Skip to main content

rucc_driver/
compile.rs

1//! Running the front end over one file, from the bytes on disk to the typed tree.
2//!
3//! Design: `spec/04-driver-and-cli.md` section 4.3, and the `M2` exit criterion in
4//! `spec/17-milestones.md` that says `--emit=tast` works.
5//!
6//! [`preprocess`](mod@crate::preprocess) stops after phase 4 because `-E` stops there. This
7//! carries on: phase 7, the parse, and the checking. It is one function rather than four composed
8//! ones because of what the four share. The tokens hold interned symbols, the untyped tree holds
9//! tokens, the typed tree holds the untyped tree's spans, and none of them owns the table it is
10//! reading, so one [`Session`] has to outlive all of them and there has to be one place that
11//! holds it.
12
13use std::path::Path;
14
15use rucc_base::Interner;
16use rucc_codegen::coverage::Fired;
17use rucc_codegen::elsewhere::Elsewhere;
18use rucc_codegen::pipeline::{self, Machine};
19use rucc_diag::{Diagnostic, Severity, Span};
20use rucc_ir::{Pic as IrPic, Visibility as IrVisibility};
21use rucc_lex::{Convert, Keywords, PpToken, convert};
22use rucc_sema::{Checker, Context as CheckContext};
23use rucc_session::{EmitKind, FileSystem, Options, Pic, Session, Visibility};
24use rucc_target::TargetInfo;
25use rucc_tuple::ObjectFormat;
26
27use crate::preprocess::render;
28
29/// What a compilation produced, which is text for most of the kinds and bytes for one of them.
30///
31/// Two variants rather than a string, because an object file is not text and a `Vec<u8>` holding
32/// UTF-8 for six kinds and a file format for the seventh would leave every reader guessing which
33/// it had. [`Artifact::Nothing`] is what a compilation that stopped early gives back, and it is
34/// not the same as an empty file: nothing is written for it at all.
35#[derive(Debug, Clone, PartialEq, Eq, Default)]
36pub enum Artifact {
37    /// The compilation stopped before it produced anything, or the kind asked for produces
38    /// nothing yet.
39    #[default]
40    Nothing,
41    /// Text, which is every kind up to and including assembly.
42    Text(String),
43    /// An object file, which is `-c`.
44    Object(Vec<u8>),
45}
46
47impl Artifact {
48    /// The bytes to write, which is nothing at all for [`Artifact::Nothing`].
49    #[must_use]
50    pub fn bytes(&self) -> &[u8] {
51        match self {
52            Artifact::Nothing => &[],
53            Artifact::Text(text) => text.as_bytes(),
54            Artifact::Object(bytes) => bytes,
55        }
56    }
57}
58
59/// What compiling one file produced.
60#[derive(Debug, Clone, PartialEq, Eq)]
61pub struct Compiled {
62    /// What to write, which is nothing when the compilation failed or produced nothing.
63    pub artifact: Artifact,
64    /// The diagnostics, already rendered, one per element, in the order they were reported.
65    pub messages: Vec<String>,
66    /// How many of them were errors.
67    pub errors: u32,
68    /// Which lowering rules this file fired, for `-Zrule-coverage`.
69    ///
70    /// Empty for a compilation that stopped before the back end, which every kind up to and
71    /// including `--emit=ir` does. That is not the same as a rule set nothing reaches and the
72    /// caller unions these rather than reading one, so a file that fired nothing adds nothing.
73    pub fired: Fired,
74    /// What `-fdump-ir=` asked to see, in the order the passes ran.
75    ///
76    /// The optimizer does not write files, because nothing below the driver in
77    /// `spec/18-package-layout.md` knows what a file is, so the text comes back here and the
78    /// caller decides where it goes.
79    pub dumps: Vec<rucc_opt::Dump>,
80    /// What `-fopt-info` asked to hear, already rendered, one remark per line.
81    ///
82    /// Empty when the flag was not given, and also empty when it was given and no pass had
83    /// anything of the kinds asked for to say. Those two are the same text and different facts,
84    /// which is why a misspelled keyword is an error rather than a quiet nothing.
85    pub remarks: String,
86    /// Every file an `#include` found, for the `-M` family.
87    ///
88    /// The same list `Preprocessed` carries and for the same reason. A `-MD` writes it beside
89    /// the object, so the compiling path needs it as much as the preprocessing one does.
90    pub deps: Vec<rucc_pp::Dependency>,
91    /// What `-save-temps` asked to be kept, which is nothing at all unless it was given.
92    ///
93    /// It comes back from here rather than being produced by a second run of the compiler under
94    /// different flags, because a second run is a second answer: the file a person reads has to
95    /// be the file that was compiled, and two runs of anything with a `__TIME__` in it are not
96    /// the same text.
97    pub temps: Temps,
98}
99
100/// The intermediate text a compilation went through, kept when `-save-temps` asked for it.
101///
102/// Both are `None` on a compilation that was not asked to keep anything, and the assembly is
103/// `None` on one that stopped before there was any. Holding the text rather than writing it is
104/// what keeps this function free of the file system, which is what lets it be tested against a
105/// map from path to bytes.
106#[derive(Debug, Clone, PartialEq, Eq, Default)]
107pub struct Temps {
108    /// Phase 4's output, the same text `-E` would have printed.
109    pub preprocessed: Option<String>,
110    /// The assembly the back end produced on the way to the object file.
111    pub assembly: Option<String>,
112}
113
114impl Compiled {
115    /// Whether anything went wrong badly enough that the output should not be used.
116    #[must_use]
117    pub fn failed(&self) -> bool {
118        self.errors > 0
119    }
120
121    /// The text that was produced, and the empty string for anything that is not text.
122    ///
123    /// A caller that asked for one of the text kinds knows which it asked for, so this saves it
124    /// matching on a variant it has already ruled out.
125    #[must_use]
126    pub fn text(&self) -> &str {
127        match &self.artifact {
128            Artifact::Text(text) => text,
129            _ => "",
130        }
131    }
132}
133
134/// Compiles one file as far as `opts.emit` asks for and renders the result.
135///
136/// `name` is the path as the user wrote it, which is the name every diagnostic about the file
137/// uses. Every kind but the executable produces something today, and that one runs the same front
138/// end and gives back nothing, so that a file with a mistake in it is reported the same way
139/// whichever kind was asked for, rather than compiling silently until the part that is written
140/// notices.
141///
142/// The checking is skipped when the parse reported an error. The two poisoning rules mean a
143/// diagnosed expression produces no further complaints, but a declaration the parser had to skip
144/// past leaves no declaration behind at all, and every later use of that name would be reported
145/// as undeclared. One mistake is worth one message.
146#[must_use]
147pub fn compile(opts: &Options, name: &str, fs: &dyn FileSystem) -> Compiled {
148    let mut sess = Session::new(opts.clone());
149    // Before anything else interns a name. The keyword symbols have to be one unbroken run for
150    // a lookup to be a subtraction, and the preprocessor interns every identifier it reads, so
151    // building this after the expansion would mean building it after `char` had been seen.
152    let keywords = Keywords::new(&mut sess.interner, opts.std, opts.gnu_extensions);
153    let mut diagnostics: Vec<Diagnostic> = Vec::new();
154    // Filled in by the back end when there is one, and empty for every kind that stops before it.
155    let mut fired = Fired::new();
156    // Filled in by the optimizer, and only when `-fdump-ir=` asked for something.
157    let mut dumps = Vec::new();
158    let mut remarks = String::new();
159    // Filled in as the compilation goes past each of them, and only under `-save-temps`.
160    let mut temps = Temps::default();
161
162    let bytes = match fs.read(Path::new(name)) {
163        Ok(bytes) => bytes,
164        Err(e) => return failure(format!("{name}: {e}")),
165    };
166    let Ok(file) = sess.sources.add_shared(name, bytes, None) else {
167        return failure(format!("{name}: the source map has no room left for this file"));
168    };
169
170    // Phases 1 to 4. The expanded stream is turned into pp-tokens straight away, because the
171    // include context borrows the source map that rendering a diagnostic reads and the borrow
172    // has to end before anything is rendered.
173    let mut pp = rucc_pp::Preprocessor::new();
174    let predef = rucc_pp::Predef::for_options(opts);
175    let expanded: Vec<PpToken> = {
176        let mut tokens = Vec::new();
177        // The inner block is the borrow. The printer under `-save-temps` reads the source map
178        // that the include context is holding, so the context has to be gone before it runs, and
179        // nothing happens in between, which is what makes the text it prints the text that is
180        // compiled below rather than a second answer to the same question.
181        {
182            let mut cx =
183                rucc_pp::Context::new(&mut sess.interner, &mut sess.sources, fs, &opts.search);
184            cx.lex = rucc_lex::Options::for_dialect(opts.std, opts.gnu_extensions);
185            if pp.predefine(&sess.target, &predef, &mut cx).is_err() {
186                return failure(format!(
187                    "{name}: the source map has no room for the built in macros"
188                ));
189            }
190            if pp.preinclude(&opts.preincludes, &mut tokens, &mut cx).is_err() {
191                return failure(format!("{name}: the source map has no room for the command line"));
192            }
193            tokens.append(&mut pp.run(file, &mut cx));
194        }
195        if opts.save_temps.wanted() {
196            temps.preprocessed = Some(rucc_pp::print(
197                file,
198                &tokens,
199                pp.line_directives(),
200                &sess.sources,
201                &sess.interner,
202                rucc_pp::PrintOptions { line_markers: opts.line_markers },
203            ));
204        }
205        tokens.iter().map(|token| token.to_pp()).collect()
206    };
207    diagnostics.extend(pp.take_diagnostics());
208    // Taken here rather than at the end, because the preprocessor is done with and everything
209    // after this is about the tree it produced.
210    let deps = pp.dependencies().to_vec();
211
212    // Phase 7, which is where a spelling becomes a keyword and a preprocessing number becomes
213    // a constant of a type.
214    let cx = Convert {
215        keywords: &keywords,
216        interner: &sess.interner,
217        target: &sess.target,
218        std: opts.std,
219        gnu: opts.gnu_extensions,
220        pedantic: opts.pedantic,
221    };
222    let (tokens, complaints) = convert(&expanded, &cx);
223    diagnostics.extend(complaints);
224
225    let parsed = rucc_parse::parse(
226        &tokens,
227        rucc_parse::Context {
228            interner: &sess.interner,
229            std: opts.std,
230            gnu: opts.gnu_extensions,
231            pedantic: opts.pedantic,
232            error_limit: opts.error_limit as usize,
233        },
234    );
235    let parse_failed = parsed.diagnostics.iter().any(|d| d.severity.is_fatal());
236    diagnostics.extend(parsed.diagnostics);
237
238    let mut artifact = Artifact::Nothing;
239    // Zero when nothing instruments, which is the truthful summary of a file built without
240    // `-fsafety`: no checks went in, so none is standing, and every call it makes is unmodelled.
241    let mut instrumented = Instrumented::default();
242    if !parse_failed {
243        let mut checker = Checker::new(
244            &parsed.ast,
245            CheckContext {
246                names: &sess.interner,
247                target: &sess.target,
248                std: opts.std,
249                gnu: opts.gnu_extensions,
250                pedantic: opts.pedantic,
251                permissive: opts.permissive,
252                gnu89_inline: opts.gnu89_inline,
253                error_limit: opts.error_limit as usize,
254                // A freestanding program has no C library, so a name that is the library's
255                // everywhere else is the program's own here and means whatever it defined.
256                builtins: opts.builtins && opts.hosted,
257                no_builtin: &opts.no_builtin,
258            },
259        );
260        checker.check_unit();
261        let checked = checker.finish();
262        if !checked.failed() {
263            match opts.emit {
264                EmitKind::Tast => {
265                    artifact = Artifact::Text(rucc_sema::print(
266                        &checked.tast,
267                        &checked.types,
268                        &sess.interner,
269                    ));
270                }
271                // Nothing past the checker, because a granule is a fact about a layout and a
272                // layout is settled the moment the closing brace is seen. Lowering the
273                // function bodies would take minutes on an amalgamation and answer nothing.
274                EmitKind::TypeGranules => {
275                    artifact = Artifact::Text(rucc_types::granule_report(
276                        &checked.types,
277                        &sess.interner,
278                        &sess.target,
279                    ));
280                }
281                EmitKind::Ir
282                | EmitKind::MirFinal
283                | EmitKind::Asm
284                | EmitKind::Object
285                | EmitKind::Executable
286                | EmitKind::SafetySummary => {
287                    let mut lowered = rucc_lower::lower(
288                        name,
289                        rucc_lower::Context {
290                            tast: &checked.tast,
291                            types: &checked.types,
292                            target: &sess.target,
293                            names: &mut sess.interner,
294                            visibility: match opts.visibility {
295                                Visibility::Default => IrVisibility::Default,
296                                Visibility::Hidden => IrVisibility::Hidden,
297                                Visibility::Protected => IrVisibility::Protected,
298                            },
299                        },
300                    );
301                    // The walk reports what it cannot build, and what it did build is printed
302                    // anyway: a file with one construct missing from it is more use to read
303                    // than nothing at all, and the errors are what stop it being compiled.
304                    let failed = lowered.diagnostics.iter().any(|d| d.severity.is_fatal());
305                    if !failed {
306                        // The verifier runs on everything the walk builds, always. It is the
307                        // one check that a bug in the walk cannot talk its way past, and a
308                        // wrong instruction found here costs a message rather than an hour
309                        // in front of a debugger over the assembly it turned into.
310                        if let Err(errors) = rucc_ir::verify(&lowered.module, &sess.interner) {
311                            for error in errors {
312                                diagnostics.push(internal(&format!("invalid IR, {error}")));
313                            }
314                        } else if let Err(complaints) =
315                            instrument(&mut lowered.module, &mut sess.interner, opts)
316                                .map(|done| instrumented = done)
317                        {
318                            diagnostics.extend(complaints);
319                        } else if let Err(complaints) = optimize(
320                            &mut lowered.module,
321                            &sess.interner,
322                            &sess.target,
323                            opts,
324                            name,
325                            &mut dumps,
326                            &mut remarks,
327                        ) {
328                            diagnostics.extend(complaints);
329                        } else if opts.emit == EmitKind::SafetySummary {
330                            // After the optimizer, because the number that matters is how many
331                            // checks are still standing and there is no way to know that before it
332                            // has run. Before the back end, because the back end turns a check into
333                            // a call and a summary of calls is not a summary of checks.
334                            artifact = Artifact::Text(
335                                rucc_safety::summarize(
336                                    &lowered.module,
337                                    &sess.interner,
338                                    name,
339                                    opts.safety.as_str(),
340                                    instrumented.checks,
341                                    instrumented.interposed,
342                                    instrumented.crossings,
343                                )
344                                .render(),
345                            );
346                        } else if opts.emit == EmitKind::Ir {
347                            // After the optimizer rather than before it, so that `--emit=ir -O2`
348                            // is the IR the back end will be given rather than the IR it would
349                            // have been given at `-O0`. There is no other way to see what a pass
350                            // did without reading the assembly it turned into.
351                            artifact =
352                                Artifact::Text(rucc_ir::print(&lowered.module, &sess.interner));
353                        } else {
354                            // The back end, which is every pass after the IR and which is
355                            // where a construct nothing has a rule for is finally noticed.
356                            match generate(
357                                &mut lowered.module,
358                                &mut sess.interner,
359                                &sess.target,
360                                opts,
361                                &mut fired,
362                                &mut temps.assembly,
363                            ) {
364                                Ok(made) => artifact = made,
365                                Err(complaints) => diagnostics.extend(complaints),
366                            }
367                        }
368                    }
369                    diagnostics.extend(lowered.diagnostics);
370                }
371                _ => {}
372            }
373        }
374        diagnostics.extend(checked.diagnostics);
375    }
376
377    let mut messages = Vec::with_capacity(diagnostics.len());
378    let mut errors = 0;
379    for diag in &diagnostics {
380        // `-w` drops the warning here rather than at the several hundred places one is raised,
381        // and it drops it before the count, so `-w -Werror` compiles. A warning that was never
382        // raised is not a warning there is anything to promote.
383        if !opts.warnings && diag.severity == Severity::Warning {
384            continue;
385        }
386        if diag.severity.is_fatal()
387            || (diag.severity == Severity::Warning && opts.warnings_are_errors)
388        {
389            errors += 1;
390        }
391        messages.push(render(diag, &sess.sources, opts.warnings_are_errors));
392    }
393    if errors > 0 {
394        // A tree built from a file that did not compile is not a tree anything should read.
395        artifact = Artifact::Nothing;
396    }
397    // Kept even when the compilation failed, because a rule that fired did fire and a report about
398    // which rules a corpus reaches should not lose the ones a file with a mistake in it reached.
399    Compiled { artifact, messages, errors, fired, dumps, remarks, deps, temps }
400}
401
402/// Reads one file of IR, checks it, and prints it back.
403///
404/// This is the compiler's own textual IR arriving as an input rather than leaving as an output,
405/// which is what makes the round trip in the M2 exit criterion something to run rather than
406/// something to believe: what the printer wrote is read back, verified, and written again, and
407/// the two files are either the same bytes or they are not.
408///
409/// The verifier runs here for the reason it runs after the walk. A module that was printed by
410/// this compiler has been through it once already, and one that a person edited has not.
411#[must_use]
412pub fn compile_ir(opts: &Options, name: &str, fs: &dyn FileSystem) -> Compiled {
413    let mut sess = Session::new(opts.clone());
414    if opts.emit != EmitKind::Ir {
415        return failure(format!(
416            "{name}: an input of IR can only be emitted as IR, and `--emit={}` asks for what \
417             the C in front of it became",
418            opts.emit.as_str()
419        ));
420    }
421    let bytes = match fs.read(Path::new(name)) {
422        Ok(bytes) => bytes,
423        Err(e) => return failure(format!("{name}: {e}")),
424    };
425    let Ok(text) = std::str::from_utf8(bytes.as_slice()) else {
426        return failure(format!("{name}: this is not text, so it is not IR"));
427    };
428
429    let module = match rucc_ir::parse(text, &mut sess.interner) {
430        Ok(module) => module,
431        Err(error) => {
432            return failure(format!("{name}:{}: {}", error.line, error.message));
433        }
434    };
435    let mut diagnostics: Vec<Diagnostic> = Vec::new();
436    if let Err(errors) = rucc_ir::verify(&module, &sess.interner) {
437        for error in errors {
438            diagnostics.push(invalid(&format!("invalid IR, {error}")));
439        }
440    }
441    let mut messages = Vec::with_capacity(diagnostics.len());
442    for diag in &diagnostics {
443        messages.push(render(diag, &sess.sources, opts.warnings_are_errors));
444    }
445    let errors = u32::try_from(messages.len()).unwrap_or(u32::MAX);
446    let artifact = if errors > 0 {
447        Artifact::Nothing
448    } else {
449        Artifact::Text(rucc_ir::print(&module, &sess.interner))
450    };
451    // Nothing here reaches the back end, so no rule fired and there is nothing to record.
452    Compiled {
453        artifact,
454        messages,
455        errors,
456        fired: Fired::new(),
457        dumps: Vec::new(),
458        remarks: String::new(),
459        deps: Vec::new(),
460        temps: Temps::default(),
461    }
462}
463
464/// Puts the memory safety checks in and redirects the calls that cross the boundary, when
465/// `-fsafety=` asked for them.
466///
467/// Between the walk and the optimizer, which is where section 15.3 of
468/// `spec/safe-memory/15-integration.md` puts it and which is the whole design in one line: the
469/// checks go in while the addresses the program computes still exist, and the optimizer then
470/// discharges the ones it can prove. Every sanitizer that came before instruments after the
471/// optimizer so that its checks cannot be deleted, and pays for all of them forever.
472///
473/// The calls to the C library are redirected here too, and in the same window and for a related
474/// reason. `spec/safe-memory/10-boundaries.md` section 10.3 wants a `memcpy` modelled by a wrapper
475/// that performs the judgements, and `rucc_safety::wrap` is why that has to happen before the
476/// optimizer sees the call rather than after.
477///
478/// The verifier runs again afterwards, for the reason it runs after the walk. This pass rewrites
479/// every function in the module, and a pass that produced IR nothing else accepts should say so
480/// here rather than in the assembly it turned into.
481///
482/// # Errors
483///
484/// When the inserted checks left the module in a state the verifier refuses, which is a bug in
485/// this compiler and not in the program being compiled.
486fn instrument(
487    module: &mut rucc_ir::Module,
488    names: &mut Interner,
489    opts: &Options,
490) -> Result<Instrumented, Vec<Diagnostic>> {
491    if !opts.safety.instruments() {
492        return Ok(Instrumented::default());
493    }
494    let checks = rucc_safety::run(module);
495    // Before the optimizer rather than beside the check lowering, which is what
496    // `rucc_safety::wrap` argues out: `memcpy` is a name an optimizer knows things about, and a
497    // pass that turns a short copy into a pair of loads and stores would leave behind accesses the
498    // check insertion has already finished walking past.
499    let interposed = rucc_safety::redirect(module, names);
500    // After the redirection, so that a call this build models with a wrapper is not also counted
501    // as a crossing it did not model.
502    let crossings = rucc_safety::witness(module, names);
503    match rucc_ir::verify(module, names) {
504        Ok(()) => Ok(Instrumented { checks, interposed, crossings }),
505        Err(errors) => Err(errors
506            .iter()
507            .map(|e| internal(&format!("invalid IR after check insertion, {e}")))
508            .collect()),
509    }
510}
511
512/// What the instrumentation did, which nothing but the summary reads.
513///
514/// Carried out of [`instrument`] rather than recovered from the module afterwards because neither
515/// number survives the optimizer: a check that was discharged leaves nothing behind saying it was
516/// ever there, and a call that was pointed at a wrapper looks like a call that always named one.
517#[derive(Clone, Copy, Debug, Default)]
518struct Instrumented {
519    /// How many checks of each class went in.
520    checks: rucc_safety::Counts,
521    /// How many calls were pointed at an interposition wrapper.
522    interposed: usize,
523    /// How many places a pointer crosses to or from code this build did not instrument.
524    crossings: rucc_safety::Sites,
525}
526
527/// Runs the optimizer over the module, and collects whatever the dumps asked for.
528///
529/// The level chooses a pipeline, the `-f` flags edit it, and at `-O0` there is nothing in it, so
530/// this is a walk over an empty list rather than a branch on the level. See section 9.1 of
531/// `spec/09-optimizer.md` for why the pipelines are written out rather than assembled.
532///
533/// # Errors
534///
535/// When a pass left the module in a state the verifier refuses, which is a bug in the pass and
536/// not in the program being compiled, so it is reported as an internal error the way a bad
537/// lowering is.
538fn optimize(
539    module: &mut rucc_ir::Module,
540    names: &Interner,
541    target: &TargetInfo,
542    opts: &Options,
543    file: &str,
544    dumps: &mut Vec<rucc_opt::Dump>,
545    remarks: &mut String,
546) -> Result<(), Vec<Diagnostic>> {
547    let mut settings = rucc_opt::Options::for_level(opts.opt_level);
548    // What the analyses that read a body may believe about it. The same question the back end asks
549    // about addresses, with one thing on top: `-fno-semantic-interposition` is the build promising
550    // that a name it exports is the one that will run, which is what every distribution builds a
551    // library with. It says nothing about how an address is reached, and gcc does not change that
552    // under the flag either, so the back end is not given this value.
553    settings.interposition = match opts.interposition {
554        true => replaceable(target, opts),
555        false => IrPic::Executable,
556    };
557    settings.toggles.clone_from(&opts.passes);
558    settings.fuel = opts.pass_fuel.iter().cloned().collect();
559    settings.global_fuel = opts.pass_fuel_global;
560    settings.verify |= opts.verify_each;
561    for (on, spec) in &opts.pass_gates {
562        // Same argument as the dumps below: every spelling in here was checked while the
563        // arguments were parsed, so a rejection now is this compiler disagreeing with itself.
564        if let Err(why) = settings.gates.add(*on, spec) {
565            return Err(vec![internal(&why)]);
566        }
567    }
568    for spec in &opts.dump_ir {
569        // Every spelling in here was checked while the arguments were parsed, so a rejection
570        // now is this compiler disagreeing with itself rather than the command line being wrong.
571        if let Err(why) = settings.dumps.add(spec) {
572            return Err(vec![internal(&why)]);
573        }
574    }
575    let mut wants = rucc_opt::Wants::none();
576    for spec in &opts.opt_info {
577        // Same argument as the dumps above: every spelling was checked while the arguments were
578        // parsed, so a rejection now is the compiler disagreeing with itself.
579        if let Err(why) = wants.add(spec) {
580            return Err(vec![internal(&why)]);
581        }
582    }
583    let report = rucc_opt::run(module, names, &settings);
584    remarks.push_str(&rucc_opt::optinfo::render(file, &report, names, wants));
585    dumps.extend(report.dumps);
586    match report.broke.is_empty() {
587        true => Ok(()),
588        false => Err(report.broke.iter().map(|why| internal(why)).collect()),
589    }
590}
591
592/// Runs the back end over every function in `module` and writes what came out.
593///
594/// One machine function per definition in the module, in the order the module holds them, every
595/// register physical and every frame offset a constant. A declaration has no body and is skipped,
596/// because there is nothing in it to compile.
597///
598/// What the last step is, is the only thing `--emit=mir-final`, `-S` and `-c` disagree about. The
599/// three read the same functions and differ in whether they are printed as machine IR, printed as
600/// assembly, or encoded and put in a file, which is the point of section 11.1 of
601/// `spec/11-asm-objects-debug.md`: a listing that disagrees with the object file beside it is
602/// worse than no listing, and the way to make that impossible is to have one description of an
603/// instruction and two ways of writing it down.
604///
605/// # Errors
606///
607/// One diagnostic per function the back end could not compile, or one about the target when no
608/// back end covers it at all. Every function is attempted rather than stopping at the first, so a
609/// file with three constructs missing from the rule set reports three rather than one at a time.
610///
611/// `assembly` is where `-save-temps` gets its listing from on the path that does not print one,
612/// which is the same functions written the other way rather than a second compilation of the same
613/// file. A listing that disagrees with the object beside it would be worse than none.
614/// Whether a name this file exports is one another object may define or replace.
615///
616/// The link that reads the object decides half of what is in it, and the command line is where that
617/// is said, which is why the flag reaches this far down. See #756.
618///
619/// ELF only, because it is a question about a format rather than about a machine and the other two
620/// answer it differently. Mach-O has a two level namespace, so a name a library defines is bound to
621/// that library and is not replaced by a definition loaded earlier, and it has no copy relocations,
622/// so a variable defined elsewhere needs the table whichever link is coming. COFF decides what
623/// leaves a DLL by an export table the linker is handed. Neither has an object writer here yet, so
624/// what this does is decline to say the ELF answer about them.
625fn replaceable(target: &TargetInfo, opts: &Options) -> IrPic {
626    match (target.tuple.os().object_format(), opts.pic) {
627        (Some(ObjectFormat::Elf), Pic::Library) => IrPic::Library,
628        _ => IrPic::Executable,
629    }
630}
631
632fn generate(
633    module: &mut rucc_ir::Module,
634    names: &mut Interner,
635    target: &TargetInfo,
636    opts: &Options,
637    fired: &mut Fired,
638    assembly: &mut Option<String>,
639) -> Result<Artifact, Vec<Diagnostic>> {
640    let Some(machine) = Machine::for_target(target) else {
641        return Err(vec![unsupported(&format!(
642            "there is no back end for {} in this compiler yet, so there is nothing to generate",
643            target.tuple
644        ))]);
645    };
646    let flags = pipeline::Flags { frame_pointer: opts.frame_pointer, red_zone: opts.red_zone };
647
648    // The checks become calls here rather than beside the insertion, because the id each one
649    // carries is an index into a table and a row for a check the optimizer deleted is a row nothing
650    // will ever name. Section 6.3.1 of `spec/safe-memory/06-instrumentation.md` is what this
651    // eventually becomes and `rucc_safety::lower` says why it is not that yet.
652    //
653    // It is inside the back end rather than beside the optimizer so that `--emit=ir` still shows
654    // the checks. The IR a person reads should say what the compiler decided, not how it spelled it
655    // for the machine.
656    if opts.safety.instruments() {
657        rucc_safety::lower(module, names);
658        if let Err(errors) = rucc_ir::verify(module, names) {
659            return Err(errors
660                .iter()
661                .map(|e| internal(&format!("invalid IR after check lowering, {e}")))
662                .collect());
663        }
664    }
665
666    // Worked out before the loop and not inside it, because it reads the whole module and the loop
667    // is holding one function of it. It has to be after the check lowering above, since that adds
668    // calls to the runtime and so can add a name this file does not define.
669    //
670    // The link that reads the object decides half of what is in it, and the command line is where
671    // that is said, which is why the flag reaches this far down. See #756.
672    //
673    let elsewhere = Elsewhere::of(module, replaceable(target, opts));
674
675    let mut funcs = Vec::new();
676    let mut complaints = Vec::new();
677    for id in module.funcs() {
678        if module[id].is_declaration() {
679            continue;
680        }
681        match pipeline::compile_recording(
682            &mut module[id],
683            names,
684            &machine,
685            &elsewhere,
686            flags,
687            fired,
688        ) {
689            Ok(func) => funcs.push(func),
690            Err(why) => {
691                let name = names.resolve(module[id].name).to_owned();
692                // The function knows where the instruction came from, so the message lands on
693                // the line somebody wrote rather than on the file as a whole.
694                let span = why.inst().map_or(Span::DUMMY, |inst| module[id].span(inst));
695                let said = format!("cannot generate code for '{name}': {why}");
696                complaints.push(unsupported_at(&said, span));
697            }
698        }
699    }
700    if !complaints.is_empty() {
701        return Err(complaints);
702    }
703    // The variables the file defines, which go through the back end the way the functions did not:
704    // there is nothing in a variable to select instructions for, so the module is what says what
705    // one is right up to the point where it is written down.
706    // The second names go the same way and for the same reason, and they are neither a function
707    // nor a variable: an alias is an entry in the symbol table and no bytes of anything.
708    let (globals, aliases) = match opts.emit {
709        EmitKind::Asm | EmitKind::Object | EmitKind::Executable => (
710            rucc_asm::globals(module, names).map_err(refused)?,
711            rucc_asm::aliases(module, names).map_err(refused)?,
712        ),
713        _ => (rucc_asm::Globals::default(), Vec::new()),
714    };
715    // A failure in either of the last two is a bug here rather than a program this compiler is
716    // behind on, because every instruction in a function that got this far came out of the same
717    // description both of them read and every register in it has been allocated.
718    let unwind = opts.unwinds();
719    match opts.emit {
720        EmitKind::Asm => {
721            rucc_asm::print(&funcs, &globals, &aliases, names, target, unwind, sections(opts))
722                .map(Artifact::Text)
723                .map_err(refused)
724        }
725        // An executable is an object as far as this gets: one is what each file of a link
726        // contributes, and the linker is what turns them into the other.
727        EmitKind::Object | EmitKind::Executable => {
728            if opts.save_temps.wanted() {
729                let listing = rucc_asm::print(
730                    &funcs,
731                    &globals,
732                    &aliases,
733                    names,
734                    target,
735                    unwind,
736                    sections(opts),
737                );
738                *assembly = Some(listing.map_err(refused)?);
739            }
740            let text = rucc_asm::assemble(&funcs, names, target, unwind).map_err(refused)?;
741            let data = globals.image();
742            // A format with no writer is a target this compiler is behind on and anything else
743            // the writer refused is a bug here, and the two are not the same news to get.
744            rucc_object::write(&text, &data, &aliases, target, sections(opts))
745                .map(Artifact::Object)
746                .map_err(|why| match why {
747                    rucc_object::Error::Format { .. } => vec![unsupported(&why.to_string())],
748                    rucc_object::Error::Refused { .. } => vec![internal(&why.to_string())],
749                })
750        }
751        _ => Ok(Artifact::Text(rucc_mir::print(&funcs, names, target.regs))),
752    }
753}
754
755/// Whether each function and each variable is being given a section of its own.
756///
757/// Two words for the same pair of facts, because the flags are the command line's and the answer
758/// the assembler and the object writer want is the object format's. The conversion is here rather
759/// than in either of them so that the two output paths are handed the same thing and cannot come
760/// to disagree about which sections a file has in it.
761fn sections(opts: &Options) -> rucc_object::Sections {
762    rucc_object::Sections { functions: opts.function_sections, data: opts.data_sections }
763}
764
765/// What the assembler said, as the kind of news it is.
766///
767/// Two of these are about a program and the rest are about this compiler. A thread-local variable
768/// and an ifunc are both valid C that the back end does not build yet, and everything else the
769/// assembler refuses is something that should never have reached it.
770fn refused(why: rucc_asm::Error) -> Vec<Diagnostic> {
771    match why {
772        rucc_asm::Error::Thread { .. } | rucc_asm::Error::IFunc { .. } => {
773            vec![unsupported(&why.to_string())]
774        }
775        _ => vec![internal(&why.to_string())],
776    }
777}
778
779/// A diagnostic about a program this compiler is not finished enough to compile.
780///
781/// Not an internal error, because nothing here is wrong: the program is valid C and the part of
782/// the back end that would handle it has not been written. The note says so, so that a report
783/// about one of these is filed against the milestone rather than as a miscompilation.
784fn unsupported(message: &str) -> Diagnostic {
785    unsupported_at(message, Span::DUMMY)
786}
787
788/// The same, about somewhere in the file rather than about the file.
789///
790/// The note names the issue tracker rather than `spec/17-milestones.md`, which is a document
791/// about the plan: a reader who follows it wants to know whether the construct in front of them
792/// is already written down as work, and the milestone list does not answer that.
793fn unsupported_at(message: &str, span: Span) -> Diagnostic {
794    Diagnostic::error(message.to_owned(), span)
795        .with_code("E0653")
796        .note("this construct is not lowered yet, see https://github.com/tamnd/rucc/issues", span)
797}
798
799/// A diagnostic about IR that was handed to us rather than built by us.
800fn invalid(message: &str) -> Diagnostic {
801    Diagnostic::error(message.to_owned(), Span::DUMMY).with_code("E0661")
802}
803
804/// A diagnostic about this compiler rather than about the program it was given.
805fn internal(message: &str) -> Diagnostic {
806    Diagnostic::error(format!("internal error: {message}"), Span::DUMMY)
807        .with_code("E0652")
808        .note("this is a bug in rucc rather than in the program, please report it", Span::DUMMY)
809}
810
811/// A result that is nothing but one message, for the failures that happen before there is
812/// anything to compile.
813fn failure(message: String) -> Compiled {
814    Compiled {
815        artifact: Artifact::Nothing,
816        messages: vec![format!("rucc: error: {message}")],
817        errors: 1,
818        fired: Fired::new(),
819        dumps: Vec::new(),
820        remarks: String::new(),
821        deps: Vec::new(),
822        temps: Temps::default(),
823    }
824}
825
826#[cfg(test)]
827mod tests {
828    use rucc_session::{MemoryFileSystem, Std};
829    use rucc_target::Triple;
830
831    use super::*;
832
833    fn options() -> Options {
834        let mut opts = Options::new("x86_64-unknown-linux-gnu".parse::<Triple>().unwrap());
835        opts.emit = EmitKind::Tast;
836        opts
837    }
838
839    fn run(opts: &Options, source: &str) -> Compiled {
840        let mut fs = MemoryFileSystem::new();
841        fs.insert("/main.c", source.to_owned().into_bytes());
842        compile(opts, "/main.c", &fs)
843    }
844
845    /// Options with the compiler's own headers on the search path and nothing else, which is
846    /// what a freestanding compilation is. There is no file system underneath these tests,
847    /// so a header that reached for one would fail to resolve and say so.
848    fn freestanding() -> Options {
849        let mut opts = options();
850        opts.hosted = false;
851        opts.search.push_system(rucc_session::runtime::DIR);
852        opts
853    }
854
855    /// The typed tree of a freestanding `source`, insisting that it compiled cleanly.
856    fn shipped(source: &str) -> String {
857        let result = run(&freestanding(), source);
858        assert_eq!(result.messages, Vec::<String>::new(), "expected this to compile:\n{source}");
859        result.text().to_owned()
860    }
861
862    /// The typed tree of `source`, insisting that it compiled cleanly.
