Skip to main content

rucc_driver/
compile.rs

1//! Running the front end over one file, from the bytes on disk to the typed tree.
2//!
3//! Design: `spec/04-driver-and-cli.md` section 4.3, and the `M2` exit criterion in
4//! `spec/17-milestones.md` that says `--emit=tast` works.
5//!
6//! [`preprocess`](mod@crate::preprocess) stops after phase 4 because `-E` stops there. This
7//! carries on: phase 7, the parse, and the checking. It is one function rather than four composed
8//! ones because of what the four share. The tokens hold interned symbols, the untyped tree holds
9//! tokens, the typed tree holds the untyped tree's spans, and none of them owns the table it is
10//! reading, so one [`Session`] has to outlive all of them and there has to be one place that
11//! holds it.
12
13use std::path::Path;
14
15use rucc_base::Interner;
16use rucc_codegen::coverage::Fired;
17use rucc_codegen::pipeline::{self, Machine};
18use rucc_diag::{Diagnostic, Severity, Span};
19use rucc_lex::{Convert, Keywords, PpToken, convert};
20use rucc_sema::{Checker, Context as CheckContext};
21use rucc_session::{EmitKind, FileSystem, Options, Session};
22use rucc_target::TargetInfo;
23
24use crate::preprocess::render;
25
26/// What a compilation produced, which is text for most of the kinds and bytes for one of them.
27///
28/// Two variants rather than a string, because an object file is not text and a `Vec<u8>` holding
29/// UTF-8 for six kinds and a file format for the seventh would leave every reader guessing which
30/// it had. [`Artifact::Nothing`] is what a compilation that stopped early gives back, and it is
31/// not the same as an empty file: nothing is written for it at all.
32#[derive(Debug, Clone, PartialEq, Eq, Default)]
33pub enum Artifact {
34    /// The compilation stopped before it produced anything, or the kind asked for produces
35    /// nothing yet.
36    #[default]
37    Nothing,
38    /// Text, which is every kind up to and including assembly.
39    Text(String),
40    /// An object file, which is `-c`.
41    Object(Vec<u8>),
42}
43
44impl Artifact {
45    /// The bytes to write, which is nothing at all for [`Artifact::Nothing`].
46    #[must_use]
47    pub fn bytes(&self) -> &[u8] {
48        match self {
49            Artifact::Nothing => &[],
50            Artifact::Text(text) => text.as_bytes(),
51            Artifact::Object(bytes) => bytes,
52        }
53    }
54}
55
56/// What compiling one file produced.
57#[derive(Debug, Clone, PartialEq, Eq)]
58pub struct Compiled {
59    /// What to write, which is nothing when the compilation failed or produced nothing.
60    pub artifact: Artifact,
61    /// The diagnostics, already rendered, one per element, in the order they were reported.
62    pub messages: Vec<String>,
63    /// How many of them were errors.
64    pub errors: u32,
65    /// Which lowering rules this file fired, for `-Zrule-coverage`.
66    ///
67    /// Empty for a compilation that stopped before the back end, which every kind up to and
68    /// including `--emit=ir` does. That is not the same as a rule set nothing reaches and the
69    /// caller unions these rather than reading one, so a file that fired nothing adds nothing.
70    pub fired: Fired,
71    /// What `-fdump-ir=` asked to see, in the order the passes ran.
72    ///
73    /// The optimizer does not write files, because nothing below the driver in
74    /// `spec/18-package-layout.md` knows what a file is, so the text comes back here and the
75    /// caller decides where it goes.
76    pub dumps: Vec<rucc_opt::Dump>,
77    /// What `-fopt-info` asked to hear, already rendered, one remark per line.
78    ///
79    /// Empty when the flag was not given, and also empty when it was given and no pass had
80    /// anything of the kinds asked for to say. Those two are the same text and different facts,
81    /// which is why a misspelled keyword is an error rather than a quiet nothing.
82    pub remarks: String,
83}
84
85impl Compiled {
86    /// Whether anything went wrong badly enough that the output should not be used.
87    #[must_use]
88    pub fn failed(&self) -> bool {
89        self.errors > 0
90    }
91
92    /// The text that was produced, and the empty string for anything that is not text.
93    ///
94    /// A caller that asked for one of the text kinds knows which it asked for, so this saves it
95    /// matching on a variant it has already ruled out.
96    #[must_use]
97    pub fn text(&self) -> &str {
98        match &self.artifact {
99            Artifact::Text(text) => text,
100            _ => "",
101        }
102    }
103}
104
105/// Compiles one file as far as `opts.emit` asks for and renders the result.
106///
107/// `name` is the path as the user wrote it, which is the name every diagnostic about the file
108/// uses. Every kind but the executable produces something today, and that one runs the same front
109/// end and gives back nothing, so that a file with a mistake in it is reported the same way
110/// whichever kind was asked for, rather than compiling silently until the part that is written
111/// notices.
112///
113/// The checking is skipped when the parse reported an error. The two poisoning rules mean a
114/// diagnosed expression produces no further complaints, but a declaration the parser had to skip
115/// past leaves no declaration behind at all, and every later use of that name would be reported
116/// as undeclared. One mistake is worth one message.
117#[must_use]
118pub fn compile(opts: &Options, name: &str, fs: &dyn FileSystem) -> Compiled {
119    let mut sess = Session::new(opts.clone());
120    // Before anything else interns a name. The keyword symbols have to be one unbroken run for
121    // a lookup to be a subtraction, and the preprocessor interns every identifier it reads, so
122    // building this after the expansion would mean building it after `char` had been seen.
123    let keywords = Keywords::new(&mut sess.interner, opts.std, opts.gnu_extensions);
124    let mut diagnostics: Vec<Diagnostic> = Vec::new();
125    // Filled in by the back end when there is one, and empty for every kind that stops before it.
126    let mut fired = Fired::new();
127    // Filled in by the optimizer, and only when `-fdump-ir=` asked for something.
128    let mut dumps = Vec::new();
129    let mut remarks = String::new();
130
131    let bytes = match fs.read(Path::new(name)) {
132        Ok(bytes) => bytes,
133        Err(e) => return failure(format!("{name}: {e}")),
134    };
135    let Ok(file) = sess.sources.add_shared(name, bytes, None) else {
136        return failure(format!("{name}: the source map has no room left for this file"));
137    };
138
139    // Phases 1 to 4. The expanded stream is turned into pp-tokens straight away, because the
140    // include context borrows the source map that rendering a diagnostic reads and the borrow
141    // has to end before anything is rendered.
142    let mut pp = rucc_pp::Preprocessor::new();
143    let predef = rucc_pp::Predef::for_options(opts);
144    let expanded: Vec<PpToken> = {
145        let mut cx = rucc_pp::Context::new(&mut sess.interner, &mut sess.sources, fs, &opts.search);
146        cx.lex = rucc_lex::Options::for_dialect(opts.std, opts.gnu_extensions);
147        if pp.predefine(&sess.target, &predef, &mut cx).is_err() {
148            return failure(format!("{name}: the source map has no room for the built in macros"));
149        }
150        pp.run(file, &mut cx).iter().map(|token| token.to_pp()).collect()
151    };
152    diagnostics.extend(pp.take_diagnostics());
153
154    // Phase 7, which is where a spelling becomes a keyword and a preprocessing number becomes
155    // a constant of a type.
156    let cx = Convert {
157        keywords: &keywords,
158        interner: &sess.interner,
159        target: &sess.target,
160        std: opts.std,
161        gnu: opts.gnu_extensions,
162        pedantic: opts.pedantic,
163    };
164    let (tokens, complaints) = convert(&expanded, &cx);
165    diagnostics.extend(complaints);
166
167    let parsed = rucc_parse::parse(
168        &tokens,
169        rucc_parse::Context {
170            interner: &sess.interner,
171            std: opts.std,
172            gnu: opts.gnu_extensions,
173            pedantic: opts.pedantic,
174            error_limit: opts.error_limit as usize,
175        },
176    );
177    let parse_failed = parsed.diagnostics.iter().any(|d| d.severity.is_fatal());
178    diagnostics.extend(parsed.diagnostics);
179
180    let mut artifact = Artifact::Nothing;
181    // Zero when nothing instruments, which is the truthful summary of a file built without
182    // `-fsafety`: no checks went in, so none is standing, and every call it makes is unmodelled.
183    let mut instrumented = Instrumented::default();
184    if !parse_failed {
185        let mut checker = Checker::new(
186            &parsed.ast,
187            CheckContext {
188                names: &sess.interner,
189                target: &sess.target,
190                std: opts.std,
191                gnu: opts.gnu_extensions,
192                pedantic: opts.pedantic,
193                error_limit: opts.error_limit as usize,
194                // A freestanding program has no C library, so a name that is the library's
195                // everywhere else is the program's own here and means whatever it defined.
196                builtins: opts.builtins && opts.hosted,
197                no_builtin: &opts.no_builtin,
198            },
199        );
200        checker.check_unit();
201        let checked = checker.finish();
202        if !checked.failed() {
203            match opts.emit {
204                EmitKind::Tast => {
205                    artifact = Artifact::Text(rucc_sema::print(
206                        &checked.tast,
207                        &checked.types,
208                        &sess.interner,
209                    ));
210                }
211                // Nothing past the checker, because a granule is a fact about a layout and a
212                // layout is settled the moment the closing brace is seen. Lowering the
213                // function bodies would take minutes on an amalgamation and answer nothing.
214                EmitKind::TypeGranules => {
215                    artifact = Artifact::Text(rucc_types::granule_report(
216                        &checked.types,
217                        &sess.interner,
218                        &sess.target,
219                    ));
220                }
221                EmitKind::Ir
222                | EmitKind::MirFinal
223                | EmitKind::Asm
224                | EmitKind::Object
225                | EmitKind::Executable
226                | EmitKind::SafetySummary => {
227                    let mut lowered = rucc_lower::lower(
228                        name,
229                        rucc_lower::Context {
230                            tast: &checked.tast,
231                            types: &checked.types,
232                            target: &sess.target,
233                            names: &mut sess.interner,
234                        },
235                    );
236                    // The walk reports what it cannot build, and what it did build is printed
237                    // anyway: a file with one construct missing from it is more use to read
238                    // than nothing at all, and the errors are what stop it being compiled.
239                    let failed = lowered.diagnostics.iter().any(|d| d.severity.is_fatal());
240                    if !failed {
241                        // The verifier runs on everything the walk builds, always. It is the
242                        // one check that a bug in the walk cannot talk its way past, and a
243                        // wrong instruction found here costs a message rather than an hour
244                        // in front of a debugger over the assembly it turned into.
245                        if let Err(errors) = rucc_ir::verify(&lowered.module, &sess.interner) {
246                            for error in errors {
247                                diagnostics.push(internal(&format!("invalid IR, {error}")));
248                            }
249                        } else if let Err(complaints) =
250                            instrument(&mut lowered.module, &mut sess.interner, opts)
251                                .map(|done| instrumented = done)
252                        {
253                            diagnostics.extend(complaints);
254                        } else if let Err(complaints) = optimize(
255                            &mut lowered.module,
256                            &sess.interner,
257                            opts,
258                            name,
259                            &mut dumps,
260                            &mut remarks,
261                        ) {
262                            diagnostics.extend(complaints);
263                        } else if opts.emit == EmitKind::SafetySummary {
264                            // After the optimizer, because the number that matters is how many
265                            // checks are still standing and there is no way to know that before it
266                            // has run. Before the back end, because the back end turns a check into
267                            // a call and a summary of calls is not a summary of checks.
268                            artifact = Artifact::Text(
269                                rucc_safety::summarize(
270                                    &lowered.module,
271                                    &sess.interner,
272                                    name,
273                                    opts.safety.as_str(),
274                                    instrumented.checks,
275                                    instrumented.interposed,
276                                    instrumented.crossings,
277                                )
278                                .render(),
279                            );
280                        } else if opts.emit == EmitKind::Ir {
281                            // After the optimizer rather than before it, so that `--emit=ir -O2`
282                            // is the IR the back end will be given rather than the IR it would
283                            // have been given at `-O0`. There is no other way to see what a pass
284                            // did without reading the assembly it turned into.
285                            artifact =
286                                Artifact::Text(rucc_ir::print(&lowered.module, &sess.interner));
287                        } else {
288                            // The back end, which is every pass after the IR and which is
289                            // where a construct nothing has a rule for is finally noticed.
290                            match generate(
291                                &mut lowered.module,
292                                &mut sess.interner,
293                                &sess.target,
294                                opts,
295                                &mut fired,
296                            ) {
297                                Ok(made) => artifact = made,
298                                Err(complaints) => diagnostics.extend(complaints),
299                            }
300                        }
301                    }
302                    diagnostics.extend(lowered.diagnostics);
303                }
304                _ => {}
305            }
306        }
307        diagnostics.extend(checked.diagnostics);
308    }
309
310    let mut messages = Vec::with_capacity(diagnostics.len());
311    let mut errors = 0;
312    for diag in &diagnostics {
313        // `-w` drops the warning here rather than at the several hundred places one is raised,
314        // and it drops it before the count, so `-w -Werror` compiles. A warning that was never
315        // raised is not a warning there is anything to promote.
316        if !opts.warnings && diag.severity == Severity::Warning {
317            continue;
318        }
319        if diag.severity.is_fatal()
320            || (diag.severity == Severity::Warning && opts.warnings_are_errors)
321        {
322            errors += 1;
323        }
324        messages.push(render(diag, &sess.sources, opts.warnings_are_errors));
325    }
326    if errors > 0 {
327        // A tree built from a file that did not compile is not a tree anything should read.
328        artifact = Artifact::Nothing;
329    }
330    // Kept even when the compilation failed, because a rule that fired did fire and a report about
331    // which rules a corpus reaches should not lose the ones a file with a mistake in it reached.
332    Compiled { artifact, messages, errors, fired, dumps, remarks }
333}
334
335/// Reads one file of IR, checks it, and prints it back.
336///
337/// This is the compiler's own textual IR arriving as an input rather than leaving as an output,
338/// which is what makes the round trip in the M2 exit criterion something to run rather than
339/// something to believe: what the printer wrote is read back, verified, and written again, and
340/// the two files are either the same bytes or they are not.
341///
342/// The verifier runs here for the reason it runs after the walk. A module that was printed by
343/// this compiler has been through it once already, and one that a person edited has not.
344#[must_use]
345pub fn compile_ir(opts: &Options, name: &str, fs: &dyn FileSystem) -> Compiled {
346    let mut sess = Session::new(opts.clone());
347    if opts.emit != EmitKind::Ir {
348        return failure(format!(
349            "{name}: an input of IR can only be emitted as IR, and `--emit={}` asks for what \
350             the C in front of it became",
351            opts.emit.as_str()
352        ));
353    }
354    let bytes = match fs.read(Path::new(name)) {
355        Ok(bytes) => bytes,
356        Err(e) => return failure(format!("{name}: {e}")),
357    };
358    let Ok(text) = std::str::from_utf8(bytes.as_slice()) else {
359        return failure(format!("{name}: this is not text, so it is not IR"));
360    };
361
362    let module = match rucc_ir::parse(text, &mut sess.interner) {
363        Ok(module) => module,
364        Err(error) => {
365            return failure(format!("{name}:{}: {}", error.line, error.message));
366        }
367    };
368    let mut diagnostics: Vec<Diagnostic> = Vec::new();
369    if let Err(errors) = rucc_ir::verify(&module, &sess.interner) {
370        for error in errors {
371            diagnostics.push(invalid(&format!("invalid IR, {error}")));
372        }
373    }
374    let mut messages = Vec::with_capacity(diagnostics.len());
375    for diag in &diagnostics {
376        messages.push(render(diag, &sess.sources, opts.warnings_are_errors));
377    }
378    let errors = u32::try_from(messages.len()).unwrap_or(u32::MAX);
379    let artifact = if errors > 0 {
380        Artifact::Nothing
381    } else {
382        Artifact::Text(rucc_ir::print(&module, &sess.interner))
383    };
384    // Nothing here reaches the back end, so no rule fired and there is nothing to record.
385    Compiled {
386        artifact,
387        messages,
388        errors,
389        fired: Fired::new(),
390        dumps: Vec::new(),
391        remarks: String::new(),
392    }
393}
394
395/// Puts the memory safety checks in and redirects the calls that cross the boundary, when
396/// `-fsafety=` asked for them.
397///
398/// Between the walk and the optimizer, which is where section 15.3 of
399/// `spec/safe-memory/15-integration.md` puts it and which is the whole design in one line: the
400/// checks go in while the addresses the program computes still exist, and the optimizer then
401/// discharges the ones it can prove. Every sanitizer that came before instruments after the
402/// optimizer so that its checks cannot be deleted, and pays for all of them forever.
403///
404/// The calls to the C library are redirected here too, and in the same window and for a related
405/// reason. `spec/safe-memory/10-boundaries.md` section 10.3 wants a `memcpy` modelled by a wrapper
406/// that performs the judgements, and `rucc_safety::wrap` is why that has to happen before the
407/// optimizer sees the call rather than after.
408///
409/// The verifier runs again afterwards, for the reason it runs after the walk. This pass rewrites
410/// every function in the module, and a pass that produced IR nothing else accepts should say so
411/// here rather than in the assembly it turned into.
412///
413/// # Errors
414///
415/// When the inserted checks left the module in a state the verifier refuses, which is a bug in
416/// this compiler and not in the program being compiled.
417fn instrument(
418    module: &mut rucc_ir::Module,
419    names: &mut Interner,
420    opts: &Options,
421) -> Result<Instrumented, Vec<Diagnostic>> {
422    if !opts.safety.instruments() {
423        return Ok(Instrumented::default());
424    }
425    let checks = rucc_safety::run(module);
426    // Before the optimizer rather than beside the check lowering, which is what
427    // `rucc_safety::wrap` argues out: `memcpy` is a name an optimizer knows things about, and a
428    // pass that turns a short copy into a pair of loads and stores would leave behind accesses the
429    // check insertion has already finished walking past.
430    let interposed = rucc_safety::redirect(module, names);
431    // After the redirection, so that a call this build models with a wrapper is not also counted
432    // as a crossing it did not model.
433    let crossings = rucc_safety::witness(module, names);
434    match rucc_ir::verify(module, names) {
435        Ok(()) => Ok(Instrumented { checks, interposed, crossings }),
436        Err(errors) => Err(errors
437            .iter()
438            .map(|e| internal(&format!("invalid IR after check insertion, {e}")))
439            .collect()),
440    }
441}
442
443/// What the instrumentation did, which nothing but the summary reads.
444///
445/// Carried out of [`instrument`] rather than recovered from the module afterwards because neither
446/// number survives the optimizer: a check that was discharged leaves nothing behind saying it was
447/// ever there, and a call that was pointed at a wrapper looks like a call that always named one.
448#[derive(Clone, Copy, Debug, Default)]
449struct Instrumented {
450    /// How many checks of each class went in.
451    checks: rucc_safety::Counts,
452    /// How many calls were pointed at an interposition wrapper.
453    interposed: usize,
454    /// How many places a pointer crosses to or from code this build did not instrument.
455    crossings: rucc_safety::Sites,
456}
457
458/// Runs the optimizer over the module, and collects whatever the dumps asked for.
459///
460/// The level chooses a pipeline, the `-f` flags edit it, and at `-O0` there is nothing in it, so
461/// this is a walk over an empty list rather than a branch on the level. See section 9.1 of
462/// `spec/09-optimizer.md` for why the pipelines are written out rather than assembled.
463///
464/// # Errors
465///
466/// When a pass left the module in a state the verifier refuses, which is a bug in the pass and
467/// not in the program being compiled, so it is reported as an internal error the way a bad
468/// lowering is.
469fn optimize(
470    module: &mut rucc_ir::Module,
471    names: &Interner,
472    opts: &Options,
473    file: &str,
474    dumps: &mut Vec<rucc_opt::Dump>,
475    remarks: &mut String,
476) -> Result<(), Vec<Diagnostic>> {
477    let mut settings = rucc_opt::Options::for_level(opts.opt_level);
478    settings.toggles.clone_from(&opts.passes);
479    settings.fuel = opts.pass_fuel.iter().cloned().collect();
480    settings.global_fuel = opts.pass_fuel_global;
481    settings.verify |= opts.verify_each;
482    for (on, spec) in &opts.pass_gates {
483        // Same argument as the dumps below: every spelling in here was checked while the
484        // arguments were parsed, so a rejection now is this compiler disagreeing with itself.
485        if let Err(why) = settings.gates.add(*on, spec) {
486            return Err(vec![internal(&why)]);
487        }
488    }
489    for spec in &opts.dump_ir {
490        // Every spelling in here was checked while the arguments were parsed, so a rejection
491        // now is this compiler disagreeing with itself rather than the command line being wrong.
492        if let Err(why) = settings.dumps.add(spec) {
493            return Err(vec![internal(&why)]);
494        }
495    }
496    let mut wants = rucc_opt::Wants::none();
497    for spec in &opts.opt_info {
498        // Same argument as the dumps above: every spelling was checked while the arguments were
499        // parsed, so a rejection now is the compiler disagreeing with itself.
500        if let Err(why) = wants.add(spec) {
501            return Err(vec![internal(&why)]);
502        }
503    }
504    let report = rucc_opt::run(module, names, &settings);
505    remarks.push_str(&rucc_opt::optinfo::render(file, &report, names, wants));
506    dumps.extend(report.dumps);
507    match report.broke.is_empty() {
508        true => Ok(()),
509        false => Err(report.broke.iter().map(|why| internal(why)).collect()),
510    }
511}
512
513/// Runs the back end over every function in `module` and writes what came out.
514///
515/// One machine function per definition in the module, in the order the module holds them, every
516/// register physical and every frame offset a constant. A declaration has no body and is skipped,
517/// because there is nothing in it to compile.
518///
519/// What the last step is, is the only thing `--emit=mir-final`, `-S` and `-c` disagree about. The
520/// three read the same functions and differ in whether they are printed as machine IR, printed as
521/// assembly, or encoded and put in a file, which is the point of section 11.1 of
522/// `spec/11-asm-objects-debug.md`: a listing that disagrees with the object file beside it is
523/// worse than no listing, and the way to make that impossible is to have one description of an
524/// instruction and two ways of writing it down.
525///
526/// # Errors
527///
528/// One diagnostic per function the back end could not compile, or one about the target when no
529/// back end covers it at all. Every function is attempted rather than stopping at the first, so a
530/// file with three constructs missing from the rule set reports three rather than one at a time.
531fn generate(
532    module: &mut rucc_ir::Module,
533    names: &mut Interner,
534    target: &TargetInfo,
535    opts: &Options,
536    fired: &mut Fired,
537) -> Result<Artifact, Vec<Diagnostic>> {
538    let Some(machine) = Machine::for_target(target) else {
539        return Err(vec![unsupported(&format!(
540            "there is no back end for {} in this compiler yet, so there is nothing to generate",
541            target.triple
542        ))]);
543    };
544    let flags = pipeline::Flags { frame_pointer: opts.frame_pointer, red_zone: opts.red_zone };
545
546    // The checks become calls here rather than beside the insertion, because the id each one
547    // carries is an index into a table and a row for a check the optimizer deleted is a row nothing
548    // will ever name. Section 6.3.1 of `spec/safe-memory/06-instrumentation.md` is what this
549    // eventually becomes and `rucc_safety::lower` says why it is not that yet.
550    //
551    // It is inside the back end rather than beside the optimizer so that `--emit=ir` still shows
552    // the checks. The IR a person reads should say what the compiler decided, not how it spelled it
553    // for the machine.
554    if opts.safety.instruments() {
555        rucc_safety::lower(module, names);
556        if let Err(errors) = rucc_ir::verify(module, names) {
557            return Err(errors
558                .iter()
559                .map(|e| internal(&format!("invalid IR after check lowering, {e}")))
560                .collect());
561        }
562    }
563
564    let mut funcs = Vec::new();
565    let mut complaints = Vec::new();
566    for id in module.funcs() {
567        if module[id].is_declaration() {
568            continue;
569        }
570        match pipeline::compile_recording(&mut module[id], names, &machine, flags, fired) {
571            Ok(func) => funcs.push(func),
572            Err(why) => {
573                let name = names.resolve(module[id].name).to_owned();
574                // The function knows where the instruction came from, so the message lands on
575                // the line somebody wrote rather than on the file as a whole.
576                let span = why.inst().map_or(Span::DUMMY, |inst| module[id].span(inst));
577                let said = format!("cannot generate code for '{name}': {why}");
578                complaints.push(unsupported_at(&said, span));
579            }
580        }
581    }
582    if !complaints.is_empty() {
583        return Err(complaints);
584    }
585    // The variables the file defines, which go through the back end the way the functions did not:
586    // there is nothing in a variable to select instructions for, so the module is what says what
587    // one is right up to the point where it is written down.
588    let globals = match opts.emit {
589        EmitKind::Asm | EmitKind::Object | EmitKind::Executable => {
590            rucc_asm::globals(module, names).map_err(refused)?
591        }
592        _ => rucc_asm::Globals::default(),
593    };
594    // A failure in either of the last two is a bug here rather than a program this compiler is
595    // behind on, because every instruction in a function that got this far came out of the same
596    // description both of them read and every register in it has been allocated.
597    match opts.emit {
598        EmitKind::Asm => {
599            rucc_asm::print(&funcs, &globals, names, target).map(Artifact::Text).map_err(refused)
600        }
601        // An executable is an object as far as this gets: one is what each file of a link
602        // contributes, and the linker is what turns them into the other.
603        EmitKind::Object | EmitKind::Executable => {
604            let text = rucc_asm::assemble(&funcs, names, target).map_err(refused)?;
605            let data = globals.image();
606            // A format with no writer is a target this compiler is behind on and anything else
607            // the writer refused is a bug here, and the two are not the same news to get.
608            rucc_object::write(&text, &data, target).map(Artifact::Object).map_err(
609                |why| match why {
610                    rucc_object::Error::Format { .. } => vec![unsupported(&why.to_string())],
611                    rucc_object::Error::Refused { .. } => vec![internal(&why.to_string())],
612                },
613            )
614        }
615        _ => Ok(Artifact::Text(rucc_mir::print(&funcs, names, target.regs))),
616    }
617}
618
619/// What the assembler said, as the kind of news it is.
620///
621/// One of these is about a program and the rest are about this compiler. A thread-local variable
622/// is valid C that the back end does not build yet, and everything else the assembler refuses is
623/// something that should never have reached it.
624fn refused(why: rucc_asm::Error) -> Vec<Diagnostic> {
625    match why {
626        rucc_asm::Error::Thread { .. } => vec![unsupported(&why.to_string())],
627        _ => vec![internal(&why.to_string())],
628    }
629}
630
631/// A diagnostic about a program this compiler is not finished enough to compile.
632///
633/// Not an internal error, because nothing here is wrong: the program is valid C and the part of
634/// the back end that would handle it has not been written. The note says so, so that a report
635/// about one of these is filed against the milestone rather than as a miscompilation.
636fn unsupported(message: &str) -> Diagnostic {
637    unsupported_at(message, Span::DUMMY)
638}
639
640/// The same, about somewhere in the file rather than about the file.
641///
642/// The note names the issue tracker rather than `spec/17-milestones.md`, which is a document
643/// about the plan: a reader who follows it wants to know whether the construct in front of them
644/// is already written down as work, and the milestone list does not answer that.
645fn unsupported_at(message: &str, span: Span) -> Diagnostic {
646    Diagnostic::error(message.to_owned(), span)
647        .with_code("E0653")
648        .note("this construct is not lowered yet, see https://github.com/tamnd/rucc/issues", span)
649}
650
651/// A diagnostic about IR that was handed to us rather than built by us.
652fn invalid(message: &str) -> Diagnostic {
653    Diagnostic::error(message.to_owned(), Span::DUMMY).with_code("E0661")
654}
655
656/// A diagnostic about this compiler rather than about the program it was given.
657fn internal(message: &str) -> Diagnostic {
658    Diagnostic::error(format!("internal error: {message}"), Span::DUMMY)
659        .with_code("E0652")
660        .note("this is a bug in rucc rather than in the program, please report it", Span::DUMMY)
661}
662
663/// A result that is nothing but one message, for the failures that happen before there is
664/// anything to compile.
665fn failure(message: String) -> Compiled {
666    Compiled {
667        artifact: Artifact::Nothing,
668        messages: vec![format!("rucc: error: {message}")],
669        errors: 1,
670        fired: Fired::new(),
671        dumps: Vec::new(),
672        remarks: String::new(),
673    }
674}
675
676#[cfg(test)]
677mod tests {
678    use rucc_session::{MemoryFileSystem, Std};
679    use rucc_target::Triple;
680
681    use super::*;
682
683    fn options() -> Options {
684        let mut opts = Options::new("x86_64-unknown-linux-gnu".parse::<Triple>().unwrap());
685        opts.emit = EmitKind::Tast;
686        opts
687    }
688
689    fn run(opts: &Options, source: &str) -> Compiled {
690        let mut fs = MemoryFileSystem::new();
691        fs.insert("/main.c", source.to_owned().into_bytes());
692        compile(opts, "/main.c", &fs)
693    }
694
695    /// Options with the compiler's own headers on the search path and nothing else, which is
696    /// what a freestanding compilation is. There is no file system underneath these tests,
697    /// so a header that reached for one would fail to resolve and say so.
698    fn freestanding() -> Options {
699        let mut opts = options();
700        opts.hosted = false;
701        opts.search.push_system(rucc_session::runtime::DIR);
702        opts
703    }
704
705    /// The typed tree of a freestanding `source`, insisting that it compiled cleanly.
706    fn shipped(source: &str) -> String {
707        let result = run(&freestanding(), source);
708        assert_eq!(result.messages, Vec::<String>::new(), "expected this to compile:\n{source}");
709        result.text().to_owned()
710    }
711
712    /// The typed tree of `source`, insisting that it compiled cleanly.
