Skip to main content

rucc_driver/
lib.rs

1//! The driver: command line parsing, the phase graph, job scheduling and the linker
2//! invocation.
3//!
4//! Design: `spec/04-driver-and-cli.md`. Layer rank 13, see `spec/18-package-layout.md`.
5//!
6//! This is the only crate that is allowed to know the process exists. It reads the command
7//! line, touches the file system, spawns the linker and writes to the terminal, and it hands
8//! everything below it a [`Session`]. The binary crate is a `main` that calls
9//! [`run`] and nothing else, so that the whole driver is reachable from a test.
10//!
11//! # Status
12//!
13//! `--help`, `--version` and `--print-config` are real, which is the `M0` exit criterion in
14//! `spec/17-milestones.md`. The phase graph is real and `-###` prints it, and the scheduler
15//! that will run it is real and tested.
16//!
17//! Two phases run. `-E` reads the file, runs phase 4 over it and writes the result, to `-o` or
18//! to standard output. `--emit=tast` carries on through phase 7, the parse and the checking,
19//! and writes the typed tree. The flags those two read are real with them, which is `-D`, `-U`,
20//! `-I`, `-I-`, `-iquote`, `-isystem`, `-idirafter`, `-iprefix`, `-iwithprefix`,
21//! `-iwithprefixbefore`, `-include`, `-imacros`, `--sysroot=`, `-isysroot`, `-P`, `-std=`,
22//! `-fgnuc-version=`, `-ansi`, `-ffreestanding`, `-fno-builtin`, `-fno-builtin-<name>`,
23//! `-fgnu89-inline`, `-pedantic` and `-Werror`.
24//! The phases after them still say they are not implemented.
25//!
26//! This crate is tier 3 in `spec/18-package-layout.md` section 18.5: its Rust API is
27//! explicitly unstable and will change without a major version bump.
28
29#![doc(html_root_url = "https://docs.rs/rucc-driver/0.10.20")]
30
31pub mod cache;
32pub mod compile;
33pub mod deps;
34pub mod library;
35pub mod link;
36mod map;
37pub mod phase;
38pub mod preprocess;
39pub mod schedule;
40
41use std::fmt::Write as _;
42use std::io::Write as _;
43use std::path::PathBuf;
44
45use rucc_codegen::coverage::{self, Fired};
46use rucc_codegen::pressure::Pressure;
47use rucc_pp::Dependency;
48use rucc_session::{
49    Compress, Control, Dumps, EmitKind, Hook, Options, Pic, PrefixMap, Preinclude, Protector,
50    SaveTemps, Session, Std, Wrapping, runtime,
51};
52use rucc_sysroot::{Manifest, Sysroot};
53use rucc_target::Triple;
54
55use crate::link::LinkOptions;
56
57pub use crate::compile::{Artifact, Compiled, Temps, compile, compile_ir};
58pub use crate::phase::{Input, InputKind, Job, LinkJob, Output, Phase, Plan};
59pub use crate::preprocess::{OsFileSystem, Preprocessed, preprocess};
60pub use crate::schedule::Jobs;
61
62/// The compiler's version, taken from the workspace manifest.
63pub const VERSION: &str = env!("CARGO_PKG_VERSION");
64
65/// What the command line asked for.
66#[derive(Debug, Clone, PartialEq, Eq)]
67pub enum Action {
68    /// Print usage and exit successfully.
69    Help,
70    /// Print the version and exit successfully.
71    Version,
72    /// Print one line and exit successfully, which is what the `-dump` and `-print` family do.
73    ///
74    /// A build system asks these before it compiles anything, and what it does with the answer
75    /// is paste it into a path or into another command line, so each one is a single line with
76    /// no decoration around it.
77    Print(String),
78    /// Print the resolved configuration and exit successfully.
79    PrintConfig(Box<Options>),
80    /// Print the passes the level will run and exit successfully.
81    PrintPipeline(Box<Options>),
82    /// Print the phase plan and the link line and exit successfully, which is `-###`.
83    PrintPlan {
84        /// The resolved options, which is what says what the link line is for.
85        opts: Box<Options>,
86        /// What to do to each input, and in what order.
87        plan: Box<Plan>,
88        /// What the command line said about linking.
89        link: Box<LinkOptions>,
90    },
91    /// Compile the given inputs.
92    Compile {
93        /// The resolved options.
94        opts: Box<Options>,
95        /// What to do to each input, and in what order.
96        plan: Box<Plan>,
97        /// What the command line said about linking.
98        link: Box<LinkOptions>,
99        /// How many translation units to compile at once.
100        jobs: Jobs,
101        /// Whether `-v` asked for the plan to be printed while it runs.
102        verbose: bool,
103    },
104}
105
106/// Why a command line was rejected.
107#[derive(Debug, Clone, PartialEq, Eq)]
108pub struct CliError {
109    /// The message, lowercase and without a trailing period, in the same shape as any other
110    /// diagnostic.
111    pub message: String,
112}
113
114impl std::fmt::Display for CliError {
115    fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
116        f.write_str(&self.message)
117    }
118}
119
120impl std::error::Error for CliError {}
121
122fn err(message: impl Into<String>) -> CliError {
123    CliError { message: message.into() }
124}
125
126/// The two halves of one prefix mapping flag's argument, where `flag` includes its trailing `=`.
127///
128/// The split is at the last `=` in what follows the flag, not the first, which is gcc's rule and
129/// the only one that lets a directory whose name contains an `=` be the old half. It also means
130/// `-fmacro-prefix-map=a=b=c` rewrites `a=b` to `c` rather than `a` to `b=c`, which looks like a
131/// trap until you notice the alternative traps the far more common case.
132fn rewrite<'a>(arg: &'a str, flag: &str) -> Result<(&'a str, &'a str), CliError> {
133    let rest = &arg[flag.len()..];
134    PrefixMap::split(rest).ok_or_else(|| {
135        let flag = flag.trim_end_matches('=');
136        err(format!(
137            "`{rest}` is not a rewrite for `{flag}`, which is an old prefix, an `=` and a new one"
138        ))
139    })
140}
141
142/// A question the command line asked instead of asking for a compilation.
143///
144/// These are answered after the loop rather than where they are read, because every one of them
145/// is about the target or about the library search and the last word on both is the end of the
146/// command line.
147enum Query {
148    /// `-dumpmachine`, the triple.
149    Machine,
150    /// `-dumpversion` and `-dumpfullversion`, which are the same three numbers here.
151    Version,
152    /// `-print-multiarch`, the directory name a distribution files this target under.
153    Multiarch,
154    /// `-print-search-dirs`, in the three lines GCC prints.
155    SearchDirs,
156    /// `-print-sysroot`, the root the headers and the libraries are read under.
157    Sysroot,
158    /// `-print-sysroot-provenance`, what is in that root and where each of it came from.
159    SysrootProvenance,
160    /// `-print-file-name=<name>`, the full path of a library file.
161    FileName(String),
162    /// `-print-prog-name=<name>`, the full path of a program.
163    ProgName(String),
164    /// `-print-libgcc-file-name`, which is `-print-file-name=libgcc.a` under another spelling.
165    Libgcc,
166}
167
168/// Usage text.
169///
170/// Deliberately short. `spec/04-driver-and-cli.md` puts the full flag reference in the
171/// manual page, because a `--help` nobody can read in one screen is a `--help` nobody reads.
172pub const USAGE: &str = "\
173rucc, an optimizing C compiler
174
175usage: rucc [options] file...
176
177options:
178  -c                     compile and assemble, do not link
179  -S                     compile only, emit assembly
180  -E                     preprocess only
181  -o <file>              write output to <file>, or to standard output for -
182  -D <name>[=<value>], -U <name>      define a macro, or undefine one after every -D
183  -I <dir>               add <dir> to the include search path
184  -iquote -isystem -idirafter <dir>   the other chains, -nostdinc drops ours
185  -I-, -iprefix <p>, -iwithprefix[before] <dir>   the older spellings of those
186  -include <file>, -imacros <file>    read <file> first, the second for its macros only
187  --sysroot=<dir>        look for the library's headers under <dir>, -isysroot too
188  -P, -dM                with -E: leave out the markers, or dump the macros
189  -M -MM -MD -MMD        write a make rule for the source, the last two compile as well
190  -MF <file> -MT <t> -MQ <t> -MP   where the rule goes, what it builds, targets with no recipe
191  -std=<dialect>         c89 through c23, and the gnu spellings
192  -fgnuc-version=<v>     the GCC release to claim, default 7.0.0
193  -x <lang>              treat later inputs as <lang>, or none to stop
194  -O<level>              optimize: 0, 1, 2, 3, s, z
195  -fsafety=<tier>        check memory safety: off, detect, enforce, kernel
196  -f[no-]safety-subobject   a write has to stay inside the member it names
197  -f[no-]safety-restrict    two restrict pointers of one block may not meet
198  -f<pass> -fno-<pass> -fdump-ir=<what> -fopt-info[-<kind>][=FILE]
199  -fpass-fuel=<pass>=<n>, -fpass-fuel-global=<n>   stop a pass, or all of them, after n
200  -fdisable-<pass>[=<funcs>], -fenable-<pass>[=<funcs>]   run a pass on some functions only
201  -g -g0 -gdwarf-5, -fno-omit-frame-pointer, -mno-red-zone   debug info, frame pointer, red zone
202  -gz[=none|zlib|zlib-gnu|zstd] -gno-split-dwarf   compress debug sections, one file not two
203  -flto[=auto|jobserver|<n>] -fno-lto -ffat-lto-objects   read, and not done yet
204  -fprofile-use[=<path>] -fprofile-dir=<dir>   read too, where -fprofile-generate is refused
205  -f[no-]stack-protector[-strong|-all], -f[no-]stack-clash-protection, -fcf-protection=<edges>
206  -ffunction-sections -fdata-sections   a section per function or variable, for --gc-sections
207  -fvisibility=<what>    default, hidden, internal or protected, when nothing in the source said
208  -l<name>, -L <dir>, -B <dir>   link a library, where to look for one, where our own tools are
209  -fPIC -fpic -fPIE -fpie, -fno-common, -pipe   what it does anyway
210  -f[no-]strict-aliasing, -f[no-]delete-null-pointer-checks   what it assumes anyway
211  -static -shared -pie -no-pie -nostdlib -nostartfiles -nodefaultlibs -rdynamic -s   how to link
212  -Wl,<arg>, -Xlinker <arg>, -fuse-ld=<name>   hand an argument to the linker, or pick one
213  -Werror -pedantic -pedantic-errors -w   how much to say, and whether it is fatal
214  -m64 -march= -mtune= -mcpu= -mabi= -mcmodel=   what machine to generate for
215  -pg -p, -mfentry -mno-fentry   call a profiler on the way in, and where that call goes
216  -fpatchable-function-entry=<n>[,<m>]   room at the top of every function to patch later
217  -fwrapv, -fwrapv-pointer, -fno-strict-overflow   signed or pointer overflow wraps
218  -ftrapv                signed overflow stops the program instead
219  -f[no-]signed-char, -f[no-]unsigned-char, -f[no-]short-enums   change the ABI
220  -ffp-contract=<how>    fuse a multiply and an addition: fast, on or off
221  -fexcess-precision=<how>, -f[no-]rounding-math, -f[no-]trapping-math   what it does anyway
222  -ffile-prefix-map=<old>=<new>   rewrite that front of every path we put in the output
223  -fmacro-prefix-map= -fdebug-prefix-map= -fprofile-prefix-map=   the same, one output each
224  -pthread               build for more than one thread, and link the library for it
225  -dumpmachine -dumpversion -print-multiarch -print-search-dirs   what this compiler is
226  -print-file-name=<name> -print-prog-name=<name>   where a file or a program is
227  -print-sysroot         the root the headers and the libraries are read under
228  -print-sysroot-provenance   every input under it, where it came from and its licence
229  -j[n]                  compile n translation units at once, default all
230  -v, -###               print each phase as it runs, or without running any
231  -save-temps[=cwd|obj], -time   keep the .i and the .s, say how long each step took
232  --target=<triple>      generate code for <triple>
233  --emit=<kind>          exe, obj, asm, preprocessed, tast, ir, mir-final,
234                         safety-summary, type-granules
235  --print-config, --print-pipeline    print the configuration or the pipeline, and exit
236  --version              print the version and exit
237  -h, --help             print this message and exit
238
239See spec/04-driver-and-cli.md for the full flag reference.
240";
241
242/// The argument of a flag that may be joined to it or may be the next word.
243///
244/// `-DFOO` and `-D FOO` are the same thing, and `at` is where the flag's own letters end.
245fn joined_or_next(
246    arg: &str,
247    at: usize,
248    args: &[String],
249    i: &mut usize,
250) -> Result<String, CliError> {
251    if arg.len() > at {
252        return Ok(arg[at..].to_owned());
253    }
254    let next = args.get(*i).ok_or_else(|| err(format!("{arg} requires an argument")))?;
255    *i += 1;
256    Ok(next.clone())
257}
258
259/// Parses a command line, without the program name.
260///
261/// # Errors
262///
263/// Returns the message to print when the arguments do not name a compilation this compiler
264/// can attempt.
265pub fn parse_args(args: &[String]) -> Result<Action, CliError> {
266    let host = Triple::host()
267        .ok_or_else(|| err("this host is not a supported target and no --target was given"))?;
268    let mut opts = Options::new(host);
269    let mut inputs: Vec<Input> = Vec::new();
270    let mut print_config = false;
271    let mut print_pipeline = false;
272    let mut print_plan = false;
273    let mut verbose = false;
274    let mut jobs = Jobs::default();
275    let mut nostdinc = false;
276    let mut sysroot: Option<PathBuf> = None;
277    // The whole ten field target, kept beside the three field one because `--target=` can pin a
278    // libc version and `Triple` has nowhere to put it. It decides `__GLIBC_MINOR__` and nothing
279    // else today, and `None` is a command line that named no target, which is this machine.
280    let mut pinned: Option<rucc_tuple::TargetTuple> = None;
281    let mut output = None;
282    let mut link = LinkOptions::default();
283    let mut query: Option<Query> = None;
284    let mut threads = false;
285    // `-x` applies to inputs that come after it and stays in effect until the next one, which
286    // is why it is tracked across the loop rather than attached to a single argument.
287    let mut forced: Option<InputKind> = None;
288    // What `-iprefix` last said, stuck on the front of every later `-iwithprefix`. It applies to
289    // the flags after it and not the ones before, so a command line may set it more than once.
290    // GCC's default is its own installed header directory with the last component taken off,
291    // which is a path a cross compiler's build system knows and passes; there is no equivalent
292    // here, so with no `-iprefix` the prefix is nothing and `-iwithprefix` names a directory
293    // outright.
294    let mut iprefix = String::new();
295
296    let mut i = 0;
297    while i < args.len() {
298        let arg = args[i].as_str();
299        i += 1;
300        match arg {
301            "-h" | "--help" => return Ok(Action::Help),
302            "--version" => return Ok(Action::Version),
303            "--print-config" => print_config = true,
304            "--print-pipeline" => print_pipeline = true,
305            "-###" => print_plan = true,
306            "-v" => verbose = true,
307            // The files a compilation goes through, kept rather than thrown away. The bare
308            // spelling means `=obj` and not `=cwd`, which is not what the manual says and is what
309            // gcc 16 does; `SaveTemps::Object` carries the measurement.
310            "-save-temps" => opts.save_temps = SaveTemps::Object,
311            _ if arg.starts_with("-save-temps=") => {
312                opts.save_temps = arg["-save-temps=".len()..].parse().map_err(err)?;
313            }
314            // How long each step took. A misspelling of this is worth rejecting rather than
315            // ignoring, since a run that says nothing looks like a compilation that took no time.
316            "-time" => opts.time = true,
317            "-c" => opts.emit = EmitKind::Object,
318            "-S" => opts.emit = EmitKind::Asm,
319            "-E" => opts.emit = EmitKind::Preprocessed,
320            "-g" => opts.debug_info = true,
321            // GCC's own levels of how much debug information to write. Zero is none and every
322            // other number is some, and this compiler has one amount, so the numbers above zero
323            // all mean the same thing here. `-ggdb` is the same flag asking for whatever the
324            // debugger on the machine prefers, which is what we emit anyway.
325            "-g0" => opts.debug_info = false,
326            "-g1" | "-g2" | "-g3" | "-ggdb" | "-ggdb1" | "-ggdb2" | "-ggdb3" => {
327                opts.debug_info = true;
328            }
329            // The version of DWARF to write. We write DWARF 5 and nothing else, so a build that
330            // asks for another version is told rather than handed a file it cannot read.
331            "-gdwarf" | "-gdwarf-5" => opts.debug_info = true,
332            _ if arg.starts_with("-gdwarf-") => {
333                return Err(err(format!(
334                    "{arg}: this compiler writes DWARF 5 and no other version, see \
335                     spec/11-debug-info.md"
336                )));
337            }
338            // Whether the debug information goes in a file of its own beside the object. gcc
339            // writes that `.dwo` whether or not it found anything to put in it, which means a
340            // build system that declares the file as an output gets one and a make rule that
341            // depends on it fires. Refused for that reason rather than taken: section 4.1 takes a
342            // flag that changes nothing and refuses one that changes what is produced, and a file
343            // that does not appear is the plainest change of that kind there is. The negative
344            // spelling is taken, because putting it all in the object is what happens anyway.
345            "-gno-split-dwarf" => {}
346            "-gsplit-dwarf" => {
347                return Err(err(format!(
348                    "{arg}: this compiler writes no separate `.dwo` file, and a build that \
349                     expects one beside each object would wait for a file that never arrives, \
350                     see spec/11-debug-info.md"
351                )));
352            }
353            // How the debug sections are compressed. There are none yet, so every answer produces
354            // the same bytes and taking the flag promises nothing that is not kept. The value is
355            // still checked, because a typo in a distribution's flags is worth finding when the
356            // compiler reads it rather than when somebody later wonders why nothing got smaller.
357            // Bare `-gz` means `zlib`, which the manual leaves for the reader to discover.
358            "-gz" => opts.compress = Compress::Zlib,
359            _ if arg.starts_with("-gz=") => {
360                let how = &arg["-gz=".len()..];
361                opts.compress = how.parse().map_err(|()| {
362                    err(format!(
363                        "`{how}` is not a way to compress debug sections, which is none, zlib, \
364                         zlib-gnu or zstd"
365                    ))
366                })?;
367            }
368            "-Werror" => opts.warnings_are_errors = true,
369            // Nothing that is not fatal is said at all. Read at the one place a diagnostic goes
370            // through rather than here, so that a warning `-w` dropped is not counted either.
371            "-w" => opts.warnings = false,
372            "-pedantic-errors" => {
373                opts.pedantic = true;
374                opts.warnings_are_errors = true;
375            }
376            "-P" => opts.line_markers = false,
377            // The dependency family, which section 4.4 calls required because every build system
378            // that generates its own makefiles asks for it. The two that end in `D` write a file
379            // beside the object and let the compilation happen, and the two that do not write to
380            // standard output and stop after it. Nothing here turns the system headers back on
381            // once a flag has turned them off, which is GCC's behaviour and is why `-MM -M` is
382            // `-MM`: the flag asking for fewer of them is the one with something to say.
383            "-M" => {
384                opts.deps.emit = true;
385                opts.deps.instead_of_compiling = true;
386            }
387            "-MM" => {
388                opts.deps.emit = true;
389                opts.deps.instead_of_compiling = true;
390                opts.deps.system_headers = false;
391            }
392            "-MD" => opts.deps.emit = true,
393            "-MMD" => {
394                opts.deps.emit = true;
395                opts.deps.system_headers = false;
396            }
397            "-MP" => opts.deps.phony = true,
398            // These three take a word and only in the separated form, which is how GCC spells
399            // them and how every build system writes them.
400            "-MF" | "-MT" | "-MQ" => {
401                let value =
402                    args.get(i).ok_or_else(|| err(format!("{arg} requires an argument")))?;
403                i += 1;
404                match arg {
405                    "-MF" => opts.deps.file = Some(value.clone()),
406                    // The whole of the difference between the two. `-MT` is for a build that has
407                    // already escaped what it is passing, and `-MQ` is for one that has a name
408                    // and wants it to arrive as that name.
409                    "-MT" => opts.deps.targets.push(value.clone()),
410                    _ => opts.deps.targets.push(deps::escaped(value)),
411                }
412            }
413            // The questions a build system asks before it compiles anything. Answered after the
414            // loop, because each one is about the target or the library search and the command
415            // line has not finished saying what those are.
416            "-dumpmachine" => query = Some(Query::Machine),
417            "-dumpversion" | "-dumpfullversion" => query = Some(Query::Version),
418            "-print-multiarch" => query = Some(Query::Multiarch),
419            "-print-search-dirs" => query = Some(Query::SearchDirs),
420            "-print-sysroot" => query = Some(Query::Sysroot),
421            // Both spellings, because this one is ours rather than GCC's and our own documents
422            // write it both ways: section 13.5 of `spec/cross-compile/13-distribution.md` gives it
423            // two dashes like the other flags we invented, and document 12's table gives it one
424            // like the `-print-` family it sits in. A person who reads either and types what it
425            // says is right, so neither is refused.
426            "-print-sysroot-provenance" | "--print-sysroot-provenance" => {
427                query = Some(Query::SysrootProvenance);
428            }
429            "-print-libgcc-file-name" => query = Some(Query::Libgcc),
430            _ if arg.starts_with("-print-file-name=") => {
431                query = Some(Query::FileName(arg["-print-file-name=".len()..].to_owned()));
432            }
433            _ if arg.starts_with("-print-prog-name=") => {
434                query = Some(Query::ProgName(arg["-print-prog-name=".len()..].to_owned()));
435            }
436            // A program built to run in more than one thread. On every platform this compiler
437            // targets that is a macro the library's headers read and one more library on the
438            // link line, and the library is added after the loop so that it lands after the
439            // objects that refer to it.
440            "-pthread" | "-pthreads" => {
441                opts.defines.push("_REENTRANT".to_owned());
442                threads = true;
443            }
444            "-ansi" => {
445                opts.std = Std::C89;
446                opts.gnu_extensions = false;
447            }
448            // `-Wpedantic` is the same flag under the name the `-W` family gives it, which is
449            // the spelling a build system that groups its warning flags tends to write.
450            "-pedantic" | "-Wpedantic" => opts.pedantic = true,
451            // Both directions, because a build that needs this for one directory turns it back
452            // off for the next one rather than leaving it on for the whole tree.
453            "-fpermissive" => opts.permissive = true,
454            "-fno-permissive" => opts.permissive = false,
455            "-ffreestanding" => opts.hosted = false,
456            "-fhosted" => opts.hosted = true,
457            "-fno-builtin" => opts.builtins = false,
458            "-fbuiltin" => opts.builtins = true,
459            // The C89 dialects are under GNU's reading whatever this says, so turning it off
460            // there is turning off something the dialect asked for, which is accepted and does
461            // nothing. gcc refuses that command line, and there is nothing it could have meant.
462            "-fgnu89-inline" => opts.gnu89_inline = true,
463            "-fno-gnu89-inline" => opts.gnu89_inline = false,
464            // Both directions of each, because a build system that wants one of these usually
465            // writes it beside the flag that turns it back off for one directory.
466            "-fno-omit-frame-pointer" => opts.frame_pointer = true,
467            "-fomit-frame-pointer" => opts.frame_pointer = false,
468            "-mno-red-zone" => opts.red_zone = false,
469            "-mred-zone" => opts.red_zone = true,
470            // Four flags rather than one with an argument, which is how gcc spells them and how
471            // every build line writes them. Last one wins, because a package build puts
472            // `-fstack-protector-strong` in its global flags and a directory that cannot have one
473            // turns it back off on the line after.
474            "-fno-stack-protector" | "-fno-stack-protector-all" | "-fno-stack-protector-strong" => {
475                opts.protector = Protector::None;
476            }
477            "-fstack-protector" => opts.protector = Protector::Buffers,
478            "-fstack-protector-strong" => opts.protector = Protector::Strong,
479            "-fstack-protector-all" => opts.protector = Protector::All,
480            // The other half of what a hardened build asks for, and it is a question about the
481            // frame rather than about the function, so it is a switch rather than a level.
482            "-fstack-clash-protection" => opts.stack_clash = true,
483            "-fno-stack-clash-protection" => opts.stack_clash = false,
484            // The third of them, and the one that is a question with an argument rather than a
485            // family of spellings, because what it asks about is which of the two edges of a
486            // control flow transfer is checked. Bare is both of them, which is what gcc does.
487            "-fcf-protection" => opts.control = Control::Full,
488            "-fno-cf-protection" => opts.control = Control::None,
489            // Two spellings of the same request, which is what gcc has as well. `-p` was the older
490            // profiler and `-pg` the one that also recorded who called whom, and on every platform
491            // this compiler targets there is now one hook and both ask for it.
492            "-pg" | "-p" => {
493                opts.profile = true;
494                link.profile = true;
495            }
496            // Accepted on their own and doing nothing on their own, which is gcc's behaviour: they
497            // say where the call goes and a command line that asked for no call has nowhere to put
498            // one. That matters because a build system that sets `-mfentry` globally and `-pg` per
499            // directory is a build system that would otherwise fail on every other directory.
500            "-mfentry" => opts.hook = Hook::Early,
501            "-mno-fentry" => opts.hook = Hook::Late,
502            // GCC drops its own include directory along with the system ones, because its
503            // headers are half of a pair with the library's and half a pair is worse than
504            // none. A build that passes this is supplying the whole set itself.
505            "-nostdinc" => nostdinc = true,
506            "-o" => {
507                output = Some(args.get(i).ok_or_else(|| err("-o requires an argument"))?.clone());
508                i += 1;
509            }
510            // The flags that take a directory only in the separated form. GCC spells them
511            // this way and nothing writes `-iquotedir`, so accepting the joined form would
512            // mean guessing at a path that starts with the flag's own letters.
513            // Apple's spelling of `--sysroot`, and the one its own build systems pass. The
514            // two mean the same thing here: the configured directories are under there rather
515            // than under the root.
516            "-isysroot" => {
517                let dir = args.get(i).ok_or_else(|| err("-isysroot requires an argument"))?;
518                i += 1;
519                sysroot = Some(PathBuf::from(dir));
520            }
521            "-iquote" | "-isystem" | "-idirafter" => {
522                let dir = args.get(i).ok_or_else(|| err(format!("{arg} requires an argument")))?;
523                i += 1;
524                match arg {
525                    "-iquote" => opts.search.push_quote(dir.clone()),
526                    "-isystem" => opts.search.push_system(dir.clone()),
527                    _ => opts.search.push_after(dir.clone()),
528                }
529            }
530            "-iprefix" => {
531                iprefix = args.get(i).ok_or_else(|| err("-iprefix requires an argument"))?.clone();
532                i += 1;
533            }
534            // Where GCC puts these is not where its manual says it puts them, and this is the
535            // measured answer rather than the documented one: `-iwithprefix` lands in the
536            // `-isystem` slot and not the `-idirafter` slot, and `-iwithprefixbefore` lands in
537            // the `-I` slot. A cross build that uses them is relying on the behaviour, since
538            // that is the compiler it was developed against.
539            "-iwithprefix" | "-iwithprefixbefore" => {
540                let dir = args.get(i).ok_or_else(|| err(format!("{arg} requires an argument")))?;
541                i += 1;
542                let dir = format!("{iprefix}{dir}");
543                if arg == "-iwithprefix" {
544                    opts.search.push_system(dir);
545                } else {
546                    opts.search.push_bracket(dir);
547                }
548            }
549            "-include" | "-imacros" => {
550                let name = args.get(i).ok_or_else(|| err(format!("{arg} requires an argument")))?;
551                i += 1;
552                opts.preincludes
553                    .push(Preinclude { name: name.clone(), macros_only: arg == "-imacros" });
554            }
555            // The flag `-iquote` was introduced to replace, still passed by build systems old
556            // enough to predate the replacement. It is not a directory: it says that every `-I`
557            // so far is for quoted includes only, and that a quoted include stops looking next
558            // to the file that wrote it.
559            "-I-" => opts.search.split_quote_chain(),
560            "-x" => {
561                let lang = args.get(i).ok_or_else(|| err("-x requires an argument"))?;
562                i += 1;
563                forced = if lang == "none" {
564                    None
565                } else {
566                    Some(InputKind::from_x_arg(lang).map_err(|e| err(format!("{e}")))?)
567                };
568            }
569            // Not a GCC flag. spec/03-architecture.md section 3.5 compiles several
570            // translation units in one process rather than making the build system fork, and
571            // section 3.8's determinism check compares `-j1` against `-j16`, so the knob has
572            // to exist and has to be spelled the way `make` spells it.
573            // `-DFOO`, `-D FOO` and the same for `-U` and `-I`. Both forms are in wide use
574            // and a build system may produce either, so both are read here rather than
575            // being normalised by whatever generated the command line.
576            _ if arg.starts_with("-D") => {
577                let value = joined_or_next(arg, 2, args, &mut i)?;
578                opts.defines.push(value);
579            }
580            _ if arg.starts_with("-U") => {
581                let value = joined_or_next(arg, 2, args, &mut i)?;
582                opts.undefines.push(value);
583            }
584            _ if arg.starts_with("-I") => {
585                let dir = joined_or_next(arg, 2, args, &mut i)?;
586                opts.search.push_bracket(dir);
587            }
588            _ if arg.starts_with("-std=") => {
589                let name = &arg["-std=".len()..];
590                let (std, gnu) = Std::from_flag(name)
591                    .ok_or_else(|| err(format!("unknown dialect `{name}`, see --help")))?;
592                opts.std = std;
593                opts.gnu_extensions = gnu;
594            }
595            // Section 4.5. The claim decides which half of glibc's `sys/cdefs.h` we are
596            // handed, so a differential run that does not set it is comparing two compilers
597            // that believe they are different compilers.
598            // GCC packs these into one flag, so `-dDI` is two of them. Letters in the family
599            // that we have not written yet are accepted and ignored, because a dump is a
600            // debugging aid and a build that asks for one should still compile. A letter
601            // outside the family falls through to the unknown option error, which is what
602            // keeps `-dumpversion` from being read as a dump of nothing.
603            _ if Dumps::is_family(arg) => {
604                opts.dumps.add(&arg[2..]);
605            }
606            // One name at a time, which is what a build that means its own `memcpy` and the
607            // library's everything else writes. The name is not checked against a list, because
608            // the flag is about what the program means by a name and a program is allowed to mean
609            // something by a name this compiler has never heard of.
610            _ if arg.starts_with("-fno-builtin-") => {
611                opts.no_builtin.push(arg["-fno-builtin-".len()..].to_owned());
612            }
613            _ if arg.starts_with("-fgnuc-version=") => {
614                let v = &arg["-fgnuc-version=".len()..];
615                opts.gnuc = v.parse().map_err(err)?;
616            }
617            // spec/13-gnu-compat.md section 13.3 promises this flag an error that says why rather
618            // than the unknown option one, because a build reaching for it is asking for a feature
619            // and deserves to be told it is not coming rather than told the spelling is wrong.
620            // The negative form is what this compiler does anyway, so it is taken and dropped.
621            "-fnested-functions" => {
622                return Err(err(
623                    "nested functions are not supported: a call to one goes through a trampoline \
624                     written on the stack, which no target that enforces an unexecutable stack \
625                     allows",
626                ));
627            }
628            "-fno-nested-functions" => {}
629            // Which of the two links the output is for, which is a real difference and not a
630            // description of what happens anyway. Everything here is position independent either
631            // way, and what these decide is whether a name may be one another object defines or
632            // replaces, because a link that produces an executable puts every name in the same
633            // program and a link that produces a shared library does not.
634            //
635            // It matters that they are accepted at all, whatever they then do. Every autoconf and
636            // cmake build puts `-fPIC` on the compile line, so a compiler that rejects it cannot
637            // be the `CC` of a project that has a configure script, whatever else it can do. That
638            // is how this was found: building SQLite's test fixture stopped on it.
639            "-fPIC" | "-fpic" => opts.pic = Pic::Library,
640            // Not a synonym of the pair above, which is what they were treated as until #756. The
641            // library is the expensive answer and gcc makes it the one that has to be asked for,
642            // so this is also what nothing at all means.
643            "-fPIE" | "-fpie" => opts.pic = Pic::Executable,
644            // A different question from the pair above, and the one every distribution build of a
645            // shared library answers. `-fPIC` decides how an address is reached, and this decides
646            // whether the optimizer may believe a body it can see, because an exported name is one
647            // the dynamic linker may find another definition of first. On by default, which is
648            // gcc's arrangement and is the honest answer, and off is a promise the build makes and
649            // nothing checks.
650            "-fsemantic-interposition" => opts.interposition = true,
651            "-fno-semantic-interposition" => opts.interposition = false,
652            // Two requests rather than one, and the same table answers both, so what decides is
653            // whether either of them is standing. gcc arranges it the same way: the asynchronous
654            // one is the default here and it implies the other, and a line that asks for a table
655            // and against an asynchronous one gets a table.
656            "-fasynchronous-unwind-tables" => opts.async_unwind_tables = true,
657            "-fno-asynchronous-unwind-tables" => opts.async_unwind_tables = false,
658            "-funwind-tables" => opts.unwind_tables = true,
659            "-fno-unwind-tables" => opts.unwind_tables = false,
660            // The other direction is a request, not a description, and it is one this compiler
661            // cannot grant, so it gets the treatment section 13.3 asks for rather than the unknown
662            // option error. Answering it by carrying on would be answering a different question:
663            // the code would still be position independent, which is correct everywhere an
664            // ordinary program runs and is wrong in a kernel, where the flag is written precisely
665            // because there is no loader to fill a global offset table in.
666            "-fno-pic" | "-fno-pie" => {
667                return Err(err(
668                    "position dependent code is not supported: an address that may be in another \
669                     object is loaded out of the global offset table, and nothing here emits the \
670                     absolute form this asks for. Use -no-pie if what you meant was how to link",
671                ));
672            }
673            // A section per function and a section per variable, which is what makes
674            // `--gc-sections` able to drop anything: a linker can leave out a section nothing
675            // reaches and cannot leave out half of one. Both directions are taken, and the off
676            // one is the default rather than a refusal, since a build that writes it is asking
677            // for what happens anyway.
678            "-ffunction-sections" => opts.function_sections = true,
679            "-fno-function-sections" => opts.function_sections = false,
680            "-fdata-sections" => opts.data_sections = true,
681            "-fno-data-sections" => opts.data_sections = false,
682            // Another description of what this compiler does. A file scope declaration with no
683            // initializer is written into `.bss` as an ordinary defined symbol, not offered to the
684            // linker as a common one for it to merge, which is what `-fno-common` asks for and what
685            // gcc has done by default since 10. Nothing in the front end produces `Linkage::Common`
686            // at all.
687            "-fno-common" => {}
688            // What overflows rather than being undefined. Every one of these takes something away
689            // from the optimizer rather than asking it to do anything, which is why the negative
690            // spellings are the interesting ones and the positive spellings are the default.
691            //
692            // `-fno-strict-overflow` is both of the others, which is gcc's own reading of it: its
693            // help text for `-fstrict-overflow` says "negated as -fwrapv -fwrapv-pointer". So it is
694            // written here as the pair rather than kept as a third thing to test everywhere.
695            //
696            // `-ftrapv` is the exception and is the one that asks for something. It is the other
697            // answer to the question `-fwrapv` answers, so the two cannot both hold and each clears
698            // the other, which makes the last one on the command line the one that counts. That is
699            // gcc 16's behaviour and was measured rather than read: `-ftrapv -fwrapv` emits no
700            // checked calls and `-fwrapv -ftrapv` emits them. The positive spelling of the pointer
701            // question is left alone by both, because neither has anything to say about it.
702            "-fwrapv" => {
703                opts.wrapping.signed = true;
704                opts.wrapping.trap = false;
705            }
706            "-fno-wrapv" => opts.wrapping.signed = false,
707            "-fwrapv-pointer" => opts.wrapping.pointer = true,
708            "-fno-wrapv-pointer" => opts.wrapping.pointer = false,
709            "-fno-strict-overflow" => opts.wrapping = Wrapping::ALL,
710            // Which does not clear the checked one, because gcc does not: `-ftrapv
711            // -fstrict-overflow` still emits the calls. It says what is assumed and not what
712            // happens.
713            "-fstrict-overflow" => {
714                opts.wrapping.signed = false;
715                opts.wrapping.pointer = false;
716            }
717            "-ftrapv" => {
718                opts.wrapping.trap = true;
719                opts.wrapping.signed = false;
720            }
721            "-fno-trapv" => opts.wrapping.trap = false,
722            // The two flags that say what a plain `char` is, which is one question with two
723            // spellings each: gcc reads `-fno-signed-char` as `-funsigned-char` and
724            // `-fno-unsigned-char` as `-fsigned-char`, so there are four ways to write two
725            // answers and the last one written wins. Nothing is set until one of them is given,
726            // because the target's own ABI is the answer otherwise and it is not the same answer
727            // everywhere: x86-64 and Apple's arm64 are signed, Linux's arm64 is not.
728            "-fsigned-char" | "-fno-unsigned-char" => opts.char_signed = Some(true),
729            "-funsigned-char" | "-fno-signed-char" => opts.char_signed = Some(false),
730            // And the size of an enumeration, which is the other thing in this group that changes
731            // the ABI rather than the code.
732            "-fshort-enums" => opts.short_enums = true,
733            "-fno-short-enums" => opts.short_enums = false,
734            // And the request, which is the one that cannot be granted. It is a real difference and
735            // not a preference: two files each writing `int g;` link under `-fcommon` and are a
736            // duplicate definition without it, which is the whole reason the flag survives.
737            "-fcommon" => {
738                return Err(err(
739                    "a tentative definition is written into .bss as its own symbol here, and \
740                     nothing emits the common symbol this asks the linker to merge. Give the \
741                     variable a definition in one file and declare it extern in the others",
742                ));
743            }
744            // Both directions of this one are recorded, and what they decide is whether lowering
745            // names the type each access goes through. Turning it off is the front end leaving the
746            // name off rather than a pass being told to ignore one it can see, which is one
747            // condition in one place, and it is the reading that survives link time optimization:
748            // a unit built with the flag off keeps its own answer when its bodies end up in a
749            // module beside bodies that were not.
750            //
751            // Nothing in the pipeline reads those names yet. Layer 3 of the alias analysis does
752            // and is tested, and no pass at any level asks the alias analysis anything today, so
753            // no program compiles differently for having passed this. The flag is wired anyway,
754            // because the change that makes a pass ask is not the change anybody will remember to
755            // wire it in, and a flag that is taken and dropped once the names mean something is
756            // the miscompilation `spec/04-driver-and-cli.md` section 4.1 warns about in as many
757            // words.
758            "-fstrict-aliasing" => opts.strict_aliasing = true,
759            "-fno-strict-aliasing" => opts.strict_aliasing = false,
760            // The same shape of answer for the same reason, and the flag the kernel writes beside
761            // the one above it.
762            //
763            // Nothing here concludes that a pointer is not null from the fact that it was
764            // dereferenced. There is no such conclusion to draw from, because no pass records one:
765            // a load says where it read and nothing else, and a comparison against null is an
766            // ordinary comparison of two values the optimizer has no fact about. So a function
767            // that reads through a pointer and then tests it keeps the test, which is what the
768            // kernel wants and what `-fno-delete-null-pointer-checks` asks for, and what gcc has
769            // to be asked for because it draws the conclusion by default.
770            //
771            // `-fdelete-null-pointer-checks` is the request to draw it, and it goes the way
772            // `-fstrict-aliasing` does: assuming less than was asked for costs speed and not
773            // correctness, and `-O2` implies it, so refusing it would stop builds for nothing.
774            "-fdelete-null-pointer-checks" | "-fno-delete-null-pointer-checks" => {}
775            // The floating point group, which goes the same way and for the same reason, and which
776            // is worth writing out because the reason is easy to get backwards.
777            //
778            // Each of these has a restrictive spelling and a permissive one. The restrictive ones,
779            // `-frounding-math` and `-ftrapping-math`, say that the rounding mode may have been
780            // changed and that an exception raised by an operation may be looked at, so an
781            // arithmetic the compiler folds at compile time is an arithmetic whose rounding and
782            // whose exception the program does not get. Nothing here folds any floating point
783            // arithmetic in a function body: `0.1 + 0.2` is an `fadd` and `1.0 / 0.0` is a divide
784            // that runs, at every level. So both of those describe what already happens.
785            //
786            // The permissive ones are the other half, and they are licences rather than requests
787            // for an answer. `-fno-rounding-math` says the rounding mode is the default one and
788            // `-fno-trapping-math` says nothing looks at the exceptions, which together are
789            // permission to fold. Not folding is the conservative side of that permission and is
790            // what a program is entitled to whichever was written, so the flag costs speed and not
791            // correctness, which is the test section 4.1 puts a licence through. `-ftrapping-math`
792            // is also gcc's default, so a build spelling it out is a build asking for what it
793            // already has.
794            "-frounding-math" | "-fno-rounding-math" => {}
795            "-ftrapping-math" | "-fno-trapping-math" => {}
796            // About temporary files rather than about code. There is nothing between the phases of
797            // one compilation here to write to a file in the first place.
798            "-pipe" => {}
799            // Nothing here writes colour, so all of these are the same answer, and it is the answer
800            // that costs nothing: the diagnostics come out plain either way and no build depends on
801            // an escape sequence being there. Taken rather than refused because cmake writes
802            // `-fdiagnostics-color=always` on every compile line when the generator is ninja, which
803            // makes this the second most common flag after `-fPIC` to stop a build over a question
804            // about how the text looks.
805            "-fdiagnostics-color" | "-fno-diagnostics-color" => {}
806            _ if arg.starts_with("-fdiagnostics-color=") => {}
807            // The link flags. None of them changes the compilation, which is why they are
808            // collected apart from `opts` and why `-lm` on a `-c` line is a note rather than an
809            // error: it is a thing said to a linker that is not going to run.
810            "-static" => link.is_static = true,
811            "-shared" => link.shared = true,
812            "-pie" => link.pie = Some(true),
813            "-no-pie" | "-nopie" => link.pie = Some(false),
814            "-nostdlib" => link.no_stdlib = true,
815            "-nostartfiles" => link.no_startfiles = true,
816            "-nodefaultlibs" => link.no_defaultlibs = true,
817            "-fno-builtins-lib" => link.no_builtins_lib = true,
818            "-fbuiltins-lib" => link.no_builtins_lib = false,
819            "-rdynamic" | "-export-dynamic" => link.export_dynamic = true,
820            "-s" => link.strip = true,
821            "-Xlinker" => {
822                let next = args.get(i).ok_or_else(|| err("-Xlinker requires an argument"))?;
823                i += 1;
824                link.passthrough.push(next.clone());
825            }
826            _ if arg.starts_with("-Wl,") => {
827                // Commas separate arguments rather than being part of one, which is what makes
828                // `-Wl,-rpath,/opt/lib` two words to the linker and one word here.
829                link.passthrough.extend(arg["-Wl,".len()..].split(',').map(str::to_owned));
830            }
831            _ if arg.starts_with("-fuse-ld=") => {
832                link.use_ld = Some(arg["-fuse-ld=".len()..].to_owned());
833            }
834            _ if arg.starts_with("-l") && arg.len() > 2 => {
835                inputs.push(Input::library(&arg[2..]));
836            }
837            "-l" => {
838                let next = args.get(i).ok_or_else(|| err("-l requires an argument"))?;
839                i += 1;
840                inputs.push(Input::library(next));
841            }
842            _ if arg.starts_with("-L") => {
843                link.search.push(PathBuf::from(joined_or_next(arg, 2, args, &mut i)?));
844            }
845            _ if arg.starts_with("-B") => {
846                link.prefixes.push(PathBuf::from(joined_or_next(arg, 2, args, &mut i)?));
847            }
848            _ if arg.starts_with("-j") => {
849                jobs = Jobs::parse(&arg[2..]).map_err(err)?;
850            }
851            _ if arg.starts_with("--sysroot=") => {
852                sysroot = Some(PathBuf::from(&arg["--sysroot=".len()..]));
853            }
854            _ if arg.starts_with("--target=") => {
855                let t = &arg["--target=".len()..];
856                opts.target = t.parse().map_err(|e| err(format!("{e}")))?;
857                // The same string again, as the model that has room for a libc version. A spelling
858                // the three field parser took and this one does not is not an error, because the
859                // one that decides what is compiled has already accepted it and the only thing
860                // lost is a version nobody asked for.
861                pinned = t.parse().ok();
862            }
863            _ if arg.starts_with("--emit=") => {
864                let k = &arg["--emit=".len()..];
865                opts.emit = k
866                    .parse()
867                    .map_err(|()| err(format!("unknown --emit kind `{k}`, see --help")))?;
868            }
869            // A bare `-O` is `-O1`, which is what GCC has and what a hand written makefile tends
870            // to write. `-Og` is GCC's level for a build somebody is going to step through, and
871            // it is `-O1` with the transformations that move code around left out; this compiler
872            // has no such level yet, so it is the nearest one and `--print-pipeline` says what
873            // that came to rather than the flag pretending otherwise.
874            "-O" | "-Og" => opts.opt_level = rucc_session::OptLevel::O1,
875            // The union of `-O3` and `-ffast-math`, and the second half of that changes what
876            // floating point arithmetic means. Refused rather than taken as `-O3`, because a
877            // build that asks for fast math and is quietly given ordinary arithmetic gets a
878            // slower program than it asked for and a build that is given fast math it did not
879            // ask for gets a wrong one.
880            "-Ofast" => {
881                return Err(err(
882                    "-Ofast is -O3 with fast math, and fast math is not implemented, see \
883                     spec/04-driver-and-cli.md section 4.6",
884                ));
885            }
886            _ if arg.starts_with("-O") => {
887                opts.opt_level = arg[2..]
888                    .parse()
889                    .map_err(|()| err(format!("unknown optimization level `{arg}`")))?;
890            }
891            // How far a multiply and an addition may be fused into one rounding. Before the
892            // optimizer's `-f` family below for the reason the ones under it are, and kept rather
893            // than dropped because it is the one flag in its group this compiler could act on: it
894            // rides into the IR as an attribute on each function with a body, so the day the code
895            // generator forms an `fma` it already knows which functions were given permission.
896            // Nothing forms one today, under any value of this and under any `-march=`.
897            _ if arg.starts_with("-ffp-contract=") => {
898                let how = &arg["-ffp-contract=".len()..];
899                opts.fp_contract = how.parse().map_err(|()| {
900                    err(format!("`{how}` is not a contraction, which is fast, on or off"))
901                })?;
902            }
903            // How much of an expression may be computed wider than it was written. The values are
904            // gcc's and so is the refusal of anything else, and none of the three changes anything
905            // here: an operation is computed in the type C says it is on every target this compiler
906            // has a back end for, so `__FLT_EVAL_METHOD__` is 0 and `standard` is already what
907            // happens. `fast` and `16` are permission to be wider, which is a licence this takes
908            // and does not use, the same way the two above are. The flag is worth taking because
909            // glibc's headers and a good deal of configure output write it, and because the answer
910            // it asks about is one this compiler can state rather than guess at: there is no x87
911            // target here, which is the machine the whole question was invented for.
912            _ if arg.starts_with("-fexcess-precision=") => {
913                let how = &arg["-fexcess-precision=".len()..];
914                if !matches!(how, "16" | "fast" | "standard") {
915                    return Err(err(format!(
916                        "`{how}` is not an excess precision, which is 16, fast or standard"
917                    )));
918                }
919            }
920            // Which front of a path is rewritten before it reaches the output, which is how a
921            // build gets the same bytes out of two different directories. The four spellings are
922            // one flag each into three lists, and `-ffile-prefix-map=` is the three of them at
923            // once. Only the macro list does anything today, because `__FILE__` is the only place
924            // a path reaches the output: there is no DWARF and no profile data yet, so the other
925            // two are recorded for the work that will read them. The argument splits at the last
926            // `=` rather than the first, which is gcc's rule and is what lets a directory with an
927            // `=` in its name be the old half.
928            _ if arg.starts_with("-fmacro-prefix-map=") => {
929                let (old, new) = rewrite(arg, "-fmacro-prefix-map=")?;
930                opts.prefix_map.macros.push(old, new);
931            }
932            _ if arg.starts_with("-fdebug-prefix-map=") => {
933                let (old, new) = rewrite(arg, "-fdebug-prefix-map=")?;
934                opts.prefix_map.debug.push(old, new);
935            }
936            _ if arg.starts_with("-fprofile-prefix-map=") => {
937                let (old, new) = rewrite(arg, "-fprofile-prefix-map=")?;
938                opts.prefix_map.profile.push(old, new);
939            }
940            _ if arg.starts_with("-ffile-prefix-map=") => {
941                let (old, new) = rewrite(arg, "-ffile-prefix-map=")?;
942                opts.prefix_map.macros.push(old, new);
943                opts.prefix_map.debug.push(old, new);
944                opts.prefix_map.profile.push(old, new);
945            }
946            // A whole optimization rather than a flag, and the family is taken rather than
947            // refused because of what ignoring it does. There is none of it here yet, so a build
948            // that asks for it gets a program that is correct and slower than it could have been,
949            // which is what section 4.1 means by a hint about speed and what every compilation at
950            // `-O0` already is. The objects settle the rest of the argument: gcc's `-flto` object
951            // holds the bytecode and no machine code at all, and every object here holds the code,
952            // which is exactly what `-ffat-lto-objects` asks gcc for. So a build passing `-flto`
953            // to this compiler gets objects that are more usable than the ones it asked for rather
954            // than different ones. Every value is still checked against gcc's, because somebody
955            // who wrote `-flto=thin` meant clang and had better hear about it here.
956            "-flto" => opts.lto.requested = true,
957            "-fno-lto" => opts.lto.requested = false,
958            _ if arg.starts_with("-flto=") => {
959                let how = &arg["-flto=".len()..];
960                opts.lto.jobs = how.parse().map_err(|()| {
961                    err(format!(
962                        "`{how}` is not a number of link time jobs, which is auto, jobserver or a \
963                         count above zero"
964                    ))
965                })?;
966                opts.lto.requested = true;
967            }
968            _ if arg.starts_with("-flto-partition=") => {
969                let how = &arg["-flto-partition=".len()..];
970                opts.lto.partition = how.parse().map_err(|()| {
971                    err(format!(
972                        "`{how}` is not a partitioning model, which is balanced, 1to1, one, max \
973                         or none"
974                    ))
975                })?;
976            }
977            _ if arg.starts_with("-flto-compression-level=") => {
978                let how = &arg["-flto-compression-level=".len()..];
979                let level =
980                    how.parse::<u8>().ok().filter(|level| *level <= 19).ok_or_else(|| {
981                        err(format!("`{how}` is not a compression level, 0 to 19"))
982                    })?;
983                opts.lto.compression = Some(level);
984            }
985            // Whether the object keeps its machine code as well as the bytecode. It always does
986            // here, so the first of these describes what happens and the second asks for an object
987            // with less in it, which is a smaller file and not a different program, so both are
988            // taken.
989            "-ffat-lto-objects" | "-fno-fat-lto-objects" => {}
990            // Whether the linker is handed a plugin that does the link time work. The design in
991            // `spec/09-optimizer.md` has this driver doing that work itself and never loading a
992            // plugin into anybody, so neither answer is a question it has to hold.
993            "-fuse-linker-plugin" | "-fno-use-linker-plugin" => {}
994            // Reading a profile back. Taken for the reason the family above it is: nothing here
995            // reads one, so a build that asks gets the program it would have got anyway, and gcc
996            // itself produces a byte for byte identical object from `-fprofile-use` when there are
997            // no counts beside the file. The path is recorded for the pass that will read it. The
998            // warning gcc prints when it looked and found nothing is deliberately not copied,
999            // because nothing here looks, and a warning about a file that was never opened would
1000            // fire on the builds that have a perfectly good profile as well as on the ones that
1001            // do not.
1002            "-fprofile-use" => opts.profile_data.requested = true,
1003            "-fno-profile-use" => opts.profile_data.requested = false,
1004            _ if arg.starts_with("-fprofile-use=") => {
1005                opts.profile_data.path = Some(arg["-fprofile-use=".len()..].to_string());
1006                opts.profile_data.requested = true;
1007            }
1008            _ if arg.starts_with("-fprofile-dir=") => {
1009                opts.profile_data.dir = Some(arg["-fprofile-dir=".len()..].to_string());
1010            }
1011            "-fprofile-abs-path" => opts.profile_data.absolute = true,
1012            "-fno-profile-abs-path" => opts.profile_data.absolute = false,
1013            "-fprofile-correction" => opts.profile_data.correction = true,
1014            "-fno-profile-correction" => opts.profile_data.correction = false,
1015            "-fprofile-partial-training" => opts.profile_data.partial_training = true,
1016            "-fno-profile-partial-training" => opts.profile_data.partial_training = false,
1017            // Writing the counts rather than reading them, which is refused rather than taken and
1018            // is the same line `-gsplit-dwarf` falls on the far side of. Ignoring these means a
1019            // file a build declared as an output never appears: the instrumented program writes a
1020            // `.gcda` as it exits and `-ftest-coverage` writes a `.gcno` beside the object, and a
1021            // two stage build that got neither would go on to optimize against no counts at all
1022            // and report coverage of nothing, with nothing along the way saying so. The objects
1023            // say the rest: gcc's `-fprofile-generate` object holds 375 bytes of code where a
1024            // plain one holds 71, and 296 bytes of counters that a plain one does not have, so
1025            // this is a flag that changes the output rather than a hint about speed.
1026            "-fprofile-arcs"
1027            | "--coverage"
1028            | "-fcondition-coverage"
1029            | "-fpath-coverage"
1030            | "-fprofile-generate" => {
1031                return Err(err(format!(
1032                    "{arg}: this compiler does not instrument for profiling, and a build that \
1033                     expects the counts a run of the instrumented program writes would optimize \
1034                     against nothing on its second pass, see spec/04-driver-and-cli.md"
1035                )));
1036            }
1037            _ if arg.starts_with("-fprofile-generate=") => {
1038                return Err(err(format!(
1039                    "{arg}: this compiler does not instrument for profiling, and a build that \
1040                     expects the counts a run of the instrumented program writes would optimize \
1041                     against nothing on its second pass, see spec/04-driver-and-cli.md"
1042                )));
1043            }
1044            "-ftest-coverage" => {
1045                return Err(err(format!(
1046                    "{arg}: this compiler writes no `.gcno` file beside the object, and a build \
1047                     that expects one would wait for a file that never arrives, see \
1048                     spec/04-driver-and-cli.md"
1049                )));
1050            }
1051            // The rest of the family describes instrumentation that is refused above, so what is
1052            // left to do with them is check them and drop them. They are checked because a
1053            // misspelling in a distribution's flags is worth finding here rather than on the day
1054            // the instrumentation lands, and dropped because there is nothing for an answer about
1055            // how a counter is written to be an answer about.
1056            _ if arg.starts_with("-fprofile-update=") => {
1057                let how = &arg["-fprofile-update=".len()..];
1058                if !matches!(how, "single" | "atomic" | "prefer-atomic") {
1059                    return Err(err(format!(
1060                        "`{how}` is not a profile update method, which is single, atomic or \
1061                         prefer-atomic"
1062                    )));
1063                }
1064            }
1065            _ if arg.starts_with("-fprofile-reproducible=") => {
1066                let how = &arg["-fprofile-reproducible=".len()..];
1067                if !matches!(how, "serial" | "parallel-runs" | "multithreaded") {
1068                    return Err(err(format!(
1069                        "`{how}` is not a profile reproducibility method, which is serial, \
1070                         parallel-runs or multithreaded"
1071                    )));
1072                }
1073            }
1074            "-fprofile-values" | "-fno-profile-values" | "-fprofile-info-section" => {}
1075            "-fno-test-coverage" | "-fno-profile-arcs" | "-fno-profile-generate" => {}
1076            _ if arg.starts_with("-fprofile-filter-files=")
1077                || arg.starts_with("-fprofile-exclude-files=")
1078                || arg.starts_with("-fprofile-note=") => {}
1079            // What every name gets when nothing in the source said, which the attribute in the
1080            // source overrides rather than the other way round. Before the optimizer's `-f`
1081            // family below for the reason the tier below it is.