863    fn tast(source: &str) -> String {
864        let result = run(&options(), source);
865        assert_eq!(result.messages, Vec::<String>::new(), "expected this to compile:\n{source}");
866        result.text().to_owned()
867    }
868
869    #[test]
870    fn the_shipped_stdarg_declares_a_list_and_the_four_operators() {
871        let text = shipped(concat!(
872            "#include <stdarg.h>\n",
873            "int sum(int n, ...) {\n",
874            "  va_list ap, copy;\n",
875            "  va_start(ap, n);\n",
876            "  va_copy(copy, ap);\n",
877            "  int total = va_arg(ap, int) + va_arg(copy, int);\n",
878            "  va_end(ap);\n",
879            "  va_end(copy);\n",
880            "  return total;\n",
881            "}\n",
882        ));
883        assert!(text.contains("va-start"), "{text}");
884        assert!(text.contains("va-copy"), "{text}");
885        assert!(text.contains("va-arg"), "{text}");
886        assert!(text.contains("va-end"), "{text}");
887    }
888
889    /// glibc includes `<stdarg.h>` this way from every header that declares a `vprintf`, and
890    /// what it wants is the type without the four macro names. Answering the whole header
891    /// would put `va_start` in the way of a program that has its own.
892    #[test]
893    fn stdarg_hands_out_the_type_alone_when_that_is_all_that_was_asked_for() {
894        let text = shipped(concat!(
895            "#define __need___va_list\n",
896            "#include <stdarg.h>\n",
897            "int vprint(const char *f, __gnuc_va_list ap);\n",
898            "#ifdef va_start\n",
899            "#error va_start should not be defined\n",
900            "#endif\n",
901            "#ifdef _VA_LIST_DEFINED\n",
902            "#error va_list should not have been made\n",
903            "#endif\n",
904        ));
905        assert!(text.contains("vprint"), "{text}");
906    }
907
908    /// The same protocol on `<stddef.h>`, which glibc uses far more heavily: `<stdio.h>` asks
909    /// for `size_t` and `NULL` and would be wrong to receive `offsetof` as well.
910    #[test]
911    fn stddef_answers_one_piece_at_a_time_and_the_next_request_still_gets_through() {
912        let text = shipped(concat!(
913            "#define __need_size_t\n",
914            "#include <stddef.h>\n",
915            "#ifdef offsetof\n",
916            "#error offsetof should not be defined yet\n",
917            "#endif\n",
918            "#define __need_ptrdiff_t\n",
919            "#include <stddef.h>\n",
920            "#include <stddef.h>\n",
921            "size_t a;\n",
922            "ptrdiff_t b;\n",
923            "wchar_t c;\n",
924            "max_align_t d;\n",
925            "void *e = NULL;\n",
926            "struct P { int x; long y; };\n",
927            "size_t f = offsetof(struct P, y);\n",
928        ));
929        assert!(text.contains("decl #0 a : unsigned long"), "{text}");
930        assert!(text.contains("decl #1 b : long"), "{text}");
931    }
932
933    #[test]
934    fn the_shipped_limits_and_float_are_the_targets_own_answers() {
935        let text = shipped(concat!(
936            "#include <limits.h>\n",
937            "#include <float.h>\n",
938            "int bits = CHAR_BIT;\n",
939            "long big = LONG_MAX;\n",
940            "int low = INT_MIN;\n",
941            "int radix = FLT_RADIX;\n",
942            "int digits = DBL_MANT_DIG;\n",
943        ));
944        assert!(text.contains("const 8 : int"), "{text}");
945        assert!(text.contains("const 9223372036854775807 : long"), "{text}");
946        assert!(text.contains("const 2 : int"), "{text}");
947        assert!(text.contains("const 53 : int"), "{text}");
948    }
949
950    /// Freestanding, so there is no library header to chain to and `<stdint.h>` writes the
951    /// whole set out itself. The widths are the ones the target picked, which is the only
952    /// reason this header is the compiler's.
953    #[test]
954    fn the_shipped_stdint_writes_the_whole_set_when_there_is_no_library_to_defer_to() {
955        let text = shipped(concat!(
956            "#include <stdint.h>\n",
957            "int64_t a = INT64_C(1);\n",
958            "uint_least16_t b;\n",
959            "intptr_t c;\n",
960            "uintmax_t d = UINTMAX_MAX;\n",
961            "int wide = sizeof(int_fast64_t);\n",
962        ));
963        assert!(text.contains("decl #0 a : long"), "{text}");
964        assert!(text.contains("decl #1 b : unsigned short"), "{text}");
965        assert!(text.contains("decl #2 c : long"), "{text}");
966    }
967
968    #[test]
969    fn the_three_formality_headers_still_have_to_work() {
970        let text = shipped(concat!(
971            "#include <stdbool.h>\n",
972            "#include <stdalign.h>\n",
973            "#include <iso646.h>\n",
974            "#include <stdnoreturn.h>\n",
975            "int t = true and not false;\n",
976            "_Alignas(16) char buf[16];\n",
977            "int a = alignof(long);\n",
978        ));
979        assert!(text.contains("decl #0 t : int"), "{text}");
980        assert!(text.contains("const 8 : unsigned long"), "{text}");
981    }
982
983    /// Including everything twice has to change nothing, because that is what happens in any
984    /// program large enough to matter and a guard that is wrong shows up nowhere else.
985    #[test]
986    fn every_shipped_header_can_be_included_twice() {
987        let mut source = String::new();
988        for _ in 0..2 {
989            for name in rucc_session::runtime::names() {
990                source.push_str(&format!("#include <{name}>\n"));
991            }
992        }
993        source.push_str("int x;\n");
994        let text = shipped(&source);
995        assert!(text.starts_with("decl #0 x : int"), "{text}");
996    }
997
998    #[test]
999    fn a_file_that_is_not_there_says_so_and_produces_nothing() {
1000        let fs = MemoryFileSystem::new();
1001        let result = compile(&options(), "/nope.c", &fs);
1002        assert!(result.failed());
1003        assert!(result.messages[0].contains("/nope.c"), "{:?}", result.messages);
1004        assert!(result.text().is_empty());
1005    }
1006
1007    #[test]
1008    fn an_object_comes_out_with_its_type_its_linkage_and_how_much_of_a_definition_it_is() {
1009        let text = tast("int x = 1;\n");
1010        let expected = "\
1011decl #0 x : int object external static defined
1012  init
1013    +0
1014      const 1 : int
1015";
1016        assert_eq!(text, expected);
1017    }
1018
1019    #[test]
1020    fn the_macros_are_expanded_before_anything_is_parsed() {
1021        // The whole pipeline in one line. The bound came out of a macro, so it was expanded,
1022        // converted from a preprocessing number to a constant of a type, parsed as an
1023        // expression, and folded to the number the array type carries.
1024        let text = tast("#define N 2\nint a[N];\n");
1025        assert!(text.starts_with("decl #0 a : int[2] object external static tentative"), "{text}");
1026    }
1027
1028    /// A pragma survives the preprocessor on purpose, since what one means is not its
1029    /// business, and nothing after it has a place for a `#` in the grammar. `pack` is the one
1030    /// the parser reads and every other line is walked past. Both spellings are here because
1031    /// they arrive by different routes and only one of them was ever on a line of its own in
1032    /// the source.
1033    #[test]
1034    fn a_pragma_is_not_a_declaration_and_the_parse_walks_past_the_ones_it_does_not_read() {
1035        let text = tast(concat!(
1036            "#pragma pack(4)\n",
1037            "struct s { int a; };\n",
1038            "#pragma pack()\n",
1039            "int b;\n",
1040            "_Pragma(\"GCC visibility push(default)\") int c;\n",
1041        ));
1042        assert!(text.contains("decl #0 b : int"), "{text}");
1043        assert!(text.contains("decl #1 c : int"), "{text}");
1044    }
1045
1046    /// Every number in these two tests was read off gcc 16 on x86-64 under `-std=gnu23`
1047    /// rather than reasoned about, which is why they are written as assertions the program
1048    /// makes about itself: a compilation with no messages is every one of them holding.
1049    ///
1050    /// This half is the attributes. `packed` takes the padding out, on the record or on one
1051    /// member, `aligned` raises and never lowers, and the two written together are the
1052    /// combination that packs and then aligns the whole thing.
1053    #[test]
1054    fn the_layout_attributes_move_the_members_and_the_record_the_way_gcc_lays_them_out() {
1055        tast(concat!(
1056            "struct A { char c; int i; } __attribute__((packed));\n",
1057            "_Static_assert(sizeof(struct A) == 5 && _Alignof(struct A) == 1, \"A\");\n",
1058            "_Static_assert(__builtin_offsetof(struct A, i) == 1, \"A.i\");\n",
1059            // `aligned` with nothing in the parentheses is the largest alignment the target
1060            // has, which gcc calls BIGGEST_ALIGNMENT and which is sixteen everywhere here.
1061            "struct B { char c; int i; } __attribute__((aligned));\n",
1062            "_Static_assert(sizeof(struct B) == 16 && _Alignof(struct B) == 16, \"B\");\n",
1063            "struct C { char c; int i __attribute__((packed)); };\n",
1064            "_Static_assert(sizeof(struct C) == 5 && _Alignof(struct C) == 1, \"C\");\n",
1065            "_Static_assert(__builtin_offsetof(struct C, i) == 1, \"C.i\");\n",
1066            "struct D { char c; int i; } __attribute__((packed, aligned(4)));\n",
1067            "_Static_assert(sizeof(struct D) == 8 && _Alignof(struct D) == 4, \"D\");\n",
1068            "_Static_assert(__builtin_offsetof(struct D, i) == 1, \"D.i\");\n",
1069            "struct E { char c; _Alignas(8) int i; };\n",
1070            "_Static_assert(sizeof(struct E) == 16 && _Alignof(struct E) == 8, \"E\");\n",
1071            "_Static_assert(__builtin_offsetof(struct E, i) == 8, \"E.i\");\n",
1072            "struct F { char c; int i __attribute__((aligned(8))); };\n",
1073            "_Static_assert(sizeof(struct F) == 16 && _Alignof(struct F) == 8, \"F\");\n",
1074            // Two the record already had, so the attribute asks for nothing new, and two
1075            // where four was already there, so the attribute is ignored rather than obeyed.
1076            "struct G { char c; short s; } __attribute__((aligned(2)));\n",
1077            "_Static_assert(sizeof(struct G) == 4 && _Alignof(struct G) == 2, \"G\");\n",
1078            "struct H { char c; int i; } __attribute__((aligned(2)));\n",
1079            "_Static_assert(sizeof(struct H) == 8 && _Alignof(struct H) == 4, \"H\");\n",
1080            // `packed` on a member takes the padding out in front of that member alone, so on
1081            // the first one it does nothing and on the second one it does all of it.
1082            "struct I { [[gnu::packed]] char c; int i; };\n",
1083            "_Static_assert(sizeof(struct I) == 8 && _Alignof(struct I) == 4, \"I\");\n",
1084            "struct J { char c; [[gnu::packed]] int i; };\n",
1085            "_Static_assert(sizeof(struct J) == 5 && _Alignof(struct J) == 1, \"J\");\n",
1086            "struct M { char c; int i : 5; int j : 20; } __attribute__((packed));\n",
1087            "_Static_assert(sizeof(struct M) == 5 && _Alignof(struct M) == 1, \"M\");\n",
1088            "struct N { char c; long long l; } __attribute__((aligned(32)));\n",
1089            "_Static_assert(sizeof(struct N) == 32 && _Alignof(struct N) == 32, \"N\");\n",
1090            "union L { char c; int i; } __attribute__((packed));\n",
1091            "_Static_assert(sizeof(union L) == 4 && _Alignof(union L) == 1, \"L\");\n",
1092            // The armoured spellings, which are the ones a system header writes, since a
1093            // program is entitled to a macro called `packed` and is not entitled to one called
1094            // `__packed__`. The two names are one attribute and the layout is the same one.
1095            "struct O { char c; int i; } __attribute__((__packed__));\n",
1096            "_Static_assert(sizeof(struct O) == 5 && _Alignof(struct O) == 1, \"O\");\n",
1097            "struct P { char c; int i; } __attribute__((__aligned__(8)));\n",
1098            "_Static_assert(sizeof(struct P) == 8 && _Alignof(struct P) == 8, \"P\");\n",
1099        ));
1100    }
1101
1102    /// The same attribute on a declaration rather than on a type, which asks that this object or
1103    /// this function be at a multiple of that, and which is where a program that has to hand a
1104    /// buffer to hardware or keep two counters off one cache line writes it.
1105    ///
1106    /// A raise and never a lower, which is the one place it does not agree with `_Alignas`: below
1107    /// what the type already has, `_Alignas` is a constraint violation and this is ignored without
1108    /// a word. `__alignof__` of the object answers what the object got and not what its type has,
1109    /// because that is the question a program asking it is asking.
1110    #[test]
1111    fn the_aligned_attribute_on_a_declaration_raises_what_that_one_object_is_aligned_to() {
1112        tast(concat!(
1113            "int v __attribute__((aligned(64)));\n",
1114            "_Static_assert(__alignof__(v) == 64, \"v\");\n",
1115            // Written on the specifiers rather than after the declarator, which asks the same
1116            // thing and is the spelling a header is more likely to use.
1117            "__attribute__((aligned(32))) int w;\n",
1118            "_Static_assert(__alignof__(w) == 32, \"w\");\n",
1119            "[[gnu::aligned(16)]] int x;\n",
1120            "_Static_assert(__alignof__(x) == 16, \"x\");\n",
1121            // Two below the four an `int` already has, so nothing is asked for and nothing is
1122            // said, and the type still answers for the object.
1123            "int y __attribute__((aligned(2)));\n",
1124            "_Static_assert(__alignof__(y) == 4, \"y\");\n",
1125            // A local, which is the same question one scope down.
1126            "void f(void) { int a __attribute__((aligned(128)));\n",
1127            "_Static_assert(__alignof__(a) == 128, \"a\"); (void)a; }\n",
1128            // The type is untouched by any of it: `aligned` on a declaration says where that
1129            // declaration goes and says nothing about every other `int` in the program.
1130            "_Static_assert(__alignof__(int) == 4, \"int\");\n",
1131            // A function, which has no alignment of its own for this to be measured against and
1132            // takes whatever was asked for.
1133            "void g(void) __attribute__((aligned(256)));\n",
1134            "void g(void) {}\n",
1135            "_Static_assert(__alignof__(g) == 256, \"g\");\n",
1136        ));
1137    }
1138
1139    /// And what the object file says, which is the half that makes the answer above true. A
1140    /// function is at a fixed offset inside the text section, so it is at a multiple of two
1141    /// hundred and fifty six only if the section is at one too.
1142    #[test]
1143    fn what_a_declaration_asked_to_be_aligned_to_is_what_the_assembler_is_told() {
1144        let text = asm(concat!(
1145            "int v __attribute__((aligned(64)));\n",
1146            "void g(void) __attribute__((aligned(256)));\n",
1147            "void g(void) {}\n",
1148            "void plain(void) {}\n",
1149        ));
1150        assert!(text.contains("\t.p2align\t6\n\t.type\tv, @object\n"), "{text}");
1151        assert!(text.contains("\t.p2align\t8, 0x90\n\t.globl\tg\n"), "{text}");
1152        assert!(text.contains("\t.p2align\t4, 0x90\n\t.globl\tplain\n"), "{text}");
1153    }
1154
1155    /// And the one position where the attribute means something else. On a declaration it raises
1156    /// what that one object is aligned to, and on a typedef it says what the type is aligned to,
1157    /// which gcc lets it lower as well: `typedef int L __attribute__((aligned(2)))` really is an
1158    /// `int` at a multiple of two and a record with one in it really is smaller for it.
1159    ///
1160    /// The size is left alone, which is gcc's answer rather than an omission here. An aligned
1161    /// typedef whose alignment is larger than what it stands for keeps the size it stands for,
1162    /// and gcc refuses an array of one rather than padding the elements out to fit.
1163    #[test]
1164    fn an_aligned_typedef_says_what_an_object_of_it_is_aligned_to_and_may_lower_it() {
1165        tast(concat!(
1166            "typedef int L __attribute__((aligned(2)));\n",
1167            "_Static_assert(__alignof__(L) == 2, \"L\");\n",
1168            "_Static_assert(_Alignof(L) == 2, \"L alignof\");\n",
1169            // Below what an `int` has, which is the half a declaration cannot ask for.
1170            "_Static_assert(sizeof(L) == 4, \"L size\");\n",
1171            "struct T { char c; L x; };\n",
1172            "_Static_assert(sizeof(struct T) == 6, \"T\");\n",
1173            "_Static_assert(__builtin_offsetof(struct T, x) == 2, \"T.x\");\n",
1174            // And upwards, which is the ordinary direction and the one a header writes.
1175            "typedef int H __attribute__((aligned(16)));\n",
1176            "_Static_assert(__alignof__(H) == 16, \"H\");\n",
1177            "_Static_assert(sizeof(H) == 4, \"H size\");\n",
1178            "struct U { char c; H x; };\n",
1179            "_Static_assert(sizeof(struct U) == 32, \"U\");\n",
1180            "_Static_assert(__builtin_offsetof(struct U, x) == 16, \"U.x\");\n",
1181            // A typedef of a typedef, where the nearer one is the one the declaration was
1182            // written with and is the one that answers.
1183            "typedef L M __attribute__((aligned(8)));\n",
1184            "_Static_assert(__alignof__(M) == 8, \"M\");\n",
1185            // And one that asked for nothing, which still has whatever the one behind it asked
1186            // for because it is the same type spelled again.
1187            "typedef L N;\n",
1188            "_Static_assert(__alignof__(N) == 2, \"N\");\n",
1189            // The type it stands for is untouched by any of it.
1190            "_Static_assert(__alignof__(int) == 4, \"int\");\n",
1191        ));
1192        let text = asm(concat!(
1193            "typedef int L __attribute__((aligned(2)));\n",
1194            "typedef int H __attribute__((aligned(16)));\n",
1195            "L low;\n",
1196            "H high;\n",
1197        ));
1198        assert!(text.contains("\t.p2align\t1\n\t.type\tlow, @object\n"), "{text}");
1199        assert!(text.contains("\t.p2align\t4\n\t.type\thigh, @object\n"), "{text}");
1200    }
1201
1202    /// The attribute that builds a type rather than changing a layout. `vector_size(n)` says the
1203    /// declared type is `n` bytes of what was written, taken as lanes, and every operator over
1204    /// one is that operator over each lane.
1205    ///
1206    /// The size is in bytes and not in lanes, which is the part a reader gets backwards: sixteen
1207    /// of `int` is four lanes and sixteen of `char` is sixteen. A vector is aligned to its own
1208    /// size, which is what a machine that has the registers wants and what gcc gives one here.
1209    #[test]
1210    fn the_vector_size_attribute_builds_a_type_of_lanes_and_measures_it_in_bytes() {
1211        tast(concat!(
1212            "typedef int __attribute__((vector_size(16))) v4si;\n",
1213            "_Static_assert(sizeof(v4si) == 16 && _Alignof(v4si) == 16, \"v4si\");\n",
1214            "typedef char __attribute__((vector_size(16))) v16qi;\n",
1215            "_Static_assert(sizeof(v16qi) == 16, \"v16qi\");\n",
1216            // One lane, which is a power of two and is a vector rather than the type it was
1217            // written on: the operators it takes are the vector's and not the scalar's.
1218            "typedef int __attribute__((vector_size(4))) v1si;\n",
1219            "_Static_assert(sizeof(v1si) == 4, \"v1si\");\n",
1220            // The armoured spelling and the bracket one, which are the same attribute.
1221            "typedef float __attribute__((__vector_size__(8))) v2sf;\n",
1222            "_Static_assert(sizeof(v2sf) == 8, \"v2sf\");\n",
1223            "typedef short [[gnu::vector_size(8)]] v4hi;\n",
1224            "_Static_assert(sizeof(v4hi) == 8, \"v4hi\");\n",
1225            // A lane is what a subscript answers with, and a vector is not a pointer: there is
1226            // nothing to decay and the lane type is the one the arithmetic happens in.
1227            "v4si g;\n",
1228            "_Static_assert(sizeof(g[0]) == 4, \"lane\");\n",
1229            "_Static_assert(sizeof(g + g) == 16, \"whole\");\n",
1230            // A scalar beside a vector stands for itself in every lane, so the answer is still
1231            // the vector and not the wider of the two types.
1232            "_Static_assert(sizeof(g + 1) == 16, \"broadcast\");\n",
1233            // An array of them, which is the ordinary way a program holds several.
1234            "_Static_assert(sizeof(v4si[3]) == 48, \"array\");\n",
1235        ));
1236    }
1237
1238    /// A whole vector written into an array of them, and a vector named by a type name rather
1239    /// than by a typedef.
1240    ///
1241    /// Both are the same question asked twice. A vector is filled like an array of its lanes when
1242    /// a list is written into it, so a braced element that is itself a vector has to be taken
1243    /// whole rather than started as the first lane, and the type of what was written is the only
1244    /// thing that says which was meant. And a type name is where a compound literal and a cast
1245    /// spell the type out, which a macro taking a lane type and a lane count does, so the
1246    /// attribute has to be read there and not only on a declaration.
1247    #[test]
1248    fn a_vector_is_written_whole_into_an_array_of_them_and_named_by_a_type_name() {
1249        tast(concat!(
1250            "typedef int __attribute__((vector_size(8))) v2si;\n",
1251            "v2si table[] = { (v2si){ 1, 2 }, (v2si){ 3, 4 } };\n",
1252            "_Static_assert(sizeof(table) == 16, \"two of them and not eight lanes\");\n",
1253            // The size written out rather than named, which is the spelling a macro expands to.
1254            "v2si written = (int __attribute__((vector_size(8)))){ 5, 6 };\n",
1255            "_Static_assert(sizeof((int __attribute__((vector_size(16)))){ 0 }) == 16, \"named\");\n",
1256            // A lane is still a lane, so a list of them fills the vector the way it always did
1257            // and the rule above did not turn brace elision off.
1258            "v2si lanes[2] = { 1, 2, 3, 4 };\n",
1259            "_Static_assert(sizeof(lanes) == 16, \"still elided\");\n",
1260        ));
1261    }
1262
1263    /// A lane written rather than read, and a shift whose two vectors are not the same type.
1264    ///
1265    /// Both are places where a vector is not the aggregate it looks like. A subscript of one is
1266    /// an lvalue because the vector it came from is an object, so a lane can be assigned to and
1267    /// has an address, and a qualifier written on the vector reaches every lane the way it does
1268    /// on an array. And a shift is the one lanewise operator whose sides are not brought to a
1269    /// single type, since the right side counts rather than computes.
1270    #[test]
1271    fn a_lane_is_assignable_and_a_shift_takes_a_count_of_its_own_lane() {
1272        let result = run(
1273            &options(),
1274            concat!(
1275                "typedef int __attribute__((vector_size(16))) v4si;\n",
1276                "typedef unsigned __attribute__((vector_size(16))) v4ui;\n",
1277                "void write(v4si *out, v4ui a, v4si b, int n) {\n",
1278                "  v4si v = { 1, 2, 3, 4 };\n",
1279                "  v[0] = n;\n",
1280                "  v[1] += n;\n",
1281                "  v[2]++;\n",
1282                "  *&v[3] = n;\n",
1283                // The count is signed and the value is not, which no other operator allows.
1284                "  v4ui shifted = a >> b;\n",
1285                "  shifted <<= b;\n",
1286                // A scalar stands in every lane on either side of a shift, which is the half
1287                // that looks wrong: the shape of the answer comes off the count here.
1288                "  *out = v + (v4si)shifted + (1 << b);\n",
1289                "}\n",
1290                // A qualifier on the vector is a qualifier on the lane, so there is nothing here
1291                // to write to.
1292                "void refused(const v4si c) {\n",
1293                "  c[0] = 1;\n",
1294                "}\n",
1295            ),
1296        );
1297        assert_eq!(result.messages.len(), 1, "{:?}", result.messages);
1298        assert!(result.messages[0].contains("assignment of read-only"), "{:?}", result.messages);
1299    }
1300
1301    /// The third layout attribute, and the one that is refused rather than read. Reversing the
1302    /// byte order of every scalar in a record is not something a compiler can do half of, and a
1303    /// compilation that ignored it would lay the record out in the host's order and hand back
1304    /// every field with its bytes the wrong way round. Both spellings are here because a header
1305    /// writes the armoured one, and the member is here because the refusal has to arrive before
1306    /// the layout is used rather than after.
1307    #[test]
1308    fn a_record_that_asks_for_the_other_byte_order_is_refused_rather_than_laid_out_in_this_one() {
1309        let opts = options();
1310        let big = "struct s { int i; } __attribute__((scalar_storage_order(\"big-endian\")));\n";
1311        assert_eq!(
1312            run(&opts, big).messages,
1313            ["/main.c:1:36: error: 'scalar_storage_order' is not implemented yet [E0688]\n\
1314              /main.c:1:36: note: every scalar in this record would be read in the wrong byte \
1315              order"]
1316        );
1317
1318        let armoured =
1319            "struct s { int i; } __attribute__((__scalar_storage_order__(\"little-endian\")));\n";
1320        let messages = run(&opts, armoured).messages;
1321        assert!(messages[0].contains("[E0688]"), "{messages:?}");
1322
1323        // The attribute in front of the body reaches the same list as the one behind it, and
1324        // the C23 spelling in gcc's namespace is the same attribute written a third way.
1325        let front = "struct __attribute__((scalar_storage_order(\"big-endian\"))) s { int i; };\n";
1326        assert!(run(&opts, front).messages[0].contains("[E0688]"), "{front}");
1327        let standard = "struct s { int i; } [[gnu::scalar_storage_order(\"big-endian\")]];\n";
1328        assert!(run(&opts, standard).messages[0].contains("[E0688]"), "{standard}");
1329    }
1330
1331    /// Where a bit-field goes, which packing decides and which is the part of all this that
1332    /// is not what the names suggest. A bit-field goes at the next free bit unless that would
1333    /// make it span more storage than its own type occupies, and then it moves to the next
1334    /// boundary of its alignment. Any packing at all takes that rule out, and `#pragma pack`
1335    /// counts even where it lowers nothing, which is the fourth and seventh cases here.
1336    ///
1337    /// Nothing in the language can be asked where a bit-field is, since `offsetof` refuses one
1338    /// and every size below comes out the same either way, so what is asked is the byte a read
1339    /// of the field loads from.
1340    #[test]
1341    fn packing_is_what_decides_whether_a_bit_field_may_straddle_its_own_storage() {
1342        // A `char` field after twelve bits, which will not straddle unpacked and does packed.
1343        assert_eq!(bit_field_byte("struct s { int x : 12; char y : 6; };"), 2);
1344        assert_eq!(
1345            bit_field_byte("struct s { int x : 12; char y : 6; } __attribute__((packed));"),
1346            1
1347        );
1348        assert_eq!(
1349            bit_field_byte("struct s { int x : 12; __attribute__((packed)) char y : 6; };"),
1350            1
1351        );
1352        assert_eq!(bit_field_byte("#pragma pack(4)\nstruct s { int x : 12; char y : 6; };"), 1);
1353        // A thirty bit field after a byte, which is the case the rule was written for.
1354        assert_eq!(bit_field_byte("struct s { char x; int y : 30; };"), 4);
1355        assert_eq!(bit_field_byte("struct s { char x; int y : 30; } __attribute__((packed));"), 1);
1356        // Four is what an `int` asked for anyway, so this caps nothing and still counts.
1357        assert_eq!(bit_field_byte("#pragma pack(4)\nstruct s { char x; int y : 30; };"), 1);
1358        assert_eq!(bit_field_byte("#pragma pack(2)\nstruct s { char x; int y : 30; };"), 1);
1359    }
1360
1361    /// The byte a read of `s.y` loads from, which is where the bit-field was placed.
1362    fn bit_field_byte(record: &str) -> u64 {
1363        let source = format!("{record}\nint f(struct s *p) {{ return p->y; }}\n");
1364        let body = body(&source);
1365        let Some((before, _)) = body.split_once("ptr_add") else { return 0 };
1366        let (_, constant) = before.rsplit_once("iconst.i64 ").expect("an offset constant");
1367        constant.lines().next().expect("a line").trim().parse().expect("a byte offset")
1368    }
1369
1370    /// An attribute in the middle of a specifier list, which is where a member usually carries
1371    /// one and which was read and then thrown away. The `[[...]]` spelling and whatever was
1372    /// written in front of the declaration are collected as the list is walked and the
1373    /// `__attribute__` spelling is put straight on the specifiers, and the two were assigned
1374    /// over each other rather than joined.
1375    #[test]
1376    fn an_attribute_among_the_specifiers_is_kept_beside_the_ones_written_in_front() {
1377        tast(concat!(
1378            "struct a { char c; __attribute__((aligned(8))) int i; };\n",
1379            "_Static_assert(sizeof(struct a) == 16 && _Alignof(struct a) == 8, \"a\");\n",
1380            "_Static_assert(__builtin_offsetof(struct a, i) == 8, \"a.i\");\n",
1381            "struct b { char c; __attribute__((packed)) int i; };\n",
1382            "_Static_assert(sizeof(struct b) == 5 && _Alignof(struct b) == 1, \"b\");\n",
1383            "_Static_assert(__builtin_offsetof(struct b, i) == 1, \"b.i\");\n",
1384            "typedef struct { char c; int i; } __attribute__((packed)) c;\n",
1385            "_Static_assert(sizeof(c) == 5 && _Alignof(c) == 1, \"c\");\n",
1386        ));
1387    }
1388
1389    /// The other half, which is `#pragma pack`. It caps a member's alignment where `packed`
1390    /// drops it, so `pack(2)` leaves a `short` where it was and moves an `int`, and it caps a
1391    /// member the program asked to align as well, which is where the two differ. It is read
1392    /// at the closing brace of the body, so a line written in the middle of one settles the
1393    /// whole record rather than the members after it, and `push` and `pop` nest.
1394    #[test]
1395    fn pragma_pack_caps_every_member_and_is_read_where_the_body_closes() {
1396        tast(concat!(
1397            "#pragma pack(1)\n",
1398            "struct A { char c; int i; };\n",
1399            "_Static_assert(sizeof(struct A) == 5 && _Alignof(struct A) == 1, \"A\");\n",
1400            "_Static_assert(__builtin_offsetof(struct A, i) == 1, \"A.i\");\n",
1401            "#pragma pack()\n",
1402            "struct B { char c; int i; };\n",
1403            "_Static_assert(sizeof(struct B) == 8 && _Alignof(struct B) == 4, \"B\");\n",
1404            "#pragma pack(2)\n",
1405            "struct C { char c; int i; double d; };\n",
1406            "_Static_assert(sizeof(struct C) == 14 && _Alignof(struct C) == 2, \"C\");\n",
1407            "_Static_assert(__builtin_offsetof(struct C, d) == 6, \"C.d\");\n",
1408            // A member the program aligned, which `pack` caps and `packed` would not.
1409            "struct K { char c; int i __attribute__((aligned(8))); };\n",
1410            "_Static_assert(sizeof(struct K) == 6 && _Alignof(struct K) == 2, \"K\");\n",
1411            "_Static_assert(__builtin_offsetof(struct K, i) == 2, \"K.i\");\n",
1412            // The record's own `aligned` is not a member's, so it is not capped.
1413            "struct J { char c; int i; } __attribute__((aligned(8)));\n",
1414            "_Static_assert(sizeof(struct J) == 8 && _Alignof(struct J) == 8, \"J\");\n",
1415            "#pragma pack()\n",
1416            "#pragma pack(push, 1)\n",
1417            "struct D { char c; short s; };\n",
1418            "_Static_assert(sizeof(struct D) == 3 && _Alignof(struct D) == 1, \"D\");\n",
1419            "#pragma pack(pop)\n",
1420            "struct E { char c; short s; };\n",
1421            "_Static_assert(sizeof(struct E) == 4 && _Alignof(struct E) == 2, \"E\");\n",
1422            // Written in the middle of a body, and it still settles the whole record.
1423            "struct H { char c;\n",
1424            "#pragma pack(1)\n",
1425            "  int i; };\n",
1426            "_Static_assert(sizeof(struct H) == 5 && _Alignof(struct H) == 1, \"H\");\n",
1427            "#pragma pack(1)\n",
1428            "struct I { char c;\n",
1429            "#pragma pack()\n",
1430            "  int i; };\n",
1431            "_Static_assert(sizeof(struct I) == 8 && _Alignof(struct I) == 4, \"I\");\n",
1432            "#pragma pack()\n",
1433            // Nested pushes, each one giving back what the one under it had.
1434            "#pragma pack(push, 8)\n",
1435            "#pragma pack(push, 1)\n",
1436            "struct P { char c; int i; };\n",
1437            "_Static_assert(sizeof(struct P) == 5 && _Alignof(struct P) == 1, \"P\");\n",
1438            "#pragma pack(pop)\n",
1439            "struct Q { char c; int i; };\n",
1440            "_Static_assert(sizeof(struct Q) == 8 && _Alignof(struct Q) == 4, \"Q\");\n",
1441            "#pragma pack(pop)\n",
1442            // A cap above what every member already asks for changes nothing at all.
1443            "#pragma pack(16)\n",
1444            "struct R { char c; int i; };\n",
1445            "_Static_assert(sizeof(struct R) == 8 && _Alignof(struct R) == 4, \"R\");\n",
1446            "#pragma pack()\n",
1447            "#pragma pack(1)\n",
1448            "struct S { char c; int i : 5; int j : 20; };\n",
1449            "_Static_assert(sizeof(struct S) == 5 && _Alignof(struct S) == 1, \"S\");\n",
1450            "union T { char c; int i; };\n",
1451            "_Static_assert(sizeof(union T) == 4 && _Alignof(union T) == 1, \"T\");\n",
1452            "#pragma pack()\n",
1453        ));
1454    }
1455
1456    /// A line the reader cannot make sense of is a warning and the line is dropped, which is
1457    /// what GCC does with one, and these are its words for each of them. The last line is the
1458    /// one nothing else would reach, since it stands after every record in the file.
1459    #[test]
1460    fn a_pack_line_that_is_not_one_is_reported_in_the_words_gcc_uses() {
1461        let result = run(
1462            &options(),
1463            concat!(
1464                "#pragma pack 4\n",
1465                "#pragma pack(pop)\n",
1466                "#pragma pack(3)\n",
1467                "#pragma pack(1) junk\n",
1468                "#pragma pack(push, 1\n",
1469                "#pragma pack(x)\n",
1470                // These two are well formed and say nothing. Zero is how a line asks for the
1471                // target's own alignments back without writing empty parentheses.
1472                "#pragma pack(0)\n",
1473                "#pragma pack(push)\n",
1474                "struct s { char c; int i; };\n",
1475                "#pragma pack(pop)\n",
1476                "#pragma pack(pop, foo)\n",
1477            ),
1478        );
1479        let expected = [
1480            "missing `(` after `#pragma pack` - ignored",
1481            "`#pragma pack (pop)` encountered without matching `#pragma pack (push)`",
1482            "alignment must be a small power of two, not 3",
1483            "junk at end of `#pragma pack`",
1484            "malformed `#pragma pack(push[, id][, <n>])` - ignored",
1485            "unknown action `x` for `#pragma pack` - ignored",
1486            "`#pragma pack(pop, foo)` encountered without matching `#pragma pack(push, foo)`",
1487        ];
1488        assert_eq!(result.messages.len(), expected.len(), "{:?}", result.messages);
1489        for (message, want) in result.messages.iter().zip(expected) {
1490            assert!(message.contains(want), "expected {want:?} in {message:?}");
1491        }
1492    }
1493
1494    /// The two typedef spellings of the 128 bit types. gcc offers them as keywords rather
1495    /// than as typedefs in a header, which is the only way a program that includes nothing at
1496    /// all can still use them, and Apple's `<mach/arm/_structs.h>` is one such program.
