English | 简体中文 · Main roadmap · Decomposition rules
Status: 🚧 In progress. The 10 parent items contain 85 implementation leaves and 6 phase-gate leaves. Completion proves only a leaf's stated delivery; subset passes do not automatically complete P1-06 through P1-10 or P1.
This inventory assigns existing commitments to stable IDs without expanding or shrinking the language contract. P1-06.01's frozen ledger enumerates the typed MIR contract, P1 gap matrix and original acceptance requirements. The existing check-only type profile stays check-only; previously promised executable behavior and listed remaining work cannot disappear through reclassification. References/provenance, slices/unsizing, patterns/closures, full source move/borrow analysis, generated Drop/panic, source package contracts and every required backend each need leaves and cases.
There is no complete P1 exit candidate yet. The initial safe-core-regression-v3 manifest fixes 26 cases: it preserves the v2 source contracts except for versioning two now-executable pattern/capture expectations, and adds combined MIR family/projection samples. The immutable v2 manifest remains unchanged. The expanded p1-differential-v3 and p1-platform-v2 manifests now contain all 56 bounded source fixtures with immutable hashes, and bounded differential/platform runners emit provenance-rich reports. Native AOT/ILVerify execution and the candidate-SHA aggregate remain open; subset results cannot automatically close the expanded P1 contract.
The follow-up evidence audit found 16 differential and 12 platform sources that only print their case identifiers. Their immutable hashes/denominators remain valid, but they cannot prove the named semantics. Runners expose semantic eligibility; expanded/candidate gates independently reject placeholder sources, missing backend/process evidence and incomplete structured closure records. P1 remains 🚧 In progress; no complete candidate or closure record is claimed.
Historical/current evidence labels (only for the corresponding bounded scope):
| Label | Existing evidence and limit |
|---|---|
| E1 | Lexical contract: 24 cases, 22 categories; historical 103-test harness. |
| E2 | Syntax contract: 49 cases, 34 AST snapshots, 18 categories; historical 141-test harness. |
| E3 | Module contract: 25 resolution cases; historical 190-test harness. |
| E4 | Type contract: 96 check-only differential cases, 16 categories; historical 265-test harness. |
| E5 | Generic contract: 32 cases and recorded ILVerify/Windows AOT; not the full P1 platform gate. |
| E6 | f4692c704b0c5432e05d7f08a00c6736ce3a1c75: local Release zero warnings/errors, 464/464; Windows CI, Linux CI, P1 platform CI all passed. The latter covers 12 platform/24 regression/16 differential cases per platform and 6 aggregate inputs; it does not establish AOT acceptance for added constructs absent from that platform manifest. |
| E7 | Historical struct/place/reference subset: 551/551 harness tests, regression v2 24/24 and borrow/Drop v2 16/16 with SDK 10.0.401. The projection sample matched CoreCLR/rustc and Windows x64 Native AOT; its former CLR byref representation reported ILVerify ReturnPtrToStack, also reproduced by equivalent C#. The companion storage sample passed ILVerify and Windows x64 Native AOT. E8 supersedes the projection implementation and verifier limitation. |
| E8 | Current frozen P1-06 families: implementation inventory, 670/670 harness tests, regression v3 26/26 and borrow/Drop v2 16/16; Release zero warnings/errors using SDK 10.0.401 (repository pin 10.0.400). Both the family sample and projection sample match rustc 1.98.0 on CoreCLR and Windows x64 Native AOT, and pass ILVerify 10.0.11 without suppressed diagnostics. GC-owned references resolve the former reference-return diagnostic. Evidence: artifacts/p1-06-final-session; native AOT temporary directories were reclaimed. These results close P1-06's own leaves, while P1-07–P1-10 and the full native candidate-SHA gate remain separate. |
E8 logs include build-final.stdout.log, harness-final.stdout.log,
regression-v3-final.json, differential-v2-final.json and both samples' CoreCLR,
ILVerify and AOT reports. All recorded final suites have zero failures, blocked
cases or skips. The 12-case native platform denominator remains unchanged.
