Skip to main content

rucc_driver/
lib.rs

1//! The driver: command line parsing, the phase graph, job scheduling and the linker
2//! invocation.
3//!
4//! Design: `spec/04-driver-and-cli.md`. Layer rank 13, see `spec/18-package-layout.md`.
5//!
6//! This is the only crate that is allowed to know the process exists. It reads the command
7//! line, touches the file system, spawns the linker and writes to the terminal, and it hands
8//! everything below it a [`Session`]. The binary crate is a `main` that calls
9//! [`run`] and nothing else, so that the whole driver is reachable from a test.
10//!
11//! # Status
12//!
13//! `--help`, `--version` and `--print-config` are real, which is the `M0` exit criterion in
14//! `spec/17-milestones.md`. The phase graph is real and `-###` prints it, and the scheduler
15//! that will run it is real and tested.
16//!
17//! Two phases run. `-E` reads the file, runs phase 4 over it and writes the result, to `-o` or
18//! to standard output. `--emit=tast` carries on through phase 7, the parse and the checking,
19//! and writes the typed tree. The flags those two read are real with them, which is `-D`, `-U`,
20//! `-I`, `-I-`, `-iquote`, `-isystem`, `-idirafter`, `-iprefix`, `-iwithprefix`,
21//! `-iwithprefixbefore`, `-include`, `-imacros`, `--sysroot=`, `-isysroot`, `-P`, `-std=`,
22//! `-fgnuc-version=`, `-ansi`, `-ffreestanding`, `-fno-builtin`, `-fno-builtin-<name>`,
23//! `-fgnu89-inline`, `-pedantic` and `-Werror`.
24//! The phases after them still say they are not implemented.
25//!
26//! This crate is tier 3 in `spec/18-package-layout.md` section 18.5: its Rust API is
27//! explicitly unstable and will change without a major version bump.
28
29#![doc(html_root_url = "https://docs.rs/rucc-driver/0.10.52")]
30
31pub mod assemble;
32pub mod cache;
33pub mod compile;
34pub mod deps;
35pub mod fetch;
36mod glibc;
37pub mod install;
38pub mod library;
39pub mod link;
40mod map;
41pub mod phase;
42pub mod preprocess;
43pub mod schedule;
44
45use std::fmt::Write as _;
46use std::io::Write as _;
47use std::path::PathBuf;
48
49use rucc_codegen::coverage::{self, Fired};
50use rucc_codegen::lowering::Lowerings;
51use rucc_codegen::pressure::Pressure;
52use rucc_pp::Dependency;
53use rucc_session::{
54    Compress, Control, Dumps, EmitKind, Hook, Options, Pic, PrefixMap, Preinclude, Protector,
55    SaveTemps, Session, Std, Wrapping, runtime,
56};
57use rucc_sysroot::{Manifest, Sysroot};
58use rucc_target::{ObjectFormat, Triple};
59use rucc_tuple::TargetTuple;
60
61use crate::link::LinkOptions;
62
63pub use crate::assemble::assemble;
64pub use crate::compile::{Artifact, Compiled, Temps, compile, compile_ir};
65pub use crate::phase::{ArchiveJob, Input, InputKind, Job, LinkJob, Output, Phase, Plan, Role};
66pub use crate::preprocess::{OsFileSystem, Preprocessed, preprocess};
67pub use crate::schedule::Jobs;
68
69/// The compiler's version, taken from the workspace manifest.
70pub const VERSION: &str = env!("CARGO_PKG_VERSION");
71
72/// What the command line asked for.
73#[derive(Debug, Clone, PartialEq, Eq)]
74pub enum Action {
75    /// Print usage and exit successfully.
76    Help,
77    /// Print the version and exit successfully.
78    Version,
79    /// Print one line and exit successfully, which is what the `-dump` and `-print` family do.
80    ///
81    /// A build system asks these before it compiles anything, and what it does with the answer
82    /// is paste it into a path or into another command line, so each one is a single line with
83    /// no decoration around it.
84    Print(String),
85    /// Print the resolved configuration and exit successfully.
86    PrintConfig(Box<Options>),
87    /// Print the passes the level will run and exit successfully.
88    PrintPipeline(Box<Options>),
89    /// Print the phase plan and the link line and exit successfully, which is `-###`.
90    PrintPlan {
91        /// The resolved options, which is what says what the link line is for.
92        opts: Box<Options>,
93        /// What to do to each input, and in what order.
94        plan: Box<Plan>,
95        /// What the command line said about linking.
96        link: Box<LinkOptions>,
97    },
98    /// `--fetch <tuple>`, which gets the sysroot this release pins for a target and installs it.
99    ///
100    /// The only action in this compiler that may run another program to move bytes onto the
101    /// machine, which is `spec/cross-compile/13-distribution.md` section 13.8's rule rather than a
102    /// property of how this happens to be written: a compilation has no branch that reaches it.
103    Fetch {
104        /// The artifact, from the table in [`rucc_sysroot::artifact`]. Resolved here rather than where the
105        /// work happens, so that a target nothing is pinned for is a refusal from the parser like
106        /// every other thing a command line can ask for and not have.
107        what: &'static rucc_sysroot::Pinned,
108        /// The target, which names the directory under the cache the tree is installed at and is
109        /// checked against the record inside the artifact.
110        target: TargetTuple,
111        /// Where the cache is, read where everything else that needs it reads it.
112        cache: PathBuf,
113    },
114    /// Compile the given inputs.
115    Compile {
116        /// The resolved options.
117        opts: Box<Options>,
118        /// What to do to each input, and in what order.
119        plan: Box<Plan>,
120        /// What the command line said about linking.
121        link: Box<LinkOptions>,
122        /// How many translation units to compile at once.
123        jobs: Jobs,
124        /// Whether `-v` asked for the plan to be printed while it runs.
125        verbose: bool,
126        /// What is worth saying about the command line before anything is compiled, printed as
127        /// warnings and once for the whole run rather than once per file.
128        ///
129        /// These are not diagnostics. A diagnostic is about a piece of source and has a span to
130        /// point at, and these are about the way two flags were combined, so there is nothing to
131        /// point at and nowhere below the driver that knows both halves. `-w` does not reach them
132        /// for the same reason it does not reach a refusal from the parser.
133        notes: Vec<String>,
134    },
135}
136
137/// Why a command line was rejected.
138#[derive(Debug, Clone, PartialEq, Eq)]
139pub struct CliError {
140    /// The message, lowercase and without a trailing period, in the same shape as any other
141    /// diagnostic.
142    pub message: String,
143}
144
145impl std::fmt::Display for CliError {
146    fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
147        f.write_str(&self.message)
148    }
149}
150
151impl std::error::Error for CliError {}
152
153fn err(message: impl Into<String>) -> CliError {
154    CliError { message: message.into() }
155}
156
157/// The two halves of one prefix mapping flag's argument, where `flag` includes its trailing `=`.
158///
159/// The split is at the last `=` in what follows the flag, not the first, which is gcc's rule and
160/// the only one that lets a directory whose name contains an `=` be the old half. It also means
161/// `-fmacro-prefix-map=a=b=c` rewrites `a=b` to `c` rather than `a` to `b=c`, which looks like a
162/// trap until you notice the alternative traps the far more common case.
163fn rewrite<'a>(arg: &'a str, flag: &str) -> Result<(&'a str, &'a str), CliError> {
164    let rest = &arg[flag.len()..];
165    PrefixMap::split(rest).ok_or_else(|| {
166        let flag = flag.trim_end_matches('=');
167        err(format!(
168            "`{rest}` is not a rewrite for `{flag}`, which is an old prefix, an `=` and a new one"
169        ))
170    })
171}
172
173/// A question the command line asked instead of asking for a compilation.
174///
175/// These are answered after the loop rather than where they are read, because every one of them
176/// is about the target or about the library search and the last word on both is the end of the
177/// command line.
178enum Query {
179    /// `-dumpmachine`, the triple.
180    Machine,
181    /// `-dumpversion` and `-dumpfullversion`, which are the same three numbers here.
182    Version,
183    /// `-print-multiarch`, the directory name a distribution files this target under.
184    Multiarch,
185    /// `-print-search-dirs`, in the three lines GCC prints.
186    SearchDirs,
187    /// `-print-sysroot`, the root the headers and the libraries are read under.
188    Sysroot,
189    /// `-print-sysroot-provenance`, what is in that root and where each of it came from.
190    SysrootProvenance,
191    /// `-print-sysroot-digest`, the one number that names all of it.
192    SysrootDigest,
193    /// `-print-file-name=<name>`, the full path of a library file.
194    FileName(String),
195    /// `-print-prog-name=<name>`, the full path of a program.
196    ProgName(String),
197    /// `-print-libgcc-file-name`, which is `-print-file-name=libgcc.a` under another spelling.
198    Libgcc,
199}
200
201/// Usage text.
202///
203/// Deliberately short. `spec/04-driver-and-cli.md` puts the full flag reference in the
204/// manual page, because a `--help` nobody can read in one screen is a `--help` nobody reads.
205pub const USAGE: &str = "\
206rucc, an optimizing C compiler
207
208usage: rucc [options] file...
209
210options:
211  -c                     compile and assemble, do not link
212  -S                     compile only, emit assembly
213  -E                     preprocess only
214  -o <file>              write output to <file>, or to standard output for -
215  -D <name>[=<value>], -U <name>      define a macro, or undefine one after every -D
216  -I <dir>               add <dir> to the include search path
217  -iquote -isystem -idirafter <dir>   the other chains, -nostdinc drops ours
218  -I-, -iprefix <p>, -iwithprefix[before] <dir>   the older spellings of those
219  -include <file>, -imacros <file>    read <file> first, the second for its macros only
220  --sysroot=<dir>        look for the library's headers under <dir>, -isysroot too
221  -P, -dM                with -E: leave out the markers, or dump the macros
222  -M -MM -MD -MMD        write a make rule for the source, the last two compile as well
223  -MF <file> -MT <t> -MQ <t> -MP   where the rule goes, what it builds, targets with no recipe
224  -std=<dialect>         c89 through c23, and the gnu spellings
225  -fgnuc-version=<v>     the GCC release to claim, default 7.0.0
226  -x <lang>              treat later inputs as <lang>, or none to stop
227  -O<level>              optimize: 0, 1, 2, 3, s, z
228  -fsafety=<tier>        check memory safety: off, detect, enforce, kernel
229  -f[no-]sanitize=<what>   the negative is taken, the positive is refused by name
230  -f[no-]safety-subobject   a write has to stay inside the member it names
231  -f[no-]safety-restrict    two restrict pointers of one block may not meet
232  -f<pass> -fno-<pass> -fdump-ir=<what> -fopt-info[-<kind>][=FILE]
233  -fpass-fuel=<pass>=<n>, -fpass-fuel-global=<n>   stop a pass, or all of them, after n
234  -fdisable-<pass>[=<funcs>], -fenable-<pass>[=<funcs>]   run a pass on some functions only
235  -g -g0 -gdwarf-5, -fno-omit-frame-pointer, -mno-red-zone   debug info, frame pointer, red zone
236  -gz[=none|zlib|zlib-gnu|zstd] -gno-split-dwarf   compress debug sections, one file not two
237  -flto[=auto|jobserver|<n>] -fno-lto -ffat-lto-objects   read, and not done yet
238  -fprofile-use[=<path>] -fprofile-dir=<dir>   read too, where -fprofile-generate is refused
239  -f[no-]stack-protector[-strong|-all], -f[no-]stack-clash-protection, -fcf-protection=<edges>
240  -ffunction-sections -fdata-sections   a section per function or variable, for --gc-sections
241  -fvisibility=<what>    default, hidden, internal or protected, when nothing in the source said
242  -l<name>, -L <dir>, -B <dir>   link a library, where to look for one, where our own tools are
243  -fPIC -fpic -fPIE -fpie, -fno-common, -pipe   what it does anyway
244  -f[no-]strict-aliasing, -f[no-]delete-null-pointer-checks   what it assumes anyway
245  -static -shared -pie -no-pie -nostdlib -nostartfiles -nodefaultlibs -rdynamic -s   how to link
246  -Wl,<arg>, -Xlinker <arg>, -fuse-ld=<name>   hand an argument to the linker, or pick one
247  -Werror -pedantic -pedantic-errors -w   how much to say, and whether it is fatal
248  -m64 -march= -mtune= -mcpu= -mabi= -mcmodel=   what machine to generate for
249  -pg -p, -mfentry -mno-fentry   call a profiler on the way in, and where that call goes
250  -fpatchable-function-entry=<n>[,<m>]   room at the top of every function to patch later
251  -fwrapv, -fwrapv-pointer, -fno-strict-overflow   signed or pointer overflow wraps
252  -ftrapv                signed overflow stops the program instead
253  -f[no-]signed-char, -f[no-]unsigned-char, -f[no-]short-enums   change the ABI
254  -ffp-contract=<how>    fuse a multiply and an addition: fast, on or off
255  -fexcess-precision=<how>, -f[no-]rounding-math, -f[no-]trapping-math   what may be folded
256  -ffile-prefix-map=<old>=<new>   rewrite that front of every path we put in the output
257  -fmacro-prefix-map= -fdebug-prefix-map= -fprofile-prefix-map=   the same, one output each
258  -pthread               build for more than one thread, and link the library for it
259  -dumpmachine -dumpversion -print-multiarch -print-search-dirs   what this compiler is
260  -print-file-name=<name> -print-prog-name=<name>   where a file or a program is
261  -print-sysroot         the root the headers and the libraries are read under
262  -print-sysroot-provenance   every input under it, where it came from and its licence
263  -print-sysroot-digest   the sha256 of that record, which names the whole sysroot in one line
264  --fetch <tuple>        get the sysroot this release pins for <tuple> and install it in the cache
265  --offline              never download anything, which a compilation never does anyway
266  -j[n]                  compile n translation units at once, default all
267  -v, -###               print each phase as it runs, or without running any
268  -save-temps[=cwd|obj], -time   keep the .i and the .s, say how long each step took
269  --target=<triple>      generate code for <triple>
270  --emit=<kind>          exe, obj, archive, asm, preprocessed, tast, ir, mir-final,
271                         safety-summary, type-granules
272  --print-config, --print-pipeline    print the configuration or the pipeline, and exit
273  --version              print the version and exit
274  -h, --help             print this message and exit
275
276See spec/04-driver-and-cli.md for the full flag reference.
277";
278
279/// The argument of a flag that may be joined to it or may be the next word.
280///
281/// `-DFOO` and `-D FOO` are the same thing, and `at` is where the flag's own letters end.
282fn joined_or_next(
283    arg: &str,
284    at: usize,
285    args: &[String],
286    i: &mut usize,
287) -> Result<String, CliError> {
288    if arg.len() > at {
289        return Ok(arg[at..].to_owned());
290    }
291    let next = args.get(*i).ok_or_else(|| err(format!("{arg} requires an argument")))?;
292    *i += 1;
293    Ok(next.clone())
294}
295
296/// Every name that may follow `-fsanitize=`, which is gcc 16's list and three of this compiler's
297/// own.
298///
299/// The three are on it because `spec/07-types-and-semantics.md` section 7.7 already promises them:
300/// each undefined behaviour this compiler exploits is listed there with the check that detects it,
301/// and `alias`, `restrict` and `memory` are checks gcc has no spelling for. gcc refuses `memory`
302/// outright, since the sanitizer of that name is clang's. A name being here means it is a name
303/// rather than a typo, and nothing more than that: every one of them is refused after the loop,
304/// because none of them is implemented.
305///
306/// `all` is deliberately absent. gcc takes it only in the negative, so it is handled where each of
307/// those two spellings is read rather than by being on this list.
308const SANITIZERS: [&str; 34] = [
309    "address",
310    "kernel-address",
311    "hwaddress",
312    "kernel-hwaddress",
313    "pointer-compare",
314    "pointer-subtract",
315    "thread",
316    "leak",
317    "undefined",
318    "shift",
319    "shift-base",
320    "shift-exponent",
321    "integer-divide-by-zero",
322    "unreachable",
323    "vla-bound",
324    "null",
325    "return",
326    "signed-integer-overflow",
327    "bounds",
328    "bounds-strict",
329    "alignment",
330    "object-size",
331    "float-divide-by-zero",
332    "float-cast-overflow",
333    "nonnull-attribute",
334    "returns-nonnull-attribute",
335    "bool",
336    "enum",
337    "vptr",
338    "pointer-overflow",
339    "builtin",
340    "alias",
341    "restrict",
342    "memory",
343];
344
345/// Parses a command line, without the program name.
346///
347/// # Errors
348///
349/// Returns the message to print when the arguments do not name a compilation this compiler
350/// can attempt.
351pub fn parse_args(args: &[String]) -> Result<Action, CliError> {
352    let host = Triple::host()
353        .ok_or_else(|| err("this host is not a supported target and no --target was given"))?;
354    let mut opts = Options::new(host);
355    let mut inputs: Vec<Input> = Vec::new();
356    let mut print_config = false;
357    let mut print_pipeline = false;
358    let mut print_plan = false;
359    let mut verbose = false;
360    let mut jobs = Jobs::default();
361    let mut nostdinc = false;
362    let mut sysroot: Option<PathBuf> = None;
363    // What the command line is worth warning about, filled in after the loop rather than during it,
364    // because every question of this kind is about two flags and the last word on both of them is
365    // the end of the loop.
366    let mut notes: Vec<String> = Vec::new();
367    // The whole ten field target, kept beside the three field one because `--target=` can pin a
368    // libc version and `Triple` has nowhere to put it. It decides `__GLIBC_MINOR__` and nothing
369    // else today, and `None` is a command line that named no target, which is this machine.
370    let mut pinned: Option<TargetTuple> = None;
371    let mut output = None;
372    let mut link = LinkOptions::default();
373    let mut query: Option<Query> = None;
374    // What `--fetch` named, and whether `--offline` forbade it. Both are weighed after the loop
375    // because either can be written after the other.
376    let mut fetch: Option<String> = None;
377    let mut offline = false;
378    let mut threads = false;
379    // Which sanitizers are still asked for by the end of the command line. Accumulated across the
380    // loop rather than answered where it was read, because `-fno-sanitize=` turns one off and a
381    // build that asks for a check and then takes it back has asked for nothing. What happens to a
382    // set that is not empty is decided after the loop.
383    let mut sanitizers: Vec<&str> = Vec::new();
384    // `-x` applies to inputs that come after it and stays in effect until the next one, which
385    // is why it is tracked across the loop rather than attached to a single argument.
386    let mut forced: Option<InputKind> = None;
387    // What `-iprefix` last said, stuck on the front of every later `-iwithprefix`. It applies to
388    // the flags after it and not the ones before, so a command line may set it more than once.
389    // GCC's default is its own installed header directory with the last component taken off,
390    // which is a path a cross compiler's build system knows and passes; there is no equivalent
391    // here, so with no `-iprefix` the prefix is nothing and `-iwithprefix` names a directory
392    // outright.
393    let mut iprefix = String::new();
394
395    let mut i = 0;
396    while i < args.len() {
397        let arg = args[i].as_str();
398        i += 1;
399        match arg {
400            "-h" | "--help" => return Ok(Action::Help),
401            "--version" => return Ok(Action::Version),
402            // The sysroot fetch, which is weighed after the loop rather than acted on here, because
403            // `--offline` written after it has to be able to forbid it. Both spellings, since a
404            // flag that takes a tuple gets written both ways and neither is a guess at what the
405            // other meant.
406            "--fetch" => {
407                let value = args
408                    .get(i)
409                    .ok_or_else(|| err("--fetch requires the target to get a sysroot for"))?;
410                i += 1;
411                fetch = Some(value.clone());
412            }
413            _ if arg.starts_with("--fetch=") => {
414                fetch = Some(arg["--fetch=".len()..].to_owned());
415            }
416            // Accepted on any command line and only ever read by the fetch, because an ordinary
417            // compile downloads nothing with or without it. So this flag takes nothing away today,
418            // which is the property section 13.2 asks for rather than an omission: a build that
419            // passes it is saying what it expects of this compiler, and what it expects is already
420            // true.
421            "--offline" => offline = true,
422            "--print-config" => print_config = true,
423            "--print-pipeline" => print_pipeline = true,
424            "-###" => print_plan = true,
425            "-v" => verbose = true,
426            // The files a compilation goes through, kept rather than thrown away. The bare
427            // spelling means `=obj` and not `=cwd`, which is not what the manual says and is what
428            // gcc 16 does; `SaveTemps::Object` carries the measurement.
429            "-save-temps" => opts.save_temps = SaveTemps::Object,
430            _ if arg.starts_with("-save-temps=") => {
431                opts.save_temps = arg["-save-temps=".len()..].parse().map_err(err)?;
432            }
433            // How long each step took. A misspelling of this is worth rejecting rather than
434            // ignoring, since a run that says nothing looks like a compilation that took no time.
435            "-time" => opts.time = true,
436            "-c" => opts.emit = EmitKind::Object,
437            "-S" => opts.emit = EmitKind::Asm,
438            "-E" => opts.emit = EmitKind::Preprocessed,
439            "-g" => opts.debug_info = true,
440            // GCC's own levels of how much debug information to write. Zero is none and every
441            // other number is some, and this compiler has one amount, so the numbers above zero
442            // all mean the same thing here. `-ggdb` is the same flag asking for whatever the
443            // debugger on the machine prefers, which is what we emit anyway.
444            "-g0" => opts.debug_info = false,
445            "-g1" | "-g2" | "-g3" | "-ggdb" | "-ggdb1" | "-ggdb2" | "-ggdb3" => {
446                opts.debug_info = true;
447            }
448            // The version of DWARF to write. We write DWARF 5 and nothing else, so a build that
449            // asks for another version is told rather than handed a file it cannot read.
450            "-gdwarf" | "-gdwarf-5" => opts.debug_info = true,
451            _ if arg.starts_with("-gdwarf-") => {
452                return Err(err(format!(
453                    "{arg}: this compiler writes DWARF 5 and no other version, see \
454                     spec/11-debug-info.md"
455                )));
456            }
457            // Whether the debug information goes in a file of its own beside the object. gcc
458            // writes that `.dwo` whether or not it found anything to put in it, which means a
459            // build system that declares the file as an output gets one and a make rule that
460            // depends on it fires. Refused for that reason rather than taken: section 4.1 takes a
461            // flag that changes nothing and refuses one that changes what is produced, and a file
462            // that does not appear is the plainest change of that kind there is. The negative
463            // spelling is taken, because putting it all in the object is what happens anyway.
464            "-gno-split-dwarf" => {}
465            "-gsplit-dwarf" => {
466                return Err(err(format!(
467                    "{arg}: this compiler writes no separate `.dwo` file, and a build that \
468                     expects one beside each object would wait for a file that never arrives, \
469                     see spec/11-debug-info.md"
470                )));
471            }
472            // How the debug sections are compressed. There are none yet, so every answer produces
473            // the same bytes and taking the flag promises nothing that is not kept. The value is
474            // still checked, because a typo in a distribution's flags is worth finding when the
475            // compiler reads it rather than when somebody later wonders why nothing got smaller.
476            // Bare `-gz` means `zlib`, which the manual leaves for the reader to discover.
477            "-gz" => opts.compress = Compress::Zlib,
478            _ if arg.starts_with("-gz=") => {
479                let how = &arg["-gz=".len()..];
480                opts.compress = how.parse().map_err(|()| {
481                    err(format!(
482                        "`{how}` is not a way to compress debug sections, which is none, zlib, \
483                         zlib-gnu or zstd"
484                    ))
485                })?;
486            }
487            "-Werror" => opts.warnings_are_errors = true,
488            // Nothing that is not fatal is said at all. Read at the one place a diagnostic goes
489            // through rather than here, so that a warning `-w` dropped is not counted either.
490            "-w" => opts.warnings = false,
491            "-pedantic-errors" => {
492                opts.pedantic = true;
493                opts.warnings_are_errors = true;
494            }
495            "-P" => opts.line_markers = false,
496            // The dependency family, which section 4.4 calls required because every build system
497            // that generates its own makefiles asks for it. The two that end in `D` write a file
498            // beside the object and let the compilation happen, and the two that do not write to
499            // standard output and stop after it. Nothing here turns the system headers back on
500            // once a flag has turned them off, which is GCC's behaviour and is why `-MM -M` is
501            // `-MM`: the flag asking for fewer of them is the one with something to say.
502            "-M" => {
503                opts.deps.emit = true;
504                opts.deps.instead_of_compiling = true;
505            }
506            "-MM" => {
507                opts.deps.emit = true;
508                opts.deps.instead_of_compiling = true;
509                opts.deps.system_headers = false;
510            }
511            "-MD" => opts.deps.emit = true,
512            "-MMD" => {
513                opts.deps.emit = true;
514                opts.deps.system_headers = false;
515            }
516            "-MP" => opts.deps.phony = true,
517            // These three take a word and only in the separated form, which is how GCC spells
518            // them and how every build system writes them.
519            "-MF" | "-MT" | "-MQ" => {
520                let value =
521                    args.get(i).ok_or_else(|| err(format!("{arg} requires an argument")))?;
522                i += 1;
523                match arg {
524                    "-MF" => opts.deps.file = Some(value.clone()),
525                    // The whole of the difference between the two. `-MT` is for a build that has
526                    // already escaped what it is passing, and `-MQ` is for one that has a name
527                    // and wants it to arrive as that name.
528                    "-MT" => opts.deps.targets.push(value.clone()),
529                    _ => opts.deps.targets.push(deps::escaped(value)),
530                }
531            }
532            // The questions a build system asks before it compiles anything. Answered after the
533            // loop, because each one is about the target or the library search and the command
534            // line has not finished saying what those are.
535            "-dumpmachine" => query = Some(Query::Machine),
536            "-dumpversion" | "-dumpfullversion" => query = Some(Query::Version),
537            "-print-multiarch" => query = Some(Query::Multiarch),
538            "-print-search-dirs" => query = Some(Query::SearchDirs),
539            "-print-sysroot" => query = Some(Query::Sysroot),
540            // Both spellings, because this one is ours rather than GCC's and our own documents
541            // write it both ways: section 13.5 of `spec/cross-compile/13-distribution.md` gives it
542            // two dashes like the other flags we invented, and document 12's table gives it one
543            // like the `-print-` family it sits in. A person who reads either and types what it
544            // says is right, so neither is refused.
545            "-print-sysroot-provenance" | "--print-sysroot-provenance" => {
546                query = Some(Query::SysrootProvenance);
547            }
548            "-print-sysroot-digest" | "--print-sysroot-digest" => {
549                query = Some(Query::SysrootDigest);
550            }
551            "-print-libgcc-file-name" => query = Some(Query::Libgcc),
552            _ if arg.starts_with("-print-file-name=") => {
553                query = Some(Query::FileName(arg["-print-file-name=".len()..].to_owned()));
554            }
555            _ if arg.starts_with("-print-prog-name=") => {
556                query = Some(Query::ProgName(arg["-print-prog-name=".len()..].to_owned()));
557            }
558            // A program built to run in more than one thread. On every platform this compiler
559            // targets that is a macro the library's headers read and one more library on the
560            // link line, and the library is added after the loop so that it lands after the
561            // objects that refer to it.
562            "-pthread" | "-pthreads" => {
563                opts.defines.push("_REENTRANT".to_owned());
564                threads = true;
565            }
566            "-ansi" => {
567                opts.std = Std::C89;
568                opts.gnu_extensions = false;
569            }
570            // `-Wpedantic` is the same flag under the name the `-W` family gives it, which is
571            // the spelling a build system that groups its warning flags tends to write.
572            "-pedantic" | "-Wpedantic" => opts.pedantic = true,
573            // Both directions, because a build that needs this for one directory turns it back
574            // off for the next one rather than leaving it on for the whole tree.
575            "-fpermissive" => opts.permissive = true,
576            "-fno-permissive" => opts.permissive = false,
577            "-ffreestanding" => opts.hosted = false,
578            "-fhosted" => opts.hosted = true,
579            "-fno-builtin" => opts.builtins = false,
580            "-fbuiltin" => opts.builtins = true,
581            // The C89 dialects are under GNU's reading whatever this says, so turning it off
582            // there is turning off something the dialect asked for, which is accepted and does
583            // nothing. gcc refuses that command line, and there is nothing it could have meant.
584            "-fgnu89-inline" => opts.gnu89_inline = true,
585            "-fno-gnu89-inline" => opts.gnu89_inline = false,
586            // Both directions of each, because a build system that wants one of these usually
587            // writes it beside the flag that turns it back off for one directory.
588            "-fno-omit-frame-pointer" => opts.frame_pointer = true,
589            "-fomit-frame-pointer" => opts.frame_pointer = false,
590            // Both directions again, for the same reason, and a third answer for a command line
591            // that wrote neither: see `reorder_blocks` in `rucc_session`.
592            "-freorder-blocks" => opts.reorder_blocks = Some(true),
593            "-fno-reorder-blocks" => opts.reorder_blocks = Some(false),
594            // gcc's name for the scheduler that runs after the registers are handed out, which is
595            // the only one rucc has: see `schedule_insns` in `rucc_session`. gcc also takes
596            // `-fschedule-insns` for the pass before allocation, and taking that one here would be
597            // a flag that says a pass ran when none did.
598            "-fschedule-insns2" => opts.schedule_insns = Some(true),
599            "-fno-schedule-insns2" => opts.schedule_insns = Some(false),
600            "-mno-red-zone" => opts.red_zone = false,
601            "-mred-zone" => opts.red_zone = true,
602            // Four flags rather than one with an argument, which is how gcc spells them and how
603            // every build line writes them. Last one wins, because a package build puts
604            // `-fstack-protector-strong` in its global flags and a directory that cannot have one
605            // turns it back off on the line after.
606            "-fno-stack-protector" | "-fno-stack-protector-all" | "-fno-stack-protector-strong" => {
607                opts.protector = Protector::None;
608            }
609            "-fstack-protector" => opts.protector = Protector::Buffers,
610            "-fstack-protector-strong" => opts.protector = Protector::Strong,
611            "-fstack-protector-all" => opts.protector = Protector::All,
612            // The other half of what a hardened build asks for, and it is a question about the
613            // frame rather than about the function, so it is a switch rather than a level.
614            "-fstack-clash-protection" => opts.stack_clash = true,
615            "-fno-stack-clash-protection" => opts.stack_clash = false,
616            // The third of them, and the one that is a question with an argument rather than a
617            // family of spellings, because what it asks about is which of the two edges of a
618            // control flow transfer is checked. Bare is both of them, which is what gcc does.
619            "-fcf-protection" => opts.control = Control::Full,
620            "-fno-cf-protection" => opts.control = Control::None,
621            // Two spellings of the same request, which is what gcc has as well. `-p` was the older
622            // profiler and `-pg` the one that also recorded who called whom, and on every platform
623            // this compiler targets there is now one hook and both ask for it.
624            "-pg" | "-p" => {
625                opts.profile = true;
626                link.profile = true;
627            }
628            // Accepted on their own and doing nothing on their own, which is gcc's behaviour: they
629            // say where the call goes and a command line that asked for no call has nowhere to put
630            // one. That matters because a build system that sets `-mfentry` globally and `-pg` per
631            // directory is a build system that would otherwise fail on every other directory.
632            "-mfentry" => opts.hook = Hook::Early,
633            "-mno-fentry" => opts.hook = Hook::Late,
634            // GCC drops its own include directory along with the system ones, because its
635            // headers are half of a pair with the library's and half a pair is worse than
636            // none. A build that passes this is supplying the whole set itself.
637            "-nostdinc" => nostdinc = true,
638            "-o" => {
639                output = Some(args.get(i).ok_or_else(|| err("-o requires an argument"))?.clone());
640                i += 1;
641            }
642            // The flags that take a directory only in the separated form. GCC spells them
643            // this way and nothing writes `-iquotedir`, so accepting the joined form would
644            // mean guessing at a path that starts with the flag's own letters.
645            // Apple's spelling of `--sysroot`, and the one its own build systems pass. The
646            // two mean the same thing here: the configured directories are under there rather
647            // than under the root.
648            "-isysroot" => {
649                let dir = args.get(i).ok_or_else(|| err("-isysroot requires an argument"))?;
650                i += 1;
651                sysroot = Some(PathBuf::from(dir));
652            }
653            "-iquote" | "-isystem" | "-idirafter" => {
654                let dir = args.get(i).ok_or_else(|| err(format!("{arg} requires an argument")))?;
655                i += 1;
656                match arg {
657                    "-iquote" => opts.search.push_quote(dir.clone()),
658                    "-isystem" => opts.search.push_system(dir.clone()),
659                    _ => opts.search.push_after(dir.clone()),
660                }
661            }
662            "-iprefix" => {
663                iprefix = args.get(i).ok_or_else(|| err("-iprefix requires an argument"))?.clone();
664                i += 1;
665            }
666            // Where GCC puts these is not where its manual says it puts them, and this is the
667            // measured answer rather than the documented one: `-iwithprefix` lands in the
668            // `-isystem` slot and not the `-idirafter` slot, and `-iwithprefixbefore` lands in
669            // the `-I` slot. A cross build that uses them is relying on the behaviour, since
670            // that is the compiler it was developed against.
671            "-iwithprefix" | "-iwithprefixbefore" => {
672                let dir = args.get(i).ok_or_else(|| err(format!("{arg} requires an argument")))?;
673                i += 1;
674                let dir = format!("{iprefix}{dir}");
675                if arg == "-iwithprefix" {
676                    opts.search.push_system(dir);
677                } else {
678                    opts.search.push_bracket(dir);
679                }
680            }
681            "-include" | "-imacros" => {
682                let name = args.get(i).ok_or_else(|| err(format!("{arg} requires an argument")))?;
683                i += 1;
684                opts.preincludes
685                    .push(Preinclude { name: name.clone(), macros_only: arg == "-imacros" });
686            }
687            // The flag `-iquote` was introduced to replace, still passed by build systems old
688            // enough to predate the replacement. It is not a directory: it says that every `-I`
689            // so far is for quoted includes only, and that a quoted include stops looking next
690            // to the file that wrote it.
691            "-I-" => opts.search.split_quote_chain(),
692            "-x" => {
693                let lang = args.get(i).ok_or_else(|| err("-x requires an argument"))?;
694                i += 1;
695                forced = if lang == "none" {
696                    None
697                } else {
698                    Some(InputKind::from_x_arg(lang).map_err(|e| err(format!("{e}")))?)
699                };
700            }
701            // Not a GCC flag. spec/03-architecture.md section 3.5 compiles several
702            // translation units in one process rather than making the build system fork, and
703            // section 3.8's determinism check compares `-j1` against `-j16`, so the knob has
704            // to exist and has to be spelled the way `make` spells it.
705            // `-DFOO`, `-D FOO` and the same for `-U` and `-I`. Both forms are in wide use
706            // and a build system may produce either, so both are read here rather than
707            // being normalised by whatever generated the command line.
708            _ if arg.starts_with("-D") => {
709                let value = joined_or_next(arg, 2, args, &mut i)?;
710                opts.defines.push(value);
711            }
712            _ if arg.starts_with("-U") => {
713                let value = joined_or_next(arg, 2, args, &mut i)?;
714                opts.undefines.push(value);
715            }
716            _ if arg.starts_with("-I") => {
717                let dir = joined_or_next(arg, 2, args, &mut i)?;
718                opts.search.push_bracket(dir);
719            }
720            _ if arg.starts_with("-std=") => {
721                let name = &arg["-std=".len()..];
722                let (std, gnu) = Std::from_flag(name)
723                    .ok_or_else(|| err(format!("unknown dialect `{name}`, see --help")))?;
724                opts.std = std;
725                opts.gnu_extensions = gnu;
726            }
727            // Section 4.5. The claim decides which half of glibc's `sys/cdefs.h` we are
728            // handed, so a differential run that does not set it is comparing two compilers
729            // that believe they are different compilers.
730            // GCC packs these into one flag, so `-dDI` is two of them. Letters in the family
731            // that we have not written yet are accepted and ignored, because a dump is a
732            // debugging aid and a build that asks for one should still compile. A letter
733            // outside the family falls through to the unknown option error, which is what
734            // keeps `-dumpversion` from being read as a dump of nothing.
735            _ if Dumps::is_family(arg) => {
736                opts.dumps.add(&arg[2..]);
737            }
738            // One name at a time, which is what a build that means its own `memcpy` and the
739            // library's everything else writes. The name is not checked against a list, because
740            // the flag is about what the program means by a name and a program is allowed to mean
741            // something by a name this compiler has never heard of.
