297        range
298    }
299
300    fn eat_punct(&mut self, p: Punct) -> Option<SourceRange> {
301        self.at_punct(p).then(|| self.bump_range())
302    }
303
304    fn eat_keyword(&mut self, k: Keyword) -> Option<SourceRange> {
305        self.at_keyword(k).then(|| self.bump_range())
306    }
307
308    fn eat_ident(&mut self) -> Option<Ident> {
309        let name = self.peek().ident()?.to_owned();
310        let range = self.bump_range();
311        Some(Ident { name, range })
312    }
313
314    fn error(&mut self, range: SourceRange, message: impl Into<String>) {
315        self.diags.error(range, message);
316    }
317
318    fn error_bail(&mut self, range: SourceRange, message: impl Into<String>) -> Bail {
319        self.diags.error(range, message);
320        Bail
321    }
322
323    fn expect_punct(&mut self, p: Punct, ctx: &str) -> PResult<SourceRange> {
324        if self.at_punct(p) {
325            return Ok(self.bump_range());
326        }
327        let range = self.cur_range();
328        let found = self.describe_cur();
329        Err(self.error_bail(
330            range,
331            format!("expected '{}'{ctx}, found {found}", p.as_str()),
332        ))
333    }
334
335    fn expect_ident(&mut self, ctx: &str) -> PResult<Ident> {
336        if let Some(id) = self.eat_ident() {
337            return Ok(id);
338        }
339        let range = self.cur_range();
340        let found = self.describe_cur();
341        Err(self.error_bail(range, format!("expected identifier{ctx}, found {found}")))
342    }
343
344    /// Range from `start` up to and including the last consumed token.
345    fn span_to_here(&self, start: SourceRange) -> SourceRange {
346        start.join(self.last_range)
347    }
348
349    /// Enters one level of recursion.
350    ///
351    /// The counter is only decremented on the success path; an error unwinds
352    /// all the way to the top level, which resets it.
353    fn enter(&mut self) -> PResult<()> {
354        self.depth += 1;
355        if self.depth > MAX_RECURSION_DEPTH {
356            let range = self.cur_range();
357            return Err(self.error_bail(range, "this construct nests too deeply"));
358        }
359        Ok(())
360    }
361
362    /// Leaves one level of recursion.
363    fn leave(&mut self) {
364        self.depth = self.depth.saturating_sub(1);
365    }
366
367    /// Reports a construct the block's own standard does not have.
368    ///
369    /// Parsing continues either way: the shape of the code is known, and
370    /// carrying on means one diagnostic that says exactly what to change
371    /// instead of a cascade of syntax errors after it.
372    ///
373    /// `__extension__` switches the gate off for the declaration it is written
374    /// in, which is exactly what it means in GCC — "this is an extension and I
375    /// know it". It is what the bundled headers put in front of their
376    /// `long long` declarations, so that `#include <stdlib.h>` in a `c89!`
377    /// block declares `llabs` instead of reporting the header, and it is
378    /// available to a program that wants the same bargain.
379    fn require_standard(&mut self, needed: Standard, what: &str, range: SourceRange) {
380        if self.in_extension {
381            return;
382        }
383        if let Some(message) = self.gating.requires(what, needed) {
384            self.error(range, message);
385        }
386    }
387
388    /// Reports a keyword the block's own standard does not have.
389    fn require_keyword(&mut self, k: Keyword, range: SourceRange) {
390        let needed = k.since();
391        self.require_standard(needed, &format!("'{}'", k.as_str()), range);
392    }
393
394    /// The gate message for the identifier at the current position, if a
395    /// newer revision would have made it a keyword.
396    fn newer_keyword_here(&self) -> Option<String> {
397        self.gating.newer_keyword(self.peek().ident()?)
398    }
399
400    /// Whether this block has the GNU leniencies; see
401    /// [`Sema::gnu_leniency`](crate::sema).
402    fn gnu_leniency(&self) -> bool {
403        self.gating.dialect.is_gnu()
404    }
405
406    /// The note that names the entry point which would have accepted what
407    /// [`Parser::gnu_leniency`] just refused.
408    fn gnu_note(&self) -> String {
409        format!(
410            "GCC accepts this with a warning; write {} for the same leniency",
411            self.gating.standard.macro_name_in(crate::Dialect::Gnu)
412        )
413    }
414
415    /// Reports a GNU-only leniency the strict entry points refuse.
416    fn error_gnu(&mut self, range: SourceRange, message: impl Into<String>) {
417        let note = self.gnu_note();
418        self.diags
419            .push(Diagnostic::error(range, message).with_note(note));
420    }
421}
422
423// ---------------------------------------------------------------------------
424// scopes / the lexer hack
425// ---------------------------------------------------------------------------
426
427impl Parser<'_> {
428    fn push_scope(&mut self) {
429        self.scopes.push(Scope::default());
430    }
431
432    fn pop_scope(&mut self) {
433        self.scopes.pop();
434    }
435
436    fn declare(&mut self, name: &str, kind: SymKind) {
437        if let Some(scope) = self.scopes.last_mut() {
438            scope.syms.insert(name.to_owned(), kind);
439        }
440    }
441
442    /// Whether `name` currently names a type.
443    fn is_typedef_name(&self, name: &str) -> bool {
444        for scope in self.scopes.iter().rev() {
445            if let Some(kind) = scope.syms.get(name) {
446                return *kind == SymKind::Typedef;
447            }
448        }
449        false
450    }
451}
452
453// ---------------------------------------------------------------------------
454// C23 attributes and `_Static_assert`
455// ---------------------------------------------------------------------------
456
457impl Parser<'_> {
458    /// Whether an attribute specifier sequence starts here.
459    ///
460    /// Both spellings count: C23's `[[…]]` and GNU's `__attribute__((…))`,
461    /// which mean the same things and are parsed by the same code.
462    fn at_attributes(&self) -> bool {
463        (self.at_punct(Punct::LBracket) && self.nth(1).is_punct(Punct::LBracket))
464            || self.at_keyword(Keyword::Attribute)
465    }
466
467    /// Consumes every attribute specifier here, keeping what is acted on.
468    ///
469    /// An attribute the front end does not know is dropped, which C23
470    /// 6.7.13.1p3 explicitly allows and which is what GCC does with a warning
471    /// this crate has no way to raise; one it knows but cannot honour —
472    /// `alias`, `weakref`, `vector_size` — is refused, because ignoring it
473    /// would change what the program means. `weak` and `cleanup` are refused
474    /// too, but only where they would mean something, so the decision is
475    /// sema's rather than this pass's.
476    fn parse_attributes(&mut self) -> PResult<Attributes> {
477        let mut attrs = Attributes::default();
478        loop {
479            if self.at_keyword(Keyword::Attribute) {
480                let start = self.bump_range();
481                self.expect_punct(Punct::LParen, " after '__attribute__'")?;
482                self.expect_punct(Punct::LParen, " after '__attribute__('")?;
483                self.parse_attribute_list(&mut attrs, Punct::RParen)?;
484                self.expect_punct(Punct::RParen, " to close '__attribute__'")?;
485                self.expect_punct(Punct::RParen, " to close '__attribute__'")?;
486                let _ = start;
487                continue;
488            }
489            if self.at_punct(Punct::LBracket) && self.nth(1).is_punct(Punct::LBracket) {
490                let start = self.cur_range();
491                self.require_standard(Standard::C23, "an attribute specifier", start);
492                self.advance(); // `[`
493                self.advance(); // `[`
494                self.parse_attribute_list(&mut attrs, Punct::RBracket)?;
495                self.expect_punct(Punct::RBracket, " to close an attribute specifier")?;
496                self.expect_punct(Punct::RBracket, " to close an attribute specifier")?;
497                continue;
498            }
499            return Ok(attrs);
500        }
501    }
502
503    /// `name (args)? , name (args)? , …`, up to `close`.
504    fn parse_attribute_list(&mut self, attrs: &mut Attributes, close: Punct) -> PResult<()> {
505        loop {
506            if self.at_punct(close) || self.at_eof() {
507                return Ok(());
508            }
509            // An empty element is legal in GNU's list: `__attribute__((,))`.
510            if self.eat_punct(Punct::Comma).is_some() {
511                continue;
512            }
513            self.parse_one_attribute(attrs, close)?;
514            if self.eat_punct(Punct::Comma).is_none() {
515                return Ok(());
516            }
517        }
518    }
519
520    /// One attribute, with its argument clause if it has one.
521    fn parse_one_attribute(&mut self, attrs: &mut Attributes, close: Punct) -> PResult<()> {
522        let start = self.cur_range();
523        // The name may be a keyword — `__attribute__((const))`, `[[noreturn]]`
524        // — and C23 allows a `vendor::` prefix, which is skipped.
525        let mut name = match &self.peek().kind {
526            TokenKind::Ident(name) => name.clone(),
527            TokenKind::Keyword(k) => k.as_str().to_owned(),
528            _ => {
529                let found = self.describe_cur();
530                return Err(self.error_bail(start, format!("expected an attribute, found {found}")));
531            }
532        };
533        self.advance();
534        // `[[cinrs::safe]]`: this crate's own namespace, whose names are read
535        // from a table of their own.
536        let mut ours = false;
537        if self.at_punct(Punct::Colon) && self.nth(1).is_punct(Punct::Colon) {
538            self.advance();
539            self.advance();
540            let prefix = std::mem::take(&mut name);
541            name = match &self.peek().kind {
542                TokenKind::Ident(name) => name.clone(),
543                TokenKind::Keyword(k) => k.as_str().to_owned(),
544                _ => {
545                    let found = self.describe_cur();
546                    return Err(
547                        self.error_bail(start, format!("expected an attribute, found {found}"))
548                    );
549                }
550            };
551            self.advance();
552            // Only the GNU namespace and this crate's own name attributes this
553            // front end knows; anything else is another vendor's and is
554            // ignored.
555            if prefix == "cinrs" {
556                if gnu::cinrs_attribute(&name).is_none() {
557                    self.skip_attribute_args()?;
558                    let range = self.span_to_here(start);
559                    self.error(
560                        range,
561                        format!(
562                            "unknown 'cinrs' attribute '{name}'; the ones this crate has are {}",
563                            Self::list_of_names(gnu::CINRS_ATTRIBUTES)
564                        ),
565                    );
566                    return Ok(());
567                }
568                ours = true;
569            } else if prefix != "gnu" && prefix != "clang" {
570                self.skip_attribute_args()?;
571                return Ok(());
572            }
573        }
574
575        let known = if ours {
576            gnu::cinrs_attribute(&name)
577        } else {
578            gnu::attribute(&name)
579        };
580        // Only three attributes have arguments this front end reads; every
581        // other clause may hold anything at all — `format(printf, 1, 2)` names
582        // a *mode* rather than a value — and is skipped as balanced tokens.
583        match known {
584            Some(gnu::Attribute::Aligned) => {
585                let alignment = if self.at_punct(Punct::LParen) {
586                    self.advance();
587                    let expr = self.parse_conditional_expr()?;
588                    self.expect_punct(Punct::RParen, " after the alignment")?;
589                    AlignmentKind::Expr(expr)
590                } else {
591                    // Bare `aligned` asks for the biggest alignment any type on
592                    // the target needs, which is 16 on every ABI here.
593                    AlignmentKind::Expr(int_expr(16, start))
594                };
595                let range = self.span_to_here(start);
596                attrs.aligned = Some(Alignment {
597                    kind: alignment,
598                    from_attribute: true,
599                    range,
600                });
601                return Ok(());
602            }
603            Some(gnu::Attribute::Deprecated) => {
604                let message = self.attribute_string()?;
605                let range = self.span_to_here(start);
606                attrs.deprecated = Some(Spanned::new(message, range));
607                return Ok(());
608            }
609            Some(gnu::Attribute::Cleanup) => {
610                // The argument is an identifier naming a function, and nothing
611                // else: GCC's own two diagnostics are "cleanup argument not an
612                // identifier" and "cleanup argument not a function", and only
613                // sema can tell the second one.
614                let func = self.attribute_identifier()?;
615                let range = self.span_to_here(start);
616                attrs.cleanup = Some(Cleanup { func, range });
617                return Ok(());
618            }
619            Some(gnu::Attribute::Mode) => {
620                // The argument names a machine mode — `QI`, `DI`, `word` —
621                // and GCC accepts the `__QI__` spelling of each as well.
622                let mode = self.attribute_identifier()?;
623                let range = self.span_to_here(start);
624                match mode {
625                    Some(mode) => attrs.mode = Some(Spanned::new(mode.name, range)),
626                    None => self.error(range, "'mode' takes one machine mode name"),
627                }
628                return Ok(());
629            }
630            Some(gnu::Attribute::Section) => {
631                let name = self.attribute_string()?;
632                let range = self.span_to_here(start);
633                match name {
634                    Some(name) => attrs.section = Some(Spanned::new(name, range)),
635                    None => self.error(range, "'section' takes one string literal"),
636                }
637                return Ok(());
638            }
639            _ => {}
640        }
641        self.skip_attribute_args()?;
642        let range = self.span_to_here(start);
643        match known {
644            Some(gnu::Attribute::Noreturn) => attrs.noreturn = attrs.noreturn.or(Some(range)),
645            Some(gnu::Attribute::AlwaysInline) => {
646                attrs.always_inline = attrs.always_inline.or(Some(range));
647            }
648            Some(gnu::Attribute::NoInline) => attrs.noinline = attrs.noinline.or(Some(range)),
649            Some(gnu::Attribute::Cold) => attrs.cold = attrs.cold.or(Some(range)),
650            // GCC's `hot` is the opposite of `cold`, and the two cancel.
651            Some(gnu::Attribute::Hot) => attrs.cold = None,
652            Some(gnu::Attribute::Packed) => attrs.packed = attrs.packed.or(Some(range)),
653            Some(gnu::Attribute::Constructor) => {
654                attrs.constructor = attrs.constructor.or(Some(range));
655            }
656            Some(gnu::Attribute::Destructor) => {
657                attrs.destructor = attrs.destructor.or(Some(range));
658            }
659            Some(gnu::Attribute::Safe) => attrs.safe = attrs.safe.or(Some(range)),
660            // Only sema knows whether a definition follows, and that is the
661            // whole of the question `weak` asks; see `Sema::reject_weak`.
662            Some(gnu::Attribute::Weak) => attrs.weak = attrs.weak.or(Some(range)),
663            // A statement attribute with nothing to say here: a `switch` group
664            // falls through in the generated Rust either way.
665            Some(gnu::Attribute::Fallthrough) | Some(gnu::Attribute::Ignored) => {}
666            Some(gnu::Attribute::Unsupported) => {
667                let reason = gnu::unsupported_reason(&name).unwrap_or("is not supported");
668                self.error(range, format!("'{name}' {reason}"));
669            }
670            // Everything above was handled; an unknown attribute is ignored,
671            // as C23 requires.
672            _ => {}
673        }
674        let _ = close;
675        Ok(())
676    }
677
678    /// The single identifier an attribute's argument clause holds, if that is
679    /// what it holds; whatever else is there is skipped as balanced tokens.
680    fn attribute_identifier(&mut self) -> PResult<Option<Ident>> {
681        if !self.at_punct(Punct::LParen) {
682            return Ok(None);
683        }
684        self.advance();
685        let name = match &self.peek().kind {
686            TokenKind::Ident(name) => {
687                let ident = Ident {
688                    name: name.clone(),
689                    range: self.cur_range(),
690                };
691                self.advance();
692                // `cleanup(f, g)` is not an identifier argument either.
693                self.at_punct(Punct::RParen).then_some(ident)
694            }
695            _ => None,
696        };
697        let mut depth = 1i32;
698        while depth > 0 && !self.at_eof() {
699            if self.at_punct(Punct::LParen) {
700                depth += 1;
701            } else if self.at_punct(Punct::RParen) {
702                depth -= 1;
703                if depth == 0 {
704                    self.advance();
705                    break;
706                }
707            }
708            self.advance();
709        }
710        Ok(name)
711    }
712
713    /// The single string literal an attribute's argument clause holds, if it
714    /// has one at all.
715    fn attribute_string(&mut self) -> PResult<Option<String>> {
716        if !self.at_punct(Punct::LParen) {
717            return Ok(None);
718        }
719        self.advance();
720        let mut text = None;
721        if let TokenKind::Str(lit) = self.peek().kind.clone() {
722            let range = self.cur_range();
723            let literal = self.parse_string_literal(lit, range);
724            if let ExprKind::Str(lit) = literal.kind {
725                text = String::from_utf8(lit.values.iter().map(|v| *v as u8).collect()).ok();
726            }
727        }
728        // Anything else — a priority, an unknown option — is skipped.
729        let mut depth = 1i32;
730        while depth > 0 && !self.at_eof() {
731            if self.at_punct(Punct::LParen) {
732                depth += 1;
733            } else if self.at_punct(Punct::RParen) {
734                depth -= 1;
735                if depth == 0 {
736                    self.advance();
737                    break;
738                }
739            }
740            self.advance();
741        }
742        Ok(text)
743    }
744
745    /// Skips a balanced argument clause without looking inside it.
746    fn skip_attribute_args(&mut self) -> PResult<()> {
747        if !self.at_punct(Punct::LParen) {
748            return Ok(());
749        }
750        let start = self.cur_range();
751        let mut depth = 0i32;
752        while !self.at_eof() {
753            if self.at_punct(Punct::LParen) {
754                depth += 1;
755            } else if self.at_punct(Punct::RParen) {
756                depth -= 1;
757                if depth == 0 {
758                    self.advance();
759                    return Ok(());
760                }
761            }
762            self.advance();
763        }
764        Err(self.error_bail(start, "unterminated attribute argument list"))
765    }
766
767    /// `'a'`, `'a' and 'b'`, `'a', 'b' and 'c'` — how a diagnostic lists the
768    /// names it would have accepted.
769    fn list_of_names(names: &[&str]) -> String {
770        let quoted: Vec<String> = names.iter().map(|name| format!("'{name}'")).collect();
771        match quoted.split_last() {
772            None => String::new(),
773            Some((last, [])) => last.clone(),
774            Some((last, rest)) => format!("{} and {last}", rest.join(", ")),
775        }
776    }
777
778    /// Whether a `_Static_assert` declaration starts here.
779    fn at_static_assert(&self) -> bool {
780        matches!(
781            self.peek().keyword(),
782            Some(Keyword::StaticAssert | Keyword::StaticAssertName)
783        )
784    }
785
786    /// `_Static_assert ( constant-expression , "message" ) ;`, whose message
787    /// C23 makes optional.