1497    #[test]
1498    fn the_wide_integer_answers_to_all_three_of_its_names() {
1499        let text = tast("__uint128_t a; __int128_t b; unsigned __int128 c;\n");
1500        assert!(text.contains("decl #0 a : unsigned __int128"), "{text}");
1501        assert!(text.contains("decl #1 b : __int128"), "{text}");
1502        assert!(text.contains("decl #2 c : unsigned __int128"), "{text}");
1503    }
1504
1505    #[test]
1506    fn every_conversion_the_language_performs_is_a_node_in_the_output() {
1507        // The point of a typed tree. The source has one operator and the output has the
1508        // widening that operator asked for, spelled out, so that nothing downstream has to
1509        // work out the conversion rules a second time.
1510        let text = tast("long f(int a, long b) { return a + b; }\n");
1511        assert!(text.contains("convert arithmetic"), "{text}");
1512    }
1513
1514    #[test]
1515    fn a_mistake_in_each_phase_reaches_the_caller_and_writes_no_tree() {
1516        for source in [
1517            "#error stop\n",
1518            "int f(void) { return 1 + ; }\n",
1519            "int f(void) { return undeclared; }\n",
1520        ] {
1521            let result = run(&options(), source);
1522            assert!(result.failed(), "expected this to fail:\n{source}");
1523            assert!(
1524                result.text().is_empty(),
1525                "a file that did not compile wrote a tree:\n{source}"
1526            );
1527        }
1528    }
1529
1530    #[test]
1531    fn one_undeclared_name_is_one_message_and_not_one_per_use() {
1532        // The poisoning rule from `spec/06-lexer-and-parser.md` section 6.8, seen from the
1533        // outside. Three uses of a name that was never declared, and the operators over them
1534        // say nothing at all.
1535        let result = run(&options(), "int f(void) { return nope + nope * nope; }\n");
1536        assert_eq!(result.errors, 1, "{:?}", result.messages);
1537    }
1538
1539    #[test]
1540    fn a_declaration_the_parser_skipped_does_not_become_an_undeclared_name_as_well() {
1541        // The reason the checking is skipped after a failed parse. The parser gave up on the
1542        // first line and there is no `x` in the tree, so a checker run over it would report
1543        // every use of `x` below as undeclared, which is a second message about one mistake.
1544        let result = run(&options(), "int x = ;\nint f(void) { return x; }\n");
1545        assert_eq!(result.errors, 1, "{:?}", result.messages);
1546    }
1547
1548    #[test]
1549    fn werror_turns_a_warning_into_an_error_in_the_count_and_in_the_word() {
1550        let source = "int f(void) { char c = 300; return c; }\n";
1551        let plain = run(&options(), source);
1552        assert_eq!(plain.errors, 0, "{:?}", plain.messages);
1553        assert_eq!(plain.messages.len(), 1, "expected a warning about the narrowed constant");
1554        assert!(!plain.text().is_empty(), "a warning is not a reason to write nothing");
1555
1556        let mut opts = options();
1557        opts.warnings_are_errors = true;
1558        let strict = run(&opts, source);
1559        assert!(strict.failed());
1560        assert!(strict.text().is_empty(), "and under -Werror it is a reason to write nothing");
1561        for message in &strict.messages {
1562            assert!(!message.contains("warning:"), "{message}");
1563        }
1564    }
1565
1566    #[test]
1567    fn w_drops_the_warning_before_werror_can_promote_it() {
1568        let source = "int f(void) { char c = 300; return c; }\n";
1569        let mut opts = options();
1570        opts.warnings = false;
1571        let quiet = run(&opts, source);
1572        assert_eq!(quiet.messages, Vec::<String>::new());
1573        assert_eq!(quiet.errors, 0);
1574        assert!(!quiet.text().is_empty(), "and the file still compiles");
1575
1576        // A build that passes both means it wants neither, and the order it wrote them in is not
1577        // something to make it think about.
1578        opts.warnings_are_errors = true;
1579        let both = run(&opts, source);
1580        assert_eq!(both.messages, Vec::<String>::new());
1581        assert!(!both.failed(), "-w -Werror is not an error about a warning nobody saw");
1582    }
1583
1584    #[test]
1585    fn the_dialect_reaches_the_keywords_and_the_checking() {
1586        // `typeof` is C23's and GNU's, so the same source is a declaration under one dialect
1587        // and a mistake under the other, which is the keyword table being built per dialect.
1588        let source = "typeof(1) x;\n";
1589        let mut opts = options();
1590        opts.std = Std::C23;
1591        opts.gnu_extensions = false;
1592        assert!(!run(&opts, source).failed(), "{:?}", run(&opts, source).messages);
1593
1594        opts.std = Std::C17;
1595        assert!(run(&opts, source).failed());
1596    }
1597
1598    #[test]
1599    fn asking_for_a_kind_that_is_not_written_yet_runs_the_front_end_and_writes_nothing() {
1600        let mut opts = options();
1601        opts.emit = EmitKind::Object;
1602        let result = run(&opts, "int x = 1;\n");
1603        assert!(!result.failed(), "{:?}", result.messages);
1604        assert!(result.text().is_empty());
1605        // And it still finds what the checking finds, so a later kind on a broken file is not
1606        // a silent success.
1607        assert!(run(&opts, "int f(void) { return undeclared; }\n").failed());
1608    }
1609
1610    /// The machine code of `source`, insisting that it compiled cleanly.
1611    fn mir(source: &str) -> String {
1612        let mut opts = options();
1613        opts.emit = EmitKind::MirFinal;
1614        let result = run(&opts, source);
1615        assert_eq!(result.messages, Vec::<String>::new(), "expected this to compile:\n{source}");
1616        result.text().to_owned()
1617    }
1618
1619    /// The whole compiler in one assertion, which is what this emit kind is for.
1620    ///
1621    /// C in, machine instructions out, every register a real one and every frame offset a
1622    /// number. Everything between the two is checked somewhere else, one pass at a time. What is
1623    /// checked here is that the passes are joined up and that the driver runs them.
1624    #[test]
1625    fn a_function_goes_from_c_to_instructions_with_real_registers_in_them() {
1626        let text = mir("int add(int a, int b) { return a + b; }\n");
1627        assert!(text.starts_with("mfunc @add {"), "{text}");
1628        assert!(text.contains("x64.add_rr_32"), "{text}");
1629        assert!(text.contains("x64.ret"), "{text}");
1630        // A virtual register is what the allocator was there to remove, so one left in the
1631        // output is the difference between code and something that looks like code.
1632        assert!(!text.contains('%'), "{text}");
1633    }
1634
1635    /// A declaration has no body, so there is nothing to generate for one and nothing is.
1636    #[test]
1637    fn a_function_with_no_body_produces_no_machine_function() {
1638        let text = mir("int g(int);\nint f(int a) { return g(a); }\n");
1639        assert_eq!(text.matches("mfunc @").count(), 1, "{text}");
1640        assert!(text.contains("mfunc @f {"), "{text}");
1641        assert!(text.contains("x64.call"), "{text}");
1642    }
1643
1644    /// Two functions come out in the order the module holds them, which is source order.
1645    #[test]
1646    fn every_definition_in_the_file_is_generated_and_they_keep_their_order() {
1647        let text = mir("int a(int x) { return x; }\nint b(int x) { return x; }\n");
1648        let first = text.find("mfunc @a").expect("the first function");
1649        let second = text.find("mfunc @b").expect("the second function");
1650        assert!(first < second, "{text}");
1651    }
1652
1653    /// The target reaches the back end, so the same C is different instructions on Windows.
1654    #[test]
1655    fn the_target_decides_which_convention_the_generated_code_follows() {
1656        let mut opts = options();
1657        opts.emit = EmitKind::MirFinal;
1658        let linux = run(&opts, "int f(int a) { return a; }\n").text().to_owned();
1659        assert!(linux.contains("$rdi"), "{linux}");
1660
1661        opts.target = "x86_64-pc-windows-msvc".parse::<Triple>().unwrap();
1662        let windows = run(&opts, "int f(int a) { return a; }\n").text().to_owned();
1663        assert!(windows.contains("$rcx"), "{windows}");
1664        assert!(!windows.contains("$rdi"), "{windows}");
1665    }
1666
1667    /// A target with no back end says so rather than generating something for another machine.
1668    #[test]
1669    fn a_target_this_has_no_back_end_for_is_reported_rather_than_generated() {
1670        let mut opts = options();
1671        opts.emit = EmitKind::MirFinal;
1672        opts.target = "aarch64-unknown-linux-gnu".parse::<Triple>().unwrap();
1673        let result = run(&opts, "int f(int a) { return a; }\n");
1674        assert!(result.failed());
1675        assert!(result.messages[0].contains("no back end for aarch64"), "{:?}", result.messages);
1676        assert!(result.text().is_empty());
1677    }
1678
1679    /// A construct the rule set does not reach yet is named, along with the function it is in.
1680    ///
1681    /// The message is about this compiler being unfinished rather than about the program, which
1682    /// is valid C either way, so it carries the note that says where the work is tracked. Both
1683    /// functions are attempted, so a file that is ahead of the back end in three places says so
1684    /// three times rather than one recompilation at a time.
1685    #[test]
1686    fn a_construct_the_back_end_cannot_reach_yet_is_reported_against_its_function() {
1687        let mut opts = options();
1688        opts.emit = EmitKind::MirFinal;
1689        let source = "void a(int n) { int v[n]; v[0] = 1; }\n\
1690                      void b(int n) { int v[n]; v[0] = 1; }\n";
1691        let result = run(&opts, source);
1692        assert!(result.failed());
1693        assert_eq!(result.messages.len(), 2, "{:?}", result.messages);
1694        assert!(result.messages[0].contains("cannot generate code for 'a'"), "{:?}", result);
1695        assert!(result.messages[0].contains("no rule lowers a `stacksave`"), "{:?}", result);
1696        assert!(result.messages[1].contains("cannot generate code for 'b'"), "{:?}", result);
1697        assert!(result.text().is_empty());
1698    }
1699
1700    /// An opcode the rule language has no word for is named anyway, and pointed at.
1701    ///
1702    /// The rule language's spelling is the better name when there is one, but an opcode it has
1703    /// no word for is exactly the opcode no rule lowers, so falling back to the opcode and the
1704    /// type is what makes the message say anything at all in the cases that happen. The span is
1705    /// the instruction's own, so the message lands on the line rather than on the file.
1706    #[test]
1707    fn an_opcode_with_no_name_in_the_rule_language_is_named_by_its_own_spelling() {
1708        let mut opts = options();
1709        opts.emit = EmitKind::MirFinal;
1710        let result = run(&opts, "int f(int a) {\n  __int128 wide = a;\n  return (int) wide;\n}\n");
1711        assert!(result.failed());
1712        assert!(
1713            result.messages[0].contains("no rule lowers a `sext` producing a `i128`"),
1714            "{result:?}"
1715        );
1716        assert!(result.messages[0].contains(":2:"), "the line the widening is on: {result:?}");
1717        assert!(!result.messages[0].contains("this instruction"), "{result:?}");
1718    }
1719
1720    /// The note names the issue tracker, which is where a reader finds out whether it is known.
1721    #[test]
1722    fn the_note_on_unfinished_work_points_at_the_issues_rather_than_at_the_plan() {
1723        let mut opts = options();
1724        opts.emit = EmitKind::MirFinal;
1725        let result = run(&opts, "int f(int a) { __int128 wide = a; return (int) wide; }\n");
1726        assert!(result.failed());
1727        let note = result.messages.iter().find(|line| line.contains("note:")).expect("a note");
1728        assert!(note.contains("https://github.com/tamnd/rucc/issues"), "{note}");
1729        assert!(!note.contains("spec/17-milestones.md"), "{note}");
1730    }
1731
1732    /// The two frame flags reach the frame, which is the only thing either of them does.
1733    #[test]
1734    fn the_frame_flags_on_the_command_line_reach_the_generated_frame() {
1735        let source = "int f(int a) { return a; }\n";
1736        assert!(!mir(source).contains("$rbp"), "a leaf needs no frame pointer by default");
1737
1738        let mut opts = options();
1739        opts.emit = EmitKind::MirFinal;
1740        opts.frame_pointer = true;
1741        let kept = run(&opts, source).text().to_owned();
1742        assert!(kept.contains("x64.push_64 $rbp"), "{kept}");
1743    }
1744
1745    /// The assembly of `source`, insisting that it compiled cleanly.
1746    fn asm(source: &str) -> String {
1747        let mut opts = options();
1748        opts.emit = EmitKind::Asm;
1749        let result = run(&opts, source);
1750        assert_eq!(result.messages, Vec::<String>::new(), "expected this to compile:\n{source}");
1751        result.text().to_owned()
1752    }
1753
1754    /// `-S`, which is the same compiler as the kind above it with a different last step.
1755    ///
1756    /// What the assembly says is checked in `rucc-asm`, one instruction at a time and against the
1757    /// target's own description of what an instruction is. What is checked here is that a C file
1758    /// goes all the way to a listing an assembler would take, which means the directives around
1759    /// the function as well as the instructions in it.
1760    #[test]
1761    fn a_function_goes_from_c_to_assembly_an_assembler_would_take() {
1762        let text = asm("int add(int a, int b) { return a + b; }\n");
1763        assert!(text.contains("\t.globl\tadd\n"), "{text}");
1764        assert!(text.contains("\t.type\tadd, @function\n"), "{text}");
1765        assert!(text.contains("\nadd:\n"), "{text}");
1766        assert!(text.contains("\taddl\t"), "{text}");
1767        assert!(text.contains("\tret\n"), "{text}");
1768        assert!(text.contains("\t.size\tadd, .-add\n"), "{text}");
1769        // Without this the stack the program runs on is executable, which is not a default
1770        // anybody chose and is not a thing a reader would notice missing.
1771        assert!(text.contains(".note.GNU-stack"), "{text}");
1772    }
1773
1774    /// A call through a function pointer, which is a different instruction from a call to a name.
1775    ///
1776    /// Both are in the one function on purpose. What is being read is that the two calls are told
1777    /// apart all the way down: one carries a name the linker resolves and one carries a register,
1778    /// and neither turns into the other on the way.
1779    #[test]
1780    fn a_call_through_a_function_pointer_goes_through_the_register_it_is_in() {
1781        let text = asm("int g(int);\nint f(int (*p)(int), int a) { return p(a) + g(a); }\n");
1782        assert!(text.contains("\tcall\t*%"), "{text}");
1783        assert!(text.contains("\tcall\tg\n"), "{text}");
1784        // The address arrived in the first argument register and the argument the call passes has
1785        // to end up there, so the two cannot be the same register and the compiler has to have
1786        // moved one of them.
1787        assert!(text.contains("%rdi"), "{text}");
1788    }
1789
1790    /// A name at file scope, which is the one address a function cannot compute for itself. The
1791    /// `lea` that computes it is folded into the load that reads through it, so what is left to
1792    /// read is the addressing mode, which is where the instruction pointer shows up.
1793    #[test]
1794    fn the_address_of_a_global_is_read_from_the_instruction_pointer() {
1795        let text = asm("extern int counter;\nint f(void) { return counter; }\n");
1796        assert!(text.contains("\tmovl\tcounter(%rip), %eax\n"), "{text}");
1797    }
1798
1799    /// A cast between a pointer and an integer as wide as one, which is every one C writes here.
1800    #[test]
1801    fn a_cast_between_a_pointer_and_an_integer_leaves_the_value_where_it_is() {
1802        let text = asm("long f(void *p) { return (long)p; }\n");
1803        // Every instruction in the body is a full width move or the return. The copies are the
1804        // allocator taking no hints, and what matters here is what is not among them: nothing
1805        // narrows the value and nothing widens it again, which is what a cast that did something
1806        // would look like.
1807        for line in text.lines().filter(|line| line.starts_with('\t') && !line.contains('.')) {
1808            let mnemonic = line.split_whitespace().next().unwrap_or("");
1809            assert!(matches!(mnemonic, "movq" | "ret"), "{line} in\n{text}");
1810        }
1811    }
1812
1813    /// The arguments past the sixth arrive in the caller's memory rather than in a register, and
1814    /// where that memory is depends on what the prologue did, so this is checked at the end of the
1815    /// pipeline rather than in the middle of it.
1816    #[test]
1817    fn an_argument_past_the_last_register_is_read_out_of_the_caller_s_stack() {
1818        let six = "long a, long b, long c, long d, long e, long f";
1819        let text = asm(&format!("long f({six}, long g, long h) {{ return g + h; }}\n"));
1820
1821        // Nothing is pushed and no frame is taken, so the only thing between the stack pointer and
1822        // the caller's arguments is the return address the call pushed. Which is where gcc 16.2.0
1823        // reads them from too, at `-O0`, in the same two instructions.
1824        assert!(text.contains("\tmovq\t8(%rsp), "), "{text}");
1825        assert!(text.contains("\tmovq\t16(%rsp), "), "{text}");
1826
1827        // A narrower one is read at its own width, because the bits above it are bits the
1828        // convention says nothing about, and one in the other register file with the other file's
1829        // instruction.
1830        let narrow = asm(&format!("int f({six}, int g) {{ return g; }}\n"));
1831        assert!(narrow.contains("\tmovl\t8(%rsp), "), "{narrow}");
1832        let eight =
1833            "double a, double b, double c, double d, double e, double f, double g, double h";
1834        let float = asm(&format!("double f({eight}, double i) {{ return i; }}\n"));
1835        assert!(float.contains("\tmovsd\t8(%rsp), "), "{float}");
1836    }
1837
1838    /// The other end of the same thing. What the caller writes is at the stack pointer, because
1839    /// that is the bottom of its frame and the bottom of its frame is where the callee looks.
1840    #[test]
1841    fn a_call_writes_the_arguments_with_no_register_left_at_the_stack_pointer() {
1842        let six = "1, 2, 3, 4, 5, 6";
1843        let decl = "long g(long, long, long, long, long, long, long, long);\n";
1844        let text = asm(&format!("{decl}long f(void) {{ return g({six}, 7, 8); }}\n"));
1845
1846        assert!(text.contains("\tmovq\t%"), "{text}");
1847        assert!(text.contains(", (%rsp)\n"), "{text}");
1848        assert!(text.contains(", 8(%rsp)\n"), "{text}");
1849        // And it reserved the bytes it wrote into, so nothing else in the frame is on top of them.
1850        assert!(text.contains("\tsubq\t$"), "{text}");
1851
1852        // A narrower one is written at its own width, matching what the callee reads it back with.
1853        let narrow = "int g(int, int, int, int, int, int, int);\n";
1854        let text = asm(&format!("{narrow}int f(void) {{ return g({six}, 7); }}\n"));
1855        assert!(text.contains("\tmovl\t%"), "{text}");
1856        assert!(text.contains(", (%rsp)\n"), "{text}");
1857    }
1858
1859    /// The count a variadic callee on this convention reads is a count of vector registers, so a
1860    /// float that ran out of them and went to memory is not in it.
1861    #[test]
1862    fn a_variadic_call_counts_registers_and_not_arguments() {
1863        let nine = "1., 2., 3., 4., 5., 6., 7., 8., 9.";
1864        let decl = "int g(int, ...);\n";
1865        let text = asm(&format!("{decl}int f(void) {{ return g(0, {nine}); }}\n"));
1866
1867        assert!(text.contains("\tmovl\t$8, "), "eight registers, not nine: {text}");
1868        assert!(text.contains("\tmovsd\t%"), "{text}");
1869        assert!(text.contains(", (%rsp)\n"), "{text}");
1870    }
1871
1872    /// The callee's half of the same convention. Every argument register it was handed is written
1873    /// into its frame on the way in, because which of them hold anything is a thing only the caller
1874    /// knew, and the ones the signature does name are left out because `va_start` sets the offsets
1875    /// past them and nothing ever reads their slots.
1876    #[test]
1877    fn a_variadic_function_writes_the_argument_registers_it_was_handed_into_its_frame() {
1878        let body =
1879            "__builtin_va_list ap; __builtin_va_start(ap, n); __builtin_va_end(ap); return n;";
1880        let text = asm(&format!("int f(int n, ...) {{ {body} }}\n"));
1881
1882        // Five general purpose registers and eight vector ones, since the one parameter the
1883        // signature names took the first of the six.
1884        let stores = |mnemonic: &str| text.matches(&format!("\t{mnemonic}\t%")).count();
1885        assert!(text.contains(", 8(%r"), "the second slot, not the first: {text}");
1886        assert!(!text.contains(", 0(%r"), "{text}");
1887        assert_eq!(stores("movsd"), 8, "every vector register: {text}");
1888
1889        // And the area is one of the function's own stack objects, so the frame holds it.
1890        assert!(text.contains("\tsubq\t$"), "{text}");
1891    }
1892
1893    /// What `va_start` writes is the four fields of the list, and the two numbers among them are
1894    /// where the arguments the signature names left the walk over each file's registers.
1895    #[test]
1896    fn va_start_writes_the_four_fields_the_psabi_describes() {
1897        let start = "__builtin_va_list ap; __builtin_va_start(ap, d);";
1898        let params = "int a, int b, int c, double d";
1899        let text = asm(&format!("int f({params}, ...) {{ {start} return a; }}\n"));
1900
1901        // Three integers took three of the six general purpose registers, and one double took one
1902        // of the eight vector ones, so the walk starts at twenty four bytes into the first half and
1903        // sixteen bytes into the second, which begins at forty eight.
1904        assert!(text.contains("	movl	$24, "), "{text}");
1905        assert!(text.contains("	movl	$64, "), "{text}");
1906        // The other two fields are addresses rather than numbers, so each is stored as a word and
1907        // each is a `lea` away. One of them reaches above the frame, which is where the caller's
1908        // arguments are and is the only thing in this function that is not below the stack pointer.
1909        assert!(text.contains(", 8(%r"), "{text}");
1910        assert!(text.contains(", 16(%r"), "{text}");
1911        let frame: u32 = text
1912            .lines()
1913            .find_map(|line| line.trim().strip_prefix("subq	$")?.split(',').next()?.parse().ok())
1914            .expect("a variadic function takes a frame for the save area");
1915        let above = |line: &str| {
1916            let at: u32 = line.trim().strip_prefix("leaq	")?.split('(').next()?.parse().ok()?;
1917            Some(at > frame)
1918        };
1919        assert!(text.lines().filter_map(above).any(|it| it), "{frame}: {text}");
1920    }
1921
1922    /// A `va_arg` is a branch on whether the argument it wants is still in the save area, and which
1923    /// of the two halves it walks is the type's answer.
1924    #[test]
1925    fn va_arg_branches_on_whether_the_argument_is_still_in_the_save_area() {
1926        let read = "__builtin_va_list ap; __builtin_va_start(ap, n);";
1927        let ints = format!("int f(int n, ...) {{ {read} return __builtin_va_arg(ap, int); }}\n");
1928        let text = asm(&ints);
1929
1930        // The last general purpose slot begins at forty, so an offset above it is an argument the
1931        // caller left in its own memory instead.
1932        assert!(text.contains("$40, "), "{text}");
1933        assert!(text.contains("	cmpl	"), "{text}");
1934        assert!(text.contains("	setbe	"), "unsigned, since an offset is a count of bytes: {text}");
1935
1936        let arg = "__builtin_va_arg(ap, double)";
1937        let text = asm(&format!("double f(int n, ...) {{ {read} return {arg}; }}\n"));
1938        assert!(text.contains("$160, "), "the last vector slot: {text}");
1939    }
1940
1941    /// A structure assigned is a copy of a known size, and a copy of a known size is a run of
1942    /// moves rather than a call to a library this compiler has no way to reach yet.
1943    #[test]
1944    fn a_structure_assignment_is_a_move_for_each_word_of_it() {
1945        let decl = "struct pair { long a, b; };\n";
1946        let body = "struct pair p = *q; return p.a + p.b;";
1947        let text = asm(&format!("{decl}long f(struct pair *q) {{ {body} }}\n"));
1948
1949        assert!(!text.contains("memcpy"), "nothing calls the library: {text}");
1950        assert!(!text.contains("\tcall"), "{text}");
1951        // Sixteen bytes aligned to eight is two words, and each is a load and a store.
1952        assert!(text.matches("\tmovq\t").count() >= 4, "two words each way: {text}");
1953    }
1954
1955    /// A word is as wide as the object is aligned to and no wider, so a character array is copied
1956    /// a byte at a time and a structure of longs eight bytes at a time.
1957    #[test]
1958    fn how_wide_a_word_of_a_copy_is_follows_the_alignment() {
1959        let decl = "struct bytes { char a[8]; };\n";
1960        let body = "struct bytes p = *q; return p.a[0];";
1961        let text = asm(&format!("{decl}int f(struct bytes *q) {{ {body} }}\n"));
1962
1963        // Eight bytes aligned to one is eight words, and each is a load and a store.
1964        assert!(text.matches("\tmovb\t").count() >= 16, "a byte at a time: {text}");
1965    }
1966
1967    /// What an initialiser does not name is zero, which the front end writes as a fill and this
1968    /// writes as the byte spread across each word.
1969    #[test]
1970    fn the_part_of_an_initialiser_that_names_nothing_is_stored_as_zero() {
1971        let decl = "struct wide { long a, b, c; };\n";
1972        let text = asm(&format!("{decl}long f(void) {{ struct wide w = {{ 7 }}; return w.c; }}\n"));
1973
1974        assert!(!text.contains("memset"), "nothing calls the library: {text}");
1975        assert!(text.contains("\tmovq\t$0, ") || text.contains("$0, %"), "the zero: {text}");
1976    }
1977
1978    /// A copy too large to be worth unrolling is a call to the runtime, which is the C library on
1979    /// a hosted target and `rucc-builtins` on a freestanding one.
1980    #[test]
1981    fn a_copy_too_large_to_unroll_calls_the_runtime() {
1982        let decl = "struct huge { char a[4096]; };\n";
1983        let mut opts = options();
1984        opts.emit = EmitKind::Asm;
1985        let source = format!("{decl}void f(struct huge *p, struct huge *q) {{ *p = *q; }}\n");
1986        let result = run(&opts, &source);
1987        assert!(!result.failed(), "{:?}", result.messages);
1988        let text = result.text();
1989        assert!(text.contains("call") && text.contains("memcpy"), "{text}");
1990        // The size in the register the convention passes the third argument in, which is what
1991        // says the call was built from the convention and not from the shape of the IR.
1992        assert!(text.contains("4096"), "the size travels: {text}");
1993    }
1994
1995    /// A frame that had to force its own alignment cannot say how far away the caller's stack
1996    /// pointer was, so it reaches back through the frame pointer instead.
1997    #[test]
1998    fn a_realigned_frame_reads_them_through_the_frame_pointer() {
1999        let six = "long a, long b, long c, long d, long e, long f";
2000        let body = "_Alignas(32) long wide[4]; wide[0] = g; return wide[0];";
2001        let text = asm(&format!("long f({six}, long g) {{ {body} }}\n"));
2002
2003        // The frame pointer is saved and pointed at where it was saved before the alignment is
2004        // forced, so the caller's arguments stay a constant distance from it: one word for the
2005        // saved frame pointer and one for the return address.
2006        assert!(text.contains("\tandq\t$-32, %rsp"), "{text}");
2007        assert!(text.contains("\tmovq\t16(%rbp), "), "{text}");
2008        assert!(!text.contains("\tmovq\t16(%rsp), "), "{text}");
2009    }
2010
2011    /// The object format decides the directives, and the target decides the object format.
2012    #[test]
2013    fn the_target_decides_how_the_assembly_is_spelled() {
2014        let mut opts = options();
2015        opts.emit = EmitKind::Asm;
2016        opts.target = "x86_64-apple-darwin".parse::<Triple>().unwrap();
2017        let text = run(&opts, "int f(void) { return 0; }\n").text().to_owned();
2018        assert!(text.contains("__TEXT,__text"), "{text}");
2019        assert!(text.contains("\n_f:\n"), "{text}");
2020        assert!(!text.contains(".note.GNU-stack"), "{text}");
2021    }
2022
2023    /// The object file of `source`, insisting that it compiled cleanly.
2024    fn obj(source: &str) -> Vec<u8> {
2025        let mut opts = options();
2026        opts.emit = EmitKind::Object;
2027        let result = run(&opts, source);
2028        assert_eq!(result.messages, Vec::<String>::new(), "expected this to compile:\n{source}");
2029        match result.artifact {
2030            Artifact::Object(bytes) => bytes,
2031            other => panic!("expected an object, got {other:?}"),
2032        }
2033    }
2034
2035    /// `-c`, which is the last step of the three the back end can end with.
2036    ///
2037    /// What is in the file is checked in `rucc-object`, a field at a time. What is checked here is
2038    /// that a C file goes all the way to one, which is the whole compiler in one line and the
2039    /// thing that stops working when a layer between them changes its mind about something.
2040    #[test]
2041    fn a_function_goes_from_c_to_an_object_a_linker_would_take() {
2042        let bytes = obj("int add(int a, int b) { return a + b; }\n");
2043        assert_eq!(&bytes[..4], b"\x7fELF", "an object file starts by saying it is one");
2044        let text = asm("int add(int a, int b) { return a + b; }\n");
2045        assert!(
2046            text.contains("\taddl\t"),
2047            "and the listing of it is the same instructions:\n{text}"
2048        );
2049    }
2050
2051    /// A variable this file defines, which is what a reference to one has to resolve against.
2052    #[test]
2053    fn a_variable_goes_from_c_to_the_section_it_belongs_in() {
2054        let text = asm("int counter = 42;\nstatic int hidden;\nconst int fixed = 7;\n");
2055        assert!(text.contains("\t.data\n\t.globl\tcounter\n"), "{text}");
2056        assert!(text.contains("\ncounter:\n\t.long\t42\n"), "{text}");
2057        assert!(text.contains("\t.size\tcounter, .-counter\n"), "{text}");
2058        // A zeroed variable carries its size and none of its bytes, and a `static` one is not
2059        // announced to the linker at all, which is the whole of what `static` means here.
2060        assert!(text.contains("\t.bss\n\t.p2align\t2\n"), "{text}");
2061        assert!(text.contains("\nhidden:\n\t.space\t4\n"), "{text}");
2062        assert!(!text.contains(".globl\thidden"), "{text}");
2063        // Nothing writes through it, so it goes in a page the loader can map read only and every
2064        // process running the program can share.
2065        assert!(text.contains("\t.section\t.rodata\n"), "{text}");
2066    }
2067
2068    /// A bit-field with a value in it, which is written as the bytes the value lands in.
2069    ///
2070    /// The interesting one is the field whose lowest byte is zero. The bytes a bit-field
2071    /// initializer makes are put together first and then taken back out as the run they make,
2072    /// and taking them out starts at the byte the field starts at, so a zero byte at the front
2073    /// used to end the object up in `.bss` with the rest of its value thrown away.
2074    #[test]
2075    fn a_bit_field_initializer_writes_every_byte_of_the_value_and_not_only_the_ones_that_are_set() {
2076        let text = asm("struct s { unsigned f : 20; } x = { 0x12300 };\n");
2077        assert!(text.contains("\t.data\n"), "there is something to write: {text}");
2078        assert!(text.contains("\nx:\n\t.ascii\t\"\\000#\\001\"\n"), "and it is the value: {text}");
2079
2080        // Two fields, the first of them zero, which is the same thing said with the zero byte
2081        // inside the run rather than at the front of it.
2082        let text = asm("struct s { unsigned a : 8; unsigned b : 8; } x = { 0, 3 };\n");
2083        assert!(text.contains("\nx:\n\t.ascii\t\"\\000\\003\"\n"), "{text}");
2084
2085        // Wider than an `int`, which is the same code and is worth saying because the value no
2086        // longer fits in the thirty two bits a bit-field used to be read at.
2087        let text = asm("struct s { unsigned long long f : 40; } x = { 0x100000 };\n");
2088        assert!(text.contains("\nx:\n\t.ascii\t\"\\000\\000\\020\"\n\t.space\t5\n"), "{text}");
2089
2090        // Nothing in it, which still costs no bytes in the file.
2091        let text = asm("struct s { unsigned f : 20; } x = { 0 };\n");
2092        assert!(text.contains("\t.bss\n"), "an object of zeroes is zeroes: {text}");
2093        assert!(text.contains("\nx:\n\t.space\t4\n"), "{text}");
2094    }
2095
2096    /// A string literal, which is a variable the program never named.
2097    #[test]
2098    fn a_string_literal_is_a_variable_with_a_name_no_program_could_write() {
2099        let text = asm("const char *f(void) { return \"hi\"; }\n");
2100        assert!(text.contains("\t.ascii\t\"hi\\000\"\n"), "{text}");
2101        assert!(text.contains("\t.section\t.rodata\n"), "{text}");
2102        let label = text
2103            .lines()
2104            .find(|line| line.starts_with(".Lstr"))
2105            .unwrap_or_else(|| panic!("a label for the literal in\n{text}"));
2106        assert!(!text.contains(&format!(".globl\t{}", label.trim_end_matches(':'))), "{text}");
2107    }
2108
2109    /// A variable holding the address of another one, which is the only hole an image has in it.
2110    #[test]
2111    fn an_address_in_an_initializer_is_left_to_the_linker() {
2112        let source = "int counter;\nint *p = &counter;\n";
2113        let text = asm(source);
2114        assert!(text.contains("\np:\n\t.quad\tcounter\n"), "{text}");
2115        // And in the object it is eight zero bytes and a relocation, which is what the two paths
2116        // being one description is for.
2117        let bytes = obj(source);
2118        assert!(bytes.windows(8).any(|w| w == b"counter\0"), "the object has to name it");
2119    }
2120
2121    /// A const table of function pointers, which is the shape that made SQLite link with a warning.
2122    ///
2123    /// The table is const so nothing in the program writes it, but the addresses in it are not
2124    /// numbers a link knows, so the loader writes it once at startup. Putting it in `.rodata`
2125    /// leaves a relocation in a section that is never writable, and what the linker does about
2126    /// that is set `DT_TEXTREL` on the whole image and say so. `.data.rel.ro` is writable for
2127    /// exactly as long as the loader is writing it and read only afterwards, which is what the
2128    /// program asked for in the first place.
2129    #[test]
2130    fn a_constant_holding_an_address_goes_in_the_section_the_loader_may_write_once() {
2131        // Both names are `static` and both are defined here, so nothing else can be the one that
2132        // defines them and the linker may lay the table out in the first pages of the segment.
2133        let text = asm("static void a(void) {}\nstatic void b(void) {}\n\
2134             struct m { void (*x)(void); void (*y)(void); };\n\
2135             const struct m t = { a, b };\n");
2136        assert!(text.contains("\t.section\t.data.rel.ro.local,\"aw\",@progbits\n"), "{text}");
2137        assert!(text.contains("\nt:\n\t.quad\ta\n\t.quad\tb\n"), "{text}");
2138
2139        // One name this file only declares is enough to lose the `.local` half, because a name the
2140        // link resolves from somewhere else is one another object may turn out to define.
2141        let text =
2142            asm("void a(void);\nstruct m { void (*x)(void); };\nconst struct m t = { a };\n");
2143        assert!(text.contains("\t.section\t.data.rel.ro,\"aw\",@progbits\n"), "{text}");
2144
2145        // And a constant with no address in it stays exactly where it was.
2146        let text = asm("const int fixed = 7;\n");
2147        assert!(text.contains("\t.section\t.rodata\n"), "{text}");
2148    }
2149
2150    /// A thread-local variable, which is valid C that the back end does not build yet.
2151    #[test]
2152    fn a_thread_local_variable_is_reported_as_work_that_is_not_done() {
2153        let mut opts = options();
2154        opts.emit = EmitKind::Asm;
2155        let result = run(&opts, "_Thread_local int x = 1;\n");
2156        assert!(result.failed(), "every thread sharing one variable is worse than a message");
2157        assert!(result.messages.iter().any(|m| m.contains("thread-local")), "{:?}", result);
2158        // Not an internal error: nothing here is wrong and the note says where the work is.
2159        assert!(!result.messages.iter().any(|m| m.contains("internal")), "{:?}", result);
2160    }
2161
2162    /// Not a rewording of the check above: what the two paths agree about is the point.
2163    #[test]
2164    fn the_object_and_the_listing_are_two_spellings_of_one_compilation() {
2165        // A call, because it is the one thing whose spelling in the two differs completely: the
2166        // listing writes a name and the object writes four zero bytes and a relocation asking the
2167        // linker for the same name. If either path had lost the callee, one of these would fail.
2168        let source = "int callee(void); int g(void) { return callee(); }\n";
2169        let bytes = obj(source);
2170        assert!(
2171            bytes.windows(7).any(|w| w == b"callee\0"),
2172            "the object has to name the callee for the linker to find it"
2173        );
2174        let text = asm(source);
2175        assert!(text.contains("\tcall\tcallee\n"), "{text}");
2176    }
2177
2178    /// What a file of a link contributes is an object, and the default emit is a link.
2179    ///
2180    /// This is here because getting it wrong is silent in the worst way: an empty file is a valid
2181    /// empty linker script, so a link fed one gets as far as reporting every symbol of the file as
2182    /// undefined and says nothing about the compilation that produced nothing.
2183    #[test]
2184    fn compiling_for_an_executable_produces_an_object_and_not_a_dump() {
2185        let mut opts = options();
2186        // What a command line with no `-c` and no `-S` on it asks for.
2187        opts.emit = EmitKind::Executable;
2188        let result = run(&opts, "int main(void) { return 0; }\n");
2189        assert_eq!(result.messages, Vec::<String>::new());
2190        match result.artifact {
2191            Artifact::Object(bytes) => assert_eq!(&bytes[..4], b"\x7fELF"),
2192            other => panic!("expected an object, got {other:?}"),
2193        }
2194    }
2195
2196    /// A target with a back end but no object writer says so rather than writing the wrong file.
2197    #[test]
2198    fn a_platform_with_no_object_writer_is_said_so_rather_than_written_as_elf() {
2199        let mut opts = options();
2200        opts.emit = EmitKind::Object;
2201        opts.target = "x86_64-apple-darwin".parse::<Triple>().unwrap();
2202        let result = run(&opts, "int f(void) { return 0; }\n");
2203        assert!(result.failed(), "an object nobody can read is worse than a message");
2204        assert!(
2205            result.messages.iter().any(|m| m.contains("no object writer")),
2206            "{:?}",
2207            result.messages
2208        );
2209    }
2210
2211    /// The IR of `source`, insisting that it compiled cleanly.
2212    fn ir(source: &str) -> String {
2213        let mut opts = options();
2214        opts.emit = EmitKind::Ir;
2215        let result = run(&opts, source);
2216        assert_eq!(result.messages, Vec::<String>::new(), "expected this to compile:\n{source}");
2217        result.text().to_owned()
2218    }
2219
2220    /// What was said about `source`, insisting that something was.
2221    fn errors(source: &str) -> Vec<String> {
2222        let mut opts = options();
2223        opts.emit = EmitKind::Ir;
2224        let result = run(&opts, source);
2225        assert!(result.failed(), "expected this to be refused:\n{source}");
2226        result.messages
2227    }
2228
2229    /// The body of the one function in `source`, which is what most of these are about.
2230    fn body(source: &str) -> String {
2231        let text = ir(source);
2232        let (_, rest) = text.split_once("{\n").expect("a function definition");
2233        let (body, _) = rest.rsplit_once("}\n").expect("a function definition");
2234        body.to_owned()
2235    }
2236
2237    /// What `-fgnu89-inline` is for, seen at the only place it shows: whether a body reached the
2238    /// module or only a declaration did.
2239    ///
2240    /// The C99 reading is the one an inline definition is written for and is not being changed
2241    /// here. What the flag is for is a program written before C99 swapped the two, which relies on
2242    /// `inline` alone leaving something behind for another unit to call, and there are twelve of
2243    /// those in the GCC torture suite alone.
2244    #[test]
2245    fn gnu89_inline_is_what_decides_whether_a_bare_inline_definition_reaches_the_module() {
2246        let source = "inline int f(int x) { return x + 1; }\n";
2247        let with = |flag: bool| {
2248            let mut opts = options();
2249            opts.emit = EmitKind::Ir;
2250            opts.gnu89_inline = flag;
2251            let result = run(&opts, source);
2252            assert_eq!(result.messages, Vec::<String>::new(), "expected this to compile");
2253            result.text().to_owned()
2254        };
2255
2256        // Under C's reading the module holds the declaration and the calls in this unit go to
2257        // whatever definition another unit has, which is C 6.7.4p7 and is what gcc does too.
2258        assert!(!with(false).contains("block0"), "no body: {}", with(false));
2259
2260        // Under GNU's it is an ordinary external definition, so the body is there and the symbol
2261        // is one the linker can resolve against.
2262        assert!(with(true).contains("block0"), "a body: {}", with(true));
2263    }
2264
2265    /// Nothing lowering writes says which type an access went through, so `-fno-strict-aliasing`
2266    /// is a description and not a request.
2267    ///
2268    /// The driver takes both spellings of that flag and does nothing about either, and this is why
2269    /// it is allowed to. The IR has a place for a type based aliasing node and the alias analysis
2270    /// reads one where there is one, and lowering fills it with nothing on every access, so no pass
2271    /// has a type to reason from and none of them assumes two objects of different types are
2272    /// different objects.
2273    ///
2274    /// If this test starts failing, the flag has stopped being a description, and taking it and
2275    /// dropping it becomes the miscompilation `spec/04-driver-and-cli.md` section 4.1 warns about
2276    /// in as many words. Whoever makes lowering emit these nodes has to make the flag turn them off
2277    /// in the same change.
2278    #[test]
2279    fn lowering_says_nothing_about_the_type_an_access_went_through() {
2280        // Every shape that would carry a node if there were any: a scalar through a pointer, a
2281        // member, an element, and the union that is the reason the rule has an exception at all.
2282        let source = "\
2283struct s { int a; float b; };\n\
2284union u { int i; float f; };\n\
2285int scalar(int *p) { return *p; }\n\
2286float member(struct s *p) { p->a = 1; return p->b; }\n\
2287int element(int *a, long i) { return a[i]; }\n\
2288float through_a_union(union u *p) { p->i = 1; return p->f; }\n";
2289        assert!(!ir(source).contains("tbaa"), "{}", ir(source));
2290    }
2291
2292    /// `return;` from a function that promised a value, which only C89 lets through and which
2293    /// therefore only reaches the IR builder under that dialect.
2294    ///
2295    /// Zero goes back. The alternatives are worse: an empty return list builds a `ret` the
2296    /// verifier refuses, which is what a torture case found, and `unreachable` would be a claim
2297    /// that the branch reaching this never runs, which is a claim about the program rather than
2298    /// about the value and lets the optimizer delete the path that led here.
2299    #[test]
2300    fn a_bare_return_from_a_function_that_promised_a_value_gives_back_a_zero() {
2301        let mut opts = options();
2302        opts.emit = EmitKind::Ir;
2303        opts.std = Std::C89;
2304        let compiled = |source: &str| {
2305            let result = run(&opts, source);
2306            assert_eq!(result.messages, Vec::<String>::new(), "C89 has nothing to say about this");
2307            result.text().to_owned()
2308        };
2309
2310        let text = compiled("int f(int x) { if (x) return; return 3; }\n");
2311        assert!(text.contains("iconst.i32 0\n    return"), "zero goes back: {text}");
2312        assert!(!text.contains("unreachable"), "the branch that reached it is kept: {text}");
2313
2314        // A floating point return needs the constant of its own kind rather than an integer one.
2315        let text = compiled("double f(int x) { if (x) return; return 1.0; }\n");
2316        assert!(text.contains("fconst.f64 0x0\n    return"), "a float zero goes back: {text}");
2317    }
2318
2319    /// What C89 6.3.2.2 declares for a call to a name nothing declared, seen in the IR rather than
2320    /// in what was said about it.
2321    ///
2322    /// `extern int f();`, so the call gives back an `int` and its arguments are promoted rather
2323    /// than converted to parameters there are none of. The declaration lasts for the file, which
2324    /// is what makes a second call to the same name ordinary and is why gcc says this once per
2325    /// file rather than once per call.
2326    #[test]
2327    fn a_call_to_a_name_nothing_declared_declares_it_as_c89_said_to() {
2328        let mut opts = options();
2329        opts.emit = EmitKind::Ir;
2330        opts.std = Std::C89;
2331        let compiled = |source: &str| {
2332            let result = run(&opts, source);
2333            assert_eq!(result.messages, Vec::<String>::new(), "C89 has nothing to say about this");
2334            result.text().to_owned()
2335        };
2336
2337        // An `int` back, which is the whole of what the implicit declaration says.
2338        let text = compiled("int f(void) { return g(); }\n");
2339        assert!(text.contains("call @g"), "the call is to the name that was written: {text}");
2340        assert!(text.contains("i32"), "and it gives back an int: {text}");
2341
2342        // No prototype, so a `char` argument arrives promoted to `int` the way an argument to a
2343        // function whose parameters are unspecified does.
2344        let text = compiled("int f(char c) { return g(c); }\n");
2345        assert!(text.contains("sext.i32"), "the argument is promoted: {text}");
2346
2347        // A name written as a value rather than called is still undeclared, since the rule is
2348        // about a call and nothing else.
2349        let mut opts = options();
2350        opts.std = Std::C89;
2351        let said = run(&opts, "int f(void) { return h; }\n").messages.join("\n");
2352        assert!(said.contains("'h' undeclared"), "not a call, so not declared: {said}");
2353    }
2354
2355    /// A file that calls a name above the definition of it, which is the shape the implicit
2356    /// declaration has to survive rather than swallow.
2357    ///
2358    /// The definition merges into the declaration the call already made rather than making a
2359    /// second one, so a declaration the tree does not carry at the top level takes the definition
2360    /// down with it: the body is attached to a node nothing walks and no function comes out.
2361    /// Nothing about the call itself looks wrong when that happens, and the program gets to the
2362    /// linker before anyone finds out, which is where `execute/cmpsi-1.c` in the torture suite
2363    /// found it, as an undefined reference to a name defined eleven lines further down.
2364    #[test]
2365    fn a_name_called_before_it_is_defined_still_gets_its_definition() {
2366        let mut opts = options();
2367        opts.emit = EmitKind::Ir;
2368        opts.std = Std::C89;
2369        let text = run(&opts, "int f(void) { return dummy(); }\ndummy () { return 7; }\n")
2370            .text()
2371            .to_owned();
2372        assert!(text.contains("func @f()"), "the caller is there: {text}");
2373        assert!(text.contains("func @dummy"), "and so is what it calls: {text}");
2374        assert!(text.contains("iconst.i32 7"), "with the body it was given: {text}");
2375    }
2376
2377    /// An old style definition whose parameter is narrower than what a call passes it.
2378    ///
2379    /// There is no prototype for a call to convert its argument to, so the argument is promoted
2380    /// and an `int` arrives for a parameter the body reads as an `unsigned char`. The entry block
2381    /// is where the two meet, and gcc writes the same pair of instructions there: store the low
2382    /// byte, read it back widened. `execute/950605-1.c` in the torture suite calls `f(-1)` and
2383    /// checks the parameter against `0xFF`, which is the difference between converting and not.
2384    #[test]
2385    fn an_old_style_parameter_is_converted_from_what_the_call_promoted_it_to() {
2386        let mut opts = options();
2387        opts.emit = EmitKind::Ir;
2388        opts.std = Std::C89;
2389        let compiled = |source: &str| run(&opts, source).text().to_owned();
2390
2391        let text = compiled("f (c) unsigned char c; { return c; }\n");
2392        assert!(text.contains("func @f(i32"), "an int arrives: {text}");
2393        assert!(text.contains("trunc.i8"), "and is cut down to what was declared: {text}");
2394        assert!(text.contains("zext.i32"), "then read back unsigned: {text}");
2395
2396        // A `short` is the same shape and signed, so it comes back the other way.
2397        let text = compiled("f (s) short s; { return s; }\n");
2398        assert!(text.contains("trunc.i16"), "cut down: {text}");
2399        assert!(text.contains("sext.i32"), "and read back signed: {text}");
2400
2401        // A `float` parameter is promoted to `double`, and without the conversion the multiply
2402        // below has one f64 operand and one f32, which the verifier refuses as invalid IR.
2403        let text = compiled("f (x) float x; { return x * 2; }\n");
2404        assert!(text.contains("func @f(f64"), "a double arrives: {text}");
2405        assert!(text.contains("fptrunc.f32"), "and is narrowed to the float: {text}");
2406
2407        // A parameter a prototype named arrives as itself and nothing is converted, which is the
2408        // case this must not have changed.
2409        let text = compiled("int f(unsigned char c) { return c; }\n");
2410        assert!(text.contains("func @f(i8)"), "the declared type arrives: {text}");
2411        assert!(!text.contains("trunc"), "so there is nothing to cut down: {text}");
2412    }
2413
2414    /// The six rules gcc 14 turned from a warning into an error, and the three answers each one
2415    /// gets depending on the dialect and on `-fpermissive`.
2416    ///
2417    /// The table is a measurement rather than a reading of the release notes. Six files, one per
2418    /// rule, put through gcc 16.2.0 on x86-64 Linux under each of the four command lines below
2419    /// with no `-W` flags on any of them, and what came back is what is written here. The three
2420    /// rules that say nothing under C89 are the three C89 did not have, and the three that warn
2421    /// there were constraint violations then as well.
2422    #[test]
2423    fn the_rules_gcc_promoted_are_decided_by_the_dialect_and_by_fpermissive() {
2424        // `-std=gnu89`, `-std=gnu17`, `-std=gnu17 -fpermissive`, and `-std=gnu23`.
2425        let modes = [(Std::C89, false), (Std::C17, false), (Std::C17, true), (Std::C23, false)];
2426        let cases = [
2427            ("static counted;\n", ["", "error", "warning", "error"]),
2428            ("int f(void) { return g(); }\n", ["", "error", "warning", "error"]),
2429            ("int f(x) { return x; }\n", ["", "error", "warning", "error"]),
2430            ("int *p;\nvoid h(void) { p = 1; }\n", ["warning", "error", "warning", "error"]),
2431            (
2432                "char *q;\nint *r;\nvoid k(void) { r = q; }\n",
2433                ["warning", "error", "warning", "error"],
2434            ),
2435            ("int f(void) { return; }\n", ["", "error", "warning", "error"]),
2436            ("void g(void) { return 1; }\n", ["warning", "error", "warning", "error"]),
2437        ];
2438
2439        for (source, wanted) in cases {
2440            for (&(std, permissive), wanted) in modes.iter().zip(wanted) {
2441                let mut opts = options();
2442                opts.std = std;
2443                opts.permissive = permissive;
2444                let said = run(&opts, source).messages.join("\n");
2445                let severity = if said.contains(": error: ") {
2446                    "error"
2447                } else if said.contains(": warning: ") {
2448                    "warning"
2449                } else {
2450                    ""
2451                };
2452                let how = if permissive { " -fpermissive" } else { "" };
2453                assert_eq!(
2454                    severity,
2455                    wanted,
2456                    "under -std={}{how}, {source} was answered with `{said}`",
2457                    std.as_str()
2458                );
2459                if wanted.is_empty() {
2460                    assert!(said.is_empty(), "nothing to say, but said `{said}`");
2461                }
2462            }
2463        }
2464    }
2465
2466    /// A first argument that is not a list, which the four variadic operators answer in two ways.
2467    ///
2468    /// gcc has `va_arg` as an operator, since it takes a type name and no function can, and the
2469    /// other three as builtin functions taking the address of a list. The difference is not a
2470    /// naming one: the operator's complaint is its own and is an error under every dialect, and
2471    /// the three functions go through the ordinary rule about an argument of the wrong type,
2472    /// which is one of the rules the table above is about. The same four command lines through
2473    /// gcc 16.2.0 on x86-64 Linux is where these came from.
2474    #[test]
2475    fn the_three_variadic_builtins_answer_a_bad_list_the_way_a_call_answers_a_bad_argument() {
2476        let modes = [(Std::C89, false), (Std::C17, false), (Std::C17, true), (Std::C23, false)];
2477        let cases = [
2478            (
2479                "int f(int n, ...) { char *p; return __builtin_va_arg(p, int); }\n",
2480                "first argument to 'va_arg' not of type 'va_list'",
2481                ["error", "error", "error", "error"],
2482            ),
2483            (
2484                "void f(int n, ...) { char *p; __builtin_va_start(p, n); }\n",
2485                "passing argument 1 of '__builtin_va_start' from incompatible pointer type",
2486                ["warning", "error", "warning", "error"],
2487            ),
2488            (
2489                "void f(int n, ...) { int x; __builtin_va_end(x); }\n",
2490                "passing argument 1 of '__builtin_va_end' makes pointer from integer without a \
2491                 cast",
2492                ["warning", "error", "warning", "error"],
2493            ),
2494            (
2495                "void f(int n, ...) { __builtin_va_list a; char *p; __builtin_va_copy(a, p); }\n",
2496                "passing argument 2 of '__builtin_va_copy' from incompatible pointer type",
2497                ["warning", "error", "warning", "error"],
2498            ),
2499        ];
2500
2501        for (source, message, wanted) in cases {
2502            for (&(std, permissive), wanted) in modes.iter().zip(wanted) {
2503                let mut opts = options();
2504                opts.std = std;
2505                opts.permissive = permissive;
2506                let said = run(&opts, source).messages.join("\n");
2507                let how = if permissive { " -fpermissive" } else { "" };
2508                assert!(
2509                    said.contains(&format!(": {wanted}: {message}")),
2510                    "under -std={}{how}, {source} was answered with `{said}`",
2511                    std.as_str()
2512                );
2513            }
2514        }
2515    }
2516
2517    /// The IR of `source` at one safety tier, insisting that it compiled cleanly.
2518    fn safe_ir(tier: rucc_session::Safety, source: &str) -> String {
2519        let mut opts = options();
2520        opts.emit = EmitKind::Ir;
2521        opts.safety = tier;
2522        let result = run(&opts, source);
2523        assert_eq!(result.messages, Vec::<String>::new(), "expected this to compile:\n{source}");
2524        result.text().to_owned()
2525    }
2526
2527    const READS_THROUGH_A_POINTER: &str = "int read(int *p) { return p[1]; }\n";
2528
2529    #[test]
2530    fn a_build_that_did_not_ask_for_the_monitor_is_compiled_the_way_it_always_was() {
2531        // This is the load bearing test of the whole flag. The monitor is being built in the open
2532        // and every build in the world is compiled by this compiler with the flag absent, so a
2533        // check that leaked into that path would be a regression for everybody.
2534        let text = ir(READS_THROUGH_A_POINTER);
2535        assert!(!text.contains("check_"), "{text}");
2536        assert!(!text.contains("cap_of"), "{text}");
2537    }
2538
2539    #[test]
2540    fn asking_for_a_tier_puts_the_checks_in_before_the_optimizer_sees_them() {
2541        let text = safe_ir(rucc_session::Safety::Detect, READS_THROUGH_A_POINTER);
2542        assert!(text.contains("cap_of"), "{text}");
2543        assert!(text.contains("check_bounds"), "{text}");
2544        assert!(text.contains("check_live"), "{text}");
2545        // The subscript is address arithmetic, so J2 applies to it as well as J1.
2546        assert!(text.contains("check_deriv"), "{text}");
2547    }
2548
2549    #[test]
2550    fn the_three_tiers_that_are_not_off_all_check_the_same_accesses_so_far() {
2551        // What separates them is the reporter and the boundary, which are milestones S2 and S3.
2552        // Pinning it here means the day they stop agreeing, this test says so rather than the
2553        // difference going unnoticed.
2554        let detect = safe_ir(rucc_session::Safety::Detect, READS_THROUGH_A_POINTER);
2555        for tier in [rucc_session::Safety::Enforce, rucc_session::Safety::Kernel] {
2556            assert_eq!(safe_ir(tier, READS_THROUGH_A_POINTER), detect, "{tier}");
2557        }
2558    }
2559
2560    /// The safety summary of `source` at one tier, insisting that it compiled cleanly.
2561    fn summary(tier: rucc_session::Safety, source: &str) -> String {
2562        let mut opts = options();
2563        opts.emit = EmitKind::SafetySummary;
2564        opts.safety = tier;
2565        let result = run(&opts, source);
2566        assert_eq!(result.messages, Vec::<String>::new(), "expected this to compile:\n{source}");
2567        result.text().to_owned()
2568    }
2569
2570    #[test]
2571    fn the_summary_counts_the_checks_that_went_in_and_the_ones_still_standing() {
2572        let text = summary(rucc_session::Safety::Detect, READS_THROUGH_A_POINTER);
2573        assert!(text.contains("\"tier\": \"detect\""), "{text}");
2574        // One load, so one of each of the two access checks, and the subscript is a derivation.
2575        assert!(
2576            text.contains("\"bounds\": { \"emitted\": 1, \"remaining\": 1, \"discharged\": 0 }"),
2577            "{text}"
2578        );
2579        assert!(
2580            text.contains(
2581                "\"derivation\": { \"emitted\": 1, \"remaining\": 1, \"discharged\": 0 }"
2582            ),
2583            "{text}"
2584        );
2585    }
2586
2587    #[test]
2588    fn a_build_without_the_monitor_summarises_as_a_build_with_no_checks_in_it() {
2589        // Which is the honest summary rather than an error. A build system that emits a summary
2590        // for every unit should get one for the units nobody asked to instrument too, and the
2591        // zeroes are what say that the guarantee over that file is nothing at all.
2592        let text = summary(rucc_session::Safety::Off, READS_THROUGH_A_POINTER);
2593        assert!(text.contains("\"tier\": \"off\""), "{text}");
2594        assert!(
2595            text.contains("\"bounds\": { \"emitted\": 0, \"remaining\": 0, \"discharged\": 0 }"),
2596            "{text}"
2597        );
2598    }
2599
2600    #[test]
2601    fn a_call_the_boundary_models_is_counted_apart_from_one_it_does_not() {
2602        let text = summary(
2603            rucc_session::Safety::Detect,
2604            "void *memcpy(void *, const void *, unsigned long);\n\
2605             int puts(const char *);\n\
2606             void f(char *d, char *s) { memcpy(d, s, 4); puts(d); }\n",
2607        );
2608        assert!(text.contains("\"interposed\": 1"), "{text}");
2609        assert!(text.contains("\"puts\""), "{text}");
2610        // The wrapper it was pointed at is ours, so it is not on the list of things this build
2611        // failed to model. Counting it there would make instrumenting a file look worse than
2612        // leaving it alone.
2613        assert!(!text.contains("__rucc_wrap_memcpy\""), "{text}");
2614    }
2615
2616    #[test]
2617    fn the_two_directions_a_pointer_crosses_the_boundary_are_counted_apart() {
2618        // `f` is a name the linker can bind to and takes a pointer, so a pointer arrives there.
2619        // `notes_open` is a library this build did not instrument, so a pointer comes back from
2620        // it. Both are crossings and neither is the other, which is why there are two numbers.
2621        let text = summary(
2622            rucc_session::Safety::Detect,
2623            "void *notes_open(void);\n\
2624             char *f(char *p) { char *q = notes_open(); return q ? q : p; }\n",
2625        );
2626        assert!(text.contains("\"crossings\": { \"entered\": 1, \"returned\": 1 }"), "{text}");
2627        assert!(text.contains("\"notes_open\""), "{text}");
2628    }
2629
2630    #[test]
2631    fn a_static_function_nobody_takes_the_address_of_is_not_a_crossing() {
2632        // Nothing outside the file can reach it, so a witness on its parameters would be counting
2633        // a crossing that does not happen.
2634        let text = summary(
2635            rucc_session::Safety::Detect,
2636            "static int len(const char *p) { return p ? 1 : 0; }\n\
2637             int f(void) { return len(\"x\"); }\n",
2638        );
2639        assert!(text.contains("\"crossings\": { \"entered\": 0, \"returned\": 0 }"), "{text}");
2640    }
2641
2642    /// The granule report for `source`, insisting that it compiled cleanly.
2643    fn granules(source: &str) -> String {
2644        let mut opts = options();
2645        opts.emit = EmitKind::TypeGranules;
2646        let result = run(&opts, source);
2647        assert_eq!(result.messages, Vec::<String>::new(), "expected this to compile:\n{source}");
2648        result.text().to_owned()
2649    }
2650
2651    #[test]
2652    fn the_granule_report_names_every_record_and_both_keyings() {
2653        let text = granules(
2654            "struct hot { char *p; int a; int b; };\n\
2655             int f(struct hot *h) { return h->a; }\n",
2656        );
2657        assert!(text.contains("struct hot"), "{text}");
2658        // Both keyings are reported because which types count as one is a decision the design
2659        // has not made yet, and a report that picked one would be hiding the cost of the other.
2660        assert!(text.contains("every type distinct"), "{text}");
2661        assert!(text.contains("every pointer one type"), "{text}");
2662        assert!(text.contains("budget"), "{text}");
2663    }
2664
2665    #[test]
2666    fn a_record_nothing_uses_is_still_measured() {
2667        // The measurement is about what a program declares, not about what it runs, so a type
2668        // that is only ever declared still costs the plane whatever its layout costs.
2669        let text = granules("struct unused { long a; double b; };\nint f(void) { return 0; }\n");
2670        assert!(text.contains("struct unused"), "{text}");
2671    }
2672
2673    #[test]
2674    fn the_granule_report_stops_before_anything_is_lowered() {
2675        // A layout is settled at the closing brace, so lowering the function bodies would take
2676        // minutes on an amalgamation and answer nothing. The evidence that it stops is that a
2677        // body the back end has no way to compile still produces a report.
2678        let text = granules(
2679            "struct wide { long double d; };\n\
2680             long double f(long double x) { return x * x; }\n",
2681        );
2682        assert!(text.contains("struct wide"), "{text}");
2683    }
2684
2685    #[test]
2686    fn a_witness_reaches_the_assembler_as_a_call_to_the_runtime() {
2687        // The count only means anything if the call is really there, and a summary saying one is
2688        // there is not evidence that the back end emitted it.
2689        let text = safe_asm(rucc_session::Safety::Detect, "char *f(char *p) { return p; }\n");
2690        assert!(text.contains("\tcall\t__rucc_cap_witness\n"), "{text}");
2691    }
2692
2693    #[test]
2694    fn a_pointer_turned_into_an_integer_is_on_the_trust_set() {
2695        let text = summary(
2696            rucc_session::Safety::Detect,
2697            "unsigned long f(int *p) { return (unsigned long) p; }\n",
2698        );
2699        assert!(text.contains("\"exposed\": 1"), "{text}");
2700    }
2701
2702    /// The assembly of `source` at one safety tier, insisting that it compiled cleanly.
2703    fn safe_asm(tier: rucc_session::Safety, source: &str) -> String {
2704        let mut opts = options();
2705        opts.emit = EmitKind::Asm;
2706        opts.safety = tier;
2707        let result = run(&opts, source);
2708        assert_eq!(result.messages, Vec::<String>::new(), "expected this to compile:\n{source}");
2709        result.text().to_owned()
2710    }
2711
2712    #[test]
2713    fn a_check_reaches_the_assembler_as_a_call_to_the_runtime() {
2714        let text = safe_asm(rucc_session::Safety::Detect, READS_THROUGH_A_POINTER);
2715        assert!(text.contains("\tcall\t__rucc_check_bounds\n"), "{text}");
2716        assert!(text.contains("\tcall\t__rucc_check_live\n"), "{text}");
2717        assert!(text.contains("\tcall\t__rucc_check_deriv\n"), "{text}");
2718    }
2719
2720    #[test]
2721    fn every_check_that_reached_the_assembler_has_a_row_describing_it() {
2722        // Three checks and three descriptors, each in the section the runtime's reporter reads.
2723        // The width is `rucc_safety::lower::WIDTH` and the row is `rucc_safe_rt::fail::Descriptor`,
2724        // and the two agreeing is what makes the address a check is handed mean anything.
2725        let text = safe_asm(rucc_session::Safety::Detect, READS_THROUGH_A_POINTER);
2726        let section = format!("\t.section\t{},", rucc_safety::SECTION);
2727        assert_eq!(text.matches(&section).count(), 3, "{text}");
2728        for index in 0..3 {
2729            let name = format!("__rucc_safety_desc_{index}");
2730            // Defined once and referenced once, because a descriptor nothing points at describes
2731            // nothing and a reference with no definition does not link.
2732            assert!(text.contains(&format!("{name}:\n")), "{text}");
2733            assert!(text.contains(&format!("{name}(%rip)")), "{text}");
2734        }
2735        assert!(!text.contains("__rucc_safety_desc_3"), "{text}");
2736    }
2737
2738    /// `__builtin_constant_p` is answered in the front end and never reaches the IR.
2739    ///
2740    /// gcc folds it after optimization, so its answer for an argument that is not written as a
2741    /// constant can differ between `-O0` and `-O2`. What is checked here is the front end's
2742    /// answer, which is the same at every level, and the four cases where gcc gives the same
2743    /// answer at both levels are the ones measured on gcc 16: a literal is one, a variable is
2744    /// zero, a string literal is one and the address of an object is zero.
2745    #[test]
2746    fn builtin_constant_p_is_folded_where_it_is_written_rather_than_called() {
2747        let text = ir(concat!(
2748            "int g;\n",
2749            "int a = __builtin_constant_p(1);\n",
2750            "int b = __builtin_constant_p(g);\n",
2751            "int c = __builtin_constant_p(\"abc\");\n",
2752            "int d = __builtin_constant_p(&g);\n",
2753            "int e = __builtin_constant_p(1.5);\n",
2754            "int h = __builtin_choose_expr(__builtin_constant_p(3), 11, 22);\n",
2755        ));
2756        assert!(text.contains("global @a : i32 = 1,"), "{text}");
2757        assert!(text.contains("global @b : i32 = 0,"), "{text}");
2758        assert!(text.contains("global @c : i32 = 1,"), "{text}");
2759        assert!(text.contains("global @d : i32 = 0,"), "{text}");
2760        assert!(text.contains("global @e : i32 = 1,"), "{text}");
2761        assert!(text.contains("global @h : i32 = 11,"), "{text}");
2762        assert!(!text.contains("__builtin_constant_p"), "it is not a call to anything:\n{text}");
2763
2764        // The argument is not evaluated, which is what gcc does with it as well, so `i` is
2765        // still zero. The second constant is the answer, which nothing reads and which the
2766        // first pass that looks for dead code will take out.
2767        let text = body("int f(void) { int i = 0; __builtin_constant_p(i++); return i; }\n");
2768        assert_eq!(text, "block0:\n    %0 = iconst.i32 0\n    %1 = iconst.i32 0\n    return %0\n");
2769    }
2770
2771    /// A library builtin is the library function of the same name, and the call says so.
2772    ///
2773    /// A program writes `__builtin_strlen` rather than `strlen` to reach the function the C
2774    /// library promises where its own name has been taken by a macro, and to say that the usual
2775    /// meaning is the one intended. So the name in the program and the name in the object file
2776    /// are two different names and the call carries the second one. gcc folds several of these
2777    /// when the arguments allow it, which is an optimization on top of a call that is already
2778    /// right rather than instead of it, so nothing here depends on any folding happening.
2779    #[test]
2780    fn a_call_to_a_library_builtin_reaches_the_library_function() {
2781        let text = body("void f(void) { __builtin_abort(); }\n");
2782        assert_eq!(text, "block0:\n    call @abort() : ()\n    return\n");
2783
2784        // Nothing declared either of these and nothing had to: the prefix is what says the name
2785        // belongs to the implementation, and the type comes out of `features.toml`.
2786        let text = ir("int f(const char *s) { return __builtin_puts(s) + __builtin_strlen(s); }\n");
2787        assert!(text.contains("call @puts(%0) : (ptr) -> i32"), "{text}");
2788        assert!(text.contains("call @strlen(%0) : (ptr) -> i64"), "{text}");
2789        assert!(!text.contains("__builtin_"), "the prefix is not part of any name here:\n{text}");
2790    }
2791
2792    /// The absolute value family is four instructions and not a call, whoever declared the name.
2793    ///
2794    /// `abs`, `labs` and `llabs` are reserved to the implementation, so a program that writes one
2795    /// means the one the C library promises and the compiler is allowed to know what it does. The
2796    /// program in `gcc.c-torture/execute/20021127-1.c` is the one that insists: it defines `llabs`
2797    /// to abort and expects the call not to reach it. Measured against gcc 16.2.0, which writes a
2798    /// `neg` and a `cmovns` and never calls the definition either.
2799    ///
2800    /// The most negative value comes back as itself, which is what the arithmetic gives and what
2801    /// gcc's pair of instructions gives, and C says the answer is undefined there.
2802    #[test]
2803    fn the_absolute_value_family_is_the_magnitude_and_not_a_call() {
2804        let text = body(concat!(
2805            "long long llabs(long long);\n",
2806            "long long f(long long x) { return llabs(x); }\n",
2807        ));
2808        assert!(text.contains("%1 = iconst.i64 63"), "{text}");
2809        assert!(text.contains("%2 = ashr %0, %1"), "{text}");
2810        assert!(text.contains("%3 = xor %0, %2"), "{text}");
2811        assert!(text.contains("%4 = sub %3, %2"), "{text}");
2812        assert!(!text.contains("call"), "the call does not happen:\n{text}");
2813
2814        // The narrower two, whose width comes from the type the library gives the name and not
2815        // from anything at the call.
2816        let text = body("int abs(int);\nint f(int x) { return abs(x); }\n");
2817        assert!(text.contains("iconst.i32 31"), "{text}");
2818        let text = body("long labs(long);\nlong f(long x) { return labs(x); }\n");
2819        assert!(text.contains("iconst.i64 63"), "{text}");
2820
2821        // The prefixed spelling is the same node, and it is what a program writes to reach the
2822        // library's meaning where the plain name has been taken.
2823        let text = body("long long f(long long x) { return __builtin_llabs(x); }\n");
2824        assert!(!text.contains("call"), "{text}");
2825
2826        // A definition of the name in the same file changes nothing, which is the whole point.
2827        let text = ir(concat!(
2828            "long long llabs(long long b);\n",
2829            "long long g(long long x) { return llabs(x); }\n",
2830            "long long llabs(long long b) { return 7; }\n",
2831        ));
2832        assert!(!text.contains("call @llabs"), "{text}");
2833    }
2834
2835    /// A byte swap is one instruction and not a call, and nothing had to declare it.
2836    ///
2837    /// SQLite writes these for its page headers and glibc's `<endian.h>` defines `htobe32` and its
2838    /// neighbours as exactly these, so a program that reads a file format reaches one without ever
2839    /// naming it. There is no object file anywhere that defines `__builtin_bswap32`, so a call left
2840    /// standing here would not link.
2841    #[test]
2842    fn a_byte_swap_is_arithmetic_and_not_a_call() {
2843        let text = body("unsigned f(unsigned x) { return __builtin_bswap32(x); }\n");
2844        assert_eq!(text, "block0(%0: i32):\n    %1 = bswap %0\n    return %1\n");
2845
2846        // The argument is converted by the prototype the way any other call's would be, so the
2847        // swap happens at the width the name says and not at the width the program wrote.
2848        let text = body("unsigned f(unsigned char c) { return __builtin_bswap32(c); }\n");
2849        assert!(text.contains("zext.i32 %0"), "widened first: {text}");
2850        assert!(text.contains("bswap %1"), "and swapped at four bytes: {text}");
2851    }
2852
2853    /// Each of the three reverses in the width its name says, which is the type of the node.
2854    ///
2855    /// The width matters more here than it looks. `__builtin_bswap16` is the two bytes of a
2856    /// `uint16_t` exchanged, and if the node came out at the machine's width instead then the bits
2857    /// above the value would be dragged into the answer and the result would be zero.
2858    #[test]
2859    fn the_byte_swaps_reverse_at_the_width_their_name_says() {
2860        for (name, ty, width) in [
2861            ("__builtin_bswap16", "unsigned short", "i16"),
2862            ("__builtin_bswap32", "unsigned", "i32"),
2863            ("__builtin_bswap64", "unsigned long long", "i64"),
2864        ] {
2865            let source = format!("{ty} f({ty} x) {{ return {name}(x); }}\n");
2866            let text = body(&source);
2867            assert_eq!(
2868                text,
2869                format!("block0(%0: {width}):\n    %1 = bswap %0\n    return %1\n"),
2870                "{name}"
2871            );
2872        }
2873    }
2874
2875    /// The three bit counts the IR has an instruction for are that instruction and not a call.
