Skip to main content

rucc_driver/
lib.rs

1//! The driver: command line parsing, the phase graph, job scheduling and the linker
2//! invocation.
3//!
4//! Design: `spec/04-driver-and-cli.md`. Layer rank 13, see `spec/18-package-layout.md`.
5//!
6//! This is the only crate that is allowed to know the process exists. It reads the command
7//! line, touches the file system, spawns the linker and writes to the terminal, and it hands
8//! everything below it a [`Session`]. The binary crate is a `main` that calls
9//! [`run`] and nothing else, so that the whole driver is reachable from a test.
10//!
11//! # Status
12//!
13//! `--help`, `--version` and `--print-config` are real, which is the `M0` exit criterion in
14//! `spec/17-milestones.md`. The phase graph is real and `-###` prints it, and the scheduler
15//! that will run it is real and tested.
16//!
17//! Two phases run. `-E` reads the file, runs phase 4 over it and writes the result, to `-o` or
18//! to standard output. `--emit=tast` carries on through phase 7, the parse and the checking,
19//! and writes the typed tree. The flags those two read are real with them, which is `-D`, `-U`,
20//! `-I`, `-I-`, `-iquote`, `-isystem`, `-idirafter`, `-iprefix`, `-iwithprefix`,
21//! `-iwithprefixbefore`, `-include`, `-imacros`, `--sysroot=`, `-isysroot`, `-P`, `-std=`,
22//! `-fgnuc-version=`, `-ansi`, `-ffreestanding`, `-fno-builtin`, `-fno-builtin-<name>`,
23//! `-fgnu89-inline`, `-pedantic` and `-Werror`.
24//! The phases after them still say they are not implemented.
25//!
26//! This crate is tier 3 in `spec/18-package-layout.md` section 18.5: its Rust API is
27//! explicitly unstable and will change without a major version bump.
28
29#![doc(html_root_url = "https://docs.rs/rucc-driver/0.10.18")]
30
31pub mod compile;
32pub mod deps;
33pub mod library;
34pub mod link;
35mod map;
36pub mod phase;
37pub mod preprocess;
38pub mod schedule;
39
40use std::fmt::Write as _;
41use std::io::Write as _;
42use std::path::PathBuf;
43
44use rucc_codegen::coverage::{self, Fired};
45use rucc_codegen::pressure::Pressure;
46use rucc_pp::Dependency;
47use rucc_session::{
48    Control, Dumps, EmitKind, Hook, Options, Pic, Preinclude, Protector, SaveTemps, Session, Std,
49    Wrapping, runtime,
50};
51use rucc_target::Triple;
52
53use crate::link::LinkOptions;
54
55pub use crate::compile::{Artifact, Compiled, Temps, compile, compile_ir};
56pub use crate::phase::{Input, InputKind, Job, LinkJob, Output, Phase, Plan};
57pub use crate::preprocess::{OsFileSystem, Preprocessed, preprocess};
58pub use crate::schedule::Jobs;
59
60/// The compiler's version, taken from the workspace manifest.
61pub const VERSION: &str = env!("CARGO_PKG_VERSION");
62
63/// What the command line asked for.
64#[derive(Debug, Clone, PartialEq, Eq)]
65pub enum Action {
66    /// Print usage and exit successfully.
67    Help,
68    /// Print the version and exit successfully.
69    Version,
70    /// Print one line and exit successfully, which is what the `-dump` and `-print` family do.
71    ///
72    /// A build system asks these before it compiles anything, and what it does with the answer
73    /// is paste it into a path or into another command line, so each one is a single line with
74    /// no decoration around it.
75    Print(String),
76    /// Print the resolved configuration and exit successfully.
77    PrintConfig(Box<Options>),
78    /// Print the passes the level will run and exit successfully.
79    PrintPipeline(Box<Options>),
80    /// Print the phase plan and the link line and exit successfully, which is `-###`.
81    PrintPlan {
82        /// The resolved options, which is what says what the link line is for.
83        opts: Box<Options>,
84        /// What to do to each input, and in what order.
85        plan: Box<Plan>,
86        /// What the command line said about linking.
87        link: Box<LinkOptions>,
88    },
89    /// Compile the given inputs.
90    Compile {
91        /// The resolved options.
92        opts: Box<Options>,
93        /// What to do to each input, and in what order.
94        plan: Box<Plan>,
95        /// What the command line said about linking.
96        link: Box<LinkOptions>,
97        /// How many translation units to compile at once.
98        jobs: Jobs,
99        /// Whether `-v` asked for the plan to be printed while it runs.
100        verbose: bool,
101    },
102}
103
104/// Why a command line was rejected.
105#[derive(Debug, Clone, PartialEq, Eq)]
106pub struct CliError {
107    /// The message, lowercase and without a trailing period, in the same shape as any other
108    /// diagnostic.
109    pub message: String,
110}
111
112impl std::fmt::Display for CliError {
113    fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
114        f.write_str(&self.message)
115    }
116}
117
118impl std::error::Error for CliError {}
119
120fn err(message: impl Into<String>) -> CliError {
121    CliError { message: message.into() }
122}
123
124/// A question the command line asked instead of asking for a compilation.
125///
126/// These are answered after the loop rather than where they are read, because every one of them
127/// is about the target or about the library search and the last word on both is the end of the
128/// command line.
129enum Query {
130    /// `-dumpmachine`, the triple.
131    Machine,
132    /// `-dumpversion` and `-dumpfullversion`, which are the same three numbers here.
133    Version,
134    /// `-print-multiarch`, the directory name a distribution files this target under.
135    Multiarch,
136    /// `-print-search-dirs`, in the three lines GCC prints.
137    SearchDirs,
138    /// `-print-file-name=<name>`, the full path of a library file.
139    FileName(String),
140    /// `-print-prog-name=<name>`, the full path of a program.
141    ProgName(String),
142    /// `-print-libgcc-file-name`, which is `-print-file-name=libgcc.a` under another spelling.
143    Libgcc,
144}
145
146/// Usage text.
147///
148/// Deliberately short. `spec/04-driver-and-cli.md` puts the full flag reference in the
149/// manual page, because a `--help` nobody can read in one screen is a `--help` nobody reads.
150pub const USAGE: &str = "\
151rucc, an optimizing C compiler
152
153usage: rucc [options] file...
154
155options:
156  -c                     compile and assemble, do not link
157  -S                     compile only, emit assembly
158  -E                     preprocess only
159  -o <file>              write output to <file>, or to standard output for -
160  -D <name>[=<value>], -U <name>      define a macro, or undefine one after every -D
161  -I <dir>               add <dir> to the include search path
162  -iquote -isystem -idirafter <dir>   the other chains, -nostdinc drops ours
163  -I-, -iprefix <p>, -iwithprefix[before] <dir>   the older spellings of those
164  -include <file>, -imacros <file>    read <file> first, the second for its macros only
165  --sysroot=<dir>        look for the library's headers under <dir>, -isysroot too
166  -P, -dM                with -E: leave out the markers, or dump the macros
167  -M -MM -MD -MMD        write a make rule for the source, the last two compile as well
168  -MF <file> -MT <t> -MQ <t> -MP   where the rule goes, what it builds, targets with no recipe
169  -std=<dialect>         c89 through c23, and the gnu spellings
170  -fgnuc-version=<v>     the GCC release to claim, default 7.0.0
171  -x <lang>              treat later inputs as <lang>, or none to stop
172  -O<level>              optimize: 0, 1, 2, 3, s, z
173  -fsafety=<tier>        check memory safety: off, detect, enforce, kernel
174  -f<pass> -fno-<pass> -fdump-ir=<what> -fopt-info[-<kind>][=FILE]
175  -fpass-fuel=<pass>=<n>, -fpass-fuel-global=<n>   stop a pass, or all of them, after n
176  -fdisable-<pass>[=<funcs>], -fenable-<pass>[=<funcs>]   run a pass on some functions only
177  -g -g0 -gdwarf-5, -fno-omit-frame-pointer, -mno-red-zone   debug info, frame pointer, red zone
178  -f[no-]stack-protector[-strong|-all], -f[no-]stack-clash-protection, -fcf-protection=<edges>
179  -ffunction-sections -fdata-sections   a section per function or variable, for --gc-sections
180  -fvisibility=<what>    default, hidden, internal or protected, when nothing in the source said
181  -l<name>, -L <dir>, -B <dir>   link a library, where to look for one, where our own tools are
182  -fPIC -fpic -fPIE -fpie, -fno-common, -f[no-]strict-aliasing, -pipe   what it does anyway
183  -static -shared -pie -no-pie -nostdlib -nostartfiles -nodefaultlibs -rdynamic -s   how to link
184  -Wl,<arg>, -Xlinker <arg>, -fuse-ld=<name>   hand an argument to the linker, or pick one
185  -Werror -pedantic -pedantic-errors -w   how much to say, and whether it is fatal
186  -m64 -march= -mtune= -mcpu= -mabi= -mcmodel=   what machine to generate for
187  -pg -p, -mfentry -mno-fentry   call a profiler on the way in, and where that call goes
188  -fpatchable-function-entry=<n>[,<m>]   room at the top of every function to patch later
189  -fwrapv, -fwrapv-pointer, -fno-strict-overflow   signed or pointer overflow wraps
190  -ftrapv                signed overflow stops the program instead
191  -pthread               build for more than one thread, and link the library for it
192  -dumpmachine -dumpversion -print-multiarch -print-search-dirs   what this compiler is
193  -print-file-name=<name> -print-prog-name=<name>   where a file or a program is
194  -j[n]                  compile n translation units at once, default all
195  -v, -###               print each phase as it runs, or without running any
196  -save-temps[=cwd|obj], -time   keep the .i and the .s, say how long each step took
197  --target=<triple>      generate code for <triple>
198  --emit=<kind>          exe, obj, asm, preprocessed, tast, ir, mir-final,
199                         safety-summary, type-granules
200  --print-config, --print-pipeline    print the configuration or the pipeline, and exit
201  --version              print the version and exit
202  -h, --help             print this message and exit
203
204See spec/04-driver-and-cli.md for the full flag reference.
205";
206
207/// The argument of a flag that may be joined to it or may be the next word.
208///
209/// `-DFOO` and `-D FOO` are the same thing, and `at` is where the flag's own letters end.
210fn joined_or_next(
211    arg: &str,
212    at: usize,
213    args: &[String],
214    i: &mut usize,
215) -> Result<String, CliError> {
216    if arg.len() > at {
217        return Ok(arg[at..].to_owned());
218    }
219    let next = args.get(*i).ok_or_else(|| err(format!("{arg} requires an argument")))?;
220    *i += 1;
221    Ok(next.clone())
222}
223
224/// Parses a command line, without the program name.
225///
226/// # Errors
227///
228/// Returns the message to print when the arguments do not name a compilation this compiler
229/// can attempt.
230pub fn parse_args(args: &[String]) -> Result<Action, CliError> {
231    let host = Triple::host()
232        .ok_or_else(|| err("this host is not a supported target and no --target was given"))?;
233    let mut opts = Options::new(host);
234    let mut inputs: Vec<Input> = Vec::new();
235    let mut print_config = false;
236    let mut print_pipeline = false;
237    let mut print_plan = false;
238    let mut verbose = false;
239    let mut jobs = Jobs::default();
240    let mut nostdinc = false;
241    let mut sysroot: Option<PathBuf> = None;
242    let mut output = None;
243    let mut link = LinkOptions::default();
244    let mut query: Option<Query> = None;
245    let mut threads = false;
246    // `-x` applies to inputs that come after it and stays in effect until the next one, which
247    // is why it is tracked across the loop rather than attached to a single argument.
248    let mut forced: Option<InputKind> = None;
249    // What `-iprefix` last said, stuck on the front of every later `-iwithprefix`. It applies to
250    // the flags after it and not the ones before, so a command line may set it more than once.
251    // GCC's default is its own installed header directory with the last component taken off,
252    // which is a path a cross compiler's build system knows and passes; there is no equivalent
253    // here, so with no `-iprefix` the prefix is nothing and `-iwithprefix` names a directory
254    // outright.
255    let mut iprefix = String::new();
256
257    let mut i = 0;
258    while i < args.len() {
259        let arg = args[i].as_str();
260        i += 1;
261        match arg {
262            "-h" | "--help" => return Ok(Action::Help),
263            "--version" => return Ok(Action::Version),
264            "--print-config" => print_config = true,
265            "--print-pipeline" => print_pipeline = true,
266            "-###" => print_plan = true,
267            "-v" => verbose = true,
268            // The files a compilation goes through, kept rather than thrown away. The bare
269            // spelling means `=obj` and not `=cwd`, which is not what the manual says and is what
270            // gcc 16 does; `SaveTemps::Object` carries the measurement.
271            "-save-temps" => opts.save_temps = SaveTemps::Object,
272            _ if arg.starts_with("-save-temps=") => {
273                opts.save_temps = arg["-save-temps=".len()..].parse().map_err(err)?;
274            }
275            // How long each step took. A misspelling of this is worth rejecting rather than
276            // ignoring, since a run that says nothing looks like a compilation that took no time.
277            "-time" => opts.time = true,
278            "-c" => opts.emit = EmitKind::Object,
279            "-S" => opts.emit = EmitKind::Asm,
280            "-E" => opts.emit = EmitKind::Preprocessed,
281            "-g" => opts.debug_info = true,
282            // GCC's own levels of how much debug information to write. Zero is none and every
283            // other number is some, and this compiler has one amount, so the numbers above zero
284            // all mean the same thing here. `-ggdb` is the same flag asking for whatever the
285            // debugger on the machine prefers, which is what we emit anyway.
286            "-g0" => opts.debug_info = false,
287            "-g1" | "-g2" | "-g3" | "-ggdb" | "-ggdb1" | "-ggdb2" | "-ggdb3" => {
288                opts.debug_info = true;
289            }
290            // The version of DWARF to write. We write DWARF 5 and nothing else, so a build that
291            // asks for another version is told rather than handed a file it cannot read.
292            "-gdwarf" | "-gdwarf-5" => opts.debug_info = true,
293            _ if arg.starts_with("-gdwarf-") => {
294                return Err(err(format!(
295                    "{arg}: this compiler writes DWARF 5 and no other version, see \
296                     spec/11-debug-info.md"
297                )));
298            }
299            "-Werror" => opts.warnings_are_errors = true,
300            // Nothing that is not fatal is said at all. Read at the one place a diagnostic goes
301            // through rather than here, so that a warning `-w` dropped is not counted either.
302            "-w" => opts.warnings = false,
303            "-pedantic-errors" => {
304                opts.pedantic = true;
305                opts.warnings_are_errors = true;
306            }
307            "-P" => opts.line_markers = false,
308            // The dependency family, which section 4.4 calls required because every build system
309            // that generates its own makefiles asks for it. The two that end in `D` write a file
310            // beside the object and let the compilation happen, and the two that do not write to
311            // standard output and stop after it. Nothing here turns the system headers back on
312            // once a flag has turned them off, which is GCC's behaviour and is why `-MM -M` is
313            // `-MM`: the flag asking for fewer of them is the one with something to say.
314            "-M" => {
315                opts.deps.emit = true;
316                opts.deps.instead_of_compiling = true;
317            }
318            "-MM" => {
319                opts.deps.emit = true;
320                opts.deps.instead_of_compiling = true;
321                opts.deps.system_headers = false;
322            }
323            "-MD" => opts.deps.emit = true,
324            "-MMD" => {
325                opts.deps.emit = true;
326                opts.deps.system_headers = false;
327            }
328            "-MP" => opts.deps.phony = true,
329            // These three take a word and only in the separated form, which is how GCC spells
330            // them and how every build system writes them.
331            "-MF" | "-MT" | "-MQ" => {
332                let value =
333                    args.get(i).ok_or_else(|| err(format!("{arg} requires an argument")))?;
334                i += 1;
335                match arg {
336                    "-MF" => opts.deps.file = Some(value.clone()),
337                    // The whole of the difference between the two. `-MT` is for a build that has
338                    // already escaped what it is passing, and `-MQ` is for one that has a name
339                    // and wants it to arrive as that name.
340                    "-MT" => opts.deps.targets.push(value.clone()),
341                    _ => opts.deps.targets.push(deps::escaped(value)),
342                }
343            }
344            // The questions a build system asks before it compiles anything. Answered after the
345            // loop, because each one is about the target or the library search and the command
346            // line has not finished saying what those are.
347            "-dumpmachine" => query = Some(Query::Machine),
348            "-dumpversion" | "-dumpfullversion" => query = Some(Query::Version),
349            "-print-multiarch" => query = Some(Query::Multiarch),
350            "-print-search-dirs" => query = Some(Query::SearchDirs),
351            "-print-libgcc-file-name" => query = Some(Query::Libgcc),
352            _ if arg.starts_with("-print-file-name=") => {
353                query = Some(Query::FileName(arg["-print-file-name=".len()..].to_owned()));
354            }
355            _ if arg.starts_with("-print-prog-name=") => {
356                query = Some(Query::ProgName(arg["-print-prog-name=".len()..].to_owned()));
357            }
358            // A program built to run in more than one thread. On every platform this compiler
359            // targets that is a macro the library's headers read and one more library on the
360            // link line, and the library is added after the loop so that it lands after the
361            // objects that refer to it.
362            "-pthread" | "-pthreads" => {
363                opts.defines.push("_REENTRANT".to_owned());
364                threads = true;
365            }
366            "-ansi" => {
367                opts.std = Std::C89;
368                opts.gnu_extensions = false;
369            }
370            // `-Wpedantic` is the same flag under the name the `-W` family gives it, which is
371            // the spelling a build system that groups its warning flags tends to write.
372            "-pedantic" | "-Wpedantic" => opts.pedantic = true,
373            // Both directions, because a build that needs this for one directory turns it back
374            // off for the next one rather than leaving it on for the whole tree.
375            "-fpermissive" => opts.permissive = true,
376            "-fno-permissive" => opts.permissive = false,
377            "-ffreestanding" => opts.hosted = false,
378            "-fhosted" => opts.hosted = true,
379            "-fno-builtin" => opts.builtins = false,
380            "-fbuiltin" => opts.builtins = true,
381            // The C89 dialects are under GNU's reading whatever this says, so turning it off
382            // there is turning off something the dialect asked for, which is accepted and does
383            // nothing. gcc refuses that command line, and there is nothing it could have meant.
384            "-fgnu89-inline" => opts.gnu89_inline = true,
385            "-fno-gnu89-inline" => opts.gnu89_inline = false,
386            // Both directions of each, because a build system that wants one of these usually
387            // writes it beside the flag that turns it back off for one directory.
388            "-fno-omit-frame-pointer" => opts.frame_pointer = true,
389            "-fomit-frame-pointer" => opts.frame_pointer = false,
390            "-mno-red-zone" => opts.red_zone = false,
391            "-mred-zone" => opts.red_zone = true,
392            // Four flags rather than one with an argument, which is how gcc spells them and how
393            // every build line writes them. Last one wins, because a package build puts
394            // `-fstack-protector-strong` in its global flags and a directory that cannot have one
395            // turns it back off on the line after.
396            "-fno-stack-protector" | "-fno-stack-protector-all" | "-fno-stack-protector-strong" => {
397                opts.protector = Protector::None;
398            }
399            "-fstack-protector" => opts.protector = Protector::Buffers,
400            "-fstack-protector-strong" => opts.protector = Protector::Strong,
401            "-fstack-protector-all" => opts.protector = Protector::All,
402            // The other half of what a hardened build asks for, and it is a question about the
403            // frame rather than about the function, so it is a switch rather than a level.
404            "-fstack-clash-protection" => opts.stack_clash = true,
405            "-fno-stack-clash-protection" => opts.stack_clash = false,
406            // The third of them, and the one that is a question with an argument rather than a
407            // family of spellings, because what it asks about is which of the two edges of a
408            // control flow transfer is checked. Bare is both of them, which is what gcc does.
409            "-fcf-protection" => opts.control = Control::Full,
410            "-fno-cf-protection" => opts.control = Control::None,
411            // Two spellings of the same request, which is what gcc has as well. `-p` was the older
412            // profiler and `-pg` the one that also recorded who called whom, and on every platform
413            // this compiler targets there is now one hook and both ask for it.
414            "-pg" | "-p" => {
415                opts.profile = true;
416                link.profile = true;
417            }
418            // Accepted on their own and doing nothing on their own, which is gcc's behaviour: they
419            // say where the call goes and a command line that asked for no call has nowhere to put
420            // one. That matters because a build system that sets `-mfentry` globally and `-pg` per
421            // directory is a build system that would otherwise fail on every other directory.
