You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
All rows are ⏳ Planned. This document decomposes the six existing P3 commitments; it does not claim that a planned API, command, corpus or report already exists. Existing implementation roots are src/RustSharp.Syntax/, src/RustSharp.Semantics/, src/RustSharp.CodeGen.IL/, src/RustSharp.Compiler/, src/RustSharp.Runtime/ and tools/RustSharp.Conformance/. New subdirectories, profile manifests, SDK/host projects and test workspaces named below are proposed deliverables. The listed rsc test commands become executable only after their CLI and fixture prerequisites exist.
A contract-freeze leaf must produce a nonempty, versioned inventory with exact APIs/features/protocols, case IDs, expected results, numeric resource budgets and denominator/hash before implementation leaves close. Upstream crate versions and TLS/ABI details are selected there, not guessed here. Expanded scope creates a new manifest version; existing cases may not be removed or weakened to pass.
Every leaf owns its named code and corresponding tests; shared roots require an explicit file assignment before parallel edits. Evidence cells describe evidence to create, not evidence already obtained. Each leaf records artifacts/roadmap/<ID>.json (planned, ignored output) with source SHA, manifest/version/hash, actual/expected counts, tool versions, platform/RID, exact command, finite timeout/retry/item limits, PID/start/parent, exit/failure reason and cleanup. CI archives these reports with stable run URLs. Contract leaves use validator/mutation tests; implementation leaves use positive, negative, boundary and resource cases. All promised cases must run with zero failures/skips; planned verification is not completion.
A parent ID means all its listed children have accepted evidence. Leaves close on their own dependencies and evidence; they do not wait for their own phase gate. P3-GATE means all four gate rows below. P2-GATE is the hard predecessor of the P3 phase. Individual earlier work may be developed once its explicit dependencies hold, but cannot close the phase early.
P3-01: Built-in and declarative macros
ID
Status
Deliverable / ownership
Depends on
Done when
Evidence
P3-01.01
⏳ Planned
docs/profiles/macros-v1.json — Freeze the built-in macro list, fragment grammar, repetition/hygiene rules and finite budgets.
P1-01, P2-GATE
Every included form has named pass, reject and limit cases; unsupported fragments have explicit diagnostics; counts and hashes are frozen.
Manifest schema and mutation tests; macro inventory.
P3-01.02
⏳ Planned
src/RustSharp.Syntax/Macros/ — Implement token-tree fragment matching and repetition.
P3-01.01
Nested/separated and zero/one/many repetitions match the frozen grammar; ambiguous or malformed captures reject with bounded matching work.
Matcher golden cases and work-limit failures.
P3-01.03
⏳ Planned
src/RustSharp.Syntax/Macros/ — Implement scoped definitions, hygiene and capture substitution.
P3-01.02
Definition/use-site names, nested scopes and shadowing resolve as declared; accidental capture and duplicate bindings fail; expansion is deterministic.
Hygiene corpus and rustc 1.98 outcome comparison.
P3-01.04
⏳ Planned
src/RustSharp.Compiler/, src/RustSharp.Semantics/ — Connect built-ins and expanded syntax to HIR and typed MIR.
P3-01.03
Every frozen built-in and expansion uses the ordinary compiler path; unsupported expansion results reject before emission; no alternate execution fallback.
Compile/run corpus and HIR/MIR snapshots.
P3-01.05
⏳ Planned
src/RustSharp.Syntax/Macros/, src/RustSharp.CodeGen.IL/ — Preserve expansion backtraces and source/PDB mappings.
P3-01.04
Nested definition/call spans identify original sources; malformed expansions and missing source maps give stable diagnostics; repeat output is byte-identical.
Diagnostic/PDB golden tests and deterministic PE checks.
P3-01.06
⏳ Planned
tests/macros/macro-rules/, tools/RustSharp.Conformance/ — Enforce expansion limits and run the complete macro corpus.
P3-01.05
Recursion, token count, matching work, deadline and cancellation boundaries pass at limit and reject above it; all frozen cases execute or diagnose as specified.
Planned: rsc test tests/macros/macro-rules/Cargo.toml; fixed macro report.
Versioned token/span/diagnostic messages, capabilities, environment inputs and size/time limits are enumerated; incompatible or malformed messages reject.
Protocol schema, compatibility and oversize fixtures.