2876    ///
2877    /// Fifteen rows of `features.toml` come out of five questions, and three of the five are one
2878    /// instruction each. The kernel's bitmap search is built on them, ffmpeg counts leading zeroes
2879    /// in its bitstream reader and SQLite uses one to size a page, so a call left standing here
2880    /// would not link against anything and would be slow if it did.
2881    #[test]
2882    fn the_bit_counts_are_instructions_and_not_calls() {
2883        let text = body("int f(unsigned x) { return __builtin_clz(x); }\n");
2884        assert_eq!(text, "block0(%0: i32):\n    %1 = ctlz %0\n    return %1\n");
2885
2886        let text = body("int f(unsigned x) { return __builtin_ctz(x); }\n");
2887        assert_eq!(text, "block0(%0: i32):\n    %1 = cttz %0\n    return %1\n");
2888
2889        let text = body("int f(unsigned x) { return __builtin_popcount(x); }\n");
2890        assert_eq!(text, "block0(%0: i32):\n    %1 = ctpop %0\n    return %1\n");
2891    }
2892
2893    /// The width counted is the operand's and the width answered is `int`, which are two different
2894    /// things at every spelling but the narrowest.
2895    ///
2896    /// This is the mistake the family invites. `__builtin_clz` of a value counts the leading zeroes
2897    /// of it narrowed to `unsigned int` and `__builtin_clzll` counts them at sixty four bits, and
2898    /// those are different numbers for the same value. What decides it is the prototype the row
2899    /// carries, so the count happens after the conversion and the narrowing back to `int` happens
2900    /// after the count.
2901    #[test]
2902    fn the_bit_counts_ask_about_the_width_their_name_says() {
2903        let text = body("int f(unsigned long long x) { return __builtin_clzll(x); }\n");
2904        assert!(text.starts_with("block0(%0: i64):"), "counted at eight bytes: {text}");
2905        assert!(text.contains("%1 = ctlz %0"), "{text}");
2906        assert!(text.contains("trunc.i32 %1"), "and answered in an int: {text}");
2907
2908        // The same value asked about at the narrower width, which converts first and so counts
2909        // something else.
2910        let text = body("int f(unsigned long long x) { return __builtin_clz(x); }\n");
2911        assert!(text.contains("trunc.i32 %0"), "narrowed to what was asked about: {text}");
2912        assert!(text.contains("ctlz %1"), "and counted there: {text}");
2913
2914        let text = body("int f(unsigned long x) { return __builtin_popcountl(x); }\n");
2915        assert!(text.contains("%1 = ctpop %0"), "{text}");
2916        assert!(!text.contains("call"), "{text}");
2917    }
2918
2919    /// A parity is whether the count of set bits is odd, which is that count and its low bit.
2920    ///
2921    /// Not the machine's parity flag, which on x86-64 is over the low byte of a result and so is a
2922    /// different question, and not the count itself, since C says the answer is zero or one.
2923    #[test]
2924    fn a_parity_is_the_low_bit_of_the_set_bit_count() {
2925        let text = body("int f(unsigned x) { return __builtin_parity(x); }\n");
2926        assert!(text.contains("%1 = ctpop %0"), "{text}");
2927        assert!(text.contains("iconst.i32 1"), "{text}");
2928        assert!(text.contains("and %1, %2"), "the low bit of it: {text}");
2929    }
2930
2931    /// `__builtin_ffs` is the trailing zero count and one, kept only when there was a bit to find.
2932    ///
2933    /// The one in the family defined at zero, where it answers zero. Written as a mask rather than
2934    /// as a branch: the count and the comparison do not depend on each other and both are cheap, so
2935    /// a branch would buy nothing and cost two blocks and a join.
2936    #[test]
2937    fn the_first_set_bit_is_one_based_and_zero_for_a_zero() {
2938        let text = body("int f(int x) { return __builtin_ffs(x); }\n");
2939        assert!(text.contains("%1 = cttz %0"), "{text}");
2940        assert!(text.contains("%4 = add %1, %2"), "one more than the count: {text}");
2941        assert!(text.contains("%5 = icmp ne %0, %3"), "whether there was a bit at all: {text}");
2942        assert!(text.contains("%7 = sub %3, %6"), "spread to a mask: {text}");
2943        assert!(text.contains("%8 = and %4, %7"), "and kept only then: {text}");
2944        assert!(!text.contains("br_if"), "no branch: {text}");
2945    }
2946
2947    /// The three overflow checks are arithmetic and a flag, and not a call to anything.
2948    ///
2949    /// gcc has emitted these since 5.0 and there is no object file that defines one, so a call left
2950    /// standing here would not link. SQLite reaches all three within twenty lines of each other, in
2951    /// `sqlite3AddInt64` and its two neighbours, which is the reason they were done now.
2952    ///
2953    /// The IR instruction answers two things at once, the wrapped value and whether it wrapped,
2954    /// which is a shape nothing else in the IR has. The store is the builtin writing the answer
2955    /// through the pointer it was handed.
2956    #[test]
2957    fn an_overflow_check_is_arithmetic_and_not_a_call() {
2958        let text =
2959            body("int f(int a, int b, int *r) { return __builtin_add_overflow(a, b, r); }\n");
2960        assert!(text.contains("%3, %4 = sadd_overflow.(i32, i1) %0, %1"), "{text}");
2961        assert!(text.contains("store %3 -> %2"), "{text}");
2962        assert!(!text.contains("call"), "{text}");
2963
2964        let text =
2965            body("int f(int a, int b, int *r) { return __builtin_sub_overflow(a, b, r); }\n");
2966        assert!(text.contains("ssub_overflow.(i32, i1) %0, %1"), "{text}");
2967
2968        let text =
2969            body("int f(int a, int b, int *r) { return __builtin_mul_overflow(a, b, r); }\n");
2970        assert!(text.contains("smul_overflow.(i32, i1) %0, %1"), "{text}");
2971
2972        // Unsigned operands get the unsigned form, which is a different question about the same
2973        // arithmetic: an unsigned sum wraps where a signed one of the same bits does not.
2974        let text = body(
2975            "int f(unsigned a, unsigned b, unsigned *r) { return __builtin_add_overflow(a, b, r); }\n",
2976        );
2977        assert!(text.contains("uadd_overflow.(i32, i1) %0, %1"), "{text}");
2978    }
2979
2980    /// The arithmetic happens at a type that holds every value all three written types can hold.
2981    ///
2982    /// That is what makes the check exact. `unsigned int` and `int` in one call need thirty three
2983    /// bits between them, so the add is done at sixty four with each operand extended the way its
2984    /// own signedness says: the unsigned one zero extended, the signed one sign extended. Sign
2985    /// extending the unsigned one would turn three billion into a negative number before the
2986    /// addition ever saw it.
2987    #[test]
2988    fn an_overflow_check_is_done_at_a_type_that_holds_every_operand() {
2989        let text = body(
2990            "int f(unsigned a, int b, long long *r) { return __builtin_add_overflow(a, b, r); }\n",
2991        );
2992        assert!(text.contains("%3 = zext.i64 %0"), "the unsigned operand keeps its value: {text}");
2993        assert!(text.contains("%4 = sext.i64 %1"), "and so does the signed one: {text}");
2994        assert!(text.contains("sadd_overflow.(i64, i1) %3, %4"), "{text}");
2995
2996        // Three types that agree need no extension at all, which is what nearly every real call
2997        // is written as.
2998        let text = body(
2999            "int f(long long a, long long b, long long *r) { return __builtin_mul_overflow(a, b, r); }\n",
3000        );
3001        assert!(text.contains("smul_overflow.(i64, i1) %0, %1"), "{text}");
3002        assert!(!text.contains("sext."), "{text}");
3003        // The one widening left is the answer, which is a bit becoming the `int` C says it is.
3004        assert!(!text.contains("zext.i64"), "{text}");
3005    }
3006
3007    /// The wrapped answer is written through the pointer whether or not it fit.
3008    ///
3009    /// That is gcc's rule and it is what makes the builtin usable as a wrapping add with a flag on
3010    /// the side. A destination narrower than the arithmetic is narrowed and widened back, and the
3011    /// answer being different is the second half of the test: the instruction says whether the
3012    /// arithmetic itself needed more room, and the round trip says whether what came out survived
3013    /// the trip down to where it was going.
3014    #[test]
3015    fn an_overflow_check_writes_the_wrapped_answer_whether_or_not_it_fit() {
3016        let text =
3017            body("int f(int a, int b, char *r) { return __builtin_sub_overflow(a, b, r); }\n");
3018        assert!(text.contains("%3, %4 = ssub_overflow.(i32, i1) %0, %1"), "{text}");
3019        assert!(text.contains("%5 = trunc.i8 %3"), "narrowed to where it goes: {text}");
3020        assert!(text.contains("%6 = sext.i32 %5"), "and back: {text}");
3021        assert!(text.contains("%7 = icmp ne %6, %3"), "which is whether it fit: {text}");
3022        assert!(text.contains("store %5 -> %2"), "the narrowed value is stored either way: {text}");
3023        assert!(text.contains("%8 = or %4, %7"), "and either bit is an overflow: {text}");
3024    }
3025
3026    /// A call needing more than sixty four bits is refused by name rather than got wrong.
3027    ///
3028    /// Two ways to reach it: a `__int128` operand, and a sixty four bit unsigned type mixed with a
3029    /// signed one, which needs sixty five bits to represent both. gcc handles the second by being
3030    /// cleverer in the mixed case rather than by widening. Until that is written, the message says
3031    /// what the call needed.
3032    #[test]
3033    fn a_call_needing_more_than_sixty_four_bits_says_so() {
3034        let refused = concat!(
3035            "int f(unsigned long long a, long long b, long long *r) {\n",
3036            "    return __builtin_add_overflow(a, b, r);\n",
3037            "}\n",
3038        );
3039        let messages = errors(refused);
3040        assert_eq!(messages.len(), 1, "{messages:?}");
3041        assert!(messages[0].contains("E0694"), "{messages:?}");
3042        assert!(messages[0].contains("wider than 64 bits"), "{messages:?}");
3043    }
3044
3045    /// An operand that is not an integer at all is the older message, from the type checking every
3046    /// type generic builtin shares.
3047    #[test]
3048    fn an_overflow_check_over_something_that_is_not_an_integer_says_so() {
3049        let messages =
3050            errors("int f(double a, int b, int *r) { return __builtin_add_overflow(a, b, r); }\n");
3051        assert!(messages.iter().any(|line| line.contains("E0671")), "{messages:?}");
3052
3053        let messages =
3054            errors("int f(int a, int b, double *r) { return __builtin_add_overflow(a, b, r); }\n");
3055        assert!(messages.iter().any(|line| line.contains("E0671")), "{messages:?}");
3056    }
3057
3058    /// An ordered access is an ordered access in the IR, with the ordering the program wrote.
3059    ///
3060    /// Which is the point of the node existing at all. An ordering is not an argument anything is
3061    /// passed, it is a thing the IR says about an access, so the number in the source is read once
3062    /// in the front end and after that the ordering travels on the instruction where every pass
3063    /// that moves code can see it.
3064    ///
3065    /// SQLite is why these are done: `AtomicLoad` and `AtomicStore` in `sqlite3.c` are
3066    /// `__atomic_load_n` and `__atomic_store_n` at the relaxed ordering, and there are thirty five
3067    /// calls to the pair.
3068    #[test]
3069    fn an_ordered_access_is_ordered_in_the_ir() {
3070        let text = body("int f(int *p) { return __atomic_load_n(p, 0); }\n");
3071        assert!(text.contains("atomic_load.i32 %0, align 4, relaxed"), "{text}");
3072
3073        let text = body("long f(long *p) { return __atomic_load_n(p, 2); }\n");
3074        assert!(text.contains("atomic_load.i64 %0, align 8, acquire"), "{text}");
3075
3076        let text = body("void f(int *p, int v) { __atomic_store_n(p, v, 3); }\n");
3077        assert!(text.contains("atomic_store %1 -> %0, align 4, release"), "{text}");
3078
3079        let text = body("void f(int *p, int v) { __atomic_store_n(p, v, 5); }\n");
3080        assert!(text.contains("atomic_store %1 -> %0, align 4, seq_cst"), "{text}");
3081
3082        // The value is converted to what the pointer points at before it is stored, which is what
3083        // the call would have done if it had a prototype to convert against.
3084        let text = body("void f(char *p, int v) { __atomic_store_n(p, v, 0); }\n");
3085        assert!(text.contains("trunc.i8 %1"), "{text}");
3086        assert!(text.contains("atomic_store %2 -> %0, align 1, relaxed"), "{text}");
3087    }
3088
3089    /// On this machine the ordered access is the plain instruction, except at the strongest
3090    /// ordering of a store.
3091    ///
3092    /// x86-64 is total store order: every load is already an acquire and every store is already a
3093    /// release, and an aligned access no wider than a word is indivisible whether or not anybody
3094    /// asked. So the whole family is `mov` and the one thing the machine does not give away is a
3095    /// store staying in front of a later load, which is `mfence` behind the store. Every line below
3096    /// is what gcc 16.2.0 writes for the same function.
3097    #[test]
3098    fn an_ordered_access_is_the_plain_instruction_on_this_machine() {
3099        let text = asm("int f(int *p) { return __atomic_load_n(p, 5); }\n");
3100        assert!(text.contains("movl\t(%rdi), %eax"), "{text}");
3101        assert!(!text.contains("mfence"), "a load needs no barrier here: {text}");
3102
3103        let text = asm("void f(int *p, int v) { __atomic_store_n(p, v, 3); }\n");
3104        assert!(text.contains("movl\t%esi, (%rdi)"), "{text}");
3105        assert!(!text.contains("mfence"), "a release store needs no barrier here: {text}");
3106
3107        let text = asm("void f(int *p, int v) { __atomic_store_n(p, v, 5); }\n");
3108        let (before, after) = text.split_once("mfence").expect("a barrier: {text}");
3109        assert!(before.contains("movl\t%esi, (%rdi)"), "the store comes first: {text}");
3110        assert!(!after.contains("movl"), "and nothing else is between them: {text}");
3111    }
3112
3113    /// A barrier is one instruction at the strongest ordering and no instruction below it.
3114    ///
3115    /// The same reasoning the other way round. An acquire, a release and an acquire release fence
3116    /// are already true of every program running on this machine, and what a program wanted from
3117    /// one is that the compiler not move accesses across it, which is already so by the time any
3118    /// instruction is picked. Sequential consistency is the one that costs something.
3119    ///
3120    /// `__sync_synchronize` is the older family's spelling of the strongest one and compiles to
3121    /// exactly the same instruction, which is what SQLite calls twice in `sqlite3.c`.
3122    #[test]
3123    fn a_barrier_is_one_instruction_at_the_strongest_ordering_and_none_below_it() {
3124        assert!(asm("void f(void) { __atomic_thread_fence(5); }\n").contains("mfence"));
3125        assert!(asm("void f(void) { __sync_synchronize(); }\n").contains("mfence"));
3126
3127        for weaker in ["1", "2", "3", "4"] {
3128            let source = format!("void f(void) {{ __atomic_thread_fence({weaker}); }}\n");
3129            assert!(!asm(&source).contains("mfence"), "{weaker} costs nothing here");
3130        }
3131    }
3132
3133    /// The four compare and exchange names are one IR instruction producing two values.
3134    ///
3135    /// Which of the two the expression answers is the difference between three of the four names,
3136    /// and the fourth difference is the C11 pair writing what they found back through the pointer
3137    /// they were handed, which is the branch after the instruction.
3138    #[test]
3139    fn a_compare_and_exchange_is_one_instruction_answering_two_things() {
3140        // The older family, whose two names are the same instruction read two ways. Neither has a
3141        // memory order argument and both are a full barrier, which is what `seq_cst` says.
3142        let text =
3143            body("int f(int *p, int e, int d) { return __sync_val_compare_and_swap(p, e, d); }\n");
3144        assert!(text.contains("%3, %4 = cmpxchg.(i32, i1) %0, %1, %2, align 4, seq_cst"), "{text}");
3145        assert!(text.contains("return %3"), "the value it found: {text}");
3146
3147        let text =
3148            body("int f(int *p, int e, int d) { return __sync_bool_compare_and_swap(p, e, d); }\n");
3149        assert!(text.contains("%3, %4 = cmpxchg.(i32, i1) %0, %1, %2, align 4, seq_cst"), "{text}");
3150        assert!(text.contains("zext.i32 %4"), "whether it happened: {text}");
3151
3152        // The C11 form, whose value expected arrives by pointer and is read before the exchange,
3153        // and whose answer is whether it happened. The write back is on the path where it did not.
3154        let text = body(
3155            "int f(int *p, int *e, int d) { return __atomic_compare_exchange_n(p, e, d, 0, 4, 2); }\n",
3156        );
3157        assert!(text.contains("%3 = load.i32 %1, align 4"), "{text}");
3158        assert!(text.contains("%4, %5 = cmpxchg.(i32, i1) %0, %3, %2, align 4, acq_rel"), "{text}");
3159        assert!(text.contains("br_if %5, block2, block1"), "{text}");
3160        assert!(text.contains("store %4 -> %1, align 4"), "{text}");
3161
3162        // And the form that takes the value to put there by pointer as well, which is one more
3163        // read and is otherwise the same node.
3164        let text = body(
3165            "int f(int *p, int *e, int *d) { return __atomic_compare_exchange(p, e, d, 0, 5, 5); }\n",
3166        );
3167        assert!(text.contains("%3 = load.i32 %1, align 4"), "{text}");
3168        assert!(text.contains("%4 = load.i32 %2, align 4"), "{text}");
3169        assert!(text.contains("%5, %6 = cmpxchg.(i32, i1) %0, %3, %4, align 4, seq_cst"), "{text}");
3170    }
3171
3172    /// On this machine it is `lock cmpxchg`, at the width of the object and at every ordering.
3173    ///
3174    /// The `lock` is what makes the whole of it one step as far as every other processor is
3175    /// concerned, and it is also what makes the instruction a full barrier, which is why the
3176    /// ordering the program wrote changes nothing in what is written here. Every line below is what
3177    /// gcc 16.2.0 writes for the same function.
3178    #[test]
3179    fn a_compare_and_exchange_is_a_locked_instruction_at_the_width_of_the_object() {
3180        let widths = [("char", "b", "%dl"), ("short", "w", "%dx"), ("int", "l", "%edx")];
3181        for (ty, suffix, reg) in widths {
3182            let source = format!(
3183                "int f({ty} *p, {ty} e, {ty} d) {{ return __sync_bool_compare_and_swap(p, e, d); }}\n"
3184            );
3185            let text = asm(&source);
3186            assert!(text.contains("\tlock\n"), "{ty}: {text}");
3187            assert!(text.contains(&format!("cmpxchg{suffix}\t{reg}, (%rdi)")), "{ty}: {text}");
3188            assert!(text.contains("sete\t"), "{ty}: {text}");
3189        }
3190        let source =
3191            "int f(long *p, long e, long d) { return __sync_bool_compare_and_swap(p, e, d); }\n";
3192        assert!(asm(source).contains("cmpxchgq\t%rdx, (%rdi)"), "{}", asm(source));
3193
3194        // The ordering the program asked for changes nothing, because a locked instruction on this
3195        // machine orders everything whatever it was asked for, so there is never a barrier beside
3196        // it either.
3197        for order in ["0", "2", "3", "4", "5"] {
3198            let call = format!("__atomic_compare_exchange_n(p, e, d, 0, {order}, 0)");
3199            let source = format!("int f(int *p, int *e, int d) {{ return {call}; }}\n");
3200            let text = asm(&source);
3201            assert!(text.contains("cmpxchgl\t"), "{order}: {text}");
3202            assert!(!text.contains("mfence"), "{order} needs no barrier here: {text}");
3203        }
3204    }
3205
3206    /// A read modify write is one IR instruction, and a name that asks for the value afterwards is
3207    /// that instruction and one more operation.
3208    ///
3209    /// The instruction answers what was there before, which is the convention every machine and
3210    /// every language in this area uses. Half the names in the family ask for the value afterwards
3211    /// instead, and that is the answer and the operand put together again, which is arithmetic on
3212    /// two values already in registers rather than a second flavour of the instruction.
3213    ///
3214    /// The two lock names are here too. They are not read modify writes in the same sense: one is
3215    /// an exchange and the other is a store of a zero, and what makes them a pair is the ordering,
3216    /// which is the one place in the older family that is not sequential consistency.
3217    #[test]
3218    fn a_read_modify_write_is_one_instruction_and_the_arithmetic_a_name_asks_for() {
3219        let text = body("int f(int *p, int v) { return __atomic_fetch_add(p, v, 5); }\n");
3220        assert!(text.contains("%2 = atomic_rmw.i32 add %0, %1, align 4, seq_cst"), "{text}");
3221        assert!(text.contains("return %2"), "the value that was there: {text}");
3222
3223        let text = body("int f(int *p, int v) { return __atomic_add_fetch(p, v, 5); }\n");
3224        assert!(text.contains("%2 = atomic_rmw.i32 add %0, %1, align 4, seq_cst"), "{text}");
3225        assert!(text.contains("%3 = add %2, %1"), "and the value afterwards: {text}");
3226
3227        let text = body("int f(int *p, int v) { return __atomic_sub_fetch(p, v, 5); }\n");
3228        assert!(text.contains("%2 = atomic_rmw.i32 sub %0, %1, align 4, seq_cst"), "{text}");
3229        assert!(text.contains("%3 = sub %2, %1"), "{text}");
3230
3231        // The older family, which passes no ordering and is a full barrier.
3232        let text = body("int f(int *p, int v) { return __sync_fetch_and_sub(p, v); }\n");
3233        assert!(text.contains("%2 = atomic_rmw.i32 sub %0, %1, align 4, seq_cst"), "{text}");
3234
3235        // The exchange, and the older family's spelling of it, which is taking a lock and so is an
3236        // acquire rather than the full barrier the rest of that family is.
3237        let text = body("int f(int *p, int v) { return __atomic_exchange_n(p, v, 5); }\n");
3238        assert!(text.contains("%2 = atomic_rmw.i32 xchg %0, %1, align 4, seq_cst"), "{text}");
3239
3240        let text = body("int f(int *p, int v) { return __sync_lock_test_and_set(p, v); }\n");
3241        assert!(text.contains("%2 = atomic_rmw.i32 xchg %0, %1, align 4, acquire"), "{text}");
3242
3243        // Giving the lock back, which is one of the two names in the family that is handed no value
3244        // to put there, because what it puts there is a zero.
3245        let text = body("void f(int *p) { __sync_lock_release(p); }\n");
3246        assert!(text.contains("release"), "{text}");
3247        assert!(text.contains("%1 = iconst.i32 0"), "{text}");
3248
3249        // And with something after the pointer, which is the list of variables the call promises to
3250        // protect rather than a value to write. Reading it as a value would store whatever the
3251        // caller happened to name there, which is the one thing giving a lock back must not do.
3252        let text = body("void f(int *p, int guard) { __sync_lock_release(p, guard); }\n");
3253        assert!(text.contains("%2 = iconst.i32 0"), "{text}");
3254        assert!(text.contains("atomic_store %2 -> %0, align 4, release"), "{text}");
3255
3256        // The bitwise four, which look no different here from the arithmetic ones: what the machine
3257        // has an instruction for is a question further down and this level does not ask it.
3258        let text = body("int f(int *p, int v) { return __atomic_fetch_and(p, v, 5); }\n");
3259        assert!(text.contains("%2 = atomic_rmw.i32 and %0, %1, align 4, seq_cst"), "{text}");
3260
3261        let text = body("int f(int *p, int v) { return __sync_or_and_fetch(p, v); }\n");
3262        assert!(text.contains("%2 = atomic_rmw.i32 or %0, %1, align 4, seq_cst"), "{text}");
3263        assert!(text.contains("%3 = or %2, %1"), "and the value afterwards: {text}");
3264
3265        // The nand, which is the one of the six that is two operations. The flip is an exclusive or
3266        // against every bit set because the IR has no not and that is what one is.
3267        let text = body("int f(int *p, int v) { return __atomic_nand_fetch(p, v, 5); }\n");
3268        assert!(text.contains("%2 = atomic_rmw.i32 nand %0, %1, align 4, seq_cst"), "{text}");
3269        assert!(text.contains("%3 = and %2, %1"), "{text}");
3270        assert!(text.contains("%4 = iconst.i32 -1"), "{text}");
3271        assert!(text.contains("%5 = xor %3, %4"), "{text}");
3272    }
3273
3274    /// The four operations with no instruction on this machine are a loop around `lock cmpxchg`.
3275    ///
3276    /// The shape is the one every architecture manual writes out by hand: read the word, work out
3277    /// what should be there instead, put it back if nothing else got in first, and go round again
3278    /// when something did. What is checked is that the loop is there at every width, that the
3279    /// operation is inside it, and that no `xchg` or `xadd` got used for something neither of them
3280    /// does.
3281    ///
3282    /// gcc 16.2.0 writes the same loop for the same functions, down to which register holds the
3283    /// value that was read.
3284    #[test]
3285    fn a_bitwise_read_modify_write_is_a_loop_around_the_compare_and_exchange() {
3286        let widths = [("char", "b", "%dl"), ("short", "w", "%dx"), ("int", "l", "%edx")];
3287        for (ty, suffix, reg) in widths {
3288            for (name, call, insn) in [
3289                ("and", "__atomic_fetch_and(p, v, 5)", "and"),
3290                ("or", "__sync_fetch_and_or(p, v)", "or"),
3291                ("xor", "__atomic_xor_fetch(p, v, 5)", "xor"),
3292            ] {
3293                let source = format!("{ty} f({ty} *p, {ty} v) {{ return {call}; }}\n");
3294                let text = asm(&source);
3295                assert!(text.contains("\tlock\n"), "{ty} {name}: {text}");
3296                assert!(
3297                    text.contains(&format!("cmpxchg{suffix}\t{reg}, (%rdi)")),
3298                    "{ty} {name}: {text}"
3299                );
3300                assert!(text.contains(&format!("{insn}{suffix}\t")), "{ty} {name}: {text}");
3301                // The tab matters on the second of these, since `cmpxchg` ends in the other name.
3302                assert!(!text.contains("\txadd"), "{ty} {name} is not an add: {text}");
3303                assert!(!text.contains("\txchg"), "{ty} {name} is not an exchange: {text}");
3304            }
3305        }
3306        let source = "long f(long *p, long v) { return __atomic_fetch_or(p, v, 5); }\n";
3307        assert!(asm(source).contains("cmpxchgq\t%rdx, (%rdi)"), "{}", asm(source));
3308
3309        // The nand, which puts two instructions inside the loop rather than one. The flip is an
3310        // exclusive or against every bit set in the IR and the folder turns that into the `not` the
3311        // machine has, which is what gcc writes here too.
3312        let text = asm("int f(int *p, int v) { return __sync_fetch_and_nand(p, v); }\n");
3313        assert!(text.contains("cmpxchgl\t"), "{text}");
3314        assert!(text.contains("andl\t"), "{text}");
3315        assert!(text.contains("notl\t"), "{text}");
3316    }
3317
3318    /// The three names that pass a value through a pointer are the same access and one plain one.
3319    ///
3320    /// They exist for an object too big to come back in a register, and the front end takes them at
3321    /// their word rather than folding them into the `_n` spellings, because the extra access is real:
3322    /// the caller handed over somewhere to read from or write into and that is where the value has
3323    /// to come from or go. Both of those accesses are plain. The object at the end of the caller's
3324    /// pointer is the caller's own and no other thread has its address, which is what the whole
3325    /// shape is for.
3326    #[test]
3327    fn an_access_through_a_second_pointer_is_the_same_access_and_one_more() {
3328        let text = body("void f(int *p, int *r) { __atomic_load(p, r, 5); }\n");
3329        assert!(text.contains("%2 = atomic_load.i32 %0, align 4, seq_cst"), "{text}");
3330        assert!(text.contains("store %2 -> %1, align 4"), "and out through the place: {text}");
3331
3332        let text = body("void f(int *p, int *v) { __atomic_store(p, v, 3); }\n");
3333        assert!(text.contains("%2 = load.i32 %1, align 4"), "in through the place: {text}");
3334        assert!(text.contains("atomic_store %2 -> %0, align 4, release"), "{text}");
3335
3336        // The exchange, which reads through one pointer and writes through another and is the same
3337        // instruction in between as the spelling that takes and answers values.
3338        let text = body("void f(int *p, int *v, int *r) { __atomic_exchange(p, v, r, 5); }\n");
3339        assert!(text.contains("%3 = load.i32 %1, align 4"), "{text}");
3340        assert!(text.contains("%4 = atomic_rmw.i32 xchg %0, %3, align 4, seq_cst"), "{text}");
3341        assert!(text.contains("store %4 -> %2, align 4"), "{text}");
3342    }
3343
3344    /// The flag pair is an exchange of one byte and a store of a zero over the same byte.
3345    ///
3346    /// One byte whatever the pointer was written as, which is the standard's reading rather than a
3347    /// liberty: the object is an `atomic_flag`, there is no other way to read or write one, so the
3348    /// type the pointer carries says nothing about the access and the width is the implementation's
3349    /// to fix. gcc 16.2.0 writes `xchgb` here through an `int *` too.
3350    ///
3351    /// The answer is a comparison against zero rather than the byte itself, because the type of the
3352    /// call is `_Bool` and a byte that is neither zero nor one is not one. gcc answers the raw byte,
3353    /// and the two agree wherever the flag is only ever touched through this pair.
3354    #[test]
3355    fn a_flag_is_an_exchange_of_one_byte_and_a_store_of_a_zero_over_the_same_byte() {
3356        for pointer in ["char", "int", "void"] {
3357            let source = format!("int f({pointer} *p) {{ return __atomic_test_and_set(p, 5); }}\n");
3358            let text = body(&source);
3359            assert!(text.contains("%1 = iconst.i8 1"), "{pointer}: {text}");
3360            assert!(
3361                text.contains("%2 = atomic_rmw.i8 xchg %0, %1, align 1, seq_cst"),
3362                "{pointer}: {text}"
3363            );
3364            assert!(text.contains("%4 = icmp ne %2, %3"), "{pointer}: {text}");
3365
3366            let source = format!("void f({pointer} *p) {{ __atomic_clear(p, 3); }}\n");
3367            let text = body(&source);
3368            assert!(text.contains("atomic_store %2 -> %0, align 1, release"), "{pointer}: {text}");
3369        }
3370
3371        // And on this machine, where the exchange carries no `lock` because one with memory locks
3372        // the bus whether it was asked to or not. Both lines are what gcc 16.2.0 writes.
3373        let text = asm("int f(int *p) { return __atomic_test_and_set(p, 5); }\n");
3374        assert!(text.contains("xchgb\t%al, (%rdi)"), "{text}");
3375        assert!(text.contains("setne\t"), "{text}");
3376    }
3377
3378    /// On this machine it is `xchg` where the machine has an exchange and `lock xadd` where it has
3379    /// an add, at the width of the object.
3380    ///
3381    /// The exchange carries no prefix and the add carries one, which is the machine rather than an
3382    /// oversight: an exchange with memory locks the bus whether it is asked to or not. Both are
3383    /// therefore full barriers whatever ordering the program wrote, so no ordering costs an
3384    /// `mfence` beside them. Every line below is what gcc 16.2.0 writes for the same function.
3385    #[test]
3386    fn a_read_modify_write_is_an_exchange_or_a_locked_add_at_the_width_of_the_object() {
3387        let widths = [("char", "b", "%sil"), ("short", "w", "%si"), ("int", "l", "%esi")];
3388        for (ty, suffix, reg) in widths {
3389            let source =
3390                format!("{ty} f({ty} *p, {ty} v) {{ return __atomic_fetch_add(p, v, 5); }}\n");
3391            let text = asm(&source);
3392            assert!(text.contains("\tlock\n"), "{ty}: {text}");
3393            assert!(text.contains(&format!("xadd{suffix}\t{reg}, (%rdi)")), "{ty}: {text}");
3394
3395            let source =
3396                format!("{ty} f({ty} *p, {ty} v) {{ return __atomic_exchange_n(p, v, 5); }}\n");
3397            let text = asm(&source);
3398            assert!(text.contains(&format!("xchg{suffix}\t{reg}, (%rdi)")), "{ty}: {text}");
3399            assert!(!text.contains("\tlock\n"), "an exchange is locked already: {ty}: {text}");
3400        }
3401        let source = "long f(long *p, long v) { return __atomic_fetch_add(p, v, 5); }\n";
3402        assert!(asm(source).contains("xaddq\t%rsi, (%rdi)"), "{}", asm(source));
3403
3404        // A subtraction is the same instruction over the negated operand, which is right at every
3405        // width because the machine's arithmetic wraps.
3406        let source = "int f(int *p, int v) { return __atomic_fetch_sub(p, v, 5); }\n";
3407        let text = asm(source);
3408        assert!(text.contains("negl\t"), "{text}");
3409        assert!(text.contains("xaddl\t"), "{text}");
3410
3411        // The ordering changes nothing, for the reason it changes nothing for a compare and
3412        // exchange: a locked instruction on this machine orders everything whatever it was asked.
3413        for order in ["0", "2", "3", "4", "5"] {
3414            let source =
3415                format!("int f(int *p, int v) {{ return __atomic_fetch_add(p, v, {order}); }}\n");
3416            let text = asm(&source);
3417            assert!(text.contains("xaddl\t"), "{order}: {text}");
3418            assert!(!text.contains("mfence"), "{order} needs no barrier here: {text}");
3419        }
3420
3421        // And the lock pair, which is the exchange and a store of a zero. Neither is a barrier
3422        // instruction: the exchange is one already and the store is a release, which this machine
3423        // gives away.
3424        let text = asm("int f(int *p, int v) { return __sync_lock_test_and_set(p, v); }\n");
3425        assert!(text.contains("xchgl\t%esi, (%rdi)"), "{text}");
3426        // The zero goes through a register on the way, which is where every constant this
3427        // compiler stores goes: gcc writes the one instruction because it has a store that takes an
3428        // immediate and no rule here does. That is a rule this rule set is missing rather than
3429        // anything about the builtin, and it is the same two instructions a plain `*p = 0` makes.
3430        let text = asm("void f(int *p) { __sync_lock_release(p); }\n");
3431        assert!(text.contains("movl\t$0, %eax"), "{text}");
3432        assert!(text.contains("movl\t%eax, (%rdi)"), "{text}");
3433        assert!(!text.contains("mfence"), "a release store needs no barrier here: {text}");
3434    }
3435
3436    /// The two lock free questions are numbers in the program rather than calls to anything.
3437    ///
3438    /// Both answer from the size, which has to be a power of two no wider than the widest access
3439    /// this compiler writes, and from what the pointer says about the alignment. Sixteen bytes is
3440    /// no here and is no in gcc without `-mcx16`, because `cmpxchg16b` is not in the baseline and
3441    /// nothing here writes it. Three bytes is no because there is no three byte access at all.
3442    ///
3443    /// The whole point of both names is that the answer is available before the program runs, so
3444    /// what is checked is that a `mov` of a constant is the whole function and that no call was
3445    /// left behind. A call would be to `__atomic_is_lock_free` in libatomic, which is not a library
3446    /// this links against.
3447    #[test]
3448    fn the_lock_free_questions_are_answered_as_constants() {
3449        for size in ["1", "2", "4", "8"] {
3450            let source =
3451                format!("int f(void) {{ return __atomic_always_lock_free({size}, 0); }}\n");
3452            let text = asm(&source);
3453            assert!(text.contains("movb\t$1, %al"), "{size} bytes is lock free: {text}");
3454            assert!(!text.contains("call"), "and is not a call: {text}");
3455        }
3456        for size in ["3", "16", "sizeof(long double)"] {
3457            let source = format!("int f(void) {{ return __atomic_is_lock_free({size}, 0); }}\n");
3458            let text = asm(&source);
3459            assert!(text.contains("movb\t$0, %al"), "{size} bytes is not: {text}");
3460            assert!(!text.contains("call"), "and is not a call either: {text}");
3461        }
3462
3463        // A size the compiler cannot work out, which is no rather than a refusal, and an object
3464        // whose type is aligned under the size asked about, which is the whole of what the second
3465        // argument is for.