| ID | Status | Deliverable / ownership | Depends on | Done when | Evidence |
|---|---|---|---|---|---|
| P1-01.01 | ✅ Complete | Token/trivia preservation — Syntax lexer | P0-GATE | Reconstruct the exact input, including mixed line endings; invalid scalars retain stable spans. | LexerTests, LexerClosureTests; E1 |
| P1-01.02 | ✅ Complete | Literal and identifier forms — Syntax lexer | P1-01.01 | The declared Rust 1.98 literal, identifier, lifetime and escape categories match lexical fixtures. | docs/lexical-profile.md; E1 |
| P1-01.03 | ✅ Complete | Token trees and lexer budgets | P1-01.01 | Delimiter/depth/work/cancellation cases terminate with the declared diagnostic; no input loss. | LexerClosureTests; E1 |
| P1-01.04 | ✅ Complete | Freeze lexical corpus categories | P1-01.02, P1-01.03 | Manifest v2 retains 24 cases and 22 categories; corrupt/missing category evidence is rejected. | LexingManifestTests; E1 |
| ID | Status | Deliverable / ownership | Depends on | Done when | Evidence |
|---|---|---|---|---|---|
| P1-02.01 | ✅ Complete | Items, declarations and type syntax — parser | P1-01 | Modules/items/generic and attribute syntax have exact AST fixtures within the syntax profile. | SafeCoreSyntaxTests, SyntaxItemExpansionTests; E2 |
| P1-02.02 | ✅ Complete | Expressions, statements and patterns — parser | P1-02.01 | Precedence, branches, closures and patterns preserve syntax without promising executable semantics. | SyntaxExpressionExpansionTests, SyntaxGrammarTests; E2 |
| P1-02.03 | ✅ Complete | Recovery, diagnostics and parser budgets | P1-02.02 | Malformed input has stable code/span; recovery, depth, allocation and cancellation are bounded. | SyntaxProfileBoundaryTests; E2 |
| P1-02.04 | ✅ Complete | Freeze syntax acceptance corpus | P1-02.03 | 49/49 cases, 34/34 AST snapshots and 18/18 categories remain exact; altered evidence fails. | eng/Test-SyntaxEvidence.ps1, SyntaxManifestTests; E2 |
| ID | Status | Deliverable / ownership | Depends on | Done when | Evidence |
|---|---|---|---|---|---|
| P1-03.01 | ✅ Complete | HIR identity and namespaces — Syntax/HIR | P1-02 | Bindings identify declarations and references; unknown/ambiguous names diagnose at source. | SafeCoreHirTests, SafeCoreNameResolutionTests; E3 |
| P1-03.02 | ✅ Complete | Modules, imports and visibility | P1-03.01 | Grouped/glob/self imports and restricted visibility resolve; inaccessible exports are rejected. | SafeCoreModuleResolutionTests; E3 |
| P1-03.03 | ✅ Complete | Cargo path packages and bounded source discovery | P1-03.02 | Declared file/Cargo commands use one bounded package graph; cycles and registry requests diagnose. | CargoWorkspaceTests, SafeCoreWorkspaceTests; E3 |
| P1-03.04 | ✅ Complete | Original-file source maps and resolution corpus | P1-03.03 | 25/25 resolution cases and original-file diagnostics/PDB mappings retain source identity. | WorkspaceSourceMapTests, NameResolutionManifestTests; E3 |
| ID | Status | Deliverable / ownership | Depends on | Done when | Evidence |
|---|---|---|---|---|---|
| P1-04.01 | ✅ Complete | Structural and nominal type descriptors | P1-03 | Primitive, tuple, array, slice, reference, function, ADT and never descriptors preserve identity. | SafeCoreTypeHirTests, SafeCoreTypeInferenceTests; E4 |
| P1-04.02 | ✅ Complete | Inference, aliases and directional coercions | P1-04.01 | Inference and coercion positives pass; recursive/conflicting constraints reject without state leakage. | SafeCoreTypeInferenceTests; E4 |
| P1-04.03 | ✅ Complete | Pattern, closure and bounded const type analysis | P1-04.02 | Type-only analysis checks the declared forms; budget and unsupported forms retain diagnostics. | SafeCorePatternClosureTests, SafeCoreConstantTests; E4 |
| P1-04.04 | ✅ Complete | Check-only boundary and type differential corpus | P1-04.03 | 96/96 cases across 16 categories pass; executable commands for this profile reject with RSC0009. | SafeCoreTypeConformanceTests, docs/type-system-profile.md; E4 |
| ID | Status | Deliverable / ownership | Depends on | Done when | Evidence |
|---|---|---|---|---|---|
| P1-05.01 | ✅ Complete | Rigid generic bodies and marker-trait solving | P0-14, P1-04 | Bounded body checks, coherence, missing and ambiguous trait cases match the declared subset. | SafeCoreGenericAnalysisTests, SafeCoreGenericProfileTests; E5 |
| P1-05.02 | ✅ Complete | Closed specialization and aggregate layouts | P1-05.01 | Reachable bodies, tuples and generic structs specialize deterministically; invalid layouts reject. | SafeCoreGenericAggregateTests, ClrLirValueTypeTests; E5 |
| P1-05.03 | ✅ Complete | Local package generic identity and body metadata | P1-05.02 | The declared path-package graph preserves definitions and orphan rules; unrelated identities cannot alias. | SafeCoreGenericPackageTests, SafeCoreGenericHirBindingTests; E5 |