742            _ if arg.starts_with("-fno-builtin-") => {
743                opts.no_builtin.push(arg["-fno-builtin-".len()..].to_owned());
744            }
745            _ if arg.starts_with("-fgnuc-version=") => {
746                let v = &arg["-fgnuc-version=".len()..];
747                opts.gnuc = v.parse().map_err(err)?;
748            }
749            // spec/13-gnu-compat.md section 13.3 promises this flag an error that says why rather
750            // than the unknown option one, because a build reaching for it is asking for a feature
751            // and deserves to be told it is not coming rather than told the spelling is wrong.
752            // The negative form is what this compiler does anyway, so it is taken and dropped.
753            "-fnested-functions" => {
754                return Err(err(
755                    "nested functions are not supported: a call to one goes through a trampoline \
756                     written on the stack, which no target that enforces an unexecutable stack \
757                     allows",
758                ));
759            }
760            "-fno-nested-functions" => {}
761            // Which of the two links the output is for, which is a real difference and not a
762            // description of what happens anyway. Everything here is position independent either
763            // way, and what these decide is whether a name may be one another object defines or
764            // replaces, because a link that produces an executable puts every name in the same
765            // program and a link that produces a shared library does not.
766            //
767            // It matters that they are accepted at all, whatever they then do. Every autoconf and
768            // cmake build puts `-fPIC` on the compile line, so a compiler that rejects it cannot
769            // be the `CC` of a project that has a configure script, whatever else it can do. That
770            // is how this was found: building SQLite's test fixture stopped on it.
771            "-fPIC" | "-fpic" => opts.pic = Pic::Library,
772            // Not a synonym of the pair above, which is what they were treated as until #756. The
773            // library is the expensive answer and gcc makes it the one that has to be asked for,
774            // so this is also what nothing at all means.
775            "-fPIE" | "-fpie" => opts.pic = Pic::Executable,
776            // A different question from the pair above, and the one every distribution build of a
777            // shared library answers. `-fPIC` decides how an address is reached, and this decides
778            // whether the optimizer may believe a body it can see, because an exported name is one
779            // the dynamic linker may find another definition of first. On by default, which is
780            // gcc's arrangement and is the honest answer, and off is a promise the build makes and
781            // nothing checks.
782            "-fsemantic-interposition" => opts.interposition = true,
783            "-fno-semantic-interposition" => opts.interposition = false,
784            // Two requests rather than one, and the same table answers both, so what decides is
785            // whether either of them is standing. gcc arranges it the same way: the asynchronous
786            // one is the default here and it implies the other, and a line that asks for a table
787            // and against an asynchronous one gets a table.
788            "-fasynchronous-unwind-tables" => opts.async_unwind_tables = true,
789            "-fno-asynchronous-unwind-tables" => opts.async_unwind_tables = false,
790            "-funwind-tables" => opts.unwind_tables = true,
791            "-fno-unwind-tables" => opts.unwind_tables = false,
792            // The other direction is a request, not a description, and it is one this compiler
793            // cannot grant, so it gets the treatment section 13.3 asks for rather than the unknown
794            // option error. Answering it by carrying on would be answering a different question:
795            // the code would still be position independent, which is correct everywhere an
796            // ordinary program runs and is wrong in a kernel, where the flag is written precisely
797            // because there is no loader to fill a global offset table in.
798            "-fno-pic" | "-fno-pie" => {
799                return Err(err(
800                    "position dependent code is not supported: an address that may be in another \
801                     object is loaded out of the global offset table, and nothing here emits the \
802                     absolute form this asks for. Use -no-pie if what you meant was how to link",
803                ));
804            }
805            // A section per function and a section per variable, which is what makes
806            // `--gc-sections` able to drop anything: a linker can leave out a section nothing
807            // reaches and cannot leave out half of one. Both directions are taken, and the off
808            // one is the default rather than a refusal, since a build that writes it is asking
809            // for what happens anyway.
810            "-ffunction-sections" => opts.function_sections = true,
811            "-fno-function-sections" => opts.function_sections = false,
812            "-fdata-sections" => opts.data_sections = true,
813            "-fno-data-sections" => opts.data_sections = false,
814            // Another description of what this compiler does. A file scope declaration with no
815            // initializer is written into `.bss` as an ordinary defined symbol, not offered to the
816            // linker as a common one for it to merge, which is what `-fno-common` asks for and what
817            // gcc has done by default since 10. Nothing in the front end produces `Linkage::Common`
818            // at all.
819            "-fno-common" => {}
820            // What overflows rather than being undefined. Every one of these takes something away
821            // from the optimizer rather than asking it to do anything, which is why the negative
822            // spellings are the interesting ones and the positive spellings are the default.
823            //
824            // `-fno-strict-overflow` is both of the others, which is gcc's own reading of it: its
825            // help text for `-fstrict-overflow` says "negated as -fwrapv -fwrapv-pointer". So it is
826            // written here as the pair rather than kept as a third thing to test everywhere.
827            //
828            // `-ftrapv` is the exception and is the one that asks for something. It is the other
829            // answer to the question `-fwrapv` answers, so the two cannot both hold and each clears
830            // the other, which makes the last one on the command line the one that counts. That is
831            // gcc 16's behaviour and was measured rather than read: `-ftrapv -fwrapv` emits no
832            // checked calls and `-fwrapv -ftrapv` emits them. The positive spelling of the pointer
833            // question is left alone by both, because neither has anything to say about it.
834            "-fwrapv" => {
835                opts.wrapping.signed = true;
836                opts.wrapping.trap = false;
837            }
838            "-fno-wrapv" => opts.wrapping.signed = false,
839            "-fwrapv-pointer" => opts.wrapping.pointer = true,
840            "-fno-wrapv-pointer" => opts.wrapping.pointer = false,
841            "-fno-strict-overflow" => opts.wrapping = Wrapping::ALL,
842            // Which does not clear the checked one, because gcc does not: `-ftrapv
843            // -fstrict-overflow` still emits the calls. It says what is assumed and not what
844            // happens.
845            "-fstrict-overflow" => {
846                opts.wrapping.signed = false;
847                opts.wrapping.pointer = false;
848            }
849            "-ftrapv" => {
850                opts.wrapping.trap = true;
851                opts.wrapping.signed = false;
852            }
853            "-fno-trapv" => opts.wrapping.trap = false,
854            // The two flags that say what a plain `char` is, which is one question with two
855            // spellings each: gcc reads `-fno-signed-char` as `-funsigned-char` and
856            // `-fno-unsigned-char` as `-fsigned-char`, so there are four ways to write two
857            // answers and the last one written wins. Nothing is set until one of them is given,
858            // because the target's own ABI is the answer otherwise and it is not the same answer
859            // everywhere: x86-64 and Apple's arm64 are signed, Linux's arm64 is not.
860            "-fsigned-char" | "-fno-unsigned-char" => opts.char_signed = Some(true),
861            "-funsigned-char" | "-fno-signed-char" => opts.char_signed = Some(false),
862            // And the size of an enumeration, which is the other thing in this group that changes
863            // the ABI rather than the code.
864            "-fshort-enums" => opts.short_enums = true,
865            "-fno-short-enums" => opts.short_enums = false,
866            // And the request, which is the one that cannot be granted. It is a real difference and
867            // not a preference: two files each writing `int g;` link under `-fcommon` and are a
868            // duplicate definition without it, which is the whole reason the flag survives.
869            "-fcommon" => {
870                return Err(err(
871                    "a tentative definition is written into .bss as its own symbol here, and \
872                     nothing emits the common symbol this asks the linker to merge. Give the \
873                     variable a definition in one file and declare it extern in the others",
874                ));
875            }
876            // Both directions of this one are recorded, and what they decide is whether lowering
877            // names the type each access goes through. Turning it off is the front end leaving the
878            // name off rather than a pass being told to ignore one it can see, which is one
879            // condition in one place, and it is the reading that survives link time optimization:
880            // a unit built with the flag off keeps its own answer when its bodies end up in a
881            // module beside bodies that were not.
882            //
883            // Nothing in the pipeline reads those names yet. Layer 3 of the alias analysis does
884            // and is tested, and no pass at any level asks the alias analysis anything today, so
885            // no program compiles differently for having passed this. The flag is wired anyway,
886            // because the change that makes a pass ask is not the change anybody will remember to
887            // wire it in, and a flag that is taken and dropped once the names mean something is
888            // the miscompilation `spec/04-driver-and-cli.md` section 4.1 warns about in as many
889            // words.
890            "-fstrict-aliasing" => opts.strict_aliasing = true,
891            "-fno-strict-aliasing" => opts.strict_aliasing = false,
892            // The same shape of answer for the same reason, and the flag the kernel writes beside
893            // the one above it.
894            //
895            // Nothing here concludes that a pointer is not null from the fact that it was
896            // dereferenced. There is no such conclusion to draw from, because no pass records one:
897            // a load says where it read and nothing else, and a comparison against null is an
898            // ordinary comparison of two values the optimizer has no fact about. So a function
899            // that reads through a pointer and then tests it keeps the test, which is what the
900            // kernel wants and what `-fno-delete-null-pointer-checks` asks for, and what gcc has
901            // to be asked for because it draws the conclusion by default.
902            //
903            // `-fdelete-null-pointer-checks` is the request to draw it, and it goes the way
904            // `-fstrict-aliasing` does: assuming less than was asked for costs speed and not
905            // correctness, and `-O2` implies it, so refusing it would stop builds for nothing.
906            "-fdelete-null-pointer-checks" | "-fno-delete-null-pointer-checks" => {}
907            // The floating point group, which goes the same way and for the same reason, and which
908            // is worth writing out because the reason is easy to get backwards.
909            //
910            // Each of these has a restrictive spelling and a permissive one. The restrictive ones,
911            // `-frounding-math` and `-ftrapping-math`, say that the rounding mode may have been
912            // changed and that an exception raised by an operation may be looked at, so an
913            // arithmetic the compiler folds at compile time is an arithmetic whose rounding and
914            // whose exception the program does not get. Nothing here folds any floating point
915            // arithmetic in a function body: `0.1 + 0.2` is an `fadd` and `1.0 / 0.0` is a divide
916            // that runs, at every level. So both of those describe what already happens.
917            //
918            // The permissive ones are the other half, and they are licences rather than requests
919            // for an answer. `-fno-rounding-math` says the rounding mode is the default one and
920            // `-fno-trapping-math` says nothing looks at the exceptions, which together are
921            // permission to fold. Not folding is the conservative side of that permission and is
922            // what a program is entitled to whichever was written, so `-fno-rounding-math` costs
923            // speed and not correctness, which is the test section 4.1 puts a licence through.
924            "-frounding-math" | "-fno-rounding-math" => {}
925            // `-fno-trapping-math` is the one of the four that is kept, because there is one
926            // conversion this compiler does not fold and gcc folds under it, and the two answers
927            // differ. Converting a constant floating value to an integer type it does not fit in
928            // is undefined behaviour rather than a value: left to the hardware it is one
929            // instruction and the answer is the integer indefinite value, and folded it is the
930            // nearest end of the integer's range. Both compilers leave it to the instruction by
931            // default and gcc folds it under this flag, so a program built with it and compiled
932            // without it gets a different number rather than a slower one. `-ftrapping-math` is
933            // gcc's default, so a build spelling it out is asking for what it already has.
934            "-ftrapping-math" => opts.trapping_math = true,
935            "-fno-trapping-math" => opts.trapping_math = false,
936            // About temporary files rather than about code. There is nothing between the phases of
937            // one compilation here to write to a file in the first place.
938            "-pipe" => {}
939            // Nothing here writes colour, so all of these are the same answer, and it is the answer
940            // that costs nothing: the diagnostics come out plain either way and no build depends on
941            // an escape sequence being there. Taken rather than refused because cmake writes
942            // `-fdiagnostics-color=always` on every compile line when the generator is ninja, which
943            // makes this the second most common flag after `-fPIC` to stop a build over a question
944            // about how the text looks.
945            "-fdiagnostics-color" | "-fno-diagnostics-color" => {}
946            _ if arg.starts_with("-fdiagnostics-color=") => {}
947            // The link flags. None of them changes the compilation, which is why they are
948            // collected apart from `opts` and why `-lm` on a `-c` line is a note rather than an
949            // error: it is a thing said to a linker that is not going to run.
950            "-static" => link.is_static = true,
951            "-shared" => link.shared = true,
952            "-pie" => link.pie = Some(true),
953            "-no-pie" | "-nopie" => link.pie = Some(false),
954            "-nostdlib" => link.no_stdlib = true,
955            "-nostartfiles" => link.no_startfiles = true,
956            "-nodefaultlibs" => link.no_defaultlibs = true,
957            "-fno-builtins-lib" => link.no_builtins_lib = true,
958            "-fbuiltins-lib" => link.no_builtins_lib = false,
959            "-rdynamic" | "-export-dynamic" => link.export_dynamic = true,
960            "-s" => link.strip = true,
961            // Into the ordered input list rather than a list of its own, because a great many of
962            // the linker's options are a bracket around the files after them and an option that
963            // lost its place among them says nothing. `--whole-archive` is the one that found this.
964            "-Xlinker" => {
965                let next = args.get(i).ok_or_else(|| err("-Xlinker requires an argument"))?;
966                i += 1;
967                inputs.push(Input::linker(next));
968            }
969            _ if arg.starts_with("-Wl,") => {
970                // Commas separate arguments rather than being part of one, which is what makes
971                // `-Wl,-rpath,/opt/lib` two words to the linker and one word here.
972                inputs.extend(arg["-Wl,".len()..].split(',').map(Input::linker));
973            }
974            _ if arg.starts_with("-fuse-ld=") => {
975                link.use_ld = Some(arg["-fuse-ld=".len()..].to_owned());
976            }
977            _ if arg.starts_with("-l") && arg.len() > 2 => {
978                inputs.push(Input::library(&arg[2..]));
979            }
980            "-l" => {
981                let next = args.get(i).ok_or_else(|| err("-l requires an argument"))?;
982                i += 1;
983                inputs.push(Input::library(next));
984            }
985            _ if arg.starts_with("-L") => {
986                link.search.push(PathBuf::from(joined_or_next(arg, 2, args, &mut i)?));
987            }
988            _ if arg.starts_with("-B") => {
989                link.prefixes.push(PathBuf::from(joined_or_next(arg, 2, args, &mut i)?));
990            }
991            _ if arg.starts_with("-j") => {
992                jobs = Jobs::parse(&arg[2..]).map_err(err)?;
993            }
994            _ if arg.starts_with("--sysroot=") => {
995                sysroot = Some(PathBuf::from(&arg["--sysroot=".len()..]));
996            }
997            _ if arg.starts_with("--target=") => {
998                let t = &arg["--target=".len()..];
999                opts.target = t.parse().map_err(|e| err(format!("{e}")))?;
1000                // The same string again, as the model that has room for a libc version. A spelling
1001                // the three field parser took and this one does not is not an error, because the
1002                // one that decides what is compiled has already accepted it and the only thing
1003                // lost is a version nobody asked for.
1004                pinned = t.parse().ok();
1005            }
1006            _ if arg.starts_with("--emit=") => {
1007                let k = &arg["--emit=".len()..];
1008                opts.emit = k
1009                    .parse()
1010                    .map_err(|()| err(format!("unknown --emit kind `{k}`, see --help")))?;
1011            }
1012            // A bare `-O` is `-O1`, which is what GCC has and what a hand written makefile tends
1013            // to write. `-Og` is GCC's level for a build somebody is going to step through, and
1014            // it is `-O1` with the transformations that move code around left out; this compiler
1015            // has no such level yet, so it is the nearest one and `--print-pipeline` says what
1016            // that came to rather than the flag pretending otherwise.
1017            "-O" | "-Og" => opts.opt_level = rucc_session::OptLevel::O1,
1018            // The union of `-O3` and `-ffast-math`, and the second half of that changes what
1019            // floating point arithmetic means. Refused rather than taken as `-O3`, because a
1020            // build that asks for fast math and is quietly given ordinary arithmetic gets a
1021            // slower program than it asked for and a build that is given fast math it did not
1022            // ask for gets a wrong one.
1023            "-Ofast" => {
1024                return Err(err(
1025                    "-Ofast is -O3 with fast math, and fast math is not implemented, see \
1026                     spec/04-driver-and-cli.md section 4.6",
1027                ));
1028            }
1029            _ if arg.starts_with("-O") => {
1030                opts.opt_level = arg[2..]
1031                    .parse()
1032                    .map_err(|()| err(format!("unknown optimization level `{arg}`")))?;
1033            }
1034            // How far a multiply and an addition may be fused into one rounding. Before the
1035            // optimizer's `-f` family below for the reason the ones under it are, and kept rather
1036            // than dropped because it is the one flag in its group this compiler could act on: it
1037            // rides into the IR as an attribute on each function with a body, so the day the code
1038            // generator forms an `fma` it already knows which functions were given permission.
1039            // Nothing forms one today, under any value of this and under any `-march=`.
1040            _ if arg.starts_with("-ffp-contract=") => {
1041                let how = &arg["-ffp-contract=".len()..];
1042                opts.fp_contract = how.parse().map_err(|()| {
1043                    err(format!("`{how}` is not a contraction, which is fast, on or off"))
1044                })?;
1045            }
1046            // How much of an expression may be computed wider than it was written. The values are
1047            // gcc's and so is the refusal of anything else, and none of the three changes anything
1048            // here: an operation is computed in the type C says it is on every target this compiler
1049            // has a back end for, so `__FLT_EVAL_METHOD__` is 0 and `standard` is already what
1050            // happens. `fast` and `16` are permission to be wider, which is a licence this takes
1051            // and does not use, the same way the two above are. The flag is worth taking because
1052            // glibc's headers and a good deal of configure output write it, and because the answer
1053            // it asks about is one this compiler can state rather than guess at: there is no x87
1054            // target here, which is the machine the whole question was invented for.
1055            // Whether a local and a spilled value that are never both wanted may be the same bytes
1056            // of the frame. gcc's three values, and two of them mean the same thing here: what rucc
1057            // shares is a local whose address provably never leaves the function, which is narrower
1058            // than `named_vars` and narrower still than `all`, so both of them get it. `none` is
1059            // the one that changes anything, and it is the flag a program that reads a local
1060            // through a pointer it kept past the end of the block writes.
1061            _ if arg.starts_with("-fstack-reuse=") => {
1062                let how = &arg["-fstack-reuse=".len()..];
1063                opts.stack_reuse = match how {
1064                    "all" | "named_vars" => Some(true),
1065                    "none" => Some(false),
1066                    _ => {
1067                        return Err(err(format!(
1068                            "`{how}` is not a stack reuse, which is all, named_vars or none"
1069                        )));
1070                    }
1071                };
1072            }
1073            _ if arg.starts_with("-fexcess-precision=") => {
1074                let how = &arg["-fexcess-precision=".len()..];
1075                if !matches!(how, "16" | "fast" | "standard") {
1076                    return Err(err(format!(
1077                        "`{how}` is not an excess precision, which is 16, fast or standard"
1078                    )));
1079                }
1080            }
1081            // Which front of a path is rewritten before it reaches the output, which is how a
1082            // build gets the same bytes out of two different directories. The four spellings are
1083            // one flag each into three lists, and `-ffile-prefix-map=` is the three of them at
1084            // once. Only the macro list does anything today, because `__FILE__` is the only place
1085            // a path reaches the output: there is no DWARF and no profile data yet, so the other
1086            // two are recorded for the work that will read them. The argument splits at the last
1087            // `=` rather than the first, which is gcc's rule and is what lets a directory with an
1088            // `=` in its name be the old half.
1089            _ if arg.starts_with("-fmacro-prefix-map=") => {
1090                let (old, new) = rewrite(arg, "-fmacro-prefix-map=")?;
1091                opts.prefix_map.macros.push(old, new);
1092            }
1093            _ if arg.starts_with("-fdebug-prefix-map=") => {
1094                let (old, new) = rewrite(arg, "-fdebug-prefix-map=")?;
1095                opts.prefix_map.debug.push(old, new);
1096            }
1097            _ if arg.starts_with("-fprofile-prefix-map=") => {
1098                let (old, new) = rewrite(arg, "-fprofile-prefix-map=")?;
1099                opts.prefix_map.profile.push(old, new);
1100            }
1101            _ if arg.starts_with("-ffile-prefix-map=") => {
1102                let (old, new) = rewrite(arg, "-ffile-prefix-map=")?;
1103                opts.prefix_map.macros.push(old, new);
1104                opts.prefix_map.debug.push(old, new);
1105                opts.prefix_map.profile.push(old, new);
1106            }
1107            // A whole optimization rather than a flag, and the family is taken rather than
1108            // refused because of what ignoring it does. There is none of it here yet, so a build
1109            // that asks for it gets a program that is correct and slower than it could have been,
1110            // which is what section 4.1 means by a hint about speed and what every compilation at
1111            // `-O0` already is. The objects settle the rest of the argument: gcc's `-flto` object
1112            // holds the bytecode and no machine code at all, and every object here holds the code,
1113            // which is exactly what `-ffat-lto-objects` asks gcc for. So a build passing `-flto`
1114            // to this compiler gets objects that are more usable than the ones it asked for rather
1115            // than different ones. Every value is still checked against gcc's, because somebody
1116            // who wrote `-flto=thin` meant clang and had better hear about it here.
1117            "-flto" => opts.lto.requested = true,
1118            "-fno-lto" => opts.lto.requested = false,
1119            _ if arg.starts_with("-flto=") => {
1120                let how = &arg["-flto=".len()..];
1121                opts.lto.jobs = how.parse().map_err(|()| {
1122                    err(format!(
1123                        "`{how}` is not a number of link time jobs, which is auto, jobserver or a \
1124                         count above zero"
1125                    ))
1126                })?;
1127                opts.lto.requested = true;
1128            }
1129            _ if arg.starts_with("-flto-partition=") => {
1130                let how = &arg["-flto-partition=".len()..];
1131                opts.lto.partition = how.parse().map_err(|()| {
1132                    err(format!(
1133                        "`{how}` is not a partitioning model, which is balanced, 1to1, one, max \
1134                         or none"
1135                    ))
1136                })?;
1137            }
1138            _ if arg.starts_with("-flto-compression-level=") => {
1139                let how = &arg["-flto-compression-level=".len()..];
1140                let level =
1141                    how.parse::<u8>().ok().filter(|level| *level <= 19).ok_or_else(|| {
1142                        err(format!("`{how}` is not a compression level, 0 to 19"))
1143                    })?;
1144                opts.lto.compression = Some(level);
1145            }
1146            // Whether the object keeps its machine code as well as the bytecode. It always does
1147            // here, so the first of these describes what happens and the second asks for an object
1148            // with less in it, which is a smaller file and not a different program, so both are
1149            // taken.
1150            "-ffat-lto-objects" | "-fno-fat-lto-objects" => {}
1151            // Whether the linker is handed a plugin that does the link time work. The design in
1152            // `spec/09-optimizer.md` has this driver doing that work itself and never loading a
1153            // plugin into anybody, so neither answer is a question it has to hold.
1154            "-fuse-linker-plugin" | "-fno-use-linker-plugin" => {}
1155            // Reading a profile back. Taken for the reason the family above it is: nothing here
1156            // reads one, so a build that asks gets the program it would have got anyway, and gcc
1157            // itself produces a byte for byte identical object from `-fprofile-use` when there are
1158            // no counts beside the file. The path is recorded for the pass that will read it. The
1159            // warning gcc prints when it looked and found nothing is deliberately not copied,
1160            // because nothing here looks, and a warning about a file that was never opened would
1161            // fire on the builds that have a perfectly good profile as well as on the ones that
1162            // do not.
1163            "-fprofile-use" => opts.profile_data.requested = true,
1164            "-fno-profile-use" => opts.profile_data.requested = false,
1165            _ if arg.starts_with("-fprofile-use=") => {
1166                opts.profile_data.path = Some(arg["-fprofile-use=".len()..].to_string());
1167                opts.profile_data.requested = true;
1168            }
1169            _ if arg.starts_with("-fprofile-dir=") => {
1170                opts.profile_data.dir = Some(arg["-fprofile-dir=".len()..].to_string());
1171            }
1172            "-fprofile-abs-path" => opts.profile_data.absolute = true,
1173            "-fno-profile-abs-path" => opts.profile_data.absolute = false,
1174            "-fprofile-correction" => opts.profile_data.correction = true,
1175            "-fno-profile-correction" => opts.profile_data.correction = false,
1176            "-fprofile-partial-training" => opts.profile_data.partial_training = true,
1177            "-fno-profile-partial-training" => opts.profile_data.partial_training = false,
1178            // Writing the counts rather than reading them, which is refused rather than taken and
1179            // is the same line `-gsplit-dwarf` falls on the far side of. Ignoring these means a
1180            // file a build declared as an output never appears: the instrumented program writes a
1181            // `.gcda` as it exits and `-ftest-coverage` writes a `.gcno` beside the object, and a
1182            // two stage build that got neither would go on to optimize against no counts at all
1183            // and report coverage of nothing, with nothing along the way saying so. The objects
1184            // say the rest: gcc's `-fprofile-generate` object holds 375 bytes of code where a
1185            // plain one holds 71, and 296 bytes of counters that a plain one does not have, so
1186            // this is a flag that changes the output rather than a hint about speed.
1187            "-fprofile-arcs"
1188            | "--coverage"
1189            | "-fcondition-coverage"
1190            | "-fpath-coverage"
1191            | "-fprofile-generate" => {
1192                return Err(err(format!(
1193                    "{arg}: this compiler does not instrument for profiling, and a build that \
1194                     expects the counts a run of the instrumented program writes would optimize \
1195                     against nothing on its second pass, see spec/04-driver-and-cli.md"
1196                )));
1197            }
1198            _ if arg.starts_with("-fprofile-generate=") => {
1199                return Err(err(format!(
1200                    "{arg}: this compiler does not instrument for profiling, and a build that \
1201                     expects the counts a run of the instrumented program writes would optimize \
1202                     against nothing on its second pass, see spec/04-driver-and-cli.md"
1203                )));
1204            }
1205            "-ftest-coverage" => {
1206                return Err(err(format!(
1207                    "{arg}: this compiler writes no `.gcno` file beside the object, and a build \
1208                     that expects one would wait for a file that never arrives, see \
1209                     spec/04-driver-and-cli.md"
1210                )));
1211            }
1212            // The rest of the family describes instrumentation that is refused above, so what is
1213            // left to do with them is check them and drop them. They are checked because a
1214            // misspelling in a distribution's flags is worth finding here rather than on the day
1215            // the instrumentation lands, and dropped because there is nothing for an answer about
1216            // how a counter is written to be an answer about.
1217            _ if arg.starts_with("-fprofile-update=") => {
1218                let how = &arg["-fprofile-update=".len()..];
1219                if !matches!(how, "single" | "atomic" | "prefer-atomic") {
1220                    return Err(err(format!(
1221                        "`{how}` is not a profile update method, which is single, atomic or \
1222                         prefer-atomic"
1223                    )));
1224                }
1225            }
1226            _ if arg.starts_with("-fprofile-reproducible=") => {
1227                let how = &arg["-fprofile-reproducible=".len()..];
1228                if !matches!(how, "serial" | "parallel-runs" | "multithreaded") {
1229                    return Err(err(format!(
1230                        "`{how}` is not a profile reproducibility method, which is serial, \
1231                         parallel-runs or multithreaded"
1232                    )));
1233                }
1234            }
1235            "-fprofile-values" | "-fno-profile-values" | "-fprofile-info-section" => {}
1236            "-fno-test-coverage" | "-fno-profile-arcs" | "-fno-profile-generate" => {}
1237            _ if arg.starts_with("-fprofile-filter-files=")
1238                || arg.starts_with("-fprofile-exclude-files=")
1239                || arg.starts_with("-fprofile-note=") => {}
1240            // What every name gets when nothing in the source said, which the attribute in the
1241            // source overrides rather than the other way round. Before the optimizer's `-f`
1242            // family below for the reason the tier below it is.
1243            _ if arg.starts_with("-fvisibility=") => {
1244                let seen = &arg["-fvisibility=".len()..];
1245                opts.visibility = seen.parse().map_err(|()| {
1246                    err(format!(
1247                        "`{seen}` is not a visibility, which is default, hidden, internal or \
1248                         protected"
1249                    ))
1250                })?;
1251            }
1252            // Which edges of a control flow transfer are checked. Before the optimizer's `-f`
1253            // family below for the reason the two above it are, and last of the three so that the
1254            // bare spelling and the negative one are matched exactly rather than by this.
1255            _ if arg.starts_with("-fcf-protection=") => {
1256                let edges = &arg["-fcf-protection=".len()..];
1257                opts.control = edges.parse().map_err(|()| {
1258                    err(format!(
1259                        "`{edges}` is not a control flow protection, which is full, branch, \
1260                         return, none or check"
1261                    ))
1262                })?;
1263            }
1264            // How much room every function opens with for something to be written over later.
1265            // Before the optimizer's `-f` family below for the reason the ones above it are.
1266            _ if arg.starts_with("-fpatchable-function-entry=") => {
1267                let room = &arg["-fpatchable-function-entry=".len()..];
1268                opts.patchable = room.parse().map_err(|()| {
1269                    err(format!(
1270                        "`{room}` is not an amount of room to reserve, which is a number of bytes                          and then, after a comma, how many of them go in front of the function's                          own label"
1271                    ))
1272                })?;
1273            }
1274            // The memory safety monitor, from section 15.4 of
1275            // `spec/safe-memory/15-integration.md`. Before the optimizer's `-f` family below,
1276            // because a pass that took the name `safety=detect` would otherwise be handed the
1277            // flag, and the tier is not a pass.
1278            _ if arg.starts_with("-fsafety=") => {
1279                let tier = &arg["-fsafety=".len()..];
1280                opts.safety = tier.parse().map_err(|()| {
1281                    err(format!(
1282                        "`{tier}` is not a safety tier, which is off, detect, enforce or kernel"
1283                    ))
1284                })?;
1285            }
1286            // Whether padding participates, from section 9.3 of document 09. Spelled out rather
1287            // than folded into the tier because it is a departure somebody who has read that
1288            // section makes, and the two defaults it describes are a property of what is being
1289            // built rather than of how much checking is wanted.
1290            _ if arg.starts_with("-fsafety-init=") => {
1291                let mode = &arg["-fsafety-init=".len()..];
1292                opts.padding = mode.parse().map_err(|()| {
1293                    err(format!("`{mode}` is not a padding mode, which is padding or nopadding"))
1294                })?;
1295            }
1296            // Row S4, from section 9.4 of document 09. A bare flag with no value, because the
1297            // strict form of that section needs a member id the front end does not name yet and
1298            // accepting the spelling for it would be accepting a promise this build cannot keep.
1299            // Before `-fno-` is looked at below, for the reason the tier is.
1300            "-fsafety-subobject" => opts.subobject = rucc_session::Subobject::Members,
1301            "-fno-safety-subobject" => opts.subobject = rucc_session::Subobject::Off,
1302            _ if arg.starts_with("-fsafety-subobject=") => {
1303                let form = &arg["-fsafety-subobject=".len()..];
1304                return Err(err(format!(
1305                    "`{form}` is not a form of -fsafety-subobject. The flag takes no value, and \
1306                     the strict form of section 9.4 is tamnd/rucc#967"
1307                )));
1308            }
1309            // Row Y8, from section 9.6 of document 09. A bare flag with no value, for the reason
1310            // the one above has none: there is one form of this check and a spelling that suggested
1311            // otherwise would be promising something. Before `-fno-` is looked at below, the same
1312            // way.
1313            "-fsafety-restrict" => opts.promise = rucc_session::Promise::Blocks,
1314            "-fno-safety-restrict" => opts.promise = rucc_session::Promise::Off,
1315            _ if arg.starts_with("-fsafety-restrict=") => {
1316                let form = &arg["-fsafety-restrict=".len()..];
1317                return Err(err(format!(
1318                    "`{form}` is not a form of -fsafety-restrict. The flag takes no value."
1319                )));
1320            }
1321            // Section 9.5's races, which take a value because the section gives them three modes
1322            // and the difference between two of them is which classes get reported rather than how
1323            // much is recorded. `-fno-` is the same as `=off` and is spelled out here for the same
1324            // reason the two above spell theirs out.
1325            _ if arg.starts_with("-fsafety-races=") => {
1326                let mode = &arg["-fsafety-races=".len()..];
1327                opts.races = mode.parse().map_err(|()| {
1328                    err(format!("`{mode}` is not a race mode, which is off, metadata or pointer"))
1329                })?;
1330            }
1331            "-fno-safety-races" => opts.races = rucc_session::Races::Off,
1332            // The sanitizers of document 12, which are checks at run time rather than a way of
1333            // generating the same program. Each name is held to gcc 16's list, and what is still
1334            // asked for by the end of the line is answered after the loop, so that a command line
1335            // which turns one on and then off again is a command line that asked for nothing.
1336            //
1337            // Before the optimizer's `-f` family below, for the reason the tier above it is.
1338            _ if arg.starts_with("-fsanitize=") => {
1339                for one in arg["-fsanitize=".len()..].split(',') {
1340                    if one == "all" {
1341                        // gcc takes `all` only in the negative, because turning every check on at
1342                        // once includes checks that contradict each other.
1343                        return Err(err(
1344                            "`-fsanitize=all` is not a gcc option, only `-fno-sanitize=all` is",
1345                        ));
1346                    }
1347                    if !SANITIZERS.contains(&one) {
1348                        return Err(err(format!(
1349                            "`{one}` is not a sanitizer, see spec/04-driver-and-cli.md section 4.7"
1350                        )));
1351                    }
1352                    if !sanitizers.contains(&one) {
1353                        sanitizers.push(one);
1354                    }
1355                }
1356            }
1357            _ if arg.starts_with("-fno-sanitize=") => {
1358                for one in arg["-fno-sanitize=".len()..].split(',') {
1359                    if one == "all" {
1360                        sanitizers.clear();
1361                        continue;
1362                    }
1363                    if !SANITIZERS.contains(&one) {
1364                        return Err(err(format!(
1365                            "`{one}` is not a sanitizer, see spec/04-driver-and-cli.md section 4.7"
1366                        )));
1367                    }
1368                    sanitizers.retain(|asked| *asked != one);
1369                }
1370            }
1371            // What a check does when it fires, and where the records about the checked objects go.
1372            // Each of them is an answer about the sanitizers refused after the loop, so there is
1373            // nothing left for them to change here. The names are still held to the list, because
1374            // a misspelling in a build's flags is worth finding when the compiler reads it.
1375            _ if arg.starts_with("-fsanitize-recover=")
1376                || arg.starts_with("-fno-sanitize-recover=")
1377                || arg.starts_with("-fsanitize-trap=")
1378                || arg.starts_with("-fno-sanitize-trap=") =>
1379            {
1380                // The guard above matched on a spelling that has an `=` in it, so the tail is
1381                // whatever follows the first one.
1382                let how = arg.split_once('=').map_or("", |(_, rest)| rest);
1383                for one in how.split(',') {
1384                    if one != "all" && !SANITIZERS.contains(&one) {
1385                        return Err(err(format!(
1386                            "`{one}` is not a sanitizer, see spec/04-driver-and-cli.md section 4.7"
1387                        )));
1388                    }
1389                }
1390            }
1391            "-fsanitize-undefined-trap-on-error"
1392            | "-fsanitize-address-use-after-scope"
1393            | "-fno-sanitize-address-use-after-scope" => {}
1394            _ if arg.starts_with("-fsanitize-sections=") => {}
1395            // Counting which edges a run reached, which is how a fuzzer knows an input was worth
1396            // keeping. Refused rather than dropped, because a fuzzer whose calls into
1397            // `__sanitizer_cov_*` were never generated runs blind and reports coverage of nothing,
1398            // and there is no point in the campaign where that announces itself.
1399            _ if arg.starts_with("-fsanitize-coverage=") => {
1400                let how = &arg["-fsanitize-coverage=".len()..];
1401                for one in how.split(',') {
1402                    if !matches!(one, "trace-pc" | "trace-cmp") {
1403                        return Err(err(format!(
1404                            "`{one}` is not a coverage instrumentation, which is trace-pc or \
1405                             trace-cmp"
1406                        )));
1407                    }
1408                }
1409                return Err(err(format!(
1410                    "{arg}: this compiler generates no coverage callbacks, and a fuzzer built \
1411                     with it would run without any feedback at all, see \
1412                     spec/04-driver-and-cli.md section 4.7"
1413                )));
1414            }
1415            // The optimizer's own flags, from section 9.10 of `spec/09-optimizer.md`. These come
1416            // after every `-f` the rest of the compiler answers to, so a pass can never take a
1417            // name that already means something else on the command line.
1418            _ if arg.starts_with("-fpass-fuel=") => {
1419                let (name, count) = arg["-fpass-fuel=".len()..]
1420                    .split_once('=')
1421                    .ok_or_else(|| err("-fpass-fuel= is spelled <pass>=<count>"))?;
1422                if rucc_opt::pass::find(name).is_none() {
1423                    return Err(err(format!(
1424                        "`{name}` is not a pass this compiler has, see --print-pipeline"
1425                    )));
1426                }
1427                let count: u32 = count
1428                    .parse()
1429                    .map_err(|_| err(format!("`{count}` is not a number of transformations")))?;
1430                opts.pass_fuel.push((name.to_owned(), count));
1431            }
1432            _ if arg.starts_with("-fpass-fuel-global=") => {
1433                let count = &arg["-fpass-fuel-global=".len()..];
1434                let count: u32 = count
1435                    .parse()
1436                    .map_err(|_| err(format!("`{count}` is not a number of transformations")))?;
1437                opts.pass_fuel_global = Some(count);
1438            }
1439            // Everything from `-fopt-info` to the end of the argument, which is optional
1440            // keywords joined by hyphens and an optional `=<file>`. Checked here rather than
1441            // where the remarks are printed, because by then the compilation somebody wanted
1442            // to hear about is over.
1443            _ if arg == "-fopt-info"
1444                || arg.starts_with("-fopt-info=")
1445                || arg.starts_with("-fopt-info-") =>
1446            {
1447                let rest = &arg["-fopt-info".len()..];
1448                let (kinds, file) = match rest.split_once('=') {
1449                    Some((kinds, file)) => (kinds, Some(file)),
1450                    None => (rest, None),
1451                };
1452                let kinds = kinds.strip_prefix('-').unwrap_or(kinds);
1453                rucc_opt::Wants::none().add(kinds).map_err(err)?;
1454                opts.opt_info.push(kinds.to_owned());
1455                if let Some(file) = file {
1456                    if file.is_empty() {
1457                        return Err(err("-fopt-info= was given no file to write to"));
1458                    }
1459                    opts.opt_info_file = Some(file.to_owned());
1460                }
1461            }
1462            _ if arg.starts_with("-fdump-ir=") => {
1463                // Checked here rather than where the dumps are taken, because the compilation
1464                // that would have been dumped is over by then.
1465                let spec = &arg["-fdump-ir=".len()..];
1466                rucc_opt::Dumps::default().add(spec).map_err(err)?;
1467                opts.dump_ir.push(spec.to_owned());
1468            }
1469            // Before the bare `-f<pass>` below, because a pass called `enable-something` would
1470            // otherwise take the flag away from the gate. Checked here rather than where the
1471            // pipeline reads it, for the reason that applies to all of these: a misspelled pass
1472            // name that quietly gated nothing looks exactly like a pass that is not the guilty
1473            // one, and a bisection would carry on past the thing it was looking for.
1474            _ if arg.starts_with("-fdisable-") || arg.starts_with("-fenable-") => {
1475                let on = arg.starts_with("-fenable-");
1476                let spec = &arg[if on { "-fenable-".len() } else { "-fdisable-".len() }..];
1477                rucc_opt::Gates::default().add(on, spec).map_err(err)?;
1478                opts.pass_gates.push((on, spec.to_owned()));
1479            }
1480            // gcc's spelling for a pass this compiler has under a shorter name. It goes above the
1481            // two arms below rather than into the pile of gcc pass names further down, because the
1482            // pass is here: dropping the flag would leave a build that asked for unrolling without
1483            // it, and refusing it stops the build outright, which is what libtommath's makefile
1484            // ran into. `-funroll-all-loops` is deliberately not in here: gcc's is the one that
1485            // unrolls without a trip count, which is a different and usually worse thing.
1486            "-funroll-loops" => opts.passes.push(("unroll".to_owned(), true)),
1487            "-fno-unroll-loops" => opts.passes.push(("unroll".to_owned(), false)),
1488            _ if arg.strip_prefix("-fno-").is_some_and(|n| rucc_opt::pass::find(n).is_some()) => {
1489                opts.passes.push((arg["-fno-".len()..].to_owned(), false));
1490            }
1491            _ if arg.strip_prefix("-f").is_some_and(|n| rucc_opt::pass::find(n).is_some()) => {
1492                opts.passes.push((arg["-f".len()..].to_owned(), true));
1493            }
1494            // The flags that name a pass of gcc's own. They arrive from the torture suite, where a
1495            // program reduced from a miscompilation usually names the pass that miscompiled it on
1496            // its `dg-options` line, and they arrive from hand written build files for the same
1497            // reason. Section 4.1 sorts a flag by what the output would be without it, and by that
1498            // rule these are one pile: a flag that turns one of gcc's passes on or off is asking
1499            // for a compiler that does not exist here, and the program it is attached to is a
1500            // correctness test that passes either way. Turning on a pass we do not have costs
1501            // speed, turning off a pass we do not have costs nothing, and neither changes what the
1502            // program computes.
1503            //
1504            // rucc's own pass names are matched above this, so `-fno-dce` turns off the dce this
1505            // compiler has rather than landing here, and the day one of these names becomes a pass
1506            // here it stops being taken and dropped without anybody editing this list.
1507            //
1508            // Two of them are prefixes rather than names, which is the one place this file takes a
1509            // family instead of a flag. gcc files its gimple passes under `-ftree-` and its
1510            // interprocedural passes under `-fipa-`, both namespaces are pass selection and
1511            // nothing else, and there is no member of either that changes the meaning of a program
1512            // that was already correct. The rest are written out one at a time, because they live
1513            // in the flat `-f` namespace where the neighbours do change meanings.
1514            _ if arg.starts_with("-ftree-") || arg.starts_with("-fno-tree-") => {}
1515            _ if arg.starts_with("-fipa-") || arg.starts_with("-fno-ipa-") => {}
1516            "-fexpensive-optimizations" | "-fno-expensive-optimizations" => {}
1517            "-fmodulo-sched" | "-fno-modulo-sched" => {}
1518            "-fvect-cost-model" | "-fno-vect-cost-model" => {}
1519            _ if arg.starts_with("-fvect-cost-model=") || arg.starts_with("-fsimd-cost-model=") => {
1520            }
1521            "-fearly-inlining" | "-fno-early-inlining" => {}
1522            "-finline"
1523            | "-fno-inline"
1524            | "-finline-functions"
1525            | "-fno-inline-functions"
1526            | "-finline-small-functions"
1527            | "-fno-inline-small-functions"
1528            | "-finline-functions-called-once"
1529            | "-fno-inline-functions-called-once" => {}
1530            "-foptimize-strlen" | "-fno-optimize-strlen" => {}
1531            "-fira-share-spill-slots" | "-fno-ira-share-spill-slots" => {}
1532            // The charset flags are not in that pile, because an encoding is a statement about
1533            // what the bytes of the source mean rather than about how fast the output is. The
1534            // preprocessor reads UTF-8 and has no converter, so the one name that describes what
1535            // already happens is taken and every other name is refused. Spelled without regard to
1536            // case and with both of the spellings iconv answers to, since a build writes whichever
1537            // one its author typed.
1538            _ if arg.starts_with("-finput-charset=") => {
1539                let name = &arg["-finput-charset=".len()..];
1540                if !name.eq_ignore_ascii_case("utf-8") && !name.eq_ignore_ascii_case("utf8") {
1541                    return Err(err(format!(
1542                        "-finput-charset={name}: the preprocessor reads UTF-8 and has no \
1543                         converter, so a file in another encoding would be read as though it were \
1544                         UTF-8 rather than converted",
1545                    )));
1546                }
1547            }
1548            // The three that come in on the same `dg-options` lines and are the other half of
1549            // section 4.1's rule, because each of them changes what the program does and not how
1550            // fast it does it. The negative form of each is what this compiler does anyway, so it
1551            // is taken and dropped, which is the shape `-fnested-functions` has above.
1552            "-ffast-math" => {
1553                return Err(err(
1554                    "-ffast-math is a licence to answer a floating point arithmetic differently \
1555                     from the way the source wrote it, and it is not one flag: it defines \
1556                     __FAST_MATH__, which a library header reads, and gcc links a startup file \
1557                     that puts the hardware in flush to zero mode for the whole process. Taking it \
1558                     and dropping it would change what other objects in the same program answer. \
1559                     -ffp-contract= and -fexcess-precision= are the parts of it this compiler has",
1560                ));
1561            }
1562            "-fno-fast-math" => {}
1563            "-fnon-call-exceptions" => {
1564                return Err(err(
1565                    "-fnon-call-exceptions is a promise that an instruction which is not a call \
1566                     can raise an exception the unwinder finds a handler for, and nothing here \
1567                     produces a landing pad for a trapping instruction. A program built without it \
1568                     would unwind past the handler it wrote",
1569                ));
1570            }
1571            "-fno-non-call-exceptions" => {}
1572            "-finstrument-functions" => {
1573                return Err(err(
1574                    "-finstrument-functions calls __cyg_profile_func_enter on entry to every \
1575                     function and __cyg_profile_func_exit on the way out, and nothing here emits \
1576                     either call. A program that asks for them usually counts them, so taking the \
1577                     flag and dropping it would turn a program that fails loudly into one that \
1578                     fails quietly",
1579                ));
1580            }
1581            "-fno-instrument-functions" => {}
1582            // The unstable options, spelled the way rustc spells them and carrying the same
1583            // promise, which is none: one of these may change or go away in any release. They are
1584            // measurements and debugging aids rather than things a build asks for, which is why
1585            // none of them is in the usage text and all of them are in section 4.11 of
1586            // `spec/04-driver-and-cli.md`.
1587            "-Zverify-each" => opts.verify_each = true,
1588            _ if arg.starts_with("-Zrule-coverage=") => {
1589                let file = &arg["-Zrule-coverage=".len()..];
1590                if file.is_empty() {
1591                    return Err(err("-Zrule-coverage= needs a file to write to"));
1592                }
1593                opts.rule_coverage = Some(file.to_owned());
1594            }
1595            _ if arg.starts_with("-Zcycle-accurate-model=") => {
1596                let value = &arg["-Zcycle-accurate-model=".len()..];
1597                opts.cycle_accurate_model = match value {
1598                    "yes" | "1" => Some(true),
1599                    "no" | "0" => Some(false),
1600                    _ => {
1601                        return Err(err("-Zcycle-accurate-model= takes yes or no"));
1602                    }
1603                };
1604            }
1605            _ if arg.starts_with("-Zlowering=") => {
1606                let file = &arg["-Zlowering=".len()..];
1607                if file.is_empty() {
1608                    return Err(err("-Zlowering= needs a file to write to"));
1609                }
1610                opts.lowering_dump = Some(file.to_owned());
1611            }
1612            _ if arg.starts_with("-Zregister-pressure=") => {
1613                let file = &arg["-Zregister-pressure=".len()..];
1614                if file.is_empty() {
1615                    return Err(err("-Zregister-pressure= needs a file to write to"));
1616                }
1617                opts.register_pressure = Some(file.to_owned());
1618            }
1619            _ if arg.starts_with("-Z") => {
1620                return Err(err(format!(
1621                    "`{arg}` is not an unstable option this compiler has, see \
1622                     spec/04-driver-and-cli.md section 4.11 for the ones it does"
1623                )));
1624            }
1625            // The word size, which is a statement about the target and is taken as one. A build
1626            // that says the size the target already has is saying nothing, and one that says the
1627            // other size is asking for a target this compiler does not have, which it is told
1628            // rather than being given the wrong one.
1629            "-m64" | "-m32" | "-mx32" => {
1630                let want: u32 = match arg {
1631                    "-m64" => 64,
1632                    _ => 32,
1633                };
1634                let have = rucc_target::TargetInfo::new(opts.target).pointer_width;
1635                if have != want {
1636                    return Err(err(format!(
1637                        "{arg} asks for a {want} bit target and {} is {have} bit, use \
1638                         --target= to name the one you mean",
1639                        opts.target
1640                    )));
1641                }
1642            }
1643            // Which processor in the family to generate for. This compiler emits the base
1644            // instruction set of the architecture and nothing above it, so a program built with
1645            // any of these runs on the machine that was named; it is a program that could have
1646            // been faster rather than a program that is wrong, which is what makes these safe to
1647            // take and ignore where a flag that changed the meaning of the code would not be.
1648            _ if arg.starts_with("-march=")
1649                || arg.starts_with("-mtune=")
1650                || arg.starts_with("-mcpu=") => {}
1651            // The calling convention, which is not safe to ignore. Taken when it names the one
1652            // the target already uses and refused otherwise.
1653            _ if arg.starts_with("-mabi=") => {
1654                let want = &arg["-mabi=".len()..];
1655                let have = match opts.target.arch {
1656                    rucc_target::Arch::X86_64 => "sysv",
1657                    rucc_target::Arch::Aarch64 => "lp64",
1658                    rucc_target::Arch::Riscv64 => "lp64d",
1659                };
1660                if want != have {
1661                    return Err(err(format!(
1662                        "{arg}: {} uses the {have} convention and this compiler has no other",
1663                        opts.target
1664                    )));
1665                }
1666            }
1667            // How far apart the pieces of the program may be. The small model is what we emit and
1668            // it is every hosted program's default; the kernel model is a different one and a
1669            // build that asks for it and does not get it links and then does not run.
1670            "-mcmodel=small" => {}
1671            _ if arg.starts_with("-mcmodel=") => {
1672                return Err(err(format!(
1673                    "{arg}: this compiler emits the small code model and no other, see \
1674                     spec/12-targets.md"
1675                )));
1676            }
1677            // GCC's own scripting language for how the driver builds a command line.
1678            // `spec/04-driver-and-cli.md` section 4.4 settles that we will not have it, so a
1679            // build reaching for it is told which flags do the same job.
1680            _ if arg.starts_with("-specs=") => {
1681                return Err(err(
1682                    "-specs= is not supported: the parts of it builds rely on are -B, -L, \
1683                     -nostdlib, -nostartfiles and -Wl,, see spec/04-driver-and-cli.md \
1684                     section 4.4",
1685                ));
1686            }
1687            // Arguments meant for a separate assembler or preprocessor, which this compiler does
1688            // not have: both are inside it and neither reads a command line. Refused rather than
1689            // dropped, because every one of these says something about the output and a build
1690            // that asked for `-Wa,--noexecstack` and was silently given an executable stack got
1691            // the opposite of what it asked for.
1692            _ if arg.starts_with("-Wa,") || arg.starts_with("-Wp,") => {
1693                return Err(err(format!(
1694                    "`{arg}` is an argument for a separate assembler or preprocessor, and both \
1695                     are inside this compiler rather than programs it runs"
1696                )));
1697            }
1698            "-Xassembler" | "-Xpreprocessor" => {
1699                return Err(err(format!(
1700                    "{arg} hands an argument to a separate assembler or preprocessor, and both \
1701                     are inside this compiler rather than programs it runs"
1702                )));
1703            }
1704            // Everything else in the `-W` family. `spec/04-driver-and-cli.md` section 4.1 has
1705            // this one as a rule about build systems rather than about warnings: autoconf finds
1706            // out whether a warning flag exists by passing it and looking at the exit status, so
1707            // a compiler that refuses one it has not heard of fails a configure script written
1708            // for a GCC newer than itself. The names are not checked against a list because this
1709            // compiler has no warning groups for a list to be of, which #485 is about.
1710            _ if arg.starts_with("-W") => {}
1711            // Flags that name something this compiler does not do and would not do differently
1712            // if it did. `-fno-ident` is about a comment in the output that we do not write
1713            // either way, and the others are about a way of ordering the compilation that has
1714            // been GCC's only way for twenty years. Section 4.1 asks for the list to be short
1715            // and for adding to it to be deliberate, which is why it is written out here.
1716            "-fno-ident"
1717            | "-fident"
1718            | "-funit-at-a-time"
1719            | "-fno-unit-at-a-time"
1720            | "-shared-libgcc"
1721            | "-static-libgcc" => {}
1722            _ if arg.starts_with('-') && arg.len() > 1 => {
1723                // Silently ignoring an unknown flag is how a build ends up not doing what
1724                // its author asked. spec/13-gnu-compat.md section 13.4 makes this an error
1725                // for the flags that change code generation, and the safe default until the
1726                // flag table is populated is to reject everything we do not know.
1727                return Err(err(format!("unknown option `{arg}`")));
1728            }
1729            _ => inputs.push(Input { path: arg.to_owned(), forced, role: Role::File }),
1730        }
1731    }
1732
1733    // The fetch, before anything that resolves a compilation, because `--fetch` does not describe
1734    // one. It is here rather than in the loop so that `--offline` can forbid it whichever order the
1735    // two were written in, and it is before the refusals below so that a command line asking for a
1736    // sysroot is not told about a sanitizer.
1737    if let Some(named) = fetch {
1738        return fetch_action(&named, offline, &inputs);
1739    }
1740
1741    // Last, so that it lands after every `-isystem` the command line gave. That is GCC's
1742    // order: a directory the user names outranks the compiler's own, and the compiler's own
1743    // outranks the library's. It is pushed after the loop rather than before it because
1744    // `SearchPath` appends within a group and the position is what the order is.
1745    // The same directory the headers were looked for under, because a sysroot is a statement
1746    // about a whole installation and not about half of one.
1747    // After the loop, because `-fno-sanitize=` can take back what an earlier flag asked for and a
1748    // command line that turns a check on and off again has asked for nothing. What is left is
1749    // refused rather than dropped, and it is the one place in this parser where the reason is not
1750    // that the output would differ. A sanitizer is a promise that the program is watched while it
1751    // runs, so a build that asks for one and is quietly given a program with no checks in it does
1752    // not get a slower program or a bigger file, it gets a test suite that passes for the wrong
1753    // reason. `-fsafety=` is the checking this compiler does have, and the message says so, because
1754    // somebody reaching for `-fsanitize=address` wants the nearest thing rather than a list of
1755    // options.
1756    if let Some(first) = sanitizers.first() {
1757        return Err(err(format!(
1758            "-fsanitize={first}: this compiler has no sanitizer instrumentation, and a build that \
1759             asked for one and got none would run its tests unchecked, see \
1760             spec/04-driver-and-cli.md section 4.7. `-fsafety=detect` is the memory checking this \
1761             compiler does have"
1762        )));
1763    }
1764    link.sysroot = sysroot.clone();
1765    // Where a sysroot for a target that is not this machine would be. Read once, here, rather than
1766    // inside the link line, because a link line that read the environment could only be tested on a
1767    // machine whose environment said the right thing, and the link line is the last thing that
1768    // touches a binary. `spec/cross-compile/13-distribution.md` section 13.2 owns the answer.
1769    link.cache = Some(cache::dir());
1770    // And the ten field spelling of the target, because the release on it decides two things the
1771    // three field one cannot say: whether a target that is this architecture is still a cross
1772    // compile, and which directory under the cache it is against. After the loop because the last
1773    // `--target=` on the command line is the one that counts.
1774    link.pinned = pinned;
1775    // After the loop rather than where `-pthread` was read, so that it lands after the objects
1776    // that refer to it. A static link takes the definitions it needs from a library when it
1777    // reaches it and not afterwards, so a library before the objects is a library that answers
1778    // nothing.
1779    if threads {
1780        inputs.push(Input::library("pthread"));
1781    }
1782    if let Some(query) = query {
1783        return Ok(Action::Print(answer(&query, &opts, &link)?));
1784    }
1785    // `-M` and `-MM` produce the rule and nothing else, so the run stops after phase 4 whatever
1786    // else the command line asked for. Read here rather than where the flag was, because a `-c`
1787    // written after it has to lose and the loop cannot know that until it has ended. The output
1788    // file is where the rule goes rather than where an object would have gone, and the last
1789    // phase being the preprocessor is what makes that true without a second rule for it.
1790    if opts.deps.instead_of_compiling {
1791        opts.emit = EmitKind::Preprocessed;
1792    }
1793    if !nostdinc {
1794        opts.search.push_system(runtime::DIR);
1795        // And the library's after ours, which is the other half of the same order. They go on
1796        // here rather than at the point `--target=` or `--sysroot=` was read because either
1797        // one changes the answer and the last word on both is the end of the loop.
1798        //
1799        // Which library's is the question `link::cross_sysroot` answers, and it is asked here so
1800        // that the headers and the libraries come from the same place. A target that is this
1801        // machine reads this machine's headers, and a target that is not reads the ones in the
1802        // sysroot for it rather than the ones next door.
1803        let cross = link::cross_sysroot(opts.target, &link);
1804        let kernel = link::cross_kernel(opts.target, &link);
1805        // And the version of those headers, which only the bundled tree has an answer for. A host
1806        // glibc and a tree the user named both define `__GLIBC_MINOR__` in their own `features.h`,
1807        // and a second definition with a different value is a warning on every file, so the
1808        // condition is the same one that chose the directories.
1809        if cross.is_some() {
1810            let target = pinned.unwrap_or_else(|| opts.target.tuple());
1811            opts.glibc_minor = rucc_sysroot::bundled_glibc_minor(target).map_err(|skew| {
1812                err(format!(
1813                    "{skew}; pin a release the tree has, or name a tree that has that one \
1814                     with --sysroot"
1815                ))
1816            })?;
1817        }
1818        let system =
1819            library::header_dirs(opts.target, sysroot.as_deref(), cross.as_ref(), kernel.as_ref());
1820        // The two licence walls of `spec/cross-compile/13-distribution.md` section 13.4, which are
1821        // the only way step 3 comes back with nothing on a hosted target. Section 8.6 asks for the
1822        // answer to name the licence and the lawful ways to get what is behind it, rather than
1823        // leaving a person with an `#include` that failed as though a directory had gone missing.
1824        //
1825        // It is left on the search path instead of refused here, because a program that includes
1826        // none of the library needs none of the SDK and section 8.6 is explicit that targeting the
1827        // platform has to keep working. So the reason waits until an include has actually failed,
1828        // which is the only moment it helps and the only moment it is true.
1829        //
1830        // The condition is that step 3 found nothing at all, so an `SDKROOT`, an `INCLUDE` or a mac
1831        // with Xcode on it all pass through untouched, and `-nostdinc` never reaches this block. A
1832        // `--sysroot` or `-isysroot` passes through as well, even when the tree it names turns out to
1833        // be empty or absent: somebody who wrote a path has already answered the question this
1834        // message asks, and answering it again over the top of a mistyped directory would hide the
1835        // mistake behind a licence notice.
1836        if system.is_empty() && sysroot.is_none() {
1837            let tuple = pinned.unwrap_or_else(|| opts.target.tuple());
1838            if let Some(wall) = rucc_sysroot::Wall::of(tuple) {
1839                opts.search.explain_missing_system(wall.no_headers(&tuple.to_canonical_string()));
1840            }
1841        }
1842        // And whether the tree somebody named is the release they asked for, which is the one
1843        // question left once the directories are settled and the only place both halves of it are
1844        // known. Only for a named tree, because that is the case where the release in the target
1845        // stops deciding anything, and `crate::glibc` is where the rest of the reasoning is.
1846        if sysroot.is_some() {
1847            notes.extend(glibc::skew(opts.target, pinned, &system));
1848        }
1849        for dir in system {
1850            opts.search.push_system(dir);
1851        }
1852    }
1853    // Once, here, rather than as each directory is pushed. A `-I` that names a system
1854    // directory has to lose to the system entry and the system entry is added last, so the
1855    // question cannot be answered until the whole path is known.
1856    opts.search.remove_duplicates();
1857
1858    // The target has to be resolved before the configuration is printed, so this check comes
1859    // after the loop rather than at the point `--print-config` was seen.
1860    if print_config {
1861        return Ok(Action::PrintConfig(Box::new(opts)));
1862    }
1863    if print_pipeline {
1864        return Ok(Action::PrintPipeline(Box::new(opts)));
1865    }
1866    let plan = Plan::new(&opts, &inputs, output.as_deref()).map_err(|e| err(e.message))?;
1867    if print_plan {
1868        return Ok(Action::PrintPlan {
1869            opts: Box::new(opts),
1870            plan: Box::new(plan),
1871            link: Box::new(link),
1872        });
1873    }
1874    Ok(Action::Compile {
1875        opts: Box::new(opts),
1876        plan: Box::new(plan),
1877        link: Box::new(link),
1878        jobs,
1879        verbose,
1880        notes,
1881    })
1882}
1883
1884/// What `--fetch <tuple>` asked for, or why it is not a thing that can be done.
1885///
1886/// The lookup happens here rather than at the point the bytes would move, so that a target this
1887/// release pins nothing for is a refusal from the parser and the only code that runs a downloader is
1888/// code that already knows what it is getting.
1889///
1890/// # Errors
1891///
1892/// [`CliError`] when `--offline` forbade it, when there are input files as well, when the tuple is
1893/// not a target this compiler knows, when its sysroot is behind one of section 13.4's licence walls,
1894/// and when this release pins no artifact for it.
1895fn fetch_action(named: &str, offline: bool, inputs: &[Input]) -> Result<Action, CliError> {
1896    // Not a precedence question. Section 13.2 says `--offline` forbids a fetch entirely, so a
1897    // command line that writes both has asked for two opposite things and the answer is to say so
1898    // rather than to pick one of them.
1899    if offline {
1900        return Err(err(
1901            "--fetch asks for a download and --offline forbids every download, so this command \
1902             line asks for two opposite things. Drop one of them: --offline is how a build says it \
1903             will not reach the network, and --fetch is the only thing in this compiler that does",
1904        ));
1905    }
1906    if let Some(first) = inputs.first() {
1907        return Err(err(format!(
1908            "--fetch gets a sysroot and compiles nothing, so `{}` on the same command line is an \
1909             input that nothing would read",
1910            first.path
1911        )));
1912    }
1913    let target: TargetTuple = named
1914        .parse()
1915        .map_err(|why| err(format!("--fetch {named}: {why}, so there is no sysroot to get")))?;
1916    // The canonical spelling, because that is what a row is named by and what the directory under
1917    // the cache is called, and a person is free to write a tuple the long way round.
1918    let tuple = target.to_canonical_string();
1919    // Before the table is consulted, because a target behind a licence wall is not a row that has not
1920    // been written yet. Section 13.4 is that no release pins one of these ever, so the message says
1921    // the licence and the two lawful ways rather than naming the producer that will publish the rest.
1922    if let Some(wall) = rucc_sysroot::Wall::of(target) {
1923        return Err(err(format!("--fetch {tuple}: {}", wall.no_fetch(&tuple))));
1924    }
1925    let Some(what) = rucc_sysroot::pinned_for(&tuple) else {
1926        return Err(err(unpinned(&tuple)));
1927    };
1928    Ok(Action::Fetch { what, target, cache: cache::dir() })
1929}
1930
1931/// Why there is nothing to fetch for a target, which is a different sentence while the table is
1932/// empty.
1933///
1934/// A release that pins nothing and a release that pins eleven targets and not this one are two
1935/// situations, and a message that did not tell them apart would send somebody looking for a typo in
1936/// their tuple when the answer is that this work is not finished.
1937fn unpinned(tuple: &str) -> String {
1938    let pinned = rucc_sysroot::pinned_targets();
1939    if pinned.is_empty() {
1940        return format!(
1941            "this release pins no sysroot for {tuple}, and it pins none for any target yet. A \
1942             sysroot is built and published by the producer in tamnd/rucc-cross, per \
1943             spec/cross-compile/13-distribution.md section 13.8, and a release of this compiler \
1944             names one by URL and by hash afterwards. Until then, pass --sysroot=<dir> to compile \
1945             against a tree you have already"
1946        );
1947    }
1948    format!(
1949        "this release pins no sysroot for {tuple}. What it pins is {}. Pass --sysroot=<dir> to \
1950         compile against a tree you have already",
1951        pinned.join(", ")
1952    )
1953}
1954
1955/// Gets the artifact and installs it, saying what each step did.
1956///
1957/// The steps are section 13.8's and so are the messages: the transport is somebody else's program
1958/// and the check is ours, so a person reading this wants to know which downloader ran, that the
1959/// bytes matched, how many files the record named and where the tree ended up. A fetch of something
1960/// that is already there says that instead and moves nothing.
1961fn fetch_sysroot(what: &rucc_sysroot::Pinned, target: TargetTuple, cache: &std::path::Path) -> i32 {
1962    let tuple = target.to_canonical_string();
1963    let archive = what.archive_in(cache);
1964    let say = |line: &str| println!("rucc: {tuple}: {line}");
1965    match fetch::fetch(what.url, what.sha256, &archive) {
1966        Ok(fetch::Fetched::AlreadyThere) => {
1967            say(&format!("{} is already here and matches the hash", archive.display()));
1968        }
1969        Ok(fetch::Fetched::Downloaded(by)) => {
1970            say(&format!("downloaded {} with {}", what.url, by.program()));
1971        }
1972        Err(why) => return complain(why),
1973    }
1974    match install::install(&archive, what.sha256, target, cache) {
1975        Ok(done) => {
1976            match &done.before {
1977                install::Before::Nothing => {
1978                    say(&format!("{} files installed at {}", done.files, done.root.display()));
1979                }
1980                install::Before::TheSame => {
1981                    say(&format!(
1982                        "the same sysroot is already at {}, so nothing moved",
1983                        done.root.display()
1984                    ));
1985                }
1986                install::Before::Different(was) => {
1987                    say(&format!(
1988                        "{} files installed at {}, over a tree whose record digested to {was}",
1989                        done.files,
1990                        done.root.display()
1991                    ));
1992                }
1993            }
1994            say(&format!("the record digests to {}", done.digest));
1995            0
1996        }
1997        Err(why) => complain(why),
1998    }
1999}
2000
2001/// What one of the `-dump` and `-print` flags prints.
2002///
2003/// GCC prints the name back unchanged when it cannot find the file a `-print` flag asked about,
2004/// which is what makes the answer safe to paste into a link line whether or not the file is
2005/// there, and this does the same.
2006fn answer(query: &Query, opts: &Options, link: &LinkOptions) -> Result<String, CliError> {
2007    let found = |name: &str| {
2008        link::find_in_search(link, opts.target, name)
2009            .map_or_else(|| name.to_owned(), |path| path.display().to_string())
2010    };
2011    Ok(match query {
2012        Query::Machine => opts.target.to_string(),
2013        Query::Version => VERSION.to_owned(),
2014        Query::Multiarch => link::multiarch(opts.target),
2015        // The three lines GCC prints, in its order and with its punctuation, because what reads
2016        // them is a script written against that shape. There is no installation directory to
2017        // report: this compiler is one binary that works wherever it is copied, and the headers
2018        // it ships are inside it, so `install` is where the binary is and nothing is under it.
2019        Query::SearchDirs => {
2020            let here = std::env::current_exe()
2021                .ok()
2022                .and_then(|p| p.parent().map(std::path::Path::to_path_buf))
2023                .unwrap_or_default();
2024            let list = |dirs: &[PathBuf]| {
2025                dirs.iter().map(|d| d.display().to_string()).collect::<Vec<_>>().join(":")
2026            };
2027            let libraries = link::search_dirs(link, opts.target);
2028            format!(
2029                "install: {}\nprograms: ={}\nlibraries: ={}",
2030                here.display(),
2031                list(&link.prefixes),
2032                list(&libraries)
2033            )
2034        }
2035        // The root the rest of the answers are under, which a build system asks for when it wants
2036        // to find a file itself rather than ask for one by name, and which is the first thing to
2037        // look at when a cross build read a header nobody expected. A native compile has no
2038        // sysroot and the answer is the empty line, which is what GCC prints when it was
2039        // configured without one. `--sysroot` wins over ours because it wins everywhere else.
2040        Query::Sysroot => {
2041            sysroot_root(opts, link).map(|root| root.display().to_string()).unwrap_or_default()
2042        }
2043        // Section 13.5 of `spec/cross-compile/13-distribution.md`: for every input that is not this
2044        // compiler's own code, what it is, where it was got, its hash, its licence and whether it
2045        // was bundled, generated or fetched. What is printed is the manifest the sysroot already
2046        // carries rather than a second format saying the same things, because the three uses 13.5
2047        // gives for this are a licence notice, a reproducibility check and a security audit, and all
2048        // three are somebody else parsing it. One format is one parser to write.
2049        // Read and rendered rather than copied out, so that what comes back is the format this
2050        // build understands. The last newline comes off because whatever prints an answer adds
2051        // one, the way it does for every other query here. Keeping it would put a blank line at
2052        // the end of the one answer that is a file somebody diffs against the file it came from.
2053        Query::SysrootProvenance => match sysroot_manifest(opts, link)? {
2054            Some(manifest) => manifest.render().trim_end_matches('\n').to_string(),
2055            None => String::new(),
2056        },
2057        // Section 13.2 of the same document, which asks for the hash of a cache directory's
2058        // contents in the directory's name. A name cannot carry one, because the path has to be
2059        // computable before anything has been read, by the producer about to write the files and by
2060        // the compiler about to read them, and neither has the contents when it asks. So the number
2061        // is here instead, and it is the sha256 of the record rather than of a walk of the tree,
2062        // which means `sha256sum` over the manifest answers the same thing.
2063        Query::SysrootDigest => match sysroot_manifest(opts, link)? {
2064            Some(manifest) => manifest.digest(),
2065            None => String::new(),
2066        },
2067        Query::FileName(name) => found(name),
2068        // The name GCC gives the library of routines a compiler's output calls that the C
2069        // library does not have. Ours is built in and there is no file, so the answer is the
2070        // name itself, which is what GCC prints when it cannot find one either.
2071        Query::Libgcc => found("libgcc.a"),
2072        // A program rather than a library: the linker and the archiver are the ones a build asks
2073        // about, and this compiler finds them on the path or under `-B` rather than shipping
2074        // them, so the name back is the honest answer unless a `-B` prefix holds one.
2075        Query::ProgName(name) => link
2076            .prefixes
2077            .iter()
2078            .map(|dir| dir.join(name))
2079            .find(|path| path.is_file())
2080            .map_or_else(|| name.clone(), |path| path.display().to_string()),
2081    })
2082}
2083
2084/// The root every sysroot answer is about.
2085///
2086/// One function rather than a copy in each, because the other flags exist to say what is inside the
2087/// tree this one names, and two answers that disagreed about which tree that is would be a
2088/// difference nobody would think to look for. `--sysroot` wins over ours because it wins everywhere
2089/// else.
2090fn sysroot_root(opts: &Options, link: &LinkOptions) -> Option<PathBuf> {
2091    link.sysroot
2092        .clone()
2093        .or_else(|| link::cross_sysroot(opts.target, link).map(|at| at.root().to_path_buf()))
2094}
2095
2096/// The record of the sysroot this command line reads, when there is one to read.
2097///
2098/// [`None`] covers two cases that both print nothing, and they are different things. A compile for
2099/// this machine has no sysroot at all, and a tree somebody laid out themselves and pointed
2100/// `--sysroot` at carries no manifest, so nothing here knows where any of it came from. Saying
2101/// nothing is the only honest answer to either, and a reader can tell it from a manifest with no
2102/// inputs in it because that one still has its header lines.
2103///
2104/// # Errors
2105///
2106/// A manifest this build cannot parse, and anything else that went wrong reading the file. Passing a
2107/// record we could not read on to whoever asked would make their parser the one that finds the
2108/// problem, and every use section 13.5 gives for these two flags is somebody else reading the
2109/// output.
2110fn sysroot_manifest(opts: &Options, link: &LinkOptions) -> Result<Option<Manifest>, CliError> {
2111    let Some(root) = sysroot_root(opts, link) else {
2112        return Ok(None);
2113    };
2114    let path = Sysroot::at(root, opts.target.tuple()).manifest_path();
2115    match std::fs::read_to_string(&path) {
2116        Ok(text) => Manifest::parse(&text)
2117            .map(Some)
2118            .map_err(|why| err(format!("{}: {why}", path.display()))),
2119        Err(why) if why.kind() == std::io::ErrorKind::NotFound => Ok(None),
2120        Err(why) => Err(err(format!("{}: {why}", path.display()))),
2121    }
2122}
2123
2124/// Renders the passes this level will run, in order, with what each one does.
2125///
2126/// The level is the whole of the answer unless a `-f` flag edited it, which is section 9.1 of
2127/// `spec/09-optimizer.md`: a level is a list somebody wrote down rather than something that
2128/// emerges from which flags happen to be set, and this is how that list is read.
