Skip to content

fix(codegen): region Number proof judges loop condition and update writes - #11782

Merged
proggeramlug merged 2 commits into
mainfrom
fix/region-proof-loop-control
Oct 3, 2026
Merged

proggeramlug merged 2 commits into
mainfrom
fix/region-proof-loop-control

Conversation

@proggeramlug

@proggeramlug proggeramlug commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Fixes a miscompile in default-on numeric receiver regions, introduced by #11680.

The bug. The Number proof for a loop-carried local only looked at writes in the loop body. A local written in the for update clause or the loop condition was proven Number by a single test before the loop. When the region needs no per-iteration recheck, that test never runs again. So o.x + s becomes a raw float add on a string's bits, and the result goes through the pointer-free raw store. Wrong output, plus a live heap pointer in an F64 field that the GC never traces.

Case node main this PR
class receiver, update s = "a" 1aa a 1aa
for (...; (s = gen(i)), i < n; ...) 5g1g2 g2 5g1g2
comma update (i++, s = t, t = "c") 3cc c 3cc
compare o.x < s with s = "9" 3 1 3
update s = {tag} 1[object Object]… { tag: 'live' } matches

PERRY_REGIONS=0 matches node, so the bug is region-only. The GC verifier doesn't catch the stray pointer.

The fix. The region's assumptions now carry the loop's condition and update. Their writes go into the same write inventory and the same fixed point as body writes. A local with any non-Number write drops to the generic route. No special case.

Tests

  • gap test test_gap_region_loop_control_writes.ts (byte-identical to node);
  • unit tests for update-clause and condition writes;
  • sabotage: removing the write walk turns both unit tests and the gap test red.

Verification

Summary by CodeRabbit

  • Bug Fixes
    • Corrected numeric handling for values reassigned in loop conditions or update clauses. Such values are no longer incorrectly treated as numbers when a loop can change them to strings or objects, helping ensure they retain their correct values after memory cleanup.
    • Added regression coverage for for and while loops, including conditions and update clauses that change loop-carried values.

Ralph Küpper added 2 commits October 3, 2026 07:38
…ites

A loop region proves a loop-carried local Number with one preheader entry
test and a fixed point over the local's writes. The fixed point walked only
the loop body, so a write in the `for` update clause or in the condition
(`for (...; i++, s = "a") { o.x = o.x + s; }`) was never judged: with no
per-iteration recheck, F added the string's NaN-box bits as a double and
stored the result into the pointer-free F64 lane. fadd propagates the
payload, so the lane held the live string pointer (o.x printed `a`, node
`1aa`), untraced by the collector.

RegionNumberAssumptions now carries the region's loop control, and the
collector feeds its writes into the same shared write inventory as the
body's. A local written there is judged by the same fixed point: a
number-producing write keeps the fact, anything else drops the local to the
generic route. The planner and the preheader pass the loop's condition and
update; a body region has none.
@coderabbitai

coderabbitai Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: d34f3447-cd9e-4954-9681-fe3ccbcaa0e6
📥 Commits

Reviewing files that changed from the base of the PR and between f6c873d and 673e19e.

📒 Files selected for processing (6)
  • changelog.d/11782-region-proof-update-clause.md
  • crates/perry-codegen/src/collectors/not_bigint_locals.rs
  • crates/perry-codegen/src/collectors/ptr_shape_numeric.rs
  • crates/perry-codegen/src/stmt/region_loop/mod.rs
  • crates/perry-codegen/src/stmt/region_loop/plan.rs
  • test-files/test_gap_region_loop_control_writes.ts

Included review availability: This review used your included allowance. Your plan provides up to 8 included reviews per hour; 7 remain after this review.


📝 Walkthrough

Walkthrough

The numeric-local proof now considers writes in loop conditions and for update clauses, as well as writes in loop bodies. Loop-region planning passes these expressions into numeric-fact analysis. Added tests cover string, object, unknown-value, and number-producing writes.

Changes

Loop numeric-local proof

Layer / File(s) Summary
Include loop-control writes in numeric analysis
crates/perry-codegen/src/collectors/ptr_shape_numeric.rs, crates/perry-codegen/src/collectors/not_bigint_locals.rs
RegionNumberAssumptions now carries loop-control expressions. The numeric-local collector includes their writes in its fixpoint analysis. Collector tests cover assignments in conditions and updates.
Pass loop controls through region planning
crates/perry-codegen/src/stmt/region_loop/mod.rs, crates/perry-codegen/src/stmt/region_loop/plan.rs, test-files/test_gap_region_loop_control_writes.ts, changelog.d/11782-region-proof-update-clause.md
Loop-region analysis passes conditions and updates into numeric-fact derivation, including during fixed-point iterations. Body-region analysis passes no loop-control expressions. The regression test covers loop-control writes, and the changelog describes the proof update.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to 673e1

The change is mergeable after normal checks; no actionable issue remains in the supplied review evidence.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 673e1

The change tightens an existing safety check rather than adding access or privileges. No introduced security issue was established in the reviewed paths, but incomplete coverage limits assurance.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The demonstrated exposure concerns source-controlled values in programs compiled with numeric receiver regions. The inspected path leads from loop assignments to arithmetic and field-storage decisions; supplied evidence does not establish deployment-wide, cross-tenant or privileged-service reachability.

Trust Boundaries and Controls

  • observed — Entry candidates exclude boxed variables and module globals, and surviving incoming values receive Number entry tests. The inspected raw class-field store helper directly stores canonical raw doubles, checks other values for plain finite representation, and canonicalizes the remaining values to pointer-free numeric output.

Resilience and Maintainability Implications

  • observed — Fast-copy lowering removes active region facts and dematerializes its numeric-proof scope before propagating a lowering error. Body-only regions intentionally use an empty control slice and test incoming values on each entry, avoiding reliance on an enclosing loop's one-time guard.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 32.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 25 functions across 5 files. (1 skipped: … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly summarizes the main change: loop-condition and update writes now affect region Number proofs.
Description check ✅ Passed The description explains the bug, fix, regression tests, and verification results. It does not include an explicit Related issue section or the checklist, but the core information is complete.
Full details: Docstring Coverage

Explanation

Docstring coverage is 32.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 25 functions across 5 files. (1 skipped: 1 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant