Skip to main content

rucc_driver/
compile.rs

1//! Running the front end over one file, from the bytes on disk to the typed tree.
2//!
3//! Design: `spec/04-driver-and-cli.md` section 4.3, and the `M2` exit criterion in
4//! `spec/17-milestones.md` that says `--emit=tast` works.
5//!
6//! [`preprocess`](mod@crate::preprocess) stops after phase 4 because `-E` stops there. This
7//! carries on: phase 7, the parse, and the checking. It is one function rather than four composed
8//! ones because of what the four share. The tokens hold interned symbols, the untyped tree holds
9//! tokens, the typed tree holds the untyped tree's spans, and none of them owns the table it is
10//! reading, so one [`Session`] has to outlive all of them and there has to be one place that
11//! holds it.
12
13use std::path::Path;
14
15use rucc_base::Interner;
16use rucc_codegen::coverage::Fired;
17use rucc_codegen::elsewhere::Elsewhere;
18use rucc_codegen::pipeline::{self, Machine};
19use rucc_codegen::pressure::Pressure;
20use rucc_diag::{Diagnostic, Severity, Span};
21use rucc_ir::{FpContract, Pic as IrPic, Visibility as IrVisibility};
22use rucc_lex::{Convert, Keywords, PpToken, convert};
23use rucc_lower::Protector as LowerProtector;
24use rucc_sema::{Checker, Context as CheckContext};
25use rucc_session::{
26    Contract, EmitKind, FileSystem, Options, Padding, Pic, Protector, Session, Visibility,
27};
28use rucc_target::TargetInfo;
29use rucc_tuple::{Arch, ObjectFormat};
30
31use crate::preprocess::render;
32
33/// What a compilation produced, which is text for most of the kinds and bytes for one of them.
34///
35/// Two variants rather than a string, because an object file is not text and a `Vec<u8>` holding
36/// UTF-8 for six kinds and a file format for the seventh would leave every reader guessing which
37/// it had. [`Artifact::Nothing`] is what a compilation that stopped early gives back, and it is
38/// not the same as an empty file: nothing is written for it at all.
39#[derive(Debug, Clone, PartialEq, Eq, Default)]
40pub enum Artifact {
41    /// The compilation stopped before it produced anything, or the kind asked for produces
42    /// nothing yet.
43    #[default]
44    Nothing,
45    /// Text, which is every kind up to and including assembly.
46    Text(String),
47    /// An object file, which is `-c`, and the names a linker can find in it.
48    ///
49    /// The names travel with the bytes rather than beside them because what wants them is the
50    /// archive step, and an index entry that does not match the member is worse than no archive:
51    /// the linker searches the index, pulls the member out, and still reports the name undefined.
52    /// One value holding both is one value the two cannot disagree in.
53    Object {
54        /// The file.
55        bytes: Vec<u8>,
56        /// Every name another object can reach, as the object writer wrote them. Empty is a real
57        /// answer: a translation unit of nothing but `static` functions is a member an archive
58        /// carries and nothing ever pulls out.
59        defines: Vec<String>,
60    },
61}
62
63impl Artifact {
64    /// The bytes to write, which is nothing at all for [`Artifact::Nothing`].
65    #[must_use]
66    pub fn bytes(&self) -> &[u8] {
67        match self {
68            Artifact::Nothing => &[],
69            Artifact::Text(text) => text.as_bytes(),
70            Artifact::Object { bytes, .. } => bytes,
71        }
72    }
73}
74
75/// What compiling one file produced.
76#[derive(Debug, Clone, PartialEq, Eq)]
77pub struct Compiled {
78    /// What to write, which is nothing when the compilation failed or produced nothing.
79    pub artifact: Artifact,
80    /// The diagnostics, already rendered, one per element, in the order they were reported.
81    pub messages: Vec<String>,
82    /// How many of them were errors.
83    pub errors: u32,
84    /// Which lowering rules this file fired, for `-Zrule-coverage`.
85    ///
86    /// Empty for a compilation that stopped before the back end, which every kind up to and
87    /// including `--emit=ir` does. That is not the same as a rule set nothing reaches and the
88    /// caller unions these rather than reading one, so a file that fired nothing adds nothing.
89    pub fired: Fired,
90    /// What the register allocator had to put on the stack, for `-Zregister-pressure`.
91    ///
92    /// Empty for the same compilations `fired` is empty for and for the same reason, since both
93    /// are written by the back end and neither is a fact a file that stopped before it has.
94    pub pressure: Pressure,
95    /// What `-fdump-ir=` asked to see, in the order the passes ran.
96    ///
97    /// The optimizer does not write files, because nothing below the driver in
98    /// `spec/18-package-layout.md` knows what a file is, so the text comes back here and the
99    /// caller decides where it goes.
100    pub dumps: Vec<rucc_opt::Dump>,
101    /// What `-fopt-info` asked to hear, already rendered, one remark per line.
102    ///
103    /// Empty when the flag was not given, and also empty when it was given and no pass had
104    /// anything of the kinds asked for to say. Those two are the same text and different facts,
105    /// which is why a misspelled keyword is an error rather than a quiet nothing.
106    pub remarks: String,
107    /// Every file an `#include` found, for the `-M` family.
108    ///
109    /// The same list `Preprocessed` carries and for the same reason. A `-MD` writes it beside
110    /// the object, so the compiling path needs it as much as the preprocessing one does.
111    pub deps: Vec<rucc_pp::Dependency>,
112    /// What `-save-temps` asked to be kept, which is nothing at all unless it was given.
113    ///
114    /// It comes back from here rather than being produced by a second run of the compiler under
115    /// different flags, because a second run is a second answer: the file a person reads has to
116    /// be the file that was compiled, and two runs of anything with a `__TIME__` in it are not
117    /// the same text.
118    pub temps: Temps,
119}
120
121/// The intermediate text a compilation went through, kept when `-save-temps` asked for it.
122///
123/// Both are `None` on a compilation that was not asked to keep anything, and the assembly is
124/// `None` on one that stopped before there was any. Holding the text rather than writing it is
125/// what keeps this function free of the file system, which is what lets it be tested against a
126/// map from path to bytes.
127#[derive(Debug, Clone, PartialEq, Eq, Default)]
128pub struct Temps {
129    /// Phase 4's output, the same text `-E` would have printed.
130    pub preprocessed: Option<String>,
131    /// The assembly the back end produced on the way to the object file.
132    pub assembly: Option<String>,
133}
134
135impl Compiled {
136    /// Whether anything went wrong badly enough that the output should not be used.
137    #[must_use]
138    pub fn failed(&self) -> bool {
139        self.errors > 0
140    }
141
142    /// The text that was produced, and the empty string for anything that is not text.
143    ///
144    /// A caller that asked for one of the text kinds knows which it asked for, so this saves it
145    /// matching on a variant it has already ruled out.
146    #[must_use]
147    pub fn text(&self) -> &str {
148        match &self.artifact {
149            Artifact::Text(text) => text,
150            _ => "",
151        }
152    }
153}
154
155/// Compiles one file as far as `opts.emit` asks for and renders the result.
156///
157/// `name` is the path as the user wrote it, which is the name every diagnostic about the file
158/// uses. Every kind but the executable produces something today, and that one runs the same front
159/// end and gives back nothing, so that a file with a mistake in it is reported the same way
160/// whichever kind was asked for, rather than compiling silently until the part that is written
161/// notices.
162///
163/// The checking is skipped when the parse reported an error. The two poisoning rules mean a
164/// diagnosed expression produces no further complaints, but a declaration the parser had to skip
165/// past leaves no declaration behind at all, and every later use of that name would be reported
166/// as undeclared. One mistake is worth one message.
167#[must_use]
168pub fn compile(opts: &Options, name: &str, fs: &dyn FileSystem) -> Compiled {
169    let mut sess = Session::new(opts.clone());
170    // Before anything else interns a name. The keyword symbols have to be one unbroken run for
171    // a lookup to be a subtraction, and the preprocessor interns every identifier it reads, so
172    // building this after the expansion would mean building it after `char` had been seen.
173    let keywords = Keywords::new(&mut sess.interner, opts.std, opts.gnu_extensions);
174    let mut diagnostics: Vec<Diagnostic> = Vec::new();
175    // Filled in by the back end when there is one, and empty for every kind that stops before it.
176    let mut fired = Fired::new();
177    // The same, and the other thing the back end is asked to record about itself.
178    let mut pressure = Pressure::new();
179    // Filled in by the optimizer, and only when `-fdump-ir=` asked for something.
180    let mut dumps = Vec::new();
181    let mut remarks = String::new();
182    // Filled in as the compilation goes past each of them, and only under `-save-temps`.
183    let mut temps = Temps::default();
184
185    let bytes = match fs.read(Path::new(name)) {
186        Ok(bytes) => bytes,
187        Err(e) => return failure(format!("{name}: {e}")),
188    };
189    let Ok(file) = sess.sources.add_shared(name, bytes, None) else {
190        return failure(format!("{name}: the source map has no room left for this file"));
191    };
192
193    // Phases 1 to 4. The expanded stream is turned into pp-tokens straight away, because the
194    // include context borrows the source map that rendering a diagnostic reads and the borrow
195    // has to end before anything is rendered.
196    let mut pp = rucc_pp::Preprocessor::with_prefix_map(opts.prefix_map.macros.clone());
197    let predef = rucc_pp::Predef::for_options(opts);
198    let expanded: Vec<PpToken> = {
199        let mut tokens = Vec::new();
200        // The inner block is the borrow. The printer under `-save-temps` reads the source map
201        // that the include context is holding, so the context has to be gone before it runs, and
202        // nothing happens in between, which is what makes the text it prints the text that is
203        // compiled below rather than a second answer to the same question.
204        {
205            let mut cx =
206                rucc_pp::Context::new(&mut sess.interner, &mut sess.sources, fs, &opts.search);
207            cx.lex = rucc_lex::Options::for_dialect(opts.std, opts.gnu_extensions);
208            if pp.predefine(&sess.target, &predef, &mut cx).is_err() {
209                return failure(format!(
210                    "{name}: the source map has no room for the built in macros"
211                ));
212            }
213            if pp.preinclude(&opts.preincludes, &mut tokens, &mut cx).is_err() {
214                return failure(format!("{name}: the source map has no room for the command line"));
215            }
216            tokens.append(&mut pp.run(file, &mut cx));
217        }
218        if opts.save_temps.wanted() {
219            temps.preprocessed = Some(rucc_pp::print(
220                file,
221                &tokens,
222                pp.line_directives(),
223                &sess.sources,
224                &sess.interner,
225                rucc_pp::PrintOptions { line_markers: opts.line_markers },
226            ));
227        }
228        tokens.iter().map(|token| token.to_pp()).collect()
229    };
230    diagnostics.extend(pp.take_diagnostics());
231    // Taken here rather than at the end, because the preprocessor is done with and everything
232    // after this is about the tree it produced.
233    let deps = pp.dependencies().to_vec();
234
235    // Phase 7, which is where a spelling becomes a keyword and a preprocessing number becomes
236    // a constant of a type.
237    let cx = Convert {
238        keywords: &keywords,
239        interner: &sess.interner,
240        target: &sess.target,
241        std: opts.std,
242        gnu: opts.gnu_extensions,
243        pedantic: opts.pedantic,
244    };
245    let (tokens, complaints) = convert(&expanded, &cx);
246    diagnostics.extend(complaints);
247
248    let parsed = rucc_parse::parse(
249        &tokens,
250        rucc_parse::Context {
251            interner: &sess.interner,
252            std: opts.std,
253            gnu: opts.gnu_extensions,
254            pedantic: opts.pedantic,
255            error_limit: opts.error_limit as usize,
256        },
257    );
258    let parse_failed = parsed.diagnostics.iter().any(|d| d.severity.is_fatal());
259    diagnostics.extend(parsed.diagnostics);
260
261    let mut artifact = Artifact::Nothing;
262    // Zero when nothing instruments, which is the truthful summary of a file built without
263    // `-fsafety`: no checks went in, so none is standing, and every call it makes is unmodelled.
264    let mut instrumented = Instrumented::default();
265    if !parse_failed {
266        let mut checker = Checker::new(
267            &parsed.ast,
268            CheckContext {
269                names: &sess.interner,
270                target: &sess.target,
271                std: opts.std,
272                gnu: opts.gnu_extensions,
273                pedantic: opts.pedantic,
274                permissive: opts.permissive,
275                gnu89_inline: opts.gnu89_inline,
276                error_limit: opts.error_limit as usize,
277                // A freestanding program has no C library, so a name that is the library's
278                // everywhere else is the program's own here and means whatever it defined.
279                builtins: opts.builtins && opts.hosted,
280                no_builtin: &opts.no_builtin,
281                short_enums: opts.short_enums,
282                trapping_math: opts.trapping_math,
283            },
284        );
285        checker.check_unit();
286        let checked = checker.finish();
287        if !checked.failed() {
288            match opts.emit {
289                EmitKind::Tast => {
290                    artifact = Artifact::Text(rucc_sema::print(
291                        &checked.tast,
292                        &checked.types,
293                        &sess.interner,
294                    ));
295                }
296                // Nothing past the checker, because a granule is a fact about a layout and a
297                // layout is settled the moment the closing brace is seen. Lowering the
298                // function bodies would take minutes on an amalgamation and answer nothing.
299                EmitKind::TypeGranules => {
300                    artifact = Artifact::Text(rucc_types::granule_report(
301                        &checked.types,
302                        &sess.interner,
303                        &sess.target,
304                    ));
305                }
306                EmitKind::Ir
307                | EmitKind::MirFinal
308                | EmitKind::Asm
309                | EmitKind::Object
310                | EmitKind::Archive
311                | EmitKind::Executable
312                | EmitKind::SafetySummary => {
313                    // What a `.incbin` in an `asm` at file scope names is read through the same
314                    // file system the sources came through, and from where the compiler was run
315                    // rather than from beside the source, because that is where an assembler
316                    // looks for it.
317                    let mut read = |named: &str| {
318                        fs.read(Path::new(named))
319                            .map(|bytes| bytes.as_slice().to_vec())
320                            .map_err(|why| why.to_string())
321                    };
322                    let mut lowered = rucc_lower::lower(
323                        name,
324                        rucc_lower::Context {
325                            tast: &checked.tast,
326                            types: &checked.types,
327                            target: &sess.target,
328                            names: &mut sess.interner,
329                            visibility: match opts.visibility {
330                                Visibility::Default => IrVisibility::Default,
331                                Visibility::Hidden => IrVisibility::Hidden,
332                                Visibility::Protected => IrVisibility::Protected,
333                            },
334                            protector: match opts.protector {
335                                Protector::None => LowerProtector::None,
336                                Protector::Buffers => LowerProtector::Buffers,
337                                Protector::Strong => LowerProtector::Strong,
338                                Protector::All => LowerProtector::All,
339                            },
340                            wrapping: rucc_lower::Wrapping {
341                                signed: opts.wrapping.signed,
342                                pointer: opts.wrapping.pointer,
343                                trap: opts.wrapping.trap,
344                            },
345                            aliasing: opts.strict_aliasing,
346                            padding: opts.padding == Padding::Ignored,
347                            contract: match opts.fp_contract {
348                                Contract::Off => FpContract::Off,
349                                Contract::On => FpContract::On,
350                                Contract::Fast => FpContract::Fast,
351                            },
352                            read: &mut read,
353                        },
354                    );
355                    // The walk reports what it cannot build, and what it did build is printed
356                    // anyway: a file with one construct missing from it is more use to read
357                    // than nothing at all, and the errors are what stop it being compiled.
358                    let failed = lowered.diagnostics.iter().any(|d| d.severity.is_fatal());
359                    if !failed {
360                        // The verifier runs on everything the walk builds, always. It is the
361                        // one check that a bug in the walk cannot talk its way past, and a
362                        // wrong instruction found here costs a message rather than an hour
363                        // in front of a debugger over the assembly it turned into.
364                        if let Err(errors) = rucc_ir::verify(&lowered.module, &sess.interner) {
365                            for error in errors {
366                                diagnostics.push(internal(&format!("invalid IR, {error}")));
367                            }
368                        } else if let Err(complaints) =
369                            instrument(&mut lowered.module, &mut sess.interner, opts)
370                                .map(|done| instrumented = done)
371                        {
372                            diagnostics.extend(complaints);
373                        } else if let Err(complaints) = optimize(
374                            &mut lowered.module,
375                            &sess.interner,
376                            &sess.target,
377                            opts,
378                            name,
379                            &mut dumps,
380                            &mut remarks,
381                        ) {
382                            diagnostics.extend(complaints);
383                        } else if opts.emit == EmitKind::SafetySummary {
384                            // After the optimizer, because the number that matters is how many
385                            // checks are still standing and there is no way to know that before it
386                            // has run. Before the back end, because the back end turns a check into
387                            // a call and a summary of calls is not a summary of checks.
388                            artifact = Artifact::Text(
389                                rucc_safety::summarize(
390                                    &lowered.module,
391                                    &sess.interner,
392                                    name,
393                                    opts.safety.as_str(),
394                                    instrumented.checks,
395                                    instrumented.interposed,
396                                    instrumented.crossings,
397                                )
398                                .render(),
399                            );
400                        } else if opts.emit == EmitKind::Ir {
401                            // After the optimizer rather than before it, so that `--emit=ir -O2`
402                            // is the IR the back end will be given rather than the IR it would
403                            // have been given at `-O0`. There is no other way to see what a pass
404                            // did without reading the assembly it turned into.
405                            artifact =
406                                Artifact::Text(rucc_ir::print(&lowered.module, &sess.interner));
407                        } else {
408                            // The back end, which is every pass after the IR and which is
409                            // where a construct nothing has a rule for is finally noticed.
410                            match generate(
411                                &mut lowered.module,
412                                &mut sess.interner,
413                                &sess.target,
414                                opts,
415                                &mut fired,
416                                &mut pressure,
417                                &mut temps.assembly,
418                            ) {
419                                Ok(made) => artifact = made,
420                                Err(complaints) => diagnostics.extend(complaints),
421                            }
422                        }
423                    }
424                    diagnostics.extend(lowered.diagnostics);
425                }
426                _ => {}
427            }
428        }
429        diagnostics.extend(checked.diagnostics);
430    }
431
432    let mut messages = Vec::with_capacity(diagnostics.len());
433    let mut errors = 0;
434    for diag in &diagnostics {
435        // `-w` drops the warning here rather than at the several hundred places one is raised,
436        // and it drops it before the count, so `-w -Werror` compiles. A warning that was never
437        // raised is not a warning there is anything to promote.
438        if !opts.warnings && diag.severity == Severity::Warning {
439            continue;
440        }
441        if diag.severity.is_fatal()
442            || (diag.severity == Severity::Warning && opts.warnings_are_errors)
443        {
444            errors += 1;
445        }
446        messages.push(render(diag, &sess.sources, opts.warnings_are_errors));
447    }
448    if errors > 0 {
449        // A tree built from a file that did not compile is not a tree anything should read.
450        artifact = Artifact::Nothing;
451    }
452    // Kept even when the compilation failed, because a rule that fired did fire and a report about
453    // which rules a corpus reaches should not lose the ones a file with a mistake in it reached.
454    Compiled { artifact, messages, errors, fired, pressure, dumps, remarks, deps, temps }
455}
456
457/// Reads one file of IR, checks it, and prints it back.
458///
459/// This is the compiler's own textual IR arriving as an input rather than leaving as an output,
460/// which is what makes the round trip in the M2 exit criterion something to run rather than
461/// something to believe: what the printer wrote is read back, verified, and written again, and
462/// the two files are either the same bytes or they are not.
463///
464/// The verifier runs here for the reason it runs after the walk. A module that was printed by
465/// this compiler has been through it once already, and one that a person edited has not.
466#[must_use]
467pub fn compile_ir(opts: &Options, name: &str, fs: &dyn FileSystem) -> Compiled {
468    let mut sess = Session::new(opts.clone());
469    if opts.emit != EmitKind::Ir {
470        return failure(format!(
471            "{name}: an input of IR can only be emitted as IR, and `--emit={}` asks for what \
472             the C in front of it became",
473            opts.emit.as_str()
474        ));
475    }
476    let bytes = match fs.read(Path::new(name)) {
477        Ok(bytes) => bytes,
478        Err(e) => return failure(format!("{name}: {e}")),
479    };
480    let Ok(text) = std::str::from_utf8(bytes.as_slice()) else {
481        return failure(format!("{name}: this is not text, so it is not IR"));
482    };
483
484    let module = match rucc_ir::parse(text, &mut sess.interner) {
485        Ok(module) => module,
486        Err(error) => {
487            return failure(format!("{name}:{}: {}", error.line, error.message));
488        }
489    };
490    let mut diagnostics: Vec<Diagnostic> = Vec::new();
491    if let Err(errors) = rucc_ir::verify(&module, &sess.interner) {
492        for error in errors {
493            diagnostics.push(invalid(&format!("invalid IR, {error}")));
494        }
495    }
496    let mut messages = Vec::with_capacity(diagnostics.len());
497    for diag in &diagnostics {
498        messages.push(render(diag, &sess.sources, opts.warnings_are_errors));
499    }
500    let errors = u32::try_from(messages.len()).unwrap_or(u32::MAX);
501    let artifact = if errors > 0 {
502        Artifact::Nothing
503    } else {
504        Artifact::Text(rucc_ir::print(&module, &sess.interner))
505    };
506    // Nothing here reaches the back end, so no rule fired and there is nothing to record.
507    Compiled {
508        artifact,
509        messages,
510        errors,
511        fired: Fired::new(),
512        pressure: Pressure::new(),
513        dumps: Vec::new(),
514        remarks: String::new(),
515        deps: Vec::new(),
516        temps: Temps::default(),
517    }
518}
519
520/// Puts the memory safety checks in and redirects the calls that cross the boundary, when
521/// `-fsafety=` asked for them.
522///
523/// Between the walk and the optimizer, which is where section 15.3 of
524/// `spec/safe-memory/15-integration.md` puts it and which is the whole design in one line: the
525/// checks go in while the addresses the program computes still exist, and the optimizer then
526/// discharges the ones it can prove. Every sanitizer that came before instruments after the
527/// optimizer so that its checks cannot be deleted, and pays for all of them forever.
528///
529/// The calls to the C library are redirected here too, and in the same window and for a related
530/// reason. `spec/safe-memory/10-boundaries.md` section 10.3 wants a `memcpy` modelled by a wrapper
531/// that performs the judgements, and `rucc_safety::wrap` is why that has to happen before the
532/// optimizer sees the call rather than after.
533///
534/// The verifier runs again afterwards, for the reason it runs after the walk. This pass rewrites
535/// every function in the module, and a pass that produced IR nothing else accepts should say so
536/// here rather than in the assembly it turned into.
537///
538/// # Errors
539///
540/// When the inserted checks left the module in a state the verifier refuses, which is a bug in
541/// this compiler and not in the program being compiled.
542fn instrument(
543    module: &mut rucc_ir::Module,
544    names: &mut Interner,
545    opts: &Options,
546) -> Result<Instrumented, Vec<Diagnostic>> {
547    if !opts.safety.instruments() {
548        return Ok(Instrumented::default());
549    }
550    let checks = rucc_safety::run(module, opts.subobject, opts.promise, opts.races);
551    // Before the optimizer rather than beside the check lowering, which is what
552    // `rucc_safety::wrap` argues out: `memcpy` is a name an optimizer knows things about, and a
553    // pass that turns a short copy into a pair of loads and stores would leave behind accesses the
554    // check insertion has already finished walking past.
555    let interposed = rucc_safety::redirect(module, names);
556    // After the redirection, so that a call this build models with a wrapper is not also counted
557    // as a crossing it did not model.
558    let crossings = rucc_safety::witness(module, names);
559    match rucc_ir::verify(module, names) {
560        Ok(()) => Ok(Instrumented { checks, interposed, crossings }),
561        Err(errors) => Err(errors
562            .iter()
563            .map(|e| internal(&format!("invalid IR after check insertion, {e}")))
564            .collect()),
565    }
566}
567
568/// What the instrumentation did, which nothing but the summary reads.
569///
570/// Carried out of [`instrument`] rather than recovered from the module afterwards because neither
571/// number survives the optimizer: a check that was discharged leaves nothing behind saying it was
572/// ever there, and a call that was pointed at a wrapper looks like a call that always named one.
573#[derive(Clone, Copy, Debug, Default)]
574struct Instrumented {
575    /// How many checks of each class went in.
576    checks: rucc_safety::Counts,
577    /// How many calls were pointed at an interposition wrapper.
578    interposed: usize,
579    /// How many places a pointer crosses to or from code this build did not instrument.
580    crossings: rucc_safety::Sites,
581}
582
583/// Runs the optimizer over the module, and collects whatever the dumps asked for.
584///
585/// The level chooses a pipeline, the `-f` flags edit it, and at `-O0` there is nothing in it, so
586/// this is a walk over an empty list rather than a branch on the level. See section 9.1 of
587/// `spec/09-optimizer.md` for why the pipelines are written out rather than assembled.
588///
589/// # Errors
590///
591/// When a pass left the module in a state the verifier refuses, which is a bug in the pass and
592/// not in the program being compiled, so it is reported as an internal error the way a bad
593/// lowering is.
594fn optimize(
595    module: &mut rucc_ir::Module,
596    names: &Interner,
597    target: &TargetInfo,
598    opts: &Options,
599    file: &str,
600    dumps: &mut Vec<rucc_opt::Dump>,
601    remarks: &mut String,
602) -> Result<(), Vec<Diagnostic>> {
603    let mut settings = rucc_opt::Options::for_level(opts.opt_level);
604    // What the analyses that read a body may believe about it. The same question the back end asks
605    // about addresses, with one thing on top: `-fno-semantic-interposition` is the build promising
606    // that a name it exports is the one that will run, which is what every distribution builds a
607    // library with. It says nothing about how an address is reached, and gcc does not change that
608    // under the flag either, so the back end is not given this value.
609    settings.interposition = match opts.interposition {
610        true => replaceable(target, opts),
611        false => IrPic::Executable,
612    };
613    settings.toggles.clone_from(&opts.passes);
614    settings.fuel = opts.pass_fuel.iter().cloned().collect();
615    settings.global_fuel = opts.pass_fuel_global;
616    settings.verify |= opts.verify_each;
617    for (on, spec) in &opts.pass_gates {
618        // Same argument as the dumps below: every spelling in here was checked while the
619        // arguments were parsed, so a rejection now is this compiler disagreeing with itself.
620        if let Err(why) = settings.gates.add(*on, spec) {
621            return Err(vec![internal(&why)]);
622        }
623    }
624    for spec in &opts.dump_ir {
625        // Every spelling in here was checked while the arguments were parsed, so a rejection
626        // now is this compiler disagreeing with itself rather than the command line being wrong.
627        if let Err(why) = settings.dumps.add(spec) {
628            return Err(vec![internal(&why)]);
629        }
630    }
631    let mut wants = rucc_opt::Wants::none();
632    for spec in &opts.opt_info {
633        // Same argument as the dumps above: every spelling was checked while the arguments were
634        // parsed, so a rejection now is the compiler disagreeing with itself.
635        if let Err(why) = wants.add(spec) {
636            return Err(vec![internal(&why)]);
637        }
638    }
639    let report = rucc_opt::run(module, names, &settings);
640    remarks.push_str(&rucc_opt::optinfo::render(file, &report, names, wants));
641    dumps.extend(report.dumps);
642    match report.broke.is_empty() {
643        true => Ok(()),
644        false => Err(report.broke.iter().map(|why| internal(why)).collect()),
645    }
646}
647
648/// Runs the back end over every function in `module` and writes what came out.
649///
650/// One machine function per definition in the module, in the order the module holds them, every
651/// register physical and every frame offset a constant. A declaration has no body and is skipped,
652/// because there is nothing in it to compile.
653///
654/// What the last step is, is the only thing `--emit=mir-final`, `-S` and `-c` disagree about. The
655/// three read the same functions and differ in whether they are printed as machine IR, printed as
656/// assembly, or encoded and put in a file, which is the point of section 11.1 of
657/// `spec/11-asm-objects-debug.md`: a listing that disagrees with the object file beside it is
658/// worse than no listing, and the way to make that impossible is to have one description of an
659/// instruction and two ways of writing it down.
660///
661/// # Errors
662///
663/// One diagnostic per function the back end could not compile, or one about the target when no
664/// back end covers it at all. Every function is attempted rather than stopping at the first, so a
665/// file with three constructs missing from the rule set reports three rather than one at a time.
666///
667/// `assembly` is where `-save-temps` gets its listing from on the path that does not print one,
668/// which is the same functions written the other way rather than a second compilation of the same
669/// file. A listing that disagrees with the object beside it would be worse than none.
670/// Whether a name this file exports is one another object may define or replace.
671///
672/// The link that reads the object decides half of what is in it, and the command line is where that
673/// is said, which is why the flag reaches this far down. See #756.
674///
675/// ELF only, because it is a question about a format rather than about a machine and the other two
676/// answer it differently. Mach-O has a two level namespace, so a name a library defines is bound to
677/// that library and is not replaced by a definition loaded earlier, and it has no copy relocations,
678/// so a variable defined elsewhere needs the table whichever link is coming. COFF decides what
679/// leaves a DLL by an export table the linker is handed. Neither has an object writer here yet, so
680/// what this does is decline to say the ELF answer about them.
681fn replaceable(target: &TargetInfo, opts: &Options) -> IrPic {
682    match (target.tuple.os().object_format(), opts.pic) {
683        (Some(ObjectFormat::Elf), Pic::Library) => IrPic::Library,
684        _ => IrPic::Executable,
685    }
686}
687
688fn generate(
689    module: &mut rucc_ir::Module,
690    names: &mut Interner,
691    target: &TargetInfo,
692    opts: &Options,
693    fired: &mut Fired,
694    pressure: &mut Pressure,
695    assembly: &mut Option<String>,
696) -> Result<Artifact, Vec<Diagnostic>> {
697    let Some(machine) = Machine::for_target(target) else {
698        return Err(vec![unsupported(&format!(
699            "there is no back end for {} in this compiler yet, so there is nothing to generate",
700            target.tuple
701        ))]);
702    };
703    // Refused rather than dropped. A command line that asks for a stack protector on a target
704    // that has nowhere to keep the word one is compared against would otherwise get code with no
705    // protection in it and no indication that the flag did nothing, which is the one outcome worse
706    // than the error. Windows is the case: it has a protector and it is a different mechanism.
707    if opts.protector != Protector::None && machine.conv.guard.is_none() {
708        return Err(vec![unsupported(&format!(
709            "{} is not supported for {} yet, because the stack protector on that target is not \
710             the one this compiler writes",
711            opts.protector, target.tuple
712        ))]);
713    }
714    // The same answer for the same reason. What says a file was built to have its control flow
715    // checked is a note, the note is an ELF one, and a target whose objects are not ELF has nowhere
716    // to put it: the landing pads would go in and nothing would ever turn the check on. Windows has
717    // the same hardware and asks for it a different way, which is a bit in the image the linker is
718    // told to set rather than anything a compiler writes into an object.
719    if opts.control.any() && target.tuple.os().object_format() != Some(ObjectFormat::Elf) {
720        return Err(vec![unsupported(&format!(
721            "-fcf-protection={} is not supported for {} yet, because what says a file was built \
722             for it there is not the note this compiler writes",
723            opts.control, target.tuple
724        ))]);
725    }
726    // And once more. A profiled build is one whose functions call a routine the runtime provides,
727    // and a target whose runtime provides no such routine would get a call to a name nothing
728    // defines, which is a link error a long way from the flag that caused it. Windows profiles a
729    // build by calling something else, asked for a different way and taking its argument in a
730    // register, so it is not this hook spelled differently.
731    let profile = match machine.conv.trace {
732        Some(trace) => opts.profile.then(|| opts.hook.early(trace.fentry)),
733        None if opts.profile => {
734            return Err(vec![unsupported(&format!(
735                "-pg is not supported for {} yet, because the profiler's hook on that target is \
736                 not the one this compiler calls",
737                target.tuple
738            ))]);
739        }
740        None => None,
741    };
742    // And once more. The room a patcher was promised is only half the feature: the other half is a
743    // section listing where every function's room is, and both the section's shape and the way it
744    // points at the text it belongs to are ELF's. A format that has no such section would take the
745    // nops and quietly lose the list, which is a build that looks patchable and is not.
746    if opts.patchable.any() && target.tuple.os().object_format() != Some(ObjectFormat::Elf) {
747        return Err(vec![unsupported(&format!(
748            "-fpatchable-function-entry= is not supported for {} yet, because what records where \
749             the room is there is not the section this compiler writes",
750            target.tuple
751        ))]);
752    }
753    let flags = pipeline::Flags {
754        frame_pointer: opts.frame_pointer,
755        red_zone: opts.red_zone,
756        stack_clash: opts.stack_clash,
757        landing: opts.control.branch(),
758        profile: match profile {
759            None => pipeline::Profile::No,
760            Some(true) => pipeline::Profile::Early,
761            Some(false) => pipeline::Profile::Late,
762        },
763        patch: pipeline::Room { after: opts.patchable.after(), before: opts.patchable.before },
764        // On at every level above `-O0`, which is where gcc turns `-freorder-blocks` on
765        // (`gcc/opts.cc:604`) and what `spec/optimizer/38-scheduling-and-layout.md` section 38.3
766        // reads off that: it is one of the earliest optimizations there is, it is nearly free,
767        // and it helps every target. `-O0` keeps the order the shape of the graph gives, so that
768        // the blocks come out in the order they were written and a person stepping through the
769        // code walks down the screen.
770        reorder: opts.reorder_blocks.unwrap_or_else(|| opts.opt_level.runs_optimizer()),
771        // On at every level above `-O0`, for the reason the line above is off at it. Sharing one
772        // run of bytes between two locals is a smaller frame and a worse debugger: a variable that
773        // is out of scope reads as whatever took its place, which is what `-O0` exists not to do.
774        // Above it the frame is the win, and `-fstack-reuse=` says either answer at any level.
775        reuse: opts.stack_reuse.unwrap_or_else(|| opts.opt_level.runs_optimizer()),
776    };
777
778    // The checks become calls here rather than beside the insertion, because the id each one
779    // carries is an index into a table and a row for a check the optimizer deleted is a row nothing
780    // will ever name. Section 6.3.1 of `spec/safe-memory/06-instrumentation.md` is what this
781    // eventually becomes and `rucc_safety::lower` says why it is not that yet.
782    //
783    // It is inside the back end rather than beside the optimizer so that `--emit=ir` still shows
784    // the checks. The IR a person reads should say what the compiler decided, not how it spelled it
785    // for the machine.
786    if opts.safety.instruments() {
787        // Which calls hand back storage, which the lowering needs and `-O0` has not worked out.
788        // `rucc_opt::pipeline` runs this only when some pass in the run reads the summaries, since a
789        // flag nothing reads is noise in a dump, and at `-O0` nothing did. Something does now: the
790        // capability for a pointer an allocator just returned is the one capability that is exact
791        // and costs a load, and `rucc_safety::slot` finds those sites by the flag. The safety suite
792        // runs at `-O0`, so without this the cheap case would be the one case that never happens.
793        //
794        // Safe to run twice and safe to run late, because it only ever sets the flag and never
795        // clears one, so a build that had it already gets the same module back.
796        rucc_opt::heap::annotate(module, names);
797        rucc_safety::lower(module, names);
798        if let Err(errors) = rucc_ir::verify(module, names) {
799            return Err(errors
800                .iter()
801                .map(|e| internal(&format!("invalid IR after check lowering, {e}")))
802                .collect());
803        }
804    }
805
806    // Worked out before the loop and not inside it, because it reads the whole module and the loop
807    // is holding one function of it. It has to be after the check lowering above, since that adds
808    // calls to the runtime and so can add a name this file does not define.
809    //
810    // The link that reads the object decides half of what is in it, and the command line is where
811    // that is said, which is why the flag reaches this far down. See #756.
812    //
813    let elsewhere = Elsewhere::of(module, replaceable(target, opts));
814
815    let mut funcs = Vec::new();
816    let mut complaints = Vec::new();
817    for id in module.funcs() {
818        if module[id].is_declaration() {
819            continue;
820        }
821        match pipeline::compile_recording(
822            &mut module[id],
823            names,
824            &machine,
825            &elsewhere,
826            flags,
827            fired,
828            pressure,
829        ) {
830            Ok(func) => funcs.push(func),
831            Err(why) => {
832                let name = names.resolve(module[id].name).to_owned();
833                // The function knows where the instruction came from, so the message lands on
834                // the line somebody wrote rather than on the file as a whole.
835                let span = why.inst().map_or(Span::DUMMY, |inst| module[id].span(inst));
836                let said = format!("cannot generate code for '{name}': {why}");
837                complaints.push(unsupported_at(&said, span));
838            }
839        }
840    }
841    if !complaints.is_empty() {
842        return Err(complaints);
843    }
844    // The variables the file defines, which go through the back end the way the functions did not:
845    // there is nothing in a variable to select instructions for, so the module is what says what
846    // one is right up to the point where it is written down.
847    // The second names go the same way and for the same reason, and they are neither a function
848    // nor a variable: an alias is an entry in the symbol table and no bytes of anything.
849    let (globals, aliases) = match opts.emit {
850        EmitKind::Asm | EmitKind::Object | EmitKind::Archive | EmitKind::Executable => (
851            rucc_asm::globals(module, names, target.object_format).map_err(refused)?,
852            rucc_asm::aliases(module, names).map_err(refused)?,
853        ),
854        _ => (rucc_asm::Globals::default(), Vec::new()),
855    };
856    // A failure in either of the last two is a bug here rather than a program this compiler is
857    // behind on, because every instruction in a function that got this far came out of the same
858    // description both of them read and every register in it has been allocated.
859    let unwind = opts.unwinds();
860    match opts.emit {
861        EmitKind::Asm => {
862            rucc_asm::print(&funcs, &globals, &aliases, names, target, unwind, output(opts, target))
863                .map(Artifact::Text)
864                .map_err(refused)
865        }
866        // An executable is an object as far as this gets: one is what each file of a link
867        // contributes, and the linker is what turns them into the other. An archive is the same
868        // again, with the archive writer in place of the linker.
869        EmitKind::Object | EmitKind::Archive | EmitKind::Executable => {
870            if opts.save_temps.wanted() {
871                let listing = rucc_asm::print(
872                    &funcs,
873                    &globals,
874                    &aliases,
875                    names,
876                    target,
877                    unwind,
878                    output(opts, target),
879                );
880                *assembly = Some(listing.map_err(refused)?);
881            }
882            let text = rucc_asm::assemble(&funcs, names, target, unwind).map_err(refused)?;
883            let data = globals.image();
884            // A format with no writer is a target this compiler is behind on and anything else
885            // the writer refused is a bug here, and the two are not the same news to get.
886            let bytes = rucc_object::write(&text, &data, &aliases, target, output(opts, target))
887                .map_err(wrote)?;
888            // Asked of the writer rather than worked out from the same three values here, so that
889            // what the archive's index says and what is in the member cannot come apart. It is
890            // wanted only by `--emit=archive` and is cheap enough that the other two kinds are not
891            // worth a second path.
892            let defines = rucc_object::defines(&text, &data, &aliases, target).map_err(wrote)?;
893            Ok(Artifact::Object { bytes, defines })
894        }
895        _ => Ok(Artifact::Text(rucc_mir::print(&funcs, names, target.regs))),
896    }
897}
898
899/// What the command line decided about the file being written, in the words the assembler and the
900/// object writer use.
901///
902/// Two spellings of the same facts, because the flags are the command line's and the answer the two
903/// writers want is the object format's. The conversion is here rather than in either of them so
904/// that the two output paths are handed the same thing and cannot come to disagree about what is
905/// in a file.
906///
907/// The feature word is empty on a machine whose bits these are not. It is the x86 one, and a target
908/// that wanted its control flow checked would want a property of its own with a key of its own, so
909/// writing this one there would be recording something untrue rather than recording nothing.
910fn output(opts: &Options, target: &TargetInfo) -> rucc_object::Output {
911    let mut features = 0;
912    if target.tuple.arch() == Arch::X86_64 {
913        if opts.control.branch() {
914            features |= rucc_object::Property::IBT;
915        }
916        if opts.control.ret() {
917            features |= rucc_object::Property::SHSTK;
918        }
919    }
920    rucc_object::Output {
921        sections: rucc_object::Sections {
922            functions: opts.function_sections,
923            data: opts.data_sections,
924        },
925        property: rucc_object::Property { features },
926    }
927}
928
929/// What the object writer said, as the kind of news it is.
930///
931/// A format with no writer is a target this compiler is behind on, which is a program nobody can
932/// compile today and not a mistake in the one being compiled. Anything else it refused is a bug
933/// here, because every value it was handed came out of this compiler.
934fn wrote(why: rucc_object::Error) -> Vec<Diagnostic> {
935    match why {
936        rucc_object::Error::Format { .. } => vec![unsupported(&why.to_string())],
937        rucc_object::Error::Refused { .. } => vec![internal(&why.to_string())],
938    }
939}
940
941/// What the assembler said, as the kind of news it is.
942///
943/// Two of these are about a program and the rest are about this compiler. A thread-local variable
944/// and an ifunc are both valid C that the back end does not build yet, and everything else the
945/// assembler refuses is something that should never have reached it.
946fn refused(why: rucc_asm::Error) -> Vec<Diagnostic> {
947    match why {
948        rucc_asm::Error::Thread { .. } | rucc_asm::Error::IFunc { .. } => {
949            vec![unsupported(&why.to_string())]
950        }
951        _ => vec![internal(&why.to_string())],
952    }
953}
954
955/// A diagnostic about a program this compiler is not finished enough to compile.
956///
957/// Not an internal error, because nothing here is wrong: the program is valid C and the part of
958/// the back end that would handle it has not been written. The note says so, so that a report
959/// about one of these is filed against the milestone rather than as a miscompilation.
960fn unsupported(message: &str) -> Diagnostic {
961    unsupported_at(message, Span::DUMMY)
962}
963
964/// The same, about somewhere in the file rather than about the file.
965///
966/// The note names the issue tracker rather than `spec/17-milestones.md`, which is a document
967/// about the plan: a reader who follows it wants to know whether the construct in front of them
968/// is already written down as work, and the milestone list does not answer that.
969fn unsupported_at(message: &str, span: Span) -> Diagnostic {
970    Diagnostic::error(message.to_owned(), span)
971        .with_code("E0653")
972        .note("this construct is not lowered yet, see https://github.com/tamnd/rucc/issues", span)
973}
974
975/// A diagnostic about IR that was handed to us rather than built by us.
976fn invalid(message: &str) -> Diagnostic {
977    Diagnostic::error(message.to_owned(), Span::DUMMY).with_code("E0661")
978}
979
980/// A diagnostic about this compiler rather than about the program it was given.
981fn internal(message: &str) -> Diagnostic {
982    Diagnostic::error(format!("internal error: {message}"), Span::DUMMY)
983        .with_code("E0652")
984        .note("this is a bug in rucc rather than in the program, please report it", Span::DUMMY)
985}
986
987/// A result that is nothing but one message, for the failures that happen before there is
988/// anything to compile.
989fn failure(message: String) -> Compiled {
990    Compiled {
991        artifact: Artifact::Nothing,
992        messages: vec![format!("rucc: error: {message}")],
993        errors: 1,
994        fired: Fired::new(),
995        pressure: Pressure::new(),
996        dumps: Vec::new(),
997        remarks: String::new(),
998        deps: Vec::new(),
999        temps: Temps::default(),
1000    }
1001}
1002
1003#[cfg(test)]
1004mod tests {
1005    use rucc_session::{MemoryFileSystem, Std};
1006    use rucc_target::Triple;
1007
1008    use super::*;
1009
1010    fn options() -> Options {
1011        let mut opts = Options::new("x86_64-unknown-linux-gnu".parse::<Triple>().unwrap());
1012        opts.emit = EmitKind::Tast;
1013        opts
1014    }
1015
1016    fn run(opts: &Options, source: &str) -> Compiled {
1017        let mut fs = MemoryFileSystem::new();
1018        fs.insert("/main.c", source.to_owned().into_bytes());
1019        compile(opts, "/main.c", &fs)
1020    }
1021
1022    /// Options with the compiler's own headers on the search path and nothing else, which is
1023    /// what a freestanding compilation is. There is no file system underneath these tests,
1024    /// so a header that reached for one would fail to resolve and say so.