422            "-mfentry" => opts.hook = Hook::Early,
423            "-mno-fentry" => opts.hook = Hook::Late,
424            // GCC drops its own include directory along with the system ones, because its
425            // headers are half of a pair with the library's and half a pair is worse than
426            // none. A build that passes this is supplying the whole set itself.
427            "-nostdinc" => nostdinc = true,
428            "-o" => {
429                output = Some(args.get(i).ok_or_else(|| err("-o requires an argument"))?.clone());
430                i += 1;
431            }
432            // The flags that take a directory only in the separated form. GCC spells them
433            // this way and nothing writes `-iquotedir`, so accepting the joined form would
434            // mean guessing at a path that starts with the flag's own letters.
435            // Apple's spelling of `--sysroot`, and the one its own build systems pass. The
436            // two mean the same thing here: the configured directories are under there rather
437            // than under the root.
438            "-isysroot" => {
439                let dir = args.get(i).ok_or_else(|| err("-isysroot requires an argument"))?;
440                i += 1;
441                sysroot = Some(PathBuf::from(dir));
442            }
443            "-iquote" | "-isystem" | "-idirafter" => {
444                let dir = args.get(i).ok_or_else(|| err(format!("{arg} requires an argument")))?;
445                i += 1;
446                match arg {
447                    "-iquote" => opts.search.push_quote(dir.clone()),
448                    "-isystem" => opts.search.push_system(dir.clone()),
449                    _ => opts.search.push_after(dir.clone()),
450                }
451            }
452            "-iprefix" => {
453                iprefix = args.get(i).ok_or_else(|| err("-iprefix requires an argument"))?.clone();
454                i += 1;
455            }
456            // Where GCC puts these is not where its manual says it puts them, and this is the
457            // measured answer rather than the documented one: `-iwithprefix` lands in the
458            // `-isystem` slot and not the `-idirafter` slot, and `-iwithprefixbefore` lands in
459            // the `-I` slot. A cross build that uses them is relying on the behaviour, since
460            // that is the compiler it was developed against.
461            "-iwithprefix" | "-iwithprefixbefore" => {
462                let dir = args.get(i).ok_or_else(|| err(format!("{arg} requires an argument")))?;
463                i += 1;
464                let dir = format!("{iprefix}{dir}");
465                if arg == "-iwithprefix" {
466                    opts.search.push_system(dir);
467                } else {
468                    opts.search.push_bracket(dir);
469                }
470            }
471            "-include" | "-imacros" => {
472                let name = args.get(i).ok_or_else(|| err(format!("{arg} requires an argument")))?;
473                i += 1;
474                opts.preincludes
475                    .push(Preinclude { name: name.clone(), macros_only: arg == "-imacros" });
476            }
477            // The flag `-iquote` was introduced to replace, still passed by build systems old
478            // enough to predate the replacement. It is not a directory: it says that every `-I`
479            // so far is for quoted includes only, and that a quoted include stops looking next
480            // to the file that wrote it.
481            "-I-" => opts.search.split_quote_chain(),
482            "-x" => {
483                let lang = args.get(i).ok_or_else(|| err("-x requires an argument"))?;
484                i += 1;
485                forced = if lang == "none" {
486                    None
487                } else {
488                    Some(InputKind::from_x_arg(lang).map_err(|e| err(format!("{e}")))?)
489                };
490            }
491            // Not a GCC flag. spec/03-architecture.md section 3.5 compiles several
492            // translation units in one process rather than making the build system fork, and
493            // section 3.8's determinism check compares `-j1` against `-j16`, so the knob has
494            // to exist and has to be spelled the way `make` spells it.
495            // `-DFOO`, `-D FOO` and the same for `-U` and `-I`. Both forms are in wide use
496            // and a build system may produce either, so both are read here rather than
497            // being normalised by whatever generated the command line.
498            _ if arg.starts_with("-D") => {
499                let value = joined_or_next(arg, 2, args, &mut i)?;
500                opts.defines.push(value);
501            }
502            _ if arg.starts_with("-U") => {
503                let value = joined_or_next(arg, 2, args, &mut i)?;
504                opts.undefines.push(value);
505            }
506            _ if arg.starts_with("-I") => {
507                let dir = joined_or_next(arg, 2, args, &mut i)?;
508                opts.search.push_bracket(dir);
509            }
510            _ if arg.starts_with("-std=") => {
511                let name = &arg["-std=".len()..];
512                let (std, gnu) = Std::from_flag(name)
513                    .ok_or_else(|| err(format!("unknown dialect `{name}`, see --help")))?;
514                opts.std = std;
515                opts.gnu_extensions = gnu;
516            }
517            // Section 4.5. The claim decides which half of glibc's `sys/cdefs.h` we are
518            // handed, so a differential run that does not set it is comparing two compilers
519            // that believe they are different compilers.
520            // GCC packs these into one flag, so `-dDI` is two of them. Letters in the family
521            // that we have not written yet are accepted and ignored, because a dump is a
522            // debugging aid and a build that asks for one should still compile. A letter
523            // outside the family falls through to the unknown option error, which is what
524            // keeps `-dumpversion` from being read as a dump of nothing.
525            _ if Dumps::is_family(arg) => {
526                opts.dumps.add(&arg[2..]);
527            }
528            // One name at a time, which is what a build that means its own `memcpy` and the
529            // library's everything else writes. The name is not checked against a list, because
530            // the flag is about what the program means by a name and a program is allowed to mean
531            // something by a name this compiler has never heard of.
532            _ if arg.starts_with("-fno-builtin-") => {
533                opts.no_builtin.push(arg["-fno-builtin-".len()..].to_owned());
534            }
535            _ if arg.starts_with("-fgnuc-version=") => {
536                let v = &arg["-fgnuc-version=".len()..];
537                opts.gnuc = v.parse().map_err(err)?;
538            }
539            // spec/13-gnu-compat.md section 13.3 promises this flag an error that says why rather
540            // than the unknown option one, because a build reaching for it is asking for a feature
541            // and deserves to be told it is not coming rather than told the spelling is wrong.
542            // The negative form is what this compiler does anyway, so it is taken and dropped.
543            "-fnested-functions" => {
544                return Err(err(
545                    "nested functions are not supported: a call to one goes through a trampoline \
546                     written on the stack, which no target that enforces an unexecutable stack \
547                     allows",
548                ));
549            }
550            "-fno-nested-functions" => {}
551            // Which of the two links the output is for, which is a real difference and not a
552            // description of what happens anyway. Everything here is position independent either
553            // way, and what these decide is whether a name may be one another object defines or
554            // replaces, because a link that produces an executable puts every name in the same
555            // program and a link that produces a shared library does not.
556            //
557            // It matters that they are accepted at all, whatever they then do. Every autoconf and
558            // cmake build puts `-fPIC` on the compile line, so a compiler that rejects it cannot
559            // be the `CC` of a project that has a configure script, whatever else it can do. That
560            // is how this was found: building SQLite's test fixture stopped on it.
561            "-fPIC" | "-fpic" => opts.pic = Pic::Library,
562            // Not a synonym of the pair above, which is what they were treated as until #756. The
563            // library is the expensive answer and gcc makes it the one that has to be asked for,
564            // so this is also what nothing at all means.
565            "-fPIE" | "-fpie" => opts.pic = Pic::Executable,
566            // A different question from the pair above, and the one every distribution build of a
567            // shared library answers. `-fPIC` decides how an address is reached, and this decides
568            // whether the optimizer may believe a body it can see, because an exported name is one
569            // the dynamic linker may find another definition of first. On by default, which is
570            // gcc's arrangement and is the honest answer, and off is a promise the build makes and
571            // nothing checks.
572            "-fsemantic-interposition" => opts.interposition = true,
573            "-fno-semantic-interposition" => opts.interposition = false,
574            // Two requests rather than one, and the same table answers both, so what decides is
575            // whether either of them is standing. gcc arranges it the same way: the asynchronous
576            // one is the default here and it implies the other, and a line that asks for a table
577            // and against an asynchronous one gets a table.
578            "-fasynchronous-unwind-tables" => opts.async_unwind_tables = true,
579            "-fno-asynchronous-unwind-tables" => opts.async_unwind_tables = false,
580            "-funwind-tables" => opts.unwind_tables = true,
581            "-fno-unwind-tables" => opts.unwind_tables = false,
582            // The other direction is a request, not a description, and it is one this compiler
583            // cannot grant, so it gets the treatment section 13.3 asks for rather than the unknown
584            // option error. Answering it by carrying on would be answering a different question:
585            // the code would still be position independent, which is correct everywhere an
586            // ordinary program runs and is wrong in a kernel, where the flag is written precisely
587            // because there is no loader to fill a global offset table in.
588            "-fno-pic" | "-fno-pie" => {
589                return Err(err(
590                    "position dependent code is not supported: an address that may be in another \
591                     object is loaded out of the global offset table, and nothing here emits the \
592                     absolute form this asks for. Use -no-pie if what you meant was how to link",
593                ));
594            }
595            // A section per function and a section per variable, which is what makes
596            // `--gc-sections` able to drop anything: a linker can leave out a section nothing
597            // reaches and cannot leave out half of one. Both directions are taken, and the off
598            // one is the default rather than a refusal, since a build that writes it is asking
599            // for what happens anyway.
600            "-ffunction-sections" => opts.function_sections = true,
601            "-fno-function-sections" => opts.function_sections = false,
602            "-fdata-sections" => opts.data_sections = true,
603            "-fno-data-sections" => opts.data_sections = false,
604            // Another description of what this compiler does. A file scope declaration with no
605            // initializer is written into `.bss` as an ordinary defined symbol, not offered to the
606            // linker as a common one for it to merge, which is what `-fno-common` asks for and what
607            // gcc has done by default since 10. Nothing in the front end produces `Linkage::Common`
608            // at all.
609            "-fno-common" => {}
610            // What overflows rather than being undefined. Every one of these takes something away
611            // from the optimizer rather than asking it to do anything, which is why the negative
612            // spellings are the interesting ones and the positive spellings are the default.
613            //
614            // `-fno-strict-overflow` is both of the others, which is gcc's own reading of it: its
615            // help text for `-fstrict-overflow` says "negated as -fwrapv -fwrapv-pointer". So it is
616            // written here as the pair rather than kept as a third thing to test everywhere.
617            //
618            // `-ftrapv` is the exception and is the one that asks for something. It is the other
619            // answer to the question `-fwrapv` answers, so the two cannot both hold and each clears
620            // the other, which makes the last one on the command line the one that counts. That is
621            // gcc 16's behaviour and was measured rather than read: `-ftrapv -fwrapv` emits no
622            // checked calls and `-fwrapv -ftrapv` emits them. The positive spelling of the pointer
623            // question is left alone by both, because neither has anything to say about it.
624            "-fwrapv" => {
625                opts.wrapping.signed = true;
626                opts.wrapping.trap = false;
627            }
628            "-fno-wrapv" => opts.wrapping.signed = false,
629            "-fwrapv-pointer" => opts.wrapping.pointer = true,
630            "-fno-wrapv-pointer" => opts.wrapping.pointer = false,
631            "-fno-strict-overflow" => opts.wrapping = Wrapping::ALL,
632            // Which does not clear the checked one, because gcc does not: `-ftrapv
633            // -fstrict-overflow` still emits the calls. It says what is assumed and not what
634            // happens.
635            "-fstrict-overflow" => {
636                opts.wrapping.signed = false;
637                opts.wrapping.pointer = false;
638            }
639            "-ftrapv" => {
640                opts.wrapping.trap = true;
641                opts.wrapping.signed = false;
642            }
643            "-fno-trapv" => opts.wrapping.trap = false,
644            // And the request, which is the one that cannot be granted. It is a real difference and
645            // not a preference: two files each writing `int g;` link under `-fcommon` and are a
646            // duplicate definition without it, which is the whole reason the flag survives.
647            "-fcommon" => {
648                return Err(err(
649                    "a tentative definition is written into .bss as its own symbol here, and \
650                     nothing emits the common symbol this asks the linker to merge. Give the \
651                     variable a definition in one file and declare it extern in the others",
652                ));
653            }
654            // Both directions of this one are taken, which is the exception to the rule above, and
655            // the reason is which way being wrong costs something.
656            //
657            // Nothing here derives anything from the type an object is accessed through. The IR has
658            // somewhere to put a type based aliasing node and lowering fills it with nothing on
659            // every access, so no pass has one to read and the alias analysis falls back to what it
660            // can see. That makes `-fno-strict-aliasing` a description, the way `-fPIC` is.
661            //
662            // `-fstrict-aliasing` is a request to assume more than that, and this compiler assumes
663            // less. Answering a request for a weaker guarantee by giving a stronger one is safe in
664            // a way the `-fno-pic` case is not: every program that is correct under the assumption
665            // is correct without it, only slower. And `-O2` implies it, so a build that spells it
666            // out is a build that would stop on a compiler that refused it, for no gain at all.
667            "-fstrict-aliasing" | "-fno-strict-aliasing" => {}
668            // About temporary files rather than about code. There is nothing between the phases of
669            // one compilation here to write to a file in the first place.
670            "-pipe" => {}
671            // Nothing here writes colour, so all of these are the same answer, and it is the answer
672            // that costs nothing: the diagnostics come out plain either way and no build depends on
673            // an escape sequence being there. Taken rather than refused because cmake writes
674            // `-fdiagnostics-color=always` on every compile line when the generator is ninja, which
675            // makes this the second most common flag after `-fPIC` to stop a build over a question
676            // about how the text looks.
677            "-fdiagnostics-color" | "-fno-diagnostics-color" => {}
678            _ if arg.starts_with("-fdiagnostics-color=") => {}
679            // The link flags. None of them changes the compilation, which is why they are
680            // collected apart from `opts` and why `-lm` on a `-c` line is a note rather than an
681            // error: it is a thing said to a linker that is not going to run.
682            "-static" => link.is_static = true,
683            "-shared" => link.shared = true,
684            "-pie" => link.pie = Some(true),
685            "-no-pie" | "-nopie" => link.pie = Some(false),
686            "-nostdlib" => link.no_stdlib = true,
687            "-nostartfiles" => link.no_startfiles = true,
688            "-nodefaultlibs" => link.no_defaultlibs = true,
689            "-fno-builtins-lib" => link.no_builtins_lib = true,
690            "-fbuiltins-lib" => link.no_builtins_lib = false,
691            "-rdynamic" | "-export-dynamic" => link.export_dynamic = true,
692            "-s" => link.strip = true,
693            "-Xlinker" => {
694                let next = args.get(i).ok_or_else(|| err("-Xlinker requires an argument"))?;
695                i += 1;
696                link.passthrough.push(next.clone());
697            }
698            _ if arg.starts_with("-Wl,") => {
699                // Commas separate arguments rather than being part of one, which is what makes
700                // `-Wl,-rpath,/opt/lib` two words to the linker and one word here.
701                link.passthrough.extend(arg["-Wl,".len()..].split(',').map(str::to_owned));
702            }
703            _ if arg.starts_with("-fuse-ld=") => {
704                link.use_ld = Some(arg["-fuse-ld=".len()..].to_owned());
705            }
706            _ if arg.starts_with("-l") && arg.len() > 2 => {
707                inputs.push(Input::library(&arg[2..]));
708            }
709            "-l" => {
710                let next = args.get(i).ok_or_else(|| err("-l requires an argument"))?;
711                i += 1;
712                inputs.push(Input::library(next));
713            }
714            _ if arg.starts_with("-L") => {
715                link.search.push(PathBuf::from(joined_or_next(arg, 2, args, &mut i)?));
716            }
717            _ if arg.starts_with("-B") => {
718                link.prefixes.push(PathBuf::from(joined_or_next(arg, 2, args, &mut i)?));
719            }
720            _ if arg.starts_with("-j") => {
721                jobs = Jobs::parse(&arg[2..]).map_err(err)?;
722            }
723            _ if arg.starts_with("--sysroot=") => {
724                sysroot = Some(PathBuf::from(&arg["--sysroot=".len()..]));
725            }
726            _ if arg.starts_with("--target=") => {
727                let t = &arg["--target=".len()..];
728                opts.target = t.parse().map_err(|e| err(format!("{e}")))?;
729            }
730            _ if arg.starts_with("--emit=") => {
731                let k = &arg["--emit=".len()..];
732                opts.emit = k
733                    .parse()
734                    .map_err(|()| err(format!("unknown --emit kind `{k}`, see --help")))?;
735            }
736            // A bare `-O` is `-O1`, which is what GCC has and what a hand written makefile tends
737            // to write. `-Og` is GCC's level for a build somebody is going to step through, and
738            // it is `-O1` with the transformations that move code around left out; this compiler
739            // has no such level yet, so it is the nearest one and `--print-pipeline` says what
740            // that came to rather than the flag pretending otherwise.
741            "-O" | "-Og" => opts.opt_level = rucc_session::OptLevel::O1,
742            // The union of `-O3` and `-ffast-math`, and the second half of that changes what
743            // floating point arithmetic means. Refused rather than taken as `-O3`, because a
744            // build that asks for fast math and is quietly given ordinary arithmetic gets a
745            // slower program than it asked for and a build that is given fast math it did not
746            // ask for gets a wrong one.
747            "-Ofast" => {
748                return Err(err(
749                    "-Ofast is -O3 with fast math, and fast math is not implemented, see \
750                     spec/04-driver-and-cli.md section 4.6",
751                ));
752            }
753            _ if arg.starts_with("-O") => {
754                opts.opt_level = arg[2..]
755                    .parse()
756                    .map_err(|()| err(format!("unknown optimization level `{arg}`")))?;
757            }
758            // What every name gets when nothing in the source said, which the attribute in the
759            // source overrides rather than the other way round. Before the optimizer's `-f`
760            // family below for the reason the tier below it is.
761            _ if arg.starts_with("-fvisibility=") => {
762                let seen = &arg["-fvisibility=".len()..];
763                opts.visibility = seen.parse().map_err(|()| {
764                    err(format!(
765                        "`{seen}` is not a visibility, which is default, hidden, internal or \
766                         protected"
767                    ))
768                })?;
769            }
770            // Which edges of a control flow transfer are checked. Before the optimizer's `-f`
771            // family below for the reason the two above it are, and last of the three so that the
772            // bare spelling and the negative one are matched exactly rather than by this.
773            _ if arg.starts_with("-fcf-protection=") => {
774                let edges = &arg["-fcf-protection=".len()..];
775                opts.control = edges.parse().map_err(|()| {
776                    err(format!(
777                        "`{edges}` is not a control flow protection, which is full, branch, \
778                         return, none or check"
779                    ))
780                })?;
781            }
782            // How much room every function opens with for something to be written over later.
783            // Before the optimizer's `-f` family below for the reason the ones above it are.
784            _ if arg.starts_with("-fpatchable-function-entry=") => {
785                let room = &arg["-fpatchable-function-entry=".len()..];
786                opts.patchable = room.parse().map_err(|()| {
787                    err(format!(
788                        "`{room}` is not an amount of room to reserve, which is a number of bytes                          and then, after a comma, how many of them go in front of the function's                          own label"
789                    ))
790                })?;
791            }
792            // The memory safety monitor, from section 15.4 of
793            // `spec/safe-memory/15-integration.md`. Before the optimizer's `-f` family below,
794            // because a pass that took the name `safety=detect` would otherwise be handed the
795            // flag, and the tier is not a pass.
796            _ if arg.starts_with("-fsafety=") => {
797                let tier = &arg["-fsafety=".len()..];
798                opts.safety = tier.parse().map_err(|()| {
799                    err(format!(
800                        "`{tier}` is not a safety tier, which is off, detect, enforce or kernel"
801                    ))
802                })?;
803            }
804            // The optimizer's own flags, from section 9.10 of `spec/09-optimizer.md`. These come
805            // after every `-f` the rest of the compiler answers to, so a pass can never take a
806            // name that already means something else on the command line.
807            _ if arg.starts_with("-fpass-fuel=") => {
808                let (name, count) = arg["-fpass-fuel=".len()..]
