nandi/rustnimpublic Fork 0
ff34e1b3229df6e21b0c5d77053bb9b7364db5cd
Commits
Clone
git clone https://git.rickub.com/nandi/rustnim.git
git clone ssh://git@rickub.com/nandi/rustnim.git

Host key fingerprint (ed25519): SHA256:iycHnxEyq0Q7uyVpB7JlznP0G7JrTPXLYRcAU5CSLhc — verify it before your first connect.

DESIGN.md · 534 lines · 26.3 KBmarkdown Blame HistoryRaw
Scaffold rustnim: Rust->Nim transpiler, type mapping 1a218c2 nandi 8h ago1# rustnim — a Rust → Nim transpiler
2
3## Status
4
Add display.rs and the alloc half: all of base16ct now goes through afb2a6e nandithebull 6h ago5**Milestone 1 is reached: all of `base16ct` goes through.** Every one of its
6source files transpiles byte-for-byte as published, `alloc` half included, and
7its decode and encode output is byte-identical to rustc's. 33 differential
8cases, 29 behavioural and 4 rejections, plus 6 unit/integration tests. All
9green. Run `cargo test`.
Add trait impls and slice iterators; base16ct's decoder now goes through ae9f986 nandithebull 6h ago10
11Passing today: functions, `impl` methods, trait impls (formatting traits and
12`From`), structs, enums (C-like and data-carrying), `Option`/`Result` with
Add closures and unsafe; base16ct's lower.rs and upper.rs go through 0a375d8 nandithebull 6h ago13`?`, closures, `unsafe`, slice iterators (`iter`/`iter_mut`/`enumerate`/`zip`/`chunks_exact`/
Add trait impls and slice iterators; base16ct's decoder now goes through ae9f986 nandithebull 6h ago14`chunks_exact_mut`/`windows`), borrowed slices as values and return types,
15`let`/`let mut`, the full integer
Add enums, Option/Result, `?`, and the machinery base16ct needs around them b0ccd80 nandithebull 7h ago16and float operator set at exact widths, `as` casts, `if`/`while`/`loop`/`for`,
17`match` including patterns that bind, `Vec`/slices/arrays, type aliases
18(including generic ones), function-typed parameters (`impl Fn(A) -> B`),
19multi-file input, `#[cfg]` evaluation, and `println!`/`format!` with `{}`,
20`{:?}`, `{:x}`, `{:b}`, positional and inline-named arguments, and
Add the differential test runner, and a lowering to measure with it 8ac32af nandithebull 7h ago21zero/space padding.
Scaffold rustnim: Rust->Nim transpiler, type mapping 1a218c2 nandi 8h ago22
23## Why this exists
24
25We tried [tarekwasfy01/Code-Transpiler](https://github.com/tarekwasfy01/Code-Transpiler),
26which advertises `rust` as a source language, on the `base16ct` crate. It emits
27empty files and exits 0. The full investigation is in [`findings/`](findings/)
28and is published at
29https://rickub.com/nandi/code-transpiler-rust-frontend-findings
30
31The decisive finding, and the reason this is a new project rather than a patch:
32its Universal AST cannot represent Rust. `defaultSemanticTypeContract()` in
33`internal/backend/semantic_program.go:85` is hardcoded to
34
35```
36numeric: binary64, integer_width: unknown, truth: r_compatible,
37ownership: unknown, index_base: 1
38```
39
40and `semantic_document.go:1014` *validates* that every contract equals exactly
41that, while `typed_operation.go:46` rejects any value model that is not
42`tagged_dynamic_binary64`. There is no integer width and no ownership in the
43model at all. Code like `base16ct`'s constant-time decoder —
44
45```rust
46ret += (((0x2fi16 - byte) & (byte - 0x3a)) >> 8) & (byte - 47);
47```
48
49— depends on exact 16-bit signed wrapping and arithmetic shift. Lowering that
50into a 1-indexed dynamic float64 model produces silently wrong answers. So the
51first rule of this project is the one that codebase broke:
52
53> **Never approximate a semantic you cannot represent. Fail loudly instead.**
54
55`src/ty.rs` already does this: `i128`/`u128` are rejected with a reason rather
56than widened or truncated.
57
58## Architecture
59
60```
61Rust source ──syn──> syn AST ──lower──> Nim source ──nim c──> binary
62```
63
64**The frontend is `syn`, deliberately.** Hand-rolling a Rust grammar is how the
65other project went wrong; a correct parser is not the interesting part of this
66problem. The interesting part is the lowering, which is where all the work goes.
67
68Planned modules:
69
70| file | role | state |
71|---|---|---|
72| `src/ty.rs` | Rust type → Nim type, exact widths, explicit rejections | written |
Add the differential test runner, and a lowering to measure with it 8ac32af nandithebull 7h ago73| `src/lower.rs` | items, statements, expressions → Nim | written |
74| `src/fmt.rs` | `println!`/`format!` format-string handling | written |
75| `src/prelude.nim` | `Option`/`Result`/panic/`Display`/`Debug` runtime | written |
76| `src/main.rs` | CLI: `rustnim <in.rs> -o <out.nim>` | written |
77| `tests/differential.rs` | the runner described below | written |
78
Add enums, Option/Result, `?`, and the machinery base16ct needs around them b0ccd80 nandithebull 7h ago79### Enums, `Option` and `Result`
80
81A C-like enum becomes a plain Nim `enum`, which compares, orders and
82`case`-checks the way Rust's does. A data-carrying enum becomes a Nim object
83variant — a discriminant enum plus one branch per variant — which is the same
84shape the prelude already uses for `Option` and `Result`. Nim requires the
85branches of a variant object to have distinct field names, so each payload
86field is prefixed with its variant.
87
88`match` takes one of two forms. Arms that neither bind nor destructure become
89a Nim `case`, which is exhaustiveness-checked the way Rust's is. Arms that do
90bind become an `if`/`elif` chain with the bindings emitted as `let`s, because
91Nim's `case` cannot destructure. The chain always ends in an arm that panics:
92Rust proved it unreachable, but Nim cannot see that, and leaving the chain
93open would silently fall through instead.
94
95`Ok`, `Err` and `Some` are emitted with their full type arguments
96(`rsOk[T, E](v)`), because Nim cannot infer `E` from an `Ok(v)` alone. That is
97why the expected type has to reach a `match` arm as well as a `let`.
98
99`?` expands to statements — a temporary, a discriminant test, and an early
100`return` — which are emitted ahead of the line being built. Rust inserts a
101`From::from` on the error there; we accept only the case where the two error
102types already agree, rather than assume a conversion is the identity. `?` in a
103`while` condition is rejected: the early return would run once before the
104loop rather than on each iteration.
105
Add trait impls and slice iterators; base16ct's decoder now goes through ae9f986 nandithebull 6h ago106### Trait impls
107
108A `Display` impl becomes `proc rsDisplay(self: T): string`. Rust's `Formatter`
109is a sink and the observable result of `{}` is exactly the bytes written into
Add display.rs and the alloc half: all of base16ct now goes through afb2a6e nandithebull 6h ago110it, so a write through the formatter **appends** to that string — a `fmt` body
111may write repeatedly, and `UpperHex` writes once per byte in a loop. A body
112that does anything else with the formatter — padding, precision,
113`debug_struct` — is rejected, because those change the output and this model
114does not carry them. `Debug`, `LowerHex`, `UpperHex`, `Binary` and `Octal`
115work the same way.
116
117Writing into a string cannot fail, so `?` on a formatter write is a no-op. `?`
118on anything else inside a `fmt` body *can* fail, and `format!` panics when a
119formatting impl returns an error — so that is what the error branch does, with
120std's own message.
121
122`{:x}` on an integer formats its two's-complement bit pattern; on any other
123type it calls that type's own `LowerHex` impl. Those are different operations,
124so a radix format on an argument of unknown type is rejected rather than
125guessed.
Add trait impls and slice iterators; base16ct's decoder now goes through ae9f986 nandithebull 6h ago126
127`impl From<A> for B` becomes a conversion proc that `.into()` resolves
128through. A marker trait with no items generates nothing: we do not model trait
129resolution anywhere, so there is nothing for it to affect; a use that actually
130needed the trait (a `dyn`, a bound) is rejected where it appears. Any other
131trait impl is rejected.
132
133Methods are keyed by `(receiver type, name)`, not by name alone — two types
134may define the same method, and Nim tells them apart by overload resolution on
135the first parameter.
136
137`fmt::Error` is *not* the same type as a crate's own `Error`. Collapsing a
138qualified path to its last segment merged them, which was a real soundness
139bug; `core::fmt`'s types are now recognised by their qualified name.
140
141### Slice iterators are resolved to one index loop
142
143Rust's slice iterators are lazy and compose. Nim's `for` is over one sequence,
144so a chain of adaptors is resolved into a small IR and emitted as a single
145index loop in which **each binding is an lvalue into the original container**.
146That is what makes `*d = v` through `iter_mut()` write back to the caller's
147slice instead of to a copy, and what lets `chunks_exact(2)` hand out a window
148that indexes straight into the source with an offset.
149
150Only adaptors with an exact index-loop equivalent are accepted. `map`,
151`filter` and `take_while` are rejected rather than partially honoured:
152silently dropping an adaptor would change which elements the loop visits.
153
154`zip` stops at the shorter side, as Rust's does — that is a test, not an
155assumption (`tests/cases/023`).
156
157### Borrowed slices are views, not copies
158
159`&[T]` is a borrow. Nim's experimental view types model exactly that,
160including returning one from a proc: writing through the returned view is
161visible in the original buffer. That was probed against Nim 2.2.4 before being
162relied on, because copying into a `seq` would print the right bytes while
163silently changing aliasing.
164
Add display.rs and the alloc half: all of base16ct now goes through afb2a6e nandithebull 6h ago165Nim does allow a view inside an object and inside an object *field* — both
166probed, both preserving aliasing — so `Result<&[u8], E>` and
167`HexDisplay<'a>(&'a [u8])` both work. (An earlier version of this document
168claimed otherwise; that was wrong.)
169
170Two real constraints remain. Nim will not let a `let` borrow out of a local,
171so `.unwrap()`/`.expect()` on a `Result` holding a view is expanded inline and
172the binding becomes an alias — a view is a reference, so there is nothing to
173materialise, and the substituted expression is a plain field access that
174re-evaluates nothing. And `s.get(a..b)` is an `Option` of a view whose
175*validity* is what matters: the view and its condition travel together through
176`ok_or` until a `?` or `unwrap` resolves them into a bounds check plus a
177binding. Keeping such an `Option` in a variable is rejected with a message
178saying so.
179
180A `let` binding a borrow keeps the view rather than copying into a `seq`:
181`let res = encode(..)?` names the caller's buffer, and copying would print the
182right bytes while silently breaking the aliasing.
Add trait impls and slice iterators; base16ct's decoder now goes through ae9f986 nandithebull 6h ago183
Add closures and unsafe; base16ct's lower.rs and upper.rs go through 0a375d8 nandithebull 6h ago184### Closures and `unsafe`
185
186`unsafe` is a permission marker, not a semantic change: it does not alter what
187the enclosed operations mean. So the block is transparent, and every operation
188inside still goes through the ordinary lowering and is still rejected if it has
189no faithful mapping. `unsafe fn` lowers like any other proc.
190
191A closure becomes a Nim anonymous proc. Nim's closures capture by reference, as
192Rust's non-`move` closures do; a `move` closure captures by value, which is a
193different thing, so it is rejected rather than lowered to the same construct.
194`impl Fn(A) -> B` is left at Nim's default calling convention, which accepts
195both a plain top-level proc and a capturing closure — as Rust's `impl Fn` does.
196
197`.map`/`.and_then` over an `Option`/`Result` are expanded inline with the
198closure's parameter aliased to the payload, rather than handed to a generic
199proc. That keeps the whole thing an expression and keeps a view a view.
200
201`&str` is a borrowed view of someone else's bytes, so it maps to
202`openArray[char]`, not to an owned `string`. Nim accepts a `string` argument
203for an `openArray[char]` parameter, so a literal still passes straight through.
204`from_utf8_unchecked` reinterprets a byte view as a character view over the
205same memory — no copy, no validation, and writes through the original are
206visible, as in Rust.
207
208### Modules
209
210Rust keeps `lower::decode` and `mixed::decode` apart by module; flattening into
211one Nim module would merge them — they are *different functions*. So the first
212input is the crate root and each later one is a module named by its file stem,
213items are emitted as `<module>_<name>`, and a call resolves through an explicit
214qualifier, then the current module, then what `use` brought into scope, then
215the root.