1025    fn freestanding() -> Options {
1026        let mut opts = options();
1027        opts.hosted = false;
1028        opts.search.push_system(rucc_session::runtime::DIR);
1029        opts
1030    }
1031
1032    /// The typed tree of a freestanding `source`, insisting that it compiled cleanly.
1033    fn shipped(source: &str) -> String {
1034        let result = run(&freestanding(), source);
1035        assert_eq!(result.messages, Vec::<String>::new(), "expected this to compile:\n{source}");
1036        result.text().to_owned()
1037    }
1038
1039    /// The typed tree of `source`, insisting that it compiled cleanly.
1040    fn tast(source: &str) -> String {
1041        let result = run(&options(), source);
1042        assert_eq!(result.messages, Vec::<String>::new(), "expected this to compile:\n{source}");
1043        result.text().to_owned()
1044    }
1045
1046    #[test]
1047    fn the_shipped_stdarg_declares_a_list_and_the_four_operators() {
1048        let text = shipped(concat!(
1049            "#include <stdarg.h>\n",
1050            "int sum(int n, ...) {\n",
1051            "  va_list ap, copy;\n",
1052            "  va_start(ap, n);\n",
1053            "  va_copy(copy, ap);\n",
1054            "  int total = va_arg(ap, int) + va_arg(copy, int);\n",
1055            "  va_end(ap);\n",
1056            "  va_end(copy);\n",
1057            "  return total;\n",
1058            "}\n",
1059        ));
1060        assert!(text.contains("va-start"), "{text}");
1061        assert!(text.contains("va-copy"), "{text}");
1062        assert!(text.contains("va-arg"), "{text}");
1063        assert!(text.contains("va-end"), "{text}");
1064    }
1065
1066    /// glibc includes `<stdarg.h>` this way from every header that declares a `vprintf`, and
1067    /// what it wants is the type without the four macro names. Answering the whole header
1068    /// would put `va_start` in the way of a program that has its own.
1069    #[test]
1070    fn stdarg_hands_out_the_type_alone_when_that_is_all_that_was_asked_for() {
1071        let text = shipped(concat!(
1072            "#define __need___va_list\n",
1073            "#include <stdarg.h>\n",
1074            "int vprint(const char *f, __gnuc_va_list ap);\n",
1075            "#ifdef va_start\n",
1076            "#error va_start should not be defined\n",
1077            "#endif\n",
1078            "#ifdef _VA_LIST_DEFINED\n",
1079            "#error va_list should not have been made\n",
1080            "#endif\n",
1081        ));
1082        assert!(text.contains("vprint"), "{text}");
1083    }
1084
1085    /// The same protocol on `<stddef.h>`, which glibc uses far more heavily: `<stdio.h>` asks
1086    /// for `size_t` and `NULL` and would be wrong to receive `offsetof` as well.
1087    #[test]
1088    fn stddef_answers_one_piece_at_a_time_and_the_next_request_still_gets_through() {
1089        let text = shipped(concat!(
1090            "#define __need_size_t\n",
1091            "#include <stddef.h>\n",
1092            "#ifdef offsetof\n",
1093            "#error offsetof should not be defined yet\n",
1094            "#endif\n",
1095            "#define __need_ptrdiff_t\n",
1096            "#include <stddef.h>\n",
1097            "#include <stddef.h>\n",
1098            "size_t a;\n",
1099            "ptrdiff_t b;\n",
1100            "wchar_t c;\n",
1101            "max_align_t d;\n",
1102            "void *e = NULL;\n",
1103            "struct P { int x; long y; };\n",
1104            "size_t f = offsetof(struct P, y);\n",
1105        ));
1106        assert!(text.contains("decl #0 a : unsigned long"), "{text}");
1107        assert!(text.contains("decl #1 b : long"), "{text}");
1108    }
1109
1110    #[test]
1111    fn the_shipped_limits_and_float_are_the_targets_own_answers() {
1112        let text = shipped(concat!(
1113            "#include <limits.h>\n",
1114            "#include <float.h>\n",
1115            "int bits = CHAR_BIT;\n",
1116            "long big = LONG_MAX;\n",
1117            "int low = INT_MIN;\n",
1118            "int radix = FLT_RADIX;\n",
1119            "int digits = DBL_MANT_DIG;\n",
1120        ));
1121        assert!(text.contains("const 8 : int"), "{text}");
1122        assert!(text.contains("const 9223372036854775807 : long"), "{text}");
1123        assert!(text.contains("const 2 : int"), "{text}");
1124        assert!(text.contains("const 53 : int"), "{text}");
1125    }
1126
1127    /// Freestanding, so there is no library header to chain to and `<stdint.h>` writes the
1128    /// whole set out itself. The widths are the ones the target picked, which is the only
1129    /// reason this header is the compiler's.
1130    #[test]
1131    fn the_shipped_stdint_writes_the_whole_set_when_there_is_no_library_to_defer_to() {
1132        let text = shipped(concat!(
1133            "#include <stdint.h>\n",
1134            "int64_t a = INT64_C(1);\n",
1135            "uint_least16_t b;\n",
1136            "intptr_t c;\n",
1137            "uintmax_t d = UINTMAX_MAX;\n",
1138            "int wide = sizeof(int_fast64_t);\n",
1139        ));
1140        assert!(text.contains("decl #0 a : long"), "{text}");
1141        assert!(text.contains("decl #1 b : unsigned short"), "{text}");
1142        assert!(text.contains("decl #2 c : long"), "{text}");
1143    }
1144
1145    /// `<mmintrin.h>` is the base of the vector header chain and the first one whose contents
1146    /// are C rather than declarations, so what this checks is that the C in it compiles: a
1147    /// header that is nothing but definitions fails as a whole or not at all.
1148    ///
1149    /// What the intrinsics answer is not checked here and cannot be, because the answer is
1150    /// only interesting next to another compiler's. Every intrinsic in the header was built
1151    /// and run against GCC 16.2.0 on the same inputs, at `-O0`, `-O1`, `-O2` and `-Os`, and
1152    /// gave the same bytes in all four. Carrying that comparison rather than repeating it by
1153    /// hand needs a facet in `tamnd/rucc-corpus` that works out the expected bytes itself,
1154    /// which is a second implementation of MMX and is `tamnd/rucc#1150`.
1155    #[test]
1156    fn the_shipped_mmintrin_defines_the_mmx_type_and_the_operations_over_it() {
1157        let text = shipped(concat!(
1158            "#include <mmintrin.h>\n",
1159            "__m64 add(__m64 a, __m64 b) { return _mm_add_pi16(a, b); }\n",
1160            "__m64 pack(__m64 a, __m64 b) { return _m_packsswb(a, b); }\n",
1161            "__m64 shift(__m64 a) { return _mm_srai_pi32(a, 3); }\n",
1162            "int low(__m64 a) { return _mm_cvtsi64_si32(a); }\n",
1163            "void done(void) { _mm_empty(); }\n",
1164        ));
1165        assert!(text.contains("add"), "{text}");
1166        assert!(text.contains("pack"), "{text}");
1167        assert!(text.contains("shift"), "{text}");
1168    }
1169
1170    /// The allocator beside the vector headers, which is the one piece of the family that is
1171    /// not a vector operation. It reaches for `<stddef.h>` and for three names out of the
1172    /// library, and the point of the test is that the reach resolves with nothing on the
1173    /// search path but the compiler's own directory.
1174    #[test]
1175    fn the_shipped_mm_malloc_asks_for_aligned_memory_and_gives_it_back() {
1176        let text = shipped(concat!(
1177            "#include <mm_malloc.h>\n",
1178            "void *get(void) { return _mm_malloc(64, 16); }\n",
1179            "void put(void *p) { _mm_free(p); }\n",
1180        ));
1181        assert!(text.contains("get"), "{text}");
1182        assert!(text.contains("put"), "{text}");
1183    }
1184
1185    /// `<xmmintrin.h>` is the next rung of the chain and pulls the other two in behind it, so a
1186    /// program that includes this one alone has to get all three. What the intrinsics answer is
1187    /// checked the same way `<mmintrin.h>` next door is checked and for the same reason: a
1188    /// hundred and forty eight lines of answers over nans, infinities, both zeros and values
1189    /// that do not fit in the integer they convert to, identical to GCC 16.2.0 at `-O0`, `-O1`,
1190    /// `-O2` and `-Os`.
1191    ///
1192    /// `_mm_rcp_ps` is the one answer in that run that is not identical, and is not meant to be.
1193    /// The instruction approximates a reciprocal and this computes one exactly, so the bits
1194    /// differ while both sit inside the relative error Intel documents, which the same program
1195    /// checks directly rather than by comparing bits.
1196    #[test]
1197    fn the_shipped_xmmintrin_defines_the_sse_type_and_the_operations_over_it() {
1198        let text = shipped(concat!(
1199            "#include <xmmintrin.h>\n",
1200            "__m128 add(__m128 a, __m128 b) { return _mm_add_ps(a, b); }\n",
1201            "__m128 one(__m128 a, __m128 b) { return _mm_max_ss(a, b); }\n",
1202            "__m128 mask(__m128 a, __m128 b) { return _mm_cmpnle_ps(a, b); }\n",
1203            "__m128 pick(__m128 a, __m128 b) { return _mm_shuffle_ps(a, b, _MM_SHUFFLE(0,1,2,3)); }\n",
1204            "int bits(__m128 a) { return _mm_movemask_ps(a); }\n",
1205            "int near(__m128 a) { return _mm_cvtss_si32(a); }\n",
1206            "__m128 wide(__m64 a) { return _mm_cvtpi16_ps(a); }\n",
1207            "void *room(void) { return _mm_malloc(64, 16); }\n",
1208            "void hint(const float *p) { _mm_prefetch(p, _MM_HINT_T0); _mm_sfence(); }\n",
1209        ));
1210        assert!(text.contains("add"), "{text}");
1211        assert!(text.contains("mask"), "{text}");
1212        assert!(text.contains("pick"), "{text}");
1213        assert!(text.contains("wide"), "{text}");
1214    }
1215
1216    /// The six names of gcc's header this one leaves out, each of which is an instruction whose
1217    /// answer no plain C reproduces exactly. Leaving them out is what turns a program that wants
1218    /// one into a diagnostic naming the function it called, rather than into a wrong answer, and
1219    /// this is what notices if one is ever quietly defined to something close.
1220    ///
1221    /// `tamnd/rucc#1157` is the square root, which brings the first four back.
1222    #[test]
1223    fn the_shipped_xmmintrin_leaves_out_the_names_that_need_an_instruction() {
1224        let text = rucc_session::runtime::header("xmmintrin.h").expect("xmmintrin.h is shipped");
1225        for absent in [
1226            "_mm_sqrt_ps",
1227            "_mm_sqrt_ss",
1228            "_mm_rsqrt_ps",
1229            "_mm_rsqrt_ss",
1230            "_mm_getcsr",
1231            "_mm_setcsr",
1232        ] {
1233            let defined = text.contains(&format!("{absent}("));
1234            assert!(!defined, "{absent} is defined and the header says it is not");
1235            assert!(text.contains(absent), "{absent} is absent and unexplained");
1236        }
1237    }
1238
1239    #[test]
1240    fn the_shipped_emmintrin_defines_both_sse2_types_and_the_operations_over_them() {
1241        let text = shipped(concat!(
1242            "#include <emmintrin.h>\n",
1243            "__m128i add(__m128i a, __m128i b) { return _mm_add_epi64(a, b); }\n",
1244            "__m128i wide(__m128i a, __m128i b) { return _mm_mul_epu32(a, b); }\n",
1245            "__m128i pick(__m128i a) { return _mm_shuffle_epi32(a, _MM_SHUFFLE(0,1,2,3)); }\n",
1246            "__m128i up(__m128i a) { return _mm_slli_epi64(a, 13); }\n",
1247            "__m128i down(__m128i a) { return _mm_srli_si128(a, 3); }\n",
1248            "__m128i pack(__m128i a, __m128i b) { return _mm_packus_epi16(a, b); }\n",
1249            "int bits(__m128i a) { return _mm_movemask_epi8(a); }\n",
1250            "__m128d sum(__m128d a, __m128d b) { return _mm_add_sd(a, b); }\n",
1251            "__m128d mask(__m128d a, __m128d b) { return _mm_cmpunord_pd(a, b); }\n",
1252            "__m128i near(__m128d a) { return _mm_cvtpd_epi32(a); }\n",
1253            "__m128d over(__m128 a) { return _mm_cvtps_pd(a); }\n",
1254            "__m128i half(__m64 a) { return _mm_movpi64_epi64(a); }\n",
1255            "__m128i grab(void const *p) { return _mm_loadu_si128(p); }\n",
1256            "void wall(void) { _mm_lfence(); _mm_mfence(); }\n",
1257        ));
1258        assert!(text.contains("wide"), "{text}");
1259        assert!(text.contains("pack"), "{text}");
1260        assert!(text.contains("near"), "{text}");
1261        assert!(text.contains("half"), "{text}");
1262    }
1263
1264    /// The umbrella header reaches the three underneath it. This is brotli's use of it, from
1265    /// `c/enc/matching_tag_mask.h`, which is the whole of what `tamnd/rucc#1236` was about: four
1266    /// SSE2 names that were already shipped and no way to get at them by the name gcc uses.
1267    #[test]
1268    fn the_shipped_immintrin_reaches_the_names_the_headers_under_it_define() {
1269        let text = shipped(concat!(
1270            "#include <immintrin.h>\n",
1271            "unsigned long long matching(unsigned char tag, unsigned char const *bucket) {\n",
1272            "  __m128i const want = _mm_set1_epi8((char)tag);\n",
1273            "  __m128i const chunk = _mm_loadu_si128((__m128i const *)(void const *)bucket);\n",
1274            "  __m128i const same = _mm_cmpeq_epi8(chunk, want);\n",
1275            "  return (unsigned long long)_mm_movemask_epi8(same);\n",
1276            "}\n",
1277            "__m64 narrow(__m64 a, __m64 b) { return _mm_add_pi32(a, b); }\n",
1278            "__m128 single(__m128 a, __m128 b) { return _mm_add_ps(a, b); }\n",
1279        ));
1280        assert!(text.contains("matching"), "{text}");
1281        assert!(text.contains("narrow"), "the MMX header is not reached: {text}");
1282        assert!(text.contains("single"), "the SSE header is not reached: {text}");
1283    }
1284
1285    /// Including it twice is the same as including it once, and so is including it beside the
1286    /// header it reaches. A program that includes both spellings is the usual case rather than an
1287    /// odd one, because one of its own headers includes the umbrella and another includes SSE2.
1288    #[test]
1289    fn the_umbrella_and_the_header_under_it_can_both_be_included() {
1290        let text = shipped(concat!(
1291            "#include <immintrin.h>\n",
1292            "#include <emmintrin.h>\n",
1293            "#include <immintrin.h>\n",
1294            "__m128i twice(__m128i a, __m128i b) { return _mm_add_epi32(a, b); }\n",
1295        ));
1296        assert!(text.contains("twice"), "{text}");
1297    }
1298
1299    /// The float header omits four square roots and SSE2 omits the matching two, for the reason
1300    /// both headers write down. A later change that quietly defines one as an approximation
1301    /// would be a wrong answer nobody sees, so the absence is held in place here.
1302    #[test]
1303    fn the_shipped_emmintrin_leaves_out_the_two_square_roots() {
1304        let text = rucc_session::runtime::header("emmintrin.h").expect("emmintrin.h is shipped");
1305        for absent in ["_mm_sqrt_pd", "_mm_sqrt_sd"] {
1306            let defined = text.contains(&format!("{absent}("));
1307            assert!(!defined, "{absent} is defined and the header says it is not");
1308            assert!(text.contains(absent), "{absent} is absent and unexplained");
1309        }
1310    }
1311
1312    #[test]
1313    fn the_three_formality_headers_still_have_to_work() {
1314        let text = shipped(concat!(
1315            "#include <stdbool.h>\n",
1316            "#include <stdalign.h>\n",
1317            "#include <iso646.h>\n",
1318            "#include <stdnoreturn.h>\n",
1319            "int t = true and not false;\n",
1320            "_Alignas(16) char buf[16];\n",
1321            "int a = alignof(long);\n",
1322        ));
1323        assert!(text.contains("decl #0 t : int"), "{text}");
1324        assert!(text.contains("const 8 : unsigned long"), "{text}");
1325    }
1326
1327    /// Including everything twice has to change nothing, because that is what happens in any
1328    /// program large enough to matter and a guard that is wrong shows up nowhere else.
1329    ///
1330    /// Stated as the two trees being the same rather than as a fact about what is in either
1331    /// one. A header that carries definitions puts them in the tree and moves everything
1332    /// after them along, so an assertion about where the program's own declaration landed is
1333    /// an assertion about how much `<mmintrin.h>` defines, which is not what is being asked.
1334    #[test]
1335    fn every_shipped_header_can_be_included_twice() {
1336        let once: String = rucc_session::runtime::names()
1337            .iter()
1338            .map(|name| format!("#include <{name}>\n"))
1339            .collect();
1340        let twice = once.repeat(2);
1341        assert_eq!(shipped(&format!("{once}int x;\n")), shipped(&format!("{twice}int x;\n")));
1342    }
1343
1344    #[test]
1345    fn a_file_that_is_not_there_says_so_and_produces_nothing() {
1346        let fs = MemoryFileSystem::new();
1347        let result = compile(&options(), "/nope.c", &fs);
1348        assert!(result.failed());
1349        assert!(result.messages[0].contains("/nope.c"), "{:?}", result.messages);
1350        assert!(result.text().is_empty());
1351    }
1352
1353    #[test]
1354    fn an_object_comes_out_with_its_type_its_linkage_and_how_much_of_a_definition_it_is() {
1355        let text = tast("int x = 1;\n");
1356        let expected = "\
1357decl #0 x : int object external static defined
1358  init
1359    +0
1360      const 1 : int
1361";
1362        assert_eq!(text, expected);
1363    }
1364
1365    #[test]
1366    fn the_macros_are_expanded_before_anything_is_parsed() {
1367        // The whole pipeline in one line. The bound came out of a macro, so it was expanded,
1368        // converted from a preprocessing number to a constant of a type, parsed as an
1369        // expression, and folded to the number the array type carries.
1370        let text = tast("#define N 2\nint a[N];\n");
1371        assert!(text.starts_with("decl #0 a : int[2] object external static tentative"), "{text}");
1372    }
1373
1374    /// A pragma survives the preprocessor on purpose, since what one means is not its
1375    /// business, and nothing after it has a place for a `#` in the grammar. `pack` is the one
1376    /// the parser reads and every other line is walked past. Both spellings are here because
1377    /// they arrive by different routes and only one of them was ever on a line of its own in
1378    /// the source.
1379    #[test]
1380    fn a_pragma_is_not_a_declaration_and_the_parse_walks_past_the_ones_it_does_not_read() {
1381        let text = tast(concat!(
1382            "#pragma pack(4)\n",
1383            "struct s { int a; };\n",
1384            "#pragma pack()\n",
1385            "int b;\n",
1386            "_Pragma(\"GCC visibility push(default)\") int c;\n",
1387        ));
1388        assert!(text.contains("decl #0 b : int"), "{text}");
1389        assert!(text.contains("decl #1 c : int"), "{text}");
1390    }
1391
1392    /// Every number in these two tests was read off gcc 16 on x86-64 under `-std=gnu23`
1393    /// rather than reasoned about, which is why they are written as assertions the program
1394    /// makes about itself: a compilation with no messages is every one of them holding.
1395    ///
1396    /// This half is the attributes. `packed` takes the padding out, on the record or on one
1397    /// member, `aligned` raises and never lowers, and the two written together are the
1398    /// combination that packs and then aligns the whole thing.
1399    #[test]
1400    fn the_layout_attributes_move_the_members_and_the_record_the_way_gcc_lays_them_out() {
1401        tast(concat!(
1402            "struct A { char c; int i; } __attribute__((packed));\n",
1403            "_Static_assert(sizeof(struct A) == 5 && _Alignof(struct A) == 1, \"A\");\n",
1404            "_Static_assert(__builtin_offsetof(struct A, i) == 1, \"A.i\");\n",
1405            // `aligned` with nothing in the parentheses is the largest alignment the target
1406            // has, which gcc calls BIGGEST_ALIGNMENT and which is sixteen everywhere here.
1407            "struct B { char c; int i; } __attribute__((aligned));\n",
1408            "_Static_assert(sizeof(struct B) == 16 && _Alignof(struct B) == 16, \"B\");\n",
1409            "struct C { char c; int i __attribute__((packed)); };\n",
1410            "_Static_assert(sizeof(struct C) == 5 && _Alignof(struct C) == 1, \"C\");\n",
1411            "_Static_assert(__builtin_offsetof(struct C, i) == 1, \"C.i\");\n",
1412            "struct D { char c; int i; } __attribute__((packed, aligned(4)));\n",
1413            "_Static_assert(sizeof(struct D) == 8 && _Alignof(struct D) == 4, \"D\");\n",
1414            "_Static_assert(__builtin_offsetof(struct D, i) == 1, \"D.i\");\n",
1415            "struct E { char c; _Alignas(8) int i; };\n",
1416            "_Static_assert(sizeof(struct E) == 16 && _Alignof(struct E) == 8, \"E\");\n",
1417            "_Static_assert(__builtin_offsetof(struct E, i) == 8, \"E.i\");\n",
1418            "struct F { char c; int i __attribute__((aligned(8))); };\n",
1419            "_Static_assert(sizeof(struct F) == 16 && _Alignof(struct F) == 8, \"F\");\n",
1420            // Two the record already had, so the attribute asks for nothing new, and two
1421            // where four was already there, so the attribute is ignored rather than obeyed.
1422            "struct G { char c; short s; } __attribute__((aligned(2)));\n",
1423            "_Static_assert(sizeof(struct G) == 4 && _Alignof(struct G) == 2, \"G\");\n",
1424            "struct H { char c; int i; } __attribute__((aligned(2)));\n",
1425            "_Static_assert(sizeof(struct H) == 8 && _Alignof(struct H) == 4, \"H\");\n",
1426            // `packed` on a member takes the padding out in front of that member alone, so on
1427            // the first one it does nothing and on the second one it does all of it.
1428            "struct I { [[gnu::packed]] char c; int i; };\n",
1429            "_Static_assert(sizeof(struct I) == 8 && _Alignof(struct I) == 4, \"I\");\n",
1430            "struct J { char c; [[gnu::packed]] int i; };\n",
1431            "_Static_assert(sizeof(struct J) == 5 && _Alignof(struct J) == 1, \"J\");\n",
1432            "struct M { char c; int i : 5; int j : 20; } __attribute__((packed));\n",
1433            "_Static_assert(sizeof(struct M) == 5 && _Alignof(struct M) == 1, \"M\");\n",
1434            "struct N { char c; long long l; } __attribute__((aligned(32)));\n",
1435            "_Static_assert(sizeof(struct N) == 32 && _Alignof(struct N) == 32, \"N\");\n",
1436            "union L { char c; int i; } __attribute__((packed));\n",
1437            "_Static_assert(sizeof(union L) == 4 && _Alignof(union L) == 1, \"L\");\n",
1438            // The armoured spellings, which are the ones a system header writes, since a
1439            // program is entitled to a macro called `packed` and is not entitled to one called
1440            // `__packed__`. The two names are one attribute and the layout is the same one.
1441            "struct O { char c; int i; } __attribute__((__packed__));\n",
1442            "_Static_assert(sizeof(struct O) == 5 && _Alignof(struct O) == 1, \"O\");\n",
1443            "struct P { char c; int i; } __attribute__((__aligned__(8)));\n",
1444            "_Static_assert(sizeof(struct P) == 8 && _Alignof(struct P) == 8, \"P\");\n",
1445        ));
1446    }
1447
1448    /// What an access to a packed member is allowed to assume about where it starts.
1449    ///
1450    /// C 6.2.8 gives an object of type `int` four byte alignment and `packed` takes it away: the
1451    /// member goes wherever the members in front of it ended, and an `int` one byte into a record
1452    /// is aligned to one. The number on the access has to say so, because it is what the back end
1453    /// picks instructions from and what judgement J1 of `spec/safe-memory/04-safety-model.md`
1454    /// tests at run time. Four on an address that is a multiple of one is the compiler refusing a
1455    /// program that is doing nothing wrong.
1456    #[test]
1457    fn an_access_to_a_packed_member_says_the_alignment_the_layout_left_it() {
1458        let packed = body(concat!(
1459            "struct P { char c; int v; } __attribute__((packed));\n",
1460            "int f(struct P *p) { return p->v; }\n",
1461        ));
1462        assert!(packed.contains("load.i32 %2, align 1,"), "{packed}");
1463        // The same record without the attribute, which is where the type's own answer is right.
1464        let plain = body(concat!(
1465            "struct P { char c; int v; };\n",
1466            "int f(struct P *p) { return p->v; }\n",
1467        ));
1468        assert!(plain.contains("load.i32 %2, align 4,"), "{plain}");
1469    }
1470
1471    /// The same, for the two ways of being further in than the member itself.
1472    ///
1473    /// An array member is stepped through rather than offset to, and a record member is offset to
1474    /// twice, and both have to carry the outer record's alignment with them. A step of a whole
1475    /// number of elements leaves what the element width and the address had in common, which for
1476    /// a one byte aligned base is one byte however wide the elements are.
1477    #[test]
1478    fn what_is_inside_a_packed_member_is_no_more_aligned_than_the_member_is() {
1479        let stepped = body(concat!(
1480            "struct P { char c; int v[4]; } __attribute__((packed));\n",
1481            "int f(struct P *p, int i) { return p->v[i]; }\n",
1482        ));
1483        assert!(stepped.contains(", align 1,"), "{stepped}");
1484        assert!(!stepped.contains(", align 4,"), "{stepped}");
1485        let nested = body(concat!(
1486            "struct Inner { int v; };\n",
1487            "struct P { char c; struct Inner in; } __attribute__((packed));\n",
1488            "int f(struct P *p) { return p->in.v; }\n",
1489        ));
1490        assert!(nested.contains(", align 1,"), "{nested}");
1491        assert!(!nested.contains(", align 4,"), "{nested}");
1492    }
1493
1494    /// The same attribute on a declaration rather than on a type, which asks that this object or
1495    /// this function be at a multiple of that, and which is where a program that has to hand a
1496    /// buffer to hardware or keep two counters off one cache line writes it.
1497    ///
1498    /// A raise and never a lower, which is the one place it does not agree with `_Alignas`: below
1499    /// what the type already has, `_Alignas` is a constraint violation and this is ignored without
1500    /// a word. `__alignof__` of the object answers what the object got and not what its type has,
1501    /// because that is the question a program asking it is asking.
1502    #[test]
1503    fn the_aligned_attribute_on_a_declaration_raises_what_that_one_object_is_aligned_to() {
1504        tast(concat!(
1505            "int v __attribute__((aligned(64)));\n",
1506            "_Static_assert(__alignof__(v) == 64, \"v\");\n",
1507            // Written on the specifiers rather than after the declarator, which asks the same
1508            // thing and is the spelling a header is more likely to use.
1509            "__attribute__((aligned(32))) int w;\n",
1510            "_Static_assert(__alignof__(w) == 32, \"w\");\n",
1511            "[[gnu::aligned(16)]] int x;\n",
1512            "_Static_assert(__alignof__(x) == 16, \"x\");\n",
1513            // Two below the four an `int` already has, so nothing is asked for and nothing is
1514            // said, and the type still answers for the object.
1515            "int y __attribute__((aligned(2)));\n",
1516            "_Static_assert(__alignof__(y) == 4, \"y\");\n",
1517            // A local, which is the same question one scope down.
1518            "void f(void) { int a __attribute__((aligned(128)));\n",
1519            "_Static_assert(__alignof__(a) == 128, \"a\"); (void)a; }\n",
1520            // The type is untouched by any of it: `aligned` on a declaration says where that
1521            // declaration goes and says nothing about every other `int` in the program.
1522            "_Static_assert(__alignof__(int) == 4, \"int\");\n",
1523            // A function, which has no alignment of its own for this to be measured against and
1524            // takes whatever was asked for.
1525            "void g(void) __attribute__((aligned(256)));\n",
1526            "void g(void) {}\n",
1527            "_Static_assert(__alignof__(g) == 256, \"g\");\n",
1528        ));
1529    }
1530
1531    /// And what the object file says, which is the half that makes the answer above true. A
1532    /// function is at a fixed offset inside the text section, so it is at a multiple of two
1533    /// hundred and fifty six only if the section is at one too.
1534    #[test]
1535    fn what_a_declaration_asked_to_be_aligned_to_is_what_the_assembler_is_told() {
1536        let text = asm(concat!(
1537            "int v __attribute__((aligned(64)));\n",
1538            "void g(void) __attribute__((aligned(256)));\n",
1539            "void g(void) {}\n",
1540            "void plain(void) {}\n",
1541        ));
1542        assert!(text.contains("\t.p2align\t6\n\t.type\tv, @object\n"), "{text}");
1543        assert!(text.contains("\t.p2align\t8, 0x90\n\t.globl\tg\n"), "{text}");
1544        assert!(text.contains("\t.p2align\t4, 0x90\n\t.globl\tplain\n"), "{text}");
1545    }
1546
1547    /// And the one position where the attribute means something else. On a declaration it raises
1548    /// what that one object is aligned to, and on a typedef it says what the type is aligned to,
1549    /// which gcc lets it lower as well: `typedef int L __attribute__((aligned(2)))` really is an
1550    /// `int` at a multiple of two and a record with one in it really is smaller for it.
1551    ///
1552    /// The size is left alone, which is gcc's answer rather than an omission here. An aligned
1553    /// typedef whose alignment is larger than what it stands for keeps the size it stands for,
1554    /// and gcc refuses an array of one rather than padding the elements out to fit.
1555    #[test]
1556    fn an_aligned_typedef_says_what_an_object_of_it_is_aligned_to_and_may_lower_it() {
1557        tast(concat!(
1558            "typedef int L __attribute__((aligned(2)));\n",
1559            "_Static_assert(__alignof__(L) == 2, \"L\");\n",
1560            "_Static_assert(_Alignof(L) == 2, \"L alignof\");\n",
1561            // Below what an `int` has, which is the half a declaration cannot ask for.
1562            "_Static_assert(sizeof(L) == 4, \"L size\");\n",
1563            "struct T { char c; L x; };\n",
1564            "_Static_assert(sizeof(struct T) == 6, \"T\");\n",
1565            "_Static_assert(__builtin_offsetof(struct T, x) == 2, \"T.x\");\n",
1566            // And upwards, which is the ordinary direction and the one a header writes.
1567            "typedef int H __attribute__((aligned(16)));\n",
1568            "_Static_assert(__alignof__(H) == 16, \"H\");\n",
1569            "_Static_assert(sizeof(H) == 4, \"H size\");\n",
1570            "struct U { char c; H x; };\n",
1571            "_Static_assert(sizeof(struct U) == 32, \"U\");\n",
1572            "_Static_assert(__builtin_offsetof(struct U, x) == 16, \"U.x\");\n",
1573            // A typedef of a typedef, where the nearer one is the one the declaration was
1574            // written with and is the one that answers.
1575            "typedef L M __attribute__((aligned(8)));\n",
1576            "_Static_assert(__alignof__(M) == 8, \"M\");\n",
1577            // And one that asked for nothing, which still has whatever the one behind it asked
1578            // for because it is the same type spelled again.
1579            "typedef L N;\n",
1580            "_Static_assert(__alignof__(N) == 2, \"N\");\n",
1581            // The type it stands for is untouched by any of it.
1582            "_Static_assert(__alignof__(int) == 4, \"int\");\n",
1583        ));
1584        let text = asm(concat!(
1585            "typedef int L __attribute__((aligned(2)));\n",
1586            "typedef int H __attribute__((aligned(16)));\n",
1587            "L low;\n",
1588            "H high;\n",
1589        ));
1590        assert!(text.contains("\t.p2align\t1\n\t.type\tlow, @object\n"), "{text}");
1591        assert!(text.contains("\t.p2align\t4\n\t.type\thigh, @object\n"), "{text}");
1592    }
1593
1594    /// The attribute that builds a type rather than changing a layout. `vector_size(n)` says the
1595    /// declared type is `n` bytes of what was written, taken as lanes, and every operator over
1596    /// one is that operator over each lane.
1597    ///
1598    /// The size is in bytes and not in lanes, which is the part a reader gets backwards: sixteen
1599    /// of `int` is four lanes and sixteen of `char` is sixteen. A vector is aligned to its own
1600    /// size, which is what a machine that has the registers wants and what gcc gives one here.
1601    #[test]
1602    fn the_vector_size_attribute_builds_a_type_of_lanes_and_measures_it_in_bytes() {
1603        tast(concat!(
1604            "typedef int __attribute__((vector_size(16))) v4si;\n",
1605            "_Static_assert(sizeof(v4si) == 16 && _Alignof(v4si) == 16, \"v4si\");\n",
1606            "typedef char __attribute__((vector_size(16))) v16qi;\n",
1607            "_Static_assert(sizeof(v16qi) == 16, \"v16qi\");\n",
1608            // One lane, which is a power of two and is a vector rather than the type it was
1609            // written on: the operators it takes are the vector's and not the scalar's.
1610            "typedef int __attribute__((vector_size(4))) v1si;\n",
1611            "_Static_assert(sizeof(v1si) == 4, \"v1si\");\n",
1612            // The armoured spelling and the bracket one, which are the same attribute.
1613            "typedef float __attribute__((__vector_size__(8))) v2sf;\n",
1614            "_Static_assert(sizeof(v2sf) == 8, \"v2sf\");\n",
1615            "typedef short [[gnu::vector_size(8)]] v4hi;\n",
1616            "_Static_assert(sizeof(v4hi) == 8, \"v4hi\");\n",
1617            // A lane is what a subscript answers with, and a vector is not a pointer: there is
1618            // nothing to decay and the lane type is the one the arithmetic happens in.
1619            "v4si g;\n",
1620            "_Static_assert(sizeof(g[0]) == 4, \"lane\");\n",
1621            "_Static_assert(sizeof(g + g) == 16, \"whole\");\n",
1622            // A scalar beside a vector stands for itself in every lane, so the answer is still
1623            // the vector and not the wider of the two types.
1624            "_Static_assert(sizeof(g + 1) == 16, \"broadcast\");\n",
1625            // An array of them, which is the ordinary way a program holds several.
1626            "_Static_assert(sizeof(v4si[3]) == 48, \"array\");\n",
1627        ));
1628    }
1629
1630    /// A whole vector written into an array of them, and a vector named by a type name rather
1631    /// than by a typedef.
1632    ///
1633    /// Both are the same question asked twice. A vector is filled like an array of its lanes when
1634    /// a list is written into it, so a braced element that is itself a vector has to be taken
1635    /// whole rather than started as the first lane, and the type of what was written is the only
1636    /// thing that says which was meant. And a type name is where a compound literal and a cast
1637    /// spell the type out, which a macro taking a lane type and a lane count does, so the
1638    /// attribute has to be read there and not only on a declaration.
1639    #[test]
1640    fn a_vector_is_written_whole_into_an_array_of_them_and_named_by_a_type_name() {
1641        tast(concat!(
1642            "typedef int __attribute__((vector_size(8))) v2si;\n",
1643            "v2si table[] = { (v2si){ 1, 2 }, (v2si){ 3, 4 } };\n",
1644            "_Static_assert(sizeof(table) == 16, \"two of them and not eight lanes\");\n",
1645            // The size written out rather than named, which is the spelling a macro expands to.
1646            "v2si written = (int __attribute__((vector_size(8)))){ 5, 6 };\n",
1647            "_Static_assert(sizeof((int __attribute__((vector_size(16)))){ 0 }) == 16, \"named\");\n",
1648            // A lane is still a lane, so a list of them fills the vector the way it always did
1649            // and the rule above did not turn brace elision off.
1650            "v2si lanes[2] = { 1, 2, 3, 4 };\n",
1651            "_Static_assert(sizeof(lanes) == 16, \"still elided\");\n",
1652        ));
1653    }
1654
1655    /// A lane written rather than read, and a shift whose two vectors are not the same type.
1656    ///
1657    /// Both are places where a vector is not the aggregate it looks like. A subscript of one is
1658    /// an lvalue because the vector it came from is an object, so a lane can be assigned to and
1659    /// has an address, and a qualifier written on the vector reaches every lane the way it does
1660    /// on an array. And a shift is the one lanewise operator whose sides are not brought to a
1661    /// single type, since the right side counts rather than computes.
1662    #[test]
1663    fn a_lane_is_assignable_and_a_shift_takes_a_count_of_its_own_lane() {
1664        let result = run(
1665            &options(),
1666            concat!(
1667                "typedef int __attribute__((vector_size(16))) v4si;\n",
1668                "typedef unsigned __attribute__((vector_size(16))) v4ui;\n",
1669                "void write(v4si *out, v4ui a, v4si b, int n) {\n",
1670                "  v4si v = { 1, 2, 3, 4 };\n",
1671                "  v[0] = n;\n",
1672                "  v[1] += n;\n",
1673                "  v[2]++;\n",
1674                "  *&v[3] = n;\n",
1675                // The count is signed and the value is not, which no other operator allows.
1676                "  v4ui shifted = a >> b;\n",
1677                "  shifted <<= b;\n",
1678                // A scalar stands in every lane on either side of a shift, which is the half
1679                // that looks wrong: the shape of the answer comes off the count here.
1680                "  *out = v + (v4si)shifted + (1 << b);\n",
1681                "}\n",
1682                // A qualifier on the vector is a qualifier on the lane, so there is nothing here
1683                // to write to.
1684                "void refused(const v4si c) {\n",
1685                "  c[0] = 1;\n",
1686                "}\n",
1687            ),
1688        );
1689        assert_eq!(result.messages.len(), 1, "{:?}", result.messages);
1690        assert!(result.messages[0].contains("assignment of read-only"), "{:?}", result.messages);
1691    }
1692
1693    /// The third layout attribute, and the one that is refused rather than read. Reversing the
1694    /// byte order of every scalar in a record is not something a compiler can do half of, and a
1695    /// compilation that ignored it would lay the record out in the host's order and hand back
1696    /// every field with its bytes the wrong way round. Both spellings are here because a header
1697    /// writes the armoured one, and the member is here because the refusal has to arrive before
1698    /// the layout is used rather than after.
1699    #[test]
1700    fn a_record_that_asks_for_the_other_byte_order_is_refused_rather_than_laid_out_in_this_one() {
1701        let opts = options();
1702        let big = "struct s { int i; } __attribute__((scalar_storage_order(\"big-endian\")));\n";
1703        assert_eq!(
1704            run(&opts, big).messages,
1705            ["/main.c:1:36: error: 'scalar_storage_order' is not implemented yet [E0688]\n\
1706              /main.c:1:36: note: every scalar in this record would be read in the wrong byte \
1707              order"]
1708        );
1709
1710        let armoured =
1711            "struct s { int i; } __attribute__((__scalar_storage_order__(\"little-endian\")));\n";
1712        let messages = run(&opts, armoured).messages;
1713        assert!(messages[0].contains("[E0688]"), "{messages:?}");
1714
1715        // The attribute in front of the body reaches the same list as the one behind it, and
1716        // the C23 spelling in gcc's namespace is the same attribute written a third way.
1717        let front = "struct __attribute__((scalar_storage_order(\"big-endian\"))) s { int i; };\n";
1718        assert!(run(&opts, front).messages[0].contains("[E0688]"), "{front}");
1719        let standard = "struct s { int i; } [[gnu::scalar_storage_order(\"big-endian\")]];\n";
1720        assert!(run(&opts, standard).messages[0].contains("[E0688]"), "{standard}");
1721    }
1722
1723    /// Where a bit-field goes, which packing decides and which is the part of all this that
1724    /// is not what the names suggest. A bit-field goes at the next free bit unless that would
1725    /// make it span more storage than its own type occupies, and then it moves to the next
1726    /// boundary of its alignment. Any packing at all takes that rule out, and `#pragma pack`
1727    /// counts even where it lowers nothing, which is the fourth and seventh cases here.
1728    ///
1729    /// Nothing in the language can be asked where a bit-field is, since `offsetof` refuses one
1730    /// and every size below comes out the same either way, so what is asked is the byte a read
1731    /// of the field loads from.
1732    #[test]
1733    fn packing_is_what_decides_whether_a_bit_field_may_straddle_its_own_storage() {
1734        // A `char` field after twelve bits, which will not straddle unpacked and does packed.
1735        assert_eq!(bit_field_byte("struct s { int x : 12; char y : 6; };"), 2);
1736        assert_eq!(
1737            bit_field_byte("struct s { int x : 12; char y : 6; } __attribute__((packed));"),
1738            1
1739        );
1740        assert_eq!(
1741            bit_field_byte("struct s { int x : 12; __attribute__((packed)) char y : 6; };"),
1742            1
1743        );
1744        assert_eq!(bit_field_byte("#pragma pack(4)\nstruct s { int x : 12; char y : 6; };"), 1);
1745        // A thirty bit field after a byte, which is the case the rule was written for.
1746        assert_eq!(bit_field_byte("struct s { char x; int y : 30; };"), 4);
1747        assert_eq!(bit_field_byte("struct s { char x; int y : 30; } __attribute__((packed));"), 1);
1748        // Four is what an `int` asked for anyway, so this caps nothing and still counts.
1749        assert_eq!(bit_field_byte("#pragma pack(4)\nstruct s { char x; int y : 30; };"), 1);
1750        assert_eq!(bit_field_byte("#pragma pack(2)\nstruct s { char x; int y : 30; };"), 1);
1751    }
1752
1753    /// The byte a read of `s.y` loads from, which is where the bit-field was placed.
1754    fn bit_field_byte(record: &str) -> u64 {
1755        let source = format!("{record}\nint f(struct s *p) {{ return p->y; }}\n");
1756        let body = body(&source);
1757        let Some((before, _)) = body.split_once("ptr_add") else { return 0 };
1758        let (_, constant) = before.rsplit_once("iconst.i64 ").expect("an offset constant");
1759        constant.lines().next().expect("a line").trim().parse().expect("a byte offset")
1760    }
1761
1762    /// An attribute in the middle of a specifier list, which is where a member usually carries
1763    /// one and which was read and then thrown away. The `[[...]]` spelling and whatever was
1764    /// written in front of the declaration are collected as the list is walked and the
1765    /// `__attribute__` spelling is put straight on the specifiers, and the two were assigned
1766    /// over each other rather than joined.
1767    #[test]
1768    fn an_attribute_among_the_specifiers_is_kept_beside_the_ones_written_in_front() {
1769        tast(concat!(
1770            "struct a { char c; __attribute__((aligned(8))) int i; };\n",
1771            "_Static_assert(sizeof(struct a) == 16 && _Alignof(struct a) == 8, \"a\");\n",
1772            "_Static_assert(__builtin_offsetof(struct a, i) == 8, \"a.i\");\n",
1773            "struct b { char c; __attribute__((packed)) int i; };\n",
1774            "_Static_assert(sizeof(struct b) == 5 && _Alignof(struct b) == 1, \"b\");\n",
1775            "_Static_assert(__builtin_offsetof(struct b, i) == 1, \"b.i\");\n",
1776            "typedef struct { char c; int i; } __attribute__((packed)) c;\n",
1777            "_Static_assert(sizeof(c) == 5 && _Alignof(c) == 1, \"c\");\n",
1778        ));
1779    }
1780
1781    /// The other half, which is `#pragma pack`. It caps a member's alignment where `packed`
1782    /// drops it, so `pack(2)` leaves a `short` where it was and moves an `int`, and it caps a
1783    /// member the program asked to align as well, which is where the two differ. It is read
1784    /// at the closing brace of the body, so a line written in the middle of one settles the
1785    /// whole record rather than the members after it, and `push` and `pop` nest.
