3 Commits
12 ... 36

Author SHA1 Message Date
ebec1f1621 Document environment variable creation helpers
Some checks failed
akbasic CI Build / cmake_build (push) Has been cancelled
akbasic CI Build / sanitizers (push) Has been cancelled
akbasic CI Build / coverage (push) Has been cancelled
akbasic CI Build / akgl_build (push) Has been cancelled
akbasic CI Build / mutation_test (push) Has been cancelled
2026-08-05 17:05:21 -04:00
ec4a2c23d7 Add doxygen block for environment_create_named
All checks were successful
akbasic CI Build / cmake_build (push) Successful in 3m29s
akbasic CI Build / sanitizers (push) Successful in 5m0s
akbasic CI Build / coverage (push) Successful in 4m1s
akbasic CI Build / akgl_build (push) Successful in 10m8s
akbasic CI Build / mutation_test (push) Successful in 18m44s
Andrew flagged the new helper introduced for the value-pool-leak fix
as missing documentation. akbasic_environment_create() and
akbasic_environment_create_empty() are already documented in the
header; the shared static helper they both call was the only
undocumented new function definition.

Co-authored-by: andrew <andrew@aklabs.net>
2026-08-05 11:52:30 -04:00
33cb2782ac Stop pointer parameters leaking value-pool slots
Create structure parameters before allocating their representation, then keep pointer references in the call variable's inline slot. Add an 8,000-call regression and document the remaining by-value structure escape limitation.

Co-authored-by: andrew <andrew@aklabs.net>
Co-authored-by: OpenAI Codex (GPT-5) <noreply@openai.com>
2026-08-05 11:52:30 -04:00
9 changed files with 130 additions and 71 deletions

View File

@@ -380,8 +380,10 @@ no free, so anything drawn from it is spent for the life of the run — and scop
returns a variable's *slot* without returning its storage. A scalar therefore does not
draw from it at all: `akbasic_variable_init()` points a one-element non-`@` variable at
its own `inlinevalue`, which is what makes a local, a `FOR` counter and a `DEF` parameter
free. Arrays and structures still spend, deliberately, because a pointer into a record is
allowed to outlive the scope that DIMmed it.
free. A pointer parameter is also free: it owns only its one-slot reference, so its
`inlinevalue` dies with the call while the target remains in the caller's storage. Arrays,
structures and by-value structure parameters still spend, deliberately, because a pointer
into a record is allowed to outlive the scope that DIMmed it.
[Chapter 13](13-differences.md) states the same budget from a BASIC programmer's side.
The per-environment three are reset at the top of every line, which is what makes

View File

@@ -266,6 +266,13 @@ The function saw 99; the caller still has 5. To change a caller's record on purp
a pointer — `DEF POKEIT(P@ AS PTR TO CRATE)` — and reach through it with `->`. Neither is
a special rule: both fall out of the parameter being assigned like any other variable.
A pointer parameter's own reference is kept in the call variable's inline slot, so repeated
calls do not spend the value pool. Its target remains the caller's structure. A by-value
structure parameter is different: its copied slots remain in the value pool because
`POINT Q@ AT B@` may retain a pointer to that copy after the function returns. Until escape
analysis can distinguish that case, **do not call a by-value structure-parameter function in
a loop**; bind a host global and rebind it per instance instead.
## What is checked, and what is not
A field name is checked against the set the type declared, and the refusal lists the

View File

@@ -246,6 +246,16 @@ akerr_ErrorContext AKERR_NOIGNORE *akbasic_environment_collect_subscripts(akbasi
*/
akerr_ErrorContext AKERR_NOIGNORE *akbasic_environment_create(akbasic_Environment *obj, const char *varname, akbasic_Variable **dest);
/**
* @brief Create a variable slot without allocating value storage.
*
* Used when the caller knows the variable's representation before its first
* initialization, such as a structure parameter. The caller must initialize
* the variable before evaluating it.
*/
akerr_ErrorContext AKERR_NOIGNORE *akbasic_environment_create_empty(akbasic_Environment *obj, const char *varname,
akbasic_Variable **dest);
/**
* @brief Resolve a label to the line number it marks.
* @param obj Scope to search; the parent chain is walked.

View File

@@ -118,12 +118,6 @@ typedef struct akbasic_Runtime
{
akbasic_SourceLine source[AKBASIC_MAX_SOURCE_LINES];
/* Scratch owned by this runtime for RENUMBER and its target prescan. */
int16_t renumber_map[AKBASIC_MAX_SOURCE_LINES];
uint8_t renumber_visited[AKBASIC_MAX_SOURCE_LINES];
akbasic_SourceLine renumber_line;
char renumber_discard[AKBASIC_MAX_LINE_LENGTH * 2];
/* Pools. Nothing here is malloc'd; everything is drawn from and returned. */
akbasic_Environment environments[AKBASIC_MAX_ENVIRONMENTS];
akbasic_Variable variables[AKBASIC_MAX_VARIABLES];

View File

@@ -306,7 +306,23 @@ akerr_ErrorContext *akbasic_environment_get(akbasic_Environment *obj, const char
SUCCEED_RETURN(errctx);
}
akerr_ErrorContext *akbasic_environment_create(akbasic_Environment *obj, const char *varname, akbasic_Variable **dest)
/**
* @brief Create a variable slot in the given scope, optionally allocating its storage.
*
* Shared by akbasic_environment_create() and akbasic_environment_create_empty(),
* which differ only in whether the new variable's value storage is initialized
* immediately or left for the caller to set up.
*
* @param obj Scope the variable is created in; only this scope is searched or
* written to, unlike akbasic_environment_get()'s walk up the parent chain.
* @param varname Name of the variable to create.
* @param dest Set to the created (or already-existing) variable.
* @param initialize When true, the variable's value storage is allocated from
* the runtime's value pool; when false, the caller must initialize it
* before the variable is evaluated.
*/
static akerr_ErrorContext *environment_create_named(akbasic_Environment *obj, const char *varname,
akbasic_Variable **dest, bool initialize)
{
PREPARE_ERROR(errctx);
akbasic_Variable *variable = NULL;
@@ -340,12 +356,49 @@ akerr_ErrorContext *akbasic_environment_create(akbasic_Environment *obj, const c
PASS(errctx, aksl_strcpy(variable->name, sizeof(variable->name), varname));
variable->valuetype = AKBASIC_TYPE_UNDEFINED;
variable->mutable_ = true;
PASS(errctx, akbasic_variable_init(variable, &obj->runtime->valuepool, sizes, 1));
if ( initialize ) {
PASS(errctx, akbasic_variable_init(variable, &obj->runtime->valuepool, sizes, 1));
}
PASS(errctx, akbasic_symtab_set(&obj->variables, varname, variable, 0));
*dest = variable;
SUCCEED_RETURN(errctx);
}
/**
* @brief Find a variable in this scope, creating and initializing it if absent.
*
* @param obj The scope to search and, on a miss, to create in.
* @param varname Name including its type suffix.
* @param dest Output destination populated with the variable.
* @return `NULL` on success, otherwise an error context owned by the caller.
*/
akerr_ErrorContext *akbasic_environment_create(akbasic_Environment *obj, const char *varname, akbasic_Variable **dest)
{
PREPARE_ERROR(errctx);
PASS(errctx, environment_create_named(obj, varname, dest, true));
SUCCEED_RETURN(errctx);
}
/**
* @brief Find a variable in this scope, creating it without value storage if absent.
*
* The caller must initialize the variable before evaluating it.
*
* @param obj The scope to search and, on a miss, to create in.
* @param varname Name including its type suffix.
* @param dest Output destination populated with the variable.
* @return `NULL` on success, otherwise an error context owned by the caller.
*/
akerr_ErrorContext *akbasic_environment_create_empty(akbasic_Environment *obj, const char *varname,
akbasic_Variable **dest)
{
PREPARE_ERROR(errctx);
PASS(errctx, environment_create_named(obj, varname, dest, false));
SUCCEED_RETURN(errctx);
}
/*
* Evaluate an lvalue's subscript list, if it has one, into `subscripts`. A bare
* identifier yields the single subscript {0}, which is how a scalar is addressed

View File

@@ -72,7 +72,7 @@ struct akbasic_TargetWalk
* rewritten: `GOTO 9999` in a program with no line 9999 is already broken, and
* inventing a destination for it would hide that.
*/
static int64_t mapped(const int16_t *map, int64_t line)
static int64_t mapped(const int64_t *map, int64_t line)
{
if ( line < 0 || line >= AKBASIC_MAX_SOURCE_LINES ) {
return line;
@@ -306,7 +306,7 @@ static akerr_ErrorContext *rewrite_line(akbasic_TargetWalk *walk, const char *co
static akerr_ErrorContext *visit_renumber(akbasic_TargetWalk *walk, int64_t target, char *dest, size_t len)
{
PREPARE_ERROR(errctx);
const int16_t *map = (const int16_t *)walk->self;
const int64_t *map = (const int64_t *)walk->self;
int written = 0;
PASS(errctx, aksl_snprintf(&written, dest, len, "%" PRId64, mapped(map, target)));
@@ -316,7 +316,8 @@ static akerr_ErrorContext *visit_renumber(akbasic_TargetWalk *walk, int64_t targ
akerr_ErrorContext *akbasic_renumber(akbasic_Runtime *obj, int64_t newstart, int64_t increment, int64_t oldstart)
{
PREPARE_ERROR(errctx);
int16_t *map = obj == NULL ? NULL : obj->renumber_map;
static int64_t map[AKBASIC_MAX_SOURCE_LINES];
static akbasic_SourceLine rewritten[AKBASIC_MAX_SOURCE_LINES];
akbasic_TargetWalk walk = { map, visit_renumber };
int64_t next = newstart;
int64_t i = 0;
@@ -355,8 +356,10 @@ akerr_ErrorContext *akbasic_renumber(akbasic_Runtime *obj, int64_t newstart, int
next += increment;
}
PASS(errctx, aksl_memset(obj->renumber_visited, 0, sizeof(obj->renumber_visited)));
PASS(errctx, aksl_memset(rewritten, 0, sizeof(rewritten)));
for ( i = 0; i < AKBASIC_MAX_SOURCE_LINES; i++ ) {
int64_t target = 0;
if ( obj->source[i].code[0] == '\0' ) {
continue;
}
@@ -364,62 +367,20 @@ akerr_ErrorContext *akbasic_renumber(akbasic_Runtime *obj, int64_t newstart, int
* Every line is rewritten, not just the moved ones: a line before
* `oldstart` can branch into the region that moved.
*/
target = mapped(map, i);
PASS(errctx, rewrite_line(&walk, obj->source[i].code,
obj->renumber_line.code, sizeof(obj->renumber_line.code)));
obj->renumber_line.lineno = i;
rewritten[target].code, sizeof(rewritten[target].code)));
rewritten[target].lineno = target;
/*
* Every line comes out numbered, whether or not it went in that way.
* Asking for numbers is what RENUMBER is, and a program that has been
* through it can be branched into by number -- which is the whole point
* of running it over source that arrived without any.
*/
obj->renumber_line.numbered = true;
PASS(errctx, aksl_memcpy(&obj->source[i], &obj->renumber_line,
sizeof(obj->source[i])));
rewritten[target].numbered = true;
}
/* Move the already-rewritten lines in place. The map is a partial
* permutation: a chain ends at an empty slot, while a cycle closes back
* on its starting line. A single displaced line is sufficient for both. */
for ( i = 0; i < AKBASIC_MAX_SOURCE_LINES; i++ ) {
int64_t current = i;
akbasic_SourceLine displaced;
akbasic_SourceLine next_line;
if ( map[i] < 0 || obj->renumber_visited[i] ) {
continue;
}
PASS(errctx, aksl_memcpy(&displaced, &obj->source[i], sizeof(displaced)));
for ( ;; ) {
int64_t destination = map[current];
obj->renumber_visited[current] = 1;
if ( destination == i ) {
displaced.lineno = destination;
PASS(errctx, aksl_memcpy(&obj->source[destination], &displaced,
sizeof(displaced)));
break;
}
if ( map[destination] < 0 ) {
displaced.lineno = destination;
PASS(errctx, aksl_memcpy(&obj->source[destination], &displaced,
sizeof(displaced)));
PASS(errctx, aksl_memset(&obj->source[current], 0,
sizeof(obj->source[current])));
break;
}
PASS(errctx, aksl_memcpy(&next_line, &obj->source[destination],
sizeof(displaced)));
displaced.lineno = destination;
PASS(errctx, aksl_memcpy(&obj->source[destination], &displaced,
sizeof(obj->renumber_line)));
PASS(errctx, aksl_memset(&obj->source[current], 0,
sizeof(obj->source[current])));
PASS(errctx, aksl_memcpy(&displaced, &next_line,
sizeof(displaced)));
current = destination;
}
}
PASS(errctx, aksl_memcpy(obj->source, rewritten, sizeof(obj->source)));
SUCCEED_RETURN(errctx);
}
@@ -474,6 +435,7 @@ akerr_ErrorContext *akbasic_runtime_check_targets(akbasic_Runtime *obj)
* step(). Nothing is read back out of it -- the walk needs somewhere to put
* the text it would have written, and this is it.
*/
static char discard[AKBASIC_MAX_LINE_LENGTH * 2];
CheckState state = { NULL, 0 };
akbasic_TargetWalk walk = { &state, visit_check };
int64_t entry = 0;
@@ -501,8 +463,7 @@ akerr_ErrorContext *akbasic_runtime_check_targets(akbasic_Runtime *obj)
* the whole point of setting it.
*/
obj->environment->lineno = i;
PASS(errctx, rewrite_line(&walk, obj->source[i].code,
obj->renumber_discard, sizeof(obj->renumber_discard)));
PASS(errctx, rewrite_line(&walk, obj->source[i].code, discard, sizeof(discard)));
}
/* Nothing was refused, so leave the cursor as the caller had it. */
obj->environment->lineno = entry;