2129#[must_use]
2130pub fn print_pipeline(opts: &Options) -> String {
2131    let mut settings = rucc_opt::Options::for_level(opts.opt_level);
2132    settings.toggles.clone_from(&opts.passes);
2133    settings.global_fuel = opts.pass_fuel_global;
2134    for (on, spec) in &opts.pass_gates {
2135        // Every spelling was checked while the arguments were parsed, so there is nothing here
2136        // this can refuse, and a listing is not the place to report it if there were.
2137        let _ = settings.gates.add(*on, spec);
2138    }
2139    rucc_opt::pipeline::print(&settings)
2140}
2141
2142/// Renders the resolved configuration.
2143///
2144/// One `key: value` per line, sorted by nothing in particular but fixed in order, because
2145/// this output is diffed across hosts in CI and a reordering would read as a change.
2146#[must_use]
2147pub fn print_config(opts: &Options) -> String {
2148    let sess = Session::new(opts.clone());
2149    let t = &sess.target;
2150    let mut out = String::new();
2151    let _ = writeln!(out, "version: {VERSION}");
2152    // The three field triple the driver was given rather than the ten field tuple it widens to,
2153    // because this output is what a build system reads to find out what it asked for. The tuple is
2154    // the compiler's model of the machine and this line is a receipt for a command line.
2155    let _ = writeln!(out, "target: {}", opts.target);
2156    let _ = writeln!(out, "arch: {}", opts.target.arch.as_str());
2157    let _ = writeln!(out, "os: {}", opts.target.os.as_str());
2158    let _ = writeln!(out, "env: {}", opts.target.env.as_str());
2159    let _ = writeln!(out, "object-format: {}", t.object_format.as_str());
2160    let _ = writeln!(out, "pointer-width: {}", t.pointer_width);
2161    let _ = writeln!(out, "long-width: {}", t.long_width);
2162    let _ = writeln!(out, "long-double-width: {}", t.long_double_width);
2163    let _ = writeln!(out, "endian: {}", if t.little_endian { "little" } else { "big" });
2164    let _ = writeln!(out, "char-signed: {}", t.char_is_signed);
2165    let _ = writeln!(out, "va-list: {}", t.va_list.map_or("none", |list| list.as_str()));
2166    // The register file as a count per class, which is enough to tell a target whose registers
2167    // are described from one whose are not without printing sixteen names nobody asked for.
2168    let regs: Vec<String> = t
2169        .regs
2170        .classes()
2171        .map(|(class, info)| format!("{} {}", info.name, t.regs.len(class)))
2172        .collect();
2173    let _ = writeln!(
2174        out,
2175        "registers: {}",
2176        if regs.is_empty() { "none".to_string() } else { regs.join(", ") }
2177    );
2178    // What the schedule was chosen with, which is a sentence rather than a name on purpose: two
2179    // runs of a benchmark that disagree are usually two models and not two compilers.
2180    let _ = writeln!(out, "timing-model: {}", t.timing.map_or("none", |timing| timing.model));
2181    let _ = writeln!(out, "opt-level: {}", sess.opts.opt_level);
2182    let _ = writeln!(out, "safety: {}", sess.opts.safety);
2183    let _ = writeln!(out, "emit: {}", sess.opts.emit.as_str());
2184    let _ = writeln!(out, "debug-info: {}", sess.opts.debug_info);
2185    let _ = writeln!(out, "frame-pointer: {}", sess.opts.frame_pointer);
2186    let _ = writeln!(out, "red-zone: {}", sess.opts.red_zone);
2187    let _ = writeln!(out, "stack-protector: {}", sess.opts.protector);
2188    let _ = writeln!(out, "stack-clash-protection: {}", sess.opts.stack_clash);
2189    let _ = writeln!(out, "cf-protection: {}", sess.opts.control);
2190    let _ = writeln!(out, "patchable-function-entry: {}", sess.opts.patchable);
2191    let _ = writeln!(out, "profile: {}", sess.opts.profile);
2192    let _ = writeln!(out, "profile-hook: {}", sess.opts.hook);
2193    // Last because it is the one key with more than one line under it, and the only one
2194    // whose value is a property of the machine rather than of the command line.
2195    for dir in sess.opts.search.dirs() {
2196        let system = if dir.is_system { " (system)" } else { "" };
2197        let _ = writeln!(out, "include: {}{system}", dir.path.display());
2198    }
2199    out
2200}
2201
2202/// The output name the make target is taken from, which is the `-o` argument or nothing.
2203///
2204/// A run that stops at the preprocessor has not named an object, whatever its `-o` says: under
2205/// `-E` that argument is the preprocessed text and under `-M` it is the rule itself, and neither
2206/// is a file `make` would rebuild by running this rule. GCC agrees and falls back to the source
2207/// name in both, which is why a `-MD -E -o out.i` writes `out.d` holding a rule for `a.o`. From
2208/// `-S` on the argument does name what the rule builds, and it is used as written.
2209fn deps_target_output<'a>(opts: &Options, plan: &'a Plan) -> Option<&'a str> {
2210    if opts.emit == EmitKind::Preprocessed { None } else { plan.output.as_deref() }
2211}
2212
2213/// Writes to a path the command line named rather than one the plan derived, where `-` is
2214/// standard output.
2215fn write_named(path: &str, bytes: &[u8]) -> Result<(), String> {
2216    if path == "-" {
2217        return write_out(&Output::Stdout, bytes);
2218    }
2219    write_out(&Output::File(path.to_owned()), bytes)
2220}
2221
2222/// Writes the make rule for one input, and reports whether it got there.
2223///
2224/// A rule with no file of its own goes where the compilation it replaced would have written,
2225/// which is what makes the usual makefile recipe work: `rucc -M $< -o $@` leaves the rule in
2226/// `$@`, and the same line with the `-o` left off puts it on standard output.
2227fn write_deps(
2228    opts: &Options,
2229    plan: &Plan,
2230    job: &Job,
2231    found: &[Dependency],
2232    stderr: &mut impl std::io::Write,
2233) -> bool {
2234    let targets = if opts.deps.targets.is_empty() {
2235        vec![deps::default_target(&job.input, deps_target_output(opts, plan))]
2236    } else {
2237        opts.deps.targets.clone()
2238    };
2239    let rule = deps::rule(&opts.deps, &targets, &job.input, found);
2240    // The file, on the other hand, is named after the `-o` in every mode that still has one to
2241    // spend, which is every mode except the two that spend it on the rule.
2242    let wrote = match deps::default_file(&opts.deps, &job.input, plan.output.as_deref()) {
2243        // A `-MF` on a run that had nowhere else to put the rule leaves the file the `-o`
2244        // named empty rather than absent, because a makefile that named it as a target of its
2245        // own is a makefile that will look for it.
2246        Some(path) => write_named(&path, rule.as_bytes()).and_then(|()| {
2247            if opts.deps.instead_of_compiling { write_out(&job.output, b"") } else { Ok(()) }
2248        }),
2249        None => write_out(&job.output, rule.as_bytes()),
2250    };
2251    if let Err(e) = wrote {
2252        let _ = writeln!(stderr, "rucc: error: {e}");
2253        return false;
2254    }
2255    true
2256}
2257
2258/// Runs phase 4 over every input that has one, and writes what came out.
2259///
2260/// One input that fails does not stop the others. A build that reports every file it could
2261/// not preprocess in one run is worth more than one that stops at the first, and the exit
2262/// status is still a failure either way.
2263fn preprocess_all(opts: &Options, plan: &Plan) -> i32 {
2264    let fs = OsFileSystem::new();
2265    let mut stderr = std::io::stderr().lock();
2266    let mut failed = false;
2267    for job in &plan.jobs {
2268        if !job.phases.first().is_some_and(|p| *p == Phase::Preprocess) {
2269            // An input that is already preprocessed, or an object file. GCC passes these
2270            // through untouched, and the plan has already said so in its notes.
2271            continue;
2272        }
2273        let started = std::time::Instant::now();
2274        let result = preprocess(opts, &job.input, &fs);
2275        if opts.time {
2276            say_time(&job.input, started.elapsed(), &mut stderr);
2277        }
2278        for message in &result.messages {
2279            let _ = writeln!(stderr, "{message}");
2280        }
2281        if result.failed() {
2282            failed = true;
2283            continue;
2284        }
2285        if opts.deps.emit {
2286            failed |= !write_deps(opts, plan, job, &result.deps, &mut stderr);
2287            // `-M` and `-MM` asked for the rule instead of the text, so there is nothing else
2288            // to write. The other two asked for both and fall through to the text below.
2289            if opts.deps.instead_of_compiling {
2290                continue;
2291            }
2292        }
2293        if let Err(e) = write_out(&job.output, result.text.as_bytes()) {
2294            let _ = writeln!(stderr, "rucc: error: {e}");
2295            failed = true;
2296        }
2297    }
2298    i32::from(failed)
2299}
2300
2301/// Whether this job is a file of assembly that has to be assembled and that nothing here assembles.
2302///
2303/// The phases rather than the kind, because there are two kinds of assembly input and one of them
2304/// is preprocessed first, and because an object file also has no compile phase and is not this: it
2305/// has no phases at all and goes to the linker as it is. A `.s` on a `-c` line has exactly
2306/// [`Phase::Assemble`] left, and a `.S` has the preprocessor in front of it, and neither has
2307/// anything the front end can do.
2308fn needs_an_assembler(job: &Job) -> bool {
2309    job.phases.contains(&Phase::Assemble) && !job.phases.contains(&Phase::Compile)
2310}
2311
2312/// Whether the preprocessor runs over it on the way in, which is the whole difference between the
2313/// two kinds of assembly input.
2314fn assembly_wants_cpp(job: &Job) -> bool {
2315    job.phases.contains(&Phase::Preprocess)
2316}
2317
2318/// Runs the front end over every input that has a compile phase, and writes what came out.
2319///
2320/// The same rule as [`preprocess_all`]: one input that fails does not stop the others, and the
2321/// exit status is a failure either way. An input that is already assembly or an object has no
2322/// compile phase and is passed over here, which the plan has already said in its notes.
2323fn compile_all(opts: &Options, plan: &Plan) -> i32 {
2324    let fs = OsFileSystem::new();
2325    let mut stderr = std::io::stderr().lock();
2326    let mut failed = false;
2327    let (mut remarks, ok) = Remarks::new(opts.opt_info_file.as_ref(), &mut stderr);
2328    failed |= !ok;
2329    let mut fired = Fired::new();
2330    let mut pressure = Pressure::new();
2331    let mut lowerings = Lowerings::new();
2332    for job in &plan.jobs {
2333        if !job.phases.contains(&Phase::Compile) && !needs_an_assembler(job) {
2334            continue;
2335        }
2336        // An input of IR is read back rather than compiled, since the C it came from is not
2337        // here any more. A file of assembly does not go through the front end at all and is
2338        // read by the assembler instead. Everything after this is the same for all three, so
2339        // the paths meet again at the messages and the file the result is written to.
2340        let started = std::time::Instant::now();
2341        let result = if needs_an_assembler(job) {
2342            assemble(opts, &job.input, assembly_wants_cpp(job), &fs)
2343        } else if job.kind == InputKind::Ir {
2344            compile_ir(opts, &job.input, &fs)
2345        } else {
2346            compile(opts, &job.input, &fs)
2347        };
2348        if opts.time {
2349            say_time(&job.input, started.elapsed(), &mut stderr);
2350        }
2351        fired.merge(&result.fired);
2352        pressure.merge(&result.pressure);
2353        lowerings.merge(&result.lowerings);
2354        failed |= !write_dumps(&job.input, &result.dumps, &mut stderr);
2355        failed |= !remarks.write(&result.remarks, &mut stderr);
2356        for message in &result.messages {
2357            let _ = writeln!(stderr, "{message}");
2358        }
2359        // Before the failure below, because a compilation that stopped in the back end is exactly
2360        // the one whose preprocessed source somebody wants to look at.
2361        failed |= !write_temps(job, &result.temps, &mut stderr);
2362        if result.failed() {
2363            failed = true;
2364            continue;
2365        }
2366        // `-MD` and `-MMD` write the rule beside the object and let the compilation happen, so
2367        // this is the one path where both files come out of the same run. An input of IR has no
2368        // dependencies to report and produces an empty list, which produces a rule naming only
2369        // itself, and that is the honest answer rather than a missing file.
2370        if opts.deps.emit {
2371            failed |= !write_deps(opts, plan, job, &result.deps, &mut stderr);
2372        }
2373        if let Err(e) = write_out(&job.output, result.artifact.bytes()) {
2374            let _ = writeln!(stderr, "rucc: error: {e}");
2375            failed = true;
2376        }
2377    }
2378    failed |= !write_coverage(opts, &fired, &mut stderr);
2379    failed |= !write_pressure(opts, &pressure, &mut stderr);
2380    failed |= !write_lowering(opts, &lowerings, &mut stderr);
2381    i32::from(failed)
2382}
2383
2384/// A directory for the object files only the link step ever sees, removed when it goes away.
2385///
2386/// `-c` writes its object where the user can see it and linking does not, which is the whole of
2387/// the difference: a `rucc a.c b.c` leaves an executable behind and nothing else, the same as
2388/// every other compiler. Removing them on drop rather than at the end of a function is so that a
2389/// link that failed leaves nothing behind either.
2390struct Scratch {
2391    /// Where the objects go.
2392    dir: PathBuf,
2393}
2394
2395impl Scratch {
2396    /// Makes one, under whatever the platform calls its temporary directory.
2397    ///
2398    /// The name carries the process id so that two compilers running at once do not share a
2399    /// directory, which they would otherwise do the moment two of them compiled a file of the
2400    /// same name.
2401    fn new() -> Result<Scratch, String> {
2402        let dir = std::env::temp_dir().join(format!("rucc-{}", std::process::id()));
2403        std::fs::create_dir_all(&dir).map_err(|e| format!("{}: {e}", dir.display()))?;
2404        Ok(Scratch { dir })
2405    }
2406}
2407
2408impl Drop for Scratch {
2409    fn drop(&mut self) {
2410        let _ = std::fs::remove_dir_all(&self.dir);
2411    }
2412}
2413
2414/// The link line the plan describes, for `-###`.
2415///
2416/// The names in it are the hints the plan carries rather than the temporaries a real compilation
2417/// would choose, because `-###` prints the line without having compiled anything and so has
2418/// nothing to point at. That also makes the printed line readable rather than naming a directory
2419/// that only exists while a compilation is running.
2420fn link_line(opts: &Options, link: &LinkOptions, job: &LinkJob) -> Result<String, link::Error> {
2421    let linker = link::find(opts.target, link)?;
2422    let args = link::line(opts.target, link, &job.inputs, &job.output)?;
2423    Ok(link::render(&linker, &args))
2424}
2425
2426/// Compiles everything, then links it.
2427///
2428/// The objects go in a directory that is removed afterwards, which is why this is not
2429/// [`compile_all`] followed by a link: the plan says an object feeding the linker is temporary
2430/// and does not say where, because where is a question that only has an answer once something is
2431/// running.
2432fn link_all(opts: &Options, plan: &Plan, link: &LinkOptions, verbose: bool) -> i32 {
2433    let Some(job) = &plan.link else {
2434        // Every path into here comes from a plan whose last phase is the link, and such a plan
2435        // has a link job. Saying so is cheaper than an unwrap that would have to be explained.
2436        let mut stderr = std::io::stderr().lock();
2437        let _ = writeln!(stderr, "rucc: error: there is nothing to link");
2438        return 1;
2439    };
2440    // Before anything is compiled, because a linker that is not on the machine is worth knowing
2441    // about in the second it takes to look rather than after the compilation.
2442    // And before that, whether this link has a line at all and whether what it reads is on the
2443    // machine. Both are answerable now, and a target whose sysroot has not been built is worth
2444    // saying so about before the compilation rather than after it.
2445    if let Err(why) = link::preflight(opts.target, link) {
2446        return complain(why);
2447    }
2448    let linker = match link::find(opts.target, link) {
2449        Ok(linker) => linker,
2450        Err(why) => return complain(why),
2451    };
2452
2453    let scratch = match Scratch::new() {
2454        Ok(scratch) => scratch,
2455        Err(why) => return complain(format!("could not make a place for the object files: {why}")),
2456    };
2457
2458    let fs = OsFileSystem::new();
2459    let mut failed = false;
2460    // One per job, in job order, which is what lets the link line below be rebuilt with the real
2461    // paths in it: every job contributes exactly one file to the line and does so in this order.
2462    let mut produced: Vec<String> = Vec::with_capacity(plan.jobs.len());
2463    let mut fired = Fired::new();
2464    let mut pressure = Pressure::new();
2465    let mut lowerings = Lowerings::new();
2466    {
2467        let mut stderr = std::io::stderr().lock();
2468        let (mut remarks, ok) = Remarks::new(opts.opt_info_file.as_ref(), &mut stderr);
2469        failed |= !ok;
2470        for (at, job) in plan.jobs.iter().enumerate() {
2471            let out = match &job.output {
2472                Output::Temporary(hint) => {
2473                    // The index because two inputs in different directories can have the same
2474                    // name, and the two objects of `rucc a/x.c b/x.c` must not be one file.
2475                    scratch.dir.join(format!("{at}-{hint}")).display().to_string()
2476                }
2477                Output::File(path) => path.clone(),
2478                // A job feeding the linker never writes to standard output, since the plan gives
2479                // it a temporary. This is here so that the match is total rather than a panic.
2480                Output::Stdout => continue,
2481            };
2482            produced.push(out.clone());
2483            if !job.phases.contains(&Phase::Compile) && !needs_an_assembler(job) {
2484                continue;
2485            }
2486            let started = std::time::Instant::now();
2487            let result = if needs_an_assembler(job) {
2488                assemble(opts, &job.input, assembly_wants_cpp(job), &fs)
2489            } else if job.kind == InputKind::Ir {
2490                compile_ir(opts, &job.input, &fs)
2491            } else {
2492                compile(opts, &job.input, &fs)
2493            };
2494            if opts.time {
2495                say_time(&job.input, started.elapsed(), &mut stderr);
2496            }
2497            fired.merge(&result.fired);
2498            pressure.merge(&result.pressure);
2499            lowerings.merge(&result.lowerings);
2500            failed |= !write_dumps(&job.input, &result.dumps, &mut stderr);
2501            failed |= !remarks.write(&result.remarks, &mut stderr);
2502            for message in &result.messages {
2503                let _ = writeln!(stderr, "{message}");
2504            }
2505            failed |= !write_temps(job, &result.temps, &mut stderr);
2506            if result.failed() {
2507                failed = true;
2508                continue;
2509            }
2510            // A `-MD` on a command line that links writes the rule next to the executable and
2511            // names the executable as its target, since that is the file this source builds
2512            // here. The object it went through is in a temporary directory and is gone by the
2513            // time `make` reads any of this.
2514            if opts.deps.emit {
2515                failed |= !write_deps(opts, plan, job, &result.deps, &mut stderr);
2516            }
2517            if !matches!(result.artifact, Artifact::Object { .. }) {
2518                // Worth saying rather than writing whatever it is and letting the linker read it.
2519                // An empty file is a valid empty linker script, so a link handed one gets as far
2520                // as reporting every symbol of this file undefined, which is a page of messages
2521                // about something that went wrong here.
2522                let _ = writeln!(
2523                    stderr,
2524                    "rucc: internal error: {}: no object file was produced for the link",
2525                    job.input
2526                );
2527                failed = true;
2528                continue;
2529            }
2530            if let Err(e) = std::fs::write(&out, result.artifact.bytes()) {
2531                let _ = writeln!(stderr, "rucc: error: {out}: {e}");
2532                failed = true;
2533            }
2534        }
2535        failed |= !write_coverage(opts, &fired, &mut stderr);
2536        failed |= !write_pressure(opts, &pressure, &mut stderr);
2537        failed |= !write_lowering(opts, &lowerings, &mut stderr);
2538        failed |= !write_lowering(opts, &lowerings, &mut stderr);
2539    }
2540    if failed {
2541        // Nothing is linked from a compilation that did not finish. A linker run over the objects
2542        // that did compile would report every function of the file that did not as undefined,
2543        // which is a page of messages about a mistake already reported once.
2544        return 1;
2545    }
2546
2547    // The items in command line order with the temporaries filled in. A library and a word for the
2548    // linker contribute no job and pass through, and every file item takes the next job's real
2549    // output, which is what keeps whatever was written between two objects between them here.
2550    let mut outputs = produced.into_iter();
2551    let mut items = Vec::with_capacity(job.inputs.len());
2552    for item in &job.inputs {
2553        match item {
2554            link::Item::Library(name) => items.push(link::Item::Library(name.clone())),
2555            link::Item::Linker(arg) => items.push(link::Item::Linker(arg.clone())),
2556            link::Item::File(_) => match outputs.next() {
2557                Some(path) => items.push(link::Item::File(path)),
2558                None => return complain("the plan asks the linker for a file nothing produced"),
2559            },
2560        }
2561    }
2562
2563    let args = match link::line(opts.target, link, &items, &job.output) {
2564        Ok(args) => args,
2565        Err(why) => return complain(why),
2566    };
2567    if verbose {
2568        let mut stderr = std::io::stderr().lock();
2569        let _ = writeln!(stderr, "{}", link::render(&linker, &args));
2570    }
2571    let started = std::time::Instant::now();
2572    let ran = link::run(&linker, &args);
2573    if opts.time {
2574        // The one step of a compilation that really is another program, so this line is the same
2575        // measurement gcc's is and names the linker the way gcc names `collect2`.
2576        let mut stderr = std::io::stderr().lock();
2577        say_time(&linker.name, started.elapsed(), &mut stderr);
2578    }
2579    match ran {
2580        Ok(()) => 0,
2581        // The linker has already said what was wrong on its own error output, and repeating that
2582        // linking failed would only push its message further up the screen.
2583        Err(link::Error::Refused { .. }) => 1,
2584        Err(why) => complain(why),
2585    }
2586}
2587
2588/// Compiles everything and writes the objects into one static library.
2589///
2590/// No temporary directory and no second program. The objects never reach the file system at all:
2591/// they go from the compiler into the archive writer, which is both faster than writing a directory
2592/// of files for an `ar` to read back and the reason the symbol index can be written at all. A
2593/// member's index entries are the names the object writer says it wrote, and the only thing that
2594/// knows those is the run that wrote it.
2595///
2596/// `-save-temps` is the exception. It asked for the objects to be kept, the plan gave them names a
2597/// person can find, and they are written there as well as put in the archive.
2598fn archive_all(opts: &Options, plan: &Plan) -> i32 {
2599    let Some(job) = &plan.archive else {
2600        // Every path into here comes from a plan whose last phase is the archive, and such a plan
2601        // has an archive job. Saying so is cheaper than an unwrap that would have to be explained.
2602        return complain("there is nothing to put in an archive");
2603    };
2604    // Before anything is compiled, because a format this has no container for is worth knowing
2605    // about in the second it takes to look rather than after the whole compilation.
2606    let flavour = match opts.target.os.object_format() {
2607        ObjectFormat::Elf => rucc_archive::Flavour::Gnu,
2608        ObjectFormat::Coff => rucc_archive::Flavour::Coff,
2609        // Mach-O wants the BSD flavour, whose index is a different member under a different name,
2610        // and wasm has no archives of its own at all. Neither has an object writer either, so a
2611        // command line reaching this would have failed in the next step regardless.
2612        format @ (ObjectFormat::MachO | ObjectFormat::Wasm) => {
2613            return complain(format!(
2614                "there is no archive format for {} objects in this compiler yet",
2615                format.as_str()
2616            ));
2617        }
2618    };
2619
2620    let fs = OsFileSystem::new();
2621    let mut failed = false;
2622    let mut members: Vec<rucc_archive::Member> = Vec::with_capacity(plan.jobs.len());
2623    let mut names = job.members.iter();
2624    let mut fired = Fired::new();
2625    let mut pressure = Pressure::new();
2626    let mut lowerings = Lowerings::new();
2627    {
2628        let mut stderr = std::io::stderr().lock();
2629        let (mut remarks, ok) = Remarks::new(opts.opt_info_file.as_ref(), &mut stderr);
2630        failed |= !ok;
2631        for plan_job in &plan.jobs {
2632            // What the plan called this member. The two lists are walked together rather than the
2633            // name being worked out again here, so that what `-###` printed and what goes in the
2634            // file cannot come apart.
2635            let Some(member) = names.next() else {
2636                return complain("the plan asks the archive for a member nothing produced");
2637            };
2638            if !plan_job.phases.contains(&Phase::Compile) && !needs_an_assembler(plan_job) {
2639                // Neither something to compile nor something to assemble, so there is nothing to
2640                // put in, and an archive quietly missing a member is worse than a message.
2641                let _ = writeln!(
2642                    &mut stderr,
2643                    "rucc: error: {}: this compiler makes an archive out of what it compiles, and \
2644                     there is nothing here for it to do",
2645                    plan_job.input
2646                );
2647                failed = true;
2648                continue;
2649            }
2650            let started = std::time::Instant::now();
2651            let result = if needs_an_assembler(plan_job) {
2652                assemble(opts, &plan_job.input, assembly_wants_cpp(plan_job), &fs)
2653            } else if plan_job.kind == InputKind::Ir {
2654                compile_ir(opts, &plan_job.input, &fs)
2655            } else {
2656                compile(opts, &plan_job.input, &fs)
2657            };
2658            if opts.time {
2659                say_time(&plan_job.input, started.elapsed(), &mut stderr);
2660            }
2661            fired.merge(&result.fired);
2662            pressure.merge(&result.pressure);
2663            lowerings.merge(&result.lowerings);
2664            failed |= !write_dumps(&plan_job.input, &result.dumps, &mut stderr);
2665            failed |= !remarks.write(&result.remarks, &mut stderr);
2666            for message in &result.messages {
2667                let _ = writeln!(stderr, "{message}");
2668            }
2669            failed |= !write_temps(plan_job, &result.temps, &mut stderr);
2670            if result.failed() {
2671                failed = true;
2672                continue;
2673            }
2674            if opts.deps.emit {
2675                failed |= !write_deps(opts, plan, plan_job, &result.deps, &mut stderr);
2676            }
2677            let Artifact::Object { bytes, defines } = result.artifact else {
2678                let _ = writeln!(
2679                    stderr,
2680                    "rucc: internal error: {}: no object file was produced for the archive",
2681                    plan_job.input
2682                );
2683                failed = true;
2684                continue;
2685            };
2686            // Under `-save-temps` the plan gave the object a name a person can find, so it is
2687            // written there too. Otherwise it is only ever a member and never a file.
2688            if let Output::File(path) = &plan_job.output {
2689                if let Err(e) = std::fs::write(path, &bytes) {
2690                    let _ = writeln!(stderr, "rucc: error: {path}: {e}");
2691                    failed = true;
2692                }
2693            }
2694            members.push(rucc_archive::Member { name: member.clone(), body: bytes, defines });
2695        }
2696        failed |= !write_coverage(opts, &fired, &mut stderr);
2697        failed |= !write_pressure(opts, &pressure, &mut stderr);
2698        failed |= !write_lowering(opts, &lowerings, &mut stderr);
2699        failed |= !write_lowering(opts, &lowerings, &mut stderr);
2700    }
2701    if failed {
2702        // Nothing is written from a compilation that did not finish, for the reason the link gives:
2703        // an archive missing the file that failed is one a link reports every name of as undefined,
2704        // which is a page of messages about a mistake already reported once.
2705        return 1;
2706    }
2707
2708    let bytes = match rucc_archive::write(flavour, &members) {
2709        Ok(bytes) => bytes,
2710        // Every one of these is a bug here rather than a program's mistake: the names came from the
2711        // object writer and the bodies came from this process.
2712        Err(why) => return complain(format!("the archive could not be written: {why}")),
2713    };
2714    match std::fs::write(&job.output, &bytes) {
2715        Ok(()) => 0,
2716        Err(e) => complain(format!("{}: {e}", job.output)),
2717    }
2718}
2719
2720/// Prints one driver level message and gives back the exit status that goes with it.
2721fn complain(why: impl std::fmt::Display) -> i32 {
2722    let mut stderr = std::io::stderr().lock();
2723    let _ = writeln!(stderr, "rucc: error: {why}");
2724    1
2725}
2726
2727/// Writes what `-Zrule-coverage=FILE` asked for, and says whether it could.
2728///
2729/// Once for the whole command line rather than once per input, because the question is which
2730/// lowering rules this run of the compiler reached and a file per input would leave the reader
2731/// unioning files to find out something one process already knew.
2732///
2733/// A file that could not be written is a failure and not a warning. What asks for this is a
2734/// measurement run, and a measurement that quietly did not happen is worse than one that stopped.
2735fn write_coverage(opts: &Options, fired: &Fired, stderr: &mut impl std::io::Write) -> bool {
2736    let Some(path) = &opts.rule_coverage else { return true };
2737    let Some(table) = coverage::table(opts.target.arch) else {
2738        let _ = writeln!(
2739            stderr,
2740            "rucc: error: there are no lowering rules for {} yet, so there is no coverage of them \
2741             to report",
2742            opts.target
2743        );
2744        return false;
2745    };
2746    match std::fs::write(path, fired.listing(table)) {
2747        Ok(()) => true,
2748        Err(e) => {
2749            let _ = writeln!(stderr, "rucc: error: {path}: {e}");
2750            false
2751        }
2752    }
2753}
2754
2755/// Writes what `-Zregister-pressure=FILE` asked for, and says whether it could.
2756///
2757/// Once for the whole command line, for the reason [`write_coverage`] gives, and a file that could
2758/// not be written is a failure for the reason it gives too. There is no equivalent of the missing
2759/// rule table here, since every target this compiles for has an allocator, and a run that reached
2760/// no back end at all writes an empty listing rather than nothing: a measurement of a build that
2761/// produced no code is still an answer and it is the honest one.
2762fn write_pressure(opts: &Options, pressure: &Pressure, stderr: &mut impl std::io::Write) -> bool {
2763    let Some(path) = &opts.register_pressure else { return true };
2764    match std::fs::write(path, pressure.listing()) {
2765        Ok(()) => true,
2766        Err(e) => {
2767            let _ = writeln!(stderr, "rucc: error: {path}: {e}");
2768            false
2769        }
2770    }
2771}
2772
2773/// Writes what `-Zlowering=FILE` asked for, and says whether it could.
2774///
2775/// Once for the whole command line, for the reason [`write_coverage`] gives, and a file that could
2776/// not be written is a failure for the reason it gives too. A run that reached no back end writes
2777/// an empty listing rather than nothing, the way [`write_pressure`] does and for the same reason.
2778fn write_lowering(opts: &Options, lowerings: &Lowerings, stderr: &mut impl std::io::Write) -> bool {
2779    let Some(path) = &opts.lowering_dump else { return true };
2780    match std::fs::write(path, lowerings.listing()) {
2781        Ok(()) => true,
2782        Err(e) => {
2783            let _ = writeln!(stderr, "rucc: error: {path}: {e}");
2784            false
2785        }
2786    }
2787}
2788
2789/// Where the `-fopt-info` remarks go, and how much of the run has already gone there.
2790///
2791/// Standard error by default, and one file for the whole run when `-fopt-info=<file>` named one.
2792/// A file rather than the diagnostic stream is what a harness wants: the corpus in
2793/// `tamnd/rucc-corpus` matches a rejection against what the compiler said on standard error, and
2794/// a few thousand remarks mixed into that would bury it.
2795struct Remarks {
2796    /// The file, if there is one.
2797    file: Option<String>,
2798    /// Whether anything has been written to it yet, which decides between truncating and
2799    /// appending. One file holds the whole run rather than the last input in it.
2800    started: bool,
2801}
2802
2803impl Remarks {
2804    /// Prepares the destination, emptying the file if there is one.
2805    ///
2806    /// Emptied here rather than at the first remark, because a run where no pass had anything to
2807    /// say should leave an empty file and not yesterday's. An absent file and an empty one are
2808    /// different facts and something reading this will act on the difference.
2809    fn new(file: Option<&String>, stderr: &mut impl std::io::Write) -> (Self, bool) {
2810        let mut ok = true;
2811        if let Some(path) = file {
2812            if let Err(e) = std::fs::write(path, "") {
2813                let _ = writeln!(stderr, "rucc: error: {path}: {e}");
2814                ok = false;
2815            }
2816        }
2817        (Self { file: file.cloned(), started: false }, ok)
2818    }
2819
2820    /// Writes one input's remarks, and says whether that worked.
2821    ///
2822    /// A file that cannot be written is a failure and not a warning, for the reason
2823    /// [`write_dumps`] gives: remarks that quietly did not arrive look exactly like a compilation
2824    /// where nothing happened.
2825    fn write(&mut self, text: &str, stderr: &mut impl std::io::Write) -> bool {
2826        if text.is_empty() {
2827            return true;
2828        }
2829        let Some(path) = &self.file else {
2830            let _ = write!(stderr, "{text}");
2831            return true;
2832        };
2833        let opened = std::fs::OpenOptions::new()
2834            .write(true)
2835            .append(self.started)
2836            .truncate(!self.started)
2837            .create(true)
2838            .open(path);
2839        self.started = true;
2840        let result =
2841            opened.and_then(|mut file| std::io::Write::write_all(&mut file, text.as_bytes()));
2842        if let Err(e) = result {
2843            let _ = writeln!(stderr, "rucc: error: {path}: {e}");
2844            return false;
2845        }
2846        true
2847    }
2848}
2849
2850/// Writes what `-fdump-ir=` asked to see, one file per dump.
2851///
2852/// The name is the input file with the dump's own name and `.ir` after it, so a directory listing
2853/// after a run is the passes in the order they ran, per input. They go in the working directory
2854/// rather than beside the output, because a dump is something a person asked for at a prompt and
2855/// the working directory is where that person is.
2856///
2857/// A file that could not be written is a failure and not a warning, for the reason
2858/// [`write_coverage`] gives: what asked for this is somebody debugging a pass, and a dump that
2859/// quietly did not happen looks exactly like a pass that did not run.
2860fn write_dumps(input: &str, dumps: &[rucc_opt::Dump], stderr: &mut impl std::io::Write) -> bool {
2861    let stem = std::path::Path::new(input)
2862        .file_name()
2863        .map_or_else(|| input.to_owned(), |name| name.to_string_lossy().into_owned());
2864    let mut ok = true;
2865    for dump in dumps {
2866        let path = format!("{stem}.{}.ir", dump.name);
2867        if let Err(e) = std::fs::write(&path, &dump.text) {
2868            let _ = writeln!(stderr, "rucc: error: {path}: {e}");
2869            ok = false;
2870        }
2871    }
2872    ok
2873}
2874
2875/// Writes the files `-save-temps` kept, which is nothing at all unless it was given.
2876///
2877/// A file that could not be written is a failure rather than a warning, for the reason
2878/// [`write_dumps`] gives: somebody asked for these by name, and one that quietly did not happen
2879/// looks like a compilation that never went through that step.
2880fn write_temps(job: &Job, temps: &Temps, stderr: &mut impl std::io::Write) -> bool {
2881    let mut ok = true;
2882    let kept = [(job.saved_text(), &temps.preprocessed), (job.saved_asm(), &temps.assembly)];
2883    for (path, text) in kept {
2884        // A step the compilation did not reach has nothing to keep, and a job that is not keeping
2885        // that step has nowhere to put it. Either way there is no file here.
2886        let (Some(path), Some(text)) = (path, text) else { continue };
2887        if let Err(e) = std::fs::write(&path, text) {
2888            let _ = writeln!(stderr, "rucc: error: {path}: {e}");
2889            ok = false;
2890        }
2891    }
2892    ok
2893}
2894
2895/// One line of `-time`, which is what a step was called and how long it took.
2896///
2897/// GCC's two numbers are the user and the system time of a subprocess it ran. This compiler runs
2898/// no subprocess for anything but the link, so what is measured here is the wall clock of the
2899/// step and the second column is always zero. The shape of the line is kept because a person
2900/// reading it next to gcc's should not have to work out which column is which.
2901fn say_time(name: &str, took: std::time::Duration, stderr: &mut impl std::io::Write) {
2902    let _ = writeln!(stderr, "# {name} {:.2} {:.2}", took.as_secs_f64(), 0.0);
2903}
2904
2905/// Writes one job's result where the plan said it goes.
2906///
2907/// # Errors
2908///
2909/// Returns the message to print, which names the file when there is one, because "permission
2910/// denied" on its own does not say which file was refused.