1786    #[test]
1787    fn pragma_pack_caps_every_member_and_is_read_where_the_body_closes() {
1788        tast(concat!(
1789            "#pragma pack(1)\n",
1790            "struct A { char c; int i; };\n",
1791            "_Static_assert(sizeof(struct A) == 5 && _Alignof(struct A) == 1, \"A\");\n",
1792            "_Static_assert(__builtin_offsetof(struct A, i) == 1, \"A.i\");\n",
1793            "#pragma pack()\n",
1794            "struct B { char c; int i; };\n",
1795            "_Static_assert(sizeof(struct B) == 8 && _Alignof(struct B) == 4, \"B\");\n",
1796            "#pragma pack(2)\n",
1797            "struct C { char c; int i; double d; };\n",
1798            "_Static_assert(sizeof(struct C) == 14 && _Alignof(struct C) == 2, \"C\");\n",
1799            "_Static_assert(__builtin_offsetof(struct C, d) == 6, \"C.d\");\n",
1800            // A member the program aligned, which `pack` caps and `packed` would not.
1801            "struct K { char c; int i __attribute__((aligned(8))); };\n",
1802            "_Static_assert(sizeof(struct K) == 6 && _Alignof(struct K) == 2, \"K\");\n",
1803            "_Static_assert(__builtin_offsetof(struct K, i) == 2, \"K.i\");\n",
1804            // The record's own `aligned` is not a member's, so it is not capped.
1805            "struct J { char c; int i; } __attribute__((aligned(8)));\n",
1806            "_Static_assert(sizeof(struct J) == 8 && _Alignof(struct J) == 8, \"J\");\n",
1807            "#pragma pack()\n",
1808            "#pragma pack(push, 1)\n",
1809            "struct D { char c; short s; };\n",
1810            "_Static_assert(sizeof(struct D) == 3 && _Alignof(struct D) == 1, \"D\");\n",
1811            "#pragma pack(pop)\n",
1812            "struct E { char c; short s; };\n",
1813            "_Static_assert(sizeof(struct E) == 4 && _Alignof(struct E) == 2, \"E\");\n",
1814            // Written in the middle of a body, and it still settles the whole record.
1815            "struct H { char c;\n",
1816            "#pragma pack(1)\n",
1817            "  int i; };\n",
1818            "_Static_assert(sizeof(struct H) == 5 && _Alignof(struct H) == 1, \"H\");\n",
1819            "#pragma pack(1)\n",
1820            "struct I { char c;\n",
1821            "#pragma pack()\n",
1822            "  int i; };\n",
1823            "_Static_assert(sizeof(struct I) == 8 && _Alignof(struct I) == 4, \"I\");\n",
1824            "#pragma pack()\n",
1825            // Nested pushes, each one giving back what the one under it had.
1826            "#pragma pack(push, 8)\n",
1827            "#pragma pack(push, 1)\n",
1828            "struct P { char c; int i; };\n",
1829            "_Static_assert(sizeof(struct P) == 5 && _Alignof(struct P) == 1, \"P\");\n",
1830            "#pragma pack(pop)\n",
1831            "struct Q { char c; int i; };\n",
1832            "_Static_assert(sizeof(struct Q) == 8 && _Alignof(struct Q) == 4, \"Q\");\n",
1833            "#pragma pack(pop)\n",
1834            // A cap above what every member already asks for changes nothing at all.
1835            "#pragma pack(16)\n",
1836            "struct R { char c; int i; };\n",
1837            "_Static_assert(sizeof(struct R) == 8 && _Alignof(struct R) == 4, \"R\");\n",
1838            "#pragma pack()\n",
1839            "#pragma pack(1)\n",
1840            "struct S { char c; int i : 5; int j : 20; };\n",
1841            "_Static_assert(sizeof(struct S) == 5 && _Alignof(struct S) == 1, \"S\");\n",
1842            "union T { char c; int i; };\n",
1843            "_Static_assert(sizeof(union T) == 4 && _Alignof(union T) == 1, \"T\");\n",
1844            "#pragma pack()\n",
1845        ));
1846    }
1847
1848    /// A line the reader cannot make sense of is a warning and the line is dropped, which is
1849    /// what GCC does with one, and these are its words for each of them. The last line is the
1850    /// one nothing else would reach, since it stands after every record in the file.
1851    #[test]
1852    fn a_pack_line_that_is_not_one_is_reported_in_the_words_gcc_uses() {
1853        let result = run(
1854            &options(),
1855            concat!(
1856                "#pragma pack 4\n",
1857                "#pragma pack(pop)\n",
1858                "#pragma pack(3)\n",
1859                "#pragma pack(1) junk\n",
1860                "#pragma pack(push, 1\n",
1861                "#pragma pack(x)\n",
1862                // These two are well formed and say nothing. Zero is how a line asks for the
1863                // target's own alignments back without writing empty parentheses.
1864                "#pragma pack(0)\n",
1865                "#pragma pack(push)\n",
1866                "struct s { char c; int i; };\n",
1867                "#pragma pack(pop)\n",
1868                "#pragma pack(pop, foo)\n",
1869            ),
1870        );
1871        let expected = [
1872            "missing `(` after `#pragma pack` - ignored",
1873            "`#pragma pack (pop)` encountered without matching `#pragma pack (push)`",
1874            "alignment must be a small power of two, not 3",
1875            "junk at end of `#pragma pack`",
1876            "malformed `#pragma pack(push[, id][, <n>])` - ignored",
1877            "unknown action `x` for `#pragma pack` - ignored",
1878            "`#pragma pack(pop, foo)` encountered without matching `#pragma pack(push, foo)`",
1879        ];
1880        assert_eq!(result.messages.len(), expected.len(), "{:?}", result.messages);
1881        for (message, want) in result.messages.iter().zip(expected) {
1882            assert!(message.contains(want), "expected {want:?} in {message:?}");
1883        }
1884    }
1885
1886    /// The two typedef spellings of the 128 bit types. gcc offers them as keywords rather
1887    /// than as typedefs in a header, which is the only way a program that includes nothing at
1888    /// all can still use them, and Apple's `<mach/arm/_structs.h>` is one such program.
1889    #[test]
1890    fn the_wide_integer_answers_to_all_three_of_its_names() {
1891        let text = tast("__uint128_t a; __int128_t b; unsigned __int128 c;\n");
1892        assert!(text.contains("decl #0 a : unsigned __int128"), "{text}");
1893        assert!(text.contains("decl #1 b : __int128"), "{text}");
1894        assert!(text.contains("decl #2 c : unsigned __int128"), "{text}");
1895    }
1896
1897    #[test]
1898    fn every_conversion_the_language_performs_is_a_node_in_the_output() {
1899        // The point of a typed tree. The source has one operator and the output has the
1900        // widening that operator asked for, spelled out, so that nothing downstream has to
1901        // work out the conversion rules a second time.
1902        let text = tast("long f(int a, long b) { return a + b; }\n");
1903        assert!(text.contains("convert arithmetic"), "{text}");
1904    }
1905
1906    #[test]
1907    fn a_mistake_in_each_phase_reaches_the_caller_and_writes_no_tree() {
1908        for source in [
1909            "#error stop\n",
1910            "int f(void) { return 1 + ; }\n",
1911            "int f(void) { return undeclared; }\n",
1912        ] {
1913            let result = run(&options(), source);
1914            assert!(result.failed(), "expected this to fail:\n{source}");
1915            assert!(
1916                result.text().is_empty(),
1917                "a file that did not compile wrote a tree:\n{source}"
1918            );
1919        }
1920    }
1921
1922    #[test]
1923    fn one_undeclared_name_is_one_message_and_not_one_per_use() {
1924        // The poisoning rule from `spec/06-lexer-and-parser.md` section 6.8, seen from the
1925        // outside. Three uses of a name that was never declared, and the operators over them
1926        // say nothing at all.
1927        let result = run(&options(), "int f(void) { return nope + nope * nope; }\n");
1928        assert_eq!(result.errors, 1, "{:?}", result.messages);
1929    }
1930
1931    #[test]
1932    fn a_declaration_the_parser_skipped_does_not_become_an_undeclared_name_as_well() {
1933        // The reason the checking is skipped after a failed parse. The parser gave up on the
1934        // first line and there is no `x` in the tree, so a checker run over it would report
1935        // every use of `x` below as undeclared, which is a second message about one mistake.
1936        let result = run(&options(), "int x = ;\nint f(void) { return x; }\n");
1937        assert_eq!(result.errors, 1, "{:?}", result.messages);
1938    }
1939
1940    #[test]
1941    fn werror_turns_a_warning_into_an_error_in_the_count_and_in_the_word() {
1942        let source = "int f(void) { char c = 300; return c; }\n";
1943        let plain = run(&options(), source);
1944        assert_eq!(plain.errors, 0, "{:?}", plain.messages);
1945        assert_eq!(plain.messages.len(), 1, "expected a warning about the narrowed constant");
1946        assert!(!plain.text().is_empty(), "a warning is not a reason to write nothing");
1947
1948        let mut opts = options();
1949        opts.warnings_are_errors = true;
1950        let strict = run(&opts, source);
1951        assert!(strict.failed());
1952        assert!(strict.text().is_empty(), "and under -Werror it is a reason to write nothing");
1953        for message in &strict.messages {
1954            assert!(!message.contains("warning:"), "{message}");
1955        }
1956    }
1957
1958    #[test]
1959    fn w_drops_the_warning_before_werror_can_promote_it() {
1960        let source = "int f(void) { char c = 300; return c; }\n";
1961        let mut opts = options();
1962        opts.warnings = false;
1963        let quiet = run(&opts, source);
1964        assert_eq!(quiet.messages, Vec::<String>::new());
1965        assert_eq!(quiet.errors, 0);
1966        assert!(!quiet.text().is_empty(), "and the file still compiles");
1967
1968        // A build that passes both means it wants neither, and the order it wrote them in is not
1969        // something to make it think about.
1970        opts.warnings_are_errors = true;
1971        let both = run(&opts, source);
1972        assert_eq!(both.messages, Vec::<String>::new());
1973        assert!(!both.failed(), "-w -Werror is not an error about a warning nobody saw");
1974    }
1975
1976    #[test]
1977    fn the_dialect_reaches_the_keywords_and_the_checking() {
1978        // `typeof` is C23's and GNU's, so the same source is a declaration under one dialect
1979        // and a mistake under the other, which is the keyword table being built per dialect.
1980        let source = "typeof(1) x;\n";
1981        let mut opts = options();
1982        opts.std = Std::C23;
1983        opts.gnu_extensions = false;
1984        assert!(!run(&opts, source).failed(), "{:?}", run(&opts, source).messages);
1985
1986        opts.std = Std::C17;
1987        assert!(run(&opts, source).failed());
1988    }
1989
1990    #[test]
1991    fn asking_for_a_kind_that_is_not_written_yet_runs_the_front_end_and_writes_nothing() {
1992        let mut opts = options();
1993        opts.emit = EmitKind::Object;
1994        let result = run(&opts, "int x = 1;\n");
1995        assert!(!result.failed(), "{:?}", result.messages);
1996        assert!(result.text().is_empty());
1997        // And it still finds what the checking finds, so a later kind on a broken file is not
1998        // a silent success.
1999        assert!(run(&opts, "int f(void) { return undeclared; }\n").failed());
2000    }
2001
2002    /// The machine code of `source`, insisting that it compiled cleanly.
2003    fn mir(source: &str) -> String {
2004        let mut opts = options();
2005        opts.emit = EmitKind::MirFinal;
2006        let result = run(&opts, source);
2007        assert_eq!(result.messages, Vec::<String>::new(), "expected this to compile:\n{source}");
2008        result.text().to_owned()
2009    }
2010
2011    /// The whole compiler in one assertion, which is what this emit kind is for.
2012    ///
2013    /// C in, machine instructions out, every register a real one and every frame offset a
2014    /// number. Everything between the two is checked somewhere else, one pass at a time. What is
2015    /// checked here is that the passes are joined up and that the driver runs them.
2016    #[test]
2017    fn a_function_goes_from_c_to_instructions_with_real_registers_in_them() {
2018        let text = mir("int add(int a, int b) { return a + b; }\n");
2019        assert!(text.starts_with("mfunc @add {"), "{text}");
2020        assert!(text.contains("x64.add_rr_32"), "{text}");
2021        assert!(text.contains("x64.ret"), "{text}");
2022        // A virtual register is what the allocator was there to remove, so one left in the
2023        // output is the difference between code and something that looks like code.
2024        assert!(!text.contains('%'), "{text}");
2025    }
2026
2027    /// A declaration has no body, so there is nothing to generate for one and nothing is.
2028    #[test]
2029    fn a_function_with_no_body_produces_no_machine_function() {
2030        let text = mir("int g(int);\nint f(int a) { return g(a); }\n");
2031        assert_eq!(text.matches("mfunc @").count(), 1, "{text}");
2032        assert!(text.contains("mfunc @f {"), "{text}");
2033        assert!(text.contains("x64.call"), "{text}");
2034    }
2035
2036    /// Two functions come out in the order the module holds them, which is source order.
2037    #[test]
2038    fn every_definition_in_the_file_is_generated_and_they_keep_their_order() {
2039        let text = mir("int a(int x) { return x; }\nint b(int x) { return x; }\n");
2040        let first = text.find("mfunc @a").expect("the first function");
2041        let second = text.find("mfunc @b").expect("the second function");
2042        assert!(first < second, "{text}");
2043    }
2044
2045    /// The target reaches the back end, so the same C is different instructions on Windows.
2046    #[test]
2047    fn the_target_decides_which_convention_the_generated_code_follows() {
2048        let mut opts = options();
2049        opts.emit = EmitKind::MirFinal;
2050        let linux = run(&opts, "int f(int a) { return a; }\n").text().to_owned();
2051        assert!(linux.contains("$rdi"), "{linux}");
2052
2053        opts.target = "x86_64-pc-windows-msvc".parse::<Triple>().unwrap();
2054        let windows = run(&opts, "int f(int a) { return a; }\n").text().to_owned();
2055        assert!(windows.contains("$rcx"), "{windows}");
2056        assert!(!windows.contains("$rdi"), "{windows}");
2057    }
2058
2059    /// A target with no back end says so rather than generating something for another machine.
2060    #[test]
2061    fn a_target_this_has_no_back_end_for_is_reported_rather_than_generated() {
2062        let mut opts = options();
2063        opts.emit = EmitKind::MirFinal;
2064        opts.target = "aarch64-unknown-linux-gnu".parse::<Triple>().unwrap();
2065        let result = run(&opts, "int f(int a) { return a; }\n");
2066        assert!(result.failed());
2067        assert!(result.messages[0].contains("no back end for aarch64"), "{:?}", result.messages);
2068        assert!(result.text().is_empty());
2069    }
2070
2071    /// A construct the rule set does not reach yet is named, along with the function it is in.
2072    ///
2073    /// The message is about this compiler being unfinished rather than about the program, which
2074    /// is valid C either way, so it carries the note that says where the work is tracked. Both
2075    /// functions are attempted, so a file that is ahead of the back end in three places says so
2076    /// three times rather than one recompilation at a time.
2077    #[test]
2078    fn a_construct_the_back_end_cannot_reach_yet_is_reported_against_its_function() {
2079        let mut opts = options();
2080        opts.emit = EmitKind::MirFinal;
2081        let source = "void a(int n) { int v[n] __attribute__((aligned(32))); v[0] = 1; }\n\
2082                      void b(int n) { int v[n] __attribute__((aligned(32))); v[0] = 1; }\n";
2083        let result = run(&opts, source);
2084        assert!(result.failed());
2085        assert_eq!(result.messages.len(), 2, "{:?}", result.messages);
2086        assert!(result.messages[0].contains("cannot generate code for 'a'"), "{:?}", result);
2087        assert!(result.messages[0].contains("wants more alignment"), "{:?}", result);
2088        assert!(result.messages[1].contains("cannot generate code for 'b'"), "{:?}", result);
2089        assert!(result.text().is_empty());
2090    }
2091
2092    /// A variable length array is refused under the flag that says every page is touched.
2093    ///
2094    /// The pages the prologue takes are touched by the prologue. The pages the array takes are
2095    /// however many the size worked out to, so touching them is a loop, and there is no loop here
2096    /// yet. A function with both is refused rather than compiled to something that keeps the flag's
2097    /// name and not what it promises.
2098    #[test]
2099    fn a_variable_length_array_is_refused_where_every_page_of_the_frame_is_to_be_touched() {
2100        let mut opts = options();
2101        opts.emit = EmitKind::MirFinal;
2102        let source = "void a(int n) { int v[n]; v[0] = 1; }\n";
2103        assert!(!run(&opts, source).failed(), "it compiles without the flag");
2104
2105        opts.stack_clash = true;
2106        let result = run(&opts, source);
2107        assert!(result.failed());
2108        assert!(result.messages[0].contains("cannot generate code for 'a'"), "{:?}", result);
2109        assert!(result.messages[0].contains("a page at a time"), "{:?}", result);
2110    }
2111
2112    /// An opcode the rule language has no word for is named anyway, and pointed at.
2113    ///
2114    /// The rule language's spelling is the better name when there is one, but an opcode it has
2115    /// no word for is exactly the opcode no rule lowers, so falling back to the opcode and the
2116    /// type is what makes the message say anything at all in the cases that happen. The span is
2117    /// the instruction's own, so the message lands on the line rather than on the file.
2118    ///
2119    /// The width of the float is what keeps the program refused. Everything else here is split into
2120    /// halves by `rucc_codegen::wide`, including the divisions and the conversions to a `float` and
2121    /// a `double`, which became calls into the compiler runtime. A `long double` is the eighty bit
2122    /// float on this target, the runtime has no conversion at that width because the back end has no
2123    /// register that holds one, which is tamnd/rucc#326, so a function converting to it is left with
2124    /// its wide values and reaches the selector the way every function of this width used to.
2125    #[test]
2126    fn an_opcode_with_no_name_in_the_rule_language_is_named_by_its_own_spelling() {
2127        let mut opts = options();
2128        opts.emit = EmitKind::MirFinal;
2129        let source =
2130            "long double f(int a) {\n  __int128 wide = a;\n  return (long double) wide;\n}\n";
2131        let result = run(&opts, source);
2132        assert!(result.failed());
2133        assert!(
2134            result.messages[0].contains("no rule lowers a `sext` producing a `i128`"),
2135            "{result:?}"
2136        );
2137        assert!(result.messages[0].contains(":2:"), "the line the widening is on: {result:?}");
2138        assert!(!result.messages[0].contains("this instruction"), "{result:?}");
2139    }
2140
2141    /// The note names the issue tracker, which is where a reader finds out whether it is known.
2142    #[test]
2143    fn the_note_on_unfinished_work_points_at_the_issues_rather_than_at_the_plan() {
2144        let mut opts = options();
2145        opts.emit = EmitKind::MirFinal;
2146        let source = "long double f(int a) { __int128 wide = a; return (long double) wide; }\n";
2147        let result = run(&opts, source);
2148        assert!(result.failed());
2149        let note = result.messages.iter().find(|line| line.contains("note:")).expect("a note");
2150        assert!(note.contains("https://github.com/tamnd/rucc/issues"), "{note}");
2151        assert!(!note.contains("spec/17-milestones.md"), "{note}");
2152    }
2153
2154    /// The two frame flags reach the frame, which is the only thing either of them does.
2155    #[test]
2156    fn the_frame_flags_on_the_command_line_reach_the_generated_frame() {
2157        let source = "int f(int a) { return a; }\n";
2158        assert!(!mir(source).contains("$rbp"), "a leaf needs no frame pointer by default");
2159
2160        let mut opts = options();
2161        opts.emit = EmitKind::MirFinal;
2162        opts.frame_pointer = true;
2163        let kept = run(&opts, source).text().to_owned();
2164        assert!(kept.contains("x64.push_64 $rbp"), "{kept}");
2165    }
2166
2167    /// The assembly of `source`, insisting that it compiled cleanly.
2168    fn asm(source: &str) -> String {
2169        let mut opts = options();
2170        opts.emit = EmitKind::Asm;
2171        let result = run(&opts, source);
2172        assert_eq!(result.messages, Vec::<String>::new(), "expected this to compile:\n{source}");
2173        result.text().to_owned()
2174    }
2175
2176    /// `-S`, which is the same compiler as the kind above it with a different last step.
2177    ///
2178    /// What the assembly says is checked in `rucc-asm`, one instruction at a time and against the
2179    /// target's own description of what an instruction is. What is checked here is that a C file
2180    /// goes all the way to a listing an assembler would take, which means the directives around
2181    /// the function as well as the instructions in it.
2182    #[test]
2183    fn a_function_goes_from_c_to_assembly_an_assembler_would_take() {
2184        let text = asm("int add(int a, int b) { return a + b; }\n");
2185        assert!(text.contains("\t.globl\tadd\n"), "{text}");
2186        assert!(text.contains("\t.type\tadd, @function\n"), "{text}");
2187        assert!(text.contains("\nadd:\n"), "{text}");
2188        assert!(text.contains("\taddl\t"), "{text}");
2189        assert!(text.contains("\tret\n"), "{text}");
2190        assert!(text.contains("\t.size\tadd, .-add\n"), "{text}");
2191        // Without this the stack the program runs on is executable, which is not a default
2192        // anybody chose and is not a thing a reader would notice missing.
2193        assert!(text.contains(".note.GNU-stack"), "{text}");
2194    }
2195
2196    /// A call through a function pointer, which is a different instruction from a call to a name.
2197    ///
2198    /// Both are in the one function on purpose. What is being read is that the two calls are told
2199    /// apart all the way down: one carries a name the linker resolves and one carries a register,
2200    /// and neither turns into the other on the way.
2201    #[test]
2202    fn a_call_through_a_function_pointer_goes_through_the_register_it_is_in() {
2203        let text = asm("int g(int);\nint f(int (*p)(int), int a) { return p(a) + g(a); }\n");
2204        assert!(text.contains("\tcall\t*%"), "{text}");
2205        assert!(text.contains("\tcall\tg\n"), "{text}");
2206        // The address arrived in the first argument register and the argument the call passes has
2207        // to end up there, so the two cannot be the same register and the compiler has to have
2208        // moved one of them.
2209        assert!(text.contains("%rdi"), "{text}");
2210    }
2211
2212    /// A name at file scope, which is the one address a function cannot compute for itself. The
2213    /// `lea` that computes it is folded into the load that reads through it, so what is left to
2214    /// read is the addressing mode, which is where the instruction pointer shows up.
2215    #[test]
2216    fn the_address_of_a_global_is_read_from_the_instruction_pointer() {
2217        let text = asm("extern int counter;\nint f(void) { return counter; }\n");
2218        assert!(text.contains("\tmovl\tcounter(%rip), %eax\n"), "{text}");
2219    }
2220
2221    /// Every comparison a branch can be on, which the machine jumps on without keeping a byte.
2222    ///
2223    /// Ten conditions, and each of them comes out as its opposite because the block falls into the
2224    /// arm the comparison is true for and jumps to the other one. That is the half of this most
2225    /// worth pinning: a jump on the condition rather than on its opposite compiles, encodes and
2226    /// runs, and gets every one of these ten functions backwards. The unsigned four and the signed
2227    /// four are separate for the same reason, since `jl` where `jb` was meant is a program that
2228    /// works until an address is above two gigabytes.
2229    #[test]
2230    fn a_branch_on_a_comparison_jumps_on_the_opposite_of_what_it_compared() {
2231        let arms = "return 1; return 2;";
2232        let signed = [("==", "jne"), ("!=", "je"), ("<", "jge"), ("<=", "jg"), (">", "jle")];
2233        for (operator, jump) in signed.into_iter().chain([(">=", "jl")]) {
2234            let text = asm(&format!("int f(int a, int b) {{ if (a {operator} b) {arms} }}\n"));
2235            assert!(
2236                text.contains(&format!("\tcmpl\t%esi, %edi\n\t{jump}\t")),
2237                "{operator}: {text}"
2238            );
2239            assert!(!text.contains("\tset"), "{operator}: {text}");
2240            assert!(!text.contains("\ttest"), "{operator}: {text}");
2241        }
2242        let unsigned = [("<", "jae"), ("<=", "ja"), (">", "jbe"), (">=", "jb")];
2243        for (operator, jump) in unsigned {
2244            let source =
2245                format!("int f(unsigned a, unsigned b) {{ if (a {operator} b) {arms} }}\n");
2246            let text = asm(&source);
2247            assert!(
2248                text.contains(&format!("\tcmpl\t%esi, %edi\n\t{jump}\t")),
2249                "{operator}: {text}"
2250            );
2251        }
2252
2253        // And against a constant, which is four comparisons in five and is where the saving
2254        // mostly is, since the byte that goes was the only reason the constant was in a register.
2255        let text = asm("int f(int a) { if (a < 7) return 1; return 2; }\n");
2256        assert!(text.contains("\tcmpl\t$7, %edi\n\tjge\t"), "{text}");
2257    }
2258
2259    /// The comparison whose answer is a value rather than a branch, which keeps its byte.
2260    ///
2261    /// The one that goes is the byte nothing but the branch reads. A comparison the program asked
2262    /// for the answer of is not that, and there is no branch behind it to fold into in any case,
2263    /// so this is here to say that what was taken out was taken out of one place and not two.
2264    #[test]
2265    fn a_comparison_whose_answer_the_program_wanted_still_writes_a_byte() {
2266        let text = asm("int f(int a, int b) { return a < b; }\n");
2267        assert!(text.contains("\tsetl\t"), "{text}");
2268    }
2269
2270    /// The same source at `-O2`, which is where the optimizer's passes are in the list.
2271    fn optimized(source: &str) -> String {
2272        let mut opts = options();
2273        opts.emit = EmitKind::Asm;
2274        opts.opt_level = rucc_session::OptLevel::O2;
2275        let result = run(&opts, source);
2276        assert_eq!(result.messages, Vec::<String>::new(), "expected this to compile:\n{source}");
2277        result.text().to_owned()
2278    }
2279
2280    /// A dense `switch` whose arms are a function of the label, which is arithmetic.
2281    ///
2282    /// Sixteen labels, and the arm for label `k` gives `k + 1`. What came out of this was a
2283    /// comparison and a jump for every one of them, which is tamnd/rucc#728. What comes out now is
2284    /// one comparison and one addition, and the count is the whole of the claim: it does not grow
2285    /// with the number of labels, so sixteen and a hundred and sixty compile to the same thing.
2286    ///
2287    /// The comparison is unsigned because the range check is the label minus the lowest one, which
2288    /// is a count and not a number the program wrote.
2289    #[test]
2290    fn a_switch_whose_arms_are_a_function_of_the_label_is_a_range_check_and_arithmetic() {
2291        let arms: String =
2292            (0..16).map(|k| format!("case {k}: return {};", k + 1)).collect::<Vec<_>>().join(" ");
2293        let text = optimized(&format!("int f(int x) {{ switch (x) {{ {arms} }} return 0; }}\n"));
2294        assert!(text.contains("\tcmpl\t$15, %edi\n\tja\t"), "{text}");
2295        assert!(text.contains("\taddl\t$1, %edi"), "{text}");
2296        assert_eq!(text.matches("\tcmp").count(), 1, "{text}");
2297    }
2298
2299    /// The same `switch` with one arm off the line, which keeps every comparison it had.
2300    ///
2301    /// The answers being a line is what licenses the range check, since a range check answers for
2302    /// every label in the range at once. One label whose arm disagrees is a label the check would
2303    /// answer wrongly, so this is here to say that the pass is reading the arms and not counting
2304    /// the labels.
2305    #[test]
2306    fn a_dense_switch_whose_arms_are_not_a_line_keeps_its_comparisons() {
2307        let arms: String = (0..16)
2308            .map(|k| format!("case {k}: return {};", if k == 9 { 100 } else { k + 1 }))
2309            .collect::<Vec<_>>()
2310            .join(" ");
2311        let text = optimized(&format!("int f(int x) {{ switch (x) {{ {arms} }} return 0; }}\n"));
2312        assert!(text.matches("\tcmp").count() > 1, "{text}");
2313    }
2314
2315    /// A cast between a pointer and an integer as wide as one, which is every one C writes here.
2316    #[test]
2317    fn a_cast_between_a_pointer_and_an_integer_leaves_the_value_where_it_is() {
2318        let text = asm("long f(void *p) { return (long)p; }\n");
2319        // Every instruction in the body is a full width move or the return. The copies are the
2320        // allocator taking no hints, and what matters here is what is not among them: nothing
2321        // narrows the value and nothing widens it again, which is what a cast that did something
2322        // would look like.
2323        for line in text.lines().filter(|line| line.starts_with('\t') && !line.contains('.')) {
2324            let mnemonic = line.split_whitespace().next().unwrap_or("");
2325            assert!(matches!(mnemonic, "movq" | "ret"), "{line} in\n{text}");
2326        }
2327    }
2328
2329    /// The arguments past the sixth arrive in the caller's memory rather than in a register, and
2330    /// where that memory is depends on what the prologue did, so this is checked at the end of the
2331    /// pipeline rather than in the middle of it.
2332    #[test]
2333    fn an_argument_past_the_last_register_is_read_out_of_the_caller_s_stack() {
2334        let six = "long a, long b, long c, long d, long e, long f";
2335        let text = asm(&format!("long f({six}, long g, long h) {{ return g + h; }}\n"));
2336
2337        // Nothing is pushed and no frame is taken, so the only thing between the stack pointer and
2338        // the caller's arguments is the return address the call pushed. Which is where gcc 16.2.0
2339        // reads them from too, at `-O0`, though it reads them in three instructions where this
2340        // reads them in two: the second read is the addition's own memory operand, which is
2341        // `rucc_codegen::combine`, and the offset in it is the one the frame layout wrote into the
2342        // load before the two were put together.
2343        assert!(text.contains("\tmovq\t8(%rsp), "), "{text}");
2344        assert!(text.contains("\taddq\t16(%rsp), "), "{text}");
2345
2346        // A narrower one is read at its own width, because the bits above it are bits the
2347        // convention says nothing about, and one in the other register file with the other file's
2348        // instruction.
2349        let narrow = asm(&format!("int f({six}, int g) {{ return g; }}\n"));
2350        assert!(narrow.contains("\tmovl\t8(%rsp), "), "{narrow}");
2351        let eight =
2352            "double a, double b, double c, double d, double e, double f, double g, double h";
2353        let float = asm(&format!("double f({eight}, double i) {{ return i; }}\n"));
2354        assert!(float.contains("\tmovsd\t8(%rsp), "), "{float}");
2355    }
2356
2357    /// The other end of the same thing. What the caller writes is at the stack pointer, because
2358    /// that is the bottom of its frame and the bottom of its frame is where the callee looks.
2359    #[test]
2360    fn a_call_writes_the_arguments_with_no_register_left_at_the_stack_pointer() {
2361        let six = "1, 2, 3, 4, 5, 6";
2362        let decl = "long g(long, long, long, long, long, long, long, long);\n";
2363        let text = asm(&format!("{decl}long f(void) {{ return g({six}, 7, 8); }}\n"));
2364
2365        assert!(text.contains("\tmovq\t%"), "{text}");
2366        assert!(text.contains(", (%rsp)\n"), "{text}");
2367        assert!(text.contains(", 8(%rsp)\n"), "{text}");
2368        // And it reserved the bytes it wrote into, so nothing else in the frame is on top of them.
2369        assert!(text.contains("\tsubq\t$"), "{text}");
2370
2371        // A narrower one is written at its own width, matching what the callee reads it back with.
2372        let narrow = "int g(int, int, int, int, int, int, int);\n";
2373        let text = asm(&format!("{narrow}int f(void) {{ return g({six}, 7); }}\n"));
2374        assert!(text.contains("\tmovl\t%"), "{text}");
2375        assert!(text.contains(", (%rsp)\n"), "{text}");
2376    }
2377
2378    /// The count a variadic callee on this convention reads is a count of vector registers, so a
2379    /// float that ran out of them and went to memory is not in it.
2380    #[test]
2381    fn a_variadic_call_counts_registers_and_not_arguments() {
2382        let nine = "1., 2., 3., 4., 5., 6., 7., 8., 9.";
2383        let decl = "int g(int, ...);\n";
2384        let text = asm(&format!("{decl}int f(void) {{ return g(0, {nine}); }}\n"));
2385
2386        assert!(text.contains("\tmovl\t$8, "), "eight registers, not nine: {text}");
2387        assert!(text.contains("\tmovsd\t%"), "{text}");
2388        assert!(text.contains(", (%rsp)\n"), "{text}");
2389    }
2390
2391    /// The callee's half of the same convention. Every argument register it was handed is written
2392    /// into its frame on the way in, because which of them hold anything is a thing only the caller
2393    /// knew, and the ones the signature does name are left out because `va_start` sets the offsets
2394    /// past them and nothing ever reads their slots.
2395    #[test]
2396    fn a_variadic_function_writes_the_argument_registers_it_was_handed_into_its_frame() {
2397        let body =
2398            "__builtin_va_list ap; __builtin_va_start(ap, n); __builtin_va_end(ap); return n;";
2399        let text = asm(&format!("int f(int n, ...) {{ {body} }}\n"));
2400
2401        // Five general purpose registers and eight vector ones, since the one parameter the
2402        // signature names took the first of the six.
2403        let stores = |mnemonic: &str| text.matches(&format!("\t{mnemonic}\t%")).count();
2404        assert!(text.contains(", 8(%r"), "the second slot, not the first: {text}");
2405        assert!(!text.contains(", 0(%r"), "{text}");
2406        // All sixteen bytes of each vector register, which is what gcc writes and what a `va_arg`
2407        // of a `_Float128` reads back, so the mnemonic is the one that moves a whole register.
2408        assert_eq!(stores("movaps"), 8, "every vector register: {text}");
2409        assert_eq!(stores("movsd"), 0, "and the whole of each one: {text}");
2410
2411        // And the area is one of the function's own stack objects, so the frame holds it.
2412        assert!(text.contains("\tsubq\t$"), "{text}");
2413    }
2414
2415    /// What `va_start` writes is the four fields of the list, and the two numbers among them are
2416    /// where the arguments the signature names left the walk over each file's registers.
2417    #[test]
2418    fn va_start_writes_the_four_fields_the_psabi_describes() {
2419        let start = "__builtin_va_list ap; __builtin_va_start(ap, d);";
2420        let params = "int a, int b, int c, double d";
2421        let text = asm(&format!("int f({params}, ...) {{ {start} return a; }}\n"));
2422
2423        // Three integers took three of the six general purpose registers, and one double took one
2424        // of the eight vector ones, so the walk starts at twenty four bytes into the first half and
2425        // sixteen bytes into the second, which begins at forty eight.
2426        assert!(text.contains("	movl	$24, "), "{text}");
2427        assert!(text.contains("	movl	$64, "), "{text}");
2428        // The other two fields are addresses rather than numbers, so each is stored as a word and
2429        // each is a `lea` away. One of them reaches above the frame, which is where the caller's
2430        // arguments are and is the only thing in this function that is not below the stack pointer.
2431        assert!(text.contains(", 8(%r"), "{text}");
2432        assert!(text.contains(", 16(%r"), "{text}");
2433        let frame: u32 = text
2434            .lines()
2435            .find_map(|line| line.trim().strip_prefix("subq	$")?.split(',').next()?.parse().ok())
2436            .expect("a variadic function takes a frame for the save area");
2437        let above = |line: &str| {
2438            let at: u32 = line.trim().strip_prefix("leaq	")?.split('(').next()?.parse().ok()?;
2439            Some(at > frame)
2440        };
2441        assert!(text.lines().filter_map(above).any(|it| it), "{frame}: {text}");
2442    }
2443
2444    /// A `va_arg` is a branch on whether the argument it wants is still in the save area, and which
2445    /// of the two halves it walks is the type's answer.
2446    #[test]
2447    fn va_arg_branches_on_whether_the_argument_is_still_in_the_save_area() {
2448        let read = "__builtin_va_list ap; __builtin_va_start(ap, n);";
2449        let ints = format!("int f(int n, ...) {{ {read} return __builtin_va_arg(ap, int); }}\n");
2450        let text = asm(&ints);
2451
2452        // The last general purpose slot begins at forty, so an offset above it is an argument the
2453        // caller left in its own memory instead.
2454        assert!(text.contains("$40, "), "{text}");
2455        assert!(text.contains("	cmpl	"), "{text}");
2456        // The jump is the unsigned one, since an offset is a count of bytes. It is the opposite
2457        // of the comparison the front end wrote, because the block falls into the half taken when
2458        // the argument is still in the save area and jumps to the other one.
2459        assert!(text.contains("	ja	"), "{text}");
2460
2461        let arg = "__builtin_va_arg(ap, double)";
2462        let text = asm(&format!("double f(int n, ...) {{ {read} return {arg}; }}\n"));
2463        assert!(text.contains("$160, "), "the last vector slot: {text}");
2464    }
2465
2466    /// A structure assigned is a copy of a known size, and a copy of a known size is a run of
2467    /// moves rather than a call to a library this compiler has no way to reach yet.
2468    #[test]
2469    fn a_structure_assignment_is_a_move_for_each_word_of_it() {
2470        let decl = "struct pair { long a, b; };\n";
2471        let body = "struct pair p = *q; return p.a + p.b;";
2472        let text = asm(&format!("{decl}long f(struct pair *q) {{ {body} }}\n"));
2473
2474        assert!(!text.contains("memcpy"), "nothing calls the library: {text}");
2475        assert!(!text.contains("\tcall"), "{text}");
2476        // Sixteen bytes aligned to eight is two words, and each is a load and a store.
2477        assert!(text.matches("\tmovq\t").count() >= 4, "two words each way: {text}");
2478    }
2479
2480    /// A word is as wide as the object is aligned to and no wider, so a character array is copied
2481    /// a byte at a time and a structure of longs eight bytes at a time.
2482    #[test]
2483    fn how_wide_a_word_of_a_copy_is_follows_the_alignment() {
2484        let decl = "struct bytes { char a[8]; };\n";
2485        let body = "struct bytes p = *q; return p.a[0];";
2486        let text = asm(&format!("{decl}int f(struct bytes *q) {{ {body} }}\n"));
2487
2488        // Eight bytes aligned to one is eight words, and each is a load and a store.
2489        assert!(text.matches("\tmovb\t").count() >= 16, "a byte at a time: {text}");
2490    }
2491
2492    /// What an initialiser does not name is zero, which the front end writes as a fill and this
2493    /// writes as the byte spread across each word.
2494    #[test]
2495    fn the_part_of_an_initialiser_that_names_nothing_is_stored_as_zero() {
2496        let decl = "struct wide { long a, b, c; };\n";
2497        let text = asm(&format!("{decl}long f(void) {{ struct wide w = {{ 7 }}; return w.c; }}\n"));
2498
2499        assert!(!text.contains("memset"), "nothing calls the library: {text}");
2500        assert!(text.contains("\tmovq\t$0, ") || text.contains("$0, %"), "the zero: {text}");
2501    }
2502
2503    /// A copy too large to be worth unrolling is a call to the runtime, which is the C library on
2504    /// a hosted target and `rucc-builtins` on a freestanding one.
2505    #[test]
2506    fn a_copy_too_large_to_unroll_calls_the_runtime() {
2507        let decl = "struct huge { char a[4096]; };\n";
2508        let mut opts = options();
2509        opts.emit = EmitKind::Asm;
2510        let source = format!("{decl}void f(struct huge *p, struct huge *q) {{ *p = *q; }}\n");
2511        let result = run(&opts, &source);
2512        assert!(!result.failed(), "{:?}", result.messages);
2513        let text = result.text();
2514        assert!(text.contains("call") && text.contains("memcpy"), "{text}");
2515        // The size in the register the convention passes the third argument in, which is what
2516        // says the call was built from the convention and not from the shape of the IR.
2517        assert!(text.contains("4096"), "the size travels: {text}");
2518    }
2519
2520    /// A frame that had to force its own alignment cannot say how far away the caller's stack
2521    /// pointer was, so it reaches back through the frame pointer instead.
2522    #[test]
2523    fn a_realigned_frame_reads_them_through_the_frame_pointer() {
2524        let six = "long a, long b, long c, long d, long e, long f";
2525        let body = "_Alignas(32) long wide[4]; wide[0] = g; return wide[0];";
2526        let text = asm(&format!("long f({six}, long g) {{ {body} }}\n"));
2527
2528        // The frame pointer is saved and pointed at where it was saved before the alignment is
2529        // forced, so the caller's arguments stay a constant distance from it: one word for the
2530        // saved frame pointer and one for the return address.
2531        assert!(text.contains("\tandq\t$-32, %rsp"), "{text}");
2532        assert!(text.contains("\tmovq\t16(%rbp), "), "{text}");
2533        assert!(!text.contains("\tmovq\t16(%rsp), "), "{text}");
2534    }
2535
2536    /// The object format decides the directives, and the target decides the object format.
2537    #[test]
2538    fn the_target_decides_how_the_assembly_is_spelled() {
2539        let mut opts = options();
2540        opts.emit = EmitKind::Asm;
2541        opts.target = "x86_64-apple-darwin".parse::<Triple>().unwrap();
2542        let text = run(&opts, "int f(void) { return 0; }\n").text().to_owned();
2543        assert!(text.contains("__TEXT,__text"), "{text}");
2544        assert!(text.contains("\n_f:\n"), "{text}");
2545        assert!(!text.contains(".note.GNU-stack"), "{text}");
2546    }
2547
2548    /// The object file of `source`, insisting that it compiled cleanly.
2549    fn obj(source: &str) -> Vec<u8> {
2550        let mut opts = options();
2551        opts.emit = EmitKind::Object;
2552        let result = run(&opts, source);
2553        assert_eq!(result.messages, Vec::<String>::new(), "expected this to compile:\n{source}");
2554        match result.artifact {
2555            Artifact::Object { bytes, .. } => bytes,
2556            other => panic!("expected an object, got {other:?}"),
2557        }
2558    }
2559
2560    /// `-c`, which is the last step of the three the back end can end with.
2561    ///
2562    /// What is in the file is checked in `rucc-object`, a field at a time. What is checked here is
2563    /// that a C file goes all the way to one, which is the whole compiler in one line and the
2564    /// thing that stops working when a layer between them changes its mind about something.
2565    #[test]
2566    fn a_function_goes_from_c_to_an_object_a_linker_would_take() {
2567        let bytes = obj("int add(int a, int b) { return a + b; }\n");
2568        assert_eq!(&bytes[..4], b"\x7fELF", "an object file starts by saying it is one");
2569        let text = asm("int add(int a, int b) { return a + b; }\n");
2570        assert!(
2571            text.contains("\taddl\t"),
2572            "and the listing of it is the same instructions:\n{text}"
2573        );
2574    }
2575
2576    /// A variable this file defines, which is what a reference to one has to resolve against.
2577    #[test]
2578    fn a_variable_goes_from_c_to_the_section_it_belongs_in() {
2579        let text = asm("int counter = 42;\nstatic int hidden;\nconst int fixed = 7;\n");
2580        assert!(text.contains("\t.data\n\t.globl\tcounter\n"), "{text}");
2581        assert!(text.contains("\ncounter:\n\t.long\t42\n"), "{text}");
2582        assert!(text.contains("\t.size\tcounter, .-counter\n"), "{text}");
2583        // A zeroed variable carries its size and none of its bytes, and a `static` one is not
2584        // announced to the linker at all, which is the whole of what `static` means here.
2585        assert!(text.contains("\t.bss\n\t.p2align\t2\n"), "{text}");
2586        assert!(text.contains("\nhidden:\n\t.space\t4\n"), "{text}");
2587        assert!(!text.contains(".globl\thidden"), "{text}");
2588        // Nothing writes through it, so it goes in a page the loader can map read only and every
2589        // process running the program can share.
2590        assert!(text.contains("\t.section\t.rodata\n"), "{text}");
2591    }
2592
2593    /// A bit-field with a value in it, which is written as the bytes the value lands in.
2594    ///
2595    /// The interesting one is the field whose lowest byte is zero. The bytes a bit-field
2596    /// initializer makes are put together first and then taken back out as the run they make,
2597    /// and taking them out starts at the byte the field starts at, so a zero byte at the front
2598    /// used to end the object up in `.bss` with the rest of its value thrown away.
