Skip to content

Latest commit

 

History

History
208 lines (163 loc) · 39.5 KB

File metadata and controls

208 lines (163 loc) · 39.5 KB

P1: Closable safe-core work items

English | 简体中文 · Main roadmap · Decomposition rules

Status: 🚧 In progress. The 10 parent items contain 85 implementation leaves and 6 phase-gate leaves. Completion proves only a leaf's stated delivery; subset passes do not automatically complete P1-06 through P1-10 or P1.

Scope and evidence baseline

This inventory assigns existing commitments to stable IDs without expanding or shrinking the language contract. P1-06.01's frozen ledger enumerates the typed MIR contract, P1 gap matrix and original acceptance requirements. The existing check-only type profile stays check-only; previously promised executable behavior and listed remaining work cannot disappear through reclassification. References/provenance, slices/unsizing, patterns/closures, full source move/borrow analysis, generated Drop/panic, source package contracts and every required backend each need leaves and cases.

There is no complete P1 exit candidate yet. The initial safe-core-regression-v3 manifest fixes 26 cases: it preserves the v2 source contracts except for versioning two now-executable pattern/capture expectations, and adds combined MIR family/projection samples. The immutable v2 manifest remains unchanged. The expanded p1-differential-v3 and p1-platform-v2 manifests now contain all 56 bounded source fixtures with immutable hashes, and bounded differential/platform runners emit provenance-rich reports. Native AOT/ILVerify execution and the candidate-SHA aggregate remain open; subset results cannot automatically close the expanded P1 contract.

The follow-up evidence audit found 16 differential and 12 platform sources that only print their case identifiers. Their immutable hashes/denominators remain valid, but they cannot prove the named semantics. Runners expose semantic eligibility; expanded/candidate gates independently reject placeholder sources, missing backend/process evidence and incomplete structured closure records. P1 remains 🚧 In progress; no complete candidate or closure record is claimed.

Historical/current evidence labels (only for the corresponding bounded scope):

Label Existing evidence and limit
E1 Lexical contract: 24 cases, 22 categories; historical 103-test harness.
E2 Syntax contract: 49 cases, 34 AST snapshots, 18 categories; historical 141-test harness.
E3 Module contract: 25 resolution cases; historical 190-test harness.
E4 Type contract: 96 check-only differential cases, 16 categories; historical 265-test harness.
E5 Generic contract: 32 cases and recorded ILVerify/Windows AOT; not the full P1 platform gate.
E6 f4692c704b0c5432e05d7f08a00c6736ce3a1c75: local Release zero warnings/errors, 464/464; Windows CI, Linux CI, P1 platform CI all passed. The latter covers 12 platform/24 regression/16 differential cases per platform and 6 aggregate inputs; it does not establish AOT acceptance for added constructs absent from that platform manifest.
E7 Historical struct/place/reference subset: 551/551 harness tests, regression v2 24/24 and borrow/Drop v2 16/16 with SDK 10.0.401. The projection sample matched CoreCLR/rustc and Windows x64 Native AOT; its former CLR byref representation reported ILVerify ReturnPtrToStack, also reproduced by equivalent C#. The companion storage sample passed ILVerify and Windows x64 Native AOT. E8 supersedes the projection implementation and verifier limitation.
E8 Current frozen P1-06 families: implementation inventory, 670/670 harness tests, regression v3 26/26 and borrow/Drop v2 16/16; Release zero warnings/errors using SDK 10.0.401 (repository pin 10.0.400). Both the family sample and projection sample match rustc 1.98.0 on CoreCLR and Windows x64 Native AOT, and pass ILVerify 10.0.11 without suppressed diagnostics. GC-owned references resolve the former reference-return diagnostic. Evidence: artifacts/p1-06-final-session; native AOT temporary directories were reclaimed. These results close P1-06's own leaves, while P1-07–P1-10 and the full native candidate-SHA gate remain separate.

E8 logs include build-final.stdout.log, harness-final.stdout.log, regression-v3-final.json, differential-v2-final.json and both samples' CoreCLR, ILVerify and AOT reports. All recorded final suites have zero failures, blocked cases or skips. The 12-case native platform denominator remains unchanged.

