Skip to content

fix(lifetime): reject local-reference escape through unbounded pointer parameters (#684 follow-up) - #1472

Merged
godofecht merged 16 commits into
mainfrom
fix/684-unbounded-parameter-pointee-followup
Oct 10, 2026
Merged

godofecht merged 16 commits into
mainfrom
fix/684-unbounded-parameter-pointee-followup

Conversation

@godofecht

@godofecht godofecht commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Soundness follow-up to #684

The composite-lifetime implementation is on main. Its docs listed an unchecked case: storing a callback or frame local reference through an unannotated pointer/span parameter. The callee cannot establish how long caller-owned pointee storage lives.

Rule

  • In a function with a lifetime domain, reject a store through a pointer/span parameter when the value contains a reference rooted in the writing frame.
  • An explicit field @lifetime(D) contract permits the store when D is the same or shorter-lived than the writer.
  • This applies to field stores and whole-composite assignments through the parameter. Existing heap, static, and domain checks remain in place.

Regression coverage

  • domain_param_field_unbounded.flow: reject a callback-local array reference stored in out[0].view.
  • domain_param_composite_unbounded.flow: reject a frame-local reference embedded in a whole Holder assignment through out[0].
  • test_domain_fields.flow: accept an explicit @lifetime(callback) field through ptr<BoundHolder>.
  • docs/language/domain-fields.md describes the rule. docs/project/Questions.md records the decision.

Verification

  • Reproduced both missing diagnostics with the previously checked-in bootstrap compiler. Regenerated bootstrap C from the updated source; self-host reached a fixed point at gen2, and bootstrap_from_c.sh --verify passed.
  • typecheck_rules: 220 passed, 0 failed.
  • ./flow test-lang tests/lang/test_domain_fields.flow: passed.
  • ./flow tool doc_examples strict: 677 examples checked, including 36 expected errors.
  • parity_typecheck.flow completed over 5,162 inputs.

@godofecht
godofecht marked this pull request as ready for review October 10, 2026 16:01
@godofecht
godofecht enabled auto-merge October 10, 2026 16:51
@godofecht
godofecht added this pull request to the merge queue Oct 10, 2026
Merged via the queue into main with commit 2b5b8db Oct 10, 2026
31 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant