1- //! Target-neutral verification of matcher control flow and result effects.
1+ //! Validation of decoded bytecode control flow and result effects.
22//!
3- //! Both the semantic NFA and validated bytecode project into this small program
4- //! shape. Keeping the abstract interpreter here prevents their two trust
5- //! boundaries from maintaining parallel implementations of recursive call
6- //! summaries, materializer-stack safety, return routing, and cursor depth.
7- //!
8- //! Representation adapters resolve their own metadata before constructing a
9- //! [`Program`], so this layer needs only normalized instructions and body
10- //! contracts. It proves every control-flow path, not just every instruction:
3+ //! The bytecode loader projects structurally decoded instructions into this
4+ //! small program shape before the VM can observe the module. The abstract
5+ //! interpreter proves every control-flow path, not just every instruction:
116//! deduplicated alternative tails may legitimately reach one address with
127//! different builder stacks, so effect analysis keeps a set of abstract states
138//! per address.
@@ -32,14 +27,14 @@ use crate::bytecode::{
3227const STATE_BUDGET : usize = 1 << 18 ;
3328
3429#[ derive( Clone , Copy , Debug ) ]
35- pub ( crate ) struct Effect {
30+ pub ( super ) struct Effect {
3631 kind : EffectKind ,
3732 payload : usize ,
3833 variant_has_no_payload : Option < bool > ,
3934}
4035
4136impl Effect {
42- pub ( crate ) fn new ( kind : EffectKind , payload : usize ) -> Self {
37+ pub ( super ) fn new ( kind : EffectKind , payload : usize ) -> Self {
4338 assert_ne ! (
4439 kind,
4540 EffectKind :: VariantOpen ,
@@ -52,7 +47,7 @@ impl Effect {
5247 }
5348 }
5449
55- pub ( crate ) fn variant_open ( payload : usize , has_no_payload : bool ) -> Self {
50+ pub ( super ) fn variant_open ( payload : usize , has_no_payload : bool ) -> Self {
5651 Self {
5752 kind : EffectKind :: VariantOpen ,
5853 payload,
@@ -62,14 +57,14 @@ impl Effect {
6257}
6358
6459#[ derive( Clone , Debug ) ]
65- pub ( crate ) struct Match < A > {
60+ pub ( super ) struct Match < A > {
6661 nav : Nav ,
6762 effects : Box < [ Effect ] > ,
6863 successors : Box < [ A ] > ,
6964}
7065
7166impl < A > Match < A > {
72- pub ( crate ) fn new (
67+ pub ( super ) fn new (
7368 nav : Nav ,
7469 effects : impl Into < Box < [ Effect ] > > ,
7570 successors : impl Into < Box < [ A ] > > ,
@@ -83,7 +78,7 @@ impl<A> Match<A> {
8378}
8479
8580#[ derive( Clone , Debug ) ]
86- pub ( crate ) struct Call < A > {
81+ pub ( super ) struct Call < A > {
8782 nav : Nav ,
8883 contract : CalleeContract ,
8984 target : A ,
@@ -92,7 +87,7 @@ pub(crate) struct Call<A> {
9287}
9388
9489impl < A > Call < A > {
95- pub ( crate ) fn new (
90+ pub ( super ) fn new (
9691 nav : Nav ,
9792 contract : CalleeContract ,
9893 target : A ,
@@ -118,45 +113,45 @@ impl<A> Call<A> {
118113}
119114
120115#[ derive( Clone , Copy , Debug ) ]
121- pub ( crate ) struct Return {
116+ pub ( super ) struct Return {
122117 port : PortId ,
123118 contract : CalleeContract ,
124119}
125120
126121impl Return {
127- pub ( crate ) fn new ( port : PortId , contract : CalleeContract ) -> Self {
122+ pub ( super ) fn new ( port : PortId , contract : CalleeContract ) -> Self {
128123 Self { port, contract }
129124 }
130125}
131126
132127#[ derive( Clone , Debug ) ]
133- pub ( crate ) enum Instruction < A > {
128+ pub ( super ) enum Instruction < A > {
134129 Match ( Match < A > ) ,
135130 Call ( Call < A > ) ,
