Repository navigation
fix(cf): #500 optimized-path forward-branch shapes fixed-or-declined; #498 estimator gap allowlist emptied (#242) - #641
Merged
Conversation
…ap allowlist emptied Salvaged work-in-progress from an interrupted session (agent hit its session limit at 198 tool uses with these changes uncommitted in the lane-500-498 worktree); committed as-found before verification. #500 (per-shape, #483 class): - optimizer_bridge wasm_to_ir: function-level br/br_if (depth reaches the implicit function body) now DECLINES loudly (checked_sub, not the silent saturating_sub clamp onto the outermost block / bogus id 0) - optimizer_bridge wasm_to_ir: non-tail `return` declines (was silently dropped -> fall-through executed post-return code) - optimizer_bridge optimize_full: a real if/else surviving the select-idiom preprocessing declines (was Nop'd -> both arms executed unconditionally) - optimizer_bridge ir_to_arm resolution: a branch whose target id has no emitted label declines loudly (was skipped -> offset-0 placeholder landed mid-shape, the #483-class miscompile) - direct selector: function-level br == return (full epilogue: result to R0, frame dealloc, pop {r4-r8,pc}) instead of the old bare `bx lr` / outermost-block clamp; function-level br_if = conditional return (BEQ over the return sequence, stack peeked not popped so the fall-through stays live) #498 (estimator<->encoder agreement, allowlist emptied): - estimator: BOffset/BCondOffset offset-sensitive (mirrors the encoder's short/.w range split); bridge resolution declines displacements that outgrow the 2-byte form its offset table assumed (latent layout-shift miscompile for large functions) - encoder: Mov imm splits on the UNSIGNED value (imm8 MOVS / imm16 MOVW / full-width MOVW+MOVT) — retires the wrong-value 2-byte MOVS #(imm&0xFF) for negative imm and the truncated MOVW above 0xFFFF; estimator mirrors - estimator_encoder_agreement oracle: KNOWN_GAP machinery removed, every case now asserts exact agreement Refs #500 #498 #242 Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…rm decline The fib-based regression test asserted optimize_full SUCCEEDS then ir_to_arm declines (#188) — but fib contains a real if/else, which now declines earlier at optimize_full (#500). Split the pin: a straight-line local-call stream isolates the #188 ir_to_arm decline; the fib body pins the #500 optimize_full decline. Plus fmt + a clippy doc-lazy-continuation fix. Refs #500 #188 Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Codecov Report❌ Patch coverage is
📢 Thoughts on this report? Let us know! |
avrabe
added a commit
that referenced
this pull request
Jul 8, 2026
avrabe
added a commit
that referenced
this pull request
Jul 10, 2026
…cross a popcnt body (#242) (#700) #498's estimator gaps (Cmn/Adds/Subs high-reg, Popcnt, i64 long-seqs) and the neg-imm/wide MOV encoder-value bug were all closed by #555/#641: the `estimator_encoder_agreement` oracle's KNOWN_GAP allowlist is EMPTY and passes with exact per-op agreement. This adds the acceptance-criterion regression the issue names but that no test exercised: a `block`/`br_if` whose body spans a mis-sizable op (`popcnt`, 86 bytes) BETWEEN the conditional branch and its target. The test lowers the shape on the real optimized path (`optimize_full` + `ir_to_arm`), re-encodes every resulting `ArmOp` with the real Thumb-2 encoder, and asserts (1) the shape stays on the optimized path with Popcnt + a resolved BCondOffset present, (2) estimator == encoder length op-for-op, and (3) the resolved br_if displacement lands on a REAL instruction boundary PAST the popcnt body. Injecting the pre-#498 `popcnt => 2` estimate makes the branch resolve to offset 0 (into the middle of the popcnt) and the test fails — confirming teeth. Test-only: no emitted bytes change; frozen anchors 10/10 untouched. Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #500. Advances #498. Part of epic #242 (VCR-ORACLE / Track C honest-degradation discipline).
#500 — per-shape verdict table
Every shape from the issue (plus the two the class implies), pinned by the new execution differential
scripts/repro/cf_shapes_500_differential.py(cf_shapes_500.wat, unicorn vs wasmtime, memory bit-compare, both branch directions):ifelseseqblocksreal_ifelseif/elseconstructIf/ElseNop'd, BOTH arms executed (real_ifelse(1)stored the else-arm's 400)optimize_full→ direct selector, correctreal_ififwith no else, content after joinreal_if(0)stored 55)br_funcbr(depth = implicit function body)saturating_subclamped onto the outermost block's end; post-block code still ran (br_func(1)also stored 88)br= full return: result→R0, frame dealloc,pop {r4-r8,pc}— old direct arm emitted a barebx lr, skipping the epilogue)early_retreturnreturndropped to Nop, fell through (early_ret(1)also stored 111)Returnarm, correctAlso in the class, no repro shape reaches it today but pinned defensively:
ir_to_arm's resolution pass: a missing label used to be skipped silently, leaving the offset-0 placeholder → br_if landed on the very next instruction (the literal Optimized (non-relocatable) path miscompiles block/br_if: branch target lands mid-instruction #483-class bug). Now declines loudly.br_if= conditional return (BEQ over the return sequence; stack peeked, not popped, so the fall-through path keeps its operands live; reload-before-CMP so a spill reload can't sit between CMP and Bcc).Red → green (full outputs in the harness,
SYNTH=<binary> python scripts/repro/cf_shapes_500_differential.py):resolved_branch_geometry(#604/#607) discipline is respected: the geometry mapper sizes resolved streams viaestimate_arm_byte_size, and the new far-branch decline guarantees every surviving numeric branch fits the 2-byte short form — so the estimator's new offset-sensitivity agrees with the layout the bridge actually froze, and no shipped stream's geometry shifts (frozen fixtures bit-identical, below).#498 — estimator gap allowlist: 2 → 0
The
estimator_encoder_agreementoracle'sKNOWN_GAPmachinery is deleted; every case now asserts exact agreement.BOffset/BCondOffsetfar ("structural survivor").wrange split (B.N imm11 / B.N imm8 → 2, else 4); the bridge's resolution pass declines any displacement outgrowing the short form its offset table assumed (previously a silent latent layout-shift miscompile for large functions) — the chicken-and-egg resolved by refusing the egg, loudlyMovnegative imm ("encoder-side survivor")*imm <= 255emittedMOVS Rd, #(imm & 0xFF)for negative imm; MOVW truncated >0xFFFFNew agreement cases:
BOffset_far,BCondOffset_far,BCondOffset_far_neg,Mov_imm_neg,Mov_imm_wide.Test repair (commit 2)
optimized_path_declines_functions_with_callsassertedoptimize_fullsucceeds on fib thenir_to_armdeclines (#188) — but fib contains a realif/else, which now declines earlier. Split the pin: a straight-line local-call stream isolates the #188ir_to_armdecline; the fib body pins the new #500optimize_fulldecline (optimized_path_declines_real_if_else).Verification (re-run in full after rebasing onto #636, which touches the same three files)
cf_shapes_500_differential.py: baseline main FAIL (4) → this branch PASS (14/14)estimator_encoder_agreement: ok (allowlist empty, exact agreement everywhere)cargo test -p synth-cli --test frozen_codegen_bytes: 10/10 ok — shipped.textuntouchedcargo test --workspace: greencargo fmt --check+cargo clippy --workspace --all-targets -- -D warnings: clean🤖 Generated with Claude Code