P1-01: Lossless lexing (accepted scope)

ID Status Deliverable / ownership Depends on Done when Evidence
P1-01.01 ✅ Complete Token/trivia preservation — Syntax lexer P0-GATE Reconstruct the exact input, including mixed line endings; invalid scalars retain stable spans. LexerTests, LexerClosureTests; E1
P1-01.02 ✅ Complete Literal and identifier forms — Syntax lexer P1-01.01 The declared Rust 1.98 literal, identifier, lifetime and escape categories match lexical fixtures. docs/lexical-profile.md; E1
P1-01.03 ✅ Complete Token trees and lexer budgets P1-01.01 Delimiter/depth/work/cancellation cases terminate with the declared diagnostic; no input loss. LexerClosureTests; E1
P1-01.04 ✅ Complete Freeze lexical corpus categories P1-01.02, P1-01.03 Manifest v2 retains 24 cases and 22 categories; corrupt/missing category evidence is rejected. LexingManifestTests; E1

P1-02: Safe-core syntax (accepted scope)

ID Status Deliverable / ownership Depends on Done when Evidence
P1-02.01 ✅ Complete Items, declarations and type syntax — parser P1-01 Modules/items/generic and attribute syntax have exact AST fixtures within the syntax profile. SafeCoreSyntaxTests, SyntaxItemExpansionTests; E2
P1-02.02 ✅ Complete Expressions, statements and patterns — parser P1-02.01 Precedence, branches, closures and patterns preserve syntax without promising executable semantics. SyntaxExpressionExpansionTests, SyntaxGrammarTests; E2
P1-02.03 ✅ Complete Recovery, diagnostics and parser budgets P1-02.02 Malformed input has stable code/span; recovery, depth, allocation and cancellation are bounded. SyntaxProfileBoundaryTests; E2
P1-02.04 ✅ Complete Freeze syntax acceptance corpus P1-02.03 49/49 cases, 34/34 AST snapshots and 18/18 categories remain exact; altered evidence fails. eng/Test-SyntaxEvidence.ps1, SyntaxManifestTests; E2

P1-03: HIR, names and package entry (accepted scope)

ID Status Deliverable / ownership Depends on Done when Evidence
P1-03.01 ✅ Complete HIR identity and namespaces — Syntax/HIR P1-02 Bindings identify declarations and references; unknown/ambiguous names diagnose at source. SafeCoreHirTests, SafeCoreNameResolutionTests; E3
P1-03.02 ✅ Complete Modules, imports and visibility P1-03.01 Grouped/glob/self imports and restricted visibility resolve; inaccessible exports are rejected. SafeCoreModuleResolutionTests; E3
P1-03.03 ✅ Complete Cargo path packages and bounded source discovery P1-03.02 Declared file/Cargo commands use one bounded package graph; cycles and registry requests diagnose. CargoWorkspaceTests, SafeCoreWorkspaceTests; E3
P1-03.04 ✅ Complete Original-file source maps and resolution corpus P1-03.03 25/25 resolution cases and original-file diagnostics/PDB mappings retain source identity. WorkspaceSourceMapTests, NameResolutionManifestTests; E3

P1-04: Monomorphic type checking (accepted check-only scope)

ID Status Deliverable / ownership Depends on Done when Evidence
P1-04.01 ✅ Complete Structural and nominal type descriptors P1-03 Primitive, tuple, array, slice, reference, function, ADT and never descriptors preserve identity. SafeCoreTypeHirTests, SafeCoreTypeInferenceTests; E4
P1-04.02 ✅ Complete Inference, aliases and directional coercions P1-04.01 Inference and coercion positives pass; recursive/conflicting constraints reject without state leakage. SafeCoreTypeInferenceTests; E4
P1-04.03 ✅ Complete Pattern, closure and bounded const type analysis P1-04.02 Type-only analysis checks the declared forms; budget and unsupported forms retain diagnostics. SafeCorePatternClosureTests, SafeCoreConstantTests; E4
P1-04.04 ✅ Complete Check-only boundary and type differential corpus P1-04.03 96/96 cases across 16 categories pass; executable commands for this profile reject with RSC0009. SafeCoreTypeConformanceTests, docs/type-system-profile.md; E4

P1-05: Bounded generics (accepted scope)

ID Status Deliverable / ownership Depends on Done when Evidence
P1-05.01 ✅ Complete Rigid generic bodies and marker-trait solving P0-14, P1-04 Bounded body checks, coherence, missing and ambiguous trait cases match the declared subset. SafeCoreGenericAnalysisTests, SafeCoreGenericProfileTests; E5
P1-05.02 ✅ Complete Closed specialization and aggregate layouts P1-05.01 Reachable bodies, tuples and generic structs specialize deterministically; invalid layouts reject. SafeCoreGenericAggregateTests, ClrLirValueTypeTests; E5
P1-05.03 ✅ Complete Local package generic identity and body metadata P1-05.02 The declared path-package graph preserves definitions and orphan rules; unrelated identities cannot alias. SafeCoreGenericPackageTests, SafeCoreGenericHirBindingTests; E5
P1-05.04 ✅ Complete Generic corpus and recorded executable gate P1-05.03 32/32 corpus cases plus recorded standalone/package ILVerify and Windows AOT pass for this scope. eng/Test-GenericEvidence.ps1, docs/generic-profile.md; E5

P1-06: Typed MIR and executable language families

ID Status Deliverable / ownership Depends on Done when Evidence
P1-06.01 ✅ Complete Freeze the P1 executable coverage ledger — Semantics + QA P1-04, P1-05 List every current P1 promise as executable, check-only by existing contract, or explicitly excluded; map every executable family to a leaf below. Existing missing semantics cannot be reclassified to obtain completion. Frozen bilingual ledger: p1-exit-scope-v1, 40 stable requirement IDs; case/backend denominators remain P1-10.01/.02
P1-06.02 ✅ Complete Immutable arenas and structural CFG validation — MIR model P1-04 Dense IDs, typed operands, terminators and CFG targets validate; malformed MIR fails before emission. SafeCoreMirModels.cs, SafeCoreMirValidationTests; E6
P1-06.03 ✅ Complete Scalar/control-flow HIR→MIR→CLR LIR foundation P1-06.02 Supported i32/bool/unit control flow preserves operand order, calls, branches and early returns in emitted programs. SafeCoreMirLoweringTests, SafeCoreMirPatternExecutionTests; E6
P1-06.04 ✅ Complete Type every place/projection — MIR model + validator P1-06.01, P1-06.02 Root/field/tuple/index/deref chains retain owner, result type and mutability; invalid field/index/type and depth overflow reject. SafeCoreMirPlaceTests, SafeCoreMirAdtLayoutTests, SafeCoreMirEnumTests, SafeCoreMirReferenceAbiTests: typed field/tuple/index/deref/downcast paths, actual-owner access, malformed evidence and bounded projection validation.
P1-06.05 ✅ Complete Reference provenance across locals, calls and joins P1-06.04 Every reference has an explicit source place and lifetime relation; returns, parameters and CFG joins cannot invent an origin. SafeCoreMirReferenceProvenanceTests, SafeCoreMirCompositeLifetimeTests, SafeCoreMirReferenceStorageTests: reference-slot origins through nested references, aggregates, calls and joins; lifetime elision, storage expiry, rebinding, aliases and escapes.
P1-06.06 ✅ Complete Structural-Copy repeated arrays P1-06.02 Evaluate the repeat operand once, including zero length; reject non-Copy repeats and preserve length/work/snapshot budgets. SafeCoreMirV2ProfileTests; E6
P1-06.07 ✅ Complete Full-array local slice foundation P1-06.03 Owner-specialized unsizing, length and constant/dynamic reads execute; index bounds, including empty arrays, are checked. General slice parameters/returns, subslices and writes retain their separate leaves. SafeCoreMirSliceTests, SafeCoreMirProjectionBackendTests: full-array owner preservation, dynamic read execution and bounds failures; E6, E7
P1-06.08 ✅ Complete General slice representation and call ABI P1-06.04, P1-06.05 Represent data/length/owner for shared and mutable slices, array unsizing and parameters/returns; reject invalid lifetime or element conversions. SafeCoreMirReferenceAbiTests, SafeCoreMirCompositeLifetimeTests: shared/mutable owner/start/length values, unsizing, source calls/returns, different-length joins and lifetime/element rejection.
P1-06.09 ✅ Complete Slice indexing, subslices and writes P1-06.08 Dynamic index/range checks, empty/end boundaries and mutable writes preserve shared owner identity; bounds and alias errors do not silently execute. SafeCoreMirReferenceAbiTests, SafeCoreMirCompositeLifetimeTests, SafeCoreMirFamilyEvidenceTests: dynamic index/range bounds, empty/inclusive subslices, aggregate writes, aliases and bounded lowering.
P1-06.10 ✅ Complete Pattern and match lowering, including move/ref bindings P1-06.04, P1-06.05 Tuple/scalar/declared ADT patterns, guards, or-patterns and exhaustiveness preserve evaluation/binding semantics; mismatched bindings reject. SafeCoreMirPatternExecutionTests, SafeCoreMirEnumTests, SafeCorePatternClosureTests: scalar/aggregate/enum match, move/ref/ref-mut bindings, rest/@/or patterns, guards, let-else, exhaustiveness and rejection fixtures.
P1-06.11 ✅ Complete Closure environment and capture ownership P1-06.04, P1-06.05 Declared captures distinguish copy, move, shared and mutable borrow; generated calls preserve capture lifetimes and reject unsupported escapes with stable diagnostics. SafeCoreMirClosureCaptureTests: declaration-time copy/move/shared/mutable capture storage, aggregate/reference captures, field independence, mutation and stable escape/conflict rejection. Recursive owned-field destruction retains P1-08 ownership.
P1-06.12 ✅ Complete Const-to-MIR integration P1-06.01, P1-06.02 Every executable const item/block in the frozen scope lowers from checked values; const cycles, overflow and evaluation budgets diagnose at source. SafeCoreConstantTests, SafeCoreMirConstantExecutionTests: checked scalar/aggregate values, const functions/blocks, immutable promotion, cycle/overflow diagnostics, tampered evidence and evaluation limits.
P1-06.13 ✅ Complete Reconcile the frozen executable lowering inventory P1-06.01, P1-06.08, P1-06.10, P1-06.11, P1-06.12, P1-06.17, P1-06.18, P1-06.19 Join the named family implementations and fixtures against the frozen ledger; every executable row has an owner and check-only exclusions retain capability diagnostics. Missing implementation is assigned to its family leaf, not added as unbounded work here. Executable family inventory maps P1-REQ-005–P1-REQ-022 to registered generated-program and rejection tests through SafeCoreMirPipeline and SafeCoreMirClrLowering.
P1-06.14 ✅ Complete Source mapping for every introduced MIR/LIR node P1-06.13 Mapped diagnostics and sequence points refer to original files/spans after desugaring, nested scopes and imports; corrupt source evidence rejects. WorkspaceSourceMapTests, SafeCoreMirFamilyEvidenceTests: original-file names/checksums and Portable PDB sequence points survive combined enum/capture/slice/promotion lowering; structural validation rejects corrupt spans.
P1-06.15 ✅ Complete Budgets, cancellation and fail-closed capability checks P1-06.13 Each new family has positive, unsupported, size/depth/work/time/cancellation tests; check/build agree and emit no partial output on failure. SafeCoreMirFamilyEvidenceTests, SafeCoreMirPlaceTests, SafeCoreMirAdtLayoutTests, SafeCoreMirConstantExecutionTests: per-family size/depth/work/time/cancellation, malformed/unsupported inputs, check/build rejection and no partial publication.
P1-06.16 ✅ Complete Deterministic MIR/LIR/PE/PDB snapshots P1-06.14, P1-06.15 Repeated builds of the same frozen inputs preserve bytes and ordered source/provenance facts; format changes get a new version. SafeCoreMirFamilyEvidenceTests, SafeCoreMirReferenceProvenanceTests, SafeCoreMirEnumTests: identical MIR/LIR/PE/PDB, ordered origins, original source evidence and versioned safe-core-mir-v3 metadata; compatible old inputs retain their snapshot format.
P1-06.17 ✅ Complete Scalar operators and conversions — MIR/CLR numeric lowering P1-06.01, P1-06.03 Implement the frozen executable scalar/operator/cast rows with signedness, overflow, comparison and conversion boundaries; check-only widths or char/float forms retain their specified rejection until explicitly included. SafeCoreMirScalarExecutionTests: i32/bool/bounded-usize arithmetic, division/remainder, bitwise/shifts, conversions and traps; check-only widths and char/float forms retain executable capability diagnostics.
P1-06.18 ✅ Complete Aggregate construction and layout — MIR/CLR value types P1-06.01, P1-06.04 Declared tuples, arrays and ADT variants preserve field order, discriminants, nested layout and single evaluation; malformed/recursive/oversized layouts reject. SafeCoreMirAdtLayoutTests, SafeCoreMirAdtSourceTests, SafeCoreMirEnumTests, SafeCoreMirReferenceAbiTests: declared struct/enum layouts, discriminants/payloads, reference-bearing values, source-order constructors and malformed/recursive/oversized rejection.
P1-06.19 ✅ Complete Aggregate projection reads, writes and evaluation order P1-06.18, P1-06.05 Declared field/tuple/index/deref operations access the checked owner, evaluate receiver/index/value in order and preserve mutations; wrong owner/type/bounds fail without alias substitution. SafeCoreMirProjectionBackendTests, SafeCoreMirReferenceAbiTests, SafeCoreMirReferenceStorageTests: actual-owner nested reads/writes, dynamic indices, reference rebinding and slice mutation preserve evaluation order and independent aggregate copies.