3466        let text = asm("int f(int n) { return __atomic_is_lock_free(n, 0); }\n");
3467        assert!(text.contains("movb\t$0, %al"), "a size nobody knows is not lock free: {text}");
3468        let text = asm("int f(int *p) { return __atomic_always_lock_free(8, p); }\n");
3469        assert!(text.contains("movb\t$0, %al"), "eight bytes at four is not: {text}");
3470        let text = asm("int f(long *p) { return __atomic_always_lock_free(8, p); }\n");
3471        assert!(text.contains("movb\t$1, %al"), "and at eight it is: {text}");
3472    }
3473
3474    /// A memory order an operation cannot carry is read as the strongest one, and said so about.
3475    ///
3476    /// There are three ways the number is not one the operation can take: it is not a constant at
3477    /// all, it is not one of the six the headers define, or it is one of them and means nothing for
3478    /// this operation, which is a release load or an acquire store. All three become sequential
3479    /// consistency, which is stronger than anything the program could have meant, so a program that
3480    /// wrote nonsense gets a correct answer rather than a fast one. gcc does the same.
3481    ///
3482    /// The last two also warn, because the number was written down and is wrong. The first does
3483    /// not: gcc takes a computed order, and so does the C11 spelling, so a warning there would fire
3484    /// on correct programs.
3485    #[test]
3486    fn a_memory_order_an_operation_cannot_carry_is_read_as_the_strongest() {
3487        let mut opts = options();
3488        opts.emit = EmitKind::Ir;
3489
3490        let acquire_store = run(&opts, "void f(int *p, int v) { __atomic_store_n(p, v, 2); }\n");
3491        assert!(acquire_store.text().contains("seq_cst"), "{:?}", acquire_store.text());
3492        assert!(acquire_store.messages[0].contains("[W0333]"), "{:?}", acquire_store.messages);
3493
3494        let nonsense = run(&opts, "int f(int *p) { return __atomic_load_n(p, 99); }\n");
3495        assert!(nonsense.text().contains("seq_cst"), "{:?}", nonsense.text());
3496        assert!(nonsense.messages[0].contains("[W0333]"), "{:?}", nonsense.messages);
3497
3498        let computed = run(&opts, "int f(int *p, int n) { return __atomic_load_n(p, n); }\n");
3499        assert!(computed.text().contains("seq_cst"), "{:?}", computed.text());
3500        assert_eq!(computed.messages, Vec::<String>::new(), "a computed order is not a mistake");
3501    }
3502
3503    /// A conversion between a float and the widest unsigned integer, which the machine has not got.
3504    ///
3505    /// Every other conversion between a float and an integer is the signed one at some width with a
3506    /// widening in front or a narrowing behind. These two are not, because there is no signed width
3507    /// that holds every value of an unsigned sixty four bit integer, so each is the signed
3508    /// conversion with arithmetic around it that brings the value into range and puts it back.
3509    ///
3510    /// What is checked here is that the conversion happens at all and that it happens without a
3511    /// branch. gcc writes a branch for both; this writes the choice as a mask, because every rewrite
3512    /// in that pass stays inside the block it started in. The arithmetic itself is checked in
3513    /// `rucc-codegen`, where it can be run against the answer rather than read in the assembly.
3514    #[test]
3515    fn a_conversion_between_a_float_and_the_widest_unsigned_integer_is_written_without_a_branch() {
3516        let text = asm("double f(unsigned long long x) { return (double)x; }\n");
3517        assert!(text.contains("cvtsi2sdq"), "the signed conversion is what runs: {text}");
3518        assert!(text.contains("shrq"), "with the value halved first: {text}");
3519        assert!(text.contains("addsd"), "and doubled after: {text}");
3520        assert!(!text.contains("\tj"), "and no branch anywhere: {text}");
3521
3522        let text = asm("unsigned long long f(double d) { return (unsigned long long)d; }\n");
3523        assert!(text.contains("cvttsd2siq"), "the signed conversion is what runs: {text}");
3524        assert!(text.contains("subsd"), "with half the range taken off first: {text}");
3525        assert!(text.contains("shlq\t$63"), "and the top bit put back: {text}");
3526        assert!(!text.contains("\tj"), "and no branch anywhere: {text}");
3527    }
3528
3529    /// The plain names are the library's only where nothing else has taken them.
3530    ///
3531    /// Four ways a program says it means something else. A `static` definition is its own
3532    /// function and the name outside the file is somebody else's. A declaration of another type
3533    /// is another function. `-fno-builtin` and `-fno-builtin-<name>` say so outright, and
3534    /// `-ffreestanding` says there is no C library for the name to be the name of. Every one of
3535    /// these was measured against gcc 16.2.0, which calls the program's function in all of them.
3536    ///
3537    /// The `__builtin_` spelling goes on meaning the library's function through all of it, which
3538    /// is what the prefix is for and what lets a freestanding build reach one deliberately.
3539    #[test]
3540    fn a_plain_name_the_program_took_is_the_programs_own_function() {
3541        let taken = concat!(
3542            "static long long llabs(long long b) { return 7; }\n",
3543            "long long f(long long x) { return llabs(x); }\n",
3544        );
3545        assert!(ir(taken).contains("call @llabs"), "a static definition is the program's own");
3546
3547        let retyped = concat!("int llabs(int b);\n", "int f(int x) { return llabs(x); }\n",);
3548        assert!(ir(retyped).contains("call @llabs"), "another type is another function");
3549
3550        let plain = concat!(
3551            "long long llabs(long long b);\n",
3552            "long long f(long long x) { return llabs(x); }\n",
3553        );
3554        let mut opts = options();
3555        opts.emit = EmitKind::Ir;
3556        assert!(!run(&opts, plain).text().contains("call @llabs"), "the library's by default");
3557
3558        opts.builtins = false;
3559        assert!(run(&opts, plain).text().contains("call @llabs"), "-fno-builtin");
3560
3561        opts.builtins = true;
3562        opts.no_builtin = vec!["llabs".to_owned()];
3563        assert!(run(&opts, plain).text().contains("call @llabs"), "-fno-builtin-llabs");
3564        let one = "long labs(long b);\nlong f(long x) { return labs(x); }\n";
3565        assert!(!run(&opts, one).text().contains("call @labs"), "one name and not the family");
3566
3567        // `-ffreestanding` reaches the front end as the same answer, which is what the driver
3568        // does with it in `compile`, and the prefixed spelling is untouched by any of it.
3569        opts.no_builtin = Vec::new();
3570        opts.builtins = false;
3571        let prefixed = "long long f(long long x) { return __builtin_llabs(x); }\n";
3572        assert!(!run(&opts, prefixed).text().contains("call @llabs"), "the prefix is a promise");
3573    }
3574
3575    /// The hint builtins are their first argument, and nothing is left of the hint.
3576    ///
3577    /// Which way a branch is expected to go is the whole of what they say, and there is nothing
3578    /// here that reads a branch weight yet, so what reaches the IR is the value and the hint is
3579    /// gone. The one thing the prototype has to keep doing is converting: gcc gives both of them
3580    /// a `long` result, so `sizeof(__builtin_expect((char)1, 1))` is eight and a narrower argument
3581    /// widens before it is answered with.
3582    ///
3583    /// Whether a side effect in the hint happens depends on the first argument, which is gcc's
3584    /// answer rather than a rule anybody designed. A constant first argument folds the whole call
3585    /// where it is written and the hint goes with it, and a first argument that is not a constant
3586    /// leaves the hint standing. Both halves are below and both were measured on gcc 16.2.0.
3587    #[test]
3588    fn the_hint_builtins_are_their_first_argument_and_the_hint_leaves_no_trace() {
3589        let text = ir(concat!(
3590            "long a = __builtin_expect(7, 1);\n",
3591            "long b = __builtin_expect_with_probability(9, 1, 0.9);\n",
3592            "unsigned long c = sizeof(__builtin_expect((char)1, 1));\n",
3593        ));
3594        assert!(text.contains("global @a : i64 = 7,"), "{text}");
3595        assert!(text.contains("global @b : i64 = 9,"), "{text}");
3596        assert!(text.contains("global @c : i64 = 8,"), "{text}");
3597        assert!(!text.contains("__builtin_expect"), "it is not a call to anything:\n{text}");
3598
3599        // A narrower argument is widened by the prototype before it is handed back, and it is
3600        // widened with its sign, since the parameter is a signed `long`.
3601        let text = body("long f(char c) { return __builtin_expect(c, 1); }\n");
3602        assert!(text.contains("sext"), "{text}");
3603
3604        // The first argument is a constant, so the second is not evaluated and `i` is still zero,
3605        // and neither is the third. What is left of each statement is the first argument widened,
3606        // which nothing reads and which the first pass that looks for dead code will take out.
3607        let one = "block0:\n    %0 = iconst.i32 0\n    %1 = iconst.i32 1\n    %2 = sext.i64 %1\n    return %0\n";
3608        assert_eq!(body("int f(void) { int i = 0; __builtin_expect(1, i++); return i; }\n"), one);
3609        let source = "int g(void) { int i = 0; __builtin_expect_with_probability(1, i++, 0.5); return i; }\n";
3610        assert_eq!(body(source), one);
3611
3612        // The first argument is not a constant, so the hint runs and `i` comes back one. There is
3613        // an increment in the body and the value it returns is the load after it, which is what
3614        // gcc gives for the same program, and the whole of tamnd/rucc#584 is that this used to
3615        // come out the same as the pair above.
3616        let kept = body("int f(int n) { int i = 0; __builtin_expect(n, i++); return i; }\n");
3617        assert!(kept.contains("add.nsw"), "the hint still runs: {kept}");
3618        assert!(kept.ends_with("return %3\n"), "and the answer is what it left behind: {kept}");
3619        let both = "int g(int n) { int i = 0; __builtin_expect_with_probability(n, i++, 0.5); return i; }\n";
3620        assert!(body(both).contains("add.nsw"), "and so does the one with three arguments");
3621    }
3622
3623    /// A point control does not arrive at, in both of the ways the compiler has one.
3624    ///
3625    /// `__builtin_unreachable()` is the promise written down, and a function whose body can run
3626    /// off the bottom is the walk arriving at the same place on its own. Neither writes an
3627    /// instruction, which is what gcc 16.2.0 does at `-O0`: it emits the epilogue and the `ret`
3628    /// for both of the functions below and nothing else, and the two of them come out byte for
3629    /// byte the same there.
3630    ///
3631    /// The `ret` is the part worth holding on to. It is not there because anything runs it, it is
3632    /// there because a function whose last instruction is not a return is one that falls into
3633    /// whatever the assembler puts after it.
3634    #[test]
3635    fn a_promise_that_control_does_not_arrive_writes_no_instruction() {
3636        let promised = "int f(int x) { if (x) return 1; __builtin_unreachable(); }\n";
3637        let text = ir(promised);
3638        assert!(text.contains("    unreachable_hint\n"), "{text}");
3639        assert!(!text.contains("call"), "it is not a call to anything:\n{text}");
3640
3641        // The statement after it is still lowered. Continuing to translate a path the program
3642        // promised is dead is one of the things a compiler may do with undefined behaviour, and
3643        // it is the one that keeps a program built at `-O0` behaving the way it was watched to.
3644        let after = body("int g(int x) { __builtin_unreachable(); return x; }\n");
3645        assert!(after.contains("return"), "{after}");
3646
3647        // Both functions are the same instructions, because the hint writes none of them and the
3648        // terminator underneath it writes none either.
3649        let text = asm(promised);
3650        let mine = text.split_once("\nf:\n").expect("a definition").1;
3651        let mine = mine.split_once("\t.size").expect("a definition").0;
3652        let plain = asm("int f(int x) { if (x) return 1; }\n");
3653        let plain = plain.split_once("\nf:\n").expect("a definition").1;
3654        let plain = plain.split_once("\t.size").expect("a definition").0;
3655        assert_eq!(mine, plain);
3656        // The last instruction, rather than the last line, because the unwind record is closed
3657        // after it and a directive is not something the machine runs.
3658        let last = mine.lines().rfind(|line| !line.trim_start().starts_with('.'));
3659        assert_eq!(last.map(str::trim), Some("ret"), "{mine}");
3660        assert!(!mine.contains("ud2"), "{mine}");
3661    }
3662
3663    /// The two names stay apart, which is what having both of them is for.
3664    ///
3665    /// The one the program wrote is what the call is checked against and what a diagnostic about
3666    /// it says, and the one the library defines is what the call ends up carrying. A compiler
3667    /// that kept only the second would report this against `abort`, which is a function the
3668    /// program never mentions.
3669    #[test]
3670    fn a_library_builtin_is_diagnosed_under_the_name_the_program_wrote() {
3671        let mut opts = options();
3672        opts.emit = EmitKind::Ir;
3673        let messages = run(&opts, "void f(void) { __builtin_abort(1); }\n").messages;
3674        assert!(
3675            messages.iter().any(|m| m.contains("__builtin_abort")),
3676            "expected the written name in {messages:?}"
3677        );
3678    }
3679
3680    /// A builtin nothing lowers is refused where it is written, rather than at the link.
3681    ///
3682    /// The names are two with a prototype and one whose type comes from the call it was written in,
3683    /// which is also the one whose prefix is not `__builtin_`. It is the last of the atomic family
3684    /// that is refused, and the older half of that family has nothing left in it at all. What the
3685    /// message has to carry is the name, because the whole complaint about the link error this
3686    /// replaces is that the name in it was one the compiler chose.
3687    #[test]
3688    fn a_builtin_nothing_lowers_is_refused_by_name() {
3689        let mut opts = options();
3690        opts.emit = EmitKind::Ir;
3691        for (builtin, call) in [
3692            ("__builtin_return_address", "(int)(long)__builtin_return_address(0)"),
3693            ("__builtin_alloca", "(int)(long)__builtin_alloca(8)"),
3694            ("__atomic_signal_fence", "(__atomic_signal_fence(5), 0)"),
3695        ] {
3696            let source = format!("int counter;\nint f(void) {{ return {call}; }}\n");
3697            let messages = run(&opts, &source).messages;
3698            let named = messages.iter().any(|m| m.contains(builtin) && m.contains("E0686"));
3699            assert!(named, "expected {builtin} to be refused by name in {messages:?}");
3700        }
3701    }
3702
3703    /// The refusal is about a call and not about the name, so the rest of what C does with one
3704    /// still works.
3705    ///
3706    /// `sizeof` does not evaluate its operand, so nothing is called and there is nothing to
3707    /// refuse; the type of the call is what it asks for and that comes from the front end. A
3708    /// program that defines the name itself gets the function it wrote, which is not what this
3709    /// is for but is what a definition in front of us means.
3710    #[test]
3711    fn what_is_refused_is_the_call_and_not_the_name() {
3712        let text = ir("unsigned long n = sizeof(__builtin_return_address(0));\n");
3713        assert!(text.contains("global @n : i64 = 8,"), "{text}");
3714
3715        let text = ir(concat!(
3716            "void *__builtin_return_address(unsigned x) { return 0; }\n",
3717            "void *f(void) { return __builtin_return_address(0); }\n",
3718        ));
3719        assert!(text.contains("call @__builtin_return_address"), "{text}");
3720    }
3721
3722    /// A `static` function nothing refers to is not emitted, and one that is refered to is.
3723    ///
3724    /// The pair is written as one program so that the two answers come out of one walk. What
3725    /// makes the difference is the call in `main` and nothing else about either definition.
3726    #[test]
3727    fn a_static_function_nothing_refers_to_is_not_emitted() {
3728        let text = ir("static int dropped(void) { return 1; }\n\
3729                       static int kept(void) { return 2; }\n\
3730                       int main(void) { return kept(); }\n");
3731        assert!(text.contains("func @kept"), "{text}");
3732        assert!(!text.contains("dropped"), "{text}");
3733    }
3734
3735    /// The set is transitive, so two of them that only call each other are both dropped.
3736    ///
3737    /// Counting the references to a name would keep this pair, since each is named once, and
3738    /// that is the mistake this is here to catch: what decides it is whether a root reaches the
3739    /// definition, and a root is something the file has a reason to emit on its own.
3740    #[test]
3741    fn two_static_functions_that_only_call_each_other_are_both_dropped() {
3742        let text = ir("static int ping(void);\n\
3743                       static int pong(void) { return ping(); }\n\
3744                       static int ping(void) { return pong(); }\n\
3745                       int main(void) { return 0; }\n");
3746        assert!(!text.contains("ping"), "{text}");
3747        assert!(!text.contains("pong"), "{text}");
3748    }
3749
3750    /// Everything that names a function keeps it, whether or not the name is being called.
3751    ///
3752    /// An address taken in a body, an image that holds one, and a body that is only reached
3753    /// through another `static` function are three different ways for a definition to be needed
3754    /// and none of them is a call at the top level of a reachable function.
3755    #[test]
3756    fn naming_a_static_function_anywhere_keeps_it() {
3757        let text = ir("static int by_address(void) { return 1; }\n\
3758                       static int in_an_image(void) { return 2; }\n\
3759                       static int deeper(void) { return 3; }\n\
3760                       static int reaches_deeper(void) { return deeper(); }\n\
3761                       static int (*table[1])(void) = {in_an_image};\n\
3762                       int main(void) {\n\
3763                         int (*p)(void) = by_address;\n\
3764                         return p() + table[0]() + reaches_deeper();\n\
3765                       }\n");
3766        for kept in ["by_address", "in_an_image", "deeper", "reaches_deeper"] {
3767            assert!(text.contains(&format!("func @{kept}")), "expected {kept} in:\n{text}");
3768        }
3769    }
3770
3771    /// An attribute that says something outside the file reaches it keeps the definition.
3772    ///
3773    /// None of the five is implemented as anything else yet, and this is the part of each of
3774    /// them that a program notices first: a symbol a linker script names or a function the
3775    /// run-up to `main` calls is not written about anywhere a C file can see.
3776    #[test]
3777    fn an_attribute_keeps_a_static_function_nothing_refers_to() {
3778        for attribute in ["used", "retain", "constructor", "destructor", "__used__"] {
3779            let source = format!(
3780                "__attribute__(({attribute})) static int kept(void) {{ return 1; }}\n\
3781                 int main(void) {{ return 0; }}\n"
3782            );
3783            let text = ir(&source);
3784            assert!(text.contains("func @kept"), "for {attribute}:\n{text}");
3785        }
3786    }
3787
3788    /// A function with external linkage is emitted whatever this file does with it, because
3789    /// another one may call it, and that is what external linkage is.
3790    #[test]
3791    fn a_function_anything_could_call_is_emitted_without_being_called() {
3792        let text =
3793            ir("int nobody_here_calls_it(void) { return 1; }\nint main(void) { return 0; }\n");
3794        assert!(text.contains("func @nobody_here_calls_it"), "{text}");
3795    }
3796
3797    /// Four of the classification builtins are operators C already has, and become those.
3798    ///
3799    /// What the standard's macro promises over the operator is that it does not raise the
3800    /// invalid operation exception on a quiet NaN. This compiler does not model floating point
3801    /// exceptions, so there is nothing left for a node of its own to carry and a second way of
3802    /// spelling a comparison would be a second thing every pass has to know about.
3803    #[test]
3804    fn a_classification_c_has_an_operator_for_is_that_operator() {
3805        for (builtin, operator) in [
3806            ("__builtin_isgreater", "binary >"),
3807            ("__builtin_isgreaterequal", "binary >="),
3808            ("__builtin_isless", "binary <"),
3809            ("__builtin_islessequal", "binary <="),
3810        ] {
3811            let source = format!("int f(double x, double y) {{ return {builtin}(x, y); }}\n");
3812            let text = tast(&source);
3813            assert!(text.contains(&format!("{operator} : int")), "for {builtin}:\n{text}");
3814        }
3815    }
3816
3817    /// The rest of the family are comparisons in the IR and never a call to anything.
3818    ///
3819    /// `math.h` defines the macro of each of these names as the builtin of the same name, so
3820    /// there is no function under any of them for a call to reach. `isunordered` and
3821    /// `islessgreater` are predicates the IR's comparison already has, `isnan` is the value that
3822    /// is unordered with itself, and the two that ask about a magnitude are written against the
3823    /// infinities. `signbit` is the one that is not a question about the value, since a negative
3824    /// zero compares equal to a positive one, so its answer comes from the bits.
3825    #[test]
3826    fn the_classification_builtins_are_comparisons_and_not_calls() {
3827        let text = body("int f(double x, double y) { return __builtin_isunordered(x, y); }\n");
3828        assert_eq!(
3829            text,
3830            "block0(%0: f64, %1: f64):\n    %2 = fcmp uno %0, %1\n    %3 = zext.i32 \
3831                          %2\n    return %3\n"
3832        );
3833
3834        // Not `x != y`, which is true when the two are unordered and so is true of a NaN.
3835        let text = body("int f(double x, double y) { return __builtin_islessgreater(x, y); }\n");
3836        assert!(text.contains("fcmp one %0, %1"), "{text}");
3837
3838        let text = body("int f(double x) { return __builtin_isnan(x); }\n");
3839        assert!(text.contains("fcmp uno %0, %0"), "{text}");
3840
3841        let text = body("int f(double x) { return __builtin_isinf(x); }\n");
3842        assert!(text.contains("fconst.f64 0x7ff0000000000000"), "{text}");
3843        assert!(text.contains("fconst.f64 0xfff0000000000000"), "{text}");
3844        assert!(text.contains("%3 = fcmp oeq %0, %1"), "{text}");
3845        assert!(text.contains("%4 = fcmp oeq %0, %2"), "{text}");
3846        assert!(text.contains("%5 = or %3, %4"), "{text}");
3847
3848        // Strictly between the two infinities, which a NaN is not, because an ordered comparison
3849        // against either of them is false. That is what makes this one test rather than two.
3850        let text = body("int f(double x) { return __builtin_isfinite(x); }\n");
3851        assert!(text.contains("%3 = fcmp olt %2, %0"), "{text}");
3852        assert!(text.contains("%4 = fcmp olt %0, %1"), "{text}");
3853        assert!(text.contains("%5 = and %3, %4"), "{text}");
3854
3855        let text = body("int f(double x) { return __builtin_signbit(x); }\n");
3856        assert!(text.contains("%1 = bitcast.i64 %0"), "{text}");
3857        assert!(text.contains("icmp slt %1, %2"), "{text}");
3858
3859        // The same question of a value in the target's widest format, where the bits are eighty
3860        // and the object they sit in is sixteen bytes.
3861        let text = body("int f(long double x) { return __builtin_signbitl(x); }\n");
3862        assert!(text.contains("%1 = bitcast.i80 %0"), "{text}");
3863
3864        // The operand is evaluated once however many times it is compared, which is the whole
3865        // reason these are nodes rather than a rewriting into the operators.
3866        let text = body("double g(void);\nint f(void) { return __builtin_isnan(g()); }\n");
3867        assert_eq!(text.matches("call @g()").count(), 1, "{text}");
3868    }
3869
3870    /// A spelling that names a width converts its argument before it asks.
3871    ///
3872    /// gcc gives `__builtin_isinff` a `float` parameter and `__builtin_isinf` no parameter type
3873    /// at all, and the difference is visible rather than academic: `1e300` does not fit in a
3874    /// `float`, so converting it first is an infinity and not converting it is not. Both numbers
3875    /// here are what gcc 16 gives.
3876    #[test]
3877    fn a_classification_spelling_that_names_a_width_converts_before_it_asks() {
3878        let text = ir(concat!(
3879            "int a = __builtin_isinff(1e300);\n",
3880            "int b = __builtin_isinf(1e300);\n",
3881            // Folded here rather than compared at run time, because a question about a value has
3882            // an answer as soon as the value is a constant, and an initializer for an object
3883            // with static storage duration has to have one.
3884            "int c = __builtin_isnan(0.0);\n",
3885            "int d = __builtin_signbit(-0.0);\n",
3886            "int e = __builtin_islessgreater(1.0, 2.0);\n",
3887        ));
3888        assert!(text.contains("global @a : i32 = 1,"), "{text}");
3889        assert!(text.contains("global @b : i32 = 0,"), "{text}");
3890        assert!(text.contains("global @c : i32 = 0,"), "{text}");
3891        assert!(text.contains("global @d : i32 = 1,"), "{text}");
3892        assert!(text.contains("global @e : i32 = 1,"), "{text}");
3893    }
3894
3895    /// An argument that is not floating point is refused, in gcc's words.
3896    #[test]
3897    fn a_classification_builtin_refuses_an_argument_that_is_not_floating_point() {
3898        let mut opts = options();
3899        opts.emit = EmitKind::Ir;
3900        let source = concat!(
3901            "int a(int x) { return __builtin_isnan(x); }\n",
3902            "int b(int x, int y) { return __builtin_isunordered(x, y); }\n",
3903            "int c(double x) { return __builtin_isnan(x, x); }\n",
3904        );
3905        let messages = run(&opts, source).messages;
3906        assert_eq!(
3907            messages,
3908            [
3909                "/main.c:1:23: error: non-floating-point argument in call to function \
3910                 '__builtin_isnan' [E0685]",
3911                "/main.c:2:30: error: non-floating-point arguments in call to function \
3912                 '__builtin_isunordered' [E0685]",
3913                "/main.c:3:26: error: too many arguments to function '__builtin_isnan' [E0511]",
3914            ]
3915        );
3916    }
3917
3918    /// The three of the family that need a constant of the format other than an infinity.
3919    ///
3920    /// `isnormal` is the one that needs the smallest normal, and it is asked of the magnitude, so
3921    /// the sign comes off first and what is left is the same shape as `isfinite`. `isinf_sign` is
3922    /// the one whose answer is a number: the two comparisons `isinf` builds, subtracted rather
3923    /// than combined. `fpclassify` is four questions of one value and five answers to pick from,
3924    /// and the picking is a mask because all five are constants and neither of them can have an
3925    /// effect.
3926    #[test]
3927    fn the_last_three_classification_builtins_are_comparisons_and_not_calls() {
3928        let text = body("int f(double x) { return __builtin_isnormal(x); }\n");
3929        // The sign off, which is the magnitude, and then the range, asked of the bits rather than
3930        // of the number, since the encoding of a value whose sign bit is clear rises with the
3931        // value in every format this compiles for.
3932        assert!(text.contains("%1 = bitcast.i64 %0"), "{text}");
3933        assert!(text.contains("%2 = iconst.i64 9223372036854775807"), "{text}");
3934        assert!(text.contains("%3 = and %1, %2"), "{text}");
3935        assert!(text.contains("%4 = iconst.i64 4503599627370496"), "{text}");
3936        assert!(text.contains("%5 = iconst.i64 9218868437227405312"), "{text}");
3937        assert!(text.contains("%6 = icmp uge %3, %4"), "{text}");
3938        assert!(text.contains("%7 = icmp ult %3, %5"), "{text}");
3939        assert!(text.contains("%8 = and %6, %7"), "{text}");
3940
3941        // The same question in the target's widest format, where the smallest normal has the
3942        // leading significand bit stored rather than implied, so its encoding is two bits and not
3943        // one.
3944        let text = body("int f(long double x) { return __builtin_isnormal(x); }\n");
3945        assert!(text.contains("%4 = iconst.i80 27670116110564327424"), "{text}");
3946        assert!(text.contains("%5 = iconst.i80 604453686435277732577280"), "{text}");
3947
3948        let text = body("int f(double x) { return __builtin_isinf_sign(x); }\n");
3949        assert!(text.contains("%3 = fcmp oeq %0, %1"), "{text}");
3950        assert!(text.contains("%4 = fcmp oeq %0, %2"), "{text}");
3951        assert!(text.contains("%7 = sub %5, %6"), "{text}");
3952
3953        let text = body("int f(double x) { return __builtin_fpclassify(0, 1, 2, 3, 4, x); }\n");
3954        assert!(text.contains("fcmp uno %0, %0"), "{text}");
3955        assert!(text.contains("fcmp oeq %0, %6"), "{text}");
3956        // Four questions, each of them a bit widened into the type of the answer and then spread
3957        // into a mask that picks between the answer and whatever the questions after it settled
3958        // on. Nothing sign extends, because no rule lowers a sign extension out of one bit.
3959        assert_eq!(text.matches(" = zext.i32 ").count(), 4, "{text}");
3960        assert_eq!(text.matches(" = xor ").count(), 4, "{text}");
3961        assert!(!text.contains("call"), "{text}");
3962
3963        // The value is evaluated once however many questions are asked of it, which is the whole
3964        // reason `fpclassify` is a node rather than the chain of tests it turns into.
3965        let text = body(concat!(
3966            "double g(void);\n",
3967            "int f(void) { return __builtin_fpclassify(0, 1, 2, 3, 4, g()); }\n",
3968        ));
3969        assert_eq!(text.matches("call @g()").count(), 1, "{text}");
3970    }
3971
3972    /// Each of the three answers a constant where its operand is one.
3973    ///
3974    /// glibc's `fpclassify` macro is exactly this builtin, so a program that writes
3975    /// `fpclassify(0.0)` in a static initializer is writing this, and it has to have a value at
3976    /// translation time or the program is refused rather than merely compiled slowly. Every
3977    /// number here is what gcc 16 gives.
3978    #[test]
3979    fn the_last_three_classification_builtins_fold_where_their_operand_is_a_constant() {
3980        let text = ir(concat!(
3981            "int a = __builtin_isnormal(1.0);\n",
3982            "int b = __builtin_isnormal(0.0);\n",
3983            "int c = __builtin_isnormal(1.0 / 0.0);\n",
3984            "int d = __builtin_isinf_sign(-1.0 / 0.0);\n",
3985            "int e = __builtin_isinf_sign(1.0);\n",
3986            "int g = __builtin_fpclassify(0, 1, 2, 3, 4, 0.0);\n",
3987            "int h = __builtin_fpclassify(0, 1, 2, 3, 4, 1.0);\n",
3988            "int i = __builtin_fpclassify(0, 1, 2, 3, 4, 1.0 / 0.0);\n",
3989        ));
3990        assert!(text.contains("global @a : i32 = 1,"), "{text}");
3991        assert!(text.contains("global @b : i32 = 0,"), "{text}");
3992        assert!(text.contains("global @c : i32 = 0,"), "{text}");
3993        assert!(text.contains("global @d : i32 = -1,"), "{text}");
3994        assert!(text.contains("global @e : i32 = 0,"), "{text}");
3995        assert!(text.contains("global @g : i32 = 4,"), "{text}");
3996        assert!(text.contains("global @h : i32 = 2,"), "{text}");
3997        assert!(text.contains("global @i : i32 = 1,"), "{text}");
3998    }
3999
4000    /// `fpclassify` refuses what gcc refuses, in gcc's words.
4001    ///
4002    /// The five answers have to be integer constant expressions, because what the builtin does is
4003    /// pick one of them and a pick between values that are not known here would be a chain of
4004    /// conditionals over expressions the call has already evaluated.
4005    #[test]
4006    fn fpclassify_refuses_an_answer_that_is_not_an_integer_constant() {
4007        let mut opts = options();
4008        opts.emit = EmitKind::Ir;
4009        let source = concat!(
4010            "int a(double x, int n) { return __builtin_fpclassify(0, 1, n, 3, 4, x); }\n",
4011            "int b(double x) { return __builtin_fpclassify(0, 1, 2, 3, x); }\n",
4012            "int c(int x) { return __builtin_fpclassify(0, 1, 2, 3, 4, x); }\n",
4013        );
4014        let messages = run(&opts, source).messages;
4015        assert_eq!(
4016            messages,
4017            [
4018                "/main.c:1:60: error: non-const integer argument 3 in call to function \
4019                 '__builtin_fpclassify' [E0687]",
4020                "/main.c:2:26: error: too few arguments to function '__builtin_fpclassify' \
4021                 [E0511]",
4022                "/main.c:3:23: error: non-floating-point argument in call to function \
4023                 '__builtin_fpclassify' [E0685]",
4024            ]
4025        );
4026    }
4027
4028    /// A builtin whose answer is a constant is one, and is not a call to the library.
4029    ///
4030    /// This is the reason the family is answered in the front end at all. `double x =
4031    /// __builtin_inf();` at file scope initializes an object with static storage duration, so
4032    /// there is no point in the program at which a call could be made, and a compiler that
4033    /// lowered it to one would reject a program gcc accepts. Every number here is the encoding
4034    /// gcc 16 gives on x86-64.
4035    #[test]
4036    fn a_builtin_whose_answer_is_a_constant_is_one_and_not_a_call() {
4037        let text = ir(concat!(
4038            "double a = __builtin_inf();\n",
4039            "float b = __builtin_huge_valf();\n",
4040            "long double c = __builtin_infl();\n",
4041            "double d = __builtin_huge_val();\n",
4042        ));
4043        assert!(text.contains("global @a : f64 = 0x7ff0000000000000,"), "{text}");
4044        assert!(text.contains("global @b : f32 = 0x7f800000,"), "{text}");
4045        assert!(text.contains("f80 0x7fff8000000000000000"), "{text}");
4046        assert!(text.contains("global @d : f64 = 0x7ff0000000000000,"), "{text}");
4047        assert!(!text.contains("call"), "{text}");
4048    }
4049
4050    /// A nan is written with the payload the program asked for.
4051    ///
4052    /// The string is read the way `strtoull` reads a number, which is what the library function
4053    /// of the same name does with it, and a string that is not one at all leaves the call for the
4054    /// library to answer at run time. A quiet nan has the high fraction bit set and a signalling
4055    /// one does not, except that a signalling nan with nothing in it would be an infinity, so it
4056    /// gets the next bit down instead. Every encoding here was measured against gcc 16, the two
4057    /// `long double` ones on a machine with the x87 format.
4058    #[test]
4059    fn a_nan_is_written_with_the_payload_the_program_asked_for() {
4060        let text = ir(concat!(
4061            "double a = __builtin_nan(\"\");\n",
4062            "double b = __builtin_nan(\"0x1\");\n",
4063            // Octal, since there is a leading zero, so this is eight and not ten.
4064            "double c = __builtin_nan(\"010\");\n",
4065            "double d = __builtin_nans(\"\");\n",
4066            "double e = __builtin_nans(\"0x1\");\n",
4067            "float f = __builtin_nanf(\"0x1\");\n",
4068            "float g = __builtin_nansf(\"\");\n",
4069            "long double h = __builtin_nansl(\"\");\n",
4070        ));
4071        assert!(text.contains("global @a : f64 = 0x7ff8000000000000,"), "{text}");
4072        assert!(text.contains("global @b : f64 = 0x7ff8000000000001,"), "{text}");
4073        assert!(text.contains("global @c : f64 = 0x7ff8000000000008,"), "{text}");
4074        assert!(text.contains("global @d : f64 = 0x7ff4000000000000,"), "{text}");
4075        assert!(text.contains("global @e : f64 = 0x7ff0000000000001,"), "{text}");
4076        assert!(text.contains("global @f : f32 = 0x7fc00001,"), "{text}");
4077        assert!(text.contains("global @g : f32 = 0x7fa00000,"), "{text}");
4078        assert!(text.contains("f80 0x7fffa000000000000000"), "{text}");
4079
4080        // A payload that is not a number, and one that is not known until run time, are both
4081        // left to the library, which is the same thing gcc emits for either of them.
4082        let text = ir(concat!(
4083            "double f(const char *p) { return __builtin_nan(p); }\n",
4084            "double g(void) { return __builtin_nans(\"1x\"); }\n",
4085        ));
4086        assert_eq!(text.matches("call @nan(").count(), 1, "{text}");
4087        assert_eq!(text.matches("call @nans(").count(), 1, "{text}");
4088    }
4089
4090    /// The length and the order of a string literal are known here.
4091    ///
4092    /// A program that asks for either of them is asking about something the translation already
4093    /// has in front of it, and folding is not only an optimization: `execute/921007-1.c` in the
4094    /// torture suite calls `__builtin_strcmp` in a file that defines its own `strcmp` with a
4095    /// different signature, so leaving the call behind is a name collision that gcc does not
4096    /// have. The comparison is over `unsigned char`, which is why the second one is negative.
