Commit Graph
21 Commits
Author SHA1 Message Date
Chris Tate c7b11a9242 Compile embeddable Wasm modules with host imports
- Emit callable Wasm reactors with explicit exports, host callbacks, and independent instance memory.
- Compile three.js scene and geometry workloads into Wasm without an embedded JavaScript engine.
- Document initialization, memory ownership, and external browser hosting.
2026-09-30 01:09:15 -05:00
Chris Tate 3f66c8e20b Make LLVM the sole production backend
- Remove C emission, debugging options, and automatic backend fallback.
- Complete LLVM lowering and native bootstrap coverage across supported targets.
- Link executables and libraries with precompiled C runtime packs, including iOS and Android.
2026-09-29 20:54:09 -05:00
Chris Tate 94fd361b54 Implement sparse native arrays and missing-value parity (#297)
Represent ordinary JavaScript arrays with hole, value, and explicit-undefined states; add sparse side storage and carry missing values through the frontend, native backends, runtime, and Node-facing consumers.
2026-09-12 22:39:07 -05:00
Chris Tateandmmamedel 9080986166 Add sparse UTF-16 indexing for large strings (#275)
* fix: index large unicode strings sparsely

Co-authored-by: mmamedel <23098414+mmamedel@users.noreply.github.com>

* fix: retain sparse anchors for long ascii prefixes

Co-authored-by: mmamedel <23098414+mmamedel@users.noreply.github.com>

* fix: skip sparse index for proven ASCII strings

Co-authored-by: mmamedel <23098414+mmamedel@users.noreply.github.com>

* fix: complete sparse UTF-16 string indexing

Co-authored-by: mmamedel <23098414+mmamedel@users.noreply.github.com>

* test: rebase static size contracts for sparse index

Co-authored-by: mmamedel <23098414+mmamedel@users.noreply.github.com>

* test: retain sparse checkpoints through ASCII prefix end

Co-authored-by: mmamedel <23098414+mmamedel@users.noreply.github.com>

* fix: retain sparse anchors across threshold append

Co-authored-by: mmamedel <23098414+mmamedel@users.noreply.github.com>

* fix: retain sparse indexes beyond cursor cache

Co-authored-by: mmamedel <23098414+mmamedel@users.noreply.github.com>

* fix: bound sparse string index residency

Co-authored-by: mmamedel <23098414+mmamedel@users.noreply.github.com>

* fix: isolate sparse string index residency

Co-authored-by: mmamedel <23098414+mmamedel@users.noreply.github.com>

* test: restore parseInt oracle outputs

* test: verify committed string oracle

- Regenerate the string case oracle with the active Node executable.\n- Compare the checked-in fixture byte-for-byte before native runtime checks.\n- Keep the Linux parseInt ULP allowance scoped to native output.

---------

Co-authored-by: mmamedel <23098414+mmamedel@users.noreply.github.com>
2026-08-31 17:12:52 -05:00
Chris Tateandmmamedel 2b6e6524a3 fix(library): reject callback re-entry (#270)
Co-authored-by: mmamedel <23098414+mmamedel@users.noreply.github.com>
2026-08-30 19:30:31 -05:00
Chris Tate 81b70b0ee6 feat: add host-callback channels to library mode (#148)
* feat: add host-callback channels to library mode

- the profile's `callbacks` array declares named channels and
  `abi.callback_register_symbol` names the one registration entry point:
  `int32_t <sym>(const char *name, void (*fn)(void), void *ctx)` — 0 on
  success, -1 for an unknown or NULL name, latest registration wins, a
  NULL fn clears, registrations persist across init/reset. The stored
  pointer's typed shape is the channel's with the opaque context first,
  the panic sink's layout
- channel signatures ride the existing marshalling classes: params are
  f64/bool/string/bytes plus the u8/u32/i32 plumbing classes (outbound
  plumbing keeps JS's ToUint32/ToInt32, the executable FFI rule);
  returns are scalar only (f64/bool/u8/u32/i32/void — a buffer return
  needs an ownership contract the mode does not define). string/bytes
  parameters arrive as (ptr, len) pairs borrowed for the call's duration
- compiled code reaches a channel as a signature-only ambient function
  declaration whose direct calls deliver synchronously on the calling
  thread; the recognition rides the FFI import machinery under a library
  flavor: SC4024 refuses a call the channels cannot serve (undeclared
  name or off-class signature), unused channels are legal capacity, and
  callback-free profiles keep the ambient ReferenceError semantics
- calling an unregistered channel is the SC4025 runtime trap: a detected
  trap through the library funnel, so the structured sink message names
  the channel in its text and the entry the host called in its symbol
  field, and profile teachings/remediations overlay it like the rest of
  the runtime family
- registration slots are per copy of the runtime state, the sink's story:
  per-archive under abi.localize_runtime (the register symbol joins the
  localization keep-list), per-thread instance under
  abi.instance_per_thread. The host callback must not reenter any library
  entry or unwind across library frames
- both emissions produce identical behavior by construction: the slot
  store/fetch lives in scr_library.c (scr_library_cb_set/_require/_ctx),
  the generated TU emits the registration dispatch and typed indirect
  calls, and the trap text is assembled once at export resolution
- callback-free profiles emit byte-identical program TUs and serialized
  IR, and executable builds are byte-identical end to end
- conformance: the CB suite (tests/harness/library-callbacks.test.ts)
  covers the acceptance stream, unregistered and pre-registration traps,
  symbol exactness, teaching overlays, SC4024 refusals, capacity and
  callback-free postures, the localized+thread-instanced composition
  probe, and ASan reruns; profile-shape refusals join
  library-profile.test.ts

* fix: preserve callback binding identity

* fix: harden library callback contracts

* fix: recognize project callback declarations

* fix: enforce host callback declarations
2026-08-13 21:44:55 -05:00
Chris Tate 6f7a1a08fe feat: support thread-instanced library state (#137)
* feat: support thread-instanced library state

- Add the abi.instance_per_thread profile field: the archive's TUs compile
  with -DSCR_THREAD_INSTANCES, and the SCR_TL qualifier in scr_runtime.h
  moves every runtime unit's mutable statics into thread-local storage;
  both backends emit the program TU's module globals, run-once guards, and
  lazily-compiled regex literal caches thread-local to match
- ONE linked archive then serves one independent instance per embedder
  thread through the unchanged entry family: a thread registers its sink
  and calls the init entry, and owns its own collector, result arena,
  poison flag, and program state — a trap poisons only the instance it
  fired in while sibling threads' instances keep answering
- Document the contract beside the profile spec: one instance per thread,
  selected implicitly by the calling thread; instance lifetime is the
  thread's lifetime; the never-entered-from-two-threads rule is unchanged;
  independent of and composable with abi.localize_runtime
- Immutable interned data (string literals, unit arms, template arrays,
  vtables) stays shared — Darwin ASan's image-registration common
  included, keeping the one-registration-per-image discipline; the
  exception cell's current pointer resolves a NULL sentinel in this mode
  because a thread-local address is not a constant initializer
- Add the four-thread acceptance probe (distinct per-thread workloads,
  concurrent instance-local inits, per-instance collects, a trap delivered
  to its own thread's sink exactly once), the composition probe pairing a
  thread-instanced localized archive with a second different-prefix
  localized archive, an explicit ASan rerun beside the suite-flavor
  sanitized builds, and profile-shape coverage; schedule the new lane
  contracts beside M1/M2
- Non-opted builds are byte-for-byte unchanged: the qualifier expands to
  nothing outside -DSCR_LIB -DSCR_THREAD_INSTANCES (verified object-level
  over every touched runtime TU in both default and library flavors)

* fix: keep sanitized runtime-localized archives linkable on ELF

ASan's instrumented globals ride ELF section groups; archives built from
shared runtime objects carry groups with REPEATED signatures, so a process
linking two runtime-localized sanitized archives kept one archive's group
and discarded the other's — whose now-local references then dangled at the
embedder's link. Resolving the groups into the combined relocatable member
(ld -r --force-group-allocation) keeps every archive's copies; the
localization step then demotes them per archive exactly like unsanitized
state. Plain builds carry no section groups, so the flag is inert there.