809                    .split_once('=')
810                    .ok_or_else(|| err("-fpass-fuel= is spelled <pass>=<count>"))?;
811                if rucc_opt::pass::find(name).is_none() {
812                    return Err(err(format!(
813                        "`{name}` is not a pass this compiler has, see --print-pipeline"
814                    )));
815                }
816                let count: u32 = count
817                    .parse()
818                    .map_err(|_| err(format!("`{count}` is not a number of transformations")))?;
819                opts.pass_fuel.push((name.to_owned(), count));
820            }
821            _ if arg.starts_with("-fpass-fuel-global=") => {
822                let count = &arg["-fpass-fuel-global=".len()..];
823                let count: u32 = count
824                    .parse()
825                    .map_err(|_| err(format!("`{count}` is not a number of transformations")))?;
826                opts.pass_fuel_global = Some(count);
827            }
828            // Everything from `-fopt-info` to the end of the argument, which is optional
829            // keywords joined by hyphens and an optional `=<file>`. Checked here rather than
830            // where the remarks are printed, because by then the compilation somebody wanted
831            // to hear about is over.
832            _ if arg == "-fopt-info"
833                || arg.starts_with("-fopt-info=")
834                || arg.starts_with("-fopt-info-") =>
835            {
836                let rest = &arg["-fopt-info".len()..];
837                let (kinds, file) = match rest.split_once('=') {
838                    Some((kinds, file)) => (kinds, Some(file)),
839                    None => (rest, None),
840                };
841                let kinds = kinds.strip_prefix('-').unwrap_or(kinds);
842                rucc_opt::Wants::none().add(kinds).map_err(err)?;
843                opts.opt_info.push(kinds.to_owned());
844                if let Some(file) = file {
845                    if file.is_empty() {
846                        return Err(err("-fopt-info= was given no file to write to"));
847                    }
848                    opts.opt_info_file = Some(file.to_owned());
849                }
850            }
851            _ if arg.starts_with("-fdump-ir=") => {
852                // Checked here rather than where the dumps are taken, because the compilation
853                // that would have been dumped is over by then.
854                let spec = &arg["-fdump-ir=".len()..];
855                rucc_opt::Dumps::default().add(spec).map_err(err)?;
856                opts.dump_ir.push(spec.to_owned());
857            }
858            // Before the bare `-f<pass>` below, because a pass called `enable-something` would
859            // otherwise take the flag away from the gate. Checked here rather than where the
860            // pipeline reads it, for the reason that applies to all of these: a misspelled pass
861            // name that quietly gated nothing looks exactly like a pass that is not the guilty
862            // one, and a bisection would carry on past the thing it was looking for.
863            _ if arg.starts_with("-fdisable-") || arg.starts_with("-fenable-") => {
864                let on = arg.starts_with("-fenable-");
865                let spec = &arg[if on { "-fenable-".len() } else { "-fdisable-".len() }..];
866                rucc_opt::Gates::default().add(on, spec).map_err(err)?;
867                opts.pass_gates.push((on, spec.to_owned()));
868            }
869            _ if arg.strip_prefix("-fno-").is_some_and(|n| rucc_opt::pass::find(n).is_some()) => {
870                opts.passes.push((arg["-fno-".len()..].to_owned(), false));
871            }
872            _ if arg.strip_prefix("-f").is_some_and(|n| rucc_opt::pass::find(n).is_some()) => {
873                opts.passes.push((arg["-f".len()..].to_owned(), true));
874            }
875            // The unstable options, spelled the way rustc spells them and carrying the same
876            // promise, which is none: one of these may change or go away in any release. They are
877            // measurements and debugging aids rather than things a build asks for, which is why
878            // none of them is in the usage text and all of them are in section 4.11 of
879            // `spec/04-driver-and-cli.md`.
880            "-Zverify-each" => opts.verify_each = true,
881            _ if arg.starts_with("-Zrule-coverage=") => {
882                let file = &arg["-Zrule-coverage=".len()..];
883                if file.is_empty() {
884                    return Err(err("-Zrule-coverage= needs a file to write to"));
885                }
886                opts.rule_coverage = Some(file.to_owned());
887            }
888            _ if arg.starts_with("-Zregister-pressure=") => {
889                let file = &arg["-Zregister-pressure=".len()..];
890                if file.is_empty() {
891                    return Err(err("-Zregister-pressure= needs a file to write to"));
892                }
893                opts.register_pressure = Some(file.to_owned());
894            }
895            _ if arg.starts_with("-Z") => {
896                return Err(err(format!(
897                    "`{arg}` is not an unstable option this compiler has, see \
898                     spec/04-driver-and-cli.md section 4.11 for the ones it does"
899                )));
900            }
901            // The word size, which is a statement about the target and is taken as one. A build
902            // that says the size the target already has is saying nothing, and one that says the
903            // other size is asking for a target this compiler does not have, which it is told
904            // rather than being given the wrong one.
905            "-m64" | "-m32" | "-mx32" => {
906                let want: u32 = match arg {
907                    "-m64" => 64,
908                    _ => 32,
909                };
910                let have = rucc_target::TargetInfo::new(opts.target).pointer_width;
911                if have != want {
912                    return Err(err(format!(
913                        "{arg} asks for a {want} bit target and {} is {have} bit, use \
914                         --target= to name the one you mean",
915                        opts.target
916                    )));
917                }
918            }
919            // Which processor in the family to generate for. This compiler emits the base
920            // instruction set of the architecture and nothing above it, so a program built with
921            // any of these runs on the machine that was named; it is a program that could have
922            // been faster rather than a program that is wrong, which is what makes these safe to
923            // take and ignore where a flag that changed the meaning of the code would not be.
924            _ if arg.starts_with("-march=")
925                || arg.starts_with("-mtune=")
926                || arg.starts_with("-mcpu=") => {}
927            // The calling convention, which is not safe to ignore. Taken when it names the one
928            // the target already uses and refused otherwise.
929            _ if arg.starts_with("-mabi=") => {
930                let want = &arg["-mabi=".len()..];
931                let have = match opts.target.arch {
932                    rucc_target::Arch::X86_64 => "sysv",
933                    rucc_target::Arch::Aarch64 => "lp64",
934                    rucc_target::Arch::Riscv64 => "lp64d",
935                };
936                if want != have {
937                    return Err(err(format!(
938                        "{arg}: {} uses the {have} convention and this compiler has no other",
939                        opts.target
940                    )));
941                }
942            }
943            // How far apart the pieces of the program may be. The small model is what we emit and
944            // it is every hosted program's default; the kernel model is a different one and a
945            // build that asks for it and does not get it links and then does not run.
946            "-mcmodel=small" => {}
947            _ if arg.starts_with("-mcmodel=") => {
948                return Err(err(format!(
949                    "{arg}: this compiler emits the small code model and no other, see \
950                     spec/12-targets.md"
951                )));
952            }
953            // GCC's own scripting language for how the driver builds a command line.
954            // `spec/04-driver-and-cli.md` section 4.4 settles that we will not have it, so a
955            // build reaching for it is told which flags do the same job.
956            _ if arg.starts_with("-specs=") => {
957                return Err(err(
958                    "-specs= is not supported: the parts of it builds rely on are -B, -L, \
959                     -nostdlib, -nostartfiles and -Wl,, see spec/04-driver-and-cli.md \
960                     section 4.4",
961                ));
962            }
963            // Arguments meant for a separate assembler or preprocessor, which this compiler does
964            // not have: both are inside it and neither reads a command line. Refused rather than
965            // dropped, because every one of these says something about the output and a build
966            // that asked for `-Wa,--noexecstack` and was silently given an executable stack got
967            // the opposite of what it asked for.
968            _ if arg.starts_with("-Wa,") || arg.starts_with("-Wp,") => {
969                return Err(err(format!(
970                    "`{arg}` is an argument for a separate assembler or preprocessor, and both \
971                     are inside this compiler rather than programs it runs"
972                )));
973            }
974            "-Xassembler" | "-Xpreprocessor" => {
975                return Err(err(format!(
976                    "{arg} hands an argument to a separate assembler or preprocessor, and both \
977                     are inside this compiler rather than programs it runs"
978                )));
979            }
980            // Everything else in the `-W` family. `spec/04-driver-and-cli.md` section 4.1 has
981            // this one as a rule about build systems rather than about warnings: autoconf finds
982            // out whether a warning flag exists by passing it and looking at the exit status, so
983            // a compiler that refuses one it has not heard of fails a configure script written
984            // for a GCC newer than itself. The names are not checked against a list because this
985            // compiler has no warning groups for a list to be of, which #485 is about.
986            _ if arg.starts_with("-W") => {}
987            // Flags that name something this compiler does not do and would not do differently
988            // if it did. `-fno-ident` is about a comment in the output that we do not write
989            // either way, and the others are about a way of ordering the compilation that has
990            // been GCC's only way for twenty years. Section 4.1 asks for the list to be short
991            // and for adding to it to be deliberate, which is why it is written out here.
992            "-fno-ident"
993            | "-fident"
994            | "-funit-at-a-time"
995            | "-fno-unit-at-a-time"
996            | "-shared-libgcc"
997            | "-static-libgcc" => {}
998            _ if arg.starts_with('-') && arg.len() > 1 => {
999                // Silently ignoring an unknown flag is how a build ends up not doing what
1000                // its author asked. spec/13-gnu-compat.md section 13.4 makes this an error
1001                // for the flags that change code generation, and the safe default until the
1002                // flag table is populated is to reject everything we do not know.
1003                return Err(err(format!("unknown option `{arg}`")));
1004            }
1005            _ => inputs.push(Input { path: arg.to_owned(), forced, library: false }),
1006        }
1007    }
1008
1009    // Last, so that it lands after every `-isystem` the command line gave. That is GCC's
1010    // order: a directory the user names outranks the compiler's own, and the compiler's own
1011    // outranks the library's. It is pushed after the loop rather than before it because
1012    // `SearchPath` appends within a group and the position is what the order is.
1013    // The same directory the headers were looked for under, because a sysroot is a statement
1014    // about a whole installation and not about half of one.
1015    link.sysroot = sysroot.clone();
1016    // After the loop rather than where `-pthread` was read, so that it lands after the objects
1017    // that refer to it. A static link takes the definitions it needs from a library when it
1018    // reaches it and not afterwards, so a library before the objects is a library that answers
1019    // nothing.
1020    if threads {
1021        inputs.push(Input::library("pthread"));
1022    }
1023    if let Some(query) = query {
1024        return Ok(Action::Print(answer(&query, &opts, &link)));
1025    }
1026    // `-M` and `-MM` produce the rule and nothing else, so the run stops after phase 4 whatever
1027    // else the command line asked for. Read here rather than where the flag was, because a `-c`
1028    // written after it has to lose and the loop cannot know that until it has ended. The output
1029    // file is where the rule goes rather than where an object would have gone, and the last
1030    // phase being the preprocessor is what makes that true without a second rule for it.
1031    if opts.deps.instead_of_compiling {
1032        opts.emit = EmitKind::Preprocessed;
1033    }
1034    if !nostdinc {
1035        opts.search.push_system(runtime::DIR);
1036        // And the library's after ours, which is the other half of the same order. They go on
1037        // here rather than at the point `--target=` or `--sysroot=` was read because either
1038        // one changes the answer and the last word on both is the end of the loop.
1039        for dir in library::system_dirs(opts.target, sysroot.as_deref()) {
1040            opts.search.push_system(dir);
1041        }
1042    }
1043    // Once, here, rather than as each directory is pushed. A `-I` that names a system
1044    // directory has to lose to the system entry and the system entry is added last, so the
1045    // question cannot be answered until the whole path is known.
1046    opts.search.remove_duplicates();
1047
1048    // The target has to be resolved before the configuration is printed, so this check comes
1049    // after the loop rather than at the point `--print-config` was seen.
1050    if print_config {
1051        return Ok(Action::PrintConfig(Box::new(opts)));
1052    }
1053    if print_pipeline {
1054        return Ok(Action::PrintPipeline(Box::new(opts)));
1055    }
1056    let plan = Plan::new(&opts, &inputs, output.as_deref()).map_err(|e| err(e.message))?;
1057    if print_plan {
1058        return Ok(Action::PrintPlan {
1059            opts: Box::new(opts),
1060            plan: Box::new(plan),
1061            link: Box::new(link),
1062        });
1063    }
1064    Ok(Action::Compile {
1065        opts: Box::new(opts),
1066        plan: Box::new(plan),
1067        link: Box::new(link),
1068        jobs,
1069        verbose,
1070    })
1071}
1072
1073/// What one of the `-dump` and `-print` flags prints.
1074///
1075/// GCC prints the name back unchanged when it cannot find the file a `-print` flag asked about,
1076/// which is what makes the answer safe to paste into a link line whether or not the file is
1077/// there, and this does the same.
1078fn answer(query: &Query, opts: &Options, link: &LinkOptions) -> String {
1079    let found = |name: &str| {
1080        link::find_in_search(link, opts.target, name)
1081            .map_or_else(|| name.to_owned(), |path| path.display().to_string())
1082    };
1083    match query {
1084        Query::Machine => opts.target.to_string(),
1085        Query::Version => VERSION.to_owned(),
1086        Query::Multiarch => link::multiarch(opts.target),
1087        // The three lines GCC prints, in its order and with its punctuation, because what reads
1088        // them is a script written against that shape. There is no installation directory to
1089        // report: this compiler is one binary that works wherever it is copied, and the headers
1090        // it ships are inside it, so `install` is where the binary is and nothing is under it.
1091        Query::SearchDirs => {
1092            let here = std::env::current_exe()
1093                .ok()
1094                .and_then(|p| p.parent().map(std::path::Path::to_path_buf))
1095                .unwrap_or_default();
1096            let list = |dirs: &[PathBuf]| {
1097                dirs.iter().map(|d| d.display().to_string()).collect::<Vec<_>>().join(":")
1098            };
1099            let libraries = link::search_dirs(link, opts.target);
1100            format!(
1101                "install: {}\nprograms: ={}\nlibraries: ={}",
1102                here.display(),
1103                list(&link.prefixes),
1104                list(&libraries)
1105            )
1106        }
1107        Query::FileName(name) => found(name),
1108        // The name GCC gives the library of routines a compiler's output calls that the C
1109        // library does not have. Ours is built in and there is no file, so the answer is the
1110        // name itself, which is what GCC prints when it cannot find one either.
1111        Query::Libgcc => found("libgcc.a"),
1112        // A program rather than a library: the linker and the archiver are the ones a build asks
1113        // about, and this compiler finds them on the path or under `-B` rather than shipping
1114        // them, so the name back is the honest answer unless a `-B` prefix holds one.
1115        Query::ProgName(name) => link
1116            .prefixes
1117            .iter()
1118            .map(|dir| dir.join(name))
1119            .find(|path| path.is_file())
1120            .map_or_else(|| name.clone(), |path| path.display().to_string()),
1121    }
1122}
1123
1124/// Renders the passes this level will run, in order, with what each one does.
1125///
1126/// The level is the whole of the answer unless a `-f` flag edited it, which is section 9.1 of
1127/// `spec/09-optimizer.md`: a level is a list somebody wrote down rather than something that
1128/// emerges from which flags happen to be set, and this is how that list is read.
1129#[must_use]
1130pub fn print_pipeline(opts: &Options) -> String {
1131    let mut settings = rucc_opt::Options::for_level(opts.opt_level);
1132    settings.toggles.clone_from(&opts.passes);
1133    settings.global_fuel = opts.pass_fuel_global;
1134    for (on, spec) in &opts.pass_gates {
1135        // Every spelling was checked while the arguments were parsed, so there is nothing here
1136        // this can refuse, and a listing is not the place to report it if there were.
1137        let _ = settings.gates.add(*on, spec);
1138    }
1139    rucc_opt::pipeline::print(&settings)
1140}
1141
1142/// Renders the resolved configuration.
1143///
1144/// One `key: value` per line, sorted by nothing in particular but fixed in order, because
1145/// this output is diffed across hosts in CI and a reordering would read as a change.
1146#[must_use]
1147pub fn print_config(opts: &Options) -> String {
1148    let sess = Session::new(opts.clone());
1149    let t = &sess.target;
1150    let mut out = String::new();
1151    let _ = writeln!(out, "version: {VERSION}");
1152    // The three field triple the driver was given rather than the ten field tuple it widens to,
1153    // because this output is what a build system reads to find out what it asked for. The tuple is
1154    // the compiler's model of the machine and this line is a receipt for a command line.
1155    let _ = writeln!(out, "target: {}", opts.target);
1156    let _ = writeln!(out, "arch: {}", opts.target.arch.as_str());
1157    let _ = writeln!(out, "os: {}", opts.target.os.as_str());
1158    let _ = writeln!(out, "env: {}", opts.target.env.as_str());
1159    let _ = writeln!(out, "object-format: {}", t.object_format.as_str());
1160    let _ = writeln!(out, "pointer-width: {}", t.pointer_width);
1161    let _ = writeln!(out, "long-width: {}", t.long_width);
1162    let _ = writeln!(out, "long-double-width: {}", t.long_double_width);
1163    let _ = writeln!(out, "endian: {}", if t.little_endian { "little" } else { "big" });
1164    let _ = writeln!(out, "char-signed: {}", t.char_is_signed);
1165    let _ = writeln!(out, "va-list: {}", t.va_list.map_or("none", |list| list.as_str()));
1166    // The register file as a count per class, which is enough to tell a target whose registers
1167    // are described from one whose are not without printing sixteen names nobody asked for.
1168    let regs: Vec<String> = t
1169        .regs
1170        .classes()
1171        .map(|(class, info)| format!("{} {}", info.name, t.regs.len(class)))
1172        .collect();
1173    let _ = writeln!(
1174        out,
1175        "registers: {}",
1176        if regs.is_empty() { "none".to_string() } else { regs.join(", ") }
1177    );
1178    let _ = writeln!(out, "opt-level: {}", sess.opts.opt_level);
1179    let _ = writeln!(out, "safety: {}", sess.opts.safety);
1180    let _ = writeln!(out, "emit: {}", sess.opts.emit.as_str());
1181    let _ = writeln!(out, "debug-info: {}", sess.opts.debug_info);
1182    let _ = writeln!(out, "frame-pointer: {}", sess.opts.frame_pointer);
1183    let _ = writeln!(out, "red-zone: {}", sess.opts.red_zone);
1184    let _ = writeln!(out, "stack-protector: {}", sess.opts.protector);
1185    let _ = writeln!(out, "stack-clash-protection: {}", sess.opts.stack_clash);
1186    let _ = writeln!(out, "cf-protection: {}", sess.opts.control);
1187    let _ = writeln!(out, "patchable-function-entry: {}", sess.opts.patchable);
1188    let _ = writeln!(out, "profile: {}", sess.opts.profile);
1189    let _ = writeln!(out, "profile-hook: {}", sess.opts.hook);
1190    // Last because it is the one key with more than one line under it, and the only one
1191    // whose value is a property of the machine rather than of the command line.
1192    for dir in sess.opts.search.dirs() {
1193        let system = if dir.is_system { " (system)" } else { "" };
1194        let _ = writeln!(out, "include: {}{system}", dir.path.display());
1195    }
1196    out
1197}
1198
1199/// The output name the make target is taken from, which is the `-o` argument or nothing.
1200///
1201/// A run that stops at the preprocessor has not named an object, whatever its `-o` says: under
1202/// `-E` that argument is the preprocessed text and under `-M` it is the rule itself, and neither
1203/// is a file `make` would rebuild by running this rule. GCC agrees and falls back to the source
1204/// name in both, which is why a `-MD -E -o out.i` writes `out.d` holding a rule for `a.o`. From
1205/// `-S` on the argument does name what the rule builds, and it is used as written.
1206fn deps_target_output<'a>(opts: &Options, plan: &'a Plan) -> Option<&'a str> {
1207    if opts.emit == EmitKind::Preprocessed { None } else { plan.output.as_deref() }
1208}
1209
1210/// Writes to a path the command line named rather than one the plan derived, where `-` is
1211/// standard output.
1212fn write_named(path: &str, bytes: &[u8]) -> Result<(), String> {
1213    if path == "-" {
1214        return write_out(&Output::Stdout, bytes);
1215    }
1216    write_out(&Output::File(path.to_owned()), bytes)
1217}
1218
1219/// Writes the make rule for one input, and reports whether it got there.
1220///
1221/// A rule with no file of its own goes where the compilation it replaced would have written,
1222/// which is what makes the usual makefile recipe work: `rucc -M $< -o $@` leaves the rule in
1223/// `$@`, and the same line with the `-o` left off puts it on standard output.