| P1-05.04 | ✅ Complete | Generic corpus and recorded executable gate | P1-05.03 | 32/32 corpus cases plus recorded standalone/package ILVerify and Windows AOT pass for this scope. | eng/Test-GenericEvidence.ps1, docs/generic-profile.md; E5 |
| ID | Status | Deliverable / ownership | Depends on | Done when | Evidence |
|---|---|---|---|---|---|
| P1-06.01 | ✅ Complete | Freeze the P1 executable coverage ledger — Semantics + QA | P1-04, P1-05 | List every current P1 promise as executable, check-only by existing contract, or explicitly excluded; map every executable family to a leaf below. Existing missing semantics cannot be reclassified to obtain completion. | Frozen bilingual ledger: p1-exit-scope-v1, 40 stable requirement IDs; case/backend denominators remain P1-10.01/.02 |
| P1-06.02 | ✅ Complete | Immutable arenas and structural CFG validation — MIR model | P1-04 | Dense IDs, typed operands, terminators and CFG targets validate; malformed MIR fails before emission. | SafeCoreMirModels.cs, SafeCoreMirValidationTests; E6 |
| P1-06.03 | ✅ Complete | Scalar/control-flow HIR→MIR→CLR LIR foundation | P1-06.02 | Supported i32/bool/unit control flow preserves operand order, calls, branches and early returns in emitted programs. | SafeCoreMirLoweringTests, SafeCoreMirPatternExecutionTests; E6 |
| P1-06.04 | ✅ Complete | Type every place/projection — MIR model + validator | P1-06.01, P1-06.02 | Root/field/tuple/index/deref chains retain owner, result type and mutability; invalid field/index/type and depth overflow reject. | SafeCoreMirPlaceTests, SafeCoreMirAdtLayoutTests, SafeCoreMirEnumTests, SafeCoreMirReferenceAbiTests: typed field/tuple/index/deref/downcast paths, actual-owner access, malformed evidence and bounded projection validation. |
| P1-06.05 | ✅ Complete | Reference provenance across locals, calls and joins | P1-06.04 | Every reference has an explicit source place and lifetime relation; returns, parameters and CFG joins cannot invent an origin. | SafeCoreMirReferenceProvenanceTests, SafeCoreMirCompositeLifetimeTests, SafeCoreMirReferenceStorageTests: reference-slot origins through nested references, aggregates, calls and joins; lifetime elision, storage expiry, rebinding, aliases and escapes. |
| P1-06.06 | ✅ Complete | Structural-Copy repeated arrays | P1-06.02 | Evaluate the repeat operand once, including zero length; reject non-Copy repeats and preserve length/work/snapshot budgets. | SafeCoreMirV2ProfileTests; E6 |
| P1-06.07 | ✅ Complete | Full-array local slice foundation | P1-06.03 | Owner-specialized unsizing, length and constant/dynamic reads execute; index bounds, including empty arrays, are checked. General slice parameters/returns, subslices and writes retain their separate leaves. | SafeCoreMirSliceTests, SafeCoreMirProjectionBackendTests: full-array owner preservation, dynamic read execution and bounds failures; E6, E7 |
| P1-06.08 | ✅ Complete | General slice representation and call ABI | P1-06.04, P1-06.05 | Represent data/length/owner for shared and mutable slices, array unsizing and parameters/returns; reject invalid lifetime or element conversions. | SafeCoreMirReferenceAbiTests, SafeCoreMirCompositeLifetimeTests: shared/mutable owner/start/length values, unsizing, source calls/returns, different-length joins and lifetime/element rejection. |
| P1-06.09 | ✅ Complete | Slice indexing, subslices and writes | P1-06.08 | Dynamic index/range checks, empty/end boundaries and mutable writes preserve shared owner identity; bounds and alias errors do not silently execute. | SafeCoreMirReferenceAbiTests, SafeCoreMirCompositeLifetimeTests, SafeCoreMirFamilyEvidenceTests: dynamic index/range bounds, empty/inclusive subslices, aggregate writes, aliases and bounded lowering. |
| P1-06.10 | ✅ Complete | Pattern and match lowering, including move/ref bindings | P1-06.04, P1-06.05 | Tuple/scalar/declared ADT patterns, guards, or-patterns and exhaustiveness preserve evaluation/binding semantics; mismatched bindings reject. | SafeCoreMirPatternExecutionTests, SafeCoreMirEnumTests, SafeCorePatternClosureTests: scalar/aggregate/enum match, move/ref/ref-mut bindings, rest/@/or patterns, guards, let-else, exhaustiveness and rejection fixtures. |
| P1-06.11 | ✅ Complete | Closure environment and capture ownership | P1-06.04, P1-06.05 | Declared captures distinguish copy, move, shared and mutable borrow; generated calls preserve capture lifetimes and reject unsupported escapes with stable diagnostics. | SafeCoreMirClosureCaptureTests: declaration-time copy/move/shared/mutable capture storage, aggregate/reference captures, field independence, mutation and stable escape/conflict rejection. Recursive owned-field destruction retains P1-08 ownership. |