P3-02.02
⏳ Planned
tools/RustSharp.MacroHost/ — Implement bounded host handshake, transport and lifecycle.
P3-02.01
One request has an owned process record and deterministic result; truncated frames, protocol mismatch, crash and timeout cannot hang or corrupt compilation.
Host fault-injection reports with PID and cleanup.
P3-02.03
⏳ Planned
src/RustSharp.MacroSdk/, tests/macros/proc/ — Provide derive, attribute and function-like SDK entry points.
P3-02.02
Each frozen entry point expands a valid example; invalid registration, unsupported capabilities and invalid token output fail at the host boundary.
Cold/warm output comparison and source-map mutation tests.
P3-02.05
⏳ Planned
tools/RustSharp.MacroHost/, tests/macros/proc/ — Enforce isolation, cancellation and owned-tree cleanup.
P3-02.02
Output floods, child-process spawning, cancellation and forbidden access match the frozen trust boundary; all owned children and temporary files are reclaimed.
Adversarial host suite with deadline/output/cleanup records.
P3-02.06
⏳ Planned
tests/macros/proc/, tools/RustSharp.Conformance/ — Run the complete macro-host integration denominator.
P3-02.04, P3-02.05
All protocol versions and three macro families in the manifest compile/run; crash and cancellation leave no partial assembly or leaked host; zero skips.
Planned: rsc test tests/macros/proc/Cargo.toml; macro-host report.
P3-03: Async lowering and runtime bridge
ID
Status
Deliverable / ownership
Depends on
Done when
Evidence
P3-03.01
⏳ Planned
docs/profiles/async-v1.json — Freeze Future/Waker/Task, cancellation and panic contracts.
P1-06, P2-02
Supported async forms, Send/thread boundaries, pinning, re-poll behavior and state budgets have finite case IDs; unsupported forms have stable rejection rules.
Async manifest and state/ownership contract review.
P3-03.02
⏳ Planned
src/RustSharp.Semantics/ — Lower async functions and await to explicit MIR states.
P3-03.01
Immediate and nested suspension preserve locals/control flow; unreachable or invalid transitions reject; state/field counts obey budgets; snapshots are deterministic.
State-machine snapshots and invalid-transition tests.
P3-03.03
⏳ Planned
src/RustSharp.Semantics/, src/RustSharp.CodeGen.IL/ — Preserve borrows, moves, pinning and Drop across suspension.
P3-03.02
Captured values live exactly as specified; invalid reference escape/move rejects; completion, cancellation and unwind clean initialized fields once in order.
rustc 1.98 borrow/Drop corpus and generated-runtime traces.
P3-03.04
⏳ Planned
src/RustSharp.Runtime/Async/ — Implement Future polling and Waker registration/dispatch.
P3-03.02
Ready/Pending and wake-before/after-registration work; duplicate wakes and concurrent registration cannot lose progress or exceed queue limits.
Deterministic scheduler interleavings and wake-budget tests.
P3-03.05
⏳ Planned
src/RustSharp.Runtime/Async/ — Bridge .NET Task completion, errors and cancellation.
P3-03.03, P3-03.04
Result/error/cancellation map once in both directions; already-complete tasks and concurrent completion/cancel races match the frozen contract without dynamic code.
Task bridge race matrix and AOT reachability checks.
All supported states emit valid deterministic IL/PDB; invalid stack/state metadata rejects before emission; async frames have declared debugger mappings.
ILVerify, metadata mutation and PDB step tests.
P3-03.07
⏳ Planned
tests/async/core/, tools/RustSharp.Conformance/ — Run completion, cancellation, panic and concurrency integration.
P3-03.06
The frozen compile-pass/fail/run/Drop denominator passes; stalled futures terminate under watchdog/cancel; CoreCLR and AOT observable behavior agrees.
Planned: rsc test tests/async/core/Cargo.toml; async report.
P3-04: Exact-version tokio profile
ID
Status
Deliverable / ownership
Depends on
Done when
Evidence
P3-04.01
⏳ Planned
compat/tokio/profile-v1.json — Freeze exact upstream version, members and feature combinations.
P3-03, P2-03
Runtime/task/timer/sync/IO/network member inventory, feature closures and unsupported APIs are finite; each included member has behavior and budget case IDs.
Locked API inventory and manifest validation.
P3-04.02
⏳ Planned
compat/tokio/runtime/, compat/tokio/task/ — Implement runtime creation, scheduling and task lifecycle.