1082            _ if arg.starts_with("-fvisibility=") => {
1083                let seen = &arg["-fvisibility=".len()..];
1084                opts.visibility = seen.parse().map_err(|()| {
1085                    err(format!(
1086                        "`{seen}` is not a visibility, which is default, hidden, internal or \
1087                         protected"
1088                    ))
1089                })?;
1090            }
1091            // Which edges of a control flow transfer are checked. Before the optimizer's `-f`
1092            // family below for the reason the two above it are, and last of the three so that the
1093            // bare spelling and the negative one are matched exactly rather than by this.
1094            _ if arg.starts_with("-fcf-protection=") => {
1095                let edges = &arg["-fcf-protection=".len()..];
1096                opts.control = edges.parse().map_err(|()| {
1097                    err(format!(
1098                        "`{edges}` is not a control flow protection, which is full, branch, \
1099                         return, none or check"
1100                    ))
1101                })?;
1102            }
1103            // How much room every function opens with for something to be written over later.
1104            // Before the optimizer's `-f` family below for the reason the ones above it are.
1105            _ if arg.starts_with("-fpatchable-function-entry=") => {
1106                let room = &arg["-fpatchable-function-entry=".len()..];
1107                opts.patchable = room.parse().map_err(|()| {
1108                    err(format!(
1109                        "`{room}` is not an amount of room to reserve, which is a number of bytes                          and then, after a comma, how many of them go in front of the function's                          own label"
1110                    ))
1111                })?;
1112            }
1113            // The memory safety monitor, from section 15.4 of
1114            // `spec/safe-memory/15-integration.md`. Before the optimizer's `-f` family below,
1115            // because a pass that took the name `safety=detect` would otherwise be handed the
1116            // flag, and the tier is not a pass.
1117            _ if arg.starts_with("-fsafety=") => {
1118                let tier = &arg["-fsafety=".len()..];
1119                opts.safety = tier.parse().map_err(|()| {
1120                    err(format!(
1121                        "`{tier}` is not a safety tier, which is off, detect, enforce or kernel"
1122                    ))
1123                })?;
1124            }
1125            // Whether padding participates, from section 9.3 of document 09. Spelled out rather
1126            // than folded into the tier because it is a departure somebody who has read that
1127            // section makes, and the two defaults it describes are a property of what is being
1128            // built rather than of how much checking is wanted.
1129            _ if arg.starts_with("-fsafety-init=") => {
1130                let mode = &arg["-fsafety-init=".len()..];
1131                opts.padding = mode.parse().map_err(|()| {
1132                    err(format!("`{mode}` is not a padding mode, which is padding or nopadding"))
1133                })?;
1134            }
1135            // Row S4, from section 9.4 of document 09. A bare flag with no value, because the
1136            // strict form of that section needs a member id the front end does not name yet and
1137            // accepting the spelling for it would be accepting a promise this build cannot keep.
1138            // Before `-fno-` is looked at below, for the reason the tier is.
1139            "-fsafety-subobject" => opts.subobject = rucc_session::Subobject::Members,
1140            "-fno-safety-subobject" => opts.subobject = rucc_session::Subobject::Off,
1141            _ if arg.starts_with("-fsafety-subobject=") => {
1142                let form = &arg["-fsafety-subobject=".len()..];
1143                return Err(err(format!(
1144                    "`{form}` is not a form of -fsafety-subobject. The flag takes no value, and                      the strict form of section 9.4 is tamnd/rucc#967"
1145                )));
1146            }
1147            // Row Y8, from section 9.6 of document 09. A bare flag with no value, for the reason
1148            // the one above has none: there is one form of this check and a spelling that suggested
1149            // otherwise would be promising something. Before `-fno-` is looked at below, the same
1150            // way.
1151            "-fsafety-restrict" => opts.promise = rucc_session::Promise::Blocks,
1152            "-fno-safety-restrict" => opts.promise = rucc_session::Promise::Off,
1153            _ if arg.starts_with("-fsafety-restrict=") => {
1154                let form = &arg["-fsafety-restrict=".len()..];
1155                return Err(err(format!(
1156                    "`{form}` is not a form of -fsafety-restrict. The flag takes no value."
1157                )));
1158            }
1159            // The optimizer's own flags, from section 9.10 of `spec/09-optimizer.md`. These come
1160            // after every `-f` the rest of the compiler answers to, so a pass can never take a
1161            // name that already means something else on the command line.
1162            _ if arg.starts_with("-fpass-fuel=") => {
1163                let (name, count) = arg["-fpass-fuel=".len()..]
1164                    .split_once('=')
1165                    .ok_or_else(|| err("-fpass-fuel= is spelled <pass>=<count>"))?;
1166                if rucc_opt::pass::find(name).is_none() {
1167                    return Err(err(format!(
1168                        "`{name}` is not a pass this compiler has, see --print-pipeline"
1169                    )));
1170                }
1171                let count: u32 = count
1172                    .parse()
1173                    .map_err(|_| err(format!("`{count}` is not a number of transformations")))?;
1174                opts.pass_fuel.push((name.to_owned(), count));
1175            }
1176            _ if arg.starts_with("-fpass-fuel-global=") => {
1177                let count = &arg["-fpass-fuel-global=".len()..];
1178                let count: u32 = count
1179                    .parse()
1180                    .map_err(|_| err(format!("`{count}` is not a number of transformations")))?;
1181                opts.pass_fuel_global = Some(count);
1182            }
1183            // Everything from `-fopt-info` to the end of the argument, which is optional
1184            // keywords joined by hyphens and an optional `=<file>`. Checked here rather than
1185            // where the remarks are printed, because by then the compilation somebody wanted
1186            // to hear about is over.
1187            _ if arg == "-fopt-info"
1188                || arg.starts_with("-fopt-info=")
1189                || arg.starts_with("-fopt-info-") =>
1190            {
1191                let rest = &arg["-fopt-info".len()..];
1192                let (kinds, file) = match rest.split_once('=') {
1193                    Some((kinds, file)) => (kinds, Some(file)),
1194                    None => (rest, None),
1195                };
1196                let kinds = kinds.strip_prefix('-').unwrap_or(kinds);
1197                rucc_opt::Wants::none().add(kinds).map_err(err)?;
1198                opts.opt_info.push(kinds.to_owned());
1199                if let Some(file) = file {
1200                    if file.is_empty() {
1201                        return Err(err("-fopt-info= was given no file to write to"));
1202                    }
1203                    opts.opt_info_file = Some(file.to_owned());
1204                }
1205            }
1206            _ if arg.starts_with("-fdump-ir=") => {
1207                // Checked here rather than where the dumps are taken, because the compilation
1208                // that would have been dumped is over by then.
1209                let spec = &arg["-fdump-ir=".len()..];
1210                rucc_opt::Dumps::default().add(spec).map_err(err)?;
1211                opts.dump_ir.push(spec.to_owned());
1212            }
1213            // Before the bare `-f<pass>` below, because a pass called `enable-something` would
1214            // otherwise take the flag away from the gate. Checked here rather than where the
1215            // pipeline reads it, for the reason that applies to all of these: a misspelled pass
1216            // name that quietly gated nothing looks exactly like a pass that is not the guilty
1217            // one, and a bisection would carry on past the thing it was looking for.
1218            _ if arg.starts_with("-fdisable-") || arg.starts_with("-fenable-") => {
1219                let on = arg.starts_with("-fenable-");
1220                let spec = &arg[if on { "-fenable-".len() } else { "-fdisable-".len() }..];
1221                rucc_opt::Gates::default().add(on, spec).map_err(err)?;
1222                opts.pass_gates.push((on, spec.to_owned()));
1223            }
1224            _ if arg.strip_prefix("-fno-").is_some_and(|n| rucc_opt::pass::find(n).is_some()) => {
1225                opts.passes.push((arg["-fno-".len()..].to_owned(), false));
1226            }
1227            _ if arg.strip_prefix("-f").is_some_and(|n| rucc_opt::pass::find(n).is_some()) => {
1228                opts.passes.push((arg["-f".len()..].to_owned(), true));
1229            }
1230            // The unstable options, spelled the way rustc spells them and carrying the same
1231            // promise, which is none: one of these may change or go away in any release. They are
1232            // measurements and debugging aids rather than things a build asks for, which is why
1233            // none of them is in the usage text and all of them are in section 4.11 of
1234            // `spec/04-driver-and-cli.md`.
1235            "-Zverify-each" => opts.verify_each = true,
1236            _ if arg.starts_with("-Zrule-coverage=") => {
1237                let file = &arg["-Zrule-coverage=".len()..];
1238                if file.is_empty() {
1239                    return Err(err("-Zrule-coverage= needs a file to write to"));
1240                }
1241                opts.rule_coverage = Some(file.to_owned());
1242            }
1243            _ if arg.starts_with("-Zregister-pressure=") => {
1244                let file = &arg["-Zregister-pressure=".len()..];
1245                if file.is_empty() {
1246                    return Err(err("-Zregister-pressure= needs a file to write to"));
1247                }
1248                opts.register_pressure = Some(file.to_owned());
1249            }
1250            _ if arg.starts_with("-Z") => {
1251                return Err(err(format!(
1252                    "`{arg}` is not an unstable option this compiler has, see \
1253                     spec/04-driver-and-cli.md section 4.11 for the ones it does"
1254                )));
1255            }
1256            // The word size, which is a statement about the target and is taken as one. A build
1257            // that says the size the target already has is saying nothing, and one that says the
1258            // other size is asking for a target this compiler does not have, which it is told
1259            // rather than being given the wrong one.
1260            "-m64" | "-m32" | "-mx32" => {
1261                let want: u32 = match arg {
1262                    "-m64" => 64,
1263                    _ => 32,
1264                };
1265                let have = rucc_target::TargetInfo::new(opts.target).pointer_width;
1266                if have != want {
1267                    return Err(err(format!(
1268                        "{arg} asks for a {want} bit target and {} is {have} bit, use \
1269                         --target= to name the one you mean",
1270                        opts.target
1271                    )));
1272                }
1273            }
1274            // Which processor in the family to generate for. This compiler emits the base
1275            // instruction set of the architecture and nothing above it, so a program built with
1276            // any of these runs on the machine that was named; it is a program that could have
1277            // been faster rather than a program that is wrong, which is what makes these safe to
1278            // take and ignore where a flag that changed the meaning of the code would not be.
1279            _ if arg.starts_with("-march=")
1280                || arg.starts_with("-mtune=")
1281                || arg.starts_with("-mcpu=") => {}
1282            // The calling convention, which is not safe to ignore. Taken when it names the one
1283            // the target already uses and refused otherwise.
1284            _ if arg.starts_with("-mabi=") => {
1285                let want = &arg["-mabi=".len()..];
1286                let have = match opts.target.arch {
1287                    rucc_target::Arch::X86_64 => "sysv",
1288                    rucc_target::Arch::Aarch64 => "lp64",
1289                    rucc_target::Arch::Riscv64 => "lp64d",
1290                };
1291                if want != have {
1292                    return Err(err(format!(
1293                        "{arg}: {} uses the {have} convention and this compiler has no other",
1294                        opts.target
1295                    )));
1296                }
1297            }
1298            // How far apart the pieces of the program may be. The small model is what we emit and
1299            // it is every hosted program's default; the kernel model is a different one and a
1300            // build that asks for it and does not get it links and then does not run.
1301            "-mcmodel=small" => {}
1302            _ if arg.starts_with("-mcmodel=") => {
1303                return Err(err(format!(
1304                    "{arg}: this compiler emits the small code model and no other, see \
1305                     spec/12-targets.md"
1306                )));
1307            }
1308            // GCC's own scripting language for how the driver builds a command line.
1309            // `spec/04-driver-and-cli.md` section 4.4 settles that we will not have it, so a
1310            // build reaching for it is told which flags do the same job.
1311            _ if arg.starts_with("-specs=") => {
1312                return Err(err(
1313                    "-specs= is not supported: the parts of it builds rely on are -B, -L, \
1314                     -nostdlib, -nostartfiles and -Wl,, see spec/04-driver-and-cli.md \
1315                     section 4.4",
1316                ));
1317            }
1318            // Arguments meant for a separate assembler or preprocessor, which this compiler does
1319            // not have: both are inside it and neither reads a command line. Refused rather than
1320            // dropped, because every one of these says something about the output and a build
1321            // that asked for `-Wa,--noexecstack` and was silently given an executable stack got
1322            // the opposite of what it asked for.
1323            _ if arg.starts_with("-Wa,") || arg.starts_with("-Wp,") => {
1324                return Err(err(format!(
1325                    "`{arg}` is an argument for a separate assembler or preprocessor, and both \
1326                     are inside this compiler rather than programs it runs"
1327                )));
1328            }
1329            "-Xassembler" | "-Xpreprocessor" => {
1330                return Err(err(format!(
1331                    "{arg} hands an argument to a separate assembler or preprocessor, and both \
1332                     are inside this compiler rather than programs it runs"
1333                )));
1334            }
1335            // Everything else in the `-W` family. `spec/04-driver-and-cli.md` section 4.1 has
1336            // this one as a rule about build systems rather than about warnings: autoconf finds
1337            // out whether a warning flag exists by passing it and looking at the exit status, so
1338            // a compiler that refuses one it has not heard of fails a configure script written
1339            // for a GCC newer than itself. The names are not checked against a list because this
1340            // compiler has no warning groups for a list to be of, which #485 is about.
1341            _ if arg.starts_with("-W") => {}
1342            // Flags that name something this compiler does not do and would not do differently
1343            // if it did. `-fno-ident` is about a comment in the output that we do not write
1344            // either way, and the others are about a way of ordering the compilation that has
1345            // been GCC's only way for twenty years. Section 4.1 asks for the list to be short
1346            // and for adding to it to be deliberate, which is why it is written out here.
1347            "-fno-ident"
1348            | "-fident"
1349            | "-funit-at-a-time"
1350            | "-fno-unit-at-a-time"
1351            | "-shared-libgcc"
1352            | "-static-libgcc" => {}
1353            _ if arg.starts_with('-') && arg.len() > 1 => {
1354                // Silently ignoring an unknown flag is how a build ends up not doing what
1355                // its author asked. spec/13-gnu-compat.md section 13.4 makes this an error
1356                // for the flags that change code generation, and the safe default until the
1357                // flag table is populated is to reject everything we do not know.
1358                return Err(err(format!("unknown option `{arg}`")));
1359            }
1360            _ => inputs.push(Input { path: arg.to_owned(), forced, library: false }),
1361        }
1362    }
1363
1364    // Last, so that it lands after every `-isystem` the command line gave. That is GCC's
1365    // order: a directory the user names outranks the compiler's own, and the compiler's own
1366    // outranks the library's. It is pushed after the loop rather than before it because
1367    // `SearchPath` appends within a group and the position is what the order is.
1368    // The same directory the headers were looked for under, because a sysroot is a statement
1369    // about a whole installation and not about half of one.
1370    link.sysroot = sysroot.clone();
1371    // Where a sysroot for a target that is not this machine would be. Read once, here, rather than
1372    // inside the link line, because a link line that read the environment could only be tested on a
1373    // machine whose environment said the right thing, and the link line is the last thing that
1374    // touches a binary. `spec/cross-compile/13-distribution.md` section 13.2 owns the answer.
1375    link.cache = Some(cache::dir());
1376    // After the loop rather than where `-pthread` was read, so that it lands after the objects
1377    // that refer to it. A static link takes the definitions it needs from a library when it
1378    // reaches it and not afterwards, so a library before the objects is a library that answers
1379    // nothing.
1380    if threads {
1381        inputs.push(Input::library("pthread"));
1382    }
1383    if let Some(query) = query {
1384        return Ok(Action::Print(answer(&query, &opts, &link)?));
1385    }
1386    // `-M` and `-MM` produce the rule and nothing else, so the run stops after phase 4 whatever
1387    // else the command line asked for. Read here rather than where the flag was, because a `-c`
1388    // written after it has to lose and the loop cannot know that until it has ended. The output
1389    // file is where the rule goes rather than where an object would have gone, and the last
1390    // phase being the preprocessor is what makes that true without a second rule for it.
1391    if opts.deps.instead_of_compiling {
1392        opts.emit = EmitKind::Preprocessed;
1393    }
1394    if !nostdinc {
1395        opts.search.push_system(runtime::DIR);
1396        // And the library's after ours, which is the other half of the same order. They go on
1397        // here rather than at the point `--target=` or `--sysroot=` was read because either
1398        // one changes the answer and the last word on both is the end of the loop.
1399        //
1400        // Which library's is the question `link::cross_sysroot` answers, and it is asked here so
1401        // that the headers and the libraries come from the same place. A target that is this
1402        // machine reads this machine's headers, and a target that is not reads the ones in the
1403        // sysroot for it rather than the ones next door.
1404        let cross = link::cross_sysroot(opts.target, &link);
1405        let kernel = link::cross_kernel(opts.target, &link);
1406        // And the version of those headers, which only the bundled tree has an answer for. A host
1407        // glibc and a tree the user named both define `__GLIBC_MINOR__` in their own `features.h`,
1408        // and a second definition with a different value is a warning on every file, so the
1409        // condition is the same one that chose the directories.
1410        if cross.is_some() {
1411            let target = pinned.unwrap_or_else(|| opts.target.tuple());
1412            opts.glibc_minor = rucc_sysroot::bundled_glibc_minor(target).map_err(|skew| {
1413                err(format!(
1414                    "{skew}; pin a release the tree has, or name a tree that has that one \
1415                     with --sysroot"
1416                ))
1417            })?;
1418        }
1419        for dir in
1420            library::header_dirs(opts.target, sysroot.as_deref(), cross.as_ref(), kernel.as_ref())
1421        {
1422            opts.search.push_system(dir);
1423        }
1424    }
1425    // Once, here, rather than as each directory is pushed. A `-I` that names a system
1426    // directory has to lose to the system entry and the system entry is added last, so the
1427    // question cannot be answered until the whole path is known.
1428    opts.search.remove_duplicates();
1429
1430    // The target has to be resolved before the configuration is printed, so this check comes
1431    // after the loop rather than at the point `--print-config` was seen.
1432    if print_config {
1433        return Ok(Action::PrintConfig(Box::new(opts)));
1434    }
1435    if print_pipeline {
1436        return Ok(Action::PrintPipeline(Box::new(opts)));
1437    }
1438    let plan = Plan::new(&opts, &inputs, output.as_deref()).map_err(|e| err(e.message))?;
1439    if print_plan {
1440        return Ok(Action::PrintPlan {
1441            opts: Box::new(opts),
1442            plan: Box::new(plan),
1443            link: Box::new(link),
1444        });
1445    }
1446    Ok(Action::Compile {
1447        opts: Box::new(opts),
1448        plan: Box::new(plan),
1449        link: Box::new(link),
1450        jobs,
1451        verbose,
1452    })
1453}
1454
1455/// What one of the `-dump` and `-print` flags prints.
1456///
1457/// GCC prints the name back unchanged when it cannot find the file a `-print` flag asked about,
1458/// which is what makes the answer safe to paste into a link line whether or not the file is
1459/// there, and this does the same.
1460fn answer(query: &Query, opts: &Options, link: &LinkOptions) -> Result<String, CliError> {
1461    let found = |name: &str| {
1462        link::find_in_search(link, opts.target, name)
1463            .map_or_else(|| name.to_owned(), |path| path.display().to_string())
1464    };
1465    Ok(match query {
1466        Query::Machine => opts.target.to_string(),
1467        Query::Version => VERSION.to_owned(),
1468        Query::Multiarch => link::multiarch(opts.target),
1469        // The three lines GCC prints, in its order and with its punctuation, because what reads
1470        // them is a script written against that shape. There is no installation directory to
1471        // report: this compiler is one binary that works wherever it is copied, and the headers
1472        // it ships are inside it, so `install` is where the binary is and nothing is under it.
1473        Query::SearchDirs => {
1474            let here = std::env::current_exe()
1475                .ok()
1476                .and_then(|p| p.parent().map(std::path::Path::to_path_buf))
1477                .unwrap_or_default();
1478            let list = |dirs: &[PathBuf]| {
1479                dirs.iter().map(|d| d.display().to_string()).collect::<Vec<_>>().join(":")
1480            };
1481            let libraries = link::search_dirs(link, opts.target);
1482            format!(
1483                "install: {}\nprograms: ={}\nlibraries: ={}",
1484                here.display(),
1485                list(&link.prefixes),
1486                list(&libraries)
1487            )
1488        }
1489        // The root the rest of the answers are under, which a build system asks for when it wants
1490        // to find a file itself rather than ask for one by name, and which is the first thing to
1491        // look at when a cross build read a header nobody expected. A native compile has no
1492        // sysroot and the answer is the empty line, which is what GCC prints when it was
1493        // configured without one. `--sysroot` wins over ours because it wins everywhere else.
1494        Query::Sysroot => {
1495            sysroot_root(opts, link).map(|root| root.display().to_string()).unwrap_or_default()
1496        }
1497        // Section 13.5 of `spec/cross-compile/13-distribution.md`: for every input that is not this
1498        // compiler's own code, what it is, where it was got, its hash, its licence and whether it
1499        // was bundled, generated or fetched. What is printed is the manifest the sysroot already
1500        // carries rather than a second format saying the same things, because the three uses 13.5
1501        // gives for this are a licence notice, a reproducibility check and a security audit, and all
1502        // three are somebody else parsing it. One format is one parser to write.
1503        Query::SysrootProvenance => {
1504            let Some(root) = sysroot_root(opts, link) else {
1505                return Ok(String::new());
1506            };
1507            let path = Sysroot::at(root, opts.target.tuple()).manifest_path();
1508            match std::fs::read_to_string(&path) {
1509                // Read and rendered rather than copied out, so that what comes back is the format
1510                // this build understands. A file this build cannot read is a file whose lines it
1511                // cannot vouch for, and printing it anyway would pass the problem to whoever parses
1512                // the output next.
1513                Ok(text) => Manifest::parse(&text)
1514                    .map_err(|why| err(format!("{}: {why}", path.display())))?
1515                    .render(),
1516                // A tree with no manifest in it is a tree somebody laid out themselves and pointed
1517                // `--sysroot` at, and nothing here knows where any of it came from. The answer is
1518                // nothing, which a reader can tell apart from a manifest with no inputs in it
1519                // because that one still has its header line.
1520                Err(why) if why.kind() == std::io::ErrorKind::NotFound => String::new(),
1521                Err(why) => return Err(err(format!("{}: {why}", path.display()))),
1522            }
1523        }
1524        Query::FileName(name) => found(name),
1525        // The name GCC gives the library of routines a compiler's output calls that the C
1526        // library does not have. Ours is built in and there is no file, so the answer is the
1527        // name itself, which is what GCC prints when it cannot find one either.
1528        Query::Libgcc => found("libgcc.a"),
1529        // A program rather than a library: the linker and the archiver are the ones a build asks
1530        // about, and this compiler finds them on the path or under `-B` rather than shipping
1531        // them, so the name back is the honest answer unless a `-B` prefix holds one.
1532        Query::ProgName(name) => link
1533            .prefixes
1534            .iter()
1535            .map(|dir| dir.join(name))
1536            .find(|path| path.is_file())
1537            .map_or_else(|| name.clone(), |path| path.display().to_string()),
1538    })
1539}
1540
1541/// The root both of the sysroot answers are about.
1542///
1543/// One function rather than a copy in each, because the second flag exists to say what is inside the
1544/// tree the first one names, and two answers that disagreed about which tree that is would be a
1545/// difference nobody would think to look for. `--sysroot` wins over ours because it wins everywhere
1546/// else.
1547fn sysroot_root(opts: &Options, link: &LinkOptions) -> Option<PathBuf> {
1548    link.sysroot
1549        .clone()
1550        .or_else(|| link::cross_sysroot(opts.target, link).map(|at| at.root().to_path_buf()))
1551}
1552
1553/// Renders the passes this level will run, in order, with what each one does.
1554///
1555/// The level is the whole of the answer unless a `-f` flag edited it, which is section 9.1 of
1556/// `spec/09-optimizer.md`: a level is a list somebody wrote down rather than something that
1557/// emerges from which flags happen to be set, and this is how that list is read.
1558#[must_use]
1559pub fn print_pipeline(opts: &Options) -> String {
1560    let mut settings = rucc_opt::Options::for_level(opts.opt_level);
1561    settings.toggles.clone_from(&opts.passes);
1562    settings.global_fuel = opts.pass_fuel_global;
1563    for (on, spec) in &opts.pass_gates {
1564        // Every spelling was checked while the arguments were parsed, so there is nothing here
1565        // this can refuse, and a listing is not the place to report it if there were.
1566        let _ = settings.gates.add(*on, spec);
1567    }
1568    rucc_opt::pipeline::print(&settings)
1569}
1570
1571/// Renders the resolved configuration.
1572///
1573/// One `key: value` per line, sorted by nothing in particular but fixed in order, because
1574/// this output is diffed across hosts in CI and a reordering would read as a change.
1575#[must_use]
1576pub fn print_config(opts: &Options) -> String {
1577    let sess = Session::new(opts.clone());
1578    let t = &sess.target;
1579    let mut out = String::new();
1580    let _ = writeln!(out, "version: {VERSION}");
1581    // The three field triple the driver was given rather than the ten field tuple it widens to,
1582    // because this output is what a build system reads to find out what it asked for. The tuple is
1583    // the compiler's model of the machine and this line is a receipt for a command line.
1584    let _ = writeln!(out, "target: {}", opts.target);
1585    let _ = writeln!(out, "arch: {}", opts.target.arch.as_str());
1586    let _ = writeln!(out, "os: {}", opts.target.os.as_str());
1587    let _ = writeln!(out, "env: {}", opts.target.env.as_str());
1588    let _ = writeln!(out, "object-format: {}", t.object_format.as_str());
1589    let _ = writeln!(out, "pointer-width: {}", t.pointer_width);
1590    let _ = writeln!(out, "long-width: {}", t.long_width);
1591    let _ = writeln!(out, "long-double-width: {}", t.long_double_width);
1592    let _ = writeln!(out, "endian: {}", if t.little_endian { "little" } else { "big" });
1593    let _ = writeln!(out, "char-signed: {}", t.char_is_signed);
1594    let _ = writeln!(out, "va-list: {}", t.va_list.map_or("none", |list| list.as_str()));
1595    // The register file as a count per class, which is enough to tell a target whose registers
1596    // are described from one whose are not without printing sixteen names nobody asked for.
1597    let regs: Vec<String> = t
1598        .regs
1599        .classes()
1600        .map(|(class, info)| format!("{} {}", info.name, t.regs.len(class)))
1601        .collect();
1602    let _ = writeln!(
1603        out,
1604        "registers: {}",
1605        if regs.is_empty() { "none".to_string() } else { regs.join(", ") }
1606    );
1607    let _ = writeln!(out, "opt-level: {}", sess.opts.opt_level);
1608    let _ = writeln!(out, "safety: {}", sess.opts.safety);
1609    let _ = writeln!(out, "emit: {}", sess.opts.emit.as_str());
1610    let _ = writeln!(out, "debug-info: {}", sess.opts.debug_info);
1611    let _ = writeln!(out, "frame-pointer: {}", sess.opts.frame_pointer);
1612    let _ = writeln!(out, "red-zone: {}", sess.opts.red_zone);
1613    let _ = writeln!(out, "stack-protector: {}", sess.opts.protector);
1614    let _ = writeln!(out, "stack-clash-protection: {}", sess.opts.stack_clash);
1615    let _ = writeln!(out, "cf-protection: {}", sess.opts.control);
1616    let _ = writeln!(out, "patchable-function-entry: {}", sess.opts.patchable);
1617    let _ = writeln!(out, "profile: {}", sess.opts.profile);
1618    let _ = writeln!(out, "profile-hook: {}", sess.opts.hook);
1619    // Last because it is the one key with more than one line under it, and the only one
1620    // whose value is a property of the machine rather than of the command line.
1621    for dir in sess.opts.search.dirs() {
1622        let system = if dir.is_system { " (system)" } else { "" };
1623        let _ = writeln!(out, "include: {}{system}", dir.path.display());
1624    }
1625    out
1626}
1627
1628/// The output name the make target is taken from, which is the `-o` argument or nothing.
1629///
1630/// A run that stops at the preprocessor has not named an object, whatever its `-o` says: under
1631/// `-E` that argument is the preprocessed text and under `-M` it is the rule itself, and neither
1632/// is a file `make` would rebuild by running this rule. GCC agrees and falls back to the source
1633/// name in both, which is why a `-MD -E -o out.i` writes `out.d` holding a rule for `a.o`. From
1634/// `-S` on the argument does name what the rule builds, and it is used as written.
1635fn deps_target_output<'a>(opts: &Options, plan: &'a Plan) -> Option<&'a str> {
1636    if opts.emit == EmitKind::Preprocessed { None } else { plan.output.as_deref() }
1637}
1638
1639/// Writes to a path the command line named rather than one the plan derived, where `-` is
1640/// standard output.
1641fn write_named(path: &str, bytes: &[u8]) -> Result<(), String> {
1642    if path == "-" {
1643        return write_out(&Output::Stdout, bytes);
1644    }
1645    write_out(&Output::File(path.to_owned()), bytes)
1646}
1647
1648/// Writes the make rule for one input, and reports whether it got there.
1649///
1650/// A rule with no file of its own goes where the compilation it replaced would have written,
1651/// which is what makes the usual makefile recipe work: `rucc -M $< -o $@` leaves the rule in
1652/// `$@`, and the same line with the `-o` left off puts it on standard output.
1653fn write_deps(
1654    opts: &Options,
1655    plan: &Plan,
1656    job: &Job,
1657    found: &[Dependency],
1658    stderr: &mut impl std::io::Write,
1659) -> bool {
1660    let targets = if opts.deps.targets.is_empty() {
1661        vec![deps::default_target(&job.input, deps_target_output(opts, plan))]
1662    } else {
1663        opts.deps.targets.clone()
1664    };
1665    let rule = deps::rule(&opts.deps, &targets, &job.input, found);
1666    // The file, on the other hand, is named after the `-o` in every mode that still has one to
1667    // spend, which is every mode except the two that spend it on the rule.
1668    let wrote = match deps::default_file(&opts.deps, &job.input, plan.output.as_deref()) {
1669        // A `-MF` on a run that had nowhere else to put the rule leaves the file the `-o`
1670        // named empty rather than absent, because a makefile that named it as a target of its
1671        // own is a makefile that will look for it.
1672        Some(path) => write_named(&path, rule.as_bytes()).and_then(|()| {
1673            if opts.deps.instead_of_compiling { write_out(&job.output, b"") } else { Ok(()) }
1674        }),
1675        None => write_out(&job.output, rule.as_bytes()),
1676    };
1677    if let Err(e) = wrote {
1678        let _ = writeln!(stderr, "rucc: error: {e}");
1679        return false;
1680    }
1681    true
1682}
1683
1684/// Runs phase 4 over every input that has one, and writes what came out.
1685///
1686/// One input that fails does not stop the others. A build that reports every file it could
1687/// not preprocess in one run is worth more than one that stops at the first, and the exit
1688/// status is still a failure either way.
1689fn preprocess_all(opts: &Options, plan: &Plan) -> i32 {
1690    let fs = OsFileSystem::new();
1691    let mut stderr = std::io::stderr().lock();
1692    let mut failed = false;
1693    for job in &plan.jobs {
1694        if !job.phases.first().is_some_and(|p| *p == Phase::Preprocess) {
1695            // An input that is already preprocessed, or an object file. GCC passes these
1696            // through untouched, and the plan has already said so in its notes.
1697            continue;
1698        }
1699        let started = std::time::Instant::now();
1700        let result = preprocess(opts, &job.input, &fs);
1701        if opts.time {
1702            say_time(&job.input, started.elapsed(), &mut stderr);
1703        }
1704        for message in &result.messages {
1705            let _ = writeln!(stderr, "{message}");
1706        }
1707        if result.failed() {
1708            failed = true;
1709            continue;
1710        }
1711        if opts.deps.emit {
1712            failed |= !write_deps(opts, plan, job, &result.deps, &mut stderr);
1713            // `-M` and `-MM` asked for the rule instead of the text, so there is nothing else
1714            // to write. The other two asked for both and fall through to the text below.
1715            if opts.deps.instead_of_compiling {
1716                continue;
1717            }
1718        }
1719        if let Err(e) = write_out(&job.output, result.text.as_bytes()) {
1720            let _ = writeln!(stderr, "rucc: error: {e}");
1721            failed = true;
1722        }
1723    }
1724    i32::from(failed)
1725}
1726
1727/// Runs the front end over every input that has a compile phase, and writes what came out.
1728///
1729/// The same rule as [`preprocess_all`]: one input that fails does not stop the others, and the
1730/// exit status is a failure either way. An input that is already assembly or an object has no
1731/// compile phase and is passed over here, which the plan has already said in its notes.
1732fn compile_all(opts: &Options, plan: &Plan) -> i32 {
1733    let fs = OsFileSystem::new();
1734    let mut stderr = std::io::stderr().lock();
1735    let mut failed = false;
1736    let (mut remarks, ok) = Remarks::new(opts.opt_info_file.as_ref(), &mut stderr);
1737    failed |= !ok;
1738    let mut fired = Fired::new();
1739    let mut pressure = Pressure::new();
1740    for job in &plan.jobs {
1741        if !job.phases.contains(&Phase::Compile) {
1742            continue;
1743        }
1744        // An input of IR is read back rather than compiled, since the C it came from is not
1745        // here any more. Everything after this is the same, so the two paths meet again at the
1746        // messages and the file the result is written to.
1747        let started = std::time::Instant::now();
1748        let result = if job.kind == InputKind::Ir {
1749            compile_ir(opts, &job.input, &fs)
1750        } else {
1751            compile(opts, &job.input, &fs)
1752        };
1753        if opts.time {
1754            say_time(&job.input, started.elapsed(), &mut stderr);
1755        }
1756        fired.merge(&result.fired);
1757        pressure.merge(&result.pressure);
1758        failed |= !write_dumps(&job.input, &result.dumps, &mut stderr);
1759        failed |= !remarks.write(&result.remarks, &mut stderr);
1760        for message in &result.messages {
1761            let _ = writeln!(stderr, "{message}");
1762        }
1763        // Before the failure below, because a compilation that stopped in the back end is exactly
1764        // the one whose preprocessed source somebody wants to look at.
1765        failed |= !write_temps(job, &result.temps, &mut stderr);
1766        if result.failed() {
1767            failed = true;
1768            continue;
1769        }
1770        // `-MD` and `-MMD` write the rule beside the object and let the compilation happen, so
1771        // this is the one path where both files come out of the same run. An input of IR has no
1772        // dependencies to report and produces an empty list, which produces a rule naming only
1773        // itself, and that is the honest answer rather than a missing file.
1774        if opts.deps.emit {
1775            failed |= !write_deps(opts, plan, job, &result.deps, &mut stderr);
1776        }
1777        if let Err(e) = write_out(&job.output, result.artifact.bytes()) {
1778            let _ = writeln!(stderr, "rucc: error: {e}");
1779            failed = true;
1780        }
1781    }
1782    failed |= !write_coverage(opts, &fired, &mut stderr);
1783    failed |= !write_pressure(opts, &pressure, &mut stderr);
1784    i32::from(failed)
1785}
1786
1787/// A directory for the object files only the link step ever sees, removed when it goes away.
1788///
1789/// `-c` writes its object where the user can see it and linking does not, which is the whole of
1790/// the difference: a `rucc a.c b.c` leaves an executable behind and nothing else, the same as
1791/// every other compiler. Removing them on drop rather than at the end of a function is so that a
1792/// link that failed leaves nothing behind either.
1793struct Scratch {
1794    /// Where the objects go.
1795    dir: PathBuf,
1796}
1797
1798impl Scratch {
1799    /// Makes one, under whatever the platform calls its temporary directory.
1800    ///
1801    /// The name carries the process id so that two compilers running at once do not share a
1802    /// directory, which they would otherwise do the moment two of them compiled a file of the
1803    /// same name.
1804    fn new() -> Result<Scratch, String> {
1805        let dir = std::env::temp_dir().join(format!("rucc-{}", std::process::id()));
1806        std::fs::create_dir_all(&dir).map_err(|e| format!("{}: {e}", dir.display()))?;
1807        Ok(Scratch { dir })
1808    }
1809}
1810
1811impl Drop for Scratch {
1812    fn drop(&mut self) {
1813        let _ = std::fs::remove_dir_all(&self.dir);
1814    }
1815}
1816
1817/// The link line the plan describes, for `-###`.
1818///
1819/// The names in it are the hints the plan carries rather than the temporaries a real compilation
1820/// would choose, because `-###` prints the line without having compiled anything and so has
1821/// nothing to point at. That also makes the printed line readable rather than naming a directory
1822/// that only exists while a compilation is running.
1823fn link_line(opts: &Options, link: &LinkOptions, job: &LinkJob) -> Result<String, link::Error> {
1824    let linker = link::find(opts.target, link)?;
1825    let args = link::line(opts.target, link, &job.inputs, &job.output)?;
1826    Ok(link::render(&linker, &args))
1827}
1828
1829/// Compiles everything, then links it.
1830///
1831/// The objects go in a directory that is removed afterwards, which is why this is not
1832/// [`compile_all`] followed by a link: the plan says an object feeding the linker is temporary
1833/// and does not say where, because where is a question that only has an answer once something is
1834/// running.
1835fn link_all(opts: &Options, plan: &Plan, link: &LinkOptions, verbose: bool) -> i32 {
1836    let Some(job) = &plan.link else {
1837        // Every path into here comes from a plan whose last phase is the link, and such a plan
1838        // has a link job. Saying so is cheaper than an unwrap that would have to be explained.
1839        let mut stderr = std::io::stderr().lock();
1840        let _ = writeln!(stderr, "rucc: error: there is nothing to link");
1841        return 1;
1842    };
1843    // Before anything is compiled, because a linker that is not on the machine is worth knowing
1844    // about in the second it takes to look rather than after the compilation.
1845    // And before that, whether this link has a line at all and whether what it reads is on the
1846    // machine. Both are answerable now, and a target whose sysroot has not been built is worth
1847    // saying so about before the compilation rather than after it.
1848    if let Err(why) = link::preflight(opts.target, link) {
1849        return complain(why);
1850    }
1851    let linker = match link::find(opts.target, link) {
1852        Ok(linker) => linker,
1853        Err(why) => return complain(why),
1854    };
1855
1856    let scratch = match Scratch::new() {
1857        Ok(scratch) => scratch,
1858        Err(why) => return complain(format!("could not make a place for the object files: {why}")),
1859    };
1860
1861    let fs = OsFileSystem::new();
1862    let mut failed = false;
1863    // One per job, in job order, which is what lets the link line below be rebuilt with the real
1864    // paths in it: every job contributes exactly one file to the line and does so in this order.
1865    let mut produced: Vec<String> = Vec::with_capacity(plan.jobs.len());
1866    let mut fired = Fired::new();
1867    let mut pressure = Pressure::new();
1868    {
1869        let mut stderr = std::io::stderr().lock();
1870        let (mut remarks, ok) = Remarks::new(opts.opt_info_file.as_ref(), &mut stderr);
1871        failed |= !ok;
1872        for (at, job) in plan.jobs.iter().enumerate() {
1873            let out = match &job.output {
1874                Output::Temporary(hint) => {
1875                    // The index because two inputs in different directories can have the same
1876                    // name, and the two objects of `rucc a/x.c b/x.c` must not be one file.
1877                    scratch.dir.join(format!("{at}-{hint}")).display().to_string()
1878                }
1879                Output::File(path) => path.clone(),
1880                // A job feeding the linker never writes to standard output, since the plan gives
1881                // it a temporary. This is here so that the match is total rather than a panic.
1882                Output::Stdout => continue,
1883            };
1884            produced.push(out.clone());
1885            if !job.phases.contains(&Phase::Compile) {
1886                continue;
1887            }
1888            let started = std::time::Instant::now();
1889            let result = if job.kind == InputKind::Ir {
1890                compile_ir(opts, &job.input, &fs)
1891            } else {
1892                compile(opts, &job.input, &fs)
1893            };
1894            if opts.time {
1895                say_time(&job.input, started.elapsed(), &mut stderr);
1896            }
1897            fired.merge(&result.fired);
1898            pressure.merge(&result.pressure);
1899            failed |= !write_dumps(&job.input, &result.dumps, &mut stderr);
1900            failed |= !remarks.write(&result.remarks, &mut stderr);
1901            for message in &result.messages {
1902                let _ = writeln!(stderr, "{message}");
1903            }
1904            failed |= !write_temps(job, &result.temps, &mut stderr);
1905            if result.failed() {
1906                failed = true;
1907                continue;
1908            }
1909            // A `-MD` on a command line that links writes the rule next to the executable and
1910            // names the executable as its target, since that is the file this source builds
1911            // here. The object it went through is in a temporary directory and is gone by the
1912            // time `make` reads any of this.
1913            if opts.deps.emit {
1914                failed |= !write_deps(opts, plan, job, &result.deps, &mut stderr);
1915            }
1916            if !matches!(result.artifact, Artifact::Object(_)) {
1917                // Worth saying rather than writing whatever it is and letting the linker read it.
1918                // An empty file is a valid empty linker script, so a link handed one gets as far
1919                // as reporting every symbol of this file undefined, which is a page of messages
1920                // about something that went wrong here.
1921                let _ = writeln!(
1922                    stderr,
1923                    "rucc: internal error: {}: no object file was produced for the link",
1924                    job.input
1925                );
1926                failed = true;
1927                continue;
1928            }
1929            if let Err(e) = std::fs::write(&out, result.artifact.bytes()) {
1930                let _ = writeln!(stderr, "rucc: error: {out}: {e}");
1931                failed = true;
1932            }
1933        }
1934        failed |= !write_coverage(opts, &fired, &mut stderr);
1935        failed |= !write_pressure(opts, &pressure, &mut stderr);
1936    }
1937    if failed {
1938        // Nothing is linked from a compilation that did not finish. A linker run over the objects
1939        // that did compile would report every function of the file that did not as undefined,
1940        // which is a page of messages about a mistake already reported once.
1941        return 1;
1942    }
1943
1944    // The items in command line order with the temporaries filled in. A library contributes no
1945    // job and passes through, and every file item takes the next job's real output, which is
1946    // what keeps a library that was written between two objects between them here.
1947    let mut outputs = produced.into_iter();
1948    let mut items = Vec::with_capacity(job.inputs.len());
1949    for item in &job.inputs {
1950        match item {
1951            link::Item::Library(name) => items.push(link::Item::Library(name.clone())),
1952            link::Item::File(_) => match outputs.next() {
1953                Some(path) => items.push(link::Item::File(path)),
1954                None => return complain("the plan asks the linker for a file nothing produced"),
1955            },
1956        }
1957    }
1958
1959    let args = match link::line(opts.target, link, &items, &job.output) {
1960        Ok(args) => args,
1961        Err(why) => return complain(why),
1962    };
1963    if verbose {
1964        let mut stderr = std::io::stderr().lock();
1965        let _ = writeln!(stderr, "{}", link::render(&linker, &args));
1966    }
1967    let started = std::time::Instant::now();
1968    let ran = link::run(&linker, &args);
1969    if opts.time {
1970        // The one step of a compilation that really is another program, so this line is the same
1971        // measurement gcc's is and names the linker the way gcc names `collect2`.
1972        let mut stderr = std::io::stderr().lock();
1973        say_time(&linker.name, started.elapsed(), &mut stderr);
1974    }
1975    match ran {
1976        Ok(()) => 0,
1977        // The linker has already said what was wrong on its own error output, and repeating that
1978        // linking failed would only push its message further up the screen.
1979        Err(link::Error::Refused { .. }) => 1,
1980        Err(why) => complain(why),
1981    }
1982}
1983
1984/// Prints one driver level message and gives back the exit status that goes with it.
1985fn complain(why: impl std::fmt::Display) -> i32 {
1986    let mut stderr = std::io::stderr().lock();
1987    let _ = writeln!(stderr, "rucc: error: {why}");
1988    1
1989}
1990
1991/// Writes what `-Zrule-coverage=FILE` asked for, and says whether it could.
1992///
1993/// Once for the whole command line rather than once per input, because the question is which
1994/// lowering rules this run of the compiler reached and a file per input would leave the reader
1995/// unioning files to find out something one process already knew.
1996///
1997/// A file that could not be written is a failure and not a warning. What asks for this is a
1998/// measurement run, and a measurement that quietly did not happen is worse than one that stopped.
1999fn write_coverage(opts: &Options, fired: &Fired, stderr: &mut impl std::io::Write) -> bool {
2000    let Some(path) = &opts.rule_coverage else { return true };
2001    let Some(table) = coverage::table(opts.target.arch) else {
2002        let _ = writeln!(
2003            stderr,
2004            "rucc: error: there are no lowering rules for {} yet, so there is no coverage of them \
2005             to report",
2006            opts.target
2007        );
2008        return false;
2009    };
2010    match std::fs::write(path, fired.listing(table)) {
2011        Ok(()) => true,
2012        Err(e) => {
2013            let _ = writeln!(stderr, "rucc: error: {path}: {e}");
2014            false
2015        }
2016    }
2017}
2018
2019/// Writes what `-Zregister-pressure=FILE` asked for, and says whether it could.
2020///
2021/// Once for the whole command line, for the reason [`write_coverage`] gives, and a file that could
2022/// not be written is a failure for the reason it gives too. There is no equivalent of the missing
2023/// rule table here, since every target this compiles for has an allocator, and a run that reached
2024/// no back end at all writes an empty listing rather than nothing: a measurement of a build that
2025/// produced no code is still an answer and it is the honest one.
2026fn write_pressure(opts: &Options, pressure: &Pressure, stderr: &mut impl std::io::Write) -> bool {
2027    let Some(path) = &opts.register_pressure else { return true };
2028    match std::fs::write(path, pressure.listing()) {
2029        Ok(()) => true,
2030        Err(e) => {
2031            let _ = writeln!(stderr, "rucc: error: {path}: {e}");
2032            false
2033        }
2034    }
2035}
2036
2037/// Where the `-fopt-info` remarks go, and how much of the run has already gone there.
2038///
2039/// Standard error by default, and one file for the whole run when `-fopt-info=<file>` named one.
2040/// A file rather than the diagnostic stream is what a harness wants: the corpus in
2041/// `tamnd/rucc-corpus` matches a rejection against what the compiler said on standard error, and
2042/// a few thousand remarks mixed into that would bury it.
2043struct Remarks {
2044    /// The file, if there is one.
2045    file: Option<String>,
2046    /// Whether anything has been written to it yet, which decides between truncating and
2047    /// appending. One file holds the whole run rather than the last input in it.
2048    started: bool,
2049}
2050
2051impl Remarks {
2052    /// Prepares the destination, emptying the file if there is one.
2053    ///
2054    /// Emptied here rather than at the first remark, because a run where no pass had anything to
2055    /// say should leave an empty file and not yesterday's. An absent file and an empty one are
2056    /// different facts and something reading this will act on the difference.
2057    fn new(file: Option<&String>, stderr: &mut impl std::io::Write) -> (Self, bool) {
2058        let mut ok = true;
2059        if let Some(path) = file {
2060            if let Err(e) = std::fs::write(path, "") {
2061                let _ = writeln!(stderr, "rucc: error: {path}: {e}");
2062                ok = false;
2063            }
2064        }
2065        (Self { file: file.cloned(), started: false }, ok)
2066    }
2067
2068    /// Writes one input's remarks, and says whether that worked.
2069    ///
2070    /// A file that cannot be written is a failure and not a warning, for the reason
2071    /// [`write_dumps`] gives: remarks that quietly did not arrive look exactly like a compilation
2072    /// where nothing happened.
2073    fn write(&mut self, text: &str, stderr: &mut impl std::io::Write) -> bool {
2074        if text.is_empty() {
2075            return true;
2076        }
2077        let Some(path) = &self.file else {
2078            let _ = write!(stderr, "{text}");
2079            return true;
2080        };
2081        let opened = std::fs::OpenOptions::new()
2082            .write(true)
2083            .append(self.started)
2084            .truncate(!self.started)
2085            .create(true)
2086            .open(path);
2087        self.started = true;
2088        let result =
2089            opened.and_then(|mut file| std::io::Write::write_all(&mut file, text.as_bytes()));
2090        if let Err(e) = result {
2091            let _ = writeln!(stderr, "rucc: error: {path}: {e}");
2092            return false;
2093        }
2094        true
2095    }
2096}
2097
2098/// Writes what `-fdump-ir=` asked to see, one file per dump.
2099///
2100/// The name is the input file with the dump's own name and `.ir` after it, so a directory listing
2101/// after a run is the passes in the order they ran, per input. They go in the working directory
2102/// rather than beside the output, because a dump is something a person asked for at a prompt and
2103/// the working directory is where that person is.
2104///
2105/// A file that could not be written is a failure and not a warning, for the reason
2106/// [`write_coverage`] gives: what asked for this is somebody debugging a pass, and a dump that
2107/// quietly did not happen looks exactly like a pass that did not run.
2108fn write_dumps(input: &str, dumps: &[rucc_opt::Dump], stderr: &mut impl std::io::Write) -> bool {
2109    let stem = std::path::Path::new(input)
2110        .file_name()
2111        .map_or_else(|| input.to_owned(), |name| name.to_string_lossy().into_owned());
2112    let mut ok = true;
2113    for dump in dumps {
2114        let path = format!("{stem}.{}.ir", dump.name);
2115        if let Err(e) = std::fs::write(&path, &dump.text) {
2116            let _ = writeln!(stderr, "rucc: error: {path}: {e}");
2117            ok = false;
2118        }
2119    }
2120    ok
2121}
2122
2123/// Writes the files `-save-temps` kept, which is nothing at all unless it was given.
2124///
2125/// A file that could not be written is a failure rather than a warning, for the reason
2126/// [`write_dumps`] gives: somebody asked for these by name, and one that quietly did not happen
2127/// looks like a compilation that never went through that step.
2128fn write_temps(job: &Job, temps: &Temps, stderr: &mut impl std::io::Write) -> bool {
2129    let mut ok = true;
2130    let kept = [(job.saved_text(), &temps.preprocessed), (job.saved_asm(), &temps.assembly)];
2131    for (path, text) in kept {
2132        // A step the compilation did not reach has nothing to keep, and a job that is not keeping
2133        // that step has nowhere to put it. Either way there is no file here.
2134        let (Some(path), Some(text)) = (path, text) else { continue };
2135        if let Err(e) = std::fs::write(&path, text) {
2136            let _ = writeln!(stderr, "rucc: error: {path}: {e}");
2137            ok = false;
2138        }
2139    }
2140    ok
2141}
2142
2143/// One line of `-time`, which is what a step was called and how long it took.
2144///
2145/// GCC's two numbers are the user and the system time of a subprocess it ran. This compiler runs
2146/// no subprocess for anything but the link, so what is measured here is the wall clock of the
2147/// step and the second column is always zero. The shape of the line is kept because a person
2148/// reading it next to gcc's should not have to work out which column is which.
2149fn say_time(name: &str, took: std::time::Duration, stderr: &mut impl std::io::Write) {
2150    let _ = writeln!(stderr, "# {name} {:.2} {:.2}", took.as_secs_f64(), 0.0);
2151}
2152
2153/// Writes one job's result where the plan said it goes.
2154///
2155/// # Errors
2156///
2157/// Returns the message to print, which names the file when there is one, because "permission
2158/// denied" on its own does not say which file was refused.
2159fn write_out(output: &Output, bytes: &[u8]) -> Result<(), String> {
2160    match output {
2161        Output::Stdout => {
2162            let mut stdout = std::io::stdout().lock();
2163            stdout.write_all(bytes).map_err(|e| format!("writing to standard output: {e}"))
2164        }
2165        Output::File(path) | Output::Temporary(path) => {
2166            std::fs::write(path, bytes).map_err(|e| format!("{path}: {e}"))
2167        }
2168    }
2169}
2170
2171/// Runs the driver and returns the process exit code.
2172///
2173/// `args` excludes the program name. Output goes to `stdout` and errors to `stderr`, which
2174/// is the one place in the compiler that is true.
2175pub fn run(args: &[String]) -> i32 {
2176    match parse_args(args) {
2177        Ok(Action::Help) => {
2178            print!("{USAGE}");
2179            0
2180        }
2181        Ok(Action::Version) => {
2182            println!("rucc {VERSION}");
2183            0
2184        }
2185        Ok(Action::Print(line)) => {
2186            println!("{line}");
2187            0
2188        }
2189        Ok(Action::PrintConfig(opts)) => {
2190            print!("{}", print_config(&opts));
2191            0
2192        }
2193        Ok(Action::PrintPipeline(opts)) => {
2194            print!("{}", print_pipeline(&opts));
2195            0
2196        }
2197        Ok(Action::PrintPlan { opts, plan, link }) => {
2198            print!("{}", plan.render());
2199            // The line as it would be typed, which is the half of `-###` that section 4.3 says
2200            // arrives with the link. It is printed even when the linker is not on this machine,
2201            // because what a build wants from `-###` is what the compiler would do.
2202            if let Some(job) = &plan.link {
2203                match link_line(&opts, &link, job) {
2204                    Ok(line) => println!("{line}"),
2205                    Err(why) => {
2206                        let mut stderr = std::io::stderr().lock();
2207                        let _ = writeln!(stderr, "rucc: error: {why}");
2208                        return 1;
2209                    }
2210                }
2211            }
2212            0
2213        }
2214        Ok(Action::Compile { opts, plan, link, jobs, verbose }) => {
2215            {
2216                let mut stderr = std::io::stderr().lock();
2217                if verbose {
2218                    let _ = write!(stderr, "{}", plan.render());
2219                    let _ = writeln!(stderr, "workers: {}", jobs.count());
2220                }
2221            }
2222            if opts.emit == EmitKind::Preprocessed {
2223                return preprocess_all(&opts, &plan);
2224            }
2225            if opts.emit != EmitKind::Executable {
2226                return compile_all(&opts, &plan);
2227            }
2228            link_all(&opts, &plan, &link, verbose)
2229        }
2230        Err(e) => {
2231            let mut stderr = std::io::stderr().lock();
2232            let _ = writeln!(stderr, "rucc: error: {e}");
2233            let _ = writeln!(stderr, "rucc: note: run `rucc --help` for usage");
2234            1
2235        }
2236    }
2237}
2238
2239#[cfg(test)]
2240mod tests {
2241    use rucc_session::{
2242        Contract, GnucVersion, IncludeForm, LtoJobs, OptLevel, Partition, Patchable, Visibility,
2243    };
2244
2245    use super::*;
2246
2247    fn args(s: &[&str]) -> Vec<String> {
2248        s.iter().map(|x| (*x).to_owned()).collect()
2249    }
2250
2251    #[test]
2252    fn help_and_version_win_over_everything_else() {
2253        assert_eq!(parse_args(&args(&["-c", "--help", "x.c"])).unwrap(), Action::Help);
2254        assert_eq!(parse_args(&args(&["--version"])).unwrap(), Action::Version);
2255    }
2256
2257    fn compile(s: &[&str]) -> (Box<Options>, Box<Plan>) {
2258        match parse_args(&args(s)).expect("expected a compilation") {
2259            Action::Compile { opts, plan, .. } => (opts, plan),
2260            other => panic!("expected a compilation, got {other:?}"),
2261        }
2262    }
2263
2264    fn linking(s: &[&str]) -> (Box<LinkOptions>, Box<Plan>) {
2265        match parse_args(&args(s)).expect("expected a compilation") {
2266            Action::Compile { link, plan, .. } => (link, plan),
2267            other => panic!("expected a compilation, got {other:?}"),
2268        }
2269    }
2270
2271    #[test]
2272    fn collects_inputs_and_flags() {
2273        let (opts, plan) = compile(&["-c", "-O2", "-g", "a.c", "b.c"]);
2274        let paths: Vec<&str> = plan.jobs.iter().map(|j| j.input.as_str()).collect();
2275        assert_eq!(paths, vec!["a.c", "b.c"]);
2276        assert_eq!(opts.opt_level, OptLevel::O2);
2277        assert_eq!(opts.emit, EmitKind::Object);
2278        assert!(opts.debug_info);
2279    }
2280
2281    /// The unstable options, which are spelled apart from everything else on purpose: what is
2282    /// under `-Z` promises nothing, and a build that reaches for one should have had to say so.