713    fn tast(source: &str) -> String {
714        let result = run(&options(), source);
715        assert_eq!(result.messages, Vec::<String>::new(), "expected this to compile:\n{source}");
716        result.text().to_owned()
717    }
718
719    #[test]
720    fn the_shipped_stdarg_declares_a_list_and_the_four_operators() {
721        let text = shipped(concat!(
722            "#include <stdarg.h>\n",
723            "int sum(int n, ...) {\n",
724            "  va_list ap, copy;\n",
725            "  va_start(ap, n);\n",
726            "  va_copy(copy, ap);\n",
727            "  int total = va_arg(ap, int) + va_arg(copy, int);\n",
728            "  va_end(ap);\n",
729            "  va_end(copy);\n",
730            "  return total;\n",
731            "}\n",
732        ));
733        assert!(text.contains("va-start"), "{text}");
734        assert!(text.contains("va-copy"), "{text}");
735        assert!(text.contains("va-arg"), "{text}");
736        assert!(text.contains("va-end"), "{text}");
737    }
738
739    /// glibc includes `<stdarg.h>` this way from every header that declares a `vprintf`, and
740    /// what it wants is the type without the four macro names. Answering the whole header
741    /// would put `va_start` in the way of a program that has its own.
742    #[test]
743    fn stdarg_hands_out_the_type_alone_when_that_is_all_that_was_asked_for() {
744        let text = shipped(concat!(
745            "#define __need___va_list\n",
746            "#include <stdarg.h>\n",
747            "int vprint(const char *f, __gnuc_va_list ap);\n",
748            "#ifdef va_start\n",
749            "#error va_start should not be defined\n",
750            "#endif\n",
751            "#ifdef _VA_LIST_DEFINED\n",
752            "#error va_list should not have been made\n",
753            "#endif\n",
754        ));
755        assert!(text.contains("vprint"), "{text}");
756    }
757
758    /// The same protocol on `<stddef.h>`, which glibc uses far more heavily: `<stdio.h>` asks
759    /// for `size_t` and `NULL` and would be wrong to receive `offsetof` as well.
760    #[test]
761    fn stddef_answers_one_piece_at_a_time_and_the_next_request_still_gets_through() {
762        let text = shipped(concat!(
763            "#define __need_size_t\n",
764            "#include <stddef.h>\n",
765            "#ifdef offsetof\n",
766            "#error offsetof should not be defined yet\n",
767            "#endif\n",
768            "#define __need_ptrdiff_t\n",
769            "#include <stddef.h>\n",
770            "#include <stddef.h>\n",
771            "size_t a;\n",
772            "ptrdiff_t b;\n",
773            "wchar_t c;\n",
774            "max_align_t d;\n",
775            "void *e = NULL;\n",
776            "struct P { int x; long y; };\n",
777            "size_t f = offsetof(struct P, y);\n",
778        ));
779        assert!(text.contains("decl #0 a : unsigned long"), "{text}");
780        assert!(text.contains("decl #1 b : long"), "{text}");
781    }
782
783    #[test]
784    fn the_shipped_limits_and_float_are_the_targets_own_answers() {
785        let text = shipped(concat!(
786            "#include <limits.h>\n",
787            "#include <float.h>\n",
788            "int bits = CHAR_BIT;\n",
789            "long big = LONG_MAX;\n",
790            "int low = INT_MIN;\n",
791            "int radix = FLT_RADIX;\n",
792            "int digits = DBL_MANT_DIG;\n",
793        ));
794        assert!(text.contains("const 8 : int"), "{text}");
795        assert!(text.contains("const 9223372036854775807 : long"), "{text}");
796        assert!(text.contains("const 2 : int"), "{text}");
797        assert!(text.contains("const 53 : int"), "{text}");
798    }
799
800    /// Freestanding, so there is no library header to chain to and `<stdint.h>` writes the
801    /// whole set out itself. The widths are the ones the target picked, which is the only
802    /// reason this header is the compiler's.
803    #[test]
804    fn the_shipped_stdint_writes_the_whole_set_when_there_is_no_library_to_defer_to() {
805        let text = shipped(concat!(
806            "#include <stdint.h>\n",
807            "int64_t a = INT64_C(1);\n",
808            "uint_least16_t b;\n",
809            "intptr_t c;\n",
810            "uintmax_t d = UINTMAX_MAX;\n",
811            "int wide = sizeof(int_fast64_t);\n",
812        ));
813        assert!(text.contains("decl #0 a : long"), "{text}");
814        assert!(text.contains("decl #1 b : unsigned short"), "{text}");
815        assert!(text.contains("decl #2 c : long"), "{text}");
816    }
817
818    #[test]
819    fn the_three_formality_headers_still_have_to_work() {
820        let text = shipped(concat!(
821            "#include <stdbool.h>\n",
822            "#include <stdalign.h>\n",
823            "#include <iso646.h>\n",
824            "#include <stdnoreturn.h>\n",
825            "int t = true and not false;\n",
826            "_Alignas(16) char buf[16];\n",
827            "int a = alignof(long);\n",
828        ));
829        assert!(text.contains("decl #0 t : int"), "{text}");
830        assert!(text.contains("const 8 : unsigned long"), "{text}");
831    }
832
833    /// Including everything twice has to change nothing, because that is what happens in any
834    /// program large enough to matter and a guard that is wrong shows up nowhere else.
835    #[test]
836    fn every_shipped_header_can_be_included_twice() {
837        let mut source = String::new();
838        for _ in 0..2 {
839            for name in rucc_session::runtime::names() {
840                source.push_str(&format!("#include <{name}>\n"));
841            }
842        }
843        source.push_str("int x;\n");
844        let text = shipped(&source);
845        assert!(text.starts_with("decl #0 x : int"), "{text}");
846    }
847
848    #[test]
849    fn a_file_that_is_not_there_says_so_and_produces_nothing() {
850        let fs = MemoryFileSystem::new();
851        let result = compile(&options(), "/nope.c", &fs);
852        assert!(result.failed());
853        assert!(result.messages[0].contains("/nope.c"), "{:?}", result.messages);
854        assert!(result.text().is_empty());
855    }
856
857    #[test]
858    fn an_object_comes_out_with_its_type_its_linkage_and_how_much_of_a_definition_it_is() {
859        let text = tast("int x = 1;\n");
860        let expected = "\
861decl #0 x : int object external static defined
862  init
863    +0
864      const 1 : int
865";
866        assert_eq!(text, expected);
867    }
868
869    #[test]
870    fn the_macros_are_expanded_before_anything_is_parsed() {
871        // The whole pipeline in one line. The bound came out of a macro, so it was expanded,
872        // converted from a preprocessing number to a constant of a type, parsed as an
873        // expression, and folded to the number the array type carries.
874        let text = tast("#define N 2\nint a[N];\n");
875        assert!(text.starts_with("decl #0 a : int[2] object external static tentative"), "{text}");
876    }
877
878    /// A pragma survives the preprocessor on purpose, since what one means is not its
879    /// business, and nothing after it has a place for a `#` in the grammar. `pack` is the one
880    /// the parser reads and every other line is walked past. Both spellings are here because
881    /// they arrive by different routes and only one of them was ever on a line of its own in
882    /// the source.
883    #[test]
884    fn a_pragma_is_not_a_declaration_and_the_parse_walks_past_the_ones_it_does_not_read() {
885        let text = tast(concat!(
886            "#pragma pack(4)\n",
887            "struct s { int a; };\n",
888            "#pragma pack()\n",
889            "int b;\n",
890            "_Pragma(\"GCC visibility push(default)\") int c;\n",
891        ));
892        assert!(text.contains("decl #0 b : int"), "{text}");
893        assert!(text.contains("decl #1 c : int"), "{text}");
894    }
895
896    /// Every number in these two tests was read off gcc 16 on x86-64 under `-std=gnu23`
897    /// rather than reasoned about, which is why they are written as assertions the program
898    /// makes about itself: a compilation with no messages is every one of them holding.
899    ///
900    /// This half is the attributes. `packed` takes the padding out, on the record or on one
901    /// member, `aligned` raises and never lowers, and the two written together are the
902    /// combination that packs and then aligns the whole thing.
903    #[test]
904    fn the_layout_attributes_move_the_members_and_the_record_the_way_gcc_lays_them_out() {
905        tast(concat!(
906            "struct A { char c; int i; } __attribute__((packed));\n",
907            "_Static_assert(sizeof(struct A) == 5 && _Alignof(struct A) == 1, \"A\");\n",
908            "_Static_assert(__builtin_offsetof(struct A, i) == 1, \"A.i\");\n",
909            // `aligned` with nothing in the parentheses is the largest alignment the target
910            // has, which gcc calls BIGGEST_ALIGNMENT and which is sixteen everywhere here.
911            "struct B { char c; int i; } __attribute__((aligned));\n",
912            "_Static_assert(sizeof(struct B) == 16 && _Alignof(struct B) == 16, \"B\");\n",
913            "struct C { char c; int i __attribute__((packed)); };\n",
914            "_Static_assert(sizeof(struct C) == 5 && _Alignof(struct C) == 1, \"C\");\n",
915            "_Static_assert(__builtin_offsetof(struct C, i) == 1, \"C.i\");\n",
916            "struct D { char c; int i; } __attribute__((packed, aligned(4)));\n",
917            "_Static_assert(sizeof(struct D) == 8 && _Alignof(struct D) == 4, \"D\");\n",
918            "_Static_assert(__builtin_offsetof(struct D, i) == 1, \"D.i\");\n",
919            "struct E { char c; _Alignas(8) int i; };\n",
920            "_Static_assert(sizeof(struct E) == 16 && _Alignof(struct E) == 8, \"E\");\n",
921            "_Static_assert(__builtin_offsetof(struct E, i) == 8, \"E.i\");\n",
922            "struct F { char c; int i __attribute__((aligned(8))); };\n",
923            "_Static_assert(sizeof(struct F) == 16 && _Alignof(struct F) == 8, \"F\");\n",
924            // Two the record already had, so the attribute asks for nothing new, and two
925            // where four was already there, so the attribute is ignored rather than obeyed.
926            "struct G { char c; short s; } __attribute__((aligned(2)));\n",
927            "_Static_assert(sizeof(struct G) == 4 && _Alignof(struct G) == 2, \"G\");\n",
928            "struct H { char c; int i; } __attribute__((aligned(2)));\n",
929            "_Static_assert(sizeof(struct H) == 8 && _Alignof(struct H) == 4, \"H\");\n",
930            // `packed` on a member takes the padding out in front of that member alone, so on
931            // the first one it does nothing and on the second one it does all of it.
932            "struct I { [[gnu::packed]] char c; int i; };\n",
933            "_Static_assert(sizeof(struct I) == 8 && _Alignof(struct I) == 4, \"I\");\n",
934            "struct J { char c; [[gnu::packed]] int i; };\n",
935            "_Static_assert(sizeof(struct J) == 5 && _Alignof(struct J) == 1, \"J\");\n",
936            "struct M { char c; int i : 5; int j : 20; } __attribute__((packed));\n",
937            "_Static_assert(sizeof(struct M) == 5 && _Alignof(struct M) == 1, \"M\");\n",
938            "struct N { char c; long long l; } __attribute__((aligned(32)));\n",
939            "_Static_assert(sizeof(struct N) == 32 && _Alignof(struct N) == 32, \"N\");\n",
940            "union L { char c; int i; } __attribute__((packed));\n",
941            "_Static_assert(sizeof(union L) == 4 && _Alignof(union L) == 1, \"L\");\n",
942            // The armoured spellings, which are the ones a system header writes, since a
943            // program is entitled to a macro called `packed` and is not entitled to one called
944            // `__packed__`. The two names are one attribute and the layout is the same one.
945            "struct O { char c; int i; } __attribute__((__packed__));\n",
946            "_Static_assert(sizeof(struct O) == 5 && _Alignof(struct O) == 1, \"O\");\n",
947            "struct P { char c; int i; } __attribute__((__aligned__(8)));\n",
948            "_Static_assert(sizeof(struct P) == 8 && _Alignof(struct P) == 8, \"P\");\n",
949        ));
950    }
951
952    /// The same attribute on a declaration rather than on a type, which asks that this object or
953    /// this function be at a multiple of that, and which is where a program that has to hand a
954    /// buffer to hardware or keep two counters off one cache line writes it.
955    ///
956    /// A raise and never a lower, which is the one place it does not agree with `_Alignas`: below
957    /// what the type already has, `_Alignas` is a constraint violation and this is ignored without
958    /// a word. `__alignof__` of the object answers what the object got and not what its type has,
959    /// because that is the question a program asking it is asking.
960    #[test]
961    fn the_aligned_attribute_on_a_declaration_raises_what_that_one_object_is_aligned_to() {
962        tast(concat!(
963            "int v __attribute__((aligned(64)));\n",
964            "_Static_assert(__alignof__(v) == 64, \"v\");\n",
965            // Written on the specifiers rather than after the declarator, which asks the same
966            // thing and is the spelling a header is more likely to use.
967            "__attribute__((aligned(32))) int w;\n",
968            "_Static_assert(__alignof__(w) == 32, \"w\");\n",
969            "[[gnu::aligned(16)]] int x;\n",
970            "_Static_assert(__alignof__(x) == 16, \"x\");\n",
971            // Two below the four an `int` already has, so nothing is asked for and nothing is
972            // said, and the type still answers for the object.
973            "int y __attribute__((aligned(2)));\n",
974            "_Static_assert(__alignof__(y) == 4, \"y\");\n",
975            // A local, which is the same question one scope down.
976            "void f(void) { int a __attribute__((aligned(128)));\n",
977            "_Static_assert(__alignof__(a) == 128, \"a\"); (void)a; }\n",
978            // The type is untouched by any of it: `aligned` on a declaration says where that
979            // declaration goes and says nothing about every other `int` in the program.
980            "_Static_assert(__alignof__(int) == 4, \"int\");\n",
981            // A function, which has no alignment of its own for this to be measured against and
982            // takes whatever was asked for.
983            "void g(void) __attribute__((aligned(256)));\n",
984            "void g(void) {}\n",
985            "_Static_assert(__alignof__(g) == 256, \"g\");\n",
986        ));
987    }
988
989    /// And what the object file says, which is the half that makes the answer above true. A
990    /// function is at a fixed offset inside the text section, so it is at a multiple of two
991    /// hundred and fifty six only if the section is at one too.
992    #[test]
993    fn what_a_declaration_asked_to_be_aligned_to_is_what_the_assembler_is_told() {
994        let text = asm(concat!(
995            "int v __attribute__((aligned(64)));\n",
996            "void g(void) __attribute__((aligned(256)));\n",
997            "void g(void) {}\n",
998            "void plain(void) {}\n",
999        ));
1000        assert!(text.contains("\t.p2align\t6\n\t.type\tv, @object\n"), "{text}");
1001        assert!(text.contains("\t.p2align\t8, 0x90\n\t.globl\tg\n"), "{text}");
1002        assert!(text.contains("\t.p2align\t4, 0x90\n\t.globl\tplain\n"), "{text}");
1003    }
1004
1005    /// And the one position where the attribute means something else. On a declaration it raises
1006    /// what that one object is aligned to, and on a typedef it says what the type is aligned to,
1007    /// which gcc lets it lower as well: `typedef int L __attribute__((aligned(2)))` really is an
1008    /// `int` at a multiple of two and a record with one in it really is smaller for it.
1009    ///
1010    /// The size is left alone, which is gcc's answer rather than an omission here. An aligned
1011    /// typedef whose alignment is larger than what it stands for keeps the size it stands for,
1012    /// and gcc refuses an array of one rather than padding the elements out to fit.
1013    #[test]
1014    fn an_aligned_typedef_says_what_an_object_of_it_is_aligned_to_and_may_lower_it() {
1015        tast(concat!(
1016            "typedef int L __attribute__((aligned(2)));\n",
1017            "_Static_assert(__alignof__(L) == 2, \"L\");\n",
1018            "_Static_assert(_Alignof(L) == 2, \"L alignof\");\n",
1019            // Below what an `int` has, which is the half a declaration cannot ask for.
1020            "_Static_assert(sizeof(L) == 4, \"L size\");\n",
1021            "struct T { char c; L x; };\n",
1022            "_Static_assert(sizeof(struct T) == 6, \"T\");\n",
1023            "_Static_assert(__builtin_offsetof(struct T, x) == 2, \"T.x\");\n",
1024            // And upwards, which is the ordinary direction and the one a header writes.
1025            "typedef int H __attribute__((aligned(16)));\n",
1026            "_Static_assert(__alignof__(H) == 16, \"H\");\n",
1027            "_Static_assert(sizeof(H) == 4, \"H size\");\n",
1028            "struct U { char c; H x; };\n",
1029            "_Static_assert(sizeof(struct U) == 32, \"U\");\n",
1030            "_Static_assert(__builtin_offsetof(struct U, x) == 16, \"U.x\");\n",
1031            // A typedef of a typedef, where the nearer one is the one the declaration was
1032            // written with and is the one that answers.
1033            "typedef L M __attribute__((aligned(8)));\n",
1034            "_Static_assert(__alignof__(M) == 8, \"M\");\n",
1035            // And one that asked for nothing, which still has whatever the one behind it asked
1036            // for because it is the same type spelled again.
1037            "typedef L N;\n",
1038            "_Static_assert(__alignof__(N) == 2, \"N\");\n",
1039            // The type it stands for is untouched by any of it.
1040            "_Static_assert(__alignof__(int) == 4, \"int\");\n",
1041        ));
1042        let text = asm(concat!(
1043            "typedef int L __attribute__((aligned(2)));\n",
1044            "typedef int H __attribute__((aligned(16)));\n",
1045            "L low;\n",
1046            "H high;\n",
1047        ));
1048        assert!(text.contains("\t.p2align\t1\n\t.type\tlow, @object\n"), "{text}");
1049        assert!(text.contains("\t.p2align\t4\n\t.type\thigh, @object\n"), "{text}");
1050    }
1051
1052    /// The attribute that builds a type rather than changing a layout. `vector_size(n)` says the
1053    /// declared type is `n` bytes of what was written, taken as lanes, and every operator over
1054    /// one is that operator over each lane.
1055    ///
1056    /// The size is in bytes and not in lanes, which is the part a reader gets backwards: sixteen
1057    /// of `int` is four lanes and sixteen of `char` is sixteen. A vector is aligned to its own
1058    /// size, which is what a machine that has the registers wants and what gcc gives one here.
1059    #[test]
1060    fn the_vector_size_attribute_builds_a_type_of_lanes_and_measures_it_in_bytes() {
1061        tast(concat!(
1062            "typedef int __attribute__((vector_size(16))) v4si;\n",
1063            "_Static_assert(sizeof(v4si) == 16 && _Alignof(v4si) == 16, \"v4si\");\n",
1064            "typedef char __attribute__((vector_size(16))) v16qi;\n",
1065            "_Static_assert(sizeof(v16qi) == 16, \"v16qi\");\n",
1066            // One lane, which is a power of two and is a vector rather than the type it was
1067            // written on: the operators it takes are the vector's and not the scalar's.
1068            "typedef int __attribute__((vector_size(4))) v1si;\n",
1069            "_Static_assert(sizeof(v1si) == 4, \"v1si\");\n",
1070            // The armoured spelling and the bracket one, which are the same attribute.
1071            "typedef float __attribute__((__vector_size__(8))) v2sf;\n",
1072            "_Static_assert(sizeof(v2sf) == 8, \"v2sf\");\n",
1073            "typedef short [[gnu::vector_size(8)]] v4hi;\n",
1074            "_Static_assert(sizeof(v4hi) == 8, \"v4hi\");\n",
1075            // A lane is what a subscript answers with, and a vector is not a pointer: there is
1076            // nothing to decay and the lane type is the one the arithmetic happens in.
1077            "v4si g;\n",
1078            "_Static_assert(sizeof(g[0]) == 4, \"lane\");\n",
1079            "_Static_assert(sizeof(g + g) == 16, \"whole\");\n",
1080            // A scalar beside a vector stands for itself in every lane, so the answer is still
1081            // the vector and not the wider of the two types.
1082            "_Static_assert(sizeof(g + 1) == 16, \"broadcast\");\n",
1083            // An array of them, which is the ordinary way a program holds several.
1084            "_Static_assert(sizeof(v4si[3]) == 48, \"array\");\n",
1085        ));
1086    }
1087
1088    /// A whole vector written into an array of them, and a vector named by a type name rather
1089    /// than by a typedef.
1090    ///
1091    /// Both are the same question asked twice. A vector is filled like an array of its lanes when
1092    /// a list is written into it, so a braced element that is itself a vector has to be taken
1093    /// whole rather than started as the first lane, and the type of what was written is the only
1094    /// thing that says which was meant. And a type name is where a compound literal and a cast
1095    /// spell the type out, which a macro taking a lane type and a lane count does, so the
1096    /// attribute has to be read there and not only on a declaration.
1097    #[test]
1098    fn a_vector_is_written_whole_into_an_array_of_them_and_named_by_a_type_name() {
1099        tast(concat!(
1100            "typedef int __attribute__((vector_size(8))) v2si;\n",
1101            "v2si table[] = { (v2si){ 1, 2 }, (v2si){ 3, 4 } };\n",
1102            "_Static_assert(sizeof(table) == 16, \"two of them and not eight lanes\");\n",
1103            // The size written out rather than named, which is the spelling a macro expands to.
1104            "v2si written = (int __attribute__((vector_size(8)))){ 5, 6 };\n",
1105            "_Static_assert(sizeof((int __attribute__((vector_size(16)))){ 0 }) == 16, \"named\");\n",
1106            // A lane is still a lane, so a list of them fills the vector the way it always did
1107            // and the rule above did not turn brace elision off.
1108            "v2si lanes[2] = { 1, 2, 3, 4 };\n",
1109            "_Static_assert(sizeof(lanes) == 16, \"still elided\");\n",
1110        ));
1111    }
1112
1113    /// A lane written rather than read, and a shift whose two vectors are not the same type.
1114    ///
1115    /// Both are places where a vector is not the aggregate it looks like. A subscript of one is
1116    /// an lvalue because the vector it came from is an object, so a lane can be assigned to and
1117    /// has an address, and a qualifier written on the vector reaches every lane the way it does
1118    /// on an array. And a shift is the one lanewise operator whose sides are not brought to a
1119    /// single type, since the right side counts rather than computes.
1120    #[test]
1121    fn a_lane_is_assignable_and_a_shift_takes_a_count_of_its_own_lane() {
1122        let result = run(
1123            &options(),
1124            concat!(
1125                "typedef int __attribute__((vector_size(16))) v4si;\n",
1126                "typedef unsigned __attribute__((vector_size(16))) v4ui;\n",
1127                "void write(v4si *out, v4ui a, v4si b, int n) {\n",
1128                "  v4si v = { 1, 2, 3, 4 };\n",
1129                "  v[0] = n;\n",
1130                "  v[1] += n;\n",
1131                "  v[2]++;\n",
1132                "  *&v[3] = n;\n",
1133                // The count is signed and the value is not, which no other operator allows.
1134                "  v4ui shifted = a >> b;\n",
1135                "  shifted <<= b;\n",
1136                // A scalar stands in every lane on either side of a shift, which is the half
1137                // that looks wrong: the shape of the answer comes off the count here.
1138                "  *out = v + (v4si)shifted + (1 << b);\n",
1139                "}\n",
1140                // A qualifier on the vector is a qualifier on the lane, so there is nothing here
1141                // to write to.
1142                "void refused(const v4si c) {\n",
1143                "  c[0] = 1;\n",
1144                "}\n",
1145            ),
1146        );
1147        assert_eq!(result.messages.len(), 1, "{:?}", result.messages);
1148        assert!(result.messages[0].contains("assignment of read-only"), "{:?}", result.messages);
1149    }
1150
1151    /// The third layout attribute, and the one that is refused rather than read. Reversing the
1152    /// byte order of every scalar in a record is not something a compiler can do half of, and a
1153    /// compilation that ignored it would lay the record out in the host's order and hand back
1154    /// every field with its bytes the wrong way round. Both spellings are here because a header
1155    /// writes the armoured one, and the member is here because the refusal has to arrive before
1156    /// the layout is used rather than after.
1157    #[test]
1158    fn a_record_that_asks_for_the_other_byte_order_is_refused_rather_than_laid_out_in_this_one() {
1159        let opts = options();
1160        let big = "struct s { int i; } __attribute__((scalar_storage_order(\"big-endian\")));\n";
1161        assert_eq!(
1162            run(&opts, big).messages,
1163            ["/main.c:1:36: error: 'scalar_storage_order' is not implemented yet [E0688]\n\
1164              /main.c:1:36: note: every scalar in this record would be read in the wrong byte \
1165              order"]
1166        );
1167
1168        let armoured =
1169            "struct s { int i; } __attribute__((__scalar_storage_order__(\"little-endian\")));\n";
1170        let messages = run(&opts, armoured).messages;
1171        assert!(messages[0].contains("[E0688]"), "{messages:?}");
1172
1173        // The attribute in front of the body reaches the same list as the one behind it, and
1174        // the C23 spelling in gcc's namespace is the same attribute written a third way.
1175        let front = "struct __attribute__((scalar_storage_order(\"big-endian\"))) s { int i; };\n";
1176        assert!(run(&opts, front).messages[0].contains("[E0688]"), "{front}");
1177        let standard = "struct s { int i; } [[gnu::scalar_storage_order(\"big-endian\")]];\n";
1178        assert!(run(&opts, standard).messages[0].contains("[E0688]"), "{standard}");
1179    }
1180
1181    /// Where a bit-field goes, which packing decides and which is the part of all this that
1182    /// is not what the names suggest. A bit-field goes at the next free bit unless that would
1183    /// make it span more storage than its own type occupies, and then it moves to the next
1184    /// boundary of its alignment. Any packing at all takes that rule out, and `#pragma pack`
1185    /// counts even where it lowers nothing, which is the fourth and seventh cases here.
1186    ///
1187    /// Nothing in the language can be asked where a bit-field is, since `offsetof` refuses one
1188    /// and every size below comes out the same either way, so what is asked is the byte a read
1189    /// of the field loads from.
1190    #[test]
1191    fn packing_is_what_decides_whether_a_bit_field_may_straddle_its_own_storage() {
1192        // A `char` field after twelve bits, which will not straddle unpacked and does packed.
1193        assert_eq!(bit_field_byte("struct s { int x : 12; char y : 6; };"), 2);
1194        assert_eq!(
1195            bit_field_byte("struct s { int x : 12; char y : 6; } __attribute__((packed));"),
1196            1
1197        );
1198        assert_eq!(
1199            bit_field_byte("struct s { int x : 12; __attribute__((packed)) char y : 6; };"),
1200            1
1201        );
1202        assert_eq!(bit_field_byte("#pragma pack(4)\nstruct s { int x : 12; char y : 6; };"), 1);
1203        // A thirty bit field after a byte, which is the case the rule was written for.
1204        assert_eq!(bit_field_byte("struct s { char x; int y : 30; };"), 4);
1205        assert_eq!(bit_field_byte("struct s { char x; int y : 30; } __attribute__((packed));"), 1);
1206        // Four is what an `int` asked for anyway, so this caps nothing and still counts.
1207        assert_eq!(bit_field_byte("#pragma pack(4)\nstruct s { char x; int y : 30; };"), 1);
1208        assert_eq!(bit_field_byte("#pragma pack(2)\nstruct s { char x; int y : 30; };"), 1);
1209    }
1210
1211    /// The byte a read of `s.y` loads from, which is where the bit-field was placed.
1212    fn bit_field_byte(record: &str) -> u64 {
1213        let source = format!("{record}\nint f(struct s *p) {{ return p->y; }}\n");
1214        let body = body(&source);
1215        let Some((before, _)) = body.split_once("ptr_add") else { return 0 };
1216        let (_, constant) = before.rsplit_once("iconst.i64 ").expect("an offset constant");
1217        constant.lines().next().expect("a line").trim().parse().expect("a byte offset")
1218    }
1219
1220    /// An attribute in the middle of a specifier list, which is where a member usually carries
1221    /// one and which was read and then thrown away. The `[[...]]` spelling and whatever was
1222    /// written in front of the declaration are collected as the list is walked and the
1223    /// `__attribute__` spelling is put straight on the specifiers, and the two were assigned
1224    /// over each other rather than joined.
1225    #[test]
1226    fn an_attribute_among_the_specifiers_is_kept_beside_the_ones_written_in_front() {
1227        tast(concat!(
1228            "struct a { char c; __attribute__((aligned(8))) int i; };\n",
1229            "_Static_assert(sizeof(struct a) == 16 && _Alignof(struct a) == 8, \"a\");\n",
1230            "_Static_assert(__builtin_offsetof(struct a, i) == 8, \"a.i\");\n",
1231            "struct b { char c; __attribute__((packed)) int i; };\n",
1232            "_Static_assert(sizeof(struct b) == 5 && _Alignof(struct b) == 1, \"b\");\n",
1233            "_Static_assert(__builtin_offsetof(struct b, i) == 1, \"b.i\");\n",
1234            "typedef struct { char c; int i; } __attribute__((packed)) c;\n",
1235            "_Static_assert(sizeof(c) == 5 && _Alignof(c) == 1, \"c\");\n",
1236        ));
1237    }
1238
1239    /// The other half, which is `#pragma pack`. It caps a member's alignment where `packed`
1240    /// drops it, so `pack(2)` leaves a `short` where it was and moves an `int`, and it caps a
1241    /// member the program asked to align as well, which is where the two differ. It is read
1242    /// at the closing brace of the body, so a line written in the middle of one settles the
1243    /// whole record rather than the members after it, and `push` and `pop` nest.
1244    #[test]
1245    fn pragma_pack_caps_every_member_and_is_read_where_the_body_closes() {
1246        tast(concat!(
1247            "#pragma pack(1)\n",
1248            "struct A { char c; int i; };\n",
1249            "_Static_assert(sizeof(struct A) == 5 && _Alignof(struct A) == 1, \"A\");\n",
1250            "_Static_assert(__builtin_offsetof(struct A, i) == 1, \"A.i\");\n",
1251            "#pragma pack()\n",
1252            "struct B { char c; int i; };\n",
1253            "_Static_assert(sizeof(struct B) == 8 && _Alignof(struct B) == 4, \"B\");\n",
1254            "#pragma pack(2)\n",
1255            "struct C { char c; int i; double d; };\n",
1256            "_Static_assert(sizeof(struct C) == 14 && _Alignof(struct C) == 2, \"C\");\n",
1257            "_Static_assert(__builtin_offsetof(struct C, d) == 6, \"C.d\");\n",
1258            // A member the program aligned, which `pack` caps and `packed` would not.
1259            "struct K { char c; int i __attribute__((aligned(8))); };\n",
1260            "_Static_assert(sizeof(struct K) == 6 && _Alignof(struct K) == 2, \"K\");\n",
1261            "_Static_assert(__builtin_offsetof(struct K, i) == 2, \"K.i\");\n",
1262            // The record's own `aligned` is not a member's, so it is not capped.
1263            "struct J { char c; int i; } __attribute__((aligned(8)));\n",
1264            "_Static_assert(sizeof(struct J) == 8 && _Alignof(struct J) == 8, \"J\");\n",
1265            "#pragma pack()\n",
1266            "#pragma pack(push, 1)\n",
1267            "struct D { char c; short s; };\n",
1268            "_Static_assert(sizeof(struct D) == 3 && _Alignof(struct D) == 1, \"D\");\n",
1269            "#pragma pack(pop)\n",
1270            "struct E { char c; short s; };\n",
1271            "_Static_assert(sizeof(struct E) == 4 && _Alignof(struct E) == 2, \"E\");\n",
1272            // Written in the middle of a body, and it still settles the whole record.
1273            "struct H { char c;\n",
1274            "#pragma pack(1)\n",
1275            "  int i; };\n",
1276            "_Static_assert(sizeof(struct H) == 5 && _Alignof(struct H) == 1, \"H\");\n",
1277            "#pragma pack(1)\n",
1278            "struct I { char c;\n",
1279            "#pragma pack()\n",
1280            "  int i; };\n",
1281            "_Static_assert(sizeof(struct I) == 8 && _Alignof(struct I) == 4, \"I\");\n",
1282            "#pragma pack()\n",
1283            // Nested pushes, each one giving back what the one under it had.
1284            "#pragma pack(push, 8)\n",
1285            "#pragma pack(push, 1)\n",
1286            "struct P { char c; int i; };\n",
1287            "_Static_assert(sizeof(struct P) == 5 && _Alignof(struct P) == 1, \"P\");\n",
1288            "#pragma pack(pop)\n",
1289            "struct Q { char c; int i; };\n",
1290            "_Static_assert(sizeof(struct Q) == 8 && _Alignof(struct Q) == 4, \"Q\");\n",
1291            "#pragma pack(pop)\n",
1292            // A cap above what every member already asks for changes nothing at all.
1293            "#pragma pack(16)\n",
1294            "struct R { char c; int i; };\n",
1295            "_Static_assert(sizeof(struct R) == 8 && _Alignof(struct R) == 4, \"R\");\n",
1296            "#pragma pack()\n",
1297            "#pragma pack(1)\n",
1298            "struct S { char c; int i : 5; int j : 20; };\n",
1299            "_Static_assert(sizeof(struct S) == 5 && _Alignof(struct S) == 1, \"S\");\n",
1300            "union T { char c; int i; };\n",
1301            "_Static_assert(sizeof(union T) == 4 && _Alignof(union T) == 1, \"T\");\n",
1302            "#pragma pack()\n",
1303        ));
1304    }
1305
1306    /// A line the reader cannot make sense of is a warning and the line is dropped, which is
1307    /// what GCC does with one, and these are its words for each of them. The last line is the
1308    /// one nothing else would reach, since it stands after every record in the file.
1309    #[test]
1310    fn a_pack_line_that_is_not_one_is_reported_in_the_words_gcc_uses() {
1311        let result = run(
1312            &options(),
1313            concat!(
1314                "#pragma pack 4\n",
1315                "#pragma pack(pop)\n",
1316                "#pragma pack(3)\n",
1317                "#pragma pack(1) junk\n",
1318                "#pragma pack(push, 1\n",
1319                "#pragma pack(x)\n",
1320                // These two are well formed and say nothing. Zero is how a line asks for the
1321                // target's own alignments back without writing empty parentheses.
1322                "#pragma pack(0)\n",
1323                "#pragma pack(push)\n",
1324                "struct s { char c; int i; };\n",
1325                "#pragma pack(pop)\n",
1326                "#pragma pack(pop, foo)\n",
1327            ),
1328        );
1329        let expected = [
1330            "missing `(` after `#pragma pack` - ignored",
1331            "`#pragma pack (pop)` encountered without matching `#pragma pack (push)`",
1332            "alignment must be a small power of two, not 3",
1333            "junk at end of `#pragma pack`",
1334            "malformed `#pragma pack(push[, id][, <n>])` - ignored",
1335            "unknown action `x` for `#pragma pack` - ignored",
1336            "`#pragma pack(pop, foo)` encountered without matching `#pragma pack(push, foo)`",
1337        ];
1338        assert_eq!(result.messages.len(), expected.len(), "{:?}", result.messages);
1339        for (message, want) in result.messages.iter().zip(expected) {
1340            assert!(message.contains(want), "expected {want:?} in {message:?}");
1341        }
1342    }
1343
1344    /// The two typedef spellings of the 128 bit types. gcc offers them as keywords rather
1345    /// than as typedefs in a header, which is the only way a program that includes nothing at
1346    /// all can still use them, and Apple's `<mach/arm/_structs.h>` is one such program.
1347    #[test]
1348    fn the_wide_integer_answers_to_all_three_of_its_names() {
1349        let text = tast("__uint128_t a; __int128_t b; unsigned __int128 c;\n");
1350        assert!(text.contains("decl #0 a : unsigned __int128"), "{text}");
1351        assert!(text.contains("decl #1 b : __int128"), "{text}");
1352        assert!(text.contains("decl #2 c : unsigned __int128"), "{text}");
1353    }
1354
1355    #[test]
1356    fn every_conversion_the_language_performs_is_a_node_in_the_output() {
1357        // The point of a typed tree. The source has one operator and the output has the
1358        // widening that operator asked for, spelled out, so that nothing downstream has to
1359        // work out the conversion rules a second time.
1360        let text = tast("long f(int a, long b) { return a + b; }\n");
1361        assert!(text.contains("convert arithmetic"), "{text}");
1362    }
1363
1364    #[test]
1365    fn a_mistake_in_each_phase_reaches_the_caller_and_writes_no_tree() {
1366        for source in [
1367            "#error stop\n",
1368            "int f(void) { return 1 + ; }\n",
1369            "int f(void) { return undeclared; }\n",
1370        ] {
1371            let result = run(&options(), source);
1372            assert!(result.failed(), "expected this to fail:\n{source}");
1373            assert!(
1374                result.text().is_empty(),
1375                "a file that did not compile wrote a tree:\n{source}"
1376            );
1377        }
1378    }
1379
1380    #[test]
1381    fn one_undeclared_name_is_one_message_and_not_one_per_use() {
1382        // The poisoning rule from `spec/06-lexer-and-parser.md` section 6.8, seen from the
1383        // outside. Three uses of a name that was never declared, and the operators over them
1384        // say nothing at all.
1385        let result = run(&options(), "int f(void) { return nope + nope * nope; }\n");
1386        assert_eq!(result.errors, 1, "{:?}", result.messages);
1387    }
1388
1389    #[test]
1390    fn a_declaration_the_parser_skipped_does_not_become_an_undeclared_name_as_well() {
1391        // The reason the checking is skipped after a failed parse. The parser gave up on the
1392        // first line and there is no `x` in the tree, so a checker run over it would report
1393        // every use of `x` below as undeclared, which is a second message about one mistake.
1394        let result = run(&options(), "int x = ;\nint f(void) { return x; }\n");
1395        assert_eq!(result.errors, 1, "{:?}", result.messages);
1396    }
1397
1398    #[test]
1399    fn werror_turns_a_warning_into_an_error_in_the_count_and_in_the_word() {
1400        let source = "int f(void) { char c = 300; return c; }\n";
1401        let plain = run(&options(), source);
1402        assert_eq!(plain.errors, 0, "{:?}", plain.messages);
1403        assert_eq!(plain.messages.len(), 1, "expected a warning about the narrowed constant");
1404        assert!(!plain.text().is_empty(), "a warning is not a reason to write nothing");
1405
1406        let mut opts = options();
1407        opts.warnings_are_errors = true;
1408        let strict = run(&opts, source);
1409        assert!(strict.failed());
1410        assert!(strict.text().is_empty(), "and under -Werror it is a reason to write nothing");
1411        for message in &strict.messages {
1412            assert!(!message.contains("warning:"), "{message}");
1413        }
1414    }
1415
1416    #[test]
1417    fn w_drops_the_warning_before_werror_can_promote_it() {
1418        let source = "int f(void) { char c = 300; return c; }\n";
1419        let mut opts = options();
1420        opts.warnings = false;
1421        let quiet = run(&opts, source);
1422        assert_eq!(quiet.messages, Vec::<String>::new());
1423        assert_eq!(quiet.errors, 0);
1424        assert!(!quiet.text().is_empty(), "and the file still compiles");
1425
1426        // A build that passes both means it wants neither, and the order it wrote them in is not
1427        // something to make it think about.
1428        opts.warnings_are_errors = true;
1429        let both = run(&opts, source);
1430        assert_eq!(both.messages, Vec::<String>::new());
1431        assert!(!both.failed(), "-w -Werror is not an error about a warning nobody saw");
1432    }
1433
1434    #[test]
1435    fn the_dialect_reaches_the_keywords_and_the_checking() {
1436        // `typeof` is C23's and GNU's, so the same source is a declaration under one dialect
1437        // and a mistake under the other, which is the keyword table being built per dialect.
1438        let source = "typeof(1) x;\n";
1439        let mut opts = options();
1440        opts.std = Std::C23;
1441        opts.gnu_extensions = false;
1442        assert!(!run(&opts, source).failed(), "{:?}", run(&opts, source).messages);
1443
1444        opts.std = Std::C17;
1445        assert!(run(&opts, source).failed());
1446    }
1447
1448    #[test]
1449    fn asking_for_a_kind_that_is_not_written_yet_runs_the_front_end_and_writes_nothing() {
1450        let mut opts = options();
1451        opts.emit = EmitKind::Object;
1452        let result = run(&opts, "int x = 1;\n");
1453        assert!(!result.failed(), "{:?}", result.messages);
1454        assert!(result.text().is_empty());
1455        // And it still finds what the checking finds, so a later kind on a broken file is not
1456        // a silent success.
1457        assert!(run(&opts, "int f(void) { return undeclared; }\n").failed());
1458    }
1459
1460    /// The machine code of `source`, insisting that it compiled cleanly.
1461    fn mir(source: &str) -> String {
1462        let mut opts = options();
1463        opts.emit = EmitKind::MirFinal;
1464        let result = run(&opts, source);
1465        assert_eq!(result.messages, Vec::<String>::new(), "expected this to compile:\n{source}");
1466        result.text().to_owned()
1467    }
1468
1469    /// The whole compiler in one assertion, which is what this emit kind is for.
1470    ///
1471    /// C in, machine instructions out, every register a real one and every frame offset a
1472    /// number. Everything between the two is checked somewhere else, one pass at a time. What is
1473    /// checked here is that the passes are joined up and that the driver runs them.
1474    #[test]
1475    fn a_function_goes_from_c_to_instructions_with_real_registers_in_them() {
1476        let text = mir("int add(int a, int b) { return a + b; }\n");
1477        assert!(text.starts_with("mfunc @add {"), "{text}");
1478        assert!(text.contains("x64.add_rr_32"), "{text}");
1479        assert!(text.contains("x64.ret"), "{text}");
1480        // A virtual register is what the allocator was there to remove, so one left in the
1481        // output is the difference between code and something that looks like code.
1482        assert!(!text.contains('%'), "{text}");
1483    }
1484
1485    /// A declaration has no body, so there is nothing to generate for one and nothing is.
1486    #[test]
1487    fn a_function_with_no_body_produces_no_machine_function() {
1488        let text = mir("int g(int);\nint f(int a) { return g(a); }\n");
1489        assert_eq!(text.matches("mfunc @").count(), 1, "{text}");
1490        assert!(text.contains("mfunc @f {"), "{text}");
1491        assert!(text.contains("x64.call"), "{text}");
1492    }
1493
1494    /// Two functions come out in the order the module holds them, which is source order.
1495    #[test]
1496    fn every_definition_in_the_file_is_generated_and_they_keep_their_order() {
1497        let text = mir("int a(int x) { return x; }\nint b(int x) { return x; }\n");
1498        let first = text.find("mfunc @a").expect("the first function");
1499        let second = text.find("mfunc @b").expect("the second function");
1500        assert!(first < second, "{text}");
1501    }
1502
1503    /// The target reaches the back end, so the same C is different instructions on Windows.
1504    #[test]
1505    fn the_target_decides_which_convention_the_generated_code_follows() {
1506        let mut opts = options();
1507        opts.emit = EmitKind::MirFinal;
1508        let linux = run(&opts, "int f(int a) { return a; }\n").text().to_owned();
1509        assert!(linux.contains("$rdi"), "{linux}");
1510
1511        opts.target = "x86_64-pc-windows-msvc".parse::<Triple>().unwrap();
1512        let windows = run(&opts, "int f(int a) { return a; }\n").text().to_owned();
1513        assert!(windows.contains("$rcx"), "{windows}");
1514        assert!(!windows.contains("$rdi"), "{windows}");
1515    }
1516
1517    /// A target with no back end says so rather than generating something for another machine.
1518    #[test]
1519    fn a_target_this_has_no_back_end_for_is_reported_rather_than_generated() {
1520        let mut opts = options();
1521        opts.emit = EmitKind::MirFinal;
1522        opts.target = "aarch64-unknown-linux-gnu".parse::<Triple>().unwrap();
1523        let result = run(&opts, "int f(int a) { return a; }\n");
1524        assert!(result.failed());
1525        assert!(result.messages[0].contains("no back end for aarch64"), "{:?}", result.messages);
1526        assert!(result.text().is_empty());
1527    }
1528
1529    /// A construct the rule set does not reach yet is named, along with the function it is in.
1530    ///
1531    /// The message is about this compiler being unfinished rather than about the program, which
1532    /// is valid C either way, so it carries the note that says where the work is tracked. Both
1533    /// functions are attempted, so a file that is ahead of the back end in three places says so
1534    /// three times rather than one recompilation at a time.
1535    #[test]
1536    fn a_construct_the_back_end_cannot_reach_yet_is_reported_against_its_function() {
1537        let mut opts = options();
1538        opts.emit = EmitKind::MirFinal;
1539        let source = "long double a(long double x) { return x; }\n\
1540                      long double b(long double x) { return x; }\n";
1541        let result = run(&opts, source);
1542        assert!(result.failed());
1543        assert_eq!(result.messages.len(), 2, "{:?}", result.messages);
1544        assert!(result.messages[0].contains("cannot generate code for 'a'"), "{:?}", result);
1545        assert!(result.messages[0].contains("x87 stack"), "{:?}", result);
1546        assert!(result.messages[1].contains("cannot generate code for 'b'"), "{:?}", result);
1547        assert!(result.text().is_empty());
1548    }
1549
1550    /// An opcode the rule language has no word for is named anyway, and pointed at.
1551    ///
1552    /// The rule language's spelling is the better name when there is one, but an opcode it has
1553    /// no word for is exactly the opcode no rule lowers, so falling back to the opcode and the
1554    /// type is what makes the message say anything at all in the cases that happen. The span is
1555    /// the instruction's own, so the message lands on the line rather than on the file.
1556    #[test]
1557    fn an_opcode_with_no_name_in_the_rule_language_is_named_by_its_own_spelling() {
1558        let mut opts = options();
1559        opts.emit = EmitKind::MirFinal;
1560        let result = run(&opts, "int f(int a) {\n  __int128 wide = a;\n  return (int) wide;\n}\n");
1561        assert!(result.failed());
1562        assert!(
1563            result.messages[0].contains("no rule lowers a `sext` producing a `i128`"),
1564            "{result:?}"
1565        );
1566        assert!(result.messages[0].contains(":2:"), "the line the widening is on: {result:?}");
1567        assert!(!result.messages[0].contains("this instruction"), "{result:?}");
1568    }
1569
1570    /// The note names the issue tracker, which is where a reader finds out whether it is known.
1571    #[test]
1572    fn the_note_on_unfinished_work_points_at_the_issues_rather_than_at_the_plan() {
1573        let mut opts = options();
1574        opts.emit = EmitKind::MirFinal;
1575        let result = run(&opts, "int f(int a) { __int128 wide = a; return (int) wide; }\n");
1576        assert!(result.failed());
1577        let note = result.messages.iter().find(|line| line.contains("note:")).expect("a note");
1578        assert!(note.contains("https://github.com/tamnd/rucc/issues"), "{note}");
1579        assert!(!note.contains("spec/17-milestones.md"), "{note}");
1580    }
1581
1582    /// The two frame flags reach the frame, which is the only thing either of them does.
1583    #[test]
1584    fn the_frame_flags_on_the_command_line_reach_the_generated_frame() {
1585        let source = "int f(int a) { return a; }\n";
1586        assert!(!mir(source).contains("$rbp"), "a leaf needs no frame pointer by default");
1587
1588        let mut opts = options();
1589        opts.emit = EmitKind::MirFinal;
1590        opts.frame_pointer = true;
1591        let kept = run(&opts, source).text().to_owned();
1592        assert!(kept.contains("x64.push_64 $rbp"), "{kept}");
1593    }
1594
1595    /// The assembly of `source`, insisting that it compiled cleanly.
1596    fn asm(source: &str) -> String {
1597        let mut opts = options();
1598        opts.emit = EmitKind::Asm;
1599        let result = run(&opts, source);
1600        assert_eq!(result.messages, Vec::<String>::new(), "expected this to compile:\n{source}");
1601        result.text().to_owned()
1602    }
1603
1604    /// `-S`, which is the same compiler as the kind above it with a different last step.
1605    ///
1606    /// What the assembly says is checked in `rucc-asm`, one instruction at a time and against the
1607    /// target's own description of what an instruction is. What is checked here is that a C file
1608    /// goes all the way to a listing an assembler would take, which means the directives around
1609    /// the function as well as the instructions in it.
1610    #[test]
1611    fn a_function_goes_from_c_to_assembly_an_assembler_would_take() {
1612        let text = asm("int add(int a, int b) { return a + b; }\n");
1613        assert!(text.contains("\t.globl\tadd\n"), "{text}");
1614        assert!(text.contains("\t.type\tadd, @function\n"), "{text}");
1615        assert!(text.contains("\nadd:\n"), "{text}");
1616        assert!(text.contains("\taddl\t"), "{text}");
1617        assert!(text.contains("\tret\n"), "{text}");
1618        assert!(text.contains("\t.size\tadd, .-add\n"), "{text}");
1619        // Without this the stack the program runs on is executable, which is not a default
1620        // anybody chose and is not a thing a reader would notice missing.
1621        assert!(text.contains(".note.GNU-stack"), "{text}");
1622    }
1623
1624    /// A call through a function pointer, which is a different instruction from a call to a name.
1625    ///
1626    /// Both are in the one function on purpose. What is being read is that the two calls are told
1627    /// apart all the way down: one carries a name the linker resolves and one carries a register,
1628    /// and neither turns into the other on the way.
1629    #[test]
1630    fn a_call_through_a_function_pointer_goes_through_the_register_it_is_in() {
1631        let text = asm("int g(int);\nint f(int (*p)(int), int a) { return p(a) + g(a); }\n");
1632        assert!(text.contains("\tcall\t*%"), "{text}");
1633        assert!(text.contains("\tcall\tg\n"), "{text}");
1634        // The address arrived in the first argument register and the argument the call passes has
1635        // to end up there, so the two cannot be the same register and the compiler has to have
1636        // moved one of them.
1637        assert!(text.contains("%rdi"), "{text}");
1638    }
1639
1640    /// A name at file scope, which is the one address a function cannot compute for itself.
1641    #[test]
1642    fn the_address_of_a_global_is_read_from_the_instruction_pointer() {
1643        let text = asm("extern int counter;\nint f(void) { return counter; }\n");
1644        assert!(text.contains("\tleaq\tcounter(%rip), "), "{text}");
1645    }
1646
1647    /// A cast between a pointer and an integer as wide as one, which is every one C writes here.
1648    #[test]
1649    fn a_cast_between_a_pointer_and_an_integer_leaves_the_value_where_it_is() {
1650        let text = asm("long f(void *p) { return (long)p; }\n");
1651        // Every instruction in the body is a full width move or the return. The copies are the
1652        // allocator taking no hints, and what matters here is what is not among them: nothing
1653        // narrows the value and nothing widens it again, which is what a cast that did something
1654        // would look like.
1655        for line in text.lines().filter(|line| line.starts_with('\t') && !line.contains('.')) {
1656            let mnemonic = line.split_whitespace().next().unwrap_or("");
1657            assert!(matches!(mnemonic, "movq" | "ret"), "{line} in\n{text}");
1658        }
1659    }
1660
1661    /// The arguments past the sixth arrive in the caller's memory rather than in a register, and
1662    /// where that memory is depends on what the prologue did, so this is checked at the end of the
1663    /// pipeline rather than in the middle of it.
1664    #[test]
1665    fn an_argument_past_the_last_register_is_read_out_of_the_caller_s_stack() {
1666        let six = "long a, long b, long c, long d, long e, long f";
1667        let text = asm(&format!("long f({six}, long g, long h) {{ return g + h; }}\n"));
1668
1669        // Nothing is pushed and no frame is taken, so the only thing between the stack pointer and
1670        // the caller's arguments is the return address the call pushed. Which is where gcc 16.2.0
1671        // reads them from too, at `-O0`, in the same two instructions.
1672        assert!(text.contains("\tmovq\t8(%rsp), "), "{text}");
1673        assert!(text.contains("\tmovq\t16(%rsp), "), "{text}");
1674
1675        // A narrower one is read at its own width, because the bits above it are bits the
1676        // convention says nothing about, and one in the other register file with the other file's
1677        // instruction.
1678        let narrow = asm(&format!("int f({six}, int g) {{ return g; }}\n"));
1679        assert!(narrow.contains("\tmovl\t8(%rsp), "), "{narrow}");
1680        let eight =
1681            "double a, double b, double c, double d, double e, double f, double g, double h";
1682        let float = asm(&format!("double f({eight}, double i) {{ return i; }}\n"));
1683        assert!(float.contains("\tmovsd\t8(%rsp), "), "{float}");
1684    }
1685
1686    /// The other end of the same thing. What the caller writes is at the stack pointer, because
1687    /// that is the bottom of its frame and the bottom of its frame is where the callee looks.
1688    #[test]
1689    fn a_call_writes_the_arguments_with_no_register_left_at_the_stack_pointer() {
1690        let six = "1, 2, 3, 4, 5, 6";
1691        let decl = "long g(long, long, long, long, long, long, long, long);\n";
1692        let text = asm(&format!("{decl}long f(void) {{ return g({six}, 7, 8); }}\n"));
1693
1694        assert!(text.contains("\tmovq\t%"), "{text}");
1695        assert!(text.contains(", (%rsp)\n"), "{text}");
1696        assert!(text.contains(", 8(%rsp)\n"), "{text}");
1697        // And it reserved the bytes it wrote into, so nothing else in the frame is on top of them.
1698        assert!(text.contains("\tsubq\t$"), "{text}");
1699
1700        // A narrower one is written at its own width, matching what the callee reads it back with.
1701        let narrow = "int g(int, int, int, int, int, int, int);\n";
1702        let text = asm(&format!("{narrow}int f(void) {{ return g({six}, 7); }}\n"));
1703        assert!(text.contains("\tmovl\t%"), "{text}");
1704        assert!(text.contains(", (%rsp)\n"), "{text}");
1705    }
1706
1707    /// The count a variadic callee on this convention reads is a count of vector registers, so a
1708    /// float that ran out of them and went to memory is not in it.
1709    #[test]
1710    fn a_variadic_call_counts_registers_and_not_arguments() {
1711        let nine = "1., 2., 3., 4., 5., 6., 7., 8., 9.";
1712        let decl = "int g(int, ...);\n";
1713        let text = asm(&format!("{decl}int f(void) {{ return g(0, {nine}); }}\n"));
1714
1715        assert!(text.contains("\tmovl\t$8, "), "eight registers, not nine: {text}");
1716        assert!(text.contains("\tmovsd\t%"), "{text}");
1717        assert!(text.contains(", (%rsp)\n"), "{text}");
1718    }
1719
1720    /// The callee's half of the same convention. Every argument register it was handed is written
1721    /// into its frame on the way in, because which of them hold anything is a thing only the caller
1722    /// knew, and the ones the signature does name are left out because `va_start` sets the offsets
1723    /// past them and nothing ever reads their slots.
1724    #[test]
1725    fn a_variadic_function_writes_the_argument_registers_it_was_handed_into_its_frame() {
1726        let body =
1727            "__builtin_va_list ap; __builtin_va_start(ap, n); __builtin_va_end(ap); return n;";
1728        let text = asm(&format!("int f(int n, ...) {{ {body} }}\n"));
1729
1730        // Five general purpose registers and eight vector ones, since the one parameter the
1731        // signature names took the first of the six.
1732        let stores = |mnemonic: &str| text.matches(&format!("\t{mnemonic}\t%")).count();
1733        assert!(text.contains(", 8(%r"), "the second slot, not the first: {text}");
1734        assert!(!text.contains(", 0(%r"), "{text}");
1735        assert_eq!(stores("movsd"), 8, "every vector register: {text}");
1736
1737        // And the area is one of the function's own stack objects, so the frame holds it.
1738        assert!(text.contains("\tsubq\t$"), "{text}");
1739    }
1740
1741    /// What `va_start` writes is the four fields of the list, and the two numbers among them are
1742    /// where the arguments the signature names left the walk over each file's registers.
1743    #[test]
1744    fn va_start_writes_the_four_fields_the_psabi_describes() {
1745        let start = "__builtin_va_list ap; __builtin_va_start(ap, d);";
1746        let params = "int a, int b, int c, double d";
1747        let text = asm(&format!("int f({params}, ...) {{ {start} return a; }}\n"));
1748
1749        // Three integers took three of the six general purpose registers, and one double took one
1750        // of the eight vector ones, so the walk starts at twenty four bytes into the first half and
1751        // sixteen bytes into the second, which begins at forty eight.
1752        assert!(text.contains("	movl	$24, "), "{text}");
1753        assert!(text.contains("	movl	$64, "), "{text}");
1754        // The other two fields are addresses rather than numbers, so each is stored as a word and
1755        // each is a `lea` away. One of them reaches above the frame, which is where the caller's
1756        // arguments are and is the only thing in this function that is not below the stack pointer.
1757        assert!(text.contains(", 8(%r"), "{text}");
1758        assert!(text.contains(", 16(%r"), "{text}");
1759        let frame: u32 = text
1760            .lines()
1761            .find_map(|line| line.trim().strip_prefix("subq	$")?.split(',').next()?.parse().ok())
1762            .expect("a variadic function takes a frame for the save area");
1763        let above = |line: &str| {
1764            let at: u32 = line.trim().strip_prefix("leaq	")?.split('(').next()?.parse().ok()?;
1765            Some(at > frame)
1766        };
1767        assert!(text.lines().filter_map(above).any(|it| it), "{frame}: {text}");
1768    }
1769
1770    /// A `va_arg` is a branch on whether the argument it wants is still in the save area, and which
1771    /// of the two halves it walks is the type's answer.
1772    #[test]
1773    fn va_arg_branches_on_whether_the_argument_is_still_in_the_save_area() {
1774        let read = "__builtin_va_list ap; __builtin_va_start(ap, n);";
1775        let ints = format!("int f(int n, ...) {{ {read} return __builtin_va_arg(ap, int); }}\n");
1776        let text = asm(&ints);
1777
1778        // The last general purpose slot begins at forty, so an offset above it is an argument the
1779        // caller left in its own memory instead.
1780        assert!(text.contains("$40, "), "{text}");
1781        assert!(text.contains("	cmpl	"), "{text}");
1782        assert!(text.contains("	setbe	"), "unsigned, since an offset is a count of bytes: {text}");
1783
1784        let arg = "__builtin_va_arg(ap, double)";
1785        let text = asm(&format!("double f(int n, ...) {{ {read} return {arg}; }}\n"));
1786        assert!(text.contains("$160, "), "the last vector slot: {text}");
1787    }
1788
1789    /// A structure assigned is a copy of a known size, and a copy of a known size is a run of
1790    /// moves rather than a call to a library this compiler has no way to reach yet.
1791    #[test]
1792    fn a_structure_assignment_is_a_move_for_each_word_of_it() {
1793        let decl = "struct pair { long a, b; };\n";
1794        let body = "struct pair p = *q; return p.a + p.b;";
1795        let text = asm(&format!("{decl}long f(struct pair *q) {{ {body} }}\n"));
1796
1797        assert!(!text.contains("memcpy"), "nothing calls the library: {text}");
1798        assert!(!text.contains("\tcall"), "{text}");
1799        // Sixteen bytes aligned to eight is two words, and each is a load and a store.