With the groups resolved, ELF surfaces the same deliberate exception
Mach-O already documented: the image-wide registration guard COMMON stays
shared so the final image registers its ASan globals exactly once — M1/M7
now pin that spelling on both platforms. The explicit ASan pairing (M8)
additionally points Linux LSan away from contractually thread-lifetime
instance state, exactly as the sanitized suite lanes do.

* fix: isolate inspect state per thread

* fix(runtime): share uptime anchor across threads
2026-08-12 09:49:43 -05:00
Chris Tate da2ad7e002 feat: support multi-instance library mode via runtime symbol localization (#136)
* feat: support multi-instance library mode via runtime symbol localization

- Add the abi.localize_runtime profile field: the archive build combines the
  program object with exactly the runtime/vendor members it reaches and
  demotes every external definition except the profile-declared symbols to a
  local symbol (darwin: one ld -r pass with -exported_symbols_list; linux:
  ld -r then objcopy --keep-global-symbols)
- N archives built under pairwise-distinct prefixes now link into one process
  with no symbol collisions and no shared mutable runtime state: each
  instance owns a private copy of the allocator, collector, result arena, and
  panic sink, so sinks register per instance and a trap poisons only the
  instance it fired in
- Document the embedder contract beside the profile spec: one thread per
  instance (an instance is never entered from two threads), and values cross
  instances only through the embedder's own byte/record marshalling
- Refuse cross-target localized builds with SC3002 (the step runs the host
  toolchain's ld/objcopy over host-format objects); absent or false keeps the
  classic single-archive artifact byte-for-byte
- Add the two-instance acceptance probe (two archives, two embedder threads,
  independent collects, a trap delivered to its own sink exactly once while
  the other instance keeps answering) plus symbol-exactness, profile-shape,
  and target-posture suites, and schedule the artifact contracts on the gate
  host

* fix: tighten runtime localization validation

* fix: harden localized library publication
2026-08-12 02:19:37 -05:00
Chris Tate 034195f588 Profile-declared integer boundary slots prove or refuse at compile time
- An interval-and-wholeness inference over the lowered IR proves integrality and range for every value reaching a declared i64/u64 slot, with loop-header widening precise enough that the bounded counter loop proves its exact range
- Refusals carry the slot path, the failed obligation with evidence, and the author's concrete fix as SC4021, SC4022, and SC4023
- Declared slots are both obligation and assumption: call sites check arguments, callee bodies assume their classes; integer returns emit exact machine-integer wrappers and inbound params trap through the structured host-contract family
- Math.trunc and Math.ceil compile statically