P1-07: Source ownership and lifetime checking

ID Status Deliverable / ownership Depends on Done when Evidence
P1-07.01 ✅ Complete Complete typed move-path tree — ownership analysis P1-06.04, P1-06.05 Roots and field/tuple/index/deref projections share typed identity; overlapping paths conflict and disjoint paths remain independent. SafeCoreOwnership.cs, SafeCoreOwnershipTests, and SafeCoreMirOwnershipAdapterTests cover typed projections, overlap/disjoint paths, self-move rejection, and Drop boundaries.
P1-07.02 🚧 In progress Copy versus Move at every operand and call P1-07.01 Copies retain values/loans and moves invalidate the exact source; source-level use-after-move rejects, including arguments and returns. SafeCoreMirOwnershipAdapterTests and SafeCoreMirAdtSourceTests cover non-Copy source moves; broader call/return corpus remains open
P1-07.03 🚧 In progress Partial move, reinitialization and Drop ownership P1-07.02 Moving one field preserves siblings, blocks whole-value use and permits valid reinitialization; forbidden partial moves from Drop owners reject. SafeCoreMirAdtSourceTests covers partial move/reinitialization; arrays and full Drop-owner source corpus remain open
P1-07.04 🚧 In progress NLL use/definition liveness P1-07.01 Loans end after their last reachable use, including temporaries and dead branches; lexically overlapping but nonoverlapping live borrows work. SafeCoreMirAdtSourceTests covers source NLL and bounded branch liveness; temporary/loop corpus remains open
P1-07.05 🚧 In progress Shared/mutable borrow conflicts and owner writes P1-07.04, P1-07.01 Read/write/move conflicts follow projected aliases, not just local IDs; shared reads work and overlapping exclusive accesses reject. SafeCoreMirReferenceExecutionTests; planned projected-alias negatives
P1-07.06 🚧 In progress Reborrow suspension, resumption and invalidation P1-07.05 Parent references resume only when child loans end; mutable/shared chains reject parent use and invalidated descendant reuse correctly. Planned nested projected reborrow and lifetime-edge fixtures
P1-07.07 🚧 In progress Parameter/return provenance and escapes P1-07.06, P1-06.05 Local functions preserve declared input-to-output lifetime relations; stack-owner, branch-local and capture escapes reject at source. SafeCoreMirReferenceProvenanceTests, SafeCoreMirAdtSourceTests: projected reference returns, repeated mutable-reference calls, CFG origin unions, caller borrow conflicts and local/branch-scope escapes; the remaining lifetime families stay open.
P1-07.08 🚧 In progress Branch joins and loop fixed points P1-07.03, P1-07.04, P1-07.06 Move/init/loan states merge conservatively across if/match/backedges, break and continue; work-limit exhaustion never accepts incomplete analysis. SafeCoreMirAdtSourceTests covers bounded loop/branch merge; full backedge budget corpus remains open
P1-07.09 🚧 In progress Bidirectional MIR/ownership evidence integrity P1-07.07, P1-07.08 Every place, loan origin, lifetime edge and call effect has matching MIR evidence; missing, extra, substituted or stale facts fail. SafeCoreMirOwnershipAdapterTests, SafeCoreMirReferenceProvenanceTests: MIR/provenance correlation and missing/substituted/escaping origin negatives; full family evidence coverage remains open.
P1-07.10 🚧 In progress Stable source ownership diagnostics P1-07.09, P1-06.14 Invalid programs report the intended move/borrow/escape code and original span; unsupported-lowering diagnostics cannot count as borrow rejections. SafeCoreMirAdtSourceTests checks source diagnostic code/span; complete golden catalog remains open
P1-07.11 ⏳ Planned Fixed rustc 1.98 source borrow differential P1-07.10, P1-10.05 The frozen borrow cases include valid/invalid projected moves, reborrows, NLL, joins, escapes and limits; every case executes with zero unexplained differences/skips. Planned borrow section of p1-differential-v3; per-case rustc/source hashes
P1-07.12 🚧 In progress Ownership solver resource contract P1-07.09 Operation/path/block/diagnostic limits and cancellation cover new analysis edges; malformed/cyclic evidence terminates deterministically. Planned ownership budget/cancellation boundary fixtures

P1-08: Generated Drop and panic behavior

ID Status Deliverable / ownership Depends on Done when Evidence
P1-08.01 ✅ Complete Freeze destructor and panic transition table P1-06.01, P1-07.01 Specify initialization/move/drop flags and normal/return/unwind/abort transitions, first destructor failure and double panic, with explicit Rust# divergences if any. docs/p1-drop-contract-v1.md and _zh.md; SafeCoreMirDropContract snapshot and transition tests freeze the v1 table.
P1-08.02 🚧 In progress Compile destructor bodies and receiver places P1-08.01, P1-06.04 Source impl Drop resolves one valid receiver/body and accesses owned fields through MIR; invalid signatures and unsupported bodies diagnose stably. SafeCoreMirLowering.cs; planned field-owning destructor fixtures
P1-08.03 🚧 In progress Per-place initialization and drop flags P1-08.02, P1-07.03 Initialized live values are eligible once; moves, partial initialization and reassignment update flags before throwing operations. SafeCoreMirDropFlagLowering.cs and SafeCoreMirCleanupTests provide bounded per-place snapshots and branch/loop evidence; emitted aggregate integration remains open.
P1-08.04 ✅ Complete Unit Drop normal scope foundation P1-06.03 Generated unit destructors run once in reverse declaration order on normal scope exit. SafeCoreMirDropCodegenTests.ReverseOrderAsync; E6
P1-08.05 🚧 In progress Branch, loop, break and continue cleanup P1-08.03, P1-08.13, P1-08.14 Only initialized live values of exited scopes are dropped in deterministic reverse order; later iterations do not reuse consumed flags. Planned generated branch/loop trace corpus
P1-08.06 🚧 In progress Explicit/early return cleanup P1-08.05 Return operands are evaluated once before cleanup; returned/moved values survive and every other live owner is dropped once. Existing unit return differential; planned aggregate/operand failure extensions
P1-08.07 ✅ Complete Unit Drop fault cleanup foundation P1-08.04 Generated overflow fault runs the supported unit destructor then propagates the original exception. SafeCoreMirDropCodegenTests.FaultPathAsync; E6
P1-08.08 🚧 In progress Unwind through nested generated scopes and calls P1-08.03, P1-08.06 Panic from bodies, arguments or nested calls unwinds live owners once; moved values and completed cleanup are not repeated. P1GeneratedUnwindEvidenceTests covers nested calls, return and argument overflow cleanup; generated PE/rustc differential traces remain open
P1-08.09 🚧 In progress Destructor failure continuation and double panic P1-08.08 First failure on a normal cleanup path applies the frozen remaining-cleanup policy; failure during unwind applies the frozen abort rule without swallowing either failure. RustDropGlue, RustPanicBoundary, and SafeCoreMirDropCodegenTests cover continuation, double-panic reporting, and abort selection; subprocess exit evidence remains open.
P1-08.10 🚧 In progress Abort behavior in generated programs P1-08.01, P1-08.03 Abort terminates at the declared boundary without unwind Drop; traces, exit category and absence of later user effects match the contract. RustPanicBoundary and SafeCoreMirDropCodegenTests cover the bounded abort outcome and untouched scope; isolated generated-process evidence remains open.
P1-08.11 🚧 In progress Generated local panic boundary and reusable call interface P1-08.09, P1-08.10 Generated local calls use the declared panic strategy; returned/unwound/aborted outcomes agree with emitted behavior. Publish the checked panic interface for P1-09.06; source imported-call integration is accepted there and in P1-09.09. Planned compiler-to-RustPanicBoundary integration and contract-negative fixtures
P1-08.12 ⏳ Planned Fixed rustc 1.98 Drop differential P1-08.11, P1-10.05 Normal/return/unwind/abort, field owners, partial moves and destructor failure have generated-program trace/exit comparisons; zero unexplained differences/skips. Planned Drop section of p1-differential-v3; Rust# and rustc process records
P1-08.13 🚧 In progress Recursive aggregate drop glue and field/element order P1-08.02, P1-08.03, P1-06.18 Structs without their own Drop still drop owned fields; declared tuples/arrays/active enum fields follow Rust field/element order after any outer destructor, distinct from reverse local declaration order. Skip moved/uninitialized fields and route failure edges to P1-08.08/.09. RustDropGlue and SafeCoreMirDropCodegenTests freeze outer-before-fields order and failure stopping; generated nested aggregate coverage remains open.
P1-08.14 🚧 In progress Assignment replacement and temporary destruction P1-08.03, P1-08.13 Replacing an initialized owner drops the old value once; expression/block temporaries expire at their declared scopes, and moving out suppresses later cleanup. Emit explicit exceptional edges; RHS-panic execution is accepted by P1-08.08. RustDropSlot and SafeCoreMirDropCodegenTests cover replacement and move-out one-shot flags; compiler temporary lowering remains open.