| P1-06.12 | ✅ Complete | Const-to-MIR integration | P1-06.01, P1-06.02 | Every executable const item/block in the frozen scope lowers from checked values; const cycles, overflow and evaluation budgets diagnose at source. | SafeCoreConstantTests, SafeCoreMirConstantExecutionTests: checked scalar/aggregate values, const functions/blocks, immutable promotion, cycle/overflow diagnostics, tampered evidence and evaluation limits. |
| P1-06.13 | ✅ Complete | Reconcile the frozen executable lowering inventory | P1-06.01, P1-06.08, P1-06.10, P1-06.11, P1-06.12, P1-06.17, P1-06.18, P1-06.19 | Join the named family implementations and fixtures against the frozen ledger; every executable row has an owner and check-only exclusions retain capability diagnostics. Missing implementation is assigned to its family leaf, not added as unbounded work here. | Executable family inventory maps P1-REQ-005–P1-REQ-022 to registered generated-program and rejection tests through SafeCoreMirPipeline and SafeCoreMirClrLowering. |
| P1-06.14 | ✅ Complete | Source mapping for every introduced MIR/LIR node | P1-06.13 | Mapped diagnostics and sequence points refer to original files/spans after desugaring, nested scopes and imports; corrupt source evidence rejects. | WorkspaceSourceMapTests, SafeCoreMirFamilyEvidenceTests: original-file names/checksums and Portable PDB sequence points survive combined enum/capture/slice/promotion lowering; structural validation rejects corrupt spans. |
| P1-06.15 | ✅ Complete | Budgets, cancellation and fail-closed capability checks | P1-06.13 | Each new family has positive, unsupported, size/depth/work/time/cancellation tests; check/build agree and emit no partial output on failure. | SafeCoreMirFamilyEvidenceTests, SafeCoreMirPlaceTests, SafeCoreMirAdtLayoutTests, SafeCoreMirConstantExecutionTests: per-family size/depth/work/time/cancellation, malformed/unsupported inputs, check/build rejection and no partial publication. |
| P1-06.16 | ✅ Complete | Deterministic MIR/LIR/PE/PDB snapshots | P1-06.14, P1-06.15 | Repeated builds of the same frozen inputs preserve bytes and ordered source/provenance facts; format changes get a new version. | SafeCoreMirFamilyEvidenceTests, SafeCoreMirReferenceProvenanceTests, SafeCoreMirEnumTests: identical MIR/LIR/PE/PDB, ordered origins, original source evidence and versioned safe-core-mir-v3 metadata; compatible old inputs retain their snapshot format. |
| P1-06.17 | ✅ Complete | Scalar operators and conversions — MIR/CLR numeric lowering | P1-06.01, P1-06.03 | Implement the frozen executable scalar/operator/cast rows with signedness, overflow, comparison and conversion boundaries; check-only widths or char/float forms retain their specified rejection until explicitly included. | SafeCoreMirScalarExecutionTests: i32/bool/bounded-usize arithmetic, division/remainder, bitwise/shifts, conversions and traps; check-only widths and char/float forms retain executable capability diagnostics. |
| P1-06.18 | ✅ Complete | Aggregate construction and layout — MIR/CLR value types | P1-06.01, P1-06.04 | Declared tuples, arrays and ADT variants preserve field order, discriminants, nested layout and single evaluation; malformed/recursive/oversized layouts reject. | SafeCoreMirAdtLayoutTests, SafeCoreMirAdtSourceTests, SafeCoreMirEnumTests, SafeCoreMirReferenceAbiTests: declared struct/enum layouts, discriminants/payloads, reference-bearing values, source-order constructors and malformed/recursive/oversized rejection. |
| P1-06.19 | ✅ Complete | Aggregate projection reads, writes and evaluation order | P1-06.18, P1-06.05 | Declared field/tuple/index/deref operations access the checked owner, evaluate receiver/index/value in order and preserve mutations; wrong owner/type/bounds fail without alias substitution. | SafeCoreMirProjectionBackendTests, SafeCoreMirReferenceAbiTests, SafeCoreMirReferenceStorageTests: actual-owner nested reads/writes, dynamic indices, reference rebinding and slice mutation preserve evaluation order and independent aggregate copies. |
| ID | Status | Deliverable / ownership | Depends on | Done when | Evidence |
|---|---|---|---|---|---|
| P1-07.01 | ✅ Complete | Complete typed move-path tree — ownership analysis | P1-06.04, P1-06.05 | Roots and field/tuple/index/deref projections share typed identity; overlapping paths conflict and disjoint paths remain independent. | SafeCoreOwnership.cs, SafeCoreOwnershipTests, and SafeCoreMirOwnershipAdapterTests cover typed projections, overlap/disjoint paths, self-move rejection, and Drop boundaries. |
| P1-07.02 | 🚧 In progress | Copy versus Move at every operand and call | P1-07.01 | Copies retain values/loans and moves invalidate the exact source; source-level use-after-move rejects, including arguments and returns. | SafeCoreMirOwnershipAdapterTests and SafeCoreMirAdtSourceTests cover non-Copy source moves; broader call/return corpus remains open |