2599    #[test]
2600    fn a_bit_field_initializer_writes_every_byte_of_the_value_and_not_only_the_ones_that_are_set() {
2601        let text = asm("struct s { unsigned f : 20; } x = { 0x12300 };\n");
2602        assert!(text.contains("\t.data\n"), "there is something to write: {text}");
2603        assert!(text.contains("\nx:\n\t.ascii\t\"\\000#\\001\"\n"), "and it is the value: {text}");
2604
2605        // Two fields, the first of them zero, which is the same thing said with the zero byte
2606        // inside the run rather than at the front of it.
2607        let text = asm("struct s { unsigned a : 8; unsigned b : 8; } x = { 0, 3 };\n");
2608        assert!(text.contains("\nx:\n\t.ascii\t\"\\000\\003\"\n"), "{text}");
2609
2610        // Wider than an `int`, which is the same code and is worth saying because the value no
2611        // longer fits in the thirty two bits a bit-field used to be read at.
2612        let text = asm("struct s { unsigned long long f : 40; } x = { 0x100000 };\n");
2613        assert!(text.contains("\nx:\n\t.ascii\t\"\\000\\000\\020\"\n\t.space\t5\n"), "{text}");
2614
2615        // Nothing in it, which still costs no bytes in the file.
2616        let text = asm("struct s { unsigned f : 20; } x = { 0 };\n");
2617        assert!(text.contains("\t.bss\n"), "an object of zeroes is zeroes: {text}");
2618        assert!(text.contains("\nx:\n\t.space\t4\n"), "{text}");
2619    }
2620
2621    /// A string literal, which is a variable the program never named.
2622    #[test]
2623    fn a_string_literal_is_a_variable_with_a_name_no_program_could_write() {
2624        let text = asm("const char *f(void) { return \"hi\"; }\n");
2625        assert!(text.contains("\t.ascii\t\"hi\\000\"\n"), "{text}");
2626        assert!(text.contains("\t.section\t.rodata\n"), "{text}");
2627        let label = text
2628            .lines()
2629            .find(|line| line.starts_with(".Lstr"))
2630            .unwrap_or_else(|| panic!("a label for the literal in\n{text}"));
2631        assert!(!text.contains(&format!(".globl\t{}", label.trim_end_matches(':'))), "{text}");
2632    }
2633
2634    /// A variable holding the address of another one, which is the only hole an image has in it.
2635    #[test]
2636    fn an_address_in_an_initializer_is_left_to_the_linker() {
2637        let source = "int counter;\nint *p = &counter;\n";
2638        let text = asm(source);
2639        assert!(text.contains("\np:\n\t.quad\tcounter\n"), "{text}");
2640        // And in the object it is eight zero bytes and a relocation, which is what the two paths
2641        // being one description is for.
2642        let bytes = obj(source);
2643        assert!(bytes.windows(8).any(|w| w == b"counter\0"), "the object has to name it");
2644    }
2645
2646    /// A const table of function pointers, which is the shape that made SQLite link with a warning.
2647    ///
2648    /// The table is const so nothing in the program writes it, but the addresses in it are not
2649    /// numbers a link knows, so the loader writes it once at startup. Putting it in `.rodata`
2650    /// leaves a relocation in a section that is never writable, and what the linker does about
2651    /// that is set `DT_TEXTREL` on the whole image and say so. `.data.rel.ro` is writable for
2652    /// exactly as long as the loader is writing it and read only afterwards, which is what the
2653    /// program asked for in the first place.
2654    #[test]
2655    fn a_constant_holding_an_address_goes_in_the_section_the_loader_may_write_once() {
2656        // Both names are `static` and both are defined here, so nothing else can be the one that
2657        // defines them and the linker may lay the table out in the first pages of the segment.
2658        let text = asm("static void a(void) {}\nstatic void b(void) {}\n\
2659             struct m { void (*x)(void); void (*y)(void); };\n\
2660             const struct m t = { a, b };\n");
2661        assert!(text.contains("\t.section\t.data.rel.ro.local,\"aw\",@progbits\n"), "{text}");
2662        assert!(text.contains("\nt:\n\t.quad\ta\n\t.quad\tb\n"), "{text}");
2663
2664        // One name this file only declares is enough to lose the `.local` half, because a name the
2665        // link resolves from somewhere else is one another object may turn out to define.
2666        let text =
2667            asm("void a(void);\nstruct m { void (*x)(void); };\nconst struct m t = { a };\n");
2668        assert!(text.contains("\t.section\t.data.rel.ro,\"aw\",@progbits\n"), "{text}");
2669
2670        // And a constant with no address in it stays exactly where it was.
2671        let text = asm("const int fixed = 7;\n");
2672        assert!(text.contains("\t.section\t.rodata\n"), "{text}");
2673    }
2674
2675    /// A thread-local variable, which is the whole of one: the storage and the way to reach it.
2676    ///
2677    /// The two halves are in one test on purpose. Either one alone is worse than neither: a
2678    /// definition with no way to reach it is a variable nothing can read, and a reference with no
2679    /// definition behind it is the bug this pair was written to prevent, where a thread-local is
2680    /// read as though it were an ordinary global and every thread quietly shares one copy.
2681    #[test]
2682    fn a_thread_local_variable_is_storage_a_thread_gets_a_copy_of_and_an_offset_into_it() {
2683        let text = asm("_Thread_local int x = 1;\nint read(void) { return x; }\n");
2684        // The storage: the section the loader makes a copy of for every thread, and the symbol
2685        // type that makes a linker refuse an ordinary relocation aimed at it.
2686        assert!(text.contains("\t.section\t.tdata,\"awT\",@progbits\n"), "{text}");
2687        assert!(text.contains("\t.type\tx, @tls_object\n"), "{text}");
2688        // The way to reach it: how far into a thread's block it sits, out of the table, plus where
2689        // this thread's block is, out of the segment register.
2690        assert!(text.contains("x@GOTTPOFF(%rip)"), "{text}");
2691        assert!(text.contains("%fs:0"), "{text}");
2692    }
2693
2694    /// The second half of that on its own, which is what a program asks for when the number it
2695    /// wants is the thread rather than anything in it.
2696    ///
2697    /// rpmalloc writes this to find its per thread cache, and it is the whole of what stood
2698    /// between that library and a build. gcc 16 writes the same one instruction.
2699    #[test]
2700    fn the_address_of_this_thread_s_own_storage_is_read_out_of_the_segment_register() {
2701        let text = asm("void *here(void) { return __builtin_thread_pointer(); }\n");
2702        assert!(text.contains("movq\t%fs:0, "), "{text}");
2703        // No table slot and no addition, because there is no variable to find inside the block.
2704        assert!(!text.contains("GOTTPOFF"), "{text}");
2705    }
2706
2707    /// The four hints and the one thing that decides between them, which is the locality.
2708    ///
2709    /// A prefetch promises nothing, so what is checked here is the instruction rather than any
2710    /// effect: the program runs the same whichever of the four it gets, and the whole point of
2711    /// writing one is which. The four spellings are what gcc 16.2.0 writes for the same four
2712    /// programs, measured on x86-64 rather than read off a manual.
2713    ///
2714    /// The write hint is not one of them. `prefetchw` is not in the base instruction set and gcc
2715    /// writes it only when the command line says the part has it, so a prefetch for a write is the
2716    /// same instruction as a prefetch for a read, which is the fourth line here.
2717    #[test]
2718    fn a_prefetch_is_one_of_four_instructions_and_the_locality_is_what_picks() {
2719        for (locality, wanted) in
2720            [(0, "prefetchnta"), (1, "prefetcht2"), (2, "prefetcht1"), (3, "prefetcht0")]
2721        {
2722            let source =
2723                format!("void warm(void *p) {{ __builtin_prefetch(p, 0, {locality}); }}\n");
2724            let text = asm(&source);
2725            assert!(text.contains(&format!("\t{wanted}\t")), "locality {locality}: {text}");
2726        }
2727        // The one argument form, which means a read that wants all of the data afterwards.
2728        let text = asm("void warm(void *p) { __builtin_prefetch(p); }\n");
2729        assert!(text.contains("\tprefetcht0\t"), "{text}");
2730        // A prefetch for a write, which on a part nobody said has `prefetchw` is the same
2731        // instruction as the read above.
2732        let text = asm("void warm(void *p) { __builtin_prefetch(p, 1); }\n");
2733        assert!(text.contains("\tprefetcht0\t"), "{text}");
2734        assert!(!text.contains("prefetchw"), "{text}");
2735    }
2736
2737    /// The stop, which is the one instruction the machine is promised never to have a meaning for.
2738    ///
2739    /// What is checked is the instruction and not any effect, because the effect is a fault and a
2740    /// unit test has nowhere to take one. gcc 16.2.0 writes the same instruction for the same
2741    /// program, and it is not a call, which is the half that matters in a kernel and in a
2742    /// freestanding program: neither has an `abort` for a call to reach.
2743    ///
2744    /// The second half is the block going on after it. A statement written under a stop is
2745    /// compiled the way it would have been without one, so the addition is still there, and that
2746    /// is the front end declining to treat a stop as the end of a path.
2747    #[test]
2748    fn a_trap_is_the_instruction_the_machine_has_no_meaning_for() {
2749        let text = asm("void stop(void) { __builtin_trap(); }\n");
2750        assert!(text.contains("\tud2\n"), "{text}");
2751        assert!(!text.contains("\tcall"), "a stop is not a call to anything: {text}");
2752
2753        let text = asm("int stop(int a) { __builtin_trap(); return a + 1; }\n");
2754        assert!(text.contains("\tud2\n"), "{text}");
2755        assert!(text.contains("\taddl\t"), "the block goes on after a stop: {text}");
2756    }
2757
2758    /// The promise about the low bits of an address, whose value is the address.
2759    ///
2760    /// Nothing here reads an alignment fact about a value yet, so what the call leaves behind is
2761    /// its first argument and no instruction at all. The claim worth checking end to end is that
2762    /// the name is gone: a builtin nothing lowers reaches the assembler as a call to a name no
2763    /// object file defines, which is how this one used to fail to link out of glibc's string
2764    /// headers.
2765    ///
2766    /// The arguments behind the address are still evaluated, because gcc 16.2.0 evaluates them at
2767    /// every optimization level even though it has folded the call away. A constant has nothing to
2768    /// run and is dropped, and a call does, so the second half asks for the callee by name.
2769    #[test]
2770    fn assume_aligned_is_its_first_argument_and_keeps_the_rest() {
2771        let text = asm("void *aligned(char *p) { return __builtin_assume_aligned(p, 16); }\n");
2772        assert!(!text.contains("assume_aligned"), "{text}");
2773        assert!(!text.contains("\tcall"), "nothing is called for an alignment fact: {text}");
2774
2775        let source = "unsigned long width(void);\n\
2776                      void *aligned(char *p) { return __builtin_assume_aligned(p, width()); }\n";
2777        let text = asm(source);
2778        assert!(!text.contains("assume_aligned"), "{text}");
2779        assert!(text.contains("width"), "the argument that is not the answer still runs: {text}");
2780    }
2781
2782    /// Where a frame is, which on this machine is what the frame pointer holds.
2783    ///
2784    /// The first half is a function that would have kept no frame pointer at all, since it is a
2785    /// leaf with no locals, and keeps one because it asked where its frame is. The answer being
2786    /// `%rbp` rather than an offset off `%rsp` is the whole of the builtin at a depth of zero.
2787    ///
2788    /// The second half is the walk. Each link above zero is one load through the register the last
2789    /// one wrote, so a depth of two is two loads and a depth of three is three, which is what gcc
2790    /// 16.2.0 writes for the same programs at `-O2`.
2791    #[test]
2792    fn the_frame_address_is_the_frame_pointer_after_walking_that_many_links() {
2793        let text = asm("void *here(void) { return __builtin_frame_address(0); }\n");
2794        assert!(text.contains("pushq\t%rbp"), "a function that asks keeps a frame pointer: {text}");
2795        assert!(text.contains("movq\t%rbp, %rax"), "{text}");
2796        assert!(!text.contains("\tcall"), "a frame address is not a call to anything: {text}");
2797
2798        let walk = |depth: u32| {
2799            let source = format!("void *up(void) {{ return __builtin_frame_address({depth}); }}\n");
2800            asm(&source).matches("movq\t(%r").count()
2801        };
2802        assert_eq!(walk(1), 1, "one link is one load");
2803        assert_eq!(walk(3), 3, "three links are three loads");
2804    }
2805
2806    /// The address a frame returns to, which is one word above the frame the walk ended at.
2807    ///
2808    /// A word is eight bytes here and the `8(...)` is the whole claim: the call instruction pushed
2809    /// the return address and the prologue pushed the caller's frame pointer under it, so what the
2810    /// frame pointer points at is the link and what is above it is where control goes back to.
2811    /// gcc 16.2.0 writes `movq 8(%rbp), %rax` for the first of these, measured at `-O2`.
2812    ///
2813    /// The second half is the same walk the frame address does, with the load at the end of it
2814    /// reading one word further along rather than the register itself being the answer.
2815    #[test]
2816    fn the_return_address_is_one_word_above_the_frame_the_walk_ended_at() {
2817        let text = asm("void *back(void) { return __builtin_return_address(0); }\n");
2818        assert!(text.contains("pushq\t%rbp"), "a function that asks keeps a frame pointer: {text}");
2819        assert!(text.contains("movq\t8(%rbp), %rax"), "{text}");
2820        assert!(!text.contains("\tcall"), "a return address is not a call to anything: {text}");
2821
2822        let text = asm("void *back(void) { return __builtin_return_address(2); }\n");
2823        assert_eq!(text.matches("movq\t(%r").count(), 2, "two links are two loads: {text}");
2824        assert!(text.contains("movq\t8(%r"), "and the answer is above the last of them: {text}");
2825    }
2826
2827    /// A depth that is not a constant is refused, and so is one past the limit.
2828    ///
2829    /// The first is gcc's rule and not a convenience: what the call becomes is a walk that many
2830    /// links long, written out, so a number that is not known until the program runs has nothing
2831    /// to walk. gcc 16.2.0 says `invalid argument to '__builtin_return_address'` for the same
2832    /// program.
2833    ///
2834    /// The second is where this and gcc part company. gcc writes the walk however long it is, and
2835    /// this refuses a depth no program has a use for rather than filling an object file with loads
2836    /// that fault part way up.
2837    #[test]
2838    fn a_depth_that_is_not_a_small_constant_is_refused() {
2839        let mut opts = options();
2840        opts.emit = EmitKind::Ir;
2841        for source in [
2842            "void *up(int n) { return __builtin_return_address(n); }\n",
2843            "void *up(void) { return __builtin_frame_address(1000); }\n",
2844        ] {
2845            let messages = run(&opts, source).messages;
2846            let named = messages.iter().any(|m| m.contains("E0705"));
2847            assert!(named, "expected a refusal in {messages:?}");
2848        }
2849    }
2850
2851    /// Bytes off the frame, which is the stack pointer moving down and the answer being where it
2852    /// moved to.
2853    ///
2854    /// The rounding is the alignment: the size is taken up to the next sixteen before it is
2855    /// subtracted, so the pointer suits anything the program puts behind it. gcc 16.2.0 rounds the
2856    /// same way at `-O0` and spends a division doing it, which is the one place the two differ and
2857    /// is about how the rounding is written rather than about what it answers.
2858    ///
2859    /// There is no call anywhere in either program. An alloca that had reached the linker would
2860    /// have found the C library's, which is a real function with a real frame and is not what a
2861    /// program writing the builtin asked for.
2862    #[test]
2863    fn an_alloca_takes_the_bytes_off_the_stack_pointer_and_answers_where_they_are() {
2864        let text =
2865            asm("void use(void *p); void f(unsigned long n) { use(__builtin_alloca(n)); }\n");
2866        assert!(text.contains("andq\t$-16"), "the size is rounded up to sixteen: {text}");
2867        assert!(text.contains("subq\t%rdi, %rsp"), "and taken off the stack pointer: {text}");
2868        assert_eq!(text.matches("\tcall").count(), 1, "the only call is the one written: {text}");
2869
2870        // The plain name, which a program that declares it the way the C library does means the
2871        // same thing by. `gcc.c-torture/execute/20010122-1.c` is exactly this program.
2872        let plain = concat!(
2873            "extern void *alloca(__SIZE_TYPE__);\n",
2874            "void use(void *p);\n",
2875            "void f(unsigned long n) { use(alloca(n)); }\n",
2876        );
2877        let text = asm(plain);
2878        assert!(text.contains("subq\t%rdi, %rsp"), "the plain name is the same bytes: {text}");
2879        assert_eq!(text.matches("\tcall").count(), 1, "and is not a call either: {text}");
2880
2881        // And a program that means something of its own by the name keeps it, which is what the
2882        // declaration is looked at for.
2883        let own = concat!(
2884            "static void *alloca(unsigned long n) { return 0; }\n",
2885            "void *f(unsigned long n) { return alloca(n); }\n",
2886        );
2887        assert!(asm(own).contains("\tcall"), "a name the program took back is a call");
2888    }
2889
2890    /// The bytes an alloca took live until the function returns and not until the end of the block
2891    /// the call was written in.
2892    ///
2893    /// That is what makes it different from a variable length array, and the way it is kept is that
2894    /// every scope open where the call was written stops giving the stack back. The second program
2895    /// is the mixed case: an array in the outer block and an alloca in the inner one, where the
2896    /// inner block gives nothing back either even though an array is in scope that ordinarily
2897    /// would. gcc 16.2.0 at `-O0` writes no restore at the end of either block, measured rather
2898    /// than read off the manual.
2899    #[test]
2900    fn the_bytes_an_alloca_took_are_still_there_at_the_end_of_the_block_that_took_them() {
2901        let inner = "{ use(__builtin_alloca(n)); }";
2902        for body in [inner.to_owned(), format!("int a[n]; {inner} use(a);")] {
2903            let source = format!("void use(void *p);\nvoid f(unsigned long n) {{ {body} }}\n");
2904            let text = asm(&source);
2905            // Every instruction that writes the stack pointer, which in a function that gives
2906            // nothing back is the alloca taking bytes and the epilogue putting the frame pointer
2907            // there. A restore would be a third kind, a move out of a register the save wrote.
2908            for line in text.lines().filter(|line| line.trim_end().ends_with(", %rsp")) {
2909                let taking = line.contains("subq");
2910                let leaving = line.contains("%rbp");
2911                assert!(taking || leaving, "nothing puts the stack back: {line} in {text}");
2912            }
2913        }
2914    }
2915
2916    /// Not a rewording of the check above: what the two paths agree about is the point.
2917    #[test]
2918    fn the_object_and_the_listing_are_two_spellings_of_one_compilation() {
2919        // A call, because it is the one thing whose spelling in the two differs completely: the
2920        // listing writes a name and the object writes four zero bytes and a relocation asking the
2921        // linker for the same name. If either path had lost the callee, one of these would fail.
2922        let source = "int callee(void); int g(void) { return callee(); }\n";
2923        let bytes = obj(source);
2924        assert!(
2925            bytes.windows(7).any(|w| w == b"callee\0"),
2926            "the object has to name the callee for the linker to find it"
2927        );
2928        let text = asm(source);
2929        assert!(text.contains("\tcall\tcallee\n"), "{text}");
2930    }
2931
2932    /// What a file of a link contributes is an object, and the default emit is a link.
2933    ///
2934    /// This is here because getting it wrong is silent in the worst way: an empty file is a valid
2935    /// empty linker script, so a link fed one gets as far as reporting every symbol of the file as
2936    /// undefined and says nothing about the compilation that produced nothing.
2937    #[test]
2938    fn compiling_for_an_executable_produces_an_object_and_not_a_dump() {
2939        let mut opts = options();
2940        // What a command line with no `-c` and no `-S` on it asks for.
2941        opts.emit = EmitKind::Executable;
2942        let result = run(&opts, "int main(void) { return 0; }\n");
2943        assert_eq!(result.messages, Vec::<String>::new());
2944        match result.artifact {
2945            Artifact::Object { bytes, .. } => assert_eq!(&bytes[..4], b"\x7fELF"),
2946            other => panic!("expected an object, got {other:?}"),
2947        }
2948    }
2949
2950    /// A target with a back end but no object writer says so rather than writing the wrong file.
2951    #[test]
2952    fn a_platform_with_no_object_writer_is_said_so_rather_than_written_as_elf() {
2953        let mut opts = options();
2954        opts.emit = EmitKind::Object;
2955        opts.target = "x86_64-apple-darwin".parse::<Triple>().unwrap();
2956        let result = run(&opts, "int f(void) { return 0; }\n");
2957        assert!(result.failed(), "an object nobody can read is worse than a message");
2958        assert!(
2959            result.messages.iter().any(|m| m.contains("no object writer")),
2960            "{:?}",
2961            result.messages
2962        );
2963    }
2964
2965    /// The IR of `source`, insisting that it compiled cleanly.
2966    fn ir(source: &str) -> String {
2967        let mut opts = options();
2968        opts.emit = EmitKind::Ir;
2969        let result = run(&opts, source);
2970        assert_eq!(result.messages, Vec::<String>::new(), "expected this to compile:\n{source}");
2971        result.text().to_owned()
2972    }
2973
2974    /// What was said about `source`, insisting that something was.
2975    fn errors(source: &str) -> Vec<String> {
2976        let mut opts = options();
2977        opts.emit = EmitKind::Ir;
2978        let result = run(&opts, source);
2979        assert!(result.failed(), "expected this to be refused:\n{source}");
2980        result.messages
2981    }
2982
2983    /// The body of the one function in `source`, which is what most of these are about.
2984    fn body(source: &str) -> String {
2985        let text = ir(source);
2986        let (_, rest) = text.split_once("{\n").expect("a function definition");
2987        let (body, _) = rest.rsplit_once("}\n").expect("a function definition");
2988        body.to_owned()
2989    }
2990
2991    /// What `-fgnu89-inline` is for, seen at the only place it shows: whether a body reached the
2992    /// module or only a declaration did.
2993    ///
2994    /// The C99 reading is the one an inline definition is written for and is not being changed
2995    /// here. What the flag is for is a program written before C99 swapped the two, which relies on
2996    /// `inline` alone leaving something behind for another unit to call, and there are twelve of
2997    /// those in the GCC torture suite alone.
2998    #[test]
2999    fn gnu89_inline_is_what_decides_whether_a_bare_inline_definition_reaches_the_module() {
3000        let source = "inline int f(int x) { return x + 1; }\n";
3001        let with = |flag: bool| {
3002            let mut opts = options();
3003            opts.emit = EmitKind::Ir;
3004            opts.gnu89_inline = flag;
3005            let result = run(&opts, source);
3006            assert_eq!(result.messages, Vec::<String>::new(), "expected this to compile");
3007            result.text().to_owned()
3008        };
3009
3010        // Under C's reading the module holds the declaration and the calls in this unit go to
3011        // whatever definition another unit has, which is C 6.7.4p7 and is what gcc does too.
3012        assert!(!with(false).contains("block0"), "no body: {}", with(false));
3013
3014        // Under GNU's it is an ordinary external definition, so the body is there and the symbol
3015        // is one the linker can resolve against.
3016        assert!(with(true).contains("block0"), "a body: {}", with(true));
3017    }
3018
3019    /// Every shape that reads or writes through a C type names that type.
3020    ///
3021    /// The tree itself is `rucc_lower::aliasing`'s and is tested there. What this is about is that
3022    /// the walk reaches it from every shape a program actually writes, since a node on the scalar
3023    /// load and nothing on the member load would be a layer that answers for a third of the
3024    /// accesses in a program and is not worth having.
3025    #[test]
3026    fn an_access_through_a_type_names_the_type_it_went_through() {
3027        let source = "\
3028struct s { int a; float b; };\n\
3029union u { int i; float f; };\n\
3030int scalar(int *p) { return *p; }\n\
3031float member(struct s *p) { p->a = 1; return p->b; }\n\
3032int element(int *a, long i) { return a[i]; }\n\
3033float through_a_union(union u *p) { p->i = 1; return p->f; }\n";
3034        let text = ir(source);
3035        assert!(text.contains(r#"!0 = tbaa "char""#), "the root: {text}");
3036        assert!(text.contains(r#"tbaa "int", parent !0"#), "int under it: {text}");
3037        assert!(text.contains(r#"tbaa "float", parent !0"#), "float under it: {text}");
3038        // One per access, and a function whose accesses all go through one type says so once per
3039        // access rather than once per function.
3040        let named = text.lines().filter(|line| line.contains(", tbaa !")).count();
3041        assert_eq!(named, 6, "six accesses: {text}");
3042    }
3043
3044    /// `-fno-strict-aliasing` is the front end leaving the name off.
3045    ///
3046    /// Nothing asks the alias analysis anything yet, so no program compiles differently for having
3047    /// passed this today. What this test is for is the day one does: the flag has to be the
3048    /// absence of the names rather than a condition somewhere downstream, since that is the only
3049    /// version of it that a pass added later cannot forget about.
3050    #[test]
3051    fn turning_strict_aliasing_off_leaves_the_type_off_every_access() {
3052        let source = "int punned(float *f, int *i) { *i = 1; *f = 2.0f; return *i; }\n";
3053        let mut opts = options();
3054        opts.emit = EmitKind::Ir;
3055        opts.strict_aliasing = false;
3056        let result = run(&opts, source);
3057        assert_eq!(result.messages, Vec::<String>::new(), "expected this to compile");
3058        let text = result.text().to_owned();
3059        assert!(!text.contains("tbaa"), "not even the root: {text}");
3060    }
3061
3062    /// `return;` from a function that promised a value, which only C89 lets through and which
3063    /// therefore only reaches the IR builder under that dialect.
3064    ///
3065    /// Zero goes back. The alternatives are worse: an empty return list builds a `ret` the
3066    /// verifier refuses, which is what a torture case found, and `unreachable` would be a claim
3067    /// that the branch reaching this never runs, which is a claim about the program rather than
3068    /// about the value and lets the optimizer delete the path that led here.
3069    #[test]
3070    fn a_bare_return_from_a_function_that_promised_a_value_gives_back_a_zero() {
3071        let mut opts = options();
3072        opts.emit = EmitKind::Ir;
3073        opts.std = Std::C89;
3074        let compiled = |source: &str| {
3075            let result = run(&opts, source);
3076            assert_eq!(result.messages, Vec::<String>::new(), "C89 has nothing to say about this");
3077            result.text().to_owned()
3078        };
3079
3080        let text = compiled("int f(int x) { if (x) return; return 3; }\n");
3081        assert!(text.contains("iconst.i32 0\n    return"), "zero goes back: {text}");
3082        assert!(!text.contains("unreachable"), "the branch that reached it is kept: {text}");
3083
3084        // A floating point return needs the constant of its own kind rather than an integer one.
3085        let text = compiled("double f(int x) { if (x) return; return 1.0; }\n");
3086        assert!(text.contains("fconst.f64 0x0\n    return"), "a float zero goes back: {text}");
3087    }
3088
3089    /// What C89 6.3.2.2 declares for a call to a name nothing declared, seen in the IR rather than
3090    /// in what was said about it.
3091    ///
3092    /// `extern int f();`, so the call gives back an `int` and its arguments are promoted rather
3093    /// than converted to parameters there are none of. The declaration lasts for the file, which
3094    /// is what makes a second call to the same name ordinary and is why gcc says this once per
3095    /// file rather than once per call.
3096    #[test]
3097    fn a_call_to_a_name_nothing_declared_declares_it_as_c89_said_to() {
3098        let mut opts = options();
3099        opts.emit = EmitKind::Ir;
3100        opts.std = Std::C89;
3101        let compiled = |source: &str| {
3102            let result = run(&opts, source);
3103            assert_eq!(result.messages, Vec::<String>::new(), "C89 has nothing to say about this");
3104            result.text().to_owned()
3105        };
3106
3107        // An `int` back, which is the whole of what the implicit declaration says.
3108        let text = compiled("int f(void) { return g(); }\n");
3109        assert!(text.contains("call @g"), "the call is to the name that was written: {text}");
3110        assert!(text.contains("i32"), "and it gives back an int: {text}");
3111
3112        // No prototype, so a `char` argument arrives promoted to `int` the way an argument to a
3113        // function whose parameters are unspecified does.
3114        let text = compiled("int f(char c) { return g(c); }\n");
3115        assert!(text.contains("sext.i32"), "the argument is promoted: {text}");
3116
3117        // A name written as a value rather than called is still undeclared, since the rule is
3118        // about a call and nothing else.
3119        let mut opts = options();
3120        opts.std = Std::C89;
3121        let said = run(&opts, "int f(void) { return h; }\n").messages.join("\n");
3122        assert!(said.contains("'h' undeclared"), "not a call, so not declared: {said}");
3123    }
3124
3125    /// A file that calls a name above the definition of it, which is the shape the implicit
3126    /// declaration has to survive rather than swallow.
3127    ///
3128    /// The definition merges into the declaration the call already made rather than making a
3129    /// second one, so a declaration the tree does not carry at the top level takes the definition
3130    /// down with it: the body is attached to a node nothing walks and no function comes out.
3131    /// Nothing about the call itself looks wrong when that happens, and the program gets to the
3132    /// linker before anyone finds out, which is where `execute/cmpsi-1.c` in the torture suite
3133    /// found it, as an undefined reference to a name defined eleven lines further down.
3134    #[test]
3135    fn a_name_called_before_it_is_defined_still_gets_its_definition() {
3136        let mut opts = options();
3137        opts.emit = EmitKind::Ir;
3138        opts.std = Std::C89;
3139        let text = run(&opts, "int f(void) { return dummy(); }\ndummy () { return 7; }\n")
3140            .text()
3141            .to_owned();
3142        assert!(text.contains("func @f()"), "the caller is there: {text}");
3143        assert!(text.contains("func @dummy"), "and so is what it calls: {text}");
3144        assert!(text.contains("iconst.i32 7"), "with the body it was given: {text}");
3145    }
3146
3147    /// An old style definition whose parameter is narrower than what a call passes it.
3148    ///
3149    /// There is no prototype for a call to convert its argument to, so the argument is promoted
3150    /// and an `int` arrives for a parameter the body reads as an `unsigned char`. The entry block
3151    /// is where the two meet, and gcc writes the same pair of instructions there: store the low
3152    /// byte, read it back widened. `execute/950605-1.c` in the torture suite calls `f(-1)` and
3153    /// checks the parameter against `0xFF`, which is the difference between converting and not.
3154    #[test]
3155    fn an_old_style_parameter_is_converted_from_what_the_call_promoted_it_to() {
3156        let mut opts = options();
3157        opts.emit = EmitKind::Ir;
3158        opts.std = Std::C89;
3159        let compiled = |source: &str| run(&opts, source).text().to_owned();
3160
3161        let text = compiled("f (c) unsigned char c; { return c; }\n");
3162        assert!(text.contains("func @f(i32"), "an int arrives: {text}");
3163        assert!(text.contains("trunc.i8"), "and is cut down to what was declared: {text}");
3164        assert!(text.contains("zext.i32"), "then read back unsigned: {text}");
3165
3166        // A `short` is the same shape and signed, so it comes back the other way.
3167        let text = compiled("f (s) short s; { return s; }\n");
3168        assert!(text.contains("trunc.i16"), "cut down: {text}");
3169        assert!(text.contains("sext.i32"), "and read back signed: {text}");
3170
3171        // A `float` parameter is promoted to `double`, and without the conversion the multiply
3172        // below has one f64 operand and one f32, which the verifier refuses as invalid IR.
3173        let text = compiled("f (x) float x; { return x * 2; }\n");
3174        assert!(text.contains("func @f(f64"), "a double arrives: {text}");
3175        assert!(text.contains("fptrunc.f32"), "and is narrowed to the float: {text}");
3176
3177        // A parameter a prototype named arrives as itself and nothing is converted, which is the
3178        // case this must not have changed.
3179        let text = compiled("int f(unsigned char c) { return c; }\n");
3180        assert!(text.contains("func @f(i8)"), "the declared type arrives: {text}");
3181        assert!(!text.contains("trunc"), "so there is nothing to cut down: {text}");
3182    }
3183
3184    /// The six rules gcc 14 turned from a warning into an error, and the three answers each one
3185    /// gets depending on the dialect and on `-fpermissive`.
3186    ///
3187    /// The table is a measurement rather than a reading of the release notes. Six files, one per
3188    /// rule, put through gcc 16.2.0 on x86-64 Linux under each of the four command lines below
3189    /// with no `-W` flags on any of them, and what came back is what is written here. The three
3190    /// rules that say nothing under C89 are the three C89 did not have, and the three that warn
3191    /// there were constraint violations then as well.
3192    #[test]
3193    fn the_rules_gcc_promoted_are_decided_by_the_dialect_and_by_fpermissive() {
3194        // `-std=gnu89`, `-std=gnu17`, `-std=gnu17 -fpermissive`, and `-std=gnu23`.
3195        let modes = [(Std::C89, false), (Std::C17, false), (Std::C17, true), (Std::C23, false)];
3196        let cases = [
3197            ("static counted;\n", ["", "error", "warning", "error"]),
3198            ("int f(void) { return g(); }\n", ["", "error", "warning", "error"]),
3199            ("int f(x) { return x; }\n", ["", "error", "warning", "error"]),
3200            ("int *p;\nvoid h(void) { p = 1; }\n", ["warning", "error", "warning", "error"]),
3201            (
3202                "char *q;\nint *r;\nvoid k(void) { r = q; }\n",
3203                ["warning", "error", "warning", "error"],
3204            ),
3205            ("int f(void) { return; }\n", ["", "error", "warning", "error"]),
3206            ("void g(void) { return 1; }\n", ["warning", "error", "warning", "error"]),
3207        ];
3208
3209        for (source, wanted) in cases {
3210            for (&(std, permissive), wanted) in modes.iter().zip(wanted) {
3211                let mut opts = options();
3212                opts.std = std;
3213                opts.permissive = permissive;
3214                let said = run(&opts, source).messages.join("\n");
3215                let severity = if said.contains(": error: ") {
3216                    "error"
3217                } else if said.contains(": warning: ") {
3218                    "warning"
3219                } else {
3220                    ""
3221                };
3222                let how = if permissive { " -fpermissive" } else { "" };
3223                assert_eq!(
3224                    severity,
3225                    wanted,
3226                    "under -std={}{how}, {source} was answered with `{said}`",
3227                    std.as_str()
3228                );
3229                if wanted.is_empty() {
3230                    assert!(said.is_empty(), "nothing to say, but said `{said}`");
3231                }
3232            }
3233        }
3234    }
3235
3236    /// A first argument that is not a list, which the four variadic operators answer in two ways.
3237    ///
3238    /// gcc has `va_arg` as an operator, since it takes a type name and no function can, and the
3239    /// other three as builtin functions taking the address of a list. The difference is not a
3240    /// naming one: the operator's complaint is its own and is an error under every dialect, and
3241    /// the three functions go through the ordinary rule about an argument of the wrong type,
3242    /// which is one of the rules the table above is about. The same four command lines through
3243    /// gcc 16.2.0 on x86-64 Linux is where these came from.
3244    #[test]
3245    fn the_three_variadic_builtins_answer_a_bad_list_the_way_a_call_answers_a_bad_argument() {
3246        let modes = [(Std::C89, false), (Std::C17, false), (Std::C17, true), (Std::C23, false)];
3247        let cases = [
3248            (
3249                "int f(int n, ...) { char *p; return __builtin_va_arg(p, int); }\n",
3250                "first argument to 'va_arg' not of type 'va_list'",
3251                ["error", "error", "error", "error"],
3252            ),
3253            (
3254                "void f(int n, ...) { char *p; __builtin_va_start(p, n); }\n",
3255                "passing argument 1 of '__builtin_va_start' from incompatible pointer type",
3256                ["warning", "error", "warning", "error"],
3257            ),
3258            (
3259                "void f(int n, ...) { int x; __builtin_va_end(x); }\n",
3260                "passing argument 1 of '__builtin_va_end' makes pointer from integer without a \
3261                 cast",
3262                ["warning", "error", "warning", "error"],
3263            ),
3264            (
3265                "void f(int n, ...) { __builtin_va_list a; char *p; __builtin_va_copy(a, p); }\n",
3266                "passing argument 2 of '__builtin_va_copy' from incompatible pointer type",
3267                ["warning", "error", "warning", "error"],
3268            ),
3269        ];
3270
3271        for (source, message, wanted) in cases {
3272            for (&(std, permissive), wanted) in modes.iter().zip(wanted) {
3273                let mut opts = options();
3274                opts.std = std;
3275                opts.permissive = permissive;
3276                let said = run(&opts, source).messages.join("\n");
3277                let how = if permissive { " -fpermissive" } else { "" };
3278                assert!(
3279                    said.contains(&format!(": {wanted}: {message}")),
3280                    "under -std={}{how}, {source} was answered with `{said}`",
3281                    std.as_str()
3282                );
3283            }
3284        }
3285    }
3286
3287    /// The IR of `source` at one safety tier, insisting that it compiled cleanly.
3288    fn safe_ir(tier: rucc_session::Safety, source: &str) -> String {
3289        let mut opts = options();
3290        opts.emit = EmitKind::Ir;
3291        opts.safety = tier;
3292        let result = run(&opts, source);
3293        assert_eq!(result.messages, Vec::<String>::new(), "expected this to compile:\n{source}");
3294        result.text().to_owned()
3295    }
3296
3297    const READS_THROUGH_A_POINTER: &str = "int read(int *p) { return p[1]; }\n";
3298
3299    /// The IR for a source built with a tier and a padding mode.
3300    fn padded_ir(padding: Padding, source: &str) -> String {
3301        let mut opts = options();
3302        opts.emit = EmitKind::Ir;
3303        opts.safety = rucc_session::Safety::Detect;
3304        opts.padding = padding;
3305        let result = run(&opts, source);
3306        assert_eq!(result.messages, Vec::<String>::new(), "expected this to compile:\n{source}");
3307        result.text().to_owned()
3308    }
3309
3310    const FILLS_A_RECORD_A_MEMBER_AT_A_TIME: &str = "struct padded { char tag; int value; };\n\
3311         void fill(struct padded *p) { p->tag = 1; p->value = 2; }\n";
3312
3313    #[test]
3314    fn a_record_filled_a_member_at_a_time_comes_out_whole_when_padding_does_not_participate() {
3315        // Section 9.3 of document 09, and the reason the default is the one it gives library code.
3316        // Four bytes from the `char` and four from the `int` is the whole of an eight byte record,
3317        // so the `memcmp` or the hash or the `write` that reads it back is not refused.
3318        let text = padded_ir(Padding::Ignored, FILLS_A_RECORD_A_MEMBER_AT_A_TIME);
3319        assert_eq!(text.matches("owns 4").count(), 2, "{text}");
3320    }
3321
3322    #[test]
3323    fn a_store_says_only_what_it_wrote_when_padding_does_participate() {
3324        // The kernel profile's default, which is section 9.3's actual rule: the padding stays
3325        // unwritten and the read of the record that would leak it is the one that reports.
3326        let text = padded_ir(Padding::Tracked, FILLS_A_RECORD_A_MEMBER_AT_A_TIME);
3327        assert!(!text.contains("owns"), "{text}");
3328    }
3329
3330    #[test]
3331    fn a_member_of_a_union_owns_nothing_after_it() {
3332        // The bytes after a short member of a union belong to a longer member rather than to
3333        // padding, and saying a store through the short one wrote them would be saying the longer
3334        // one holds a value nobody put there.
3335        let text = padded_ir(
3336            Padding::Ignored,
3337            "union u { char tag; long wide; };\nvoid fill(union u *p) { p->tag = 1; }\n",
3338        );
3339        assert!(!text.contains("owns"), "{text}");
3340    }
3341
3342    #[test]
3343    fn an_inner_records_trailing_padding_reaches_the_outer_records() {
3344        // The composition. `in` owns four bytes of `outer` because `x` starts there, and `c` is
3345        // the last member of `in`, so what it owns is what `in` owns rather than its own one byte.
3346        // Without that the three bytes between them would stay unwritten and a read of the whole
3347        // thing would report.
3348        let text = padded_ir(
3349            Padding::Ignored,
3350            "struct inner { char c; };\n\
3351             struct outer { struct inner in; int x; };\n\
3352             void fill(struct outer *p) { p->in.c = 1; p->x = 2; }\n",
3353        );
3354        assert_eq!(text.matches("owns 4").count(), 2, "{text}");
3355    }
3356
3357    #[test]
3358    fn a_build_that_did_not_ask_for_the_monitor_is_compiled_the_way_it_always_was() {
3359        // This is the load bearing test of the whole flag. The monitor is being built in the open
3360        // and every build in the world is compiled by this compiler with the flag absent, so a
3361        // check that leaked into that path would be a regression for everybody.
3362        let text = ir(READS_THROUGH_A_POINTER);
3363        assert!(!text.contains("check_"), "{text}");
3364        assert!(!text.contains("cap_of"), "{text}");
3365    }
3366
3367    #[test]
3368    fn asking_for_a_tier_puts_the_checks_in_before_the_optimizer_sees_them() {
3369        let text = safe_ir(rucc_session::Safety::Detect, READS_THROUGH_A_POINTER);
3370        assert!(text.contains("cap_of"), "{text}");
3371        assert!(text.contains("check_bounds"), "{text}");
3372        assert!(text.contains("check_live"), "{text}");
3373        // The subscript is address arithmetic, so J2 applies to it as well as J1.
3374        assert!(text.contains("check_deriv"), "{text}");
3375        // And the read names a type, so it asks the type plane about the bytes as well.
3376        assert!(text.contains("check_type"), "{text}");
3377    }
3378
3379    #[test]
3380    fn the_three_tiers_that_are_not_off_all_check_the_same_accesses_so_far() {
3381        // What separates them is the reporter and the boundary, which are milestones S2 and S3.
3382        // Pinning it here means the day they stop agreeing, this test says so rather than the
3383        // difference going unnoticed.
3384        let detect = safe_ir(rucc_session::Safety::Detect, READS_THROUGH_A_POINTER);
3385        for tier in [rucc_session::Safety::Enforce, rucc_session::Safety::Kernel] {
3386            assert_eq!(safe_ir(tier, READS_THROUGH_A_POINTER), detect, "{tier}");
3387        }
3388    }
3389
3390    /// The safety summary of `source` at one tier, insisting that it compiled cleanly.
3391    fn summary(tier: rucc_session::Safety, source: &str) -> String {
3392        let mut opts = options();
3393        opts.emit = EmitKind::SafetySummary;
3394        opts.safety = tier;
3395        let result = run(&opts, source);
3396        assert_eq!(result.messages, Vec::<String>::new(), "expected this to compile:\n{source}");
3397        result.text().to_owned()
3398    }
3399
3400    #[test]
3401    fn the_summary_counts_the_checks_that_went_in_and_the_ones_still_standing() {
3402        let text = summary(rucc_session::Safety::Detect, READS_THROUGH_A_POINTER);
3403        assert!(text.contains("\"tier\": \"detect\""), "{text}");
3404        // One load, so one of each of the two access checks, and the subscript is a derivation.
3405        assert!(
3406            text.contains("\"bounds\": { \"emitted\": 1, \"remaining\": 1, \"discharged\": 0 }"),
3407            "{text}"
3408        );
3409        assert!(
3410            text.contains(
3411                "\"derivation\": { \"emitted\": 1, \"remaining\": 1, \"discharged\": 0 }"
3412            ),
3413            "{text}"
3414        );
3415    }
3416
3417    #[test]
3418    fn a_build_without_the_monitor_summarises_as_a_build_with_no_checks_in_it() {
3419        // Which is the honest summary rather than an error. A build system that emits a summary
3420        // for every unit should get one for the units nobody asked to instrument too, and the
3421        // zeroes are what say that the guarantee over that file is nothing at all.