788    fn parse_static_assert(&mut self) -> PResult<StaticAssert> {
789        let start = self.cur_range();
790        let keyword = self.peek().keyword().expect("the caller checked");
791        self.require_keyword(keyword, start);
792        self.advance();
793        let name = keyword.as_str();
794        self.expect_punct(Punct::LParen, &format!(" after '{name}'"))?;
795        let cond = self.parse_conditional_expr()?;
796        let mut message = None;
797        if self.eat_punct(Punct::Comma).is_some() {
798            let range = self.cur_range();
799            let TokenKind::Str(first) = self.peek().kind.clone() else {
800                let found = self.describe_cur();
801                return Err(self.error_bail(
802                    range,
803                    format!("expected a string literal as the message of '{name}', found {found}"),
804                ));
805            };
806            let literal = self.parse_string_literal(first, range);
807            if let ExprKind::Str(lit) = literal.kind {
808                message = Some(lit.text);
809            }
810        } else {
811            self.require_standard(
812                Standard::C23,
813                &format!("'{name}' without a message"),
814                self.span_to_here(start),
815            );
816        }
817        self.expect_punct(Punct::RParen, &format!(" to close '{name}'"))?;
818        self.expect_punct(Punct::Semi, &format!(" after '{name}'"))?;
819        Ok(StaticAssert {
820            cond,
821            message,
822            range: self.span_to_here(start),
823        })
824    }
825}
826
827// ---------------------------------------------------------------------------
828// top level
829// ---------------------------------------------------------------------------
830
831impl Parser<'_> {
832    fn parse_translation_unit(&mut self, range: SourceRange) -> TranslationUnit {
833        let mut items = Vec::new();
834        while !self.at_eof() {
835            let before = self.pos;
836            self.depth = 0;
837            // A stray `;` at file scope. C's grammar has no empty external
838            // declaration — 6.9p1 is a *declaration* or a function definition,
839            // and C23 6.7p1 did not add one — but GCC accepts it with only a
840            // pedantic warning ("ISO C does not allow extra ';' outside of a
841            // function"), and a macro whose expansion already ends in `;`
842            // being written with one after it is common enough that seven of
843            // the torture suite's cases do it. The GNU dialects accept it; the
844            // strict ones keep the error.
845            if self.at_punct(Punct::Semi) {
846                let range = self.bump_range();
847                if !self.gnu_leniency() {
848                    self.error_gnu(range, "expected a declaration, found ';'");
849                }
850                continue;
851            }
852            match self.parse_external_decl() {
853                Ok(item) => items.push(item),
854                Err(Bail) => self.recover_top_level(before),
855            }
856            if self.pos == before {
857                self.advance();
858            }
859        }
860        TranslationUnit {
861            items,
862            records: std::mem::take(&mut self.records),
863            enums: std::mem::take(&mut self.enums),
864            typeofs: std::mem::take(&mut self.typeofs),
865            range,
866        }
867    }
868
869    /// How deeply nested in brackets the current position is, relative to the
870    /// token at `start`.
871    fn depth_from(&self, start: usize) -> i32 {
872        let mut depth = 0i32;
873        for tok in &self.tokens[start.min(self.pos)..self.pos] {
874            match &tok.kind {
875                TokenKind::Punct(Punct::LBrace | Punct::LParen | Punct::LBracket) => depth += 1,
876                TokenKind::Punct(Punct::RBrace | Punct::RParen | Punct::RBracket) => depth -= 1,
877                _ => {}
878            }
879        }
880        depth.max(0)
881    }
882
883    /// Skips forward to just past the `;` or `}` that ends the external
884    /// declaration that started at token `decl_start`.
885    ///
886    /// Starting from the nesting depth the error was found at (rather than
887    /// from zero) is what keeps a single broken statement inside a function
888    /// body from producing a cascade of errors for the rest of the body.
889    fn recover_top_level(&mut self, decl_start: usize) {
890        let mut depth = self.depth_from(decl_start);
891        while !self.at_eof() {
892            match &self.peek().kind {
893                TokenKind::Punct(Punct::LBrace | Punct::LParen | Punct::LBracket) => {
894                    depth += 1;
895                    self.advance();
896                }
897                TokenKind::Punct(Punct::RBrace | Punct::RParen | Punct::RBracket) => {
898                    let paren = self.at_punct(Punct::RParen) || self.at_punct(Punct::RBracket);
899                    depth -= 1;
900                    self.advance();
901                    if depth <= 0 {
902                        // `struct S { int x };` — swallow the `;` that closes
903                        // the declaration so that it is not mistaken for the
904                        // start of the next one.
905                        if self.eat_punct(Punct::Semi).is_some() {
906                            return;
907                        }
908                        // A declarator's own `)` or `]` closing is not the end
909                        // of the declaration: `void f(<error>) { … }` still
910                        // owes a body, and reporting its `{` as a stray one
911                        // would be a second error for one mistake. Keep
912                        // scanning and let the body's `}` finish the job.
913                        if paren && self.at_punct(Punct::LBrace) {
914                            depth = 0;
915                            continue;
916                        }
917                        return;
918                    }
919                }
920                TokenKind::Punct(Punct::Semi) => {
921                    self.advance();
922                    if depth <= 0 {
923                        return;
924                    }
925                }
926                _ => self.advance(),
927            }
928        }
929    }
930
931    fn parse_external_decl(&mut self) -> PResult<ExternalDecl> {
932        let start = self.cur_range();
933        // `__extension__` marks what follows as a GNU extension and asks for
934        // the diagnostics about using one to be held back, which here means
935        // the gates a `c89!` block puts on what C99 added. Every external
936        // declaration starts afresh, so the flag never outlives the one it
937        // was written in — including down an error path.
938        self.in_extension = false;
939        while self.eat_keyword(Keyword::Extension).is_some() {
940            self.in_extension = true;
941        }
942        let attrs = self.parse_attributes()?;
943        if self.at_static_assert() {
944            return Ok(ExternalDecl::StaticAssert(self.parse_static_assert()?));
945        }
946        let mut specs = self.parse_decl_specifiers(true)?;
947        specs.attrs.merge(attrs);
948        specs.noreturn = specs.noreturn.or(specs.attrs.noreturn);
949
950        if let Some(semi) = self.eat_punct(Punct::Semi) {
951            return Ok(ExternalDecl::Decl(Decl {
952                specifiers: specs,
953                declarators: Vec::new(),
954                range: start.join(semi),
955            }));
956        }
957
958        let mut first = self.parse_declarator(specs.base.clone(), false)?;
959        self.parse_declarator_tail(&mut first)?;
960
961        let looks_like_definition = matches!(first.ty.kind, TypeKind::Function(_))
962            && (self.at_punct(Punct::LBrace) || self.starts_declaration());
963        if looks_like_definition && !specs.is_typedef() {
964            return self.finish_function_def(specs, first, start);
965        }
966
967        let decl = self.finish_declaration(specs, Some(first), start)?;
968        Ok(ExternalDecl::Decl(decl))
969    }
970
971    /// `__asm__("symbol")` and `__attribute__((…))`, which may follow any
972    /// declarator and in that order.
973    fn parse_declarator_tail(&mut self, declarator: &mut DeclaratorResult) -> PResult<()> {
974        loop {
975            if self.at_keyword(Keyword::Asm) {
976                let start = self.cur_range();
977                self.advance();
978                self.expect_punct(Punct::LParen, " after 'asm'")?;
979                let range = self.cur_range();
980                let TokenKind::Str(lit) = self.peek().kind.clone() else {
981                    let found = self.describe_cur();
982                    return Err(self.error_bail(
983                        range,
984                        format!("expected the symbol name as a string literal, found {found}"),
985                    ));
986                };
987                let literal = self.parse_string_literal(lit, range);
988                self.expect_punct(Punct::RParen, " after the symbol name")?;
989                if let ExprKind::Str(lit) = literal.kind
990                    && let Ok(name) =
991                        String::from_utf8(lit.values.iter().map(|v| *v as u8).collect())
992                {
993                    declarator.asm_label = Some(Spanned::new(name, self.span_to_here(start)));
994                }
995                continue;
996            }
997            if self.at_attributes() {
998                let attrs = self.parse_attributes()?;
999                declarator.attrs.merge(attrs);
1000                continue;
1001            }
1002            return Ok(());
1003        }
1004    }
1005
1006    /// The declaration list of an old-style definition — `int a, b;` between
1007    /// `f(a, b)` and the body.
1008    ///
1009    /// A static assertion is a declaration, so the grammar admits one here and
1010    /// C99 6.9.1p6 then forbids it: every declaration in the list has to
1011    /// declare one of the parameters, and a static assertion declares nothing.
1012    /// Saying so and reading on is one error for one mistake — giving up here
1013    /// would report the body's `{` as a stray one as well, which is two.
1014    fn parse_kr_declaration_list(&mut self) -> PResult<Vec<Decl>> {
1015        let mut decls = Vec::new();
1016        loop {
1017            if self.at_static_assert() {
1018                let range = self.cur_range();
1019                self.error(
1020                    range,
1021                    "a static assertion is not allowed in the declaration list of an old-style \
1022                     function definition; every declaration there has to declare one of the \
1023                     parameters (C99 6.9.1p6)",
1024                );
1025                self.parse_static_assert()?;
1026                continue;
1027            }
1028            if !self.starts_declaration() {
1029                return Ok(decls);
1030            }
1031            decls.push(self.parse_declaration()?);
1032        }
1033    }
1034
1035    fn finish_function_def(
1036        &mut self,
1037        specs: DeclSpecifiers,
1038        declarator: DeclaratorResult,
1039        start: SourceRange,
1040    ) -> PResult<ExternalDecl> {
1041        let Some(name) = declarator.name.clone() else {
1042            return Err(self.error_bail(declarator.range, "function definition requires a name"));
1043        };
1044        self.declare(&name.name, SymKind::Ordinary);
1045
1046        // Parameters (and old-style parameter declarations) share a scope with
1047        // the body's outermost block.
1048        self.push_scope();
1049        if let TypeKind::Function(ft) = &declarator.ty.kind {
1050            for param in &ft.params {
1051                if let Some(pname) = &param.name {
1052                    self.scopes
1053                        .last_mut()
1054                        .expect("scope stack is never empty")
1055                        .syms
1056                        .insert(pname.name.clone(), SymKind::Ordinary);
1057                }
1058            }
1059            for kr in &ft.kr_names {
1060                self.scopes
1061                    .last_mut()
1062                    .expect("scope stack is never empty")
1063                    .syms
1064                    .insert(kr.name.clone(), SymKind::Ordinary);
1065            }
1066        }
1067
1068        let kr_decls = match self.parse_kr_declaration_list() {
1069            Ok(decls) => decls,
1070            Err(bail) => {
1071                self.pop_scope();
1072                return Err(bail);
1073            }
1074        };
1075
1076        let before = self.label_addrs;
1077        let body = match self.parse_compound_stmt() {
1078            Ok(body) => body,
1079            Err(bail) => {
1080                self.pop_scope();
1081                return Err(bail);
1082            }
1083        };
1084        self.pop_scope();
1085
1086        Ok(ExternalDecl::Function(FunctionDef {
1087            specifiers: specs,
1088            name,
1089            ty: declarator.ty,
1090            kr_decls,
1091            attrs: declarator.attrs,
1092            asm_label: declarator.asm_label,
1093            body,
1094            uses_label_addrs: self.label_addrs != before,
1095            range: self.span_to_here(start),
1096        }))
1097    }
1098
1099    /// Parses `declarator (= initializer)? (, declarator (= initializer)?)* ;`.
1100    fn finish_declaration(
1101        &mut self,
1102        specs: DeclSpecifiers,
1103        first: Option<DeclaratorResult>,
1104        start: SourceRange,
1105    ) -> PResult<Decl> {
1106        let is_typedef = specs.is_typedef();
1107        let mut declarators = Vec::new();
1108        let mut pending = first;
1109        loop {
1110            let mut declarator = match pending.take() {
1111                Some(d) => d,
1112                None => {
1113                    let mut d = self.parse_declarator(specs.base.clone(), false)?;
1114                    self.parse_declarator_tail(&mut d)?;
1115                    d
1116                }
1117            };
1118            if let Some(name) = &declarator.name {
1119                let kind = if is_typedef {
1120                    SymKind::Typedef
1121                } else {
1122                    SymKind::Ordinary
1123                };
1124                self.declare(&name.name.clone(), kind);
1125            }
1126            let init = if self.eat_punct(Punct::Assign).is_some() {
1127                Some(self.parse_initializer()?)
1128            } else {
1129                None
1130            };
1131            // GCC lets the attributes come after the initialiser too.
1132            if self.at_attributes() {
1133                let attrs = self.parse_attributes()?;
1134                declarator.attrs.merge(attrs);
1135            }
1136            let range = self.span_to_here(declarator.range);
1137            declarators.push(InitDeclarator {
1138                name: declarator.name,
1139                ty: declarator.ty,
1140                init,
1141                attrs: declarator.attrs,
1142                asm_label: declarator.asm_label,
1143                range,
1144            });
1145            if self.eat_punct(Punct::Comma).is_none() {
1146                break;
1147            }
1148        }
1149        let semi = self.expect_punct(Punct::Semi, " after declaration")?;
1150        Ok(Decl {
1151            specifiers: specs,
1152            declarators,
1153            range: start.join(semi),
1154        })
1155    }
1156
1157    /// Parses a declaration that cannot be a function definition.
1158    ///
1159    /// A K&R parameter declaration list and a `for` clause are the two places
1160    /// that use it — neither may hold a definition, and in the K&R list the
1161    /// `{` that follows opens the body of the function being defined, not a
1162    /// nested one. A block item goes through
1163    /// [`Parser::parse_block_declaration`], which may find GNU's nested
1164    /// function definition instead.
1165    fn parse_declaration(&mut self) -> PResult<Decl> {
1166        // `__extension__` covers the declaration it is written on, so one
1167        // nested inside another — a local in the body of a function whose
1168        // definition carries it — starts afresh, and the enclosing one gets
1169        // its answer back whichever way this goes.
1170        let enclosing = std::mem::take(&mut self.in_extension);
1171        let result = self.parse_declaration_inner();
1172        self.in_extension = enclosing;
1173        result
1174    }
1175
1176    fn parse_declaration_inner(&mut self) -> PResult<Decl> {
1177        let (specs, start) = self.parse_declaration_head()?;
1178        if let Some(semi) = self.eat_punct(Punct::Semi) {
1179            return Ok(Decl {
1180                specifiers: specs,
1181                declarators: Vec::new(),
1182                range: start.join(semi),
1183            });
1184        }
1185        self.finish_declaration(specs, None, start)
1186    }
1187
1188    /// The `__extension__`s, attributes and declaration specifiers that a
1189    /// declaration — and a nested function definition, which begins as one —
1190    /// opens with, and where they began.
1191    fn parse_declaration_head(&mut self) -> PResult<(DeclSpecifiers, SourceRange)> {
1192        let start = self.cur_range();
1193        while self.eat_keyword(Keyword::Extension).is_some() {
1194            self.in_extension = true;
1195        }
1196        let attrs = self.parse_attributes()?;
1197        let mut specs = self.parse_decl_specifiers(true)?;
1198        specs.attrs.merge(attrs);
1199        specs.noreturn = specs.noreturn.or(specs.attrs.noreturn);
1200        Ok((specs, start))
1201    }
1202
1203    /// Parses a block item that begins like a declaration.
1204    ///
1205    /// Block scope is the one place where what looks like a declaration may
1206    /// really be a function *definition*: GNU's nested functions. See
1207    /// [`Parser::parse_nested_function`].
1208    fn parse_block_declaration(&mut self) -> PResult<BlockItem> {
1209        let enclosing = std::mem::take(&mut self.in_extension);
1210        let result = self.parse_block_declaration_inner();
1211        self.in_extension = enclosing;
1212        result
1213    }
1214
1215    fn parse_block_declaration_inner(&mut self) -> PResult<BlockItem> {
1216        let (specs, start) = self.parse_declaration_head()?;
1217        if let Some(semi) = self.eat_punct(Punct::Semi) {
1218            return Ok(BlockItem::Decl(Decl {
1219                specifiers: specs,
1220                declarators: Vec::new(),
1221                range: start.join(semi),
1222            }));
1223        }
1224        // The first declarator is taken here rather than left to
1225        // [`Parser::finish_declaration`], because it is the declarator that
1226        // says whether this is a declaration at all.
1227        let mut first = self.parse_declarator(specs.base.clone(), false)?;
1228        self.parse_declarator_tail(&mut first)?;
1229        if self.at_nested_function_body(&specs, &first) {
1230            return self
1231                .parse_nested_function(specs, first, start)
1232                .map(BlockItem::NestedFunction);
1233        }
1234        self.finish_declaration(specs, Some(first), start)
1235            .map(BlockItem::Decl)
1236    }
1237
1238    /// Whether the block-scope declaration just read is really the head of a
1239    /// GNU nested function definition — `int f(void) { int g(int x) { … } }`.
1240    ///
1241    /// The shape is a named function declarator followed by the body, either
1242    /// straight away or after a K&R parameter declaration list. Insisting that
1243    /// the `{` really be there is what keeps a plain missing semicolon —
1244    /// `int g(int)` and then `int x;` — reported as the missing semicolon it
1245    /// is.
1246    fn at_nested_function_body(
1247        &self,
1248        specs: &DeclSpecifiers,
1249        declarator: &DeclaratorResult,
1250    ) -> bool {
1251        declarator.name.is_some()
1252            && !specs.is_typedef()
1253            && matches!(declarator.ty.kind, TypeKind::Function(_))
1254            && (self.at_punct(Punct::LBrace) || self.at_kr_declaration_list())
1255    }
1256
1257    /// Whether a K&R parameter declaration list and then a body follow the
1258    /// declarator: `g(a) int a; { … }`.
1259    ///
1260    /// A lookahead, over tokens only — each declaration runs to the `;` that
1261    /// is not inside brackets, and what has to come after the last of them is
1262    /// the `{`.
1263    fn at_kr_declaration_list(&self) -> bool {
1264        let mut n = 0;
1265        while self.starts_decl_specifier(n) {
1266            let mut depth = 0i32;
1267            loop {
1268                let tok = self.nth(n);
1269                if tok.is_eof() {
1270                    return false;
1271                }
1272                n += 1;
1273                match &tok.kind {
1274                    TokenKind::Punct(Punct::LBrace | Punct::LParen | Punct::LBracket) => depth += 1,
1275                    TokenKind::Punct(Punct::RBrace | Punct::RParen | Punct::RBracket) => {
1276                        depth -= 1;
1277                        if depth < 0 {
1278                            return false;
1279                        }
1280                    }
1281                    TokenKind::Punct(Punct::Semi) if depth == 0 => break,
1282                    _ => {}
1283                }
1284            }
1285        }
1286        n > 0 && self.nth(n).is_punct(Punct::LBrace)
1287    }
1288
1289    /// Parses a GNU nested function definition, body and all.
