ERR/E1.8: path-sensitive value-slot liveness check
A `v, err := failable()` destructure now binds the value slot(s) "live
only where `err` is proven absent". Reading `v` where the compiler cannot
prove `err == null` is a compile error.
New diagnostic-only Pass 1e (`checkErrorFlow` in ir/lower.zig): a
structured, path-sensitive walk over each main-file function body. A
proven-null set is threaded across branches and joined by intersection
at each `if`'s merge. Proof shapes recognized:
- `if !err { … v … }` (proven inside the guard)
- `if err { return/raise } … v` (proven on the fall-through)
- `if err { … } else { … v … }` (proven in the else branch)
- `!err and <reads v>` (short-circuit refinement)
Error-set tag compares (`if err == error.X`) prove nothing about
absence — they narrow the tag only. Nested lambdas are analyzed as their
own boundaries. Library modules are trusted (skipped).
Migrated the canon value-failable examples (1011/1012/1018/1044) to read
their value slots under `if !err` guards — output unchanged. New
regressions: 1046 (every proof shape compiles + runs, exit 210) and 1047
(unproven reads rejected, exit 1).
Gates: zig build, zig build test, run_examples.sh -> 338 passed, 0 failed.
This commit is contained in:
@@ -46,8 +46,7 @@ classify :: (n: s32) -> s32 {
|
||||
main :: () -> s32 {
|
||||
r : s32 = 0;
|
||||
a, ea := inc(5); // parse(5)=10 → v=10 → 11
|
||||
if ea == error.Bad { r = r + 100; } // false
|
||||
r = r + a; // +11
|
||||
if !ea { r = r + a; } // success → +11 (value live only when proven ok)
|
||||
b, eb := inc(-1); // parse(-1)=Bad → propagate {undef, Bad}
|
||||
if eb == error.Bad { r = r + 4; } // true → +4
|
||||
er := relay(3); // parse(3)=6 ok → relay ok
|
||||
|
||||
Reference in New Issue
Block a user