1224fn write_deps(
1225    opts: &Options,
1226    plan: &Plan,
1227    job: &Job,
1228    found: &[Dependency],
1229    stderr: &mut impl std::io::Write,
1230) -> bool {
1231    let targets = if opts.deps.targets.is_empty() {
1232        vec![deps::default_target(&job.input, deps_target_output(opts, plan))]
1233    } else {
1234        opts.deps.targets.clone()
1235    };
1236    let rule = deps::rule(&opts.deps, &targets, &job.input, found);
1237    // The file, on the other hand, is named after the `-o` in every mode that still has one to
1238    // spend, which is every mode except the two that spend it on the rule.
1239    let wrote = match deps::default_file(&opts.deps, &job.input, plan.output.as_deref()) {
1240        // A `-MF` on a run that had nowhere else to put the rule leaves the file the `-o`
1241        // named empty rather than absent, because a makefile that named it as a target of its
1242        // own is a makefile that will look for it.
1243        Some(path) => write_named(&path, rule.as_bytes()).and_then(|()| {
1244            if opts.deps.instead_of_compiling { write_out(&job.output, b"") } else { Ok(()) }
1245        }),
1246        None => write_out(&job.output, rule.as_bytes()),
1247    };
1248    if let Err(e) = wrote {
1249        let _ = writeln!(stderr, "rucc: error: {e}");
1250        return false;
1251    }
1252    true
1253}
1254
1255/// Runs phase 4 over every input that has one, and writes what came out.
1256///
1257/// One input that fails does not stop the others. A build that reports every file it could
1258/// not preprocess in one run is worth more than one that stops at the first, and the exit
1259/// status is still a failure either way.
1260fn preprocess_all(opts: &Options, plan: &Plan) -> i32 {
1261    let fs = OsFileSystem::new();
1262    let mut stderr = std::io::stderr().lock();
1263    let mut failed = false;
1264    for job in &plan.jobs {
1265        if !job.phases.first().is_some_and(|p| *p == Phase::Preprocess) {
1266            // An input that is already preprocessed, or an object file. GCC passes these
1267            // through untouched, and the plan has already said so in its notes.
1268            continue;
1269        }
1270        let started = std::time::Instant::now();
1271        let result = preprocess(opts, &job.input, &fs);
1272        if opts.time {
1273            say_time(&job.input, started.elapsed(), &mut stderr);
1274        }
1275        for message in &result.messages {
1276            let _ = writeln!(stderr, "{message}");
1277        }
1278        if result.failed() {
1279            failed = true;
1280            continue;
1281        }
1282        if opts.deps.emit {
1283            failed |= !write_deps(opts, plan, job, &result.deps, &mut stderr);
1284            // `-M` and `-MM` asked for the rule instead of the text, so there is nothing else
1285            // to write. The other two asked for both and fall through to the text below.
1286            if opts.deps.instead_of_compiling {
1287                continue;
1288            }
1289        }
1290        if let Err(e) = write_out(&job.output, result.text.as_bytes()) {
1291            let _ = writeln!(stderr, "rucc: error: {e}");
1292            failed = true;
1293        }
1294    }
1295    i32::from(failed)
1296}
1297
1298/// Runs the front end over every input that has a compile phase, and writes what came out.
1299///
1300/// The same rule as [`preprocess_all`]: one input that fails does not stop the others, and the
1301/// exit status is a failure either way. An input that is already assembly or an object has no
1302/// compile phase and is passed over here, which the plan has already said in its notes.
1303fn compile_all(opts: &Options, plan: &Plan) -> i32 {
1304    let fs = OsFileSystem::new();
1305    let mut stderr = std::io::stderr().lock();
1306    let mut failed = false;
1307    let (mut remarks, ok) = Remarks::new(opts.opt_info_file.as_ref(), &mut stderr);
1308    failed |= !ok;
1309    let mut fired = Fired::new();
1310    let mut pressure = Pressure::new();
1311    for job in &plan.jobs {
1312        if !job.phases.contains(&Phase::Compile) {
1313            continue;
1314        }
1315        // An input of IR is read back rather than compiled, since the C it came from is not
1316        // here any more. Everything after this is the same, so the two paths meet again at the
1317        // messages and the file the result is written to.
1318        let started = std::time::Instant::now();
1319        let result = if job.kind == InputKind::Ir {
1320            compile_ir(opts, &job.input, &fs)
1321        } else {
1322            compile(opts, &job.input, &fs)
1323        };
1324        if opts.time {
1325            say_time(&job.input, started.elapsed(), &mut stderr);
1326        }
1327        fired.merge(&result.fired);
1328        pressure.merge(&result.pressure);
1329        failed |= !write_dumps(&job.input, &result.dumps, &mut stderr);
1330        failed |= !remarks.write(&result.remarks, &mut stderr);
1331        for message in &result.messages {
1332            let _ = writeln!(stderr, "{message}");
1333        }
1334        // Before the failure below, because a compilation that stopped in the back end is exactly
1335        // the one whose preprocessed source somebody wants to look at.
1336        failed |= !write_temps(job, &result.temps, &mut stderr);
1337        if result.failed() {
1338            failed = true;
1339            continue;
1340        }
1341        // `-MD` and `-MMD` write the rule beside the object and let the compilation happen, so
1342        // this is the one path where both files come out of the same run. An input of IR has no
1343        // dependencies to report and produces an empty list, which produces a rule naming only
1344        // itself, and that is the honest answer rather than a missing file.
1345        if opts.deps.emit {
1346            failed |= !write_deps(opts, plan, job, &result.deps, &mut stderr);
1347        }
1348        if let Err(e) = write_out(&job.output, result.artifact.bytes()) {
1349            let _ = writeln!(stderr, "rucc: error: {e}");
1350            failed = true;
1351        }
1352    }
1353    failed |= !write_coverage(opts, &fired, &mut stderr);
1354    failed |= !write_pressure(opts, &pressure, &mut stderr);
1355    i32::from(failed)
1356}
1357
1358/// A directory for the object files only the link step ever sees, removed when it goes away.
1359///
1360/// `-c` writes its object where the user can see it and linking does not, which is the whole of
1361/// the difference: a `rucc a.c b.c` leaves an executable behind and nothing else, the same as
1362/// every other compiler. Removing them on drop rather than at the end of a function is so that a
1363/// link that failed leaves nothing behind either.
1364struct Scratch {
1365    /// Where the objects go.
1366    dir: PathBuf,
1367}
1368
1369impl Scratch {
1370    /// Makes one, under whatever the platform calls its temporary directory.
1371    ///
1372    /// The name carries the process id so that two compilers running at once do not share a
1373    /// directory, which they would otherwise do the moment two of them compiled a file of the
1374    /// same name.
1375    fn new() -> Result<Scratch, String> {
1376        let dir = std::env::temp_dir().join(format!("rucc-{}", std::process::id()));
1377        std::fs::create_dir_all(&dir).map_err(|e| format!("{}: {e}", dir.display()))?;
1378        Ok(Scratch { dir })
1379    }
1380}
1381
1382impl Drop for Scratch {
1383    fn drop(&mut self) {
1384        let _ = std::fs::remove_dir_all(&self.dir);
1385    }
1386}
1387
1388/// The link line the plan describes, for `-###`.
1389///
1390/// The names in it are the hints the plan carries rather than the temporaries a real compilation
1391/// would choose, because `-###` prints the line without having compiled anything and so has
1392/// nothing to point at. That also makes the printed line readable rather than naming a directory
1393/// that only exists while a compilation is running.
1394fn link_line(opts: &Options, link: &LinkOptions, job: &LinkJob) -> Result<String, link::Error> {
1395    let linker = link::find(opts.target, link)?;
1396    let args = link::line(opts.target, link, &job.inputs, &job.output)?;
1397    Ok(link::render(&linker, &args))
1398}
1399
1400/// Compiles everything, then links it.
1401///
1402/// The objects go in a directory that is removed afterwards, which is why this is not
1403/// [`compile_all`] followed by a link: the plan says an object feeding the linker is temporary
1404/// and does not say where, because where is a question that only has an answer once something is
1405/// running.
1406fn link_all(opts: &Options, plan: &Plan, link: &LinkOptions, verbose: bool) -> i32 {
1407    let Some(job) = &plan.link else {
1408        // Every path into here comes from a plan whose last phase is the link, and such a plan
1409        // has a link job. Saying so is cheaper than an unwrap that would have to be explained.
1410        let mut stderr = std::io::stderr().lock();
1411        let _ = writeln!(stderr, "rucc: error: there is nothing to link");
1412        return 1;
1413    };
1414    // Before anything is compiled, because a linker that is not on the machine is worth knowing
1415    // about in the second it takes to look rather than after the compilation.
1416    let linker = match link::find(opts.target, link) {
1417        Ok(linker) => linker,
1418        Err(why) => return complain(why),
1419    };
1420
1421    let scratch = match Scratch::new() {
1422        Ok(scratch) => scratch,
1423        Err(why) => return complain(format!("could not make a place for the object files: {why}")),
1424    };
1425
1426    let fs = OsFileSystem::new();
1427    let mut failed = false;
1428    // One per job, in job order, which is what lets the link line below be rebuilt with the real
1429    // paths in it: every job contributes exactly one file to the line and does so in this order.
1430    let mut produced: Vec<String> = Vec::with_capacity(plan.jobs.len());
1431    let mut fired = Fired::new();
1432    let mut pressure = Pressure::new();
1433    {
1434        let mut stderr = std::io::stderr().lock();
1435        let (mut remarks, ok) = Remarks::new(opts.opt_info_file.as_ref(), &mut stderr);
1436        failed |= !ok;
1437        for (at, job) in plan.jobs.iter().enumerate() {
1438            let out = match &job.output {
1439                Output::Temporary(hint) => {
1440                    // The index because two inputs in different directories can have the same
1441                    // name, and the two objects of `rucc a/x.c b/x.c` must not be one file.
1442                    scratch.dir.join(format!("{at}-{hint}")).display().to_string()
1443                }
1444                Output::File(path) => path.clone(),
1445                // A job feeding the linker never writes to standard output, since the plan gives
1446                // it a temporary. This is here so that the match is total rather than a panic.
1447                Output::Stdout => continue,
1448            };
1449            produced.push(out.clone());
1450            if !job.phases.contains(&Phase::Compile) {
1451                continue;
1452            }
1453            let started = std::time::Instant::now();
1454            let result = if job.kind == InputKind::Ir {
1455                compile_ir(opts, &job.input, &fs)
1456            } else {
1457                compile(opts, &job.input, &fs)
1458            };
1459            if opts.time {
1460                say_time(&job.input, started.elapsed(), &mut stderr);
1461            }
1462            fired.merge(&result.fired);
1463            pressure.merge(&result.pressure);
1464            failed |= !write_dumps(&job.input, &result.dumps, &mut stderr);
1465            failed |= !remarks.write(&result.remarks, &mut stderr);
1466            for message in &result.messages {
1467                let _ = writeln!(stderr, "{message}");
1468            }
1469            failed |= !write_temps(job, &result.temps, &mut stderr);
1470            if result.failed() {
1471                failed = true;
1472                continue;
1473            }
1474            // A `-MD` on a command line that links writes the rule next to the executable and
1475            // names the executable as its target, since that is the file this source builds
1476            // here. The object it went through is in a temporary directory and is gone by the
1477            // time `make` reads any of this.
1478            if opts.deps.emit {
1479                failed |= !write_deps(opts, plan, job, &result.deps, &mut stderr);
1480            }
1481            if !matches!(result.artifact, Artifact::Object(_)) {
1482                // Worth saying rather than writing whatever it is and letting the linker read it.
1483                // An empty file is a valid empty linker script, so a link handed one gets as far
1484                // as reporting every symbol of this file undefined, which is a page of messages
1485                // about something that went wrong here.
1486                let _ = writeln!(
1487                    stderr,
1488                    "rucc: internal error: {}: no object file was produced for the link",
1489                    job.input
1490                );
1491                failed = true;
1492                continue;
1493            }
1494            if let Err(e) = std::fs::write(&out, result.artifact.bytes()) {
1495                let _ = writeln!(stderr, "rucc: error: {out}: {e}");
1496                failed = true;
1497            }
1498        }
1499        failed |= !write_coverage(opts, &fired, &mut stderr);
1500        failed |= !write_pressure(opts, &pressure, &mut stderr);
1501    }
1502    if failed {
1503        // Nothing is linked from a compilation that did not finish. A linker run over the objects
1504        // that did compile would report every function of the file that did not as undefined,
1505        // which is a page of messages about a mistake already reported once.
1506        return 1;
1507    }
1508
1509    // The items in command line order with the temporaries filled in. A library contributes no
1510    // job and passes through, and every file item takes the next job's real output, which is
1511    // what keeps a library that was written between two objects between them here.
1512    let mut outputs = produced.into_iter();
1513    let mut items = Vec::with_capacity(job.inputs.len());
1514    for item in &job.inputs {
1515        match item {
1516            link::Item::Library(name) => items.push(link::Item::Library(name.clone())),
1517            link::Item::File(_) => match outputs.next() {
1518                Some(path) => items.push(link::Item::File(path)),
1519                None => return complain("the plan asks the linker for a file nothing produced"),
1520            },
1521        }
1522    }
1523
1524    let args = match link::line(opts.target, link, &items, &job.output) {
1525        Ok(args) => args,
1526        Err(why) => return complain(why),
1527    };
1528    if verbose {
1529        let mut stderr = std::io::stderr().lock();
1530        let _ = writeln!(stderr, "{}", link::render(&linker, &args));
1531    }
1532    let started = std::time::Instant::now();
1533    let ran = link::run(&linker, &args);
1534    if opts.time {
1535        // The one step of a compilation that really is another program, so this line is the same
1536        // measurement gcc's is and names the linker the way gcc names `collect2`.
1537        let mut stderr = std::io::stderr().lock();
1538        say_time(&linker.name, started.elapsed(), &mut stderr);
1539    }
1540    match ran {
1541        Ok(()) => 0,
1542        // The linker has already said what was wrong on its own error output, and repeating that
1543        // linking failed would only push its message further up the screen.
1544        Err(link::Error::Refused { .. }) => 1,
1545        Err(why) => complain(why),
1546    }
1547}
1548
1549/// Prints one driver level message and gives back the exit status that goes with it.
1550fn complain(why: impl std::fmt::Display) -> i32 {
1551    let mut stderr = std::io::stderr().lock();
1552    let _ = writeln!(stderr, "rucc: error: {why}");
1553    1
1554}
1555
1556/// Writes what `-Zrule-coverage=FILE` asked for, and says whether it could.
1557///
1558/// Once for the whole command line rather than once per input, because the question is which
1559/// lowering rules this run of the compiler reached and a file per input would leave the reader
1560/// unioning files to find out something one process already knew.
1561///
1562/// A file that could not be written is a failure and not a warning. What asks for this is a
1563/// measurement run, and a measurement that quietly did not happen is worse than one that stopped.
1564fn write_coverage(opts: &Options, fired: &Fired, stderr: &mut impl std::io::Write) -> bool {
1565    let Some(path) = &opts.rule_coverage else { return true };
1566    let Some(table) = coverage::table(opts.target.arch) else {
1567        let _ = writeln!(
1568            stderr,
1569            "rucc: error: there are no lowering rules for {} yet, so there is no coverage of them \
1570             to report",
1571            opts.target
1572        );
1573        return false;
1574    };
1575    match std::fs::write(path, fired.listing(table)) {
1576        Ok(()) => true,
1577        Err(e) => {
1578            let _ = writeln!(stderr, "rucc: error: {path}: {e}");
1579            false
1580        }
1581    }
1582}
1583
1584/// Writes what `-Zregister-pressure=FILE` asked for, and says whether it could.
1585///
1586/// Once for the whole command line, for the reason [`write_coverage`] gives, and a file that could
1587/// not be written is a failure for the reason it gives too. There is no equivalent of the missing
1588/// rule table here, since every target this compiles for has an allocator, and a run that reached
1589/// no back end at all writes an empty listing rather than nothing: a measurement of a build that
1590/// produced no code is still an answer and it is the honest one.
1591fn write_pressure(opts: &Options, pressure: &Pressure, stderr: &mut impl std::io::Write) -> bool {
1592    let Some(path) = &opts.register_pressure else { return true };
1593    match std::fs::write(path, pressure.listing()) {
1594        Ok(()) => true,
1595        Err(e) => {
1596            let _ = writeln!(stderr, "rucc: error: {path}: {e}");
1597            false
1598        }
1599    }
1600}
1601
1602/// Where the `-fopt-info` remarks go, and how much of the run has already gone there.
1603///
1604/// Standard error by default, and one file for the whole run when `-fopt-info=<file>` named one.
1605/// A file rather than the diagnostic stream is what a harness wants: the corpus in
1606/// `tamnd/rucc-corpus` matches a rejection against what the compiler said on standard error, and
1607/// a few thousand remarks mixed into that would bury it.
1608struct Remarks {
1609    /// The file, if there is one.
1610    file: Option<String>,
1611    /// Whether anything has been written to it yet, which decides between truncating and
1612    /// appending. One file holds the whole run rather than the last input in it.
1613    started: bool,
1614}
1615
1616impl Remarks {
1617    /// Prepares the destination, emptying the file if there is one.
1618    ///
1619    /// Emptied here rather than at the first remark, because a run where no pass had anything to
1620    /// say should leave an empty file and not yesterday's. An absent file and an empty one are
1621    /// different facts and something reading this will act on the difference.
1622    fn new(file: Option<&String>, stderr: &mut impl std::io::Write) -> (Self, bool) {
1623        let mut ok = true;
1624        if let Some(path) = file {
1625            if let Err(e) = std::fs::write(path, "") {
1626                let _ = writeln!(stderr, "rucc: error: {path}: {e}");
1627                ok = false;
1628            }
1629        }
1630        (Self { file: file.cloned(), started: false }, ok)
1631    }
1632
1633    /// Writes one input's remarks, and says whether that worked.
1634    ///
1635    /// A file that cannot be written is a failure and not a warning, for the reason
1636    /// [`write_dumps`] gives: remarks that quietly did not arrive look exactly like a compilation
1637    /// where nothing happened.
1638    fn write(&mut self, text: &str, stderr: &mut impl std::io::Write) -> bool {
1639        if text.is_empty() {
1640            return true;
1641        }
1642        let Some(path) = &self.file else {
1643            let _ = write!(stderr, "{text}");
1644            return true;
1645        };
1646        let opened = std::fs::OpenOptions::new()
1647            .write(true)
1648            .append(self.started)
1649            .truncate(!self.started)
1650            .create(true)
1651            .open(path);
1652        self.started = true;
1653        let result =
1654            opened.and_then(|mut file| std::io::Write::write_all(&mut file, text.as_bytes()));
1655        if let Err(e) = result {
1656            let _ = writeln!(stderr, "rucc: error: {path}: {e}");
1657            return false;
1658        }
1659        true
1660    }
1661}
1662
1663/// Writes what `-fdump-ir=` asked to see, one file per dump.
1664///
1665/// The name is the input file with the dump's own name and `.ir` after it, so a directory listing
1666/// after a run is the passes in the order they ran, per input. They go in the working directory
1667/// rather than beside the output, because a dump is something a person asked for at a prompt and
1668/// the working directory is where that person is.
1669///
1670/// A file that could not be written is a failure and not a warning, for the reason
1671/// [`write_coverage`] gives: what asked for this is somebody debugging a pass, and a dump that
1672/// quietly did not happen looks exactly like a pass that did not run.
1673fn write_dumps(input: &str, dumps: &[rucc_opt::Dump], stderr: &mut impl std::io::Write) -> bool {
1674    let stem = std::path::Path::new(input)
1675        .file_name()
1676        .map_or_else(|| input.to_owned(), |name| name.to_string_lossy().into_owned());
1677    let mut ok = true;
1678    for dump in dumps {
1679        let path = format!("{stem}.{}.ir", dump.name);
1680        if let Err(e) = std::fs::write(&path, &dump.text) {
1681            let _ = writeln!(stderr, "rucc: error: {path}: {e}");
1682            ok = false;
1683        }
1684    }
1685    ok
1686}
1687
1688/// Writes the files `-save-temps` kept, which is nothing at all unless it was given.
1689///
1690/// A file that could not be written is a failure rather than a warning, for the reason
1691/// [`write_dumps`] gives: somebody asked for these by name, and one that quietly did not happen
1692/// looks like a compilation that never went through that step.
1693fn write_temps(job: &Job, temps: &Temps, stderr: &mut impl std::io::Write) -> bool {
1694    let mut ok = true;
1695    let kept = [(job.saved_text(), &temps.preprocessed), (job.saved_asm(), &temps.assembly)];
1696    for (path, text) in kept {
1697        // A step the compilation did not reach has nothing to keep, and a job that is not keeping
1698        // that step has nowhere to put it. Either way there is no file here.