View File

@@ -989,12 +989,13 @@ static akerr_ErrorContext *bind_structure_parameter(akbasic_Runtime *obj, akbasi
obj->structtypes.types[typeindex].name,
obj->structtypes.types[argvalue->structtype].name);
PASS(errctx, akbasic_environment_create(callenv, param->identifier, &variable));
PASS(errctx, akbasic_environment_create_empty(callenv, param->identifier, &variable));
sizes[0] = (ispointer ? 1 : obj->structtypes.types[typeindex].slotcount);
/* A pointer parameter's own reference cannot escape its call scope. */
variable->ispointer = ispointer;
PASS(errctx, akbasic_variable_init(variable, &obj->valuepool, sizes, 1));
variable->valuetype = AKBASIC_TYPE_STRUCT;
variable->structtype = typeindex;
variable->ispointer = ispointer;
if ( ispointer ) {
PASS(errctx, akbasic_value_clone(argvalue, &variable->values[0]));

View File

@@ -99,18 +99,21 @@ akerr_ErrorContext *akbasic_variable_init(akbasic_Variable *obj, akbasic_ValuePo
* the run was over, which a game loop reaches in half a minute. TODO.md
* section 6 item 30 has the whole reduction.
*
* **A `@` name is the one exclusion**, and it is the whole of it. A
* structure or a pointer to one keeps pool storage because a pointer may
* outlive the scope that DIMmed it -- docs/16-structures.md says nothing is
* reclaimed and akbasic_runtime_prev_environment() relies on it. The suffix
* is the right test rather than `structtype`, which the DIM path sets
* **A `@` name is the one exclusion**, except for a one-slot pointer
* parameter. A structure or a pointer variable keeps pool storage because
* a pointer may outlive the scope that DIMmed it -- docs/16-structures.md
* says nothing is reclaimed and akbasic_runtime_prev_environment() relies
* on it. A pointer parameter owns only its reference slot; the target is
* owned by the caller, so bind_structure_parameter() marks it before this
* call and lets that slot use inline storage. The suffix is the right test
* for every other case rather than `structtype`, which the DIM path sets
* *after* calling this.
*
* Otherwise: reuse the existing slice when it is already big enough, which
* makes a re-DIM to the same or a smaller size free; growing takes fresh
* slots and abandons the old ones, as documented on akbasic_ValuePool.
*/
if ( totalsize == 1 && lastchar != '@' ) {
if ( totalsize == 1 && (lastchar != '@' || obj->ispointer) ) {
obj->values = &obj->inlinevalue;
} else if ( obj->values == NULL || obj->valuecount < (int)totalsize ) {
PASS(errctx, akbasic_valuepool_take(pool, (int)totalsize, &obj->values));

View File

@@ -183,6 +183,33 @@ static void test_structure_parameters(void)
harness_stop();
}
/**
* @brief Pointer parameters do not consume value-pool slots per call.
*
* The pointer's parameter variable owns only one reference to the caller's
* record, so that reference can live in the variable's inline slot. The target
* remains in the caller's storage. One pointer parameter and 8,000 calls make
* one leaked slot per call fail against the 4,096-slot value pool.
*/
static void test_pointer_parameters_do_not_leak_value_slots(void)
{
TEST_REQUIRE_OK(run_program_bounded("10 TYPE CRATE\n"
"20 W#\n"
"30 END TYPE\n"
"40 DIM A@ AS CRATE\n"
"50 DIM P@ AS PTR TO CRATE\n"
"60 POINT P@ AT A@\n"
"70 DEF POKEIT(P@ AS PTR TO CRATE)\n"
"80 P@->W# = P@->W# + 1\n"
"90 RETURN P@->W#\n"
"100 FOR I# = 1 TO 8000\n"
"110 R# = POKEIT(P@)\n"
"120 NEXT I#\n"
"130 PRINT A@.W#\n", 1000000));
TEST_REQUIRE_STR(HARNESS_OUTPUT, "8000\n");
harness_stop();
}
/**
* @brief A structure parameter must name its type, and the type is checked.
*
@@ -454,6 +481,7 @@ int main(void)
test_runaway_recursion_is_diagnosed();
test_single_expression_form();
test_structure_parameters();
test_pointer_parameters_do_not_leak_value_slots();
test_structure_parameter_types_are_checked();
test_call_scopes_are_reclaimed();
test_calls_do_not_leak_value_slots();