2911fn write_out(output: &Output, bytes: &[u8]) -> Result<(), String> {
2912    match output {
2913        Output::Stdout => {
2914            let mut stdout = std::io::stdout().lock();
2915            stdout.write_all(bytes).map_err(|e| format!("writing to standard output: {e}"))
2916        }
2917        Output::File(path) | Output::Temporary(path) => {
2918            std::fs::write(path, bytes).map_err(|e| format!("{path}: {e}"))
2919        }
2920    }
2921}
2922
2923/// Runs the driver and returns the process exit code.
2924///
2925/// `args` excludes the program name. Output goes to `stdout` and errors to `stderr`, which
2926/// is the one place in the compiler that is true.
2927pub fn run(args: &[String]) -> i32 {
2928    match parse_args(args) {
2929        Ok(Action::Help) => {
2930            print!("{USAGE}");
2931            0
2932        }
2933        Ok(Action::Version) => {
2934            println!("rucc {VERSION}");
2935            0
2936        }
2937        Ok(Action::Print(line)) => {
2938            println!("{line}");
2939            0
2940        }
2941        Ok(Action::PrintConfig(opts)) => {
2942            print!("{}", print_config(&opts));
2943            0
2944        }
2945        Ok(Action::PrintPipeline(opts)) => {
2946            print!("{}", print_pipeline(&opts));
2947            0
2948        }
2949        Ok(Action::PrintPlan { opts, plan, link }) => {
2950            print!("{}", plan.render());
2951            // The line as it would be typed, which is the half of `-###` that section 4.3 says
2952            // arrives with the link. It is printed even when the linker is not on this machine,
2953            // because what a build wants from `-###` is what the compiler would do.
2954            if let Some(job) = &plan.link {
2955                match link_line(&opts, &link, job) {
2956                    Ok(line) => println!("{line}"),
2957                    Err(why) => {
2958                        let mut stderr = std::io::stderr().lock();
2959                        let _ = writeln!(stderr, "rucc: error: {why}");
2960                        return 1;
2961                    }
2962                }
2963            }
2964            0
2965        }
2966        Ok(Action::Fetch { what, target, cache }) => fetch_sysroot(what, target, &cache),
2967        Ok(Action::Compile { opts, plan, link, jobs, verbose, notes }) => {
2968            {
2969                let mut stderr = std::io::stderr().lock();
2970                // Before the plan rather than after it, because a note is about the command line
2971                // and the plan is what the command line was read as, so the reader wants the two
2972                // in that order.
2973                for note in &notes {
2974                    let _ = writeln!(stderr, "rucc: warning: {note}");
2975                }
2976                if verbose {
2977                    let _ = write!(stderr, "{}", plan.render());
2978                    let _ = writeln!(stderr, "workers: {}", jobs.count());
2979                }
2980            }
2981            if opts.emit == EmitKind::Preprocessed {
2982                return preprocess_all(&opts, &plan);
2983            }
2984            if opts.emit == EmitKind::Archive {
2985                return archive_all(&opts, &plan);
2986            }
2987            if opts.emit != EmitKind::Executable {
2988                return compile_all(&opts, &plan);
2989            }
2990            link_all(&opts, &plan, &link, verbose)
2991        }
2992        Err(e) => {
2993            let mut stderr = std::io::stderr().lock();
2994            let _ = writeln!(stderr, "rucc: error: {e}");
2995            let _ = writeln!(stderr, "rucc: note: run `rucc --help` for usage");
2996            1
2997        }
2998    }
2999}
3000
3001#[cfg(test)]
3002mod tests {
3003    use rucc_session::{
3004        Contract, GnucVersion, IncludeForm, LtoJobs, OptLevel, Partition, Patchable, Visibility,
3005    };
3006
3007    use super::*;
3008
3009    fn args(s: &[&str]) -> Vec<String> {
3010        s.iter().map(|x| (*x).to_owned()).collect()
3011    }
3012
3013    #[test]
3014    fn help_and_version_win_over_everything_else() {
3015        assert_eq!(parse_args(&args(&["-c", "--help", "x.c"])).unwrap(), Action::Help);
3016        assert_eq!(parse_args(&args(&["--version"])).unwrap(), Action::Version);
3017    }
3018
3019    fn compile(s: &[&str]) -> (Box<Options>, Box<Plan>) {
3020        match parse_args(&args(s)).expect("expected a compilation") {
3021            Action::Compile { opts, plan, .. } => (opts, plan),
3022            other => panic!("expected a compilation, got {other:?}"),
3023        }
3024    }
3025
3026    fn linking(s: &[&str]) -> (Box<LinkOptions>, Box<Plan>) {
3027        match parse_args(&args(s)).expect("expected a compilation") {
3028            Action::Compile { link, plan, .. } => (link, plan),
3029            other => panic!("expected a compilation, got {other:?}"),
3030        }
3031    }
3032
3033    fn notes(s: &[&str]) -> Vec<String> {
3034        match parse_args(&args(s)).expect("expected a compilation") {
3035            Action::Compile { notes, .. } => notes,
3036            other => panic!("expected a compilation, got {other:?}"),
3037        }
3038    }
3039
3040    /// The ordinary command line has nothing to say about itself, which is the property that makes
3041    /// a note worth reading when there is one.
3042    #[test]
3043    fn a_command_line_with_nothing_wrong_with_it_carries_no_notes() {
3044        assert_eq!(notes(&["-c", "a.c"]), Vec::<String>::new());
3045    }
3046
3047    /// A directory that is not there contributes nothing to the search path, so there is no tree to
3048    /// read a release out of and nothing to compare the pin against. Said as a test because this is
3049    /// the shape a hermetic machine takes: the probe reads the disk and every other machine has a
3050    /// different disk, so what can be asserted here is the silence.
3051    #[test]
3052    fn a_named_tree_that_is_not_on_the_machine_is_not_a_release_mismatch() {
3053        let said =
3054            notes(&["--target=x86_64-linux-gnu.2.28", "--sysroot=/nowhere-at-all", "-c", "a.c"]);
3055        assert_eq!(said, Vec::<String>::new());
3056    }
3057
3058    #[test]
3059    fn collects_inputs_and_flags() {
3060        let (opts, plan) = compile(&["-c", "-O2", "-g", "a.c", "b.c"]);
3061        let paths: Vec<&str> = plan.jobs.iter().map(|j| j.input.as_str()).collect();
3062        assert_eq!(paths, vec!["a.c", "b.c"]);
3063        assert_eq!(opts.opt_level, OptLevel::O2);
3064        assert_eq!(opts.emit, EmitKind::Object);
3065        assert!(opts.debug_info);
3066    }
3067
3068    /// The unstable options, which are spelled apart from everything else on purpose: what is
3069    /// under `-Z` promises nothing, and a build that reaches for one should have had to say so.
3070    #[test]
3071    fn an_unstable_option_is_taken_and_one_that_does_not_exist_is_refused() {
3072        let (opts, _) = compile(&["-c", "-Zrule-coverage=/tmp/rules.cov", "a.c"]);
3073        assert_eq!(opts.rule_coverage.as_deref(), Some("/tmp/rules.cov"));
3074
3075        let (plain, _) = compile(&["-c", "a.c"]);
3076        assert_eq!(plain.rule_coverage, None, "nothing is measured unless it was asked for");
3077
3078        assert!(parse_args(&args(&["-Zrule-coverage=", "a.c"])).is_err(), "a file with no name");
3079        let unknown = parse_args(&args(&["-Zwhat", "a.c"])).expect_err("there is no such option");
3080        assert!(unknown.message.contains("4.11"), "{}", unknown.message);
3081    }
3082
3083    /// The other measurement written to a file, which reads the same way and fails the same way.
3084    #[test]
3085    fn where_the_register_pressure_goes_is_asked_for_the_same_way() {
3086        let (opts, _) = compile(&["-c", "-O2", "-Zregister-pressure=/tmp/spills.txt", "a.c"]);
3087        assert_eq!(opts.register_pressure.as_deref(), Some("/tmp/spills.txt"));
3088
3089        let (plain, _) = compile(&["-c", "a.c"]);
3090        assert_eq!(plain.register_pressure, None, "nothing is measured unless it was asked for");
3091
3092        assert!(parse_args(&args(&["-Zregister-pressure=", "a.c"])).is_err(), "no file named");
3093    }
3094
3095    /// The third one, which says what the pre-selection lowering group did.
3096    #[test]
3097    fn where_the_lowering_dump_goes_is_asked_for_the_same_way() {
3098        let (opts, _) = compile(&["-c", "-O2", "-Zlowering=/tmp/lowering.txt", "a.c"]);
3099        assert_eq!(opts.lowering_dump.as_deref(), Some("/tmp/lowering.txt"));
3100
3101        let (plain, _) = compile(&["-c", "a.c"]);
3102        assert_eq!(plain.lowering_dump, None, "nothing is dumped unless it was asked for");
3103
3104        assert!(parse_args(&args(&["-Zlowering=", "a.c"])).is_err(), "no file named");
3105    }
3106
3107    /// Scheduling, which has the three way answer every optimization flag has: on, off, and
3108    /// nothing said, which is whatever the optimization level asks for. The name is gcc's, and
3109    /// gcc's has a two in it because gcc has a scheduler before allocation and one after and this
3110    /// is the one after.
3111    #[test]
3112    fn scheduling_can_be_turned_on_and_off_and_left_to_the_optimization_level() {
3113        let (on, _) = compile(&["-c", "-O0", "-fschedule-insns2", "a.c"]);
3114        assert_eq!(on.schedule_insns, Some(true));
3115
3116        let (off, _) = compile(&["-c", "-O2", "-fno-schedule-insns2", "a.c"]);
3117        assert_eq!(off.schedule_insns, Some(false));
3118
3119        let (quiet, _) = compile(&["-c", "-O2", "a.c"]);
3120        assert_eq!(quiet.schedule_insns, None, "nothing said, so the level decides");
3121        assert!(quiet.opt_level.schedules(), "and at this level the level says yes");
3122
3123        let (none, _) = compile(&["-c", "a.c"]);
3124        assert!(!none.opt_level.schedules(), "at no optimization it says no");
3125    }
3126
3127    /// Whether the timing model is worth holding an instruction back over, which is a `-Z` because
3128    /// it is a question about a target's description rather than about the program being compiled.
3129    #[test]
3130    fn whether_the_timing_model_is_cycle_accurate_can_be_overridden() {
3131        let (yes, _) = compile(&["-c", "-O2", "-Zcycle-accurate-model=yes", "a.c"]);
3132        assert_eq!(yes.cycle_accurate_model, Some(true));
3133
3134        let (no, _) = compile(&["-c", "-O2", "-Zcycle-accurate-model=no", "a.c"]);
3135        assert_eq!(no.cycle_accurate_model, Some(false));
3136
3137        let (plain, _) = compile(&["-c", "-O2", "a.c"]);
3138        assert_eq!(plain.cycle_accurate_model, None, "the target's own answer stands");
3139
3140        let bad = parse_args(&args(&["-Zcycle-accurate-model=maybe", "a.c"]))
3141            .expect_err("it takes yes or no");
3142        assert!(bad.message.contains("yes or no"), "{}", bad.message);
3143    }
3144
3145    #[test]
3146    fn a_bare_dash_o_means_o1_the_way_gcc_reads_it() {
3147        let (opts, _) = compile(&["-O", "a.c"]);
3148        assert_eq!(opts.opt_level, OptLevel::O1);
3149    }
3150
3151    #[test]
3152    fn dash_x_applies_to_later_inputs_only_and_none_stops_it() {
3153        let (_, plan) = compile(&["a.o", "-x", "c", "b.txt", "-x", "none", "c.o"]);
3154        assert_eq!(plan.jobs[0].kind, InputKind::LinkerInput);
3155        assert_eq!(plan.jobs[1].kind, InputKind::C);
3156        assert_eq!(plan.jobs[2].kind, InputKind::LinkerInput);
3157    }
3158
3159    #[test]
3160    fn dash_j_reaches_the_scheduler_and_defaults_to_the_machine() {
3161        let (_, _, jobs) = match parse_args(&args(&["-j4", "a.c"])).unwrap() {
3162            Action::Compile { opts, plan, jobs, .. } => (opts, plan, jobs),
3163            other => panic!("expected a compilation, got {other:?}"),
3164        };
3165        assert_eq!(jobs.count(), 4);
3166
3167        let default = match parse_args(&args(&["a.c"])).unwrap() {
3168            Action::Compile { jobs, .. } => jobs,
3169            other => panic!("expected a compilation, got {other:?}"),
3170        };
3171        assert_eq!(default, Jobs::available());
3172        assert!(parse_args(&args(&["-j0", "a.c"])).is_err());
3173    }
3174
3175    #[test]
3176    fn triple_hash_prints_the_plan_and_runs_nothing() {
3177        let a = parse_args(&args(&["-###", "-c", "a.c"])).unwrap();
3178        let Action::PrintPlan { plan, .. } = a else { panic!("expected a plan dump") };
3179        assert!(plan.render().contains("a.c: preprocess, compile, assemble -> a.o"));
3180    }
3181
3182    #[test]
3183    fn the_flag_that_keeps_the_intermediate_files_has_three_spellings_and_two_meanings() {
3184        // The bare one is `=obj` and not `=cwd`. gcc's manual says the opposite and gcc 16 does
3185        // this, and following the compiler is what makes a build that reads either of them find
3186        // the files where they are.
3187        assert_eq!(compile(&["-c", "-save-temps", "a.c"]).0.save_temps, SaveTemps::Object);
3188        assert_eq!(compile(&["-c", "-save-temps=obj", "a.c"]).0.save_temps, SaveTemps::Object);
3189        assert_eq!(compile(&["-c", "-save-temps=cwd", "a.c"]).0.save_temps, SaveTemps::Cwd);
3190        assert_eq!(compile(&["-c", "a.c"]).0.save_temps, SaveTemps::No);
3191        // The last one on the line decides, the way it does for every other flag with an
3192        // argument, and a keyword that is neither is fatal rather than ignored: a run that kept
3193        // nothing and said nothing looks exactly like one where the files were not produced.
3194        let (opts, _) = compile(&["-c", "-save-temps", "-save-temps=cwd", "a.c"]);
3195        assert_eq!(opts.save_temps, SaveTemps::Cwd);
3196        let e = parse_args(&args(&["-c", "-save-temps=nowhere", "a.c"])).unwrap_err();
3197        assert!(e.message.contains("accepted: cwd, obj"), "{}", e.message);
3198    }
3199
3200    #[test]
3201    fn the_flag_that_times_each_step_reaches_the_options_and_changes_nothing_else() {
3202        let (opts, plan) = compile(&["-c", "-time", "a.c"]);
3203        let (plain, without) = compile(&["-c", "a.c"]);
3204        assert!(opts.time);
3205        assert!(!plain.time);
3206        // Against the same line without the flag rather than against a spelling of the object's
3207        // name, since what the object is called is the host's business and this is not about that.
3208        assert_eq!(plan.jobs[0].output, without.jobs[0].output);
3209    }
3210
3211    #[test]
3212    fn dash_x_names_what_it_accepts_when_it_does_not_know_a_language() {
3213        let e = parse_args(&args(&["-x", "fortran", "a.c"])).unwrap_err();
3214        assert!(e.message.contains("assembler-with-cpp"), "{}", e.message);
3215    }
3216
3217    /// What `--fetch` says while the table in [`artifact`] has no rows in it, which is what every
3218    /// run of it says today and is the reason the message distinguishes the two cases.
3219    #[test]
3220    fn a_fetch_of_a_target_nothing_is_pinned_for_says_so_rather_than_reaching_the_network() {
3221        let e = parse_args(&args(&["--fetch", "x86_64-linux-musl"])).unwrap_err();
3222        assert!(e.message.contains("pins no sysroot for x86_64-linux-musl"), "{}", e.message);
3223        // And where one comes from, because the answer is not on this machine.
3224        assert!(e.message.contains("tamnd/rucc-cross"), "{}", e.message);
3225        // The joined spelling is the same flag.
3226        let joined = parse_args(&args(&["--fetch=x86_64-linux-musl"])).unwrap_err();
3227        assert_eq!(joined, e);
3228    }
3229
3230    /// The two targets a release will never pin, which is a different answer from the one above.
3231    ///
3232    /// Section 13.4. A person who reads "this release pins no sysroot yet" waits for a release that
3233    /// does, and no release of this compiler can ship either of these, so the message names the
3234    /// licence that decides it and what to do instead.
3235    #[test]
3236    fn a_fetch_of_a_target_behind_a_licence_wall_says_so_rather_than_saying_not_yet() {
3237        let e = parse_args(&args(&["--fetch", "aarch64-macos"])).unwrap_err();
3238        assert!(e.message.contains("Xcode licence"), "{}", e.message);
3239        assert!(e.message.contains("there never will be"), "{}", e.message);
3240        assert!(!e.message.contains("tamnd/rucc-cross"), "{}", e.message);
3241
3242        let e = parse_args(&args(&["--fetch", "x86_64-windows-msvc"])).unwrap_err();
3243        assert!(e.message.contains("redistributed"), "{}", e.message);
3244        // The way out of this one is a target rather than a download, and it is the default already.
3245        assert!(e.message.contains("mingw-w64"), "{}", e.message);
3246        // And the mingw-w64 target next to it is an ordinary unpinned target.
3247        let e = parse_args(&args(&["--fetch", "x86_64-windows-gnu"])).unwrap_err();
3248        assert!(e.message.contains("pins no sysroot"), "{}", e.message);
3249    }
3250
3251    /// An Apple target on a machine with no SDK, which is section 8.6's other host.
3252    ///
3253    /// Not run on a mac, where the SDK this is about is installed and the compile is the ordinary one
3254    /// that uses it. What the reason says is asserted in `rucc_sysroot::wall` and where it is printed
3255    /// is asserted in `rucc-pp`, so what is left here is that the driver works it out and leaves it
3256    /// where the preprocessor will find it, and that neither way past the wall leaves one behind.
3257    #[test]
3258    fn an_apple_target_with_no_sdk_anywhere_carries_the_licence_rather_than_a_missing_directory() {
3259        if cfg!(target_os = "macos") || std::env::var_os("SDKROOT").is_some() {
3260            return;
3261        }
3262        let (opts, _) = compile(&["--target=aarch64-macos", "-c", "a.c"]);
3263        let why = opts.search.missing_system().expect("the wall is the reason there are none");
3264        assert!(why.contains("aarch64-macos needs a macOS SDK"), "{why}");
3265        assert!(why.contains("Xcode licence"), "{why}");
3266        assert!(why.contains("-isysroot"), "{why}");
3267
3268        // A program that includes none of the library needs none of the SDK, which is what section
3269        // 8.6 means by being able to target the platform without one, so there is nothing to explain.
3270        let (opts, _) = compile(&["--target=aarch64-macos", "-nostdinc", "-c", "a.c"]);
3271        assert_eq!(opts.search.missing_system(), None);
3272        // And naming a path is the other way through, whether or not the path is there: a mistyped
3273        // directory is a mistake to report on its own terms rather than a licence to explain.
3274        let (opts, _) = compile(&["--target=aarch64-macos", "-isysroot", "/opt/sdk", "-c", "a.c"]);
3275        assert_eq!(opts.search.missing_system(), None);
3276    }
3277
3278    /// The same wall on the compile side of an MSVC target, where the way past it is a tuple.
3279    #[test]
3280    fn an_msvc_target_with_no_sdk_named_says_which_environment_needs_nothing_installed() {
3281        if std::env::var_os("INCLUDE").is_some() {
3282            return;
3283        }
3284        let (opts, _) = compile(&["--target=x86_64-windows-msvc", "-c", "a.c"]);
3285        let why = opts.search.missing_system().expect("the wall is the reason there are none");
3286        assert!(why.contains("the Windows SDK and its universal CRT"), "{why}");
3287        assert!(why.contains("mingw-w64"), "{why}");
3288        // And the mingw-w64 target has its headers from us, so nothing is missing to explain.
3289        let (opts, _) = compile(&["--target=x86_64-windows-gnu", "-c", "a.c"]);
3290        assert_eq!(opts.search.missing_system(), None);
3291    }
3292
3293    #[test]
3294    fn a_fetch_with_no_target_and_a_fetch_of_a_tuple_that_is_not_one_both_say_which() {
3295        let e = parse_args(&args(&["--fetch"])).unwrap_err();
3296        assert!(e.message.contains("--fetch requires"), "{}", e.message);
3297        let e = parse_args(&args(&["--fetch", "sparc64-solaris-gnu"])).unwrap_err();
3298        assert!(e.message.contains("--fetch sparc64-solaris-gnu"), "{}", e.message);
3299        assert!(e.message.contains("no sysroot to get"), "{}", e.message);
3300    }
3301
3302    /// Both flags on one line ask for opposite things, in either order.
3303    #[test]
3304    fn a_fetch_and_offline_together_is_a_refusal_whichever_way_round_they_are_written() {
3305        for line in [
3306            vec!["--offline", "--fetch", "x86_64-linux-musl"],
3307            vec!["--fetch", "x86_64-linux-musl", "--offline"],
3308        ] {
3309            let e = parse_args(&args(&line)).unwrap_err();
3310            assert!(e.message.contains("two opposite things"), "{}", e.message);
3311        }
3312    }
3313
3314    #[test]
3315    fn a_fetch_does_not_compile_anything_and_says_so_when_it_is_handed_a_file() {
3316        let e = parse_args(&args(&["--fetch", "x86_64-linux-musl", "a.c"])).unwrap_err();
3317        assert!(e.message.contains("compiles nothing"), "{}", e.message);
3318        assert!(e.message.contains("a.c"), "{}", e.message);
3319    }
3320
3321    /// `--offline` on its own is accepted and changes nothing, because an ordinary compile
3322    /// downloads nothing with or without it. A build that passes it everywhere is the case this is
3323    /// for, and it must not lose the compilation it was passed beside.
3324    #[test]
3325    fn offline_on_a_compilation_is_the_same_compilation() {
3326        let (opts, plan) = compile(&["-c", "--offline", "a.c"]);
3327        let (plain, without) = compile(&["-c", "a.c"]);
3328        assert_eq!(opts.target, plain.target);
3329        assert_eq!(plan.jobs.len(), without.jobs.len());
3330        assert_eq!(plan.jobs[0].output, without.jobs[0].output);
3331    }
3332
3333    #[test]
3334    fn an_unknown_flag_is_an_error_rather_than_a_shrug() {
3335        let e = parse_args(&args(&["-fno-such-thing", "a.c"])).unwrap_err();
3336        assert!(e.message.contains("unknown option"), "{}", e.message);
3337    }
3338
3339    /// `-fpermissive` and the flag that turns it back off, which a build writes beside it when
3340    /// one directory needs the older rules and the rest of the tree does not.
3341    #[test]
3342    fn permissive_reads_in_both_directions_and_the_last_one_wins() {
3343        let (opts, _) = compile(&["-c", "a.c"]);
3344        assert!(!opts.permissive, "off unless it is asked for");
3345
3346        let (opts, _) = compile(&["-c", "-fpermissive", "a.c"]);
3347        assert!(opts.permissive);
3348
3349        let (opts, _) = compile(&["-c", "-fpermissive", "-fno-permissive", "a.c"]);
3350        assert!(!opts.permissive);
3351    }
3352
3353    #[test]
3354    fn asking_for_nested_functions_is_told_why_it_is_not_coming() {
3355        let e = parse_args(&args(&["-fnested-functions", "a.c"])).unwrap_err();
3356        assert!(e.message.contains("trampoline"), "{}", e.message);
3357        assert!(parse_args(&args(&["-fno-nested-functions", "a.c"])).is_ok());
3358    }
3359
3360    #[test]
3361    fn the_flag_every_configure_script_writes_is_taken() {
3362        // All four spellings, because a build writes whichever one its macros picked and a
3363        // compiler that takes three of them is a compiler that fails on the fourth.
3364        for flag in ["-fPIC", "-fpic", "-fPIE", "-fpie"] {
3365            let (opts, _) = compile(&["-c", flag, "a.c"]);
3366            assert_eq!(opts.emit, EmitKind::Object, "{flag}");
3367        }
3368    }
3369
3370    #[test]
3371    fn a_table_is_written_unless_the_build_says_nothing_will_walk_it() {
3372        let (opts, _) = compile(&["-c", "a.c"]);
3373        assert!(opts.unwinds(), "the default is off");
3374        let (opts, _) = compile(&["-c", "-fno-asynchronous-unwind-tables", "a.c"]);
3375        assert!(!opts.unwinds(), "the build was not taken at its word");
3376        let (opts, _) = compile(&[
3377            "-c",
3378            "-fno-asynchronous-unwind-tables",
3379            "-fasynchronous-unwind-tables",
3380            "a.c",
3381        ]);
3382        assert!(opts.unwinds(), "the last flag did not win");
3383        // The weaker request, which the same table answers, so a line that asks for a table and
3384        // against an asynchronous one gets one. That is gcc's arrangement and it turns up when a
3385        // build turns the asynchronous one off globally and a directory asks for a table back.
3386        let (opts, _) =
3387            compile(&["-c", "-fno-asynchronous-unwind-tables", "-funwind-tables", "a.c"]);
3388        assert!(opts.unwinds(), "the weaker request was dropped");
3389        let (opts, _) = compile(&["-c", "-fno-unwind-tables", "a.c"]);
3390        assert!(opts.unwinds(), "the weaker negative turned off the stronger request");
3391        let (opts, _) =
3392            compile(&["-c", "-fno-unwind-tables", "-fno-asynchronous-unwind-tables", "a.c"]);
3393        assert!(!opts.unwinds(), "both were turned off and one stayed on");
3394    }
3395
3396    #[test]
3397    fn the_flags_that_describe_what_this_compiler_already_does_are_taken() {
3398        // Every one of these is on a real build line somewhere and every one of them was an
3399        // unknown option. What they have in common is that the answer rucc gives is the answer
3400        // they ask for, so there is nothing to implement and nothing to refuse.
3401        for flag in [
3402            "-fno-common",
3403            "-fstrict-aliasing",
3404            "-fno-strict-aliasing",
3405            "-fdelete-null-pointer-checks",
3406            "-fno-delete-null-pointer-checks",
3407            "-frounding-math",
3408            "-fno-rounding-math",
3409            "-fexcess-precision=standard",
3410            "-fexcess-precision=fast",
3411            "-fexcess-precision=16",
3412            "-pipe",
3413            "-fdiagnostics-color",
3414            "-fno-diagnostics-color",
3415            "-fdiagnostics-color=always",
3416            "-fdiagnostics-color=never",
3417            "-fdiagnostics-color=auto",
3418        ] {
3419            let (opts, _) = compile(&["-c", flag, "a.c"]);
3420            assert_eq!(opts.emit, EmitKind::Object, "{flag}");
3421        }
3422    }
3423
3424    #[test]
3425    fn whether_an_exception_is_looked_at_is_kept_and_defaults_to_gccs_answer() {
3426        let (opts, _) = compile(&["-c", "a.c"]);
3427        assert!(opts.trapping_math, "the default was not gcc's");
3428        let (opts, _) = compile(&["-c", "-fno-trapping-math", "a.c"]);
3429        assert!(!opts.trapping_math);
3430        let (opts, _) = compile(&["-c", "-ftrapping-math", "a.c"]);
3431        assert!(opts.trapping_math, "spelling out the default turned it off");
3432        // The last one written wins, which is how a build line that inherits a flag from one
3433        // place and overrides it in another is read.
3434        let (opts, _) = compile(&["-c", "-fno-trapping-math", "-ftrapping-math", "a.c"]);
3435        assert!(opts.trapping_math);
3436    }
3437
3438    /// The flags a torture program writes on its own `dg-options` line, which is where most of
3439    /// these come from: a program reduced from a miscompilation names the pass that miscompiled
3440    /// it. Eighteen programs in the suite stopped on the driver before anything read them, and
3441    /// tamnd/rucc#1019 is the list.
3442    #[test]
3443    fn the_flags_that_name_a_pass_of_gccs_own_are_taken_and_dropped() {
3444        for flag in [
3445            "-fno-tree-ccp",
3446            "-fno-tree-dominator-opts",
3447            "-fno-tree-vrp",
3448            "-fno-tree-bit-ccp",
3449            "-fno-tree-coalesce-vars",
3450            "-ftree-vectorize",
3451            "-ftree-loop-distribution",
3452            "-fno-ipa-cp",
3453            "-fipa-pta",
3454            "-fmodulo-sched",
3455            "-fno-vect-cost-model",
3456            "-fvect-cost-model=unlimited",
3457            "-fsimd-cost-model=cheap",
3458            "-fexpensive-optimizations",
3459            "-fno-early-inlining",
3460            "-fno-inline",
3461            "-finline-functions",
3462            "-foptimize-strlen",
3463            "-fno-ira-share-spill-slots",
3464        ] {
3465            let (opts, _) = compile(&["-c", flag, "a.c"]);
3466            assert_eq!(opts.emit, EmitKind::Object, "{flag}");
3467            assert!(opts.passes.is_empty(), "{flag} named a pass of gcc's and not one of ours");
3468        }
3469    }
3470
3471    /// The two namespaces are taken whole, so a name neither this test nor gcc 16 has heard of
3472    /// goes the same way as the ones above rather than stopping a build on the day gcc adds it.
3473    #[test]
3474    fn a_pass_name_in_either_family_is_taken_whether_or_not_it_is_one_gcc_has() {
3475        for flag in ["-ftree-no-such-pass", "-fno-ipa-no-such-pass"] {
3476            let (opts, _) = compile(&["-c", flag, "a.c"]);
3477            assert_eq!(opts.emit, EmitKind::Object, "{flag}");
3478        }
3479    }
3480
3481    /// A pass this compiler has keeps its flag, since the arms that read the registry are above
3482    /// the family arms. `dce` is the one both compilers have a name for, and `execute/pr97421-2.c`
3483    /// is the program that writes it.
3484    #[test]
3485    fn a_pass_name_this_compiler_has_is_still_read_as_a_pass() {
3486        let (opts, _) = compile(&["-c", "-fno-dce", "a.c"]);
3487        assert_eq!(opts.passes, vec![("dce".to_owned(), false)]);
3488    }
3489
3490    /// gcc's name for the unroller reaches the unroller, in both directions. libtommath puts
3491    /// `-funroll-loops` in `CFLAGS` unconditionally, and before this it was an unknown option and
3492    /// the build stopped on its first file.
3493    #[test]
3494    fn the_gcc_spelling_of_the_unroller_turns_the_unroller_on_and_off() {
3495        let (opts, _) = compile(&["-c", "-funroll-loops", "a.c"]);
3496        assert_eq!(opts.passes, vec![("unroll".to_owned(), true)]);
3497        let (opts, _) = compile(&["-c", "-fno-unroll-loops", "a.c"]);
3498        assert_eq!(opts.passes, vec![("unroll".to_owned(), false)]);
3499    }
3500
3501    /// The encoding of the source is not a question about speed, so the one name that describes
3502    /// what the preprocessor does is taken and every other name is refused.
3503    #[test]
3504    fn the_input_charset_is_taken_when_it_names_the_one_that_is_read() {
3505        for flag in ["-finput-charset=utf-8", "-finput-charset=UTF-8", "-finput-charset=utf8"] {
3506            let (opts, _) = compile(&["-c", flag, "a.c"]);
3507            assert_eq!(opts.emit, EmitKind::Object, "{flag}");
3508        }
3509
3510        let e = parse_args(&args(&["-c", "-finput-charset=latin1", "a.c"])).unwrap_err();
3511        assert!(e.message.contains("latin1"), "{}", e.message);
3512        assert!(e.message.contains("UTF-8"), "what is read is worth saying: {}", e.message);
3513    }
3514
3515    /// The other half of the same rule. Each of these changes what the program does rather than
3516    /// how fast it does it, so each is refused with the reason, and the negative of each is what
3517    /// happens anyway and is taken.
3518    #[test]
3519    fn the_three_that_change_the_answer_are_refused_and_their_negatives_are_taken() {
3520        for (flag, word) in [
3521            ("-ffast-math", "__FAST_MATH__"),
3522            ("-fnon-call-exceptions", "landing pad"),
3523            ("-finstrument-functions", "__cyg_profile_func_enter"),
3524        ] {
3525            let e = parse_args(&args(&["-c", flag, "a.c"])).unwrap_err();
3526            assert!(e.message.contains(word), "{flag}: {}", e.message);
3527            assert!(!e.message.contains("unknown option"), "{flag} deserves a reason");
3528
3529            let off = format!("-fno-{}", flag.trim_start_matches("-f"));
3530            let (opts, _) = compile(&["-c", &off, "a.c"]);
3531            assert_eq!(opts.emit, EmitKind::Object, "{off}");
3532        }
3533    }
3534
3535    #[test]
3536    fn asking_the_linker_to_merge_tentative_definitions_is_told_why_it_is_not_coming() {
3537        // The one of that family that is a request rather than a description, and it is a real
3538        // difference: two files each writing `int g;` link under it and do not without it.
3539        let e = parse_args(&args(&["-fcommon", "a.c"])).unwrap_err();
3540        assert!(e.message.contains(".bss"), "{}", e.message);
3541        assert!(e.message.contains("extern"), "the way out is worth saying: {}", e.message);
3542    }
3543
3544    #[test]
3545    fn asking_for_position_dependent_code_is_told_why_it_is_not_coming() {
3546        for flag in ["-fno-pic", "-fno-pie"] {
3547            let e = parse_args(&args(&[flag, "a.c"])).unwrap_err();
3548            assert!(e.message.contains("global offset table"), "{flag}: {}", e.message);
3549            // The one it may have meant, since the two are a letter apart and one of them is
3550            // about linking and is taken.
3551            assert!(e.message.contains("-no-pie"), "{flag}: {}", e.message);
3552        }
3553    }
3554
3555    #[test]
3556    fn an_unsupported_target_names_itself() {
3557        let e = parse_args(&args(&["--target=sparc64-linux-gnu", "a.c"])).unwrap_err();
3558        assert!(e.message.contains("sparc64"), "{}", e.message);
3559    }
3560
3561    #[test]
3562    fn no_inputs_is_an_error_but_print_config_needs_none() {
3563        assert!(parse_args(&args(&[])).is_err());
3564        assert!(matches!(parse_args(&args(&["--print-config"])), Ok(Action::PrintConfig(_))));
3565    }
3566
3567    #[test]
3568    fn print_config_reports_the_target_it_was_given_not_the_host() {
3569        let a = parse_args(&args(&["--print-config", "--target=riscv64-linux-musl"])).unwrap();
3570        let Action::PrintConfig(opts) = a else { panic!("expected a configuration dump") };
3571        let text = print_config(&opts);
3572        assert!(text.contains("target: riscv64-unknown-linux-musl"), "{text}");
3573        assert!(text.contains("char-signed: false"), "{text}");
3574        assert!(text.contains("object-format: elf"), "{text}");
3575        assert!(text.contains("va-list: void-pointer"), "{text}");
3576        // RISC-V has a register file and this compiler has not written it down yet, and the
3577        // dump says which of those two it is rather than leaving the line out.
3578        assert!(text.contains("registers: none"), "{text}");
3579        assert!(text.contains("timing-model: none"), "{text}");
3580    }
3581
3582    /// The model the schedule was chosen with, which is a receipt anybody comparing two runs of a
3583    /// benchmark needs: two numbers that disagree are usually two models and not two compilers.
3584    #[test]
3585    fn print_config_names_the_model_the_schedule_was_chosen_with() {
3586        let opts = Options::new("x86_64-unknown-linux-gnu".parse().unwrap());
3587        let text = print_config(&opts);
3588        let line = text.lines().find(|l| l.starts_with("timing-model:")).expect("the model");
3589        assert!(line.contains("Skylake"), "{line}");
3590        assert!(line.contains("published"), "a sentence saying where it came from: {line}");
3591    }
3592
3593    #[test]
3594    fn print_config_has_one_key_per_line_and_a_fixed_order() {
3595        let opts = Options::new("x86_64-unknown-linux-gnu".parse().unwrap());
3596        let text = print_config(&opts);
3597        let keys: Vec<&str> =
3598            text.lines().map(|l| l.split(':').next().unwrap_or_default()).collect();
3599        assert_eq!(keys[0], "version");
3600        assert_eq!(keys[1], "target");
3601        assert_eq!(keys.len(), 26);
3602        assert!(text.ends_with('\n'));
3603    }
3604
3605    #[test]
3606    fn the_safety_tier_is_read_off_the_command_line_and_a_wrong_one_is_refused() {
3607        let (opts, _) = compile(&["a.c"]);
3608        assert_eq!(opts.safety, rucc_session::Safety::Off);
3609
3610        for (flag, tier) in [
3611            ("-fsafety=detect", rucc_session::Safety::Detect),
3612            ("-fsafety=enforce", rucc_session::Safety::Enforce),
3613            ("-fsafety=kernel", rucc_session::Safety::Kernel),
3614            ("-fsafety=off", rucc_session::Safety::Off),
3615        ] {
3616            let (opts, _) = compile(&[flag, "a.c"]);
3617            assert_eq!(opts.safety, tier, "{flag}");
3618        }
3619
3620        // The last one wins, the way every other repeated flag on this command line does.