1800        assert!(text.matches("\tmovq\t").count() >= 4, "two words each way: {text}");
1801    }
1802
1803    /// A word is as wide as the object is aligned to and no wider, so a character array is copied
1804    /// a byte at a time and a structure of longs eight bytes at a time.
1805    #[test]
1806    fn how_wide_a_word_of_a_copy_is_follows_the_alignment() {
1807        let decl = "struct bytes { char a[8]; };\n";
1808        let body = "struct bytes p = *q; return p.a[0];";
1809        let text = asm(&format!("{decl}int f(struct bytes *q) {{ {body} }}\n"));
1810
1811        // Eight bytes aligned to one is eight words, and each is a load and a store.
1812        assert!(text.matches("\tmovb\t").count() >= 16, "a byte at a time: {text}");
1813    }
1814
1815    /// What an initialiser does not name is zero, which the front end writes as a fill and this
1816    /// writes as the byte spread across each word.
1817    #[test]
1818    fn the_part_of_an_initialiser_that_names_nothing_is_stored_as_zero() {
1819        let decl = "struct wide { long a, b, c; };\n";
1820        let text = asm(&format!("{decl}long f(void) {{ struct wide w = {{ 7 }}; return w.c; }}\n"));
1821
1822        assert!(!text.contains("memset"), "nothing calls the library: {text}");
1823        assert!(text.contains("\tmovq\t$0, ") || text.contains("$0, %"), "the zero: {text}");
1824    }
1825
1826    /// A copy too large to be worth unrolling is a call to the runtime, which is the C library on
1827    /// a hosted target and `rucc-builtins` on a freestanding one.
1828    #[test]
1829    fn a_copy_too_large_to_unroll_calls_the_runtime() {
1830        let decl = "struct huge { char a[4096]; };\n";
1831        let mut opts = options();
1832        opts.emit = EmitKind::Asm;
1833        let source = format!("{decl}void f(struct huge *p, struct huge *q) {{ *p = *q; }}\n");
1834        let result = run(&opts, &source);
1835        assert!(!result.failed(), "{:?}", result.messages);
1836        let text = result.text();
1837        assert!(text.contains("call") && text.contains("memcpy"), "{text}");
1838        // The size in the register the convention passes the third argument in, which is what
1839        // says the call was built from the convention and not from the shape of the IR.
1840        assert!(text.contains("4096"), "the size travels: {text}");
1841    }
1842
1843    /// A frame that had to force its own alignment cannot say how far away the caller's stack
1844    /// pointer was, so it reaches back through the frame pointer instead.
1845    #[test]
1846    fn a_realigned_frame_reads_them_through_the_frame_pointer() {
1847        let six = "long a, long b, long c, long d, long e, long f";
1848        let body = "_Alignas(32) long wide[4]; wide[0] = g; return wide[0];";
1849        let text = asm(&format!("long f({six}, long g) {{ {body} }}\n"));
1850
1851        // The frame pointer is saved and pointed at where it was saved before the alignment is
1852        // forced, so the caller's arguments stay a constant distance from it: one word for the
1853        // saved frame pointer and one for the return address.
1854        assert!(text.contains("\tandq\t$-32, %rsp"), "{text}");
1855        assert!(text.contains("\tmovq\t16(%rbp), "), "{text}");
1856        assert!(!text.contains("\tmovq\t16(%rsp), "), "{text}");
1857    }
1858
1859    /// The object format decides the directives, and the target decides the object format.
1860    #[test]
1861    fn the_target_decides_how_the_assembly_is_spelled() {
1862        let mut opts = options();
1863        opts.emit = EmitKind::Asm;
1864        opts.target = "x86_64-apple-darwin".parse::<Triple>().unwrap();
1865        let text = run(&opts, "int f(void) { return 0; }\n").text().to_owned();
1866        assert!(text.contains("__TEXT,__text"), "{text}");
1867        assert!(text.contains("\n_f:\n"), "{text}");
1868        assert!(!text.contains(".note.GNU-stack"), "{text}");
1869    }
1870
1871    /// The object file of `source`, insisting that it compiled cleanly.
1872    fn obj(source: &str) -> Vec<u8> {
1873        let mut opts = options();
1874        opts.emit = EmitKind::Object;
1875        let result = run(&opts, source);
1876        assert_eq!(result.messages, Vec::<String>::new(), "expected this to compile:\n{source}");
1877        match result.artifact {
1878            Artifact::Object(bytes) => bytes,
1879            other => panic!("expected an object, got {other:?}"),
1880        }
1881    }
1882
1883    /// `-c`, which is the last step of the three the back end can end with.
1884    ///
1885    /// What is in the file is checked in `rucc-object`, a field at a time. What is checked here is
1886    /// that a C file goes all the way to one, which is the whole compiler in one line and the
1887    /// thing that stops working when a layer between them changes its mind about something.
1888    #[test]
1889    fn a_function_goes_from_c_to_an_object_a_linker_would_take() {
1890        let bytes = obj("int add(int a, int b) { return a + b; }\n");
1891        assert_eq!(&bytes[..4], b"\x7fELF", "an object file starts by saying it is one");
1892        let text = asm("int add(int a, int b) { return a + b; }\n");
1893        assert!(
1894            text.contains("\taddl\t"),
1895            "and the listing of it is the same instructions:\n{text}"
1896        );
1897    }
1898
1899    /// A variable this file defines, which is what a reference to one has to resolve against.
1900    #[test]
1901    fn a_variable_goes_from_c_to_the_section_it_belongs_in() {
1902        let text = asm("int counter = 42;\nstatic int hidden;\nconst int fixed = 7;\n");
1903        assert!(text.contains("\t.data\n\t.globl\tcounter\n"), "{text}");
1904        assert!(text.contains("\ncounter:\n\t.long\t42\n"), "{text}");
1905        assert!(text.contains("\t.size\tcounter, .-counter\n"), "{text}");
1906        // A zeroed variable carries its size and none of its bytes, and a `static` one is not
1907        // announced to the linker at all, which is the whole of what `static` means here.
1908        assert!(text.contains("\t.bss\n\t.p2align\t2\n"), "{text}");
1909        assert!(text.contains("\nhidden:\n\t.space\t4\n"), "{text}");
1910        assert!(!text.contains(".globl\thidden"), "{text}");
1911        // Nothing writes through it, so it goes in a page the loader can map read only and every
1912        // process running the program can share.
1913        assert!(text.contains("\t.section\t.rodata\n"), "{text}");
1914    }
1915
1916    /// A bit-field with a value in it, which is written as the bytes the value lands in.
1917    ///
1918    /// The interesting one is the field whose lowest byte is zero. The bytes a bit-field
1919    /// initializer makes are put together first and then taken back out as the run they make,
1920    /// and taking them out starts at the byte the field starts at, so a zero byte at the front
1921    /// used to end the object up in `.bss` with the rest of its value thrown away.
1922    #[test]
1923    fn a_bit_field_initializer_writes_every_byte_of_the_value_and_not_only_the_ones_that_are_set() {
1924        let text = asm("struct s { unsigned f : 20; } x = { 0x12300 };\n");
1925        assert!(text.contains("\t.data\n"), "there is something to write: {text}");
1926        assert!(text.contains("\nx:\n\t.ascii\t\"\\000#\\001\"\n"), "and it is the value: {text}");
1927
1928        // Two fields, the first of them zero, which is the same thing said with the zero byte
1929        // inside the run rather than at the front of it.
1930        let text = asm("struct s { unsigned a : 8; unsigned b : 8; } x = { 0, 3 };\n");
1931        assert!(text.contains("\nx:\n\t.ascii\t\"\\000\\003\"\n"), "{text}");
1932
1933        // Wider than an `int`, which is the same code and is worth saying because the value no
1934        // longer fits in the thirty two bits a bit-field used to be read at.
1935        let text = asm("struct s { unsigned long long f : 40; } x = { 0x100000 };\n");
1936        assert!(text.contains("\nx:\n\t.ascii\t\"\\000\\000\\020\"\n\t.space\t5\n"), "{text}");
1937
1938        // Nothing in it, which still costs no bytes in the file.
1939        let text = asm("struct s { unsigned f : 20; } x = { 0 };\n");
1940        assert!(text.contains("\t.bss\n"), "an object of zeroes is zeroes: {text}");
1941        assert!(text.contains("\nx:\n\t.space\t4\n"), "{text}");
1942    }
1943
1944    /// A string literal, which is a variable the program never named.
1945    #[test]
1946    fn a_string_literal_is_a_variable_with_a_name_no_program_could_write() {
1947        let text = asm("const char *f(void) { return \"hi\"; }\n");
1948        assert!(text.contains("\t.ascii\t\"hi\\000\"\n"), "{text}");
1949        assert!(text.contains("\t.section\t.rodata\n"), "{text}");
1950        let label = text
1951            .lines()
1952            .find(|line| line.starts_with(".Lstr"))
1953            .unwrap_or_else(|| panic!("a label for the literal in\n{text}"));
1954        assert!(!text.contains(&format!(".globl\t{}", label.trim_end_matches(':'))), "{text}");
1955    }
1956
1957    /// A variable holding the address of another one, which is the only hole an image has in it.
1958    #[test]
1959    fn an_address_in_an_initializer_is_left_to_the_linker() {
1960        let source = "int counter;\nint *p = &counter;\n";
1961        let text = asm(source);
1962        assert!(text.contains("\np:\n\t.quad\tcounter\n"), "{text}");
1963        // And in the object it is eight zero bytes and a relocation, which is what the two paths
1964        // being one description is for.
1965        let bytes = obj(source);
1966        assert!(bytes.windows(8).any(|w| w == b"counter\0"), "the object has to name it");
1967    }
1968
1969    /// A thread-local variable, which is valid C that the back end does not build yet.
1970    #[test]
1971    fn a_thread_local_variable_is_reported_as_work_that_is_not_done() {
1972        let mut opts = options();
1973        opts.emit = EmitKind::Asm;
1974        let result = run(&opts, "_Thread_local int x = 1;\n");
1975        assert!(result.failed(), "every thread sharing one variable is worse than a message");
1976        assert!(result.messages.iter().any(|m| m.contains("thread-local")), "{:?}", result);
1977        // Not an internal error: nothing here is wrong and the note says where the work is.
1978        assert!(!result.messages.iter().any(|m| m.contains("internal")), "{:?}", result);
1979    }
1980
1981    /// Not a rewording of the check above: what the two paths agree about is the point.
1982    #[test]
1983    fn the_object_and_the_listing_are_two_spellings_of_one_compilation() {
1984        // A call, because it is the one thing whose spelling in the two differs completely: the
1985        // listing writes a name and the object writes four zero bytes and a relocation asking the
1986        // linker for the same name. If either path had lost the callee, one of these would fail.
1987        let source = "int callee(void); int g(void) { return callee(); }\n";
1988        let bytes = obj(source);
1989        assert!(
1990            bytes.windows(7).any(|w| w == b"callee\0"),
1991            "the object has to name the callee for the linker to find it"
1992        );
1993        let text = asm(source);
1994        assert!(text.contains("\tcall\tcallee\n"), "{text}");
1995    }
1996
1997    /// What a file of a link contributes is an object, and the default emit is a link.
1998    ///
1999    /// This is here because getting it wrong is silent in the worst way: an empty file is a valid
2000    /// empty linker script, so a link fed one gets as far as reporting every symbol of the file as
2001    /// undefined and says nothing about the compilation that produced nothing.
2002    #[test]
2003    fn compiling_for_an_executable_produces_an_object_and_not_a_dump() {
2004        let mut opts = options();
2005        // What a command line with no `-c` and no `-S` on it asks for.
2006        opts.emit = EmitKind::Executable;
2007        let result = run(&opts, "int main(void) { return 0; }\n");
2008        assert_eq!(result.messages, Vec::<String>::new());
2009        match result.artifact {
2010            Artifact::Object(bytes) => assert_eq!(&bytes[..4], b"\x7fELF"),
2011            other => panic!("expected an object, got {other:?}"),
2012        }
2013    }
2014
2015    /// A target with a back end but no object writer says so rather than writing the wrong file.
2016    #[test]
2017    fn a_platform_with_no_object_writer_is_said_so_rather_than_written_as_elf() {
2018        let mut opts = options();
2019        opts.emit = EmitKind::Object;
2020        opts.target = "x86_64-apple-darwin".parse::<Triple>().unwrap();
2021        let result = run(&opts, "int f(void) { return 0; }\n");
2022        assert!(result.failed(), "an object nobody can read is worse than a message");
2023        assert!(
2024            result.messages.iter().any(|m| m.contains("no object writer")),
2025            "{:?}",
2026            result.messages
2027        );
2028    }
2029
2030    /// The IR of `source`, insisting that it compiled cleanly.
2031    fn ir(source: &str) -> String {
2032        let mut opts = options();
2033        opts.emit = EmitKind::Ir;
2034        let result = run(&opts, source);
2035        assert_eq!(result.messages, Vec::<String>::new(), "expected this to compile:\n{source}");
2036        result.text().to_owned()
2037    }
2038
2039    /// What was said about `source`, insisting that something was.
2040    fn errors(source: &str) -> Vec<String> {
2041        let mut opts = options();
2042        opts.emit = EmitKind::Ir;
2043        let result = run(&opts, source);
2044        assert!(result.failed(), "expected this to be refused:\n{source}");
2045        result.messages
2046    }
2047
2048    /// The body of the one function in `source`, which is what most of these are about.
2049    fn body(source: &str) -> String {
2050        let text = ir(source);
2051        let (_, rest) = text.split_once("{\n").expect("a function definition");
2052        let (body, _) = rest.rsplit_once("}\n").expect("a function definition");
2053        body.to_owned()
2054    }
2055
2056    /// The IR of `source` at one safety tier, insisting that it compiled cleanly.
2057    fn safe_ir(tier: rucc_session::Safety, source: &str) -> String {
2058        let mut opts = options();
2059        opts.emit = EmitKind::Ir;
2060        opts.safety = tier;
2061        let result = run(&opts, source);
2062        assert_eq!(result.messages, Vec::<String>::new(), "expected this to compile:\n{source}");
2063        result.text().to_owned()
2064    }
2065
2066    const READS_THROUGH_A_POINTER: &str = "int read(int *p) { return p[1]; }\n";
2067
2068    #[test]
2069    fn a_build_that_did_not_ask_for_the_monitor_is_compiled_the_way_it_always_was() {
2070        // This is the load bearing test of the whole flag. The monitor is being built in the open
2071        // and every build in the world is compiled by this compiler with the flag absent, so a
2072        // check that leaked into that path would be a regression for everybody.
2073        let text = ir(READS_THROUGH_A_POINTER);
2074        assert!(!text.contains("check_"), "{text}");
2075        assert!(!text.contains("cap_of"), "{text}");
2076    }
2077
2078    #[test]
2079    fn asking_for_a_tier_puts_the_checks_in_before_the_optimizer_sees_them() {
2080        let text = safe_ir(rucc_session::Safety::Detect, READS_THROUGH_A_POINTER);
2081        assert!(text.contains("cap_of"), "{text}");
2082        assert!(text.contains("check_bounds"), "{text}");
2083        assert!(text.contains("check_live"), "{text}");
2084        // The subscript is address arithmetic, so J2 applies to it as well as J1.
2085        assert!(text.contains("check_deriv"), "{text}");
2086    }
2087
2088    #[test]
2089    fn the_three_tiers_that_are_not_off_all_check_the_same_accesses_so_far() {
2090        // What separates them is the reporter and the boundary, which are milestones S2 and S3.
2091        // Pinning it here means the day they stop agreeing, this test says so rather than the
2092        // difference going unnoticed.
2093        let detect = safe_ir(rucc_session::Safety::Detect, READS_THROUGH_A_POINTER);
2094        for tier in [rucc_session::Safety::Enforce, rucc_session::Safety::Kernel] {
2095            assert_eq!(safe_ir(tier, READS_THROUGH_A_POINTER), detect, "{tier}");
2096        }
2097    }
2098
2099    /// The safety summary of `source` at one tier, insisting that it compiled cleanly.
2100    fn summary(tier: rucc_session::Safety, source: &str) -> String {
2101        let mut opts = options();
2102        opts.emit = EmitKind::SafetySummary;
2103        opts.safety = tier;
2104        let result = run(&opts, source);
2105        assert_eq!(result.messages, Vec::<String>::new(), "expected this to compile:\n{source}");
2106        result.text().to_owned()
2107    }
2108
2109    #[test]
2110    fn the_summary_counts_the_checks_that_went_in_and_the_ones_still_standing() {
2111        let text = summary(rucc_session::Safety::Detect, READS_THROUGH_A_POINTER);
2112        assert!(text.contains("\"tier\": \"detect\""), "{text}");
2113        // One load, so one of each of the two access checks, and the subscript is a derivation.
2114        assert!(
2115            text.contains("\"bounds\": { \"emitted\": 1, \"remaining\": 1, \"discharged\": 0 }"),
2116            "{text}"
2117        );
2118        assert!(
2119            text.contains(
2120                "\"derivation\": { \"emitted\": 1, \"remaining\": 1, \"discharged\": 0 }"
2121            ),
2122            "{text}"
2123        );
2124    }
2125
2126    #[test]
2127    fn a_build_without_the_monitor_summarises_as_a_build_with_no_checks_in_it() {
2128        // Which is the honest summary rather than an error. A build system that emits a summary
2129        // for every unit should get one for the units nobody asked to instrument too, and the
2130        // zeroes are what say that the guarantee over that file is nothing at all.
2131        let text = summary(rucc_session::Safety::Off, READS_THROUGH_A_POINTER);
2132        assert!(text.contains("\"tier\": \"off\""), "{text}");
2133        assert!(
2134            text.contains("\"bounds\": { \"emitted\": 0, \"remaining\": 0, \"discharged\": 0 }"),
2135            "{text}"
2136        );
2137    }
2138
2139    #[test]
2140    fn a_call_the_boundary_models_is_counted_apart_from_one_it_does_not() {
2141        let text = summary(
2142            rucc_session::Safety::Detect,
2143            "void *memcpy(void *, const void *, unsigned long);\n\
2144             int puts(const char *);\n\
2145             void f(char *d, char *s) { memcpy(d, s, 4); puts(d); }\n",
2146        );
2147        assert!(text.contains("\"interposed\": 1"), "{text}");
2148        assert!(text.contains("\"puts\""), "{text}");
2149        // The wrapper it was pointed at is ours, so it is not on the list of things this build
2150        // failed to model. Counting it there would make instrumenting a file look worse than
2151        // leaving it alone.
2152        assert!(!text.contains("__rucc_wrap_memcpy\""), "{text}");
2153    }
2154
2155    #[test]
2156    fn the_two_directions_a_pointer_crosses_the_boundary_are_counted_apart() {
2157        // `f` is a name the linker can bind to and takes a pointer, so a pointer arrives there.
2158        // `notes_open` is a library this build did not instrument, so a pointer comes back from
2159        // it. Both are crossings and neither is the other, which is why there are two numbers.
2160        let text = summary(
2161            rucc_session::Safety::Detect,
2162            "void *notes_open(void);\n\
2163             char *f(char *p) { char *q = notes_open(); return q ? q : p; }\n",
2164        );
2165        assert!(text.contains("\"crossings\": { \"entered\": 1, \"returned\": 1 }"), "{text}");
2166        assert!(text.contains("\"notes_open\""), "{text}");
2167    }
2168
2169    #[test]
2170    fn a_static_function_nobody_takes_the_address_of_is_not_a_crossing() {
2171        // Nothing outside the file can reach it, so a witness on its parameters would be counting
2172        // a crossing that does not happen.
2173        let text = summary(
2174            rucc_session::Safety::Detect,
2175            "static int len(const char *p) { return p ? 1 : 0; }\n\
2176             int f(void) { return len(\"x\"); }\n",
2177        );
2178        assert!(text.contains("\"crossings\": { \"entered\": 0, \"returned\": 0 }"), "{text}");
2179    }
2180
2181    /// The granule report for `source`, insisting that it compiled cleanly.
2182    fn granules(source: &str) -> String {
2183        let mut opts = options();
2184        opts.emit = EmitKind::TypeGranules;
2185        let result = run(&opts, source);
2186        assert_eq!(result.messages, Vec::<String>::new(), "expected this to compile:\n{source}");
2187        result.text().to_owned()
2188    }
2189
2190    #[test]
2191    fn the_granule_report_names_every_record_and_both_keyings() {
2192        let text = granules(
2193            "struct hot { char *p; int a; int b; };\n\
2194             int f(struct hot *h) { return h->a; }\n",
2195        );
2196        assert!(text.contains("struct hot"), "{text}");
2197        // Both keyings are reported because which types count as one is a decision the design
2198        // has not made yet, and a report that picked one would be hiding the cost of the other.
2199        assert!(text.contains("every type distinct"), "{text}");
2200        assert!(text.contains("every pointer one type"), "{text}");
2201        assert!(text.contains("budget"), "{text}");
2202    }
2203
2204    #[test]
2205    fn a_record_nothing_uses_is_still_measured() {
2206        // The measurement is about what a program declares, not about what it runs, so a type
2207        // that is only ever declared still costs the plane whatever its layout costs.
2208        let text = granules("struct unused { long a; double b; };\nint f(void) { return 0; }\n");
2209        assert!(text.contains("struct unused"), "{text}");
2210    }
2211
2212    #[test]
2213    fn the_granule_report_stops_before_anything_is_lowered() {
2214        // A layout is settled at the closing brace, so lowering the function bodies would take
2215        // minutes on an amalgamation and answer nothing. The evidence that it stops is that a
2216        // body the back end has no way to compile still produces a report.
2217        let text = granules(
2218            "struct wide { long double d; };\n\
2219             long double f(long double x) { return x * x; }\n",
2220        );
2221        assert!(text.contains("struct wide"), "{text}");
2222    }
2223
2224    #[test]
2225    fn a_witness_reaches_the_assembler_as_a_call_to_the_runtime() {
2226        // The count only means anything if the call is really there, and a summary saying one is
2227        // there is not evidence that the back end emitted it.
2228        let text = safe_asm(rucc_session::Safety::Detect, "char *f(char *p) { return p; }\n");
2229        assert!(text.contains("\tcall\t__rucc_cap_witness\n"), "{text}");
2230    }
2231
2232    #[test]
2233    fn a_pointer_turned_into_an_integer_is_on_the_trust_set() {
2234        let text = summary(
2235            rucc_session::Safety::Detect,
2236            "unsigned long f(int *p) { return (unsigned long) p; }\n",
2237        );
2238        assert!(text.contains("\"exposed\": 1"), "{text}");
2239    }
2240
2241    /// The assembly of `source` at one safety tier, insisting that it compiled cleanly.
2242    fn safe_asm(tier: rucc_session::Safety, source: &str) -> String {
2243        let mut opts = options();
2244        opts.emit = EmitKind::Asm;
2245        opts.safety = tier;
2246        let result = run(&opts, source);
2247        assert_eq!(result.messages, Vec::<String>::new(), "expected this to compile:\n{source}");
2248        result.text().to_owned()
2249    }
2250
2251    #[test]
2252    fn a_check_reaches_the_assembler_as_a_call_to_the_runtime() {
2253        let text = safe_asm(rucc_session::Safety::Detect, READS_THROUGH_A_POINTER);
2254        assert!(text.contains("\tcall\t__rucc_check_bounds\n"), "{text}");
2255        assert!(text.contains("\tcall\t__rucc_check_live\n"), "{text}");
2256        assert!(text.contains("\tcall\t__rucc_check_deriv\n"), "{text}");
2257    }
2258
2259    #[test]
2260    fn every_check_that_reached_the_assembler_has_a_row_describing_it() {
2261        // Three checks and three descriptors, each in the section the runtime's reporter reads.
2262        // The width is `rucc_safety::lower::WIDTH` and the row is `rucc_safe_rt::fail::Descriptor`,
2263        // and the two agreeing is what makes the address a check is handed mean anything.
2264        let text = safe_asm(rucc_session::Safety::Detect, READS_THROUGH_A_POINTER);
2265        let section = format!("\t.section\t{},", rucc_safety::SECTION);
2266        assert_eq!(text.matches(&section).count(), 3, "{text}");
2267        for index in 0..3 {
2268            let name = format!("__rucc_safety_desc_{index}");
2269            // Defined once and referenced once, because a descriptor nothing points at describes
2270            // nothing and a reference with no definition does not link.
2271            assert!(text.contains(&format!("{name}:\n")), "{text}");
2272            assert!(text.contains(&format!("{name}(%rip)")), "{text}");
2273        }
2274        assert!(!text.contains("__rucc_safety_desc_3"), "{text}");
2275    }
2276
2277    /// `__builtin_constant_p` is answered in the front end and never reaches the IR.
2278    ///
2279    /// gcc folds it after optimization, so its answer for an argument that is not written as a
2280    /// constant can differ between `-O0` and `-O2`. What is checked here is the front end's
2281    /// answer, which is the same at every level, and the four cases where gcc gives the same
2282    /// answer at both levels are the ones measured on gcc 16: a literal is one, a variable is
2283    /// zero, a string literal is one and the address of an object is zero.
2284    #[test]
2285    fn builtin_constant_p_is_folded_where_it_is_written_rather_than_called() {
2286        let text = ir(concat!(
2287            "int g;\n",
2288            "int a = __builtin_constant_p(1);\n",
2289            "int b = __builtin_constant_p(g);\n",
2290            "int c = __builtin_constant_p(\"abc\");\n",
2291            "int d = __builtin_constant_p(&g);\n",
2292            "int e = __builtin_constant_p(1.5);\n",
2293            "int h = __builtin_choose_expr(__builtin_constant_p(3), 11, 22);\n",
2294        ));
2295        assert!(text.contains("global @a : i32 = 1,"), "{text}");
2296        assert!(text.contains("global @b : i32 = 0,"), "{text}");
2297        assert!(text.contains("global @c : i32 = 1,"), "{text}");
2298        assert!(text.contains("global @d : i32 = 0,"), "{text}");
2299        assert!(text.contains("global @e : i32 = 1,"), "{text}");
2300        assert!(text.contains("global @h : i32 = 11,"), "{text}");
2301        assert!(!text.contains("__builtin_constant_p"), "it is not a call to anything:\n{text}");
2302
2303        // The argument is not evaluated, which is what gcc does with it as well, so `i` is
2304        // still zero. The second constant is the answer, which nothing reads and which the
2305        // first pass that looks for dead code will take out.
2306        let text = body("int f(void) { int i = 0; __builtin_constant_p(i++); return i; }\n");
2307        assert_eq!(text, "block0:\n    %0 = iconst.i32 0\n    %1 = iconst.i32 0\n    return %0\n");
2308    }
2309
2310    /// A library builtin is the library function of the same name, and the call says so.
2311    ///
2312    /// A program writes `__builtin_strlen` rather than `strlen` to reach the function the C
2313    /// library promises where its own name has been taken by a macro, and to say that the usual
2314    /// meaning is the one intended. So the name in the program and the name in the object file
2315    /// are two different names and the call carries the second one. gcc folds several of these
2316    /// when the arguments allow it, which is an optimization on top of a call that is already
2317    /// right rather than instead of it, so nothing here depends on any folding happening.
2318    #[test]
2319    fn a_call_to_a_library_builtin_reaches_the_library_function() {
2320        let text = body("void f(void) { __builtin_abort(); }\n");
2321        assert_eq!(text, "block0:\n    call @abort() : ()\n    return\n");
2322
2323        // Nothing declared either of these and nothing had to: the prefix is what says the name
2324        // belongs to the implementation, and the type comes out of `features.toml`.
2325        let text = ir("int f(const char *s) { return __builtin_puts(s) + __builtin_strlen(s); }\n");
2326        assert!(text.contains("call @puts(%0) : (ptr) -> i32"), "{text}");
2327        assert!(text.contains("call @strlen(%0) : (ptr) -> i64"), "{text}");
2328        assert!(!text.contains("__builtin_"), "the prefix is not part of any name here:\n{text}");
2329    }
2330
2331    /// The absolute value family is four instructions and not a call, whoever declared the name.
2332    ///
2333    /// `abs`, `labs` and `llabs` are reserved to the implementation, so a program that writes one
2334    /// means the one the C library promises and the compiler is allowed to know what it does. The
2335    /// program in `gcc.c-torture/execute/20021127-1.c` is the one that insists: it defines `llabs`
2336    /// to abort and expects the call not to reach it. Measured against gcc 16.2.0, which writes a
2337    /// `neg` and a `cmovns` and never calls the definition either.
2338    ///
2339    /// The most negative value comes back as itself, which is what the arithmetic gives and what
2340    /// gcc's pair of instructions gives, and C says the answer is undefined there.
2341    #[test]
2342    fn the_absolute_value_family_is_the_magnitude_and_not_a_call() {
2343        let text = body(concat!(
2344            "long long llabs(long long);\n",
2345            "long long f(long long x) { return llabs(x); }\n",
2346        ));
2347        assert!(text.contains("%1 = iconst.i64 63"), "{text}");
2348        assert!(text.contains("%2 = ashr %0, %1"), "{text}");
2349        assert!(text.contains("%3 = xor %0, %2"), "{text}");
2350        assert!(text.contains("%4 = sub %3, %2"), "{text}");
2351        assert!(!text.contains("call"), "the call does not happen:\n{text}");
2352
2353        // The narrower two, whose width comes from the type the library gives the name and not
2354        // from anything at the call.
2355        let text = body("int abs(int);\nint f(int x) { return abs(x); }\n");
2356        assert!(text.contains("iconst.i32 31"), "{text}");
2357        let text = body("long labs(long);\nlong f(long x) { return labs(x); }\n");
2358        assert!(text.contains("iconst.i64 63"), "{text}");
2359
2360        // The prefixed spelling is the same node, and it is what a program writes to reach the
2361        // library's meaning where the plain name has been taken.
2362        let text = body("long long f(long long x) { return __builtin_llabs(x); }\n");
2363        assert!(!text.contains("call"), "{text}");
2364
2365        // A definition of the name in the same file changes nothing, which is the whole point.
2366        let text = ir(concat!(
2367            "long long llabs(long long b);\n",
2368            "long long g(long long x) { return llabs(x); }\n",
2369            "long long llabs(long long b) { return 7; }\n",
2370        ));
2371        assert!(!text.contains("call @llabs"), "{text}");
2372    }
2373
2374    /// A byte swap is one instruction and not a call, and nothing had to declare it.
2375    ///
2376    /// SQLite writes these for its page headers and glibc's `<endian.h>` defines `htobe32` and its
2377    /// neighbours as exactly these, so a program that reads a file format reaches one without ever
2378    /// naming it. There is no object file anywhere that defines `__builtin_bswap32`, so a call left
2379    /// standing here would not link.
2380    #[test]
2381    fn a_byte_swap_is_arithmetic_and_not_a_call() {
2382        let text = body("unsigned f(unsigned x) { return __builtin_bswap32(x); }\n");
2383        assert_eq!(text, "block0(%0: i32):\n    %1 = bswap %0\n    return %1\n");
2384
2385        // The argument is converted by the prototype the way any other call's would be, so the
2386        // swap happens at the width the name says and not at the width the program wrote.
2387        let text = body("unsigned f(unsigned char c) { return __builtin_bswap32(c); }\n");
2388        assert!(text.contains("zext.i32 %0"), "widened first: {text}");
2389        assert!(text.contains("bswap %1"), "and swapped at four bytes: {text}");
2390    }
2391
2392    /// Each of the three reverses in the width its name says, which is the type of the node.
2393    ///
2394    /// The width matters more here than it looks. `__builtin_bswap16` is the two bytes of a
2395    /// `uint16_t` exchanged, and if the node came out at the machine's width instead then the bits
2396    /// above the value would be dragged into the answer and the result would be zero.
2397    #[test]
2398    fn the_byte_swaps_reverse_at_the_width_their_name_says() {
2399        for (name, ty, width) in [
2400            ("__builtin_bswap16", "unsigned short", "i16"),
2401            ("__builtin_bswap32", "unsigned", "i32"),
2402            ("__builtin_bswap64", "unsigned long long", "i64"),
2403        ] {
2404            let source = format!("{ty} f({ty} x) {{ return {name}(x); }}\n");
2405            let text = body(&source);
2406            assert_eq!(
2407                text,
2408                format!("block0(%0: {width}):\n    %1 = bswap %0\n    return %1\n"),
2409                "{name}"
2410            );
2411        }
2412    }
2413
2414    /// The three bit counts the IR has an instruction for are that instruction and not a call.
2415    ///
2416    /// Fifteen rows of `features.toml` come out of five questions, and three of the five are one
2417    /// instruction each. The kernel's bitmap search is built on them, ffmpeg counts leading zeroes
2418    /// in its bitstream reader and SQLite uses one to size a page, so a call left standing here
2419    /// would not link against anything and would be slow if it did.
2420    #[test]
2421    fn the_bit_counts_are_instructions_and_not_calls() {
2422        let text = body("int f(unsigned x) { return __builtin_clz(x); }\n");
2423        assert_eq!(text, "block0(%0: i32):\n    %1 = ctlz %0\n    return %1\n");
2424
2425        let text = body("int f(unsigned x) { return __builtin_ctz(x); }\n");
2426        assert_eq!(text, "block0(%0: i32):\n    %1 = cttz %0\n    return %1\n");
2427
2428        let text = body("int f(unsigned x) { return __builtin_popcount(x); }\n");
2429        assert_eq!(text, "block0(%0: i32):\n    %1 = ctpop %0\n    return %1\n");
2430    }
2431
2432    /// The width counted is the operand's and the width answered is `int`, which are two different
2433    /// things at every spelling but the narrowest.
2434    ///
2435    /// This is the mistake the family invites. `__builtin_clz` of a value counts the leading zeroes
2436    /// of it narrowed to `unsigned int` and `__builtin_clzll` counts them at sixty four bits, and
2437    /// those are different numbers for the same value. What decides it is the prototype the row
2438    /// carries, so the count happens after the conversion and the narrowing back to `int` happens
2439    /// after the count.
2440    #[test]
2441    fn the_bit_counts_ask_about_the_width_their_name_says() {
2442        let text = body("int f(unsigned long long x) { return __builtin_clzll(x); }\n");
2443        assert!(text.starts_with("block0(%0: i64):"), "counted at eight bytes: {text}");
2444        assert!(text.contains("%1 = ctlz %0"), "{text}");
2445        assert!(text.contains("trunc.i32 %1"), "and answered in an int: {text}");
2446
2447        // The same value asked about at the narrower width, which converts first and so counts
2448        // something else.
2449        let text = body("int f(unsigned long long x) { return __builtin_clz(x); }\n");
2450        assert!(text.contains("trunc.i32 %0"), "narrowed to what was asked about: {text}");
2451        assert!(text.contains("ctlz %1"), "and counted there: {text}");
2452
2453        let text = body("int f(unsigned long x) { return __builtin_popcountl(x); }\n");
2454        assert!(text.contains("%1 = ctpop %0"), "{text}");
2455        assert!(!text.contains("call"), "{text}");
2456    }
2457
2458    /// A parity is whether the count of set bits is odd, which is that count and its low bit.
2459    ///
2460    /// Not the machine's parity flag, which on x86-64 is over the low byte of a result and so is a
2461    /// different question, and not the count itself, since C says the answer is zero or one.
2462    #[test]
2463    fn a_parity_is_the_low_bit_of_the_set_bit_count() {
2464        let text = body("int f(unsigned x) { return __builtin_parity(x); }\n");
2465        assert!(text.contains("%1 = ctpop %0"), "{text}");
2466        assert!(text.contains("iconst.i32 1"), "{text}");
2467        assert!(text.contains("and %1, %2"), "the low bit of it: {text}");
2468    }
2469
2470    /// `__builtin_ffs` is the trailing zero count and one, kept only when there was a bit to find.
2471    ///
2472    /// The one in the family defined at zero, where it answers zero. Written as a mask rather than
2473    /// as a branch: the count and the comparison do not depend on each other and both are cheap, so
2474    /// a branch would buy nothing and cost two blocks and a join.
2475    #[test]
2476    fn the_first_set_bit_is_one_based_and_zero_for_a_zero() {
2477        let text = body("int f(int x) { return __builtin_ffs(x); }\n");
2478        assert!(text.contains("%1 = cttz %0"), "{text}");
2479        assert!(text.contains("%4 = add %1, %2"), "one more than the count: {text}");
2480        assert!(text.contains("%5 = icmp ne %0, %3"), "whether there was a bit at all: {text}");
2481        assert!(text.contains("%7 = sub %3, %6"), "spread to a mask: {text}");
2482        assert!(text.contains("%8 = and %4, %7"), "and kept only then: {text}");
2483        assert!(!text.contains("br_if"), "no branch: {text}");
2484    }
2485
2486    /// The three overflow checks are arithmetic and a flag, and not a call to anything.
2487    ///
2488    /// gcc has emitted these since 5.0 and there is no object file that defines one, so a call left
2489    /// standing here would not link. SQLite reaches all three within twenty lines of each other, in
2490    /// `sqlite3AddInt64` and its two neighbours, which is the reason they were done now.
2491    ///
2492    /// The IR instruction answers two things at once, the wrapped value and whether it wrapped,
2493    /// which is a shape nothing else in the IR has. The store is the builtin writing the answer
2494    /// through the pointer it was handed.
2495    #[test]
2496    fn an_overflow_check_is_arithmetic_and_not_a_call() {
2497        let text =
2498            body("int f(int a, int b, int *r) { return __builtin_add_overflow(a, b, r); }\n");
2499        assert!(text.contains("%3, %4 = sadd_overflow.(i32, i1) %0, %1"), "{text}");
2500        assert!(text.contains("store %3 -> %2"), "{text}");
2501        assert!(!text.contains("call"), "{text}");
2502
2503        let text =
2504            body("int f(int a, int b, int *r) { return __builtin_sub_overflow(a, b, r); }\n");
2505        assert!(text.contains("ssub_overflow.(i32, i1) %0, %1"), "{text}");
2506
2507        let text =
2508            body("int f(int a, int b, int *r) { return __builtin_mul_overflow(a, b, r); }\n");
2509        assert!(text.contains("smul_overflow.(i32, i1) %0, %1"), "{text}");
2510
2511        // Unsigned operands get the unsigned form, which is a different question about the same
2512        // arithmetic: an unsigned sum wraps where a signed one of the same bits does not.
2513        let text = body(
2514            "int f(unsigned a, unsigned b, unsigned *r) { return __builtin_add_overflow(a, b, r); }\n",
2515        );
2516        assert!(text.contains("uadd_overflow.(i32, i1) %0, %1"), "{text}");
2517    }
2518
2519    /// The arithmetic happens at a type that holds every value all three written types can hold.
2520    ///
2521    /// That is what makes the check exact. `unsigned int` and `int` in one call need thirty three
2522    /// bits between them, so the add is done at sixty four with each operand extended the way its
2523    /// own signedness says: the unsigned one zero extended, the signed one sign extended. Sign
2524    /// extending the unsigned one would turn three billion into a negative number before the
2525    /// addition ever saw it.
2526    #[test]
2527    fn an_overflow_check_is_done_at_a_type_that_holds_every_operand() {
2528        let text = body(
2529            "int f(unsigned a, int b, long long *r) { return __builtin_add_overflow(a, b, r); }\n",
2530        );
2531        assert!(text.contains("%3 = zext.i64 %0"), "the unsigned operand keeps its value: {text}");
2532        assert!(text.contains("%4 = sext.i64 %1"), "and so does the signed one: {text}");
2533        assert!(text.contains("sadd_overflow.(i64, i1) %3, %4"), "{text}");
2534
2535        // Three types that agree need no extension at all, which is what nearly every real call
2536        // is written as.
2537        let text = body(
2538            "int f(long long a, long long b, long long *r) { return __builtin_mul_overflow(a, b, r); }\n",
2539        );
2540        assert!(text.contains("smul_overflow.(i64, i1) %0, %1"), "{text}");
2541        assert!(!text.contains("sext."), "{text}");
2542        // The one widening left is the answer, which is a bit becoming the `int` C says it is.
2543        assert!(!text.contains("zext.i64"), "{text}");
2544    }
2545
2546    /// The wrapped answer is written through the pointer whether or not it fit.
2547    ///
2548    /// That is gcc's rule and it is what makes the builtin usable as a wrapping add with a flag on
2549    /// the side. A destination narrower than the arithmetic is narrowed and widened back, and the
2550    /// answer being different is the second half of the test: the instruction says whether the
2551    /// arithmetic itself needed more room, and the round trip says whether what came out survived
2552    /// the trip down to where it was going.
2553    #[test]
2554    fn an_overflow_check_writes_the_wrapped_answer_whether_or_not_it_fit() {
2555        let text =
2556            body("int f(int a, int b, char *r) { return __builtin_sub_overflow(a, b, r); }\n");
2557        assert!(text.contains("%3, %4 = ssub_overflow.(i32, i1) %0, %1"), "{text}");
2558        assert!(text.contains("%5 = trunc.i8 %3"), "narrowed to where it goes: {text}");
2559        assert!(text.contains("%6 = sext.i32 %5"), "and back: {text}");
2560        assert!(text.contains("%7 = icmp ne %6, %3"), "which is whether it fit: {text}");
2561        assert!(text.contains("store %5 -> %2"), "the narrowed value is stored either way: {text}");
2562        assert!(text.contains("%8 = or %4, %7"), "and either bit is an overflow: {text}");
2563    }
2564
2565    /// A call needing more than sixty four bits is refused by name rather than got wrong.
2566    ///
2567    /// Two ways to reach it: a `__int128` operand, and a sixty four bit unsigned type mixed with a
2568    /// signed one, which needs sixty five bits to represent both. gcc handles the second by being
2569    /// cleverer in the mixed case rather than by widening. Until that is written, the message says
2570    /// what the call needed.
2571    #[test]
2572    fn a_call_needing_more_than_sixty_four_bits_says_so() {
2573        let refused = concat!(
2574            "int f(unsigned long long a, long long b, long long *r) {\n",
2575            "    return __builtin_add_overflow(a, b, r);\n",
2576            "}\n",
2577        );
2578        let messages = errors(refused);
2579        assert_eq!(messages.len(), 1, "{messages:?}");
2580        assert!(messages[0].contains("E0694"), "{messages:?}");
2581        assert!(messages[0].contains("wider than 64 bits"), "{messages:?}");
2582    }
2583
2584    /// An operand that is not an integer at all is the older message, from the type checking every
2585    /// type generic builtin shares.
2586    #[test]
2587    fn an_overflow_check_over_something_that_is_not_an_integer_says_so() {
2588        let messages =
2589            errors("int f(double a, int b, int *r) { return __builtin_add_overflow(a, b, r); }\n");
2590        assert!(messages.iter().any(|line| line.contains("E0671")), "{messages:?}");
2591
2592        let messages =
2593            errors("int f(int a, int b, double *r) { return __builtin_add_overflow(a, b, r); }\n");
2594        assert!(messages.iter().any(|line| line.contains("E0671")), "{messages:?}");
2595    }
2596
2597    /// An ordered access is an ordered access in the IR, with the ordering the program wrote.
2598    ///
2599    /// Which is the point of the node existing at all. An ordering is not an argument anything is
2600    /// passed, it is a thing the IR says about an access, so the number in the source is read once
2601    /// in the front end and after that the ordering travels on the instruction where every pass
2602    /// that moves code can see it.
2603    ///
2604    /// SQLite is why these are done: `AtomicLoad` and `AtomicStore` in `sqlite3.c` are
2605    /// `__atomic_load_n` and `__atomic_store_n` at the relaxed ordering, and there are thirty five
2606    /// calls to the pair.
2607    #[test]
2608    fn an_ordered_access_is_ordered_in_the_ir() {
2609        let text = body("int f(int *p) { return __atomic_load_n(p, 0); }\n");
2610        assert!(text.contains("atomic_load.i32 %0, align 4, relaxed"), "{text}");
2611
2612        let text = body("long f(long *p) { return __atomic_load_n(p, 2); }\n");
2613        assert!(text.contains("atomic_load.i64 %0, align 8, acquire"), "{text}");
2614
2615        let text = body("void f(int *p, int v) { __atomic_store_n(p, v, 3); }\n");
2616        assert!(text.contains("atomic_store %1 -> %0, align 4, release"), "{text}");
2617
2618        let text = body("void f(int *p, int v) { __atomic_store_n(p, v, 5); }\n");
2619        assert!(text.contains("atomic_store %1 -> %0, align 4, seq_cst"), "{text}");
2620
2621        // The value is converted to what the pointer points at before it is stored, which is what
2622        // the call would have done if it had a prototype to convert against.
2623        let text = body("void f(char *p, int v) { __atomic_store_n(p, v, 0); }\n");
2624        assert!(text.contains("trunc.i8 %1"), "{text}");
2625        assert!(text.contains("atomic_store %2 -> %0, align 1, relaxed"), "{text}");
2626    }
2627
2628    /// On this machine the ordered access is the plain instruction, except at the strongest
2629    /// ordering of a store.
2630    ///
2631    /// x86-64 is total store order: every load is already an acquire and every store is already a
2632    /// release, and an aligned access no wider than a word is indivisible whether or not anybody
2633    /// asked. So the whole family is `mov` and the one thing the machine does not give away is a
2634    /// store staying in front of a later load, which is `mfence` behind the store. Every line below
2635    /// is what gcc 16.2.0 writes for the same function.
2636    #[test]
2637    fn an_ordered_access_is_the_plain_instruction_on_this_machine() {
2638        let text = asm("int f(int *p) { return __atomic_load_n(p, 5); }\n");
2639        assert!(text.contains("movl\t(%rdi), %eax"), "{text}");
2640        assert!(!text.contains("mfence"), "a load needs no barrier here: {text}");
2641
2642        let text = asm("void f(int *p, int v) { __atomic_store_n(p, v, 3); }\n");
2643        assert!(text.contains("movl\t%esi, (%rdi)"), "{text}");
2644        assert!(!text.contains("mfence"), "a release store needs no barrier here: {text}");
2645
2646        let text = asm("void f(int *p, int v) { __atomic_store_n(p, v, 5); }\n");
2647        let (before, after) = text.split_once("mfence").expect("a barrier: {text}");
2648        assert!(before.contains("movl\t%esi, (%rdi)"), "the store comes first: {text}");
2649        assert!(!after.contains("movl"), "and nothing else is between them: {text}");
2650    }
2651
2652    /// A barrier is one instruction at the strongest ordering and no instruction below it.
2653    ///
2654    /// The same reasoning the other way round. An acquire, a release and an acquire release fence
2655    /// are already true of every program running on this machine, and what a program wanted from
2656    /// one is that the compiler not move accesses across it, which is already so by the time any
2657    /// instruction is picked. Sequential consistency is the one that costs something.
2658    ///
2659    /// `__sync_synchronize` is the older family's spelling of the strongest one and compiles to
2660    /// exactly the same instruction, which is what SQLite calls twice in `sqlite3.c`.
2661    #[test]
2662    fn a_barrier_is_one_instruction_at_the_strongest_ordering_and_none_below_it() {
2663        assert!(asm("void f(void) { __atomic_thread_fence(5); }\n").contains("mfence"));
2664        assert!(asm("void f(void) { __sync_synchronize(); }\n").contains("mfence"));
2665
2666        for weaker in ["1", "2", "3", "4"] {
2667            let source = format!("void f(void) {{ __atomic_thread_fence({weaker}); }}\n");
2668            assert!(!asm(&source).contains("mfence"), "{weaker} costs nothing here");
2669        }
2670    }
2671
2672    /// A memory order an operation cannot carry is read as the strongest one, and said so about.
2673    ///
2674    /// There are three ways the number is not one the operation can take: it is not a constant at
2675    /// all, it is not one of the six the headers define, or it is one of them and means nothing for
2676    /// this operation, which is a release load or an acquire store. All three become sequential
2677    /// consistency, which is stronger than anything the program could have meant, so a program that
2678    /// wrote nonsense gets a correct answer rather than a fast one. gcc does the same.
2679    ///
2680    /// The last two also warn, because the number was written down and is wrong. The first does
2681    /// not: gcc takes a computed order, and so does the C11 spelling, so a warning there would fire
2682    /// on correct programs.
2683    #[test]
2684    fn a_memory_order_an_operation_cannot_carry_is_read_as_the_strongest() {
2685        let mut opts = options();
2686        opts.emit = EmitKind::Ir;
2687
2688        let acquire_store = run(&opts, "void f(int *p, int v) { __atomic_store_n(p, v, 2); }\n");
2689        assert!(acquire_store.text().contains("seq_cst"), "{:?}", acquire_store.text());
2690        assert!(acquire_store.messages[0].contains("[W0333]"), "{:?}", acquire_store.messages);
2691
2692        let nonsense = run(&opts, "int f(int *p) { return __atomic_load_n(p, 99); }\n");
2693        assert!(nonsense.text().contains("seq_cst"), "{:?}", nonsense.text());
2694        assert!(nonsense.messages[0].contains("[W0333]"), "{:?}", nonsense.messages);
2695
2696        let computed = run(&opts, "int f(int *p, int n) { return __atomic_load_n(p, n); }\n");
2697        assert!(computed.text().contains("seq_cst"), "{:?}", computed.text());
2698        assert_eq!(computed.messages, Vec::<String>::new(), "a computed order is not a mistake");
2699    }
2700
2701    /// A conversion between a float and the widest unsigned integer, which the machine has not got.
2702    ///
2703    /// Every other conversion between a float and an integer is the signed one at some width with a
2704    /// widening in front or a narrowing behind. These two are not, because there is no signed width
2705    /// that holds every value of an unsigned sixty four bit integer, so each is the signed
2706    /// conversion with arithmetic around it that brings the value into range and puts it back.
2707    ///
2708    /// What is checked here is that the conversion happens at all and that it happens without a
2709    /// branch. gcc writes a branch for both; this writes the choice as a mask, because every rewrite
2710    /// in that pass stays inside the block it started in. The arithmetic itself is checked in
2711    /// `rucc-codegen`, where it can be run against the answer rather than read in the assembly.
2712    #[test]
2713    fn a_conversion_between_a_float_and_the_widest_unsigned_integer_is_written_without_a_branch() {
2714        let text = asm("double f(unsigned long long x) { return (double)x; }\n");
2715        assert!(text.contains("cvtsi2sdq"), "the signed conversion is what runs: {text}");
2716        assert!(text.contains("shrq"), "with the value halved first: {text}");
2717        assert!(text.contains("addsd"), "and doubled after: {text}");
2718        assert!(!text.contains("\tj"), "and no branch anywhere: {text}");
2719
2720        let text = asm("unsigned long long f(double d) { return (unsigned long long)d; }\n");
2721        assert!(text.contains("cvttsd2siq"), "the signed conversion is what runs: {text}");
2722        assert!(text.contains("subsd"), "with half the range taken off first: {text}");
2723        assert!(text.contains("shlq\t$63"), "and the top bit put back: {text}");
2724        assert!(!text.contains("\tj"), "and no branch anywhere: {text}");
2725    }
2726
2727    /// The plain names are the library's only where nothing else has taken them.
2728    ///
2729    /// Four ways a program says it means something else. A `static` definition is its own
2730    /// function and the name outside the file is somebody else's. A declaration of another type
2731    /// is another function. `-fno-builtin` and `-fno-builtin-<name>` say so outright, and
2732    /// `-ffreestanding` says there is no C library for the name to be the name of. Every one of
2733    /// these was measured against gcc 16.2.0, which calls the program's function in all of them.
2734    ///
2735    /// The `__builtin_` spelling goes on meaning the library's function through all of it, which
2736    /// is what the prefix is for and what lets a freestanding build reach one deliberately.
2737    #[test]
2738    fn a_plain_name_the_program_took_is_the_programs_own_function() {
2739        let taken = concat!(
2740            "static long long llabs(long long b) { return 7; }\n",
2741            "long long f(long long x) { return llabs(x); }\n",
2742        );
2743        assert!(ir(taken).contains("call @llabs"), "a static definition is the program's own");
2744
2745        let retyped = concat!("int llabs(int b);\n", "int f(int x) { return llabs(x); }\n",);
2746        assert!(ir(retyped).contains("call @llabs"), "another type is another function");
2747
2748        let plain = concat!(
2749            "long long llabs(long long b);\n",
2750            "long long f(long long x) { return llabs(x); }\n",
2751        );
2752        let mut opts = options();
2753        opts.emit = EmitKind::Ir;
2754        assert!(!run(&opts, plain).text().contains("call @llabs"), "the library's by default");
2755
2756        opts.builtins = false;
2757        assert!(run(&opts, plain).text().contains("call @llabs"), "-fno-builtin");
2758
2759        opts.builtins = true;
2760        opts.no_builtin = vec!["llabs".to_owned()];
2761        assert!(run(&opts, plain).text().contains("call @llabs"), "-fno-builtin-llabs");
2762        let one = "long labs(long b);\nlong f(long x) { return labs(x); }\n";
2763        assert!(!run(&opts, one).text().contains("call @labs"), "one name and not the family");
2764
2765        // `-ffreestanding` reaches the front end as the same answer, which is what the driver
2766        // does with it in `compile`, and the prefixed spelling is untouched by any of it.
2767        opts.no_builtin = Vec::new();
2768        opts.builtins = false;
2769        let prefixed = "long long f(long long x) { return __builtin_llabs(x); }\n";
2770        assert!(!run(&opts, prefixed).text().contains("call @llabs"), "the prefix is a promise");
2771    }
2772
2773    /// The hint builtins are their first argument, and nothing is left of the hint.
2774    ///
2775    /// Which way a branch is expected to go is the whole of what they say, and there is nothing
2776    /// here that reads a branch weight yet, so what reaches the IR is the value and the hint is
2777    /// gone. The one thing the prototype has to keep doing is converting: gcc gives both of them
2778    /// a `long` result, so `sizeof(__builtin_expect((char)1, 1))` is eight and a narrower argument
2779    /// widens before it is answered with.
2780    ///
2781    /// The arguments after the first are checked and then dropped, so a side effect in one does
2782    /// not happen. That is what gcc does with them too, measured on gcc 16.2.0: the `i` below
2783    /// comes back zero there as well.
2784    #[test]
2785    fn the_hint_builtins_are_their_first_argument_and_the_hint_leaves_no_trace() {
2786        let text = ir(concat!(
2787            "long a = __builtin_expect(7, 1);\n",
2788            "long b = __builtin_expect_with_probability(9, 1, 0.9);\n",
2789            "unsigned long c = sizeof(__builtin_expect((char)1, 1));\n",
2790        ));
2791        assert!(text.contains("global @a : i64 = 7,"), "{text}");
2792        assert!(text.contains("global @b : i64 = 9,"), "{text}");
2793        assert!(text.contains("global @c : i64 = 8,"), "{text}");
2794        assert!(!text.contains("__builtin_expect"), "it is not a call to anything:\n{text}");
2795
2796        // A narrower argument is widened by the prototype before it is handed back, and it is
2797        // widened with its sign, since the parameter is a signed `long`.
2798        let text = body("long f(char c) { return __builtin_expect(c, 1); }\n");
2799        assert!(text.contains("sext"), "{text}");
2800
2801        // The second argument is not evaluated, so `i` is still zero, and neither is the third.
2802        // What is left of each statement is the first argument widened, which nothing reads and
2803        // which the first pass that looks for dead code will take out.
2804        let one = "block0:\n    %0 = iconst.i32 0\n    %1 = iconst.i32 1\n    %2 = sext.i64 %1\n    return %0\n";
2805        assert_eq!(body("int f(void) { int i = 0; __builtin_expect(1, i++); return i; }\n"), one);
2806        let source = "int g(void) { int i = 0; __builtin_expect_with_probability(1, i++, 0.5); return i; }\n";
2807        assert_eq!(body(source), one);
2808    }
2809
2810    /// A point control does not arrive at, in both of the ways the compiler has one.
2811    ///
2812    /// `__builtin_unreachable()` is the promise written down, and a function whose body can run
2813    /// off the bottom is the walk arriving at the same place on its own. Neither writes an
2814    /// instruction, which is what gcc 16.2.0 does at `-O0`: it emits the epilogue and the `ret`
2815    /// for both of the functions below and nothing else, and the two of them come out byte for
2816    /// byte the same there.
2817    ///
2818    /// The `ret` is the part worth holding on to. It is not there because anything runs it, it is
2819    /// there because a function whose last instruction is not a return is one that falls into
2820    /// whatever the assembler puts after it.
2821    #[test]
2822    fn a_promise_that_control_does_not_arrive_writes_no_instruction() {
2823        let promised = "int f(int x) { if (x) return 1; __builtin_unreachable(); }\n";
2824        let text = ir(promised);
2825        assert!(text.contains("    unreachable_hint\n"), "{text}");
2826        assert!(!text.contains("call"), "it is not a call to anything:\n{text}");
2827
2828        // The statement after it is still lowered. Continuing to translate a path the program
2829        // promised is dead is one of the things a compiler may do with undefined behaviour, and
2830        // it is the one that keeps a program built at `-O0` behaving the way it was watched to.
2831        let after = body("int g(int x) { __builtin_unreachable(); return x; }\n");
2832        assert!(after.contains("return"), "{after}");
2833
2834        // Both functions are the same instructions, because the hint writes none of them and the
2835        // terminator underneath it writes none either.
2836        let text = asm(promised);
2837        let mine = text.split_once("\nf:\n").expect("a definition").1;
2838        let mine = mine.split_once("\t.size").expect("a definition").0;
2839        let plain = asm("int f(int x) { if (x) return 1; }\n");
2840        let plain = plain.split_once("\nf:\n").expect("a definition").1;
2841        let plain = plain.split_once("\t.size").expect("a definition").0;
2842        assert_eq!(mine, plain);
2843        assert!(mine.trim_end().ends_with("ret"), "{mine}");
2844        assert!(!mine.contains("ud2"), "{mine}");
2845    }
2846
2847    /// The two names stay apart, which is what having both of them is for.
2848    ///
2849    /// The one the program wrote is what the call is checked against and what a diagnostic about
2850    /// it says, and the one the library defines is what the call ends up carrying. A compiler
2851    /// that kept only the second would report this against `abort`, which is a function the
2852    /// program never mentions.
2853    #[test]
2854    fn a_library_builtin_is_diagnosed_under_the_name_the_program_wrote() {
2855        let mut opts = options();
2856        opts.emit = EmitKind::Ir;
2857        let messages = run(&opts, "void f(void) { __builtin_abort(1); }\n").messages;
2858        assert!(
2859            messages.iter().any(|m| m.contains("__builtin_abort")),
2860            "expected the written name in {messages:?}"
2861        );
2862    }
2863
2864    /// A builtin nothing lowers is refused where it is written, rather than at the link.
2865    ///
2866    /// The names are one from each shape the table holds: a `__builtin_` with a prototype, one
2867    /// whose type comes from the call it was written in, and one from each of the two older
2868    /// families whose prefix is not `__builtin_`. What the message has to carry is the name,
2869    /// because the whole complaint about the link error this replaces is that the name in it was
2870    /// one the compiler chose.
2871    #[test]
2872    fn a_builtin_nothing_lowers_is_refused_by_name() {
2873        let mut opts = options();
2874        opts.emit = EmitKind::Ir;
2875        for (builtin, call) in [
2876            ("__builtin_return_address", "(int)(long)__builtin_return_address(0)"),
2877            ("__builtin_alloca", "(int)(long)__builtin_alloca(8)"),
2878            ("__atomic_exchange_n", "__atomic_exchange_n(&counter, 1, 0)"),
2879            ("__sync_fetch_and_add", "(int)__sync_fetch_and_add(&counter, 1)"),
2880        ] {
2881            let source = format!("int counter;\nint f(void) {{ return {call}; }}\n");
2882            let messages = run(&opts, &source).messages;
2883            let named = messages.iter().any(|m| m.contains(builtin) && m.contains("E0686"));
2884            assert!(named, "expected {builtin} to be refused by name in {messages:?}");
2885        }
2886    }
2887
2888    /// The refusal is about a call and not about the name, so the rest of what C does with one
2889    /// still works.