| P1-07.03 | 🚧 In progress | Partial move, reinitialization and Drop ownership | P1-07.02 | Moving one field preserves siblings, blocks whole-value use and permits valid reinitialization; forbidden partial moves from Drop owners reject. | SafeCoreMirAdtSourceTests covers partial move/reinitialization; arrays and full Drop-owner source corpus remain open |
| P1-07.04 | 🚧 In progress | NLL use/definition liveness | P1-07.01 | Loans end after their last reachable use, including temporaries and dead branches; lexically overlapping but nonoverlapping live borrows work. | SafeCoreMirAdtSourceTests covers source NLL and bounded branch liveness; temporary/loop corpus remains open |
| P1-07.05 | 🚧 In progress | Shared/mutable borrow conflicts and owner writes | P1-07.04, P1-07.01 | Read/write/move conflicts follow projected aliases, not just local IDs; shared reads work and overlapping exclusive accesses reject. | SafeCoreMirReferenceExecutionTests; planned projected-alias negatives |
| P1-07.06 | 🚧 In progress | Reborrow suspension, resumption and invalidation | P1-07.05 | Parent references resume only when child loans end; mutable/shared chains reject parent use and invalidated descendant reuse correctly. | Planned nested projected reborrow and lifetime-edge fixtures |
| P1-07.07 | 🚧 In progress | Parameter/return provenance and escapes | P1-07.06, P1-06.05 | Local functions preserve declared input-to-output lifetime relations; stack-owner, branch-local and capture escapes reject at source. | SafeCoreMirReferenceProvenanceTests, SafeCoreMirAdtSourceTests: projected reference returns, repeated mutable-reference calls, CFG origin unions, caller borrow conflicts and local/branch-scope escapes; the remaining lifetime families stay open. |
| P1-07.08 | 🚧 In progress | Branch joins and loop fixed points | P1-07.03, P1-07.04, P1-07.06 | Move/init/loan states merge conservatively across if/match/backedges, break and continue; work-limit exhaustion never accepts incomplete analysis. | SafeCoreMirAdtSourceTests covers bounded loop/branch merge; full backedge budget corpus remains open |
| P1-07.09 | 🚧 In progress | Bidirectional MIR/ownership evidence integrity | P1-07.07, P1-07.08 | Every place, loan origin, lifetime edge and call effect has matching MIR evidence; missing, extra, substituted or stale facts fail. | SafeCoreMirOwnershipAdapterTests, SafeCoreMirReferenceProvenanceTests: MIR/provenance correlation and missing/substituted/escaping origin negatives; full family evidence coverage remains open. |
| P1-07.10 | 🚧 In progress | Stable source ownership diagnostics | P1-07.09, P1-06.14 | Invalid programs report the intended move/borrow/escape code and original span; unsupported-lowering diagnostics cannot count as borrow rejections. | SafeCoreMirAdtSourceTests checks source diagnostic code/span; complete golden catalog remains open |
| P1-07.11 | ⏳ Planned | Fixed rustc 1.98 source borrow differential | P1-07.10, P1-10.05 | The frozen borrow cases include valid/invalid projected moves, reborrows, NLL, joins, escapes and limits; every case executes with zero unexplained differences/skips. | Planned borrow section of p1-differential-v3; per-case rustc/source hashes |
| P1-07.12 | 🚧 In progress | Ownership solver resource contract | P1-07.09 | Operation/path/block/diagnostic limits and cancellation cover new analysis edges; malformed/cyclic evidence terminates deterministically. | Planned ownership budget/cancellation boundary fixtures |
| ID | Status | Deliverable / ownership | Depends on | Done when | Evidence |
|---|---|---|---|---|---|
| P1-08.01 | ✅ Complete | Freeze destructor and panic transition table | P1-06.01, P1-07.01 | Specify initialization/move/drop flags and normal/return/unwind/abort transitions, first destructor failure and double panic, with explicit Rust# divergences if any. | docs/p1-drop-contract-v1.md and _zh.md; SafeCoreMirDropContract snapshot and transition tests freeze the v1 table. |
| P1-08.02 | 🚧 In progress | Compile destructor bodies and receiver places | P1-08.01, P1-06.04 | Source impl Drop resolves one valid receiver/body and accesses owned fields through MIR; invalid signatures and unsupported bodies diagnose stably. | SafeCoreMirLowering.cs; planned field-owning destructor fixtures |
| P1-08.03 | 🚧 In progress | Per-place initialization and drop flags | P1-08.02, P1-07.03 | Initialized live values are eligible once; moves, partial initialization and reassignment update flags before throwing operations. | SafeCoreMirDropFlagLowering.cs and SafeCoreMirCleanupTests provide bounded per-place snapshots and branch/loop evidence; emitted aggregate integration remains open. |
| P1-08.04 | ✅ Complete | Unit Drop normal scope foundation | P1-06.03 | Generated unit destructors run once in reverse declaration order on normal scope exit. | SafeCoreMirDropCodegenTests.ReverseOrderAsync; E6 |
