Skip to content

Harden MIR validation against nested typed-nil values - #160

Merged
itsfuad merged 3 commits into
mainfrom
fix/mir-typed-nil-validation
Oct 9, 2026
Merged

itsfuad merged 3 commits into
mainfrom
fix/mir-typed-nil-validation

Conversation

@itsfuad

@itsfuad itsfuad commented Oct 7, 2026 •

Copy link
Copy Markdown
Member

Summary

  • Reject nested typed-nil MIR values with validation errors instead of panicking.
  • Validate MIR at direct LLVM entry and prevent backend phase advancement when emission fails.
  • Add validator, LLVM, and pipeline regression coverage.
  • Update IR/backend architecture docs and remove architecture-audit-masterprompt.md.

Production ownership

  • mir.Module.Validate remains canonical owner of backend-independent MIR validation.
  • Nested guards reuse typednil.IsNil.
  • Pipeline and direct LLVM callers share canonical validator; no new production symbols or helpers.

Design and behavior

  • MIR rejected by Module.Validate() produces ErrInvalidEvidence and empty LLVM output.
  • Pipeline remains at MIR when emission reports errors or returns empty output.
  • Plain-nil return values and omitted payloads for payloadless variants preserve existing semantics.
  • Direct-entry revalidation protects callers that bypass pipeline.

Validation

Passed during implementation:

CCACHE_DISABLE=1 go test -count=1 ./internal/ir/mir ./internal/pipeline ./internal/backend/llvm
CCACHE_DISABLE=1 go test -count=1 ./...
CCACHE_DISABLE=1 go test -race -count=1 ./...
go vet ./...

Formatting clean. Current branch diff check passed:

git diff --check origin/main...HEAD

Risks and follow-up

  • Pipeline regression exercises MIR-to-backend rejection; earlier post-lowering validation remains intact.
  • Revalidation at both entry boundaries intentionally uses same canonical implementation.
  • Linked follow-up issues: none.

Use canonical typed-nil guards before nested MIR value access while preserving plain-nil return and payloadless variant semantics.

Keep pipeline validation and revalidate at the direct LLVM entry boundary. Stop backend phase advancement on diagnostics or empty output. Add regression tests and update architecture contracts and review reports.
@itsfuad
itsfuad merged commit b8e29b9 into main Oct 9, 2026
17 checks passed
@itsfuad
itsfuad deleted the fix/mir-typed-nil-validation branch October 9, 2026 16:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

1 participant