1699        let (Some(path), Some(text)) = (path, text) else { continue };
1700        if let Err(e) = std::fs::write(&path, text) {
1701            let _ = writeln!(stderr, "rucc: error: {path}: {e}");
1702            ok = false;
1703        }
1704    }
1705    ok
1706}
1707
1708/// One line of `-time`, which is what a step was called and how long it took.
1709///
1710/// GCC's two numbers are the user and the system time of a subprocess it ran. This compiler runs
1711/// no subprocess for anything but the link, so what is measured here is the wall clock of the
1712/// step and the second column is always zero. The shape of the line is kept because a person
1713/// reading it next to gcc's should not have to work out which column is which.
1714fn say_time(name: &str, took: std::time::Duration, stderr: &mut impl std::io::Write) {
1715    let _ = writeln!(stderr, "# {name} {:.2} {:.2}", took.as_secs_f64(), 0.0);
1716}
1717
1718/// Writes one job's result where the plan said it goes.
1719///
1720/// # Errors
1721///
1722/// Returns the message to print, which names the file when there is one, because "permission
1723/// denied" on its own does not say which file was refused.
1724fn write_out(output: &Output, bytes: &[u8]) -> Result<(), String> {
1725    match output {
1726        Output::Stdout => {
1727            let mut stdout = std::io::stdout().lock();
1728            stdout.write_all(bytes).map_err(|e| format!("writing to standard output: {e}"))
1729        }
1730        Output::File(path) | Output::Temporary(path) => {
1731            std::fs::write(path, bytes).map_err(|e| format!("{path}: {e}"))
1732        }
1733    }
1734}
1735
1736/// Runs the driver and returns the process exit code.
1737///
1738/// `args` excludes the program name. Output goes to `stdout` and errors to `stderr`, which
1739/// is the one place in the compiler that is true.
1740pub fn run(args: &[String]) -> i32 {
1741    match parse_args(args) {
1742        Ok(Action::Help) => {
1743            print!("{USAGE}");
1744            0
1745        }
1746        Ok(Action::Version) => {
1747            println!("rucc {VERSION}");
1748            0
1749        }
1750        Ok(Action::Print(line)) => {
1751            println!("{line}");
1752            0
1753        }
1754        Ok(Action::PrintConfig(opts)) => {
1755            print!("{}", print_config(&opts));
1756            0
1757        }
1758        Ok(Action::PrintPipeline(opts)) => {
1759            print!("{}", print_pipeline(&opts));
1760            0
1761        }
1762        Ok(Action::PrintPlan { opts, plan, link }) => {
1763            print!("{}", plan.render());
1764            // The line as it would be typed, which is the half of `-###` that section 4.3 says
1765            // arrives with the link. It is printed even when the linker is not on this machine,
1766            // because what a build wants from `-###` is what the compiler would do.
1767            if let Some(job) = &plan.link {
1768                match link_line(&opts, &link, job) {
1769                    Ok(line) => println!("{line}"),
1770                    Err(why) => {
1771                        let mut stderr = std::io::stderr().lock();
1772                        let _ = writeln!(stderr, "rucc: error: {why}");
1773                        return 1;
1774                    }
1775                }
1776            }
1777            0
1778        }
1779        Ok(Action::Compile { opts, plan, link, jobs, verbose }) => {
1780            {
1781                let mut stderr = std::io::stderr().lock();
1782                if verbose {
1783                    let _ = write!(stderr, "{}", plan.render());
1784                    let _ = writeln!(stderr, "workers: {}", jobs.count());
1785                }
1786            }
1787            if opts.emit == EmitKind::Preprocessed {
1788                return preprocess_all(&opts, &plan);
1789            }
1790            if opts.emit != EmitKind::Executable {
1791                return compile_all(&opts, &plan);
1792            }
1793            link_all(&opts, &plan, &link, verbose)
1794        }
1795        Err(e) => {
1796            let mut stderr = std::io::stderr().lock();
1797            let _ = writeln!(stderr, "rucc: error: {e}");
1798            let _ = writeln!(stderr, "rucc: note: run `rucc --help` for usage");
1799            1
1800        }
1801    }
1802}
1803
1804#[cfg(test)]
1805mod tests {
1806    use rucc_session::{GnucVersion, IncludeForm, OptLevel, Patchable, Visibility};
1807
1808    use super::*;
1809
1810    fn args(s: &[&str]) -> Vec<String> {
1811        s.iter().map(|x| (*x).to_owned()).collect()
1812    }
1813
1814    #[test]
1815    fn help_and_version_win_over_everything_else() {
1816        assert_eq!(parse_args(&args(&["-c", "--help", "x.c"])).unwrap(), Action::Help);
1817        assert_eq!(parse_args(&args(&["--version"])).unwrap(), Action::Version);
1818    }
1819
1820    fn compile(s: &[&str]) -> (Box<Options>, Box<Plan>) {
1821        match parse_args(&args(s)).expect("expected a compilation") {
1822            Action::Compile { opts, plan, .. } => (opts, plan),
1823            other => panic!("expected a compilation, got {other:?}"),
1824        }
1825    }
1826
1827    fn linking(s: &[&str]) -> (Box<LinkOptions>, Box<Plan>) {
1828        match parse_args(&args(s)).expect("expected a compilation") {
1829            Action::Compile { link, plan, .. } => (link, plan),
1830            other => panic!("expected a compilation, got {other:?}"),
1831        }
1832    }
1833
1834    #[test]
1835    fn collects_inputs_and_flags() {
1836        let (opts, plan) = compile(&["-c", "-O2", "-g", "a.c", "b.c"]);
1837        let paths: Vec<&str> = plan.jobs.iter().map(|j| j.input.as_str()).collect();
1838        assert_eq!(paths, vec!["a.c", "b.c"]);
1839        assert_eq!(opts.opt_level, OptLevel::O2);
1840        assert_eq!(opts.emit, EmitKind::Object);
1841        assert!(opts.debug_info);
1842    }
1843
1844    /// The unstable options, which are spelled apart from everything else on purpose: what is
1845    /// under `-Z` promises nothing, and a build that reaches for one should have had to say so.
1846    #[test]
1847    fn an_unstable_option_is_taken_and_one_that_does_not_exist_is_refused() {
1848        let (opts, _) = compile(&["-c", "-Zrule-coverage=/tmp/rules.cov", "a.c"]);
1849        assert_eq!(opts.rule_coverage.as_deref(), Some("/tmp/rules.cov"));
1850
1851        let (plain, _) = compile(&["-c", "a.c"]);
1852        assert_eq!(plain.rule_coverage, None, "nothing is measured unless it was asked for");
1853
1854        assert!(parse_args(&args(&["-Zrule-coverage=", "a.c"])).is_err(), "a file with no name");
1855        let unknown = parse_args(&args(&["-Zwhat", "a.c"])).expect_err("there is no such option");
1856        assert!(unknown.message.contains("4.11"), "{}", unknown.message);
1857    }
1858
1859    /// The other measurement written to a file, which reads the same way and fails the same way.
1860    #[test]
1861    fn where_the_register_pressure_goes_is_asked_for_the_same_way() {
1862        let (opts, _) = compile(&["-c", "-O2", "-Zregister-pressure=/tmp/spills.txt", "a.c"]);
1863        assert_eq!(opts.register_pressure.as_deref(), Some("/tmp/spills.txt"));
1864
1865        let (plain, _) = compile(&["-c", "a.c"]);
1866        assert_eq!(plain.register_pressure, None, "nothing is measured unless it was asked for");
1867
1868        assert!(parse_args(&args(&["-Zregister-pressure=", "a.c"])).is_err(), "no file named");
1869    }
1870
1871    #[test]
1872    fn a_bare_dash_o_means_o1_the_way_gcc_reads_it() {
1873        let (opts, _) = compile(&["-O", "a.c"]);
1874        assert_eq!(opts.opt_level, OptLevel::O1);
1875    }
1876
1877    #[test]
1878    fn dash_x_applies_to_later_inputs_only_and_none_stops_it() {
1879        let (_, plan) = compile(&["a.o", "-x", "c", "b.txt", "-x", "none", "c.o"]);
1880        assert_eq!(plan.jobs[0].kind, InputKind::LinkerInput);
1881        assert_eq!(plan.jobs[1].kind, InputKind::C);
1882        assert_eq!(plan.jobs[2].kind, InputKind::LinkerInput);
1883    }
1884
1885    #[test]
1886    fn dash_j_reaches_the_scheduler_and_defaults_to_the_machine() {
1887        let (_, _, jobs) = match parse_args(&args(&["-j4", "a.c"])).unwrap() {
1888            Action::Compile { opts, plan, jobs, .. } => (opts, plan, jobs),
1889            other => panic!("expected a compilation, got {other:?}"),
1890        };
1891        assert_eq!(jobs.count(), 4);
1892
1893        let default = match parse_args(&args(&["a.c"])).unwrap() {
1894            Action::Compile { jobs, .. } => jobs,
1895            other => panic!("expected a compilation, got {other:?}"),
1896        };
1897        assert_eq!(default, Jobs::available());
1898        assert!(parse_args(&args(&["-j0", "a.c"])).is_err());
1899    }
1900
1901    #[test]
1902    fn triple_hash_prints_the_plan_and_runs_nothing() {
1903        let a = parse_args(&args(&["-###", "-c", "a.c"])).unwrap();
1904        let Action::PrintPlan { plan, .. } = a else { panic!("expected a plan dump") };
1905        assert!(plan.render().contains("a.c: preprocess, compile, assemble -> a.o"));
1906    }
1907
1908    #[test]
1909    fn the_flag_that_keeps_the_intermediate_files_has_three_spellings_and_two_meanings() {
1910        // The bare one is `=obj` and not `=cwd`. gcc's manual says the opposite and gcc 16 does
1911        // this, and following the compiler is what makes a build that reads either of them find
1912        // the files where they are.
1913        assert_eq!(compile(&["-c", "-save-temps", "a.c"]).0.save_temps, SaveTemps::Object);
1914        assert_eq!(compile(&["-c", "-save-temps=obj", "a.c"]).0.save_temps, SaveTemps::Object);
1915        assert_eq!(compile(&["-c", "-save-temps=cwd", "a.c"]).0.save_temps, SaveTemps::Cwd);
1916        assert_eq!(compile(&["-c", "a.c"]).0.save_temps, SaveTemps::No);
1917        // The last one on the line decides, the way it does for every other flag with an
1918        // argument, and a keyword that is neither is fatal rather than ignored: a run that kept
1919        // nothing and said nothing looks exactly like one where the files were not produced.
1920        let (opts, _) = compile(&["-c", "-save-temps", "-save-temps=cwd", "a.c"]);
1921        assert_eq!(opts.save_temps, SaveTemps::Cwd);
1922        let e = parse_args(&args(&["-c", "-save-temps=nowhere", "a.c"])).unwrap_err();
1923        assert!(e.message.contains("accepted: cwd, obj"), "{}", e.message);
1924    }
1925
1926    #[test]
1927    fn the_flag_that_times_each_step_reaches_the_options_and_changes_nothing_else() {
1928        let (opts, plan) = compile(&["-c", "-time", "a.c"]);
1929        let (plain, without) = compile(&["-c", "a.c"]);
1930        assert!(opts.time);
1931        assert!(!plain.time);
1932        // Against the same line without the flag rather than against a spelling of the object's
1933        // name, since what the object is called is the host's business and this is not about that.
1934        assert_eq!(plan.jobs[0].output, without.jobs[0].output);
1935    }
1936
1937    #[test]
1938    fn dash_x_names_what_it_accepts_when_it_does_not_know_a_language() {
1939        let e = parse_args(&args(&["-x", "fortran", "a.c"])).unwrap_err();
1940        assert!(e.message.contains("assembler-with-cpp"), "{}", e.message);
1941    }
1942
1943    #[test]
1944    fn an_unknown_flag_is_an_error_rather_than_a_shrug() {
1945        let e = parse_args(&args(&["-fno-such-thing", "a.c"])).unwrap_err();
1946        assert!(e.message.contains("unknown option"), "{}", e.message);
1947    }
1948
1949    /// `-fpermissive` and the flag that turns it back off, which a build writes beside it when
1950    /// one directory needs the older rules and the rest of the tree does not.
1951    #[test]
1952    fn permissive_reads_in_both_directions_and_the_last_one_wins() {
1953        let (opts, _) = compile(&["-c", "a.c"]);
1954        assert!(!opts.permissive, "off unless it is asked for");
1955
1956        let (opts, _) = compile(&["-c", "-fpermissive", "a.c"]);
1957        assert!(opts.permissive);
1958
1959        let (opts, _) = compile(&["-c", "-fpermissive", "-fno-permissive", "a.c"]);
1960        assert!(!opts.permissive);
1961    }
1962
1963    #[test]
1964    fn asking_for_nested_functions_is_told_why_it_is_not_coming() {
1965        let e = parse_args(&args(&["-fnested-functions", "a.c"])).unwrap_err();
1966        assert!(e.message.contains("trampoline"), "{}", e.message);
1967        assert!(parse_args(&args(&["-fno-nested-functions", "a.c"])).is_ok());
1968    }
1969
1970    #[test]
1971    fn the_flag_every_configure_script_writes_is_taken() {
1972        // All four spellings, because a build writes whichever one its macros picked and a
1973        // compiler that takes three of them is a compiler that fails on the fourth.
1974        for flag in ["-fPIC", "-fpic", "-fPIE", "-fpie"] {
1975            let (opts, _) = compile(&["-c", flag, "a.c"]);
1976            assert_eq!(opts.emit, EmitKind::Object, "{flag}");
1977        }
1978    }
1979
1980    #[test]
1981    fn a_table_is_written_unless_the_build_says_nothing_will_walk_it() {
1982        let (opts, _) = compile(&["-c", "a.c"]);
1983        assert!(opts.unwinds(), "the default is off");
1984        let (opts, _) = compile(&["-c", "-fno-asynchronous-unwind-tables", "a.c"]);
1985        assert!(!opts.unwinds(), "the build was not taken at its word");
1986        let (opts, _) = compile(&[
1987            "-c",
1988            "-fno-asynchronous-unwind-tables",
1989            "-fasynchronous-unwind-tables",
1990            "a.c",
1991        ]);
1992        assert!(opts.unwinds(), "the last flag did not win");
1993        // The weaker request, which the same table answers, so a line that asks for a table and
1994        // against an asynchronous one gets one. That is gcc's arrangement and it turns up when a
1995        // build turns the asynchronous one off globally and a directory asks for a table back.
1996        let (opts, _) =
1997            compile(&["-c", "-fno-asynchronous-unwind-tables", "-funwind-tables", "a.c"]);
1998        assert!(opts.unwinds(), "the weaker request was dropped");
1999        let (opts, _) = compile(&["-c", "-fno-unwind-tables", "a.c"]);
2000        assert!(opts.unwinds(), "the weaker negative turned off the stronger request");
2001        let (opts, _) =
2002            compile(&["-c", "-fno-unwind-tables", "-fno-asynchronous-unwind-tables", "a.c"]);
2003        assert!(!opts.unwinds(), "both were turned off and one stayed on");
2004    }
2005
2006    #[test]
2007    fn the_flags_that_describe_what_this_compiler_already_does_are_taken() {
2008        // Every one of these is on a real build line somewhere and every one of them was an
2009        // unknown option. What they have in common is that the answer rucc gives is the answer
2010        // they ask for, so there is nothing to implement and nothing to refuse.
2011        for flag in [
2012            "-fno-common",
2013            "-fstrict-aliasing",
2014            "-fno-strict-aliasing",
2015            "-pipe",
2016            "-fdiagnostics-color",
2017            "-fno-diagnostics-color",
2018            "-fdiagnostics-color=always",
2019            "-fdiagnostics-color=never",
2020            "-fdiagnostics-color=auto",
2021        ] {
2022            let (opts, _) = compile(&["-c", flag, "a.c"]);
2023            assert_eq!(opts.emit, EmitKind::Object, "{flag}");
2024        }
2025    }
2026
2027    #[test]
2028    fn asking_the_linker_to_merge_tentative_definitions_is_told_why_it_is_not_coming() {
2029        // The one of that family that is a request rather than a description, and it is a real
2030        // difference: two files each writing `int g;` link under it and do not without it.
2031        let e = parse_args(&args(&["-fcommon", "a.c"])).unwrap_err();
2032        assert!(e.message.contains(".bss"), "{}", e.message);
2033        assert!(e.message.contains("extern"), "the way out is worth saying: {}", e.message);
2034    }
2035
2036    #[test]
2037    fn asking_for_position_dependent_code_is_told_why_it_is_not_coming() {
2038        for flag in ["-fno-pic", "-fno-pie"] {
2039            let e = parse_args(&args(&[flag, "a.c"])).unwrap_err();
2040            assert!(e.message.contains("global offset table"), "{flag}: {}", e.message);
2041            // The one it may have meant, since the two are a letter apart and one of them is
2042            // about linking and is taken.
2043            assert!(e.message.contains("-no-pie"), "{flag}: {}", e.message);
2044        }
2045    }
2046
2047    #[test]
2048    fn an_unsupported_target_names_itself() {
2049        let e = parse_args(&args(&["--target=sparc64-linux-gnu", "a.c"])).unwrap_err();
2050        assert!(e.message.contains("sparc64"), "{}", e.message);
2051    }
2052
2053    #[test]
2054    fn no_inputs_is_an_error_but_print_config_needs_none() {
2055        assert!(parse_args(&args(&[])).is_err());
2056        assert!(matches!(parse_args(&args(&["--print-config"])), Ok(Action::PrintConfig(_))));
2057    }
2058
2059    #[test]
2060    fn print_config_reports_the_target_it_was_given_not_the_host() {
2061        let a = parse_args(&args(&["--print-config", "--target=riscv64-linux-musl"])).unwrap();
2062        let Action::PrintConfig(opts) = a else { panic!("expected a configuration dump") };
2063        let text = print_config(&opts);
2064        assert!(text.contains("target: riscv64-unknown-linux-musl"), "{text}");
2065        assert!(text.contains("char-signed: false"), "{text}");
2066        assert!(text.contains("object-format: elf"), "{text}");
2067        assert!(text.contains("va-list: void-pointer"), "{text}");
2068        // RISC-V has a register file and this compiler has not written it down yet, and the
2069        // dump says which of those two it is rather than leaving the line out.
2070        assert!(text.contains("registers: none"), "{text}");
2071    }
2072
2073    #[test]
2074    fn print_config_has_one_key_per_line_and_a_fixed_order() {
2075        let opts = Options::new("x86_64-unknown-linux-gnu".parse().unwrap());
2076        let text = print_config(&opts);
2077        let keys: Vec<&str> =
2078            text.lines().map(|l| l.split(':').next().unwrap_or_default()).collect();
2079        assert_eq!(keys[0], "version");
2080        assert_eq!(keys[1], "target");
2081        assert_eq!(keys.len(), 25);
2082        assert!(text.ends_with('\n'));
2083    }
2084
2085    #[test]
2086    fn the_safety_tier_is_read_off_the_command_line_and_a_wrong_one_is_refused() {
2087        let (opts, _) = compile(&["a.c"]);
2088        assert_eq!(opts.safety, rucc_session::Safety::Off);
2089
2090        for (flag, tier) in [
2091            ("-fsafety=detect", rucc_session::Safety::Detect),
2092            ("-fsafety=enforce", rucc_session::Safety::Enforce),
2093            ("-fsafety=kernel", rucc_session::Safety::Kernel),
2094            ("-fsafety=off", rucc_session::Safety::Off),
2095        ] {
2096            let (opts, _) = compile(&[flag, "a.c"]);
2097            assert_eq!(opts.safety, tier, "{flag}");
2098        }
2099
2100        // The last one wins, the way every other repeated flag on this command line does.
2101        let (opts, _) = compile(&["-fsafety=enforce", "-fsafety=off", "a.c"]);
2102        assert_eq!(opts.safety, rucc_session::Safety::Off);
2103
2104        // A misspelled tier is refused rather than ignored. Silently compiling without the
2105        // monitor a build asked for is the one failure mode this feature cannot have.