1290    ///
1291    /// The shape is a function definition written where a declaration may
1292    /// stand, so this is [`Parser::finish_function_def`] with two differences:
1293    /// the name is declared in the *enclosing block*, which is the scope GNU
1294    /// gives it and which is what lets the body call the function
1295    /// recursively, and the result is a block item rather than an external
1296    /// declaration. Semantic analysis lifts it out; see
1297    /// `Sema::nested_function_def`.
1298    fn parse_nested_function(
1299        &mut self,
1300        specs: DeclSpecifiers,
1301        declarator: DeclaratorResult,
1302        start: SourceRange,
1303    ) -> PResult<FunctionDef> {
1304        let name = declarator
1305            .name
1306            .clone()
1307            .expect("at_nested_function_body requires a name");
1308        self.declare(&name.name, SymKind::Ordinary);
1309
1310        // Parameters (and old-style parameter declarations) share a scope with
1311        // the body's outermost block.
1312        self.push_scope();
1313        if let TypeKind::Function(ft) = &declarator.ty.kind {
1314            for param in &ft.params {
1315                if let Some(pname) = &param.name {
1316                    self.scopes
1317                        .last_mut()
1318                        .expect("scope stack is never empty")
1319                        .syms
1320                        .insert(pname.name.clone(), SymKind::Ordinary);
1321                }
1322            }
1323            for kr in &ft.kr_names {
1324                self.scopes
1325                    .last_mut()
1326                    .expect("scope stack is never empty")
1327                    .syms
1328                    .insert(kr.name.clone(), SymKind::Ordinary);
1329            }
1330        }
1331
1332        let kr_decls = match self.parse_kr_declaration_list() {
1333            Ok(decls) => decls,
1334            Err(bail) => {
1335                self.pop_scope();
1336                return Err(bail);
1337            }
1338        };
1339
1340        let before = self.label_addrs;
1341        let body = match self.parse_compound_stmt() {
1342            Ok(body) => body,
1343            Err(bail) => {
1344                self.pop_scope();
1345                return Err(bail);
1346            }
1347        };
1348        self.pop_scope();
1349        let uses_label_addrs = self.label_addrs != before;
1350        // A nested function's `&&label` names a label of its *own* body, so
1351        // the count goes back to what the enclosing function had.
1352        self.label_addrs = before;
1353
1354        Ok(FunctionDef {
1355            specifiers: specs,
1356            name,
1357            ty: declarator.ty,
1358            kr_decls,
1359            attrs: declarator.attrs,
1360            asm_label: declarator.asm_label,
1361            body,
1362            uses_label_addrs,
1363            range: self.span_to_here(start),
1364        })
1365    }
1366}
1367
1368// ---------------------------------------------------------------------------
1369// declaration specifiers
1370// ---------------------------------------------------------------------------
1371
1372/// Counters for the combinable type-specifier keywords.
1373#[derive(Default)]
1374struct SpecCounts {
1375    void: u32,
1376    char: u32,
1377    short: u32,
1378    int: u32,
1379    long: u32,
1380    float: u32,
1381    double: u32,
1382    signed: u32,
1383    unsigned: u32,
1384    bool: u32,
1385    complex: u32,
1386    imaginary: u32,
1387    int128: u32,
1388}
1389
1390impl SpecCounts {
1391    fn any(&self) -> bool {
1392        self.void
1393            + self.char
1394            + self.short
1395            + self.int
1396            + self.long
1397            + self.float
1398            + self.double
1399            + self.signed
1400            + self.unsigned
1401            + self.bool
1402            + self.complex
1403            + self.imaginary
1404            + self.int128
1405            > 0
1406    }
1407}
1408
1409impl Parser<'_> {
1410    /// Whether the current token can begin a declaration.
1411    fn starts_declaration(&self) -> bool {
1412        self.starts_decl_specifier(0)
1413    }
1414
1415    /// Whether the current token can begin a declarator.
1416    ///
1417    /// Only asked where there were no declaration specifiers at all, to tell
1418    /// `f() { … }` — implicit `int`, and a diagnostic that says so from C99 on
1419    /// — from a stray token that begins nothing.
1420    fn starts_declarator(&self) -> bool {
1421        let tok = self.peek();
1422        tok.ident().is_some() || tok.is_punct(Punct::Star) || tok.is_punct(Punct::LParen)
1423    }
1424
1425    /// Whether the token `n` positions ahead can begin a declaration
1426    /// specifier (or, for a type name, a specifier-qualifier list).
1427    fn starts_decl_specifier(&self, n: usize) -> bool {
1428        let tok = self.nth(n);
1429        if let Some(k) = tok.keyword() {
1430            return matches!(
1431                k,
1432                Keyword::Typedef
1433                    | Keyword::Extern
1434                    | Keyword::Static
1435                    | Keyword::Auto
1436                    | Keyword::Register
1437                    | Keyword::Const
1438                    | Keyword::Volatile
1439                    | Keyword::Restrict
1440                    | Keyword::Inline
1441                    | Keyword::Void
1442                    | Keyword::Char
1443                    | Keyword::Short
1444                    | Keyword::Int
1445                    | Keyword::Long
1446                    | Keyword::Float
1447                    | Keyword::Double
1448                    | Keyword::Signed
1449                    | Keyword::Unsigned
1450                    | Keyword::Bool
1451                    | Keyword::Complex
1452                    | Keyword::Imaginary
1453                    | Keyword::Struct
1454                    | Keyword::Union
1455                    | Keyword::Enum
1456                    | Keyword::Alignas
1457                    | Keyword::AlignasName
1458                    | Keyword::Atomic
1459                    | Keyword::BitInt
1460                    | Keyword::Noreturn
1461                    | Keyword::ThreadLocal
1462                    | Keyword::ThreadLocalName
1463                    | Keyword::Constexpr
1464                    | Keyword::Typeof
1465                    | Keyword::TypeofUnqual
1466                    | Keyword::BoolName
1467                    | Keyword::Attribute
1468                    | Keyword::Extension
1469                    | Keyword::TypeofGnu
1470                    | Keyword::TypeofUnqualGnu
1471                    | Keyword::AutoType
1472                    | Keyword::ThreadGnu
1473                    | Keyword::Int128
1474                    | Keyword::InlineGnu
1475                    | Keyword::RestrictGnu
1476            );
1477        }
1478        match tok.ident() {
1479            Some(NORETURN_BUILTIN) => true,
1480            // A label such as `done:` must not look like a declaration even
1481            // when it happens to share a name with a `typedef`.
1482            Some(name) => self.is_typedef_name(name) && !self.nth(n + 1).is_punct(Punct::Colon),
1483            None => false,
1484        }
1485    }
1486
1487    fn eat_type_qualifier(&mut self) -> Option<TypeQualifiers> {
1488        let keyword = self.peek().keyword()?;
1489        let q = match keyword {
1490            Keyword::Const => TypeQualifiers {
1491                is_const: true,
1492                ..TypeQualifiers::NONE
1493            },
1494            Keyword::Volatile => TypeQualifiers {
1495                is_volatile: true,
1496                ..TypeQualifiers::NONE
1497            },
1498            Keyword::Restrict | Keyword::RestrictGnu => TypeQualifiers {
1499                is_restrict: true,
1500                ..TypeQualifiers::NONE
1501            },
1502            // `_Atomic` with a parenthesised type name after it is a type
1503            // *specifier* — `_Atomic(int) x;` — and is parsed where the
1504            // specifiers are; everywhere else the keyword is a qualifier.
1505            Keyword::Atomic if !self.at_atomic_specifier(0) => TypeQualifiers {
1506                is_atomic: true,
1507                ..TypeQualifiers::NONE
1508            },
1509            _ => return None,
1510        };
1511        // `restrict` is C99's (N448); `__restrict` is reserved and works in
1512        // every entry point, exactly as it does in GCC's own `-std=c89`.
1513        if keyword == Keyword::Restrict {
1514            let range = self.cur_range();
1515            self.require_standard(Standard::C99, "'restrict'", range);
1516        }
1517        if keyword == Keyword::Atomic {
1518            let range = self.cur_range();
1519            self.require_keyword(Keyword::Atomic, range);
1520        }
1521        self.advance();
1522        Some(q)
1523    }
1524
1525    /// Whether the `_Atomic` at offset `n` is the `_Atomic (type-name)` form.
1526    ///
1527    /// C11 6.7.2.4p4 draws the line exactly here: the keyword is a type
1528    /// specifier when it is followed by a parenthesised type name and a type
1529    /// qualifier otherwise, which is what makes `int * _Atomic (*p)(void)` a
1530    /// qualified pointer to a function rather than a syntax error.
1531    fn at_atomic_specifier(&self, n: usize) -> bool {
1532        self.nth(n).is_keyword(Keyword::Atomic)
1533            && self.nth(n + 1).is_punct(Punct::LParen)
1534            && self.starts_decl_specifier(n + 2)
1535    }
1536
1537    fn parse_type_qualifiers(&mut self) -> TypeQualifiers {
1538        let mut quals = TypeQualifiers::NONE;
1539        while let Some(q) = self.eat_type_qualifier() {
1540            quals = quals.merge(q);
1541        }
1542        quals
1543    }
1544
1545    /// Parses a declaration-specifier list (or, with `allow_storage == false`,
1546    /// a specifier-qualifier list).
1547    fn parse_decl_specifiers(&mut self, allow_storage: bool) -> PResult<DeclSpecifiers> {
1548        let start = self.cur_range();
1549        let mut storage: Option<Spanned<StorageClass>> = None;
1550        let mut thread_local: Option<SourceRange> = None;
1551        let mut inline = false;
1552        let mut noreturn: Option<SourceRange> = None;
1553        let mut alignas: Vec<Alignment> = Vec::new();
1554        let mut attributes = Attributes::default();
1555        let mut quals = TypeQualifiers::NONE;
1556        let mut counts = SpecCounts::default();
1557        let mut tag: Option<Type> = None;
1558        let mut typedef_name: Option<Ident> = None;
1559        let mut auto_type: Option<SourceRange> = None;
1560        // Where the C23 `auto` was written, which is *not* the same question
1561        // as what [`DeclSpecifiers::storage`] holds; see the storage-class
1562        // branch below.
1563        let mut auto_kw: Option<SourceRange> = None;
1564        let mut consumed_any = false;
1565
1566        loop {
1567            let has_type = counts.any() || tag.is_some() || typedef_name.is_some();
1568            // C23 allows an attribute specifier sequence among the specifiers,
1569            // and GNU's `__attribute__((…))` goes in the same places.
1570            if self.at_attributes() {
1571                let attrs = self.parse_attributes()?;
1572                noreturn = noreturn.or(attrs.noreturn);
1573                attributes.merge(attrs);
1574                consumed_any = true;
1575                continue;
1576            }
1577            if self.at_keyword(Keyword::Extension) {
1578                self.advance();
1579                self.in_extension = true;
1580                consumed_any = true;
1581                continue;
1582            }
1583            if let Some(k) = self.peek().keyword() {
1584                // `_Thread_local` is not a storage class of its own: C11
1585                // 6.7.1p2 lets it sit beside `static` or `extern`, and at
1586                // block scope 6.7.1p3 requires one of them.
1587                if matches!(
1588                    k,
1589                    Keyword::ThreadLocal | Keyword::ThreadLocalName | Keyword::ThreadGnu
1590                ) {
1591                    let range = self.bump_range();
1592                    self.require_keyword(k, range);
1593                    consumed_any = true;
1594                    if !allow_storage {
1595                        self.error(
1596                            range,
1597                            format!("storage class '{}' is not allowed here", k.as_str()),
1598                        );
1599                    } else if thread_local.is_none() {
1600                        thread_local = Some(range);
1601                    }
1602                    continue;
1603                }
1604                let storage_class = match k {
1605                    Keyword::Typedef => Some(StorageClass::Typedef),
1606                    Keyword::Extern => Some(StorageClass::Extern),
1607                    Keyword::Static => Some(StorageClass::Static),
1608                    Keyword::Auto => Some(StorageClass::Auto),
1609                    Keyword::Register => Some(StorageClass::Register),
1610                    Keyword::Constexpr => Some(StorageClass::Constexpr),
1611                    _ => None,
1612                };
1613                if let Some(sc) = storage_class {
1614                    let range = self.bump_range();
1615                    self.require_keyword(k, range);
1616                    consumed_any = true;
1617                    // C23 6.7.1p2 keeps "at most one storage-class specifier"
1618                    // but makes `auto` the exception: it "may appear with all
1619                    // the others, except `typedef`". That is what
1620                    // `static auto c = 1UL;` is — an object with static
1621                    // storage duration whose type is inferred — and the
1622                    // exception is symmetric, so `auto static c = 1UL;` says
1623                    // the same thing. `auto` therefore does not claim the one
1624                    // slot: it is remembered in `auto_kw`, which is what
1625                    // decides the inference below, and yields the slot to the
1626                    // specifier that decides the storage duration whichever
1627                    // side of it that one was written.
1628                    let c23_auto = allow_storage
1629                        && self.standard >= Standard::C23
1630                        && (sc == StorageClass::Auto
1631                            || matches!(
1632                                storage,
1633                                Some(Spanned {
1634                                    node: StorageClass::Auto,
1635                                    ..
1636                                })
1637                            ))
1638                        && sc != StorageClass::Typedef
1639                        && !matches!(
1640                            storage,
1641                            Some(Spanned {
1642                                node: StorageClass::Typedef,
1643                                ..
1644                            })
1645                        );
1646                    // 6.7.1p2's other exception, in the same clause:
1647                    // `constexpr` "may appear with `auto`, `register` or
1648                    // `static`" — and with nothing else, so `extern
1649                    // constexpr` and `typedef constexpr` stay violations, and
1650                    // `thread_local` is refused where it is checked. The three
1651                    // it pairs with say where the object would *live* and
1652                    // `constexpr` says it is a constant instead, which is what
1653                    // decides the declaration here, so `constexpr` takes the
1654                    // slot from whichever side it was written.
1655                    let pairs_with_constexpr = |s: StorageClass| {
1656                        matches!(
1657                            s,
1658                            StorageClass::Static | StorageClass::Register | StorageClass::Auto
1659                        )
1660                    };
1661                    let c23_constexpr = allow_storage
1662                        && self.standard >= Standard::C23
1663                        && match (sc, storage.as_ref().map(|s| s.node)) {
1664                            (StorageClass::Constexpr, Some(prev)) => pairs_with_constexpr(prev),
1665                            (other, Some(StorageClass::Constexpr)) => pairs_with_constexpr(other),
1666                            _ => false,
1667                        };
1668                    if sc == StorageClass::Auto {
1669                        auto_kw = auto_kw.or(Some(range));
1670                    }
1671                    if !allow_storage {
1672                        self.error(
1673                            range,
1674                            format!("storage class '{}' is not allowed here", sc.as_str()),
1675                        );
1676                    } else if c23_constexpr {
1677                        if sc == StorageClass::Constexpr {
1678                            storage = Some(Spanned::new(sc, range));
1679                        }
1680                    } else if c23_auto {
1681                        // A specifier that is *not* `auto` takes the slot, so
1682                        // `auto` written first gives way and `auto` written
1683                        // second leaves what is already there alone. With
1684                        // nothing else in the declaration `auto` keeps it, as
1685                        // it did before C23.
1686                        if sc != StorageClass::Auto || storage.is_none() {
1687                            storage = Some(Spanned::new(sc, range));
1688                        }
1689                    } else if let Some(prev) = &storage {
1690                        self.error(
1691                            range,
1692                            format!(
1693                                "cannot combine storage class '{}' with '{}'",
1694                                sc.as_str(),
1695                                prev.node.as_str()
1696                            ),
1697                        );
1698                    } else {
1699                        storage = Some(Spanned::new(sc, range));
1700                    }
1701                    continue;
1702                }
1703                if let Some(q) = self.eat_type_qualifier() {
1704                    quals = quals.merge(q);
1705                    consumed_any = true;
1706                    continue;
1707                }
1708                if matches!(k, Keyword::Inline | Keyword::InlineGnu) {
1709                    let range = self.bump_range();
1710                    // C99 added `inline` (N741); `__inline__` is GCC's
1711                    // spelling of it and needs no entry point.
1712                    if k == Keyword::Inline {
1713                        self.require_standard(Standard::C99, "'inline'", range);
1714                    }
1715                    inline = true;
1716                    consumed_any = true;
1717                    continue;
1718                }
1719                if k == Keyword::Noreturn {
1720                    let range = self.bump_range();
1721                    self.require_keyword(k, range);
1722                    noreturn = noreturn.or(Some(range));
1723                    consumed_any = true;
1724                    continue;
1725                }
1726                if matches!(k, Keyword::Alignas | Keyword::AlignasName) {
1727                    // C11 6.7.5p6 allows several, and makes the strictest of
1728                    // them the one that holds; sema is where that is decided,
1729                    // since only it can evaluate the operands.
1730                    let spec = self.parse_alignment_specifier(k)?;
1731                    alignas.push(spec);
1732                    consumed_any = true;
1733                    continue;
1734                }
1735                // GNU's `__auto_type`, which is C23's `auto` under another
1736                // name and needs no entry point of its own.
1737                if k == Keyword::AutoType {
1738                    let range = self.bump_range();
1739                    auto_type = auto_type.or(Some(range));
1740                    consumed_any = true;
1741                    continue;
1742                }
1743                if matches!(
1744                    k,
1745                    Keyword::Typeof
1746                        | Keyword::TypeofUnqual
1747                        | Keyword::TypeofGnu
1748                        | Keyword::TypeofUnqualGnu
1749                ) {
1750                    let ty = self.parse_typeof_specifier(k)?;
1751                    if tag.is_some() || has_type {
1752                        self.error(ty.range, "two or more data types in declaration specifiers");
1753                    } else {
1754                        tag = Some(ty);
1755                    }
1756                    consumed_any = true;
1757                    continue;
1758                }
1759                // `_Atomic ( type-name )`, the type-specifier form (C11
1760                // 6.7.2.4). The qualifier form was taken by
1761                // `eat_type_qualifier` above, so only this one gets here.
1762                if k == Keyword::Atomic {
1763                    let range = self.bump_range();
1764                    self.require_keyword(k, range);
1765                    self.expect_punct(Punct::LParen, " after '_Atomic'")?;
1766                    let inner = self.parse_type_name()?;
1767                    self.expect_punct(Punct::RParen, " after the type name")?;
1768                    if tag.is_some() || has_type {
1769                        self.error(range, "two or more data types in declaration specifiers");
1770                    } else {
1771                        tag = Some(inner.ty);
1772                    }
1773                    quals = quals.merge(TypeQualifiers {
1774                        is_atomic: true,
1775                        ..TypeQualifiers::NONE
1776                    });
1777                    consumed_any = true;
1778                    continue;
1779                }
1780                // `_BitInt` is parsed so that the diagnostic is about it
1781                // rather than about the tokens that follow.
