Skip to content

Latest commit

 

History

History
102 lines (76 loc) · 18.6 KB

File metadata and controls

102 lines (76 loc) · 18.6 KB

P3 granular work: macros, async and bounded unsafe/FFI

English | 简体中文 | Main roadmap

All rows are ⏳ Planned. This document decomposes the six existing P3 commitments; it does not claim that a planned API, command, corpus or report already exists. Existing implementation roots are src/RustSharp.Syntax/, src/RustSharp.Semantics/, src/RustSharp.CodeGen.IL/, src/RustSharp.Compiler/, src/RustSharp.Runtime/ and tools/RustSharp.Conformance/. New subdirectories, profile manifests, SDK/host projects and test workspaces named below are proposed deliverables. The listed rsc test commands become executable only after their CLI and fixture prerequisites exist.

A contract-freeze leaf must produce a nonempty, versioned inventory with exact APIs/features/protocols, case IDs, expected results, numeric resource budgets and denominator/hash before implementation leaves close. Upstream crate versions and TLS/ABI details are selected there, not guessed here. Expanded scope creates a new manifest version; existing cases may not be removed or weakened to pass.

Every leaf owns its named code and corresponding tests; shared roots require an explicit file assignment before parallel edits. Evidence cells describe evidence to create, not evidence already obtained. Each leaf records artifacts/roadmap/<ID>.json (planned, ignored output) with source SHA, manifest/version/hash, actual/expected counts, tool versions, platform/RID, exact command, finite timeout/retry/item limits, PID/start/parent, exit/failure reason and cleanup. CI archives these reports with stable run URLs. Contract leaves use validator/mutation tests; implementation leaves use positive, negative, boundary and resource cases. All promised cases must run with zero failures/skips; planned verification is not completion.

A parent ID means all its listed children have accepted evidence. Leaves close on their own dependencies and evidence; they do not wait for their own phase gate. P3-GATE means all four gate rows below. P2-GATE is the hard predecessor of the P3 phase. Individual earlier work may be developed once its explicit dependencies hold, but cannot close the phase early.

P3-01: Built-in and declarative macros

ID Status Deliverable / ownership Depends on Done when Evidence
P3-01.01 ⏳ Planned docs/profiles/macros-v1.json — Freeze the built-in macro list, fragment grammar, repetition/hygiene rules and finite budgets. P1-01, P2-GATE Every included form has named pass, reject and limit cases; unsupported fragments have explicit diagnostics; counts and hashes are frozen. Manifest schema and mutation tests; macro inventory.
P3-01.02 ⏳ Planned src/RustSharp.Syntax/Macros/ — Implement token-tree fragment matching and repetition. P3-01.01 Nested/separated and zero/one/many repetitions match the frozen grammar; ambiguous or malformed captures reject with bounded matching work. Matcher golden cases and work-limit failures.
P3-01.03 ⏳ Planned src/RustSharp.Syntax/Macros/ — Implement scoped definitions, hygiene and capture substitution. P3-01.02 Definition/use-site names, nested scopes and shadowing resolve as declared; accidental capture and duplicate bindings fail; expansion is deterministic. Hygiene corpus and rustc 1.98 outcome comparison.
P3-01.04 ⏳ Planned src/RustSharp.Compiler/, src/RustSharp.Semantics/ — Connect built-ins and expanded syntax to HIR and typed MIR. P3-01.03 Every frozen built-in and expansion uses the ordinary compiler path; unsupported expansion results reject before emission; no alternate execution fallback. Compile/run corpus and HIR/MIR snapshots.
P3-01.05 ⏳ Planned src/RustSharp.Syntax/Macros/, src/RustSharp.CodeGen.IL/ — Preserve expansion backtraces and source/PDB mappings. P3-01.04 Nested definition/call spans identify original sources; malformed expansions and missing source maps give stable diagnostics; repeat output is byte-identical. Diagnostic/PDB golden tests and deterministic PE checks.
P3-01.06 ⏳ Planned tests/macros/macro-rules/, tools/RustSharp.Conformance/ — Enforce expansion limits and run the complete macro corpus. P3-01.05 Recursion, token count, matching work, deadline and cancellation boundaries pass at limit and reject above it; all frozen cases execute or diagnose as specified. Planned: rsc test tests/macros/macro-rules/Cargo.toml; fixed macro report.