3422        let text = summary(rucc_session::Safety::Off, READS_THROUGH_A_POINTER);
3423        assert!(text.contains("\"tier\": \"off\""), "{text}");
3424        assert!(
3425            text.contains("\"bounds\": { \"emitted\": 0, \"remaining\": 0, \"discharged\": 0 }"),
3426            "{text}"
3427        );
3428    }
3429
3430    #[test]
3431    fn a_call_the_boundary_models_is_counted_apart_from_one_it_does_not() {
3432        let text = summary(
3433            rucc_session::Safety::Detect,
3434            "void *memcpy(void *, const void *, unsigned long);\n\
3435             int puts(const char *);\n\
3436             void f(char *d, char *s) { memcpy(d, s, 4); puts(d); }\n",
3437        );
3438        assert!(text.contains("\"interposed\": 1"), "{text}");
3439        assert!(text.contains("\"puts\""), "{text}");
3440        // The wrapper it was pointed at is ours, so it is not on the list of things this build
3441        // failed to model. Counting it there would make instrumenting a file look worse than
3442        // leaving it alone.
3443        assert!(!text.contains("__rucc_wrap_memcpy\""), "{text}");
3444    }
3445
3446    #[test]
3447    fn the_two_directions_a_pointer_crosses_the_boundary_are_counted_apart() {
3448        // `f` is a name the linker can bind to and takes a pointer, so a pointer arrives there.
3449        // `notes_open` is a library this build did not instrument, so a pointer comes back from
3450        // it. Both are crossings and neither is the other, which is why there are two numbers.
3451        let text = summary(
3452            rucc_session::Safety::Detect,
3453            "void *notes_open(void);\n\
3454             char *f(char *p) { char *q = notes_open(); return q ? q : p; }\n",
3455        );
3456        assert!(text.contains("\"crossings\": { \"entered\": 1, \"returned\": 1 }"), "{text}");
3457        assert!(text.contains("\"notes_open\""), "{text}");
3458    }
3459
3460    #[test]
3461    fn a_static_function_nobody_takes_the_address_of_is_not_a_crossing() {
3462        // Nothing outside the file can reach it, so a witness on its parameters would be counting
3463        // a crossing that does not happen.
3464        let text = summary(
3465            rucc_session::Safety::Detect,
3466            "static int len(const char *p) { return p ? 1 : 0; }\n\
3467             int f(void) { return len(\"x\"); }\n",
3468        );
3469        assert!(text.contains("\"crossings\": { \"entered\": 0, \"returned\": 0 }"), "{text}");
3470    }
3471
3472    /// The granule report for `source`, insisting that it compiled cleanly.
3473    fn granules(source: &str) -> String {
3474        let mut opts = options();
3475        opts.emit = EmitKind::TypeGranules;
3476        let result = run(&opts, source);
3477        assert_eq!(result.messages, Vec::<String>::new(), "expected this to compile:\n{source}");
3478        result.text().to_owned()
3479    }
3480
3481    #[test]
3482    fn the_granule_report_names_every_record_and_both_keyings() {
3483        let text = granules(
3484            "struct hot { char *p; int a; int b; };\n\
3485             int f(struct hot *h) { return h->a; }\n",
3486        );
3487        assert!(text.contains("struct hot"), "{text}");
3488        // Both keyings are reported because which types count as one is a decision the design
3489        // has not made yet, and a report that picked one would be hiding the cost of the other.
3490        assert!(text.contains("every type distinct"), "{text}");
3491        assert!(text.contains("every pointer one type"), "{text}");
3492        assert!(text.contains("budget"), "{text}");
3493    }
3494
3495    #[test]
3496    fn a_record_nothing_uses_is_still_measured() {
3497        // The measurement is about what a program declares, not about what it runs, so a type
3498        // that is only ever declared still costs the plane whatever its layout costs.
3499        let text = granules("struct unused { long a; double b; };\nint f(void) { return 0; }\n");
3500        assert!(text.contains("struct unused"), "{text}");
3501    }
3502
3503    #[test]
3504    fn the_granule_report_stops_before_anything_is_lowered() {
3505        // A layout is settled at the closing brace, so lowering the function bodies would take
3506        // minutes on an amalgamation and answer nothing. The evidence that it stops is that a
3507        // body the back end has no way to compile still produces a report.
3508        let text = granules(
3509            "struct wide { long double d; };\n\
3510             long double f(long double x) { return x * x; }\n",
3511        );
3512        assert!(text.contains("struct wide"), "{text}");
3513    }
3514
3515    #[test]
3516    fn a_witness_reaches_the_assembler_as_a_call_to_the_runtime() {
3517        // The count only means anything if the call is really there, and a summary saying one is
3518        // there is not evidence that the back end emitted it.
3519        let text = safe_asm(rucc_session::Safety::Detect, "char *f(char *p) { return p; }\n");
3520        assert!(text.contains("\tcall\t__rucc_cap_witness\n"), "{text}");
3521    }
3522
3523    #[test]
3524    fn a_pointer_turned_into_an_integer_is_on_the_trust_set() {
3525        let text = summary(
3526            rucc_session::Safety::Detect,
3527            "unsigned long f(int *p) { return (unsigned long) p; }\n",
3528        );
3529        assert!(text.contains("\"exposed\": 1"), "{text}");
3530    }
3531
3532    /// The assembly of `source` at one safety tier, insisting that it compiled cleanly.
3533    fn safe_asm(tier: rucc_session::Safety, source: &str) -> String {
3534        let mut opts = options();
3535        opts.emit = EmitKind::Asm;
3536        opts.safety = tier;
3537        let result = run(&opts, source);
3538        assert_eq!(result.messages, Vec::<String>::new(), "expected this to compile:\n{source}");
3539        result.text().to_owned()
3540    }
3541
3542    #[test]
3543    fn a_check_reaches_the_assembler_as_a_call_to_the_runtime() {
3544        let text = safe_asm(rucc_session::Safety::Detect, READS_THROUGH_A_POINTER);
3545        assert!(text.contains("\tcall\t__rucc_check_bounds\n"), "{text}");
3546        assert!(text.contains("\tcall\t__rucc_check_live\n"), "{text}");
3547        assert!(text.contains("\tcall\t__rucc_check_deriv\n"), "{text}");
3548        assert!(text.contains("\tcall\t__rucc_check_type\n"), "{text}");
3549        assert!(text.contains("\tcall\t__rucc_check_init\n"), "{text}");
3550    }
3551
3552    #[test]
3553    fn every_check_that_reached_the_assembler_has_a_row_describing_it() {
3554        // Five checks and five descriptors, each in the section the runtime's reporter reads.
3555        // The width is `rucc_safety::lower::WIDTH` and the row is `rucc_safe_rt::fail::Descriptor`,
3556        // and the two agreeing is what makes the address a check is handed mean anything.
3557        let text = safe_asm(rucc_session::Safety::Detect, READS_THROUGH_A_POINTER);
3558        let section = format!("\t.section\t{},", rucc_safety::SECTION);
3559        assert_eq!(text.matches(&section).count(), 5, "{text}");
3560        for index in 0..5 {
3561            let name = format!("__rucc_safety_desc_{index}");
3562            // Defined once and referenced once, because a descriptor nothing points at describes
3563            // nothing and a reference with no definition does not link.
3564            assert!(text.contains(&format!("{name}:\n")), "{text}");
3565            assert!(text.contains(&format!("{name}(%rip)")), "{text}");
3566        }
3567        assert!(!text.contains("__rucc_safety_desc_5"), "{text}");
3568    }
3569
3570    /// `__builtin_constant_p` is answered in the front end and never reaches the IR.
3571    ///
3572    /// gcc folds it after optimization, so its answer for an argument that is not written as a
3573    /// constant can differ between `-O0` and `-O2`. What is checked here is the front end's
3574    /// answer, which is the same at every level, and the four cases where gcc gives the same
3575    /// answer at both levels are the ones measured on gcc 16: a literal is one, a variable is
3576    /// zero, a string literal is one and the address of an object is zero.
3577    #[test]
3578    fn builtin_constant_p_is_folded_where_it_is_written_rather_than_called() {
3579        let text = ir(concat!(
3580            "int g;\n",
3581            "int a = __builtin_constant_p(1);\n",
3582            "int b = __builtin_constant_p(g);\n",
3583            "int c = __builtin_constant_p(\"abc\");\n",
3584            "int d = __builtin_constant_p(&g);\n",
3585            "int e = __builtin_constant_p(1.5);\n",
3586            "int h = __builtin_choose_expr(__builtin_constant_p(3), 11, 22);\n",
3587        ));
3588        assert!(text.contains("global @a : i32 = 1,"), "{text}");
3589        assert!(text.contains("global @b : i32 = 0,"), "{text}");
3590        assert!(text.contains("global @c : i32 = 1,"), "{text}");
3591        assert!(text.contains("global @d : i32 = 0,"), "{text}");
3592        assert!(text.contains("global @e : i32 = 1,"), "{text}");
3593        assert!(text.contains("global @h : i32 = 11,"), "{text}");
3594        assert!(!text.contains("__builtin_constant_p"), "it is not a call to anything:\n{text}");
3595
3596        // The argument is not evaluated, which is what gcc does with it as well, so `i` is
3597        // still zero. The second constant is the answer, which nothing reads and which the
3598        // first pass that looks for dead code will take out.
3599        let text = body("int f(void) { int i = 0; __builtin_constant_p(i++); return i; }\n");
3600        assert_eq!(text, "block0:\n    %0 = iconst.i32 0\n    %1 = iconst.i32 0\n    return %0\n");
3601    }
3602
3603    /// A library builtin is the library function of the same name, and the call says so.
3604    ///
3605    /// A program writes `__builtin_strlen` rather than `strlen` to reach the function the C
3606    /// library promises where its own name has been taken by a macro, and to say that the usual
3607    /// meaning is the one intended. So the name in the program and the name in the object file
3608    /// are two different names and the call carries the second one. gcc folds several of these
3609    /// when the arguments allow it, which is an optimization on top of a call that is already
3610    /// right rather than instead of it, so nothing here depends on any folding happening.
3611    #[test]
3612    fn a_call_to_a_library_builtin_reaches_the_library_function() {
3613        let text = body("void f(void) { __builtin_abort(); }\n");
3614        assert_eq!(text, "block0:\n    call @abort() : ()\n    return\n");
3615
3616        // Nothing declared either of these and nothing had to: the prefix is what says the name
3617        // belongs to the implementation, and the type comes out of `features.toml`.
3618        let text = ir("int f(const char *s) { return __builtin_puts(s) + __builtin_strlen(s); }\n");
3619        assert!(text.contains("call @puts(%0) : (ptr) -> i32"), "{text}");
3620        assert!(text.contains("call @strlen(%0) : (ptr) -> i64"), "{text}");
3621        assert!(!text.contains("__builtin_"), "the prefix is not part of any name here:\n{text}");
3622    }
3623
3624    /// The absolute value family is four instructions and not a call, whoever declared the name.
3625    ///
3626    /// `abs`, `labs` and `llabs` are reserved to the implementation, so a program that writes one
3627    /// means the one the C library promises and the compiler is allowed to know what it does. The
3628    /// program in `gcc.c-torture/execute/20021127-1.c` is the one that insists: it defines `llabs`
3629    /// to abort and expects the call not to reach it. Measured against gcc 16.2.0, which writes a
3630    /// `neg` and a `cmovns` and never calls the definition either.
3631    ///
3632    /// The most negative value comes back as itself, which is what the arithmetic gives and what
3633    /// gcc's pair of instructions gives, and C says the answer is undefined there.
3634    #[test]
3635    fn the_absolute_value_family_is_the_magnitude_and_not_a_call() {
3636        let text = body(concat!(
3637            "long long llabs(long long);\n",
3638            "long long f(long long x) { return llabs(x); }\n",
3639        ));
3640        assert!(text.contains("%1 = iconst.i64 63"), "{text}");
3641        assert!(text.contains("%2 = ashr %0, %1"), "{text}");
3642        assert!(text.contains("%3 = xor %0, %2"), "{text}");
3643        assert!(text.contains("%4 = sub %3, %2"), "{text}");
3644        assert!(!text.contains("call"), "the call does not happen:\n{text}");
3645
3646        // The narrower two, whose width comes from the type the library gives the name and not
3647        // from anything at the call.
3648        let text = body("int abs(int);\nint f(int x) { return abs(x); }\n");
3649        assert!(text.contains("iconst.i32 31"), "{text}");
3650        let text = body("long labs(long);\nlong f(long x) { return labs(x); }\n");
3651        assert!(text.contains("iconst.i64 63"), "{text}");
3652
3653        // The prefixed spelling is the same node, and it is what a program writes to reach the
3654        // library's meaning where the plain name has been taken.
3655        let text = body("long long f(long long x) { return __builtin_llabs(x); }\n");
3656        assert!(!text.contains("call"), "{text}");
3657
3658        // A definition of the name in the same file changes nothing, which is the whole point.
3659        let text = ir(concat!(
3660            "long long llabs(long long b);\n",
3661            "long long g(long long x) { return llabs(x); }\n",
3662            "long long llabs(long long b) { return 7; }\n",
3663        ));
3664        assert!(!text.contains("call @llabs"), "{text}");
3665    }
3666
3667    /// A byte swap is one instruction and not a call, and nothing had to declare it.
3668    ///
3669    /// SQLite writes these for its page headers and glibc's `<endian.h>` defines `htobe32` and its
3670    /// neighbours as exactly these, so a program that reads a file format reaches one without ever
3671    /// naming it. There is no object file anywhere that defines `__builtin_bswap32`, so a call left
3672    /// standing here would not link.
3673    #[test]
3674    fn a_byte_swap_is_arithmetic_and_not_a_call() {
3675        let text = body("unsigned f(unsigned x) { return __builtin_bswap32(x); }\n");
3676        assert_eq!(text, "block0(%0: i32):\n    %1 = bswap %0\n    return %1\n");
3677
3678        // The argument is converted by the prototype the way any other call's would be, so the
3679        // swap happens at the width the name says and not at the width the program wrote.
3680        let text = body("unsigned f(unsigned char c) { return __builtin_bswap32(c); }\n");
3681        assert!(text.contains("zext.i32 %0"), "widened first: {text}");
3682        assert!(text.contains("bswap %1"), "and swapped at four bytes: {text}");
3683    }
3684
3685    /// Each of the three reverses in the width its name says, which is the type of the node.
3686    ///
3687    /// The width matters more here than it looks. `__builtin_bswap16` is the two bytes of a
3688    /// `uint16_t` exchanged, and if the node came out at the machine's width instead then the bits
3689    /// above the value would be dragged into the answer and the result would be zero.
3690    #[test]
3691    fn the_byte_swaps_reverse_at_the_width_their_name_says() {
3692        for (name, ty, width) in [
3693            ("__builtin_bswap16", "unsigned short", "i16"),
3694            ("__builtin_bswap32", "unsigned", "i32"),
3695            ("__builtin_bswap64", "unsigned long long", "i64"),
3696        ] {
3697            let source = format!("{ty} f({ty} x) {{ return {name}(x); }}\n");
3698            let text = body(&source);
3699            assert_eq!(
3700                text,
3701                format!("block0(%0: {width}):\n    %1 = bswap %0\n    return %1\n"),
3702                "{name}"
3703            );
3704        }
3705    }
3706
3707    /// The three bit counts the IR has an instruction for are that instruction and not a call.
3708    ///
3709    /// Fifteen rows of `features.toml` come out of five questions, and three of the five are one
3710    /// instruction each. The kernel's bitmap search is built on them, ffmpeg counts leading zeroes
3711    /// in its bitstream reader and SQLite uses one to size a page, so a call left standing here
3712    /// would not link against anything and would be slow if it did.
3713    #[test]
3714    fn the_bit_counts_are_instructions_and_not_calls() {
3715        let text = body("int f(unsigned x) { return __builtin_clz(x); }\n");
3716        assert_eq!(text, "block0(%0: i32):\n    %1 = ctlz %0\n    return %1\n");
3717
3718        let text = body("int f(unsigned x) { return __builtin_ctz(x); }\n");
3719        assert_eq!(text, "block0(%0: i32):\n    %1 = cttz %0\n    return %1\n");
3720
3721        let text = body("int f(unsigned x) { return __builtin_popcount(x); }\n");
3722        assert_eq!(text, "block0(%0: i32):\n    %1 = ctpop %0\n    return %1\n");
3723    }
3724
3725    /// The width counted is the operand's and the width answered is `int`, which are two different
3726    /// things at every spelling but the narrowest.
3727    ///
3728    /// This is the mistake the family invites. `__builtin_clz` of a value counts the leading zeroes
3729    /// of it narrowed to `unsigned int` and `__builtin_clzll` counts them at sixty four bits, and
3730    /// those are different numbers for the same value. What decides it is the prototype the row
3731    /// carries, so the count happens after the conversion and the narrowing back to `int` happens
3732    /// after the count.
3733    #[test]
3734    fn the_bit_counts_ask_about_the_width_their_name_says() {
3735        let text = body("int f(unsigned long long x) { return __builtin_clzll(x); }\n");
3736        assert!(text.starts_with("block0(%0: i64):"), "counted at eight bytes: {text}");
3737        assert!(text.contains("%1 = ctlz %0"), "{text}");
3738        assert!(text.contains("trunc.i32 %1"), "and answered in an int: {text}");
3739
3740        // The same value asked about at the narrower width, which converts first and so counts
3741        // something else.
3742        let text = body("int f(unsigned long long x) { return __builtin_clz(x); }\n");
3743        assert!(text.contains("trunc.i32 %0"), "narrowed to what was asked about: {text}");
3744        assert!(text.contains("ctlz %1"), "and counted there: {text}");
3745
3746        let text = body("int f(unsigned long x) { return __builtin_popcountl(x); }\n");
3747        assert!(text.contains("%1 = ctpop %0"), "{text}");
3748        assert!(!text.contains("call"), "{text}");
3749    }
3750
3751    /// A parity is whether the count of set bits is odd, which is that count and its low bit.
3752    ///
3753    /// Not the machine's parity flag, which on x86-64 is over the low byte of a result and so is a
3754    /// different question, and not the count itself, since C says the answer is zero or one.
3755    #[test]
3756    fn a_parity_is_the_low_bit_of_the_set_bit_count() {
3757        let text = body("int f(unsigned x) { return __builtin_parity(x); }\n");
3758        assert!(text.contains("%1 = ctpop %0"), "{text}");
3759        assert!(text.contains("iconst.i32 1"), "{text}");
3760        assert!(text.contains("and %1, %2"), "the low bit of it: {text}");
3761    }
3762
3763    /// `__builtin_ffs` is the trailing zero count and one, kept only when there was a bit to find.
3764    ///
3765    /// The one in the family defined at zero, where it answers zero. Written as a mask rather than
3766    /// as a branch: the count and the comparison do not depend on each other and both are cheap, so
3767    /// a branch would buy nothing and cost two blocks and a join.
3768    #[test]
3769    fn the_first_set_bit_is_one_based_and_zero_for_a_zero() {
3770        let text = body("int f(int x) { return __builtin_ffs(x); }\n");
3771        assert!(text.contains("%1 = cttz %0"), "{text}");
3772        assert!(text.contains("%4 = add %1, %2"), "one more than the count: {text}");
3773        assert!(text.contains("%5 = icmp ne %0, %3"), "whether there was a bit at all: {text}");
3774        assert!(text.contains("%7 = sub %3, %6"), "spread to a mask: {text}");
3775        assert!(text.contains("%8 = and %4, %7"), "and kept only then: {text}");
3776        assert!(!text.contains("br_if"), "no branch: {text}");
3777    }
3778
3779    /// The three overflow checks are arithmetic and a flag, and not a call to anything.
3780    ///
3781    /// gcc has emitted these since 5.0 and there is no object file that defines one, so a call left
3782    /// standing here would not link. SQLite reaches all three within twenty lines of each other, in
3783    /// `sqlite3AddInt64` and its two neighbours, which is the reason they were done now.
3784    ///
3785    /// The IR instruction answers two things at once, the wrapped value and whether it wrapped,
3786    /// which is a shape nothing else in the IR has. The store is the builtin writing the answer
3787    /// through the pointer it was handed.
3788    #[test]
3789    fn an_overflow_check_is_arithmetic_and_not_a_call() {
3790        let text =
3791            body("int f(int a, int b, int *r) { return __builtin_add_overflow(a, b, r); }\n");
3792        assert!(text.contains("%3, %4 = sadd_overflow.(i32, i1) %0, %1"), "{text}");
3793        assert!(text.contains("store %3 -> %2"), "{text}");
3794        assert!(!text.contains("call"), "{text}");
3795
3796        let text =
3797            body("int f(int a, int b, int *r) { return __builtin_sub_overflow(a, b, r); }\n");
3798        assert!(text.contains("ssub_overflow.(i32, i1) %0, %1"), "{text}");
3799
3800        let text =
3801            body("int f(int a, int b, int *r) { return __builtin_mul_overflow(a, b, r); }\n");
3802        assert!(text.contains("smul_overflow.(i32, i1) %0, %1"), "{text}");
3803
3804        // Unsigned operands get the unsigned form, which is a different question about the same
3805        // arithmetic: an unsigned sum wraps where a signed one of the same bits does not.
3806        let text = body(
3807            "int f(unsigned a, unsigned b, unsigned *r) { return __builtin_add_overflow(a, b, r); }\n",
3808        );
3809        assert!(text.contains("uadd_overflow.(i32, i1) %0, %1"), "{text}");
3810    }
3811
3812    /// The arithmetic happens at a type that holds every value all three written types can hold.
3813    ///
3814    /// That is what makes the check exact. `unsigned int` and `int` in one call need thirty three
3815    /// bits between them, so the add is done at sixty four with each operand extended the way its
3816    /// own signedness says: the unsigned one zero extended, the signed one sign extended. Sign
3817    /// extending the unsigned one would turn three billion into a negative number before the
3818    /// addition ever saw it.
3819    #[test]
3820    fn an_overflow_check_is_done_at_a_type_that_holds_every_operand() {
3821        let text = body(
3822            "int f(unsigned a, int b, long long *r) { return __builtin_add_overflow(a, b, r); }\n",
3823        );
3824        assert!(text.contains("%3 = zext.i64 %0"), "the unsigned operand keeps its value: {text}");
3825        assert!(text.contains("%4 = sext.i64 %1"), "and so does the signed one: {text}");
3826        assert!(text.contains("sadd_overflow.(i64, i1) %3, %4"), "{text}");
3827
3828        // Three types that agree need no extension at all, which is what nearly every real call
3829        // is written as.
3830        let text = body(
3831            "int f(long long a, long long b, long long *r) { return __builtin_mul_overflow(a, b, r); }\n",
3832        );
3833        assert!(text.contains("smul_overflow.(i64, i1) %0, %1"), "{text}");
3834        assert!(!text.contains("sext."), "{text}");
3835        // The one widening left is the answer, which is a bit becoming the `int` C says it is.
3836        assert!(!text.contains("zext.i64"), "{text}");
3837    }
3838
3839    /// The wrapped answer is written through the pointer whether or not it fit.
3840    ///
3841    /// That is gcc's rule and it is what makes the builtin usable as a wrapping add with a flag on
3842    /// the side. A destination narrower than the arithmetic is narrowed and widened back, and the
3843    /// answer being different is the second half of the test: the instruction says whether the
3844    /// arithmetic itself needed more room, and the round trip says whether what came out survived
3845    /// the trip down to where it was going.
3846    #[test]
3847    fn an_overflow_check_writes_the_wrapped_answer_whether_or_not_it_fit() {
3848        let text =
3849            body("int f(int a, int b, char *r) { return __builtin_sub_overflow(a, b, r); }\n");
3850        assert!(text.contains("%3, %4 = ssub_overflow.(i32, i1) %0, %1"), "{text}");
3851        assert!(text.contains("%5 = trunc.i8 %3"), "narrowed to where it goes: {text}");
3852        assert!(text.contains("%6 = sext.i32 %5"), "and back: {text}");
3853        assert!(text.contains("%7 = icmp ne %6, %3"), "which is whether it fit: {text}");
3854        assert!(text.contains("store %5 -> %2"), "the narrowed value is stored either way: {text}");
3855        assert!(text.contains("%8 = or %4, %7"), "and either bit is an overflow: {text}");
3856    }
3857
3858    /// A call needing more than the widest type there is compiles, by not asking for such a type.
3859    ///
3860    /// One way to reach it: an unsigned `__int128` mixed with a signed type, which needs a hundred
3861    /// and twenty nine bits to represent both and so has nowhere left to go. That used to be refused
3862    /// by name. It is done now by carrying the sign of each operand alongside its value rather than
3863    /// inside it, which is what gcc does, so all three of the family compile for that mix.
3864    #[test]
3865    fn a_call_needing_more_than_the_widest_type_still_compiles() {
3866        for name in ["add", "sub", "mul"] {
3867            let source = format!(
3868                "int f(unsigned __int128 a, long long b, __int128 *r) {{\n    \
3869                 return __builtin_{name}_overflow(a, b, r);\n}}\n"
3870            );
3871            let mut opts = options();
3872            opts.emit = EmitKind::MirFinal;
3873            assert!(!run(&opts, &source).failed(), "{name} was refused or stopped the back end");
3874        }
3875    }
3876
3877    /// An operand that is not an integer at all is the older message, from the type checking every
3878    /// type generic builtin shares.
3879    #[test]
3880    fn an_overflow_check_over_something_that_is_not_an_integer_says_so() {
3881        let messages =
3882            errors("int f(double a, int b, int *r) { return __builtin_add_overflow(a, b, r); }\n");
3883        assert!(messages.iter().any(|line| line.contains("E0671")), "{messages:?}");
3884
3885        let messages =
3886            errors("int f(int a, int b, double *r) { return __builtin_add_overflow(a, b, r); }\n");
3887        assert!(messages.iter().any(|line| line.contains("E0671")), "{messages:?}");
3888    }
3889
3890    /// An ordered access is an ordered access in the IR, with the ordering the program wrote.
3891    ///
3892    /// Which is the point of the node existing at all. An ordering is not an argument anything is
3893    /// passed, it is a thing the IR says about an access, so the number in the source is read once
3894    /// in the front end and after that the ordering travels on the instruction where every pass
3895    /// that moves code can see it.
3896    ///
3897    /// SQLite is why these are done: `AtomicLoad` and `AtomicStore` in `sqlite3.c` are
3898    /// `__atomic_load_n` and `__atomic_store_n` at the relaxed ordering, and there are thirty five
3899    /// calls to the pair.
3900    #[test]
3901    fn an_ordered_access_is_ordered_in_the_ir() {
3902        let text = body("int f(int *p) { return __atomic_load_n(p, 0); }\n");
3903        assert!(text.contains("atomic_load.i32 %0, align 4, relaxed"), "{text}");
3904
3905        let text = body("long f(long *p) { return __atomic_load_n(p, 2); }\n");
3906        assert!(text.contains("atomic_load.i64 %0, align 8, acquire"), "{text}");
3907
3908        let text = body("void f(int *p, int v) { __atomic_store_n(p, v, 3); }\n");
3909        assert!(text.contains("atomic_store %1 -> %0, align 4, release"), "{text}");
3910
3911        let text = body("void f(int *p, int v) { __atomic_store_n(p, v, 5); }\n");
3912        assert!(text.contains("atomic_store %1 -> %0, align 4, seq_cst"), "{text}");
3913
3914        // The value is converted to what the pointer points at before it is stored, which is what
3915        // the call would have done if it had a prototype to convert against.
3916        let text = body("void f(char *p, int v) { __atomic_store_n(p, v, 0); }\n");
3917        assert!(text.contains("trunc.i8 %1"), "{text}");
3918        assert!(text.contains("atomic_store %2 -> %0, align 1, relaxed"), "{text}");
3919    }
3920
3921    /// On this machine the ordered access is the plain instruction, except at the strongest
3922    /// ordering of a store.
3923    ///
3924    /// x86-64 is total store order: every load is already an acquire and every store is already a
3925    /// release, and an aligned access no wider than a word is indivisible whether or not anybody
3926    /// asked. So the whole family is `mov` and the one thing the machine does not give away is a
3927    /// store staying in front of a later load, which is `mfence` behind the store. Every line below
3928    /// is what gcc 16.2.0 writes for the same function.
3929    #[test]
3930    fn an_ordered_access_is_the_plain_instruction_on_this_machine() {
3931        let text = asm("int f(int *p) { return __atomic_load_n(p, 5); }\n");
3932        assert!(text.contains("movl\t(%rdi), %eax"), "{text}");
3933        assert!(!text.contains("mfence"), "a load needs no barrier here: {text}");
3934
3935        let text = asm("void f(int *p, int v) { __atomic_store_n(p, v, 3); }\n");
3936        assert!(text.contains("movl\t%esi, (%rdi)"), "{text}");
3937        assert!(!text.contains("mfence"), "a release store needs no barrier here: {text}");
3938
3939        let text = asm("void f(int *p, int v) { __atomic_store_n(p, v, 5); }\n");
3940        let (before, after) = text.split_once("mfence").expect("a barrier: {text}");
3941        assert!(before.contains("movl\t%esi, (%rdi)"), "the store comes first: {text}");
3942        assert!(!after.contains("movl"), "and nothing else is between them: {text}");
3943    }
3944
3945    /// A barrier is one instruction at the strongest ordering and no instruction below it.
3946    ///
3947    /// The same reasoning the other way round. An acquire, a release and an acquire release fence
3948    /// are already true of every program running on this machine, and what a program wanted from
3949    /// one is that the compiler not move accesses across it, which is already so by the time any
3950    /// instruction is picked. Sequential consistency is the one that costs something.
3951    ///
3952    /// `__sync_synchronize` is the older family's spelling of the strongest one and compiles to
3953    /// exactly the same instruction, which is what SQLite calls twice in `sqlite3.c`.
3954    #[test]
3955    fn a_barrier_is_one_instruction_at_the_strongest_ordering_and_none_below_it() {
3956        assert!(asm("void f(void) { __atomic_thread_fence(5); }\n").contains("mfence"));
3957        assert!(asm("void f(void) { __sync_synchronize(); }\n").contains("mfence"));
3958
3959        for weaker in ["1", "2", "3", "4"] {
3960            let source = format!("void f(void) {{ __atomic_thread_fence({weaker}); }}\n");
3961            assert!(!asm(&source).contains("mfence"), "{weaker} costs nothing here");
3962        }
3963    }
3964
3965    /// The four compare and exchange names are one IR instruction producing two values.
3966    ///
3967    /// Which of the two the expression answers is the difference between three of the four names,
3968    /// and the fourth difference is the C11 pair writing what they found back through the pointer
3969    /// they were handed, which is the branch after the instruction.
3970    #[test]
3971    fn a_compare_and_exchange_is_one_instruction_answering_two_things() {
3972        // The older family, whose two names are the same instruction read two ways. Neither has a
3973        // memory order argument and both are a full barrier, which is what `seq_cst` says.
3974        let text =
3975            body("int f(int *p, int e, int d) { return __sync_val_compare_and_swap(p, e, d); }\n");
3976        assert!(text.contains("%3, %4 = cmpxchg.(i32, i1) %0, %1, %2, align 4, seq_cst"), "{text}");
3977        assert!(text.contains("return %3"), "the value it found: {text}");
3978
3979        let text =
3980            body("int f(int *p, int e, int d) { return __sync_bool_compare_and_swap(p, e, d); }\n");
3981        assert!(text.contains("%3, %4 = cmpxchg.(i32, i1) %0, %1, %2, align 4, seq_cst"), "{text}");
3982        assert!(text.contains("zext.i32 %4"), "whether it happened: {text}");
3983
3984        // The C11 form, whose value expected arrives by pointer and is read before the exchange,
3985        // and whose answer is whether it happened. The write back is on the path where it did not.
3986        let text = body(
3987            "int f(int *p, int *e, int d) { return __atomic_compare_exchange_n(p, e, d, 0, 4, 2); }\n",
3988        );
3989        assert!(text.contains("%3 = load.i32 %1, align 4"), "{text}");
3990        assert!(text.contains("%4, %5 = cmpxchg.(i32, i1) %0, %3, %2, align 4, acq_rel"), "{text}");
3991        assert!(text.contains("br_if %5, block2, block1"), "{text}");
3992        assert!(text.contains("store %4 -> %1, align 4"), "{text}");
3993
3994        // And the form that takes the value to put there by pointer as well, which is one more
3995        // read and is otherwise the same node.
3996        let text = body(
3997            "int f(int *p, int *e, int *d) { return __atomic_compare_exchange(p, e, d, 0, 5, 5); }\n",
3998        );
3999        assert!(text.contains("%3 = load.i32 %1, align 4"), "{text}");
4000        assert!(text.contains("%4 = load.i32 %2, align 4"), "{text}");
4001        assert!(text.contains("%5, %6 = cmpxchg.(i32, i1) %0, %3, %4, align 4, seq_cst"), "{text}");
4002    }
4003
4004    /// On this machine it is `lock cmpxchg`, at the width of the object and at every ordering.
4005    ///
4006    /// The `lock` is what makes the whole of it one step as far as every other processor is
4007    /// concerned, and it is also what makes the instruction a full barrier, which is why the
4008    /// ordering the program wrote changes nothing in what is written here. Every line below is what
4009    /// gcc 16.2.0 writes for the same function.
4010    #[test]
4011    fn a_compare_and_exchange_is_a_locked_instruction_at_the_width_of_the_object() {
4012        let widths = [("char", "b", "%dl"), ("short", "w", "%dx"), ("int", "l", "%edx")];
4013        for (ty, suffix, reg) in widths {
4014            let source = format!(
4015                "int f({ty} *p, {ty} e, {ty} d) {{ return __sync_bool_compare_and_swap(p, e, d); }}\n"
4016            );
4017            let text = asm(&source);
4018            assert!(text.contains("\tlock\n"), "{ty}: {text}");
4019            assert!(text.contains(&format!("cmpxchg{suffix}\t{reg}, (%rdi)")), "{ty}: {text}");
4020            assert!(text.contains("sete\t"), "{ty}: {text}");
4021        }
4022        let source =
4023            "int f(long *p, long e, long d) { return __sync_bool_compare_and_swap(p, e, d); }\n";
4024        assert!(asm(source).contains("cmpxchgq\t%rdx, (%rdi)"), "{}", asm(source));
4025
4026        // The ordering the program asked for changes nothing, because a locked instruction on this
4027        // machine orders everything whatever it was asked for, so there is never a barrier beside
4028        // it either.
4029        for order in ["0", "2", "3", "4", "5"] {
4030            let call = format!("__atomic_compare_exchange_n(p, e, d, 0, {order}, 0)");
4031            let source = format!("int f(int *p, int *e, int d) {{ return {call}; }}\n");
4032            let text = asm(&source);
4033            assert!(text.contains("cmpxchgl\t"), "{order}: {text}");
4034            assert!(!text.contains("mfence"), "{order} needs no barrier here: {text}");
4035        }
4036    }
4037
4038    /// A read modify write is one IR instruction, and a name that asks for the value afterwards is
4039    /// that instruction and one more operation.
4040    ///
4041    /// The instruction answers what was there before, which is the convention every machine and
4042    /// every language in this area uses. Half the names in the family ask for the value afterwards
4043    /// instead, and that is the answer and the operand put together again, which is arithmetic on
4044    /// two values already in registers rather than a second flavour of the instruction.
4045    ///
4046    /// The two lock names are here too. They are not read modify writes in the same sense: one is
4047    /// an exchange and the other is a store of a zero, and what makes them a pair is the ordering,
4048    /// which is the one place in the older family that is not sequential consistency.
4049    #[test]
4050    fn a_read_modify_write_is_one_instruction_and_the_arithmetic_a_name_asks_for() {
4051        let text = body("int f(int *p, int v) { return __atomic_fetch_add(p, v, 5); }\n");
4052        assert!(text.contains("%2 = atomic_rmw.i32 add %0, %1, align 4, seq_cst"), "{text}");
4053        assert!(text.contains("return %2"), "the value that was there: {text}");
4054
4055        let text = body("int f(int *p, int v) { return __atomic_add_fetch(p, v, 5); }\n");
4056        assert!(text.contains("%2 = atomic_rmw.i32 add %0, %1, align 4, seq_cst"), "{text}");
4057        assert!(text.contains("%3 = add %2, %1"), "and the value afterwards: {text}");
4058
4059        let text = body("int f(int *p, int v) { return __atomic_sub_fetch(p, v, 5); }\n");
4060        assert!(text.contains("%2 = atomic_rmw.i32 sub %0, %1, align 4, seq_cst"), "{text}");
4061        assert!(text.contains("%3 = sub %2, %1"), "{text}");
4062
4063        // The older family, which passes no ordering and is a full barrier.
4064        let text = body("int f(int *p, int v) { return __sync_fetch_and_sub(p, v); }\n");
4065        assert!(text.contains("%2 = atomic_rmw.i32 sub %0, %1, align 4, seq_cst"), "{text}");
4066
4067        // The exchange, and the older family's spelling of it, which is taking a lock and so is an
4068        // acquire rather than the full barrier the rest of that family is.
4069        let text = body("int f(int *p, int v) { return __atomic_exchange_n(p, v, 5); }\n");
4070        assert!(text.contains("%2 = atomic_rmw.i32 xchg %0, %1, align 4, seq_cst"), "{text}");
4071
4072        let text = body("int f(int *p, int v) { return __sync_lock_test_and_set(p, v); }\n");
4073        assert!(text.contains("%2 = atomic_rmw.i32 xchg %0, %1, align 4, acquire"), "{text}");
4074
4075        // Giving the lock back, which is one of the two names in the family that is handed no value
4076        // to put there, because what it puts there is a zero.
4077        let text = body("void f(int *p) { __sync_lock_release(p); }\n");
4078        assert!(text.contains("release"), "{text}");
4079        assert!(text.contains("%1 = iconst.i32 0"), "{text}");
4080
4081        // And with something after the pointer, which is the list of variables the call promises to
4082        // protect rather than a value to write. Reading it as a value would store whatever the
4083        // caller happened to name there, which is the one thing giving a lock back must not do.
4084        let text = body("void f(int *p, int guard) { __sync_lock_release(p, guard); }\n");
4085        assert!(text.contains("%2 = iconst.i32 0"), "{text}");
4086        assert!(text.contains("atomic_store %2 -> %0, align 4, release"), "{text}");
4087
4088        // The bitwise four, which look no different here from the arithmetic ones: what the machine
4089        // has an instruction for is a question further down and this level does not ask it.
4090        let text = body("int f(int *p, int v) { return __atomic_fetch_and(p, v, 5); }\n");
4091        assert!(text.contains("%2 = atomic_rmw.i32 and %0, %1, align 4, seq_cst"), "{text}");
4092
4093        let text = body("int f(int *p, int v) { return __sync_or_and_fetch(p, v); }\n");
4094        assert!(text.contains("%2 = atomic_rmw.i32 or %0, %1, align 4, seq_cst"), "{text}");
4095        assert!(text.contains("%3 = or %2, %1"), "and the value afterwards: {text}");
4096
4097        // The nand, which is the one of the six that is two operations. The flip is an exclusive or
4098        // against every bit set because the IR has no not and that is what one is.
4099        let text = body("int f(int *p, int v) { return __atomic_nand_fetch(p, v, 5); }\n");
4100        assert!(text.contains("%2 = atomic_rmw.i32 nand %0, %1, align 4, seq_cst"), "{text}");
4101        assert!(text.contains("%3 = and %2, %1"), "{text}");
4102        assert!(text.contains("%4 = iconst.i32 -1"), "{text}");
4103        assert!(text.contains("%5 = xor %3, %4"), "{text}");
4104    }
4105
4106    /// The four operations with no instruction on this machine are a loop around `lock cmpxchg`.
4107    ///
4108    /// The shape is the one every architecture manual writes out by hand: read the word, work out
4109    /// what should be there instead, put it back if nothing else got in first, and go round again
4110    /// when something did. What is checked is that the loop is there at every width, that the
4111    /// operation is inside it, and that no `xchg` or `xadd` got used for something neither of them
4112    /// does.
4113    ///
4114    /// gcc 16.2.0 writes the same loop for the same functions, down to which register holds the
4115    /// value that was read.
4116    #[test]
4117    fn a_bitwise_read_modify_write_is_a_loop_around_the_compare_and_exchange() {
4118        let widths = [("char", "b", "%dl"), ("short", "w", "%dx"), ("int", "l", "%edx")];
4119        for (ty, suffix, reg) in widths {
4120            for (name, call, insn) in [
4121                ("and", "__atomic_fetch_and(p, v, 5)", "and"),
4122                ("or", "__sync_fetch_and_or(p, v)", "or"),
4123                ("xor", "__atomic_xor_fetch(p, v, 5)", "xor"),
4124            ] {
4125                let source = format!("{ty} f({ty} *p, {ty} v) {{ return {call}; }}\n");
4126                let text = asm(&source);
4127                assert!(text.contains("\tlock\n"), "{ty} {name}: {text}");
4128                assert!(
4129                    text.contains(&format!("cmpxchg{suffix}\t{reg}, (%rdi)")),
4130                    "{ty} {name}: {text}"
4131                );
4132                assert!(text.contains(&format!("{insn}{suffix}\t")), "{ty} {name}: {text}");
4133                // The tab matters on the second of these, since `cmpxchg` ends in the other name.
4134                assert!(!text.contains("\txadd"), "{ty} {name} is not an add: {text}");
4135                assert!(!text.contains("\txchg"), "{ty} {name} is not an exchange: {text}");
4136            }
4137        }
4138        let source = "long f(long *p, long v) { return __atomic_fetch_or(p, v, 5); }\n";
4139        assert!(asm(source).contains("cmpxchgq\t%rdx, (%rdi)"), "{}", asm(source));
4140
4141        // The nand, which puts two instructions inside the loop rather than one. The flip is an
4142        // exclusive or against every bit set in the IR and the folder turns that into the `not` the
4143        // machine has, which is what gcc writes here too.
4144        let text = asm("int f(int *p, int v) { return __sync_fetch_and_nand(p, v); }\n");
4145        assert!(text.contains("cmpxchgl\t"), "{text}");
4146        assert!(text.contains("andl\t"), "{text}");
4147        assert!(text.contains("notl\t"), "{text}");
4148    }
4149
4150    /// The three names that pass a value through a pointer are the same access and one plain one.
4151    ///
4152    /// They exist for an object too big to come back in a register, and the front end takes them at
4153    /// their word rather than folding them into the `_n` spellings, because the extra access is real:
4154    /// the caller handed over somewhere to read from or write into and that is where the value has
4155    /// to come from or go. Both of those accesses are plain. The object at the end of the caller's
4156    /// pointer is the caller's own and no other thread has its address, which is what the whole
4157    /// shape is for.
4158    #[test]
4159    fn an_access_through_a_second_pointer_is_the_same_access_and_one_more() {
4160        let text = body("void f(int *p, int *r) { __atomic_load(p, r, 5); }\n");
4161        assert!(text.contains("%2 = atomic_load.i32 %0, align 4, seq_cst"), "{text}");
4162        assert!(text.contains("store %2 -> %1, align 4"), "and out through the place: {text}");
4163
4164        let text = body("void f(int *p, int *v) { __atomic_store(p, v, 3); }\n");
4165        assert!(text.contains("%2 = load.i32 %1, align 4"), "in through the place: {text}");
4166        assert!(text.contains("atomic_store %2 -> %0, align 4, release"), "{text}");
4167
4168        // The exchange, which reads through one pointer and writes through another and is the same
4169        // instruction in between as the spelling that takes and answers values.
4170        let text = body("void f(int *p, int *v, int *r) { __atomic_exchange(p, v, r, 5); }\n");
4171        assert!(text.contains("%3 = load.i32 %1, align 4"), "{text}");
4172        assert!(text.contains("%4 = atomic_rmw.i32 xchg %0, %3, align 4, seq_cst"), "{text}");
4173        assert!(text.contains("store %4 -> %2, align 4"), "{text}");
4174    }
4175
4176    /// The flag pair is an exchange of one byte and a store of a zero over the same byte.
4177    ///
4178    /// One byte whatever the pointer was written as, which is the standard's reading rather than a
4179    /// liberty: the object is an `atomic_flag`, there is no other way to read or write one, so the
4180    /// type the pointer carries says nothing about the access and the width is the implementation's
4181    /// to fix. gcc 16.2.0 writes `xchgb` here through an `int *` too.
4182    ///
4183    /// The answer is a comparison against zero rather than the byte itself, because the type of the
4184    /// call is `_Bool` and a byte that is neither zero nor one is not one. gcc answers the raw byte,
4185    /// and the two agree wherever the flag is only ever touched through this pair.