2890    ///
2891    /// `sizeof` does not evaluate its operand, so nothing is called and there is nothing to
2892    /// refuse; the type of the call is what it asks for and that comes from the front end. A
2893    /// program that defines the name itself gets the function it wrote, which is not what this
2894    /// is for but is what a definition in front of us means.
2895    #[test]
2896    fn what_is_refused_is_the_call_and_not_the_name() {
2897        let text = ir("unsigned long n = sizeof(__builtin_return_address(0));\n");
2898        assert!(text.contains("global @n : i64 = 8,"), "{text}");
2899
2900        let text = ir(concat!(
2901            "void *__builtin_return_address(unsigned x) { return 0; }\n",
2902            "void *f(void) { return __builtin_return_address(0); }\n",
2903        ));
2904        assert!(text.contains("call @__builtin_return_address"), "{text}");
2905    }
2906
2907    /// A `static` function nothing refers to is not emitted, and one that is refered to is.
2908    ///
2909    /// The pair is written as one program so that the two answers come out of one walk. What
2910    /// makes the difference is the call in `main` and nothing else about either definition.
2911    #[test]
2912    fn a_static_function_nothing_refers_to_is_not_emitted() {
2913        let text = ir("static int dropped(void) { return 1; }\n\
2914                       static int kept(void) { return 2; }\n\
2915                       int main(void) { return kept(); }\n");
2916        assert!(text.contains("func @kept"), "{text}");
2917        assert!(!text.contains("dropped"), "{text}");
2918    }
2919
2920    /// The set is transitive, so two of them that only call each other are both dropped.
2921    ///
2922    /// Counting the references to a name would keep this pair, since each is named once, and
2923    /// that is the mistake this is here to catch: what decides it is whether a root reaches the
2924    /// definition, and a root is something the file has a reason to emit on its own.
2925    #[test]
2926    fn two_static_functions_that_only_call_each_other_are_both_dropped() {
2927        let text = ir("static int ping(void);\n\
2928                       static int pong(void) { return ping(); }\n\
2929                       static int ping(void) { return pong(); }\n\
2930                       int main(void) { return 0; }\n");
2931        assert!(!text.contains("ping"), "{text}");
2932        assert!(!text.contains("pong"), "{text}");
2933    }
2934
2935    /// Everything that names a function keeps it, whether or not the name is being called.
2936    ///
2937    /// An address taken in a body, an image that holds one, and a body that is only reached
2938    /// through another `static` function are three different ways for a definition to be needed
2939    /// and none of them is a call at the top level of a reachable function.
2940    #[test]
2941    fn naming_a_static_function_anywhere_keeps_it() {
2942        let text = ir("static int by_address(void) { return 1; }\n\
2943                       static int in_an_image(void) { return 2; }\n\
2944                       static int deeper(void) { return 3; }\n\
2945                       static int reaches_deeper(void) { return deeper(); }\n\
2946                       static int (*table[1])(void) = {in_an_image};\n\
2947                       int main(void) {\n\
2948                         int (*p)(void) = by_address;\n\
2949                         return p() + table[0]() + reaches_deeper();\n\
2950                       }\n");
2951        for kept in ["by_address", "in_an_image", "deeper", "reaches_deeper"] {
2952            assert!(text.contains(&format!("func @{kept}")), "expected {kept} in:\n{text}");
2953        }
2954    }
2955
2956    /// An attribute that says something outside the file reaches it keeps the definition.
2957    ///
2958    /// None of the five is implemented as anything else yet, and this is the part of each of
2959    /// them that a program notices first: a symbol a linker script names or a function the
2960    /// run-up to `main` calls is not written about anywhere a C file can see.
2961    #[test]
2962    fn an_attribute_keeps_a_static_function_nothing_refers_to() {
2963        for attribute in ["used", "retain", "constructor", "destructor", "__used__"] {
2964            let source = format!(
2965                "__attribute__(({attribute})) static int kept(void) {{ return 1; }}\n\
2966                 int main(void) {{ return 0; }}\n"
2967            );
2968            let text = ir(&source);
2969            assert!(text.contains("func @kept"), "for {attribute}:\n{text}");
2970        }
2971    }
2972
2973    /// A function with external linkage is emitted whatever this file does with it, because
2974    /// another one may call it, and that is what external linkage is.
2975    #[test]
2976    fn a_function_anything_could_call_is_emitted_without_being_called() {
2977        let text =
2978            ir("int nobody_here_calls_it(void) { return 1; }\nint main(void) { return 0; }\n");
2979        assert!(text.contains("func @nobody_here_calls_it"), "{text}");
2980    }
2981
2982    /// Four of the classification builtins are operators C already has, and become those.
2983    ///
2984    /// What the standard's macro promises over the operator is that it does not raise the
2985    /// invalid operation exception on a quiet NaN. This compiler does not model floating point
2986    /// exceptions, so there is nothing left for a node of its own to carry and a second way of
2987    /// spelling a comparison would be a second thing every pass has to know about.
2988    #[test]
2989    fn a_classification_c_has_an_operator_for_is_that_operator() {
2990        for (builtin, operator) in [
2991            ("__builtin_isgreater", "binary >"),
2992            ("__builtin_isgreaterequal", "binary >="),
2993            ("__builtin_isless", "binary <"),
2994            ("__builtin_islessequal", "binary <="),
2995        ] {
2996            let source = format!("int f(double x, double y) {{ return {builtin}(x, y); }}\n");
2997            let text = tast(&source);
2998            assert!(text.contains(&format!("{operator} : int")), "for {builtin}:\n{text}");
2999        }
3000    }
3001
3002    /// The rest of the family are comparisons in the IR and never a call to anything.
3003    ///
3004    /// `math.h` defines the macro of each of these names as the builtin of the same name, so
3005    /// there is no function under any of them for a call to reach. `isunordered` and
3006    /// `islessgreater` are predicates the IR's comparison already has, `isnan` is the value that
3007    /// is unordered with itself, and the two that ask about a magnitude are written against the
3008    /// infinities. `signbit` is the one that is not a question about the value, since a negative
3009    /// zero compares equal to a positive one, so its answer comes from the bits.
3010    #[test]
3011    fn the_classification_builtins_are_comparisons_and_not_calls() {
3012        let text = body("int f(double x, double y) { return __builtin_isunordered(x, y); }\n");
3013        assert_eq!(
3014            text,
3015            "block0(%0: f64, %1: f64):\n    %2 = fcmp uno %0, %1\n    %3 = zext.i32 \
3016                          %2\n    return %3\n"
3017        );
3018
3019        // Not `x != y`, which is true when the two are unordered and so is true of a NaN.
3020        let text = body("int f(double x, double y) { return __builtin_islessgreater(x, y); }\n");
3021        assert!(text.contains("fcmp one %0, %1"), "{text}");
3022
3023        let text = body("int f(double x) { return __builtin_isnan(x); }\n");
3024        assert!(text.contains("fcmp uno %0, %0"), "{text}");
3025
3026        let text = body("int f(double x) { return __builtin_isinf(x); }\n");
3027        assert!(text.contains("fconst.f64 0x7ff0000000000000"), "{text}");
3028        assert!(text.contains("fconst.f64 0xfff0000000000000"), "{text}");
3029        assert!(text.contains("%3 = fcmp oeq %0, %1"), "{text}");
3030        assert!(text.contains("%4 = fcmp oeq %0, %2"), "{text}");
3031        assert!(text.contains("%5 = or %3, %4"), "{text}");
3032
3033        // Strictly between the two infinities, which a NaN is not, because an ordered comparison
3034        // against either of them is false. That is what makes this one test rather than two.
3035        let text = body("int f(double x) { return __builtin_isfinite(x); }\n");
3036        assert!(text.contains("%3 = fcmp olt %2, %0"), "{text}");
3037        assert!(text.contains("%4 = fcmp olt %0, %1"), "{text}");
3038        assert!(text.contains("%5 = and %3, %4"), "{text}");
3039
3040        let text = body("int f(double x) { return __builtin_signbit(x); }\n");
3041        assert!(text.contains("%1 = bitcast.i64 %0"), "{text}");
3042        assert!(text.contains("icmp slt %1, %2"), "{text}");
3043
3044        // The same question of a value in the target's widest format, where the bits are eighty
3045        // and the object they sit in is sixteen bytes.
3046        let text = body("int f(long double x) { return __builtin_signbitl(x); }\n");
3047        assert!(text.contains("%1 = bitcast.i80 %0"), "{text}");
3048
3049        // The operand is evaluated once however many times it is compared, which is the whole
3050        // reason these are nodes rather than a rewriting into the operators.
3051        let text = body("double g(void);\nint f(void) { return __builtin_isnan(g()); }\n");
3052        assert_eq!(text.matches("call @g()").count(), 1, "{text}");
3053    }
3054
3055    /// A spelling that names a width converts its argument before it asks.
3056    ///
3057    /// gcc gives `__builtin_isinff` a `float` parameter and `__builtin_isinf` no parameter type
3058    /// at all, and the difference is visible rather than academic: `1e300` does not fit in a
3059    /// `float`, so converting it first is an infinity and not converting it is not. Both numbers
3060    /// here are what gcc 16 gives.
3061    #[test]
3062    fn a_classification_spelling_that_names_a_width_converts_before_it_asks() {
3063        let text = ir(concat!(
3064            "int a = __builtin_isinff(1e300);\n",
3065            "int b = __builtin_isinf(1e300);\n",
3066            // Folded here rather than compared at run time, because a question about a value has
3067            // an answer as soon as the value is a constant, and an initializer for an object
3068            // with static storage duration has to have one.
3069            "int c = __builtin_isnan(0.0);\n",
3070            "int d = __builtin_signbit(-0.0);\n",
3071            "int e = __builtin_islessgreater(1.0, 2.0);\n",
3072        ));
3073        assert!(text.contains("global @a : i32 = 1,"), "{text}");
3074        assert!(text.contains("global @b : i32 = 0,"), "{text}");
3075        assert!(text.contains("global @c : i32 = 0,"), "{text}");
3076        assert!(text.contains("global @d : i32 = 1,"), "{text}");
3077        assert!(text.contains("global @e : i32 = 1,"), "{text}");
3078    }
3079
3080    /// An argument that is not floating point is refused, in gcc's words.
3081    #[test]
3082    fn a_classification_builtin_refuses_an_argument_that_is_not_floating_point() {
3083        let mut opts = options();
3084        opts.emit = EmitKind::Ir;
3085        let source = concat!(
3086            "int a(int x) { return __builtin_isnan(x); }\n",
3087            "int b(int x, int y) { return __builtin_isunordered(x, y); }\n",
3088            "int c(double x) { return __builtin_isnan(x, x); }\n",
3089        );
3090        let messages = run(&opts, source).messages;
3091        assert_eq!(
3092            messages,
3093            [
3094                "/main.c:1:23: error: non-floating-point argument in call to function \
3095                 '__builtin_isnan' [E0685]",
3096                "/main.c:2:30: error: non-floating-point arguments in call to function \
3097                 '__builtin_isunordered' [E0685]",
3098                "/main.c:3:26: error: too many arguments to function '__builtin_isnan' [E0511]",
3099            ]
3100        );
3101    }
3102
3103    /// The three of the family that need a constant of the format other than an infinity.
3104    ///
3105    /// `isnormal` is the one that needs the smallest normal, and it is asked of the magnitude, so
3106    /// the sign comes off first and what is left is the same shape as `isfinite`. `isinf_sign` is
3107    /// the one whose answer is a number: the two comparisons `isinf` builds, subtracted rather
3108    /// than combined. `fpclassify` is four questions of one value and five answers to pick from,
3109    /// and the picking is a mask because all five are constants and neither of them can have an
3110    /// effect.
3111    #[test]
3112    fn the_last_three_classification_builtins_are_comparisons_and_not_calls() {
3113        let text = body("int f(double x) { return __builtin_isnormal(x); }\n");
3114        // The sign off, which is the magnitude, and then the range, asked of the bits rather than
3115        // of the number, since the encoding of a value whose sign bit is clear rises with the
3116        // value in every format this compiles for.
3117        assert!(text.contains("%1 = bitcast.i64 %0"), "{text}");
3118        assert!(text.contains("%2 = iconst.i64 9223372036854775807"), "{text}");
3119        assert!(text.contains("%3 = and %1, %2"), "{text}");
3120        assert!(text.contains("%4 = iconst.i64 4503599627370496"), "{text}");
3121        assert!(text.contains("%5 = iconst.i64 9218868437227405312"), "{text}");
3122        assert!(text.contains("%6 = icmp uge %3, %4"), "{text}");
3123        assert!(text.contains("%7 = icmp ult %3, %5"), "{text}");
3124        assert!(text.contains("%8 = and %6, %7"), "{text}");
3125
3126        // The same question in the target's widest format, where the smallest normal has the
3127        // leading significand bit stored rather than implied, so its encoding is two bits and not
3128        // one.
3129        let text = body("int f(long double x) { return __builtin_isnormal(x); }\n");
3130        assert!(text.contains("%4 = iconst.i80 27670116110564327424"), "{text}");
3131        assert!(text.contains("%5 = iconst.i80 604453686435277732577280"), "{text}");
3132
3133        let text = body("int f(double x) { return __builtin_isinf_sign(x); }\n");
3134        assert!(text.contains("%3 = fcmp oeq %0, %1"), "{text}");
3135        assert!(text.contains("%4 = fcmp oeq %0, %2"), "{text}");
3136        assert!(text.contains("%7 = sub %5, %6"), "{text}");
3137
3138        let text = body("int f(double x) { return __builtin_fpclassify(0, 1, 2, 3, 4, x); }\n");
3139        assert!(text.contains("fcmp uno %0, %0"), "{text}");
3140        assert!(text.contains("fcmp oeq %0, %6"), "{text}");
3141        // Four questions, each of them a bit widened into the type of the answer and then spread
3142        // into a mask that picks between the answer and whatever the questions after it settled
3143        // on. Nothing sign extends, because no rule lowers a sign extension out of one bit.
3144        assert_eq!(text.matches(" = zext.i32 ").count(), 4, "{text}");
3145        assert_eq!(text.matches(" = xor ").count(), 4, "{text}");
3146        assert!(!text.contains("call"), "{text}");
3147
3148        // The value is evaluated once however many questions are asked of it, which is the whole
3149        // reason `fpclassify` is a node rather than the chain of tests it turns into.
3150        let text = body(concat!(
3151            "double g(void);\n",
3152            "int f(void) { return __builtin_fpclassify(0, 1, 2, 3, 4, g()); }\n",
3153        ));
3154        assert_eq!(text.matches("call @g()").count(), 1, "{text}");
3155    }
3156
3157    /// Each of the three answers a constant where its operand is one.
3158    ///
3159    /// glibc's `fpclassify` macro is exactly this builtin, so a program that writes
3160    /// `fpclassify(0.0)` in a static initializer is writing this, and it has to have a value at
3161    /// translation time or the program is refused rather than merely compiled slowly. Every
3162    /// number here is what gcc 16 gives.
3163    #[test]
3164    fn the_last_three_classification_builtins_fold_where_their_operand_is_a_constant() {
3165        let text = ir(concat!(
3166            "int a = __builtin_isnormal(1.0);\n",
3167            "int b = __builtin_isnormal(0.0);\n",
3168            "int c = __builtin_isnormal(1.0 / 0.0);\n",
3169            "int d = __builtin_isinf_sign(-1.0 / 0.0);\n",
3170            "int e = __builtin_isinf_sign(1.0);\n",
3171            "int g = __builtin_fpclassify(0, 1, 2, 3, 4, 0.0);\n",
3172            "int h = __builtin_fpclassify(0, 1, 2, 3, 4, 1.0);\n",
3173            "int i = __builtin_fpclassify(0, 1, 2, 3, 4, 1.0 / 0.0);\n",
3174        ));
3175        assert!(text.contains("global @a : i32 = 1,"), "{text}");
3176        assert!(text.contains("global @b : i32 = 0,"), "{text}");
3177        assert!(text.contains("global @c : i32 = 0,"), "{text}");
3178        assert!(text.contains("global @d : i32 = -1,"), "{text}");
3179        assert!(text.contains("global @e : i32 = 0,"), "{text}");
3180        assert!(text.contains("global @g : i32 = 4,"), "{text}");
3181        assert!(text.contains("global @h : i32 = 2,"), "{text}");
3182        assert!(text.contains("global @i : i32 = 1,"), "{text}");
3183    }
3184
3185    /// `fpclassify` refuses what gcc refuses, in gcc's words.
3186    ///
3187    /// The five answers have to be integer constant expressions, because what the builtin does is
3188    /// pick one of them and a pick between values that are not known here would be a chain of
3189    /// conditionals over expressions the call has already evaluated.
3190    #[test]
3191    fn fpclassify_refuses_an_answer_that_is_not_an_integer_constant() {
3192        let mut opts = options();
3193        opts.emit = EmitKind::Ir;
3194        let source = concat!(
3195            "int a(double x, int n) { return __builtin_fpclassify(0, 1, n, 3, 4, x); }\n",
3196            "int b(double x) { return __builtin_fpclassify(0, 1, 2, 3, x); }\n",
3197            "int c(int x) { return __builtin_fpclassify(0, 1, 2, 3, 4, x); }\n",
3198        );
3199        let messages = run(&opts, source).messages;
3200        assert_eq!(
3201            messages,
3202            [
3203                "/main.c:1:60: error: non-const integer argument 3 in call to function \
3204                 '__builtin_fpclassify' [E0687]",
3205                "/main.c:2:26: error: too few arguments to function '__builtin_fpclassify' \
3206                 [E0511]",
3207                "/main.c:3:23: error: non-floating-point argument in call to function \
3208                 '__builtin_fpclassify' [E0685]",
3209            ]
3210        );
3211    }
3212
3213    /// A builtin whose answer is a constant is one, and is not a call to the library.
3214    ///
3215    /// This is the reason the family is answered in the front end at all. `double x =
3216    /// __builtin_inf();` at file scope initializes an object with static storage duration, so
3217    /// there is no point in the program at which a call could be made, and a compiler that
3218    /// lowered it to one would reject a program gcc accepts. Every number here is the encoding
3219    /// gcc 16 gives on x86-64.
3220    #[test]
3221    fn a_builtin_whose_answer_is_a_constant_is_one_and_not_a_call() {
3222        let text = ir(concat!(
3223            "double a = __builtin_inf();\n",
3224            "float b = __builtin_huge_valf();\n",
3225            "long double c = __builtin_infl();\n",
3226            "double d = __builtin_huge_val();\n",
3227        ));
3228        assert!(text.contains("global @a : f64 = 0x7ff0000000000000,"), "{text}");
3229        assert!(text.contains("global @b : f32 = 0x7f800000,"), "{text}");
3230        assert!(text.contains("f80 0x7fff8000000000000000"), "{text}");
3231        assert!(text.contains("global @d : f64 = 0x7ff0000000000000,"), "{text}");
3232        assert!(!text.contains("call"), "{text}");
3233    }
3234
3235    /// A nan is written with the payload the program asked for.
3236    ///
3237    /// The string is read the way `strtoull` reads a number, which is what the library function
3238    /// of the same name does with it, and a string that is not one at all leaves the call for the
3239    /// library to answer at run time. A quiet nan has the high fraction bit set and a signalling
3240    /// one does not, except that a signalling nan with nothing in it would be an infinity, so it
3241    /// gets the next bit down instead. Every encoding here was measured against gcc 16, the two
3242    /// `long double` ones on a machine with the x87 format.
3243    #[test]
3244    fn a_nan_is_written_with_the_payload_the_program_asked_for() {
3245        let text = ir(concat!(
3246            "double a = __builtin_nan(\"\");\n",
3247            "double b = __builtin_nan(\"0x1\");\n",
3248            // Octal, since there is a leading zero, so this is eight and not ten.
3249            "double c = __builtin_nan(\"010\");\n",
3250            "double d = __builtin_nans(\"\");\n",
3251            "double e = __builtin_nans(\"0x1\");\n",
3252            "float f = __builtin_nanf(\"0x1\");\n",
3253            "float g = __builtin_nansf(\"\");\n",
3254            "long double h = __builtin_nansl(\"\");\n",
3255        ));
3256        assert!(text.contains("global @a : f64 = 0x7ff8000000000000,"), "{text}");
3257        assert!(text.contains("global @b : f64 = 0x7ff8000000000001,"), "{text}");
3258        assert!(text.contains("global @c : f64 = 0x7ff8000000000008,"), "{text}");
3259        assert!(text.contains("global @d : f64 = 0x7ff4000000000000,"), "{text}");
3260        assert!(text.contains("global @e : f64 = 0x7ff0000000000001,"), "{text}");
3261        assert!(text.contains("global @f : f32 = 0x7fc00001,"), "{text}");
3262        assert!(text.contains("global @g : f32 = 0x7fa00000,"), "{text}");
3263        assert!(text.contains("f80 0x7fffa000000000000000"), "{text}");
3264
3265        // A payload that is not a number, and one that is not known until run time, are both
3266        // left to the library, which is the same thing gcc emits for either of them.
3267        let text = ir(concat!(
3268            "double f(const char *p) { return __builtin_nan(p); }\n",
3269            "double g(void) { return __builtin_nans(\"1x\"); }\n",
3270        ));
3271        assert_eq!(text.matches("call @nan(").count(), 1, "{text}");
3272        assert_eq!(text.matches("call @nans(").count(), 1, "{text}");
3273    }
3274
3275    /// The length and the order of a string literal are known here.
3276    ///
3277    /// A program that asks for either of them is asking about something the translation already
3278    /// has in front of it, and folding is not only an optimization: `execute/921007-1.c` in the
3279    /// torture suite calls `__builtin_strcmp` in a file that defines its own `strcmp` with a
3280    /// different signature, so leaving the call behind is a name collision that gcc does not
3281    /// have. The comparison is over `unsigned char`, which is why the second one is negative.
3282    #[test]
3283    fn the_length_and_the_order_of_a_string_literal_are_known_here() {
3284        let text = ir(concat!(
3285            "unsigned long a = __builtin_strlen(\"hello\");\n",
3286            "unsigned long b = __builtin_strlen(\"a\\0bc\");\n",
3287            "int c = __builtin_strcmp(\"X\", \"X\\376\") < 0;\n",
3288            "int d = __builtin_strcmp(\"abc\", \"abc\");\n",
3289            "int e = __builtin_strcmp(\"abc\", \"ab\") > 0;\n",
3290        ));
3291        assert!(text.contains("global @a : i64 = 5,"), "{text}");
3292        assert!(text.contains("global @b : i64 = 1,"), "{text}");
3293        assert!(text.contains("global @c : i32 = 1,"), "{text}");
3294        assert!(text.contains("global @d : i32 = 0,"), "{text}");
3295        assert!(text.contains("global @e : i32 = 1,"), "{text}");
3296        assert!(!text.contains("call"), "{text}");
3297
3298        // An argument that is not a literal is the library's to answer, as it has to be.
3299        let text = ir("unsigned long f(const char *p) { return __builtin_strlen(p); }\n");
3300        assert!(text.contains("call @strlen("), "{text}");
3301    }
3302
3303    /// A sign builtin is a mask over the bits, and is not a call.
3304    ///
3305    /// `fabs` and `copysign` are in the math library rather than the C one, so a program that
3306    /// only ever wrote the prefixed spelling never asked for `-lm` and a call left behind here
3307    /// would not link. Neither needs anything the library has: one clears the sign bit and the
3308    /// other takes it from the second operand, and every other bit goes through untouched.
3309    #[test]
3310    fn a_sign_builtin_is_a_mask_over_the_bits_and_not_a_call() {
3311        let text = body("double f(double x) { return __builtin_fabs(x); }\n");
3312        assert!(text.contains("bitcast.i64 %0"), "{text}");
3313        assert!(text.contains("iconst.i64 9223372036854775807"), "{text}");
3314        assert!(text.contains("and %1, %2"), "{text}");
3315        assert!(text.contains("bitcast.f64 %3"), "{text}");
3316        assert!(!text.contains("call"), "{text}");
3317
3318        let text = body("double f(double x, double y) { return __builtin_copysign(x, y); }\n");
3319        assert!(text.contains("iconst.i64 -9223372036854775808"), "{text}");
3320        assert!(text.contains("%8 = or %4, %7"), "{text}");
3321        assert!(!text.contains("call"), "{text}");
3322
3323        // The x87 format, whose value is eighty bits sitting in an object of sixteen. The mask is
3324        // as wide as the value and not as wide as the object, so the padding is not part of it.
3325        let text = body("long double f(long double x) { return __builtin_fabsl(x); }\n");
3326        assert!(text.contains("bitcast.i80 %0"), "{text}");
3327        assert!(text.contains("bitcast.f80"), "{text}");
3328
3329        // The width a name does not spell out is `double`, so a `float` argument widens first and
3330        // the answer is a `double`, which is what gcc's declaration of it says.
3331        let text = body("double f(float x) { return __builtin_fabs(x); }\n");
3332        assert!(text.contains("fpext.f64 %0"), "{text}");
3333        assert!(text.contains("bitcast.i64 %1"), "{text}");
3334    }
3335
3336    /// The sign builtins answer a zero and a nan the way the bits say.
3337    ///
3338    /// This is why they are described over the bits rather than written with comparisons and
3339    /// negation. A negative zero compares equal to a positive one and has a sign bit to clear,
3340    /// and a nan compares equal to nothing at all and keeps its payload through both operations.
3341    /// `execute/ieee/copysign1.c` in the torture suite is the test that notices, because it
3342    /// compares its answers with `memcmp`. Every number here is what gcc 16 gives, the two in the
3343    /// x87 format measured on a machine that has it.
3344    #[test]
3345    fn the_sign_builtins_answer_a_zero_and_a_nan_the_way_the_bits_say() {
3346        let text = ir(concat!(
3347            "double a = __builtin_fabs(-3.5);\n",
3348            "double b = __builtin_copysign(1.0, -0.0);\n",
3349            "double c = __builtin_copysign(0.0, -2.0);\n",
3350            // The payload survives both, and only the sign bit moves.
3351            "double d = __builtin_copysign(-__builtin_nan(\"\"), 1.0);\n",
3352            "double e = __builtin_fabs(-__builtin_nan(\"0x1\"));\n",
3353            "float g = __builtin_copysignf(-0.0f, 2.0f);\n",
3354            "long double h = __builtin_copysignl(1.0L, -1.0L);\n",
3355            "long double i = __builtin_fabsl(-__builtin_infl());\n",
3356        ));
3357        assert!(text.contains("global @a : f64 = 0x400c000000000000,"), "{text}");
3358        assert!(text.contains("global @b : f64 = 0xbff0000000000000,"), "{text}");
3359        assert!(text.contains("global @c : f64 = 0x8000000000000000,"), "{text}");
3360        assert!(text.contains("global @d : f64 = 0x7ff8000000000000,"), "{text}");
3361        assert!(text.contains("global @e : f64 = 0x7ff8000000000001,"), "{text}");
3362        assert!(text.contains("global @g : f32 = 0x0,"), "{text}");
3363        assert!(text.contains("f80 0xbfff8000000000000000"), "{text}");
3364        assert!(text.contains("f80 0x7fff8000000000000000"), "{text}");
3365    }
3366
3367    /// A `constexpr` object is a named constant, which is the whole reason the keyword exists.
3368    ///
3369    /// C23 6.6p8 puts two of them on the list an integer constant expression is built from: one
3370    /// of an arithmetic type, and a member of one of a structure or union type. A subscript of
3371    /// one is not on the list and is a variably modified type in gcc 16 as well, and every
3372    /// number here is what gcc 16 gives on x86-64.
3373    #[test]
3374    fn a_constexpr_object_is_a_constant_wherever_one_is_required() {
3375        let text = ir(concat!(
3376            "constexpr int side = 4;\n",
3377            "constexpr int wider = side + 1;\n",
3378            "constexpr double half = 1.5;\n",
3379            "struct point { int x; int y; };\n",
3380            "constexpr struct point origin = { 5, 6 };\n",
3381            "int square[side * side];\n",
3382            "int rectangle[wider];\n",
3383            "int rounded[(int)half * 2];\n",
3384            "int across[origin.y];\n",
3385            "enum named { four = side };\n",
3386            "int e = four;\n",
3387        ));
3388        assert!(text.contains("global @square : bytes 64 ="), "{text}");
3389        assert!(text.contains("global @rectangle : bytes 20 ="), "{text}");
3390        assert!(text.contains("global @rounded : bytes 8 ="), "{text}");
3391        assert!(text.contains("global @across : bytes 24 ="), "{text}");
3392        assert!(text.contains("global @e : i32 = 4,"), "{text}");
3393
3394        // A `const` object is not one of them, which is what makes `int a[n];` a variable
3395        // length array in C and is the distinction the keyword was added to draw.
3396        let mut opts = options();
3397        opts.emit = EmitKind::Ir;
3398        let konst = "const int n = 1;\nint a[n];\n";
3399        let message = "/main.c:2:5: error: variably modified 'a' at file scope [E0538]";
3400        assert_eq!(run(&opts, konst).messages, [message]);
3401
3402        // Nor is a subscript of one, which gcc 16 refuses in the same words.
3403        let subscript = "constexpr int t[3] = { 1, 2, 3 };\nint a[t[1]];\n";
3404        assert_eq!(run(&opts, subscript).messages, [message]);
3405
3406        // And `constexpr` implies `const`, so the address of one is an address of a `const`.