# Conflicts:
#	packages/compiler/src/library/profile.ts
2026-07-24 12:07:29 -05:00
Chris Tate a2c68beadb The ask-4 conformance corpus end to end, with the sidecar attestation and inbound-trap fixtures
- tests/harness/library-int.test.ts: all 16 reference-corpus cases as library fixtures on both emissions — send/sendU64 are profile-mapped exports with i64/u64 params, PROVE cases pin every crossed value against the Node oracle (the test process runs the same case source), the counter loop crosses 0..9 in order, REFUSE cases name obligation, slot path, and evidence
- int-returns fixture: i64/u64 returns cross as real int64_t/uint64_t (9007199254740991, -0 as 0, -7 % 3 as -1, ToUint32 max on a u64 slot)
- int-trap fixture: inbound integers past 2^53-1 deliver the structured SC4012 host-contract trap with profile teaching/remediation; in-range extremes convert exactly
- Sidecar slots: integer_slots attestation in declaration order, declared slots spelled i64 (V10 bijection validated), unproven writes refused by slot path (Msg.count, helpers.clampIdx.return), unresolvable and non-number declarations refused SC4009, teachings ride SC4022 as attributed notes
- Layer-1 differential: no Layer-1 representation exists (trivially unobservable); pinned consequence — f64-declared vs i64-declared builds cross byte-identical values
- Integer-declared helpers join libRoots so their attestation covers a compiled body, never a dead-stripped vacuity
2026-07-24 11:39:43 -05:00
Chris Tate 165ca1f125 Project the attestation's ambient ground into the surface manifest so full fences imply deterministic
- The determinism attestation demoted on Date/perf_hooks/process libCalls that had no manifest entry, so the ask-5 §4 invariant (compiles under full fences => deterministic) could not be stated and the spec's own worked-example prefix stdlib.date. refused as unknown; AMBIENT_SURFACE_FNS now projects those families as permanent manifest ids (stdlib.date.*, node-builtin.perf_hooks.performance.now, node-builtin.process.*) with reach-witnessing detectors.
- BUILTIN_MODULE_FN_ALIASES folds the special-cased alternate spellings into their member detectors: the fs Buffer/fd/options/withFileTypes/watch-listener variants, the JS-ladder mkdtempSyncChk and lchmodSyncChk, crypto's composed randomBytesToString, and os.userInfo's userHomedir/userShell scalars.
- A parity test holds the two scans together over the exhaustive IrLibFn registry: every spelling LIB_NONDETERMINISTIC_PREFIXES demotes on must be deniable through a manifest-id fence, with the library-mode-refused and validate-then-fence residue pinned by name with reasons.
- The §4 invariant fixture and K14's worked fences now cover every attestation-known family, and a new K14 case pins the teeth: Date.now / process.env reads under the full-fence profile refuse SC4008 naming the entry instead of attesting deterministic: false post hoc.
- Sampling probes cover the new static entries (Date.now, process.pid, performance.now); surface-manifest.json regenerated (18 new entries, 336 total).
2026-07-24 11:25:42 -05:00
Chris Tate 72f01a3cea Fence ambient surfaces by manifest id: SC4008 denials, teachings on any refusal
- Profile fences (determinism.fences) resolve at load against this release's surface manifest: exactly one of id/prefix, unknown selectors and unpoliceable static entries refuse SC4001 loudly (ratified strictness), folded constants exempt under a prefix only
- A fenced static surface reached by the compiled library graph refuses SC4008 at the reaching construct, over the same dead-stripped module IR the deterministic attestation reads; unreached fences emit byte-identical code
- The SC4004/SC4005 teaching rider generalizes: one decoration pass attaches profile text to any library refusal by code, manifest id, or fence coverage, rendered as a visibly-attributed note line the renderer prints after the hint
- Teaching/remediation strings now refuse every control byte below 0x20 except newline and cap at 512 UTF-8 bytes; fence remediations feed profileRemediation through covered entry codes
- K14 fence conformance on both emissions, fence-family SC4001 exact-path tests, and the ask-5 §4 pin: the full-fence worked-example profile compiles and attests deterministic: true
2026-07-24 09:11:50 -05:00
Chris Tate a21a7dd035 Library mode takes the static-or-refuse posture for bare npm specifiers
- Eligible packages compile statically into the archive through the npm-static machinery, transitive deps judged to the same bar at a fixpoint
- Ineligible packages refuse with a teaching naming the package, the failed bar, and the vendor-or-drop remedy — never the executable lane's dynamic advice
- npm module bytes join source_hash and build_id; npm declarations stay out of the contract type tables by construction
- Inter-package requires run the dependency's init in both lanes