2106        let e = parse_args(&args(&["-fsafety=on", "a.c"])).unwrap_err();
2107        assert!(e.message.contains("is not a safety tier"), "{}", e.message);
2108        assert!(parse_args(&args(&["-fsafety", "a.c"])).is_err());
2109    }
2110
2111    #[test]
2112    fn print_pipeline_answers_with_the_passes_the_level_asked_for() {
2113        let a = parse_args(&args(&["--print-pipeline", "-O2"])).unwrap();
2114        let Action::PrintPipeline(opts) = a else { panic!("expected a pipeline dump") };
2115        let text = print_pipeline(&opts);
2116        assert!(text.starts_with("level: -O2\n"), "{text}");
2117        assert!(text.contains("fold"), "{text}");
2118
2119        let a = parse_args(&args(&["--print-pipeline"])).unwrap();
2120        let Action::PrintPipeline(opts) = a else { panic!("expected a pipeline dump") };
2121        // One pass runs at `-O0` and it is the one that removes code nothing reaches, which is
2122        // not an optimization. See issue 359.
2123        assert!(print_pipeline(&opts).contains("1: simplify-cfg,"), "{}", print_pipeline(&opts));
2124
2125        let a = parse_args(&args(&["--print-pipeline", "-fno-simplify-cfg"])).unwrap();
2126        let Action::PrintPipeline(opts) = a else { panic!("expected a pipeline dump") };
2127        // And with that one turned off there is nothing left, which the dump says rather than
2128        // printing an empty list.
2129        assert!(print_pipeline(&opts).contains("no passes"), "{}", print_pipeline(&opts));
2130    }
2131
2132    #[test]
2133    fn print_pipeline_takes_the_toggles_into_account() {
2134        let a = parse_args(&args(&["--print-pipeline", "-O2", "-fno-fold"])).unwrap();
2135        let Action::PrintPipeline(opts) = a else { panic!("expected a pipeline dump") };
2136        let text = print_pipeline(&opts);
2137        // The one that was named is gone and the rest of the level is not, which is the whole
2138        // of what a toggle promises.
2139        assert!(!text.contains("fold"), "{text}");
2140        assert!(text.contains("dce"), "{text}");
2141
2142        // Every pass the compiler has, named off. Built from the registry rather than written
2143        // out, so a pass added later is turned off here too and this keeps testing the thing it
2144        // is about, which is that the toggles can empty a level.
2145        let mut off = vec!["--print-pipeline".to_owned(), "-O2".to_owned()];
2146        off.extend(rucc_opt::PASSES.iter().map(|p| format!("-fno-{}", p.name())));
2147        let spelled: Vec<&str> = off.iter().map(String::as_str).collect();
2148        let a = parse_args(&args(&spelled)).unwrap();
2149        let Action::PrintPipeline(opts) = a else { panic!("expected a pipeline dump") };
2150        assert!(print_pipeline(&opts).contains("no passes"), "{}", print_pipeline(&opts));
2151    }
2152
2153    #[test]
2154    fn print_pipeline_says_when_a_budget_will_stop_the_run_short() {
2155        let a = parse_args(&args(&["--print-pipeline", "-O2"])).unwrap();
2156        let Action::PrintPipeline(opts) = a else { panic!("expected a pipeline dump") };
2157        assert!(!print_pipeline(&opts).contains("global fuel"));
2158
2159        let a = parse_args(&args(&["--print-pipeline", "-O2", "-fpass-fuel-global=4"])).unwrap();
2160        let Action::PrintPipeline(opts) = a else { panic!("expected a pipeline dump") };
2161        let text = print_pipeline(&opts);
2162        // Because the listing is the answer to what this compilation will do, and a run that
2163        // stops after four rewrites is not doing what the level says it does.
2164        assert!(text.contains("global fuel: 4"), "{text}");
2165    }
2166
2167    /// A pass is turned on and off by its own name, and the order the flags were given in is
2168    /// kept, because the last spelling of a name is the one that decides.
2169    #[test]
2170    fn a_pass_is_named_by_dash_f_and_unnamed_by_dash_f_no() {
2171        let (opts, _) = compile(&["-c", "-O0", "-ffold", "-fno-fold", "-ffold", "a.c"]);
2172        assert_eq!(
2173            opts.passes,
2174            [("fold".to_owned(), true), ("fold".to_owned(), false), ("fold".to_owned(), true)]
2175        );
2176
2177        let e = parse_args(&args(&["-fno-such-pass", "a.c"])).unwrap_err();
2178        assert!(e.message.contains("unknown option"), "{}", e.message);
2179    }
2180
2181    #[test]
2182    fn pass_fuel_names_a_pass_and_a_count_and_refuses_anything_else() {
2183        let (opts, _) = compile(&["-c", "-O2", "-fpass-fuel=fold=3", "a.c"]);
2184        assert_eq!(opts.pass_fuel, [("fold".to_owned(), 3)]);
2185
2186        let e = parse_args(&args(&["-fpass-fuel=fold", "a.c"])).unwrap_err();
2187        assert!(e.message.contains("<pass>=<count>"), "{}", e.message);
2188        let e = parse_args(&args(&["-fpass-fuel=nosuch=3", "a.c"])).unwrap_err();
2189        assert!(e.message.contains("--print-pipeline"), "{}", e.message);
2190        let e = parse_args(&args(&["-fpass-fuel=fold=lots", "a.c"])).unwrap_err();
2191        assert!(e.message.contains("not a number"), "{}", e.message);
2192    }
2193
2194    #[test]
2195    fn global_pass_fuel_is_a_count_on_its_own_and_defaults_to_no_limit() {
2196        let (opts, _) = compile(&["-c", "-O2", "a.c"]);
2197        assert_eq!(opts.pass_fuel_global, None);
2198
2199        let (opts, _) = compile(&["-c", "-O2", "-fpass-fuel-global=12", "a.c"]);
2200        assert_eq!(opts.pass_fuel_global, Some(12));
2201        // And it is not the per pass flag with a longer name, so neither spelling swallows the
2202        // other.
2203        assert!(opts.pass_fuel.is_empty());
2204
2205        let e = parse_args(&args(&["-fpass-fuel-global=lots", "a.c"])).unwrap_err();
2206        assert!(e.message.contains("not a number"), "{}", e.message);
2207    }
2208
2209    #[test]
2210    fn a_gate_names_a_pass_and_optionally_the_functions_it_covers() {
2211        let (opts, _) = compile(&["-c", "-O2", "-fdisable-fold", "-fenable-fold=2-4,main", "a.c"]);
2212        assert_eq!(
2213            opts.pass_gates,
2214            [(false, "fold".to_owned()), (true, "fold=2-4,main".to_owned())],
2215            "the order is what decides, so it has to survive the parse"
2216        );
2217
2218        let e = parse_args(&args(&["-fdisable-nosuch", "a.c"])).unwrap_err();
2219        assert!(e.message.contains("--print-pipeline"), "{}", e.message);
2220        let e = parse_args(&args(&["-fenable-fold=9-2", "a.c"])).unwrap_err();
2221        assert!(e.message.contains("ends before it starts"), "{}", e.message);
2222        let e = parse_args(&args(&["-fdisable-fold=", "a.c"])).unwrap_err();
2223        assert!(e.message.contains("is empty"), "{}", e.message);
2224    }
2225
2226    #[test]
2227    fn the_pipeline_listing_says_which_passes_a_gate_touched() {
2228        let (opts, _) = compile(&["-c", "-O2", "-fdisable-fold=main", "a.c"]);
2229        let text = print_pipeline(&opts);
2230        assert!(text.contains("fold, "), "{text}");
2231        assert!(text.contains("[off for main]"), "{text}");
2232    }
2233
2234    /// The spelling is checked while the arguments are read, because a dump that names a pass
2235    /// this compiler does not have is a typo, and a typo found after the compilation has run is
2236    /// found too late to be any use.
2237    #[test]
2238    fn a_dump_is_checked_when_it_is_asked_for_rather_than_when_it_is_taken() {
2239        let (opts, _) = compile(&["-c", "-O2", "-fdump-ir=all", "-fdump-ir=after-fold", "a.c"]);
2240        assert_eq!(opts.dump_ir, ["all", "after-fold"]);
2241
2242        let e = parse_args(&args(&["-fdump-ir=after-nosuch", "a.c"])).unwrap_err();
2243        assert!(e.message.contains("nosuch"), "{}", e.message);
2244        assert!(parse_args(&args(&["-fdump-ir=sideways-fold", "a.c"])).is_err());
2245    }
2246
2247    /// Every spelling `-fopt-info` takes, and the one it does not.
2248    ///
2249    /// The keywords are checked here for the same reason a dump's pass name is: a person who
2250    /// misspelled one gets no output, and no output is also what a compilation where nothing
2251    /// happened looks like. Telling those two apart is the entire reason to reach for this flag.
2252    #[test]
2253    fn opt_info_takes_kinds_and_a_file_and_refuses_a_kind_it_does_not_have() {
2254        let (opts, _) = compile(&["-c", "-O2", "-fopt-info", "a.c"]);
2255        assert_eq!(opts.opt_info, [""], "a bare flag asks for the rewrites");
2256        assert_eq!(opts.opt_info_file, None, "and goes to standard error");
2257
2258        let (opts, _) = compile(&["-c", "-O2", "-fopt-info-missed-note", "a.c"]);
2259        assert_eq!(opts.opt_info, ["missed-note"]);
2260
2261        // Two flags add up rather than the second replacing the first, and the file is the last
2262        // one that named a file, which is how GCC treats both.
2263        let (opts, _) =
2264            compile(&["-c", "-O2", "-fopt-info-missed=one.txt", "-fopt-info-all=two.txt", "a.c"]);
2265        assert_eq!(opts.opt_info, ["missed", "all"]);
2266        assert_eq!(opts.opt_info_file.as_deref(), Some("two.txt"));
2267
2268        let e = parse_args(&args(&["-fopt-info-vectorized", "a.c"])).unwrap_err();
2269        assert!(e.message.contains("vectorized"), "{}", e.message);
2270        assert!(e.message.contains("`missed`"), "{}", e.message);
2271        let e = parse_args(&args(&["-fopt-info-missed=", "a.c"])).unwrap_err();
2272        assert!(e.message.contains("no file"), "{}", e.message);
2273    }
2274
2275    #[test]
2276    fn verify_each_is_unstable_and_off_unless_it_was_asked_for() {
2277        let (opts, _) = compile(&["-c", "-Zverify-each", "a.c"]);
2278        assert!(opts.verify_each);
2279        assert!(!USAGE.contains("verify-each"), "an unstable option stays out of the usage text");
2280    }
2281
2282    #[test]
2283    fn dash_o_needs_an_argument() {
2284        let e = parse_args(&args(&["a.c", "-o"])).unwrap_err();
2285        assert_eq!(e.message, "-o requires an argument");
2286    }
2287
2288    #[test]
2289    fn dash_d_and_dash_u_are_read_joined_or_separated_and_keep_their_order() {
2290        let (opts, _) = compile(&["-DFOO=1", "-D", "BAR", "-UBAZ", "-U", "QUX", "a.c"]);
2291        assert_eq!(opts.defines, ["FOO=1", "BAR"]);
2292        assert_eq!(opts.undefines, ["BAZ", "QUX"]);
2293    }
2294
2295    #[test]
2296    fn the_include_flags_land_on_the_chain_each_one_names() {
2297        // A sysroot with nothing under it, so that the library's own directories are the
2298        // same on every machine this test runs on, which is none of them.
2299        let (opts, _) = compile(&[
2300            "-Ii",
2301            "-iquote",
2302            "q",
2303            "-isystem",
2304            "sys",
2305            "-idirafter",
2306            "after",
2307            "--sysroot=/nowhere-at-all",
2308            "a.c",
2309        ]);
2310        let dirs: Vec<&str> = opts.search.dirs().iter().filter_map(|d| d.path.to_str()).collect();
2311        // The compiler's own headers sit after every `-isystem` and before `-idirafter`,
2312        // which is where GCC puts its own: a directory the user named outranks ours.
2313        assert_eq!(dirs, ["q", "i", "sys", runtime::DIR, "after"]);
2314        assert!(!opts.search.dirs()[1].is_system);
2315        assert!(opts.search.dirs()[2].is_system);
2316    }
2317
2318    #[test]
2319    fn the_librarys_headers_come_after_the_compilers_own_and_go_away_with_them() {
2320        // Which machine this runs on decides what is on the path, so the test is about the
2321        // order rather than about the names: ours is on it, the library's follow it, and
2322        // `-nostdinc` is the one flag that takes both halves of the pair off at once.
2323        let (opts, _) = compile(&["a.c"]);
2324        let dirs = opts.search.dirs();
2325        let ours = dirs.iter().position(|d| d.path.to_str() == Some(runtime::DIR));
2326        assert_eq!(ours, Some(0), "{dirs:?}");
2327        assert!(dirs[1..].iter().all(|d| d.is_system), "{dirs:?}");
2328        let (bare, _) = compile(&["-nostdinc", "a.c"]);
2329        assert!(bare.search.dirs().is_empty(), "{:?}", bare.search.dirs());
2330    }
2331
2332    #[test]
2333    fn a_sysroot_moves_the_librarys_directories_and_nothing_else() {
2334        let (opts, _) = compile(&["-isystem", "sys", "--sysroot=/nowhere-at-all", "a.c"]);
2335        let dirs: Vec<&str> = opts.search.dirs().iter().filter_map(|d| d.path.to_str()).collect();
2336        assert_eq!(dirs, ["sys", runtime::DIR]);
2337    }
2338
2339    #[test]
2340    fn dash_i_dash_moves_the_bracket_directories_into_the_quoted_chain() {
2341        let (opts, _) =
2342            compile(&["-Iinc1", "-iquote", "inc2", "-I-", "-Iinc3", "-nostdinc", "a.c"]);
2343        let dirs: Vec<&str> = opts.search.dirs().iter().filter_map(|d| d.path.to_str()).collect();
2344        assert_eq!(dirs, ["inc1", "inc2", "inc3"]);
2345        // An angled include sees only what came after the flag.
2346        assert_eq!(opts.search.start(IncludeForm::Angled), 2);
2347        assert!(!opts.search.searches_current_dir());
2348    }
2349
2350    #[test]
2351    fn the_prefix_flags_stick_what_iprefix_said_on_the_front_of_what_follows_it() {
2352        let (opts, _) = compile(&[
2353            "-iprefix",
2354            "/tools/",
2355            "-iwithprefix",
2356            "late",
2357            "-iwithprefixbefore",
2358            "early",
2359            "-iprefix",
2360            "/other/",
2361            "-iwithprefix",
2362            "last",
2363            "-nostdinc",
2364            "a.c",
2365        ]);
2366        let dirs: Vec<&str> = opts.search.dirs().iter().filter_map(|d| d.path.to_str()).collect();
2367        // `-iwithprefixbefore` is an `-I` and the other two are `-isystem`, which is where GCC
2368        // puts them rather than where its manual says it does.
2369        assert_eq!(dirs, ["/tools/early", "/tools/late", "/other/last"]);
2370        assert!(!opts.search.dirs()[0].is_system);
2371        assert!(opts.search.dirs()[1].is_system);
2372    }
2373
2374    #[test]
2375    fn the_files_named_on_the_command_line_keep_their_order_and_which_flag_named_them() {
2376        let (opts, _) =
2377            compile(&["-include", "one.h", "-imacros", "two.h", "-include", "3.h", "a.c"]);
2378        let names: Vec<&str> = opts.preincludes.iter().map(|p| p.name.as_str()).collect();
2379        assert_eq!(names, ["one.h", "two.h", "3.h"]);
2380        assert_eq!(opts.preincludes.iter().filter(|p| p.macros_only).count(), 1);
2381    }
2382
2383    #[test]
2384    fn nostdinc_takes_the_compilers_own_headers_off_the_path() {
2385        let (opts, _) = compile(&["-Ii", "-nostdinc", "a.c"]);
2386        let dirs: Vec<&str> = opts.search.dirs().iter().filter_map(|d| d.path.to_str()).collect();
2387        assert_eq!(dirs, ["i"]);
2388    }
2389
2390    #[test]
2391    fn the_dialect_flags_set_the_language_and_the_extensions_separately() {
2392        let (opts, _) = compile(&["-std=gnu11", "a.c"]);
2393        assert_eq!(opts.std, Std::C11);
2394        assert!(opts.gnu_extensions);
2395
2396        let (opts, _) = compile(&["-std=iso9899:1999", "a.c"]);
2397        assert_eq!(opts.std, Std::C99);
2398        assert!(!opts.gnu_extensions);
2399
2400        let (opts, _) = compile(&["-ansi", "a.c"]);
2401        assert_eq!(opts.std, Std::C89);
2402        assert!(!opts.gnu_extensions);
2403
2404        let e = parse_args(&args(&["-std=c94jr", "a.c"])).unwrap_err();
2405        assert!(e.message.contains("unknown dialect"), "{}", e.message);
2406    }
2407
2408    #[test]
2409    fn the_dump_letters_are_a_family_and_everything_else_beginning_with_d_is_not() {
2410        let (opts, _) = compile(&["-dM", "a.c"]);
2411        assert!(opts.dumps.macros);
2412
2413        // Packed, the way GCC takes them, and a letter in the family we have not written yet
2414        // is accepted and does nothing rather than failing a build.
2415        let (opts, _) = compile(&["-dDM", "a.c"]);
2416        assert!(opts.dumps.macros);
2417        let (opts, _) = compile(&["-dD", "a.c"]);
2418        assert!(!opts.dumps.macros);
2419
2420        let (opts, _) = compile(&["a.c"]);
2421        assert!(!opts.dumps.any());
2422
2423        // `-dumpversion` is a different flag that happens to start the same way, and it is read
2424        // as itself rather than as a dump of nothing.
2425        assert_eq!(printed(&["-dumpversion", "a.c"]), VERSION);
2426    }
2427
2428    #[test]
2429    fn the_gcc_version_claimed_is_a_flag_and_the_short_spellings_are_the_ones_people_write() {
2430        let (opts, _) = compile(&["a.c"]);
2431        assert_eq!(
2432            opts.gnuc,
2433            GnucVersion { major: 7, minor: 0, patch: 0 },
2434            "the lowest claim a modern glibc gives its own declarations to"
2435        );
2436
2437        let (opts, _) = compile(&["-fgnuc-version=15.1.0", "a.c"]);
2438        assert_eq!(opts.gnuc, GnucVersion { major: 15, minor: 1, patch: 0 });
2439
2440        // A missing component is zero. `gcc -dumpversion` says `15` on a release with no
2441        // patchlevel and a harness that pastes that back has to be understood.
2442        let (opts, _) = compile(&["-fgnuc-version=15", "a.c"]);
2443        assert_eq!(opts.gnuc, GnucVersion { major: 15, minor: 0, patch: 0 });
2444
2445        let (opts, _) = compile(&["-fgnuc-version=13.2", "a.c"]);
2446        assert_eq!(opts.gnuc, GnucVersion { major: 13, minor: 2, patch: 0 });
2447
2448        let e = parse_args(&args(&["-fgnuc-version=15.x", "a.c"])).unwrap_err();
2449        assert!(e.message.contains("minor that is not a number"), "{}", e.message);
2450
2451        let e = parse_args(&args(&["-fgnuc-version=1.2.3.4", "a.c"])).unwrap_err();
2452        assert!(e.message.contains("more than three"), "{}", e.message);
2453    }
2454
2455    #[test]
2456    fn pedantic_has_two_spellings_and_is_not_the_same_knob_as_the_dialect() {
2457        let (opts, _) = compile(&["-std=c17", "-pedantic", "a.c"]);
2458        assert!(opts.pedantic);
2459        assert_eq!(opts.std, Std::C17);
2460
2461        // The `-W` family's name for it, which is what a build that groups its warning flags
2462        // tends to write.
2463        let (opts, _) = compile(&["-Wpedantic", "a.c"]);
2464        assert!(opts.pedantic);
2465
2466        let (opts, _) = compile(&["-std=c17", "a.c"]);
2467        assert!(!opts.pedantic, "a dialect on its own does not diagnose an extension");
2468    }
2469
2470    #[test]
2471    fn dash_p_and_dash_ffreestanding_reach_the_options() {
2472        let (opts, _) = compile(&["-E", "-P", "-ffreestanding", "a.c"]);
2473        assert!(!opts.line_markers);
2474        assert!(!opts.hosted);
2475        assert_eq!(opts.emit, EmitKind::Preprocessed);
2476    }
2477
2478    /// The two ways a build says it means its own function by a name the C library also has.
2479    ///
2480    /// `-fno-builtin` is all of them and `-fno-builtin-<name>` is one, and the second is what a
2481    /// build writes when it means its own `memcpy` and the library's everything else. The name is
2482    /// kept as it was written and not checked against anything, because a program is allowed to
2483    /// mean something by a name this compiler has never heard of.