P3-04.01
Spawn/join/abort/shutdown follow the frozen thread model; task panic, nested runtime misuse and task-capacity exhaustion have declared results.
Runtime/task API cases and bounded scheduler stress.
P3-04.03
⏳ Planned
compat/tokio/time/ — Implement declared timers and timeouts.
P3-04.02
Sleep/interval/timeout cases use controlled clocks; cancellation and missed ticks match policy; overflow and timer-capacity limits reject deterministically.
Virtual-clock timelines and timer-boundary cases.
P3-04.04
⏳ Planned
compat/tokio/sync/ — Implement declared channels, locks and notification primitives.
P3-04.02
Included primitives preserve ordering/ownership; closed endpoints, canceled waiters and contention have specified outcomes; queue limits are enforced.
Sync API denominator and finite interleaving matrix.
P3-04.05
⏳ Planned
compat/tokio/io/, compat/tokio/net/ — Implement declared async IO and network members.
P3-04.02
Partial reads/writes, EOF, readiness and connection lifecycle pass local fixtures; disconnect, timeout, cancel and buffer limits leave no owned socket/task.
Loopback IO/network contract and cleanup reports.
P3-04.06
⏳ Planned
compat/tokio/, tools/RustSharp.Conformance/ — Reconcile API inventory and execute the full feature matrix.
P3-04.03, P3-04.04, P3-04.05
Every frozen API/feature combination passes both runtimes; unsupported feature combinations reject explicitly; no missing, duplicated or skipped case IDs.
Planned: rsc test compat/tokio/Cargo.toml --features declared-profile; API report.
P3-05: Bounded unsafe, layout and C FFI
ID
Status
Deliverable / ownership
Depends on
Done when
Evidence
P3-05.01
⏳ Planned
docs/profiles/unsafe-ffi-v1.json — Freeze supported unsafe operations, layouts and ABI contracts.
P1-08, P2-06
Types, pointer provenance, calling conventions, ownership, callbacks and error boundaries have finite cases; Rust ABI, unrestricted transmute, intrinsics and assembly exclusions remain explicit.
Accepted layout/FFI contract and reject inventory.
P3-05.02
⏳ Planned
src/RustSharp.Semantics/, tests/unsafe-ffi/layout/ — Compute repr(C), union, alignment and packing layouts.
P3-05.01
Frozen field offsets/size/alignment agree with native C fixtures; illegal combinations and arithmetic/size overflow reject before allocation.
Windows/Linux native layout oracle tables.
P3-05.03
⏳ Planned
src/RustSharp.Semantics/, src/RustSharp.CodeGen.IL/ — Lower declared raw-pointer operations and union access.
P3-05.02
Valid typed pointer/address operations and union accesses execute; unsafe-context/type/escape violations reject where promised; invalid-memory UB cases are classified, not executed as safe tests.
Pointer/union compile and defined-behavior execution corpus.
P3-05.04
⏳ Planned
src/RustSharp.Runtime/, src/RustSharp.Semantics/ — Implement managed/native pinning and lifetime guards.
P3-05.03
Declared pointers remain stable during owned pin scopes; escape, premature unpin and double release reject or fail as specified; cancellation/Drop releases once.
GC-pressure pin tests and ownership/cleanup negatives.
P3-05.05
⏳ Planned
src/RustSharp.CodeGen.IL/, tests/unsafe-ffi/native/ — Emit C imports and marshal declared scalar/aggregate/buffer signatures.
P3-05.04
Native functions observe exact ABI layout and buffer lengths; missing symbols, unsupported convention/signature and ownership mismatch fail predictably.
Native C caller/callee fixtures, ILVerify applicability ledger.
P3-05.06
⏳ Planned
src/RustSharp.Runtime/, tests/unsafe-ffi/native/ — Implement declared callback, thread and panic boundaries.
P3-05.05
Callback lifetime/thread contracts hold; callback-after-release and unsupported thread usage reject as specified; panic never unwinds through a C boundary.
Callback/error fixtures and subprocess panic-boundary tests.
P3-05.07
⏳ Planned
tests/unsafe-ffi/, tools/RustSharp.Conformance/ — Run the defined-behavior ABI and exclusion matrix.
P3-05.06
All supported cases agree with native fixtures on both x64 platforms/runtimes; excluded syntax produces stable diagnostics; allocations, pin handles and children are reclaimed.
Planned: rsc test tests/unsafe-ffi/Cargo.toml; ABI and resource report.
P3-06: TLS primitives and platform certificates
ID
Status
Deliverable / ownership
Depends on
Done when
Evidence
P3-06.01
⏳ Planned
docs/profiles/tls-v1.json — Freeze TLS adapter, protocol and certificate validation profile.
P3-03, P2-03
Exact provider/dependency versions, allowed protocols, trust/revocation/hostname rules and handshake/buffer budgets are explicit; no protocol choice is implied by this roadmap.
TLS API/security manifest and fixture inventory.
P3-06.02
⏳ Planned
src/RustSharp.Runtime/Tls/, tests/tls/certificates/ — Implement certificate loading and trust validation.
P3-06.01
Local trusted chains pass; untrusted/expired/wrong-purpose chains fail under the frozen policy; malformed/oversized certificates reject within bounds.
Deterministic local PKI positive/negative matrix.
P3-06.03
⏳ Planned
src/RustSharp.Runtime/Tls/, tests/tls/ — Enforce peer hostname and declared protocol negotiation.
P3-06.02
Declared DNS/IP names and protocol overlaps succeed; mismatches, excluded protocols and downgrade cases fail closed with stable errors.
Hostname/protocol loopback matrix.
P3-06.04
⏳ Planned
src/RustSharp.Runtime/Tls/ — Implement bounded async handshake and encrypted streams.
P3-06.03
Fragmented reads/writes and half-close follow contract; stalled handshake, canceled IO and oversize buffers terminate within declared limits without data reuse.
TLS stream, timeout and buffer-limit fixtures.
P3-06.05
⏳ Planned
src/RustSharp.Runtime/Tls/, tests/tls/ — Verify disposal, platform adapter and AOT reachability.
P3-06.04
Success/failure/cancel dispose sockets and certificate handles once; Windows/Linux adapters have equivalent declared results; dynamic code/reflection serialization is unreachable.
Handle-count fault injection and AOT analyzer report.
P3-06.06
⏳ Planned
tests/tls/, tools/RustSharp.Conformance/ — Execute the complete TLS contract against local endpoints.
P3-06.05
All frozen trusted/untrusted, hostname, negotiation, cancellation and disposal cases pass without public-service dependency or skipped cases.
Planned: rsc test tests/tls/Cargo.toml; TLS contract report.
P3-GATE: Phase exit
ID
Status
Deliverable / ownership
Depends on
Done when
Evidence
P3-GATE.01
⏳ Planned
tools/RustSharp.Conformance/, docs/profiles/p3-exit-v1.json — Freeze and reconcile the complete P3 exit denominator.
P2-GATE, P3-01, P3-02, P3-03, P3-04, P3-05, P3-06
Union all accepted manifests, API/features and pass/fail/run/resource cases; reject missing/duplicate cases, denominator changes and missing prerequisite evidence; zero unexplained rustc differences.
Exit-manifest validator tests and per-leaf evidence index.
P3-GATE.02
⏳ Planned
.github/workflows/, eng/ — Run the complete P3 gate on native Windows x64.
P3-GATE.01
Release has zero warnings/errors; fixed CoreCLR and Native AOT denominators pass with zero failures/skips; emitted verifiable IL passes ILVerify; unsafe IL exclusions follow the frozen policy, never disappear silently.
Windows CI SHA/URL, native run logs and IL policy report.
P3-GATE.03
⏳ Planned
.github/workflows/, eng/ — Run the complete P3 gate on native Linux x64.
P3-GATE.01
The same fixed manifests pass CoreCLR/Native AOT and IL verification policy with zero failures/skips and no AOT/trimming suppressions; native ABI/TLS fixtures execute locally.
Linux CI SHA/URL, native run logs and IL policy report.
P3-GATE.04
⏳ Planned
docs/roadmap/P3.md, docs/roadmap/P3_zh.md, ROADMAP.md, ROADMAP_zh.md — Reconcile final SHA, compatibility claims and cleanup before closing P3.
P3-GATE.02, P3-GATE.03
Same-commit evidence covers every required cell, deterministic output and bounded cleanup; bilingual API/exclusion claims agree; report mutation rejects stale/missing data; only then close P3-GATE.
Final evidence index with tools, manifests, RIDs, commands, PID, timeout and cleanup.