2283    #[test]
2284    fn an_unstable_option_is_taken_and_one_that_does_not_exist_is_refused() {
2285        let (opts, _) = compile(&["-c", "-Zrule-coverage=/tmp/rules.cov", "a.c"]);
2286        assert_eq!(opts.rule_coverage.as_deref(), Some("/tmp/rules.cov"));
2287
2288        let (plain, _) = compile(&["-c", "a.c"]);
2289        assert_eq!(plain.rule_coverage, None, "nothing is measured unless it was asked for");
2290
2291        assert!(parse_args(&args(&["-Zrule-coverage=", "a.c"])).is_err(), "a file with no name");
2292        let unknown = parse_args(&args(&["-Zwhat", "a.c"])).expect_err("there is no such option");
2293        assert!(unknown.message.contains("4.11"), "{}", unknown.message);
2294    }
2295
2296    /// The other measurement written to a file, which reads the same way and fails the same way.
2297    #[test]
2298    fn where_the_register_pressure_goes_is_asked_for_the_same_way() {
2299        let (opts, _) = compile(&["-c", "-O2", "-Zregister-pressure=/tmp/spills.txt", "a.c"]);
2300        assert_eq!(opts.register_pressure.as_deref(), Some("/tmp/spills.txt"));
2301
2302        let (plain, _) = compile(&["-c", "a.c"]);
2303        assert_eq!(plain.register_pressure, None, "nothing is measured unless it was asked for");
2304
2305        assert!(parse_args(&args(&["-Zregister-pressure=", "a.c"])).is_err(), "no file named");
2306    }
2307
2308    #[test]
2309    fn a_bare_dash_o_means_o1_the_way_gcc_reads_it() {
2310        let (opts, _) = compile(&["-O", "a.c"]);
2311        assert_eq!(opts.opt_level, OptLevel::O1);
2312    }
2313
2314    #[test]
2315    fn dash_x_applies_to_later_inputs_only_and_none_stops_it() {
2316        let (_, plan) = compile(&["a.o", "-x", "c", "b.txt", "-x", "none", "c.o"]);
2317        assert_eq!(plan.jobs[0].kind, InputKind::LinkerInput);
2318        assert_eq!(plan.jobs[1].kind, InputKind::C);
2319        assert_eq!(plan.jobs[2].kind, InputKind::LinkerInput);
2320    }
2321
2322    #[test]
2323    fn dash_j_reaches_the_scheduler_and_defaults_to_the_machine() {
2324        let (_, _, jobs) = match parse_args(&args(&["-j4", "a.c"])).unwrap() {
2325            Action::Compile { opts, plan, jobs, .. } => (opts, plan, jobs),
2326            other => panic!("expected a compilation, got {other:?}"),
2327        };
2328        assert_eq!(jobs.count(), 4);
2329
2330        let default = match parse_args(&args(&["a.c"])).unwrap() {
2331            Action::Compile { jobs, .. } => jobs,
2332            other => panic!("expected a compilation, got {other:?}"),
2333        };
2334        assert_eq!(default, Jobs::available());
2335        assert!(parse_args(&args(&["-j0", "a.c"])).is_err());
2336    }
2337
2338    #[test]
2339    fn triple_hash_prints_the_plan_and_runs_nothing() {
2340        let a = parse_args(&args(&["-###", "-c", "a.c"])).unwrap();
2341        let Action::PrintPlan { plan, .. } = a else { panic!("expected a plan dump") };
2342        assert!(plan.render().contains("a.c: preprocess, compile, assemble -> a.o"));
2343    }
2344
2345    #[test]
2346    fn the_flag_that_keeps_the_intermediate_files_has_three_spellings_and_two_meanings() {
2347        // The bare one is `=obj` and not `=cwd`. gcc's manual says the opposite and gcc 16 does
2348        // this, and following the compiler is what makes a build that reads either of them find
2349        // the files where they are.
2350        assert_eq!(compile(&["-c", "-save-temps", "a.c"]).0.save_temps, SaveTemps::Object);
2351        assert_eq!(compile(&["-c", "-save-temps=obj", "a.c"]).0.save_temps, SaveTemps::Object);
2352        assert_eq!(compile(&["-c", "-save-temps=cwd", "a.c"]).0.save_temps, SaveTemps::Cwd);
2353        assert_eq!(compile(&["-c", "a.c"]).0.save_temps, SaveTemps::No);
2354        // The last one on the line decides, the way it does for every other flag with an
2355        // argument, and a keyword that is neither is fatal rather than ignored: a run that kept
2356        // nothing and said nothing looks exactly like one where the files were not produced.
2357        let (opts, _) = compile(&["-c", "-save-temps", "-save-temps=cwd", "a.c"]);
2358        assert_eq!(opts.save_temps, SaveTemps::Cwd);
2359        let e = parse_args(&args(&["-c", "-save-temps=nowhere", "a.c"])).unwrap_err();
2360        assert!(e.message.contains("accepted: cwd, obj"), "{}", e.message);
2361    }
2362
2363    #[test]
2364    fn the_flag_that_times_each_step_reaches_the_options_and_changes_nothing_else() {
2365        let (opts, plan) = compile(&["-c", "-time", "a.c"]);
2366        let (plain, without) = compile(&["-c", "a.c"]);
2367        assert!(opts.time);
2368        assert!(!plain.time);
2369        // Against the same line without the flag rather than against a spelling of the object's
2370        // name, since what the object is called is the host's business and this is not about that.
2371        assert_eq!(plan.jobs[0].output, without.jobs[0].output);
2372    }
2373
2374    #[test]
2375    fn dash_x_names_what_it_accepts_when_it_does_not_know_a_language() {
2376        let e = parse_args(&args(&["-x", "fortran", "a.c"])).unwrap_err();
2377        assert!(e.message.contains("assembler-with-cpp"), "{}", e.message);
2378    }
2379
2380    #[test]
2381    fn an_unknown_flag_is_an_error_rather_than_a_shrug() {
2382        let e = parse_args(&args(&["-fno-such-thing", "a.c"])).unwrap_err();
2383        assert!(e.message.contains("unknown option"), "{}", e.message);
2384    }
2385
2386    /// `-fpermissive` and the flag that turns it back off, which a build writes beside it when
2387    /// one directory needs the older rules and the rest of the tree does not.
2388    #[test]
2389    fn permissive_reads_in_both_directions_and_the_last_one_wins() {
2390        let (opts, _) = compile(&["-c", "a.c"]);
2391        assert!(!opts.permissive, "off unless it is asked for");
2392
2393        let (opts, _) = compile(&["-c", "-fpermissive", "a.c"]);
2394        assert!(opts.permissive);
2395
2396        let (opts, _) = compile(&["-c", "-fpermissive", "-fno-permissive", "a.c"]);
2397        assert!(!opts.permissive);
2398    }
2399
2400    #[test]
2401    fn asking_for_nested_functions_is_told_why_it_is_not_coming() {
2402        let e = parse_args(&args(&["-fnested-functions", "a.c"])).unwrap_err();
2403        assert!(e.message.contains("trampoline"), "{}", e.message);
2404        assert!(parse_args(&args(&["-fno-nested-functions", "a.c"])).is_ok());
2405    }
2406
2407    #[test]
2408    fn the_flag_every_configure_script_writes_is_taken() {
2409        // All four spellings, because a build writes whichever one its macros picked and a
2410        // compiler that takes three of them is a compiler that fails on the fourth.
2411        for flag in ["-fPIC", "-fpic", "-fPIE", "-fpie"] {
2412            let (opts, _) = compile(&["-c", flag, "a.c"]);
2413            assert_eq!(opts.emit, EmitKind::Object, "{flag}");
2414        }
2415    }
2416
2417    #[test]
2418    fn a_table_is_written_unless_the_build_says_nothing_will_walk_it() {
2419        let (opts, _) = compile(&["-c", "a.c"]);
2420        assert!(opts.unwinds(), "the default is off");
2421        let (opts, _) = compile(&["-c", "-fno-asynchronous-unwind-tables", "a.c"]);
2422        assert!(!opts.unwinds(), "the build was not taken at its word");
2423        let (opts, _) = compile(&[
2424            "-c",
2425            "-fno-asynchronous-unwind-tables",
2426            "-fasynchronous-unwind-tables",
2427            "a.c",
2428        ]);
2429        assert!(opts.unwinds(), "the last flag did not win");
2430        // The weaker request, which the same table answers, so a line that asks for a table and
2431        // against an asynchronous one gets one. That is gcc's arrangement and it turns up when a
2432        // build turns the asynchronous one off globally and a directory asks for a table back.
2433        let (opts, _) =
2434            compile(&["-c", "-fno-asynchronous-unwind-tables", "-funwind-tables", "a.c"]);
2435        assert!(opts.unwinds(), "the weaker request was dropped");
2436        let (opts, _) = compile(&["-c", "-fno-unwind-tables", "a.c"]);
2437        assert!(opts.unwinds(), "the weaker negative turned off the stronger request");
2438        let (opts, _) =
2439            compile(&["-c", "-fno-unwind-tables", "-fno-asynchronous-unwind-tables", "a.c"]);
2440        assert!(!opts.unwinds(), "both were turned off and one stayed on");
2441    }
2442
2443    #[test]
2444    fn the_flags_that_describe_what_this_compiler_already_does_are_taken() {
2445        // Every one of these is on a real build line somewhere and every one of them was an
2446        // unknown option. What they have in common is that the answer rucc gives is the answer
2447        // they ask for, so there is nothing to implement and nothing to refuse.
2448        for flag in [
2449            "-fno-common",
2450            "-fstrict-aliasing",
2451            "-fno-strict-aliasing",
2452            "-fdelete-null-pointer-checks",
2453            "-fno-delete-null-pointer-checks",
2454            "-frounding-math",
2455            "-fno-rounding-math",
2456            "-ftrapping-math",
2457            "-fno-trapping-math",
2458            "-fexcess-precision=standard",
2459            "-fexcess-precision=fast",
2460            "-fexcess-precision=16",
2461            "-pipe",
2462            "-fdiagnostics-color",
2463            "-fno-diagnostics-color",
2464            "-fdiagnostics-color=always",
2465            "-fdiagnostics-color=never",
2466            "-fdiagnostics-color=auto",
2467        ] {
2468            let (opts, _) = compile(&["-c", flag, "a.c"]);
2469            assert_eq!(opts.emit, EmitKind::Object, "{flag}");
2470        }
2471    }
2472
2473    #[test]
2474    fn asking_the_linker_to_merge_tentative_definitions_is_told_why_it_is_not_coming() {
2475        // The one of that family that is a request rather than a description, and it is a real
2476        // difference: two files each writing `int g;` link under it and do not without it.
2477        let e = parse_args(&args(&["-fcommon", "a.c"])).unwrap_err();
2478        assert!(e.message.contains(".bss"), "{}", e.message);
2479        assert!(e.message.contains("extern"), "the way out is worth saying: {}", e.message);
2480    }
2481
2482    #[test]
2483    fn asking_for_position_dependent_code_is_told_why_it_is_not_coming() {
2484        for flag in ["-fno-pic", "-fno-pie"] {
2485            let e = parse_args(&args(&[flag, "a.c"])).unwrap_err();
2486            assert!(e.message.contains("global offset table"), "{flag}: {}", e.message);
2487            // The one it may have meant, since the two are a letter apart and one of them is
2488            // about linking and is taken.
2489            assert!(e.message.contains("-no-pie"), "{flag}: {}", e.message);
2490        }
2491    }
2492
2493    #[test]
2494    fn an_unsupported_target_names_itself() {
2495        let e = parse_args(&args(&["--target=sparc64-linux-gnu", "a.c"])).unwrap_err();
2496        assert!(e.message.contains("sparc64"), "{}", e.message);
2497    }
2498
2499    #[test]
2500    fn no_inputs_is_an_error_but_print_config_needs_none() {
2501        assert!(parse_args(&args(&[])).is_err());
2502        assert!(matches!(parse_args(&args(&["--print-config"])), Ok(Action::PrintConfig(_))));
2503    }
2504
2505    #[test]
2506    fn print_config_reports_the_target_it_was_given_not_the_host() {
2507        let a = parse_args(&args(&["--print-config", "--target=riscv64-linux-musl"])).unwrap();
2508        let Action::PrintConfig(opts) = a else { panic!("expected a configuration dump") };
2509        let text = print_config(&opts);
2510        assert!(text.contains("target: riscv64-unknown-linux-musl"), "{text}");
2511        assert!(text.contains("char-signed: false"), "{text}");
2512        assert!(text.contains("object-format: elf"), "{text}");
2513        assert!(text.contains("va-list: void-pointer"), "{text}");
2514        // RISC-V has a register file and this compiler has not written it down yet, and the
2515        // dump says which of those two it is rather than leaving the line out.
2516        assert!(text.contains("registers: none"), "{text}");
2517    }
2518
2519    #[test]
2520    fn print_config_has_one_key_per_line_and_a_fixed_order() {
2521        let opts = Options::new("x86_64-unknown-linux-gnu".parse().unwrap());
2522        let text = print_config(&opts);
2523        let keys: Vec<&str> =
2524            text.lines().map(|l| l.split(':').next().unwrap_or_default()).collect();
2525        assert_eq!(keys[0], "version");
2526        assert_eq!(keys[1], "target");
2527        assert_eq!(keys.len(), 25);
2528        assert!(text.ends_with('\n'));
2529    }
2530
2531    #[test]
2532    fn the_safety_tier_is_read_off_the_command_line_and_a_wrong_one_is_refused() {
2533        let (opts, _) = compile(&["a.c"]);
2534        assert_eq!(opts.safety, rucc_session::Safety::Off);
2535
2536        for (flag, tier) in [
2537            ("-fsafety=detect", rucc_session::Safety::Detect),
2538            ("-fsafety=enforce", rucc_session::Safety::Enforce),
2539            ("-fsafety=kernel", rucc_session::Safety::Kernel),
2540            ("-fsafety=off", rucc_session::Safety::Off),
2541        ] {
2542            let (opts, _) = compile(&[flag, "a.c"]);
2543            assert_eq!(opts.safety, tier, "{flag}");
2544        }
2545
2546        // The last one wins, the way every other repeated flag on this command line does.
2547        let (opts, _) = compile(&["-fsafety=enforce", "-fsafety=off", "a.c"]);
2548        assert_eq!(opts.safety, rucc_session::Safety::Off);
2549
2550        // A misspelled tier is refused rather than ignored. Silently compiling without the
2551        // monitor a build asked for is the one failure mode this feature cannot have.
2552        let e = parse_args(&args(&["-fsafety=on", "a.c"])).unwrap_err();
2553        assert!(e.message.contains("is not a safety tier"), "{}", e.message);
2554        assert!(parse_args(&args(&["-fsafety", "a.c"])).is_err());
2555    }
2556
2557    #[test]
2558    fn the_padding_mode_is_read_off_the_command_line_and_a_wrong_one_is_refused() {
2559        // The default is the one section 9.3 of document 09 gives library code, which is that
2560        // padding does not participate, so a record filled a member at a time is not reported.
2561        let (opts, _) = compile(&["a.c"]);
2562        assert_eq!(opts.padding, rucc_session::Padding::Ignored);
2563
2564        let (opts, _) = compile(&["-fsafety=detect", "-fsafety-init=padding", "a.c"]);
2565        assert_eq!(opts.padding, rucc_session::Padding::Tracked);
2566
2567        let (opts, _) = compile(&["-fsafety-init=padding", "-fsafety-init=nopadding", "a.c"]);
2568        assert_eq!(opts.padding, rucc_session::Padding::Ignored);
2569
2570        // The tier is still a tier. A flag whose name starts the same way must not be eaten by
2571        // the one above it, which is the thing worth pinning about a pair of names like these.
2572        let (opts, _) = compile(&["-fsafety-init=padding", "a.c"]);
2573        assert_eq!(opts.safety, rucc_session::Safety::Off);
2574
2575        let e = parse_args(&args(&["-fsafety-init=some", "a.c"])).unwrap_err();
2576        assert!(e.message.contains("is not a padding mode"), "{}", e.message);
2577    }
2578
2579    #[test]
2580    fn whether_a_write_has_to_stay_inside_its_member_is_read_off_the_command_line() {
2581        // Off by default, because a store to allocated storage sets its effective type and C 6.5
2582        // lets a program reuse a buffer as something else. Row S4 is a build opting out of that.
2583        let (opts, _) = compile(&["a.c"]);
2584        assert_eq!(opts.subobject, rucc_session::Subobject::Off);
2585
2586        let (opts, _) = compile(&["-fsafety=detect", "-fsafety-subobject", "a.c"]);
2587        assert_eq!(opts.subobject, rucc_session::Subobject::Members);
2588
2589        let (opts, _) = compile(&["-fsafety-subobject", "-fno-safety-subobject", "a.c"]);
2590        assert_eq!(opts.subobject, rucc_session::Subobject::Off);
2591
2592        // It takes no value. The form that would take one is the strict reading of section 9.4,
2593        // which is not written yet, so say so rather than accept a spelling that does nothing.
2594        let e = parse_args(&args(&["-fsafety-subobject=strict", "a.c"])).unwrap_err();
2595        assert!(e.message.contains("tamnd/rucc#967"), "{}", e.message);
2596    }
2597
2598    #[test]
2599    fn whether_two_restrict_pointers_may_meet_is_read_off_the_command_line() {
2600        // Off by default, because the record a block keeps is the union of what each pointer
2601        // reached, so two pointers striding through one array without landing on the same byte are
2602        // reported and by the letter of the standard those are different objects. Row Y8 is a build
2603        // deciding it would rather know.
2604        let (opts, _) = compile(&["a.c"]);
2605        assert_eq!(opts.promise, rucc_session::Promise::Off);
2606
2607        let (opts, _) = compile(&["-fsafety=detect", "-fsafety-restrict", "a.c"]);
2608        assert_eq!(opts.promise, rucc_session::Promise::Blocks);
2609
2610        let (opts, _) = compile(&["-fsafety-restrict", "-fno-safety-restrict", "a.c"]);
2611        assert_eq!(opts.promise, rucc_session::Promise::Off);
2612
2613        // The tier is still a tier, which is the thing worth pinning about a pair of names where
2614        // one is the front of the other.
2615        let (opts, _) = compile(&["-fsafety-restrict", "a.c"]);
2616        assert_eq!(opts.safety, rucc_session::Safety::Off);
2617
2618        let e = parse_args(&args(&["-fsafety-restrict=blocks", "a.c"])).unwrap_err();
2619        assert!(e.message.contains("takes no value"), "{}", e.message);
2620    }
2621
2622    #[test]
2623    fn print_pipeline_answers_with_the_passes_the_level_asked_for() {
2624        let a = parse_args(&args(&["--print-pipeline", "-O2"])).unwrap();
2625        let Action::PrintPipeline(opts) = a else { panic!("expected a pipeline dump") };
2626        let text = print_pipeline(&opts);
2627        assert!(text.starts_with("level: -O2\n"), "{text}");
2628        assert!(text.contains("fold"), "{text}");
2629
2630        let a = parse_args(&args(&["--print-pipeline"])).unwrap();
2631        let Action::PrintPipeline(opts) = a else { panic!("expected a pipeline dump") };
2632        // One pass runs at `-O0` and it is the one that removes code nothing reaches, which is
2633        // not an optimization. See issue 359.
2634        assert!(print_pipeline(&opts).contains("1: simplify-cfg,"), "{}", print_pipeline(&opts));
2635
2636        let a = parse_args(&args(&["--print-pipeline", "-fno-simplify-cfg"])).unwrap();
2637        let Action::PrintPipeline(opts) = a else { panic!("expected a pipeline dump") };
2638        // And with that one turned off there is nothing left, which the dump says rather than
2639        // printing an empty list.
2640        assert!(print_pipeline(&opts).contains("no passes"), "{}", print_pipeline(&opts));
2641    }
2642
2643    #[test]
2644    fn print_pipeline_takes_the_toggles_into_account() {
2645        let a = parse_args(&args(&["--print-pipeline", "-O2", "-fno-fold"])).unwrap();
2646        let Action::PrintPipeline(opts) = a else { panic!("expected a pipeline dump") };
2647        let text = print_pipeline(&opts);
2648        // The one that was named is gone and the rest of the level is not, which is the whole
2649        // of what a toggle promises.
2650        assert!(!text.contains("fold"), "{text}");
2651        assert!(text.contains("dce"), "{text}");
2652
2653        // Every pass the compiler has, named off. Built from the registry rather than written
2654        // out, so a pass added later is turned off here too and this keeps testing the thing it
2655        // is about, which is that the toggles can empty a level.
2656        let mut off = vec!["--print-pipeline".to_owned(), "-O2".to_owned()];
2657        off.extend(rucc_opt::PASSES.iter().map(|p| format!("-fno-{}", p.name())));
2658        let spelled: Vec<&str> = off.iter().map(String::as_str).collect();
2659        let a = parse_args(&args(&spelled)).unwrap();
2660        let Action::PrintPipeline(opts) = a else { panic!("expected a pipeline dump") };
2661        assert!(print_pipeline(&opts).contains("no passes"), "{}", print_pipeline(&opts));
2662    }
2663
2664    #[test]
2665    fn print_pipeline_says_when_a_budget_will_stop_the_run_short() {
2666        let a = parse_args(&args(&["--print-pipeline", "-O2"])).unwrap();
2667        let Action::PrintPipeline(opts) = a else { panic!("expected a pipeline dump") };
2668        assert!(!print_pipeline(&opts).contains("global fuel"));
2669
2670        let a = parse_args(&args(&["--print-pipeline", "-O2", "-fpass-fuel-global=4"])).unwrap();
2671        let Action::PrintPipeline(opts) = a else { panic!("expected a pipeline dump") };
2672        let text = print_pipeline(&opts);
2673        // Because the listing is the answer to what this compilation will do, and a run that
2674        // stops after four rewrites is not doing what the level says it does.
2675        assert!(text.contains("global fuel: 4"), "{text}");
2676    }
2677
2678    /// A pass is turned on and off by its own name, and the order the flags were given in is
2679    /// kept, because the last spelling of a name is the one that decides.
2680    #[test]
2681    fn a_pass_is_named_by_dash_f_and_unnamed_by_dash_f_no() {
2682        let (opts, _) = compile(&["-c", "-O0", "-ffold", "-fno-fold", "-ffold", "a.c"]);
2683        assert_eq!(
2684            opts.passes,
2685            [("fold".to_owned(), true), ("fold".to_owned(), false), ("fold".to_owned(), true)]
2686        );
2687
2688        let e = parse_args(&args(&["-fno-such-pass", "a.c"])).unwrap_err();
2689        assert!(e.message.contains("unknown option"), "{}", e.message);
2690    }
2691
2692    #[test]
2693    fn pass_fuel_names_a_pass_and_a_count_and_refuses_anything_else() {
2694        let (opts, _) = compile(&["-c", "-O2", "-fpass-fuel=fold=3", "a.c"]);
2695        assert_eq!(opts.pass_fuel, [("fold".to_owned(), 3)]);
2696
2697        let e = parse_args(&args(&["-fpass-fuel=fold", "a.c"])).unwrap_err();
2698        assert!(e.message.contains("<pass>=<count>"), "{}", e.message);
2699        let e = parse_args(&args(&["-fpass-fuel=nosuch=3", "a.c"])).unwrap_err();
2700        assert!(e.message.contains("--print-pipeline"), "{}", e.message);
2701        let e = parse_args(&args(&["-fpass-fuel=fold=lots", "a.c"])).unwrap_err();
2702        assert!(e.message.contains("not a number"), "{}", e.message);
2703    }
2704
2705    #[test]
2706    fn global_pass_fuel_is_a_count_on_its_own_and_defaults_to_no_limit() {
2707        let (opts, _) = compile(&["-c", "-O2", "a.c"]);
2708        assert_eq!(opts.pass_fuel_global, None);
2709
2710        let (opts, _) = compile(&["-c", "-O2", "-fpass-fuel-global=12", "a.c"]);
2711        assert_eq!(opts.pass_fuel_global, Some(12));
2712        // And it is not the per pass flag with a longer name, so neither spelling swallows the
2713        // other.
2714        assert!(opts.pass_fuel.is_empty());
2715
2716        let e = parse_args(&args(&["-fpass-fuel-global=lots", "a.c"])).unwrap_err();
2717        assert!(e.message.contains("not a number"), "{}", e.message);
2718    }
2719
2720    #[test]
2721    fn a_gate_names_a_pass_and_optionally_the_functions_it_covers() {
2722        let (opts, _) = compile(&["-c", "-O2", "-fdisable-fold", "-fenable-fold=2-4,main", "a.c"]);
2723        assert_eq!(
2724            opts.pass_gates,
2725            [(false, "fold".to_owned()), (true, "fold=2-4,main".to_owned())],
2726            "the order is what decides, so it has to survive the parse"
2727        );
2728
2729        let e = parse_args(&args(&["-fdisable-nosuch", "a.c"])).unwrap_err();
2730        assert!(e.message.contains("--print-pipeline"), "{}", e.message);
2731        let e = parse_args(&args(&["-fenable-fold=9-2", "a.c"])).unwrap_err();
2732        assert!(e.message.contains("ends before it starts"), "{}", e.message);
2733        let e = parse_args(&args(&["-fdisable-fold=", "a.c"])).unwrap_err();
2734        assert!(e.message.contains("is empty"), "{}", e.message);
2735    }
2736
2737    #[test]
2738    fn the_pipeline_listing_says_which_passes_a_gate_touched() {
2739        let (opts, _) = compile(&["-c", "-O2", "-fdisable-fold=main", "a.c"]);
2740        let text = print_pipeline(&opts);
2741        assert!(text.contains("fold, "), "{text}");
2742        assert!(text.contains("[off for main]"), "{text}");
2743    }
2744
2745    /// The spelling is checked while the arguments are read, because a dump that names a pass
2746    /// this compiler does not have is a typo, and a typo found after the compilation has run is
2747    /// found too late to be any use.
2748    #[test]
2749    fn a_dump_is_checked_when_it_is_asked_for_rather_than_when_it_is_taken() {
2750        let (opts, _) = compile(&["-c", "-O2", "-fdump-ir=all", "-fdump-ir=after-fold", "a.c"]);
2751        assert_eq!(opts.dump_ir, ["all", "after-fold"]);
2752
2753        let e = parse_args(&args(&["-fdump-ir=after-nosuch", "a.c"])).unwrap_err();
2754        assert!(e.message.contains("nosuch"), "{}", e.message);
2755        assert!(parse_args(&args(&["-fdump-ir=sideways-fold", "a.c"])).is_err());
2756    }
2757
2758    /// Every spelling `-fopt-info` takes, and the one it does not.
2759    ///
2760    /// The keywords are checked here for the same reason a dump's pass name is: a person who
2761    /// misspelled one gets no output, and no output is also what a compilation where nothing
2762    /// happened looks like. Telling those two apart is the entire reason to reach for this flag.