1782                if k == Keyword::BitInt {
1783                    let range = self.bump_range();
1784                    self.error(range, format!("'{}' is not supported yet", k.as_str()));
1785                    if self.at_punct(Punct::LParen) {
1786                        self.advance();
1787                        let _ = self.parse_conditional_expr()?;
1788                        self.expect_punct(Punct::RParen, " after the operand")?;
1789                    }
1790                    // Recover as `int`, so that the declaration does not also
1791                    // complain about a missing type specifier.
1792                    counts.int += 1;
1793                    consumed_any = true;
1794                    continue;
1795                }
1796                let counter = match k {
1797                    Keyword::Void => Some(&mut counts.void),
1798                    Keyword::Char => Some(&mut counts.char),
1799                    Keyword::Short => Some(&mut counts.short),
1800                    Keyword::Int => Some(&mut counts.int),
1801                    Keyword::Long => Some(&mut counts.long),
1802                    Keyword::Float => Some(&mut counts.float),
1803                    Keyword::Double => Some(&mut counts.double),
1804                    Keyword::Signed => Some(&mut counts.signed),
1805                    Keyword::Unsigned => Some(&mut counts.unsigned),
1806                    Keyword::Bool | Keyword::BoolName => Some(&mut counts.bool),
1807                    Keyword::Complex => Some(&mut counts.complex),
1808                    Keyword::Imaginary => Some(&mut counts.imaginary),
1809                    Keyword::Int128 => Some(&mut counts.int128),
1810                    _ => None,
1811                };
1812                if let Some(c) = counter {
1813                    *c += 1;
1814                    self.advance();
1815                    consumed_any = true;
1816                    continue;
1817                }
1818                if matches!(k, Keyword::Struct | Keyword::Union) {
1819                    let ty = self.parse_record_specifier()?;
1820                    if tag.is_some() || has_type {
1821                        self.error(ty.range, "two or more data types in declaration specifiers");
1822                    } else {
1823                        tag = Some(ty);
1824                    }
1825                    consumed_any = true;
1826                    continue;
1827                }
1828                if k == Keyword::Enum {
1829                    let ty = self.parse_enum_specifier()?;
1830                    if tag.is_some() || has_type {
1831                        self.error(ty.range, "two or more data types in declaration specifiers");
1832                    } else {
1833                        tag = Some(ty);
1834                    }
1835                    consumed_any = true;
1836                    continue;
1837                }
1838                break;
1839            }
1840
1841            // The spelling of `_Noreturn` that every standard accepts, which
1842            // is what the bundled headers mark `exit` and `abort` with: they
1843            // are read by `c99!` blocks too, where `_Noreturn` itself would be
1844            // an error.
1845            if self.peek().ident() == Some(NORETURN_BUILTIN) {
1846                let range = self.bump_range();
1847                noreturn = noreturn.or(Some(range));
1848                consumed_any = true;
1849                continue;
1850            }
1851
1852            // An extended floating type: `__float128`, `_Float128`, the rest
1853            // of TS 18661-3's set. None of them is a type specifier here, and
1854            // without this they would look like an identifier and turn one
1855            // refusal into "type specifier missing" plus whatever follows.
1856            if !has_type
1857                && let Some(name) = self.peek().ident()
1858                && let Some(what) = extended_float_type(name)
1859            {
1860                let range = self.cur_range();
1861                return Err(self.error_bail(
1862                    range,
1863                    format!(
1864                        "'{name}' is not supported: {what} has no Rust type to become, and \
1865                         mapping it onto 'double' would compute and pass the wrong values"
1866                    ),
1867                ));
1868            }
1869
1870            // A `typedef` name is a type specifier only while we do not have
1871            // one yet; otherwise it is the declarator's identifier.
1872            let is_typedef_use = match self.peek().ident() {
1873                Some(name) => !has_type && self.is_typedef_name(name),
1874                None => false,
1875            };
1876            if is_typedef_use {
1877                let id = self.eat_ident().expect("checked above");
1878                typedef_name = Some(id);
1879                consumed_any = true;
1880                continue;
1881            }
1882            break;
1883        }
1884
1885        if !consumed_any {
1886            let range = self.cur_range();
1887            // A name a newer revision would have made a keyword is almost
1888            // always that keyword rather than a declaration nobody finished
1889            // writing, and saying so is the difference between a fix and a
1890            // puzzle.
1891            if let Some(message) = self.newer_keyword_here() {
1892                return Err(self.error_bail(range, message));
1893            }
1894            // A declaration with no specifiers at all is an `int` one —
1895            // `f() { … }` and `(*fp)();` at file scope are the common
1896            // shapes — so the declarator is parsed and `build_base_type`
1897            // supplies the type, which is where C89's implicit `int` is
1898            // accepted and every later revision's "type specifier missing"
1899            // comes from. Anything that cannot begin a declarator is still
1900            // nothing at all.
1901            if !self.starts_declarator() {
1902                let found = self.describe_cur();
1903                return Err(
1904                    self.error_bail(range, format!("expected a declaration, found {found}"))
1905                );
1906            }
1907        }
1908
1909        // With nothing consumed the specifiers are where the declarator
1910        // begins, which is where a diagnostic about the implicit `int` has to
1911        // point.
1912        let specs_range = if consumed_any {
1913            self.span_to_here(start)
1914        } else {
1915            self.cur_range()
1916        };
1917        // C23's `auto x = e;` and GNU's `__auto_type x = e;`: a declaration
1918        // with no type specifier at all takes its type from the initialiser.
1919        let no_type = !counts.any() && tag.is_none() && typedef_name.is_none();
1920        let inferred = no_type
1921            && (auto_type.is_some() || (self.standard >= Standard::C23 && auto_kw.is_some()));
1922        let base = if inferred {
1923            Type::new(TypeKind::Auto, quals, specs_range)
1924        } else {
1925            self.build_base_type(&counts, tag, typedef_name, quals, specs_range)
1926        };
1927        // `__attribute__((aligned(N)))` on a declaration says exactly what
1928        // `_Alignas(N)` says, so the two go through one path.
1929        if let Some(aligned) = attributes.aligned.clone() {
1930            alignas.push(aligned);
1931        }
1932
1933        Ok(DeclSpecifiers {
1934            storage,
1935            thread_local,
1936            inline,
1937            noreturn,
1938            alignas,
1939            attrs: attributes,
1940            base,
1941            range: specs_range,
1942        })
1943    }
1944
1945    /// `_Alignas ( constant-expression )` or `_Alignas ( type-name )`.
1946    fn parse_alignment_specifier(&mut self, keyword: Keyword) -> PResult<Alignment> {
1947        let start = self.cur_range();
1948        self.require_keyword(keyword, start);
1949        self.advance();
1950        let name = keyword.as_str();
1951        self.expect_punct(Punct::LParen, &format!(" after '{name}'"))?;
1952        let kind = if self.starts_declaration() {
1953            AlignmentKind::Type(Box::new(self.parse_type_name()?))
1954        } else {
1955            AlignmentKind::Expr(self.parse_conditional_expr()?)
1956        };
1957        self.expect_punct(Punct::RParen, &format!(" after the operand of '{name}'"))?;
1958        Ok(Alignment {
1959            kind,
1960            from_attribute: false,
1961            range: self.span_to_here(start),
1962        })
1963    }
1964
1965    /// `typeof ( expression )` or `typeof ( type-name )`.
1966    ///
1967    /// `typeof_unqual` parses the same way and differs in one thing: it takes
1968    /// the *unqualified* type of the operand. Of the qualifiers, only
1969    /// `_Atomic` is part of a resolved type here — `const` on a pointee is not
1970    /// a top-level qualifier, and `volatile` and `restrict` say nothing to the
1971    /// generated Rust — so `_Atomic` is what the unqualified form drops.
1972    fn parse_typeof_specifier(&mut self, keyword: Keyword) -> PResult<Type> {
1973        let start = self.cur_range();
1974        self.require_keyword(keyword, start);
1975        self.advance();
1976        let name = keyword.as_str();
1977        self.expect_punct(Punct::LParen, &format!(" after '{name}'"))?;
1978        let operand = if self.starts_declaration() {
1979            TypeofOperand::Type(self.parse_type_name()?)
1980        } else {
1981            TypeofOperand::Expr(self.parse_expr()?)
1982        };
1983        self.expect_punct(Punct::RParen, &format!(" after the operand of '{name}'"))?;
1984        let range = self.span_to_here(start);
1985        let id = self.add_typeof(operand);
1986        let unqual = matches!(keyword, Keyword::TypeofUnqual | Keyword::TypeofUnqualGnu);
1987        Ok(Type::plain(TypeKind::Typeof { id, unqual }, range))
1988    }
1989
1990    fn build_base_type(
1991        &mut self,
1992        counts: &SpecCounts,
1993        tag: Option<Type>,
1994        typedef_name: Option<Ident>,
1995        quals: TypeQualifiers,
1996        range: SourceRange,
1997    ) -> Type {
1998        if let Some(mut ty) = tag {
1999            if counts.any() || typedef_name.is_some() {
2000                self.error(range, "two or more data types in declaration specifiers");
2001            }
2002            ty.qualifiers = ty.qualifiers.merge(quals);
2003            return ty;
2004        }
2005        if let Some(name) = typedef_name {
2006            if counts.any() {
2007                self.error(range, "two or more data types in declaration specifiers");
2008            }
2009            return Type::new(TypeKind::Typedef(name), quals, range);
2010        }
2011        if !counts.any() {
2012            // C89 6.5.2: a declaration with no type specifier declares an
2013            // `int`. C99 removed the rule (N635) and GCC diagnoses it in every
2014            // later mode, GNU dialects included, so this is the standard
2015            // rather than the dialect talking.
2016            if !self.gating.implicit_int() {
2017                self.error(
2018                    range,
2019                    "type specifier missing; C99 does not support implicit 'int'",
2020                );
2021            }
2022            return Type::new(
2023                TypeKind::Int {
2024                    sign: Sign::Signed,
2025                    size: IntSize::Int,
2026                },
2027                quals,
2028                range,
2029            );
2030        }
2031        if counts.bool > 0 {
2032            self.require_standard(Standard::C99, "'_Bool'", range);
2033        }
2034        if counts.complex > 0 {
2035            self.require_standard(Standard::C99, "'_Complex'", range);
2036        }
2037        if counts.imaginary > 0 {
2038            self.require_standard(Standard::C99, "'_Imaginary'", range);
2039        }
2040        if counts.long > 1 {
2041            self.require_standard(Standard::C99, "'long long'", range);
2042        }
2043        // `_Complex int`, `_Complex char`, `__complex__ long` — GCC's complex
2044        // *integer* types, which are an extension of their own and which
2045        // nothing in the generated Rust could be. Saying so beats the
2046        // "cannot combine 'char' with other type specifiers" the chain below
2047        // would otherwise produce.
2048        if (counts.complex > 0 || counts.imaginary > 0)
2049            && counts.float == 0
2050            && counts.double == 0
2051            && counts.int
2052                + counts.char
2053                + counts.short
2054                + counts.long
2055                + counts.signed
2056                + counts.unsigned
2057                + counts.int128
2058                + counts.bool
2059                + counts.void
2060                > 0
2061        {
2062            self.error(
2063                range,
2064                "a complex integer type is a GNU extension that cinrs does not support; \
2065                 the complex types are 'float _Complex', 'double _Complex' and \
2066                 'long double _Complex'",
2067            );
2068            let kind = if counts.complex > 0 {
2069                TypeKind::Complex(FloatSize::Double)
2070            } else {
2071                TypeKind::Imaginary(FloatSize::Double)
2072            };
2073            return Type::new(kind, quals, range);
2074        }
2075
2076        let sign = if counts.unsigned > 0 {
2077            Some(Sign::Unsigned)
2078        } else if counts.signed > 0 {
2079            Some(Sign::Signed)
2080        } else {
2081            None
2082        };
2083        if counts.signed > 0 && counts.unsigned > 0 {
2084            self.error(range, "cannot combine 'signed' with 'unsigned'");
2085        }
2086
2087        let kind = if counts.void > 0 {
2088            if counts.void > 1 || counts.any_besides(&["void"]) {
2089                self.error(range, "cannot combine 'void' with other type specifiers");
2090            }
2091            TypeKind::Void
2092        } else if counts.bool > 0 {
2093            if counts.any_besides(&["_Bool"]) {
2094                self.error(range, "cannot combine '_Bool' with other type specifiers");
2095            }
2096            TypeKind::Bool
2097        } else if counts.char > 0 {
2098            if counts.any_besides(&["char", "signed", "unsigned"]) {
2099                self.error(range, "cannot combine 'char' with other type specifiers");
2100            }
2101            TypeKind::Char(sign)
2102        } else if counts.float > 0 || counts.double > 0 {
2103            let size = if counts.float > 0 {
2104                if counts.double > 0 {
2105                    self.error(range, "cannot combine 'float' with 'double'");
2106                }
2107                if counts.long > 0 {
2108                    self.error(range, "cannot combine 'long' with 'float'");
2109                }
2110                FloatSize::Float
2111            } else if counts.long > 0 {
2112                FloatSize::LongDouble
2113            } else {
2114                FloatSize::Double
2115            };
2116            if sign.is_some() {
2117                self.error(
2118                    range,
2119                    "cannot combine 'signed' or 'unsigned' with a floating type",
2120                );
2121            }
2122            if counts.complex > 0 {
2123                TypeKind::Complex(size)
2124            } else if counts.imaginary > 0 {
2125                TypeKind::Imaginary(size)
2126            } else {
2127                TypeKind::Float(size)
2128            }
2129        } else if counts.complex > 0 || counts.imaginary > 0 {
2130            // `__complex__ x;` on its own means `double _Complex` in GNU C,
2131            // and saying so gets the honest "complex types are not supported"
2132            // rather than a complaint about a missing type specifier.
2133            if counts.complex > 0 {
2134                TypeKind::Complex(FloatSize::Double)
2135            } else {
2136                TypeKind::Imaginary(FloatSize::Double)
2137            }
2138        } else if counts.int128 > 0 {
2139            // GCC's `__int128` combines with `signed` and `unsigned` and with
2140            // nothing else — not even `int`.
2141            if counts.int128 > 1 || counts.any_besides(&["__int128", "signed", "unsigned"]) {
2142                self.error(
2143                    range,
2144                    "cannot combine '__int128' with other type specifiers",
2145                );
2146            }
2147            TypeKind::Int {
2148                sign: sign.unwrap_or(Sign::Signed),
2149                size: IntSize::Int128,
2150            }
2151        } else {
2152            let size = if counts.short > 0 {
2153                if counts.long > 0 {
2154                    self.error(range, "cannot combine 'short' with 'long'");
2155                }
2156                IntSize::Short
2157            } else {
2158                match counts.long {
2159                    0 => IntSize::Int,
2160                    1 => IntSize::Long,
2161                    2 => IntSize::LongLong,
2162                    _ => {
2163                        self.error(range, "'long long long' is too long for cinrs");
2164                        IntSize::LongLong
2165                    }
2166                }
2167            };
2168            TypeKind::Int {
2169                sign: sign.unwrap_or(Sign::Signed),
2170                size,
2171            }
2172        };
2173
2174        Type::new(kind, quals, range)
2175    }
2176}
2177
2178impl SpecCounts {
2179    /// Whether any counter outside `allowed` is non-zero.
2180    fn any_besides(&self, allowed: &[&str]) -> bool {
2181        let all: [(&str, u32); 13] = [
2182            ("__int128", self.int128),
2183            ("void", self.void),
2184            ("char", self.char),
2185            ("short", self.short),
2186            ("int", self.int),
2187            ("long", self.long),
2188            ("float", self.float),
2189            ("double", self.double),
2190            ("signed", self.signed),
2191            ("unsigned", self.unsigned),
2192            ("_Bool", self.bool),
2193            ("_Complex", self.complex),
2194            ("_Imaginary", self.imaginary),
2195        ];
2196        all.iter()
2197            .any(|(name, count)| *count > 0 && !allowed.contains(name))
2198    }
2199}
2200
2201// ---------------------------------------------------------------------------
2202// struct / union / enum
2203// ---------------------------------------------------------------------------
2204
2205impl Parser<'_> {
2206    /// Stores a `struct`/`union` specifier and hands back its id.
2207    fn add_record(&mut self, spec: RecordSpec) -> RecordSpecId {
2208        let id = RecordSpecId(self.records.len() as u32);
2209        self.records.push(spec);
2210        id
2211    }
2212
2213    /// Stores an `enum` specifier and hands back its id.
2214    fn add_enum(&mut self, spec: EnumSpec) -> EnumSpecId {
2215        let id = EnumSpecId(self.enums.len() as u32);
2216        self.enums.push(spec);
2217        id
2218    }
2219
2220    /// Stores a `typeof` operand and hands back its id.
2221    fn add_typeof(&mut self, operand: TypeofOperand) -> TypeofId {
2222        let id = TypeofId(self.typeofs.len() as u32);
2223        self.typeofs.push(operand);
2224        id
2225    }
2226
2227    /// A `struct`/`union` specifier, whose body may hold more of them.
2228    ///
2229    /// The nesting is counted: a member list is parsed by a recursive call, so
2230    /// a specifier nested past [`MAX_RECURSION_DEPTH`] is a diagnostic rather
2231    /// than a stack overflow. C23 5.2.5.2p1 asks for 63 levels.
2232    fn parse_record_specifier(&mut self) -> PResult<Type> {
2233        self.enter()?;
2234        let result = self.parse_record_specifier_inner();
2235        self.leave();
2236        result
2237    }
2238
2239    fn parse_record_specifier_inner(&mut self) -> PResult<Type> {
2240        let start = self.cur_range();
2241        // What `#pragma pack` was asking for *here* is what applies to this
2242        // record; a pragma written after it changes nothing about it.
2243        let pack = self.packing.at(self.pos);
2244        let kind = match self.peek().keyword() {
2245            Some(Keyword::Struct) => RecordKind::Struct,
2246            Some(Keyword::Union) => RecordKind::Union,
2247            _ => unreachable!("caller checked the keyword"),
2248        };
2249        self.advance();
2250        let mut attrs = self.parse_attributes()?;
2251        let name = self.eat_ident();
2252        let mut asserts = Vec::new();
2253        let fields = if self.at_punct(Punct::LBrace) {
2254            let (fields, found) = self.parse_struct_body()?;
2255            asserts = found;
2256            Some(fields)
2257        } else {
2258            if name.is_none() {
2259                let range = self.cur_range();
2260                let found = self.describe_cur();
2261                return Err(self.error_bail(
2262                    range,
2263                    format!(
2264                        "expected identifier or '{{' after '{}', found {found}",
2265                        kind.as_str()
2266                    ),
2267                ));
2268            }
2269            None
2270        };
2271        // GCC lets `__attribute__((packed))` come after the member list too,
2272        // which is where most code writes it.