4097    #[test]
4098    fn the_length_and_the_order_of_a_string_literal_are_known_here() {
4099        let text = ir(concat!(
4100            "unsigned long a = __builtin_strlen(\"hello\");\n",
4101            "unsigned long b = __builtin_strlen(\"a\\0bc\");\n",
4102            "int c = __builtin_strcmp(\"X\", \"X\\376\") < 0;\n",
4103            "int d = __builtin_strcmp(\"abc\", \"abc\");\n",
4104            "int e = __builtin_strcmp(\"abc\", \"ab\") > 0;\n",
4105        ));
4106        assert!(text.contains("global @a : i64 = 5,"), "{text}");
4107        assert!(text.contains("global @b : i64 = 1,"), "{text}");
4108        assert!(text.contains("global @c : i32 = 1,"), "{text}");
4109        assert!(text.contains("global @d : i32 = 0,"), "{text}");
4110        assert!(text.contains("global @e : i32 = 1,"), "{text}");
4111        assert!(!text.contains("call"), "{text}");
4112
4113        // An argument that is not a literal is the library's to answer, as it has to be.
4114        let text = ir("unsigned long f(const char *p) { return __builtin_strlen(p); }\n");
4115        assert!(text.contains("call @strlen("), "{text}");
4116    }
4117
4118    /// A sign builtin is a mask over the bits, and is not a call.
4119    ///
4120    /// `fabs` and `copysign` are in the math library rather than the C one, so a program that
4121    /// only ever wrote the prefixed spelling never asked for `-lm` and a call left behind here
4122    /// would not link. Neither needs anything the library has: one clears the sign bit and the
4123    /// other takes it from the second operand, and every other bit goes through untouched.
4124    #[test]
4125    fn a_sign_builtin_is_a_mask_over_the_bits_and_not_a_call() {
4126        let text = body("double f(double x) { return __builtin_fabs(x); }\n");
4127        assert!(text.contains("bitcast.i64 %0"), "{text}");
4128        assert!(text.contains("iconst.i64 9223372036854775807"), "{text}");
4129        assert!(text.contains("and %1, %2"), "{text}");
4130        assert!(text.contains("bitcast.f64 %3"), "{text}");
4131        assert!(!text.contains("call"), "{text}");
4132
4133        let text = body("double f(double x, double y) { return __builtin_copysign(x, y); }\n");
4134        assert!(text.contains("iconst.i64 -9223372036854775808"), "{text}");
4135        assert!(text.contains("%8 = or %4, %7"), "{text}");
4136        assert!(!text.contains("call"), "{text}");
4137
4138        // The x87 format, whose value is eighty bits sitting in an object of sixteen. The mask is
4139        // as wide as the value and not as wide as the object, so the padding is not part of it.
4140        let text = body("long double f(long double x) { return __builtin_fabsl(x); }\n");
4141        assert!(text.contains("bitcast.i80 %0"), "{text}");
4142        assert!(text.contains("bitcast.f80"), "{text}");
4143
4144        // The width a name does not spell out is `double`, so a `float` argument widens first and
4145        // the answer is a `double`, which is what gcc's declaration of it says.
4146        let text = body("double f(float x) { return __builtin_fabs(x); }\n");
4147        assert!(text.contains("fpext.f64 %0"), "{text}");
4148        assert!(text.contains("bitcast.i64 %1"), "{text}");
4149    }
4150
4151    /// The sign builtins answer a zero and a nan the way the bits say.
4152    ///
4153    /// This is why they are described over the bits rather than written with comparisons and
4154    /// negation. A negative zero compares equal to a positive one and has a sign bit to clear,
4155    /// and a nan compares equal to nothing at all and keeps its payload through both operations.
4156    /// `execute/ieee/copysign1.c` in the torture suite is the test that notices, because it
4157    /// compares its answers with `memcmp`. Every number here is what gcc 16 gives, the two in the
4158    /// x87 format measured on a machine that has it.
4159    #[test]
4160    fn the_sign_builtins_answer_a_zero_and_a_nan_the_way_the_bits_say() {
4161        let text = ir(concat!(
4162            "double a = __builtin_fabs(-3.5);\n",
4163            "double b = __builtin_copysign(1.0, -0.0);\n",
4164            "double c = __builtin_copysign(0.0, -2.0);\n",
4165            // The payload survives both, and only the sign bit moves.
4166            "double d = __builtin_copysign(-__builtin_nan(\"\"), 1.0);\n",
4167            "double e = __builtin_fabs(-__builtin_nan(\"0x1\"));\n",
4168            "float g = __builtin_copysignf(-0.0f, 2.0f);\n",
4169            "long double h = __builtin_copysignl(1.0L, -1.0L);\n",
4170            "long double i = __builtin_fabsl(-__builtin_infl());\n",
4171        ));
4172        assert!(text.contains("global @a : f64 = 0x400c000000000000,"), "{text}");
4173        assert!(text.contains("global @b : f64 = 0xbff0000000000000,"), "{text}");
4174        assert!(text.contains("global @c : f64 = 0x8000000000000000,"), "{text}");
4175        assert!(text.contains("global @d : f64 = 0x7ff8000000000000,"), "{text}");
4176        assert!(text.contains("global @e : f64 = 0x7ff8000000000001,"), "{text}");
4177        assert!(text.contains("global @g : f32 = 0x0,"), "{text}");
4178        assert!(text.contains("f80 0xbfff8000000000000000"), "{text}");
4179        assert!(text.contains("f80 0x7fff8000000000000000"), "{text}");
4180    }
4181
4182    /// A `constexpr` object is a named constant, which is the whole reason the keyword exists.
4183    ///
4184    /// C23 6.6p8 puts two of them on the list an integer constant expression is built from: one
4185    /// of an arithmetic type, and a member of one of a structure or union type. A subscript of
4186    /// one is not on the list and is a variably modified type in gcc 16 as well, and every
4187    /// number here is what gcc 16 gives on x86-64.
4188    #[test]
4189    fn a_constexpr_object_is_a_constant_wherever_one_is_required() {
4190        let text = ir(concat!(
4191            "constexpr int side = 4;\n",
4192            "constexpr int wider = side + 1;\n",
4193            "constexpr double half = 1.5;\n",
4194            "struct point { int x; int y; };\n",
4195            "constexpr struct point origin = { 5, 6 };\n",
4196            "int square[side * side];\n",
4197            "int rectangle[wider];\n",
4198            "int rounded[(int)half * 2];\n",
4199            "int across[origin.y];\n",
4200            "enum named { four = side };\n",
4201            "int e = four;\n",
4202        ));
4203        assert!(text.contains("global @square : bytes 64 ="), "{text}");
4204        assert!(text.contains("global @rectangle : bytes 20 ="), "{text}");
4205        assert!(text.contains("global @rounded : bytes 8 ="), "{text}");
4206        assert!(text.contains("global @across : bytes 24 ="), "{text}");
4207        assert!(text.contains("global @e : i32 = 4,"), "{text}");
4208
4209        // A `const` object is not one of them, which is what makes `int a[n];` a variable
4210        // length array in C and is the distinction the keyword was added to draw.
4211        let mut opts = options();
4212        opts.emit = EmitKind::Ir;
4213        let konst = "const int n = 1;\nint a[n];\n";
4214        let message = "/main.c:2:5: error: variably modified 'a' at file scope [E0538]";
4215        assert_eq!(run(&opts, konst).messages, [message]);
4216
4217        // Nor is a subscript of one, which gcc 16 refuses in the same words.
4218        let subscript = "constexpr int t[3] = { 1, 2, 3 };\nint a[t[1]];\n";
4219        assert_eq!(run(&opts, subscript).messages, [message]);
4220
4221        // And `constexpr` implies `const`, so the address of one is an address of a `const`.
4222        let address = "constexpr int c = 3;\nint *p = &c;\n";
4223        let warning = "/main.c:2:6: warning: initialization discards 'const' qualifier from \
4224             pointer target type [E0514]";
4225        assert_eq!(run(&opts, address).messages, [warning]);
4226    }
4227
4228    /// A definition that names its parameters and then declares them under the list.
4229    ///
4230    /// The declarations say what the types are, 6.9.1p6, and what the function takes is those
4231    /// types with the default argument promotions over them, which is what a caller of an
4232    /// unprototyped function hands over. A prototype already in scope overrules the promoted
4233    /// types, since a header saying `int narrow(char);` over a definition written this way is
4234    /// the pairing all the code written this way relies on and 6.7.6.3p15 is read that way by
4235    /// every compiler.
4236    #[test]
4237    fn an_old_style_definition_takes_its_types_from_the_declarations_under_its_list() {
4238        // C17, since the default dialect is the one that warns about the form and this is
4239        // about what it means rather than about the warning.
4240        let mut opts = options();
4241        opts.std = Std::C17;
4242        let source = concat!(
4243            "int add(a, b)\n",
4244            "int a;\n",
4245            "int b;\n",
4246            "{ return a + b; }\n",
4247            "int promoted(c)\n",
4248            "char c;\n",
4249            "{ return c; }\n",
4250            "int narrow(char);\n",
4251            "int narrow(c)\n",
4252            "char c;\n",
4253            "{ return c; }\n",
4254            "int first(a)\n",
4255            "int a[4];\n",
4256            "{ return a[0]; }\n",
4257        );
4258        let result = run(&opts, source);
4259        assert_eq!(result.messages, Vec::<String>::new(), "expected this to compile:\n{source}");
4260        let text = result.text();
4261        assert!(text.contains("add : int(int, int) function external defined"), "{text}");
4262        assert!(text.contains("promoted : int(int) function external defined"), "{text}");
4263        // The body still sees the `char` it was declared as, whatever the caller hands over.
4264        assert!(text.contains("c : char object automatic defined"), "{text}");
4265        assert!(text.contains("narrow : int(char) function external defined"), "{text}");
4266        // An array parameter is a pointer here as much as it is in a prototype.
4267        assert!(text.contains("first : int(int *) function external defined"), "{text}");
4268    }
4269
4270    /// What the two halves of an old-style parameter list can disagree about.
4271    ///
4272    /// Each of these is a sentence gcc 16 has, and every message below is the one it prints,
4273    /// read off it on x86-64 rather than reasoned about. The last two are the dialect: a name
4274    /// with no declaration is an `int` in C89 and a diagnostic from C99 on, and the whole form
4275    /// left the language in C23, where gcc still takes it and warns.
4276    #[test]
4277    fn the_two_halves_of_an_old_style_parameter_list_have_to_agree() {
4278        let mut opts = options();
4279        opts.std = Std::C17;
4280        for (source, message) in [
4281            ("int f(a, a)\nint a;\n{ return a; }\n", "1:10: error: multiple parameters named 'a'"),
4282            (
4283                "int f(a)\nint a;\nint b;\n{ return a; }\n",
4284                "3:5: error: declaration for parameter 'b' but no such parameter",
4285            ),
4286            ("int f(a)\nint a;\nint a;\n{ return a; }\n", "3:5: error: redefinition of parameter"),
4287            ("int f(a)\nint a = 1;\n{ return a; }\n", "2:5: error: parameter 'a' is initialized"),
4288            (
4289                "int f(a)\nstatic int a;\n{ return a; }\n",
4290                "2:12: error: storage class specified for parameter 'a'",
4291            ),
4292            (
4293                "int f(char);\nint f(a)\nshort a;\n{ return a; }\n",
4294                "2:7: error: argument 'a' doesn't match prototype",
4295            ),
4296        ] {
4297            let result = run(&opts, source);
4298            assert!(result.failed(), "expected this to fail:\n{source}");
4299            assert!(result.messages[0].contains(message), "{:?}", result.messages);
4300        }
4301
4302        // A name the declarations never mention. C89 gave it an `int` and gcc still takes it
4303        // in that dialect, and every dialect after it made the same line a diagnostic.
4304        let implicit = "int f(a, b)\nint a;\n{ return a + b; }\n";
4305        let mut older = options();
4306        older.std = Std::C89;
4307        assert!(!run(&older, implicit).failed(), "{:?}", run(&older, implicit).messages);
4308        let result = run(&opts, implicit);
4309        assert!(
4310            result.messages[0].contains("1:10: error: type of 'b' defaults to 'int'"),
4311            "{:?}",
4312            result.messages
4313        );
4314
4315        // C23 took the form out of the language and gcc kept accepting it with a warning, and
4316        // a warning is what this is, because the code written this way is not going to be
4317        // rewritten and refusing it would put the compiler out of reach of it.
4318        let mut newer = options();
4319        newer.std = Std::C23;
4320        let plain = "int f(a)\nint a;\n{ return a; }\n";
4321        let result = run(&newer, plain);
4322        assert!(!result.failed(), "{:?}", result.messages);
4323        assert_eq!(
4324            result.messages,
4325            ["/main.c:1:5: warning: old-style function definition [E0412]"]
4326        );
4327        assert!(run(&opts, plain).messages.is_empty(), "and nothing to say in the dialects before");
4328    }
4329
4330    /// The two obsolete designators, which are silent until `-pedantic` asks about them.
4331    ///
4332    /// `[3] 7` is what GCC had for an array before C99 settled on `[3] = 7`, and `x: 7` is the
4333    /// same era's spelling for a member. Both are still in code written against a compiler of
4334    /// that era, and gcc 16 takes both without a word unless it is asked to be pedantic, which
4335    /// is where the columns below come from as well.
4336    #[test]
4337    fn the_obsolete_designators_are_taken_and_are_pedantic_warnings() {
4338        let array = "int a[8] = { [3] 7 };\n";
4339        let member = "struct s { int x; } v = { x: 7 };\n";
4340        for source in [array, member] {
4341            let result = run(&options(), source);
4342            assert!(!result.failed(), "{:?}", result.messages);
4343            assert!(result.messages.is_empty(), "nothing to say: {:?}", result.messages);
4344        }
4345
4346        let mut asked = options();
4347        asked.pedantic = true;
4348        assert_eq!(
4349            run(&asked, array).messages,
4350            ["/main.c:1:18: warning: obsolete designator, write `[i] =` instead [E0415]"]
4351        );
4352        assert_eq!(
4353            run(&asked, member).messages,
4354            ["/main.c:1:27: warning: obsolete designator, write `.field =` instead [E0413]"]
4355        );
4356    }
4357
4358    /// A type nothing is ever an object of is a type `sizeof` still has to answer about, which
4359    /// is what `991014-1.c` in the gcc.c-torture execution suite asks.
4360    ///
4361    /// The limit is `PTRDIFF_MAX` and it is the same one for an array and for a record, so a
4362    /// record of every byte an object may have is laid out and one byte more is refused. All
4363    /// four numbers are what gcc 16 gives on x86-64.
4364    #[test]
4365    fn a_type_is_refused_when_it_passes_the_largest_object_and_not_before() {
4366        let text = ir(concat!(
4367            "struct huge_struct { short buf[(1L << 62) - 256]; int a, b, c, d; };\n",
4368            "struct brim { char buf[9223372036854775807L]; };\n",
4369            "struct bitty { char buf[9223372036854775800L]; int x : 1; };\n",
4370            "unsigned long h = sizeof(struct huge_struct);\n",
4371            "unsigned long b = sizeof(struct brim);\n",
4372            "unsigned long y = sizeof(struct bitty);\n",
4373        ));
4374        assert!(text.contains("global @h : i64 = 9223372036854775312,"), "{text}");
4375        assert!(text.contains("global @b : i64 = 9223372036854775807,"), "{text}");
4376        assert!(text.contains("global @y : i64 = 9223372036854775804,"), "{text}");
4377
4378        let mut opts = options();
4379        opts.emit = EmitKind::Ir;
4380        let over = "struct over { char buf[9223372036854775800L]; char x[8]; };\n";
4381        let message = "/main.c:1:1: error: type 'struct over' is too large [E0560]";
4382        assert_eq!(run(&opts, over).messages, [message]);
4383        let array = "struct wide { short buf[1L << 62]; };\n";
4384        let message = "/main.c:1:25: error: size of array 'buf' exceeds \
4385             maximum object size '9223372036854775807' [E0537]";
4386        assert_eq!(run(&opts, array).messages[0], message);
4387    }
4388
4389    /// A byte in the source that is not part of a character, which only a literal may hold.
4390    ///
4391    /// The source cannot be a `&str` here, which is the whole point: a file is bytes and only
4392    /// mostly text.
4393    fn compile_bytes(source: &[u8]) -> Compiled {
4394        let mut opts = options();
4395        opts.emit = EmitKind::Ir;
4396        let mut fs = MemoryFileSystem::new();
4397        fs.insert("/main.c", source.to_vec());
4398        compile(&opts, "/main.c", &fs)
4399    }
4400
4401    /// A raw byte inside a string literal is that byte, which gcc has always taken and which is
4402    /// the only place in a source file where a byte does not have to be part of a character.
4403    /// Replacing it would give the object three bytes rather than one, since the replacement
4404    /// character is three bytes of UTF-8, so the object would not be the one that was written
4405    /// even where the diagnostic is ignored. Anywhere else the byte is still a mistake, which
4406    /// is where gcc draws the same line.
4407    #[test]
4408    fn a_byte_that_is_not_a_character_is_kept_in_a_literal_and_refused_outside_one() {
4409        let mut source = b"char s[] = \"a".to_vec();
4410        source.push(0xff);
4411        source.extend_from_slice(b"b\";\nchar c = '");
4412        source.push(0xff);
4413        source.extend_from_slice(b"';\n");
4414        let result = compile_bytes(&source);
4415        assert_eq!(result.messages, Vec::<String>::new(), "a raw byte in a literal is that byte");
4416        assert!(result.text().contains(r#"bytes "a\ffb\00""#), "{}", result.text());
4417        // Plain `char` is signed on this target, so the constant is minus one rather than 255.
4418        assert!(result.text().contains("global @c : i8 = -1,"), "{}", result.text());
4419
4420        let mut stray = b"int a".to_vec();
4421        stray.push(0xff);
4422        stray.extend_from_slice(b" = 1;\n");
4423        let result = compile_bytes(&stray);
4424        assert!(
4425            result.messages.iter().any(|m| m.contains("source is not valid UTF-8 here")),
4426            "{:?}",
4427            result.messages
4428        );
4429    }
4430
4431    #[test]
4432    fn an_object_becomes_a_global_with_an_image_and_a_function_becomes_a_func() {
4433        let text = ir("int x = 7;\nint add(int a, int b) { return a + b; }\n");
4434        assert!(text.contains("global @x : i32 = 7, align 4, linkage(external)\n"), "{text}");
4435        let expected = "\
4436func @add(i32, i32) -> i32, linkage(external) {
4437block0(%0: i32, %1: i32):
4438    %2 = add.nsw %0, %1
4439    return %2
4440}
4441";
4442        assert!(text.contains(expected), "{text}");
4443    }
4444
4445    #[test]
4446    fn a_local_nothing_takes_the_address_of_is_a_value_and_never_a_stack_slot() {
4447        let text = body("int f(int n) { int a = n + 1; int b = a * 2; return a + b; }\n");
4448        assert!(!text.contains("alloca"), "{text}");
4449        assert!(!text.contains("load"), "{text}");
4450        assert!(!text.contains("store"), "{text}");
4451    }
4452
4453    #[test]
4454    fn a_local_whose_address_is_taken_gets_a_slot_in_the_entry_block() {
4455        let text = body("int g(int *);\nint f(void) { int a = 1; return g(&a); }\n");
4456        let expected = "\
4457block0:
4458    %0 = alloca, size 4, align 4
4459    %1 = iconst.i32 1
4460    store %1 -> %0, align 4
4461    %2 = call @g(%0) : (ptr) -> i32
4462    return %2
4463";
4464        assert_eq!(text, expected);
4465    }
4466
4467    #[test]
4468    fn a_loop_carries_what_it_changes_as_block_parameters() {
4469        // The whole point of building SSA during the walk rather than after it: `i` and
4470        // `total` are values that arrive on an edge, and neither has ever been in memory.
4471        let text = body(
4472            "int f(int n) {\n  int total = 0;\n  for (int i = 0; i < n; i++) total += i;\n  \
4473             return total;\n}\n",
4474        );
4475        assert!(!text.contains("alloca"), "{text}");
4476        assert!(text.contains("block1(%3: i32, %4: i32):"), "{text}");
4477        assert!(text.contains("jump block1("), "{text}");
4478    }
4479
4480    #[test]
4481    fn a_comparison_used_as_a_condition_is_not_widened_and_narrowed_again() {
4482        let text = body("int f(int a, int b) { if (a < b) return 1; return 0; }\n");
4483        assert!(text.contains("icmp slt %0, %1"), "{text}");
4484        assert!(!text.contains("zext"), "{text}");
4485    }
4486
4487    #[test]
4488    fn the_right_side_of_a_short_circuit_is_in_a_block_of_its_own() {
4489        let text = body("int f(int a, int b) { return a && b; }\n");
4490        let expected = "\
4491block0(%0: i32, %1: i32):
4492    %2 = iconst.i32 0
4493    %3 = icmp ne %0, %2
4494    %4 = iconst.i1 0
4495    br_if %3, block1, block2(%4)
4496
4497block1:
4498    %5 = iconst.i32 0
4499    %6 = icmp ne %1, %5
4500    jump block2(%6)
4501
4502block2(%7: i1):
4503    %8 = zext.i32 %7
4504    return %8
4505";
4506        assert_eq!(text, expected);
4507    }
4508
4509    #[test]
4510    fn code_after_a_return_is_not_built_and_does_not_leave_an_empty_block_behind() {
4511        let text = body("int f(int a) { if (a) return 1; else return 2; return 3; }\n");
4512        // Three blocks, the test and the two arms. The join the `return 3` would need is
4513        // never created, because a block nothing branches to is not a block.
4514        assert!(!text.contains("block3"), "{text}");
4515        assert!(!text.contains("iconst.i32 3"), "{text}");
4516    }
4517
4518    #[test]
4519    fn falling_off_the_end_returns_zero_from_main_and_nothing_from_a_void_function() {
4520        assert!(body("int main(void) { }\n").contains("iconst.i32 0\n    return"));
4521        assert_eq!(body("void f(void) { }\n"), "block0:\n    return\n");
4522        assert!(body("int f(void) { }\n").contains("unreachable"));
4523    }
4524
4525    #[test]
4526    fn a_structure_is_copied_rather_than_held_in_a_value() {
4527        let text = body(
4528            "struct point { int x, y; };\n\
4529             int f(void) { struct point p = { 1, 2 }; struct point q = p; return q.x; }\n",
4530        );
4531        assert!(text.contains("memcpy"), "{text}");
4532    }
4533
4534    #[test]
4535    fn an_initializer_that_leaves_part_of_an_object_unwritten_zeroes_it_first() {
4536        let text = body("int f(void) { int a[4] = { 1 }; return a[3]; }\n");
4537        assert!(text.contains("memset"), "{text}");
4538    }
4539
4540    #[test]
4541    fn a_switch_is_one_branch_and_a_case_that_falls_through_carries_what_it_wrote() {
4542        let text = body(
4543            "int f(int x) { int r = 0; switch (x) { case 1: r = 1; case 2: r += 2; break; \
4544             default: r = 4; } return r; }\n",
4545        );
4546        let expected = "\
4547block0(%0: i32):
4548    %1 = iconst.i32 0
4549    switch %0, block1, [1 => block2, 2 => block3(%1)]
4550
4551block1:
4552    %2 = iconst.i32 4
4553    jump block4(%2)
4554
4555block2:
4556    %3 = iconst.i32 1
4557    jump block3(%3)
4558
4559block3(%4: i32):
4560    %5 = iconst.i32 2
4561    %6 = add.nsw %4, %5
4562    jump block4(%6)
4563
4564block4(%7: i32):
4565    return %7
4566";
4567        assert_eq!(text, expected);
4568    }
4569
4570    #[test]
4571    fn a_case_range_is_tested_for_rather_than_put_in_the_table() {
4572        // GNU's `case 1 ... 9`. Nine table entries would be nine here and four billion for the
4573        // range a program is allowed to write, so it is a subtraction and one unsigned compare.
4574        let text = body("int f(int x) { switch (x) { case 1 ... 9: return 1; } return 0; }\n");
4575        assert!(text.contains("%2 = sub %0, %1"), "{text}");
4576        assert!(text.contains("icmp ule"), "{text}");
4577        assert!(!text.contains("switch"), "{text}");
4578    }
4579
4580    #[test]
4581    fn break_leaves_the_switch_and_continue_leaves_the_loop_around_it() {
4582        let text = body(
4583            "int f(int n) { int t = 0; for (int i = 0; i < n; i++) { switch (i) { \
4584             case 0: continue; case 1: break; default: t += i; } t++; } return t; }\n",
4585        );
4586        // The `continue` goes to the step and the `break` goes to the `t++` after the switch,
4587        // which is also where the default falls out to.
4588        assert!(text.contains("switch %3, block4, [0 => block5, 1 => block6]"), "{text}");
4589        assert!(text.contains("block5:\n    jump block7("), "{text}");
4590        assert!(text.contains("block6:\n    jump block8("), "{text}");
4591    }
4592
4593    #[test]
4594    fn a_switch_with_nothing_to_branch_on_still_runs_what_comes_after_it() {
4595        assert_eq!(body("void f(int x) { switch (x) { } }\n"), "block0(%0: i32):\n    return\n");
4596    }
4597
4598    #[test]
4599    fn a_label_a_loop_is_only_entered_through_builds_the_loop_around_it() {
4600        // A branch into the middle of a loop that nothing else reaches, the Duff's device shape.
4601        // The `while` is not reached in order, so the walk starts a block nothing branches to and
4602        // builds it from there. What comes out is the loop with an edge straight into its body,
4603        // and the header that nothing arrives at is pruned.
4604        let text = body(
4605            "int f(int x, int n) { switch (x) { case 1: break; while (n) { case 2: n--; } } \
4606             return n; }\n",
4607        );
4608        // `case 2` lands on the body, `case 1` and the default land on the return, and the test
4609        // at the bottom of the loop comes back round to the body.
4610        assert!(text.contains("switch %0, block1(%1), [1 => block2, 2 => block3(%1)]"), "{text}");
4611        assert!(text.contains("block3(%3: i32):\n    %4 = iconst.i32 1"), "{text}");
4612        assert!(text.contains("block4:\n    jump block3("), "{text}");
4613    }
4614
4615    #[test]
4616    fn a_goto_into_a_loop_body_enters_it_without_the_test() {
4617        // The same thing through a `goto`. The first pass through the body runs whatever the
4618        // label is on, and only then does the loop reach its own test.
4619        let text = body("int f(int x, int n) { goto in; while (n) { in: n--; } return n; }\n");
4620        assert!(text.starts_with("block0(%0: i32, %1: i32):\n    jump block1(%1)"), "{text}");
4621        assert!(text.contains("block1(%2: i32):\n    %3 = iconst.i32 1"), "{text}");
4622        assert!(text.contains("br_if %6, block2, block3"), "{text}");
4623    }
4624
4625    #[test]
4626    fn a_goto_is_a_jump_to_the_block_the_label_starts() {
4627        let text = body("int f(int x) { int r = 0; if (x) goto out; r = 1; out: return r; }\n");
4628        // Both edges into `out` carry what `r` holds on the way, and neither is a stack slot. The
4629        // block the `goto` jumps out of is empty and hands its edge on, which is what moves `out`
4630        // up the block list to second place.
4631        assert!(!text.contains("alloca"), "{text}");
4632        assert!(text.contains("block2(%4: i32):\n    return %4"), "{text}");
4633        assert_eq!(text.matches("jump block2(").count(), 2, "{text}");
4634    }
4635
4636    #[test]
4637    fn a_backward_goto_is_a_loop_and_carries_what_it_changes() {
4638        let text =
4639            body("int f(int n) { int i = 0; again: if (i < n) { i++; goto again; } return i; }\n");
4640        assert!(!text.contains("alloca"), "{text}");
4641        assert!(text.contains("block1(%2: i32):"), "{text}");
4642        assert!(text.contains("jump block1(%5)"), "{text}");
4643    }
4644
4645    #[test]
4646    fn a_label_nothing_reaches_is_taken_out_rather_than_left_for_the_verifier() {
4647        // A block nothing branches to is not a legal function, and which labels are dead is not
4648        // known until the last statement has been walked, since the `goto` is allowed to be it.
4649        assert_eq!(
4650            body("int f(int x) { return x; spare: return 0; }\n"),
4651            "block0(%0: i32):\n    return %0\n"
4652        );
4653    }
4654
4655    #[test]
4656    fn a_bit_field_is_read_by_loading_the_bytes_it_lies_in_and_shifting() {
4657        let text = body(
4658            "struct s { unsigned a : 3; signed b : 5; };\nint f(struct s *p) { return p->b; }\n",
4659        );
4660        // One byte holds both fields, and the signed one needs no mask: shifting it down
4661        // arithmetically is what says its top bit is a sign.
4662        assert_eq!(
4663            text,
4664            "\
4665block0(%0: ptr):
4666    %1 = load.i8 %0, align 1
4667    %2 = iconst.i8 3
4668    %3 = ashr %1, %2
4669    %4 = sext.i32 %3
4670    return %4
4671"
4672        );
4673    }
4674
4675    #[test]
4676    fn a_store_to_a_bit_field_does_not_write_a_byte_it_has_no_bit_in() {
4677        // C11 says an ordinary member beside a bit-field is a memory location of its own, so
4678        // the four byte store this would take is a data race in a program that has none. The
4679        // three bytes of `a` go in as two and one, and `c` is not touched.
4680        let text =
4681            body("struct s { int a : 24; char c; };\nvoid f(struct s *p, int v) { p->a = v; }\n");
4682        assert_eq!(
4683            text,
4684            "\
4685block0(%0: ptr, %1: i32):
4686    %2 = iconst.i32 16777215
4687    %3 = and %1, %2
4688    %4 = trunc.i16 %3
4689    store %4 -> %0, align 2
4690    %5 = iconst.i32 16
4691    %6 = lshr %3, %5
4692    %7 = trunc.i8 %6
4693    %8 = iconst.i64 2
4694    %9 = ptr_add %0, %8
4695    store %7 -> %9, align 1
4696    return
4697"
4698        );
4699    }
4700
4701    #[test]
4702    fn what_an_assignment_to_a_bit_field_is_worth_is_what_fits_in_it() {
4703        let text =
4704            body("struct s { unsigned b : 5; };\nunsigned f(struct s *p) { return p->b = 33; }\n");
4705        // 33 does not fit in five bits, and 1 is both what goes in the field and what the
4706        // assignment is worth.
4707        assert!(text.contains("%3 = iconst.i8 31\n    %4 = and %2, %3"), "{text}");
4708        assert!(text.ends_with("%9 = zext.i32 %4\n    return %9\n"), "{text}");
4709    }
4710
4711    #[test]
4712    fn an_assignment_a_statement_throws_away_builds_none_of_what_it_is_worth() {
4713        // The value of an assignment to a bit-field takes a shift to build, and a statement
4714        // has no use for it. Nothing here reads back what was stored.
4715        let text = body("struct s { signed b : 5; };\nvoid f(struct s *p) { p->b = 3; }\n");
4716        assert_eq!(text.matches("ashr").count(), 0, "{text}");
4717        assert!(text.ends_with("store %8 -> %0, align 1\n    return\n"), "{text}");
4718    }
4719
4720    #[test]
4721    fn a_bit_field_in_an_initializer_goes_in_over_bytes_that_were_zeroed_first() {
4722        // A bit-field writes part of a byte and leaves the rest of it alone, so the object has
4723        // to be zero before it goes in or what the initializer did not name is whatever the
4724        // stack held.
4725        let text = body(
4726            "struct s { int a : 3; int b; };\nint f(void) { struct s v = { 1 }; return v.b; }\n",
4727        );
4728        assert!(text.contains("memset %0, %1, size 8, align 4"), "{text}");
4729    }
4730
4731    #[test]
4732    fn the_image_of_a_static_bit_field_is_the_bytes_the_fields_share() {
4733        // Two fields in one byte are not two entries in the image, because an image is written
4734        // in bytes: they are the byte they are both in.
4735        let text = ir("struct s { unsigned a : 3; unsigned b : 5; } g = { 1, 2 };\n");
4736        assert!(
4737            text.contains("global @g : bytes 4 = { bytes \"\\11\", zero 3 }, align 4"),
4738            "{text}"
4739        );
4740    }
4741
4742    #[test]
4743    fn an_initialized_flexible_array_member_makes_the_object_larger_than_its_type() {
4744        // `sizeof` answers without the array and the definition has to hold what was written, so
4745        // the object is the size of its image. gcc 16 gives these four, three and two bytes and
4746        // so does this. The image used to be written at the size the type had, which left the
4747        // verifier looking at twenty bytes going into four.
4748        let text = ir(concat!(
4749            "struct a { int i; int j[]; } x = { 1, { 2, 0, 2, 3 } };\n",
4750            "struct b { char c; char p[]; } y = { 'o', \"wx\" };\n",
4751            "struct c { char c; char p[]; } z = { '9', { 'e', 'b' } };\n",
4752            "char s[2] = \"hi\";\n",
4753        ));
4754        assert!(
4755            text.contains("global @x : bytes 20 = { i32 1, i32 2, i32 0, i32 2, i32 3 }"),
4756            "{text}"
4757        );
4758        assert!(text.contains("global @y : bytes 4 = { i8 111, bytes \"wx\\00\" }"), "{text}");
4759        assert!(text.contains("global @z : bytes 3 = { i8 57, i8 101, i8 98 }"), "{text}");
4760        // The array with a length of its own still cuts the literal down to it, which is the
4761        // one case in C where a string initializer drops its terminator.
4762        assert!(text.contains("global @s : bytes 2 = { bytes \"hi\" }"), "{text}");
4763    }
4764
4765    #[test]
4766    fn a_definition_takes_a_parameter_it_left_unnamed() {
4767        // The entry block's parameters are the definition's, and one the front end dropped for
4768        // having no name left the two lists different lengths, which the walk read as an
4769        // old-style definition and refused. gcc has taken these for far longer than C23 has.
4770        let text = ir("int f(int a, int) { return a; }\n");
4771        assert!(text.contains("func @f(i32, i32) -> i32"), "{text}");
4772        assert!(text.contains("block0(%0: i32, %1: i32):"), "{text}");
4773
4774        // The unnamed one first, so that the named one is the second parameter of the entry
4775        // block and not the first: the list says the order and not only how many there are.
4776        let text = ir("int g(int, int n) { return n; }\n");
4777        assert!(text.contains("block0(%0: i32, %1: i32):\n    return %1\n"), "{text}");
4778    }
4779
4780    #[test]
4781    fn an_assignment_of_a_structure_is_the_object_it_wrote() {
4782        // `d = e = c` used to be refused, because the middle assignment is a value of structure
4783        // type and the walk had nowhere to read one from. What an assignment is worth is the
4784        // value it stored, so the object it stored into is the answer and the chain is three
4785        // copies out of the one source with no temporary in it.
4786        let text = body(concat!(
4787            "struct s { int f; int g; };\n",
4788            "void h(struct s *a, struct s *c, struct s *d, struct s *e)\n",
4789            "{ *d = *e = a[0] = *c; }\n",
4790        ));
4791        assert_eq!(text.matches("memcpy").count(), 3, "{text}");
4792        assert!(text.contains("memcpy %8, %1, size 8, align 4\n"), "{text}");
4793        assert!(text.contains("memcpy %3, %8, size 8, align 4\n"), "{text}");
4794        assert!(text.contains("memcpy %2, %3, size 8, align 4\n"), "{text}");
4795    }
4796
4797    #[test]
4798    fn a_string_literal_stops_at_the_end_of_the_array_it_is_filling() {
4799        // The excess used to be laid into the object anyway, so the row after was written over
4800        // and the image refused the entry that came to it. C 6.7.10p14 says the terminator goes
4801        // in only if there is room for it, and gcc discards the rest of a literal that is longer
4802        // still, which is what the first of these is and why it warns.