2484    #[test]
2485    fn the_builtin_flags_are_read_in_both_directions_and_one_name_at_a_time() {
2486        let (opts, _) = compile(&["-c", "a.c"]);
2487        assert!(opts.builtins, "a library name means the library function by default");
2488        assert!(opts.no_builtin.is_empty());
2489
2490        let (opts, _) = compile(&["-c", "-fno-builtin", "a.c"]);
2491        assert!(!opts.builtins);
2492
2493        let (opts, _) = compile(&["-c", "-fno-builtin", "-fbuiltin", "a.c"]);
2494        assert!(opts.builtins, "the last mention decides");
2495
2496        let (opts, _) = compile(&["-c", "-fno-builtin-memcpy", "-fno-builtin-nonesuch", "a.c"]);
2497        assert!(opts.builtins, "one name is not the family");
2498        assert_eq!(opts.no_builtin, vec!["memcpy".to_owned(), "nonesuch".to_owned()]);
2499    }
2500
2501    /// `-fvisibility=`, which is on every cmake project that cares about which names it exports
2502    /// and which was refused as an unknown option until now.
2503    ///
2504    /// Four spellings and three answers. `internal` is hidden plus a promise about never taking
2505    /// the address across a component boundary, and nothing derives anything from that promise
2506    /// here, so it comes out as the weaker of the two rather than as a refusal that stops a build
2507    /// over a distinction this compiler does not make.
2508    #[test]
2509    fn visibility_takes_the_four_spellings_gcc_takes_and_refuses_the_rest() {
2510        let (opts, _) = compile(&["-c", "a.c"]);
2511        assert_eq!(opts.visibility, Visibility::Default, "exported unless something says not");
2512
2513        for (written, wanted) in [
2514            ("default", Visibility::Default),
2515            ("hidden", Visibility::Hidden),
2516            ("internal", Visibility::Hidden),
2517            ("protected", Visibility::Protected),
2518        ] {
2519            let (opts, _) = compile(&["-c", &format!("-fvisibility={written}"), "a.c"]);
2520            assert_eq!(opts.visibility, wanted, "{written}");
2521        }
2522
2523        // The last mention decides, which is what every other flag of this shape does and what a
2524        // build that turns something off for one directory relies on.
2525        let (opts, _) = compile(&["-c", "-fvisibility=hidden", "-fvisibility=default", "a.c"]);
2526        assert_eq!(opts.visibility, Visibility::Default, "the last mention decides");
2527
2528        // A spelling gcc does not take is refused rather than read as the default, because a
2529        // build that meant hidden and got exported is a library with the wrong interface and
2530        // nothing said about it anywhere.
2531        let failed = parse_args(&args(&["-fvisibility=none", "a.c"])).expect_err("refused");
2532        assert!(failed.to_string().contains("is not a visibility"), "{failed}");
2533    }
2534
2535    /// `-ffunction-sections` and `-fdata-sections`, which are what make `--gc-sections` able to
2536    /// drop anything: a linker can leave out a section nothing reaches and cannot leave out half of
2537    /// one. A kernel and an embedded image are both linked that way.
2538    ///
2539    /// Two flags rather than one because gcc has two, and a build that asks for one of them and not
2540    /// the other is a build that measured something: splitting the code is nearly free at link time
2541    /// and splitting the data can defeat the linker's ordering of what is next to what.
2542    #[test]
2543    fn a_section_per_function_and_a_section_per_variable_are_asked_for_one_at_a_time() {
2544        let (opts, _) = compile(&["-c", "a.c"]);
2545        assert!(!opts.function_sections, "one text section unless something says otherwise");
2546        assert!(!opts.data_sections);
2547
2548        let (opts, _) = compile(&["-c", "-ffunction-sections", "a.c"]);
2549        assert!(opts.function_sections);
2550        assert!(!opts.data_sections, "one flag is not the other");
2551
2552        let (opts, _) = compile(&["-c", "-fdata-sections", "a.c"]);
2553        assert!(opts.data_sections);
2554        assert!(!opts.function_sections);
2555
2556        // Both directions taken, and the off one is what happens anyway rather than a refusal,
2557        // since a build that writes it is asking for the default.
2558        let (opts, _) = compile(&[
2559            "-c",
2560            "-ffunction-sections",
2561            "-fno-function-sections",
2562            "-fdata-sections",
2563            "-fno-data-sections",
2564            "a.c",
2565        ]);
2566        assert!(!opts.function_sections, "the last mention decides");
2567        assert!(!opts.data_sections, "the last mention decides");
2568    }
2569
2570    /// `-fgnu89-inline`, which is off by default and is not implied by anything on the command
2571    /// line, since the dialect asks for GNU's reading further in rather than through this.
2572    #[test]
2573    fn gnu89_inline_is_off_until_it_is_asked_for_and_the_last_mention_decides() {
2574        let (opts, _) = compile(&["-c", "a.c"]);
2575        assert!(!opts.gnu89_inline, "C's reading of inline by default");
2576
2577        let (opts, _) = compile(&["-c", "-fgnu89-inline", "a.c"]);
2578        assert!(opts.gnu89_inline);
2579
2580        let (opts, _) = compile(&["-c", "-fgnu89-inline", "-fno-gnu89-inline", "a.c"]);
2581        assert!(!opts.gnu89_inline, "the last mention decides");
2582
2583        // The C89 dialects are under GNU's reading whether this was written or not, so the flag
2584        // stays off there and the dialect is what the checker and the macro set both ask. That is
2585        // also why `-std=c89 -fno-gnu89-inline` needs no diagnostic: it asks for the reading the
2586        // dialect already has. gcc refuses that command line, which is measured in the issue.
2587        let (opts, _) = compile(&["-c", "-std=c89", "a.c"]);
2588        assert!(!opts.gnu89_inline);
2589    }
2590
2591    /// Both spellings of both frame flags, since a build that wants one usually writes the
2592    /// other beside it for the one file that has to be compiled the ordinary way.
2593    #[test]
2594    fn the_two_frame_flags_are_read_in_both_directions() {
2595        let (opts, _) = compile(&["-c", "a.c"]);
2596        assert!(!opts.frame_pointer, "gcc omits it above -O0 and so does this");
2597        assert!(opts.red_zone, "the psABI has one and nothing said not to use it");
2598
2599        let (opts, _) = compile(&["-c", "-fno-omit-frame-pointer", "-mno-red-zone", "a.c"]);
2600        assert!(opts.frame_pointer);
2601        assert!(!opts.red_zone);
2602
2603        let (opts, _) = compile(&[
2604            "-c",
2605            "-fno-omit-frame-pointer",
2606            "-fomit-frame-pointer",
2607            "-mno-red-zone",
2608            "-mred-zone",
2609            "a.c",
2610        ]);
2611        assert!(!opts.frame_pointer, "the last one wins, as it does in gcc");
2612        assert!(opts.red_zone);
2613    }
2614
2615    /// Four flags rather than one with an argument, which is how gcc spells them, and the negative
2616    /// spelled three ways because a build that turns one off writes whichever it turned on.
2617    #[test]
2618    fn the_stack_protector_is_four_flags_and_the_last_one_wins() {
2619        let (opts, _) = compile(&["-c", "a.c"]);
2620        assert_eq!(opts.protector, Protector::None, "gcc protects nothing unless it was asked");
2621
2622        for (flag, want) in [
2623            ("-fstack-protector", Protector::Buffers),
2624            ("-fstack-protector-strong", Protector::Strong),
2625            ("-fstack-protector-all", Protector::All),
2626        ] {
2627            let (opts, _) = compile(&["-c", flag, "a.c"]);
2628            assert_eq!(opts.protector, want, "{flag}");
2629        }
2630
2631        // What a package build does: the strong one in the global flags and one directory that
2632        // cannot have a protector turning it off on the line after.
2633        for off in ["-fno-stack-protector", "-fno-stack-protector-strong"] {
2634            let (opts, _) = compile(&["-c", "-fstack-protector-strong", off, "a.c"]);
2635            assert_eq!(opts.protector, Protector::None, "{off}");
2636        }
2637        let (opts, _) = compile(&["-c", "-fno-stack-protector", "-fstack-protector-all", "a.c"]);
2638        assert_eq!(opts.protector, Protector::All, "the last one wins either way round");
2639    }
2640
2641    /// A switch rather than a level, because how a frame is taken is one question and which
2642    /// functions get a canary is another, and gcc spells it that way for the same reason.
2643    #[test]
2644    fn taking_a_frame_a_page_at_a_time_is_off_until_it_is_asked_for() {
2645        let (opts, _) = compile(&["-c", "a.c"]);
2646        assert!(!opts.stack_clash, "gcc takes a frame in one subtraction unless it was asked");
2647
2648        let (opts, _) = compile(&["-c", "-fstack-clash-protection", "a.c"]);
2649        assert!(opts.stack_clash);
2650
2651        // The same shape a package build uses for the protector: on in the global flags and off
2652        // for the one directory that cannot have it.
2653        let (opts, _) =
2654            compile(&["-c", "-fstack-clash-protection", "-fno-stack-clash-protection", "a.c"]);
2655        assert!(!opts.stack_clash);
2656        let (opts, _) =
2657            compile(&["-c", "-fno-stack-clash-protection", "-fstack-clash-protection", "a.c"]);
2658        assert!(opts.stack_clash, "the last one wins either way round");
2659
2660        // The two are independent, since one is about the frame and the other about the function.
2661        let (opts, _) =
2662            compile(&["-c", "-fstack-clash-protection", "-fstack-protector-strong", "a.c"]);
2663        assert!(opts.stack_clash);
2664        assert_eq!(opts.protector, Protector::Strong);
2665    }
2666
2667    /// One flag with an argument rather than a family of spellings, because what it asks about is
2668    /// which of the two edges of a control flow transfer is checked and the two are not separate
2669    /// questions to the hardware.
2670    #[test]
2671    fn which_control_flow_edges_are_checked_is_asked_for_by_name() {
2672        let (opts, _) = compile(&["-c", "a.c"]);
2673        assert_eq!(opts.control, Control::None, "gcc's default on the targets this compiler has");
2674
2675        for (arg, want) in [
2676            ("-fcf-protection", Control::Full),
2677            ("-fcf-protection=full", Control::Full),
2678            ("-fcf-protection=branch", Control::Branch),
2679            ("-fcf-protection=return", Control::Return),
2680            ("-fcf-protection=none", Control::None),
2681            ("-fcf-protection=check", Control::Check),
2682        ] {
2683            let (opts, _) = compile(&["-c", arg, "a.c"]);
2684            assert_eq!(opts.control, want, "{arg}");
2685        }
2686
2687        // The shape a package build uses: on in the global flags and off for the one directory
2688        // that cannot have it, whichever of the two spellings of off it reaches for.
2689        let (opts, _) = compile(&["-c", "-fcf-protection=full", "-fno-cf-protection", "a.c"]);
2690        assert_eq!(opts.control, Control::None);
2691        let (opts, _) = compile(&["-c", "-fno-cf-protection", "-fcf-protection=branch", "a.c"]);
2692        assert_eq!(opts.control, Control::Branch, "the last one wins either way round");
2693    }
2694
2695    /// The profiler is asked for by two spellings, and where its hook goes by two more.
2696    ///
2697    /// The two halves are separate on purpose. `-mfentry` on its own says where a call would go and
2698    /// asks for no call, which is what gcc does with it, and a build system that sets it globally
2699    /// and asks for the profile per directory needs that to be true rather than an error.
2700    ///
2701    /// The link is asserted alongside, because the flag changes it too and a build that compiled
2702    /// with it and linked without it is a program that calls the hook everywhere and never writes a
2703    /// profile.
2704    #[test]
2705    fn the_profiler_and_where_its_hook_goes_are_two_separate_questions() {
2706        let (opts, _) = compile(&["-c", "a.c"]);
2707        assert!(!opts.profile);
2708        assert_eq!(opts.hook, Hook::Platform, "neither was named, so the target decides");
2709
2710        for arg in ["-pg", "-p"] {
2711            let (opts, _) = compile(&["-c", arg, "a.c"]);
2712            assert!(opts.profile, "{arg}");
2713            let (link, _) = linking(&[arg, "a.c"]);
2714            assert!(link.profile, "{arg} changes the link as well");
2715        }
2716
2717        for (arg, want) in [("-mfentry", Hook::Early), ("-mno-fentry", Hook::Late)] {
2718            let (opts, _) = compile(&["-c", arg, "a.c"]);
2719            assert_eq!(opts.hook, want, "{arg}");
2720            assert!(!opts.profile, "{arg} asks for no call of its own");
2721        }
2722
2723        let (opts, _) = compile(&["-c", "-mfentry", "-mno-fentry", "-pg", "a.c"]);
2724        assert_eq!(opts.hook, Hook::Late, "the last one wins");
2725        assert!(opts.profile);
2726    }
2727
2728    /// How much room a patcher is promised, which is one number or two.
2729    ///
2730    /// A command line that did not ask is asserted alongside, because the flag has to be written to
2731    /// mean anything and a build that reserved room nobody asked for would grow every function in
2732    /// it for nothing.
2733    #[test]
2734    fn the_room_a_patcher_is_promised_is_a_number_of_bytes_and_where_they_go() {
2735        let (opts, _) = compile(&["-c", "a.c"]);
2736        assert_eq!(opts.patchable, Patchable::default());
2737        assert!(!opts.patchable.any(), "nothing is reserved unless it was asked for");
2738
2739        let (opts, _) = compile(&["-c", "-fpatchable-function-entry=16", "a.c"]);
2740        assert_eq!(opts.patchable, Patchable { total: 16, before: 0 });
2741
2742        let (opts, _) = compile(&["-c", "-fpatchable-function-entry=5,3", "a.c"]);
2743        assert_eq!(opts.patchable, Patchable { total: 5, before: 3 });
2744        assert_eq!(opts.patchable.after(), 2);
2745
2746        // The last one wins, which is what every other flag of this shape does and what a build
2747        // that adds one to a command line it did not write is relying on.
2748        let (opts, _) = compile(&[
2749            "-c",
2750            "-fpatchable-function-entry=5,3",
2751            "-fpatchable-function-entry=2",
2752            "a.c",
2753        ]);
2754        assert_eq!(opts.patchable, Patchable { total: 2, before: 0 });
2755    }
2756
2757    /// And a request nothing could satisfy is refused rather than rounded into one that can be.
2758    #[test]
2759    fn room_in_front_of_the_label_that_is_more_than_the_room_asked_for_is_refused() {
2760        for arg in ["-fpatchable-function-entry=1,2", "-fpatchable-function-entry=x"] {
2761            let e = parse_args(&args(&["-c", arg, "a.c"])).unwrap_err();
2762            assert!(e.message.contains("is not an amount of room to reserve"), "{}", e.message);
2763        }
2764    }
2765
2766    /// What wraps rather than being undefined, which is two questions and three flags.
2767    ///
2768    /// The older flag is the pair of the newer two, which is gcc's own reading of it, so a build
2769    /// that writes `-fno-strict-overflow` gets both and a build that writes one of the others gets
2770    /// only what it asked for.
2771    #[test]
2772    fn what_overflows_rather_than_being_undefined_is_asked_for_two_ways() {
2773        let (opts, _) = compile(&["-c", "a.c"]);
2774        assert_eq!(opts.wrapping, Wrapping::NONE, "nothing wraps unless it was asked for");
2775
2776        let (opts, _) = compile(&["-c", "-fwrapv", "a.c"]);
2777        assert_eq!(opts.wrapping, Wrapping { signed: true, pointer: false, trap: false });
2778
2779        let (opts, _) = compile(&["-c", "-fwrapv-pointer", "a.c"]);
2780        assert_eq!(opts.wrapping, Wrapping { signed: false, pointer: true, trap: false });
2781
2782        let (opts, _) = compile(&["-c", "-fno-strict-overflow", "a.c"]);
2783        assert_eq!(opts.wrapping, Wrapping::ALL);
2784
2785        // And the last one wins, in both directions. A build that turns one of these on globally
2786        // and off for one directory is relying on that, and so is one that writes the pair and
2787        // then takes half of it back.
2788        let (opts, _) = compile(&["-c", "-fwrapv", "-fno-wrapv", "a.c"]);
2789        assert_eq!(opts.wrapping, Wrapping::NONE);
2790
2791        let (opts, _) = compile(&["-c", "-fno-strict-overflow", "-fstrict-overflow", "a.c"]);
2792        assert_eq!(opts.wrapping, Wrapping::NONE);
2793
2794        let (opts, _) = compile(&["-c", "-fno-strict-overflow", "-fno-wrapv-pointer", "a.c"]);
2795        assert_eq!(opts.wrapping, Wrapping { signed: true, pointer: false, trap: false });
2796    }
2797
2798    /// And the other answer to the signed question cannot be held at the same time as the first.
2799    ///
2800    /// A program cannot both wrap and stop, so writing both is writing a contradiction, and gcc
2801    /// resolves it by letting the last one win rather than by reporting anything. That was measured
2802    /// against gcc 16 rather than read out of the manual, which says nothing about it: `-ftrapv
2803    /// -fwrapv` emits no checked calls and `-fwrapv -ftrapv` emits them.
2804    #[test]
2805    fn a_signed_overflow_that_stops_is_the_other_answer_and_not_a_third_one() {
2806        let (opts, _) = compile(&["-c", "-ftrapv", "a.c"]);
2807        assert_eq!(opts.wrapping, Wrapping { signed: false, pointer: false, trap: true });
2808
2809        let (opts, _) = compile(&["-c", "-fwrapv", "-ftrapv", "a.c"]);
2810        assert_eq!(opts.wrapping, Wrapping { signed: false, pointer: false, trap: true });
2811
2812        let (opts, _) = compile(&["-c", "-ftrapv", "-fwrapv", "a.c"]);
2813        assert_eq!(opts.wrapping, Wrapping { signed: true, pointer: false, trap: false });
2814
2815        let (opts, _) = compile(&["-c", "-ftrapv", "-fno-strict-overflow", "a.c"]);
2816        assert_eq!(opts.wrapping, Wrapping::ALL);
2817
2818        let (opts, _) = compile(&["-c", "-ftrapv", "-fno-trapv", "a.c"]);
2819        assert_eq!(opts.wrapping, Wrapping::NONE);
2820
2821        // And the flag that says what may be assumed says nothing about what happens, so it leaves
2822        // this alone where it takes the wrapping away. gcc does the same.
2823        let (opts, _) = compile(&["-c", "-ftrapv", "-fstrict-overflow", "a.c"]);
2824        assert_eq!(opts.wrapping, Wrapping { signed: false, pointer: false, trap: true });
2825    }
2826
2827    /// And a value nothing means is refused rather than taken for the nearest thing it looks like.
2828    ///
2829    /// `-fcf-protection=all` is the spelling somebody writes from memory, and a compiler that read
2830    /// it as `full` would be guessing, while one that let it fall through to the optimizer's `-f`
2831    /// family would report it as an unknown pass. Neither is the news the build wants.
2832    #[test]
2833    fn a_control_flow_protection_nothing_means_is_refused() {
2834        let e = parse_args(&args(&["-c", "-fcf-protection=all", "a.c"])).unwrap_err();
2835        assert!(e.message.contains("is not a control flow protection"), "{}", e.message);
2836        assert!(e.message.contains("full, branch, return, none or check"), "{}", e.message);
2837    }
2838
2839    #[test]
2840    fn the_link_flags_are_collected_apart_from_the_compilation() {
2841        let (link, _) = linking(&[
2842            "-static",
2843            "-nostartfiles",
2844            "-rdynamic",
2845            "-s",
2846            "-fuse-ld=mold",
2847            "-L/opt/lib",
2848            "-B",
2849            "/opt/tools",
2850            "a.c",
2851        ]);
2852        assert!(link.is_static);
2853        assert!(link.no_startfiles);
2854        assert!(link.export_dynamic);
2855        assert!(link.strip);
2856        assert_eq!(link.use_ld.as_deref(), Some("mold"));
2857        assert_eq!(link.search, vec![PathBuf::from("/opt/lib")]);
2858        assert_eq!(link.prefixes, vec![PathBuf::from("/opt/tools")]);
2859    }
2860
2861    #[test]
2862    fn a_comma_in_dash_wl_separates_two_arguments() {
2863        let (link, _) = linking(&["-Wl,-rpath,/opt/lib", "-Xlinker", "--as-needed", "a.c"]);
2864        assert_eq!(link.passthrough, vec!["-rpath", "/opt/lib", "--as-needed"]);
2865    }
2866
2867    #[test]
2868    fn a_library_keeps_its_place_between_the_objects() {
2869        // Link order is semantic: `-lm` written between two files resolves for the one before
2870        // it and not for the one after, so a library cannot be collected into a list of its own.