2273        if self.at_attributes() {
2274            let after = self.parse_attributes()?;
2275            attrs.merge(after);
2276        }
2277        let range = self.span_to_here(start);
2278        let id = self.add_record(RecordSpec {
2279            kind,
2280            name,
2281            fields,
2282            asserts,
2283            attrs,
2284            pack,
2285            range,
2286        });
2287        Ok(Type::plain(TypeKind::Record(id), range))
2288    }
2289
2290    /// The member list of a `struct` or `union`, and the `_Static_assert`
2291    /// declarations written among the members.
2292    fn parse_struct_body(&mut self) -> PResult<(Vec<FieldDecl>, Vec<StaticAssert>)> {
2293        self.expect_punct(Punct::LBrace, " to open a member list")?;
2294        let mut fields = Vec::new();
2295        let mut asserts = Vec::new();
2296        while !self.at_punct(Punct::RBrace) && !self.at_eof() {
2297            let before = self.pos;
2298            // A stray `;` is harmless; skip it.
2299            if self.eat_punct(Punct::Semi).is_some() {
2300                continue;
2301            }
2302            if self.at_static_assert() {
2303                asserts.push(self.parse_static_assert()?);
2304                continue;
2305            }
2306            let start = self.cur_range();
2307            while self.eat_keyword(Keyword::Extension).is_some() {
2308                self.in_extension = true;
2309            }
2310            let leading = self.parse_attributes()?;
2311            let mut specs = self.parse_decl_specifiers(false)?;
2312            specs.attrs.merge(leading);
2313
2314            if self.at_punct(Punct::Semi) {
2315                // An anonymous struct/union member: C11 6.7.2.1p13.
2316                let range = self.span_to_here(start);
2317                self.require_standard(Standard::C11, "an anonymous struct or union member", range);
2318                fields.push(FieldDecl {
2319                    ty: specs.base.clone(),
2320                    attrs: specs.attrs.clone(),
2321                    specifiers: specs,
2322                    name: None,
2323                    bit_width: None,
2324                    range,
2325                });
2326                self.expect_punct(Punct::Semi, " after member declaration")?;
2327                continue;
2328            }
2329
2330            loop {
2331                let (name, ty, dstart, mut attrs) = if self.at_punct(Punct::Colon) {
2332                    (
2333                        None,
2334                        specs.base.clone(),
2335                        self.cur_range(),
2336                        Attributes::default(),
2337                    )
2338                } else {
2339                    let mut d = self.parse_declarator(specs.base.clone(), true)?;
2340                    self.parse_declarator_tail(&mut d)?;
2341                    (d.name, d.ty, d.range, d.attrs)
2342                };
2343                let bit_width = if self.eat_punct(Punct::Colon).is_some() {
2344                    Some(self.parse_conditional_expr()?)
2345                } else {
2346                    None
2347                };
2348                // A member's attributes may follow its width.
2349                if self.at_attributes() {
2350                    let after = self.parse_attributes()?;
2351                    attrs.merge(after);
2352                }
2353                attrs.merge(specs.attrs.clone());
2354                let range = self.span_to_here(dstart);
2355                fields.push(FieldDecl {
2356                    specifiers: specs.clone(),
2357                    name,
2358                    ty,
2359                    bit_width,
2360                    attrs,
2361                    range,
2362                });
2363                if self.eat_punct(Punct::Comma).is_none() {
2364                    break;
2365                }
2366            }
2367            self.expect_punct(Punct::Semi, " after member declaration")?;
2368            if self.pos == before {
2369                self.advance();
2370            }
2371        }
2372        self.expect_punct(Punct::RBrace, " to close a member list")?;
2373        Ok((fields, asserts))
2374    }
2375
2376    fn parse_enum_specifier(&mut self) -> PResult<Type> {
2377        let start = self.cur_range();
2378        self.advance(); // `enum`
2379        // An attribute specifier sequence is allowed here and ignored.
2380        let _ = self.parse_attributes()?;
2381        let name = self.eat_ident();
2382        // C23's fixed underlying type: `enum E : unsigned char { … }`.
2383        //
2384        // The `:` only introduces one when a type follows it. Among the members
2385        // of a record, `enum E : 3;` is an unnamed bit-field of the
2386        // enumeration's type — which C has had for far longer — and the width
2387        // is an expression, never a type.
2388        let underlying = if self.at_punct(Punct::Colon) && self.starts_decl_specifier(1) {
2389            let colon = self.bump_range();
2390            self.require_standard(Standard::C23, "an enum with a fixed underlying type", colon);
2391            let specs = self.parse_decl_specifiers(false)?;
2392            Some(specs.base)
2393        } else {
2394            None
2395        };
2396        let enumerators = if self.at_punct(Punct::LBrace) {
2397            self.advance();
2398            let mut list = Vec::new();
2399            while !self.at_punct(Punct::RBrace) && !self.at_eof() {
2400                let ename = self.expect_ident(" in enumerator list")?;
2401                self.declare(&ename.name.clone(), SymKind::Ordinary);
2402                // An attribute specifier sequence is allowed here and ignored.
2403                let _ = self.parse_attributes()?;
2404                let value = if self.eat_punct(Punct::Assign).is_some() {
2405                    Some(self.parse_conditional_expr()?)
2406                } else {
2407                    None
2408                };
2409                let range = self.span_to_here(ename.range);
2410                list.push(Enumerator {
2411                    name: ename,
2412                    value,
2413                    range,
2414                });
2415                let Some(comma) = self.eat_punct(Punct::Comma) else {
2416                    break;
2417                };
2418                if self.at_punct(Punct::RBrace) {
2419                    self.require_standard(
2420                        Standard::C99,
2421                        "a trailing comma in an enumerator list",
2422                        comma,
2423                    );
2424                }
2425            }
2426            self.expect_punct(Punct::RBrace, " to close an enumerator list")?;
2427            Some(list)
2428        } else {
2429            if name.is_none() {
2430                let range = self.cur_range();
2431                let found = self.describe_cur();
2432                return Err(self.error_bail(
2433                    range,
2434                    format!("expected identifier or '{{' after 'enum', found {found}"),
2435                ));
2436            }
2437            None
2438        };
2439        let range = self.span_to_here(start);
2440        let id = self.add_enum(EnumSpec {
2441            name,
2442            enumerators,
2443            underlying,
2444            range,
2445        });
2446        Ok(Type::plain(TypeKind::Enum(id), range))
2447    }
2448}
2449
2450// ---------------------------------------------------------------------------
2451// declarators
2452// ---------------------------------------------------------------------------
2453
2454/// The outcome of parsing one declarator.
2455#[derive(Clone, Debug)]
2456pub struct DeclaratorResult {
2457    /// The declared name, absent for an abstract declarator.
2458    pub name: Option<Ident>,
2459    /// The type the declarator builds from the base type.
2460    pub ty: Type,
2461    /// What `__attribute__((…))` on the declarator asked for.
2462    pub attrs: Attributes,
2463    /// The symbol `__asm__("name")` renamed it to.
2464    pub asm_label: Option<Spanned<String>>,
2465    /// Where the declarator was written.
2466    pub range: SourceRange,
2467}
2468
2469impl Parser<'_> {
2470    /// Parses a declarator, applying it to `base`.
2471    ///
2472    /// With `allow_abstract` the identifier may be omitted, which is what
2473    /// parameter declarations and type names need.
2474    fn parse_declarator(&mut self, base: Type, allow_abstract: bool) -> PResult<DeclaratorResult> {
2475        self.enter()?;
2476        let result = self.parse_declarator_inner(base, allow_abstract);
2477        self.leave();
2478        result
2479    }
2480
2481    fn parse_declarator_inner(
2482        &mut self,
2483        base: Type,
2484        allow_abstract: bool,
2485    ) -> PResult<DeclaratorResult> {
2486        let start = self.cur_range();
2487        // GNU allows an attribute at the head of a declarator, which is where
2488        // a calling convention is usually written.
2489        let leading = self.parse_attributes()?;
2490        let mut ty = base;
2491
2492        // `* qual* ` repeated: the leftmost `*` becomes the innermost pointer,
2493        // so `int * const * p` is "pointer to const pointer to int".
2494        while self.at_punct(Punct::Star) {
2495            let star = self.bump_range();
2496            let mut quals = self.parse_type_qualifiers();
2497            // GNU allows `int * __attribute__((x)) p;` and mixes the two.
2498            while self.at_attributes() {
2499                let _ = self.parse_attributes()?;
2500                quals = quals.merge(self.parse_type_qualifiers());
2501            }
2502            let range = self.span_to_here(star);
2503            ty = Type::new(TypeKind::Pointer(Box::new(ty)), quals, range);
2504        }
2505
2506        if self.at_punct(Punct::LParen) && self.is_grouping_paren() {
2507            let save = self.pos;
2508            let balanced = self.skip_balanced_parens();
2509            if !balanced {
2510                let range = self.cur_range();
2511                return Err(self.error_bail(range, "unbalanced '(' in declarator"));
2512            }
2513            let rparen = self.pos - 1;
2514            ty = self.parse_type_suffix(ty)?;
2515            let after = self.pos;
2516            self.pos = save + 1;
2517            let inner = self.parse_declarator(ty, allow_abstract)?;
2518            if self.pos != rparen {
2519                let range = self.cur_range();
2520                let found = self.describe_cur();
2521                return Err(self.error_bail(
2522                    range,
2523                    format!("expected ')' after declarator, found {found}"),
2524                ));
2525            }
2526            self.pos = after;
2527            self.last_range = self.tokens[after - 1].range;
2528            let mut attrs = inner.attrs;
2529            attrs.merge(leading);
2530            return Ok(DeclaratorResult {
2531                name: inner.name,
2532                ty: inner.ty,
2533                attrs,
2534                asm_label: inner.asm_label,
2535                range: self.span_to_here(start),
2536            });
2537        }
2538
2539        let name = match self.eat_ident() {
2540            Some(id) => Some(id),
2541            None if allow_abstract => None,
2542            None => {
2543                let range = self.cur_range();
2544                let found = self.describe_cur();
2545                return Err(self.error_bail(
2546                    range,
2547                    format!("expected identifier in declarator, found {found}"),
2548                ));
2549            }
2550        };
2551        // C23 allows an attribute specifier sequence after the declared name
2552        // (`int x [[deprecated]];`), and so does GNU.
2553        let mut attrs = self.parse_attributes()?;
2554        attrs.merge(leading);
2555        let ty = self.parse_type_suffix(ty)?;
2556        Ok(DeclaratorResult {
2557            name,
2558            ty,
2559            attrs,
2560            asm_label: None,
2561            range: self.span_to_here(start),
2562        })
2563    }
2564
2565    /// At a `(` that begins a direct-declarator: does it group a nested
2566    /// declarator, or is it a parameter list?
2567    ///
2568    /// An attribute may stand at the head of either — `int (__attribute__((x))
2569    /// *)(void)` groups a declarator and `int (__attribute__((x)) int)` is a
2570    /// parameter list — so the question is asked of what follows it.
2571    fn is_grouping_paren(&self) -> bool {
2572        let after = self.after_attributes(1);
2573        !self.nth(after).is_punct(Punct::RParen) && !self.starts_decl_specifier(after)
2574    }
2575
2576    /// The offset of the first token after any attribute specifiers at `n`.
2577    ///
2578    /// Used for lookahead only, so it never reports: an unbalanced clause
2579    /// stops at the end of the input and the caller's own parse reports it.
2580    fn after_attributes(&self, mut n: usize) -> usize {
2581        loop {
2582            let brackets =
2583                self.nth(n).is_punct(Punct::LBracket) && self.nth(n + 1).is_punct(Punct::LBracket);
2584            if !self.nth(n).is_keyword(Keyword::Attribute) && !brackets {
2585                return n;
2586            }
2587            let (open, close) = if brackets {
2588                (Punct::LBracket, Punct::RBracket)
2589            } else {
2590                (Punct::LParen, Punct::RParen)
2591            };
2592            let mut i = if brackets { n } else { n + 1 };
2593            let mut depth = 0i32;
2594            while !self.nth(i).is_eof() {
2595                if self.nth(i).is_punct(open) {
2596                    depth += 1;
2597                } else if self.nth(i).is_punct(close) {
2598                    depth -= 1;
2599                    if depth == 0 {
2600                        i += 1;
2601                        break;
2602                    }
2603                }
2604                i += 1;
2605            }
2606            if i <= n {
2607                return n;
2608            }
2609            n = i;
2610        }
2611    }
2612
2613    /// From the current `(`, skips to just past its matching `)`.
2614    fn skip_balanced_parens(&mut self) -> bool {
2615        let mut depth = 0i32;
2616        while !self.at_eof() {
2617            if self.at_punct(Punct::LParen) {
2618                depth += 1;
2619            } else if self.at_punct(Punct::RParen) {
2620                depth -= 1;
2621                if depth == 0 {
2622                    self.advance();
2623                    return true;
2624                }
2625            }
2626            self.advance();
2627        }
2628        false
2629    }
2630
2631    /// Parses the `[...]` and `(...)` suffixes of a direct-declarator.
2632    ///
2633    /// The remaining suffixes are resolved *before* wrapping, so `int a[3][4]`
2634    /// becomes "array of 3 array of 4 int" rather than the other way round.
2635    fn parse_type_suffix(&mut self, ty: Type) -> PResult<Type> {
2636        if let Some(lb) = self.eat_punct(Punct::LBracket) {
2637            let mut is_static = false;
2638            let mut quals = TypeQualifiers::NONE;
2639            loop {
2640                if self.at_keyword(Keyword::Static) {
2641                    self.advance();
2642                    is_static = true;
2643                    continue;
2644                }
2645                match self.eat_type_qualifier() {
2646                    Some(q) => quals = quals.merge(q),
2647                    None => break,
2648                }
2649            }
2650            if is_static {
2651                self.require_standard(
2652                    Standard::C99,
2653                    "'static' in an array parameter declarator",
2654                    lb,
2655                );
2656            }
2657            let size = if self.at_punct(Punct::RBracket) {
2658                ArraySize::Unspecified
2659            } else if self.at_punct(Punct::Star) && self.nth(1).is_punct(Punct::RBracket) {
2660                let star = self.bump_range();
2661                self.require_standard(Standard::C99, "'[*]'", star);
2662                ArraySize::Star
2663            } else {
2664                ArraySize::Expr(Box::new(self.parse_assignment_expr()?))
2665            };
2666            let rb = self.expect_punct(Punct::RBracket, " after array bound")?;
2667            let elem = self.parse_type_suffix(ty)?;
2668            return Ok(Type::plain(
2669                TypeKind::Array {
2670                    elem: Box::new(elem),
2671                    size,
2672                    qualifiers: quals,
2673                    is_static,
2674                },
2675                lb.join(rb),
2676            ));
2677        }
2678
2679        if let Some(lp) = self.eat_punct(Punct::LParen) {
2680            let list = self.parse_param_list()?;
2681            let rp = self.expect_punct(Punct::RParen, " after parameter list")?;
2682            let ret = self.parse_type_suffix(ty)?;
2683            return Ok(Type::plain(
2684                TypeKind::Function(Box::new(FunctionType {
2685                    ret,
2686                    params: list.params,
2687                    variadic: list.ellipsis.is_some(),
2688                    ellipsis: list.ellipsis,
2689                    has_prototype: list.has_prototype,
2690                    kr_names: list.kr_names,
2691                    old_style: false,
2692                })),
2693                lp.join(rp),
2694            ));
2695        }
2696
2697        Ok(ty)
2698    }
2699
2700    fn parse_param_list(&mut self) -> PResult<ParamList> {
2701        if self.at_punct(Punct::RParen) {
2702            return Ok(ParamList::default());
2703        }
2704        // `(void)` — an explicitly empty prototype.
2705        if self.at_keyword(Keyword::Void) && self.nth(1).is_punct(Punct::RParen) {
2706            self.advance();
2707            return Ok(ParamList {
2708                has_prototype: true,
2709                ..ParamList::default()
2710            });
2711        }
2712        // An old-style identifier list: `int f(a, b)`.
2713        let kr = match self.peek().ident() {
2714            Some(name) => !self.is_typedef_name(name),
2715            None => false,
2716        };
2717        if kr {
2718            let mut names = Vec::new();
2719            loop {
2720                names.push(self.expect_ident(" in parameter list")?);
2721                if self.eat_punct(Punct::Comma).is_none() {
2722                    break;
2723                }
2724            }
2725            return Ok(ParamList {
2726                kr_names: names,
2727                ..ParamList::default()
2728            });
2729        }
2730
2731        // Parameter names are visible to later parameters' declarators, so
2732        // they get their own scope.
2733        self.push_scope();
2734        let result = self.parse_prototype_params();
2735        self.pop_scope();
2736        result
2737    }
2738
2739    fn parse_prototype_params(&mut self) -> PResult<ParamList> {
2740        let mut params = Vec::new();
2741        let mut ellipsis = None;
2742        loop {
2743            if self.at_punct(Punct::Ellipsis) {
2744                ellipsis = Some(self.bump_range());
2745                break;
2746            }
2747            let start = self.cur_range();
2748            let specs = self.parse_decl_specifiers(true)?;
2749            let declarator = self.parse_declarator(specs.base.clone(), true)?;
2750            if let Some(name) = &declarator.name {
2751                self.declare(&name.name.clone(), SymKind::Ordinary);
2752            }
2753            let range = self.span_to_here(start);
2754            // A parameter is not an object whose scope a `cleanup` could hang
2755            // on: it is the caller's value, and GCC drops the attribute with
2756            // "'cleanup' attribute ignored". Dropping it silently would change
2757            // what the program does.
2758            for cleanup in [&declarator.attrs.cleanup, &specs.attrs.cleanup]
2759                .into_iter()
2760                .flatten()
2761            {
2762                self.error(
2763                    cleanup.range,
2764                    "'cleanup' attribute ignored on a parameter: it calls the function when \
2765                     the object goes out of scope, and only an object with automatic storage \
2766                     duration ever does",
2767                );
2768            }
2769            params.push(ParamDecl {
2770                specifiers: specs,
2771                name: declarator.name,
2772                ty: declarator.ty,
2773                range,
2774            });
2775            if self.eat_punct(Punct::Comma).is_none() {
2776                break;
2777            }
2778        }
2779        Ok(ParamList {
2780            params,
2781            ellipsis,
2782            has_prototype: true,
2783            kr_names: Vec::new(),
2784        })
2785    }
2786
2787    fn parse_type_name(&mut self) -> PResult<TypeName> {
2788        let start = self.cur_range();
2789        let specs = self.parse_decl_specifiers(false)?;
2790        let declarator = self.parse_declarator(specs.base.clone(), true)?;
2791        if let Some(name) = &declarator.name {
2792            let range = name.range;
2793            self.error(range, "a type name must not declare an identifier");
2794        }
2795        Ok(TypeName {
2796            specifiers: specs,
2797            ty: declarator.ty,
2798            range: self.span_to_here(start),
2799        })
2800    }
2801}
2802
2803/// The pieces of a parsed parameter list.