3407        let address = "constexpr int c = 3;\nint *p = &c;\n";
3408        let warning = "/main.c:2:6: warning: initialization discards 'const' qualifier from \
3409             pointer target type [E0514]";
3410        assert_eq!(run(&opts, address).messages, [warning]);
3411    }
3412
3413    /// A definition that names its parameters and then declares them under the list.
3414    ///
3415    /// The declarations say what the types are, 6.9.1p6, and what the function takes is those
3416    /// types with the default argument promotions over them, which is what a caller of an
3417    /// unprototyped function hands over. A prototype already in scope overrules the promoted
3418    /// types, since a header saying `int narrow(char);` over a definition written this way is
3419    /// the pairing all the code written this way relies on and 6.7.6.3p15 is read that way by
3420    /// every compiler.
3421    #[test]
3422    fn an_old_style_definition_takes_its_types_from_the_declarations_under_its_list() {
3423        // C17, since the default dialect is the one that warns about the form and this is
3424        // about what it means rather than about the warning.
3425        let mut opts = options();
3426        opts.std = Std::C17;
3427        let source = concat!(
3428            "int add(a, b)\n",
3429            "int a;\n",
3430            "int b;\n",
3431            "{ return a + b; }\n",
3432            "int promoted(c)\n",
3433            "char c;\n",
3434            "{ return c; }\n",
3435            "int narrow(char);\n",
3436            "int narrow(c)\n",
3437            "char c;\n",
3438            "{ return c; }\n",
3439            "int first(a)\n",
3440            "int a[4];\n",
3441            "{ return a[0]; }\n",
3442        );
3443        let result = run(&opts, source);
3444        assert_eq!(result.messages, Vec::<String>::new(), "expected this to compile:\n{source}");
3445        let text = result.text();
3446        assert!(text.contains("add : int(int, int) function external defined"), "{text}");
3447        assert!(text.contains("promoted : int(int) function external defined"), "{text}");
3448        // The body still sees the `char` it was declared as, whatever the caller hands over.
3449        assert!(text.contains("c : char object automatic defined"), "{text}");
3450        assert!(text.contains("narrow : int(char) function external defined"), "{text}");
3451        // An array parameter is a pointer here as much as it is in a prototype.
3452        assert!(text.contains("first : int(int *) function external defined"), "{text}");
3453    }
3454
3455    /// What the two halves of an old-style parameter list can disagree about.
3456    ///
3457    /// Each of these is a sentence gcc 16 has, and every message below is the one it prints,
3458    /// read off it on x86-64 rather than reasoned about. The last two are the dialect: a name
3459    /// with no declaration is an `int` in C89 and a diagnostic from C99 on, and the whole form
3460    /// left the language in C23, where gcc still takes it and warns.
3461    #[test]
3462    fn the_two_halves_of_an_old_style_parameter_list_have_to_agree() {
3463        let mut opts = options();
3464        opts.std = Std::C17;
3465        for (source, message) in [
3466            ("int f(a, a)\nint a;\n{ return a; }\n", "1:10: error: multiple parameters named 'a'"),
3467            (
3468                "int f(a)\nint a;\nint b;\n{ return a; }\n",
3469                "3:5: error: declaration for parameter 'b' but no such parameter",
3470            ),
3471            ("int f(a)\nint a;\nint a;\n{ return a; }\n", "3:5: error: redefinition of parameter"),
3472            ("int f(a)\nint a = 1;\n{ return a; }\n", "2:5: error: parameter 'a' is initialized"),
3473            (
3474                "int f(a)\nstatic int a;\n{ return a; }\n",
3475                "2:12: error: storage class specified for parameter 'a'",
3476            ),
3477            (
3478                "int f(char);\nint f(a)\nshort a;\n{ return a; }\n",
3479                "2:7: error: argument 'a' doesn't match prototype",
3480            ),
3481        ] {
3482            let result = run(&opts, source);
3483            assert!(result.failed(), "expected this to fail:\n{source}");
3484            assert!(result.messages[0].contains(message), "{:?}", result.messages);
3485        }
3486
3487        // A name the declarations never mention. C89 gave it an `int` and gcc still takes it
3488        // in that dialect, and every dialect after it made the same line a diagnostic.
3489        let implicit = "int f(a, b)\nint a;\n{ return a + b; }\n";
3490        let mut older = options();
3491        older.std = Std::C89;
3492        assert!(!run(&older, implicit).failed(), "{:?}", run(&older, implicit).messages);
3493        let result = run(&opts, implicit);
3494        assert!(
3495            result.messages[0].contains("1:10: error: type of 'b' defaults to 'int'"),
3496            "{:?}",
3497            result.messages
3498        );
3499
3500        // C23 took the form out of the language and gcc kept accepting it with a warning, and
3501        // a warning is what this is, because the code written this way is not going to be
3502        // rewritten and refusing it would put the compiler out of reach of it.
3503        let mut newer = options();
3504        newer.std = Std::C23;
3505        let plain = "int f(a)\nint a;\n{ return a; }\n";
3506        let result = run(&newer, plain);
3507        assert!(!result.failed(), "{:?}", result.messages);
3508        assert_eq!(
3509            result.messages,
3510            ["/main.c:1:5: warning: old-style function definition [E0412]"]
3511        );
3512        assert!(run(&opts, plain).messages.is_empty(), "and nothing to say in the dialects before");
3513    }
3514
3515    /// A type nothing is ever an object of is a type `sizeof` still has to answer about, which
3516    /// is what `991014-1.c` in the gcc.c-torture execution suite asks.
3517    ///
3518    /// The limit is `PTRDIFF_MAX` and it is the same one for an array and for a record, so a
3519    /// record of every byte an object may have is laid out and one byte more is refused. All
3520    /// four numbers are what gcc 16 gives on x86-64.
3521    #[test]
3522    fn a_type_is_refused_when_it_passes_the_largest_object_and_not_before() {
3523        let text = ir(concat!(
3524            "struct huge_struct { short buf[(1L << 62) - 256]; int a, b, c, d; };\n",
3525            "struct brim { char buf[9223372036854775807L]; };\n",
3526            "struct bitty { char buf[9223372036854775800L]; int x : 1; };\n",
3527            "unsigned long h = sizeof(struct huge_struct);\n",
3528            "unsigned long b = sizeof(struct brim);\n",
3529            "unsigned long y = sizeof(struct bitty);\n",
3530        ));
3531        assert!(text.contains("global @h : i64 = 9223372036854775312,"), "{text}");
3532        assert!(text.contains("global @b : i64 = 9223372036854775807,"), "{text}");
3533        assert!(text.contains("global @y : i64 = 9223372036854775804,"), "{text}");
3534
3535        let mut opts = options();
3536        opts.emit = EmitKind::Ir;
3537        let over = "struct over { char buf[9223372036854775800L]; char x[8]; };\n";
3538        let message = "/main.c:1:1: error: type 'struct over' is too large [E0560]";
3539        assert_eq!(run(&opts, over).messages, [message]);
3540        let array = "struct wide { short buf[1L << 62]; };\n";
3541        let message = "/main.c:1:25: error: size of array 'buf' exceeds \
3542             maximum object size '9223372036854775807' [E0537]";
3543        assert_eq!(run(&opts, array).messages[0], message);
3544    }
3545
3546    /// A byte in the source that is not part of a character, which only a literal may hold.
3547    ///
3548    /// The source cannot be a `&str` here, which is the whole point: a file is bytes and only
3549    /// mostly text.
3550    fn compile_bytes(source: &[u8]) -> Compiled {
3551        let mut opts = options();
3552        opts.emit = EmitKind::Ir;
3553        let mut fs = MemoryFileSystem::new();
3554        fs.insert("/main.c", source.to_vec());
3555        compile(&opts, "/main.c", &fs)
3556    }
3557
3558    /// A raw byte inside a string literal is that byte, which gcc has always taken and which is
3559    /// the only place in a source file where a byte does not have to be part of a character.
3560    /// Replacing it would give the object three bytes rather than one, since the replacement
3561    /// character is three bytes of UTF-8, so the object would not be the one that was written
3562    /// even where the diagnostic is ignored. Anywhere else the byte is still a mistake, which
3563    /// is where gcc draws the same line.
3564    #[test]
3565    fn a_byte_that_is_not_a_character_is_kept_in_a_literal_and_refused_outside_one() {
3566        let mut source = b"char s[] = \"a".to_vec();
3567        source.push(0xff);
3568        source.extend_from_slice(b"b\";\nchar c = '");
3569        source.push(0xff);
3570        source.extend_from_slice(b"';\n");
3571        let result = compile_bytes(&source);
3572        assert_eq!(result.messages, Vec::<String>::new(), "a raw byte in a literal is that byte");
3573        assert!(result.text().contains(r#"bytes "a\ffb\00""#), "{}", result.text());
3574        // Plain `char` is signed on this target, so the constant is minus one rather than 255.
3575        assert!(result.text().contains("global @c : i8 = -1,"), "{}", result.text());
3576
3577        let mut stray = b"int a".to_vec();
3578        stray.push(0xff);
3579        stray.extend_from_slice(b" = 1;\n");
3580        let result = compile_bytes(&stray);
3581        assert!(
3582            result.messages.iter().any(|m| m.contains("source is not valid UTF-8 here")),
3583            "{:?}",
3584            result.messages
3585        );
3586    }
3587
3588    #[test]
3589    fn an_object_becomes_a_global_with_an_image_and_a_function_becomes_a_func() {
3590        let text = ir("int x = 7;\nint add(int a, int b) { return a + b; }\n");
3591        assert!(text.contains("global @x : i32 = 7, align 4, linkage(external)\n"), "{text}");
3592        let expected = "\
3593func @add(i32, i32) -> i32, linkage(external) {
3594block0(%0: i32, %1: i32):
3595    %2 = add.nsw %0, %1
3596    return %2
3597}
3598";
3599        assert!(text.contains(expected), "{text}");
3600    }
3601
3602    #[test]
3603    fn a_local_nothing_takes_the_address_of_is_a_value_and_never_a_stack_slot() {
3604        let text = body("int f(int n) { int a = n + 1; int b = a * 2; return a + b; }\n");
3605        assert!(!text.contains("alloca"), "{text}");
3606        assert!(!text.contains("load"), "{text}");
3607        assert!(!text.contains("store"), "{text}");
3608    }
3609
3610    #[test]
3611    fn a_local_whose_address_is_taken_gets_a_slot_in_the_entry_block() {
3612        let text = body("int g(int *);\nint f(void) { int a = 1; return g(&a); }\n");
3613        let expected = "\
3614block0:
3615    %0 = alloca, size 4, align 4
3616    %1 = iconst.i32 1
3617    store %1 -> %0, align 4
3618    %2 = call @g(%0) : (ptr) -> i32
3619    return %2
3620";
3621        assert_eq!(text, expected);
3622    }
3623
3624    #[test]
3625    fn a_loop_carries_what_it_changes_as_block_parameters() {
3626        // The whole point of building SSA during the walk rather than after it: `i` and
3627        // `total` are values that arrive on an edge, and neither has ever been in memory.
3628        let text = body(
3629            "int f(int n) {\n  int total = 0;\n  for (int i = 0; i < n; i++) total += i;\n  \
3630             return total;\n}\n",
3631        );
3632        assert!(!text.contains("alloca"), "{text}");
3633        assert!(text.contains("block1(%3: i32, %4: i32):"), "{text}");
3634        assert!(text.contains("jump block1("), "{text}");
3635    }
3636
3637    #[test]
3638    fn a_comparison_used_as_a_condition_is_not_widened_and_narrowed_again() {
3639        let text = body("int f(int a, int b) { if (a < b) return 1; return 0; }\n");
3640        assert!(text.contains("icmp slt %0, %1"), "{text}");
3641        assert!(!text.contains("zext"), "{text}");
3642    }
3643
3644    #[test]
3645    fn the_right_side_of_a_short_circuit_is_in_a_block_of_its_own() {
3646        let text = body("int f(int a, int b) { return a && b; }\n");
3647        let expected = "\
3648block0(%0: i32, %1: i32):
3649    %2 = iconst.i32 0
3650    %3 = icmp ne %0, %2
3651    %4 = iconst.i1 0
3652    br_if %3, block1, block2(%4)
3653
3654block1:
3655    %5 = iconst.i32 0
3656    %6 = icmp ne %1, %5
3657    jump block2(%6)
3658
3659block2(%7: i1):
3660    %8 = zext.i32 %7
3661    return %8
3662";
3663        assert_eq!(text, expected);
3664    }
3665
3666    #[test]
3667    fn code_after_a_return_is_not_built_and_does_not_leave_an_empty_block_behind() {
3668        let text = body("int f(int a) { if (a) return 1; else return 2; return 3; }\n");
3669        // Three blocks, the test and the two arms. The join the `return 3` would need is
3670        // never created, because a block nothing branches to is not a block.
3671        assert!(!text.contains("block3"), "{text}");
3672        assert!(!text.contains("iconst.i32 3"), "{text}");
3673    }
3674
3675    #[test]
3676    fn falling_off_the_end_returns_zero_from_main_and_nothing_from_a_void_function() {
3677        assert!(body("int main(void) { }\n").contains("iconst.i32 0\n    return"));
3678        assert_eq!(body("void f(void) { }\n"), "block0:\n    return\n");
3679        assert!(body("int f(void) { }\n").contains("unreachable"));
3680    }
3681
3682    #[test]
3683    fn a_structure_is_copied_rather_than_held_in_a_value() {
3684        let text = body(
3685            "struct point { int x, y; };\n\
3686             int f(void) { struct point p = { 1, 2 }; struct point q = p; return q.x; }\n",
3687        );
3688        assert!(text.contains("memcpy"), "{text}");
3689    }
3690
3691    #[test]
3692    fn an_initializer_that_leaves_part_of_an_object_unwritten_zeroes_it_first() {
3693        let text = body("int f(void) { int a[4] = { 1 }; return a[3]; }\n");
3694        assert!(text.contains("memset"), "{text}");
3695    }
3696
3697    #[test]
3698    fn a_switch_is_one_branch_and_a_case_that_falls_through_carries_what_it_wrote() {
3699        let text = body(
3700            "int f(int x) { int r = 0; switch (x) { case 1: r = 1; case 2: r += 2; break; \
3701             default: r = 4; } return r; }\n",
3702        );
3703        let expected = "\
3704block0(%0: i32):
3705    %1 = iconst.i32 0
3706    switch %0, block1, [1 => block2, 2 => block3(%1)]
3707
3708block1:
3709    %2 = iconst.i32 4
3710    jump block4(%2)
3711
3712block2:
3713    %3 = iconst.i32 1
3714    jump block3(%3)
3715
3716block3(%4: i32):
3717    %5 = iconst.i32 2
3718    %6 = add.nsw %4, %5
3719    jump block4(%6)
3720
3721block4(%7: i32):
3722    return %7
3723";
3724        assert_eq!(text, expected);
3725    }
3726
3727    #[test]
3728    fn a_case_range_is_tested_for_rather_than_put_in_the_table() {
3729        // GNU's `case 1 ... 9`. Nine table entries would be nine here and four billion for the
3730        // range a program is allowed to write, so it is a subtraction and one unsigned compare.
3731        let text = body("int f(int x) { switch (x) { case 1 ... 9: return 1; } return 0; }\n");
3732        assert!(text.contains("%2 = sub %0, %1"), "{text}");
3733        assert!(text.contains("icmp ule"), "{text}");
3734        assert!(!text.contains("switch"), "{text}");
3735    }
3736
3737    #[test]
3738    fn break_leaves_the_switch_and_continue_leaves_the_loop_around_it() {
3739        let text = body(
3740            "int f(int n) { int t = 0; for (int i = 0; i < n; i++) { switch (i) { \
3741             case 0: continue; case 1: break; default: t += i; } t++; } return t; }\n",
3742        );
3743        // The `continue` goes to the step and the `break` goes to the `t++` after the switch,
3744        // which is also where the default falls out to.
3745        assert!(text.contains("switch %3, block4, [0 => block5, 1 => block6]"), "{text}");
3746        assert!(text.contains("block5:\n    jump block7("), "{text}");
3747        assert!(text.contains("block6:\n    jump block8("), "{text}");
3748    }
3749
3750    #[test]
3751    fn a_switch_with_nothing_to_branch_on_still_runs_what_comes_after_it() {
3752        assert_eq!(body("void f(int x) { switch (x) { } }\n"), "block0(%0: i32):\n    return\n");
3753    }
3754
3755    #[test]
3756    fn a_label_a_loop_is_only_entered_through_builds_the_loop_around_it() {
3757        // A branch into the middle of a loop that nothing else reaches, the Duff's device shape.
3758        // The `while` is not reached in order, so the walk starts a block nothing branches to and
3759        // builds it from there. What comes out is the loop with an edge straight into its body,
3760        // and the header that nothing arrives at is pruned.
3761        let text = body(
3762            "int f(int x, int n) { switch (x) { case 1: break; while (n) { case 2: n--; } } \
3763             return n; }\n",
3764        );
3765        // `case 2` lands on the body, `case 1` and the default land on the return, and the test
3766        // at the bottom of the loop comes back round to the body.
3767        assert!(text.contains("switch %0, block1(%1), [1 => block2, 2 => block3(%1)]"), "{text}");
3768        assert!(text.contains("block3(%3: i32):\n    %4 = iconst.i32 1"), "{text}");
3769        assert!(text.contains("block5:\n    jump block3("), "{text}");
3770    }
3771
3772    #[test]
3773    fn a_goto_into_a_loop_body_enters_it_without_the_test() {
3774        // The same thing through a `goto`. The first pass through the body runs whatever the
3775        // label is on, and only then does the loop reach its own test.
3776        let text = body("int f(int x, int n) { goto in; while (n) { in: n--; } return n; }\n");
3777        assert!(text.starts_with("block0(%0: i32, %1: i32):\n    jump block1(%1)"), "{text}");
3778        assert!(text.contains("block1(%2: i32):\n    %3 = iconst.i32 1"), "{text}");
3779        assert!(text.contains("br_if %7, block3, block4"), "{text}");
3780    }
3781
3782    #[test]
3783    fn a_goto_is_a_jump_to_the_block_the_label_starts() {
3784        let text = body("int f(int x) { int r = 0; if (x) goto out; r = 1; out: return r; }\n");
3785        // Both edges into `out` carry what `r` holds on the way, and neither is a stack slot.
3786        assert!(!text.contains("alloca"), "{text}");
3787        assert!(text.contains("block3(%4: i32):\n    return %4"), "{text}");
3788        assert_eq!(text.matches("jump block3(").count(), 2, "{text}");
3789    }
3790
3791    #[test]
3792    fn a_backward_goto_is_a_loop_and_carries_what_it_changes() {
3793        let text =
3794            body("int f(int n) { int i = 0; again: if (i < n) { i++; goto again; } return i; }\n");
3795        assert!(!text.contains("alloca"), "{text}");
3796        assert!(text.contains("block1(%2: i32):"), "{text}");
3797        assert!(text.contains("jump block1(%5)"), "{text}");
3798    }
3799
3800    #[test]
3801    fn a_label_nothing_reaches_is_taken_out_rather_than_left_for_the_verifier() {
3802        // A block nothing branches to is not a legal function, and which labels are dead is not
3803        // known until the last statement has been walked, since the `goto` is allowed to be it.
3804        assert_eq!(
3805            body("int f(int x) { return x; spare: return 0; }\n"),
3806            "block0(%0: i32):\n    return %0\n"
3807        );
3808    }
3809
3810    #[test]
3811    fn a_bit_field_is_read_by_loading_the_bytes_it_lies_in_and_shifting() {
3812        let text = body(
3813            "struct s { unsigned a : 3; signed b : 5; };\nint f(struct s *p) { return p->b; }\n",
3814        );
3815        // One byte holds both fields, and the signed one needs no mask: shifting it down
3816        // arithmetically is what says its top bit is a sign.
3817        assert_eq!(
3818            text,
3819            "\
3820block0(%0: ptr):
3821    %1 = load.i8 %0, align 1
3822    %2 = iconst.i8 3
3823    %3 = ashr %1, %2
3824    %4 = sext.i32 %3
3825    return %4
3826"
3827        );
3828    }
3829
3830    #[test]
3831    fn a_store_to_a_bit_field_does_not_write_a_byte_it_has_no_bit_in() {
3832        // C11 says an ordinary member beside a bit-field is a memory location of its own, so
3833        // the four byte store this would take is a data race in a program that has none. The
3834        // three bytes of `a` go in as two and one, and `c` is not touched.
3835        let text =
3836            body("struct s { int a : 24; char c; };\nvoid f(struct s *p, int v) { p->a = v; }\n");
3837        assert_eq!(
3838            text,
3839            "\
3840block0(%0: ptr, %1: i32):
3841    %2 = iconst.i32 16777215
3842    %3 = and %1, %2
3843    %4 = trunc.i16 %3
3844    store %4 -> %0, align 2
3845    %5 = iconst.i32 16
3846    %6 = lshr %3, %5
3847    %7 = trunc.i8 %6
3848    %8 = iconst.i64 2
3849    %9 = ptr_add %0, %8
3850    store %7 -> %9, align 1
3851    return
3852"
3853        );
3854    }
3855
3856    #[test]
3857    fn what_an_assignment_to_a_bit_field_is_worth_is_what_fits_in_it() {
3858        let text =
3859            body("struct s { unsigned b : 5; };\nunsigned f(struct s *p) { return p->b = 33; }\n");
3860        // 33 does not fit in five bits, and 1 is both what goes in the field and what the
3861        // assignment is worth.
3862        assert!(text.contains("%3 = iconst.i8 31\n    %4 = and %2, %3"), "{text}");
3863        assert!(text.ends_with("%9 = zext.i32 %4\n    return %9\n"), "{text}");
3864    }
3865
3866    #[test]
3867    fn an_assignment_a_statement_throws_away_builds_none_of_what_it_is_worth() {
3868        // The value of an assignment to a bit-field takes a shift to build, and a statement
3869        // has no use for it. Nothing here reads back what was stored.
3870        let text = body("struct s { signed b : 5; };\nvoid f(struct s *p) { p->b = 3; }\n");
3871        assert_eq!(text.matches("ashr").count(), 0, "{text}");
3872        assert!(text.ends_with("store %8 -> %0, align 1\n    return\n"), "{text}");
3873    }
3874
3875    #[test]
3876    fn a_bit_field_in_an_initializer_goes_in_over_bytes_that_were_zeroed_first() {
3877        // A bit-field writes part of a byte and leaves the rest of it alone, so the object has
3878        // to be zero before it goes in or what the initializer did not name is whatever the
3879        // stack held.
3880        let text = body(
3881            "struct s { int a : 3; int b; };\nint f(void) { struct s v = { 1 }; return v.b; }\n",
3882        );
3883        assert!(text.contains("memset %0, %1, size 8, align 4"), "{text}");
3884    }
3885
3886    #[test]
3887    fn the_image_of_a_static_bit_field_is_the_bytes_the_fields_share() {
3888        // Two fields in one byte are not two entries in the image, because an image is written
3889        // in bytes: they are the byte they are both in.
3890        let text = ir("struct s { unsigned a : 3; unsigned b : 5; } g = { 1, 2 };\n");
3891        assert!(
3892            text.contains("global @g : bytes 4 = { bytes \"\\11\", zero 3 }, align 4"),
3893            "{text}"
3894        );
3895    }
3896
3897    #[test]
3898    fn an_initialized_flexible_array_member_makes_the_object_larger_than_its_type() {
3899        // `sizeof` answers without the array and the definition has to hold what was written, so
3900        // the object is the size of its image. gcc 16 gives these four, three and two bytes and
3901        // so does this. The image used to be written at the size the type had, which left the
3902        // verifier looking at twenty bytes going into four.
3903        let text = ir(concat!(
3904            "struct a { int i; int j[]; } x = { 1, { 2, 0, 2, 3 } };\n",
3905            "struct b { char c; char p[]; } y = { 'o', \"wx\" };\n",
3906            "struct c { char c; char p[]; } z = { '9', { 'e', 'b' } };\n",
3907            "char s[2] = \"hi\";\n",
3908        ));
3909        assert!(
3910            text.contains("global @x : bytes 20 = { i32 1, i32 2, i32 0, i32 2, i32 3 }"),
3911            "{text}"
3912        );
3913        assert!(text.contains("global @y : bytes 4 = { i8 111, bytes \"wx\\00\" }"), "{text}");
3914        assert!(text.contains("global @z : bytes 3 = { i8 57, i8 101, i8 98 }"), "{text}");
3915        // The array with a length of its own still cuts the literal down to it, which is the
3916        // one case in C where a string initializer drops its terminator.
3917        assert!(text.contains("global @s : bytes 2 = { bytes \"hi\" }"), "{text}");
3918    }
3919
3920    #[test]
3921    fn a_definition_takes_a_parameter_it_left_unnamed() {
3922        // The entry block's parameters are the definition's, and one the front end dropped for
3923        // having no name left the two lists different lengths, which the walk read as an
3924        // old-style definition and refused. gcc has taken these for far longer than C23 has.
3925        let text = ir("int f(int a, int) { return a; }\n");
3926        assert!(text.contains("func @f(i32, i32) -> i32"), "{text}");
3927        assert!(text.contains("block0(%0: i32, %1: i32):"), "{text}");
3928
3929        // The unnamed one first, so that the named one is the second parameter of the entry
3930        // block and not the first: the list says the order and not only how many there are.
3931        let text = ir("int g(int, int n) { return n; }\n");
3932        assert!(text.contains("block0(%0: i32, %1: i32):\n    return %1\n"), "{text}");
3933    }
3934
3935    #[test]
3936    fn an_assignment_of_a_structure_is_the_object_it_wrote() {
3937        // `d = e = c` used to be refused, because the middle assignment is a value of structure
3938        // type and the walk had nowhere to read one from. What an assignment is worth is the
3939        // value it stored, so the object it stored into is the answer and the chain is three
3940        // copies out of the one source with no temporary in it.
3941        let text = body(concat!(
3942            "struct s { int f; int g; };\n",
3943            "void h(struct s *a, struct s *c, struct s *d, struct s *e)\n",
3944            "{ *d = *e = a[0] = *c; }\n",
3945        ));
3946        assert_eq!(text.matches("memcpy").count(), 3, "{text}");
3947        assert!(text.contains("memcpy %8, %1, size 8, align 4\n"), "{text}");
3948        assert!(text.contains("memcpy %3, %8, size 8, align 4\n"), "{text}");
3949        assert!(text.contains("memcpy %2, %3, size 8, align 4\n"), "{text}");
3950    }
3951
3952    #[test]
3953    fn a_string_literal_stops_at_the_end_of_the_array_it_is_filling() {
3954        // The excess used to be laid into the object anyway, so the row after was written over
3955        // and the image refused the entry that came to it. C 6.7.10p14 says the terminator goes
3956        // in only if there is room for it, and gcc discards the rest of a literal that is longer
3957        // still, which is what the first of these is and why it warns.
3958        let mut opts = options();
3959        opts.emit = EmitKind::Ir;
3960        let result = run(
3961            &opts,
3962            concat!(
3963                "const char a[2][3] = { \"1234\", \"xyz\" };\n",
3964                "static const char b[3][5] = { \"12345\", \"678\", \"9\" };\n",
3965                "union u { struct { char x[4]; char y[4]; }; struct { char z[8]; }; };\n",
3966                "const union u c = { { \"1234\", \"567\" } };\n",
3967            ),
3968        );
3969        let text = result.text();
3970        assert_eq!(
3971            result.messages,
3972            ["/main.c:1:24: warning: initializer-string for array of 'const char' is too long \
3973              (5 chars into 3 available) [E0637]"]
3974        );
3975        assert!(text.contains("global @a : bytes 6 = { bytes \"123\", bytes \"xyz\" }"), "{text}");
3976        assert!(
3977            text.contains(
3978                "global @b : bytes 15 = { bytes \"12345\", bytes \"678\\00\", zero 1, \
3979                 bytes \"9\\00\", zero 3 }"
3980            ),
3981            "{text}"
3982        );
3983        // The eight bytes are four, three and a terminator, and then the byte the shorter
3984        // literal left for the string in the other member of the union to end at.
3985        assert!(
3986            text.contains("global @c : bytes 8 = { bytes \"1234\", bytes \"567\\00\" }"),
3987            "{text}"
3988        );
3989    }
3990
3991    #[test]
3992    fn a_cast_of_a_record_to_its_own_type_is_the_object_that_was_cast() {
3993        // gcc accepts one and does nothing with it, which sema already had. Lowering asked for
3994        // the object under it and had no arm for a cast, so `(struct s)x` in an initializer was
3995        // refused with E0519. It is one copy out of the object named, not two.
3996        let text = body(concat!(
3997            "struct s { int a, b; };\nstruct v { struct s s; int t; };\n",
3998            "void g(struct v *);\n",
3999            "void f(struct s *p) { struct v w = { (struct s)*p, 5 }; g(&w); }\n",
4000        ));
4001        assert_eq!(text.matches("memcpy").count(), 1, "{text}");
4002    }
4003
4004    #[test]
4005    fn a_compound_literal_read_in_a_static_initializer_lays_its_bytes_into_the_image() {
4006        // C 6.7.11p4 says a compound literal at file scope has static storage duration, which
4007        // makes it a constant element, and tcc and c-testsuite both write one. Sema used to call
4008        // it a non constant because reading it is a node of its own and the read was what it
4009        // looked at, and lowering had no way to put an object where it wanted a number.
