Add strict pointers: AS PTR TO, POINT ... AT, and the -> operator
A pointer is a distinct declared kind rather than a mode a structure can be in, which is what "strict" means here: `.` requires a structure on its left and `->` requires a pointer, neither stands in for the other, and both refusals name the operator the program should have used. So a reader always knows from the spelling whether the thing on the left is their own copy or somebody else's data. Assignment still copies. POINT is the only way to share, so a program that never writes it can never be surprised by aliasing -- and `P@ = A@` is refused with a message saying to POINT it instead, rather than quietly becoming the one assignment in the language that does not copy. PTR TO is also the only way a TYPE may refer to itself, since by value it would have no finite size. That is what makes a linked list possible, and tests/language/structures/pointers.bas builds one, walks it and renders it. Rendering follows pointers, so it needs a depth bound where copying does not: copy stops at a pointer by construction, but two nodes pointing at each other is easy to write and PRINT would not come back. Four levels, chosen so the bound bites before the 256-byte render buffer does -- otherwise a cycle would stop because it ran out of room rather than because it was told to. Three things the work turned up, all now pinned by tests: A freshly DIMmed record printed `(UNDEFINED STRING REPRESENTATION FOR 0)` for every field. Slots now take the type their field declared, so it reads as zeros. Adding POINT as a verb makes POINT unusable as a type name, and the parser reported that as "Expected expression or literal" pointing at the line rather than the problem. The prescan now refuses a reserved word as a type name and says so. Field names follow the same reserved-word rule as variable names, enforced by the loader's own scan -- `TO@` is a bad field name for exactly the reason `TO#` is a bad variable name. Recorded rather than worked around. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
32
tests/language/structures/pointers.bas
Normal file
32
tests/language/structures/pointers.bas
Normal file
@@ -0,0 +1,32 @@
|
||||
10 REM A strict pointer is a distinct declared kind. Assignment always copies;
|
||||
20 REM POINT is the only way to share, so a program that never writes it can
|
||||
30 REM never be surprised by aliasing.
|
||||
40 TYPE NODE
|
||||
50 COUNT#
|
||||
60 TAIL@ AS PTR TO NODE
|
||||
70 END TYPE
|
||||
80 DIM N1@ AS NODE
|
||||
90 DIM N2@ AS NODE
|
||||
100 DIM N3@ AS NODE
|
||||
110 N1@.COUNT# = 10
|
||||
120 N2@.COUNT# = 20
|
||||
130 N3@.COUNT# = 30
|
||||
140 REM A TYPE may refer to itself only through PTR TO, which is what makes a
|
||||
150 REM list possible at all -- by value it would have no finite size.
|
||||
160 POINT N1@.TAIL@ AT N2@
|
||||
170 POINT N2@.TAIL@ AT N3@
|
||||
180 DIM WALK@ AS PTR TO NODE
|
||||
190 POINT WALK@ AT N1@
|
||||
200 PRINT WALK@->COUNT#
|
||||
210 WALK@ = WALK@->TAIL@
|
||||
220 PRINT WALK@->COUNT#
|
||||
230 WALK@ = WALK@->TAIL@
|
||||
240 PRINT WALK@->COUNT#
|
||||
250 REM An unbound pointer is NOTHING, not a crash.
|
||||
260 PRINT WALK@->TAIL@
|
||||
270 REM Writing through a pointer changes what it points at.
|
||||
280 POINT WALK@ AT N1@
|
||||
290 WALK@->COUNT# = 99
|
||||
300 PRINT N1@.COUNT#
|
||||
310 REM And the whole list renders, following pointers as it goes.
|
||||
320 PRINT N1@
|
||||
6
tests/language/structures/pointers.txt
Normal file
6
tests/language/structures/pointers.txt
Normal file
@@ -0,0 +1,6 @@
|
||||
10
|
||||
20
|
||||
30
|
||||
NOTHING
|
||||
99
|
||||
NODE(COUNT#=99, TAIL@=NODE(COUNT#=20, TAIL@=NODE(COUNT#=30, TAIL@=NOTHING)))