| P1-08.05 | 🚧 In progress | Branch, loop, break and continue cleanup | P1-08.03, P1-08.13, P1-08.14 | Only initialized live values of exited scopes are dropped in deterministic reverse order; later iterations do not reuse consumed flags. | Planned generated branch/loop trace corpus |
| P1-08.06 | 🚧 In progress | Explicit/early return cleanup | P1-08.05 | Return operands are evaluated once before cleanup; returned/moved values survive and every other live owner is dropped once. | Existing unit return differential; planned aggregate/operand failure extensions |
| P1-08.07 | ✅ Complete | Unit Drop fault cleanup foundation | P1-08.04 | Generated overflow fault runs the supported unit destructor then propagates the original exception. | SafeCoreMirDropCodegenTests.FaultPathAsync; E6 |
| P1-08.08 | 🚧 In progress | Unwind through nested generated scopes and calls | P1-08.03, P1-08.06 | Panic from bodies, arguments or nested calls unwinds live owners once; moved values and completed cleanup are not repeated. | P1GeneratedUnwindEvidenceTests covers nested calls, return and argument overflow cleanup; generated PE/rustc differential traces remain open |
| P1-08.09 | 🚧 In progress | Destructor failure continuation and double panic | P1-08.08 | First failure on a normal cleanup path applies the frozen remaining-cleanup policy; failure during unwind applies the frozen abort rule without swallowing either failure. | RustDropGlue, RustPanicBoundary, and SafeCoreMirDropCodegenTests cover continuation, double-panic reporting, and abort selection; subprocess exit evidence remains open. |
| P1-08.10 | 🚧 In progress | Abort behavior in generated programs | P1-08.01, P1-08.03 | Abort terminates at the declared boundary without unwind Drop; traces, exit category and absence of later user effects match the contract. | RustPanicBoundary and SafeCoreMirDropCodegenTests cover the bounded abort outcome and untouched scope; isolated generated-process evidence remains open. |
| P1-08.11 | 🚧 In progress | Generated local panic boundary and reusable call interface | P1-08.09, P1-08.10 | Generated local calls use the declared panic strategy; returned/unwound/aborted outcomes agree with emitted behavior. Publish the checked panic interface for P1-09.06; source imported-call integration is accepted there and in P1-09.09. | Planned compiler-to-RustPanicBoundary integration and contract-negative fixtures |
| P1-08.12 | ⏳ Planned | Fixed rustc 1.98 Drop differential | P1-08.11, P1-10.05 | Normal/return/unwind/abort, field owners, partial moves and destructor failure have generated-program trace/exit comparisons; zero unexplained differences/skips. | Planned Drop section of p1-differential-v3; Rust# and rustc process records |
| P1-08.13 | 🚧 In progress | Recursive aggregate drop glue and field/element order | P1-08.02, P1-08.03, P1-06.18 | Structs without their own Drop still drop owned fields; declared tuples/arrays/active enum fields follow Rust field/element order after any outer destructor, distinct from reverse local declaration order. Skip moved/uninitialized fields and route failure edges to P1-08.08/.09. | RustDropGlue and SafeCoreMirDropCodegenTests freeze outer-before-fields order and failure stopping; generated nested aggregate coverage remains open. |
| P1-08.14 | 🚧 In progress | Assignment replacement and temporary destruction | P1-08.03, P1-08.13 | Replacing an initialized owner drops the old value once; expression/block temporaries expire at their declared scopes, and moving out suppresses later cleanup. Emit explicit exceptional edges; RHS-panic execution is accepted by P1-08.08. | RustDropSlot and SafeCoreMirDropCodegenTests cover replacement and move-out one-shot flags; compiler temporary lowering remains open. |
| ID | Status | Deliverable / ownership | Depends on | Done when | Evidence |
|---|---|---|---|---|---|
| P1-09.01 | 🚧 In progress | One CLR LIR emission route per executable family | P1-06.13 | All frozen executable families use validated CLR LIR/PE emission; unsupported MIR never falls back to primitive or simulated execution. | Planned compiler route coverage and rejection-before-output fixtures |
| P1-09.02 | ✅ Complete | Scalar imported signatures and real external calls | P1-05 | Scalar producer/consumer calls execute via AssemblyRef/TypeRef/MemberRef; MethodDef static/visibility/signature drift rejects. | RustSharpMetadataTests.CrossAssemblyCallAsync; E6 |
| P1-09.03 | 🚧 In progress | Versioned imported ownership/lifetime/panic schema | P1-06.01, P1-07.01 | Parameter positions, move/copy/borrow effects, return origins and panic strategy round-trip without deduplication or unknown-function acceptance. | RustSharpMetadata.cs; planned schema and evidence mutation fixtures |
