Skip to content

Fix native filesystem, memory, environment and CLI boundaries - #803

Merged
LunaStev merged 2 commits into
wavefnd:masterfrom
LunaStev:fix/native-boundary-stabilization
Sep 27, 2026
Merged

LunaStev merged 2 commits into
wavefnd:masterfrom
LunaStev:fix/native-boundary-stabilization

Conversation

@LunaStev

Copy link
Copy Markdown
Member

Summary

  • Fix Windows file opening so TRUNC works without CREAT and append handles write at EOF after seeks or duplication. Obtain the restricted append handle before truncation so a duplication failure preserves existing data.
  • Populate Windows fstat from native handle metadata and reject unsupported handle types. Honor supported anonymous private mmap protections and reject unsupported flags/protections before allocating.
  • Read Linux environments through EOF, retry interrupted reads, and grow the internal lookup buffer beyond 32 KiB. Distinguish missing keys, caller capacity, source/read failures, and allocation failures.
  • Replace non-UTF-8 CLI argument panics with structured diagnostics before output planning; remove unchecked default output-name conversions and lossy backend path conversion.

Motivation

These paths could silently overwrite append data, retain data after a requested truncation, report invented file metadata, grant unrequested memory access, or return truncated environment values as successful reads.

Fixes #527
Fixes #524
Fixes #784
Fixes #511
Fixes #400

Target and compatibility impact

  • Windows amd64/ARM64: native Win32 APIs only; no libc bindings. mmap supports anonymous private no-access, read-only and read/write mappings. Write-only and unknown protection/flag combinations return null.
  • Linux amd64/ARM64/RISC-V64/LoongArch64: raw environment reads return -ENOSPC instead of a successful partial source; env_get grows and retries. New environment error constants distinguish read, incomplete-source and allocation failures. Other OS error domains are not treated as Linux ENOSPC.
  • CLI arguments remain UTF-8. Invalid byte sequences now produce a usage diagnostic, including JSON mode, rather than a panic or lossy filename substitution. This does not add arbitrary-byte CLI path support.
  • Windows ARM64 CI explicitly includes the new integration suite; Windows amd64 already runs all targets. The later std revision pinning (Install a compiler-compatible standard-library revision #768) and constant-expression evaluator (Evaluate constant arithmetic before backend lowering #750) are outside this PR.

Validation

Local checks used LLVM 21 and checkout std:

  • LLVM_SYS_211_PREFIX=/usr/lib64/llvm21 cargo test --locked --jobs 2 --no-default-features --features llvm-target-core64 --test native_boundaries --test stabilization_17: 6 new boundary tests and 9 existing stabilization tests passed. The existing opt-in WASM runtime test was gated off.
  • LLVM_SYS_211_PREFIX=/usr/lib64/llvm21 cargo test --locked --jobs 2 --no-default-features --features llvm-target-core64 --test codegen_regressions --test frontend_regressions --lib: library tests passed (7); codegen passed 89/90 in the restricted sandbox. The TCP test failed there and passed when rerun individually with local socket permission. Because Cargo stopped after that suite, --test frontend_regressions was run separately: 16 passed.
  • LLVM_SYS_211_PREFIX=/usr/lib64/llvm21 cargo test --locked --jobs 2 --no-default-features --features llvm-target-core64 --test codegen_regressions async_tasks_suspend_resume_cancel_and_exchange_tcp_data -- --exact: passed outside the restricted sandbox.
  • LLVM_SYS_211_PREFIX=/usr/lib64/llvm21 cargo test --locked --jobs 2 --test native_boundaries environment_provider_cross_target_objects: passed with default backends, including LoongArch64 and WASI; 20 O0/O2 objects across 10 targets.
  • LLVM_SYS_211_PREFIX=/usr/lib64/llvm21 cargo clippy --locked --jobs 2 --lib --bin wavec --test native_boundaries -- -D warnings, cargo fmt --all -- --check, bash tools/check_std_policy.sh, and git diff --check: passed.

The new suite runs real Linux controlled environments and O0/O2 Win32 API mocks, including failure cleanup. Native Windows fixtures cross-compile for amd64/ARM64; actual Windows execution is pending CI.

Checklist

  • Commits include a DCO Signed-off-by line.
  • Tests cover new behavior or the PR explains why no test is needed.
  • User-facing changes include documentation or diagnostics updates.
  • The change preserves the license boundary between the compiler and std/.

Signed-off-by: LunaStev <luna@lunastev.org>
Signed-off-by: LunaStev <luna@lunastev.org>
@LunaStev
LunaStev merged commit 1a181e9 into wavefnd:master Sep 27, 2026
26 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

1 participant