P1-09: Production emission and source-level package contracts

ID Status Deliverable / ownership Depends on Done when Evidence
P1-09.01 🚧 In progress One CLR LIR emission route per executable family P1-06.13 All frozen executable families use validated CLR LIR/PE emission; unsupported MIR never falls back to primitive or simulated execution. Planned compiler route coverage and rejection-before-output fixtures
P1-09.02 ✅ Complete Scalar imported signatures and real external calls P1-05 Scalar producer/consumer calls execute via AssemblyRef/TypeRef/MemberRef; MethodDef static/visibility/signature drift rejects. RustSharpMetadataTests.CrossAssemblyCallAsync; E6
P1-09.03 🚧 In progress Versioned imported ownership/lifetime/panic schema P1-06.01, P1-07.01 Parameter positions, move/copy/borrow effects, return origins and panic strategy round-trip without deduplication or unknown-function acceptance. RustSharpMetadata.cs; planned schema and evidence mutation fixtures
P1-09.04 🚧 In progress Imported aggregate layout and nominal identity P1-09.03, P1-06.13 Source imports reconstruct declared layouts/identities across producers; same-name/different-layout and unsupported generic shapes reject. P1SourcePackageContractTests covers stale producer layout and source aggregate import rejection; successful source package reconstruction remains open
P1-09.05 🚧 In progress Source reference/slice signatures and lifetime checking P1-09.04, P1-07.07, P1-06.08 Source consumer HIR/type analysis understands supported reference, slice and aggregate signatures; invalid returned origins and borrow effects reject. Existing manual LIR byref test; planned source imported-signature corpus
P1-09.06 🚧 In progress Imported calls through ownership-aware MIR and LIR P1-09.05, P1-08.11, P1-09.01 Source cross-package calls transfer/copy/borrow and unwind according to checked contracts; actual MemberRef signatures agree. Planned imported-call MIR/ownership/PE fixtures
P1-09.07 🚧 In progress Producer/consumer metadata reconciliation and limits P1-09.04, P1-09.05 Reconcile MethodDef/MemberRef type, assembly, visibility, static flag and all terms; malformed, duplicate, oversized or missing evidence rejects. P1SourcePackageContractTests covers stale layout rejection; malformed/limit corpus remains open
P1-09.08 🚧 In progress Deterministic cross-package artifacts P1-09.06, P1-09.07 Equivalent frozen source/package inputs produce identical ordered metadata and PE/PDB bytes; stale producer evidence cannot be reused. Planned independent-build hash and stale-assembly negatives
P1-09.09 ⏳ Planned Source producer/consumer CoreCLR integration P1-09.08 Separately compile real source packages and execute aggregate/reference/ownership/Drop calls; hand-built LIR alone does not satisfy this row. Planned source package fixtures, output/trace and package hashes
P1-09.10 ⏳ Planned Cross-package ILVerify and both native x64 AOT platforms P1-09.09, P1-10.06 The same fixed source packages verify and execute on Windows/Linux native x64 AOT with CoreCLR-equivalent traces and zero warnings/skips. Planned package platform rows in the versioned P1 platform suite

P1-10: Versioned suites and evidence aggregation

ID Status Deliverable / ownership Depends on Done when Evidence
P1-10.01 ✅ Complete Requirement-to-case coverage ledger P1-06.01 Every required leaf, including completed foundations whose new backend evidence is still missing, maps to named positive/negative/boundary/budget cases and required execution backends; no orphan requirement or case. p1-coverage-v1-manifest.json fixes 40 requirements and 160 cases; P1CoverageProfileRunner validates source hashes, categories, backends and bounds
P1-10.02 ✅ Complete Freeze expanded manifest versions and denominators P1-10.01 Check in the complete case IDs, immutable source/expectation hashes and integer denominators before implementations claim conformance; no runtime-discovered denominator. p1-expanded-suites-v1-manifest.json fixes 32 p1-differential-v3 and 24 p1-platform-v2 cases with source/expectation hashes; P1ExpandedSuiteValidator verifies every fixture source and bound
P1-10.03 🚧 In progress Compile-pass/fail and run-pass report coverage P1-10.02 Pass/fail/run cases record actual outcomes and exact expected diagnostics; unsupported, timeout, infrastructure failure and skip cannot count as expected semantic failure. P1ExpandedSuiteValidator rejects duplicate, missing-hash, skipped, altered-denominator and oversized reports; bounded v3 execution is wired, while a passing full denominator remains open
P1-10.04 ✅ Complete Preserve existing immutable regression baselines P0-11 Retain regression v1 8, regression v2 24 and differential v2 16 IDs/expectations; current platform v1 remains 12 per native platform. SafeCoreRegressionV2Tests, P1DifferentialProfileTests; E6
P1-10.05 🚧 In progress Borrow/Drop differential process runner P1-10.02 Execute every frozen v3 source with exact rustc 1.98; capture version, command, PID/start/parent, timeout, termination and cleanup even on failures. P1ExpandedDifferentialRunner and p1-differential-v3 reports provide bounded process evidence; full denominator requires native candidate resources
P1-10.06 🚧 In progress Expanded native-platform execution runner P1-10.02 Every executable family/package case runs through CoreCLR, ILVerify and native AOT on Windows/Linux x64; declared non-runtime negatives remain diagnostic cases. P1ExpandedPlatformRunner emits fixed 24-case CoreCLR/provenance reports; ILVerify and Native AOT extension remains open
P1-10.07 🚧 In progress Bind reports to source, tools and case manifests P1-10.03, P1-10.05, P1-10.06 Reports include compiler SHA, manifest hashes, platform/RID, runtime/SDK/oracle versions, bounds and cleanup; empty/missing/duplicate/stale records fail. P1EvidenceBindingValidator and P1EvidenceBindingTests validate complete, forged, stale and missing provenance; integration with expanded platform reports remains open
P1-10.08 🚧 In progress Aggregate semantic coverage and platform evidence P1-10.07 Aggregator requires the expanded frozen denominators and every required leaf/backend at one candidate SHA; 6 old reports alone cannot close the new contract. eng/Test-P1ExpandedExitGate.ps1, eng/Test-P1CandidateGate.ps1, shared eng/P1EvidenceValidation.ps1 and 13 bounded rejection checks; real semantic/native candidate evidence remains open
P1-10.09 🚧 In progress CI report publication and failure provenance P1-10.08 Both native jobs upload all success/failure reports with stable run/artifact references; unavailable infrastructure is blocked, never passed/skipped. Manual .github/workflows/p1-expanded.yml publishes paired differential/platform reports; candidate-SHA aggregation remains open
P1-10.10 ⏳ Planned Audit regression preservation and fresh candidate verification P1-10.09, P1-10.04 Full Release harness has at least 464 cases plus additions, zero failures/skips and zero build warnings/errors; legacy suites remain immutable and new suites have fixed denominators. Planned fresh candidate build/harness/manifest-audit reports