4803        let mut opts = options();
4804        opts.emit = EmitKind::Ir;
4805        let result = run(
4806            &opts,
4807            concat!(
4808                "const char a[2][3] = { \"1234\", \"xyz\" };\n",
4809                "static const char b[3][5] = { \"12345\", \"678\", \"9\" };\n",
4810                "union u { struct { char x[4]; char y[4]; }; struct { char z[8]; }; };\n",
4811                "const union u c = { { \"1234\", \"567\" } };\n",
4812            ),
4813        );
4814        let text = result.text();
4815        assert_eq!(
4816            result.messages,
4817            ["/main.c:1:24: warning: initializer-string for array of 'const char' is too long \
4818              (5 chars into 3 available) [E0637]"]
4819        );
4820        assert!(text.contains("global @a : bytes 6 = { bytes \"123\", bytes \"xyz\" }"), "{text}");
4821        assert!(
4822            text.contains(
4823                "global @b : bytes 15 = { bytes \"12345\", bytes \"678\\00\", zero 1, \
4824                 bytes \"9\\00\", zero 3 }"
4825            ),
4826            "{text}"
4827        );
4828        // The eight bytes are four, three and a terminator, and then the byte the shorter
4829        // literal left for the string in the other member of the union to end at.
4830        assert!(
4831            text.contains("global @c : bytes 8 = { bytes \"1234\", bytes \"567\\00\" }"),
4832            "{text}"
4833        );
4834    }
4835
4836    #[test]
4837    fn a_cast_of_a_record_to_its_own_type_is_the_object_that_was_cast() {
4838        // gcc accepts one and does nothing with it, which sema already had. Lowering asked for
4839        // the object under it and had no arm for a cast, so `(struct s)x` in an initializer was
4840        // refused with E0519. It is one copy out of the object named, not two.
4841        let text = body(concat!(
4842            "struct s { int a, b; };\nstruct v { struct s s; int t; };\n",
4843            "void g(struct v *);\n",
4844            "void f(struct s *p) { struct v w = { (struct s)*p, 5 }; g(&w); }\n",
4845        ));
4846        assert_eq!(text.matches("memcpy").count(), 1, "{text}");
4847    }
4848
4849    #[test]
4850    fn a_compound_literal_read_in_a_static_initializer_lays_its_bytes_into_the_image() {
4851        // C 6.7.11p4 says a compound literal at file scope has static storage duration, which
4852        // makes it a constant element, and tcc and c-testsuite both write one. Sema used to call
4853        // it a non constant because reading it is a node of its own and the read was what it
4854        // looked at, and lowering had no way to put an object where it wanted a number.
4855        let text = ir(concat!(
4856            "struct s { int x; };\n",
4857            "struct t { struct s s; int o; } a = { (struct s){ 2 }, 3 };\n",
4858            "int n = (int){ 7 };\n",
4859            "struct u { struct s p; struct s q; } b = { (struct s){ 1 }, (struct s){ } };\n",
4860        ));
4861        assert!(text.contains("global @a : bytes 8 = { i32 2, i32 3 }"), "{text}");
4862        assert!(text.contains("global @n : i32 = 7,"), "{text}");
4863        // The second literal names nothing, so what it puts in is the zeros of its own size and
4864        // not the tail of the object it went in, which would have been the same bytes by luck.
4865        assert!(text.contains("global @b : bytes 8 = { i32 1, zero 4 }"), "{text}");
4866    }
4867
4868    #[test]
4869    fn the_address_of_a_compound_literal_asks_for_the_object_it_points_at() {
4870        // Nothing declares a compound literal, so the reference is the only thing that can ask
4871        // for it to be emitted. The image named `.Lanon.0` and the module defined no such
4872        // symbol, which the link would have been the first to find out.
4873        let text = ir("struct s { int x; };\nstruct s *q = &(struct s){ 9 };\n");
4874        assert!(text.contains("global @.Lanon.0 : i32 = 9, align 4, linkage(internal)"), "{text}");
4875        assert!(text.contains("global @q : bytes 8 = { addr.8 @.Lanon.0 }"), "{text}");
4876    }
4877
4878    #[test]
4879    fn an_object_of_no_size_at_all_has_an_image_with_nothing_in_it() {
4880        // A zero length array, which gcc allows and real code uses as the tail of a structure.
4881        // The image is there and holds nothing, which is not the global that has no image at
4882        // all, and the IR reader used to stop on the empty one.
4883        let text = ir("unsigned char foo[1][0];\n");
4884        assert!(text.contains("global @foo : bytes 0 = {}, align 1"), "{text}");
4885    }
4886
4887    #[test]
4888    fn a_null_pointer_in_an_image_is_the_bits_an_address_has_room_for() {
4889        // `NULL` in a static initializer, which every program has. The IR type is `ptr` and a
4890        // `ptr` has no width of its own, so the width the bits are cut to is the target's.
4891        let text = ir("void *p = 0;\nchar *q = (char *) 4096;\n");
4892        assert!(text.contains("global @p : i64 = 0, align 8"), "{text}");
4893        assert!(text.contains("global @q : i64 = 4096, align 8"), "{text}");
4894    }
4895
4896    #[test]
4897    fn an_object_another_module_defines_may_be_one_that_cannot_be_written_through() {
4898        // Which the verifier used to refuse, having read a declaration as a definition with
4899        // nothing in it. `extern const` is how a program names something in the library's read
4900        // only data, and glibc and Darwin both have one in a header a real program includes.
4901        let text = ir("extern const int limit;\nint f(void) { return limit; }\n");
4902        assert!(
4903            text.contains("global @limit : bytes 4, align 4, linkage(external), constant"),
4904            "{text}"
4905        );
4906    }
4907
4908    #[test]
4909    fn a_conditional_whose_value_is_an_object_answers_where_the_object_is() {
4910        // A structure is not a value in the IR, so the two arms cannot be joined as one. The
4911        // addresses can, and the answer is the address of whichever arm was taken rather than
4912        // a copy of it into a third place: both arms outlive the expression, so a copy would
4913        // be one nothing could observe. SQLite's parser writes one of these.
4914        let text = body(
4915            "\
4916struct s { int a, b; };
4917struct s pick(int c, struct s x, struct s y) { return c ? x : y; }
4918",
4919        );
4920        // The join takes an address, each arm hands it the one it has, and nothing is copied.
4921        assert!(text.contains("block3(%7: ptr)"), "{text}");
4922        assert!(text.contains("jump block3(%3)") && text.contains("jump block3(%4)"), "{text}");
4923        assert!(!text.contains("memcpy"), "the arms are joined rather than copied: {text}");
4924    }
4925
4926    /// GNU's `a ?: b` evaluates `a` once, and the arm answers the value that was tested.
4927    ///
4928    /// The checking keeps one node for `a` and converts it in two directions, to the bit the
4929    /// branch is taken on and to the type the whole expression has. Walking into the arm used to
4930    /// reach that node a second time and build a second copy of whatever it says, so `++i ?: 10`
4931    /// incremented twice and `f() ?: 10` called twice. Measured against gcc 16.2.0, which
4932    /// increments once.
4933    #[test]
4934    fn the_left_side_of_a_conditional_with_no_middle_is_evaluated_once() {
4935        let text = body("int f(int i) { return ++i ?: 10; }\n");
4936        assert!(text.contains("jump block3(%2)"), "the arm is the value that was tested: {text}");
4937        assert_eq!(text.matches("add.nsw").count(), 1, "incremented once: {text}");
4938
4939        // The arm still converts, since what the whole expression is worth is a `long` here and
4940        // the node under it is an `int`. What it converts is the value in hand.
4941        let text = body("long f(int i) { return ++i ?: 10L; }\n");
4942        assert!(text.contains("%5 = sext.i64 %2"), "the arm widens what was tested: {text}");
4943        assert_eq!(text.matches("add.nsw").count(), 1, "incremented once: {text}");
4944
4945        // A call, which is where evaluating twice is a wrong answer rather than a slow one.
4946        let text = body("int g(void);\nint f(void) { return g() ?: 10; }\n");
4947        assert_eq!(text.matches("call @g").count(), 1, "called once: {text}");
4948
4949        // Written out in full it is two reads of `i`, which is what C says it is, so the middle
4950        // operand being absent is the whole of the difference.
4951        let text = body("int f(int i) { return ++i ? ++i : 10; }\n");
4952        assert_eq!(text.matches("add.nsw").count(), 2, "incremented twice: {text}");
4953    }
4954
4955    #[test]
4956    fn a_structure_that_fits_in_registers_travels_as_the_registers_it_fits_in() {
4957        // `struct pair` is two eightbytes on SysV, one of them integer, so the signature says
4958        // one `i64` in each direction and the body takes the object apart and puts it back
4959        // together around the call.
4960        let text = ir("\
4961struct pair { int a, b; };
4962struct pair make(int a, int b);
4963struct pair twice(struct pair p) { return make(p.a, p.b); }
4964");
4965        assert!(text.contains("func @make(i32, i32) -> i64"), "{text}");
4966        assert!(text.contains("func @twice(i64) -> i64"), "{text}");
4967    }
4968
4969    #[test]
4970    fn a_structure_too_large_for_the_registers_travels_as_where_its_bytes_are() {
4971        // Over two eightbytes the caller passes the bytes in the argument area, which is
4972        // `byval`, and passes somewhere to write the return value, which is `sret`. Neither is
4973        // a parameter the program wrote and both are parameters the function has.
4974        let text = ir("\
4975struct big { double v[8]; };
4976struct big grow(struct big b);
4977struct big twice(struct big b) { return grow(grow(b)); }
4978");
4979        assert!(
4980            text.contains("func @grow(ptr sret(64, align 8), ptr byval(64, align 8))"),
4981            "{text}"
4982        );
4983        assert!(text.contains("block0(%0: ptr, %1: ptr):"), "{text}");
4984        // The inner call writes into a slot and the outer one reads the same slot, so the
4985        // object between the two calls is never copied anywhere.
4986        assert_eq!(text.matches("call @grow").count(), 2, "{text}");
4987    }
4988
4989    #[test]
4990    fn a_structure_passed_to_a_variadic_function_says_so_at_the_call() {
4991        // The bytes travel in the argument area the same way they would for a parameter, and
4992        // `printf` has no parameter there to say it on, so the call says it instead. The one
4993        // that fits in registers says nothing, because travelling as the registers it fits in
4994        // is what an argument does when nothing says otherwise.
4995        let text = ir("\
4996struct big { double v[8]; };
4997struct pair { int a, b; };
4998int p(const char *, ...);
4999int f(struct big b, struct pair q) { return p(\"\", 1, b, q); }
5000");
5001        assert!(
5002            text.contains("call @p(%4, %5, %2 byval(64, align 8), %6) : (ptr, ...) -> i32"),
5003            "{text}"
5004        );
5005    }
5006
5007    #[test]
5008    fn what_a_call_produced_is_somewhere_before_anything_is_read_out_of_it() {
5009        // `make(1, 2).b` has no object to read a member of until one is made, and what makes it
5010        // is a slot the returned registers are written to.
5011        let body = body(
5012            "\
5013struct pair { int a, b; };
5014struct pair make(int a, int b);
5015int second(void) { return make(1, 2).b; }
5016",
5017        );
5018        assert!(body.starts_with("block0:\n    %0 = alloca, size 8, align 4\n"), "{body}");
5019        assert!(body.contains("store %3 -> %0, align 4\n"), "{body}");
5020    }
5021
5022    #[test]
5023    fn a_structure_of_floats_travels_in_floating_point_registers_on_aarch64() {
5024        // The same declaration, classified by a different ABI: three `float` members are an
5025        // eightbyte of two of them and a half eightbyte of the third on SysV, and three vector
5026        // registers on AAPCS64.
5027        let source = "\
5028struct hfa { float x, y, z; };
5029int take(struct hfa h);
5030int give(struct hfa h) { return take(h); }
5031";
5032        assert!(ir(source).contains("func @take(f64, f32) -> i32"), "{}", ir(source));
5033        let mut opts = options();
5034        opts.emit = EmitKind::Ir;
5035        opts.target = "aarch64-unknown-linux-gnu".parse::<Triple>().unwrap();
5036        let result = run(&opts, source);
5037        assert_eq!(result.messages, Vec::<String>::new());
5038        assert!(result.text().contains("func @take(f32, f32, f32) -> i32"), "{}", result.text());
5039    }
5040
5041    #[test]
5042    fn an_array_whose_length_is_not_a_constant_is_a_slot_made_where_its_declaration_is() {
5043        // The size is a multiplication rather than a number, the slot is taken from the stack
5044        // where the declaration is, and the scope it was declared in gives it back.
5045        let source = "\
5046int use(int *);
5047void f(int n) {
5048  {
5049    int a[n];
5050    use(a);
5051  }
5052  use(0);
5053}
5054";
5055        let body = body(source);
5056        assert!(body.contains("mul.nsw"), "{body}");
5057        assert!(body.contains("stacksave"), "{body}");
5058        assert!(body.contains("alloca %"), "{body}");
5059        assert!(body.contains("stackrestore"), "{body}");
5060    }
5061
5062    #[test]
5063    fn a_goto_out_of_the_scope_of_one_gives_its_stack_back_on_the_way() {
5064        // The label is outside the block the array is in, so arriving there means the array is
5065        // gone, and the restore that says so goes in front of the branch. The `goto` is written
5066        // before the walk knows where the label is, which is why the restore is put there at
5067        // the end rather than built where the branch was.
5068        let source = "\
5069int use(int *);
5070int f(int n) {
5071  {
5072    int a[n];
5073    if (use(a)) goto out;
5074    use(0);
5075  }
5076out:
5077  return 0;
5078}
5079";
5080        let body = body(source);
5081        // Two ways out of the block and a restore on each: the jump and the end of the block.
5082        assert_eq!(body.matches("stackrestore").count(), 2, "{body}");
5083        let (_, after) = body.split_once("stackrestore").expect("the stack is given back");
5084        assert!(after.starts_with(" %4\n    jump block"), "{body}");
5085    }
5086
5087    #[test]
5088    fn a_goto_to_a_label_the_array_is_still_alive_at_leaves_the_stack_alone() {
5089        // The label is after the declaration and in the same block, so control that arrives
5090        // there arrives somewhere the array exists. Giving it back would be giving back an
5091        // object the next statement reads.
5092        let source = "\
5093int use(int *);
5094int f(int n) {
5095  int a[n];
5096again:
5097  if (use(a)) goto again;
5098  return 0;
5099}
5100";
5101        let body = body(source);
5102        assert!(body.contains("stacksave"), "{body}");
5103        assert!(!body.contains("stackrestore"), "{body}");
5104    }
5105
5106    #[test]
5107    fn a_goto_back_to_a_label_in_front_of_one_gives_it_back_every_time_round() {
5108        // A loop written out of a `goto`, with the array made inside it. The label is in the
5109        // same block as the declaration and before it, which is a place where the array does
5110        // not exist yet, so the jump there leaves its scope and has to give the stack back. A
5111        // compiler that skips this restore grows the stack once per iteration.
5112        let source = "\
5113int use(int *);
5114int f(int n) {
5115again:
5116  {
5117    int a[n];
5118    if (use(a)) goto again;
5119  }
5120  return 0;
5121}
5122";
5123        let body = body(source);
5124        assert_eq!(body.matches("stacksave").count(), 1, "{body}");
5125        let (_, after) = body.split_once("stackrestore").expect("the stack is given back");
5126        assert!(after.starts_with(" %4\n    jump block1\n"), "{body}");
5127    }
5128
5129    #[test]
5130    fn the_head_of_a_for_loop_is_a_scope_that_closes_where_the_loop_is_left() {
5131        // The scope opened for `for (int a[n];;)` used to stay open, and a scope left open is
5132        // not one mark nobody reads. The marks are a stack, so the next close took this one
5133        // instead of its own, and the body of the loop gave back nothing while the block after
5134        // the loop restored a pointer saved inside it. The verifier refused that, which is how
5135        // it was found.
5136        let source = "\
5137int f(void);
5138void t(void) {
5139  int count = 10;
5140  for (; count--;) {
5141    int b[f()];
5142    int i;
5143    for (i = 0; i < f(); i++) {
5144      b[i] = count;
5145    }
5146  }
5147}
5148";
5149        let body = body(source);
5150        // One save, in the body, and one restore for it, also in the body: the block the
5151        // restore is in is the one the inner loop leaves through, and it goes back round the
5152        // outer loop rather than out of it.
5153        assert_eq!(body.matches("stacksave").count(), 1, "{body}");
5154        let (_, after) = body.split_once("stackrestore").expect("the stack is given back");
5155        // The rest of the block the restore is in, which is the last block here, so there is not
5156        // always another one after it to split on.
5157        let next = after.split("\n\n").next().expect("the block the restore is in");
5158        assert!(next.contains("jump block1("), "{body}");
5159    }
5160
5161    #[test]
5162    fn how_long_one_of_those_is_was_decided_where_it_was_declared_and_not_where_it_is_asked() {
5163        // What C says about the length being evaluated once: `sizeof a` after `n` changed is
5164        // still as long as the array is, which is what `n` was when the array came into being.
5165        let source = "\
5166unsigned long f(int n) {
5167  int a[n];
5168  n = 0;
5169  return sizeof a;
5170}
5171";
5172        let body = body(source);
5173        // One read of the parameter, at the declaration, and the answer is built out of it.
5174        assert_eq!(body.matches("sext.i64 %0").count(), 2, "{body}");
5175    }
5176
5177    #[test]
5178    fn a_block_in_the_middle_of_an_expression_is_walked_where_the_expression_is() {
5179        // GNU's statement expression: the statements happen where they are written and the last
5180        // one is the value, so the temporary in it never becomes a slot and never is copied.
5181        let source = "\
5182int use(int);
5183int f(int x) {
5184  return ({
5185    int t = use(x);
5186    t * t;
5187  });
5188}
5189";
5190        let expected = "\
5191block0(%0: i32):
5192    %1 = call @use(%0) : (i32) -> i32
5193    %2 = mul.nsw %1, %1
5194    return %2
5195";
5196        assert_eq!(body(source), expected);
5197    }
5198
5199    #[test]
5200    fn one_of_those_that_control_never_leaves_is_lowered_and_what_follows_it_is_dropped() {
5201        // A macro that always jumps, which is what this shape is in real code. The value is
5202        // never taken, and the block the rest of the expression would have been built in is
5203        // one nothing branches to, so it goes with the other unreachable blocks.
5204        let source = "int f(int x) { return ({ return x; 0; }); }\n";
5205        assert_eq!(body(source), "block0(%0: i32):\n    return %0\n");
5206    }
5207
5208    #[test]
5209    fn one_argument_off_a_variable_argument_list_stays_an_intrinsic() {
5210        // What it becomes is the target's answer, and this is not where the target's answers
5211        // are, so the walk writes down which list and which type and leaves it at that. Two of
5212        // them are two instructions, since each moves the list on.
5213        let source = "double f(__builtin_va_list ap) { return __builtin_va_arg(ap, double) + __builtin_va_arg(ap, double); }\n";
5214        let expected = "\
5215block0(%0: ptr):
5216    %1 = va_arg.f64 %0
5217    %2 = va_arg.f64 %0
5218    %3 = fadd %1, %2
5219    return %3
5220";
5221        assert_eq!(body(source), expected);
5222    }
5223
5224    #[test]
5225    fn one_that_reads_a_structure_answers_where_the_object_is() {
5226        // An aggregate is not a value, so there is nothing for the result of `va_arg` to be and
5227        // the object form is a second instruction. What it answers is an address, so it is a
5228        // place already and the walk copies nothing out of it: the copy here is the one the
5229        // initializer asks for, into the variable being declared. The size and the alignment
5230        // travel with it because they are what steps the list on and what a target that has to
5231        // put registers somewhere needs to know. So does the classification, which says the two
5232        // halves of this one arrived in general purpose registers: that is an answer about a C
5233        // type, and this is the last place that still has one.
5234        //
5235        // The slot is aligned to sixteen and the copy into it to eight, which is not a
5236        // disagreement. Sixteen is what a local aggregate of sixteen bytes gets whatever its
5237        // members ask for, and eight is what the type asks for and so what the copy may assume
5238        // about the object it is reading from.
5239        let source = "\
5240struct s { int a; long b; };
5241long f(__builtin_va_list ap) { struct s v = __builtin_va_arg(ap, struct s); return v.b; }
5242";
5243        let expected = "\
5244block0(%0: ptr):
5245    %1 = alloca, size 16, align 16
5246    %2 = va_object %0, size 16, align 8, in(int 8 at 0, int 8 at 8)
5247    memcpy %1, %2, size 16, align 8
5248    %3 = iconst.i64 8
5249    %4 = ptr_add %1, %3
5250    %5 = load.i64 %4, align 8
5251    return %5
5252";
5253        assert_eq!(body(source), expected);
5254    }
5255
5256    /// Which register file each eightbyte arrived in is the whole of what the classification adds,
5257    /// and an object with no slots at all is one it sent to the caller's argument area, which is
5258    /// what everything over two eightbytes is whatever its members are.
5259    #[test]
5260    fn the_classification_says_which_registers_the_object_arrived_in() {
5261        let source = "\
5262struct s { double a; double b; };
5263double f(__builtin_va_list ap) { struct s v = __builtin_va_arg(ap, struct s); return v.a; }
5264";
5265        assert!(
5266            body(source)
5267                .contains("va_object %0, size 16, align 8, in(float f64 at 0, float f64 at 8)"),
5268            "{}",
5269            body(source)
5270        );
5271
5272        let big = "\
5273struct s { long a[4]; };
5274long f(__builtin_va_list ap) { struct s v = __builtin_va_arg(ap, struct s); return v.a[0]; }
5275";
5276        assert!(body(big).contains("va_object %0, size 32, align 8\n"), "{}", body(big));
5277    }
5278
5279    #[test]
5280    fn a_jump_to_an_address_branches_to_every_label_the_function_takes_the_address_of() {
5281        // GNU's computed goto. Which label the address holds is not known here, so all of them
5282        // are listed, and the values arriving at one are passed on every edge the same way they
5283        // are on an ordinary branch.
5284        let source = "\
5285int f(int c) {
5286  void *p = c ? &&one : &&two;
5287  goto *p;
5288one:
5289  return 1;
5290two:
5291  return 2;
5292}
5293";
5294        let expected = "\
5295block0(%0: i32):
5296    %1 = iconst.i32 0
5297    %2 = icmp ne %0, %1
5298    br_if %2, block1, block2
5299
5300block1:
5301    %3 = block_addr block3
5302    jump block4(%3)
5303
5304block2:
5305    %4 = block_addr block5
5306    jump block4(%4)
5307
5308block3:
5309    %5 = iconst.i32 1
5310    return %5
5311
5312block4(%6: ptr):
5313    indirect_br %6, block3, block5
5314
5315block5:
5316    %7 = iconst.i32 2
5317    return %7
5318";
5319        assert_eq!(body(source), expected);
5320    }
5321
5322    #[test]
5323    fn a_jump_to_an_address_no_label_in_the_function_has_arrives_nowhere() {
5324        // The address came from outside the function, and a jump to a label in another function
5325        // is undefined. The expression is still evaluated, since a call in it has to happen.
5326        let source = "void **next(void);
5327void f(void) { goto *next(); }
5328";
5329        let expected = "\
5330block0:
5331    %0 = call @next() : () -> ptr
5332    unreachable
5333";
5334        assert_eq!(body(source), expected);
5335    }
5336
5337    #[test]
5338    fn an_asm_with_no_operands_is_volatile_and_the_clobbers_are_the_whole_of_what_it_says() {
5339        // Nothing reads a result, so the only thing that keeps it is that it is volatile, which
5340        // a basic asm implies.
5341        let source = "void f(void) { __asm__(\"mfence\" ::: \"memory\"); }\n";
5342        let expected = "\
5343block0:
5344    inline_asm.volatile \"mfence\", \"\", \"memory\"()
5345    return
5346";
5347        assert_eq!(body(source), expected);
5348    }
5349
5350    #[test]
5351    fn the_constraints_are_one_list_in_the_order_the_template_counts_the_operands() {
5352        // The outputs first and then the inputs, which is the numbering `%0` and `%1` use. An
5353        // output in a register is a result, and one that is read as well is an argument too.
5354        let source = "\
5355int f(int x, int y) {
5356  int r;
5357  __asm__(\"addl %2, %0\" : \"=r\"(r), \"+r\"(y) : \"r\"(x));
5358  return r + y;
5359}
5360";
5361        let expected = "\
5362block0(%0: i32, %1: i32):
5363    %2, %3 = inline_asm.(i32, i32) \"addl %2, %0\", \"=r,+r,r\", \"\"(%1, %0)
5364    %4 = add.nsw %2, %3
5365    return %4
5366";
5367        assert_eq!(body(source), expected);
5368    }
5369
5370    #[test]
5371    fn a_memory_operand_travels_as_the_address_of_an_object_that_is_given_a_slot() {
5372        // The assembly is handed a pointer, so the object cannot live in a value, and the scan
5373        // that runs before the walk has to have known that or there would be nothing to point
5374        // at. A structure travels this way whatever else its constraint allows, since there is
5375        // no register that holds one.
5376        let source = "\
5377struct pair { int a, b; };
5378int f(int x) {
5379  int slot = x;
5380  struct pair p = { x, x };
5381  __asm__(\"incl %0\" : \"+m\"(slot), \"=m\"(p));
5382  return slot + p.a;
5383}
5384";
5385        let text = body(source);
5386        assert!(text.contains("inline_asm \"incl %0\", \"+m,=m\", \"\"(%1, %2)\n"), "{text}");
5387        assert!(text.contains("%1 = alloca, size 4, align 4\n"), "{text}");
5388        assert!(text.contains("%2 = alloca, size 8, align 4\n"), "{text}");
5389    }
5390
5391    #[test]
5392    fn an_asm_goto_falls_through_to_its_first_target_and_writes_its_outputs_there() {
5393        // The output is only in scope where the instruction dominates, which is the fall through
5394        // block, so the edge to the label carries the value the object had before the assembly
5395        // ran. That is what document 11 asks for and it is what putting the fall through first
5396        // buys.
5397        let source = "\
5398int f(int x) {
5399  int r = 7;
5400  __asm__ goto(\"cbnz %0, %l1\" : \"=r\"(r) : \"r\"(x) :: away);
5401  return r;
5402away:
5403  return r;
5404}
5405";
5406        let expected = "\
5407block0(%0: i32):
5408    %1 = iconst.i32 7
5409    %2 = inline_asm.volatile \"cbnz %0, %l1\", \"=r,r\", \"\"(%0), labels [block1, block2]
5410
5411block1:
5412    return %2
5413
5414block2:
5415    return %1
5416";
5417        assert_eq!(body(source), expected);
5418    }
5419
5420    #[test]
5421    fn an_asm_statement_that_is_not_well_formed_is_reported_in_the_words_gcc_uses() {
5422        // The operands are checked here rather than by the assembler, because by the time the
5423        // assembler sees the template the operands have become registers and it has nothing left
5424        // to say about the C that named them.
5425        let mut opts = options();
5426        opts.emit = EmitKind::Ir;
5427        for (source, expected) in [
5428            (
5429                "void f(int x) { __asm__(\"\" : \"r\"(x)); }\n",
5430                "output operand constraint lacks '='",
5431            ),
5432            (
5433                "void f(int x) { __asm__(\"\" : \"=r\"(x + 1)); }\n",
5434                "lvalue required in 'asm' statement",
5435            ),
5436            (
5437                "const int g = 1;\nvoid f(void) { __asm__(\"\" : \"=r\"(g)); }\n",
5438                "read-only variable 'g' used as 'asm' output",
5439            ),
5440            (
5441                "void f(int x) { __asm__(\"\" : : \"=r\"(x)); }\n",
5442                "input operand constraint contains '='",
5443            ),
5444            (
5445                "void f(void) { __asm__(\"\" : : \"m\"(1)); }\n",
5446                "memory input 0 is not directly addressable",
5447            ),
5448            ("void f(void) { __asm__(L\"\"); }\n", "wide string literal in 'asm'"),
5449            (
5450                "void f(int x, int y) { __asm__(\"\" : [a] \"=r\"(x) : [a] \"r\"(y)); }\n",
5451                "duplicate asm operand name 'a'",
5452            ),
5453            ("void f(int x) { __asm__(\"%[in]\" : \"=r\"(x)); }\n", "undefined named operand 'in'"),
5454        ] {
5455            let result = run(&opts, source);
5456            assert!(result.failed(), "expected this to be reported:\n{source}");
5457            assert!(
5458                result.messages.iter().any(|m| m.contains(expected)),
5459                "{expected}\n{:?}",
5460                result.messages
5461            );
5462        }
5463    }
5464
5465    #[test]
5466    fn what_the_walk_cannot_build_yet_is_reported_rather_than_mislowered() {
5467        let mut opts = options();
5468        opts.emit = EmitKind::Ir;
5469        for source in [
5470            "int f(int n) { void *p = &&out; if (n) goto *p; { int a[n]; out: return 1; } }\n",
5471            "int f(int n) { int a[n]; __asm__ goto(\"\" ::::out); out: return a[0]; }\n",
5472        ] {
5473            let result = run(&opts, source);
5474            assert!(result.failed(), "expected this to be reported:\n{source}");
5475            assert!(
5476                result.messages.iter().any(|m| m.contains("not supported yet")),
5477                "{:?}",
5478                result.messages
5479            );
5480        }
5481    }
5482
5483    /// Compiles `source` to IR, reads that back as an input, and gives back both texts.
5484    fn round_trip(source: &str) -> (String, String) {
5485        let printed = ir(source);
5486        let mut opts = options();
5487        opts.emit = EmitKind::Ir;
5488        let mut fs = MemoryFileSystem::new();
5489        fs.insert("/main.ir", printed.clone().into_bytes());
5490        let result = compile_ir(&opts, "/main.ir", &fs);
5491        assert_eq!(result.messages, Vec::<String>::new(), "expected this to read back:\n{printed}");
5492        (printed, result.text().to_owned())
5493    }
5494
5495    #[test]
5496    fn ir_that_arrives_as_an_input_is_read_back_and_written_out_the_same() {
5497        // The other half of the round trip test below, through the driver rather than through
5498        // the library, which is what makes the property something to run over a real program
5499        // rather than over the modules a test builds.
5500        let (printed, again) = round_trip(
5501            "struct point { int x, y; };\n             static const char greeting[] = \"hi\";\n             int puts(const char *);\n             int f(int n) { struct point p = { n, 1 }; puts(greeting); return p.x; }\n",
5502        );
5503        assert_eq!(printed, again);
5504    }
5505
5506    #[test]
5507    fn ir_that_is_not_ir_says_which_line_stopped_it() {
5508        let mut opts = options();
5509        opts.emit = EmitKind::Ir;
5510        let mut fs = MemoryFileSystem::new();
5511        let text = "\
5512; ModuleID = 'a.c'
5513; format 0
5514target triple = \"x86_64-unknown-linux-gnu\"
5515target datalayout = \"e-p:64:64-i64:64-S128\"
5516
5517func @f(), linkage(external) {
5518block0:
5519    frobnicate
5520}
5521";
5522        fs.insert("/main.ir", text.as_bytes().to_vec());
5523        let result = compile_ir(&opts, "/main.ir", &fs);
5524        assert!(result.failed());
5525        assert!(result.messages[0].contains("/main.ir:8"), "{:?}", result.messages);
5526    }
5527
5528    #[test]
5529    fn ir_that_reads_but_does_not_hold_together_is_reported_by_the_verifier() {
5530        // A module that a person edited has not been through the verifier, and the return of
5531        // an `i32` from a function that returns nothing is the kind of thing editing produces.
5532        let mut opts = options();
5533        opts.emit = EmitKind::Ir;
5534        let mut fs = MemoryFileSystem::new();
5535        let text = "\
5536; ModuleID = 'a.c'
5537; format 0
5538target triple = \"x86_64-unknown-linux-gnu\"
5539target datalayout = \"e-p:64:64-i64:64-S128\"
5540
5541func @f(), linkage(external) {
5542block0:
5543    %0 = iconst.i32 1
5544    return %0
5545}
5546";
5547        fs.insert("/main.ir", text.as_bytes().to_vec());
5548        let result = compile_ir(&opts, "/main.ir", &fs);
5549        assert!(result.failed());
5550        assert!(result.messages[0].contains("invalid IR"), "{:?}", result.messages);
5551    }
5552
5553    #[test]
5554    fn a_typed_tree_is_not_something_an_input_of_ir_can_produce() {
5555        // The C that became this is not here any more, so there is nothing to print a tree of.
5556        let mut fs = MemoryFileSystem::new();
5557        fs.insert("/main.ir", Vec::new());
5558        let result = compile_ir(&options(), "/main.ir", &fs);
5559        assert!(result.failed());
5560        assert!(result.messages[0].contains("can only be emitted as IR"), "{:?}", result.messages);
5561    }
5562
5563    #[test]
5564    fn the_printed_ir_reads_back_as_the_same_module() {
5565        // The M2 exit criterion: the text is the module and nothing about it is lost by
5566        // writing it down. Anything the printer invents or the parser drops shows up here.
5567        let text = ir("\
5568struct point { int x, y; };
5569static const char greeting[] = \"hi\";
5570int table[4] = { 1, 2, 3 };
5571int puts(const char *);
5572double half(double x) { return x / 2.0; }
5573int f(int n) {
5574  int total = 0;
5575  for (int i = 0; i < n; i++) {
5576    if (i == 3) continue;
5577    total += table[i];
5578  }
5579  switch (n) {
5580    case 0: total = 1;
5581    case 1: total++; break;
5582    default: total = -total;
5583  }
5584  struct point p = { total, 1 };
5585  int *q = &p.y;
5586  puts(greeting);
5587  return p.x + *q;
5588}
5589int dispatch(int c) {
5590  void *p = c ? &&one : &&two;
5591  goto *p;
5592one:
5593  return 1;
5594two:
5595  return 2;
5596}
5597int assembly(int x, int *p) {
5598  int r;
5599  __asm__ volatile(\"xadd %0, %2\" : \"=r\"(r), \"+m\"(*p) : \"0\"(x) : \"cc\");
5600  __asm__ goto(\"cbnz %0, %l1\" : : \"r\"(r) : : away);
5601  return r;
5602away:
5603  return 0;
5604}
5605");
5606        let mut names = Interner::new();
5607        let module = rucc_ir::parse(&text, &mut names).expect("the printer writes what it reads");
5608        assert_eq!(rucc_ir::print(&module, &names), text);
5609    }
5610
5611    #[test]
5612    fn what_save_temps_keeps_is_the_text_that_was_compiled_and_the_assembly_that_was_assembled() {
5613        // The point of the flag is that these two are the compilation rather than a description
5614        // of one, so both come out of the run that produced the object rather than out of a
5615        // second run under different flags.
5616        let mut opts = options();
5617        opts.emit = EmitKind::Object;
5618        opts.save_temps = rucc_session::SaveTemps::Object;
5619        let result = run(&opts, "#define N 2\nint a[N];\n");
5620        assert_eq!(result.messages, Vec::<String>::new());
5621        let text = result.temps.preprocessed.expect("the preprocessed text");
5622        assert!(text.contains("int a[2];"), "{text}");
5623        assert!(text.starts_with("# 1 \"/main.c\""), "{text}");
5624        let asm = result.temps.assembly.expect("the assembly");
5625        assert!(asm.contains("a:"), "{asm}");
5626        assert!(matches!(result.artifact, Artifact::Object(_)), "{:?}", result.artifact);
5627    }
5628
5629    #[test]
5630    fn nothing_is_kept_unless_the_flag_asked_for_it() {
5631        // A compilation that was not asked to keep anything must not pay for printing text
5632        // nobody will read, and the empty value is what says so.
5633        let mut opts = options();
5634        opts.emit = EmitKind::Object;
5635        assert_eq!(run(&opts, "int a;\n").temps, Temps::default());
5636    }
5637
5638    #[test]
5639    fn a_compilation_that_stops_before_the_back_end_keeps_the_text_and_no_assembly() {
5640        // `--emit=ir` never produces any, and the text is worth keeping all the same: it is
5641        // what a report about the file being read wrongly has to have in it.
5642        let mut opts = options();
5643        opts.emit = EmitKind::Ir;
5644        opts.save_temps = rucc_session::SaveTemps::Cwd;
5645        let result = run(&opts, "int a;\n");
5646        assert!(result.temps.preprocessed.is_some());
5647        assert_eq!(result.temps.assembly, None);
5648    }
5649}