Files
sx/examples/1045-errors-closure-var-bare-slot-reject.sx
agra 2e6e031233 ERR/E5.1: reject closure-value into bare function-pointer slot
A closure VALUE (a pre-bound variable) flowing into a bare (T)->U slot
was passed unsoundly: the bare ABI calls fn_ptr(ctx, args) with no env
channel, so the closure's underlying fn (which takes an env slot) had its
env dropped and args shifted — UB for a matching ABI, a wrong-tuple read
for the non-failable->failable widening (returned -1), and a segfault when
the closure captured.

coerceToType now rejects a .closure -> .function coercion with a
diagnostic pointing at the idiom (pass the literal directly, which gets
the static adapter, or type the parameter Closure(...) so the env is
carried). Closure LITERALS are unaffected — lowerLambda pre-adapts them to
a .function-typed value before coercion.

Regression: 1045-errors-closure-var-bare-slot-reject.sx.
2026-06-01 22:44:20 +03:00

28 lines
1.2 KiB
Plaintext

// A closure VALUE (a pre-bound variable) cannot be passed into a bare
// function-pointer slot `(...) -> ...` (ERR E5.1). The bare ABI calls
// `fn_ptr(ctx, args)` with no env channel, so a closure's environment can't be
// carried — passing one is unsound (drops env / shifts args / segfaults on a
// capturing closure). Only a closure LITERAL crosses this boundary (lowerLambda
// emits a static adapter); a variable is rejected with a pointer to the idiom.
//
// The fix for these is either to pass the literal directly, or to type the
// parameter `Closure(...)` so the environment is carried (the idiomatic form).
#import "modules/std.sx";
E :: error { Z }
bare :: (cb: (s64) -> s64, n: s64) -> s64 { return cb(n); }
baref :: (cb: (s64) -> (s64, !E), n: s64) -> s64 { return cb(n) catch e -1; }
main :: () -> s32 {
inc := closure((x: s64) -> s64 => x + 1); // capture-free closure var
base := 100;
add := closure((x: s64) -> s64 => x + base); // CAPTURING closure var
_ := bare(inc, 9); // reject: closure value → bare slot
_ := baref(inc, 9); // reject: also the ∅-widening crossing
_ := bare(add, 9); // reject: capturing closure → bare slot
return 0;
}