P3-02: Out-of-process procedural macros

ID Status Deliverable / ownership Depends on Done when Evidence
P3-02.01 ⏳ Planned docs/profiles/proc-macros-v1.json — Freeze protocol, SDK, trust boundary and host resource contract. P3-01, P0-04 Versioned token/span/diagnostic messages, capabilities, environment inputs and size/time limits are enumerated; incompatible or malformed messages reject. Protocol schema, compatibility and oversize fixtures.
P3-02.02 ⏳ Planned tools/RustSharp.MacroHost/ — Implement bounded host handshake, transport and lifecycle. P3-02.01 One request has an owned process record and deterministic result; truncated frames, protocol mismatch, crash and timeout cannot hang or corrupt compilation. Host fault-injection reports with PID and cleanup.
P3-02.03 ⏳ Planned src/RustSharp.MacroSdk/, tests/macros/proc/ — Provide derive, attribute and function-like SDK entry points. P3-02.02 Each frozen entry point expands a valid example; invalid registration, unsupported capabilities and invalid token output fail at the host boundary. Three macro families plus negative SDK fixtures.
P3-02.04 ⏳ Planned src/RustSharp.Compiler/, src/RustSharp.Syntax/Macros/ — Integrate expansion maps, diagnostics and deterministic cache keys. P3-02.03 Host output re-enters HIR/MIR; source maps survive nested calls; declared input changes invalidate cache; corrupt/stale cache rejects. Cold/warm output comparison and source-map mutation tests.
P3-02.05 ⏳ Planned tools/RustSharp.MacroHost/, tests/macros/proc/ — Enforce isolation, cancellation and owned-tree cleanup. P3-02.02 Output floods, child-process spawning, cancellation and forbidden access match the frozen trust boundary; all owned children and temporary files are reclaimed. Adversarial host suite with deadline/output/cleanup records.
P3-02.06 ⏳ Planned tests/macros/proc/, tools/RustSharp.Conformance/ — Run the complete macro-host integration denominator. P3-02.04, P3-02.05 All protocol versions and three macro families in the manifest compile/run; crash and cancellation leave no partial assembly or leaked host; zero skips. Planned: rsc test tests/macros/proc/Cargo.toml; macro-host report.

P3-03: Async lowering and runtime bridge

ID Status Deliverable / ownership Depends on Done when Evidence
P3-03.01 ⏳ Planned docs/profiles/async-v1.json — Freeze Future/Waker/Task, cancellation and panic contracts. P1-06, P2-02 Supported async forms, Send/thread boundaries, pinning, re-poll behavior and state budgets have finite case IDs; unsupported forms have stable rejection rules. Async manifest and state/ownership contract review.
P3-03.02 ⏳ Planned src/RustSharp.Semantics/ — Lower async functions and await to explicit MIR states. P3-03.01 Immediate and nested suspension preserve locals/control flow; unreachable or invalid transitions reject; state/field counts obey budgets; snapshots are deterministic. State-machine snapshots and invalid-transition tests.
P3-03.03 ⏳ Planned src/RustSharp.Semantics/, src/RustSharp.CodeGen.IL/ — Preserve borrows, moves, pinning and Drop across suspension. P3-03.02 Captured values live exactly as specified; invalid reference escape/move rejects; completion, cancellation and unwind clean initialized fields once in order. rustc 1.98 borrow/Drop corpus and generated-runtime traces.
P3-03.04 ⏳ Planned src/RustSharp.Runtime/Async/ — Implement Future polling and Waker registration/dispatch. P3-03.02 Ready/Pending and wake-before/after-registration work; duplicate wakes and concurrent registration cannot lose progress or exceed queue limits. Deterministic scheduler interleavings and wake-budget tests.
P3-03.05 ⏳ Planned src/RustSharp.Runtime/Async/ — Bridge .NET Task completion, errors and cancellation. P3-03.03, P3-03.04 Result/error/cancellation map once in both directions; already-complete tasks and concurrent completion/cancel races match the frozen contract without dynamic code. Task bridge race matrix and AOT reachability checks.
P3-03.06 ⏳ Planned src/RustSharp.CodeGen.IL/ — Emit async CLR LIR, metadata and suspension source maps. P3-03.05 All supported states emit valid deterministic IL/PDB; invalid stack/state metadata rejects before emission; async frames have declared debugger mappings. ILVerify, metadata mutation and PDB step tests.
P3-03.07 ⏳ Planned tests/async/core/, tools/RustSharp.Conformance/ — Run completion, cancellation, panic and concurrency integration. P3-03.06 The frozen compile-pass/fail/run/Drop denominator passes; stalled futures terminate under watchdog/cancel; CoreCLR and AOT observable behavior agrees. Planned: rsc test tests/async/core/Cargo.toml; async report.