216
Add generics; transpile the part of cosmic-theme that is reachable ff34e1b nandithebull 4h ago217### Generics
218
219Rust type parameters become Nim's. Nim instantiates a generic structurally at
220the call site much as Rust does, so `fn f<T>(x: T) -> T` has a direct target in
221`proc f[T](x: T): T` and no monomorphisation pass is needed.
222
223**Trait bounds and `where` clauses are dropped.** That is sound in the
224direction that matters: an operation the bound permitted either exists for the
225instantiated type or is a compile error at that instantiation site. Dropping a
226bound cannot make an accepted program mean something different — it only makes
227rustnim accept some programs rustc would reject, which does not matter when
228the input is known-good Rust. (Where it *would* matter is bound-directed
229method selection, e.g. blanket impls choosing between candidates. We do not
230model trait resolution at all, so such a program is rejected elsewhere.)
231
232Const generic parameters have no Nim equivalent and are still rejected.
233
234Two things need more than a rename. Nim cannot infer an object's generic
235parameters from a constructor's field values, so `Pair { a: 1, b: 2 }` is
236emitted as `Pair[int32](...)` using the expected type — and a generic enum's
237unit variant (`Holder::Empty`) likewise. And a binding's annotation cannot
238name a parameter Nim is still inferring, so call sites run a small unifier:
239the callee's declared parameter types are matched against the actual argument
240types to bind `T`, and the result is substituted into the return type.
241
Add trait impls and slice iterators; base16ct's decoder now goes through ae9f986 nandithebull 6h ago242### Declaration order
243
244Rust has no declaration-before-use rule and Nim does, so every proc is
245forward-declared between the type definitions and the bodies. Reordering the
246input instead would not handle mutual recursion.
247
Add the differential test runner, and a lowering to measure with it 8ac32af nandithebull 7h ago248### Type propagation is load-bearing
249
250Rust infers an unsuffixed integer literal's type from context and falls back
251to `i32`; Nim falls back to 64-bit `int`. So `lower.rs` threads an *expected
252type* down through every expression — into `let` annotations, call arguments,
253`match` patterns, compound assignments and both operands of a binary — and
254annotates every binding it emits. Without that, `let x: u8 = 200; x + 100`
255means two different things in the two languages. With it, a width the lowering
256gets wrong becomes a Nim compile error (a loud failure, reported by the
257runner) rather than a wrong answer.
Scaffold rustnim: Rust->Nim transpiler, type mapping 1a218c2 nandi 8h ago258
259## Mapping decisions made so far
260
261- **Integers**: exact width. `i32``int32`, `usize``uint`, etc. `i128`/`u128`
262 rejected.
263- **Indexing**: both 0-based. Direct.
264- **`&T`** → plain value. **`&mut T`** → `var T` parameter.
265- **`&[T]`** → `openArray[T]` in parameter position, `seq[T]` when owned.
266 `Nim::owned()` performs that conversion.
267- **Ownership/borrowck**: ignored. Nim is GC'd; for safe Rust this is sound.
268- **`Option`/`Result`** → object variants in the prelude.
269- **`match`** → Nim `case` where the arms are simple, `if`/`elif` when arms have
270 guards or bindings.
271- **Rust's expression-orientation** maps well: Nim `if`/`case` are expressions
272 too, and a proc's trailing expression is its return value.
273
Settle signed-shr and unsigned-wrap semantics against both compilers 87c9cc8 nandi 8h ago274### Settled empirically (Nim 2.2.4 vs rustc 1.98.1, both run)
275
2761. **Nim's `shr` on a signed integer is arithmetic**, matching Rust.
277 `int16(-256) shr 8` = `-1` in Nim; `(-256i16) >> 8` = `-1` in Rust.
278 `base16ct`'s decoder depends on this, so it maps directly with no helper.
2792. **Nim's fixed-width unsigned arithmetic wraps silently**, matching Rust's
280 `wrapping_*`. `uint8(200) + 100` = `44` in Nim; `200u8.wrapping_add(100)`
281 = `44` in Rust. So `wrapping_add` on an unsigned type is just `+`.
