3 Commits

Author SHA1 Message Date
ebec1f1621 Document environment variable creation helpers
Some checks failed
akbasic CI Build / cmake_build (push) Has been cancelled
akbasic CI Build / sanitizers (push) Has been cancelled
akbasic CI Build / coverage (push) Has been cancelled
akbasic CI Build / akgl_build (push) Has been cancelled
akbasic CI Build / mutation_test (push) Has been cancelled
2026-08-05 17:05:21 -04:00
ec4a2c23d7 Add doxygen block for environment_create_named
All checks were successful
akbasic CI Build / cmake_build (push) Successful in 3m29s
akbasic CI Build / sanitizers (push) Successful in 5m0s
akbasic CI Build / coverage (push) Successful in 4m1s
akbasic CI Build / akgl_build (push) Successful in 10m8s
akbasic CI Build / mutation_test (push) Successful in 18m44s
Andrew flagged the new helper introduced for the value-pool-leak fix
as missing documentation. akbasic_environment_create() and
akbasic_environment_create_empty() are already documented in the
header; the shared static helper they both call was the only
undocumented new function definition.

Co-authored-by: andrew <andrew@aklabs.net>
2026-08-05 11:52:30 -04:00
33cb2782ac Stop pointer parameters leaking value-pool slots
Create structure parameters before allocating their representation, then keep pointer references in the call variable's inline slot. Add an 8,000-call regression and document the remaining by-value structure escape limitation.

Co-authored-by: andrew <andrew@aklabs.net>
Co-authored-by: OpenAI Codex (GPT-5) <noreply@openai.com>
2026-08-05 11:52:30 -04:00
13 changed files with 120 additions and 110 deletions

View File

@@ -380,8 +380,10 @@ no free, so anything drawn from it is spent for the life of the run — and scop
returns a variable's *slot* without returning its storage. A scalar therefore does not
draw from it at all: `akbasic_variable_init()` points a one-element non-`@` variable at
its own `inlinevalue`, which is what makes a local, a `FOR` counter and a `DEF` parameter
free. Arrays and structures still spend, deliberately, because a pointer into a record is
allowed to outlive the scope that DIMmed it.
free. A pointer parameter is also free: it owns only its one-slot reference, so its
`inlinevalue` dies with the call while the target remains in the caller's storage. Arrays,
structures and by-value structure parameters still spend, deliberately, because a pointer
into a record is allowed to outlive the scope that DIMmed it.
[Chapter 13](13-differences.md) states the same budget from a BASIC programmer's side.
The per-environment three are reset at the top of every line, which is what makes

View File

@@ -50,7 +50,7 @@ nothing would say which type it is.
```
```output
? 10 : PARSE ERROR TYPE POINT: POINT is a reserved word and cannot name a type
? 40 : PARSE ERROR TYPE POINT: POINT is a reserved word and cannot name a type
```
@@ -266,6 +266,13 @@ The function saw 99; the caller still has 5. To change a caller's record on purp
a pointer — `DEF POKEIT(P@ AS PTR TO CRATE)` — and reach through it with `->`. Neither is
a special rule: both fall out of the parameter being assigned like any other variable.
A pointer parameter's own reference is kept in the call variable's inline slot, so repeated
calls do not spend the value pool. Its target remains the caller's structure. A by-value
structure parameter is different: its copied slots remain in the value pool because
`POINT Q@ AT B@` may retain a pointer to that copy after the function returns. Until escape
analysis can distinguish that case, **do not call a by-value structure-parameter function in
a loop**; bind a host global and rebind it per instance instead.
## What is checked, and what is not
A field name is checked against the set the type declared, and the refusal lists the

View File

@@ -246,6 +246,16 @@ akerr_ErrorContext AKERR_NOIGNORE *akbasic_environment_collect_subscripts(akbasi
*/
akerr_ErrorContext AKERR_NOIGNORE *akbasic_environment_create(akbasic_Environment *obj, const char *varname, akbasic_Variable **dest);
/**
* @brief Create a variable slot without allocating value storage.
*
* Used when the caller knows the variable's representation before its first
* initialization, such as a structure parameter. The caller must initialize
* the variable before evaluating it.
*/
akerr_ErrorContext AKERR_NOIGNORE *akbasic_environment_create_empty(akbasic_Environment *obj, const char *varname,
akbasic_Variable **dest);
/**
* @brief Resolve a label to the line number it marks.
* @param obj Scope to search; the parent chain is walked.

View File

@@ -160,21 +160,14 @@ akerr_ErrorContext *akbasic_data_scan(akbasic_Runtime *obj)
{
PREPARE_ERROR(errctx);
int64_t i = 0;
int64_t entry = 0;
FAIL_ZERO_RETURN(errctx, (obj != NULL), AKERR_NULLPOINTER, "NULL runtime in data_scan");
FAIL_ZERO_RETURN(errctx, (obj->environment != NULL), AKERR_NULLPOINTER,
"Runtime has no environment; call akbasic_runtime_init() first");
entry = obj->environment->lineno;
PASS(errctx, akbasic_data_state_init(&obj->data_state));
for ( i = 0; i < AKBASIC_MAX_SOURCE_LINES; i++ ) {
if ( obj->source[i].code[0] != '\0' ) {
/* Keep BASIC's error prefix on the source line being prescanned. */
obj->environment->lineno = i;
PASS(errctx, scan_line(&obj->data_state, obj->source[i].code, i));
}
}
obj->environment->lineno = entry;
SUCCEED_RETURN(errctx);
}

View File

@@ -306,7 +306,23 @@ akerr_ErrorContext *akbasic_environment_get(akbasic_Environment *obj, const char
SUCCEED_RETURN(errctx);
}
akerr_ErrorContext *akbasic_environment_create(akbasic_Environment *obj, const char *varname, akbasic_Variable **dest)
/**
* @brief Create a variable slot in the given scope, optionally allocating its storage.
*
* Shared by akbasic_environment_create() and akbasic_environment_create_empty(),
* which differ only in whether the new variable's value storage is initialized
* immediately or left for the caller to set up.
*
* @param obj Scope the variable is created in; only this scope is searched or
* written to, unlike akbasic_environment_get()'s walk up the parent chain.
* @param varname Name of the variable to create.
* @param dest Set to the created (or already-existing) variable.
* @param initialize When true, the variable's value storage is allocated from
* the runtime's value pool; when false, the caller must initialize it
* before the variable is evaluated.
*/
static akerr_ErrorContext *environment_create_named(akbasic_Environment *obj, const char *varname,
akbasic_Variable **dest, bool initialize)
{
PREPARE_ERROR(errctx);
akbasic_Variable *variable = NULL;
@@ -340,12 +356,49 @@ akerr_ErrorContext *akbasic_environment_create(akbasic_Environment *obj, const c
PASS(errctx, aksl_strcpy(variable->name, sizeof(variable->name), varname));
variable->valuetype = AKBASIC_TYPE_UNDEFINED;
variable->mutable_ = true;
PASS(errctx, akbasic_variable_init(variable, &obj->runtime->valuepool, sizes, 1));
if ( initialize ) {
PASS(errctx, akbasic_variable_init(variable, &obj->runtime->valuepool, sizes, 1));
}
PASS(errctx, akbasic_symtab_set(&obj->variables, varname, variable, 0));
*dest = variable;
SUCCEED_RETURN(errctx);
}
/**
* @brief Find a variable in this scope, creating and initializing it if absent.
*
* @param obj The scope to search and, on a miss, to create in.
* @param varname Name including its type suffix.
* @param dest Output destination populated with the variable.
* @return `NULL` on success, otherwise an error context owned by the caller.
*/
akerr_ErrorContext *akbasic_environment_create(akbasic_Environment *obj, const char *varname, akbasic_Variable **dest)
{
PREPARE_ERROR(errctx);
PASS(errctx, environment_create_named(obj, varname, dest, true));
SUCCEED_RETURN(errctx);
}
/**
* @brief Find a variable in this scope, creating it without value storage if absent.
*
* The caller must initialize the variable before evaluating it.
*
* @param obj The scope to search and, on a miss, to create in.
* @param varname Name including its type suffix.
* @param dest Output destination populated with the variable.
* @return `NULL` on success, otherwise an error context owned by the caller.
*/
akerr_ErrorContext *akbasic_environment_create_empty(akbasic_Environment *obj, const char *varname,
akbasic_Variable **dest)
{
PREPARE_ERROR(errctx);
PASS(errctx, environment_create_named(obj, varname, dest, false));
SUCCEED_RETURN(errctx);
}
/*
* Evaluate an lvalue's subscript list, if it has one, into `subscripts`. A bare
* identifier yields the single subscript {0}, which is how a scalar is addressed

View File

@@ -989,12 +989,13 @@ static akerr_ErrorContext *bind_structure_parameter(akbasic_Runtime *obj, akbasi
obj->structtypes.types[typeindex].name,
obj->structtypes.types[argvalue->structtype].name);
PASS(errctx, akbasic_environment_create(callenv, param->identifier, &variable));
PASS(errctx, akbasic_environment_create_empty(callenv, param->identifier, &variable));
sizes[0] = (ispointer ? 1 : obj->structtypes.types[typeindex].slotcount);
/* A pointer parameter's own reference cannot escape its call scope. */
variable->ispointer = ispointer;
PASS(errctx, akbasic_variable_init(variable, &obj->valuepool, sizes, 1));
variable->valuetype = AKBASIC_TYPE_STRUCT;
variable->structtype = typeindex;
variable->ispointer = ispointer;
if ( ispointer ) {
PASS(errctx, akbasic_value_clone(argvalue, &variable->values[0]));
@@ -1600,22 +1601,17 @@ akerr_ErrorContext *akbasic_runtime_scan_labels(akbasic_Runtime *obj)
PREPARE_ERROR(errctx);
akbasic_Environment *root = NULL;
int64_t i = 0;
int64_t entry = 0;
FAIL_ZERO_RETURN(errctx, (obj != NULL), AKERR_NULLPOINTER, "NULL runtime in scan_labels");
FAIL_ZERO_RETURN(errctx, (obj->environment != NULL), AKERR_NULLPOINTER,
"Runtime has no environment; call akbasic_runtime_init() first");
for ( root = obj->environment; root->parent != NULL; root = root->parent ) {
}
entry = obj->environment->lineno;
for ( i = 0; i < AKBASIC_MAX_SOURCE_LINES; i++ ) {
if ( obj->source[i].code[0] != '\0' ) {
/* Keep BASIC's error prefix on the source line being prescanned. */
obj->environment->lineno = i;
PASS(errctx, scan_line_labels(root, obj->source[i].code, i));
}
}
obj->environment->lineno = entry;
SUCCEED_RETURN(errctx);
}

View File

@@ -260,13 +260,11 @@ static akerr_ErrorContext *scan_names(akbasic_Runtime *obj)
size_t namelen = 0;
bool matched = false;
const akbasic_Verb *verb = NULL;
int64_t entry = obj->environment->lineno;
for ( i = 0; i < AKBASIC_MAX_SOURCE_LINES; i++ ) {
if ( obj->source[i].code[0] == '\0' ) {
continue;
}
obj->environment->lineno = i;
cursor = next_word(skip_lineno(obj->source[i].code), word, sizeof(word));
PASS(errctx, word_is(word, "END", &matched));
@@ -329,7 +327,6 @@ static akerr_ErrorContext *scan_names(akbasic_Runtime *obj)
FAIL_NONZERO_RETURN(errctx, (open >= 0), AKBASIC_ERR_SYNTAX,
"TYPE %s is never closed with END TYPE", table->types[open >= 0 ? open : 0].name);
obj->environment->lineno = entry;
SUCCEED_RETURN(errctx);
}
@@ -443,7 +440,7 @@ static akerr_ErrorContext *parse_field(akbasic_StructTypeTable *table, akbasic_S
* each other by value, which has no finite size. That is the diagnosis rather
* than a stack overflow later.
*/
static akerr_ErrorContext *resolve_sizes(akbasic_Runtime *runtime, akbasic_StructTypeTable *table)
static akerr_ErrorContext *resolve_sizes(akbasic_StructTypeTable *table)
{
PREPARE_ERROR(errctx);
bool progress = true;
@@ -480,7 +477,6 @@ static akerr_ErrorContext *resolve_sizes(akbasic_Runtime *runtime, akbasic_Struc
}
for ( i = 0; i < table->count; i++ ) {
runtime->environment->lineno = table->types[i].firstline;
FAIL_NONZERO_RETURN(errctx, (table->types[i].slotcount < 0), AKBASIC_ERR_VALUE,
"TYPE %s contains itself by value, so it has no size. "
"A type may only refer to itself through PTR TO",
@@ -497,13 +493,9 @@ akerr_ErrorContext *akbasic_structtype_scan(akbasic_Runtime *obj)
akbasic_StructTypeTable *table = NULL;
int64_t i = 0;
int t = 0;
int64_t entry = 0;
FAIL_ZERO_RETURN(errctx, (obj != NULL), AKERR_NULLPOINTER, "NULL runtime in structtype scan");
FAIL_ZERO_RETURN(errctx, (obj->environment != NULL), AKERR_NULLPOINTER,
"Runtime has no environment; call akbasic_runtime_init() first");
table = &obj->structtypes;
entry = obj->environment->lineno;
/*
* Drop what the *script* declared and keep what the *host* registered.