P3-04: Exact-version tokio profile

ID Status Deliverable / ownership Depends on Done when Evidence
P3-04.01 ⏳ Planned compat/tokio/profile-v1.json — Freeze exact upstream version, members and feature combinations. P3-03, P2-03 Runtime/task/timer/sync/IO/network member inventory, feature closures and unsupported APIs are finite; each included member has behavior and budget case IDs. Locked API inventory and manifest validation.
P3-04.02 ⏳ Planned compat/tokio/runtime/, compat/tokio/task/ — Implement runtime creation, scheduling and task lifecycle. P3-04.01 Spawn/join/abort/shutdown follow the frozen thread model; task panic, nested runtime misuse and task-capacity exhaustion have declared results. Runtime/task API cases and bounded scheduler stress.
P3-04.03 ⏳ Planned compat/tokio/time/ — Implement declared timers and timeouts. P3-04.02 Sleep/interval/timeout cases use controlled clocks; cancellation and missed ticks match policy; overflow and timer-capacity limits reject deterministically. Virtual-clock timelines and timer-boundary cases.
P3-04.04 ⏳ Planned compat/tokio/sync/ — Implement declared channels, locks and notification primitives. P3-04.02 Included primitives preserve ordering/ownership; closed endpoints, canceled waiters and contention have specified outcomes; queue limits are enforced. Sync API denominator and finite interleaving matrix.
P3-04.05 ⏳ Planned compat/tokio/io/, compat/tokio/net/ — Implement declared async IO and network members. P3-04.02 Partial reads/writes, EOF, readiness and connection lifecycle pass local fixtures; disconnect, timeout, cancel and buffer limits leave no owned socket/task. Loopback IO/network contract and cleanup reports.
P3-04.06 ⏳ Planned compat/tokio/, tools/RustSharp.Conformance/ — Reconcile API inventory and execute the full feature matrix. P3-04.03, P3-04.04, P3-04.05 Every frozen API/feature combination passes both runtimes; unsupported feature combinations reject explicitly; no missing, duplicated or skipped case IDs. Planned: rsc test compat/tokio/Cargo.toml --features declared-profile; API report.

P3-05: Bounded unsafe, layout and C FFI

ID Status Deliverable / ownership Depends on Done when Evidence
P3-05.01 ⏳ Planned docs/profiles/unsafe-ffi-v1.json — Freeze supported unsafe operations, layouts and ABI contracts. P1-08, P2-06 Types, pointer provenance, calling conventions, ownership, callbacks and error boundaries have finite cases; Rust ABI, unrestricted transmute, intrinsics and assembly exclusions remain explicit. Accepted layout/FFI contract and reject inventory.
P3-05.02 ⏳ Planned src/RustSharp.Semantics/, tests/unsafe-ffi/layout/ — Compute repr(C), union, alignment and packing layouts. P3-05.01 Frozen field offsets/size/alignment agree with native C fixtures; illegal combinations and arithmetic/size overflow reject before allocation. Windows/Linux native layout oracle tables.
P3-05.03 ⏳ Planned src/RustSharp.Semantics/, src/RustSharp.CodeGen.IL/ — Lower declared raw-pointer operations and union access. P3-05.02 Valid typed pointer/address operations and union accesses execute; unsafe-context/type/escape violations reject where promised; invalid-memory UB cases are classified, not executed as safe tests. Pointer/union compile and defined-behavior execution corpus.
P3-05.04 ⏳ Planned src/RustSharp.Runtime/, src/RustSharp.Semantics/ — Implement managed/native pinning and lifetime guards. P3-05.03 Declared pointers remain stable during owned pin scopes; escape, premature unpin and double release reject or fail as specified; cancellation/Drop releases once. GC-pressure pin tests and ownership/cleanup negatives.
P3-05.05 ⏳ Planned src/RustSharp.CodeGen.IL/, tests/unsafe-ffi/native/ — Emit C imports and marshal declared scalar/aggregate/buffer signatures. P3-05.04 Native functions observe exact ABI layout and buffer lengths; missing symbols, unsupported convention/signature and ownership mismatch fail predictably. Native C caller/callee fixtures, ILVerify applicability ledger.
P3-05.06 ⏳ Planned src/RustSharp.Runtime/, tests/unsafe-ffi/native/ — Implement declared callback, thread and panic boundaries. P3-05.05 Callback lifetime/thread contracts hold; callback-after-release and unsupported thread usage reject as specified; panic never unwinds through a C boundary. Callback/error fixtures and subprocess panic-boundary tests.
P3-05.07 ⏳ Planned tests/unsafe-ffi/, tools/RustSharp.Conformance/ — Run the defined-behavior ABI and exclusion matrix. P3-05.06 All supported cases agree with native fixtures on both x64 platforms/runtimes; excluded syntax produces stable diagnostics; allocations, pin handles and children are reclaimed. Planned: rsc test tests/unsafe-ffi/Cargo.toml; ABI and resource report.