3621        let (opts, _) = compile(&["-fsafety=enforce", "-fsafety=off", "a.c"]);
3622        assert_eq!(opts.safety, rucc_session::Safety::Off);
3623
3624        // A misspelled tier is refused rather than ignored. Silently compiling without the
3625        // monitor a build asked for is the one failure mode this feature cannot have.
3626        let e = parse_args(&args(&["-fsafety=on", "a.c"])).unwrap_err();
3627        assert!(e.message.contains("is not a safety tier"), "{}", e.message);
3628        assert!(parse_args(&args(&["-fsafety", "a.c"])).is_err());
3629    }
3630
3631    #[test]
3632    fn the_padding_mode_is_read_off_the_command_line_and_a_wrong_one_is_refused() {
3633        // The default is the one section 9.3 of document 09 gives library code, which is that
3634        // padding does not participate, so a record filled a member at a time is not reported.
3635        let (opts, _) = compile(&["a.c"]);
3636        assert_eq!(opts.padding, rucc_session::Padding::Ignored);
3637
3638        let (opts, _) = compile(&["-fsafety=detect", "-fsafety-init=padding", "a.c"]);
3639        assert_eq!(opts.padding, rucc_session::Padding::Tracked);
3640
3641        let (opts, _) = compile(&["-fsafety-init=padding", "-fsafety-init=nopadding", "a.c"]);
3642        assert_eq!(opts.padding, rucc_session::Padding::Ignored);
3643
3644        // The tier is still a tier. A flag whose name starts the same way must not be eaten by
3645        // the one above it, which is the thing worth pinning about a pair of names like these.
3646        let (opts, _) = compile(&["-fsafety-init=padding", "a.c"]);
3647        assert_eq!(opts.safety, rucc_session::Safety::Off);
3648
3649        let e = parse_args(&args(&["-fsafety-init=some", "a.c"])).unwrap_err();
3650        assert!(e.message.contains("is not a padding mode"), "{}", e.message);
3651    }
3652
3653    #[test]
3654    fn whether_a_write_has_to_stay_inside_its_member_is_read_off_the_command_line() {
3655        // Off by default, because a store to allocated storage sets its effective type and C 6.5
3656        // lets a program reuse a buffer as something else. Row S4 is a build opting out of that.
3657        let (opts, _) = compile(&["a.c"]);
3658        assert_eq!(opts.subobject, rucc_session::Subobject::Off);
3659
3660        let (opts, _) = compile(&["-fsafety=detect", "-fsafety-subobject", "a.c"]);
3661        assert_eq!(opts.subobject, rucc_session::Subobject::Members);
3662
3663        let (opts, _) = compile(&["-fsafety-subobject", "-fno-safety-subobject", "a.c"]);
3664        assert_eq!(opts.subobject, rucc_session::Subobject::Off);
3665
3666        // It takes no value. The form that would take one is the strict reading of section 9.4,
3667        // which is not written yet, so say so rather than accept a spelling that does nothing.
3668        let e = parse_args(&args(&["-fsafety-subobject=strict", "a.c"])).unwrap_err();
3669        assert!(e.message.contains("tamnd/rucc#967"), "{}", e.message);
3670    }
3671
3672    #[test]
3673    fn whether_two_restrict_pointers_may_meet_is_read_off_the_command_line() {
3674        // Off by default, because the record a block keeps is the union of what each pointer
3675        // reached, so two pointers striding through one array without landing on the same byte are
3676        // reported and by the letter of the standard those are different objects. Row Y8 is a build
3677        // deciding it would rather know.
3678        let (opts, _) = compile(&["a.c"]);
3679        assert_eq!(opts.promise, rucc_session::Promise::Off);
3680
3681        let (opts, _) = compile(&["-fsafety=detect", "-fsafety-restrict", "a.c"]);
3682        assert_eq!(opts.promise, rucc_session::Promise::Blocks);
3683
3684        let (opts, _) = compile(&["-fsafety-restrict", "-fno-safety-restrict", "a.c"]);
3685        assert_eq!(opts.promise, rucc_session::Promise::Off);
3686
3687        // The tier is still a tier, which is the thing worth pinning about a pair of names where
3688        // one is the front of the other.
3689        let (opts, _) = compile(&["-fsafety-restrict", "a.c"]);
3690        assert_eq!(opts.safety, rucc_session::Safety::Off);
3691
3692        let e = parse_args(&args(&["-fsafety-restrict=blocks", "a.c"])).unwrap_err();
3693        assert!(e.message.contains("takes no value"), "{}", e.message);
3694    }
3695
3696    #[test]
3697    fn safety_races_takes_a_mode_and_defaults_to_watching_nothing() {
3698        // Three modes rather than a bare flag, because section 9.5 gives two answers that record
3699        // the same thing and report different classes, so a flag with no value could not say which
3700        // was wanted. Off by default for the reason on `rucc_session::Races`, which is not a cost
3701        // argument: this is the one plane where an edge nobody interposed costs a false report.
3702        let (opts, _) = compile(&["a.c"]);
3703        assert_eq!(opts.races, rucc_session::Races::Off);
3704
3705        let (opts, _) = compile(&["-fsafety-races=metadata", "a.c"]);
3706        assert_eq!(opts.races, rucc_session::Races::Metadata);
3707
3708        let (opts, _) = compile(&["-fsafety-races=pointer", "a.c"]);
3709        assert_eq!(opts.races, rucc_session::Races::Pointer);
3710
3711        // Last one wins, as it does for every other mode flag here.
3712        let (opts, _) = compile(&["-fsafety-races=pointer", "-fno-safety-races", "a.c"]);
3713        assert_eq!(opts.races, rucc_session::Races::Off);
3714
3715        let e = parse_args(&args(&["-fsafety-races=all", "a.c"])).unwrap_err();
3716        assert!(e.message.contains("off, metadata or pointer"), "{}", e.message);
3717    }
3718
3719    #[test]
3720    fn print_pipeline_answers_with_the_passes_the_level_asked_for() {
3721        let a = parse_args(&args(&["--print-pipeline", "-O2"])).unwrap();
3722        let Action::PrintPipeline(opts) = a else { panic!("expected a pipeline dump") };
3723        let text = print_pipeline(&opts);
3724        assert!(text.starts_with("level: -O2\n"), "{text}");
3725        assert!(text.contains("fold"), "{text}");
3726
3727        let a = parse_args(&args(&["--print-pipeline"])).unwrap();
3728        let Action::PrintPipeline(opts) = a else { panic!("expected a pipeline dump") };
3729        // Two passes run at `-O0` and neither is an optimization. The first moves what
3730        // `__builtin_expect` said onto the branch and takes the instruction away, so that nothing
3731        // past the optimizer has to know the instruction exists. The second removes code nothing
3732        // reaches. See issue 359.
3733        assert!(print_pipeline(&opts).contains("1: expect,"), "{}", print_pipeline(&opts));
3734        assert!(print_pipeline(&opts).contains("2: simplify-cfg,"), "{}", print_pipeline(&opts));
3735
3736        let a = parse_args(&args(&["--print-pipeline", "-fno-simplify-cfg"])).unwrap();
3737        let Action::PrintPipeline(opts) = a else { panic!("expected a pipeline dump") };
3738        // The second turns off and the first does not, because nothing below the optimizer lowers
3739        // what it removes, so `-fno-expect` is a compile that stops rather than one that runs.
3740        let text = print_pipeline(&opts);
3741        assert!(text.contains("1: expect,"), "{text}");
3742        assert!(!text.contains("simplify-cfg"), "{text}");
3743    }
3744
3745    #[test]
3746    fn print_pipeline_takes_the_toggles_into_account() {
3747        let a = parse_args(&args(&["--print-pipeline", "-O2", "-fno-fold"])).unwrap();
3748        let Action::PrintPipeline(opts) = a else { panic!("expected a pipeline dump") };
3749        let text = print_pipeline(&opts);
3750        // The one that was named is gone and the rest of the level is not, which is the whole
3751        // of what a toggle promises.
3752        assert!(!text.contains("fold"), "{text}");
3753        assert!(text.contains("dce"), "{text}");
3754
3755        // Every pass the compiler has, named off. Built from the registry rather than written
3756        // out, so a pass added later is turned off here too and this keeps testing the thing it
3757        // is about, which is that the toggles can empty a level down to the passes that are not
3758        // optional. Those are named, because a listing that is all of them is a level nobody
3759        // emptied and the assertion would pass while saying nothing.
3760        let mut off = vec!["--print-pipeline".to_owned(), "-O2".to_owned()];
3761        off.extend(rucc_opt::PASSES.iter().map(|p| format!("-fno-{}", p.name())));
3762        let spelled: Vec<&str> = off.iter().map(String::as_str).collect();
3763        let a = parse_args(&args(&spelled)).unwrap();
3764        let Action::PrintPipeline(opts) = a else { panic!("expected a pipeline dump") };
3765        let text = print_pipeline(&opts);
3766        let left: Vec<&str> =
3767            rucc_opt::PASSES.iter().filter(|p| p.required()).map(|p| p.name()).collect();
3768        assert_eq!(left, vec!["expect"], "{text}");
3769        for (at, name) in left.iter().enumerate() {
3770            assert!(text.contains(&format!("{}: {name},", at + 1)), "{text}");
3771        }
3772        assert!(!text.contains("dce"), "{text}");
3773    }
3774
3775    #[test]
3776    fn print_pipeline_says_when_a_budget_will_stop_the_run_short() {
3777        let a = parse_args(&args(&["--print-pipeline", "-O2"])).unwrap();
3778        let Action::PrintPipeline(opts) = a else { panic!("expected a pipeline dump") };
3779        assert!(!print_pipeline(&opts).contains("global fuel"));
3780
3781        let a = parse_args(&args(&["--print-pipeline", "-O2", "-fpass-fuel-global=4"])).unwrap();
3782        let Action::PrintPipeline(opts) = a else { panic!("expected a pipeline dump") };
3783        let text = print_pipeline(&opts);
3784        // Because the listing is the answer to what this compilation will do, and a run that
3785        // stops after four rewrites is not doing what the level says it does.
3786        assert!(text.contains("global fuel: 4"), "{text}");
3787    }
3788
3789    /// A pass is turned on and off by its own name, and the order the flags were given in is
3790    /// kept, because the last spelling of a name is the one that decides.
3791    #[test]
3792    fn a_pass_is_named_by_dash_f_and_unnamed_by_dash_f_no() {
3793        let (opts, _) = compile(&["-c", "-O0", "-ffold", "-fno-fold", "-ffold", "a.c"]);
3794        assert_eq!(
3795            opts.passes,
3796            [("fold".to_owned(), true), ("fold".to_owned(), false), ("fold".to_owned(), true)]
3797        );
3798
3799        let e = parse_args(&args(&["-fno-such-pass", "a.c"])).unwrap_err();
3800        assert!(e.message.contains("unknown option"), "{}", e.message);
3801    }
3802
3803    #[test]
3804    fn pass_fuel_names_a_pass_and_a_count_and_refuses_anything_else() {
3805        let (opts, _) = compile(&["-c", "-O2", "-fpass-fuel=fold=3", "a.c"]);
3806        assert_eq!(opts.pass_fuel, [("fold".to_owned(), 3)]);
3807
3808        let e = parse_args(&args(&["-fpass-fuel=fold", "a.c"])).unwrap_err();
3809        assert!(e.message.contains("<pass>=<count>"), "{}", e.message);
3810        let e = parse_args(&args(&["-fpass-fuel=nosuch=3", "a.c"])).unwrap_err();
3811        assert!(e.message.contains("--print-pipeline"), "{}", e.message);
3812        let e = parse_args(&args(&["-fpass-fuel=fold=lots", "a.c"])).unwrap_err();
3813        assert!(e.message.contains("not a number"), "{}", e.message);
3814    }
3815
3816    #[test]
3817    fn global_pass_fuel_is_a_count_on_its_own_and_defaults_to_no_limit() {
3818        let (opts, _) = compile(&["-c", "-O2", "a.c"]);
3819        assert_eq!(opts.pass_fuel_global, None);
3820
3821        let (opts, _) = compile(&["-c", "-O2", "-fpass-fuel-global=12", "a.c"]);
3822        assert_eq!(opts.pass_fuel_global, Some(12));
3823        // And it is not the per pass flag with a longer name, so neither spelling swallows the
3824        // other.
3825        assert!(opts.pass_fuel.is_empty());
3826
3827        let e = parse_args(&args(&["-fpass-fuel-global=lots", "a.c"])).unwrap_err();
3828        assert!(e.message.contains("not a number"), "{}", e.message);
3829    }
3830
3831    #[test]
3832    fn a_gate_names_a_pass_and_optionally_the_functions_it_covers() {
3833        let (opts, _) = compile(&["-c", "-O2", "-fdisable-fold", "-fenable-fold=2-4,main", "a.c"]);
3834        assert_eq!(
3835            opts.pass_gates,
3836            [(false, "fold".to_owned()), (true, "fold=2-4,main".to_owned())],
3837            "the order is what decides, so it has to survive the parse"
3838        );
3839
3840        let e = parse_args(&args(&["-fdisable-nosuch", "a.c"])).unwrap_err();
3841        assert!(e.message.contains("--print-pipeline"), "{}", e.message);
3842        let e = parse_args(&args(&["-fenable-fold=9-2", "a.c"])).unwrap_err();
3843        assert!(e.message.contains("ends before it starts"), "{}", e.message);
3844        let e = parse_args(&args(&["-fdisable-fold=", "a.c"])).unwrap_err();
3845        assert!(e.message.contains("is empty"), "{}", e.message);
3846    }
3847
3848    #[test]
3849    fn the_pipeline_listing_says_which_passes_a_gate_touched() {
3850        let (opts, _) = compile(&["-c", "-O2", "-fdisable-fold=main", "a.c"]);
3851        let text = print_pipeline(&opts);
3852        assert!(text.contains("fold, "), "{text}");
3853        assert!(text.contains("[off for main]"), "{text}");
3854    }
3855
3856    /// The spelling is checked while the arguments are read, because a dump that names a pass
3857    /// this compiler does not have is a typo, and a typo found after the compilation has run is
3858    /// found too late to be any use.
3859    #[test]
3860    fn a_dump_is_checked_when_it_is_asked_for_rather_than_when_it_is_taken() {
3861        let (opts, _) = compile(&["-c", "-O2", "-fdump-ir=all", "-fdump-ir=after-fold", "a.c"]);
3862        assert_eq!(opts.dump_ir, ["all", "after-fold"]);
3863
3864        let e = parse_args(&args(&["-fdump-ir=after-nosuch", "a.c"])).unwrap_err();
3865        assert!(e.message.contains("nosuch"), "{}", e.message);
3866        assert!(parse_args(&args(&["-fdump-ir=sideways-fold", "a.c"])).is_err());
3867    }
3868
3869    /// Every spelling `-fopt-info` takes, and the one it does not.
3870    ///
3871    /// The keywords are checked here for the same reason a dump's pass name is: a person who
3872    /// misspelled one gets no output, and no output is also what a compilation where nothing
3873    /// happened looks like. Telling those two apart is the entire reason to reach for this flag.
3874    #[test]
3875    fn opt_info_takes_kinds_and_a_file_and_refuses_a_kind_it_does_not_have() {
3876        let (opts, _) = compile(&["-c", "-O2", "-fopt-info", "a.c"]);
3877        assert_eq!(opts.opt_info, [""], "a bare flag asks for the rewrites");
3878        assert_eq!(opts.opt_info_file, None, "and goes to standard error");
3879
3880        let (opts, _) = compile(&["-c", "-O2", "-fopt-info-missed-note", "a.c"]);
3881        assert_eq!(opts.opt_info, ["missed-note"]);
3882
3883        // Two flags add up rather than the second replacing the first, and the file is the last
3884        // one that named a file, which is how GCC treats both.
3885        let (opts, _) =
3886            compile(&["-c", "-O2", "-fopt-info-missed=one.txt", "-fopt-info-all=two.txt", "a.c"]);
3887        assert_eq!(opts.opt_info, ["missed", "all"]);
3888        assert_eq!(opts.opt_info_file.as_deref(), Some("two.txt"));
3889
3890        let e = parse_args(&args(&["-fopt-info-vectorized", "a.c"])).unwrap_err();
3891        assert!(e.message.contains("vectorized"), "{}", e.message);
3892        assert!(e.message.contains("`missed`"), "{}", e.message);
3893        let e = parse_args(&args(&["-fopt-info-missed=", "a.c"])).unwrap_err();
3894        assert!(e.message.contains("no file"), "{}", e.message);
3895    }
3896
3897    #[test]
3898    fn verify_each_is_unstable_and_off_unless_it_was_asked_for() {
3899        let (opts, _) = compile(&["-c", "-Zverify-each", "a.c"]);
3900        assert!(opts.verify_each);
3901        assert!(!USAGE.contains("verify-each"), "an unstable option stays out of the usage text");
3902    }
3903
3904    #[test]
3905    fn dash_o_needs_an_argument() {
3906        let e = parse_args(&args(&["a.c", "-o"])).unwrap_err();
3907        assert_eq!(e.message, "-o requires an argument");
3908    }
3909
3910    #[test]
3911    fn dash_d_and_dash_u_are_read_joined_or_separated_and_keep_their_order() {
3912        let (opts, _) = compile(&["-DFOO=1", "-D", "BAR", "-UBAZ", "-U", "QUX", "a.c"]);
3913        assert_eq!(opts.defines, ["FOO=1", "BAR"]);
3914        assert_eq!(opts.undefines, ["BAZ", "QUX"]);
3915    }
3916
3917    #[test]
3918    fn the_include_flags_land_on_the_chain_each_one_names() {
3919        // A sysroot with nothing under it, so that the library's own directories are the
3920        // same on every machine this test runs on, which is none of them.
3921        let (opts, _) = compile(&[
3922            "-Ii",
3923            "-iquote",
3924            "q",
3925            "-isystem",
3926            "sys",
3927            "-idirafter",
3928            "after",
3929            "--sysroot=/nowhere-at-all",
3930            "a.c",
3931        ]);
3932        let dirs: Vec<&str> = opts.search.dirs().iter().filter_map(|d| d.path.to_str()).collect();
3933        // The compiler's own headers sit after every `-isystem` and before `-idirafter`,
3934        // which is where GCC puts its own: a directory the user named outranks ours.
3935        assert_eq!(dirs, ["q", "i", "sys", runtime::DIR, "after"]);
3936        assert!(!opts.search.dirs()[1].is_system);
3937        assert!(opts.search.dirs()[2].is_system);
3938    }
3939
3940    #[test]
3941    fn the_librarys_headers_come_after_the_compilers_own_and_go_away_with_them() {
3942        // Which machine this runs on decides what is on the path, so the test is about the
3943        // order rather than about the names: ours is on it, the library's follow it, and
3944        // `-nostdinc` is the one flag that takes both halves of the pair off at once.
3945        let (opts, _) = compile(&["a.c"]);
3946        let dirs = opts.search.dirs();
3947        let ours = dirs.iter().position(|d| d.path.to_str() == Some(runtime::DIR));
3948        assert_eq!(ours, Some(0), "{dirs:?}");
3949        assert!(dirs[1..].iter().all(|d| d.is_system), "{dirs:?}");
3950        let (bare, _) = compile(&["-nostdinc", "a.c"]);
3951        assert!(bare.search.dirs().is_empty(), "{:?}", bare.search.dirs());
3952    }
3953
3954    #[test]
3955    fn a_sysroot_moves_the_librarys_directories_and_nothing_else() {
3956        let (opts, _) = compile(&["-isystem", "sys", "--sysroot=/nowhere-at-all", "a.c"]);
3957        let dirs: Vec<&str> = opts.search.dirs().iter().filter_map(|d| d.path.to_str()).collect();
3958        assert_eq!(dirs, ["sys", runtime::DIR]);
3959    }
3960
3961    #[test]
3962    fn a_cross_compile_reads_the_targets_own_headers_rather_than_the_ones_next_door() {
3963        // The target is not the machine this test runs on wherever it runs, so the answer is the
3964        // same on all of them: the libc's two include directories for that target, the kernel's
3965        // two, and nothing from here. A header read from here is the quiet failure of section 8.5, a
3966        // program that builds on the build machine and is wrong everywhere else.
3967        let (opts, _) = compile(&["--target=riscv64-linux-musl", "-c", "a.c"]);
3968        let dirs: Vec<&std::path::Path> =
3969            opts.search.dirs().iter().map(|d| d.path.as_path()).collect();
3970        let root = cache::dir().join("sysroots").join("riscv64-linux-musl");
3971        let kernel = cache::dir().join("kernel-headers");
3972        assert_eq!(dirs.len(), 5, "{dirs:?}");
3973        assert_eq!(dirs[0], std::path::Path::new(runtime::DIR));
3974        assert_eq!(dirs[1], root.join("include").join("riscv64"));
3975        assert_eq!(dirs[2], root.join("include").join("generic"));
3976        // The kernel's, which are beside the sysroots rather than inside one, because every target
3977        // that shares an architecture reads the same files.
3978        assert_eq!(dirs[3], kernel.join("riscv"));
3979        assert_eq!(dirs[4], kernel.join("generic"));
3980    }
3981
3982    #[test]
3983    fn a_cross_compile_to_something_that_is_not_linux_reads_no_kernel_headers() {
3984        // The other side of the same answer. Windows has its own system headers and no `linux/` at
3985        // all, so the list is the libc's two and the question never arises, which is the `None` that
3986        // `link::cross_kernel` returns rather than a directory nothing would be found in.
3987        let (opts, _) = compile(&["--target=x86_64-pc-windows-gnu", "-c", "a.c"]);
3988        let dirs: Vec<&std::path::Path> =
3989            opts.search.dirs().iter().map(|d| d.path.as_path()).collect();
3990        assert_eq!(dirs.len(), 3, "{dirs:?}");
3991        assert!(!dirs.iter().any(|dir| dir.ends_with("kernel-headers")), "{dirs:?}");
3992    }
3993
3994    #[test]
3995    fn the_glibc_version_macro_goes_with_the_bundled_tree_and_with_nothing_else() {
3996        // One tree serves every glibc release, so the release is what the target supplies, and the
3997        // condition is the same one that chose the directories. A host glibc and a tree somebody
3998        // named both define `__GLIBC_MINOR__` in their own `features.h`, and two definitions with
3999        // different values is a warning on every compilation of every file.
4000        //
4001        // The architecture is chosen against this machine's rather than written down, because the
4002        // bundled tree is only in effect for a target that is not this machine. The first version of
4003        // this test said x86_64-linux-gnu, which is a cross compile on a mac and this machine on a
4004        // Linux runner, so it passed here and failed there.
4005        let gnu = format!("--target={}-linux-gnu", cross_arch());
4006        let (bundled, _) = compile(&[&gnu, "-c", "a.c"]);
4007        assert_eq!(bundled.glibc_minor, Some(44));
4008        let pin = format!("{gnu}.2.28");
4009        let (pinned, _) = compile(&[&pin, "-c", "a.c"]);
4010        assert_eq!(pinned.glibc_minor, Some(28));
4011
4012        let (named, _) = compile(&[&gnu, "--sysroot=/nowhere-at-all", "-c", "a.c"]);
4013        assert_eq!(named.glibc_minor, None);
4014        let (none, _) = compile(&[&gnu, "-nostdinc", "-c", "a.c"]);
4015        assert_eq!(none.glibc_minor, None);
4016        let musl = format!("--target={}-linux-musl", cross_arch());
4017        let (musl, _) = compile(&[&musl, "-c", "a.c"]);
4018        assert_eq!(musl.glibc_minor, None);
4019
4020        // And this machine's own target gets nothing, whatever this machine is, because its headers
4021        // come from the machine and its own `features.h` defines the macro. On a glibc Linux box
4022        // that is the case this test had backwards; on a mac it is true for the other reason, which
4023        // is that Darwin is not a glibc target at all.
4024        if let Some(host) = Triple::host() {
4025            let native = format!("--target={}", host.tuple());
4026            let (native, _) = compile(&[&native, "-c", "a.c"]);
4027            assert_eq!(native.glibc_minor, None);
4028        }
4029    }
4030
4031    #[test]
4032    fn a_pinned_release_on_this_machines_own_target_reads_the_bundled_tree() {
4033        // The end to end half of the answer in `link::cross_for`. A release named for this machine's
4034        // own target is a cross compile, so the headers are the bundled tree's and the macro says
4035        // what was asked for rather than what this machine has.
4036        //
4037        // Only on a glibc box, because a release is a glibc release: a mac has no `__GLIBC_MINOR__`
4038        // to get wrong and nothing to pin. That makes this a test the Linux runners carry, which is
4039        // where the case lives.
4040        let Some(host) = Triple::host() else { return };
4041        if host.env != rucc_target::Env::Gnu {
4042            return;
4043        }
4044        let pin = format!("--target={}.2.28", host.tuple());
4045        let (opts, _) = compile(&[&pin, "-c", "a.c"]);
4046        assert_eq!(opts.glibc_minor, Some(28));
4047        let root = cache::dir().join("sysroots").join(format!("{}.2.28", host.tuple()));
4048        let dirs: Vec<&std::path::Path> =
4049            opts.search.dirs().iter().map(|d| d.path.as_path()).collect();
4050        assert!(dirs.iter().any(|dir| dir.starts_with(&root)), "{dirs:?}");
4051        // And nothing of this machine's, which is the failure this was: a program compiled against
4052        // 2.44 declarations and told it was 2.28.
4053        assert!(!dirs.iter().any(|dir| *dir == std::path::Path::new("/usr/include")), "{dirs:?}");
4054    }
4055
4056    /// An architecture that is not this machine's, out of the three the driver has targets for.
4057    ///
4058    /// A test about the bundled sysroot has to name a target that is not the host, because a target
4059    /// that is the host reads the host's own headers and libraries. Asking which machine this is
4060    /// beats picking a row and hoping, and it is two lines.
4061    fn cross_arch() -> &'static str {
4062        match Triple::host().map(|host| host.arch) {
4063            Some(rucc_target::Arch::X86_64) => "aarch64",
4064            _ => "x86_64",
4065        }
4066    }
4067
4068    #[test]
4069    fn a_glibc_newer_than_the_bundled_tree_is_refused_by_name() {
4070        // Both versions in the message, because the two things a person can do about it are pin a
4071        // release the tree has and name a sysroot that has the one they asked for, and neither is a
4072        // choice they can make without knowing which release the tree is.
4073        //
4074        // Not this machine's architecture, for the reason the test above gives: the refusal is about
4075        // the bundled tree, and the bundled tree is not what a target that is this machine reads.
4076        let target = format!("--target={}-linux-gnu.2.99", cross_arch());
4077        let message = refused(&[&target, "-c", "a.c"]);
4078        assert!(message.contains("asked for glibc 2.99"), "{message}");
4079        assert!(message.contains("bundled headers are glibc 2.44"), "{message}");
4080        assert!(message.contains("--sysroot"), "{message}");
4081    }
4082
4083    #[test]
4084    fn a_sysroot_the_user_named_is_still_what_a_cross_compile_reads() {
4085        // The tree somebody assembled beats the one we would build, on the headers as on the
4086        // libraries. It is empty here, which is why the list comes out short: the directories under
4087        // it are checked for rather than assumed, and a tree that is not there offers nothing.
4088        let (opts, _) =
4089            compile(&["--target=riscv64-linux-musl", "--sysroot=/nowhere-at-all", "-c", "a.c"]);
4090        let dirs: Vec<&std::path::Path> =
4091            opts.search.dirs().iter().map(|d| d.path.as_path()).collect();
4092        assert_eq!(dirs, [std::path::Path::new(runtime::DIR)]);
4093    }
4094
4095    #[test]
4096    fn dash_i_dash_moves_the_bracket_directories_into_the_quoted_chain() {
4097        let (opts, _) =
4098            compile(&["-Iinc1", "-iquote", "inc2", "-I-", "-Iinc3", "-nostdinc", "a.c"]);
4099        let dirs: Vec<&str> = opts.search.dirs().iter().filter_map(|d| d.path.to_str()).collect();
4100        assert_eq!(dirs, ["inc1", "inc2", "inc3"]);
4101        // An angled include sees only what came after the flag.
4102        assert_eq!(opts.search.start(IncludeForm::Angled), 2);
4103        assert!(!opts.search.searches_current_dir());
4104    }
4105
4106    #[test]
4107    fn the_prefix_flags_stick_what_iprefix_said_on_the_front_of_what_follows_it() {
4108        let (opts, _) = compile(&[
4109            "-iprefix",
4110            "/tools/",
4111            "-iwithprefix",
4112            "late",
4113            "-iwithprefixbefore",
4114            "early",
4115            "-iprefix",
4116            "/other/",
4117            "-iwithprefix",
4118            "last",
4119            "-nostdinc",
4120            "a.c",
4121        ]);
4122        let dirs: Vec<&str> = opts.search.dirs().iter().filter_map(|d| d.path.to_str()).collect();
4123        // `-iwithprefixbefore` is an `-I` and the other two are `-isystem`, which is where GCC
4124        // puts them rather than where its manual says it does.
4125        assert_eq!(dirs, ["/tools/early", "/tools/late", "/other/last"]);
4126        assert!(!opts.search.dirs()[0].is_system);
4127        assert!(opts.search.dirs()[1].is_system);
4128    }
4129
4130    #[test]
4131    fn the_files_named_on_the_command_line_keep_their_order_and_which_flag_named_them() {
4132        let (opts, _) =
4133            compile(&["-include", "one.h", "-imacros", "two.h", "-include", "3.h", "a.c"]);
4134        let names: Vec<&str> = opts.preincludes.iter().map(|p| p.name.as_str()).collect();
4135        assert_eq!(names, ["one.h", "two.h", "3.h"]);
4136        assert_eq!(opts.preincludes.iter().filter(|p| p.macros_only).count(), 1);
4137    }
4138
4139    #[test]
4140    fn nostdinc_takes_the_compilers_own_headers_off_the_path() {
4141        let (opts, _) = compile(&["-Ii", "-nostdinc", "a.c"]);
4142        let dirs: Vec<&str> = opts.search.dirs().iter().filter_map(|d| d.path.to_str()).collect();
4143        assert_eq!(dirs, ["i"]);
4144    }
4145
4146    #[test]
4147    fn the_dialect_flags_set_the_language_and_the_extensions_separately() {
4148        let (opts, _) = compile(&["-std=gnu11", "a.c"]);
4149        assert_eq!(opts.std, Std::C11);
4150        assert!(opts.gnu_extensions);
4151
4152        let (opts, _) = compile(&["-std=iso9899:1999", "a.c"]);
4153        assert_eq!(opts.std, Std::C99);
4154        assert!(!opts.gnu_extensions);
4155
4156        let (opts, _) = compile(&["-ansi", "a.c"]);
4157        assert_eq!(opts.std, Std::C89);
4158        assert!(!opts.gnu_extensions);
4159
4160        let e = parse_args(&args(&["-std=c94jr", "a.c"])).unwrap_err();
4161        assert!(e.message.contains("unknown dialect"), "{}", e.message);
4162    }
4163
4164    #[test]
4165    fn the_dump_letters_are_a_family_and_everything_else_beginning_with_d_is_not() {
4166        let (opts, _) = compile(&["-dM", "a.c"]);
4167        assert!(opts.dumps.macros);
4168
4169        // Packed, the way GCC takes them, and a letter in the family we have not written yet
4170        // is accepted and does nothing rather than failing a build.
4171        let (opts, _) = compile(&["-dDM", "a.c"]);
4172        assert!(opts.dumps.macros);
4173        let (opts, _) = compile(&["-dD", "a.c"]);
4174        assert!(!opts.dumps.macros);
4175
4176        let (opts, _) = compile(&["a.c"]);
4177        assert!(!opts.dumps.any());
4178
4179        // `-dumpversion` is a different flag that happens to start the same way, and it is read
4180        // as itself rather than as a dump of nothing.
4181        assert_eq!(printed(&["-dumpversion", "a.c"]), VERSION);
4182    }
4183
4184    #[test]
4185    fn the_gcc_version_claimed_is_a_flag_and_the_short_spellings_are_the_ones_people_write() {
4186        let (opts, _) = compile(&["a.c"]);
4187        assert_eq!(
4188            opts.gnuc,
4189            GnucVersion { major: 7, minor: 0, patch: 0 },
4190            "the lowest claim a modern glibc gives its own declarations to"
4191        );
4192
4193        let (opts, _) = compile(&["-fgnuc-version=15.1.0", "a.c"]);
4194        assert_eq!(opts.gnuc, GnucVersion { major: 15, minor: 1, patch: 0 });
4195
4196        // A missing component is zero. `gcc -dumpversion` says `15` on a release with no
4197        // patchlevel and a harness that pastes that back has to be understood.
4198        let (opts, _) = compile(&["-fgnuc-version=15", "a.c"]);
4199        assert_eq!(opts.gnuc, GnucVersion { major: 15, minor: 0, patch: 0 });
4200
4201        let (opts, _) = compile(&["-fgnuc-version=13.2", "a.c"]);
4202        assert_eq!(opts.gnuc, GnucVersion { major: 13, minor: 2, patch: 0 });
4203
4204        let e = parse_args(&args(&["-fgnuc-version=15.x", "a.c"])).unwrap_err();
4205        assert!(e.message.contains("minor that is not a number"), "{}", e.message);
4206
4207        let e = parse_args(&args(&["-fgnuc-version=1.2.3.4", "a.c"])).unwrap_err();
4208        assert!(e.message.contains("more than three"), "{}", e.message);
4209    }
4210
4211    #[test]
4212    fn pedantic_has_two_spellings_and_is_not_the_same_knob_as_the_dialect() {
4213        let (opts, _) = compile(&["-std=c17", "-pedantic", "a.c"]);
4214        assert!(opts.pedantic);
4215        assert_eq!(opts.std, Std::C17);
4216
4217        // The `-W` family's name for it, which is what a build that groups its warning flags
4218        // tends to write.
4219        let (opts, _) = compile(&["-Wpedantic", "a.c"]);
4220        assert!(opts.pedantic);
4221
4222        let (opts, _) = compile(&["-std=c17", "a.c"]);
4223        assert!(!opts.pedantic, "a dialect on its own does not diagnose an extension");
4224    }
4225
4226    #[test]
4227    fn dash_p_and_dash_ffreestanding_reach_the_options() {
4228        let (opts, _) = compile(&["-E", "-P", "-ffreestanding", "a.c"]);
4229        assert!(!opts.line_markers);
4230        assert!(!opts.hosted);
4231        assert_eq!(opts.emit, EmitKind::Preprocessed);
4232    }
4233
4234    /// The two ways a build says it means its own function by a name the C library also has.
4235    ///
4236    /// `-fno-builtin` is all of them and `-fno-builtin-<name>` is one, and the second is what a
4237    /// build writes when it means its own `memcpy` and the library's everything else. The name is
4238    /// kept as it was written and not checked against anything, because a program is allowed to
4239    /// mean something by a name this compiler has never heard of.
4240    #[test]
4241    fn the_builtin_flags_are_read_in_both_directions_and_one_name_at_a_time() {
4242        let (opts, _) = compile(&["-c", "a.c"]);
4243        assert!(opts.builtins, "a library name means the library function by default");
4244        assert!(opts.no_builtin.is_empty());
4245
4246        let (opts, _) = compile(&["-c", "-fno-builtin", "a.c"]);
4247        assert!(!opts.builtins);
4248
4249        let (opts, _) = compile(&["-c", "-fno-builtin", "-fbuiltin", "a.c"]);
4250        assert!(opts.builtins, "the last mention decides");
4251
4252        let (opts, _) = compile(&["-c", "-fno-builtin-memcpy", "-fno-builtin-nonesuch", "a.c"]);
4253        assert!(opts.builtins, "one name is not the family");
4254        assert_eq!(opts.no_builtin, vec!["memcpy".to_owned(), "nonesuch".to_owned()]);
4255    }
4256
4257    /// `-fvisibility=`, which is on every cmake project that cares about which names it exports
4258    /// and which was refused as an unknown option until now.