4186    #[test]
4187    fn a_flag_is_an_exchange_of_one_byte_and_a_store_of_a_zero_over_the_same_byte() {
4188        for pointer in ["char", "int", "void"] {
4189            let source = format!("int f({pointer} *p) {{ return __atomic_test_and_set(p, 5); }}\n");
4190            let text = body(&source);
4191            assert!(text.contains("%1 = iconst.i8 1"), "{pointer}: {text}");
4192            assert!(
4193                text.contains("%2 = atomic_rmw.i8 xchg %0, %1, align 1, seq_cst"),
4194                "{pointer}: {text}"
4195            );
4196            assert!(text.contains("%4 = icmp ne %2, %3"), "{pointer}: {text}");
4197
4198            let source = format!("void f({pointer} *p) {{ __atomic_clear(p, 3); }}\n");
4199            let text = body(&source);
4200            assert!(text.contains("atomic_store %2 -> %0, align 1, release"), "{pointer}: {text}");
4201        }
4202
4203        // And on this machine, where the exchange carries no `lock` because one with memory locks
4204        // the bus whether it was asked to or not. Both lines are what gcc 16.2.0 writes.
4205        let text = asm("int f(int *p) { return __atomic_test_and_set(p, 5); }\n");
4206        assert!(text.contains("xchgb\t%al, (%rdi)"), "{text}");
4207        assert!(text.contains("setne\t"), "{text}");
4208    }
4209
4210    /// On this machine it is `xchg` where the machine has an exchange and `lock xadd` where it has
4211    /// an add, at the width of the object.
4212    ///
4213    /// The exchange carries no prefix and the add carries one, which is the machine rather than an
4214    /// oversight: an exchange with memory locks the bus whether it is asked to or not. Both are
4215    /// therefore full barriers whatever ordering the program wrote, so no ordering costs an
4216    /// `mfence` beside them. Every line below is what gcc 16.2.0 writes for the same function.
4217    #[test]
4218    fn a_read_modify_write_is_an_exchange_or_a_locked_add_at_the_width_of_the_object() {
4219        let widths = [("char", "b", "%sil"), ("short", "w", "%si"), ("int", "l", "%esi")];
4220        for (ty, suffix, reg) in widths {
4221            let source =
4222                format!("{ty} f({ty} *p, {ty} v) {{ return __atomic_fetch_add(p, v, 5); }}\n");
4223            let text = asm(&source);
4224            assert!(text.contains("\tlock\n"), "{ty}: {text}");
4225            assert!(text.contains(&format!("xadd{suffix}\t{reg}, (%rdi)")), "{ty}: {text}");
4226
4227            let source =
4228                format!("{ty} f({ty} *p, {ty} v) {{ return __atomic_exchange_n(p, v, 5); }}\n");
4229            let text = asm(&source);
4230            assert!(text.contains(&format!("xchg{suffix}\t{reg}, (%rdi)")), "{ty}: {text}");
4231            assert!(!text.contains("\tlock\n"), "an exchange is locked already: {ty}: {text}");
4232        }
4233        let source = "long f(long *p, long v) { return __atomic_fetch_add(p, v, 5); }\n";
4234        assert!(asm(source).contains("xaddq\t%rsi, (%rdi)"), "{}", asm(source));
4235
4236        // A subtraction is the same instruction over the negated operand, which is right at every
4237        // width because the machine's arithmetic wraps.
4238        let source = "int f(int *p, int v) { return __atomic_fetch_sub(p, v, 5); }\n";
4239        let text = asm(source);
4240        assert!(text.contains("negl\t"), "{text}");
4241        assert!(text.contains("xaddl\t"), "{text}");
4242
4243        // The ordering changes nothing, for the reason it changes nothing for a compare and
4244        // exchange: a locked instruction on this machine orders everything whatever it was asked.
4245        for order in ["0", "2", "3", "4", "5"] {
4246            let source =
4247                format!("int f(int *p, int v) {{ return __atomic_fetch_add(p, v, {order}); }}\n");
4248            let text = asm(&source);
4249            assert!(text.contains("xaddl\t"), "{order}: {text}");
4250            assert!(!text.contains("mfence"), "{order} needs no barrier here: {text}");
4251        }
4252
4253        // And the lock pair, which is the exchange and a store of a zero. Neither is a barrier
4254        // instruction: the exchange is one already and the store is a release, which this machine
4255        // gives away.
4256        let text = asm("int f(int *p, int v) { return __sync_lock_test_and_set(p, v); }\n");
4257        assert!(text.contains("xchgl\t%esi, (%rdi)"), "{text}");
4258        // The zero goes through a register on the way, which is where every constant this
4259        // compiler stores goes: gcc writes the one instruction because it has a store that takes an
4260        // immediate and no rule here does. That is a rule this rule set is missing rather than
4261        // anything about the builtin, and it is the same two instructions a plain `*p = 0` makes.
4262        let text = asm("void f(int *p) { __sync_lock_release(p); }\n");
4263        assert!(text.contains("movl\t$0, %eax"), "{text}");
4264        assert!(text.contains("movl\t%eax, (%rdi)"), "{text}");
4265        assert!(!text.contains("mfence"), "a release store needs no barrier here: {text}");
4266    }
4267
4268    /// The two lock free questions are numbers in the program rather than calls to anything.
4269    ///
4270    /// Both answer from the size, which has to be a power of two no wider than the widest access
4271    /// this compiler writes, and from what the pointer says about the alignment. Sixteen bytes is
4272    /// no here and is no in gcc without `-mcx16`, because `cmpxchg16b` is not in the baseline and
4273    /// nothing here writes it. Three bytes is no because there is no three byte access at all.
4274    ///
4275    /// The whole point of both names is that the answer is available before the program runs, so
4276    /// what is checked is that a `mov` of a constant is the whole function and that no call was
4277    /// left behind. A call would be to `__atomic_is_lock_free` in libatomic, which is not a library
4278    /// this links against.
4279    #[test]
4280    fn the_lock_free_questions_are_answered_as_constants() {
4281        for size in ["1", "2", "4", "8"] {
4282            let source =
4283                format!("int f(void) {{ return __atomic_always_lock_free({size}, 0); }}\n");
4284            let text = asm(&source);
4285            assert!(text.contains("movb\t$1, %al"), "{size} bytes is lock free: {text}");
4286            assert!(!text.contains("call"), "and is not a call: {text}");
4287        }
4288        for size in ["3", "16", "sizeof(long double)"] {
4289            let source = format!("int f(void) {{ return __atomic_is_lock_free({size}, 0); }}\n");
4290            let text = asm(&source);
4291            assert!(text.contains("movb\t$0, %al"), "{size} bytes is not: {text}");
4292            assert!(!text.contains("call"), "and is not a call either: {text}");
4293        }
4294
4295        // A size the compiler cannot work out, which is no rather than a refusal, and an object
4296        // whose type is aligned under the size asked about, which is the whole of what the second
4297        // argument is for.
4298        let text = asm("int f(int n) { return __atomic_is_lock_free(n, 0); }\n");
4299        assert!(text.contains("movb\t$0, %al"), "a size nobody knows is not lock free: {text}");
4300        let text = asm("int f(int *p) { return __atomic_always_lock_free(8, p); }\n");
4301        assert!(text.contains("movb\t$0, %al"), "eight bytes at four is not: {text}");
4302        let text = asm("int f(long *p) { return __atomic_always_lock_free(8, p); }\n");
4303        assert!(text.contains("movb\t$1, %al"), "and at eight it is: {text}");
4304    }
4305
4306    /// A memory order an operation cannot carry is read as the strongest one, and said so about.
4307    ///
4308    /// There are three ways the number is not one the operation can take: it is not a constant at
4309    /// all, it is not one of the six the headers define, or it is one of them and means nothing for
4310    /// this operation, which is a release load or an acquire store. All three become sequential
4311    /// consistency, which is stronger than anything the program could have meant, so a program that
4312    /// wrote nonsense gets a correct answer rather than a fast one. gcc does the same.
4313    ///
4314    /// The last two also warn, because the number was written down and is wrong. The first does
4315    /// not: gcc takes a computed order, and so does the C11 spelling, so a warning there would fire
4316    /// on correct programs.
4317    #[test]
4318    fn a_memory_order_an_operation_cannot_carry_is_read_as_the_strongest() {
4319        let mut opts = options();
4320        opts.emit = EmitKind::Ir;
4321
4322        let acquire_store = run(&opts, "void f(int *p, int v) { __atomic_store_n(p, v, 2); }\n");
4323        assert!(acquire_store.text().contains("seq_cst"), "{:?}", acquire_store.text());
4324        assert!(acquire_store.messages[0].contains("[W0333]"), "{:?}", acquire_store.messages);
4325
4326        let nonsense = run(&opts, "int f(int *p) { return __atomic_load_n(p, 99); }\n");
4327        assert!(nonsense.text().contains("seq_cst"), "{:?}", nonsense.text());
4328        assert!(nonsense.messages[0].contains("[W0333]"), "{:?}", nonsense.messages);
4329
4330        let computed = run(&opts, "int f(int *p, int n) { return __atomic_load_n(p, n); }\n");
4331        assert!(computed.text().contains("seq_cst"), "{:?}", computed.text());
4332        assert_eq!(computed.messages, Vec::<String>::new(), "a computed order is not a mistake");
4333    }
4334
4335    /// A conversion between a float and the widest unsigned integer, which the machine has not got.
4336    ///
4337    /// Every other conversion between a float and an integer is the signed one at some width with a
4338    /// widening in front or a narrowing behind. These two are not, because there is no signed width
4339    /// that holds every value of an unsigned sixty four bit integer, so each is the signed
4340    /// conversion with arithmetic around it that brings the value into range and puts it back.
4341    ///
4342    /// What is checked here is that the conversion happens at all and that it happens without a
4343    /// branch. gcc writes a branch for both; this writes the choice as a mask, because every rewrite
4344    /// in that pass stays inside the block it started in. The arithmetic itself is checked in
4345    /// `rucc-codegen`, where it can be run against the answer rather than read in the assembly.
4346    #[test]
4347    fn a_conversion_between_a_float_and_the_widest_unsigned_integer_is_written_without_a_branch() {
4348        let text = asm("double f(unsigned long long x) { return (double)x; }\n");
4349        assert!(text.contains("cvtsi2sdq"), "the signed conversion is what runs: {text}");
4350        assert!(text.contains("shrq"), "with the value halved first: {text}");
4351        assert!(text.contains("addsd"), "and doubled after: {text}");
4352        assert!(!text.contains("\tj"), "and no branch anywhere: {text}");
4353
4354        let text = asm("unsigned long long f(double d) { return (unsigned long long)d; }\n");
4355        assert!(text.contains("cvttsd2siq"), "the signed conversion is what runs: {text}");
4356        assert!(text.contains("subsd"), "with half the range taken off first: {text}");
4357        assert!(text.contains("shlq\t$63"), "and the top bit put back: {text}");
4358        assert!(!text.contains("\tj"), "and no branch anywhere: {text}");
4359    }
4360
4361    /// The plain names are the library's only where nothing else has taken them.
4362    ///
4363    /// Four ways a program says it means something else. A `static` definition is its own
4364    /// function and the name outside the file is somebody else's. A declaration of another type
4365    /// is another function. `-fno-builtin` and `-fno-builtin-<name>` say so outright, and
4366    /// `-ffreestanding` says there is no C library for the name to be the name of. Every one of
4367    /// these was measured against gcc 16.2.0, which calls the program's function in all of them.
4368    ///
4369    /// The `__builtin_` spelling goes on meaning the library's function through all of it, which
4370    /// is what the prefix is for and what lets a freestanding build reach one deliberately.
4371    #[test]
4372    fn a_plain_name_the_program_took_is_the_programs_own_function() {
4373        let taken = concat!(
4374            "static long long llabs(long long b) { return 7; }\n",
4375            "long long f(long long x) { return llabs(x); }\n",
4376        );
4377        assert!(ir(taken).contains("call @llabs"), "a static definition is the program's own");
4378
4379        let retyped = concat!("int llabs(int b);\n", "int f(int x) { return llabs(x); }\n",);
4380        assert!(ir(retyped).contains("call @llabs"), "another type is another function");
4381
4382        let plain = concat!(
4383            "long long llabs(long long b);\n",
4384            "long long f(long long x) { return llabs(x); }\n",
4385        );
4386        let mut opts = options();
4387        opts.emit = EmitKind::Ir;
4388        assert!(!run(&opts, plain).text().contains("call @llabs"), "the library's by default");
4389
4390        opts.builtins = false;
4391        assert!(run(&opts, plain).text().contains("call @llabs"), "-fno-builtin");
4392
4393        opts.builtins = true;
4394        opts.no_builtin = vec!["llabs".to_owned()];
4395        assert!(run(&opts, plain).text().contains("call @llabs"), "-fno-builtin-llabs");
4396        let one = "long labs(long b);\nlong f(long x) { return labs(x); }\n";
4397        assert!(!run(&opts, one).text().contains("call @labs"), "one name and not the family");
4398
4399        // `-ffreestanding` reaches the front end as the same answer, which is what the driver
4400        // does with it in `compile`, and the prefixed spelling is untouched by any of it.
4401        opts.no_builtin = Vec::new();
4402        opts.builtins = false;
4403        let prefixed = "long long f(long long x) { return __builtin_llabs(x); }\n";
4404        assert!(!run(&opts, prefixed).text().contains("call @llabs"), "the prefix is a promise");
4405    }
4406
4407    /// The hint builtins are their first argument, and nothing is left of the hint.
4408    ///
4409    /// Which way a branch is expected to go is the whole of what they say, and there is nothing
4410    /// here that reads a branch weight yet, so what reaches the IR is the value and the hint is
4411    /// gone. The one thing the prototype has to keep doing is converting: gcc gives both of them
4412    /// a `long` result, so `sizeof(__builtin_expect((char)1, 1))` is eight and a narrower argument
4413    /// widens before it is answered with.
4414    ///
4415    /// Whether a side effect in the hint happens depends on the first argument, which is gcc's
4416    /// answer rather than a rule anybody designed. A constant first argument folds the whole call
4417    /// where it is written and the hint goes with it, and a first argument that is not a constant
4418    /// leaves the hint standing. Both halves are below and both were measured on gcc 16.2.0.
4419    #[test]
4420    fn the_hint_builtins_are_their_first_argument_and_the_hint_leaves_no_trace() {
4421        let text = ir(concat!(
4422            "long a = __builtin_expect(7, 1);\n",
4423            "long b = __builtin_expect_with_probability(9, 1, 0.9);\n",
4424            "unsigned long c = sizeof(__builtin_expect((char)1, 1));\n",
4425        ));
4426        assert!(text.contains("global @a : i64 = 7,"), "{text}");
4427        assert!(text.contains("global @b : i64 = 9,"), "{text}");
4428        assert!(text.contains("global @c : i64 = 8,"), "{text}");
4429        assert!(!text.contains("__builtin_expect"), "it is not a call to anything:\n{text}");
4430
4431        // A narrower argument is widened by the prototype before it is handed back, and it is
4432        // widened with its sign, since the parameter is a signed `long`.
4433        let text = body("long f(char c) { return __builtin_expect(c, 1); }\n");
4434        assert!(text.contains("sext"), "{text}");
4435
4436        // The first argument is a constant, so the second is not evaluated and `i` is still zero,
4437        // and neither is the third. What is left of each statement is the first argument widened,
4438        // which nothing reads and which the first pass that looks for dead code will take out.
4439        let one = "block0:\n    %0 = iconst.i32 0\n    %1 = iconst.i32 1\n    %2 = sext.i64 %1\n    return %0\n";
4440        assert_eq!(body("int f(void) { int i = 0; __builtin_expect(1, i++); return i; }\n"), one);
4441        let source = "int g(void) { int i = 0; __builtin_expect_with_probability(1, i++, 0.5); return i; }\n";
4442        assert_eq!(body(source), one);
4443
4444        // The first argument is not a constant, so the hint runs and `i` comes back one. There is
4445        // an increment in the body and the value it returns is the load after it, which is what
4446        // gcc gives for the same program, and the whole of tamnd/rucc#584 is that this used to
4447        // come out the same as the pair above.
4448        let kept = body("int f(int n) { int i = 0; __builtin_expect(n, i++); return i; }\n");
4449        assert!(kept.contains("add.nsw"), "the hint still runs: {kept}");
4450        assert!(kept.ends_with("return %3\n"), "and the answer is what it left behind: {kept}");
4451        let both = "int g(int n) { int i = 0; __builtin_expect_with_probability(n, i++, 0.5); return i; }\n";
4452        assert!(body(both).contains("add.nsw"), "and so does the one with three arguments");
4453    }
4454
4455    /// A point control does not arrive at, in both of the ways the compiler has one.
4456    ///
4457    /// `__builtin_unreachable()` is the promise written down, and a function whose body can run
4458    /// off the bottom is the walk arriving at the same place on its own. Neither writes an
4459    /// instruction, which is what gcc 16.2.0 does at `-O0`: it emits the epilogue and the `ret`
4460    /// for both of the functions below and nothing else, and the two of them come out byte for
4461    /// byte the same there.
4462    ///
4463    /// The `ret` is the part worth holding on to. It is not there because anything runs it, it is
4464    /// there because a function whose last instruction is not a return is one that falls into
4465    /// whatever the assembler puts after it.
4466    #[test]
4467    fn a_promise_that_control_does_not_arrive_writes_no_instruction() {
4468        let promised = "int f(int x) { if (x) return 1; __builtin_unreachable(); }\n";
4469        let text = ir(promised);
4470        assert!(text.contains("    unreachable_hint\n"), "{text}");
4471        assert!(!text.contains("call"), "it is not a call to anything:\n{text}");
4472
4473        // The statement after it is still lowered. Continuing to translate a path the program
4474        // promised is dead is one of the things a compiler may do with undefined behaviour, and
4475        // it is the one that keeps a program built at `-O0` behaving the way it was watched to.
4476        let after = body("int g(int x) { __builtin_unreachable(); return x; }\n");
4477        assert!(after.contains("return"), "{after}");
4478
4479        // Both functions are the same instructions, because the hint writes none of them and the
4480        // terminator underneath it writes none either.
4481        let text = asm(promised);
4482        let mine = text.split_once("\nf:\n").expect("a definition").1;
4483        let mine = mine.split_once("\t.size").expect("a definition").0;
4484        let plain = asm("int f(int x) { if (x) return 1; }\n");
4485        let plain = plain.split_once("\nf:\n").expect("a definition").1;
4486        let plain = plain.split_once("\t.size").expect("a definition").0;
4487        assert_eq!(mine, plain);
4488        // The last instruction, rather than the last line, because the unwind record is closed
4489        // after it and a directive is not something the machine runs.
4490        let last = mine.lines().rfind(|line| !line.trim_start().starts_with('.'));
4491        assert_eq!(last.map(str::trim), Some("ret"), "{mine}");
4492        assert!(!mine.contains("ud2"), "{mine}");
4493    }
4494
4495    /// The two names stay apart, which is what having both of them is for.
4496    ///
4497    /// The one the program wrote is what the call is checked against and what a diagnostic about
4498    /// it says, and the one the library defines is what the call ends up carrying. A compiler
4499    /// that kept only the second would report this against `abort`, which is a function the
4500    /// program never mentions.
4501    #[test]
4502    fn a_library_builtin_is_diagnosed_under_the_name_the_program_wrote() {
4503        let mut opts = options();
4504        opts.emit = EmitKind::Ir;
4505        let messages = run(&opts, "void f(void) { __builtin_abort(1); }\n").messages;
4506        assert!(
4507            messages.iter().any(|m| m.contains("__builtin_abort")),
4508            "expected the written name in {messages:?}"
4509        );
4510    }
4511
4512    /// A builtin nothing lowers is refused where it is written, rather than at the link.
4513    ///
4514    /// The names are two with a prototype and one whose type comes from the call it was written in,
4515    /// which is also the one whose prefix is not `__builtin_`. The two with a prototype are what is
4516    /// left of the builtins that have one, and the third is the last of the atomic family that is
4517    /// refused, whose older half has nothing left in it at all. What the
4518    /// message has to carry is the name, because the whole complaint about the link error this
4519    /// replaces is that the name in it was one the compiler chose.
4520    #[test]
4521    fn a_builtin_nothing_lowers_is_refused_by_name() {
4522        let mut opts = options();
4523        opts.emit = EmitKind::Ir;
4524        for (builtin, call) in [
4525            ("__builtin_object_size", "(int)__builtin_object_size(&counter, 0)"),
4526            ("__builtin_dynamic_object_size", "(int)__builtin_dynamic_object_size(&counter, 0)"),
4527            ("__atomic_signal_fence", "(__atomic_signal_fence(5), 0)"),
4528        ] {
4529            let source = format!("int counter;\nint f(void) {{ return {call}; }}\n");
4530            let messages = run(&opts, &source).messages;
4531            let named = messages.iter().any(|m| m.contains(builtin) && m.contains("E0686"));
4532            assert!(named, "expected {builtin} to be refused by name in {messages:?}");
4533        }
4534    }
4535
4536    /// The refusal is about a call and not about the name, so the rest of what C does with one
4537    /// still works.
4538    ///
4539    /// `sizeof` does not evaluate its operand, so nothing is called and there is nothing to
4540    /// refuse; the type of the call is what it asks for and that comes from the front end. A
4541    /// program that defines the name itself gets the function it wrote, which is not what this
4542    /// is for but is what a definition in front of us means.
4543    #[test]
4544    fn what_is_refused_is_the_call_and_not_the_name() {
4545        let text = ir("unsigned long n = sizeof(__builtin_object_size(0, 0));\n");
4546        assert!(text.contains("global @n : i64 = 8,"), "{text}");
4547
4548        let text = ir(concat!(
4549            "unsigned long __builtin_object_size(const void *p, int kind) { return 0; }\n",
4550            "unsigned long f(void) { return __builtin_object_size(0, 0); }\n",
4551        ));
4552        assert!(text.contains("call @__builtin_object_size"), "{text}");
4553    }
4554
4555    /// A `static` function nothing refers to is not emitted, and one that is refered to is.
4556    ///
4557    /// The pair is written as one program so that the two answers come out of one walk. What
4558    /// makes the difference is the call in `main` and nothing else about either definition.
4559    #[test]
4560    fn a_static_function_nothing_refers_to_is_not_emitted() {
4561        let text = ir("static int dropped(void) { return 1; }\n\
4562                       static int kept(void) { return 2; }\n\
4563                       int main(void) { return kept(); }\n");
4564        assert!(text.contains("func @kept"), "{text}");
4565        assert!(!text.contains("dropped"), "{text}");
4566    }
4567
4568    /// The set is transitive, so two of them that only call each other are both dropped.
4569    ///
4570    /// Counting the references to a name would keep this pair, since each is named once, and
4571    /// that is the mistake this is here to catch: what decides it is whether a root reaches the
4572    /// definition, and a root is something the file has a reason to emit on its own.
4573    #[test]
4574    fn two_static_functions_that_only_call_each_other_are_both_dropped() {
4575        let text = ir("static int ping(void);\n\
4576                       static int pong(void) { return ping(); }\n\
4577                       static int ping(void) { return pong(); }\n\
4578                       int main(void) { return 0; }\n");
4579        assert!(!text.contains("ping"), "{text}");
4580        assert!(!text.contains("pong"), "{text}");
4581    }
4582
4583    /// Everything that names a function keeps it, whether or not the name is being called.
4584    ///
4585    /// An address taken in a body, an image that holds one, and a body that is only reached
4586    /// through another `static` function are three different ways for a definition to be needed
4587    /// and none of them is a call at the top level of a reachable function.
4588    #[test]
4589    fn naming_a_static_function_anywhere_keeps_it() {
4590        let text = ir("static int by_address(void) { return 1; }\n\
4591                       static int in_an_image(void) { return 2; }\n\
4592                       static int deeper(void) { return 3; }\n\
4593                       static int reaches_deeper(void) { return deeper(); }\n\
4594                       static int (*table[1])(void) = {in_an_image};\n\
4595                       int main(void) {\n\
4596                         int (*p)(void) = by_address;\n\
4597                         return p() + table[0]() + reaches_deeper();\n\
4598                       }\n");
4599        for kept in ["by_address", "in_an_image", "deeper", "reaches_deeper"] {
4600            assert!(text.contains(&format!("func @{kept}")), "expected {kept} in:\n{text}");
4601        }
4602    }
4603
4604    /// An attribute that says something outside the file reaches it keeps the definition.
4605    ///
4606    /// None of the five is implemented as anything else yet, and this is the part of each of
4607    /// them that a program notices first: a symbol a linker script names or a function the
4608    /// run-up to `main` calls is not written about anywhere a C file can see.
4609    #[test]
4610    fn an_attribute_keeps_a_static_function_nothing_refers_to() {
4611        for attribute in ["used", "retain", "constructor", "destructor", "__used__"] {
4612            let source = format!(
4613                "__attribute__(({attribute})) static int kept(void) {{ return 1; }}\n\
4614                 int main(void) {{ return 0; }}\n"
4615            );
4616            let text = ir(&source);
4617            assert!(text.contains("func @kept"), "for {attribute}:\n{text}");
4618        }
4619    }
4620
4621    /// A function with external linkage is emitted whatever this file does with it, because
4622    /// another one may call it, and that is what external linkage is.
4623    #[test]
4624    fn a_function_anything_could_call_is_emitted_without_being_called() {
4625        let text =
4626            ir("int nobody_here_calls_it(void) { return 1; }\nint main(void) { return 0; }\n");
4627        assert!(text.contains("func @nobody_here_calls_it"), "{text}");
4628    }
4629
4630    /// Four of the classification builtins are operators C already has, and become those.
4631    ///
4632    /// What the standard's macro promises over the operator is that it does not raise the
4633    /// invalid operation exception on a quiet NaN. This compiler does not model floating point
4634    /// exceptions, so there is nothing left for a node of its own to carry and a second way of
4635    /// spelling a comparison would be a second thing every pass has to know about.
4636    #[test]
4637    fn a_classification_c_has_an_operator_for_is_that_operator() {
4638        for (builtin, operator) in [
4639            ("__builtin_isgreater", "binary >"),
4640            ("__builtin_isgreaterequal", "binary >="),
4641            ("__builtin_isless", "binary <"),
4642            ("__builtin_islessequal", "binary <="),
4643        ] {
4644            let source = format!("int f(double x, double y) {{ return {builtin}(x, y); }}\n");
4645            let text = tast(&source);
4646            assert!(text.contains(&format!("{operator} : int")), "for {builtin}:\n{text}");
4647        }
4648    }
4649
4650    /// The rest of the family are comparisons in the IR and never a call to anything.
4651    ///
4652    /// `math.h` defines the macro of each of these names as the builtin of the same name, so
4653    /// there is no function under any of them for a call to reach. `isunordered` and
4654    /// `islessgreater` are predicates the IR's comparison already has, `isnan` is the value that
4655    /// is unordered with itself, and the two that ask about a magnitude are written against the
4656    /// infinities. `signbit` is the one that is not a question about the value, since a negative
4657    /// zero compares equal to a positive one, so its answer comes from the bits.
4658    #[test]
4659    fn the_classification_builtins_are_comparisons_and_not_calls() {
4660        let text = body("int f(double x, double y) { return __builtin_isunordered(x, y); }\n");
4661        assert_eq!(
4662            text,
4663            "block0(%0: f64, %1: f64):\n    %2 = fcmp uno %0, %1\n    %3 = zext.i32 \
4664                          %2\n    return %3\n"
4665        );
4666
4667        // Not `x != y`, which is true when the two are unordered and so is true of a NaN.
4668        let text = body("int f(double x, double y) { return __builtin_islessgreater(x, y); }\n");
4669        assert!(text.contains("fcmp one %0, %1"), "{text}");
4670
4671        let text = body("int f(double x) { return __builtin_isnan(x); }\n");
4672        assert!(text.contains("fcmp uno %0, %0"), "{text}");
4673
4674        let text = body("int f(double x) { return __builtin_isinf(x); }\n");
4675        assert!(text.contains("fconst.f64 0x7ff0000000000000"), "{text}");
4676        assert!(text.contains("fconst.f64 0xfff0000000000000"), "{text}");
4677        assert!(text.contains("%3 = fcmp oeq %0, %1"), "{text}");
4678        assert!(text.contains("%4 = fcmp oeq %0, %2"), "{text}");
4679        assert!(text.contains("%5 = or %3, %4"), "{text}");
4680
4681        // Strictly between the two infinities, which a NaN is not, because an ordered comparison
4682        // against either of them is false. That is what makes this one test rather than two.
4683        let text = body("int f(double x) { return __builtin_isfinite(x); }\n");
4684        assert!(text.contains("%3 = fcmp olt %2, %0"), "{text}");
4685        assert!(text.contains("%4 = fcmp olt %0, %1"), "{text}");
4686        assert!(text.contains("%5 = and %3, %4"), "{text}");
4687
4688        let text = body("int f(double x) { return __builtin_signbit(x); }\n");
4689        assert!(text.contains("%1 = bitcast.i64 %0"), "{text}");
4690        assert!(text.contains("icmp slt %1, %2"), "{text}");
4691
4692        // The same question of a value in the target's widest format, where the bits are eighty
4693        // and the object they sit in is sixteen bytes.
4694        let text = body("int f(long double x) { return __builtin_signbitl(x); }\n");
4695        assert!(text.contains("%1 = bitcast.i80 %0"), "{text}");
4696
4697        // The operand is evaluated once however many times it is compared, which is the whole
4698        // reason these are nodes rather than a rewriting into the operators.
4699        let text = body("double g(void);\nint f(void) { return __builtin_isnan(g()); }\n");
4700        assert_eq!(text.matches("call @g()").count(), 1, "{text}");
4701    }
4702
4703    /// A spelling that names a width converts its argument before it asks.
4704    ///
4705    /// gcc gives `__builtin_isinff` a `float` parameter and `__builtin_isinf` no parameter type
4706    /// at all, and the difference is visible rather than academic: `1e300` does not fit in a
4707    /// `float`, so converting it first is an infinity and not converting it is not. Both numbers
4708    /// here are what gcc 16 gives.
4709    #[test]
4710    fn a_classification_spelling_that_names_a_width_converts_before_it_asks() {
4711        let text = ir(concat!(
4712            "int a = __builtin_isinff(1e300);\n",
4713            "int b = __builtin_isinf(1e300);\n",
4714            // Folded here rather than compared at run time, because a question about a value has
4715            // an answer as soon as the value is a constant, and an initializer for an object
4716            // with static storage duration has to have one.
4717            "int c = __builtin_isnan(0.0);\n",
4718            "int d = __builtin_signbit(-0.0);\n",
4719            "int e = __builtin_islessgreater(1.0, 2.0);\n",
4720        ));
4721        assert!(text.contains("global @a : i32 = 1,"), "{text}");
4722        assert!(text.contains("global @b : i32 = 0,"), "{text}");
4723        assert!(text.contains("global @c : i32 = 0,"), "{text}");
4724        assert!(text.contains("global @d : i32 = 1,"), "{text}");
4725        assert!(text.contains("global @e : i32 = 1,"), "{text}");
4726    }
4727
4728    /// An argument that is not floating point is refused, in gcc's words.
4729    #[test]
4730    fn a_classification_builtin_refuses_an_argument_that_is_not_floating_point() {
4731        let mut opts = options();
4732        opts.emit = EmitKind::Ir;
4733        let source = concat!(
4734            "int a(int x) { return __builtin_isnan(x); }\n",
4735            "int b(int x, int y) { return __builtin_isunordered(x, y); }\n",
4736            "int c(double x) { return __builtin_isnan(x, x); }\n",
4737        );
4738        let messages = run(&opts, source).messages;
4739        assert_eq!(
4740            messages,
4741            [
4742                "/main.c:1:23: error: non-floating-point argument in call to function \
4743                 '__builtin_isnan' [E0685]",
4744                "/main.c:2:30: error: non-floating-point arguments in call to function \
4745                 '__builtin_isunordered' [E0685]",
4746                "/main.c:3:26: error: too many arguments to function '__builtin_isnan' [E0511]",
4747            ]
4748        );
4749    }
4750
4751    /// The three of the family that need a constant of the format other than an infinity.
4752    ///
4753    /// `isnormal` is the one that needs the smallest normal, and it is asked of the magnitude, so
4754    /// the sign comes off first and what is left is the same shape as `isfinite`. `isinf_sign` is
4755    /// the one whose answer is a number: the two comparisons `isinf` builds, subtracted rather
4756    /// than combined. `fpclassify` is four questions of one value and five answers to pick from,
4757    /// and the picking is a mask because all five are constants and neither of them can have an
4758    /// effect.
4759    #[test]
4760    fn the_last_three_classification_builtins_are_comparisons_and_not_calls() {
4761        let text = body("int f(double x) { return __builtin_isnormal(x); }\n");
4762        // The sign off, which is the magnitude, and then the range, asked of the bits rather than
4763        // of the number, since the encoding of a value whose sign bit is clear rises with the
4764        // value in every format this compiles for.
4765        assert!(text.contains("%1 = bitcast.i64 %0"), "{text}");
4766        assert!(text.contains("%2 = iconst.i64 9223372036854775807"), "{text}");
4767        assert!(text.contains("%3 = and %1, %2"), "{text}");
4768        assert!(text.contains("%4 = iconst.i64 4503599627370496"), "{text}");
4769        assert!(text.contains("%5 = iconst.i64 9218868437227405312"), "{text}");
4770        assert!(text.contains("%6 = icmp uge %3, %4"), "{text}");
4771        assert!(text.contains("%7 = icmp ult %3, %5"), "{text}");
4772        assert!(text.contains("%8 = and %6, %7"), "{text}");
4773
4774        // The same question in the target's widest format, where the smallest normal has the
4775        // leading significand bit stored rather than implied, so its encoding is two bits and not
4776        // one.
4777        let text = body("int f(long double x) { return __builtin_isnormal(x); }\n");
4778        assert!(text.contains("%4 = iconst.i80 27670116110564327424"), "{text}");
4779        assert!(text.contains("%5 = iconst.i80 604453686435277732577280"), "{text}");
4780
4781        let text = body("int f(double x) { return __builtin_isinf_sign(x); }\n");
4782        assert!(text.contains("%3 = fcmp oeq %0, %1"), "{text}");
4783        assert!(text.contains("%4 = fcmp oeq %0, %2"), "{text}");
4784        assert!(text.contains("%7 = sub %5, %6"), "{text}");
4785
4786        let text = body("int f(double x) { return __builtin_fpclassify(0, 1, 2, 3, 4, x); }\n");
4787        assert!(text.contains("fcmp uno %0, %0"), "{text}");
4788        assert!(text.contains("fcmp oeq %0, %6"), "{text}");
4789        // Four questions, each of them a bit widened into the type of the answer and then spread
4790        // into a mask that picks between the answer and whatever the questions after it settled
4791        // on. Nothing sign extends, because no rule lowers a sign extension out of one bit.
4792        assert_eq!(text.matches(" = zext.i32 ").count(), 4, "{text}");
4793        assert_eq!(text.matches(" = xor ").count(), 4, "{text}");
4794        assert!(!text.contains("call"), "{text}");
4795
4796        // The value is evaluated once however many questions are asked of it, which is the whole
4797        // reason `fpclassify` is a node rather than the chain of tests it turns into.
4798        let text = body(concat!(
4799            "double g(void);\n",
4800            "int f(void) { return __builtin_fpclassify(0, 1, 2, 3, 4, g()); }\n",
4801        ));
4802        assert_eq!(text.matches("call @g()").count(), 1, "{text}");
4803    }
4804
4805    /// Each of the three answers a constant where its operand is one.
4806    ///
4807    /// glibc's `fpclassify` macro is exactly this builtin, so a program that writes
4808    /// `fpclassify(0.0)` in a static initializer is writing this, and it has to have a value at
4809    /// translation time or the program is refused rather than merely compiled slowly. Every
4810    /// number here is what gcc 16 gives.
4811    #[test]
4812    fn the_last_three_classification_builtins_fold_where_their_operand_is_a_constant() {
4813        let text = ir(concat!(
4814            "int a = __builtin_isnormal(1.0);\n",
4815            "int b = __builtin_isnormal(0.0);\n",
4816            "int c = __builtin_isnormal(1.0 / 0.0);\n",
4817            "int d = __builtin_isinf_sign(-1.0 / 0.0);\n",
4818            "int e = __builtin_isinf_sign(1.0);\n",
4819            "int g = __builtin_fpclassify(0, 1, 2, 3, 4, 0.0);\n",
4820            "int h = __builtin_fpclassify(0, 1, 2, 3, 4, 1.0);\n",
4821            "int i = __builtin_fpclassify(0, 1, 2, 3, 4, 1.0 / 0.0);\n",
4822        ));
4823        assert!(text.contains("global @a : i32 = 1,"), "{text}");
4824        assert!(text.contains("global @b : i32 = 0,"), "{text}");
4825        assert!(text.contains("global @c : i32 = 0,"), "{text}");
4826        assert!(text.contains("global @d : i32 = -1,"), "{text}");
4827        assert!(text.contains("global @e : i32 = 0,"), "{text}");
4828        assert!(text.contains("global @g : i32 = 4,"), "{text}");
4829        assert!(text.contains("global @h : i32 = 2,"), "{text}");
4830        assert!(text.contains("global @i : i32 = 1,"), "{text}");
4831    }
4832
4833    /// `fpclassify` refuses what gcc refuses, in gcc's words.
4834    ///
4835    /// The five answers have to be integer constant expressions, because what the builtin does is
4836    /// pick one of them and a pick between values that are not known here would be a chain of
4837    /// conditionals over expressions the call has already evaluated.
4838    #[test]
4839    fn fpclassify_refuses_an_answer_that_is_not_an_integer_constant() {
4840        let mut opts = options();
4841        opts.emit = EmitKind::Ir;
4842        let source = concat!(
4843            "int a(double x, int n) { return __builtin_fpclassify(0, 1, n, 3, 4, x); }\n",
4844            "int b(double x) { return __builtin_fpclassify(0, 1, 2, 3, x); }\n",
4845            "int c(int x) { return __builtin_fpclassify(0, 1, 2, 3, 4, x); }\n",
4846        );
4847        let messages = run(&opts, source).messages;
4848        assert_eq!(
4849            messages,
4850            [
4851                "/main.c:1:60: error: non-const integer argument 3 in call to function \
4852                 '__builtin_fpclassify' [E0687]",
4853                "/main.c:2:26: error: too few arguments to function '__builtin_fpclassify' \
4854                 [E0511]",
4855                "/main.c:3:23: error: non-floating-point argument in call to function \
4856                 '__builtin_fpclassify' [E0685]",
4857            ]
4858        );
4859    }
4860
4861    /// A builtin whose answer is a constant is one, and is not a call to the library.
4862    ///
4863    /// This is the reason the family is answered in the front end at all. `double x =
4864    /// __builtin_inf();` at file scope initializes an object with static storage duration, so
4865    /// there is no point in the program at which a call could be made, and a compiler that
4866    /// lowered it to one would reject a program gcc accepts. Every number here is the encoding
4867    /// gcc 16 gives on x86-64.
4868    #[test]
4869    fn a_builtin_whose_answer_is_a_constant_is_one_and_not_a_call() {
4870        let text = ir(concat!(
4871            "double a = __builtin_inf();\n",
4872            "float b = __builtin_huge_valf();\n",
4873            "long double c = __builtin_infl();\n",
4874            "double d = __builtin_huge_val();\n",
4875        ));
4876        assert!(text.contains("global @a : f64 = 0x7ff0000000000000,"), "{text}");
4877        assert!(text.contains("global @b : f32 = 0x7f800000,"), "{text}");
4878        assert!(text.contains("f80 0x7fff8000000000000000"), "{text}");
4879        assert!(text.contains("global @d : f64 = 0x7ff0000000000000,"), "{text}");
4880        assert!(!text.contains("call"), "{text}");
4881    }
4882
4883    /// A nan is written with the payload the program asked for.
4884    ///
4885    /// The string is read the way `strtoull` reads a number, which is what the library function
4886    /// of the same name does with it, and a string that is not one at all leaves the call for the
4887    /// library to answer at run time. A quiet nan has the high fraction bit set and a signalling
4888    /// one does not, except that a signalling nan with nothing in it would be an infinity, so it
4889    /// gets the next bit down instead. Every encoding here was measured against gcc 16, the two
4890    /// `long double` ones on a machine with the x87 format.
4891    #[test]
4892    fn a_nan_is_written_with_the_payload_the_program_asked_for() {
4893        let text = ir(concat!(
4894            "double a = __builtin_nan(\"\");\n",
4895            "double b = __builtin_nan(\"0x1\");\n",
4896            // Octal, since there is a leading zero, so this is eight and not ten.
4897            "double c = __builtin_nan(\"010\");\n",
4898            "double d = __builtin_nans(\"\");\n",
4899            "double e = __builtin_nans(\"0x1\");\n",
4900            "float f = __builtin_nanf(\"0x1\");\n",
4901            "float g = __builtin_nansf(\"\");\n",
4902            "long double h = __builtin_nansl(\"\");\n",
4903        ));
4904        assert!(text.contains("global @a : f64 = 0x7ff8000000000000,"), "{text}");
4905        assert!(text.contains("global @b : f64 = 0x7ff8000000000001,"), "{text}");
4906        assert!(text.contains("global @c : f64 = 0x7ff8000000000008,"), "{text}");
4907        assert!(text.contains("global @d : f64 = 0x7ff4000000000000,"), "{text}");
4908        assert!(text.contains("global @e : f64 = 0x7ff0000000000001,"), "{text}");
4909        assert!(text.contains("global @f : f32 = 0x7fc00001,"), "{text}");
4910        assert!(text.contains("global @g : f32 = 0x7fa00000,"), "{text}");
4911        assert!(text.contains("f80 0x7fffa000000000000000"), "{text}");
4912
4913        // A payload that is not a number, and one that is not known until run time, are both
4914        // left to the library, which is the same thing gcc emits for either of them.
4915        let text = ir(concat!(
4916            "double f(const char *p) { return __builtin_nan(p); }\n",
4917            "double g(void) { return __builtin_nans(\"1x\"); }\n",
4918        ));
4919        assert_eq!(text.matches("call @nan(").count(), 1, "{text}");
4920        assert_eq!(text.matches("call @nans(").count(), 1, "{text}");
4921    }
4922
4923    /// The length and the order of a string literal are known here.
4924    ///
4925    /// A program that asks for either of them is asking about something the translation already
4926    /// has in front of it, and folding is not only an optimization: `execute/921007-1.c` in the
4927    /// torture suite calls `__builtin_strcmp` in a file that defines its own `strcmp` with a
4928    /// different signature, so leaving the call behind is a name collision that gcc does not
4929    /// have. The comparison is over `unsigned char`, which is why the second one is negative.
4930    #[test]
4931    fn the_length_and_the_order_of_a_string_literal_are_known_here() {
4932        let text = ir(concat!(
4933            "unsigned long a = __builtin_strlen(\"hello\");\n",
4934            "unsigned long b = __builtin_strlen(\"a\\0bc\");\n",
4935            "int c = __builtin_strcmp(\"X\", \"X\\376\") < 0;\n",
4936            "int d = __builtin_strcmp(\"abc\", \"abc\");\n",
4937            "int e = __builtin_strcmp(\"abc\", \"ab\") > 0;\n",
4938        ));
4939        assert!(text.contains("global @a : i64 = 5,"), "{text}");
4940        assert!(text.contains("global @b : i64 = 1,"), "{text}");
4941        assert!(text.contains("global @c : i32 = 1,"), "{text}");
4942        assert!(text.contains("global @d : i32 = 0,"), "{text}");
4943        assert!(text.contains("global @e : i32 = 1,"), "{text}");
4944        assert!(!text.contains("call"), "{text}");
4945
4946        // An argument that is not a literal is the library's to answer, as it has to be.
4947        let text = ir("unsigned long f(const char *p) { return __builtin_strlen(p); }\n");
4948        assert!(text.contains("call @strlen("), "{text}");
4949    }
4950
4951    /// A sign builtin is a mask over the bits, and is not a call.