P3-06: TLS primitives and platform certificates

ID Status Deliverable / ownership Depends on Done when Evidence
P3-06.01 ⏳ Planned docs/profiles/tls-v1.json — Freeze TLS adapter, protocol and certificate validation profile. P3-03, P2-03 Exact provider/dependency versions, allowed protocols, trust/revocation/hostname rules and handshake/buffer budgets are explicit; no protocol choice is implied by this roadmap. TLS API/security manifest and fixture inventory.
P3-06.02 ⏳ Planned src/RustSharp.Runtime/Tls/, tests/tls/certificates/ — Implement certificate loading and trust validation. P3-06.01 Local trusted chains pass; untrusted/expired/wrong-purpose chains fail under the frozen policy; malformed/oversized certificates reject within bounds. Deterministic local PKI positive/negative matrix.
P3-06.03 ⏳ Planned src/RustSharp.Runtime/Tls/, tests/tls/ — Enforce peer hostname and declared protocol negotiation. P3-06.02 Declared DNS/IP names and protocol overlaps succeed; mismatches, excluded protocols and downgrade cases fail closed with stable errors. Hostname/protocol loopback matrix.
P3-06.04 ⏳ Planned src/RustSharp.Runtime/Tls/ — Implement bounded async handshake and encrypted streams. P3-06.03 Fragmented reads/writes and half-close follow contract; stalled handshake, canceled IO and oversize buffers terminate within declared limits without data reuse. TLS stream, timeout and buffer-limit fixtures.
P3-06.05 ⏳ Planned src/RustSharp.Runtime/Tls/, tests/tls/ — Verify disposal, platform adapter and AOT reachability. P3-06.04 Success/failure/cancel dispose sockets and certificate handles once; Windows/Linux adapters have equivalent declared results; dynamic code/reflection serialization is unreachable. Handle-count fault injection and AOT analyzer report.
P3-06.06 ⏳ Planned tests/tls/, tools/RustSharp.Conformance/ — Execute the complete TLS contract against local endpoints. P3-06.05 All frozen trusted/untrusted, hostname, negotiation, cancellation and disposal cases pass without public-service dependency or skipped cases. Planned: rsc test tests/tls/Cargo.toml; TLS contract report.

P3-GATE: Phase exit

ID Status Deliverable / ownership Depends on Done when Evidence
P3-GATE.01 ⏳ Planned tools/RustSharp.Conformance/, docs/profiles/p3-exit-v1.json — Freeze and reconcile the complete P3 exit denominator. P2-GATE, P3-01, P3-02, P3-03, P3-04, P3-05, P3-06 Union all accepted manifests, API/features and pass/fail/run/resource cases; reject missing/duplicate cases, denominator changes and missing prerequisite evidence; zero unexplained rustc differences. Exit-manifest validator tests and per-leaf evidence index.
P3-GATE.02 ⏳ Planned .github/workflows/, eng/ — Run the complete P3 gate on native Windows x64. P3-GATE.01 Release has zero warnings/errors; fixed CoreCLR and Native AOT denominators pass with zero failures/skips; emitted verifiable IL passes ILVerify; unsafe IL exclusions follow the frozen policy, never disappear silently. Windows CI SHA/URL, native run logs and IL policy report.
P3-GATE.03 ⏳ Planned .github/workflows/, eng/ — Run the complete P3 gate on native Linux x64. P3-GATE.01 The same fixed manifests pass CoreCLR/Native AOT and IL verification policy with zero failures/skips and no AOT/trimming suppressions; native ABI/TLS fixtures execute locally. Linux CI SHA/URL, native run logs and IL policy report.
P3-GATE.04 ⏳ Planned docs/roadmap/P3.md, docs/roadmap/P3_zh.md, ROADMAP.md, ROADMAP_zh.md — Reconcile final SHA, compatibility claims and cleanup before closing P3. P3-GATE.02, P3-GATE.03 Same-commit evidence covers every required cell, deterministic output and bounded cleanup; bilingual API/exclusion claims agree; report mutation rejects stale/missing data; only then close P3-GATE. Final evidence index with tools, manifests, RIDs, commands, PID, timeout and cleanup.