2763    #[test]
2764    fn opt_info_takes_kinds_and_a_file_and_refuses_a_kind_it_does_not_have() {
2765        let (opts, _) = compile(&["-c", "-O2", "-fopt-info", "a.c"]);
2766        assert_eq!(opts.opt_info, [""], "a bare flag asks for the rewrites");
2767        assert_eq!(opts.opt_info_file, None, "and goes to standard error");
2768
2769        let (opts, _) = compile(&["-c", "-O2", "-fopt-info-missed-note", "a.c"]);
2770        assert_eq!(opts.opt_info, ["missed-note"]);
2771
2772        // Two flags add up rather than the second replacing the first, and the file is the last
2773        // one that named a file, which is how GCC treats both.
2774        let (opts, _) =
2775            compile(&["-c", "-O2", "-fopt-info-missed=one.txt", "-fopt-info-all=two.txt", "a.c"]);
2776        assert_eq!(opts.opt_info, ["missed", "all"]);
2777        assert_eq!(opts.opt_info_file.as_deref(), Some("two.txt"));
2778
2779        let e = parse_args(&args(&["-fopt-info-vectorized", "a.c"])).unwrap_err();
2780        assert!(e.message.contains("vectorized"), "{}", e.message);
2781        assert!(e.message.contains("`missed`"), "{}", e.message);
2782        let e = parse_args(&args(&["-fopt-info-missed=", "a.c"])).unwrap_err();
2783        assert!(e.message.contains("no file"), "{}", e.message);
2784    }
2785
2786    #[test]
2787    fn verify_each_is_unstable_and_off_unless_it_was_asked_for() {
2788        let (opts, _) = compile(&["-c", "-Zverify-each", "a.c"]);
2789        assert!(opts.verify_each);
2790        assert!(!USAGE.contains("verify-each"), "an unstable option stays out of the usage text");
2791    }
2792
2793    #[test]
2794    fn dash_o_needs_an_argument() {
2795        let e = parse_args(&args(&["a.c", "-o"])).unwrap_err();
2796        assert_eq!(e.message, "-o requires an argument");
2797    }
2798
2799    #[test]
2800    fn dash_d_and_dash_u_are_read_joined_or_separated_and_keep_their_order() {
2801        let (opts, _) = compile(&["-DFOO=1", "-D", "BAR", "-UBAZ", "-U", "QUX", "a.c"]);
2802        assert_eq!(opts.defines, ["FOO=1", "BAR"]);
2803        assert_eq!(opts.undefines, ["BAZ", "QUX"]);
2804    }
2805
2806    #[test]
2807    fn the_include_flags_land_on_the_chain_each_one_names() {
2808        // A sysroot with nothing under it, so that the library's own directories are the
2809        // same on every machine this test runs on, which is none of them.
2810        let (opts, _) = compile(&[
2811            "-Ii",
2812            "-iquote",
2813            "q",
2814            "-isystem",
2815            "sys",
2816            "-idirafter",
2817            "after",
2818            "--sysroot=/nowhere-at-all",
2819            "a.c",
2820        ]);
2821        let dirs: Vec<&str> = opts.search.dirs().iter().filter_map(|d| d.path.to_str()).collect();
2822        // The compiler's own headers sit after every `-isystem` and before `-idirafter`,
2823        // which is where GCC puts its own: a directory the user named outranks ours.
2824        assert_eq!(dirs, ["q", "i", "sys", runtime::DIR, "after"]);
2825        assert!(!opts.search.dirs()[1].is_system);
2826        assert!(opts.search.dirs()[2].is_system);
2827    }
2828
2829    #[test]
2830    fn the_librarys_headers_come_after_the_compilers_own_and_go_away_with_them() {
2831        // Which machine this runs on decides what is on the path, so the test is about the
2832        // order rather than about the names: ours is on it, the library's follow it, and
2833        // `-nostdinc` is the one flag that takes both halves of the pair off at once.
2834        let (opts, _) = compile(&["a.c"]);
2835        let dirs = opts.search.dirs();
2836        let ours = dirs.iter().position(|d| d.path.to_str() == Some(runtime::DIR));
2837        assert_eq!(ours, Some(0), "{dirs:?}");
2838        assert!(dirs[1..].iter().all(|d| d.is_system), "{dirs:?}");
2839        let (bare, _) = compile(&["-nostdinc", "a.c"]);
2840        assert!(bare.search.dirs().is_empty(), "{:?}", bare.search.dirs());
2841    }
2842
2843    #[test]
2844    fn a_sysroot_moves_the_librarys_directories_and_nothing_else() {
2845        let (opts, _) = compile(&["-isystem", "sys", "--sysroot=/nowhere-at-all", "a.c"]);
2846        let dirs: Vec<&str> = opts.search.dirs().iter().filter_map(|d| d.path.to_str()).collect();
2847        assert_eq!(dirs, ["sys", runtime::DIR]);
2848    }
2849
2850    #[test]
2851    fn a_cross_compile_reads_the_targets_own_headers_rather_than_the_ones_next_door() {
2852        // The target is not the machine this test runs on wherever it runs, so the answer is the
2853        // same on all of them: the libc's two include directories for that target, the kernel's
2854        // two, and nothing from here. A header read from here is the quiet failure of section 8.5, a
2855        // program that builds on the build machine and is wrong everywhere else.
2856        let (opts, _) = compile(&["--target=riscv64-linux-musl", "-c", "a.c"]);
2857        let dirs: Vec<&std::path::Path> =
2858            opts.search.dirs().iter().map(|d| d.path.as_path()).collect();
2859        let root = cache::dir().join("sysroots").join("riscv64-linux-musl");
2860        let kernel = cache::dir().join("kernel-headers");
2861        assert_eq!(dirs.len(), 5, "{dirs:?}");
2862        assert_eq!(dirs[0], std::path::Path::new(runtime::DIR));
2863        assert_eq!(dirs[1], root.join("include").join("riscv64"));
2864        assert_eq!(dirs[2], root.join("include").join("generic"));
2865        // The kernel's, which are beside the sysroots rather than inside one, because every target
2866        // that shares an architecture reads the same files.
2867        assert_eq!(dirs[3], kernel.join("riscv"));
2868        assert_eq!(dirs[4], kernel.join("generic"));
2869    }
2870
2871    #[test]
2872    fn a_cross_compile_to_something_that_is_not_linux_reads_no_kernel_headers() {
2873        // The other side of the same answer. Windows has its own system headers and no `linux/` at
2874        // all, so the list is the libc's two and the question never arises, which is the `None` that
2875        // `link::cross_kernel` returns rather than a directory nothing would be found in.
2876        let (opts, _) = compile(&["--target=x86_64-pc-windows-gnu", "-c", "a.c"]);
2877        let dirs: Vec<&std::path::Path> =
2878            opts.search.dirs().iter().map(|d| d.path.as_path()).collect();
2879        assert_eq!(dirs.len(), 3, "{dirs:?}");
2880        assert!(!dirs.iter().any(|dir| dir.ends_with("kernel-headers")), "{dirs:?}");
2881    }
2882
2883    #[test]
2884    fn the_glibc_version_macro_goes_with_the_bundled_tree_and_with_nothing_else() {
2885        // One tree serves every glibc release, so the release is what the target supplies, and the
2886        // condition is the same one that chose the directories. A host glibc and a tree somebody
2887        // named both define `__GLIBC_MINOR__` in their own `features.h`, and two definitions with
2888        // different values is a warning on every compilation of every file.
2889        //
2890        // The architecture is chosen against this machine's rather than written down, because the
2891        // bundled tree is only in effect for a target that is not this machine. The first version of
2892        // this test said x86_64-linux-gnu, which is a cross compile on a mac and this machine on a
2893        // Linux runner, so it passed here and failed there.
2894        let gnu = format!("--target={}-linux-gnu", cross_arch());
2895        let (bundled, _) = compile(&[&gnu, "-c", "a.c"]);
2896        assert_eq!(bundled.glibc_minor, Some(44));
2897        let pin = format!("{gnu}.2.28");
2898        let (pinned, _) = compile(&[&pin, "-c", "a.c"]);
2899        assert_eq!(pinned.glibc_minor, Some(28));
2900
2901        let (named, _) = compile(&[&gnu, "--sysroot=/nowhere-at-all", "-c", "a.c"]);
2902        assert_eq!(named.glibc_minor, None);
2903        let (none, _) = compile(&[&gnu, "-nostdinc", "-c", "a.c"]);
2904        assert_eq!(none.glibc_minor, None);
2905        let musl = format!("--target={}-linux-musl", cross_arch());
2906        let (musl, _) = compile(&[&musl, "-c", "a.c"]);
2907        assert_eq!(musl.glibc_minor, None);
2908
2909        // And this machine's own target gets nothing, whatever this machine is, because its headers
2910        // come from the machine and its own `features.h` defines the macro. On a glibc Linux box
2911        // that is the case this test had backwards; on a mac it is true for the other reason, which
2912        // is that Darwin is not a glibc target at all.
2913        if let Some(host) = Triple::host() {
2914            let native = format!("--target={}", host.tuple());
2915            let (native, _) = compile(&[&native, "-c", "a.c"]);
2916            assert_eq!(native.glibc_minor, None);
2917        }
2918    }
2919
2920    /// An architecture that is not this machine's, out of the three the driver has targets for.
2921    ///
2922    /// A test about the bundled sysroot has to name a target that is not the host, because a target
2923    /// that is the host reads the host's own headers and libraries. Asking which machine this is
2924    /// beats picking a row and hoping, and it is two lines.
2925    fn cross_arch() -> &'static str {
2926        match Triple::host().map(|host| host.arch) {
2927            Some(rucc_target::Arch::X86_64) => "aarch64",
2928            _ => "x86_64",
2929        }
2930    }
2931
2932    #[test]
2933    fn a_glibc_newer_than_the_bundled_tree_is_refused_by_name() {
2934        // Both versions in the message, because the two things a person can do about it are pin a
2935        // release the tree has and name a sysroot that has the one they asked for, and neither is a
2936        // choice they can make without knowing which release the tree is.
2937        //
2938        // Not this machine's architecture, for the reason the test above gives: the refusal is about
2939        // the bundled tree, and the bundled tree is not what a target that is this machine reads.
2940        let target = format!("--target={}-linux-gnu.2.99", cross_arch());
2941        let message = refused(&[&target, "-c", "a.c"]);
2942        assert!(message.contains("asked for glibc 2.99"), "{message}");
2943        assert!(message.contains("bundled headers are glibc 2.44"), "{message}");
2944        assert!(message.contains("--sysroot"), "{message}");
2945    }
2946
2947    #[test]
2948    fn a_sysroot_the_user_named_is_still_what_a_cross_compile_reads() {
2949        // The tree somebody assembled beats the one we would build, on the headers as on the
2950        // libraries. It is empty here, which is why the list comes out short: the directories under
2951        // it are checked for rather than assumed, and a tree that is not there offers nothing.
2952        let (opts, _) =
2953            compile(&["--target=riscv64-linux-musl", "--sysroot=/nowhere-at-all", "-c", "a.c"]);
2954        let dirs: Vec<&std::path::Path> =
2955            opts.search.dirs().iter().map(|d| d.path.as_path()).collect();
2956        assert_eq!(dirs, [std::path::Path::new(runtime::DIR)]);
2957    }
2958
2959    #[test]
2960    fn dash_i_dash_moves_the_bracket_directories_into_the_quoted_chain() {
2961        let (opts, _) =
2962            compile(&["-Iinc1", "-iquote", "inc2", "-I-", "-Iinc3", "-nostdinc", "a.c"]);
2963        let dirs: Vec<&str> = opts.search.dirs().iter().filter_map(|d| d.path.to_str()).collect();
2964        assert_eq!(dirs, ["inc1", "inc2", "inc3"]);
2965        // An angled include sees only what came after the flag.
2966        assert_eq!(opts.search.start(IncludeForm::Angled), 2);
2967        assert!(!opts.search.searches_current_dir());
2968    }
2969
2970    #[test]
2971    fn the_prefix_flags_stick_what_iprefix_said_on_the_front_of_what_follows_it() {
2972        let (opts, _) = compile(&[
2973            "-iprefix",
2974            "/tools/",
2975            "-iwithprefix",
2976            "late",
2977            "-iwithprefixbefore",
2978            "early",
2979            "-iprefix",
2980            "/other/",
2981            "-iwithprefix",
2982            "last",
2983            "-nostdinc",
2984            "a.c",
2985        ]);
2986        let dirs: Vec<&str> = opts.search.dirs().iter().filter_map(|d| d.path.to_str()).collect();
2987        // `-iwithprefixbefore` is an `-I` and the other two are `-isystem`, which is where GCC
2988        // puts them rather than where its manual says it does.
2989        assert_eq!(dirs, ["/tools/early", "/tools/late", "/other/last"]);
2990        assert!(!opts.search.dirs()[0].is_system);
2991        assert!(opts.search.dirs()[1].is_system);
2992    }
2993
2994    #[test]
2995    fn the_files_named_on_the_command_line_keep_their_order_and_which_flag_named_them() {
2996        let (opts, _) =
2997            compile(&["-include", "one.h", "-imacros", "two.h", "-include", "3.h", "a.c"]);
2998        let names: Vec<&str> = opts.preincludes.iter().map(|p| p.name.as_str()).collect();
2999        assert_eq!(names, ["one.h", "two.h", "3.h"]);
3000        assert_eq!(opts.preincludes.iter().filter(|p| p.macros_only).count(), 1);
3001    }
3002
3003    #[test]
3004    fn nostdinc_takes_the_compilers_own_headers_off_the_path() {
3005        let (opts, _) = compile(&["-Ii", "-nostdinc", "a.c"]);
3006        let dirs: Vec<&str> = opts.search.dirs().iter().filter_map(|d| d.path.to_str()).collect();
3007        assert_eq!(dirs, ["i"]);
3008    }
3009
3010    #[test]
3011    fn the_dialect_flags_set_the_language_and_the_extensions_separately() {
3012        let (opts, _) = compile(&["-std=gnu11", "a.c"]);
3013        assert_eq!(opts.std, Std::C11);
3014        assert!(opts.gnu_extensions);
3015
3016        let (opts, _) = compile(&["-std=iso9899:1999", "a.c"]);
3017        assert_eq!(opts.std, Std::C99);
3018        assert!(!opts.gnu_extensions);
3019
3020        let (opts, _) = compile(&["-ansi", "a.c"]);
3021        assert_eq!(opts.std, Std::C89);
3022        assert!(!opts.gnu_extensions);
3023
3024        let e = parse_args(&args(&["-std=c94jr", "a.c"])).unwrap_err();
3025        assert!(e.message.contains("unknown dialect"), "{}", e.message);
3026    }
3027
3028    #[test]
3029    fn the_dump_letters_are_a_family_and_everything_else_beginning_with_d_is_not() {
3030        let (opts, _) = compile(&["-dM", "a.c"]);
3031        assert!(opts.dumps.macros);
3032
3033        // Packed, the way GCC takes them, and a letter in the family we have not written yet
3034        // is accepted and does nothing rather than failing a build.
3035        let (opts, _) = compile(&["-dDM", "a.c"]);
3036        assert!(opts.dumps.macros);
3037        let (opts, _) = compile(&["-dD", "a.c"]);
3038        assert!(!opts.dumps.macros);
3039
3040        let (opts, _) = compile(&["a.c"]);
3041        assert!(!opts.dumps.any());
3042
3043        // `-dumpversion` is a different flag that happens to start the same way, and it is read
3044        // as itself rather than as a dump of nothing.
3045        assert_eq!(printed(&["-dumpversion", "a.c"]), VERSION);
3046    }
3047
3048    #[test]
3049    fn the_gcc_version_claimed_is_a_flag_and_the_short_spellings_are_the_ones_people_write() {
3050        let (opts, _) = compile(&["a.c"]);
3051        assert_eq!(
3052            opts.gnuc,
3053            GnucVersion { major: 7, minor: 0, patch: 0 },
3054            "the lowest claim a modern glibc gives its own declarations to"
3055        );
3056
3057        let (opts, _) = compile(&["-fgnuc-version=15.1.0", "a.c"]);
3058        assert_eq!(opts.gnuc, GnucVersion { major: 15, minor: 1, patch: 0 });
3059
3060        // A missing component is zero. `gcc -dumpversion` says `15` on a release with no
3061        // patchlevel and a harness that pastes that back has to be understood.
3062        let (opts, _) = compile(&["-fgnuc-version=15", "a.c"]);
3063        assert_eq!(opts.gnuc, GnucVersion { major: 15, minor: 0, patch: 0 });
3064
3065        let (opts, _) = compile(&["-fgnuc-version=13.2", "a.c"]);
3066        assert_eq!(opts.gnuc, GnucVersion { major: 13, minor: 2, patch: 0 });
3067
3068        let e = parse_args(&args(&["-fgnuc-version=15.x", "a.c"])).unwrap_err();
3069        assert!(e.message.contains("minor that is not a number"), "{}", e.message);
3070
3071        let e = parse_args(&args(&["-fgnuc-version=1.2.3.4", "a.c"])).unwrap_err();
3072        assert!(e.message.contains("more than three"), "{}", e.message);
3073    }
3074
3075    #[test]
3076    fn pedantic_has_two_spellings_and_is_not_the_same_knob_as_the_dialect() {
3077        let (opts, _) = compile(&["-std=c17", "-pedantic", "a.c"]);
3078        assert!(opts.pedantic);
3079        assert_eq!(opts.std, Std::C17);
3080
3081        // The `-W` family's name for it, which is what a build that groups its warning flags
3082        // tends to write.
3083        let (opts, _) = compile(&["-Wpedantic", "a.c"]);
3084        assert!(opts.pedantic);
3085
3086        let (opts, _) = compile(&["-std=c17", "a.c"]);
3087        assert!(!opts.pedantic, "a dialect on its own does not diagnose an extension");
3088    }
3089
3090    #[test]
3091    fn dash_p_and_dash_ffreestanding_reach_the_options() {
3092        let (opts, _) = compile(&["-E", "-P", "-ffreestanding", "a.c"]);
3093        assert!(!opts.line_markers);
3094        assert!(!opts.hosted);
3095        assert_eq!(opts.emit, EmitKind::Preprocessed);
3096    }
3097
3098    /// The two ways a build says it means its own function by a name the C library also has.
3099    ///
3100    /// `-fno-builtin` is all of them and `-fno-builtin-<name>` is one, and the second is what a
3101    /// build writes when it means its own `memcpy` and the library's everything else. The name is
3102    /// kept as it was written and not checked against anything, because a program is allowed to
3103    /// mean something by a name this compiler has never heard of.
3104    #[test]
3105    fn the_builtin_flags_are_read_in_both_directions_and_one_name_at_a_time() {
3106        let (opts, _) = compile(&["-c", "a.c"]);
3107        assert!(opts.builtins, "a library name means the library function by default");
3108        assert!(opts.no_builtin.is_empty());
3109
3110        let (opts, _) = compile(&["-c", "-fno-builtin", "a.c"]);
3111        assert!(!opts.builtins);
3112
3113        let (opts, _) = compile(&["-c", "-fno-builtin", "-fbuiltin", "a.c"]);
3114        assert!(opts.builtins, "the last mention decides");
3115
3116        let (opts, _) = compile(&["-c", "-fno-builtin-memcpy", "-fno-builtin-nonesuch", "a.c"]);
3117        assert!(opts.builtins, "one name is not the family");
3118        assert_eq!(opts.no_builtin, vec!["memcpy".to_owned(), "nonesuch".to_owned()]);
3119    }
3120
3121    /// `-fvisibility=`, which is on every cmake project that cares about which names it exports
3122    /// and which was refused as an unknown option until now.
3123    ///
3124    /// Four spellings and three answers. `internal` is hidden plus a promise about never taking
3125    /// the address across a component boundary, and nothing derives anything from that promise
3126    /// here, so it comes out as the weaker of the two rather than as a refusal that stops a build
3127    /// over a distinction this compiler does not make.
3128    #[test]
3129    fn visibility_takes_the_four_spellings_gcc_takes_and_refuses_the_rest() {
3130        let (opts, _) = compile(&["-c", "a.c"]);
3131        assert_eq!(opts.visibility, Visibility::Default, "exported unless something says not");
3132
3133        for (written, wanted) in [
3134            ("default", Visibility::Default),
3135            ("hidden", Visibility::Hidden),
3136            ("internal", Visibility::Hidden),
3137            ("protected", Visibility::Protected),
3138        ] {
3139            let (opts, _) = compile(&["-c", &format!("-fvisibility={written}"), "a.c"]);
3140            assert_eq!(opts.visibility, wanted, "{written}");
3141        }
3142
3143        // The last mention decides, which is what every other flag of this shape does and what a
3144        // build that turns something off for one directory relies on.
3145        let (opts, _) = compile(&["-c", "-fvisibility=hidden", "-fvisibility=default", "a.c"]);
3146        assert_eq!(opts.visibility, Visibility::Default, "the last mention decides");
3147
3148        // A spelling gcc does not take is refused rather than read as the default, because a
3149        // build that meant hidden and got exported is a library with the wrong interface and
3150        // nothing said about it anywhere.
3151        let failed = parse_args(&args(&["-fvisibility=none", "a.c"])).expect_err("refused");
3152        assert!(failed.to_string().contains("is not a visibility"), "{failed}");
3153    }
3154
3155    /// `-ffp-contract=`, which is the one flag in the floating point group that is kept rather than
3156    /// described, and the values are gcc 16's three.
3157    #[test]
3158    fn how_far_a_multiply_and_an_addition_may_be_fused_is_asked_for() {
3159        let (opts, _) = compile(&["-c", "a.c"]);
3160        assert_eq!(opts.fp_contract, Contract::Off, "a licence nobody granted is not assumed");
3161
3162        for (written, wanted) in
3163            [("off", Contract::Off), ("on", Contract::On), ("fast", Contract::Fast)]
3164        {
3165            let (opts, _) = compile(&["-c", &format!("-ffp-contract={written}"), "a.c"]);
3166            assert_eq!(opts.fp_contract, wanted, "{written}");
3167        }
3168
3169        let (opts, _) = compile(&["-c", "-ffp-contract=fast", "-ffp-contract=off", "a.c"]);
3170        assert_eq!(opts.fp_contract, Contract::Off, "the last mention decides");
3171
3172        // Refused rather than read as one of the three, because a build that asked for no fusing
3173        // and was given the default would be one whose numbers change and whose command line says
3174        // they should not. gcc refuses the same spellings and names the same three in its message.
3175        for bad in ["-ffp-contract=none", "-ffp-contract=", "-ffp-contract=Fast"] {
3176            let failed = parse_args(&args(&[bad, "a.c"])).expect_err("refused");
3177            assert!(failed.to_string().contains("is not a contraction"), "{bad}: {failed}");
3178        }
3179
3180        // And the other one that takes a value, which is taken and kept nowhere: every operation
3181        // here is computed in the type it was written in, so `standard` is what happens and the
3182        // other two are permission to do something this does not do.
3183        let failed = parse_args(&args(&["-fexcess-precision=long", "a.c"])).expect_err("refused");
3184        assert!(failed.to_string().contains("is not an excess precision"), "{failed}");
3185    }
3186
3187    /// The four prefix mapping flags, which are what a distribution passes to get the same bytes
3188    /// out of `/build/pkg-1.2` and out of `/home/someone/pkg-1.2`. Three lists rather than one
3189    /// because gcc has three, and `-ffile-prefix-map=` is the three of them at once.
3190    #[test]
3191    fn a_prefix_mapping_flag_goes_on_the_list_its_spelling_names() {
3192        let (opts, _) = compile(&["-c", "a.c"]);
3193        assert!(opts.prefix_map.macros.is_empty(), "nothing is rewritten unless it is asked for");
3194        assert!(opts.prefix_map.debug.is_empty(), "nor here");
3195        assert!(opts.prefix_map.profile.is_empty(), "nor here");
3196
3197        let (opts, _) = compile(&["-c", "-fmacro-prefix-map=/build=.", "a.c"]);
3198        assert_eq!(opts.prefix_map.macros.apply("/build/a.c"), "./a.c", "the one it names");
3199        assert!(opts.prefix_map.debug.is_empty(), "and not the two it does not");
3200
3201        let (opts, _) = compile(&["-c", "-fdebug-prefix-map=/build=.", "a.c"]);
3202        assert_eq!(opts.prefix_map.debug.apply("/build/a.c"), "./a.c", "the one it names");
3203        assert!(opts.prefix_map.macros.is_empty(), "and not the two it does not");
3204
3205        let (opts, _) = compile(&["-c", "-fprofile-prefix-map=/build=.", "a.c"]);
3206        assert_eq!(opts.prefix_map.profile.apply("/build/a.c"), "./a.c", "the one it names");
3207        assert!(opts.prefix_map.macros.is_empty(), "and not the two it does not");
3208
3209        let (opts, _) = compile(&["-c", "-ffile-prefix-map=/build=.", "a.c"]);
3210        for list in [&opts.prefix_map.macros, &opts.prefix_map.debug, &opts.prefix_map.profile] {
3211            assert_eq!(list.apply("/build/a.c"), "./a.c", "all three at once");
3212        }
3213
3214        // Every mention is kept and the last one that matches wins, unlike the flags above whose
3215        // last mention replaces the earlier ones. A build writes one of these per source root and
3216        // expects all of them to be in force, which is the whole point of a list.
3217        let (opts, _) =
3218            compile(&["-c", "-ffile-prefix-map=/a=one", "-ffile-prefix-map=/b=two", "a.c"]);
3219        assert_eq!(opts.prefix_map.macros.apply("/a/x.c"), "one/x.c", "the earlier one still acts");
3220        assert_eq!(opts.prefix_map.macros.apply("/b/x.c"), "two/x.c", "and so does the later one");
3221
3222        // An argument with no `=` is refused rather than ignored, because a build whose paths were
3223        // meant to be rewritten and were not is one that ships the build directory's name and says
3224        // nothing about it. gcc refuses the same thing.
3225        for bad in ["-fmacro-prefix-map=nope", "-ffile-prefix-map=", "-fdebug-prefix-map=/build"] {
3226            let failed = parse_args(&args(&[bad, "a.c"])).expect_err("refused");
3227            assert!(failed.to_string().contains("is not a rewrite for"), "{bad}: {failed}");
3228        }
3229    }
3230
3231    /// `-ffunction-sections` and `-fdata-sections`, which are what make `--gc-sections` able to
3232    /// drop anything: a linker can leave out a section nothing reaches and cannot leave out half of
3233    /// one. A kernel and an embedded image are both linked that way.
3234    ///
3235    /// Two flags rather than one because gcc has two, and a build that asks for one of them and not
3236    /// the other is a build that measured something: splitting the code is nearly free at link time
3237    /// and splitting the data can defeat the linker's ordering of what is next to what.
3238    #[test]
3239    fn a_section_per_function_and_a_section_per_variable_are_asked_for_one_at_a_time() {
3240        let (opts, _) = compile(&["-c", "a.c"]);
3241        assert!(!opts.function_sections, "one text section unless something says otherwise");
3242        assert!(!opts.data_sections);
3243
3244        let (opts, _) = compile(&["-c", "-ffunction-sections", "a.c"]);
3245        assert!(opts.function_sections);
3246        assert!(!opts.data_sections, "one flag is not the other");
3247
3248        let (opts, _) = compile(&["-c", "-fdata-sections", "a.c"]);
3249        assert!(opts.data_sections);
3250        assert!(!opts.function_sections);
3251
3252        // Both directions taken, and the off one is what happens anyway rather than a refusal,
3253        // since a build that writes it is asking for the default.
3254        let (opts, _) = compile(&[
3255            "-c",
3256            "-ffunction-sections",
3257            "-fno-function-sections",
3258            "-fdata-sections",
3259            "-fno-data-sections",
3260            "a.c",
3261        ]);
3262        assert!(!opts.function_sections, "the last mention decides");
3263        assert!(!opts.data_sections, "the last mention decides");
3264    }
3265
3266    /// `-fgnu89-inline`, which is off by default and is not implied by anything on the command
3267    /// line, since the dialect asks for GNU's reading further in rather than through this.