2804#[derive(Default)]
2805struct ParamList {
2806    params: Vec<ParamDecl>,
2807    /// Where `...` was written, if it was.
2808    ellipsis: Option<SourceRange>,
2809    has_prototype: bool,
2810    kr_names: Vec<Ident>,
2811}
2812
2813// ---------------------------------------------------------------------------
2814// initialisers
2815// ---------------------------------------------------------------------------
2816
2817impl Parser<'_> {
2818    fn parse_initializer(&mut self) -> PResult<Initializer> {
2819        self.enter()?;
2820        let result = self.parse_initializer_inner();
2821        self.leave();
2822        result
2823    }
2824
2825    fn parse_initializer_inner(&mut self) -> PResult<Initializer> {
2826        if self.at_punct(Punct::LBrace) {
2827            let start = self.cur_range();
2828            let items = self.parse_initializer_list()?;
2829            return Ok(Initializer {
2830                kind: InitializerKind::List(items),
2831                range: self.span_to_here(start),
2832            });
2833        }
2834        let expr = self.parse_assignment_expr()?;
2835        Ok(Initializer {
2836            range: expr.range,
2837            kind: InitializerKind::Expr(expr),
2838        })
2839    }
2840
2841    fn parse_initializer_list(&mut self) -> PResult<Vec<InitItem>> {
2842        let brace = self.expect_punct(Punct::LBrace, " to open an initializer list")?;
2843        if self.at_punct(Punct::RBrace) {
2844            // `= {}` zero-initialises anything; before C23 an initializer list
2845            // had to hold at least one initializer.
2846            let range = brace.join(self.cur_range());
2847            self.require_standard(Standard::C23, "an empty initializer", range);
2848        }
2849        let mut items = Vec::new();
2850        while !self.at_punct(Punct::RBrace) && !self.at_eof() {
2851            let start = self.cur_range();
2852            let mut designators = Vec::new();
2853            // The obsolete `name:` designator GNU still accepts, which is what
2854            // pre-C99 code writes for `.name =`.
2855            let mut old_style = false;
2856            if self.peek().ident().is_some() && self.nth(1).is_punct(Punct::Colon) {
2857                let field = self.eat_ident().expect("checked above");
2858                self.advance();
2859                designators.push(Designator::Field(field));
2860                old_style = true;
2861            }
2862            loop {
2863                if old_style {
2864                    break;
2865                }
2866                if self.eat_punct(Punct::Dot).is_some() {
2867                    let field = self.expect_ident(" after '.' in designator")?;
2868                    designators.push(Designator::Field(field));
2869                } else if self.eat_punct(Punct::LBracket).is_some() {
2870                    let index = self.parse_conditional_expr()?;
2871                    // GNU's range designator, `[low ... high] = v`.
2872                    if self.eat_punct(Punct::Ellipsis).is_some() {
2873                        let high = self.parse_conditional_expr()?;
2874                        self.expect_punct(Punct::RBracket, " after array designator")?;
2875                        designators.push(Designator::Range(index, high));
2876                    } else {
2877                        self.expect_punct(Punct::RBracket, " after array designator")?;
2878                        designators.push(Designator::Index(index));
2879                    }
2880                } else {
2881                    break;
2882                }
2883            }
2884            if !designators.is_empty() {
2885                // C99's own form and GCC's older `name:` one alike: before
2886                // C99 an initializer list was positional and nothing else.
2887                let at = self.span_to_here(start);
2888                self.require_standard(Standard::C99, "a designated initializer", at);
2889            }
2890            if !designators.is_empty() && !old_style {
2891                self.expect_punct(Punct::Assign, " after designator")?;
2892            }
2893            let init = self.parse_initializer()?;
2894            items.push(InitItem {
2895                designators,
2896                init,
2897                range: self.span_to_here(start),
2898            });
2899            if self.eat_punct(Punct::Comma).is_none() {
2900                break;
2901            }
2902        }
2903        self.expect_punct(Punct::RBrace, " to close an initializer list")?;
2904        Ok(items)
2905    }
2906}
2907
2908// ---------------------------------------------------------------------------
2909// statements
2910// ---------------------------------------------------------------------------
2911
2912impl Parser<'_> {
2913    fn parse_compound_stmt(&mut self) -> PResult<Block> {
2914        let start = self.expect_punct(Punct::LBrace, " to open a block")?;
2915        self.push_scope();
2916        // GNU's `__label__ a, b;` declares labels local to the block. Every
2917        // label already has function scope here and no two may share a name,
2918        // so the declaration is accepted and changes nothing.
2919        let mut local_labels = Vec::new();
2920        while self.at_keyword(Keyword::Label) {
2921            self.advance();
2922            loop {
2923                match self.expect_ident(" in a '__label__' declaration") {
2924                    Ok(name) => local_labels.push(name),
2925                    Err(bail) => {
2926                        self.pop_scope();
2927                        return Err(bail);
2928                    }
2929                }
2930                if self.eat_punct(Punct::Comma).is_none() {
2931                    break;
2932                }
2933            }
2934            if let Err(bail) = self.expect_punct(Punct::Semi, " after '__label__'") {
2935                self.pop_scope();
2936                return Err(bail);
2937            }
2938        }
2939        let mut items = Vec::new();
2940        // C89 6.6.2: a block is declarations *then* statements. C99 mixed the
2941        // two (N740), and the gate is here rather than in sema because it is
2942        // the block's shape that says which one this is.
2943        let mut saw_statement = false;
2944        while !self.at_punct(Punct::RBrace) && !self.at_eof() {
2945            let before = self.pos;
2946            if saw_statement && self.starts_declaration() {
2947                let at = self.cur_range();
2948                self.require_standard(Standard::C99, "a declaration after a statement", at);
2949            }
2950            let item = if self.at_static_assert() {
2951                self.parse_static_assert().map(BlockItem::StaticAssert)
2952            } else {
2953                // An attribute sequence here belongs either to a declaration
2954                // or to a statement, and only what follows says which; taking
2955                // it first is what lets `[[fallthrough]];` be a statement.
2956                match self.parse_attributes() {
2957                    Ok(attrs) => {
2958                        if self.starts_declaration() {
2959                            self.parse_block_declaration().map(|mut item| {
2960                                // The sequence belongs to the declaration —
2961                                // or to the GNU nested function definition —
2962                                // that follows it, exactly as one written
2963                                // among the specifiers does, which is where
2964                                // `parse_declaration_head` finds the same
2965                                // attributes at file scope.
2966                                let specifiers = match &mut item {
2967                                    BlockItem::Decl(decl) => Some(&mut decl.specifiers),
2968                                    BlockItem::NestedFunction(def) => Some(&mut def.specifiers),
2969                                    _ => None,
2970                                };
2971                                if let Some(specifiers) = specifiers {
2972                                    specifiers.noreturn = specifiers.noreturn.or(attrs.noreturn);
2973                                    specifiers.attrs.merge(attrs);
2974                                }
2975                                item
2976                            })
2977                        } else {
2978                            self.parse_stmt().map(BlockItem::Stmt)
2979                        }
2980                    }
2981                    Err(bail) => Err(bail),
2982                }
2983            };
2984            match item {
2985                Ok(item) => {
2986                    saw_statement |= matches!(item, BlockItem::Stmt(_));
2987                    items.push(item);
2988                }
2989                Err(bail) => {
2990                    self.pop_scope();
2991                    return Err(bail);
2992                }
2993            }
2994            if self.pos == before {
2995                self.advance();
2996            }
2997        }
2998        self.pop_scope();
2999        let end = self.expect_punct(Punct::RBrace, " to close a block")?;
3000        Ok(Block {
3001            items,
3002            local_labels,
3003            range: start.join(end),
3004        })
3005    }
3006
3007    fn parse_stmt(&mut self) -> PResult<Stmt> {
3008        self.enter()?;
3009        let result = self.parse_stmt_inner();
3010        self.leave();
3011        result
3012    }
3013
3014    /// Parses a statement, taking the labels in front of it iteratively.
3015    ///
3016    /// `case 0: case 1: … case 1022: break;` is one statement under 1023
3017    /// labels, and C23 5.2.5.2p1 asks for exactly that many. Recursing per
3018    /// label would spend a stack frame — and a level of the recursion guard —
3019    /// on each of them, so the run is collected into a list and folded into
3020    /// the tree afterwards. What the tree looks like does not change.
3021    fn parse_stmt_inner(&mut self) -> PResult<Stmt> {
3022        let mut labels: Vec<(PendingLabel, SourceRange)> = Vec::new();
3023        let start = loop {
3024            let start = self.cur_range();
3025            // A statement may carry attributes of its own: `[[fallthrough]];`,
3026            // `__attribute__((fallthrough));`, `[[likely]] if (…)`. They are
3027            // consumed and dropped — a `switch` group falls through either way.
3028            let _ = self.parse_attributes()?;
3029            // `__extension__ stmt` asks for the pedantic warnings to be held
3030            // back; there are none.
3031            while self.eat_keyword(Keyword::Extension).is_some() {}
3032
3033            // `label:`
3034            let label = if self.peek().ident().is_some() && self.nth(1).is_punct(Punct::Colon) {
3035                let label = self.eat_ident().expect("checked above");
3036                self.advance(); // `:`
3037                PendingLabel::Ident { label }
3038            } else if self.at_keyword(Keyword::Case) {
3039                self.advance();
3040                let value = self.parse_conditional_expr()?;
3041                // GNU's `case low ... high:`, which is one label for every
3042                // value in the range.
3043                let upper = if self.eat_punct(Punct::Ellipsis).is_some() {
3044                    Some(self.parse_conditional_expr()?)
3045                } else {
3046                    None
3047                };
3048                self.expect_punct(Punct::Colon, " after 'case' label")?;
3049                PendingLabel::Case { value, upper }
3050            } else if self.at_keyword(Keyword::Default) {
3051                self.advance();
3052                self.expect_punct(Punct::Colon, " after 'default' label")?;
3053                PendingLabel::Default
3054            } else {
3055                break start;
3056            };
3057            labels.push((label, start));
3058            if labels.len() > MAX_LABEL_CHAIN {
3059                let range = self.cur_range();
3060                return Err(self.error_bail(
3061                    range,
3062                    format!("more than {MAX_LABEL_CHAIN} labels on one statement"),
3063                ));
3064            }
3065        };
3066
3067        if !labels.is_empty() {
3068            return self.finish_labeled_stmt(labels);
3069        }
3070        self.parse_unlabeled_stmt(start)
3071    }
3072
3073    /// A statement with the labels — and the attributes — already taken.
3074    ///
3075    /// `start` is where the statement began, attributes included, which is
3076    /// where its range starts.
3077    fn parse_unlabeled_stmt(&mut self, start: SourceRange) -> PResult<Stmt> {
3078        // Inline assembly, which has no honest translation. Recognising the
3079        // whole statement is what turns it into one clear diagnostic.
3080        if self.at_keyword(Keyword::Asm) {
3081            return self.parse_asm_stmt();
3082        }
3083
3084        if self.at_punct(Punct::LBrace) {
3085            let block = self.parse_compound_stmt()?;
3086            return Ok(Stmt {
3087                range: block.range,
3088                kind: StmtKind::Compound(block),
3089            });
3090        }
3091
3092        if let Some(k) = self.peek().keyword() {
3093            match k {
3094                Keyword::If => return self.parse_if_stmt(),
3095                Keyword::Switch => {
3096                    self.advance();
3097                    self.expect_punct(Punct::LParen, " after 'switch'")?;
3098                    let cond = self.parse_expr()?;
3099                    self.expect_punct(Punct::RParen, " after switch condition")?;
3100                    let body = self.parse_stmt()?;
3101                    return Ok(Stmt {
3102                        kind: StmtKind::Switch {
3103                            cond,
3104                            body: Box::new(body),
3105                        },
3106                        range: self.span_to_here(start),
3107                    });
3108                }
3109                Keyword::While => {
3110                    self.advance();
3111                    self.expect_punct(Punct::LParen, " after 'while'")?;
3112                    let cond = self.parse_expr()?;
3113                    self.expect_punct(Punct::RParen, " after loop condition")?;
3114                    let body = self.parse_stmt()?;
3115                    return Ok(Stmt {
3116                        kind: StmtKind::While {
3117                            cond,
3118                            body: Box::new(body),
3119                        },
3120                        range: self.span_to_here(start),
3121                    });
3122                }
3123                Keyword::Do => {
3124                    self.advance();
3125                    let body = self.parse_stmt()?;
3126                    self.expect_keyword(Keyword::While, " after 'do' body")?;
3127                    self.expect_punct(Punct::LParen, " after 'while'")?;
3128                    let cond = self.parse_expr()?;
3129                    self.expect_punct(Punct::RParen, " after loop condition")?;
3130                    self.expect_punct(Punct::Semi, " after 'do' statement")?;
3131                    return Ok(Stmt {
3132                        kind: StmtKind::DoWhile {
3133                            body: Box::new(body),
3134                            cond,
3135                        },
3136                        range: self.span_to_here(start),
3137                    });
3138                }
3139                Keyword::For => return self.parse_for_stmt(),
3140                Keyword::Goto => {
3141                    self.advance();
3142                    // GNU's computed `goto *expr;`, whose operand is a label
3143                    // address rather than a label name.
3144                    if self.eat_punct(Punct::Star).is_some() {
3145                        let target = self.parse_expr()?;
3146                        self.expect_punct(Punct::Semi, " after 'goto' statement")?;
3147                        return Ok(Stmt {
3148                            kind: StmtKind::GotoPtr(target),
3149                            range: self.span_to_here(start),
3150                        });
3151                    }
3152                    let label = self.expect_ident(" after 'goto'")?;
3153                    self.expect_punct(Punct::Semi, " after 'goto' statement")?;
3154                    return Ok(Stmt {
3155                        kind: StmtKind::Goto(label),
3156                        range: self.span_to_here(start),
3157                    });
3158                }
3159                Keyword::Continue => {
3160                    self.advance();
3161                    self.expect_punct(Punct::Semi, " after 'continue'")?;
3162                    return Ok(Stmt {
3163                        kind: StmtKind::Continue,
3164                        range: self.span_to_here(start),
3165                    });
3166                }
3167                Keyword::Break => {
3168                    self.advance();
3169                    self.expect_punct(Punct::Semi, " after 'break'")?;
3170                    return Ok(Stmt {
3171                        kind: StmtKind::Break,
3172                        range: self.span_to_here(start),
3173                    });
3174                }
3175                Keyword::Return => {
3176                    self.advance();
3177                    let value = if self.at_punct(Punct::Semi) {
3178                        None
3179                    } else {
3180                        Some(self.parse_expr()?)
3181                    };
3182                    self.expect_punct(Punct::Semi, " after 'return' statement")?;
3183                    return Ok(Stmt {
3184                        kind: StmtKind::Return(value),
3185                        range: self.span_to_here(start),
3186                    });
3187                }
3188                _ => {}
3189            }
3190        }
3191
3192        if let Some(semi) = self.eat_punct(Punct::Semi) {
3193            return Ok(Stmt {
3194                kind: StmtKind::Expr(None),
3195                range: semi,
3196            });
3197        }
3198
3199        let expr = self.parse_expr()?;
3200        self.expect_punct(Punct::Semi, " after expression")?;
3201        Ok(Stmt {
3202            kind: StmtKind::Expr(Some(expr)),
3203            range: self.span_to_here(start),
3204        })
3205    }
3206
3207    /// Parses what a run of labels labels, and folds the run into the tree.
3208    ///
3209    /// The list is never empty; see [`Parser::parse_stmt_inner`].
3210    fn finish_labeled_stmt(&mut self, labels: Vec<(PendingLabel, SourceRange)>) -> PResult<Stmt> {
3211        // C23 lets a label stand before a declaration and at the very end of a
3212        // compound statement; before that it had to label a statement. Either
3213        // way the label itself labels nothing, so it takes a null statement and
3214        // whatever follows is parsed on its own.
3215        // N2508 is about *every* label, `case` and `default` included: `switch
3216        // (x) { case 1: }` and `case 1: _Static_assert(1, "");` are both what
3217        // it made legal, and `C23/n2508.c` writes both.
3218        let colon = self.last_range;
3219        let (_, label_start) = labels.last().expect("a label chain is never empty");
3220        let what = if self.at_punct(Punct::RBrace) {
3221            Some("a label at the end of a compound statement")
3222        } else if self.starts_declaration() || self.at_static_assert() {
3223            Some("a label before a declaration")
3224        } else {
3225            None
3226        };
3227        let trailing = what.map(|what| (what, label_start.join(colon), colon));
3228        let mut stmt = match trailing {
3229            Some((what, at, colon)) => {
3230                self.require_standard(Standard::C23, what, at);
3231                Stmt {
3232                    kind: StmtKind::Expr(None),
3233                    range: colon,
3234                }
3235            }
3236            None => {
3237                let start = self.cur_range();
3238                self.parse_unlabeled_stmt(start)?
3239            }
3240        };
3241        let end = self.last_range;
3242        for (label, start) in labels.into_iter().rev() {
3243            let body = Box::new(stmt);
3244            let kind = match label {
3245                PendingLabel::Ident { label, .. } => StmtKind::Labeled { label, body },
3246                PendingLabel::Case { value, upper } => StmtKind::Case { value, upper, body },
3247                PendingLabel::Default => StmtKind::Default { body },
3248            };
3249            stmt = Stmt {
3250                kind,
3251                range: start.join(end),
3252            };
3253        }
3254        Ok(stmt)
3255    }
3256
3257    /// `asm [qualifiers] ( … ) ;` — an inline assembly statement.
3258    ///
3259    /// Rust has `core::arch::asm!`, but its operand constraints are a language
3260    /// of their own and mapping GCC's onto them is a project rather than a
3261    /// feature; half a translation of assembly would be worse than none. The
3262    /// whole statement is consumed so that the diagnostic is about the `asm`
3263    /// rather than about the tokens inside it.
3264    fn parse_asm_stmt(&mut self) -> PResult<Stmt> {
3265        let start = self.cur_range();
3266        self.advance();
3267        // `volatile`, `inline` and `goto` may qualify it.
3268        while matches!(
3269            self.peek().keyword(),
3270            Some(
3271                Keyword::Volatile
3272                    | Keyword::Const
3273                    | Keyword::Inline
3274                    | Keyword::InlineGnu
3275                    | Keyword::Goto
3276            )
3277        ) {
3278            self.advance();
3279        }
3280        if self.at_punct(Punct::LParen) {
3281            self.skip_attribute_args()?;
3282        }
3283        self.eat_punct(Punct::Semi);
3284        let range = self.span_to_here(start);
3285        self.error(range, "inline assembly is not supported");
3286        Ok(Stmt {
3287            kind: StmtKind::Error,
3288            range,
3289        })
3290    }
3291
3292    fn parse_if_stmt(&mut self) -> PResult<Stmt> {
3293        let start = self.cur_range();
3294        self.advance(); // `if`
3295        self.expect_punct(Punct::LParen, " after 'if'")?;
3296        let cond = self.parse_expr()?;
3297        self.expect_punct(Punct::RParen, " after if condition")?;
3298        let then_branch = Box::new(self.parse_stmt()?);
3299        let else_branch = if self.eat_keyword(Keyword::Else).is_some() {
3300            Some(Box::new(self.parse_stmt()?))
3301        } else {
3302            None
3303        };
3304        Ok(Stmt {
3305            kind: StmtKind::If {
3306                cond,
3307                then_branch,
3308                else_branch,
3309            },
3310            range: self.span_to_here(start),
3311        })
3312    }
3313
3314    fn parse_for_stmt(&mut self) -> PResult<Stmt> {
3315        let start = self.cur_range();
3316        self.advance(); // `for`
3317        self.expect_punct(Punct::LParen, " after 'for'")?;
3318        // C99 allows a declaration here; it scopes to the loop.
3319        self.push_scope();
3320        let result = (|parser: &mut Self| {
3321            let init = if parser.at_punct(Punct::Semi) {
3322                parser.advance();
3323                ForInit::None
3324            } else if parser.at_static_assert() {
3325                // A static assertion is a declaration and takes its own `;`
3326                // with it; see [`ForInit::StaticAssert`].
3327                ForInit::StaticAssert(parser.parse_static_assert()?)
3328            } else if parser.starts_declaration() {
3329                let at = parser.cur_range();
3330                parser.require_standard(Standard::C99, "a declaration in a 'for' clause", at);
3331                ForInit::Decl(Box::new(parser.parse_declaration()?))
3332            } else {
3333                let expr = parser.parse_expr()?;
3334                parser.expect_punct(Punct::Semi, " after 'for' initializer")?;
3335                ForInit::Expr(expr)
3336            };
3337            let cond = if parser.at_punct(Punct::Semi) {
3338                None
3339            } else {
3340                Some(parser.parse_expr()?)
3341            };
3342            parser.expect_punct(Punct::Semi, " after 'for' condition")?;
3343            let step = if parser.at_punct(Punct::RParen) {
3344                None
3345            } else {
3346                Some(parser.parse_expr()?)
3347            };
3348            parser.expect_punct(Punct::RParen, " after 'for' clauses")?;
3349            let body = parser.parse_stmt()?;
3350            Ok(StmtKind::For {
3351                init,
3352                cond,
3353                step,
3354                body: Box::new(body),
3355            })
3356        })(self);
3357        self.pop_scope();
3358        Ok(Stmt {
3359            kind: result?,
3360            range: self.span_to_here(start),
3361        })
3362    }
3363
3364    fn expect_keyword(&mut self, k: Keyword, ctx: &str) -> PResult<SourceRange> {
3365        if self.at_keyword(k) {
3366            return Ok(self.bump_range());
3367        }
3368        let range = self.cur_range();
3369        let found = self.describe_cur();
3370        Err(self.error_bail(
3371            range,
3372            format!("expected '{}'{ctx}, found {found}", k.as_str()),
3373        ))
3374    }
3375}
3376
3377// ---------------------------------------------------------------------------
3378// expressions
3379// ---------------------------------------------------------------------------
3380
3381/// Binding power of the binary operators, tightest last.
3382fn binary_op(kind: &TokenKind) -> Option<(BinaryOp, u8)> {
3383    let TokenKind::Punct(p) = kind else {
3384        return None;
3385    };
3386    Some(match p {
3387        Punct::PipePipe => (BinaryOp::LogOr, 1),
3388        Punct::AmpAmp => (BinaryOp::LogAnd, 2),
3389        Punct::Pipe => (BinaryOp::BitOr, 3),
3390        Punct::Caret => (BinaryOp::BitXor, 4),
3391        Punct::Amp => (BinaryOp::BitAnd, 5),
3392        Punct::EqEq => (BinaryOp::Eq, 6),
3393        Punct::Ne => (BinaryOp::Ne, 6),
3394        Punct::Lt => (BinaryOp::Lt, 7),
3395        Punct::Gt => (BinaryOp::Gt, 7),
3396        Punct::Le => (BinaryOp::Le, 7),
3397        Punct::Ge => (BinaryOp::Ge, 7),
3398        Punct::Shl => (BinaryOp::Shl, 8),
3399        Punct::Shr => (BinaryOp::Shr, 8),
3400        Punct::Plus => (BinaryOp::Add, 9),
3401        Punct::Minus => (BinaryOp::Sub, 9),
3402        Punct::Star => (BinaryOp::Mul, 10),
3403        Punct::Slash => (BinaryOp::Div, 10),
3404        Punct::Percent => (BinaryOp::Rem, 10),
3405        _ => return None,
3406    })
3407}
3408
3409/// The compound operator of an assignment token, if it is one.
3410fn assign_op(kind: &TokenKind) -> Option<Option<BinaryOp>> {
3411    let TokenKind::Punct(p) = kind else {
3412        return None;
3413    };
3414    Some(match p {
3415        Punct::Assign => None,
3416        Punct::StarAssign => Some(BinaryOp::Mul),
3417        Punct::SlashAssign => Some(BinaryOp::Div),
3418        Punct::PercentAssign => Some(BinaryOp::Rem),
3419        Punct::PlusAssign => Some(BinaryOp::Add),
3420        Punct::MinusAssign => Some(BinaryOp::Sub),
3421        Punct::ShlAssign => Some(BinaryOp::Shl),
3422        Punct::ShrAssign => Some(BinaryOp::Shr),
3423        Punct::AmpAssign => Some(BinaryOp::BitAnd),
3424        Punct::CaretAssign => Some(BinaryOp::BitXor),
3425        Punct::PipeAssign => Some(BinaryOp::BitOr),
3426        _ => return None,
3427    })
3428}
3429
3430impl Parser<'_> {
3431    /// `expression` — including the comma operator.
3432    pub(crate) fn parse_expr(&mut self) -> PResult<Expr> {
3433        self.enter()?;
3434        let result = self.parse_expr_inner();
3435        self.leave();
3436        result
3437    }
3438
3439    /// `a, b, c, …` — the comma operator, which is left-associative.
3440    ///
3441    /// Taken in a loop, so the length of the chain costs the parser no stack;
3442    /// sema and code generation walk it iteratively too, so it costs them
3443    /// none either and nothing but memory bounds it. See
3444    /// [`MAX_RECURSION_DEPTH`].
3445    fn parse_expr_inner(&mut self) -> PResult<Expr> {
3446        let mut lhs = self.parse_assignment_expr()?;
3447        while self.eat_punct(Punct::Comma).is_some() {
3448            let rhs = self.parse_assignment_expr()?;
3449            let range = lhs.range.join(rhs.range);
3450            lhs = Expr {
3451                kind: ExprKind::Comma {
3452                    lhs: Box::new(lhs),
3453                    rhs: Box::new(rhs),
3454                },
3455                range,
3456            };
3457        }
3458        Ok(lhs)
3459    }
3460
3461    /// `assignment-expression`, which is right associative.
3462    ///
3463    /// `a = b = c` is taken in a loop and folded from the right afterwards, so
3464    /// the parser itself never recurses down the chain — but what it folds is
3465    /// `Assign(a, Assign(b, c))`, one level of *nesting* per operator, and
3466    /// nesting is what [`MAX_RECURSION_DEPTH`] is for. Each operator is
3467    /// therefore charged to the same counter `((((…))))` is charged to, and
3468    /// released again however the chain ends.
3469    fn parse_assignment_expr(&mut self) -> PResult<Expr> {
3470        let mut charged = 0u32;
3471        let result = self.assignment_chain(&mut charged);
3472        for _ in 0..charged {
3473            self.leave();
3474        }
3475        result
3476    }
3477
3478    /// [`Parser::parse_assignment_expr`], reporting the nesting it charged.
3479    fn assignment_chain(&mut self, charged: &mut u32) -> PResult<Expr> {
3480        let mut pending: Vec<(Expr, Option<BinaryOp>)> = Vec::new();
3481        let mut value = loop {
3482            let lhs = self.parse_conditional_expr()?;
3483            let Some(op) = assign_op(&self.peek().kind) else {
3484                break lhs;
3485            };
3486            self.advance();
3487            self.enter()?;
3488            *charged += 1;
3489            pending.push((lhs, op));
3490        };
3491        for (lhs, op) in pending.into_iter().rev() {
3492            let range = lhs.range.join(value.range);
3493            value = Expr {
3494                kind: ExprKind::Assign {
3495                    op,
3496                    lhs: Box::new(lhs),
3497                    rhs: Box::new(value),
3498                },
3499                range,
3500            };
3501        }
3502        Ok(value)
3503    }
3504
3505    /// `conditional-expression`, whose `else` operand is another one.
3506    ///
3507    /// `a ? b : c ? d : e` is taken in a loop and folded from the right, for
3508    /// the reason [`Parser::parse_assignment_expr`] is — and, for the same
3509    /// reason, each operator is charged to [`MAX_RECURSION_DEPTH`]: the tree
3510    /// it builds nests one level per operator, and every pass after this one
3511    /// has to walk it.
3512    fn parse_conditional_expr(&mut self) -> PResult<Expr> {
3513        let mut charged = 0u32;
3514        let result = self.conditional_chain(&mut charged);
3515        for _ in 0..charged {
3516            self.leave();
3517        }
3518        result
3519    }
3520
3521    /// [`Parser::parse_conditional_expr`], reporting the nesting it charged.
3522    fn conditional_chain(&mut self, charged: &mut u32) -> PResult<Expr> {
3523        #[allow(clippy::type_complexity)]
3524        let mut pending: Vec<(Expr, Option<Box<Expr>>)> = Vec::new();
3525        let mut value = loop {
3526            let cond = self.parse_binary_expr(1)?;
3527            if self.eat_punct(Punct::Question).is_none() {
3528                break cond;
3529            }
3530            // GNU's `a ?: b`: the middle operand is the condition itself, and
3531            // the condition is evaluated exactly once.
3532            let then_expr = if self.at_punct(Punct::Colon) {
3533                None
3534            } else {
3535                Some(Box::new(self.parse_expr()?))
3536            };
3537            self.expect_punct(Punct::Colon, " in conditional expression")?;
3538            self.enter()?;
3539            *charged += 1;
3540            pending.push((cond, then_expr));
3541        };
3542        for (cond, then_expr) in pending.into_iter().rev() {
3543            let range = cond.range.join(value.range);
3544            value = Expr {
3545                kind: ExprKind::Conditional {
3546                    cond: Box::new(cond),
3547                    then_expr,
3548                    else_expr: Box::new(value),
3549                },
3550                range,
3551            };
3552        }
3553        Ok(value)
3554    }
3555
3556    /// The binary operators, by precedence climbing.
3557    ///
3558    /// Every level is left-associative, so a run of one operator is a loop
3559    /// rather than recursion and its length costs no stack — here or in the
3560    /// passes after it; the recursion is over the ten *precedence levels*.
3561    /// See [`MAX_RECURSION_DEPTH`].
3562    fn parse_binary_expr(&mut self, min_prec: u8) -> PResult<Expr> {
3563        let mut lhs = self.parse_cast_expr()?;
3564        while let Some((op, prec)) = binary_op(&self.peek().kind) {
3565            if prec < min_prec {
3566                break;
3567            }
3568            self.advance();
3569            let rhs = self.parse_binary_expr(prec + 1)?;
3570            let range = lhs.range.join(rhs.range);
3571            lhs = Expr {
3572                kind: ExprKind::Binary {
3573                    op,
3574                    lhs: Box::new(lhs),
3575                    rhs: Box::new(rhs),
3576                },
3577                range,
3578            };
3579        }
3580        Ok(lhs)
3581    }
3582
3583    /// Whether a `(` at the current position introduces a type name — that is,
3584    /// whether this is a cast or a compound literal rather than a
3585    /// parenthesised expression.
3586    fn at_paren_type_name(&self) -> bool {
3587        if !self.at_punct(Punct::LParen) {
3588            return false;
3589        }
3590        // `__extension__` prefixes a declaration *and* an expression, so it
3591        // says nothing about which of the two a parenthesis opens; what comes
3592        // after it does. `(__extension__ 1.0iF)` — which is how GCC's own
3593        // `<complex.h>` spells `_Complex_I` — is a parenthesised constant, and
3594        // `(__extension__ long long)x` is a cast.
3595        let mut n = 1;
3596        while self.nth(n).keyword() == Some(Keyword::Extension) {
3597            n += 1;
3598        }
3599        self.starts_decl_specifier(n)
3600    }
3601
3602    fn parse_cast_expr(&mut self) -> PResult<Expr> {
3603        self.enter()?;
3604        let result = self.parse_cast_expr_inner();
3605        self.leave();
3606        result
3607    }
3608
3609    fn parse_cast_expr_inner(&mut self) -> PResult<Expr> {
3610        if !self.at_paren_type_name() {
3611            return self.parse_unary_expr();
3612        }
3613        let start = self.cur_range();
3614        self.advance(); // `(`
3615        let ty = self.parse_type_name()?;
3616        self.expect_punct(Punct::RParen, " after type name")?;
3617        if self.at_punct(Punct::LBrace) {
3618            // `(T){ ... }` is a compound literal, i.e. a postfix expression.
3619            let at = self.span_to_here(start);
3620            self.require_standard(Standard::C99, "a compound literal", at);
3621            let items = self.parse_initializer_list()?;
3622            let expr = Expr {
3623                kind: ExprKind::CompoundLiteral {
3624                    ty: Box::new(ty),
3625                    init: items,
3626                },
3627                range: self.span_to_here(start),
3628            };
3629            return self.parse_postfix_suffixes(expr);
3630        }
3631        let expr = self.parse_cast_expr()?;
3632        let range = start.join(expr.range);
3633        Ok(Expr {
3634            kind: ExprKind::Cast {
3635                ty: Box::new(ty),
3636                expr: Box::new(expr),
3637            },
3638            range,
3639        })
3640    }
3641
3642    fn parse_unary_expr(&mut self) -> PResult<Expr> {
3643        let start = self.cur_range();
3644
3645        if let Some(p) = match &self.peek().kind {
3646            TokenKind::Punct(p) => Some(*p),
3647            _ => None,
3648        } {
3649            let unary = match p {
3650                Punct::Amp => Some(UnaryOp::AddrOf),
3651                Punct::Star => Some(UnaryOp::Deref),
3652                Punct::Plus => Some(UnaryOp::Plus),
3653                Punct::Minus => Some(UnaryOp::Minus),
3654                Punct::Tilde => Some(UnaryOp::BitNot),
3655                Punct::Bang => Some(UnaryOp::LogNot),
3656                _ => None,
3657            };
3658            if let Some(op) = unary {
3659                self.advance();
3660                let operand = self.parse_cast_expr()?;
3661                let range = start.join(operand.range);
3662                return Ok(Expr {
3663                    kind: ExprKind::Unary {
3664                        op,
3665                        operand: Box::new(operand),
3666                    },
3667                    range,
3668                });
3669            }
3670            // GNU's `&&label`, the address of a label of this function. It is
3671            // an rvalue of type `void *` and the only operand `goto *` has;
3672            // `&&` can never open an expression otherwise, so there is nothing
3673            // to disambiguate.
3674            if p == Punct::AmpAmp {
3675                self.advance();
3676                let label = self.expect_ident(" after '&&'")?;
3677                self.label_addrs += 1;
3678                let range = start.join(label.range);
3679                return Ok(Expr {
3680                    kind: ExprKind::LabelAddr(label),
3681                    range,
3682                });
3683            }
3684            if matches!(p, Punct::PlusPlus | Punct::MinusMinus) {
3685                self.advance();
3686                let op = if p == Punct::PlusPlus {
3687                    IncDec::Inc
3688                } else {
3689                    IncDec::Dec
3690                };
3691                let operand = self.parse_unary_expr()?;
3692                let range = start.join(operand.range);
3693                return Ok(Expr {
3694                    kind: ExprKind::PreIncDec {
3695                        op,
3696                        operand: Box::new(operand),
3697                    },
3698                    range,
3699                });
3700            }
3701        }
3702
3703        if self.at_keyword(Keyword::Sizeof) {
3704            self.advance();
3705            if self.at_paren_type_name() {
3706                self.advance(); // `(`
3707                let ty = self.parse_type_name()?;
3708                self.expect_punct(Punct::RParen, " after type name")?;
3709                if self.at_punct(Punct::LBrace) {
3710                    // `sizeof (T){ ... }` measures a compound literal.
3711                    let at = self.span_to_here(start);
3712                    self.require_standard(Standard::C99, "a compound literal", at);
3713                    let items = self.parse_initializer_list()?;
3714                    let literal = Expr {
3715                        kind: ExprKind::CompoundLiteral {
3716                            ty: Box::new(ty),
3717                            init: items,
3718                        },
3719                        range: self.span_to_here(start),
3720                    };
3721                    let operand = self.parse_postfix_suffixes(literal)?;
3722                    let range = start.join(operand.range);
3723                    return Ok(Expr {
3724                        kind: ExprKind::SizeofExpr(Box::new(operand)),
3725                        range,
3726                    });
3727                }
3728                return Ok(Expr {
3729                    kind: ExprKind::SizeofType(Box::new(ty)),
3730                    range: self.span_to_here(start),
3731                });
3732            }
3733            let operand = self.parse_unary_expr()?;
3734            let range = start.join(operand.range);
3735            return Ok(Expr {
3736                kind: ExprKind::SizeofExpr(Box::new(operand)),
3737                range,
3738            });
3739        }
3740
3741        // `__extension__ expr` holds back the pedantic warnings there are none
3742        // of. `__real__` and `__imag__` are GNU's two halves of a complex
3743        // value, and sema types them: each is an lvalue whenever its operand
3744        // is, and each has a meaning on a *real* operand too.
3745        if self.eat_keyword(Keyword::Extension).is_some() {
3746            return self.parse_unary_expr();
3747        }
3748        if let Some(k @ (Keyword::RealGnu | Keyword::ImagGnu)) = self.peek().keyword() {
3749            self.advance();
3750            let operand = self.parse_cast_expr()?;
3751            let range = start.join(operand.range);
3752            return Ok(Expr {
3753                kind: ExprKind::ComplexPart {
3754                    real: k == Keyword::RealGnu,
3755                    operand: Box::new(operand),
3756                },
3757                range,
3758            });
3759        }
3760
3761        if let Some(k @ (Keyword::Alignof | Keyword::AlignofName | Keyword::AlignofGnu)) =
3762            self.peek().keyword()
3763        {
3764            self.require_keyword(k, start);
3765            self.advance();
3766            if self.at_paren_type_name() {
3767                self.advance(); // `(`
3768                let ty = self.parse_type_name()?;
3769                self.expect_punct(Punct::RParen, " after type name")?;
3770                return Ok(Expr {
3771                    kind: ExprKind::AlignofType(Box::new(ty)),
3772                    range: self.span_to_here(start),
3773                });
3774            }
3775            // `_Alignof expr` is GCC's extension, which C never standardised;
3776            // accepting it costs nothing and `_Alignof(x)` is what people
3777            // write when `x` is an object.
3778            let operand = self.parse_unary_expr()?;
3779            let range = start.join(operand.range);
3780            return Ok(Expr {
3781                kind: ExprKind::AlignofExpr(Box::new(operand)),
3782                range,
3783            });
3784        }
3785
3786        if self.at_va_arg() {
3787            return self.parse_va_arg();
3788        }
3789        if self.at_builtin("__builtin_offsetof") {
3790            return self.parse_offsetof();
3791        }
3792        if self.at_builtin("__builtin_types_compatible_p") {
3793            return self.parse_types_compatible();
3794        }
3795        if self.at_builtin("__builtin_choose_expr") {
3796            return self.parse_choose_expr();
3797        }
3798
3799        self.parse_postfix_expr()
3800    }
3801
3802    /// `__builtin_types_compatible_p(T1, T2)`, whose operands are type names.
3803    fn parse_types_compatible(&mut self) -> PResult<Expr> {
3804        let start = self.cur_range();
3805        self.advance(); // the name
3806        self.advance(); // `(`
3807        let lhs = self.parse_type_name()?;
3808        self.expect_punct(
3809            Punct::Comma,
3810            " after the first type of '__builtin_types_compatible_p'",
3811        )?;
3812        let rhs = self.parse_type_name()?;
3813        self.expect_punct(
3814            Punct::RParen,
3815            " after the second type of '__builtin_types_compatible_p'",
3816        )?;
3817        let expr = Expr {
3818            kind: ExprKind::TypesCompatible {
3819                lhs: Box::new(lhs),
3820                rhs: Box::new(rhs),
3821            },
3822            range: self.span_to_here(start),
3823        };
3824        self.parse_postfix_suffixes(expr)
3825    }
3826
3827    /// `__builtin_choose_expr(c, a, b)`, whose unchosen operand is never even
3828    /// type checked — which is why it needs the parser's help.
3829    fn parse_choose_expr(&mut self) -> PResult<Expr> {
3830        let start = self.cur_range();
3831        self.advance(); // the name
3832        self.advance(); // `(`
3833        let cond = self.parse_assignment_expr()?;
3834        self.expect_punct(
3835            Punct::Comma,
3836            " after the condition of '__builtin_choose_expr'",
3837        )?;
3838        let then_expr = self.parse_assignment_expr()?;
3839        self.expect_punct(Punct::Comma, " in '__builtin_choose_expr'")?;
3840        let else_expr = self.parse_assignment_expr()?;
3841        self.expect_punct(Punct::RParen, " to close '__builtin_choose_expr'")?;
3842        let expr = Expr {
3843            kind: ExprKind::ChooseExpr {
3844                cond: Box::new(cond),
3845                then_expr: Box::new(then_expr),
3846                else_expr: Box::new(else_expr),
3847            },
3848            range: self.span_to_here(start),
3849        };
3850        self.parse_postfix_suffixes(expr)
3851    }
3852
3853    /// Whether the next tokens invoke the named builtin.
3854    ///
3855    /// The `__builtin_` names are reserved, so no declaration can turn one
3856    /// back into an ordinary identifier; without the check the type name each
3857    /// of them takes would not parse as an expression.
3858    fn at_builtin(&self, name: &str) -> bool {
3859        self.peek().ident() == Some(name) && self.nth(1).is_punct(Punct::LParen)
3860    }
3861
3862    /// Whether the next tokens are a `va_arg(…)` invocation.
3863    fn at_va_arg(&self) -> bool {
3864        self.at_builtin("__builtin_va_arg")
3865    }
3866
3867    /// `__builtin_offsetof(T, member-designator)`, the special form
3868    /// `offsetof` is.
3869    ///
3870    /// C99 7.17p3's member designator is an identifier followed by any number
3871    /// of `.member` and `[expr]` steps, so that `offsetof(struct S, a[2].b)`
3872    /// names the offset of a member of an element of a member. Sema folds the
3873    /// whole path to one constant.
3874    fn parse_offsetof(&mut self) -> PResult<Expr> {
3875        let start = self.cur_range();
3876        self.advance(); // `__builtin_offsetof`
3877        self.advance(); // `(`
3878        let ty = self.parse_type_name()?;
3879        self.expect_punct(Punct::Comma, " after the type of 'offsetof'")?;
3880        let member = self.expect_ident(" as the member of 'offsetof'")?;
3881        let mut path = Vec::new();
3882        loop {
3883            if self.eat_punct(Punct::Dot).is_some() {
3884                path.push(Designator::Field(self.expect_ident(
3885                    " after '.' in the member designator of 'offsetof'",
3886                )?));
3887                continue;
3888            }
3889            if self.eat_punct(Punct::LBracket).is_some() {
3890                path.push(Designator::Index(self.parse_expr()?));
3891                self.expect_punct(
3892                    Punct::RBracket,
3893                    " after the subscript in the member designator of 'offsetof'",
3894                )?;
3895                continue;
3896            }
3897            break;
3898        }
3899        self.expect_punct(Punct::RParen, " after the member of 'offsetof'")?;
3900        let expr = Expr {
3901            kind: ExprKind::OffsetOf {
3902                ty: Box::new(ty),
3903                member,
3904                path,
3905            },
3906            range: self.span_to_here(start),
3907        };
3908        self.parse_postfix_suffixes(expr)
3909    }
3910
3911    /// `va_arg(ap, T)`, whose second argument is a type name.
3912    fn parse_va_arg(&mut self) -> PResult<Expr> {
3913        let start = self.cur_range();
3914        self.advance(); // `va_arg`
3915        self.advance(); // `(`
3916        let ap = self.parse_assignment_expr()?;
3917        self.expect_punct(Punct::Comma, " after the argument list of 'va_arg'")?;
3918        let ty = self.parse_type_name()?;
3919        self.expect_punct(Punct::RParen, " after the type of 'va_arg'")?;
3920        let expr = Expr {
3921            kind: ExprKind::VaArg {
3922                ap: Box::new(ap),
3923                ty: Box::new(ty),
3924            },
3925            range: self.span_to_here(start),
3926        };
3927        self.parse_postfix_suffixes(expr)
3928    }
3929
3930    fn parse_postfix_expr(&mut self) -> PResult<Expr> {
3931        let primary = self.parse_primary_expr()?;
3932        self.parse_postfix_suffixes(primary)
3933    }
3934
3935    /// The `[…]`, `(…)`, `.x`, `->x`, `++` and `--` that follow an operand.
3936    ///
3937    /// A run of them is left-associative in the source and *nested* in the
3938    /// tree — `p->a->b` is a member of a member — and code generation walks
3939    /// that nesting recursively, so each suffix taken is charged to
3940    /// [`MAX_RECURSION_DEPTH`]. It is the tightest of the three constructs
3941    /// charged there: a `->` chain is what overflows first, at about 450.
3942    fn parse_postfix_suffixes(&mut self, expr: Expr) -> PResult<Expr> {
3943        let mut charged = 0u32;
3944        let result = self.postfix_suffixes(expr, &mut charged);
3945        for _ in 0..charged {
3946            self.leave();
3947        }
3948        result
3949    }
3950
3951    /// [`Parser::parse_postfix_suffixes`], reporting the nesting it charged.
3952    fn postfix_suffixes(&mut self, mut expr: Expr, charged: &mut u32) -> PResult<Expr> {
3953        let mut suffixes = 0usize;
3954        loop {
3955            // Nothing is charged for an operand with no suffix at all, so
3956            // that the 63 levels of parenthesised expression C23 5.2.5.2p1
3957            // asks for keep the whole budget to themselves.
3958            if suffixes > 0 {
3959                self.enter()?;
3960                *charged += 1;
3961            }
3962            suffixes += 1;
3963            if self.eat_punct(Punct::LBracket).is_some() {
3964                let index = self.parse_expr()?;
3965                let rb = self.expect_punct(Punct::RBracket, " after subscript")?;
3966                expr = Expr {
3967                    range: expr.range.join(rb),
3968                    kind: ExprKind::Index {
3969                        base: Box::new(expr),
3970                        index: Box::new(index),
3971                    },
3972                };
3973                continue;
3974            }
3975            if self.eat_punct(Punct::LParen).is_some() {
3976                let mut args = Vec::new();
3977                if !self.at_punct(Punct::RParen) {
3978                    loop {
3979                        args.push(self.parse_assignment_expr()?);
3980                        if self.eat_punct(Punct::Comma).is_none() {
3981                            break;
3982                        }
3983                    }
3984                }
3985                let rp = self.expect_punct(Punct::RParen, " after argument list")?;
3986                expr = Expr {
3987                    range: expr.range.join(rp),
3988                    kind: ExprKind::Call {
3989                        callee: Box::new(expr),
3990                        args,
3991                    },
3992                };
3993                continue;
3994            }
3995            let arrow = if self.at_punct(Punct::Dot) {
3996                false
3997            } else if self.at_punct(Punct::Arrow) {
3998                true
3999            } else if self.at_punct(Punct::PlusPlus) || self.at_punct(Punct::MinusMinus) {
4000                let op = if self.at_punct(Punct::PlusPlus) {
4001                    IncDec::Inc
4002                } else {
4003                    IncDec::Dec
4004                };
4005                let range = expr.range.join(self.bump_range());
4006                expr = Expr {
4007                    kind: ExprKind::PostIncDec {
4008                        op,
4009                        operand: Box::new(expr),
4010                    },
4011                    range,
4012                };
4013                continue;
4014            } else {
4015                break;
4016            };
4017            self.advance();
4018            let field = self.expect_ident(if arrow { " after '->'" } else { " after '.'" })?;
4019            expr = Expr {
4020                range: expr.range.join(field.range),
4021                kind: ExprKind::Member {
4022                    base: Box::new(expr),
4023                    arrow,
4024                    field,
4025                },
4026            };
4027        }
4028        Ok(expr)
4029    }
4030
4031    /// `_Generic ( controlling-expression , type : value , … )` — C11 6.5.1.1.
4032    ///
4033    /// Every association is parsed; only the chosen one is checked, which is
4034    /// what makes `_Generic` usable for a type the other arms would refuse.
4035    fn parse_generic_selection(&mut self) -> PResult<Expr> {
4036        let start = self.cur_range();
4037        self.require_keyword(Keyword::Generic, start);
4038        self.advance();
4039        self.expect_punct(Punct::LParen, " after '_Generic'")?;
4040        let controlling = self.parse_assignment_expr()?;
4041        let mut assocs = Vec::new();
4042        while self.eat_punct(Punct::Comma).is_some() {
4043            let astart = self.cur_range();
4044            let ty = if self.eat_keyword(Keyword::Default).is_some() {
4045                None
4046            } else {
4047                Some(self.parse_type_name()?)
4048            };
4049            self.expect_punct(Punct::Colon, " after the type of a '_Generic' association")?;
4050            let value = self.parse_assignment_expr()?;
4051            assocs.push(GenericAssoc {
4052                ty,
4053                value,
4054                range: self.span_to_here(astart),
4055            });
4056        }
4057        let rparen = self.expect_punct(Punct::RParen, " to close '_Generic'")?;
4058        if assocs.is_empty() {
4059            self.error(
4060                start.join(rparen),
4061                "'_Generic' requires at least one association",
4062            );
4063        }
4064        Ok(Expr {
4065            kind: ExprKind::Generic {
4066                controlling: Box::new(controlling),
4067                assocs,
4068            },
4069            range: start.join(rparen),
4070        })
4071    }
4072
4073    fn parse_primary_expr(&mut self) -> PResult<Expr> {
4074        let range = self.cur_range();
4075        match self.peek().kind.clone() {
4076            TokenKind::Keyword(Keyword::Generic) => self.parse_generic_selection(),
4077            TokenKind::Keyword(k @ (Keyword::True | Keyword::False)) => {
4078                self.advance();
4079                Ok(Expr {
4080                    kind: ExprKind::Bool(k == Keyword::True),
4081                    range,
4082                })
4083            }
4084            TokenKind::Keyword(Keyword::Nullptr) => {
4085                self.advance();
4086                Ok(Expr {
4087                    kind: ExprKind::Nullptr,
4088                    range,
4089                })
4090            }
4091            TokenKind::Ident(name) => {
4092                self.advance();
4093                Ok(Expr {
4094                    kind: ExprKind::Ident(Ident { name, range }),
4095                    range,
4096                })
4097            }
4098            TokenKind::Int(lit) => {
4099                self.advance();
4100                Ok(Expr {
4101                    kind: ExprKind::Int(lit),
4102                    range,
4103                })
4104            }
4105            TokenKind::Float(lit) => {
4106                self.advance();
4107                Ok(Expr {
4108                    kind: ExprKind::Float(lit),
4109                    range,
4110                })
4111            }
4112            TokenKind::Char(lit) => {
4113                self.advance();
4114                Ok(Expr {
4115                    kind: ExprKind::Char(lit),
4116                    range,
4117                })
4118            }
4119            TokenKind::Str(first) => Ok(self.parse_string_literal(first, range)),
4120            TokenKind::Punct(Punct::LParen) => {
4121                self.advance();
4122                // GNU's statement expression, `({ … })`: a compound statement
4123                // where an expression goes, whose value is the value of the
4124                // last expression statement in it.
4125                if self.at_punct(Punct::LBrace) {
4126                    let block = self.parse_compound_stmt()?;
4127                    let rp =
4128                        self.expect_punct(Punct::RParen, " to close a statement expression")?;
4129                    return Ok(Expr {
4130                        kind: ExprKind::StmtExpr(Box::new(block)),
4131                        range: range.join(rp),
4132                    });
4133                }
4134                let inner = self.parse_expr()?;
4135                let rp = self.expect_punct(Punct::RParen, " after parenthesized expression")?;
4136                Ok(Expr {
4137                    kind: inner.kind,
4138                    range: range.join(rp),
4139                })
4140            }
4141            _ => {
4142                let found = self.describe_cur();
4143                Err(self.error_bail(range, format!("expected expression, found {found}")))
4144            }
4145        }
4146    }
4147
4148    /// Concatenates adjacent string literals, as translation phase 6 does.
4149    ///
4150    /// C11 6.4.5p5 gives the result the prefix of whichever half has one; two
4151    /// *different* prefixes have no meaning (and C23's N2594 deleted the last
4152    /// of the wording that gave them one), so that is a diagnostic. An
4153    /// unprefixed half being absorbed is re-encoded, because its elements are
4154    /// the UTF-8 bytes of the source and the result's are code units.
4155    fn parse_string_literal(&mut self, first: StrLit, first_range: SourceRange) -> Expr {
4156        self.advance();
4157        let mut kind = first.kind;
4158        let mut values = first.values;
4159        let mut text = first.text;
4160        let mut range = first_range;
4161        while let TokenKind::Str(next) = self.peek().kind.clone() {
4162            let piece_range = self.cur_range();
4163            if next.kind != kind {
4164                if kind == StrKind::Narrow {
4165                    values = recode_from_narrow(&values, next.kind);
4166                    kind = next.kind;
4167                } else if next.kind != StrKind::Narrow {
4168                    self.error(
4169                        piece_range,
4170                        format!(
4171                            "cannot concatenate a '{}' string literal with a '{}' one",
4172                            kind.prefix(),
4173                            next.kind.prefix()
4174                        ),
4175                    );
4176                }
4177            }
4178            if next.kind == kind || next.kind != StrKind::Narrow {
4179                values.extend_from_slice(&next.values);
4180            } else {
4181                values.extend(recode_from_narrow(&next.values, kind));
4182            }
4183            text.push(' ');
4184            text.push_str(&next.text);
4185            range = range.join(piece_range);
4186            self.advance();
4187        }
4188        Expr {
4189            kind: ExprKind::Str(StrLit { kind, values, text }),
4190            range,
4191        }
4192    }
4193}
4194
4195/// Whether a name is one of the extended floating types, and how to describe
4196/// it.
4197///
4198/// GCC's `__float128` and `__fp16`, and TS 18661-3's `_FloatN` / `_FloatNx`
4199/// set, which C23 made optional in Annex H. None of them is here: `f32` and
4200/// `f64` are Rust's only two floating types on a stable compiler, `f16` and
4201/// `f128` are unstable, and the 80-bit `long double` an x86 `_Float64x` really
4202/// is has no Rust type at all. They are recognised so that a *declaration* of
4203/// one — which is all a header ever writes, and only behind a
4204/// `__GNUC_PREREQ` that this crate's `__GNUC__` does not meet — is one clear
4205/// refusal rather than an "implicit int" cascade.
4206fn extended_float_type(name: &str) -> Option<&'static str> {
4207    match name {
4208        "__float128" | "_Float128" | "_Float128x" => Some("binary128"),
4209        "_Float64x" => Some("the extended-precision type behind 'long double'"),
4210        "__fp16" | "_Float16" => Some("binary16"),
4211        "__bf16" | "__bfloat16" => Some("bfloat16"),
4212        // `_Float32` and `_Float64` are `float` and `double` in every format
4213        // this crate models, but they are still distinct *types* to C, and a
4214        // `_Generic` over them would answer differently.
4215        "_Float32" | "_Float32x" => Some("the TS 18661-3 spelling of a binary32 type"),
4216        "_Float64" => Some("the TS 18661-3 spelling of a binary64 type"),
4217        _ => None,
4218    }
4219}
4220
4221/// Re-encodes the UTF-8 bytes of an unprefixed literal as elements of `kind`.
4222///
4223/// `"é" L"x"` is one wide literal of two characters, not of the two bytes the
4224/// `é` was written as.
4225fn recode_from_narrow(values: &[u32], kind: StrKind) -> Vec<u32> {
4226    if kind == StrKind::Narrow || kind == StrKind::Utf8 {
4227        return values.to_vec();
4228    }
4229    let bytes: Vec<u8> = values.iter().map(|v| *v as u8).collect();
4230    let text = String::from_utf8_lossy(&bytes);
4231    let mut out = Vec::with_capacity(values.len());
4232    for ch in text.chars() {
4233        let value = ch as u32;
4234        if kind == StrKind::Utf16 && value > 0xffff {
4235            let v = value - 0x1_0000;
4236            out.push(0xd800 + (v >> 10));
4237            out.push(0xdc00 + (v & 0x3ff));
4238        } else {
4239            out.push(value);
4240        }
4241    }
4242    out
4243}