| P1-09.04 | 🚧 In progress | Imported aggregate layout and nominal identity | P1-09.03, P1-06.13 | Source imports reconstruct declared layouts/identities across producers; same-name/different-layout and unsupported generic shapes reject. | P1SourcePackageContractTests covers stale producer layout and source aggregate import rejection; successful source package reconstruction remains open |
| P1-09.05 | 🚧 In progress | Source reference/slice signatures and lifetime checking | P1-09.04, P1-07.07, P1-06.08 | Source consumer HIR/type analysis understands supported reference, slice and aggregate signatures; invalid returned origins and borrow effects reject. | Existing manual LIR byref test; planned source imported-signature corpus |
| P1-09.06 | 🚧 In progress | Imported calls through ownership-aware MIR and LIR | P1-09.05, P1-08.11, P1-09.01 | Source cross-package calls transfer/copy/borrow and unwind according to checked contracts; actual MemberRef signatures agree. | Planned imported-call MIR/ownership/PE fixtures |
| P1-09.07 | 🚧 In progress | Producer/consumer metadata reconciliation and limits | P1-09.04, P1-09.05 | Reconcile MethodDef/MemberRef type, assembly, visibility, static flag and all terms; malformed, duplicate, oversized or missing evidence rejects. | P1SourcePackageContractTests covers stale layout rejection; malformed/limit corpus remains open |
| P1-09.08 | 🚧 In progress | Deterministic cross-package artifacts | P1-09.06, P1-09.07 | Equivalent frozen source/package inputs produce identical ordered metadata and PE/PDB bytes; stale producer evidence cannot be reused. | Planned independent-build hash and stale-assembly negatives |
| P1-09.09 | ⏳ Planned | Source producer/consumer CoreCLR integration | P1-09.08 | Separately compile real source packages and execute aggregate/reference/ownership/Drop calls; hand-built LIR alone does not satisfy this row. | Planned source package fixtures, output/trace and package hashes |
| P1-09.10 | ⏳ Planned | Cross-package ILVerify and both native x64 AOT platforms | P1-09.09, P1-10.06 | The same fixed source packages verify and execute on Windows/Linux native x64 AOT with CoreCLR-equivalent traces and zero warnings/skips. | Planned package platform rows in the versioned P1 platform suite |
| ID | Status | Deliverable / ownership | Depends on | Done when | Evidence |
|---|---|---|---|---|---|
| P1-10.01 | ✅ Complete | Requirement-to-case coverage ledger | P1-06.01 | Every required leaf, including completed foundations whose new backend evidence is still missing, maps to named positive/negative/boundary/budget cases and required execution backends; no orphan requirement or case. | p1-coverage-v1-manifest.json fixes 40 requirements and 160 cases; P1CoverageProfileRunner validates source hashes, categories, backends and bounds |
| P1-10.02 | ✅ Complete | Freeze expanded manifest versions and denominators | P1-10.01 | Check in the complete case IDs, immutable source/expectation hashes and integer denominators before implementations claim conformance; no runtime-discovered denominator. | p1-expanded-suites-v1-manifest.json fixes 32 p1-differential-v3 and 24 p1-platform-v2 cases with source/expectation hashes; P1ExpandedSuiteValidator verifies every fixture source and bound |
| P1-10.03 | 🚧 In progress | Compile-pass/fail and run-pass report coverage | P1-10.02 | Pass/fail/run cases record actual outcomes and exact expected diagnostics; unsupported, timeout, infrastructure failure and skip cannot count as expected semantic failure. | P1ExpandedSuiteValidator rejects duplicate, missing-hash, skipped, altered-denominator and oversized reports; bounded v3 execution is wired, while a passing full denominator remains open |
| P1-10.04 | ✅ Complete | Preserve existing immutable regression baselines | P0-11 | Retain regression v1 8, regression v2 24 and differential v2 16 IDs/expectations; current platform v1 remains 12 per native platform. | SafeCoreRegressionV2Tests, P1DifferentialProfileTests; E6 |
| P1-10.05 | 🚧 In progress | Borrow/Drop differential process runner | P1-10.02 | Execute every frozen v3 source with exact rustc 1.98; capture version, command, PID/start/parent, timeout, termination and cleanup even on failures. | P1ExpandedDifferentialRunner and p1-differential-v3 reports provide bounded process evidence; full denominator requires native candidate resources |
| P1-10.06 | 🚧 In progress | Expanded native-platform execution runner | P1-10.02 | Every executable family/package case runs through CoreCLR, ILVerify and native AOT on Windows/Linux x64; declared non-runtime negatives remain diagnostic cases. | P1ExpandedPlatformRunner emits fixed 24-case CoreCLR/provenance reports; ILVerify and Native AOT extension remains open |