3268    #[test]
3269    fn gnu89_inline_is_off_until_it_is_asked_for_and_the_last_mention_decides() {
3270        let (opts, _) = compile(&["-c", "a.c"]);
3271        assert!(!opts.gnu89_inline, "C's reading of inline by default");
3272
3273        let (opts, _) = compile(&["-c", "-fgnu89-inline", "a.c"]);
3274        assert!(opts.gnu89_inline);
3275
3276        let (opts, _) = compile(&["-c", "-fgnu89-inline", "-fno-gnu89-inline", "a.c"]);
3277        assert!(!opts.gnu89_inline, "the last mention decides");
3278
3279        // The C89 dialects are under GNU's reading whether this was written or not, so the flag
3280        // stays off there and the dialect is what the checker and the macro set both ask. That is
3281        // also why `-std=c89 -fno-gnu89-inline` needs no diagnostic: it asks for the reading the
3282        // dialect already has. gcc refuses that command line, which is measured in the issue.
3283        let (opts, _) = compile(&["-c", "-std=c89", "a.c"]);
3284        assert!(!opts.gnu89_inline);
3285    }
3286
3287    /// Both spellings of both frame flags, since a build that wants one usually writes the
3288    /// other beside it for the one file that has to be compiled the ordinary way.
3289    #[test]
3290    fn the_two_frame_flags_are_read_in_both_directions() {
3291        let (opts, _) = compile(&["-c", "a.c"]);
3292        assert!(!opts.frame_pointer, "gcc omits it above -O0 and so does this");
3293        assert!(opts.red_zone, "the psABI has one and nothing said not to use it");
3294
3295        let (opts, _) = compile(&["-c", "-fno-omit-frame-pointer", "-mno-red-zone", "a.c"]);
3296        assert!(opts.frame_pointer);
3297        assert!(!opts.red_zone);
3298
3299        let (opts, _) = compile(&[
3300            "-c",
3301            "-fno-omit-frame-pointer",
3302            "-fomit-frame-pointer",
3303            "-mno-red-zone",
3304            "-mred-zone",
3305            "a.c",
3306        ]);
3307        assert!(!opts.frame_pointer, "the last one wins, as it does in gcc");
3308        assert!(opts.red_zone);
3309    }
3310
3311    /// Four flags rather than one with an argument, which is how gcc spells them, and the negative
3312    /// spelled three ways because a build that turns one off writes whichever it turned on.
3313    #[test]
3314    fn the_stack_protector_is_four_flags_and_the_last_one_wins() {
3315        let (opts, _) = compile(&["-c", "a.c"]);
3316        assert_eq!(opts.protector, Protector::None, "gcc protects nothing unless it was asked");
3317
3318        for (flag, want) in [
3319            ("-fstack-protector", Protector::Buffers),
3320            ("-fstack-protector-strong", Protector::Strong),
3321            ("-fstack-protector-all", Protector::All),
3322        ] {
3323            let (opts, _) = compile(&["-c", flag, "a.c"]);
3324            assert_eq!(opts.protector, want, "{flag}");
3325        }
3326
3327        // What a package build does: the strong one in the global flags and one directory that
3328        // cannot have a protector turning it off on the line after.
3329        for off in ["-fno-stack-protector", "-fno-stack-protector-strong"] {
3330            let (opts, _) = compile(&["-c", "-fstack-protector-strong", off, "a.c"]);
3331            assert_eq!(opts.protector, Protector::None, "{off}");
3332        }
3333        let (opts, _) = compile(&["-c", "-fno-stack-protector", "-fstack-protector-all", "a.c"]);
3334        assert_eq!(opts.protector, Protector::All, "the last one wins either way round");
3335    }
3336
3337    /// A switch rather than a level, because how a frame is taken is one question and which
3338    /// functions get a canary is another, and gcc spells it that way for the same reason.
3339    #[test]
3340    fn taking_a_frame_a_page_at_a_time_is_off_until_it_is_asked_for() {
3341        let (opts, _) = compile(&["-c", "a.c"]);
3342        assert!(!opts.stack_clash, "gcc takes a frame in one subtraction unless it was asked");
3343
3344        let (opts, _) = compile(&["-c", "-fstack-clash-protection", "a.c"]);
3345        assert!(opts.stack_clash);
3346
3347        // The same shape a package build uses for the protector: on in the global flags and off
3348        // for the one directory that cannot have it.
3349        let (opts, _) =
3350            compile(&["-c", "-fstack-clash-protection", "-fno-stack-clash-protection", "a.c"]);
3351        assert!(!opts.stack_clash);
3352        let (opts, _) =
3353            compile(&["-c", "-fno-stack-clash-protection", "-fstack-clash-protection", "a.c"]);
3354        assert!(opts.stack_clash, "the last one wins either way round");
3355
3356        // The two are independent, since one is about the frame and the other about the function.
3357        let (opts, _) =
3358            compile(&["-c", "-fstack-clash-protection", "-fstack-protector-strong", "a.c"]);
3359        assert!(opts.stack_clash);
3360        assert_eq!(opts.protector, Protector::Strong);
3361    }
3362
3363    /// One flag with an argument rather than a family of spellings, because what it asks about is
3364    /// which of the two edges of a control flow transfer is checked and the two are not separate
3365    /// questions to the hardware.
3366    #[test]
3367    fn which_control_flow_edges_are_checked_is_asked_for_by_name() {
3368        let (opts, _) = compile(&["-c", "a.c"]);
3369        assert_eq!(opts.control, Control::None, "gcc's default on the targets this compiler has");
3370
3371        for (arg, want) in [
3372            ("-fcf-protection", Control::Full),
3373            ("-fcf-protection=full", Control::Full),
3374            ("-fcf-protection=branch", Control::Branch),
3375            ("-fcf-protection=return", Control::Return),
3376            ("-fcf-protection=none", Control::None),
3377            ("-fcf-protection=check", Control::Check),
3378        ] {
3379            let (opts, _) = compile(&["-c", arg, "a.c"]);
3380            assert_eq!(opts.control, want, "{arg}");
3381        }
3382
3383        // The shape a package build uses: on in the global flags and off for the one directory
3384        // that cannot have it, whichever of the two spellings of off it reaches for.
3385        let (opts, _) = compile(&["-c", "-fcf-protection=full", "-fno-cf-protection", "a.c"]);
3386        assert_eq!(opts.control, Control::None);
3387        let (opts, _) = compile(&["-c", "-fno-cf-protection", "-fcf-protection=branch", "a.c"]);
3388        assert_eq!(opts.control, Control::Branch, "the last one wins either way round");
3389    }
3390
3391    /// The profiler is asked for by two spellings, and where its hook goes by two more.
3392    ///
3393    /// The two halves are separate on purpose. `-mfentry` on its own says where a call would go and
3394    /// asks for no call, which is what gcc does with it, and a build system that sets it globally
3395    /// and asks for the profile per directory needs that to be true rather than an error.
3396    ///
3397    /// The link is asserted alongside, because the flag changes it too and a build that compiled
3398    /// with it and linked without it is a program that calls the hook everywhere and never writes a
3399    /// profile.
3400    #[test]
3401    fn the_profiler_and_where_its_hook_goes_are_two_separate_questions() {
3402        let (opts, _) = compile(&["-c", "a.c"]);
3403        assert!(!opts.profile);
3404        assert_eq!(opts.hook, Hook::Platform, "neither was named, so the target decides");
3405
3406        for arg in ["-pg", "-p"] {
3407            let (opts, _) = compile(&["-c", arg, "a.c"]);
3408            assert!(opts.profile, "{arg}");
3409            let (link, _) = linking(&[arg, "a.c"]);
3410            assert!(link.profile, "{arg} changes the link as well");
3411        }
3412
3413        for (arg, want) in [("-mfentry", Hook::Early), ("-mno-fentry", Hook::Late)] {
3414            let (opts, _) = compile(&["-c", arg, "a.c"]);
3415            assert_eq!(opts.hook, want, "{arg}");
3416            assert!(!opts.profile, "{arg} asks for no call of its own");
3417        }
3418
3419        let (opts, _) = compile(&["-c", "-mfentry", "-mno-fentry", "-pg", "a.c"]);
3420        assert_eq!(opts.hook, Hook::Late, "the last one wins");
3421        assert!(opts.profile);
3422    }
3423
3424    /// How much room a patcher is promised, which is one number or two.
3425    ///
3426    /// A command line that did not ask is asserted alongside, because the flag has to be written to
3427    /// mean anything and a build that reserved room nobody asked for would grow every function in
3428    /// it for nothing.
3429    #[test]
3430    fn the_room_a_patcher_is_promised_is_a_number_of_bytes_and_where_they_go() {
3431        let (opts, _) = compile(&["-c", "a.c"]);
3432        assert_eq!(opts.patchable, Patchable::default());
3433        assert!(!opts.patchable.any(), "nothing is reserved unless it was asked for");
3434
3435        let (opts, _) = compile(&["-c", "-fpatchable-function-entry=16", "a.c"]);
3436        assert_eq!(opts.patchable, Patchable { total: 16, before: 0 });
3437
3438        let (opts, _) = compile(&["-c", "-fpatchable-function-entry=5,3", "a.c"]);
3439        assert_eq!(opts.patchable, Patchable { total: 5, before: 3 });
3440        assert_eq!(opts.patchable.after(), 2);
3441
3442        // The last one wins, which is what every other flag of this shape does and what a build
3443        // that adds one to a command line it did not write is relying on.
3444        let (opts, _) = compile(&[
3445            "-c",
3446            "-fpatchable-function-entry=5,3",
3447            "-fpatchable-function-entry=2",
3448            "a.c",
3449        ]);
3450        assert_eq!(opts.patchable, Patchable { total: 2, before: 0 });
3451    }
3452
3453    /// And a request nothing could satisfy is refused rather than rounded into one that can be.
3454    #[test]
3455    fn room_in_front_of_the_label_that_is_more_than_the_room_asked_for_is_refused() {
3456        for arg in ["-fpatchable-function-entry=1,2", "-fpatchable-function-entry=x"] {
3457            let e = parse_args(&args(&["-c", arg, "a.c"])).unwrap_err();
3458            assert!(e.message.contains("is not an amount of room to reserve"), "{}", e.message);
3459        }
3460    }
3461
3462    /// What wraps rather than being undefined, which is two questions and three flags.
3463    ///
3464    /// The older flag is the pair of the newer two, which is gcc's own reading of it, so a build
3465    /// that writes `-fno-strict-overflow` gets both and a build that writes one of the others gets
3466    /// only what it asked for.
3467    #[test]
3468    fn what_overflows_rather_than_being_undefined_is_asked_for_two_ways() {
3469        let (opts, _) = compile(&["-c", "a.c"]);
3470        assert_eq!(opts.wrapping, Wrapping::NONE, "nothing wraps unless it was asked for");
3471
3472        let (opts, _) = compile(&["-c", "-fwrapv", "a.c"]);
3473        assert_eq!(opts.wrapping, Wrapping { signed: true, pointer: false, trap: false });
3474
3475        let (opts, _) = compile(&["-c", "-fwrapv-pointer", "a.c"]);
3476        assert_eq!(opts.wrapping, Wrapping { signed: false, pointer: true, trap: false });
3477
3478        let (opts, _) = compile(&["-c", "-fno-strict-overflow", "a.c"]);
3479        assert_eq!(opts.wrapping, Wrapping::ALL);
3480
3481        // And the last one wins, in both directions. A build that turns one of these on globally
3482        // and off for one directory is relying on that, and so is one that writes the pair and
3483        // then takes half of it back.
3484        let (opts, _) = compile(&["-c", "-fwrapv", "-fno-wrapv", "a.c"]);
3485        assert_eq!(opts.wrapping, Wrapping::NONE);
3486
3487        let (opts, _) = compile(&["-c", "-fno-strict-overflow", "-fstrict-overflow", "a.c"]);
3488        assert_eq!(opts.wrapping, Wrapping::NONE);
3489
3490        let (opts, _) = compile(&["-c", "-fno-strict-overflow", "-fno-wrapv-pointer", "a.c"]);
3491        assert_eq!(opts.wrapping, Wrapping { signed: true, pointer: false, trap: false });
3492    }
3493
3494    /// And the other answer to the signed question cannot be held at the same time as the first.
3495    ///
3496    /// A program cannot both wrap and stop, so writing both is writing a contradiction, and gcc
3497    /// resolves it by letting the last one win rather than by reporting anything. That was measured
3498    /// against gcc 16 rather than read out of the manual, which says nothing about it: `-ftrapv
3499    /// -fwrapv` emits no checked calls and `-fwrapv -ftrapv` emits them.
3500    #[test]
3501    fn a_signed_overflow_that_stops_is_the_other_answer_and_not_a_third_one() {
3502        let (opts, _) = compile(&["-c", "-ftrapv", "a.c"]);
3503        assert_eq!(opts.wrapping, Wrapping { signed: false, pointer: false, trap: true });
3504
3505        let (opts, _) = compile(&["-c", "-fwrapv", "-ftrapv", "a.c"]);
3506        assert_eq!(opts.wrapping, Wrapping { signed: false, pointer: false, trap: true });
3507
3508        let (opts, _) = compile(&["-c", "-ftrapv", "-fwrapv", "a.c"]);
3509        assert_eq!(opts.wrapping, Wrapping { signed: true, pointer: false, trap: false });
3510
3511        let (opts, _) = compile(&["-c", "-ftrapv", "-fno-strict-overflow", "a.c"]);
3512        assert_eq!(opts.wrapping, Wrapping::ALL);
3513
3514        let (opts, _) = compile(&["-c", "-ftrapv", "-fno-trapv", "a.c"]);
3515        assert_eq!(opts.wrapping, Wrapping::NONE);
3516
3517        // And the flag that says what may be assumed says nothing about what happens, so it leaves
3518        // this alone where it takes the wrapping away. gcc does the same.
3519        let (opts, _) = compile(&["-c", "-ftrapv", "-fstrict-overflow", "a.c"]);
3520        assert_eq!(opts.wrapping, Wrapping { signed: false, pointer: false, trap: true });
3521    }
3522
3523    /// What a plain `char` is, which is four spellings of two answers and nothing by default.
3524    ///
3525    /// Nothing is the target's own answer and has to stay distinct from both of the others, since
3526    /// the same command line means a signed `char` on x86-64 and an unsigned one on Linux's arm64.
3527    /// The negative spellings are the other flag rather than a way of asking for the default, which
3528    /// was measured against gcc 16: `-fno-signed-char` defines `__CHAR_UNSIGNED__` and
3529    /// `-fno-unsigned-char` does not.
3530    #[test]
3531    fn the_signedness_of_a_plain_char_is_asked_for_in_four_ways() {
3532        let (opts, _) = compile(&["-c", "a.c"]);
3533        assert_eq!(opts.char_signed, None);
3534
3535        for flag in ["-fsigned-char", "-fno-unsigned-char"] {
3536            let (opts, _) = compile(&["-c", flag, "a.c"]);
3537            assert_eq!(opts.char_signed, Some(true), "{flag}");
3538        }
3539
3540        for flag in ["-funsigned-char", "-fno-signed-char"] {
3541            let (opts, _) = compile(&["-c", flag, "a.c"]);
3542            assert_eq!(opts.char_signed, Some(false), "{flag}");
3543        }
3544
3545        // And the last one wins, which is what a build that sets one globally and the other for a
3546        // directory relies on.
3547        let (opts, _) = compile(&["-c", "-funsigned-char", "-fsigned-char", "a.c"]);
3548        assert_eq!(opts.char_signed, Some(true));
3549
3550        // And what is asked for reaches the target, because that is what every other part of the
3551        // compiler asks. The triple is one whose own answer is the opposite, so a session that
3552        // ignored the flag would still read as signed here.
3553        let (opts, _) =
3554            compile(&["-c", "--target=aarch64-unknown-linux-gnu", "-fsigned-char", "a.c"]);
3555        assert!(Session::new(*opts).target.char_is_signed);
3556        let (opts, _) = compile(&["-c", "--target=aarch64-unknown-linux-gnu", "a.c"]);
3557        assert!(!Session::new(*opts).target.char_is_signed);
3558    }
3559
3560    /// And the size of an enumeration, which is one question with two spellings.
3561    #[test]
3562    fn the_smallest_enumeration_is_asked_for_and_taken_back() {
3563        let (opts, _) = compile(&["-c", "a.c"]);
3564        assert!(!opts.short_enums);
3565
3566        let (opts, _) = compile(&["-c", "-fshort-enums", "a.c"]);
3567        assert!(opts.short_enums);
3568
3569        let (opts, _) = compile(&["-c", "-fshort-enums", "-fno-short-enums", "a.c"]);
3570        assert!(!opts.short_enums);
3571
3572        let (opts, _) = compile(&["-c", "-fno-short-enums", "-fshort-enums", "a.c"]);
3573        assert!(opts.short_enums);
3574    }
3575
3576    /// And a value nothing means is refused rather than taken for the nearest thing it looks like.
3577    ///
3578    /// `-fcf-protection=all` is the spelling somebody writes from memory, and a compiler that read
3579    /// it as `full` would be guessing, while one that let it fall through to the optimizer's `-f`
3580    /// family would report it as an unknown pass. Neither is the news the build wants.
3581    #[test]
3582    fn a_control_flow_protection_nothing_means_is_refused() {
3583        let e = parse_args(&args(&["-c", "-fcf-protection=all", "a.c"])).unwrap_err();
3584        assert!(e.message.contains("is not a control flow protection"), "{}", e.message);
3585        assert!(e.message.contains("full, branch, return, none or check"), "{}", e.message);
3586    }
3587
3588    #[test]
3589    fn the_link_flags_are_collected_apart_from_the_compilation() {
3590        let (link, _) = linking(&[
3591            "-static",
3592            "-nostartfiles",
3593            "-rdynamic",
3594            "-s",
3595            "-fuse-ld=mold",
3596            "-L/opt/lib",
3597            "-B",
3598            "/opt/tools",
3599            "a.c",
3600        ]);
3601        assert!(link.is_static);
3602        assert!(link.no_startfiles);
3603        assert!(link.export_dynamic);
3604        assert!(link.strip);
3605        assert_eq!(link.use_ld.as_deref(), Some("mold"));
3606        assert_eq!(link.search, vec![PathBuf::from("/opt/lib")]);
3607        assert_eq!(link.prefixes, vec![PathBuf::from("/opt/tools")]);
3608    }
3609
3610    #[test]
3611    fn a_comma_in_dash_wl_separates_two_arguments() {
3612        let (link, _) = linking(&["-Wl,-rpath,/opt/lib", "-Xlinker", "--as-needed", "a.c"]);
3613        assert_eq!(link.passthrough, vec!["-rpath", "/opt/lib", "--as-needed"]);
3614    }
3615
3616    #[test]
3617    fn a_library_keeps_its_place_between_the_objects() {
3618        // Link order is semantic: `-lm` written between two files resolves for the one before
3619        // it and not for the one after, so a library cannot be collected into a list of its own.
3620        // The target is named because the suffix of an object is the target's and this asserts
3621        // on the names: the same command line on a Windows host plans two `.obj` files.
3622        let (_, plan) = linking(&["--target=x86_64-unknown-linux-gnu", "a.c", "-lm", "b.c"]);
3623        let link = plan.link.expect("expected a link step");
3624        assert_eq!(
3625            link.inputs,
3626            vec![
3627                link::Item::File("a.o".into()),
3628                link::Item::Library("m".into()),
3629                link::Item::File("b.o".into()),
3630            ]
3631        );
3632        // And it is not a job, because there is nothing to compile in a library.
3633        assert_eq!(plan.jobs.len(), 2);
3634    }
3635
3636    #[test]
3637    fn a_library_on_a_dash_c_line_is_a_note_rather_than_an_error() {
3638        let (_, plan) = linking(&["-c", "-lm", "a.c"]);
3639        assert!(plan.link.is_none());
3640        assert!(plan.notes.iter().any(|n| n.contains("-lm")), "{:?}", plan.notes);
3641    }
3642
3643    #[test]
3644    fn the_sysroot_reaches_the_linker_as_well_as_the_headers() {
3645        let (link, _) = linking(&["--sysroot=/opt/root", "a.c"]);
3646        assert_eq!(link.sysroot, Some(PathBuf::from("/opt/root")));
3647    }
3648
3649    fn printed(s: &[&str]) -> String {
3650        match parse_args(&args(s)).expect("expected an answer") {
3651            Action::Print(line) => line,
3652            other => panic!("expected an answer, got {other:?}"),
3653        }
3654    }
3655
3656    fn refused(s: &[&str]) -> String {
3657        parse_args(&args(s)).expect_err("expected a refusal").message
3658    }
3659
3660    #[test]
3661    fn a_warning_flag_this_compiler_has_not_heard_of_is_taken_rather_than_refused() {
3662        // The rule in section 4.1, and the reason for it is autoconf: a configure script finds
3663        // out whether a warning flag exists by passing it and looking at the exit status, so a
3664        // compiler that refuses one it does not know fails a script written for a newer GCC.
3665        let (opts, _) = compile(&["-Wall", "-Wextra", "-Wno-format-truncation", "-c", "a.c"]);
3666        assert!(!opts.warnings_are_errors);
3667        assert!(opts.warnings);
3668        // The two spellings that do mean something are still read.
3669        let (opts, _) = compile(&["-Werror", "-c", "a.c"]);
3670        assert!(opts.warnings_are_errors);
3671        let (opts, _) = compile(&["-w", "-c", "a.c"]);
3672        assert!(!opts.warnings);
3673        let (opts, _) = compile(&["-pedantic-errors", "-c", "a.c"]);
3674        assert!(opts.pedantic && opts.warnings_are_errors);
3675    }
3676
3677    #[test]
3678    fn an_argument_for_a_separate_tool_is_refused_rather_than_dropped() {
3679        // Every one of these says something about the output, so the wrong answer is silence.
3680        assert!(refused(&["-Wa,--noexecstack", "-c", "a.c"]).contains("separate assembler"));
3681        assert!(refused(&["-Wp,-DX", "-c", "a.c"]).contains("separate assembler"));
3682        assert!(refused(&["-specs=/x", "a.c"]).contains("-specs= is not supported"));
3683        assert!(refused(&["-mcmodel=kernel", "-c", "a.c"]).contains("small code model"));
3684        assert!(refused(&["-gdwarf-4", "-c", "a.c"]).contains("DWARF 5"));
3685        assert!(refused(&["-Ofast", "-c", "a.c"]).contains("fast math"));
3686        // The word size the target does not have, which is a target this compiler was not asked
3687        // for rather than a flag it does not know.
3688        let no32 = refused(&["--target=x86_64-unknown-linux-gnu", "-m32", "-c", "a.c"]);
3689        assert!(no32.contains("32 bit target"), "{no32}");
3690    }
3691
3692    /// `-gz` and the two spellings of the split, which are the two questions about the shape of
3693    /// the debug output rather than about how much of it there is.
3694    ///
3695    /// Both answers here are about what happens when there is debug information to shape, and
3696    /// there is none yet, so what is being asserted is that the flags are read and remembered
3697    /// rather than that anything changed in the output. That is the whole of what taking them
3698    /// claims, and it is worth a test because the day `rucc-debug` writes a section this is where
3699    /// it comes to find out what the command line said.
3700    #[test]
3701    fn the_shape_of_the_debug_output_is_recorded_even_where_there_is_none_of_it() {
3702        let (opts, _) = compile(&["-c", "a.c"]);
3703        assert_eq!(opts.compress, Compress::None, "uncompressed unless somebody asks");
3704
3705        // Bare `-gz` is `-gz=zlib`, measured against gcc 16 rather than read out of the manual,
3706        // which describes the flag without ever saying which algorithm it picks.
3707        assert_eq!(compile(&["-gz", "-c", "a.c"]).0.compress, Compress::Zlib);
3708        for (spelling, want) in [
3709            ("none", Compress::None),
3710            ("zlib", Compress::Zlib),
3711            ("zlib-gnu", Compress::ZlibGnu),
3712            ("zstd", Compress::Zstd),
3713        ] {
3714            let (opts, _) = compile(&[&format!("-gz={spelling}"), "-c", "a.c"]);
3715            assert_eq!(opts.compress, want, "{spelling}");
3716        }
3717
3718        // A value nothing here has heard of is refused rather than rounded to the nearest one,
3719        // because a build that asked for `zstd` and quietly got `zlib` would ship a file its
3720        // reader may not understand and would have no way of finding out.
3721        for bad in ["-gz=gzip", "-gz="] {
3722            let failed = refused(&[bad, "-c", "a.c"]);
3723            assert!(failed.contains("is not a way to compress"), "{bad}: {failed}");
3724        }
3725
3726        // The split is refused in the direction that would have written a file and taken in the
3727        // direction that describes what happens. A build system that names the `.dwo` as an
3728        // output has to hear about it now rather than at the point the file is missing.
3729        let (opts, _) = compile(&["-gno-split-dwarf", "-g", "-c", "a.c"]);
3730        assert!(opts.debug_info, "the negative spelling says nothing about how much");
3731        let failed = refused(&["-gsplit-dwarf", "-c", "a.c"]);
3732        assert!(failed.contains(".dwo"), "the refusal names the file it would have written");
3733    }
3734
3735    /// The `-flto` family, which is the whole of an optimization this compiler does not do.
3736    ///
3737    /// Taken rather than refused because ignoring it gives a correct program that is slower than
3738    /// it could have been, which is section 4.1's hint about speed. The values are still held to
3739    /// gcc's, so a command line written for clang is told rather than quietly taken.
3740    #[test]
3741    fn the_link_time_family_is_read_and_checked_and_nothing_is_done_about_it() {
3742        let (opts, _) = compile(&["-c", "a.c"]);
3743        assert!(!opts.lto.requested, "nothing asks unless the command line does");
3744
3745        let (opts, _) = compile(&["-flto", "-c", "a.c"]);
3746        assert!(opts.lto.requested);
3747        assert_eq!(opts.lto.jobs, LtoJobs::One, "bare -flto is one process, the way gcc reads it");
3748
3749        // The last of the two directions wins, the same as every other pair of `-f` spellings.
3750        assert!(!compile(&["-flto", "-fno-lto", "-c", "a.c"]).0.lto.requested);
3751        assert!(compile(&["-fno-lto", "-flto", "-c", "a.c"]).0.lto.requested);
3752
3753        // A count is a count, and asking for one implies asking for the optimization.
3754        for (spelling, want) in [
3755            ("auto", LtoJobs::Auto),
3756            ("jobserver", LtoJobs::Jobserver),
3757            ("1", LtoJobs::One),
3758            ("8", LtoJobs::Count(8)),
3759        ] {
3760            let (opts, _) = compile(&[&format!("-flto={spelling}"), "-c", "a.c"]);
3761            assert_eq!(opts.lto.jobs, want, "{spelling}");
3762            assert!(opts.lto.requested, "{spelling} asks for it too");
3763        }
3764
3765        // gcc refuses a zero rather than reading it as `-fno-lto`, and `thin` is clang's spelling
3766        // of a question gcc answers with `-flto-partition=`, so somebody who wrote it meant a
3767        // different compiler and gets told so here rather than getting a serial link.
3768        for bad in ["-flto=0", "-flto=thin", "-flto=full", "-flto=-1"] {
3769            let failed = refused(&[bad, "-c", "a.c"]);
3770            assert!(failed.contains("link time jobs"), "{bad}: {failed}");
3771        }
3772
3773        // How the program is cut up before the work is spread over it.
3774        assert_eq!(compile(&["-c", "a.c"]).0.lto.partition, Partition::Balanced, "gcc's default");
3775        for (spelling, want) in [
3776            ("balanced", Partition::Balanced),
3777            ("1to1", Partition::OneToOne),
3778            ("one", Partition::One),
3779            ("max", Partition::Max),
3780            ("none", Partition::None),
3781        ] {
3782            let (opts, _) = compile(&[&format!("-flto-partition={spelling}"), "-c", "a.c"]);
3783            assert_eq!(opts.lto.partition, want, "{spelling}");
3784        }
3785        assert!(refused(&["-flto-partition=big", "-c", "a.c"]).contains("partitioning model"));
3786
3787        // And how hard the bytecode is compressed on its way into the object, which is zstd's
3788        // range of levels and is the range gcc checks an argument against.