2871        // The target is named because the suffix of an object is the target's and this asserts
2872        // on the names: the same command line on a Windows host plans two `.obj` files.
2873        let (_, plan) = linking(&["--target=x86_64-unknown-linux-gnu", "a.c", "-lm", "b.c"]);
2874        let link = plan.link.expect("expected a link step");
2875        assert_eq!(
2876            link.inputs,
2877            vec![
2878                link::Item::File("a.o".into()),
2879                link::Item::Library("m".into()),
2880                link::Item::File("b.o".into()),
2881            ]
2882        );
2883        // And it is not a job, because there is nothing to compile in a library.
2884        assert_eq!(plan.jobs.len(), 2);
2885    }
2886
2887    #[test]
2888    fn a_library_on_a_dash_c_line_is_a_note_rather_than_an_error() {
2889        let (_, plan) = linking(&["-c", "-lm", "a.c"]);
2890        assert!(plan.link.is_none());
2891        assert!(plan.notes.iter().any(|n| n.contains("-lm")), "{:?}", plan.notes);
2892    }
2893
2894    #[test]
2895    fn the_sysroot_reaches_the_linker_as_well_as_the_headers() {
2896        let (link, _) = linking(&["--sysroot=/opt/root", "a.c"]);
2897        assert_eq!(link.sysroot, Some(PathBuf::from("/opt/root")));
2898    }
2899
2900    fn printed(s: &[&str]) -> String {
2901        match parse_args(&args(s)).expect("expected an answer") {
2902            Action::Print(line) => line,
2903            other => panic!("expected an answer, got {other:?}"),
2904        }
2905    }
2906
2907    fn refused(s: &[&str]) -> String {
2908        parse_args(&args(s)).expect_err("expected a refusal").message
2909    }
2910
2911    #[test]
2912    fn a_warning_flag_this_compiler_has_not_heard_of_is_taken_rather_than_refused() {
2913        // The rule in section 4.1, and the reason for it is autoconf: a configure script finds
2914        // out whether a warning flag exists by passing it and looking at the exit status, so a
2915        // compiler that refuses one it does not know fails a script written for a newer GCC.
2916        let (opts, _) = compile(&["-Wall", "-Wextra", "-Wno-format-truncation", "-c", "a.c"]);
2917        assert!(!opts.warnings_are_errors);
2918        assert!(opts.warnings);
2919        // The two spellings that do mean something are still read.
2920        let (opts, _) = compile(&["-Werror", "-c", "a.c"]);
2921        assert!(opts.warnings_are_errors);
2922        let (opts, _) = compile(&["-w", "-c", "a.c"]);
2923        assert!(!opts.warnings);
2924        let (opts, _) = compile(&["-pedantic-errors", "-c", "a.c"]);
2925        assert!(opts.pedantic && opts.warnings_are_errors);
2926    }
2927
2928    #[test]
2929    fn an_argument_for_a_separate_tool_is_refused_rather_than_dropped() {
2930        // Every one of these says something about the output, so the wrong answer is silence.
2931        assert!(refused(&["-Wa,--noexecstack", "-c", "a.c"]).contains("separate assembler"));
2932        assert!(refused(&["-Wp,-DX", "-c", "a.c"]).contains("separate assembler"));
2933        assert!(refused(&["-specs=/x", "a.c"]).contains("-specs= is not supported"));
2934        assert!(refused(&["-mcmodel=kernel", "-c", "a.c"]).contains("small code model"));
2935        assert!(refused(&["-gdwarf-4", "-c", "a.c"]).contains("DWARF 5"));
2936        assert!(refused(&["-Ofast", "-c", "a.c"]).contains("fast math"));
2937        // The word size the target does not have, which is a target this compiler was not asked
2938        // for rather than a flag it does not know.
2939        let no32 = refused(&["--target=x86_64-unknown-linux-gnu", "-m32", "-c", "a.c"]);
2940        assert!(no32.contains("32 bit target"), "{no32}");
2941    }
2942
2943    #[test]
2944    fn the_levels_gcc_spells_differently_are_the_levels_they_mean() {
2945        assert_eq!(compile(&["-O", "-c", "a.c"]).0.opt_level, OptLevel::O1);
2946        assert_eq!(compile(&["-Og", "-c", "a.c"]).0.opt_level, OptLevel::O1);
2947        assert_eq!(compile(&["-O2", "-c", "a.c"]).0.opt_level, OptLevel::O2);
2948    }
2949
2950    #[test]
2951    fn the_machine_flags_that_name_what_we_already_do_are_taken_and_the_rest_are_not() {
2952        let line = ["--target=x86_64-unknown-linux-gnu", "-m64", "-march=x86-64-v3"];
2953        let (opts, _) =
2954            compile(&[&line[..], &["-mtune=native", "-mabi=sysv", "-c", "a.c"]].concat());
2955        assert_eq!(opts.target.to_string(), "x86_64-unknown-linux-gnu");
2956        let wrong = refused(&["--target=x86_64-unknown-linux-gnu", "-mabi=ms", "-c", "a.c"]);
2957        assert!(wrong.contains("sysv convention"), "{wrong}");
2958    }
2959
2960    #[test]
2961    fn the_thread_flag_is_a_macro_and_a_library_and_the_library_goes_last() {
2962        let (opts, plan) = compile(&["-pthread", "-c", "a.c"]);
2963        assert!(opts.defines.iter().any(|d| d == "_REENTRANT"));
2964        // After the input, because a static link takes what it needs from a library when it
2965        // reaches it and not afterwards.
2966        let names: Vec<&str> = plan.jobs.iter().map(|j| j.input.as_str()).collect();
2967        assert_eq!(names, vec!["a.c"]);
2968    }
2969
2970    #[test]
2971    fn the_questions_a_build_system_asks_before_it_compiles_anything() {
2972        let target = "--target=x86_64-unknown-linux-gnu";
2973        assert_eq!(printed(&[target, "-dumpmachine"]), "x86_64-unknown-linux-gnu");
2974        assert_eq!(printed(&[target, "-dumpversion"]), VERSION);
2975        assert_eq!(printed(&[target, "-dumpfullversion"]), VERSION);
2976        assert_eq!(printed(&[target, "-print-multiarch"]), "x86_64-linux-gnu");
2977        // A name nothing holds comes back unchanged, which is GCC's rule and is what makes the
2978        // answer safe to paste into a link line whether or not the file is there.
2979        assert_eq!(printed(&[target, "-print-file-name=no-such-library.a"]), "no-such-library.a");
2980        assert_eq!(printed(&[target, "-print-prog-name=ld"]), "ld");
2981        let dirs = printed(&[target, "-print-search-dirs"]);
2982        assert!(dirs.starts_with("install: "), "{dirs}");
2983        assert!(dirs.contains("\nlibraries: ="), "{dirs}");
2984    }
2985
2986    #[test]
2987    fn the_two_dependency_flags_that_stop_after_the_rule_stop_after_the_rule() {
2988        let (opts, _) = compile(&["-M", "a.c"]);
2989        assert!(opts.deps.emit && opts.deps.instead_of_compiling);
2990        assert!(opts.deps.system_headers, "plain -M lists them");
2991        assert_eq!(opts.emit, EmitKind::Preprocessed);
2992
2993        // Even where a later flag asked for something else, because the family is a mode and
2994        // the mode is what the run is for.
2995        let (opts, _) = compile(&["-M", "-c", "a.c"]);
2996        assert_eq!(opts.emit, EmitKind::Preprocessed);
2997
2998        let (opts, _) = compile(&["-MM", "a.c"]);
2999        assert!(!opts.deps.system_headers);
3000    }
3001
3002    #[test]
3003    fn the_two_that_end_in_d_leave_the_compilation_alone() {
3004        let (opts, _) = compile(&["-MD", "-c", "a.c"]);
3005        assert!(opts.deps.emit && !opts.deps.instead_of_compiling);
3006        assert!(opts.deps.system_headers);
3007        assert_eq!(opts.emit, EmitKind::Object);
3008
3009        let (opts, _) = compile(&["-MMD", "-c", "a.c"]);
3010        assert!(opts.deps.emit && !opts.deps.instead_of_compiling);
3011        assert!(!opts.deps.system_headers);
3012    }
3013
3014    #[test]
3015    fn nothing_puts_the_system_headers_back_once_a_flag_has_taken_them_out() {
3016        // GCC's rule, and not an oversight in it. The flag asking for fewer of them is read as
3017        // the answer, because the other one never asked the question.
3018        let (opts, _) = compile(&["-MM", "-M", "a.c"]);
3019        assert!(!opts.deps.system_headers);
3020        let (opts, _) = compile(&["-MD", "-MMD", "-c", "a.c"]);
3021        assert!(!opts.deps.system_headers);
3022        let (opts, _) = compile(&["-MMD", "-MD", "-c", "a.c"]);
3023        assert!(!opts.deps.system_headers);
3024    }
3025
3026    #[test]
3027    fn a_target_arrives_escaped_from_one_flag_and_untouched_from_the_other() {
3028        let (opts, _) = compile(&["-MM", "-MT", "a b.o", "-MQ", "a b.o", "a.c"]);
3029        assert_eq!(opts.deps.targets, vec!["a b.o".to_owned(), "a\\ b.o".to_owned()]);
3030    }
3031
3032    #[test]
3033    fn the_rest_of_the_family_is_a_file_and_a_switch() {
3034        let (opts, _) = compile(&["-MM", "-MF", "dep.d", "-MP", "a.c"]);
3035        assert_eq!(opts.deps.file.as_deref(), Some("dep.d"));
3036        assert!(opts.deps.phony);
3037
3038        for flag in ["-MF", "-MT", "-MQ"] {
3039            let e = parse_args(&args(&[flag])).unwrap_err();
3040            assert!(e.message.contains("requires an argument"), "{}", e.message);
3041        }
3042    }
3043
3044    /// A directory of sources for one test, removed when the test is done with it.
3045    struct TempTree(PathBuf);
3046
3047    impl Drop for TempTree {
3048        fn drop(&mut self) {
3049            let _ = std::fs::remove_dir_all(&self.0);
3050        }
3051    }
3052
3053    impl TempTree {
3054        fn new(name: &str, files: &[(&str, &str)]) -> TempTree {
3055            let dir = std::env::temp_dir().join(format!("rucc-deps-{}-{name}", std::process::id()));
3056            let _ = std::fs::remove_dir_all(&dir);
3057            std::fs::create_dir_all(&dir).expect("temporary directory should be writable");
3058            for (path, text) in files {
3059                let at = dir.join(path);
3060                if let Some(parent) = at.parent() {
3061                    std::fs::create_dir_all(parent).expect("creating a subdirectory should work");
3062                }
3063                std::fs::write(&at, text).expect("writing a temporary file should work");
3064            }
3065            TempTree(dir)
3066        }
3067
3068        fn path(&self, name: &str) -> String {
3069            self.0.join(name).to_string_lossy().into_owned()
3070        }
3071    }
3072
3073    #[test]
3074    fn the_rule_names_what_the_includes_found_and_names_each_of_them_once() {
3075        // End to end, because the list comes from the preprocessor and the format comes from
3076        // somewhere else, and a test of either half on its own would pass with the two of them
3077        // wired up backwards.
3078        let tree = TempTree::new(
3079            "found",
3080            &[
3081                ("a.c", "#include \"one.h\"\n#include \"two.h\"\nint main(void) { return X; }\n"),
3082                ("one.h", "#define X 0\n"),
3083                ("two.h", "#include \"one.h\"\n"),
3084            ],
3085        );
3086        let out = tree.path("dep.d");
3087        let code = run(&args(&["-MM", "-MF", &out, "-o", &tree.path("a.i"), &tree.path("a.c")]));
3088        assert_eq!(code, 0);
3089
3090        let text = std::fs::read_to_string(&out).expect("the rule should have been written");
3091        let names: Vec<&str> = text.split_whitespace().collect();
3092        // The target, the source, and each header once however many times it was reached.
3093        assert_eq!(names.first(), Some(&"a.o:"), "{text}");
3094        assert_eq!(names.iter().filter(|n| n.ends_with("one.h")).count(), 1, "{text}");
3095        assert_eq!(names.iter().filter(|n| n.ends_with("two.h")).count(), 1, "{text}");
3096        // And the `-o` went to the file the rule replaced, which is left empty rather than
3097        // absent because a makefile that named it as a target will look for it.
3098        assert_eq!(std::fs::read(tree.path("a.i")).expect("the output should exist"), b"");
3099    }
3100
3101    #[test]
3102    fn a_header_that_is_only_reached_under_a_guard_is_still_a_dependency() {
3103        // The multiple-include optimization means the second reach never opens the file. It is
3104        // still a file this translation unit was built from, so it is still in the rule.
3105        let tree = TempTree::new(
3106            "guarded",
3107            &[
3108                ("a.c", "#include \"g.h\"\n#include \"g.h\"\nint main(void) { return 0; }\n"),
3109                ("g.h", "#ifndef G\n#define G\n#endif\n"),
3110            ],
3111        );
3112        let out = tree.path("dep.d");
3113        let code = run(&args(&["-MM", "-MF", &out, "-o", &tree.path("a.i"), &tree.path("a.c")]));
3114        assert_eq!(code, 0);
3115        let text = std::fs::read_to_string(&out).expect("the rule should have been written");
3116        assert_eq!(text.split_whitespace().filter(|n| n.ends_with("g.h")).count(), 1, "{text}");
3117    }
3118
3119    #[test]
3120    fn every_imacros_file_is_read_before_every_include_file_whatever_order_they_were_written() {
3121        // Measured against GCC rather than read: the two flags the other way round produce the
3122        // same output byte for byte, so the command line order between the two families does not
3123        // decide anything and the order within one does. The `-include` file here can only see
3124        // the definition if the `-imacros` file that was written after it ran first.
3125        let tree = TempTree::new(
3126            "preinclude",
3127            &[
3128                ("a.c", "int main(void) { return 0; }\n"),
3129                ("i.h", "#ifdef FROM_MACROS\nint saw_it;\n#else\nint missed_it;\n#endif\n"),
3130                ("m.h", "#define FROM_MACROS 1\nint macros_text;\n"),
3131            ],
3132        );
3133        let out = tree.path("a.i");
3134        let code = run(&args(&[
3135            "-E",
3136            "-include",
3137            &tree.path("i.h"),
3138            "-imacros",
3139            &tree.path("m.h"),
3140            "-o",
3141            &out,
3142            &tree.path("a.c"),
3143        ]));
3144        assert_eq!(code, 0);
3145        let text = std::fs::read_to_string(&out).expect("the output should have been written");
3146        assert!(text.contains("saw_it"), "{text}");
3147        // And the text of the `-imacros` file is thrown away, which is the whole difference
3148        // between the two flags.
3149        assert!(!text.contains("macros_text"), "{text}");
3150    }
3151
3152    #[test]
3153    fn a_file_the_command_line_named_is_a_prerequisite_the_same_as_one_a_directive_named() {
3154        let tree = TempTree::new(
3155            "preinclude-deps",
3156            &[
3157                ("a.c", "int main(void) { return 0; }\n"),
3158                ("i.h", "int from_include;\n"),
3159                ("m.h", "#define M 1\n"),
3160            ],
3161        );
3162        let out = tree.path("dep.d");
3163        let code = run(&args(&[
3164            "-MM",
3165            "-MF",
3166            &out,
3167            "-include",
3168            &tree.path("i.h"),
3169            "-imacros",
3170            &tree.path("m.h"),
3171            "-o",
3172            &tree.path("a.i"),
3173            &tree.path("a.c"),
3174        ]));
3175        assert_eq!(code, 0);
3176        let text = std::fs::read_to_string(&out).expect("the rule should have been written");
3177        assert!(text.contains("i.h"), "{text}");
3178        assert!(text.contains("m.h"), "{text}");
3179    }
3180
3181    #[test]
3182    fn a_command_line_include_that_is_nowhere_on_the_path_is_an_error_and_not_a_warning() {
3183        // Including the directory of the source file, which is not on the path for these: the
3184        // command line was not written there, so a name in it is relative to where the compiler
3185        // was run rather than to where the source sits.
3186        let tree = TempTree::new(
3187            "preinclude-missing",
3188            &[("sub/a.c", "int main(void) { return 0; }\n"), ("sub/beside.h", "int x;\n")],
3189        );
3190        let code = run(&args(&["-E", "-include", "beside.h", "-o", "-", &tree.path("sub/a.c")]));
3191        assert_eq!(code, 1);
3192    }
3193
3194    #[test]
3195    fn a_command_line_that_links_names_the_executable_and_not_the_object_it_went_through() {
3196        // The object a link goes through is in a temporary directory and is gone before `make`
3197        // reads any of this, so the rule that named it would be a rule for a file that is never
3198        // there. The target and the file are both the `-o`, which is the executable.
3199        let (opts, plan) = compile(&["-MD", "sub/a.c", "-o", "prog"]);
3200        assert_eq!(plan.output.as_deref(), Some("prog"));
3201        assert_eq!(deps::default_target("sub/a.c", deps_target_output(&opts, &plan)), "prog");
3202        assert_eq!(
3203            deps::default_file(&opts.deps, "sub/a.c", plan.output.as_deref()).as_deref(),
3204            Some("prog.d")
3205        );
3206    }
3207
3208    #[test]
3209    fn the_plan_keeps_the_output_name_because_the_rule_is_written_from_it() {
3210        let (_, plan) = compile(&["-MMD", "-c", "sub/a.c", "-o", "obj/x.o"]);
3211        assert_eq!(plan.output.as_deref(), Some("obj/x.o"));
3212        let (_, plan) = compile(&["-MMD", "-c", "sub/a.c"]);
3213        assert_eq!(plan.output, None);
3214    }
3215
3216    #[test]
3217    fn usage_fits_on_a_screen() {
3218        // Not a style preference. A help text that scrolls is one nobody reads, and this is
3219        // the cheapest way to keep it honest as flags accumulate. The number goes up only when
3220        // a family of flags arrives that has nowhere to share a line, which the two pass gates
3221        // were and which the two fuel flags and `-fsafety=` now are, and it goes up by exactly
3222        // the lines that family took. The four it went up by last are the flags a build system
3223        // passes without being asked to: how much to say, what machine to generate for, threads,
3224        // and the questions `configure` asks before it compiles anything. The one it went up by
3225        // last is the second line of `--emit`, whose kinds are a family that has now outgrown
3226        // one line and has nowhere else to go. The two it went up by last are the dependency
3227        // family, which is eight flags that share nothing with anything above them. The one it
3228        // went up by last is the four spellings of position independent code, which every
3229        // configure script writes and which could only have shared the link line, and that line
3230        // is already four characters short of the limit. The two it went up by last are the rest
3231        // of the include family, which is six more flags that change where a header is looked for
3232        // and two that name a header outright. The one it went up by last is the pair that keeps
3233        // the intermediate files and times the steps, which belong next to the two flags above
3234        // them that are also about watching a compilation rather than changing one. The two it
3235        // went up by last are the section flags and the visibility flag, which are what a build
3236        // that cares about the size of what it ships and about which names it exports writes, and
3237        // the second of them was already taken and only missing from here. The one it went up by
3238        // last is the stack protector, which is four spellings of one question and which every
3239        // distribution puts on every command line it issues, so a build that reads this list
3240        // looking for it and does not find it has to go and read the specification instead. The one
3241        // it went up by last is the profiler, which is two spellings of the request and two of
3242        // where the call goes, and which is about watching a program run rather than about what is
3243        // generated, so it shares its subject with nothing above it. The one it went up by last is
3244        // the room a function opens with for something to be written over it later, which takes an
3245        // argument of its own shape and is what a kernel build asks for, so it fits beside the
3246        // profiler and nothing else. The one it went up by last is what overflows rather than being
3247        // undefined, which is three spellings of two questions and which a kernel build and a great
3248        // deal of code written before the standard settled both pass. The one it went up by last is
3249        // the other answer to the first of those questions, which could not share the line because
3250        // what it asks for is the opposite of what the flags on that line ask for.
3251        assert!(USAGE.lines().count() < 55, "usage text has grown past one screen");
3252    }
3253}