282
Add the differential test runner, and a lowering to measure with it 8ac32af nandithebull 7h ago2833. **We model rustc's debug profile.** Rust debug builds panic on signed
284 integer overflow; Nim's default build raises `OverflowDefect` on it. Those
285 are the matching pair, so the runner invokes `rustc` without `-O` and `nim
286 c` with its defaults, and `tests/cases/016` pins the behaviour. A Rust
287 panic exits 101 where a Nim Defect exits 1, so every generated module ends
288 with a handler that maps one to the other — otherwise the runner's
289 exit-status comparison would be vacuous. `wrapping_*` is therefore an
290 explicit operation on both sides: unsigned maps to the bare operator (item
291 2), signed is routed through the unsigned view of the same width.
2924. **`char` round-trips.** Rust `char` → Nim `Rune`, confirmed for ASCII and
293 non-ASCII scalars in both `{}` and `{:?}`, and across `as u32`
294 (`tests/cases/014`).
Prove byte-identity for base16ct by enumerating whole input domains 99b8376 nandithebull 5h ago2955. **Nim's integer conversion `T(x)` truncates; it does not range-check.**
296 `uint8(511'u16)` is `255`, `uint8(300'i32)` is `44`, `uint8(-1'i32)` is
297 `255` — the same answers as `cast[uint8]`. An earlier version of this
298 document asserted that `T(x)` range-checks, and used that to justify
299 `cast`. The conclusion stands — `cast` is the clearer spelling of
300 "truncate" — but the stated reason was wrong, and it had been assumed
301 rather than probed. Found by sabotaging the cast lowering and watching the
302 exhaustive proof *not* fail, which is what a sabotage test is for.
Add the differential test runner, and a lowering to measure with it 8ac32af nandithebull 7h ago303
Settle signed-shr and unsigned-wrap semantics against both compilers 87c9cc8 nandi 8h ago304### Still open
305
Add generics; transpile the part of cosmic-theme that is reachable ff34e1b nandithebull 4h ago3066. Const generic parameters, `move` closures, closure bodies with statements,
307 associated types in an `impl`, and trait objects are rejected with a reason.
Add trait impls and slice iterators; base16ct's decoder now goes through ae9f986 nandithebull 6h ago308 Lifetime parameters are *not* a rejection: they carry no runtime meaning
309 and Nim is GC'd, so `fn encode<'a>(..)` lowers fine.
Add generics; transpile the part of cosmic-theme that is reachable ff34e1b nandithebull 4h ago3107. `saturating_*` and `checked_*` are implemented, detecting overflow on the
311 unsigned view of the same width rather than with a range check that would
312 itself trap. `wrapping_*`, `overflowing_*` and `strict_*` are not all
313 covered: only add, sub and mul have the saturating and checked forms.
Prove byte-identity for base16ct by enumerating whole input domains 99b8376 nandithebull 5h ago3148. Float formatting matches Rust for ordinary values and for `inf`/`NaN`, but
Add the differential test runner, and a lowering to measure with it 8ac32af nandithebull 7h ago315 the exponent-form thresholds have only been checked at `1e21`.
Prove byte-identity for base16ct by enumerating whole input domains 99b8376 nandithebull 5h ago3169. Functions are scoped by module now, but *types* are still global: two
Add closures and unsafe; base16ct's lower.rs and upper.rs go through 0a375d8 nandithebull 6h ago317 modules declaring the same type name would collide. Relatedly, a crate's
318 own `type Result<T>` is told apart from the builtin `Result<T, E>` by
319 arity, which is not how Rust resolves it.
Evaluate host cfg predicates, and measure what that actually buys 0e6c394 nandithebull 5h ago32010. Host `#[cfg]` predicates — `unix`, `windows`, `target_os`, `target_arch`,
321 `target_family`, `target_pointer_width`, `target_endian` — are evaluated
322 against the machine, since the generated Nim is compiled for it. That makes
323 the output host-shaped: a crate branching on platform has had that branch
324 decided at transpile time. `doc`/`doctest`/`miri` are false. A custom or
325 build-script `cfg` (`crossbeam_loom`, `target_has_atomic`) has no value we
326 could know and is rejected.
Transpile a second crate, adler2, to test whether any of this generalises 5fdd5be nandithebull 5h ago32711. Associated types (`impl Iterator { type Item = .. }`) and `mod`
328 directories (`specialized/mod.rs`) are not implemented.
32912. `String::from_utf8_unchecked` copies, because Nim's `string` is an owned
Add display.rs and the alloc half: all of base16ct now goes through afb2a6e nandithebull 6h ago330 value. Rust's consumes the `Vec` without copying. Observably the same from
331 the caller, but it is a copy where Rust has none.