| P1-10.07 | 🚧 In progress | Bind reports to source, tools and case manifests | P1-10.03, P1-10.05, P1-10.06 | Reports include compiler SHA, manifest hashes, platform/RID, runtime/SDK/oracle versions, bounds and cleanup; empty/missing/duplicate/stale records fail. | P1EvidenceBindingValidator and P1EvidenceBindingTests validate complete, forged, stale and missing provenance; integration with expanded platform reports remains open |
| P1-10.08 | 🚧 In progress | Aggregate semantic coverage and platform evidence | P1-10.07 | Aggregator requires the expanded frozen denominators and every required leaf/backend at one candidate SHA; 6 old reports alone cannot close the new contract. | eng/Test-P1ExpandedExitGate.ps1, eng/Test-P1CandidateGate.ps1, shared eng/P1EvidenceValidation.ps1 and 13 bounded rejection checks; real semantic/native candidate evidence remains open |
| P1-10.09 | 🚧 In progress | CI report publication and failure provenance | P1-10.08 | Both native jobs upload all success/failure reports with stable run/artifact references; unavailable infrastructure is blocked, never passed/skipped. | Manual .github/workflows/p1-expanded.yml publishes paired differential/platform reports; candidate-SHA aggregation remains open |
| P1-10.10 | ⏳ Planned | Audit regression preservation and fresh candidate verification | P1-10.09, P1-10.04 | Full Release harness has at least 464 cases plus additions, zero failures/skips and zero build warnings/errors; legacy suites remain immutable and new suites have fixed denominators. | Planned fresh candidate build/harness/manifest-audit reports |
| ID | Status | Deliverable / ownership | Depends on | Done when | Evidence |
|---|---|---|---|---|---|
| P1-GATE.01 | ⏳ Planned | Close the frozen language inventory | P0-GATE, P1-01, P1-02, P1-03, P1-04, P1-05, P1-06 | Every required executable/check-only/rejection boundary in P1-06.01 has its designated completed leaf and case evidence; no unmapped category. | Planned requirement coverage audit at candidate SHA |
| P1-GATE.02 | ⏳ Planned | Close source ownership and generated cleanup semantics | P1-07, P1-08 | Borrow/Drop fixed cases agree with rustc 1.98 or already approved versioned divergences; simulation-only traces cannot satisfy emitted behavior. | Planned borrow/Drop closure report |
| P1-GATE.03 | ⏳ Planned | Close source package/backend integration | P1-09 | Every source import family has reconciled metadata and generated CoreCLR/ILVerify/Windows/Linux AOT evidence. | Planned source-package coverage report |
| P1-GATE.04 | ⏳ Planned | Close fixed test and report contracts | P1-10 | Every preserved and expanded denominator passes with failed/blocked/skipped all zero; negative evidence tests reject missing coverage. | Planned expanded regression/differential/platform aggregator report |
| P1-GATE.05 | ⏳ Planned | Verify one pushed SHA on both native x64 platforms | P1-GATE.01, P1-GATE.02, P1-GATE.03, P1-GATE.04 | All required jobs pass at the candidate SHA; download reports and reconcile hashes/counts/platforms/versions, not just badge color. | Planned stable Windows/Linux run URLs and artifact provenance |
| P1-GATE.06 | ⏳ Planned | Publish P1 closure record and synchronized status | P1-GATE.05 | Record leaf IDs, manifest versions, denominators, SHA/run links, clean diff and owned-resource cleanup; update both language statuses together. | Planned docs/p1-completion.md; no new acceptance added at this step |
- P1-06 is ✅ Complete with its frozen scope ledger and E8 implementation evidence. P1-10.01 and P1-10.02 are ✅ Complete as inventory deliveries. The audit identifies placeholder-source gaps; replace them through a new immutable suite version with real semantic scenarios and explicit expectations before claiming P1 exit coverage.
- P1-06.04/.05/.08/.09 provide the place/reference/slice prerequisites. The ownership lane advances P1-07.01 through .10; the destructor lane advances P1-08.01 through .11 after move/drop-flag prerequisites. Changes to the same
SafeCoreMirLowering.csor validator must integrate serially; separate agents cannot write that file concurrently. - The metadata lane can advance P1-09.03/.04, while corpus/runner work advances P1-10.03/.05/.06/.07 independently. Source call integration P1-09.06 waits for reference and panic contracts.
- Finish source borrow/Drop differentials, real package platform cases and P1-10.08 through .10, then reconcile P1-GATE.01 through .06. Preserve existing library probes and hand-built LIR tests.
A parent ID means all required implementation leaves in that group; P1-GATE means the conjunction of its six gate leaves. A leaf never depends on its own parent or P1-GATE. The old coarse parent dependencies are refined: P1-07 starts specifically after P1-06.04/.05, and P1-08 after its place/Drop contracts, allowing parallel work without circular waits.