P1-GATE: P1 exit checks (not additional language scope)

ID Status Deliverable / ownership Depends on Done when Evidence
P1-GATE.01 ⏳ Planned Close the frozen language inventory P0-GATE, P1-01, P1-02, P1-03, P1-04, P1-05, P1-06 Every required executable/check-only/rejection boundary in P1-06.01 has its designated completed leaf and case evidence; no unmapped category. Planned requirement coverage audit at candidate SHA
P1-GATE.02 ⏳ Planned Close source ownership and generated cleanup semantics P1-07, P1-08 Borrow/Drop fixed cases agree with rustc 1.98 or already approved versioned divergences; simulation-only traces cannot satisfy emitted behavior. Planned borrow/Drop closure report
P1-GATE.03 ⏳ Planned Close source package/backend integration P1-09 Every source import family has reconciled metadata and generated CoreCLR/ILVerify/Windows/Linux AOT evidence. Planned source-package coverage report
P1-GATE.04 ⏳ Planned Close fixed test and report contracts P1-10 Every preserved and expanded denominator passes with failed/blocked/skipped all zero; negative evidence tests reject missing coverage. Planned expanded regression/differential/platform aggregator report
P1-GATE.05 ⏳ Planned Verify one pushed SHA on both native x64 platforms P1-GATE.01, P1-GATE.02, P1-GATE.03, P1-GATE.04 All required jobs pass at the candidate SHA; download reports and reconcile hashes/counts/platforms/versions, not just badge color. Planned stable Windows/Linux run URLs and artifact provenance
P1-GATE.06 ⏳ Planned Publish P1 closure record and synchronized status P1-GATE.05 Record leaf IDs, manifest versions, denominators, SHA/run links, clean diff and owned-resource cleanup; update both language statuses together. Planned docs/p1-completion.md; no new acceptance added at this step

Next deliveries and parallel ownership boundaries

  1. P1-06 is ✅ Complete with its frozen scope ledger and E8 implementation evidence. P1-10.01 and P1-10.02 are ✅ Complete as inventory deliveries. The audit identifies placeholder-source gaps; replace them through a new immutable suite version with real semantic scenarios and explicit expectations before claiming P1 exit coverage.
  2. P1-06.04/.05/.08/.09 provide the place/reference/slice prerequisites. The ownership lane advances P1-07.01 through .10; the destructor lane advances P1-08.01 through .11 after move/drop-flag prerequisites. Changes to the same SafeCoreMirLowering.cs or validator must integrate serially; separate agents cannot write that file concurrently.
  3. The metadata lane can advance P1-09.03/.04, while corpus/runner work advances P1-10.03/.05/.06/.07 independently. Source call integration P1-09.06 waits for reference and panic contracts.
  4. Finish source borrow/Drop differentials, real package platform cases and P1-10.08 through .10, then reconcile P1-GATE.01 through .06. Preserve existing library probes and hand-built LIR tests.

A parent ID means all required implementation leaves in that group; P1-GATE means the conjunction of its six gate leaves. A leaf never depends on its own parent or P1-GATE. The old coarse parent dependencies are refined: P1-07 starts specifically after P1-06.04/.05, and P1-08 after its place/Drop contracts, allowing parallel work without circular waits.