# Conflicts:
#	packages/compiler/src/diagnostics/diagnostic.ts
#	packages/compiler/src/frontend/lowering/lowerer.ts
#	packages/compiler/src/index.ts
#	tests/harness/library-mode.test.ts
2026-07-23 21:07:29 -05:00
Chris Tate f9cbff164f Library mode takes the static-or-refuse npm posture: eligible packages compile, SC4013 refuses the rest
- compileLibrary runs the --npm-static eligibility bar automatically over every bare specifier the graph exposes (opted-in packages' own import and top-level require edges included, iterated to a fixpoint) — an eligible package compiles statically into the library graph, and every fallback the shared frontend records refuses as SC4013 naming the package, the specific failed bar, and the vendor-or-drop remedy (with the profile's SC4013 teaching riding the hint), never SC1010/SC2013's executable-lane teachings.
- requireInitStmt now emits the guarded %init call for a bare require naming another opted-in package: the dep's module body never ran before (NULL-closure crash at first use), a latent npm-static gap on both lanes that the library fixpoint hits immediately; the executable lane never exercised an inter-package require.
- Contract facts exclude statically-compiled npm files (their .d.ts is dropped by construction, so no npm declaration can name a wire-contract type) while their bytes keep joining source_hash/build_id through moduleOrder; the sidecar stays byte-deterministic and a package-file edit flips both identity hashes.
- Builtins keep their story under the npm posture: async_free builtin imports compile alongside npm code, event-loop surfaces still refuse SC4005, no new fence.
- New fixtures npm-static, npm-refuse, and contract-npm vendor fake packages per the tests/fixtures/npm precedent; the K12 suites assert the compile and refusal sides on both emissions and the contract suite covers the identity-hash implications.
2026-07-23 20:06:31 -05:00
Chris Tate e1f93475cb Deliver runtime-detected library traps structured, with codes, entry symbols, and profile overlays
- The library trap funnel (scr_library.c) now assembles every detected trap into the ratified 0x01 text 0x1F code 0x1F symbol [0x1F remediation] form: the baseline human line rides unchanged as field 0, and 0x01-led messages (facade-authored throws, the compile-time SC4012 contract trap) still pass verbatim.
- Trap kinds classify over the runtime's own message conventions into a new SC4013-SC4019 runtime code family (escaped exception, range, type, syntax, OOM, internal invariant, residual), documented beside SC4012 in the diagnostics registry; no arithmetic kind exists because no runtime site can fire one.
- Every generated entry prologue (init, reset, collect, each export, both emissions) records its external symbol in a SCR_LIB-only static slot the funnel reads, so the structured message names the trapping entry as the host linked it; profile teachings/remediations for the family land as a program-TU overlay table both backends emit identically.
- K5/K7/init-trap fixtures now pin the structured layout with the spec's parse rule (default text, code, entry symbol, fields=3 on a no-teachings profile), and new K12 tests pin the SC4014 teaching/remediation overlay plus the undeclared-code default; the verbatim and text-leads-printable pins stay.
- The default executable lane is byte-identical (signature-stripped cmp over a stash/rebuild pair); all library suites and the diagnostics suite are green on both emissions.
2026-07-23 19:57:38 -05:00
Chris Tate 18f2cf2df0 Library traps carry the structured teaching encoding
- Trap messages assemble as 0x01 text 0x1F code 0x1F symbol with an optional remediation field, built once at export resolution so both backends emit identical bytes
- Thrown messages already leading with the marker pass to the sink verbatim through a length-delimited funnel entry
- Profiles refuse teaching and remediation strings containing the reserved bytes; embedder codes validate only as clean tokens
- A conformance fixture parses the structured bytes with the ten-line host rule and pins printable-first-byte on baseline messages

# Conflicts:
#	packages/compiler/src/diagnostics/diagnostic.ts
2026-07-23 18:01:24 -05:00
Chris Tate 9d811bf7b5 Pin declaration-order conformance and define-or-refuse for order-ambiguous sidecar inputs
- New contract-order conformance fixture (both emissions): union arms anti-alphabetical with payload records declared in a separate file (import order never perturbs table order), an anti-alphabetical enum with a global-shadowing "Infinity" member, and a union referenced through a type alias (the table derives from the aliased declaration; the alias adds no entry and no reordering).
- Contract facts now scan the whole program graph, not just the entry: type-only modules join (they have no runtime edge, so they ride the program's source files rather than moduleOrder), non-entry modules anchor after the entry in bytewise path order, and the identity hashes cover type-only modules so contract-bearing edits always move source_hash/build_id.
- SC4010: a tabled or designated type whose members gather from multiple declaration sites (interface merging, module augmentation, a same-name exported type in another module) refuses with every site named file:line.
- SC4011: a conditional or mapped type producing a tabled/designated type refuses with its own teaching.
- Union composition (type Msg = A | B where A/B are kind-tagged unions) is allowed and pinned: arms flatten depth-first in source order, each constituent in its own declaration order, and an arm name appearing in several constituents keeps its first occurrence; a repeat among one declaration's own inline arms still refuses.
2026-07-23 17:57:09 -05:00
Chris Tate f1b0048325 Structured trap teachings: the library sink message grows a versioned encoding
- A library-mode trap that carries a diagnostic code and/or the trapping symbol is assembled as 0x01 text 0x1F code 0x1F symbol [0x1F remediation]: the teaching text leads so plain-text hosts degrade gracefully, the whole remediation field is absent when the profile supplies none, and the frozen sink signature is untouched — all structure lives in the message bytes. The compiler assembles the buffer once at export resolution (library/trap-teaching.ts), both backends emit the same bytes, and the runtime funnel carries them opaque; the first wired site is the inbound-bytes host-contract trap (new runtime code SC4010), naming the trapping export's C symbol.
- The profile's determinism riders now feed the encoding: teachings gains a remediations sibling, both keyed by code, with keys validated only as tokens free of the reserved bytes (SC space stays the compiler registry's; embedder codes are embedder-prefixed) and values refused at load (SC4001) when they contain 0x01 or 0x1F.
- The escaped-exception renderer honors the verbatim rule: a thrown string or Error message that already begins with 0x01 reaches the sink byte-for-byte — no "Uncaught " prefix, no added newline — which is how facade-authored structured teachings ride the throw channel; everything else keeps the baseline shape, whose printable first byte is what makes the marker unambiguous.
- New K11 conformance fixture (tests/library-mode/teach) drives all of it through a real C host on both emissions: exact structured byte layout via the spec's parse rule, verbatim 0x01-led throws (Error and string), and the printable-first-byte pin on baseline trap and throw messages; library-profile tests cover the remediations round-trip and the reserved-byte refusals.
- The executable lane is untouched: every change sits behind SCR_LIB or the library emission path, verified by byte-identical executable binaries on both backends before and after.
2026-07-23 17:45:44 -05:00
Chris Tate 1ea08e4f80 Helper returns synthesize helpers_<name>: the member slot is the helper name
- The return shapeRef now seeds container 'helpers' with the helper name as the member, so an inline-record helper return tables helpers_<name> instead of helpers_<name>_return; parameter naming (helpers_<name>_<param>) is unchanged
- The contract fixture gains 'extent', a helper returning an inline record, pinning the synthesized name helpers_extent in the type table and the value-kind helper return with the arena bit
- The anti-alphabetical suite asserts the new struct entry and helper row on both emissions; V13 byte-determinism stays green
2026-07-23 15:42:03 -05:00
Chris Tate 5eecd268ef Pin the sidecar contract: anti-alphabetical fixtures and the V1-V14 suite
- the contract fixture declares every order anti-alphabetically (type names, fields, enum members, union arms, msg arms, helpers) and the harness asserts the exact orders on both emissions
- its probe reads the identity getters before init and after a poisoning trap and the harness compares both reads to the sidecar's build_id (V12 plus the ratified exemption, end to end)
- V13 rides two independent identical invocations compared hash-equal; V11 rides nm both directions over the prefix
- the contract-attest fixture pins tuple-returning init/update, subscriptions presence, the default <out>.contract.json path, the empty absent forms, and Date.now demoting deterministic to false
- the validator suite passes a full-vocabulary conformance document and catches one targeted mutation per rule, plus SC4009 refusal coverage through compileLibrary
2026-07-23 14:44:57 -05:00
Chris Tate b5e3d019fc Rename the capability: library mode, never "core", surface and internals
- CLI: the core verb becomes `scriptc build --lib --profile <p.json>` (no positional; profile names the entry); artifact renames to <name>.lib.a with .lib.ll/.lib.c/.lib.ir.json siblings
- SC4xxx diagnostic text and hints say library, never core; trap-message strings likewise (LIBRARY RC AUDIT, library reset registry, library inbound bytes)
- internals: compileLibrary/compileLibArchive, IrModule.lib + IrLibSection/IrLibExport, moduleLibAsyncSurface, libRoots, loadLibraryProfile/LibraryProfile under src/library/, frontend/lib-exports.ts, emitLibEntries/emitLibDefs
- runtime: scr_core.c -> scr_library.c with scr_library_* symbols and the SCR_LIB macro (scr_lib_* was taken by the stdlib unit); scr_lib_session_cleanup
- tests: tests/library-mode/ fixtures (entries lib.ts), library-*.test.ts harness files
2026-07-23 09:24:44 -05:00