@@ -533,12 +525,10 @@ akerr_ErrorContext *akbasic_structtype_scan(akbasic_Runtime *obj)
if ( obj->source[i].code[0] == '\0' ) {
continue;
}
obj->environment->lineno = i;
PASS(errctx, parse_field(table, type, obj->source[i].code, i));
}
}
PASS(errctx, resolve_sizes(obj, table));
obj->environment->lineno = entry;
PASS(errctx, resolve_sizes(table));
SUCCEED_RETURN(errctx);
}

View File

@@ -99,18 +99,21 @@ akerr_ErrorContext *akbasic_variable_init(akbasic_Variable *obj, akbasic_ValuePo
* the run was over, which a game loop reaches in half a minute. TODO.md
* section 6 item 30 has the whole reduction.
*
* **A `@` name is the one exclusion**, and it is the whole of it. A
* structure or a pointer to one keeps pool storage because a pointer may
* outlive the scope that DIMmed it -- docs/16-structures.md says nothing is
* reclaimed and akbasic_runtime_prev_environment() relies on it. The suffix
* is the right test rather than `structtype`, which the DIM path sets
* **A `@` name is the one exclusion**, except for a one-slot pointer
* parameter. A structure or a pointer variable keeps pool storage because
* a pointer may outlive the scope that DIMmed it -- docs/16-structures.md
* says nothing is reclaimed and akbasic_runtime_prev_environment() relies
* on it. A pointer parameter owns only its reference slot; the target is
* owned by the caller, so bind_structure_parameter() marks it before this
* call and lets that slot use inline storage. The suffix is the right test
* for every other case rather than `structtype`, which the DIM path sets
* *after* calling this.
*
* Otherwise: reuse the existing slice when it is already big enough, which
* makes a re-DIM to the same or a smaller size free; growing takes fresh
* slots and abandons the old ones, as documented on akbasic_ValuePool.
*/
if ( totalsize == 1 && lastchar != '@' ) {
if ( totalsize == 1 && (lastchar != '@' || obj->ispointer) ) {
obj->values = &obj->inlinevalue;
} else if ( obj->values == NULL || obj->valuecount < (int)totalsize ) {
PASS(errctx, akbasic_valuepool_take(pool, (int)totalsize, &obj->values));

View File

@@ -16,8 +16,6 @@
* below.
*/
#include <stdio.h>
#include "harness.h"
/**
@@ -343,28 +341,6 @@ static akerr_ErrorContext AKERR_NOIGNORE *test_prescan_boundaries(void)
SUCCEED_RETURN(errctx);
}
/** @brief A full label table reports the line whose label could not be filed. */
static void test_label_prescan_error_line(void)
{
char source[4096] = "";
size_t used = 0;
int i = 0;
for ( i = 1; i <= AKBASIC_MAX_LABELS + 1; i++ ) {
used += (size_t)snprintf(source + used, sizeof(source) - used,
"%d LABEL L%d\n", i, i);
}
(void)snprintf(source + used, sizeof(source) - used, "100 PRINT 1\n");
TEST_REQUIRE_OK(harness_start(NULL));
TEST_REQUIRE_OK(akbasic_runtime_load(&HARNESS_RUNTIME, source));
TEST_REQUIRE_OK(akbasic_runtime_start(&HARNESS_RUNTIME, AKBASIC_MODE_RUN));
TEST_REQUIRE(strstr(HARNESS_OUTPUT, "? 65 : PARSE ERROR") != NULL,
"a full label table should report its source line, got \"%s\"",
HARNESS_OUTPUT);
harness_stop();
}
int main(void)
{
PREPARE_ERROR(errctx);
@@ -379,7 +355,6 @@ int main(void)
CATCH(errctx, test_undefined_label_is_reported());
CATCH(errctx, test_arm_refusals());
CATCH(errctx, test_prescan_boundaries());
test_label_prescan_error_line();
} CLEANUP {
} PROCESS(errctx) {
} HANDLE_DEFAULT(errctx) {

View File

@@ -1,2 +1,2 @@
? 60 : PARSE ERROR TYPE POINT: POINT is a reserved word and cannot name a type
? 90 : PARSE ERROR TYPE POINT: POINT is a reserved word and cannot name a type

View File

@@ -8,7 +8,6 @@
* TODO.md section 6.