136131 Return ( Return ) ,
137132}
138133
139134#[ derive( Clone , Copy , Debug ) ]
140- pub ( crate ) struct Entry < A > {
135+ pub ( super ) struct Entry < A > {
141136 target : A ,
142137 boundary : EntryBoundary ,
143138}
144139
145140impl < A > Entry < A > {
146- pub ( crate ) fn new ( target : A , boundary : EntryBoundary ) -> Self {
141+ pub ( super ) fn new ( target : A , boundary : EntryBoundary ) -> Self {
147142 Self { target, boundary }
148143 }
149144}
150145
151146#[ derive( Clone , Copy , Debug , PartialEq , Eq ) ]
152- pub ( crate ) struct BodyContract {
147+ struct BodyContract {
153148 contract : CalleeContract ,
154149 arity : u8 ,
155150 consumed_mask : u8 ,
156151}
157152
158153impl BodyContract {
159- pub ( crate ) fn new ( contract : CalleeContract , arity : usize , consumed_mask : u8 ) -> Self {
154+ fn new ( contract : CalleeContract , arity : usize , consumed_mask : u8 ) -> Self {
160155 Self {
161156 contract,
162157 arity : u8:: try_from ( arity) . expect ( "matcher call arity fits u8" ) ,
@@ -205,7 +200,7 @@ impl BodyContract {
205200 }
206201}
207202
208- pub ( crate ) struct Program < A > {
203+ pub ( super ) struct Program < A > {
209204 instructions : HashMap < A , Instruction < A > > ,
210205 entries : Vec < Entry < A > > ,
211206 roots : HashMap < A , BodyContract > ,
@@ -215,10 +210,9 @@ impl<A> Program<A>
215210where
216211 A : Copy + Eq + Hash + Debug ,
217212{
218- pub ( crate ) fn new (
213+ pub ( super ) fn new (
219214 instructions : impl IntoIterator < Item = ( A , Instruction < A > ) > ,
220215 entries : Vec < Entry < A > > ,
221- declared_roots : impl IntoIterator < Item = ( A , BodyContract ) > ,
222216 ) -> Result < Self , VerifyError < A > > {
223217 let mut instruction_map = HashMap :: new ( ) ;
224218 for ( address, instruction) in instructions {
@@ -231,9 +225,6 @@ where
231225 }
232226
233227 let mut roots = HashMap :: new ( ) ;
234- for ( address, contract) in declared_roots {
235- insert_root ( & mut roots, address, contract) ?;
236- }
237228 for entry in & entries {
238229 insert_root ( & mut roots, entry. target , BodyContract :: entry_point ( ) ) ?;
239230 }
@@ -322,7 +313,7 @@ where
322313}
323314
324315#[ derive( Clone , Debug , PartialEq , Eq ) ]
325- pub ( crate ) enum VerifyError < A > {
316+ pub ( super ) enum VerifyError < A > {
326317 Malformed { at : Option < A > , detail : String } ,
327318 EffectStack ( A ) ,
328319 SpanStack ( A ) ,
@@ -341,28 +332,17 @@ impl<A> VerifyError<A> {
341332}
342333
343334#[ derive( Clone , Copy , Debug , Default , PartialEq , Eq ) ]
344- pub ( crate ) struct VerifyStats {
345- pub ( crate ) body_analyses : usize ,
335+ pub ( super ) struct VerifyStats {
336+ pub ( super ) body_analyses : usize ,
346337}
347338
348- #[ derive( Clone , Copy , Debug , PartialEq , Eq ) ]
349- pub ( crate ) enum EmptyPathCheck {
350- Verify ,
351- Skip ,
352- }
353-
354- pub ( crate ) fn verify < A > (
355- program : & Program < A > ,
356- empty_paths : EmptyPathCheck ,
357- ) -> Result < VerifyStats , VerifyError < A > >
339+ pub ( super ) fn verify < A > ( program : & Program < A > ) -> Result < VerifyStats , VerifyError < A > >
358340where
359341 A : Copy + Eq + Hash + Debug ,
360342{
361343 verify_return_routes ( program) ?;
362344 verify_cursor_depth ( program) ?;
363- if empty_paths == EmptyPathCheck :: Verify {
364- verify_empty_paths ( program) ?;
365- }
345+ verify_empty_paths ( program) ?;
366346 verify_effects ( program)
367347}
368348
0 commit comments