3789        assert_eq!(compile(&["-c", "a.c"]).0.lto.compression, None, "whatever it does by default");
3790        assert_eq!(compile(&["-flto-compression-level=0", "-c", "a.c"]).0.lto.compression, Some(0));
3791        let (opts, _) = compile(&["-flto-compression-level=19", "-c", "a.c"]);
3792        assert_eq!(opts.lto.compression, Some(19));
3793        for bad in ["-flto-compression-level=20", "-flto-compression-level=-1"] {
3794            let failed = refused(&[bad, "-c", "a.c"]);
3795            assert!(failed.contains("compression level"), "{bad}: {failed}");
3796        }
3797
3798        // The two pairs that describe an arrangement rather than ask for one. Every object here
3799        // holds its machine code, so the fat spelling is what already happens and the other is a
3800        // smaller file rather than a different program, and the plugin pair is about a tool the
3801        // design in `spec/09-optimizer.md` never loads.
3802        for taken in [
3803            "-ffat-lto-objects",
3804            "-fno-fat-lto-objects",
3805            "-fuse-linker-plugin",
3806            "-fno-use-linker-plugin",
3807        ] {
3808            let (opts, _) = compile(&[taken, "-c", "a.c"]);
3809            assert!(!opts.lto.requested, "{taken} says nothing about whether to do it");
3810        }
3811    }
3812
3813    /// The profile family, which is the only one here that splits down the middle.
3814    ///
3815    /// Reading a profile is taken and writing one is refused, and the line between them is the one
3816    /// section 4.1 draws: ignoring a request to read the counts gives a correct program that is
3817    /// slower than it could have been, and ignoring a request to write them means a file the build
3818    /// declared as an output never appears.
3819    #[test]
3820    fn reading_a_profile_is_taken_and_writing_one_is_refused() {
3821        let (opts, _) = compile(&["-c", "a.c"]);
3822        assert!(!opts.profile_data.requested, "nothing asks unless the command line does");
3823        assert_eq!(opts.profile_data.path, None);
3824
3825        let (opts, _) = compile(&["-fprofile-use", "-c", "a.c"]);
3826        assert!(opts.profile_data.requested);
3827        assert_eq!(opts.profile_data.path, None, "beside the object, the way gcc looks");
3828
3829        let (opts, _) = compile(&["-fprofile-use=/counts", "-c", "a.c"]);
3830        assert!(opts.profile_data.requested, "naming a path asks for it too");
3831        assert_eq!(opts.profile_data.path.as_deref(), Some("/counts"));
3832
3833        // The last of the two directions wins, the same as every other pair of `-f` spellings.
3834        assert!(
3835            !compile(&["-fprofile-use", "-fno-profile-use", "-c", "a.c"]).0.profile_data.requested
3836        );
3837        assert!(
3838            compile(&["-fno-profile-use", "-fprofile-use", "-c", "a.c"]).0.profile_data.requested
3839        );
3840
3841        // The rest of the reading half, which is where the files are and three answers about what
3842        // to make of what is in them.
3843        let (opts, _) = compile(&[
3844            "-fprofile-dir=/build/profiles",
3845            "-fprofile-abs-path",
3846            "-fprofile-correction",
3847            "-fprofile-partial-training",
3848            "-c",
3849            "a.c",
3850        ]);
3851        assert_eq!(opts.profile_data.dir.as_deref(), Some("/build/profiles"));
3852        assert!(opts.profile_data.absolute);
3853        assert!(opts.profile_data.correction);
3854        assert!(opts.profile_data.partial_training);
3855
3856        // Writing one, which is refused by name. The first four instrument the program and the
3857        // last writes a file beside the object, and a build that got neither and no message would
3858        // go on to optimize against counts that were never gathered.
3859        for writing in [
3860            "-fprofile-generate",
3861            "-fprofile-generate=/build/profiles",
3862            "-fprofile-arcs",
3863            "--coverage",
3864            "-fcondition-coverage",
3865            "-fpath-coverage",
3866        ] {
3867            let failed = refused(&[writing, "-c", "a.c"]);
3868            assert!(failed.contains("instrument"), "{writing}: {failed}");
3869        }
3870        assert!(refused(&["-ftest-coverage", "-c", "a.c"]).contains(".gcno"), "it names the file");
3871
3872        // The negative spellings of the refused half are what already happens, so they are taken.
3873        for taken in ["-fno-profile-generate", "-fno-profile-arcs", "-fno-test-coverage"] {
3874            let (opts, _) = compile(&[taken, "-c", "a.c"]);
3875            assert!(!opts.profile_data.requested, "{taken} asks for nothing");
3876        }
3877
3878        // And the flags that describe the instrumentation that is refused above, which are checked
3879        // and dropped. Checked because a typo is worth finding here rather than on the day the
3880        // instrumentation lands.
3881        for taken in [
3882            "-fprofile-update=single",
3883            "-fprofile-update=atomic",
3884            "-fprofile-update=prefer-atomic",
3885            "-fprofile-reproducible=serial",
3886            "-fprofile-reproducible=parallel-runs",
3887            "-fprofile-reproducible=multithreaded",
3888            "-fprofile-values",
3889            "-fno-profile-values",
3890            "-fprofile-info-section",
3891            "-fprofile-filter-files=a.c",
3892            "-fprofile-exclude-files=b.c",
3893            "-fprofile-note=a.gcno",
3894        ] {
3895            let (opts, _) = compile(&[taken, "-c", "a.c"]);
3896            assert!(!opts.profile_data.requested, "{taken} says nothing about reading one");
3897        }
3898        assert!(refused(&["-fprofile-update=none", "-c", "a.c"]).contains("update method"));
3899        assert!(refused(&["-fprofile-reproducible=any", "-c", "a.c"]).contains("reproducibility"));
3900    }
3901
3902    #[test]
3903    fn the_levels_gcc_spells_differently_are_the_levels_they_mean() {
3904        assert_eq!(compile(&["-O", "-c", "a.c"]).0.opt_level, OptLevel::O1);
3905        assert_eq!(compile(&["-Og", "-c", "a.c"]).0.opt_level, OptLevel::O1);
3906        assert_eq!(compile(&["-O2", "-c", "a.c"]).0.opt_level, OptLevel::O2);
3907    }
3908
3909    #[test]
3910    fn the_machine_flags_that_name_what_we_already_do_are_taken_and_the_rest_are_not() {
3911        let line = ["--target=x86_64-unknown-linux-gnu", "-m64", "-march=x86-64-v3"];
3912        let (opts, _) =
3913            compile(&[&line[..], &["-mtune=native", "-mabi=sysv", "-c", "a.c"]].concat());
3914        assert_eq!(opts.target.to_string(), "x86_64-unknown-linux-gnu");
3915        let wrong = refused(&["--target=x86_64-unknown-linux-gnu", "-mabi=ms", "-c", "a.c"]);
3916        assert!(wrong.contains("sysv convention"), "{wrong}");
3917    }
3918
3919    #[test]
3920    fn the_thread_flag_is_a_macro_and_a_library_and_the_library_goes_last() {
3921        let (opts, plan) = compile(&["-pthread", "-c", "a.c"]);
3922        assert!(opts.defines.iter().any(|d| d == "_REENTRANT"));
3923        // After the input, because a static link takes what it needs from a library when it
3924        // reaches it and not afterwards.
3925        let names: Vec<&str> = plan.jobs.iter().map(|j| j.input.as_str()).collect();
3926        assert_eq!(names, vec!["a.c"]);
3927    }
3928
3929    #[test]
3930    fn the_questions_a_build_system_asks_before_it_compiles_anything() {
3931        let target = "--target=x86_64-unknown-linux-gnu";
3932        assert_eq!(printed(&[target, "-dumpmachine"]), "x86_64-unknown-linux-gnu");
3933        assert_eq!(printed(&[target, "-dumpversion"]), VERSION);
3934        assert_eq!(printed(&[target, "-dumpfullversion"]), VERSION);
3935        assert_eq!(printed(&[target, "-print-multiarch"]), "x86_64-linux-gnu");
3936        // A name nothing holds comes back unchanged, which is GCC's rule and is what makes the
3937        // answer safe to paste into a link line whether or not the file is there.
3938        assert_eq!(printed(&[target, "-print-file-name=no-such-library.a"]), "no-such-library.a");
3939        assert_eq!(printed(&[target, "-print-prog-name=ld"]), "ld");
3940        let dirs = printed(&[target, "-print-search-dirs"]);
3941        assert!(dirs.starts_with("install: "), "{dirs}");
3942        assert!(dirs.contains("\nlibraries: ="), "{dirs}");
3943    }
3944
3945    #[test]
3946    fn the_sysroot_in_effect_is_the_one_the_command_line_named_or_the_one_for_the_target() {
3947        // A tree the user named is the answer whatever the target is, because it is the answer to
3948        // every other question too.
3949        assert_eq!(printed(&["--sysroot=/opt/cross", "-print-sysroot"]), "/opt/cross");
3950
3951        // A target that is no machine this suite runs on is read under the cache, and the answer is
3952        // the root rather than one of the directories under it, since what asks is looking for a
3953        // file of its own.
3954        let root = cache::dir().join("sysroots").join("riscv64-linux-musl");
3955        assert_eq!(
3956            printed(&["--target=riscv64-linux-musl", "-print-sysroot"]),
3957            root.display().to_string()
3958        );
3959
3960        // And a compile for this machine has no sysroot, which is the empty line GCC prints when it
3961        // was configured without one rather than a `/` that would be a claim about the filesystem.
3962        let host = Triple::host().expect("a host this compiler knows");
3963        assert_eq!(printed(&[&format!("--target={host}"), "-print-sysroot"]), "");
3964    }
3965
3966    #[test]
3967    fn the_provenance_of_a_sysroot_is_the_manifest_it_carries() {
3968        // Section 13.5 wants seven things per input and wants them machine readable, and the manifest
3969        // is the record that already has them, so the flag prints that rather than a second format.
3970        let manifest = "rucc sysroot manifest 2\n\
3971                        target\tx86_64-linux-musl\n\
3972                        include/generic/stdio.h\tmusl-1.2.5\t\
3973                        https://musl.libc.org/releases/musl-1.2.5.tar.gz\t\
3974                        0000000000000000000000000000000000000000000000000000000000000000\tmit\t\
3975                        bundled\n\
3976                        lib/libc.so\tmusl-1.2.5\t\
3977                        https://musl.libc.org/releases/musl-1.2.5.tar.gz\t\
3978                        1111111111111111111111111111111111111111111111111111111111111111\tmit\t\
3979                        generated\n";
3980        let tree = TempTree::new("provenance", &[("manifest", manifest)]);
3981        let sysroot = format!("--sysroot={}", tree.0.display());
3982        assert_eq!(printed(&[&sysroot, "-print-sysroot-provenance"]), manifest);
3983
3984        // A tree with no manifest in it is a tree somebody assembled themselves, and nothing here
3985        // knows where any of it came from. Saying nothing is the only honest answer, and a reader can
3986        // tell it from a manifest with no inputs because that one still has its two header lines.
3987        let bare = TempTree::new("provenance-bare", &[]);
3988        assert_eq!(
3989            printed(&[&format!("--sysroot={}", bare.0.display()), "-print-sysroot-provenance"]),
3990            ""
3991        );
3992
3993        // And a compile for this machine has no sysroot at all, which is the same empty answer
3994        // `-print-sysroot` gives for it.
3995        let host = Triple::host().expect("a host this compiler knows");
3996        assert_eq!(printed(&[&format!("--target={host}"), "-print-sysroot-provenance"]), "");
3997
3998        // And the other spelling, which section 13.5 is the document that writes.
3999        assert_eq!(printed(&[&sysroot, "--print-sysroot-provenance"]), manifest);
4000    }
4001
4002    #[test]
4003    fn a_manifest_this_build_cannot_read_is_refused_rather_than_printed() {
4004        // Passing a file we could not parse to whoever asked would make their parser the one that
4005        // finds the problem, and the three uses section 13.5 gives for this are all somebody else
4006        // parsing it.
4007        let tree = TempTree::new(
4008            "provenance-bad",
4009            &[("manifest", "rucc sysroot manifest 2\ntarget\tx86_64-linux-musl\nlib/libc.a\n")],
4010        );
4011        let message =
4012            refused(&[&format!("--sysroot={}", tree.0.display()), "-print-sysroot-provenance"]);
4013        assert!(message.contains("manifest"), "{message}");
4014        assert!(message.contains("1 fields where an input has six"), "{message}");
4015    }
4016
4017    #[test]
4018    fn the_two_dependency_flags_that_stop_after_the_rule_stop_after_the_rule() {
4019        let (opts, _) = compile(&["-M", "a.c"]);
4020        assert!(opts.deps.emit && opts.deps.instead_of_compiling);
4021        assert!(opts.deps.system_headers, "plain -M lists them");
4022        assert_eq!(opts.emit, EmitKind::Preprocessed);
4023
4024        // Even where a later flag asked for something else, because the family is a mode and
4025        // the mode is what the run is for.
4026        let (opts, _) = compile(&["-M", "-c", "a.c"]);
4027        assert_eq!(opts.emit, EmitKind::Preprocessed);
4028
4029        let (opts, _) = compile(&["-MM", "a.c"]);
4030        assert!(!opts.deps.system_headers);
4031    }
4032
4033    #[test]
4034    fn the_two_that_end_in_d_leave_the_compilation_alone() {
4035        let (opts, _) = compile(&["-MD", "-c", "a.c"]);
4036        assert!(opts.deps.emit && !opts.deps.instead_of_compiling);
4037        assert!(opts.deps.system_headers);
4038        assert_eq!(opts.emit, EmitKind::Object);
4039
4040        let (opts, _) = compile(&["-MMD", "-c", "a.c"]);
4041        assert!(opts.deps.emit && !opts.deps.instead_of_compiling);
4042        assert!(!opts.deps.system_headers);
4043    }
4044
4045    #[test]
4046    fn nothing_puts_the_system_headers_back_once_a_flag_has_taken_them_out() {
4047        // GCC's rule, and not an oversight in it. The flag asking for fewer of them is read as
4048        // the answer, because the other one never asked the question.
4049        let (opts, _) = compile(&["-MM", "-M", "a.c"]);
4050        assert!(!opts.deps.system_headers);
4051        let (opts, _) = compile(&["-MD", "-MMD", "-c", "a.c"]);
4052        assert!(!opts.deps.system_headers);
4053        let (opts, _) = compile(&["-MMD", "-MD", "-c", "a.c"]);
4054        assert!(!opts.deps.system_headers);
4055    }
4056
4057    #[test]
4058    fn a_target_arrives_escaped_from_one_flag_and_untouched_from_the_other() {
4059        let (opts, _) = compile(&["-MM", "-MT", "a b.o", "-MQ", "a b.o", "a.c"]);
4060        assert_eq!(opts.deps.targets, vec!["a b.o".to_owned(), "a\\ b.o".to_owned()]);
4061    }
4062
4063    #[test]
4064    fn the_rest_of_the_family_is_a_file_and_a_switch() {
4065        let (opts, _) = compile(&["-MM", "-MF", "dep.d", "-MP", "a.c"]);
4066        assert_eq!(opts.deps.file.as_deref(), Some("dep.d"));
4067        assert!(opts.deps.phony);
4068
4069        for flag in ["-MF", "-MT", "-MQ"] {
4070            let e = parse_args(&args(&[flag])).unwrap_err();
4071            assert!(e.message.contains("requires an argument"), "{}", e.message);
4072        }
4073    }
4074
4075    /// A directory of sources for one test, removed when the test is done with it.
4076    struct TempTree(PathBuf);
4077
4078    impl Drop for TempTree {
4079        fn drop(&mut self) {
4080            let _ = std::fs::remove_dir_all(&self.0);
4081        }
4082    }
4083
4084    impl TempTree {
4085        fn new(name: &str, files: &[(&str, &str)]) -> TempTree {
4086            let dir = std::env::temp_dir().join(format!("rucc-deps-{}-{name}", std::process::id()));
4087            let _ = std::fs::remove_dir_all(&dir);
4088            std::fs::create_dir_all(&dir).expect("temporary directory should be writable");
4089            for (path, text) in files {
4090                let at = dir.join(path);
4091                if let Some(parent) = at.parent() {
4092                    std::fs::create_dir_all(parent).expect("creating a subdirectory should work");
4093                }
4094                std::fs::write(&at, text).expect("writing a temporary file should work");
4095            }
4096            TempTree(dir)
4097        }
4098
4099        fn path(&self, name: &str) -> String {
4100            self.0.join(name).to_string_lossy().into_owned()
4101        }
4102    }
4103
4104    #[test]
4105    fn the_rule_names_what_the_includes_found_and_names_each_of_them_once() {
4106        // End to end, because the list comes from the preprocessor and the format comes from
4107        // somewhere else, and a test of either half on its own would pass with the two of them
4108        // wired up backwards.
4109        let tree = TempTree::new(
4110            "found",
4111            &[
4112                ("a.c", "#include \"one.h\"\n#include \"two.h\"\nint main(void) { return X; }\n"),
4113                ("one.h", "#define X 0\n"),
4114                ("two.h", "#include \"one.h\"\n"),
4115            ],
4116        );
4117        let out = tree.path("dep.d");
4118        let code = run(&args(&["-MM", "-MF", &out, "-o", &tree.path("a.i"), &tree.path("a.c")]));
4119        assert_eq!(code, 0);
4120
4121        let text = std::fs::read_to_string(&out).expect("the rule should have been written");
4122        let names: Vec<&str> = text.split_whitespace().collect();
4123        // The target, the source, and each header once however many times it was reached.
4124        assert_eq!(names.first(), Some(&"a.o:"), "{text}");
4125        assert_eq!(names.iter().filter(|n| n.ends_with("one.h")).count(), 1, "{text}");
4126        assert_eq!(names.iter().filter(|n| n.ends_with("two.h")).count(), 1, "{text}");
4127        // And the `-o` went to the file the rule replaced, which is left empty rather than
4128        // absent because a makefile that named it as a target will look for it.
4129        assert_eq!(std::fs::read(tree.path("a.i")).expect("the output should exist"), b"");
4130    }
4131
4132    #[test]
4133    fn a_header_that_is_only_reached_under_a_guard_is_still_a_dependency() {
4134        // The multiple-include optimization means the second reach never opens the file. It is
4135        // still a file this translation unit was built from, so it is still in the rule.
4136        let tree = TempTree::new(
4137            "guarded",
4138            &[
4139                ("a.c", "#include \"g.h\"\n#include \"g.h\"\nint main(void) { return 0; }\n"),
4140                ("g.h", "#ifndef G\n#define G\n#endif\n"),
4141            ],
4142        );
4143        let out = tree.path("dep.d");
4144        let code = run(&args(&["-MM", "-MF", &out, "-o", &tree.path("a.i"), &tree.path("a.c")]));
4145        assert_eq!(code, 0);
4146        let text = std::fs::read_to_string(&out).expect("the rule should have been written");
4147        assert_eq!(text.split_whitespace().filter(|n| n.ends_with("g.h")).count(), 1, "{text}");
4148    }
4149
4150    #[test]
4151    fn every_imacros_file_is_read_before_every_include_file_whatever_order_they_were_written() {
4152        // Measured against GCC rather than read: the two flags the other way round produce the
4153        // same output byte for byte, so the command line order between the two families does not
4154        // decide anything and the order within one does. The `-include` file here can only see
4155        // the definition if the `-imacros` file that was written after it ran first.
4156        let tree = TempTree::new(
4157            "preinclude",
4158            &[
4159                ("a.c", "int main(void) { return 0; }\n"),
4160                ("i.h", "#ifdef FROM_MACROS\nint saw_it;\n#else\nint missed_it;\n#endif\n"),
4161                ("m.h", "#define FROM_MACROS 1\nint macros_text;\n"),
4162            ],
4163        );
4164        let out = tree.path("a.i");
4165        let code = run(&args(&[
4166            "-E",
4167            "-include",
4168            &tree.path("i.h"),
4169            "-imacros",
4170            &tree.path("m.h"),
4171            "-o",
4172            &out,
4173            &tree.path("a.c"),
4174        ]));
4175        assert_eq!(code, 0);
4176        let text = std::fs::read_to_string(&out).expect("the output should have been written");
4177        assert!(text.contains("saw_it"), "{text}");
4178        // And the text of the `-imacros` file is thrown away, which is the whole difference
4179        // between the two flags.
4180        assert!(!text.contains("macros_text"), "{text}");
4181    }
4182
4183    #[test]
4184    fn a_file_the_command_line_named_is_a_prerequisite_the_same_as_one_a_directive_named() {
4185        let tree = TempTree::new(
4186            "preinclude-deps",
4187            &[
4188                ("a.c", "int main(void) { return 0; }\n"),
4189                ("i.h", "int from_include;\n"),
4190                ("m.h", "#define M 1\n"),
4191            ],
4192        );
4193        let out = tree.path("dep.d");
4194        let code = run(&args(&[
4195            "-MM",
4196            "-MF",
4197            &out,
4198            "-include",
4199            &tree.path("i.h"),
4200            "-imacros",
4201            &tree.path("m.h"),
4202            "-o",
4203            &tree.path("a.i"),
4204            &tree.path("a.c"),
4205        ]));
4206        assert_eq!(code, 0);
4207        let text = std::fs::read_to_string(&out).expect("the rule should have been written");
4208        assert!(text.contains("i.h"), "{text}");
4209        assert!(text.contains("m.h"), "{text}");
4210    }
4211
4212    #[test]
4213    fn a_command_line_include_that_is_nowhere_on_the_path_is_an_error_and_not_a_warning() {
4214        // Including the directory of the source file, which is not on the path for these: the
4215        // command line was not written there, so a name in it is relative to where the compiler
4216        // was run rather than to where the source sits.
4217        let tree = TempTree::new(
4218            "preinclude-missing",
4219            &[("sub/a.c", "int main(void) { return 0; }\n"), ("sub/beside.h", "int x;\n")],
4220        );
4221        let code = run(&args(&["-E", "-include", "beside.h", "-o", "-", &tree.path("sub/a.c")]));
4222        assert_eq!(code, 1);
4223    }
4224
4225    #[test]
4226    fn a_command_line_that_links_names_the_executable_and_not_the_object_it_went_through() {
4227        // The object a link goes through is in a temporary directory and is gone before `make`
4228        // reads any of this, so the rule that named it would be a rule for a file that is never
4229        // there. The target and the file are both the `-o`, which is the executable.
4230        let (opts, plan) = compile(&["-MD", "sub/a.c", "-o", "prog"]);
4231        assert_eq!(plan.output.as_deref(), Some("prog"));
4232        assert_eq!(deps::default_target("sub/a.c", deps_target_output(&opts, &plan)), "prog");
4233        assert_eq!(
4234            deps::default_file(&opts.deps, "sub/a.c", plan.output.as_deref()).as_deref(),
4235            Some("prog.d")
4236        );
4237    }
4238
4239    #[test]
4240    fn the_plan_keeps_the_output_name_because_the_rule_is_written_from_it() {
4241        let (_, plan) = compile(&["-MMD", "-c", "sub/a.c", "-o", "obj/x.o"]);
4242        assert_eq!(plan.output.as_deref(), Some("obj/x.o"));
4243        let (_, plan) = compile(&["-MMD", "-c", "sub/a.c"]);
4244        assert_eq!(plan.output, None);
4245    }
4246
4247    #[test]
4248    fn usage_fits_on_a_screen() {
4249        // Not a style preference. A help text that scrolls is one nobody reads, and this is
4250        // the cheapest way to keep it honest as flags accumulate. The number goes up only when
4251        // a family of flags arrives that has nowhere to share a line, which the two pass gates
4252        // were and which the two fuel flags and `-fsafety=` now are, and it goes up by exactly
4253        // the lines that family took. The four it went up by last are the flags a build system
4254        // passes without being asked to: how much to say, what machine to generate for, threads,
4255        // and the questions `configure` asks before it compiles anything. The one it went up by
4256        // last is the second line of `--emit`, whose kinds are a family that has now outgrown
4257        // one line and has nowhere else to go. The two it went up by last are the dependency
4258        // family, which is eight flags that share nothing with anything above them. The one it
4259        // went up by last is the four spellings of position independent code, which every
4260        // configure script writes and which could only have shared the link line, and that line
4261        // is already four characters short of the limit. The two it went up by last are the rest
4262        // of the include family, which is six more flags that change where a header is looked for
4263        // and two that name a header outright. The one it went up by last is the pair that keeps
4264        // the intermediate files and times the steps, which belong next to the two flags above
4265        // them that are also about watching a compilation rather than changing one. The two it
4266        // went up by last are the section flags and the visibility flag, which are what a build
4267        // that cares about the size of what it ships and about which names it exports writes, and
4268        // the second of them was already taken and only missing from here. The one it went up by
4269        // last is the stack protector, which is four spellings of one question and which every
4270        // distribution puts on every command line it issues, so a build that reads this list
4271        // looking for it and does not find it has to go and read the specification instead. The one
4272        // it went up by last is the profiler, which is two spellings of the request and two of
4273        // where the call goes, and which is about watching a program run rather than about what is
4274        // generated, so it shares its subject with nothing above it. The one it went up by last is
4275        // the room a function opens with for something to be written over it later, which takes an
4276        // argument of its own shape and is what a kernel build asks for, so it fits beside the
4277        // profiler and nothing else. The one it went up by last is what overflows rather than being
4278        // undefined, which is three spellings of two questions and which a kernel build and a great
4279        // deal of code written before the standard settled both pass. The one it went up by last is
4280        // the other answer to the first of those questions, which could not share the line because
4281        // what it asks for is the opposite of what the flags on that line ask for. The one it went
4282        // up by last is the split of the line that lists what this compiler does anyway into that
4283        // and what it assumes anyway, which are two different claims that were sharing a line until
4284        // the second of them got a second flag and the line stopped fitting. The one it went up by
4285        // last is the three flags that change the ABI rather than the code, which have to be given
4286        // to every file in a program or none of them and which therefore belong somewhere a person
4287        // reading this list will see them. The one it went up by last is the floating point group,
4288        // which is two lines rather than one because the first of them is a choice this compiler
4289        // records and the rest are claims about what it does anyway, and putting a real setting on
4290        // the same line as three flags that change nothing would be misleading about both. The one
4291        // it went up by last is the flag that says a write has to stay inside the member it names,
4292        // which is a setting rather than a claim and so cannot share the line above it, that being
4293        // the one that picks a tier. The two it went up by last are the prefix mapping family,
4294        // which is four flags whose whole job is to keep a build's output the same from two
4295        // different directories, and which a person chasing a reproducible build comes here
4296        // looking for by name. The one it went up by last is how the debug sections are compressed
4297        // and whether they go in a file of their own, which are two questions about the shape of
4298        // the debug output, where the line above them is about how much of it there is. The one it
4299        // went up by last is the `restrict` contract, which is a setting for the same reason the
4300        // flag that keeps a write inside its member is and which is the check a person who has been
4301        // bitten by a vectorizer comes here looking for. The one it went up by last is link time
4302        // optimization, which is a whole optimization rather than a flag and which says so on its
4303        // own line, because a build that passes it and reads this looking for what it got is
4304        // asking a question no other line here answers. The one it went up by last is the sysroot,
4305        // which is the question somebody asks when a cross build read a file nobody expected, and
4306        // which has no room on the line above it because the answers there are a path each and this
4307        // one is the root all of them are under. The one it went up by last is what is inside that
4308        // root and where each of it came from, which is a question about a whole tree rather than
4309        // about a path and which is long enough on its own that it could not have shared a line with
4310        // anything. The one it went up by last is the profile family, which splits down the middle
4311        // where no other family here does, so the line has to name the half that is taken and the
4312        // half that is refused or it would be read as taking both.
4313        assert!(USAGE.lines().count() < 68, "usage text has grown past one screen");
4314    }
4315}