Scaffold rustnim: Rust->Nim transpiler, type mapping 1a218c2 nandi 8h ago332
Transpile a second crate, adler2, to test whether any of this generalises 5fdd5be nandithebull 5h ago333## A second crate: does this generalise, or is it fitted to `base16ct`?
334
335`base16ct` is the crate this was built toward, so passing it proves less than
336it looks. `adler2` 2.0.1 was picked as a deliberately different shape —
337a stateful struct with methods, operator-overload trait impls, a hand-unrolled
338four-lane inner loop — and it now works: `tests/cases/029-adler2-crate/`
339transpiles `algo.rs` byte-for-byte as published, with `lib.rs`'s items and a
340driver, and its checksums are byte-identical to rustc's across every single
341byte, every length to 600 (crossing the 4-byte unrolling boundary and the
3425552-chunk path), and 144 incremental-write splits.
343
344It needed real work, which is the honest part of the answer. Ten features:
345trait impls generalised beyond formatting and `From` (any trait's methods
346become procs on the type, with the operator traits wired into `+=`/`+`
347dispatch), `Self`, `Type::method()` static calls, `u32::from` between
348primitives, tuple-destructuring `let`, `split_at`, iterators bound to
349variables and `.remainder()`, `[0; 4]` as an array rather than a `seq`, and
350the bare `#[cfg]` flags.
351
352It also caught a **regression I had introduced**: the three-phase emission
353added for forward declarations was silently dropping `const` items declared
354*inside* a function body. `base16ct` has none, so 33 passing cases said
355nothing about it.
356
357### What the other crates did
358
359Run without fixing anything, to see where the wall is rather than to move it:
360
361| crate | outcome |
362|---|---|
363| `adler2` 2.0.1 | **works**, byte-identical |
364| `siphasher` 1.0.1 | rejected: `u128` |
365| `rustc-hash` 2.1.1 | rejected: `u128` |
366| `hex` 0.4.3 | rejected: `impl Iterator` needs an associated type |
367| `crc32fast` 1.5.0 | rejected: directory modules (`specialized/mod.rs`), then SIMD intrinsics |
368
369Two of the five stop at `u128`, which is the founding rule doing its job
370rather than a gap: they are told they cannot be translated instead of being
371handed a silently truncated hasher. The other two are honest missing
372features — associated types, and `mod` directories.
373
Evaluate host cfg predicates, and measure what that actually buys 0e6c394 nandithebull 5h ago374## How far off is a crate like `libcosmic`?
375
376Measured, not guessed. Running rustnim over `libcosmic`'s own `src/`:
377
378```
3790 of 164 files produce any translation
38050,633 lines, 112 direct dependencies
381```
382
383with 66 generic-parameter blockers, 20 trait objects, 51 `async` uses, 235
384`where` clauses, 73 associated types and 1,104 lifetime annotations. Those are
385not features the crate happens to use; they are its architecture. `libcosmic`
386is a north star, not a next step.
387
388### The blocker survey, and what it says about roadmaps
389
390400 crates from the local registry (under 4,000 lines each), all their module
391files passed together, first blocker recorded:
392
Add generics; transpile the part of cosmic-theme that is reachable ff34e1b nandithebull 4h ago393| blocker | start | after host-`cfg` | after generics |
394|---|---|---|---|
395| unevaluable `#[cfg]` | 124 | 34 | 34 |
396| generic type parameter | 69 | 91 | **1** |
397| unsupported item in an `impl` (associated types) | 54 | 63 | 87 |
398| unsupported type | 20 | 29 | 60 |
399| trait object | 17 | 25 | 30 |
400| macro definition | 21 | 24 | 25 |
401| raw pointer | 12 | 22 | 24 |
402| **crates fully transpiled** | **2** | **2** | **2** |
403
404This has now happened twice. Evaluating the host `#[cfg]` predicates cleared
40590 of 124 blockers and moved the fully-working count by zero. Generics then
406cleared 90 of 91 and moved it by zero again. Every crate each unblocked simply
407hit its next blocker.
408
409That is the shape of the problem: blockers are **deep, not wide**. A frequency
410ranking of *first* blockers is not a roadmap — it says which feature is most
411often first, not which one finishes a crate. `base16ct`, `adler2` and
412`cosmic-theme`'s spacing model work because their whole stack was ground
413through, one blocker at a time.