|
||||
@@ -1,12 +1,12 @@
|
||||
10 REM A TYPE declares its fields; each takes its own type from its own suffix,
|
||||
20 REM which is the same rule every other name in this language follows.
|
||||
30 TYPE POINT
|
||||
30 TYPE COORD
|
||||
40 X#
|
||||
50 Y#
|
||||
60 END TYPE
|
||||
70 TYPE SHAPE
|
||||
80 NAME$
|
||||
90 ORIGIN@ AS POINT
|
||||
90 ORIGIN@ AS COORD
|
||||
100 AREA%
|
||||
110 END TYPE
|
||||
120 DIM A@ AS SHAPE
|
||||
@@ -22,7 +22,7 @@
|
||||
220 PRINT A@
|
||||
230 PRINT B@
|
||||
240 REM A whole nested record copies as a unit too.
|
||||
250 DIM P@ AS POINT
|
||||
250 DIM P@ AS COORD
|
||||
260 P@ = B@.ORIGIN@
|
||||
270 PRINT P@
|
||||
280 REM And a structure renders with its type name and its fields.
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
SHAPE(NAME$=CHANGED, ORIGIN@=POINT(X#=99, Y#=20), AREA%=2.500000)
|
||||
SHAPE(NAME$=FIRST, ORIGIN@=POINT(X#=10, Y#=20), AREA%=2.500000)
|
||||
POINT(X#=10, Y#=20)
|
||||
SHAPE(NAME$=CHANGED, ORIGIN@=COORD(X#=99, Y#=20), AREA%=2.500000)
|
||||
SHAPE(NAME$=FIRST, ORIGIN@=COORD(X#=10, Y#=20), AREA%=2.500000)
|
||||
COORD(X#=10, Y#=20)
|
||||
30
|
||||
|
||||
9
tests/language/structures/reserved_names.bas
Normal file
9
tests/language/structures/reserved_names.bas
Normal file
@@ -0,0 +1,9 @@
|
||||
10 REM A type name and a field name are bare words, and so is every verb, so
|
||||
20 REM they share a namespace whether we like it or not. Both are refused with
|
||||
30 REM the same rule the scanner already applies to variable names -- and a type
|
||||
40 REM name is refused by the prescan, which can say so plainly rather than
|
||||
50 REM leaving the parser to report "Expected expression or literal".
|
||||
60 TYPE POINT
|
||||
70 X#
|
||||
80 END TYPE
|
||||
90 PRINT 1
|
||||
2
tests/language/structures/reserved_names.txt
Normal file
2
tests/language/structures/reserved_names.txt
Normal file
@@ -0,0 +1,2 @@
|
||||
? 90 : PARSE ERROR TYPE POINT: POINT is a reserved word and cannot name a type
|
||||
|
||||
209
tests/struct_pointers.c
Normal file
209
tests/struct_pointers.c
Normal file
@@ -0,0 +1,209 @@
|
||||
/**
|
||||
* @file struct_pointers.c
|
||||
* @brief Tests strict pointers: `PTR TO`, `POINT ... AT`, and `->`.
|
||||
*
|
||||
* The assertions worth having here are the *refusals*. A pointer that works is
|
||||
* visible in tests/language/structures/; a pointer that should not have worked
|
||||
* is not, because the failure mode of a missing check is a program that keeps
|
||||
* going and gives the wrong answer later.
|
||||
*
|
||||
* "Strict" means the two operators do not stand in for one another: `.` needs a
|
||||
* structure and `->` needs a pointer, so a reader always knows from the spelling
|
||||
* whether the thing on the left is their own copy or somebody else's data.