4259    ///
4260    /// Four spellings and three answers. `internal` is hidden plus a promise about never taking
4261    /// the address across a component boundary, and nothing derives anything from that promise
4262    /// here, so it comes out as the weaker of the two rather than as a refusal that stops a build
4263    /// over a distinction this compiler does not make.
4264    #[test]
4265    fn visibility_takes_the_four_spellings_gcc_takes_and_refuses_the_rest() {
4266        let (opts, _) = compile(&["-c", "a.c"]);
4267        assert_eq!(opts.visibility, Visibility::Default, "exported unless something says not");
4268
4269        for (written, wanted) in [
4270            ("default", Visibility::Default),
4271            ("hidden", Visibility::Hidden),
4272            ("internal", Visibility::Hidden),
4273            ("protected", Visibility::Protected),
4274        ] {
4275            let (opts, _) = compile(&["-c", &format!("-fvisibility={written}"), "a.c"]);
4276            assert_eq!(opts.visibility, wanted, "{written}");
4277        }
4278
4279        // The last mention decides, which is what every other flag of this shape does and what a
4280        // build that turns something off for one directory relies on.
4281        let (opts, _) = compile(&["-c", "-fvisibility=hidden", "-fvisibility=default", "a.c"]);
4282        assert_eq!(opts.visibility, Visibility::Default, "the last mention decides");
4283
4284        // A spelling gcc does not take is refused rather than read as the default, because a
4285        // build that meant hidden and got exported is a library with the wrong interface and
4286        // nothing said about it anywhere.
4287        let failed = parse_args(&args(&["-fvisibility=none", "a.c"])).expect_err("refused");
4288        assert!(failed.to_string().contains("is not a visibility"), "{failed}");
4289    }
4290
4291    /// `-ffp-contract=`, which is the one flag in the floating point group that is kept rather than
4292    /// described, and the values are gcc 16's three.
4293    #[test]
4294    fn how_far_a_multiply_and_an_addition_may_be_fused_is_asked_for() {
4295        let (opts, _) = compile(&["-c", "a.c"]);
4296        assert_eq!(opts.fp_contract, Contract::Off, "a licence nobody granted is not assumed");
4297
4298        for (written, wanted) in
4299            [("off", Contract::Off), ("on", Contract::On), ("fast", Contract::Fast)]
4300        {
4301            let (opts, _) = compile(&["-c", &format!("-ffp-contract={written}"), "a.c"]);
4302            assert_eq!(opts.fp_contract, wanted, "{written}");
4303        }
4304
4305        let (opts, _) = compile(&["-c", "-ffp-contract=fast", "-ffp-contract=off", "a.c"]);
4306        assert_eq!(opts.fp_contract, Contract::Off, "the last mention decides");
4307
4308        // Refused rather than read as one of the three, because a build that asked for no fusing
4309        // and was given the default would be one whose numbers change and whose command line says
4310        // they should not. gcc refuses the same spellings and names the same three in its message.
4311        for bad in ["-ffp-contract=none", "-ffp-contract=", "-ffp-contract=Fast"] {
4312            let failed = parse_args(&args(&[bad, "a.c"])).expect_err("refused");
4313            assert!(failed.to_string().contains("is not a contraction"), "{bad}: {failed}");
4314        }
4315
4316        // And the other one that takes a value, which is taken and kept nowhere: every operation
4317        // here is computed in the type it was written in, so `standard` is what happens and the
4318        // other two are permission to do something this does not do.
4319        let failed = parse_args(&args(&["-fexcess-precision=long", "a.c"])).expect_err("refused");
4320        assert!(failed.to_string().contains("is not an excess precision"), "{failed}");
4321    }
4322
4323    /// The four prefix mapping flags, which are what a distribution passes to get the same bytes
4324    /// out of `/build/pkg-1.2` and out of `/home/someone/pkg-1.2`. Three lists rather than one
4325    /// because gcc has three, and `-ffile-prefix-map=` is the three of them at once.
4326    #[test]
4327    fn a_prefix_mapping_flag_goes_on_the_list_its_spelling_names() {
4328        let (opts, _) = compile(&["-c", "a.c"]);
4329        assert!(opts.prefix_map.macros.is_empty(), "nothing is rewritten unless it is asked for");
4330        assert!(opts.prefix_map.debug.is_empty(), "nor here");
4331        assert!(opts.prefix_map.profile.is_empty(), "nor here");
4332
4333        let (opts, _) = compile(&["-c", "-fmacro-prefix-map=/build=.", "a.c"]);
4334        assert_eq!(opts.prefix_map.macros.apply("/build/a.c"), "./a.c", "the one it names");
4335        assert!(opts.prefix_map.debug.is_empty(), "and not the two it does not");
4336
4337        let (opts, _) = compile(&["-c", "-fdebug-prefix-map=/build=.", "a.c"]);
4338        assert_eq!(opts.prefix_map.debug.apply("/build/a.c"), "./a.c", "the one it names");
4339        assert!(opts.prefix_map.macros.is_empty(), "and not the two it does not");
4340
4341        let (opts, _) = compile(&["-c", "-fprofile-prefix-map=/build=.", "a.c"]);
4342        assert_eq!(opts.prefix_map.profile.apply("/build/a.c"), "./a.c", "the one it names");
4343        assert!(opts.prefix_map.macros.is_empty(), "and not the two it does not");
4344
4345        let (opts, _) = compile(&["-c", "-ffile-prefix-map=/build=.", "a.c"]);
4346        for list in [&opts.prefix_map.macros, &opts.prefix_map.debug, &opts.prefix_map.profile] {
4347            assert_eq!(list.apply("/build/a.c"), "./a.c", "all three at once");
4348        }
4349
4350        // Every mention is kept and the last one that matches wins, unlike the flags above whose
4351        // last mention replaces the earlier ones. A build writes one of these per source root and
4352        // expects all of them to be in force, which is the whole point of a list.
4353        let (opts, _) =
4354            compile(&["-c", "-ffile-prefix-map=/a=one", "-ffile-prefix-map=/b=two", "a.c"]);
4355        assert_eq!(opts.prefix_map.macros.apply("/a/x.c"), "one/x.c", "the earlier one still acts");
4356        assert_eq!(opts.prefix_map.macros.apply("/b/x.c"), "two/x.c", "and so does the later one");
4357
4358        // An argument with no `=` is refused rather than ignored, because a build whose paths were
4359        // meant to be rewritten and were not is one that ships the build directory's name and says
4360        // nothing about it. gcc refuses the same thing.
4361        for bad in ["-fmacro-prefix-map=nope", "-ffile-prefix-map=", "-fdebug-prefix-map=/build"] {
4362            let failed = parse_args(&args(&[bad, "a.c"])).expect_err("refused");
4363            assert!(failed.to_string().contains("is not a rewrite for"), "{bad}: {failed}");
4364        }
4365    }
4366
4367    /// `-ffunction-sections` and `-fdata-sections`, which are what make `--gc-sections` able to
4368    /// drop anything: a linker can leave out a section nothing reaches and cannot leave out half of
4369    /// one. A kernel and an embedded image are both linked that way.
4370    ///
4371    /// Two flags rather than one because gcc has two, and a build that asks for one of them and not
4372    /// the other is a build that measured something: splitting the code is nearly free at link time
4373    /// and splitting the data can defeat the linker's ordering of what is next to what.
4374    #[test]
4375    fn a_section_per_function_and_a_section_per_variable_are_asked_for_one_at_a_time() {
4376        let (opts, _) = compile(&["-c", "a.c"]);
4377        assert!(!opts.function_sections, "one text section unless something says otherwise");
4378        assert!(!opts.data_sections);
4379
4380        let (opts, _) = compile(&["-c", "-ffunction-sections", "a.c"]);
4381        assert!(opts.function_sections);
4382        assert!(!opts.data_sections, "one flag is not the other");
4383
4384        let (opts, _) = compile(&["-c", "-fdata-sections", "a.c"]);
4385        assert!(opts.data_sections);
4386        assert!(!opts.function_sections);
4387
4388        // Both directions taken, and the off one is what happens anyway rather than a refusal,
4389        // since a build that writes it is asking for the default.
4390        let (opts, _) = compile(&[
4391            "-c",
4392            "-ffunction-sections",
4393            "-fno-function-sections",
4394            "-fdata-sections",
4395            "-fno-data-sections",
4396            "a.c",
4397        ]);
4398        assert!(!opts.function_sections, "the last mention decides");
4399        assert!(!opts.data_sections, "the last mention decides");
4400    }
4401
4402    /// `-fgnu89-inline`, which is off by default and is not implied by anything on the command
4403    /// line, since the dialect asks for GNU's reading further in rather than through this.
4404    #[test]
4405    fn gnu89_inline_is_off_until_it_is_asked_for_and_the_last_mention_decides() {
4406        let (opts, _) = compile(&["-c", "a.c"]);
4407        assert!(!opts.gnu89_inline, "C's reading of inline by default");
4408
4409        let (opts, _) = compile(&["-c", "-fgnu89-inline", "a.c"]);
4410        assert!(opts.gnu89_inline);
4411
4412        let (opts, _) = compile(&["-c", "-fgnu89-inline", "-fno-gnu89-inline", "a.c"]);
4413        assert!(!opts.gnu89_inline, "the last mention decides");
4414
4415        // The C89 dialects are under GNU's reading whether this was written or not, so the flag
4416        // stays off there and the dialect is what the checker and the macro set both ask. That is
4417        // also why `-std=c89 -fno-gnu89-inline` needs no diagnostic: it asks for the reading the
4418        // dialect already has. gcc refuses that command line, which is measured in the issue.
4419        let (opts, _) = compile(&["-c", "-std=c89", "a.c"]);
4420        assert!(!opts.gnu89_inline);
4421    }
4422
4423    /// Both spellings of both frame flags, since a build that wants one usually writes the
4424    /// other beside it for the one file that has to be compiled the ordinary way.
4425    #[test]
4426    fn the_two_frame_flags_are_read_in_both_directions() {
4427        let (opts, _) = compile(&["-c", "a.c"]);
4428        assert!(!opts.frame_pointer, "gcc omits it above -O0 and so does this");
4429        assert!(opts.red_zone, "the psABI has one and nothing said not to use it");
4430
4431        let (opts, _) = compile(&["-c", "-fno-omit-frame-pointer", "-mno-red-zone", "a.c"]);
4432        assert!(opts.frame_pointer);
4433        assert!(!opts.red_zone);
4434
4435        let (opts, _) = compile(&[
4436            "-c",
4437            "-fno-omit-frame-pointer",
4438            "-fomit-frame-pointer",
4439            "-mno-red-zone",
4440            "-mred-zone",
4441            "a.c",
4442        ]);
4443        assert!(!opts.frame_pointer, "the last one wins, as it does in gcc");
4444        assert!(opts.red_zone);
4445    }
4446
4447    /// Four flags rather than one with an argument, which is how gcc spells them, and the negative
4448    /// spelled three ways because a build that turns one off writes whichever it turned on.
4449    #[test]
4450    fn the_stack_protector_is_four_flags_and_the_last_one_wins() {
4451        let (opts, _) = compile(&["-c", "a.c"]);
4452        assert_eq!(opts.protector, Protector::None, "gcc protects nothing unless it was asked");
4453
4454        for (flag, want) in [
4455            ("-fstack-protector", Protector::Buffers),
4456            ("-fstack-protector-strong", Protector::Strong),
4457            ("-fstack-protector-all", Protector::All),
4458        ] {
4459            let (opts, _) = compile(&["-c", flag, "a.c"]);
4460            assert_eq!(opts.protector, want, "{flag}");
4461        }
4462
4463        // What a package build does: the strong one in the global flags and one directory that
4464        // cannot have a protector turning it off on the line after.
4465        for off in ["-fno-stack-protector", "-fno-stack-protector-strong"] {
4466            let (opts, _) = compile(&["-c", "-fstack-protector-strong", off, "a.c"]);
4467            assert_eq!(opts.protector, Protector::None, "{off}");
4468        }
4469        let (opts, _) = compile(&["-c", "-fno-stack-protector", "-fstack-protector-all", "a.c"]);
4470        assert_eq!(opts.protector, Protector::All, "the last one wins either way round");
4471    }
4472
4473    /// A switch rather than a level, because how a frame is taken is one question and which
4474    /// functions get a canary is another, and gcc spells it that way for the same reason.
4475    #[test]
4476    fn taking_a_frame_a_page_at_a_time_is_off_until_it_is_asked_for() {
4477        let (opts, _) = compile(&["-c", "a.c"]);
4478        assert!(!opts.stack_clash, "gcc takes a frame in one subtraction unless it was asked");
4479
4480        let (opts, _) = compile(&["-c", "-fstack-clash-protection", "a.c"]);
4481        assert!(opts.stack_clash);
4482
4483        // The same shape a package build uses for the protector: on in the global flags and off
4484        // for the one directory that cannot have it.
4485        let (opts, _) =
4486            compile(&["-c", "-fstack-clash-protection", "-fno-stack-clash-protection", "a.c"]);
4487        assert!(!opts.stack_clash);
4488        let (opts, _) =
4489            compile(&["-c", "-fno-stack-clash-protection", "-fstack-clash-protection", "a.c"]);
4490        assert!(opts.stack_clash, "the last one wins either way round");
4491
4492        // The two are independent, since one is about the frame and the other about the function.
4493        let (opts, _) =
4494            compile(&["-c", "-fstack-clash-protection", "-fstack-protector-strong", "a.c"]);
4495        assert!(opts.stack_clash);
4496        assert_eq!(opts.protector, Protector::Strong);
4497    }
4498
4499    /// One flag with an argument rather than a family of spellings, because what it asks about is
4500    /// which of the two edges of a control flow transfer is checked and the two are not separate
4501    /// questions to the hardware.
4502    #[test]
4503    fn which_control_flow_edges_are_checked_is_asked_for_by_name() {
4504        let (opts, _) = compile(&["-c", "a.c"]);
4505        assert_eq!(opts.control, Control::None, "gcc's default on the targets this compiler has");
4506
4507        for (arg, want) in [
4508            ("-fcf-protection", Control::Full),
4509            ("-fcf-protection=full", Control::Full),
4510            ("-fcf-protection=branch", Control::Branch),
4511            ("-fcf-protection=return", Control::Return),
4512            ("-fcf-protection=none", Control::None),
4513            ("-fcf-protection=check", Control::Check),
4514        ] {
4515            let (opts, _) = compile(&["-c", arg, "a.c"]);
4516            assert_eq!(opts.control, want, "{arg}");
4517        }
4518
4519        // The shape a package build uses: on in the global flags and off for the one directory
4520        // that cannot have it, whichever of the two spellings of off it reaches for.
4521        let (opts, _) = compile(&["-c", "-fcf-protection=full", "-fno-cf-protection", "a.c"]);
4522        assert_eq!(opts.control, Control::None);
4523        let (opts, _) = compile(&["-c", "-fno-cf-protection", "-fcf-protection=branch", "a.c"]);
4524        assert_eq!(opts.control, Control::Branch, "the last one wins either way round");
4525    }
4526
4527    /// The profiler is asked for by two spellings, and where its hook goes by two more.
4528    ///
4529    /// The two halves are separate on purpose. `-mfentry` on its own says where a call would go and
4530    /// asks for no call, which is what gcc does with it, and a build system that sets it globally
4531    /// and asks for the profile per directory needs that to be true rather than an error.
4532    ///
4533    /// The link is asserted alongside, because the flag changes it too and a build that compiled
4534    /// with it and linked without it is a program that calls the hook everywhere and never writes a
4535    /// profile.
4536    #[test]
4537    fn the_profiler_and_where_its_hook_goes_are_two_separate_questions() {
4538        let (opts, _) = compile(&["-c", "a.c"]);
4539        assert!(!opts.profile);
4540        assert_eq!(opts.hook, Hook::Platform, "neither was named, so the target decides");
4541
4542        for arg in ["-pg", "-p"] {
4543            let (opts, _) = compile(&["-c", arg, "a.c"]);
4544            assert!(opts.profile, "{arg}");
4545            let (link, _) = linking(&[arg, "a.c"]);
4546            assert!(link.profile, "{arg} changes the link as well");
4547        }
4548
4549        for (arg, want) in [("-mfentry", Hook::Early), ("-mno-fentry", Hook::Late)] {
4550            let (opts, _) = compile(&["-c", arg, "a.c"]);
4551            assert_eq!(opts.hook, want, "{arg}");
4552            assert!(!opts.profile, "{arg} asks for no call of its own");
4553        }
4554
4555        let (opts, _) = compile(&["-c", "-mfentry", "-mno-fentry", "-pg", "a.c"]);
4556        assert_eq!(opts.hook, Hook::Late, "the last one wins");
4557        assert!(opts.profile);
4558    }
4559
4560    /// How much room a patcher is promised, which is one number or two.
4561    ///
4562    /// A command line that did not ask is asserted alongside, because the flag has to be written to
4563    /// mean anything and a build that reserved room nobody asked for would grow every function in
4564    /// it for nothing.
4565    #[test]
4566    fn the_room_a_patcher_is_promised_is_a_number_of_bytes_and_where_they_go() {
4567        let (opts, _) = compile(&["-c", "a.c"]);
4568        assert_eq!(opts.patchable, Patchable::default());
4569        assert!(!opts.patchable.any(), "nothing is reserved unless it was asked for");
4570
4571        let (opts, _) = compile(&["-c", "-fpatchable-function-entry=16", "a.c"]);
4572        assert_eq!(opts.patchable, Patchable { total: 16, before: 0 });
4573
4574        let (opts, _) = compile(&["-c", "-fpatchable-function-entry=5,3", "a.c"]);
4575        assert_eq!(opts.patchable, Patchable { total: 5, before: 3 });
4576        assert_eq!(opts.patchable.after(), 2);
4577
4578        // The last one wins, which is what every other flag of this shape does and what a build
4579        // that adds one to a command line it did not write is relying on.
4580        let (opts, _) = compile(&[
4581            "-c",
4582            "-fpatchable-function-entry=5,3",
4583            "-fpatchable-function-entry=2",
4584            "a.c",
4585        ]);
4586        assert_eq!(opts.patchable, Patchable { total: 2, before: 0 });
4587    }
4588
4589    /// And a request nothing could satisfy is refused rather than rounded into one that can be.
4590    #[test]
4591    fn room_in_front_of_the_label_that_is_more_than_the_room_asked_for_is_refused() {
4592        for arg in ["-fpatchable-function-entry=1,2", "-fpatchable-function-entry=x"] {
4593            let e = parse_args(&args(&["-c", arg, "a.c"])).unwrap_err();
4594            assert!(e.message.contains("is not an amount of room to reserve"), "{}", e.message);
4595        }
4596    }
4597
4598    /// What wraps rather than being undefined, which is two questions and three flags.
4599    ///
4600    /// The older flag is the pair of the newer two, which is gcc's own reading of it, so a build
4601    /// that writes `-fno-strict-overflow` gets both and a build that writes one of the others gets
4602    /// only what it asked for.
4603    #[test]
4604    fn what_overflows_rather_than_being_undefined_is_asked_for_two_ways() {
4605        let (opts, _) = compile(&["-c", "a.c"]);
4606        assert_eq!(opts.wrapping, Wrapping::NONE, "nothing wraps unless it was asked for");
4607
4608        let (opts, _) = compile(&["-c", "-fwrapv", "a.c"]);
4609        assert_eq!(opts.wrapping, Wrapping { signed: true, pointer: false, trap: false });
4610
4611        let (opts, _) = compile(&["-c", "-fwrapv-pointer", "a.c"]);
4612        assert_eq!(opts.wrapping, Wrapping { signed: false, pointer: true, trap: false });
4613
4614        let (opts, _) = compile(&["-c", "-fno-strict-overflow", "a.c"]);
4615        assert_eq!(opts.wrapping, Wrapping::ALL);
4616
4617        // And the last one wins, in both directions. A build that turns one of these on globally
4618        // and off for one directory is relying on that, and so is one that writes the pair and
4619        // then takes half of it back.
4620        let (opts, _) = compile(&["-c", "-fwrapv", "-fno-wrapv", "a.c"]);
4621        assert_eq!(opts.wrapping, Wrapping::NONE);
4622
4623        let (opts, _) = compile(&["-c", "-fno-strict-overflow", "-fstrict-overflow", "a.c"]);
4624        assert_eq!(opts.wrapping, Wrapping::NONE);
4625
4626        let (opts, _) = compile(&["-c", "-fno-strict-overflow", "-fno-wrapv-pointer", "a.c"]);
4627        assert_eq!(opts.wrapping, Wrapping { signed: true, pointer: false, trap: false });
4628    }
4629
4630    /// And the other answer to the signed question cannot be held at the same time as the first.
4631    ///
4632    /// A program cannot both wrap and stop, so writing both is writing a contradiction, and gcc
4633    /// resolves it by letting the last one win rather than by reporting anything. That was measured
4634    /// against gcc 16 rather than read out of the manual, which says nothing about it: `-ftrapv
4635    /// -fwrapv` emits no checked calls and `-fwrapv -ftrapv` emits them.
4636    #[test]
4637    fn a_signed_overflow_that_stops_is_the_other_answer_and_not_a_third_one() {
4638        let (opts, _) = compile(&["-c", "-ftrapv", "a.c"]);
4639        assert_eq!(opts.wrapping, Wrapping { signed: false, pointer: false, trap: true });
4640
4641        let (opts, _) = compile(&["-c", "-fwrapv", "-ftrapv", "a.c"]);
4642        assert_eq!(opts.wrapping, Wrapping { signed: false, pointer: false, trap: true });
4643
4644        let (opts, _) = compile(&["-c", "-ftrapv", "-fwrapv", "a.c"]);
4645        assert_eq!(opts.wrapping, Wrapping { signed: true, pointer: false, trap: false });
4646
4647        let (opts, _) = compile(&["-c", "-ftrapv", "-fno-strict-overflow", "a.c"]);
4648        assert_eq!(opts.wrapping, Wrapping::ALL);
4649
4650        let (opts, _) = compile(&["-c", "-ftrapv", "-fno-trapv", "a.c"]);
4651        assert_eq!(opts.wrapping, Wrapping::NONE);
4652
4653        // And the flag that says what may be assumed says nothing about what happens, so it leaves
4654        // this alone where it takes the wrapping away. gcc does the same.
4655        let (opts, _) = compile(&["-c", "-ftrapv", "-fstrict-overflow", "a.c"]);
4656        assert_eq!(opts.wrapping, Wrapping { signed: false, pointer: false, trap: true });
4657    }
4658
4659    /// What a plain `char` is, which is four spellings of two answers and nothing by default.
4660    ///
4661    /// Nothing is the target's own answer and has to stay distinct from both of the others, since
4662    /// the same command line means a signed `char` on x86-64 and an unsigned one on Linux's arm64.
4663    /// The negative spellings are the other flag rather than a way of asking for the default, which
4664    /// was measured against gcc 16: `-fno-signed-char` defines `__CHAR_UNSIGNED__` and
4665    /// `-fno-unsigned-char` does not.
4666    #[test]
4667    fn the_signedness_of_a_plain_char_is_asked_for_in_four_ways() {
4668        let (opts, _) = compile(&["-c", "a.c"]);
4669        assert_eq!(opts.char_signed, None);
4670
4671        for flag in ["-fsigned-char", "-fno-unsigned-char"] {
4672            let (opts, _) = compile(&["-c", flag, "a.c"]);
4673            assert_eq!(opts.char_signed, Some(true), "{flag}");
4674        }
4675
4676        for flag in ["-funsigned-char", "-fno-signed-char"] {
4677            let (opts, _) = compile(&["-c", flag, "a.c"]);
4678            assert_eq!(opts.char_signed, Some(false), "{flag}");
4679        }
4680
4681        // And the last one wins, which is what a build that sets one globally and the other for a
4682        // directory relies on.
4683        let (opts, _) = compile(&["-c", "-funsigned-char", "-fsigned-char", "a.c"]);
4684        assert_eq!(opts.char_signed, Some(true));
4685
4686        // And what is asked for reaches the target, because that is what every other part of the
4687        // compiler asks. The triple is one whose own answer is the opposite, so a session that
4688        // ignored the flag would still read as signed here.
4689        let (opts, _) =
4690            compile(&["-c", "--target=aarch64-unknown-linux-gnu", "-fsigned-char", "a.c"]);
4691        assert!(Session::new(*opts).target.char_is_signed);
4692        let (opts, _) = compile(&["-c", "--target=aarch64-unknown-linux-gnu", "a.c"]);
4693        assert!(!Session::new(*opts).target.char_is_signed);
4694    }
4695
4696    /// And the size of an enumeration, which is one question with two spellings.
4697    #[test]
4698    fn the_smallest_enumeration_is_asked_for_and_taken_back() {
4699        let (opts, _) = compile(&["-c", "a.c"]);
4700        assert!(!opts.short_enums);
4701
4702        let (opts, _) = compile(&["-c", "-fshort-enums", "a.c"]);
4703        assert!(opts.short_enums);
4704
4705        let (opts, _) = compile(&["-c", "-fshort-enums", "-fno-short-enums", "a.c"]);
4706        assert!(!opts.short_enums);
4707
4708        let (opts, _) = compile(&["-c", "-fno-short-enums", "-fshort-enums", "a.c"]);
4709        assert!(opts.short_enums);
4710    }
4711
4712    /// And a value nothing means is refused rather than taken for the nearest thing it looks like.
4713    ///
4714    /// `-fcf-protection=all` is the spelling somebody writes from memory, and a compiler that read
4715    /// it as `full` would be guessing, while one that let it fall through to the optimizer's `-f`
4716    /// family would report it as an unknown pass. Neither is the news the build wants.
4717    #[test]
4718    fn a_control_flow_protection_nothing_means_is_refused() {
4719        let e = parse_args(&args(&["-c", "-fcf-protection=all", "a.c"])).unwrap_err();
4720        assert!(e.message.contains("is not a control flow protection"), "{}", e.message);
4721        assert!(e.message.contains("full, branch, return, none or check"), "{}", e.message);
4722    }
4723
4724    #[test]
4725    fn the_link_flags_are_collected_apart_from_the_compilation() {
4726        let (link, _) = linking(&[
4727            "-static",
4728            "-nostartfiles",
4729            "-rdynamic",
4730            "-s",
4731            "-fuse-ld=mold",
4732            "-L/opt/lib",
4733            "-B",
4734            "/opt/tools",
4735            "a.c",
4736        ]);
4737        assert!(link.is_static);
4738        assert!(link.no_startfiles);
4739        assert!(link.export_dynamic);
4740        assert!(link.strip);
4741        assert_eq!(link.use_ld.as_deref(), Some("mold"));
4742        assert_eq!(link.search, vec![PathBuf::from("/opt/lib")]);
4743        assert_eq!(link.prefixes, vec![PathBuf::from("/opt/tools")]);
4744    }
4745
4746    #[test]
4747    fn a_comma_in_dash_wl_separates_two_arguments() {
4748        let (_, plan) = linking(&["-Wl,-rpath,/opt/lib", "-Xlinker", "--as-needed", "a.c"]);
4749        let link = plan.link.expect("expected a link step");
4750        assert_eq!(
4751            link.inputs,
4752            vec![
4753                link::Item::Linker("-rpath".into()),
4754                link::Item::Linker("/opt/lib".into()),
4755                link::Item::Linker("--as-needed".into()),
4756                link::Item::File("a.o".into()),
4757            ]
4758        );
4759    }
4760
4761    #[test]
4762    fn a_word_for_the_linker_keeps_its_place_among_the_files_too() {
4763        // What libtool writes around a set of convenience archives, and what #1279 was. Both words
4764        // are about the files between them, so the pair collected out of the line and appended to
4765        // the end is two options that bracket nothing and an archive that went in empty.
4766        let (_, plan) = linking(&[
4767            "--target=x86_64-unknown-linux-gnu",
4768            "a.c",
4769            "-Wl,--whole-archive",
4770            "libaesni.a",
4771            "-Wl,--no-whole-archive",
4772            "-lm",
4773        ]);
4774        let link = plan.link.expect("expected a link step");
4775        assert_eq!(
4776            link.inputs,
4777            vec![
4778                link::Item::File("a.o".into()),
4779                link::Item::Linker("--whole-archive".into()),
4780                link::Item::File("libaesni.a".into()),
4781                link::Item::Linker("--no-whole-archive".into()),
4782                link::Item::Library("m".into()),
4783            ]
4784        );
4785        // And it is not a job, because there is nothing to compile in a word for the linker.
4786        assert_eq!(plan.jobs.len(), 2);
4787    }
4788
4789    #[test]
4790    fn a_word_for_the_linker_on_a_dash_c_line_is_dropped_without_a_word() {
4791        // GCC says nothing about one either. `-Wl,` on a compile line is what a build system
4792        // writes when one variable holds the flags for both, and a note here would be a note on
4793        // every compile of every autotools project.
4794        let (_, plan) = linking(&["-c", "-Wl,--as-needed", "a.c"]);
4795        assert!(plan.link.is_none());
4796        assert!(plan.notes.is_empty(), "{:?}", plan.notes);
4797        assert_eq!(plan.jobs.len(), 1);
4798    }
4799
4800    #[test]
4801    fn a_library_keeps_its_place_between_the_objects() {
4802        // Link order is semantic: `-lm` written between two files resolves for the one before
4803        // it and not for the one after, so a library cannot be collected into a list of its own.
4804        // The target is named because the suffix of an object is the target's and this asserts
4805        // on the names: the same command line on a Windows host plans two `.obj` files.
4806        let (_, plan) = linking(&["--target=x86_64-unknown-linux-gnu", "a.c", "-lm", "b.c"]);
4807        let link = plan.link.expect("expected a link step");
4808        assert_eq!(
4809            link.inputs,
4810            vec![
4811                link::Item::File("a.o".into()),
4812                link::Item::Library("m".into()),
4813                link::Item::File("b.o".into()),
4814            ]
4815        );
4816        // And it is not a job, because there is nothing to compile in a library.
4817        assert_eq!(plan.jobs.len(), 2);
4818    }
4819
4820    #[test]
4821    fn a_library_on_a_dash_c_line_is_a_note_rather_than_an_error() {
4822        let (_, plan) = linking(&["-c", "-lm", "a.c"]);
4823        assert!(plan.link.is_none());
4824        assert!(plan.notes.iter().any(|n| n.contains("-lm")), "{:?}", plan.notes);
4825    }
4826
4827    #[test]
4828    fn the_sysroot_reaches_the_linker_as_well_as_the_headers() {
4829        let (link, _) = linking(&["--sysroot=/opt/root", "a.c"]);
4830        assert_eq!(link.sysroot, Some(PathBuf::from("/opt/root")));
4831    }
4832
4833    fn printed(s: &[&str]) -> String {
4834        match parse_args(&args(s)).expect("expected an answer") {
4835            Action::Print(line) => line,
4836            other => panic!("expected an answer, got {other:?}"),
4837        }
4838    }
4839
4840    fn refused(s: &[&str]) -> String {
4841        parse_args(&args(s)).expect_err("expected a refusal").message
4842    }
4843
4844    #[test]
4845    fn a_warning_flag_this_compiler_has_not_heard_of_is_taken_rather_than_refused() {
4846        // The rule in section 4.1, and the reason for it is autoconf: a configure script finds
4847        // out whether a warning flag exists by passing it and looking at the exit status, so a
4848        // compiler that refuses one it does not know fails a script written for a newer GCC.
4849        let (opts, _) = compile(&["-Wall", "-Wextra", "-Wno-format-truncation", "-c", "a.c"]);
4850        assert!(!opts.warnings_are_errors);
4851        assert!(opts.warnings);
4852        // The two spellings that do mean something are still read.
4853        let (opts, _) = compile(&["-Werror", "-c", "a.c"]);
4854        assert!(opts.warnings_are_errors);
4855        let (opts, _) = compile(&["-w", "-c", "a.c"]);
4856        assert!(!opts.warnings);
4857        let (opts, _) = compile(&["-pedantic-errors", "-c", "a.c"]);
4858        assert!(opts.pedantic && opts.warnings_are_errors);
4859    }
4860
4861    #[test]
4862    fn an_argument_for_a_separate_tool_is_refused_rather_than_dropped() {
4863        // Every one of these says something about the output, so the wrong answer is silence.
4864        assert!(refused(&["-Wa,--noexecstack", "-c", "a.c"]).contains("separate assembler"));
4865        assert!(refused(&["-Wp,-DX", "-c", "a.c"]).contains("separate assembler"));
4866        assert!(refused(&["-specs=/x", "a.c"]).contains("-specs= is not supported"));
4867        assert!(refused(&["-mcmodel=kernel", "-c", "a.c"]).contains("small code model"));
4868        assert!(refused(&["-gdwarf-4", "-c", "a.c"]).contains("DWARF 5"));
4869        assert!(refused(&["-Ofast", "-c", "a.c"]).contains("fast math"));
4870        // The word size the target does not have, which is a target this compiler was not asked
4871        // for rather than a flag it does not know.
4872        let no32 = refused(&["--target=x86_64-unknown-linux-gnu", "-m32", "-c", "a.c"]);
4873        assert!(no32.contains("32 bit target"), "{no32}");
4874    }
4875
4876    /// `-gz` and the two spellings of the split, which are the two questions about the shape of
4877    /// the debug output rather than about how much of it there is.
4878    ///
4879    /// Both answers here are about what happens when there is debug information to shape, and
4880    /// there is none yet, so what is being asserted is that the flags are read and remembered
4881    /// rather than that anything changed in the output. That is the whole of what taking them
4882    /// claims, and it is worth a test because the day `rucc-debug` writes a section this is where
4883    /// it comes to find out what the command line said.
4884    #[test]
4885    fn the_shape_of_the_debug_output_is_recorded_even_where_there_is_none_of_it() {
4886        let (opts, _) = compile(&["-c", "a.c"]);
4887        assert_eq!(opts.compress, Compress::None, "uncompressed unless somebody asks");
4888
4889        // Bare `-gz` is `-gz=zlib`, measured against gcc 16 rather than read out of the manual,
4890        // which describes the flag without ever saying which algorithm it picks.
4891        assert_eq!(compile(&["-gz", "-c", "a.c"]).0.compress, Compress::Zlib);
4892        for (spelling, want) in [
4893            ("none", Compress::None),
4894            ("zlib", Compress::Zlib),
4895            ("zlib-gnu", Compress::ZlibGnu),
4896            ("zstd", Compress::Zstd),
4897        ] {
4898            let (opts, _) = compile(&[&format!("-gz={spelling}"), "-c", "a.c"]);
4899            assert_eq!(opts.compress, want, "{spelling}");
4900        }
4901
4902        // A value nothing here has heard of is refused rather than rounded to the nearest one,
4903        // because a build that asked for `zstd` and quietly got `zlib` would ship a file its
4904        // reader may not understand and would have no way of finding out.
4905        for bad in ["-gz=gzip", "-gz="] {
4906            let failed = refused(&[bad, "-c", "a.c"]);
4907            assert!(failed.contains("is not a way to compress"), "{bad}: {failed}");
4908        }
4909
4910        // The split is refused in the direction that would have written a file and taken in the
4911        // direction that describes what happens. A build system that names the `.dwo` as an
4912        // output has to hear about it now rather than at the point the file is missing.
4913        let (opts, _) = compile(&["-gno-split-dwarf", "-g", "-c", "a.c"]);
4914        assert!(opts.debug_info, "the negative spelling says nothing about how much");
4915        let failed = refused(&["-gsplit-dwarf", "-c", "a.c"]);
4916        assert!(failed.contains(".dwo"), "the refusal names the file it would have written");
4917    }
4918
4919    /// The `-flto` family, which is the whole of an optimization this compiler does not do.
4920    ///
4921    /// Taken rather than refused because ignoring it gives a correct program that is slower than
4922    /// it could have been, which is section 4.1's hint about speed. The values are still held to
4923    /// gcc's, so a command line written for clang is told rather than quietly taken.
4924    #[test]
4925    fn the_link_time_family_is_read_and_checked_and_nothing_is_done_about_it() {
4926        let (opts, _) = compile(&["-c", "a.c"]);
4927        assert!(!opts.lto.requested, "nothing asks unless the command line does");
4928
4929        let (opts, _) = compile(&["-flto", "-c", "a.c"]);
4930        assert!(opts.lto.requested);
4931        assert_eq!(opts.lto.jobs, LtoJobs::One, "bare -flto is one process, the way gcc reads it");
4932
4933        // The last of the two directions wins, the same as every other pair of `-f` spellings.