4952    ///
4953    /// `fabs` and `copysign` are in the math library rather than the C one, so a program that
4954    /// only ever wrote the prefixed spelling never asked for `-lm` and a call left behind here
4955    /// would not link. Neither needs anything the library has: one clears the sign bit and the
4956    /// other takes it from the second operand, and every other bit goes through untouched.
4957    #[test]
4958    fn a_sign_builtin_is_a_mask_over_the_bits_and_not_a_call() {
4959        let text = body("double f(double x) { return __builtin_fabs(x); }\n");
4960        assert!(text.contains("bitcast.i64 %0"), "{text}");
4961        assert!(text.contains("iconst.i64 9223372036854775807"), "{text}");
4962        assert!(text.contains("and %1, %2"), "{text}");
4963        assert!(text.contains("bitcast.f64 %3"), "{text}");
4964        assert!(!text.contains("call"), "{text}");
4965
4966        let text = body("double f(double x, double y) { return __builtin_copysign(x, y); }\n");
4967        assert!(text.contains("iconst.i64 -9223372036854775808"), "{text}");
4968        assert!(text.contains("%8 = or %4, %7"), "{text}");
4969        assert!(!text.contains("call"), "{text}");
4970
4971        // The x87 format, whose value is eighty bits sitting in an object of sixteen. The mask is
4972        // as wide as the value and not as wide as the object, so the padding is not part of it.
4973        let text = body("long double f(long double x) { return __builtin_fabsl(x); }\n");
4974        assert!(text.contains("bitcast.i80 %0"), "{text}");
4975        assert!(text.contains("bitcast.f80"), "{text}");
4976
4977        // The width a name does not spell out is `double`, so a `float` argument widens first and
4978        // the answer is a `double`, which is what gcc's declaration of it says.
4979        let text = body("double f(float x) { return __builtin_fabs(x); }\n");
4980        assert!(text.contains("fpext.f64 %0"), "{text}");
4981        assert!(text.contains("bitcast.i64 %1"), "{text}");
4982    }
4983
4984    /// The plain math library names are the same mask, which is what makes a program link.
4985    ///
4986    /// `math.h` declares `fabs` and never spells `__builtin_fabs`, so the plain name is the one
4987    /// every program that includes the header reaches. Recognising only the prefixed spelling
4988    /// leaves a call to the math library behind, and the math library is not on the link line
4989    /// unless the program asked for `-lm`. parson is the project that shows it: its makefile has
4990    /// no `-lm`, it does not need one under gcc, and `undefined reference to 'fabs'` is where the
4991    /// build stopped. That is issue 630.
4992    #[test]
4993    fn the_plain_math_names_are_the_same_mask_and_not_a_call() {
4994        let text =
4995            body(concat!("double fabs(double x);\n", "double f(double x) { return fabs(x); }\n",));
4996        assert!(text.contains("iconst.i64 9223372036854775807"), "{text}");
4997        assert!(!text.contains("call"), "{text}");
4998
4999        let text =
5000            body(concat!("float fabsf(float x);\n", "float f(float x) { return fabsf(x); }\n",));
5001        assert!(text.contains("bitcast.i32 %0"), "{text}");
5002        assert!(!text.contains("call"), "{text}");
5003
5004        let text = body(concat!(
5005            "double copysign(double x, double y);\n",
5006            "double f(double x, double y) { return copysign(x, y); }\n",
5007        ));
5008        assert!(text.contains("iconst.i64 -9223372036854775808"), "{text}");
5009        assert!(!text.contains("call"), "{text}");
5010
5011        let text = body(concat!(
5012            "float copysignf(float x, float y);\n",
5013            "float f(float x, float y) { return copysignf(x, y); }\n",
5014        ));
5015        assert!(!text.contains("call"), "{text}");
5016
5017        // The `long double` pair is left alone on purpose. The prefixed spelling of both stops in
5018        // the back end with `no rule lowers a bitcast producing an i80`, so expanding the plain
5019        // name would trade a link error for a worse one. They go in with issue 540.
5020        let text = ir(concat!(
5021            "long double fabsl(long double x);\n",
5022            "long double f(long double x) { return fabsl(x); }\n",
5023        ));
5024        assert!(text.contains("call @fabsl"), "{text}");
5025    }
5026
5027    /// A plain math name the program took is the program's own function.
5028    ///
5029    /// The same four ways as the absolute value family next door, asked again here because these
5030    /// two go through a different path: the plain names of this family are taken after the call
5031    /// has been checked against the declaration, and the declaration is the whole reason the
5032    /// question can be answered at all. Measured against gcc 16.2.0, which calls the program's
5033    /// function in every one of them.
5034    #[test]
5035    fn a_plain_math_name_the_program_took_is_the_programs_own_function() {
5036        let taken = concat!(
5037            "static double fabs(double b) { return 7; }\n",
5038            "double f(double x) { return fabs(x); }\n",
5039        );
5040        assert!(ir(taken).contains("call @fabs"), "a static definition is the program's own");
5041
5042        let retyped = concat!("int fabs(int b);\n", "int f(int x) { return fabs(x); }\n");
5043        assert!(ir(retyped).contains("call @fabs"), "another type is another function");
5044
5045        let plain = concat!("double fabs(double b);\n", "double f(double x) { return fabs(x); }\n");
5046        let mut opts = options();
5047        opts.emit = EmitKind::Ir;
5048        assert!(!run(&opts, plain).text().contains("call @fabs"), "the library's by default");
5049
5050        opts.builtins = false;
5051        assert!(run(&opts, plain).text().contains("call @fabs"), "-fno-builtin");
5052
5053        opts.builtins = true;
5054        opts.no_builtin = vec!["fabs".to_owned()];
5055        assert!(run(&opts, plain).text().contains("call @fabs"), "-fno-builtin-fabs");
5056        let one = concat!(
5057            "double copysign(double a, double b);\n",
5058            "double f(double x) { return copysign(x, 1.0); }\n",
5059        );
5060        assert!(!run(&opts, one).text().contains("call @copysign"), "one name and not the family");
5061
5062        // The prefixed spelling is untouched by any of it, which is what the prefix is for.
5063        opts.no_builtin = Vec::new();
5064        opts.builtins = false;
5065        let prefixed = "double f(double x) { return __builtin_fabs(x); }\n";
5066        assert!(!run(&opts, prefixed).text().contains("call @fabs"), "the prefix is not a library");
5067    }
5068
5069    /// The sign builtins answer a zero and a nan the way the bits say.
5070    ///
5071    /// This is why they are described over the bits rather than written with comparisons and
5072    /// negation. A negative zero compares equal to a positive one and has a sign bit to clear,
5073    /// and a nan compares equal to nothing at all and keeps its payload through both operations.
5074    /// `execute/ieee/copysign1.c` in the torture suite is the test that notices, because it
5075    /// compares its answers with `memcmp`. Every number here is what gcc 16 gives, the two in the
5076    /// x87 format measured on a machine that has it.
5077    #[test]
5078    fn the_sign_builtins_answer_a_zero_and_a_nan_the_way_the_bits_say() {
5079        let text = ir(concat!(
5080            "double a = __builtin_fabs(-3.5);\n",
5081            "double b = __builtin_copysign(1.0, -0.0);\n",
5082            "double c = __builtin_copysign(0.0, -2.0);\n",
5083            // The payload survives both, and only the sign bit moves.
5084            "double d = __builtin_copysign(-__builtin_nan(\"\"), 1.0);\n",
5085            "double e = __builtin_fabs(-__builtin_nan(\"0x1\"));\n",
5086            "float g = __builtin_copysignf(-0.0f, 2.0f);\n",
5087            "long double h = __builtin_copysignl(1.0L, -1.0L);\n",
5088            "long double i = __builtin_fabsl(-__builtin_infl());\n",
5089        ));
5090        assert!(text.contains("global @a : f64 = 0x400c000000000000,"), "{text}");
5091        assert!(text.contains("global @b : f64 = 0xbff0000000000000,"), "{text}");
5092        assert!(text.contains("global @c : f64 = 0x8000000000000000,"), "{text}");
5093        assert!(text.contains("global @d : f64 = 0x7ff8000000000000,"), "{text}");
5094        assert!(text.contains("global @e : f64 = 0x7ff8000000000001,"), "{text}");
5095        assert!(text.contains("global @g : f32 = 0x0,"), "{text}");
5096        assert!(text.contains("f80 0xbfff8000000000000000"), "{text}");
5097        assert!(text.contains("f80 0x7fff8000000000000000"), "{text}");
5098    }
5099
5100    /// The complex builtins are the halves of the value, and are not a call.
5101    ///
5102    /// `conj`, `creal` and `cimag` are `~`, `__real__` and `__imag__` under the names `complex.h`
5103    /// gives them, so there is nothing for the math library to do that the translation cannot do
5104    /// with the object in front of it. Leaving the call behind would not link either, since all
5105    /// three are in the math library and a program that wrote one never had a reason to ask for
5106    /// `-lm`. Measured against gcc 16.2.0, which emits no call for any of them even at `-O0`.
5107    #[test]
5108    fn the_complex_builtins_are_the_halves_of_the_value_and_not_a_call() {
5109        let text = body("double f(_Complex double z) { return __builtin_creal(z); }\n");
5110        assert!(!text.contains("call"), "{text}");
5111        let text = body("double f(_Complex double z) { return __builtin_cimag(z); }\n");
5112        assert!(!text.contains("call"), "{text}");
5113
5114        // The conjugate is the imaginary half negated and the real half as it stands, so there is
5115        // one negation in it. A complex negation is the one with two.
5116        let text = body("_Complex double f(_Complex double z) { return __builtin_conj(z); }\n");
5117        assert_eq!(text.matches("fneg").count(), 1, "{text}");
5118        assert!(!text.contains("call"), "{text}");
5119        let negated = body("_Complex double f(_Complex double z) { return -z; }\n");
5120        assert_eq!(negated.matches("fneg").count(), 2, "{negated}");
5121
5122        // `~` on a complex operand is the same operator, which is the spelling the language has
5123        // had all along and the one a program that never included the header writes.
5124        let written = body("_Complex double f(_Complex double z) { return ~z; }\n");
5125        assert_eq!(written, text, "the name and the operator are the same thing");
5126
5127        // The plain names, which are the ones the header declares and so the ones programs write.
5128        let text = body(concat!(
5129            "double creal(_Complex double z);\n",
5130            "double f(_Complex double z) { return creal(z); }\n",
5131        ));
5132        assert!(!text.contains("call"), "{text}");
5133        let text = body(concat!(
5134            "_Complex float conjf(_Complex float z);\n",
5135            "_Complex float f(_Complex float z) { return conjf(z); }\n",
5136        ));
5137        assert_eq!(text.matches("fneg").count(), 1, "{text}");
5138        assert!(!text.contains("call"), "{text}");
5139
5140        // A program that took the name means its own function, the same four ways the absolute
5141        // value family next door asks it.
5142        let taken = concat!(
5143            "static double creal(_Complex double z) { return 7; }\n",
5144            "double f(_Complex double z) { return creal(z); }\n",
5145        );
5146        assert!(ir(taken).contains("call @creal"), "a static definition is the program's own");
5147        let retyped = concat!("int cimag(int z);\n", "int f(int z) { return cimag(z); }\n");
5148        assert!(ir(retyped).contains("call @cimag"), "another type is another function");
5149        let plain = concat!(
5150            "double cimag(_Complex double z);\n",
5151            "double f(_Complex double z) { return cimag(z); }\n",
5152        );
5153        let mut opts = options();
5154        opts.emit = EmitKind::Ir;
5155        opts.builtins = false;
5156        assert!(run(&opts, plain).text().contains("call @cimag"), "-fno-builtin");
5157        opts.builtins = true;
5158        opts.no_builtin = vec!["cimag".to_owned()];
5159        assert!(run(&opts, plain).text().contains("call @cimag"), "-fno-builtin-cimag");
5160
5161        // A constant folds, which is what a static initializer written with one needs.
5162        let text = ir(concat!(
5163            "double a = __builtin_creal(1.5 + 2.5i);\n",
5164            "double b = __builtin_cimag(1.5 + 2.5i);\n",
5165            "_Complex double c = __builtin_conj(1.5 + 2.5i);\n",
5166        ));
5167        assert!(text.contains("global @a : f64 = 0x3ff8000000000000,"), "{text}");
5168        assert!(text.contains("global @b : f64 = 0x4004000000000000,"), "{text}");
5169        assert!(
5170            text.contains("{ f64 0x3ff8000000000000, f64 0xc004000000000000 }"),
5171            "the conjugate of a constant is the constant with the second half negated: {text}"
5172        );
5173        assert!(!text.contains("call"), "{text}");
5174    }
5175
5176    /// A math library builtin handed a constant is the answer, and is not a call.
5177    ///
5178    /// This is the reason the family is answered in the front end at all. `double x =
5179    /// __builtin_ceil(1.5);` at file scope initializes an object with static storage duration, so
5180    /// there is no point in the program at which a call could be made, and a compiler that lowered
5181    /// it to one would refuse a program gcc accepts. Every number here is the encoding gcc 16.2.0
5182    /// gives on x86-64, read out of the object file one initializer at a time.
5183    #[test]
5184    fn a_math_library_builtin_of_a_constant_is_the_answer_and_not_a_call() {
5185        let text = ir(concat!(
5186            "double a = __builtin_ceil(1.5);\n",
5187            "double b = __builtin_floor(1.5);\n",
5188            "double c = __builtin_trunc(-1.5);\n",
5189            // A half goes away from zero and not to even, which is where C and the default
5190            // rounding of IEEE 754 part company.
5191            "double d = __builtin_round(2.5);\n",
5192            // The sign survives a number that rounds away to nothing, so this is a negative zero.
5193            "double e = __builtin_ceil(-0.5);\n",
5194            "double f = __builtin_fmax(1.0, 2.0);\n",
5195            "double g = __builtin_fmin(1.0, 2.0);\n",
5196            "float h = __builtin_ceilf(1.25f);\n",
5197            // The plain name is the same answer, which is what a program that included `math.h`
5198            // and never wrote a prefix reaches.
5199            "double ceil(double x);\n",
5200            "double i = ceil(2.25);\n",
5201        ));
5202        assert!(text.contains("global @a : f64 = 0x4000000000000000,"), "{text}");
5203        assert!(text.contains("global @b : f64 = 0x3ff0000000000000,"), "{text}");
5204        assert!(text.contains("global @c : f64 = 0xbff0000000000000,"), "{text}");
5205        assert!(text.contains("global @d : f64 = 0x4008000000000000,"), "{text}");
5206        assert!(text.contains("global @e : f64 = 0x8000000000000000,"), "{text}");
5207        assert!(text.contains("global @f : f64 = 0x4000000000000000,"), "{text}");
5208        assert!(text.contains("global @g : f64 = 0x3ff0000000000000,"), "{text}");
5209        assert!(text.contains("global @h : f32 = 0x40000000,"), "{text}");
5210        assert!(text.contains("global @i : f64 = 0x4008000000000000,"), "{text}");
5211        assert!(!text.contains("call"), "{text}");
5212    }
5213
5214    /// A math library builtin handed anything else is a call to the library function it is.
5215    ///
5216    /// gcc emits `jmp ceil` for `__builtin_ceil` on x86-64 at the default architecture, measured
5217    /// on gcc 16.2.0, and reaches the `roundsd` instruction only under `-msse4.1`. So the call is
5218    /// what a program gets from gcc too, and the name on it is the plain one, which is the whole
5219    /// point of the prefixed spelling: a program writing it reaches the library's function even
5220    /// where a macro or a definition of its own has taken the short name.
5221    #[test]
5222    fn a_math_library_builtin_of_anything_else_is_a_call_to_the_library() {
5223        let text = ir(concat!(
5224            "double f(double x) { return __builtin_ceil(x); }\n",
5225            "float g(float x) { return __builtin_floorf(x); }\n",
5226            "double h(double x, double y) { return __builtin_fmax(x, y); }\n",
5227        ));
5228        assert!(text.contains("call @ceil("), "{text}");
5229        assert!(text.contains("call @floorf("), "{text}");
5230        assert!(text.contains("call @fmax("), "{text}");
5231
5232        // The two the rounding mode decides are calls even when the argument is a constant, since
5233        // what they answer is not known until the program runs. gcc refuses a static initializer
5234        // written with one for that reason, so there is nothing to fold here either.
5235        let text = ir(concat!(
5236            "double f(void) { return __builtin_rint(2.5); }\n",
5237            "double g(void) { return __builtin_nearbyint(2.5); }\n",
5238        ));
5239        assert!(text.contains("call @rint("), "{text}");
5240        assert!(text.contains("call @nearbyint("), "{text}");
5241
5242        // A nan operand is the library's rule rather than the machine's, 7.12.12.2 saying the
5243        // answer is the other operand, and gcc will not fold that one either.
5244        let text = ir("double f(void) { return __builtin_fmin(__builtin_nan(\"\"), 1.0); }\n");
5245        assert!(text.contains("call @fmin("), "{text}");
5246
5247        // `-fno-builtin-ceil` is a program saying it means its own `ceil`, and it leaves the
5248        // prefixed spelling alone, which is what writing the prefix is for.
5249        let plain = concat!("double ceil(double x);\n", "double f(void) { return ceil(2.25); }\n");
5250        let mut opts = options();
5251        opts.emit = EmitKind::Ir;
5252        opts.no_builtin = vec!["ceil".to_owned()];
5253        assert!(run(&opts, plain).text().contains("call @ceil("), "-fno-builtin-ceil");
5254    }
5255
5256    /// A `constexpr` object is a named constant, which is the whole reason the keyword exists.
5257    ///
5258    /// C23 6.6p8 puts two of them on the list an integer constant expression is built from: one
5259    /// of an arithmetic type, and a member of one of a structure or union type. A subscript of
5260    /// one is not on the list and is a variably modified type in gcc 16 as well, and every
5261    /// number here is what gcc 16 gives on x86-64.
5262    #[test]
5263    fn a_constexpr_object_is_a_constant_wherever_one_is_required() {
5264        let text = ir(concat!(
5265            "constexpr int side = 4;\n",
5266            "constexpr int wider = side + 1;\n",
5267            "constexpr double half = 1.5;\n",
5268            "struct point { int x; int y; };\n",
5269            "constexpr struct point origin = { 5, 6 };\n",
5270            "int square[side * side];\n",
5271            "int rectangle[wider];\n",
5272            "int rounded[(int)half * 2];\n",
5273            "int across[origin.y];\n",
5274            "enum named { four = side };\n",
5275            "int e = four;\n",
5276        ));
5277        assert!(text.contains("global @square : bytes 64 ="), "{text}");
5278        assert!(text.contains("global @rectangle : bytes 20 ="), "{text}");
5279        assert!(text.contains("global @rounded : bytes 8 ="), "{text}");
5280        assert!(text.contains("global @across : bytes 24 ="), "{text}");
5281        assert!(text.contains("global @e : i32 = 4,"), "{text}");
5282
5283        // A `const` object is not one of them, which is what makes `int a[n];` a variable
5284        // length array in C and is the distinction the keyword was added to draw.
5285        let mut opts = options();
5286        opts.emit = EmitKind::Ir;
5287        let konst = "const int n = 1;\nint a[n];\n";
5288        let message = "/main.c:2:5: error: variably modified 'a' at file scope [E0538]";
5289        assert_eq!(run(&opts, konst).messages, [message]);
5290
5291        // Nor is a subscript of one, which gcc 16 refuses in the same words.
5292        let subscript = "constexpr int t[3] = { 1, 2, 3 };\nint a[t[1]];\n";
5293        assert_eq!(run(&opts, subscript).messages, [message]);
5294
5295        // And `constexpr` implies `const`, so the address of one is an address of a `const`.
5296        let address = "constexpr int c = 3;\nint *p = &c;\n";
5297        let warning = "/main.c:2:6: warning: initialization discards 'const' qualifier from \
5298             pointer target type [E0514]";
5299        assert_eq!(run(&opts, address).messages, [warning]);
5300    }
5301
5302    /// A definition that names its parameters and then declares them under the list.
5303    ///
5304    /// The declarations say what the types are, 6.9.1p6, and what the function takes is those
5305    /// types with the default argument promotions over them, which is what a caller of an
5306    /// unprototyped function hands over. A prototype already in scope overrules the promoted
5307    /// types, since a header saying `int narrow(char);` over a definition written this way is
5308    /// the pairing all the code written this way relies on and 6.7.6.3p15 is read that way by
5309    /// every compiler.
5310    #[test]
5311    fn an_old_style_definition_takes_its_types_from_the_declarations_under_its_list() {
5312        // C17, since the default dialect is the one that warns about the form and this is
5313        // about what it means rather than about the warning.
5314        let mut opts = options();
5315        opts.std = Std::C17;
5316        let source = concat!(
5317            "int add(a, b)\n",
5318            "int a;\n",
5319            "int b;\n",
5320            "{ return a + b; }\n",
5321            "int promoted(c)\n",
5322            "char c;\n",
5323            "{ return c; }\n",
5324            "int narrow(char);\n",
5325            "int narrow(c)\n",
5326            "char c;\n",
5327            "{ return c; }\n",
5328            "int first(a)\n",
5329            "int a[4];\n",
5330            "{ return a[0]; }\n",
5331        );
5332        let result = run(&opts, source);
5333        assert_eq!(result.messages, Vec::<String>::new(), "expected this to compile:\n{source}");
5334        let text = result.text();
5335        assert!(text.contains("add : int(int, int) function external defined"), "{text}");
5336        assert!(text.contains("promoted : int(int) function external defined"), "{text}");
5337        // The body still sees the `char` it was declared as, whatever the caller hands over.
5338        assert!(text.contains("c : char object automatic defined"), "{text}");
5339        assert!(text.contains("narrow : int(char) function external defined"), "{text}");
5340        // An array parameter is a pointer here as much as it is in a prototype.
5341        assert!(text.contains("first : int(int *) function external defined"), "{text}");
5342    }
5343
5344    /// What the two halves of an old-style parameter list can disagree about.
5345    ///
5346    /// Each of these is a sentence gcc 16 has, and every message below is the one it prints,
5347    /// read off it on x86-64 rather than reasoned about. The last two are the dialect: a name
5348    /// with no declaration is an `int` in C89 and a diagnostic from C99 on, and the whole form
5349    /// left the language in C23, where gcc still takes it and warns.
5350    #[test]
5351    fn the_two_halves_of_an_old_style_parameter_list_have_to_agree() {
5352        let mut opts = options();
5353        opts.std = Std::C17;
5354        for (source, message) in [
5355            ("int f(a, a)\nint a;\n{ return a; }\n", "1:10: error: multiple parameters named 'a'"),
5356            (
5357                "int f(a)\nint a;\nint b;\n{ return a; }\n",
5358                "3:5: error: declaration for parameter 'b' but no such parameter",
5359            ),
5360            ("int f(a)\nint a;\nint a;\n{ return a; }\n", "3:5: error: redefinition of parameter"),
5361            ("int f(a)\nint a = 1;\n{ return a; }\n", "2:5: error: parameter 'a' is initialized"),
5362            (
5363                "int f(a)\nstatic int a;\n{ return a; }\n",
5364                "2:12: error: storage class specified for parameter 'a'",
5365            ),
5366            (
5367                "int f(char);\nint f(a)\nshort a;\n{ return a; }\n",
5368                "2:7: error: argument 'a' doesn't match prototype",
5369            ),
5370        ] {
5371            let result = run(&opts, source);
5372            assert!(result.failed(), "expected this to fail:\n{source}");
5373            assert!(result.messages[0].contains(message), "{:?}", result.messages);
5374        }
5375
5376        // A name the declarations never mention. C89 gave it an `int` and gcc still takes it
5377        // in that dialect, and every dialect after it made the same line a diagnostic.
5378        let implicit = "int f(a, b)\nint a;\n{ return a + b; }\n";
5379        let mut older = options();
5380        older.std = Std::C89;
5381        assert!(!run(&older, implicit).failed(), "{:?}", run(&older, implicit).messages);
5382        let result = run(&opts, implicit);
5383        assert!(
5384            result.messages[0].contains("1:10: error: type of 'b' defaults to 'int'"),
5385            "{:?}",
5386            result.messages
5387        );
5388
5389        // C23 took the form out of the language and gcc kept accepting it with a warning, and
5390        // a warning is what this is, because the code written this way is not going to be
5391        // rewritten and refusing it would put the compiler out of reach of it.
5392        let mut newer = options();
5393        newer.std = Std::C23;
5394        let plain = "int f(a)\nint a;\n{ return a; }\n";
5395        let result = run(&newer, plain);
5396        assert!(!result.failed(), "{:?}", result.messages);
5397        assert_eq!(
5398            result.messages,
5399            ["/main.c:1:5: warning: old-style function definition [E0412]"]
5400        );
5401        assert!(run(&opts, plain).messages.is_empty(), "and nothing to say in the dialects before");
5402    }
5403
5404    /// The two obsolete designators, which are silent until `-pedantic` asks about them.
5405    ///
5406    /// `[3] 7` is what GCC had for an array before C99 settled on `[3] = 7`, and `x: 7` is the
5407    /// same era's spelling for a member. Both are still in code written against a compiler of
5408    /// that era, and gcc 16 takes both without a word unless it is asked to be pedantic, which
5409    /// is where the columns below come from as well.
5410    #[test]
5411    fn the_obsolete_designators_are_taken_and_are_pedantic_warnings() {
5412        let array = "int a[8] = { [3] 7 };\n";
5413        let member = "struct s { int x; } v = { x: 7 };\n";
5414        for source in [array, member] {
5415            let result = run(&options(), source);
5416            assert!(!result.failed(), "{:?}", result.messages);
5417            assert!(result.messages.is_empty(), "nothing to say: {:?}", result.messages);
5418        }
5419
5420        let mut asked = options();
5421        asked.pedantic = true;
5422        assert_eq!(
5423            run(&asked, array).messages,
5424            ["/main.c:1:18: warning: obsolete designator, write `[i] =` instead [E0415]"]
5425        );
5426        assert_eq!(
5427            run(&asked, member).messages,
5428            ["/main.c:1:27: warning: obsolete designator, write `.field =` instead [E0413]"]
5429        );
5430    }
5431
5432    /// A type nothing is ever an object of is a type `sizeof` still has to answer about, which
5433    /// is what `991014-1.c` in the gcc.c-torture execution suite asks.
5434    ///
5435    /// The limit is `PTRDIFF_MAX` and it is the same one for an array and for a record, so a
5436    /// record of every byte an object may have is laid out and one byte more is refused. All
5437    /// four numbers are what gcc 16 gives on x86-64.
5438    #[test]
5439    fn a_type_is_refused_when_it_passes_the_largest_object_and_not_before() {
5440        let text = ir(concat!(
5441            "struct huge_struct { short buf[(1L << 62) - 256]; int a, b, c, d; };\n",
5442            "struct brim { char buf[9223372036854775807L]; };\n",
5443            "struct bitty { char buf[9223372036854775800L]; int x : 1; };\n",
5444            "unsigned long h = sizeof(struct huge_struct);\n",
5445            "unsigned long b = sizeof(struct brim);\n",
5446            "unsigned long y = sizeof(struct bitty);\n",
5447        ));
5448        assert!(text.contains("global @h : i64 = 9223372036854775312,"), "{text}");
5449        assert!(text.contains("global @b : i64 = 9223372036854775807,"), "{text}");
5450        assert!(text.contains("global @y : i64 = 9223372036854775804,"), "{text}");
5451
5452        let mut opts = options();
5453        opts.emit = EmitKind::Ir;
5454        let over = "struct over { char buf[9223372036854775800L]; char x[8]; };\n";
5455        let message = "/main.c:1:1: error: type 'struct over' is too large [E0560]";
5456        assert_eq!(run(&opts, over).messages, [message]);
5457        let array = "struct wide { short buf[1L << 62]; };\n";
5458        let message = "/main.c:1:25: error: size of array 'buf' exceeds \
5459             maximum object size '9223372036854775807' [E0537]";
5460        assert_eq!(run(&opts, array).messages[0], message);
5461    }
5462
5463    /// A byte in the source that is not part of a character, which only a literal may hold.
5464    ///
5465    /// The source cannot be a `&str` here, which is the whole point: a file is bytes and only
5466    /// mostly text.
5467    fn compile_bytes(source: &[u8]) -> Compiled {
5468        let mut opts = options();
5469        opts.emit = EmitKind::Ir;
5470        let mut fs = MemoryFileSystem::new();
5471        fs.insert("/main.c", source.to_vec());
5472        compile(&opts, "/main.c", &fs)
5473    }
5474
5475    /// A raw byte inside a string literal is that byte, which gcc has always taken and which is
5476    /// the only place in a source file where a byte does not have to be part of a character.
5477    /// Replacing it would give the object three bytes rather than one, since the replacement
5478    /// character is three bytes of UTF-8, so the object would not be the one that was written
5479    /// even where the diagnostic is ignored. Anywhere else the byte is still a mistake, which
5480    /// is where gcc draws the same line.
5481    #[test]
5482    fn a_byte_that_is_not_a_character_is_kept_in_a_literal_and_refused_outside_one() {
5483        let mut source = b"char s[] = \"a".to_vec();
5484        source.push(0xff);
5485        source.extend_from_slice(b"b\";\nchar c = '");
5486        source.push(0xff);
5487        source.extend_from_slice(b"';\n");
5488        let result = compile_bytes(&source);
5489        assert_eq!(result.messages, Vec::<String>::new(), "a raw byte in a literal is that byte");
5490        assert!(result.text().contains(r#"bytes "a\ffb\00""#), "{}", result.text());
5491        // Plain `char` is signed on this target, so the constant is minus one rather than 255.
5492        assert!(result.text().contains("global @c : i8 = -1,"), "{}", result.text());
5493
5494        let mut stray = b"int a".to_vec();
5495        stray.push(0xff);
5496        stray.extend_from_slice(b" = 1;\n");
5497        let result = compile_bytes(&stray);
5498        assert!(
5499            result.messages.iter().any(|m| m.contains("source is not valid UTF-8 here")),
5500            "{:?}",
5501            result.messages
5502        );
5503    }
5504
5505    #[test]
5506    fn an_object_becomes_a_global_with_an_image_and_a_function_becomes_a_func() {
5507        let text = ir("int x = 7;\nint add(int a, int b) { return a + b; }\n");
5508        assert!(text.contains("global @x : i32 = 7, align 4, linkage(external)\n"), "{text}");
5509        let expected = "\
5510func @add(i32, i32) -> i32, linkage(external) {
5511block0(%0: i32, %1: i32):
5512    %2 = add.nsw %0, %1
5513    return %2
5514}
5515";
5516        assert!(text.contains(expected), "{text}");
5517    }
5518
5519    #[test]
5520    fn a_local_nothing_takes_the_address_of_is_a_value_and_never_a_stack_slot() {
5521        let text = body("int f(int n) { int a = n + 1; int b = a * 2; return a + b; }\n");
5522        assert!(!text.contains("alloca"), "{text}");
5523        assert!(!text.contains("load"), "{text}");
5524        assert!(!text.contains("store"), "{text}");
5525    }
5526
5527    #[test]
5528    fn a_local_whose_address_is_taken_gets_a_slot_in_the_entry_block() {
5529        let text = body("int g(int *);\nint f(void) { int a = 1; return g(&a); }\n");
5530        let expected = "\
5531block0:
5532    %0 = alloca, size 4, align 4
5533    %1 = iconst.i32 1
5534    store %1 -> %0, align 4, tbaa !1
5535    %2 = call @g(%0) : (ptr) -> i32
5536    return %2
5537";
5538        assert_eq!(text, expected);
5539    }
5540
5541    #[test]
5542    fn a_loop_carries_what_it_changes_as_block_parameters() {
5543        // The whole point of building SSA during the walk rather than after it: `i` and
5544        // `total` are values that arrive on an edge, and neither has ever been in memory.
5545        let text = body(
5546            "int f(int n) {\n  int total = 0;\n  for (int i = 0; i < n; i++) total += i;\n  \
5547             return total;\n}\n",
5548        );
5549        assert!(!text.contains("alloca"), "{text}");
5550        assert!(text.contains("block1(%3: i32, %4: i32):"), "{text}");
5551        assert!(text.contains("jump block1("), "{text}");
5552    }
5553
5554    #[test]
5555    fn a_comparison_used_as_a_condition_is_not_widened_and_narrowed_again() {
5556        let text = body("int f(int a, int b) { if (a < b) return 1; return 0; }\n");
5557        assert!(text.contains("icmp slt %0, %1"), "{text}");
5558        assert!(!text.contains("zext"), "{text}");
5559    }
5560
5561    #[test]
5562    fn the_right_side_of_a_short_circuit_is_in_a_block_of_its_own() {
5563        let text = body("int f(int a, int b) { return a && b; }\n");
5564        let expected = "\
5565block0(%0: i32, %1: i32):
5566    %2 = iconst.i32 0
5567    %3 = icmp ne %0, %2
5568    %4 = iconst.i1 0
5569    br_if %3, block1, block2(%4)
5570
5571block1:
5572    %5 = iconst.i32 0
5573    %6 = icmp ne %1, %5
5574    jump block2(%6)
5575
5576block2(%7: i1):
5577    %8 = zext.i32 %7
5578    return %8
5579";
5580        assert_eq!(text, expected);
5581    }
5582
5583    #[test]
5584    fn code_after_a_return_is_not_built_and_does_not_leave_an_empty_block_behind() {
5585        let text = body("int f(int a) { if (a) return 1; else return 2; return 3; }\n");
5586        // Three blocks, the test and the two arms. The join the `return 3` would need is
5587        // never created, because a block nothing branches to is not a block.
5588        assert!(!text.contains("block3"), "{text}");
5589        assert!(!text.contains("iconst.i32 3"), "{text}");
5590    }
5591
5592    #[test]
5593    fn falling_off_the_end_returns_zero_from_main_and_nothing_from_a_void_function() {
5594        assert!(body("int main(void) { }\n").contains("iconst.i32 0\n    return"));
5595        assert_eq!(body("void f(void) { }\n"), "block0:\n    return\n");
5596        assert!(body("int f(void) { }\n").contains("unreachable"));
5597    }
5598
5599    #[test]
5600    fn a_structure_is_copied_rather_than_held_in_a_value() {
5601        let text = body(
5602            "struct point { int x, y; };\n\
5603             int f(void) { struct point p = { 1, 2 }; struct point q = p; return q.x; }\n",
5604        );
5605        assert!(text.contains("memcpy"), "{text}");
5606    }
5607
5608    #[test]
5609    fn an_initializer_that_leaves_part_of_an_object_unwritten_zeroes_it_first() {
5610        let text = body("int f(void) { int a[4] = { 1 }; return a[3]; }\n");
5611        assert!(text.contains("memset"), "{text}");
5612    }
5613
5614    #[test]
5615    fn a_switch_is_one_branch_and_a_case_that_falls_through_carries_what_it_wrote() {
5616        let text = body(
5617            "int f(int x) { int r = 0; switch (x) { case 1: r = 1; case 2: r += 2; break; \
5618             default: r = 4; } return r; }\n",
5619        );
5620        let expected = "\
5621block0(%0: i32):
5622    %1 = iconst.i32 0
5623    switch %0, block1, [1 => block2, 2 => block3(%1)]
5624
5625block1:
5626    %2 = iconst.i32 4
5627    jump block4(%2)
5628
5629block2:
5630    %3 = iconst.i32 1
5631    jump block3(%3)
5632
5633block3(%4: i32):
5634    %5 = iconst.i32 2
5635    %6 = add.nsw %4, %5
5636    jump block4(%6)
5637
5638block4(%7: i32):
5639    return %7
5640";
5641        assert_eq!(text, expected);
5642    }
5643
5644    #[test]
5645    fn a_case_range_is_tested_for_rather_than_put_in_the_table() {
5646        // GNU's `case 1 ... 9`. Nine table entries would be nine here and four billion for the
5647        // range a program is allowed to write, so it is a subtraction and one unsigned compare.
5648        let text = body("int f(int x) { switch (x) { case 1 ... 9: return 1; } return 0; }\n");
5649        assert!(text.contains("%2 = sub %0, %1"), "{text}");
5650        assert!(text.contains("icmp ule"), "{text}");
5651        assert!(!text.contains("switch"), "{text}");
5652    }
5653
5654    #[test]
5655    fn break_leaves_the_switch_and_continue_leaves_the_loop_around_it() {
5656        let text = body(
5657            "int f(int n) { int t = 0; for (int i = 0; i < n; i++) { switch (i) { \
5658             case 0: continue; case 1: break; default: t += i; } t++; } return t; }\n",
5659        );
5660        // The `continue` goes to the step and the `break` goes to the `t++` after the switch,
5661        // which is also where the default falls out to.
5662        assert!(text.contains("switch %3, block4, [0 => block5, 1 => block6]"), "{text}");
5663        assert!(text.contains("block5:\n    jump block7("), "{text}");
5664        assert!(text.contains("block6:\n    jump block8("), "{text}");
5665    }
5666
5667    #[test]
5668    fn a_switch_with_nothing_to_branch_on_still_runs_what_comes_after_it() {
5669        assert_eq!(body("void f(int x) { switch (x) { } }\n"), "block0(%0: i32):\n    return\n");
5670    }
5671
5672    #[test]
5673    fn a_label_a_loop_is_only_entered_through_builds_the_loop_around_it() {
5674        // A branch into the middle of a loop that nothing else reaches, the Duff's device shape.
5675        // The `while` is not reached in order, so the walk starts a block nothing branches to and
5676        // builds it from there. What comes out is the loop with an edge straight into its body,
5677        // and the header that nothing arrives at is pruned.
5678        let text = body(
5679            "int f(int x, int n) { switch (x) { case 1: break; while (n) { case 2: n--; } } \
5680             return n; }\n",
5681        );
5682        // `case 2` lands on the body, `case 1` and the default land on the return, and the test
5683        // at the bottom of the loop comes back round to the body.
5684        assert!(text.contains("switch %0, block1(%1), [1 => block2, 2 => block3(%1)]"), "{text}");
5685        assert!(text.contains("block3(%3: i32):\n    %4 = iconst.i32 1"), "{text}");
5686        assert!(text.contains("block4:\n    jump block3("), "{text}");
5687    }
5688
5689    #[test]
5690    fn a_goto_into_a_loop_body_enters_it_without_the_test() {
5691        // The same thing through a `goto`. The first pass through the body runs whatever the
5692        // label is on, and only then does the loop reach its own test.
5693        let text = body("int f(int x, int n) { goto in; while (n) { in: n--; } return n; }\n");
5694        assert!(text.starts_with("block0(%0: i32, %1: i32):\n    jump block1(%1)"), "{text}");
5695        assert!(text.contains("block1(%2: i32):\n    %3 = iconst.i32 1"), "{text}");
5696        assert!(text.contains("br_if %6, block2, block3"), "{text}");
5697    }
5698
5699    #[test]
5700    fn a_goto_is_a_jump_to_the_block_the_label_starts() {
5701        let text = body("int f(int x) { int r = 0; if (x) goto out; r = 1; out: return r; }\n");
5702        // Both edges into `out` carry what `r` holds on the way, and neither is a stack slot. The
5703        // block the `goto` jumps out of is empty and hands its edge on, which is what moves `out`
5704        // up the block list to second place.
5705        assert!(!text.contains("alloca"), "{text}");
5706        assert!(text.contains("block2(%4: i32):\n    return %4"), "{text}");
5707        assert_eq!(text.matches("jump block2(").count(), 2, "{text}");
5708    }
5709
5710    #[test]
5711    fn a_backward_goto_is_a_loop_and_carries_what_it_changes() {
5712        let text =
5713            body("int f(int n) { int i = 0; again: if (i < n) { i++; goto again; } return i; }\n");
5714        assert!(!text.contains("alloca"), "{text}");
5715        assert!(text.contains("block1(%2: i32):"), "{text}");
5716        assert!(text.contains("jump block1(%5)"), "{text}");
5717    }
5718
5719    #[test]
5720    fn a_label_nothing_reaches_is_taken_out_rather_than_left_for_the_verifier() {
5721        // A block nothing branches to is not a legal function, and which labels are dead is not
5722        // known until the last statement has been walked, since the `goto` is allowed to be it.
5723        assert_eq!(
5724            body("int f(int x) { return x; spare: return 0; }\n"),
5725            "block0(%0: i32):\n    return %0\n"
5726        );
5727    }
5728
5729    #[test]
5730    fn a_bit_field_is_read_by_loading_the_bytes_it_lies_in_and_shifting() {
5731        let text = body(
5732            "struct s { unsigned a : 3; signed b : 5; };\nint f(struct s *p) { return p->b; }\n",
5733        );
5734        // One byte holds both fields, and the signed one needs no mask: shifting it down
5735        // arithmetically is what says its top bit is a sign.
5736        assert_eq!(
5737            text,
5738            "\
5739block0(%0: ptr):
5740    %1 = load.i8 %0, align 1
5741    %2 = iconst.i8 3
5742    %3 = ashr %1, %2
5743    %4 = sext.i32 %3
5744    return %4
5745"
5746        );
5747    }
5748
5749    #[test]
5750    fn a_store_to_a_bit_field_does_not_write_a_byte_it_has_no_bit_in() {
5751        // C11 says an ordinary member beside a bit-field is a memory location of its own, so
5752        // the four byte store this would take is a data race in a program that has none. The
5753        // three bytes of `a` go in as two and one, and `c` is not touched.
5754        let text =
5755            body("struct s { int a : 24; char c; };\nvoid f(struct s *p, int v) { p->a = v; }\n");
5756        assert_eq!(
5757            text,
5758            "\
5759block0(%0: ptr, %1: i32):
5760    %2 = iconst.i32 16777215
5761    %3 = and %1, %2
5762    %4 = trunc.i16 %3
5763    store %4 -> %0, align 2
5764    %5 = iconst.i32 16
5765    %6 = lshr %3, %5
5766    %7 = trunc.i8 %6
5767    %8 = iconst.i64 2
5768    %9 = ptr_add %0, %8
5769    store %7 -> %9, align 1
5770    return
5771"
5772        );
5773    }
5774
5775    #[test]
5776    fn what_an_assignment_to_a_bit_field_is_worth_is_what_fits_in_it() {
5777        let text =
5778            body("struct s { unsigned b : 5; };\nunsigned f(struct s *p) { return p->b = 33; }\n");
5779        // 33 does not fit in five bits, and 1 is both what goes in the field and what the
5780        // assignment is worth.
5781        assert!(text.contains("%3 = iconst.i8 31\n    %4 = and %2, %3"), "{text}");
5782        assert!(text.ends_with("%9 = zext.i32 %4\n    return %9\n"), "{text}");
5783    }
5784
5785    #[test]
5786    fn an_assignment_a_statement_throws_away_builds_none_of_what_it_is_worth() {
5787        // The value of an assignment to a bit-field takes a shift to build, and a statement
5788        // has no use for it. Nothing here reads back what was stored.
5789        let text = body("struct s { signed b : 5; };\nvoid f(struct s *p) { p->b = 3; }\n");
5790        assert_eq!(text.matches("ashr").count(), 0, "{text}");
5791        assert!(text.ends_with("store %8 -> %0, align 1\n    return\n"), "{text}");
5792    }
5793
5794    #[test]
5795    fn a_bit_field_in_an_initializer_goes_in_over_bytes_that_were_zeroed_first() {
5796        // A bit-field writes part of a byte and leaves the rest of it alone, so the object has
5797        // to be zero before it goes in or what the initializer did not name is whatever the
5798        // stack held.
5799        let text = body(
5800            "struct s { int a : 3; int b; };\nint f(void) { struct s v = { 1 }; return v.b; }\n",
5801        );
5802        assert!(text.contains("memset %0, %1, size 8, align 4"), "{text}");
5803    }
5804
5805    #[test]
5806    fn the_image_of_a_static_bit_field_is_the_bytes_the_fields_share() {
5807        // Two fields in one byte are not two entries in the image, because an image is written
5808        // in bytes: they are the byte they are both in.