*/
#include <stdio.h>
#include <string.h>
#include <akbasic/error.h>
@@ -175,34 +174,6 @@ static void test_colon_ends_data(void)
harness_stop();
}
/** @brief DATA overflow reports the line where the item limit was crossed. */
static void test_data_prescan_error_line(void)
{
char source[4096] = "";
size_t used = 0;
int line = 0;
int item = 0;
for ( line = 1; line <= 34; line++ ) {
used += (size_t)snprintf(source + used, sizeof(source) - used, "%d DATA ", line);
for ( item = 0; item < 15; item++ ) {
used += (size_t)snprintf(source + used, sizeof(source) - used,
"%s1", (item == 0 ? "" : ","));
}
used += (size_t)snprintf(source + used, sizeof(source) - used, "\n");
}
used += (size_t)snprintf(source + used, sizeof(source) - used, "100 DATA 1,1\n");
(void)snprintf(source + used, sizeof(source) - used, "101 DATA 1\n200 PRINT 1\n");
TEST_REQUIRE_OK(harness_start(NULL));
TEST_REQUIRE_OK(akbasic_runtime_load(&HARNESS_RUNTIME, source));
TEST_REQUIRE_OK(akbasic_runtime_start(&HARNESS_RUNTIME, AKBASIC_MODE_RUN));
TEST_REQUIRE(strstr(HARNESS_OUTPUT, "? 101 : PARSE ERROR") != NULL,
"DATA overflow should report its source line, got \"%s\"",
HARNESS_OUTPUT);
harness_stop();
}
/** @brief A float item fills a float variable with its fractional part intact. */
static void test_float_items(void)
{
@@ -256,7 +227,6 @@ int main(void)
test_type_mismatch();
test_quoted_items();
test_colon_ends_data();
test_data_prescan_error_line();
test_float_items();
test_negative_items();
return akbasic_test_failures;

View File

@@ -218,22 +218,6 @@ static void test_declaration_errors_are_basic_errors(void)
}
}
/** @brief A field declaration error reports the field's source line. */
static void test_type_prescan_error_line(void)
{
TEST_REQUIRE_OK(harness_start(NULL));
TEST_REQUIRE_OK(akbasic_runtime_load(&HARNESS_RUNTIME,
"10 TYPE RECT\n"
"20 W# EXTRA\n"
"30 END TYPE\n"
"40 PRINT 1\n"));
TEST_REQUIRE_OK(akbasic_runtime_start(&HARNESS_RUNTIME, AKBASIC_MODE_RUN));
TEST_REQUIRE(strstr(HARNESS_OUTPUT, "? 20 : PARSE ERROR") != NULL,
"TYPE prescan should report its source line, got \"%s\"",
HARNESS_OUTPUT);
harness_stop();
}
/**
* @brief An over-long type or field name is refused, not silently trimmed.
*
@@ -286,7 +270,6 @@ int main(void)
test_missing_field_lists_the_others();
test_self_by_value_refused();
test_declaration_errors_are_basic_errors();
test_type_prescan_error_line();
test_long_names_are_refused();
return akbasic_test_failures;

View File

@@ -183,6 +183,33 @@ static void test_structure_parameters(void)
harness_stop();
}
/**
* @brief Pointer parameters do not consume value-pool slots per call.
*
* The pointer's parameter variable owns only one reference to the caller's
* record, so that reference can live in the variable's inline slot. The target
* remains in the caller's storage. One pointer parameter and 8,000 calls make
* one leaked slot per call fail against the 4,096-slot value pool.
*/
static void test_pointer_parameters_do_not_leak_value_slots(void)
{
TEST_REQUIRE_OK(run_program_bounded("10 TYPE CRATE\n"
"20 W#\n"
"30 END TYPE\n"
"40 DIM A@ AS CRATE\n"
"50 DIM P@ AS PTR TO CRATE\n"
"60 POINT P@ AT A@\n"
"70 DEF POKEIT(P@ AS PTR TO CRATE)\n"
"80 P@->W# = P@->W# + 1\n"
"90 RETURN P@->W#\n"
"100 FOR I# = 1 TO 8000\n"
"110 R# = POKEIT(P@)\n"
"120 NEXT I#\n"
"130 PRINT A@.W#\n", 1000000));
TEST_REQUIRE_STR(HARNESS_OUTPUT, "8000\n");
harness_stop();
}
/**
* @brief A structure parameter must name its type, and the type is checked.
*
@@ -454,6 +481,7 @@ int main(void)
test_runaway_recursion_is_diagnosed();
test_single_expression_form();
test_structure_parameters();
test_pointer_parameters_do_not_leak_value_slots();
test_structure_parameter_types_are_checked();
test_call_scopes_are_reclaimed();
test_calls_do_not_leak_value_slots();