|
||||
*/
|
||||
|
||||
#include <string.h>
|
||||
|
||||
#include <akbasic/error.h>
|
||||
#include <akbasic/runtime.h>
|
||||
#include <akbasic/structtype.h>
|
||||
|
||||
#include "harness.h"
|
||||
#include "testutil.h"
|
||||
|
||||
/** @brief A RECT, an instance, and a pointer already aimed at it. */
|
||||
static const char *PRELUDE =
|
||||
"10 TYPE RECT\n"
|
||||
"20 W#\n"
|
||||
"30 H#\n"
|
||||
"40 END TYPE\n"
|
||||
"50 DIM A@ AS RECT\n"
|
||||
"60 DIM P@ AS PTR TO RECT\n"
|
||||
"70 A@.W# = 3\n"
|
||||
"80 A@.H# = 4\n"
|
||||
"90 POINT P@ AT A@\n";
|
||||
|
||||
/** @brief Run the prelude plus @p tail, and leave the output in HARNESS_OUTPUT. */
|
||||
static akerr_ErrorContext AKERR_NOIGNORE *run_with(const char *tail)
|
||||
{
|
||||
PREPARE_ERROR(errctx);
|
||||
char source[2048];
|
||||
|
||||
snprintf(source, sizeof(source), "%s%s", PRELUDE, tail);
|
||||
PASS(errctx, harness_start(NULL));
|
||||
PASS(errctx, akbasic_runtime_load(&HARNESS_RUNTIME, source));
|
||||
PASS(errctx, akbasic_runtime_start(&HARNESS_RUNTIME, AKBASIC_MODE_RUN));
|
||||
PASS(errctx, akbasic_runtime_run(&HARNESS_RUNTIME, 4000));
|
||||
SUCCEED_RETURN(errctx);
|
||||
}
|
||||
|
||||
/** @brief Writing through a pointer changes the thing it points at. */
|
||||
static void test_pointer_writes_through(void)
|
||||
{
|
||||
TEST_REQUIRE_OK(run_with("100 P@->W# = 99\n110 PRINT A@.W#\n"));
|
||||
TEST_REQUIRE_STR(HARNESS_OUTPUT, "99\n");
|
||||
harness_stop();
|
||||
}
|
||||
|
||||
/**
|
||||
* @brief Assignment still copies, even with a pointer in the room.
|
||||
*
|
||||
* The property the whole design rests on: `POINT` is the only way to share, so
|
||||
* a program that never writes it can never be surprised by aliasing.
|
||||
*/
|
||||
static void test_assignment_still_copies(void)
|
||||
{
|
||||
TEST_REQUIRE_OK(run_with("100 DIM B@ AS RECT\n"
|
||||
"110 B@ = A@\n"
|
||||
"120 P@->W# = 7\n"
|
||||
"130 PRINT A@.W#\n"
|
||||
"140 PRINT B@.W#\n"));
|
||||
TEST_REQUIRE_STR(HARNESS_OUTPUT, "7\n3\n");
|
||||
harness_stop();
|
||||
}
|
||||
|
||||
/**
|
||||
* @brief The two operators do not stand in for one another.
|
||||
*
|
||||
* Both messages name the other operator, because the mistake is always one of
|
||||
* the two and saying which is most of the fix.
|
||||
*/
|
||||
static void test_wrong_operator_refused(void)
|
||||
{
|
||||
TEST_REQUIRE_OK(run_with("100 PRINT P@.W#\n"));
|
||||
TEST_REQUIRE(strstr(HARNESS_OUTPUT, "use -> to reach a field through a pointer") != NULL,
|
||||
"'.' on a pointer should say to use ->, got \"%s\"", HARNESS_OUTPUT);
|
||||
harness_stop();
|
||||
|
||||
TEST_REQUIRE_OK(run_with("100 PRINT A@->W#\n"));
|
||||
TEST_REQUIRE(strstr(HARNESS_OUTPUT, "use . to reach a field of a structure") != NULL,
|
||||
"'->' on a structure should say to use ., got \"%s\"", HARNESS_OUTPUT);
|
||||
harness_stop();
|
||||
}
|
||||
|
||||
/** @brief A pointer that has never been POINTed is not a null dereference. */
|
||||
static void test_unbound_pointer_refused(void)
|
||||
{
|
||||
TEST_REQUIRE_OK(run_with("100 DIM Q@ AS PTR TO RECT\n110 PRINT Q@->W#\n"));
|
||||
TEST_REQUIRE(strstr(HARNESS_OUTPUT, "not pointing at anything") != NULL,
|
||||
"an unbound pointer should refuse by name, got \"%s\"", HARNESS_OUTPUT);
|
||||
harness_stop();
|
||||
|
||||
/* And it renders as NOTHING rather than as a crash or an empty line. */
|
||||
TEST_REQUIRE_OK(run_with("100 DIM Q@ AS PTR TO RECT\n110 PRINT Q@\n"));
|
||||
TEST_REQUIRE_STR(HARNESS_OUTPUT, "NOTHING\n");
|
||||
harness_stop();
|
||||
}
|
||||
|
||||
/** @brief A pointer is to one type and will not be aimed at another. */
|
||||
static void test_pointer_type_is_checked(void)
|
||||
{
|
||||
TEST_REQUIRE_OK(run_with("100 TYPE OTHER\n"
|
||||
"110 N#\n"
|
||||
"120 END TYPE\n"
|
||||
"130 DIM O@ AS OTHER\n"
|
||||
"140 POINT P@ AT O@\n"));
|
||||
TEST_REQUIRE(strstr(HARNESS_OUTPUT, "cannot be pointed at") != NULL,
|
||||
"a pointer to RECT should refuse an OTHER, got \"%s\"", HARNESS_OUTPUT);
|
||||
harness_stop();
|
||||
}
|
||||
|
||||
/**
|
||||
* @brief A structure cannot be assigned to a pointer, and the message says why.
|
||||
*
|
||||
* The two are spelled differently on purpose. Allowing `P@ = A@` to mean "point
|
||||
* at" would make assignment sometimes copy and sometimes alias, which is the one
|
||||
* ambiguity this design exists to avoid.
|
||||
*/
|
||||
static void test_structure_not_assignable_to_pointer(void)
|
||||
{
|
||||
TEST_REQUIRE_OK(run_with("100 P@ = A@\n"));
|
||||
TEST_REQUIRE(strstr(HARNESS_OUTPUT, "POINT it AT") != NULL,
|
||||
"assigning a structure to a pointer should say to POINT it, got \"%s\"",
|
||||
HARNESS_OUTPUT);
|
||||
harness_stop();
|
||||
}
|
||||
|
||||
/**
|
||||
* @brief A list is built, walked and rendered -- the reason pointers exist.
|
||||
*
|
||||
* Walked with reassignment rather than recursion, deliberately: a recursive
|
||||
* multi-line DEF does not return in this interpreter, which is recorded in
|
||||
* TODO.md and is not this feature's to fix.
|
||||
*/
|
||||
static void test_linked_list(void)
|
||||
{
|
||||
TEST_REQUIRE_OK(harness_start(NULL));
|
||||
TEST_REQUIRE_OK(akbasic_runtime_load(&HARNESS_RUNTIME,
|
||||
"10 TYPE NODE\n"
|
||||
"20 COUNT#\n"
|
||||
"30 TAIL@ AS PTR TO NODE\n"
|
||||
"40 END TYPE\n"
|
||||
"50 DIM N1@ AS NODE\n"
|
||||
"60 DIM N2@ AS NODE\n"
|
||||
"70 N1@.COUNT# = 10\n"
|
||||
"80 N2@.COUNT# = 20\n"
|
||||
"90 POINT N1@.TAIL@ AT N2@\n"
|
||||
"100 DIM WALK@ AS PTR TO NODE\n"
|
||||
"110 POINT WALK@ AT N1@\n"
|
||||
"120 PRINT WALK@->COUNT#\n"
|
||||
"130 WALK@ = WALK@->TAIL@\n"
|
||||
"140 PRINT WALK@->COUNT#\n"));
|
||||
TEST_REQUIRE_OK(akbasic_runtime_start(&HARNESS_RUNTIME, AKBASIC_MODE_RUN));
|
||||
TEST_REQUIRE_OK(akbasic_runtime_run(&HARNESS_RUNTIME, 4000));
|
||||
TEST_REQUIRE_STR(HARNESS_OUTPUT, "10\n20\n");
|
||||
harness_stop();
|
||||
}
|
||||
|
||||
/**
|
||||
* @brief A cycle renders to a bounded depth instead of forever.
|
||||
*
|
||||
* Copy cannot follow a pointer, so no *copy* can loop -- but rendering must
|
||||
* follow one or a list would not be worth printing, and two nodes pointing at
|
||||
* each other is easy to write by accident.