4010        let text = ir(concat!(
4011            "struct s { int x; };\n",
4012            "struct t { struct s s; int o; } a = { (struct s){ 2 }, 3 };\n",
4013            "int n = (int){ 7 };\n",
4014            "struct u { struct s p; struct s q; } b = { (struct s){ 1 }, (struct s){ } };\n",
4015        ));
4016        assert!(text.contains("global @a : bytes 8 = { i32 2, i32 3 }"), "{text}");
4017        assert!(text.contains("global @n : i32 = 7,"), "{text}");
4018        // The second literal names nothing, so what it puts in is the zeros of its own size and
4019        // not the tail of the object it went in, which would have been the same bytes by luck.
4020        assert!(text.contains("global @b : bytes 8 = { i32 1, zero 4 }"), "{text}");
4021    }
4022
4023    #[test]
4024    fn the_address_of_a_compound_literal_asks_for_the_object_it_points_at() {
4025        // Nothing declares a compound literal, so the reference is the only thing that can ask
4026        // for it to be emitted. The image named `.Lanon.0` and the module defined no such
4027        // symbol, which the link would have been the first to find out.
4028        let text = ir("struct s { int x; };\nstruct s *q = &(struct s){ 9 };\n");
4029        assert!(text.contains("global @.Lanon.0 : i32 = 9, align 4, linkage(internal)"), "{text}");
4030        assert!(text.contains("global @q : bytes 8 = { addr.8 @.Lanon.0 }"), "{text}");
4031    }
4032
4033    #[test]
4034    fn an_object_of_no_size_at_all_has_an_image_with_nothing_in_it() {
4035        // A zero length array, which gcc allows and real code uses as the tail of a structure.
4036        // The image is there and holds nothing, which is not the global that has no image at
4037        // all, and the IR reader used to stop on the empty one.
4038        let text = ir("unsigned char foo[1][0];\n");
4039        assert!(text.contains("global @foo : bytes 0 = {}, align 1"), "{text}");
4040    }
4041
4042    #[test]
4043    fn a_null_pointer_in_an_image_is_the_bits_an_address_has_room_for() {
4044        // `NULL` in a static initializer, which every program has. The IR type is `ptr` and a
4045        // `ptr` has no width of its own, so the width the bits are cut to is the target's.
4046        let text = ir("void *p = 0;\nchar *q = (char *) 4096;\n");
4047        assert!(text.contains("global @p : i64 = 0, align 8"), "{text}");
4048        assert!(text.contains("global @q : i64 = 4096, align 8"), "{text}");
4049    }
4050
4051    #[test]
4052    fn an_object_another_module_defines_may_be_one_that_cannot_be_written_through() {
4053        // Which the verifier used to refuse, having read a declaration as a definition with
4054        // nothing in it. `extern const` is how a program names something in the library's read
4055        // only data, and glibc and Darwin both have one in a header a real program includes.
4056        let text = ir("extern const int limit;\nint f(void) { return limit; }\n");
4057        assert!(
4058            text.contains("global @limit : bytes 4, align 4, linkage(external), constant"),
4059            "{text}"
4060        );
4061    }
4062
4063    #[test]
4064    fn a_conditional_whose_value_is_an_object_answers_where_the_object_is() {
4065        // A structure is not a value in the IR, so the two arms cannot be joined as one. The
4066        // addresses can, and the answer is the address of whichever arm was taken rather than
4067        // a copy of it into a third place: both arms outlive the expression, so a copy would
4068        // be one nothing could observe. SQLite's parser writes one of these.
4069        let text = body(
4070            "\
4071struct s { int a, b; };
4072struct s pick(int c, struct s x, struct s y) { return c ? x : y; }
4073",
4074        );
4075        // The join takes an address, each arm hands it the one it has, and nothing is copied.
4076        assert!(text.contains("block3(%7: ptr)"), "{text}");
4077        assert!(text.contains("jump block3(%3)") && text.contains("jump block3(%4)"), "{text}");
4078        assert!(!text.contains("memcpy"), "the arms are joined rather than copied: {text}");
4079    }
4080
4081    #[test]
4082    fn a_structure_that_fits_in_registers_travels_as_the_registers_it_fits_in() {
4083        // `struct pair` is two eightbytes on SysV, one of them integer, so the signature says
4084        // one `i64` in each direction and the body takes the object apart and puts it back
4085        // together around the call.
4086        let text = ir("\
4087struct pair { int a, b; };
4088struct pair make(int a, int b);
4089struct pair twice(struct pair p) { return make(p.a, p.b); }
4090");
4091        assert!(text.contains("func @make(i32, i32) -> i64"), "{text}");
4092        assert!(text.contains("func @twice(i64) -> i64"), "{text}");
4093    }
4094
4095    #[test]
4096    fn a_structure_too_large_for_the_registers_travels_as_where_its_bytes_are() {
4097        // Over two eightbytes the caller passes the bytes in the argument area, which is
4098        // `byval`, and passes somewhere to write the return value, which is `sret`. Neither is
4099        // a parameter the program wrote and both are parameters the function has.
4100        let text = ir("\
4101struct big { double v[8]; };
4102struct big grow(struct big b);
4103struct big twice(struct big b) { return grow(grow(b)); }
4104");
4105        assert!(
4106            text.contains("func @grow(ptr sret(64, align 8), ptr byval(64, align 8))"),
4107            "{text}"
4108        );
4109        assert!(text.contains("block0(%0: ptr, %1: ptr):"), "{text}");
4110        // The inner call writes into a slot and the outer one reads the same slot, so the
4111        // object between the two calls is never copied anywhere.
4112        assert_eq!(text.matches("call @grow").count(), 2, "{text}");
4113    }
4114
4115    #[test]
4116    fn a_structure_passed_to_a_variadic_function_says_so_at_the_call() {
4117        // The bytes travel in the argument area the same way they would for a parameter, and
4118        // `printf` has no parameter there to say it on, so the call says it instead. The one
4119        // that fits in registers says nothing, because travelling as the registers it fits in
4120        // is what an argument does when nothing says otherwise.
4121        let text = ir("\
4122struct big { double v[8]; };
4123struct pair { int a, b; };
4124int p(const char *, ...);
4125int f(struct big b, struct pair q) { return p(\"\", 1, b, q); }
4126");
4127        assert!(
4128            text.contains("call @p(%4, %5, %2 byval(64, align 8), %6) : (ptr, ...) -> i32"),
4129            "{text}"
4130        );
4131    }
4132
4133    #[test]
4134    fn what_a_call_produced_is_somewhere_before_anything_is_read_out_of_it() {
4135        // `make(1, 2).b` has no object to read a member of until one is made, and what makes it
4136        // is a slot the returned registers are written to.
4137        let body = body(
4138            "\
4139struct pair { int a, b; };
4140struct pair make(int a, int b);
4141int second(void) { return make(1, 2).b; }
4142",
4143        );
4144        assert!(body.starts_with("block0:\n    %0 = alloca, size 8, align 4\n"), "{body}");
4145        assert!(body.contains("store %3 -> %0, align 4\n"), "{body}");
4146    }
4147
4148    #[test]
4149    fn a_structure_of_floats_travels_in_floating_point_registers_on_aarch64() {
4150        // The same declaration, classified by a different ABI: three `float` members are an
4151        // eightbyte of two of them and a half eightbyte of the third on SysV, and three vector
4152        // registers on AAPCS64.
4153        let source = "\
4154struct hfa { float x, y, z; };
4155int take(struct hfa h);
4156int give(struct hfa h) { return take(h); }
4157";
4158        assert!(ir(source).contains("func @take(f64, f32) -> i32"), "{}", ir(source));
4159        let mut opts = options();
4160        opts.emit = EmitKind::Ir;
4161        opts.target = "aarch64-unknown-linux-gnu".parse::<Triple>().unwrap();
4162        let result = run(&opts, source);
4163        assert_eq!(result.messages, Vec::<String>::new());
4164        assert!(result.text().contains("func @take(f32, f32, f32) -> i32"), "{}", result.text());
4165    }
4166
4167    #[test]
4168    fn an_array_whose_length_is_not_a_constant_is_a_slot_made_where_its_declaration_is() {
4169        // The size is a multiplication rather than a number, the slot is taken from the stack
4170        // where the declaration is, and the scope it was declared in gives it back.
4171        let source = "\
4172int use(int *);
4173void f(int n) {
4174  {
4175    int a[n];
4176    use(a);
4177  }
4178  use(0);
4179}
4180";
4181        let body = body(source);
4182        assert!(body.contains("mul.nsw"), "{body}");
4183        assert!(body.contains("stacksave"), "{body}");
4184        assert!(body.contains("alloca %"), "{body}");
4185        assert!(body.contains("stackrestore"), "{body}");
4186    }
4187
4188    #[test]
4189    fn a_goto_out_of_the_scope_of_one_gives_its_stack_back_on_the_way() {
4190        // The label is outside the block the array is in, so arriving there means the array is
4191        // gone, and the restore that says so goes in front of the branch. The `goto` is written
4192        // before the walk knows where the label is, which is why the restore is put there at
4193        // the end rather than built where the branch was.
4194        let source = "\
4195int use(int *);
4196int f(int n) {
4197  {
4198    int a[n];
4199    if (use(a)) goto out;
4200    use(0);
4201  }
4202out:
4203  return 0;
4204}
4205";
4206        let body = body(source);
4207        // Two ways out of the block and a restore on each: the jump and the end of the block.
4208        assert_eq!(body.matches("stackrestore").count(), 2, "{body}");
4209        let (_, after) = body.split_once("stackrestore").expect("the stack is given back");
4210        assert!(after.starts_with(" %4\n    jump block"), "{body}");
4211    }
4212
4213    #[test]
4214    fn a_goto_to_a_label_the_array_is_still_alive_at_leaves_the_stack_alone() {
4215        // The label is after the declaration and in the same block, so control that arrives
4216        // there arrives somewhere the array exists. Giving it back would be giving back an
4217        // object the next statement reads.
4218        let source = "\
4219int use(int *);
4220int f(int n) {
4221  int a[n];
4222again:
4223  if (use(a)) goto again;
4224  return 0;
4225}
4226";
4227        let body = body(source);
4228        assert!(body.contains("stacksave"), "{body}");
4229        assert!(!body.contains("stackrestore"), "{body}");
4230    }
4231
4232    #[test]
4233    fn a_goto_back_to_a_label_in_front_of_one_gives_it_back_every_time_round() {
4234        // A loop written out of a `goto`, with the array made inside it. The label is in the
4235        // same block as the declaration and before it, which is a place where the array does
4236        // not exist yet, so the jump there leaves its scope and has to give the stack back. A
4237        // compiler that skips this restore grows the stack once per iteration.
4238        let source = "\
4239int use(int *);
4240int f(int n) {
4241again:
4242  {
4243    int a[n];
4244    if (use(a)) goto again;
4245  }
4246  return 0;
4247}
4248";
4249        let body = body(source);
4250        assert_eq!(body.matches("stacksave").count(), 1, "{body}");
4251        let (_, after) = body.split_once("stackrestore").expect("the stack is given back");
4252        assert!(after.starts_with(" %4\n    jump block1\n"), "{body}");
4253    }
4254
4255    #[test]
4256    fn the_head_of_a_for_loop_is_a_scope_that_closes_where_the_loop_is_left() {
4257        // The scope opened for `for (int a[n];;)` used to stay open, and a scope left open is
4258        // not one mark nobody reads. The marks are a stack, so the next close took this one
4259        // instead of its own, and the body of the loop gave back nothing while the block after
4260        // the loop restored a pointer saved inside it. The verifier refused that, which is how
4261        // it was found.
4262        let source = "\
4263int f(void);
4264void t(void) {
4265  int count = 10;
4266  for (; count--;) {
4267    int b[f()];
4268    int i;
4269    for (i = 0; i < f(); i++) {
4270      b[i] = count;
4271    }
4272  }
4273}
4274";
4275        let body = body(source);
4276        // One save, in the body, and one restore for it, also in the body: the block the
4277        // restore is in is the one the inner loop leaves through, and it goes back round the
4278        // outer loop rather than out of it.
4279        assert_eq!(body.matches("stacksave").count(), 1, "{body}");
4280        let (_, after) = body.split_once("stackrestore").expect("the stack is given back");
4281        let (next, _) = after.split_once("\n\n").expect("a block after the restore");
4282        assert!(next.contains("jump block1("), "{body}");
4283    }
4284
4285    #[test]
4286    fn how_long_one_of_those_is_was_decided_where_it_was_declared_and_not_where_it_is_asked() {
4287        // What C says about the length being evaluated once: `sizeof a` after `n` changed is
4288        // still as long as the array is, which is what `n` was when the array came into being.
4289        let source = "\
4290unsigned long f(int n) {
4291  int a[n];
4292  n = 0;
4293  return sizeof a;
4294}
4295";
4296        let body = body(source);
4297        // One read of the parameter, at the declaration, and the answer is built out of it.
4298        assert_eq!(body.matches("sext.i64 %0").count(), 2, "{body}");
4299    }
4300
4301    #[test]
4302    fn a_block_in_the_middle_of_an_expression_is_walked_where_the_expression_is() {
4303        // GNU's statement expression: the statements happen where they are written and the last
4304        // one is the value, so the temporary in it never becomes a slot and never is copied.
4305        let source = "\
4306int use(int);
4307int f(int x) {
4308  return ({
4309    int t = use(x);
4310    t * t;
4311  });
4312}
4313";
4314        let expected = "\
4315block0(%0: i32):
4316    %1 = call @use(%0) : (i32) -> i32
4317    %2 = mul.nsw %1, %1
4318    return %2
4319";
4320        assert_eq!(body(source), expected);
4321    }
4322
4323    #[test]
4324    fn one_of_those_that_control_never_leaves_is_lowered_and_what_follows_it_is_dropped() {
4325        // A macro that always jumps, which is what this shape is in real code. The value is
4326        // never taken, and the block the rest of the expression would have been built in is
4327        // one nothing branches to, so it goes with the other unreachable blocks.
4328        let source = "int f(int x) { return ({ return x; 0; }); }\n";
4329        assert_eq!(body(source), "block0(%0: i32):\n    return %0\n");
4330    }
4331
4332    #[test]
4333    fn one_argument_off_a_variable_argument_list_stays_an_intrinsic() {
4334        // What it becomes is the target's answer, and this is not where the target's answers
4335        // are, so the walk writes down which list and which type and leaves it at that. Two of
4336        // them are two instructions, since each moves the list on.
4337        let source = "double f(__builtin_va_list ap) { return __builtin_va_arg(ap, double) + __builtin_va_arg(ap, double); }\n";
4338        let expected = "\
4339block0(%0: ptr):
4340    %1 = va_arg.f64 %0
4341    %2 = va_arg.f64 %0
4342    %3 = fadd %1, %2
4343    return %3
4344";
4345        assert_eq!(body(source), expected);
4346    }
4347
4348    #[test]
4349    fn one_that_reads_a_structure_answers_where_the_object_is() {
4350        // An aggregate is not a value, so there is nothing for the result of `va_arg` to be and
4351        // the object form is a second instruction. What it answers is an address, so it is a
4352        // place already and the walk copies nothing out of it: the copy here is the one the
4353        // initializer asks for, into the variable being declared. The size and the alignment
4354        // travel with it because they are what steps the list on and what a target that has to
4355        // put registers somewhere needs to know. So does the classification, which says the two
4356        // halves of this one arrived in general purpose registers: that is an answer about a C
4357        // type, and this is the last place that still has one.
4358        //
4359        // The slot is aligned to sixteen and the copy into it to eight, which is not a
4360        // disagreement. Sixteen is what a local aggregate of sixteen bytes gets whatever its
4361        // members ask for, and eight is what the type asks for and so what the copy may assume
4362        // about the object it is reading from.
4363        let source = "\
4364struct s { int a; long b; };
4365long f(__builtin_va_list ap) { struct s v = __builtin_va_arg(ap, struct s); return v.b; }
4366";
4367        let expected = "\
4368block0(%0: ptr):
4369    %1 = alloca, size 16, align 16
4370    %2 = va_object %0, size 16, align 8, in(int 8 at 0, int 8 at 8)
4371    memcpy %1, %2, size 16, align 8
4372    %3 = iconst.i64 8
4373    %4 = ptr_add %1, %3
4374    %5 = load.i64 %4, align 8
4375    return %5
4376";
4377        assert_eq!(body(source), expected);
4378    }
4379
4380    /// Which register file each eightbyte arrived in is the whole of what the classification adds,
4381    /// and an object with no slots at all is one it sent to the caller's argument area, which is
4382    /// what everything over two eightbytes is whatever its members are.
4383    #[test]
4384    fn the_classification_says_which_registers_the_object_arrived_in() {
4385        let source = "\
4386struct s { double a; double b; };
4387double f(__builtin_va_list ap) { struct s v = __builtin_va_arg(ap, struct s); return v.a; }
4388";
4389        assert!(
4390            body(source)
4391                .contains("va_object %0, size 16, align 8, in(float f64 at 0, float f64 at 8)"),
4392            "{}",
4393            body(source)
4394        );
4395
4396        let big = "\
4397struct s { long a[4]; };
4398long f(__builtin_va_list ap) { struct s v = __builtin_va_arg(ap, struct s); return v.a[0]; }
4399";
4400        assert!(body(big).contains("va_object %0, size 32, align 8\n"), "{}", body(big));
4401    }
4402
4403    #[test]
4404    fn a_jump_to_an_address_branches_to_every_label_the_function_takes_the_address_of() {
4405        // GNU's computed goto. Which label the address holds is not known here, so all of them
4406        // are listed, and the values arriving at one are passed on every edge the same way they
4407        // are on an ordinary branch.
4408        let source = "\
4409int f(int c) {
4410  void *p = c ? &&one : &&two;
4411  goto *p;
4412one:
4413  return 1;
4414two:
4415  return 2;
4416}
4417";
4418        let expected = "\
4419block0(%0: i32):
4420    %1 = iconst.i32 0
4421    %2 = icmp ne %0, %1
4422    br_if %2, block1, block2
4423
4424block1:
4425    %3 = block_addr block3
4426    jump block4(%3)
4427
4428block2:
4429    %4 = block_addr block5
4430    jump block4(%4)
4431
4432block3:
4433    %5 = iconst.i32 1
4434    return %5
4435
4436block4(%6: ptr):
4437    indirect_br %6, block3, block5
4438
4439block5:
4440    %7 = iconst.i32 2
4441    return %7
4442";
4443        assert_eq!(body(source), expected);
4444    }
4445
4446    #[test]
4447    fn a_jump_to_an_address_no_label_in_the_function_has_arrives_nowhere() {
4448        // The address came from outside the function, and a jump to a label in another function
4449        // is undefined. The expression is still evaluated, since a call in it has to happen.
4450        let source = "void **next(void);
4451void f(void) { goto *next(); }
4452";
4453        let expected = "\
4454block0:
4455    %0 = call @next() : () -> ptr
4456    unreachable
4457";
4458        assert_eq!(body(source), expected);
4459    }
4460
4461    #[test]
4462    fn an_asm_with_no_operands_is_volatile_and_the_clobbers_are_the_whole_of_what_it_says() {
4463        // Nothing reads a result, so the only thing that keeps it is that it is volatile, which
4464        // a basic asm implies.
4465        let source = "void f(void) { __asm__(\"mfence\" ::: \"memory\"); }\n";
4466        let expected = "\
4467block0:
4468    inline_asm.volatile \"mfence\", \"\", \"memory\"()
4469    return
4470";
4471        assert_eq!(body(source), expected);
4472    }
4473
4474    #[test]
4475    fn the_constraints_are_one_list_in_the_order_the_template_counts_the_operands() {
4476        // The outputs first and then the inputs, which is the numbering `%0` and `%1` use. An
4477        // output in a register is a result, and one that is read as well is an argument too.
4478        let source = "\
4479int f(int x, int y) {
4480  int r;
4481  __asm__(\"addl %2, %0\" : \"=r\"(r), \"+r\"(y) : \"r\"(x));
4482  return r + y;
4483}
4484";
4485        let expected = "\
4486block0(%0: i32, %1: i32):
4487    %2, %3 = inline_asm.(i32, i32) \"addl %2, %0\", \"=r,+r,r\", \"\"(%1, %0)
4488    %4 = add.nsw %2, %3
4489    return %4
4490";
4491        assert_eq!(body(source), expected);
4492    }
4493
4494    #[test]
4495    fn a_memory_operand_travels_as_the_address_of_an_object_that_is_given_a_slot() {
4496        // The assembly is handed a pointer, so the object cannot live in a value, and the scan
4497        // that runs before the walk has to have known that or there would be nothing to point
4498        // at. A structure travels this way whatever else its constraint allows, since there is
4499        // no register that holds one.
4500        let source = "\
4501struct pair { int a, b; };
4502int f(int x) {
4503  int slot = x;
4504  struct pair p = { x, x };
4505  __asm__(\"incl %0\" : \"+m\"(slot), \"=m\"(p));
4506  return slot + p.a;
4507}
4508";
4509        let text = body(source);
4510        assert!(text.contains("inline_asm \"incl %0\", \"+m,=m\", \"\"(%1, %2)\n"), "{text}");
4511        assert!(text.contains("%1 = alloca, size 4, align 4\n"), "{text}");
4512        assert!(text.contains("%2 = alloca, size 8, align 4\n"), "{text}");
4513    }
4514
4515    #[test]
4516    fn an_asm_goto_falls_through_to_its_first_target_and_writes_its_outputs_there() {
4517        // The output is only in scope where the instruction dominates, which is the fall through
4518        // block, so the edge to the label carries the value the object had before the assembly
4519        // ran. That is what document 11 asks for and it is what putting the fall through first
4520        // buys.
4521        let source = "\
4522int f(int x) {
4523  int r = 7;
4524  __asm__ goto(\"cbnz %0, %l1\" : \"=r\"(r) : \"r\"(x) :: away);
4525  return r;
4526away:
4527  return r;
4528}
4529";
4530        let expected = "\
4531block0(%0: i32):
4532    %1 = iconst.i32 7
4533    %2 = inline_asm.volatile \"cbnz %0, %l1\", \"=r,r\", \"\"(%0), labels [block1, block2]
4534
4535block1:
4536    return %2
4537
4538block2:
4539    return %1
4540";
4541        assert_eq!(body(source), expected);
4542    }
4543
4544    #[test]
4545    fn an_asm_statement_that_is_not_well_formed_is_reported_in_the_words_gcc_uses() {
4546        // The operands are checked here rather than by the assembler, because by the time the
4547        // assembler sees the template the operands have become registers and it has nothing left
4548        // to say about the C that named them.
4549        let mut opts = options();
4550        opts.emit = EmitKind::Ir;
4551        for (source, expected) in [
4552            (
4553                "void f(int x) { __asm__(\"\" : \"r\"(x)); }\n",
4554                "output operand constraint lacks '='",
4555            ),
4556            (
4557                "void f(int x) { __asm__(\"\" : \"=r\"(x + 1)); }\n",
4558                "lvalue required in 'asm' statement",
4559            ),
4560            (
4561                "const int g = 1;\nvoid f(void) { __asm__(\"\" : \"=r\"(g)); }\n",
4562                "read-only variable 'g' used as 'asm' output",
4563            ),
4564            (
4565                "void f(int x) { __asm__(\"\" : : \"=r\"(x)); }\n",
4566                "input operand constraint contains '='",
4567            ),
4568            (
4569                "void f(void) { __asm__(\"\" : : \"m\"(1)); }\n",
4570                "memory input 0 is not directly addressable",
4571            ),
4572            ("void f(void) { __asm__(L\"\"); }\n", "wide string literal in 'asm'"),
4573            (
4574                "void f(int x, int y) { __asm__(\"\" : [a] \"=r\"(x) : [a] \"r\"(y)); }\n",
4575                "duplicate asm operand name 'a'",
4576            ),
4577            ("void f(int x) { __asm__(\"%[in]\" : \"=r\"(x)); }\n", "undefined named operand 'in'"),
4578        ] {
4579            let result = run(&opts, source);
4580            assert!(result.failed(), "expected this to be reported:\n{source}");
4581            assert!(
4582                result.messages.iter().any(|m| m.contains(expected)),
4583                "{expected}\n{:?}",
4584                result.messages
4585            );
4586        }
4587    }
4588
4589    #[test]
4590    fn what_the_walk_cannot_build_yet_is_reported_rather_than_mislowered() {
4591        let mut opts = options();
4592        opts.emit = EmitKind::Ir;
4593        for source in [
4594            "int f(int n) { void *p = &&out; if (n) goto *p; { int a[n]; out: return 1; } }\n",
4595            "int f(int n) { int a[n]; __asm__ goto(\"\" ::::out); out: return a[0]; }\n",
4596        ] {
4597            let result = run(&opts, source);
4598            assert!(result.failed(), "expected this to be reported:\n{source}");
4599            assert!(
4600                result.messages.iter().any(|m| m.contains("not supported yet")),
4601                "{:?}",
4602                result.messages
4603            );
4604        }
4605    }
4606
4607    /// Compiles `source` to IR, reads that back as an input, and gives back both texts.
4608    fn round_trip(source: &str) -> (String, String) {
4609        let printed = ir(source);
4610        let mut opts = options();
4611        opts.emit = EmitKind::Ir;
4612        let mut fs = MemoryFileSystem::new();
4613        fs.insert("/main.ir", printed.clone().into_bytes());
4614        let result = compile_ir(&opts, "/main.ir", &fs);
4615        assert_eq!(result.messages, Vec::<String>::new(), "expected this to read back:\n{printed}");
4616        (printed, result.text().to_owned())
4617    }
4618
4619    #[test]
4620    fn ir_that_arrives_as_an_input_is_read_back_and_written_out_the_same() {
4621        // The other half of the round trip test below, through the driver rather than through
4622        // the library, which is what makes the property something to run over a real program
4623        // rather than over the modules a test builds.
4624        let (printed, again) = round_trip(
4625            "struct point { int x, y; };\n             static const char greeting[] = \"hi\";\n             int puts(const char *);\n             int f(int n) { struct point p = { n, 1 }; puts(greeting); return p.x; }\n",
4626        );
4627        assert_eq!(printed, again);
4628    }
4629
4630    #[test]
4631    fn ir_that_is_not_ir_says_which_line_stopped_it() {
4632        let mut opts = options();
4633        opts.emit = EmitKind::Ir;
4634        let mut fs = MemoryFileSystem::new();
4635        let text = "\
4636; ModuleID = 'a.c'
4637; format 0
4638target triple = \"x86_64-unknown-linux-gnu\"
4639target datalayout = \"e-p:64:64-i64:64-S128\"
4640
4641func @f(), linkage(external) {
4642block0:
4643    frobnicate
4644}
4645";
4646        fs.insert("/main.ir", text.as_bytes().to_vec());
4647        let result = compile_ir(&opts, "/main.ir", &fs);
4648        assert!(result.failed());
4649        assert!(result.messages[0].contains("/main.ir:8"), "{:?}", result.messages);
4650    }
4651
4652    #[test]
4653    fn ir_that_reads_but_does_not_hold_together_is_reported_by_the_verifier() {
4654        // A module that a person edited has not been through the verifier, and the return of
4655        // an `i32` from a function that returns nothing is the kind of thing editing produces.
4656        let mut opts = options();
4657        opts.emit = EmitKind::Ir;
4658        let mut fs = MemoryFileSystem::new();
4659        let text = "\
4660; ModuleID = 'a.c'
4661; format 0
4662target triple = \"x86_64-unknown-linux-gnu\"
4663target datalayout = \"e-p:64:64-i64:64-S128\"
4664
4665func @f(), linkage(external) {
4666block0:
4667    %0 = iconst.i32 1
4668    return %0
4669}
4670";
4671        fs.insert("/main.ir", text.as_bytes().to_vec());
4672        let result = compile_ir(&opts, "/main.ir", &fs);
4673        assert!(result.failed());
4674        assert!(result.messages[0].contains("invalid IR"), "{:?}", result.messages);
4675    }
4676
4677    #[test]
4678    fn a_typed_tree_is_not_something_an_input_of_ir_can_produce() {
4679        // The C that became this is not here any more, so there is nothing to print a tree of.
4680        let mut fs = MemoryFileSystem::new();
4681        fs.insert("/main.ir", Vec::new());
4682        let result = compile_ir(&options(), "/main.ir", &fs);
4683        assert!(result.failed());
4684        assert!(result.messages[0].contains("can only be emitted as IR"), "{:?}", result.messages);
4685    }
4686
4687    #[test]
4688    fn the_printed_ir_reads_back_as_the_same_module() {
4689        // The M2 exit criterion: the text is the module and nothing about it is lost by
4690        // writing it down. Anything the printer invents or the parser drops shows up here.
4691        let text = ir("\
4692struct point { int x, y; };
4693static const char greeting[] = \"hi\";
4694int table[4] = { 1, 2, 3 };
4695int puts(const char *);
4696double half(double x) { return x / 2.0; }
4697int f(int n) {
4698  int total = 0;
4699  for (int i = 0; i < n; i++) {
4700    if (i == 3) continue;
4701    total += table[i];
4702  }
4703  switch (n) {
4704    case 0: total = 1;
4705    case 1: total++; break;
4706    default: total = -total;
4707  }
4708  struct point p = { total, 1 };
4709  int *q = &p.y;
4710  puts(greeting);
4711  return p.x + *q;
4712}
4713int dispatch(int c) {
4714  void *p = c ? &&one : &&two;
4715  goto *p;
4716one:
4717  return 1;
4718two:
4719  return 2;
4720}
4721int assembly(int x, int *p) {
4722  int r;
4723  __asm__ volatile(\"xadd %0, %2\" : \"=r\"(r), \"+m\"(*p) : \"0\"(x) : \"cc\");
4724  __asm__ goto(\"cbnz %0, %l1\" : : \"r\"(r) : : away);
4725  return r;
4726away:
4727  return 0;
4728}
4729");
4730        let mut names = Interner::new();
4731        let module = rucc_ir::parse(&text, &mut names).expect("the printer writes what it reads");
4732        assert_eq!(rucc_ir::print(&module, &names), text);
4733    }
4734}