4934        assert!(!compile(&["-flto", "-fno-lto", "-c", "a.c"]).0.lto.requested);
4935        assert!(compile(&["-fno-lto", "-flto", "-c", "a.c"]).0.lto.requested);
4936
4937        // A count is a count, and asking for one implies asking for the optimization.
4938        for (spelling, want) in [
4939            ("auto", LtoJobs::Auto),
4940            ("jobserver", LtoJobs::Jobserver),
4941            ("1", LtoJobs::One),
4942            ("8", LtoJobs::Count(8)),
4943        ] {
4944            let (opts, _) = compile(&[&format!("-flto={spelling}"), "-c", "a.c"]);
4945            assert_eq!(opts.lto.jobs, want, "{spelling}");
4946            assert!(opts.lto.requested, "{spelling} asks for it too");
4947        }
4948
4949        // gcc refuses a zero rather than reading it as `-fno-lto`, and `thin` is clang's spelling
4950        // of a question gcc answers with `-flto-partition=`, so somebody who wrote it meant a
4951        // different compiler and gets told so here rather than getting a serial link.
4952        for bad in ["-flto=0", "-flto=thin", "-flto=full", "-flto=-1"] {
4953            let failed = refused(&[bad, "-c", "a.c"]);
4954            assert!(failed.contains("link time jobs"), "{bad}: {failed}");
4955        }
4956
4957        // How the program is cut up before the work is spread over it.
4958        assert_eq!(compile(&["-c", "a.c"]).0.lto.partition, Partition::Balanced, "gcc's default");
4959        for (spelling, want) in [
4960            ("balanced", Partition::Balanced),
4961            ("1to1", Partition::OneToOne),
4962            ("one", Partition::One),
4963            ("max", Partition::Max),
4964            ("none", Partition::None),
4965        ] {
4966            let (opts, _) = compile(&[&format!("-flto-partition={spelling}"), "-c", "a.c"]);
4967            assert_eq!(opts.lto.partition, want, "{spelling}");
4968        }
4969        assert!(refused(&["-flto-partition=big", "-c", "a.c"]).contains("partitioning model"));
4970
4971        // And how hard the bytecode is compressed on its way into the object, which is zstd's
4972        // range of levels and is the range gcc checks an argument against.
4973        assert_eq!(compile(&["-c", "a.c"]).0.lto.compression, None, "whatever it does by default");
4974        assert_eq!(compile(&["-flto-compression-level=0", "-c", "a.c"]).0.lto.compression, Some(0));
4975        let (opts, _) = compile(&["-flto-compression-level=19", "-c", "a.c"]);
4976        assert_eq!(opts.lto.compression, Some(19));
4977        for bad in ["-flto-compression-level=20", "-flto-compression-level=-1"] {
4978            let failed = refused(&[bad, "-c", "a.c"]);
4979            assert!(failed.contains("compression level"), "{bad}: {failed}");
4980        }
4981
4982        // The two pairs that describe an arrangement rather than ask for one. Every object here
4983        // holds its machine code, so the fat spelling is what already happens and the other is a
4984        // smaller file rather than a different program, and the plugin pair is about a tool the
4985        // design in `spec/09-optimizer.md` never loads.
4986        for taken in [
4987            "-ffat-lto-objects",
4988            "-fno-fat-lto-objects",
4989            "-fuse-linker-plugin",
4990            "-fno-use-linker-plugin",
4991        ] {
4992            let (opts, _) = compile(&[taken, "-c", "a.c"]);
4993            assert!(!opts.lto.requested, "{taken} says nothing about whether to do it");
4994        }
4995    }
4996
4997    /// The profile family, which is the only one here that splits down the middle.
4998    ///
4999    /// Reading a profile is taken and writing one is refused, and the line between them is the one
5000    /// section 4.1 draws: ignoring a request to read the counts gives a correct program that is
5001    /// slower than it could have been, and ignoring a request to write them means a file the build
5002    /// declared as an output never appears.
5003    #[test]
5004    fn reading_a_profile_is_taken_and_writing_one_is_refused() {
5005        let (opts, _) = compile(&["-c", "a.c"]);
5006        assert!(!opts.profile_data.requested, "nothing asks unless the command line does");
5007        assert_eq!(opts.profile_data.path, None);
5008
5009        let (opts, _) = compile(&["-fprofile-use", "-c", "a.c"]);
5010        assert!(opts.profile_data.requested);
5011        assert_eq!(opts.profile_data.path, None, "beside the object, the way gcc looks");
5012
5013        let (opts, _) = compile(&["-fprofile-use=/counts", "-c", "a.c"]);
5014        assert!(opts.profile_data.requested, "naming a path asks for it too");
5015        assert_eq!(opts.profile_data.path.as_deref(), Some("/counts"));
5016
5017        // The last of the two directions wins, the same as every other pair of `-f` spellings.
5018        assert!(
5019            !compile(&["-fprofile-use", "-fno-profile-use", "-c", "a.c"]).0.profile_data.requested
5020        );
5021        assert!(
5022            compile(&["-fno-profile-use", "-fprofile-use", "-c", "a.c"]).0.profile_data.requested
5023        );
5024
5025        // The rest of the reading half, which is where the files are and three answers about what
5026        // to make of what is in them.
5027        let (opts, _) = compile(&[
5028            "-fprofile-dir=/build/profiles",
5029            "-fprofile-abs-path",
5030            "-fprofile-correction",
5031            "-fprofile-partial-training",
5032            "-c",
5033            "a.c",
5034        ]);
5035        assert_eq!(opts.profile_data.dir.as_deref(), Some("/build/profiles"));
5036        assert!(opts.profile_data.absolute);
5037        assert!(opts.profile_data.correction);
5038        assert!(opts.profile_data.partial_training);
5039
5040        // Writing one, which is refused by name. The first four instrument the program and the
5041        // last writes a file beside the object, and a build that got neither and no message would
5042        // go on to optimize against counts that were never gathered.
5043        for writing in [
5044            "-fprofile-generate",
5045            "-fprofile-generate=/build/profiles",
5046            "-fprofile-arcs",
5047            "--coverage",
5048            "-fcondition-coverage",
5049            "-fpath-coverage",
5050        ] {
5051            let failed = refused(&[writing, "-c", "a.c"]);
5052            assert!(failed.contains("instrument"), "{writing}: {failed}");
5053        }
5054        assert!(refused(&["-ftest-coverage", "-c", "a.c"]).contains(".gcno"), "it names the file");
5055
5056        // The negative spellings of the refused half are what already happens, so they are taken.
5057        for taken in ["-fno-profile-generate", "-fno-profile-arcs", "-fno-test-coverage"] {
5058            let (opts, _) = compile(&[taken, "-c", "a.c"]);
5059            assert!(!opts.profile_data.requested, "{taken} asks for nothing");
5060        }
5061
5062        // And the flags that describe the instrumentation that is refused above, which are checked
5063        // and dropped. Checked because a typo is worth finding here rather than on the day the
5064        // instrumentation lands.
5065        for taken in [
5066            "-fprofile-update=single",
5067            "-fprofile-update=atomic",
5068            "-fprofile-update=prefer-atomic",
5069            "-fprofile-reproducible=serial",
5070            "-fprofile-reproducible=parallel-runs",
5071            "-fprofile-reproducible=multithreaded",
5072            "-fprofile-values",
5073            "-fno-profile-values",
5074            "-fprofile-info-section",
5075            "-fprofile-filter-files=a.c",
5076            "-fprofile-exclude-files=b.c",
5077            "-fprofile-note=a.gcno",
5078        ] {
5079            let (opts, _) = compile(&[taken, "-c", "a.c"]);
5080            assert!(!opts.profile_data.requested, "{taken} says nothing about reading one");
5081        }
5082        assert!(refused(&["-fprofile-update=none", "-c", "a.c"]).contains("update method"));
5083        assert!(refused(&["-fprofile-reproducible=any", "-c", "a.c"]).contains("reproducibility"));
5084    }
5085
5086    /// The sanitizers, which are refused by name and are the one family refused for a reason that
5087    /// is not about the bytes.
5088    ///
5089    /// A sanitizer is a promise that the program is watched while it runs, so a build that asked
5090    /// for one and was quietly given a program with no checks in it gets a test suite that passes
5091    /// for the wrong reason rather than a slower program.
5092    #[test]
5093    fn a_sanitizer_that_is_still_asked_for_at_the_end_of_the_line_is_refused_by_name() {
5094        for asked in ["address", "undefined", "thread", "kernel-address", "leak", "memory"] {
5095            let failed = refused(&[&format!("-fsanitize={asked}"), "-c", "a.c"]);
5096            assert!(failed.contains(asked), "the refusal names what was asked for: {failed}");
5097            assert!(failed.contains("-fsafety=detect"), "and the nearest thing: {failed}");
5098        }
5099
5100        // A list is every name in it, and the first one still standing is the one named.
5101        let failed = refused(&["-fsanitize=address,undefined", "-c", "a.c"]);
5102        assert!(failed.contains("address"), "{failed}");
5103
5104        // A name that is not one, which is worth its own message: somebody who wrote `-fsanitize`
5105        // with a typo in it has a different problem from somebody who wrote a real one.
5106        for bad in ["-fsanitize=bogus", "-fsanitize=address,bogus", "-fno-sanitize=bogus"] {
5107            let failed = refused(&[bad, "-c", "a.c"]);
5108            assert!(failed.contains("is not a sanitizer"), "{bad}: {failed}");
5109        }
5110
5111        // gcc takes `all` only in the negative, and so does this.
5112        assert!(refused(&["-fsanitize=all", "-c", "a.c"]).contains("only `-fno-sanitize=all`"));
5113
5114        // Asking and then taking it back is asking for nothing, which is why the answer waits for
5115        // the end of the line. A build whose shared flags turn a check on and whose rule for one
5116        // file turns it off again compiles that file here.
5117        for pair in [
5118            ["-fsanitize=address", "-fno-sanitize=address"],
5119            ["-fsanitize=address,undefined", "-fno-sanitize=all"],
5120            ["-fsanitize=undefined", "-fno-sanitize=undefined"],
5121        ] {
5122            let (opts, _) = compile(&[pair[0], pair[1], "-c", "a.c"]);
5123            assert_eq!(opts.safety, rucc_session::Safety::Off, "{pair:?} asked for nothing");
5124        }
5125        // And the other order still asks, because the last word is the one that counts.
5126        assert!(!refused(&["-fno-sanitize=address", "-fsanitize=address", "-c", "a.c"]).is_empty());
5127
5128        // What a check does when it fires is an answer about checks that are refused, so there is
5129        // nothing left for it to change and it is taken.
5130        for taken in [
5131            "-fsanitize-recover=undefined",
5132            "-fno-sanitize-recover=all",
5133            "-fsanitize-trap=undefined",
5134            "-fno-sanitize-trap=all",
5135            "-fsanitize-undefined-trap-on-error",
5136            "-fsanitize-address-use-after-scope",
5137            "-fno-sanitize-address-use-after-scope",
5138            "-fsanitize-sections=.data",
5139        ] {
5140            let (opts, _) = compile(&[taken, "-c", "a.c"]);
5141            assert_eq!(opts.safety, rucc_session::Safety::Off, "{taken} asks for no checking");
5142        }
5143        assert!(refused(&["-fsanitize-recover=bogus", "-c", "a.c"]).contains("is not a sanitizer"));
5144
5145        // Coverage instrumentation is refused rather than dropped, because a fuzzer with no
5146        // feedback runs blind and never says so.
5147        let failed = refused(&["-fsanitize-coverage=trace-pc", "-c", "a.c"]);
5148        assert!(failed.contains("feedback"), "{failed}");
5149        let failed = refused(&["-fsanitize-coverage=trace-pc-guard", "-c", "a.c"]);
5150        assert!(failed.contains("trace-pc or trace-cmp"), "gcc takes two of them: {failed}");
5151    }
5152
5153    #[test]
5154    fn the_levels_gcc_spells_differently_are_the_levels_they_mean() {
5155        assert_eq!(compile(&["-O", "-c", "a.c"]).0.opt_level, OptLevel::O1);
5156        assert_eq!(compile(&["-Og", "-c", "a.c"]).0.opt_level, OptLevel::O1);
5157        assert_eq!(compile(&["-O2", "-c", "a.c"]).0.opt_level, OptLevel::O2);
5158    }
5159
5160    #[test]
5161    fn the_machine_flags_that_name_what_we_already_do_are_taken_and_the_rest_are_not() {
5162        let line = ["--target=x86_64-unknown-linux-gnu", "-m64", "-march=x86-64-v3"];
5163        let (opts, _) =
5164            compile(&[&line[..], &["-mtune=native", "-mabi=sysv", "-c", "a.c"]].concat());
5165        assert_eq!(opts.target.to_string(), "x86_64-unknown-linux-gnu");
5166        let wrong = refused(&["--target=x86_64-unknown-linux-gnu", "-mabi=ms", "-c", "a.c"]);
5167        assert!(wrong.contains("sysv convention"), "{wrong}");
5168    }
5169
5170    #[test]
5171    fn the_thread_flag_is_a_macro_and_a_library_and_the_library_goes_last() {
5172        let (opts, plan) = compile(&["-pthread", "-c", "a.c"]);
5173        assert!(opts.defines.iter().any(|d| d == "_REENTRANT"));
5174        // After the input, because a static link takes what it needs from a library when it
5175        // reaches it and not afterwards.
5176        let names: Vec<&str> = plan.jobs.iter().map(|j| j.input.as_str()).collect();
5177        assert_eq!(names, vec!["a.c"]);
5178    }
5179
5180    #[test]
5181    fn the_questions_a_build_system_asks_before_it_compiles_anything() {
5182        let target = "--target=x86_64-unknown-linux-gnu";
5183        assert_eq!(printed(&[target, "-dumpmachine"]), "x86_64-unknown-linux-gnu");
5184        assert_eq!(printed(&[target, "-dumpversion"]), VERSION);
5185        assert_eq!(printed(&[target, "-dumpfullversion"]), VERSION);
5186        assert_eq!(printed(&[target, "-print-multiarch"]), "x86_64-linux-gnu");
5187        // A name nothing holds comes back unchanged, which is GCC's rule and is what makes the
5188        // answer safe to paste into a link line whether or not the file is there.
5189        assert_eq!(printed(&[target, "-print-file-name=no-such-library.a"]), "no-such-library.a");
5190        assert_eq!(printed(&[target, "-print-prog-name=ld"]), "ld");
5191        let dirs = printed(&[target, "-print-search-dirs"]);
5192        assert!(dirs.starts_with("install: "), "{dirs}");
5193        assert!(dirs.contains("\nlibraries: ="), "{dirs}");
5194    }
5195
5196    #[test]
5197    fn the_sysroot_in_effect_is_the_one_the_command_line_named_or_the_one_for_the_target() {
5198        // A tree the user named is the answer whatever the target is, because it is the answer to
5199        // every other question too.
5200        assert_eq!(printed(&["--sysroot=/opt/cross", "-print-sysroot"]), "/opt/cross");
5201
5202        // A target that is no machine this suite runs on is read under the cache, and the answer is
5203        // the root rather than one of the directories under it, since what asks is looking for a
5204        // file of its own.
5205        let root = cache::dir().join("sysroots").join("riscv64-linux-musl");
5206        assert_eq!(
5207            printed(&["--target=riscv64-linux-musl", "-print-sysroot"]),
5208            root.display().to_string()
5209        );
5210
5211        // And a compile for this machine has no sysroot, which is the empty line GCC prints when it
5212        // was configured without one rather than a `/` that would be a claim about the filesystem.
5213        let host = Triple::host().expect("a host this compiler knows");
5214        assert_eq!(printed(&[&format!("--target={host}"), "-print-sysroot"]), "");
5215    }
5216
5217    #[test]
5218    fn the_provenance_of_a_sysroot_is_the_manifest_it_carries() {
5219        // Section 13.5 wants seven things per input and wants them machine readable, and the manifest
5220        // is the record that already has them, so the flag prints that rather than a second format.
5221        let manifest = "rucc sysroot manifest 3\n\
5222                        target\tx86_64-linux-musl\n\
5223                        kernel\t6.12\n\
5224                        include/generic/stdio.h\tmusl-1.2.5\t\
5225                        https://musl.libc.org/releases/musl-1.2.5.tar.gz\t\
5226                        0000000000000000000000000000000000000000000000000000000000000000\tmit\t\
5227                        bundled\n\
5228                        lib/libc.so\tmusl-1.2.5\t\
5229                        https://musl.libc.org/releases/musl-1.2.5.tar.gz\t\
5230                        1111111111111111111111111111111111111111111111111111111111111111\tmit\t\
5231                        generated\n";
5232        let tree = TempTree::new("provenance", &[("manifest", manifest)]);
5233        let sysroot = format!("--sysroot={}", tree.0.display());
5234        // The kernel line of tamnd/rucc#934 is in the answer without anything here naming it, because
5235        // the flag parses the record and renders it again rather than picking fields out of it. That
5236        // is the reason it prints a manifest and not a format of its own.
5237        //
5238        // The answer is the file without its last newline, because whatever prints it adds one. The
5239        // file is what somebody diffs the output against, so the two have to be the same bytes.
5240        assert_eq!(printed(&[&sysroot, "-print-sysroot-provenance"]) + "\n", manifest);
5241
5242        // A tree with no manifest in it is a tree somebody assembled themselves, and nothing here
5243        // knows where any of it came from. Saying nothing is the only honest answer, and a reader can
5244        // tell it from a manifest with no inputs because that one still has its two header lines.
5245        let bare = TempTree::new("provenance-bare", &[]);
5246        assert_eq!(
5247            printed(&[&format!("--sysroot={}", bare.0.display()), "-print-sysroot-provenance"]),
5248            ""
5249        );
5250
5251        // And a compile for this machine has no sysroot at all, which is the same empty answer
5252        // `-print-sysroot` gives for it.
5253        let host = Triple::host().expect("a host this compiler knows");
5254        assert_eq!(printed(&[&format!("--target={host}"), "-print-sysroot-provenance"]), "");
5255
5256        // And the other spelling, which section 13.5 is the document that writes.
5257        assert_eq!(printed(&[&sysroot, "--print-sysroot-provenance"]) + "\n", manifest);
5258
5259        // tamnd/rucc#1021. The digest of the same tree is the sha256 of that record, so it is one
5260        // line where the provenance is a few hundred, and it is checkable with `sha256sum` because
5261        // the bytes it is over are the bytes of the file. The number here is that hash of the
5262        // fixture above, computed by `sha256sum` rather than by this compiler.
5263        assert_eq!(
5264            printed(&[&sysroot, "-print-sysroot-digest"]),
5265            "d705ae6ebeafeb7fda4bd57cecc7882bf49784b17015664a09cfae25a1b2000a"
5266        );
5267        assert_eq!(
5268            printed(&[&sysroot, "--print-sysroot-digest"]),
5269            printed(&[&sysroot, "-print-sysroot-digest"])
5270        );
5271
5272        // And the two empty answers are empty here too, because a digest of nothing would read as a
5273        // claim about a sysroot rather than as the absence of one.
5274        assert_eq!(
5275            printed(&[&format!("--sysroot={}", bare.0.display()), "-print-sysroot-digest"]),
5276            ""
5277        );
5278        assert_eq!(printed(&[&format!("--target={host}"), "-print-sysroot-digest"]), "");
5279    }
5280
5281    #[test]
5282    fn a_manifest_this_build_cannot_read_is_refused_rather_than_printed() {
5283        // Passing a file we could not parse to whoever asked would make their parser the one that
5284        // finds the problem, and the three uses section 13.5 gives for this are all somebody else
5285        // parsing it.
5286        let tree = TempTree::new(
5287            "provenance-bad",
5288            &[("manifest", "rucc sysroot manifest 3\ntarget\tx86_64-linux-musl\nlib/libc.a\n")],
5289        );
5290        let message =
5291            refused(&[&format!("--sysroot={}", tree.0.display()), "-print-sysroot-provenance"]);
5292        assert!(message.contains("manifest"), "{message}");
5293        assert!(message.contains("1 fields where an input has six"), "{message}");
5294
5295        // The digest is refused for the same file and for a stronger reason: a hash of bytes this
5296        // build cannot read would be a number that names a record nobody can act on.
5297        let digest =
5298            refused(&[&format!("--sysroot={}", tree.0.display()), "-print-sysroot-digest"]);
5299        assert_eq!(digest, message);
5300    }
5301
5302    #[test]
5303    fn the_two_dependency_flags_that_stop_after_the_rule_stop_after_the_rule() {
5304        let (opts, _) = compile(&["-M", "a.c"]);
5305        assert!(opts.deps.emit && opts.deps.instead_of_compiling);
5306        assert!(opts.deps.system_headers, "plain -M lists them");
5307        assert_eq!(opts.emit, EmitKind::Preprocessed);
5308
5309        // Even where a later flag asked for something else, because the family is a mode and
5310        // the mode is what the run is for.
5311        let (opts, _) = compile(&["-M", "-c", "a.c"]);
5312        assert_eq!(opts.emit, EmitKind::Preprocessed);
5313
5314        let (opts, _) = compile(&["-MM", "a.c"]);
5315        assert!(!opts.deps.system_headers);
5316    }
5317
5318    #[test]
5319    fn the_two_that_end_in_d_leave_the_compilation_alone() {
5320        let (opts, _) = compile(&["-MD", "-c", "a.c"]);
5321        assert!(opts.deps.emit && !opts.deps.instead_of_compiling);
5322        assert!(opts.deps.system_headers);
5323        assert_eq!(opts.emit, EmitKind::Object);
5324
5325        let (opts, _) = compile(&["-MMD", "-c", "a.c"]);
5326        assert!(opts.deps.emit && !opts.deps.instead_of_compiling);
5327        assert!(!opts.deps.system_headers);
5328    }
5329
5330    #[test]
5331    fn nothing_puts_the_system_headers_back_once_a_flag_has_taken_them_out() {
5332        // GCC's rule, and not an oversight in it. The flag asking for fewer of them is read as
5333        // the answer, because the other one never asked the question.
5334        let (opts, _) = compile(&["-MM", "-M", "a.c"]);
5335        assert!(!opts.deps.system_headers);
5336        let (opts, _) = compile(&["-MD", "-MMD", "-c", "a.c"]);
5337        assert!(!opts.deps.system_headers);
5338        let (opts, _) = compile(&["-MMD", "-MD", "-c", "a.c"]);
5339        assert!(!opts.deps.system_headers);
5340    }
5341
5342    #[test]
5343    fn a_target_arrives_escaped_from_one_flag_and_untouched_from_the_other() {
5344        let (opts, _) = compile(&["-MM", "-MT", "a b.o", "-MQ", "a b.o", "a.c"]);
5345        assert_eq!(opts.deps.targets, vec!["a b.o".to_owned(), "a\\ b.o".to_owned()]);
5346    }
5347
5348    #[test]
5349    fn the_rest_of_the_family_is_a_file_and_a_switch() {
5350        let (opts, _) = compile(&["-MM", "-MF", "dep.d", "-MP", "a.c"]);
5351        assert_eq!(opts.deps.file.as_deref(), Some("dep.d"));
5352        assert!(opts.deps.phony);
5353
5354        for flag in ["-MF", "-MT", "-MQ"] {
5355            let e = parse_args(&args(&[flag])).unwrap_err();
5356            assert!(e.message.contains("requires an argument"), "{}", e.message);
5357        }
5358    }
5359
5360    /// A directory of sources for one test, removed when the test is done with it.
5361    struct TempTree(PathBuf);
5362
5363    impl Drop for TempTree {
5364        fn drop(&mut self) {
5365            let _ = std::fs::remove_dir_all(&self.0);
5366        }
5367    }
5368
5369    impl TempTree {
5370        fn new(name: &str, files: &[(&str, &str)]) -> TempTree {
5371            let dir = std::env::temp_dir().join(format!("rucc-deps-{}-{name}", std::process::id()));
5372            let _ = std::fs::remove_dir_all(&dir);
5373            std::fs::create_dir_all(&dir).expect("temporary directory should be writable");
5374            for (path, text) in files {
5375                let at = dir.join(path);
5376                if let Some(parent) = at.parent() {
5377                    std::fs::create_dir_all(parent).expect("creating a subdirectory should work");
5378                }
5379                std::fs::write(&at, text).expect("writing a temporary file should work");
5380            }
5381            TempTree(dir)
5382        }
5383
5384        fn path(&self, name: &str) -> String {
5385            self.0.join(name).to_string_lossy().into_owned()
5386        }
5387    }
5388
5389    #[test]
5390    fn the_rule_names_what_the_includes_found_and_names_each_of_them_once() {
5391        // End to end, because the list comes from the preprocessor and the format comes from
5392        // somewhere else, and a test of either half on its own would pass with the two of them
5393        // wired up backwards.
5394        let tree = TempTree::new(
5395            "found",
5396            &[
5397                ("a.c", "#include \"one.h\"\n#include \"two.h\"\nint main(void) { return X; }\n"),
5398                ("one.h", "#define X 0\n"),
5399                ("two.h", "#include \"one.h\"\n"),
5400            ],
5401        );
5402        let out = tree.path("dep.d");
5403        let code = run(&args(&["-MM", "-MF", &out, "-o", &tree.path("a.i"), &tree.path("a.c")]));
5404        assert_eq!(code, 0);
5405
5406        let text = std::fs::read_to_string(&out).expect("the rule should have been written");
5407        let names: Vec<&str> = text.split_whitespace().collect();
5408        // The target, the source, and each header once however many times it was reached.
5409        assert_eq!(names.first(), Some(&"a.o:"), "{text}");
5410        assert_eq!(names.iter().filter(|n| n.ends_with("one.h")).count(), 1, "{text}");
5411        assert_eq!(names.iter().filter(|n| n.ends_with("two.h")).count(), 1, "{text}");
5412        // And the `-o` went to the file the rule replaced, which is left empty rather than
5413        // absent because a makefile that named it as a target will look for it.
5414        assert_eq!(std::fs::read(tree.path("a.i")).expect("the output should exist"), b"");
5415    }
5416
5417    #[test]
5418    fn a_header_that_is_only_reached_under_a_guard_is_still_a_dependency() {
5419        // The multiple-include optimization means the second reach never opens the file. It is
5420        // still a file this translation unit was built from, so it is still in the rule.
5421        let tree = TempTree::new(
5422            "guarded",
5423            &[
5424                ("a.c", "#include \"g.h\"\n#include \"g.h\"\nint main(void) { return 0; }\n"),
5425                ("g.h", "#ifndef G\n#define G\n#endif\n"),
5426            ],
5427        );
5428        let out = tree.path("dep.d");
5429        let code = run(&args(&["-MM", "-MF", &out, "-o", &tree.path("a.i"), &tree.path("a.c")]));
5430        assert_eq!(code, 0);
5431        let text = std::fs::read_to_string(&out).expect("the rule should have been written");
5432        assert_eq!(text.split_whitespace().filter(|n| n.ends_with("g.h")).count(), 1, "{text}");
5433    }
5434
5435    #[test]
5436    fn every_imacros_file_is_read_before_every_include_file_whatever_order_they_were_written() {
5437        // Measured against GCC rather than read: the two flags the other way round produce the
5438        // same output byte for byte, so the command line order between the two families does not
5439        // decide anything and the order within one does. The `-include` file here can only see
5440        // the definition if the `-imacros` file that was written after it ran first.
5441        let tree = TempTree::new(
5442            "preinclude",
5443            &[
5444                ("a.c", "int main(void) { return 0; }\n"),
5445                ("i.h", "#ifdef FROM_MACROS\nint saw_it;\n#else\nint missed_it;\n#endif\n"),
5446                ("m.h", "#define FROM_MACROS 1\nint macros_text;\n"),
5447            ],
5448        );
5449        let out = tree.path("a.i");
5450        let code = run(&args(&[
5451            "-E",
5452            "-include",
5453            &tree.path("i.h"),
5454            "-imacros",
5455            &tree.path("m.h"),
5456            "-o",
5457            &out,
5458            &tree.path("a.c"),
5459        ]));
5460        assert_eq!(code, 0);
5461        let text = std::fs::read_to_string(&out).expect("the output should have been written");
5462        assert!(text.contains("saw_it"), "{text}");
5463        // And the text of the `-imacros` file is thrown away, which is the whole difference
5464        // between the two flags.
5465        assert!(!text.contains("macros_text"), "{text}");
5466    }
5467
5468    #[test]
5469    fn a_file_the_command_line_named_is_a_prerequisite_the_same_as_one_a_directive_named() {
5470        let tree = TempTree::new(
5471            "preinclude-deps",
5472            &[
5473                ("a.c", "int main(void) { return 0; }\n"),
5474                ("i.h", "int from_include;\n"),
5475                ("m.h", "#define M 1\n"),
5476            ],
5477        );
5478        let out = tree.path("dep.d");
5479        let code = run(&args(&[
5480            "-MM",
5481            "-MF",
5482            &out,
5483            "-include",
5484            &tree.path("i.h"),
5485            "-imacros",
5486            &tree.path("m.h"),
5487            "-o",
5488            &tree.path("a.i"),
5489            &tree.path("a.c"),
5490        ]));
5491        assert_eq!(code, 0);
5492        let text = std::fs::read_to_string(&out).expect("the rule should have been written");
5493        assert!(text.contains("i.h"), "{text}");
5494        assert!(text.contains("m.h"), "{text}");
5495    }
5496
5497    #[test]
5498    fn a_command_line_include_that_is_nowhere_on_the_path_is_an_error_and_not_a_warning() {
5499        // Including the directory of the source file, which is not on the path for these: the
5500        // command line was not written there, so a name in it is relative to where the compiler
5501        // was run rather than to where the source sits.
5502        let tree = TempTree::new(
5503            "preinclude-missing",
5504            &[("sub/a.c", "int main(void) { return 0; }\n"), ("sub/beside.h", "int x;\n")],
5505        );
5506        let code = run(&args(&["-E", "-include", "beside.h", "-o", "-", &tree.path("sub/a.c")]));
5507        assert_eq!(code, 1);
5508    }
5509
5510    #[test]
5511    fn a_command_line_that_links_names_the_executable_and_not_the_object_it_went_through() {
5512        // The object a link goes through is in a temporary directory and is gone before `make`
5513        // reads any of this, so the rule that named it would be a rule for a file that is never
5514        // there. The target and the file are both the `-o`, which is the executable.
5515        let (opts, plan) = compile(&["-MD", "sub/a.c", "-o", "prog"]);
5516        assert_eq!(plan.output.as_deref(), Some("prog"));
5517        assert_eq!(deps::default_target("sub/a.c", deps_target_output(&opts, &plan)), "prog");
5518        assert_eq!(
5519            deps::default_file(&opts.deps, "sub/a.c", plan.output.as_deref()).as_deref(),
5520            Some("prog.d")
5521        );
5522    }
5523
5524    #[test]
5525    fn the_plan_keeps_the_output_name_because_the_rule_is_written_from_it() {
5526        let (_, plan) = compile(&["-MMD", "-c", "sub/a.c", "-o", "obj/x.o"]);
5527        assert_eq!(plan.output.as_deref(), Some("obj/x.o"));
5528        let (_, plan) = compile(&["-MMD", "-c", "sub/a.c"]);
5529        assert_eq!(plan.output, None);
5530    }
5531
5532    #[test]
5533    fn usage_fits_on_a_screen() {
5534        // Not a style preference. A help text that scrolls is one nobody reads, and this is
5535        // the cheapest way to keep it honest as flags accumulate. The number goes up only when
5536        // a family of flags arrives that has nowhere to share a line, which the two pass gates
5537        // were and which the two fuel flags and `-fsafety=` now are, and it goes up by exactly
5538        // the lines that family took. The four it went up by last are the flags a build system
5539        // passes without being asked to: how much to say, what machine to generate for, threads,
5540        // and the questions `configure` asks before it compiles anything. The one it went up by
5541        // last is the second line of `--emit`, whose kinds are a family that has now outgrown
5542        // one line and has nowhere else to go. The two it went up by last are the dependency
5543        // family, which is eight flags that share nothing with anything above them. The one it
5544        // went up by last is the four spellings of position independent code, which every
5545        // configure script writes and which could only have shared the link line, and that line
5546        // is already four characters short of the limit. The two it went up by last are the rest
5547        // of the include family, which is six more flags that change where a header is looked for
5548        // and two that name a header outright. The one it went up by last is the pair that keeps
5549        // the intermediate files and times the steps, which belong next to the two flags above
5550        // them that are also about watching a compilation rather than changing one. The two it
5551        // went up by last are the section flags and the visibility flag, which are what a build
5552        // that cares about the size of what it ships and about which names it exports writes, and
5553        // the second of them was already taken and only missing from here. The one it went up by
5554        // last is the stack protector, which is four spellings of one question and which every
5555        // distribution puts on every command line it issues, so a build that reads this list
5556        // looking for it and does not find it has to go and read the specification instead. The one
5557        // it went up by last is the profiler, which is two spellings of the request and two of
5558        // where the call goes, and which is about watching a program run rather than about what is
5559        // generated, so it shares its subject with nothing above it. The one it went up by last is
5560        // the room a function opens with for something to be written over it later, which takes an
5561        // argument of its own shape and is what a kernel build asks for, so it fits beside the
5562        // profiler and nothing else. The one it went up by last is what overflows rather than being
5563        // undefined, which is three spellings of two questions and which a kernel build and a great
5564        // deal of code written before the standard settled both pass. The one it went up by last is
5565        // the other answer to the first of those questions, which could not share the line because
5566        // what it asks for is the opposite of what the flags on that line ask for. The one it went
5567        // up by last is the split of the line that lists what this compiler does anyway into that
5568        // and what it assumes anyway, which are two different claims that were sharing a line until
5569        // the second of them got a second flag and the line stopped fitting. The one it went up by
5570        // last is the three flags that change the ABI rather than the code, which have to be given
5571        // to every file in a program or none of them and which therefore belong somewhere a person
5572        // reading this list will see them. The one it went up by last is the floating point group,
5573        // which is two lines rather than one because the first of them is a choice this compiler
5574        // records and the rest are claims about what it does anyway, and putting a real setting on
5575        // the same line as three flags that change nothing would be misleading about both. The one
5576        // it went up by last is the flag that says a write has to stay inside the member it names,
5577        // which is a setting rather than a claim and so cannot share the line above it, that being
5578        // the one that picks a tier. The two it went up by last are the prefix mapping family,
5579        // which is four flags whose whole job is to keep a build's output the same from two
5580        // different directories, and which a person chasing a reproducible build comes here
5581        // looking for by name. The one it went up by last is how the debug sections are compressed
5582        // and whether they go in a file of their own, which are two questions about the shape of
5583        // the debug output, where the line above them is about how much of it there is. The one it
5584        // went up by last is the `restrict` contract, which is a setting for the same reason the
5585        // flag that keeps a write inside its member is and which is the check a person who has been
5586        // bitten by a vectorizer comes here looking for. The one it went up by last is link time
5587        // optimization, which is a whole optimization rather than a flag and which says so on its
5588        // own line, because a build that passes it and reads this looking for what it got is
5589        // asking a question no other line here answers. The one it went up by last is the sysroot,
5590        // which is the question somebody asks when a cross build read a file nobody expected, and
5591        // which has no room on the line above it because the answers there are a path each and this
5592        // one is the root all of them are under. The one it went up by last is what is inside that
5593        // root and where each of it came from, which is a question about a whole tree rather than
5594        // about a path and which is long enough on its own that it could not have shared a line with
5595        // anything. The one it went up by last is the profile family, which splits down the middle
5596        // where no other family here does, so the line has to name the half that is taken and the
5597        // half that is refused or it would be read as taking both. The one it went up by last is
5598        // the sanitizers, which are what somebody reaching for a checked build writes first and
5599        // which belong beside the tier that is the nearest thing here to what they asked for. The
5600        // one it went up by last is the digest of that record, which is the same tree as one number
5601        // and could not share the line above it because that line prints a few hundred lines and
5602        // this one prints sixty four characters, and a reader who wants the short answer is looking
5603        // for it by name rather than reading the long one. The one it went up by last is the
5604        // sysroot fetch, which is the only command here that gets something from somewhere else and
5605        // is therefore the one a person wants to have read before they run it rather than after.
5606        // And the flag beside it that forbids every download, which earns its line by being what a
5607        // build in a sealed environment passes and by meaning something even though an ordinary
5608        // compile downloads nothing either way.
5609        assert!(USAGE.lines().count() < 72, "usage text has grown past one screen");
5610    }
5611}