|
||||
*/
|
||||
static void test_cycle_renders_bounded(void)
|
||||
{
|
||||
TEST_REQUIRE_OK(harness_start(NULL));
|
||||
TEST_REQUIRE_OK(akbasic_runtime_load(&HARNESS_RUNTIME,
|
||||
"10 TYPE NODE\n"
|
||||
"20 COUNT#\n"
|
||||
"30 TAIL@ AS PTR TO NODE\n"
|
||||
"40 END TYPE\n"
|
||||
"50 DIM A@ AS NODE\n"
|
||||
"60 DIM B@ AS NODE\n"
|
||||
"70 POINT A@.TAIL@ AT B@\n"
|
||||
"80 POINT B@.TAIL@ AT A@\n"
|
||||
"90 PRINT A@\n"));
|
||||
TEST_REQUIRE_OK(akbasic_runtime_start(&HARNESS_RUNTIME, AKBASIC_MODE_RUN));
|
||||
TEST_REQUIRE_OK(akbasic_runtime_run(&HARNESS_RUNTIME, 4000));
|
||||
TEST_REQUIRE(strstr(HARNESS_OUTPUT, "(...)") != NULL,
|
||||
"a cycle should stop at the depth bound, got \"%s\"", HARNESS_OUTPUT);
|
||||
harness_stop();
|
||||
}
|
||||
|
||||
int main(void)
|
||||
{
|
||||
TEST_REQUIRE_OK(akbasic_error_register());
|
||||
|
||||
test_pointer_writes_through();
|
||||
test_assignment_still_copies();
|
||||
test_wrong_operator_refused();
|
||||
test_unbound_pointer_refused();
|
||||
test_pointer_type_is_checked();
|
||||
test_structure_not_assignable_to_pointer();
|
||||
test_linked_list();
|
||||
test_cycle_renders_bounded();
|
||||
|
||||
return akbasic_test_failures;
|
||||
}
|
||||
@@ -76,25 +76,29 @@ static void test_nesting_flattens(void)
|
||||
akbasic_StructField *field = NULL;
|
||||
int index = -1;
|
||||
|
||||
TEST_REQUIRE_OK(declare("10 TYPE POINT\n"
|
||||
TEST_REQUIRE_OK(declare("10 TYPE COORD\n"
|
||||
"20 X#\n"
|
||||
"30 Y#\n"
|
||||
"40 END TYPE\n"
|
||||
"50 TYPE LINE\n"
|
||||
"60 FROM@ AS POINT\n"
|
||||
"70 TO@ AS POINT\n"
|
||||
"50 TYPE SEGMENT\n"
|
||||
"60 SRC@ AS COORD\n"
|
||||
"70 DEST@ AS COORD\n"
|
||||
"80 NAME$\n"
|
||||
"90 END TYPE\n"
|
||||
"100 PRINT 1\n"));
|
||||
TEST_REQUIRE_OK(akbasic_structtype_find(&HARNESS_RUNTIME.structtypes, "LINE", &index));
|
||||
TEST_REQUIRE(index >= 0, "LINE should have been declared");
|
||||
/* Two points of two slots each, plus one string: five, not three. */
|
||||
TEST_REQUIRE_OK(akbasic_structtype_find(&HARNESS_RUNTIME.structtypes, "SEGMENT", &index));
|
||||
TEST_REQUIRE(index >= 0, "SEGMENT should have been declared");
|
||||
if ( index < 0 ) {
|
||||
harness_stop();
|
||||
return;
|
||||
}
|
||||
/* Two coordinates of two slots each, plus one string: five, not three. */
|
||||
TEST_REQUIRE_INT(HARNESS_RUNTIME.structtypes.types[index].slotcount, 5);
|
||||
|
||||
TEST_REQUIRE_OK(akbasic_structtype_field(&HARNESS_RUNTIME.structtypes, index, "FROM@", &field));
|
||||
TEST_REQUIRE_OK(akbasic_structtype_field(&HARNESS_RUNTIME.structtypes, index, "SRC@", &field));
|
||||
TEST_REQUIRE_INT(field->offset, 0);
|
||||
TEST_REQUIRE_INT(field->slotcount, 2);
|
||||
TEST_REQUIRE_OK(akbasic_structtype_field(&HARNESS_RUNTIME.structtypes, index, "TO@", &field));
|
||||
TEST_REQUIRE_OK(akbasic_structtype_field(&HARNESS_RUNTIME.structtypes, index, "DEST@", &field));
|
||||
TEST_REQUIRE_INT(field->offset, 2);
|
||||
TEST_REQUIRE_OK(akbasic_structtype_field(&HARNESS_RUNTIME.structtypes, index, "NAME$", &field));
|
||||
TEST_REQUIRE_INT(field->offset, 4);
|
||||
@@ -120,6 +124,10 @@ static void test_forward_reference(void)
|
||||
"70 PRINT 1\n"));
|
||||
TEST_REQUIRE_OK(akbasic_structtype_find(&HARNESS_RUNTIME.structtypes, "OUTER", &index));
|
||||
TEST_REQUIRE(index >= 0, "OUTER should have been declared");
|
||||
if ( index < 0 ) {
|
||||
harness_stop();
|
||||
return;
|
||||
}
|
||||
TEST_REQUIRE_INT(HARNESS_RUNTIME.structtypes.types[index].slotcount, 1);
|
||||
harness_stop();
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user