5809        let text = ir("struct s { unsigned a : 3; unsigned b : 5; } g = { 1, 2 };\n");
5810        assert!(
5811            text.contains("global @g : bytes 4 = { bytes \"\\11\", zero 3 }, align 4"),
5812            "{text}"
5813        );
5814    }
5815
5816    #[test]
5817    fn an_initialized_flexible_array_member_makes_the_object_larger_than_its_type() {
5818        // `sizeof` answers without the array and the definition has to hold what was written, so
5819        // the object is the size of its image. gcc 16 gives these four, three and two bytes and
5820        // so does this. The image used to be written at the size the type had, which left the
5821        // verifier looking at twenty bytes going into four.
5822        let text = ir(concat!(
5823            "struct a { int i; int j[]; } x = { 1, { 2, 0, 2, 3 } };\n",
5824            "struct b { char c; char p[]; } y = { 'o', \"wx\" };\n",
5825            "struct c { char c; char p[]; } z = { '9', { 'e', 'b' } };\n",
5826            "char s[2] = \"hi\";\n",
5827        ));
5828        assert!(
5829            text.contains("global @x : bytes 20 = { i32 1, i32 2, i32 0, i32 2, i32 3 }"),
5830            "{text}"
5831        );
5832        assert!(text.contains("global @y : bytes 4 = { i8 111, bytes \"wx\\00\" }"), "{text}");
5833        assert!(text.contains("global @z : bytes 3 = { i8 57, i8 101, i8 98 }"), "{text}");
5834        // The array with a length of its own still cuts the literal down to it, which is the
5835        // one case in C where a string initializer drops its terminator.
5836        assert!(text.contains("global @s : bytes 2 = { bytes \"hi\" }"), "{text}");
5837    }
5838
5839    #[test]
5840    fn a_definition_takes_a_parameter_it_left_unnamed() {
5841        // The entry block's parameters are the definition's, and one the front end dropped for
5842        // having no name left the two lists different lengths, which the walk read as an
5843        // old-style definition and refused. gcc has taken these for far longer than C23 has.
5844        let text = ir("int f(int a, int) { return a; }\n");
5845        assert!(text.contains("func @f(i32, i32) -> i32"), "{text}");
5846        assert!(text.contains("block0(%0: i32, %1: i32):"), "{text}");
5847
5848        // The unnamed one first, so that the named one is the second parameter of the entry
5849        // block and not the first: the list says the order and not only how many there are.
5850        let text = ir("int g(int, int n) { return n; }\n");
5851        assert!(text.contains("block0(%0: i32, %1: i32):\n    return %1\n"), "{text}");
5852    }
5853
5854    #[test]
5855    fn an_assignment_of_a_structure_is_the_object_it_wrote() {
5856        // `d = e = c` used to be refused, because the middle assignment is a value of structure
5857        // type and the walk had nowhere to read one from. What an assignment is worth is the
5858        // value it stored, so the object it stored into is the answer and the chain is three
5859        // copies out of the one source with no temporary in it.
5860        let text = body(concat!(
5861            "struct s { int f; int g; };\n",
5862            "void h(struct s *a, struct s *c, struct s *d, struct s *e)\n",
5863            "{ *d = *e = a[0] = *c; }\n",
5864        ));
5865        assert_eq!(text.matches("memcpy").count(), 3, "{text}");
5866        assert!(text.contains("memcpy %8, %1, size 8, align 4\n"), "{text}");
5867        assert!(text.contains("memcpy %3, %8, size 8, align 4\n"), "{text}");
5868        assert!(text.contains("memcpy %2, %3, size 8, align 4\n"), "{text}");
5869    }
5870
5871    #[test]
5872    fn a_string_literal_stops_at_the_end_of_the_array_it_is_filling() {
5873        // The excess used to be laid into the object anyway, so the row after was written over
5874        // and the image refused the entry that came to it. C 6.7.10p14 says the terminator goes
5875        // in only if there is room for it, and gcc discards the rest of a literal that is longer
5876        // still, which is what the first of these is and why it warns.
5877        let mut opts = options();
5878        opts.emit = EmitKind::Ir;
5879        let result = run(
5880            &opts,
5881            concat!(
5882                "const char a[2][3] = { \"1234\", \"xyz\" };\n",
5883                "static const char b[3][5] = { \"12345\", \"678\", \"9\" };\n",
5884                "union u { struct { char x[4]; char y[4]; }; struct { char z[8]; }; };\n",
5885                "const union u c = { { \"1234\", \"567\" } };\n",
5886            ),
5887        );
5888        let text = result.text();
5889        assert_eq!(
5890            result.messages,
5891            ["/main.c:1:24: warning: initializer-string for array of 'const char' is too long \
5892              (5 chars into 3 available) [E0637]"]
5893        );
5894        assert!(text.contains("global @a : bytes 6 = { bytes \"123\", bytes \"xyz\" }"), "{text}");
5895        assert!(
5896            text.contains(
5897                "global @b : bytes 15 = { bytes \"12345\", bytes \"678\\00\", zero 1, \
5898                 bytes \"9\\00\", zero 3 }"
5899            ),
5900            "{text}"
5901        );
5902        // The eight bytes are four, three and a terminator, and then the byte the shorter
5903        // literal left for the string in the other member of the union to end at.
5904        assert!(
5905            text.contains("global @c : bytes 8 = { bytes \"1234\", bytes \"567\\00\" }"),
5906            "{text}"
5907        );
5908    }
5909
5910    #[test]
5911    fn a_cast_of_a_record_to_its_own_type_is_the_object_that_was_cast() {
5912        // gcc accepts one and does nothing with it, which sema already had. Lowering asked for
5913        // the object under it and had no arm for a cast, so `(struct s)x` in an initializer was
5914        // refused with E0519. It is one copy out of the object named, not two.
5915        let text = body(concat!(
5916            "struct s { int a, b; };\nstruct v { struct s s; int t; };\n",
5917            "void g(struct v *);\n",
5918            "void f(struct s *p) { struct v w = { (struct s)*p, 5 }; g(&w); }\n",
5919        ));
5920        assert_eq!(text.matches("memcpy").count(), 1, "{text}");
5921    }
5922
5923    #[test]
5924    fn a_compound_literal_read_in_a_static_initializer_lays_its_bytes_into_the_image() {
5925        // C 6.7.11p4 says a compound literal at file scope has static storage duration, which
5926        // makes it a constant element, and tcc and c-testsuite both write one. Sema used to call
5927        // it a non constant because reading it is a node of its own and the read was what it
5928        // looked at, and lowering had no way to put an object where it wanted a number.
5929        let text = ir(concat!(
5930            "struct s { int x; };\n",
5931            "struct t { struct s s; int o; } a = { (struct s){ 2 }, 3 };\n",
5932            "int n = (int){ 7 };\n",
5933            "struct u { struct s p; struct s q; } b = { (struct s){ 1 }, (struct s){ } };\n",
5934        ));
5935        assert!(text.contains("global @a : bytes 8 = { i32 2, i32 3 }"), "{text}");
5936        assert!(text.contains("global @n : i32 = 7,"), "{text}");
5937        // The second literal names nothing, so what it puts in is the zeros of its own size and
5938        // not the tail of the object it went in, which would have been the same bytes by luck.
5939        assert!(text.contains("global @b : bytes 8 = { i32 1, zero 4 }"), "{text}");
5940    }
5941
5942    #[test]
5943    fn the_address_of_a_compound_literal_asks_for_the_object_it_points_at() {
5944        // Nothing declares a compound literal, so the reference is the only thing that can ask
5945        // for it to be emitted. The image named `.Lanon.0` and the module defined no such
5946        // symbol, which the link would have been the first to find out.
5947        let text = ir("struct s { int x; };\nstruct s *q = &(struct s){ 9 };\n");
5948        assert!(text.contains("global @.Lanon.0 : i32 = 9, align 4, linkage(internal)"), "{text}");
5949        assert!(text.contains("global @q : bytes 8 = { addr.8 @.Lanon.0 }"), "{text}");
5950    }
5951
5952    #[test]
5953    fn an_object_of_no_size_at_all_has_an_image_with_nothing_in_it() {
5954        // A zero length array, which gcc allows and real code uses as the tail of a structure.
5955        // The image is there and holds nothing, which is not the global that has no image at
5956        // all, and the IR reader used to stop on the empty one.
5957        let text = ir("unsigned char foo[1][0];\n");
5958        assert!(text.contains("global @foo : bytes 0 = {}, align 1"), "{text}");
5959    }
5960
5961    #[test]
5962    fn a_null_pointer_in_an_image_is_the_bits_an_address_has_room_for() {
5963        // `NULL` in a static initializer, which every program has. The IR type is `ptr` and a
5964        // `ptr` has no width of its own, so the width the bits are cut to is the target's.
5965        let text = ir("void *p = 0;\nchar *q = (char *) 4096;\n");
5966        assert!(text.contains("global @p : i64 = 0, align 8"), "{text}");
5967        assert!(text.contains("global @q : i64 = 4096, align 8"), "{text}");
5968    }
5969
5970    #[test]
5971    fn an_object_another_module_defines_may_be_one_that_cannot_be_written_through() {
5972        // Which the verifier used to refuse, having read a declaration as a definition with
5973        // nothing in it. `extern const` is how a program names something in the library's read
5974        // only data, and glibc and Darwin both have one in a header a real program includes.
5975        let text = ir("extern const int limit;\nint f(void) { return limit; }\n");
5976        assert!(
5977            text.contains("global @limit : bytes 4, align 4, linkage(external), constant"),
5978            "{text}"
5979        );
5980    }
5981
5982    #[test]
5983    fn a_conditional_whose_value_is_an_object_answers_where_the_object_is() {
5984        // A structure is not a value in the IR, so the two arms cannot be joined as one. The
5985        // addresses can, and the answer is the address of whichever arm was taken rather than
5986        // a copy of it into a third place: both arms outlive the expression, so a copy would
5987        // be one nothing could observe. SQLite's parser writes one of these.
5988        let text = body(
5989            "\
5990struct s { int a, b; };
5991struct s pick(int c, struct s x, struct s y) { return c ? x : y; }
5992",
5993        );
5994        // The join takes an address, each arm hands it the one it has, and nothing is copied.
5995        assert!(text.contains("block3(%7: ptr)"), "{text}");
5996        assert!(text.contains("jump block3(%3)") && text.contains("jump block3(%4)"), "{text}");
5997        assert!(!text.contains("memcpy"), "the arms are joined rather than copied: {text}");
5998    }
5999
6000    /// GNU's `a ?: b` evaluates `a` once, and the arm answers the value that was tested.
6001    ///
6002    /// The checking keeps one node for `a` and converts it in two directions, to the bit the
6003    /// branch is taken on and to the type the whole expression has. Walking into the arm used to
6004    /// reach that node a second time and build a second copy of whatever it says, so `++i ?: 10`
6005    /// incremented twice and `f() ?: 10` called twice. Measured against gcc 16.2.0, which
6006    /// increments once.
6007    #[test]
6008    fn the_left_side_of_a_conditional_with_no_middle_is_evaluated_once() {
6009        let text = body("int f(int i) { return ++i ?: 10; }\n");
6010        assert!(text.contains("jump block3(%2)"), "the arm is the value that was tested: {text}");
6011        assert_eq!(text.matches("add.nsw").count(), 1, "incremented once: {text}");
6012
6013        // The arm still converts, since what the whole expression is worth is a `long` here and
6014        // the node under it is an `int`. What it converts is the value in hand.
6015        let text = body("long f(int i) { return ++i ?: 10L; }\n");
6016        assert!(text.contains("%5 = sext.i64 %2"), "the arm widens what was tested: {text}");
6017        assert_eq!(text.matches("add.nsw").count(), 1, "incremented once: {text}");
6018
6019        // A call, which is where evaluating twice is a wrong answer rather than a slow one.
6020        let text = body("int g(void);\nint f(void) { return g() ?: 10; }\n");
6021        assert_eq!(text.matches("call @g").count(), 1, "called once: {text}");
6022
6023        // Written out in full it is two reads of `i`, which is what C says it is, so the middle
6024        // operand being absent is the whole of the difference.
6025        let text = body("int f(int i) { return ++i ? ++i : 10; }\n");
6026        assert_eq!(text.matches("add.nsw").count(), 2, "incremented twice: {text}");
6027    }
6028
6029    #[test]
6030    fn a_structure_that_fits_in_registers_travels_as_the_registers_it_fits_in() {
6031        // `struct pair` is two eightbytes on SysV, one of them integer, so the signature says
6032        // one `i64` in each direction and the body takes the object apart and puts it back
6033        // together around the call.
6034        let text = ir("\
6035struct pair { int a, b; };
6036struct pair make(int a, int b);
6037struct pair twice(struct pair p) { return make(p.a, p.b); }
6038");
6039        assert!(text.contains("func @make(i32, i32) -> i64"), "{text}");
6040        assert!(text.contains("func @twice(i64) -> i64"), "{text}");
6041    }
6042
6043    #[test]
6044    fn a_structure_too_large_for_the_registers_travels_as_where_its_bytes_are() {
6045        // Over two eightbytes the caller passes the bytes in the argument area, which is
6046        // `byval`, and passes somewhere to write the return value, which is `sret`. Neither is
6047        // a parameter the program wrote and both are parameters the function has.
6048        let text = ir("\
6049struct big { double v[8]; };
6050struct big grow(struct big b);
6051struct big twice(struct big b) { return grow(grow(b)); }
6052");
6053        assert!(
6054            text.contains("func @grow(ptr sret(64, align 8), ptr byval(64, align 8))"),
6055            "{text}"
6056        );
6057        assert!(text.contains("block0(%0: ptr, %1: ptr):"), "{text}");
6058        // The inner call writes into a slot and the outer one reads the same slot, so the
6059        // object between the two calls is never copied anywhere.
6060        assert_eq!(text.matches("call @grow").count(), 2, "{text}");
6061    }
6062
6063    #[test]
6064    fn a_structure_passed_to_a_variadic_function_says_so_at_the_call() {
6065        // The bytes travel in the argument area the same way they would for a parameter, and
6066        // `printf` has no parameter there to say it on, so the call says it instead. The one
6067        // that fits in registers says nothing, because travelling as the registers it fits in
6068        // is what an argument does when nothing says otherwise.
6069        let text = ir("\
6070struct big { double v[8]; };
6071struct pair { int a, b; };
6072int p(const char *, ...);
6073int f(struct big b, struct pair q) { return p(\"\", 1, b, q); }
6074");
6075        assert!(
6076            text.contains("call @p(%4, %5, %2 byval(64, align 8), %6) : (ptr, ...) -> i32"),
6077            "{text}"
6078        );
6079    }
6080
6081    #[test]
6082    fn what_a_call_produced_is_somewhere_before_anything_is_read_out_of_it() {
6083        // `make(1, 2).b` has no object to read a member of until one is made, and what makes it
6084        // is a slot the returned registers are written to.
6085        let body = body(
6086            "\
6087struct pair { int a, b; };
6088struct pair make(int a, int b);
6089int second(void) { return make(1, 2).b; }
6090",
6091        );
6092        assert!(body.starts_with("block0:\n    %0 = alloca, size 8, align 4\n"), "{body}");
6093        assert!(body.contains("store %3 -> %0, align 4\n"), "{body}");
6094    }
6095
6096    #[test]
6097    fn a_structure_of_floats_travels_in_floating_point_registers_on_aarch64() {
6098        // The same declaration, classified by a different ABI: three `float` members are an
6099        // eightbyte of two of them and a half eightbyte of the third on SysV, and three vector
6100        // registers on AAPCS64.
6101        let source = "\
6102struct hfa { float x, y, z; };
6103int take(struct hfa h);
6104int give(struct hfa h) { return take(h); }
6105";
6106        assert!(ir(source).contains("func @take(f64, f32) -> i32"), "{}", ir(source));
6107        let mut opts = options();
6108        opts.emit = EmitKind::Ir;
6109        opts.target = "aarch64-unknown-linux-gnu".parse::<Triple>().unwrap();
6110        let result = run(&opts, source);
6111        assert_eq!(result.messages, Vec::<String>::new());
6112        assert!(result.text().contains("func @take(f32, f32, f32) -> i32"), "{}", result.text());
6113    }
6114
6115    #[test]
6116    fn an_array_whose_length_is_not_a_constant_is_a_slot_made_where_its_declaration_is() {
6117        // The size is a multiplication rather than a number, the slot is taken from the stack
6118        // where the declaration is, and the scope it was declared in gives it back.
6119        let source = "\
6120int use(int *);
6121void f(int n) {
6122  {
6123    int a[n];
6124    use(a);
6125  }
6126  use(0);
6127}
6128";
6129        let body = body(source);
6130        assert!(body.contains("mul.nsw"), "{body}");
6131        assert!(body.contains("stacksave"), "{body}");
6132        assert!(body.contains("alloca %"), "{body}");
6133        assert!(body.contains("stackrestore"), "{body}");
6134    }
6135
6136    #[test]
6137    fn a_goto_out_of_the_scope_of_one_gives_its_stack_back_on_the_way() {
6138        // The label is outside the block the array is in, so arriving there means the array is
6139        // gone, and the restore that says so goes in front of the branch. The `goto` is written
6140        // before the walk knows where the label is, which is why the restore is put there at
6141        // the end rather than built where the branch was.
6142        let source = "\
6143int use(int *);
6144int f(int n) {
6145  {
6146    int a[n];
6147    if (use(a)) goto out;
6148    use(0);
6149  }
6150out:
6151  return 0;
6152}
6153";
6154        let body = body(source);
6155        // Two ways out of the block and a restore on each: the jump and the end of the block.
6156        assert_eq!(body.matches("stackrestore").count(), 2, "{body}");
6157        let (_, after) = body.split_once("stackrestore").expect("the stack is given back");
6158        assert!(after.starts_with(" %4\n    jump block"), "{body}");
6159    }
6160
6161    #[test]
6162    fn a_goto_to_a_label_the_array_is_still_alive_at_leaves_the_stack_alone() {
6163        // The label is after the declaration and in the same block, so control that arrives
6164        // there arrives somewhere the array exists. Giving it back would be giving back an
6165        // object the next statement reads.
6166        let source = "\
6167int use(int *);
6168int f(int n) {
6169  int a[n];
6170again:
6171  if (use(a)) goto again;
6172  return 0;
6173}
6174";
6175        let body = body(source);
6176        assert!(body.contains("stacksave"), "{body}");
6177        assert!(!body.contains("stackrestore"), "{body}");
6178    }
6179
6180    #[test]
6181    fn a_goto_back_to_a_label_in_front_of_one_gives_it_back_every_time_round() {
6182        // A loop written out of a `goto`, with the array made inside it. The label is in the
6183        // same block as the declaration and before it, which is a place where the array does
6184        // not exist yet, so the jump there leaves its scope and has to give the stack back. A
6185        // compiler that skips this restore grows the stack once per iteration.
6186        let source = "\
6187int use(int *);
6188int f(int n) {
6189again:
6190  {
6191    int a[n];
6192    if (use(a)) goto again;
6193  }
6194  return 0;
6195}
6196";
6197        let body = body(source);
6198        assert_eq!(body.matches("stacksave").count(), 1, "{body}");
6199        let (_, after) = body.split_once("stackrestore").expect("the stack is given back");
6200        assert!(after.starts_with(" %4\n    jump block1\n"), "{body}");
6201    }
6202
6203    #[test]
6204    fn the_head_of_a_for_loop_is_a_scope_that_closes_where_the_loop_is_left() {
6205        // The scope opened for `for (int a[n];;)` used to stay open, and a scope left open is
6206        // not one mark nobody reads. The marks are a stack, so the next close took this one
6207        // instead of its own, and the body of the loop gave back nothing while the block after
6208        // the loop restored a pointer saved inside it. The verifier refused that, which is how
6209        // it was found.
6210        let source = "\
6211int f(void);
6212void t(void) {
6213  int count = 10;
6214  for (; count--;) {
6215    int b[f()];
6216    int i;
6217    for (i = 0; i < f(); i++) {
6218      b[i] = count;
6219    }
6220  }
6221}
6222";
6223        let body = body(source);
6224        // One save, in the body, and one restore for it, also in the body: the block the
6225        // restore is in is the one the inner loop leaves through, and it goes back round the
6226        // outer loop rather than out of it.
6227        assert_eq!(body.matches("stacksave").count(), 1, "{body}");
6228        let (_, after) = body.split_once("stackrestore").expect("the stack is given back");
6229        // The rest of the block the restore is in, which is the last block here, so there is not
6230        // always another one after it to split on.
6231        let next = after.split("\n\n").next().expect("the block the restore is in");
6232        assert!(next.contains("jump block1("), "{body}");
6233    }
6234
6235    #[test]
6236    fn how_long_one_of_those_is_was_decided_where_it_was_declared_and_not_where_it_is_asked() {
6237        // What C says about the length being evaluated once: `sizeof a` after `n` changed is
6238        // still as long as the array is, which is what `n` was when the array came into being.
6239        let source = "\
6240unsigned long f(int n) {
6241  int a[n];
6242  n = 0;
6243  return sizeof a;
6244}
6245";
6246        let body = body(source);
6247        // One read of the parameter, at the declaration, and the answer is built out of it.
6248        assert_eq!(body.matches("sext.i64 %0").count(), 2, "{body}");
6249    }
6250
6251    #[test]
6252    fn a_block_in_the_middle_of_an_expression_is_walked_where_the_expression_is() {
6253        // GNU's statement expression: the statements happen where they are written and the last
6254        // one is the value, so the temporary in it never becomes a slot and never is copied.
6255        let source = "\
6256int use(int);
6257int f(int x) {
6258  return ({
6259    int t = use(x);
6260    t * t;
6261  });
6262}
6263";
6264        let expected = "\
6265block0(%0: i32):
6266    %1 = call @use(%0) : (i32) -> i32
6267    %2 = mul.nsw %1, %1
6268    return %2
6269";
6270        assert_eq!(body(source), expected);
6271    }
6272
6273    #[test]
6274    fn one_of_those_that_control_never_leaves_is_lowered_and_what_follows_it_is_dropped() {
6275        // A macro that always jumps, which is what this shape is in real code. The value is
6276        // never taken, and the block the rest of the expression would have been built in is
6277        // one nothing branches to, so it goes with the other unreachable blocks.
6278        let source = "int f(int x) { return ({ return x; 0; }); }\n";
6279        assert_eq!(body(source), "block0(%0: i32):\n    return %0\n");
6280    }
6281
6282    #[test]
6283    fn one_argument_off_a_variable_argument_list_stays_an_intrinsic() {
6284        // What it becomes is the target's answer, and this is not where the target's answers
6285        // are, so the walk writes down which list and which type and leaves it at that. Two of
6286        // them are two instructions, since each moves the list on.
6287        let source = "double f(__builtin_va_list ap) { return __builtin_va_arg(ap, double) + __builtin_va_arg(ap, double); }\n";
6288        let expected = "\
6289block0(%0: ptr):
6290    %1 = va_arg.f64 %0
6291    %2 = va_arg.f64 %0
6292    %3 = fadd %1, %2
6293    return %3
6294";
6295        assert_eq!(body(source), expected);
6296    }
6297
6298    #[test]
6299    fn one_that_reads_a_structure_answers_where_the_object_is() {
6300        // An aggregate is not a value, so there is nothing for the result of `va_arg` to be and
6301        // the object form is a second instruction. What it answers is an address, so it is a
6302        // place already and the walk copies nothing out of it: the copy here is the one the
6303        // initializer asks for, into the variable being declared. The size and the alignment
6304        // travel with it because they are what steps the list on and what a target that has to
6305        // put registers somewhere needs to know. So does the classification, which says the two
6306        // halves of this one arrived in general purpose registers: that is an answer about a C
6307        // type, and this is the last place that still has one.
6308        //
6309        // The slot is aligned to sixteen and the copy into it to eight, which is not a
6310        // disagreement. Sixteen is what a local aggregate of sixteen bytes gets whatever its
6311        // members ask for, and eight is what the type asks for and so what the copy may assume
6312        // about the object it is reading from.
6313        let source = "\
6314struct s { int a; long b; };
6315long f(__builtin_va_list ap) { struct s v = __builtin_va_arg(ap, struct s); return v.b; }
6316";
6317        let expected = "\
6318block0(%0: ptr):
6319    %1 = alloca, size 16, align 16
6320    %2 = va_object %0, size 16, align 8, in(int 8 at 0, int 8 at 8)
6321    memcpy %1, %2, size 16, align 8
6322    %3 = iconst.i64 8
6323    %4 = ptr_add %1, %3
6324    %5 = load.i64 %4, align 8, tbaa !1
6325    return %5
6326";
6327        assert_eq!(body(source), expected);
6328    }
6329
6330    /// Which register file each eightbyte arrived in is the whole of what the classification adds,
6331    /// and an object with no slots at all is one it sent to the caller's argument area, which is
6332    /// what everything over two eightbytes is whatever its members are.
6333    #[test]
6334    fn the_classification_says_which_registers_the_object_arrived_in() {
6335        let source = "\
6336struct s { double a; double b; };
6337double f(__builtin_va_list ap) { struct s v = __builtin_va_arg(ap, struct s); return v.a; }
6338";
6339        assert!(
6340            body(source)
6341                .contains("va_object %0, size 16, align 8, in(float f64 at 0, float f64 at 8)"),
6342            "{}",
6343            body(source)
6344        );
6345
6346        let big = "\
6347struct s { long a[4]; };
6348long f(__builtin_va_list ap) { struct s v = __builtin_va_arg(ap, struct s); return v.a[0]; }
6349";
6350        assert!(body(big).contains("va_object %0, size 32, align 8\n"), "{}", body(big));
6351    }
6352
6353    #[test]
6354    fn a_jump_to_an_address_branches_to_every_label_the_function_takes_the_address_of() {
6355        // GNU's computed goto. Which label the address holds is not known here, so all of them
6356        // are listed, and the values arriving at one are passed on every edge the same way they
6357        // are on an ordinary branch.
6358        let source = "\
6359int f(int c) {
6360  void *p = c ? &&one : &&two;
6361  goto *p;
6362one:
6363  return 1;
6364two:
6365  return 2;
6366}
6367";
6368        let expected = "\
6369block0(%0: i32):
6370    %1 = iconst.i32 0
6371    %2 = icmp ne %0, %1
6372    br_if %2, block1, block2
6373
6374block1:
6375    %3 = block_addr block3
6376    jump block4(%3)
6377
6378block2:
6379    %4 = block_addr block5
6380    jump block4(%4)
6381
6382block3:
6383    %5 = iconst.i32 1
6384    return %5
6385
6386block4(%6: ptr):
6387    indirect_br %6, block3, block5
6388
6389block5:
6390    %7 = iconst.i32 2
6391    return %7
6392";
6393        assert_eq!(body(source), expected);
6394    }
6395
6396    #[test]
6397    fn a_jump_to_an_address_no_label_in_the_function_has_arrives_nowhere() {
6398        // The address came from outside the function, and a jump to a label in another function
6399        // is undefined. The expression is still evaluated, since a call in it has to happen.
6400        let source = "void **next(void);
6401void f(void) { goto *next(); }
6402";
6403        let expected = "\
6404block0:
6405    %0 = call @next() : () -> ptr
6406    unreachable
6407";
6408        assert_eq!(body(source), expected);
6409    }
6410
6411    #[test]
6412    fn an_asm_with_no_operands_is_volatile_and_the_clobbers_are_the_whole_of_what_it_says() {
6413        // Nothing reads a result, so the only thing that keeps it is that it is volatile, which
6414        // a basic asm implies.
6415        let source = "void f(void) { __asm__(\"mfence\" ::: \"memory\"); }\n";
6416        let expected = "\
6417block0:
6418    inline_asm.volatile \"mfence\", \"\", \"memory\"()
6419    return
6420";
6421        assert_eq!(body(source), expected);
6422    }
6423
6424    #[test]
6425    fn the_constraints_are_one_list_in_the_order_the_template_counts_the_operands() {
6426        // The outputs first and then the inputs, which is the numbering `%0` and `%1` use. An
6427        // output in a register is a result, and one that is read as well is an argument too.
6428        let source = "\
6429int f(int x, int y) {
6430  int r;
6431  __asm__(\"addl %2, %0\" : \"=r\"(r), \"+r\"(y) : \"r\"(x));
6432  return r + y;
6433}
6434";
6435        let expected = "\
6436block0(%0: i32, %1: i32):
6437    %2, %3 = inline_asm.(i32, i32) \"addl %2, %0\", \"=r,+r,r\", \"\"(%1, %0)
6438    %4 = add.nsw %2, %3
6439    return %4
6440";
6441        assert_eq!(body(source), expected);
6442    }
6443
6444    #[test]
6445    fn a_memory_operand_travels_as_the_address_of_an_object_that_is_given_a_slot() {
6446        // The assembly is handed a pointer, so the object cannot live in a value, and the scan
6447        // that runs before the walk has to have known that or there would be nothing to point
6448        // at. A structure travels this way whatever else its constraint allows, since there is
6449        // no register that holds one.
6450        let source = "\
6451struct pair { int a, b; };
6452int f(int x) {
6453  int slot = x;
6454  struct pair p = { x, x };
6455  __asm__(\"incl %0\" : \"+m\"(slot), \"=m\"(p));
6456  return slot + p.a;
6457}
6458";
6459        let text = body(source);
6460        assert!(text.contains("inline_asm \"incl %0\", \"+m,=m\", \"\"(%1, %2)\n"), "{text}");
6461        assert!(text.contains("%1 = alloca, size 4, align 4\n"), "{text}");
6462        assert!(text.contains("%2 = alloca, size 8, align 4\n"), "{text}");
6463    }
6464
6465    #[test]
6466    fn an_asm_goto_falls_through_to_its_first_target_and_writes_its_outputs_there() {
6467        // The output is only in scope where the instruction dominates, which is the fall through
6468        // block, so the edge to the label carries the value the object had before the assembly
6469        // ran. That is what document 11 asks for and it is what putting the fall through first
6470        // buys.
6471        let source = "\
6472int f(int x) {
6473  int r = 7;
6474  __asm__ goto(\"cbnz %0, %l1\" : \"=r\"(r) : \"r\"(x) :: away);
6475  return r;
6476away:
6477  return r;
6478}
6479";
6480        let expected = "\
6481block0(%0: i32):
6482    %1 = iconst.i32 7
6483    %2 = inline_asm.volatile \"cbnz %0, %l1\", \"=r,r\", \"\"(%0), labels [block1, block2]
6484
6485block1:
6486    return %2
6487
6488block2:
6489    return %1
6490";
6491        assert_eq!(body(source), expected);
6492    }
6493
6494    #[test]
6495    fn an_asm_statement_that_is_not_well_formed_is_reported_in_the_words_gcc_uses() {
6496        // The operands are checked here rather than by the assembler, because by the time the
6497        // assembler sees the template the operands have become registers and it has nothing left
6498        // to say about the C that named them.
6499        let mut opts = options();
6500        opts.emit = EmitKind::Ir;
6501        for (source, expected) in [
6502            (
6503                "void f(int x) { __asm__(\"\" : \"r\"(x)); }\n",
6504                "output operand constraint lacks '='",
6505            ),
6506            (
6507                "void f(int x) { __asm__(\"\" : \"=r\"(x + 1)); }\n",
6508                "lvalue required in 'asm' statement",
6509            ),
6510            (
6511                "const int g = 1;\nvoid f(void) { __asm__(\"\" : \"=r\"(g)); }\n",
6512                "read-only variable 'g' used as 'asm' output",
6513            ),
6514            (
6515                "void f(int x) { __asm__(\"\" : : \"=r\"(x)); }\n",
6516                "input operand constraint contains '='",
6517            ),
6518            (
6519                "void f(void) { __asm__(\"\" : : \"m\"(1)); }\n",
6520                "memory input 0 is not directly addressable",
6521            ),
6522            ("void f(void) { __asm__(L\"\"); }\n", "wide string literal in 'asm'"),
6523            (
6524                "void f(int x, int y) { __asm__(\"\" : [a] \"=r\"(x) : [a] \"r\"(y)); }\n",
6525                "duplicate asm operand name 'a'",
6526            ),
6527            ("void f(int x) { __asm__(\"%[in]\" : \"=r\"(x)); }\n", "undefined named operand 'in'"),
6528        ] {
6529            let result = run(&opts, source);
6530            assert!(result.failed(), "expected this to be reported:\n{source}");
6531            assert!(
6532                result.messages.iter().any(|m| m.contains(expected)),
6533                "{expected}\n{:?}",
6534                result.messages
6535            );
6536        }
6537    }
6538
6539    /// An `asm` at file scope whose template is directives is the whole of what the incbin
6540    /// header, an alias table and a hand written jump table each write, and what it says is a
6541    /// section holding named bytes. So it becomes the globals it names, in the order it names
6542    /// them, which is what `spec/11-asm-objects-debug.md` section 11.2 asks for.
6543    #[test]
6544    fn an_asm_at_file_scope_that_is_directives_becomes_the_objects_it_defines() {
6545        let text = ir(concat!(
6546            "__asm__(\n",
6547            "  \".section .rodata\\n\"\n",
6548            "  \".globl first\\n\"\n",
6549            "  \".balign 8\\n\"\n",
6550            "  \"first:\\n\"\n",
6551            "  \".long 1\\n\"\n",
6552            "  \".long 2\\n\"\n",
6553            "  \".globl last\\n\"\n",
6554            "  \"last:\\n\"\n",
6555            "  \".quad last - first\\n\");\n",
6556            "extern const int first[];\n",
6557            "extern const long last;\n",
6558        ));
6559        assert!(text.contains("global @first : bytes 8 = { i32 1, i32 2 }, align 8"), "{text}");
6560        assert!(text.contains("global @last : i64 = 8"), "{text}");
6561    }
6562
6563    /// The distance between two labels is what the incbin header hands a program as the size of
6564    /// the data, so a declaration of one of the names has to find the definition the template
6565    /// made rather than turn it back into something the linker is asked for.
6566    #[test]
6567    fn a_name_an_asm_at_file_scope_defined_is_not_undone_by_a_declaration_of_it() {
6568        let text = ir(concat!(
6569            "__asm__(\".data\\n.globl counter\\ncounter:\\n.long 7\\n\");\n",
6570            "extern int counter;\n",
6571            "int read(void) { return counter; }\n",
6572        ));
6573        assert!(text.contains("global @counter : i32 = 7"), "{text}");
6574    }
6575
6576    /// `.incbin` is the one directive that reads something, and what it reads comes through the
6577    /// same file system the sources did.
6578    #[test]
6579    fn an_incbin_at_file_scope_is_the_bytes_of_the_file_it_names() {
6580        let mut opts = options();
6581        opts.emit = EmitKind::Ir;
6582        let mut fs = MemoryFileSystem::new();
6583        fs.insert(
6584            "/main.c",
6585            b"__asm__(\".data\\n.globl blob\\nblob:\\n.incbin \\\"seed\\\"\\n\");\n".to_vec(),
6586        );
6587        fs.insert("seed", b"hi".to_vec());
6588        let result = compile(&opts, "/main.c", &fs);
6589        assert_eq!(result.messages, Vec::<String>::new());
6590        let text = result.text();
6591        assert!(text.contains("global @blob : bytes 2 = { bytes \"hi\" }"), "{text}");
6592    }
6593
6594    /// A file that is not there is the mistake a build makes when it runs the compiler from the
6595    /// wrong directory, and it is worth saying which file rather than saying the template failed.
6596    #[test]
6597    fn an_incbin_naming_a_file_that_is_not_there_says_which_file() {
6598        let messages = errors("__asm__(\".data\\nb:\\n.incbin \\\"nowhere\\\"\\n\");\n");
6599        assert!(
6600            messages
6601                .iter()
6602                .any(|m| m.contains("cannot open 'nowhere' for reading") && m.contains("E0702")),
6603            "{messages:?}"
6604        );
6605    }
6606
6607    /// The line drawn is the same one the `asm` inside a function draws: directives are read and
6608    /// an instruction waits for an assembler. Refusing by name is what makes the wait visible.
6609    #[test]
6610    fn an_instruction_in_an_asm_at_file_scope_is_refused_rather_than_ignored() {
6611        for source in [
6612            "__asm__(\".text\\n.globl f\\nf:\\n  ret\\n\");\n",
6613            "__asm__(\".data\\n.set alias, 4\\n\");\n",
6614        ] {
6615            let messages = errors(source);
6616            assert!(
6617                messages
6618                    .iter()
6619                    .any(|m| m.contains("not supported yet")
6620                        && m.contains("in an `asm` at file scope")),
6621                "{source}\n{messages:?}"
6622            );
6623        }
6624    }
6625
6626    #[test]
6627    fn what_the_walk_cannot_build_yet_is_reported_rather_than_mislowered() {
6628        let mut opts = options();
6629        opts.emit = EmitKind::Ir;
6630        for source in [
6631            "int f(int n) { void *p = &&out; if (n) goto *p; { int a[n]; out: return 1; } }\n",
6632            "int f(int n) { int a[n]; __asm__ goto(\"\" ::::out); out: return a[0]; }\n",
6633        ] {
6634            let result = run(&opts, source);
6635            assert!(result.failed(), "expected this to be reported:\n{source}");
6636            assert!(
6637                result.messages.iter().any(|m| m.contains("not supported yet")),
6638                "{:?}",
6639                result.messages
6640            );
6641        }
6642    }
6643
6644    /// Compiles `source` to IR, reads that back as an input, and gives back both texts.
6645    fn round_trip(source: &str) -> (String, String) {
6646        let printed = ir(source);
6647        let mut opts = options();
6648        opts.emit = EmitKind::Ir;
6649        let mut fs = MemoryFileSystem::new();
6650        fs.insert("/main.ir", printed.clone().into_bytes());
6651        let result = compile_ir(&opts, "/main.ir", &fs);
6652        assert_eq!(result.messages, Vec::<String>::new(), "expected this to read back:\n{printed}");
6653        (printed, result.text().to_owned())
6654    }
6655
6656    #[test]
6657    fn ir_that_arrives_as_an_input_is_read_back_and_written_out_the_same() {
6658        // The other half of the round trip test below, through the driver rather than through
6659        // the library, which is what makes the property something to run over a real program
6660        // rather than over the modules a test builds.
6661        let (printed, again) = round_trip(
6662            "struct point { int x, y; };\n             static const char greeting[] = \"hi\";\n             int puts(const char *);\n             int f(int n) { struct point p = { n, 1 }; puts(greeting); return p.x; }\n",
6663        );
6664        assert_eq!(printed, again);
6665    }
6666
6667    #[test]
6668    fn ir_that_is_not_ir_says_which_line_stopped_it() {
6669        let mut opts = options();
6670        opts.emit = EmitKind::Ir;
6671        let mut fs = MemoryFileSystem::new();
6672        let text = "\
6673; ModuleID = 'a.c'
6674; format 0
6675target triple = \"x86_64-unknown-linux-gnu\"
6676target datalayout = \"e-p:64:64-i64:64-S128\"
6677
6678func @f(), linkage(external) {
6679block0:
6680    frobnicate
6681}
6682";
6683        fs.insert("/main.ir", text.as_bytes().to_vec());
6684        let result = compile_ir(&opts, "/main.ir", &fs);
6685        assert!(result.failed());
6686        assert!(result.messages[0].contains("/main.ir:8"), "{:?}", result.messages);
6687    }
6688
6689    #[test]
6690    fn ir_that_reads_but_does_not_hold_together_is_reported_by_the_verifier() {
6691        // A module that a person edited has not been through the verifier, and the return of
6692        // an `i32` from a function that returns nothing is the kind of thing editing produces.
6693        let mut opts = options();
6694        opts.emit = EmitKind::Ir;
6695        let mut fs = MemoryFileSystem::new();
6696        let text = "\
6697; ModuleID = 'a.c'
6698; format 0
6699target triple = \"x86_64-unknown-linux-gnu\"
6700target datalayout = \"e-p:64:64-i64:64-S128\"
6701
6702func @f(), linkage(external) {
6703block0:
6704    %0 = iconst.i32 1
6705    return %0
6706}
6707";
6708        fs.insert("/main.ir", text.as_bytes().to_vec());
6709        let result = compile_ir(&opts, "/main.ir", &fs);
6710        assert!(result.failed());
6711        assert!(result.messages[0].contains("invalid IR"), "{:?}", result.messages);
6712    }
6713
6714    #[test]
6715    fn a_typed_tree_is_not_something_an_input_of_ir_can_produce() {
6716        // The C that became this is not here any more, so there is nothing to print a tree of.
6717        let mut fs = MemoryFileSystem::new();
6718        fs.insert("/main.ir", Vec::new());
6719        let result = compile_ir(&options(), "/main.ir", &fs);
6720        assert!(result.failed());
6721        assert!(result.messages[0].contains("can only be emitted as IR"), "{:?}", result.messages);
6722    }
6723
6724    #[test]
6725    fn the_printed_ir_reads_back_as_the_same_module() {
6726        // The M2 exit criterion: the text is the module and nothing about it is lost by
6727        // writing it down. Anything the printer invents or the parser drops shows up here.
6728        let text = ir("\
6729struct point { int x, y; };
6730static const char greeting[] = \"hi\";
6731int table[4] = { 1, 2, 3 };
6732int puts(const char *);
6733double half(double x) { return x / 2.0; }
6734int f(int n) {
6735  int total = 0;
6736  for (int i = 0; i < n; i++) {
6737    if (i == 3) continue;
6738    total += table[i];
6739  }
6740  switch (n) {
6741    case 0: total = 1;
6742    case 1: total++; break;
6743    default: total = -total;
6744  }
6745  struct point p = { total, 1 };
6746  int *q = &p.y;
6747  puts(greeting);
6748  return p.x + *q;
6749}
6750int dispatch(int c) {
6751  void *p = c ? &&one : &&two;
6752  goto *p;
6753one:
6754  return 1;
6755two:
6756  return 2;
6757}
6758int assembly(int x, int *p) {
6759  int r;
6760  __asm__ volatile(\"xadd %0, %2\" : \"=r\"(r), \"+m\"(*p) : \"0\"(x) : \"cc\");
6761  __asm__ goto(\"cbnz %0, %l1\" : : \"r\"(r) : : away);
6762  return r;
6763away:
6764  return 0;
6765}
6766");
6767        let mut names = Interner::new();
6768        let module = rucc_ir::parse(&text, &mut names).expect("the printer writes what it reads");
6769        assert_eq!(rucc_ir::print(&module, &names), text);
6770    }
6771
6772    #[test]
6773    fn what_save_temps_keeps_is_the_text_that_was_compiled_and_the_assembly_that_was_assembled() {
6774        // The point of the flag is that these two are the compilation rather than a description
6775        // of one, so both come out of the run that produced the object rather than out of a
6776        // second run under different flags.
6777        let mut opts = options();
6778        opts.emit = EmitKind::Object;
6779        opts.save_temps = rucc_session::SaveTemps::Object;
6780        let result = run(&opts, "#define N 2\nint a[N];\n");
6781        assert_eq!(result.messages, Vec::<String>::new());
6782        let text = result.temps.preprocessed.expect("the preprocessed text");
6783        assert!(text.contains("int a[2];"), "{text}");
6784        assert!(text.starts_with("# 1 \"/main.c\""), "{text}");
6785        let asm = result.temps.assembly.expect("the assembly");
6786        assert!(asm.contains("a:"), "{asm}");
6787        assert!(matches!(result.artifact, Artifact::Object { .. }), "{:?}", result.artifact);
6788    }
6789
6790    #[test]
6791    fn nothing_is_kept_unless_the_flag_asked_for_it() {
6792        // A compilation that was not asked to keep anything must not pay for printing text
6793        // nobody will read, and the empty value is what says so.
6794        let mut opts = options();
6795        opts.emit = EmitKind::Object;
6796        assert_eq!(run(&opts, "int a;\n").temps, Temps::default());
6797    }
6798
6799    #[test]
6800    fn a_compilation_that_stops_before_the_back_end_keeps_the_text_and_no_assembly() {
6801        // `--emit=ir` never produces any, and the text is worth keeping all the same: it is
6802        // what a report about the file being read wrongly has to have in it.
6803        let mut opts = options();
6804        opts.emit = EmitKind::Ir;
6805        opts.save_temps = rucc_session::SaveTemps::Cwd;
6806        let result = run(&opts, "int a;\n");
6807        assert!(result.temps.preprocessed.is_some());
6808        assert_eq!(result.temps.assembly, None);
6809    }
6810}