Evaluate host cfg predicates, and measure what that actually buys 0e6c394 nandithebull 5h ago414
415So the ranking above is not a roadmap — it says which feature is most often
416*first*, which is not the same as which feature finishes a crate. The only
417honest way to add a crate is to pick it and clear its stack, as was done
418twice.
419
Add generics; transpile the part of cosmic-theme that is reachable ff34e1b nandithebull 4h ago420Generics are now done. The next blocker by frequency is associated types
421(`type Item = ..` inside an `impl`, 87), then unsupported types (60) and trait
422objects (30) — but see the paragraph above before treating that as a plan.
423
424### `cosmic-theme`: what was reachable
425
426`tests/cases/032-cosmic-theme-spacing/` transpiles `corner.rs`, `spacing.rs`
427and `layout.rs` from `cosmic-theme` 1.0.0 — the spacing scale, corner radii
428and density model a COSMIC-native UI needs to match the desktop — with output
429byte-identical to rustc's, including the `Density`/`Spacing` and
430`Roundness`/`CornerRadii` round trips.
431
432Those files are the crate's own, with one mechanical change recorded here: the
433`use serde::{Deserialize, Serialize}` line and the `Serialize, Deserialize`
434entries in two `derive` lists were removed, because the oracle is plain
435`rustc` with no dependencies available. Nothing else was touched; rustnim
436ignores both anyway.
437
438The rest of `cosmic-theme``theme.rs` (1,830 lines), `color.rs`,
439`cosmic_palette.rs`, `derivation.rs`, `steps.rs`, `composite.rs` — is colour
440work built on `palette` (40,874 lines across 122 files, plus a proc-macro
441crate). `mode.rs` needs `cosmic-config` and its derive macro. Those are
442dependency walls, not language gaps.
Evaluate host cfg predicates, and measure what that actually buys 0e6c394 nandithebull 5h ago443
Prove byte-identity for base16ct by enumerating whole input domains 99b8376 nandithebull 5h ago444## Proof of byte-identity for `base16ct`
445
446[`PROOF.md`](PROOF.md) sets out what is actually established: exhaustive
447agreement over every two-byte decode input (65,536), every two-byte encode
448input (65,536), every single byte through `encode_str` and `HexDisplay`, and
449every length to 128 — plus a compositional argument extending those to inputs
450of any length, and 20,000 pseudorandom multi-chunk cases attacking the one
451step in that argument that is inspection rather than enumeration. Run it with
452`cargo test --test proof`. It is explicit about the difference between the
453exhaustive parts and the sampled ones.
454
Scaffold rustnim: Rust->Nim transpiler, type mapping 1a218c2 nandi 8h ago455## Testing: differential, not golden
456
457The bar is **behavioural equivalence with rustc**, not that the output looks
458plausible. For each case in `tests/cases/`:
459
460```
461rustc case.rs && ./case > expected
462rustnim case.rs -o case.nim && nim c -r case.nim > actual
463diff expected actual
464```
465
466A case only counts as passing when both binaries build *and* produce identical
Add the differential test runner, and a lowering to measure with it 8ac32af nandithebull 7h ago467stdout *and* exit with the same status.
468
469`tests/differential.rs` implements this, and checks each stage separately so a
470failure says where it went wrong: `rustnim`, `rustc`, `nim`, or `diff`. Three
471guards exist specifically because of how the other transpiler failed:
472
473- `rustnim` exiting 0 while writing **no output file** is a failure.
474- `rustnim` exiting 0 while writing an **empty output file** is a failure.
475- An **empty corpus** is a failure, so the runner cannot pass by finding
476 nothing to do.
477
478All three have been verified by deliberately breaking the transpiler and
479confirming the runner goes red.
480
481Cases carry directives in leading `//@` comments:
482
483| directive | meaning |
484|---|---|
485| `//@ reject: <substring>` | `rustnim` must *fail*, with this in its message |
486| `//@ skip: <reason>` | not run; reported as skipped |
487| `//@ args: <argv>` | passed to both binaries |
488| `//@ stdin: <line>` | fed to both binaries |
489
490`reject` cases are how the "fail loudly" rule is tested rather than merely
491stated: `900``904` pin the rejections of `i128`, an unmapped standard-library
492method, a float→int cast, an unimplemented format spec, and a closure.
493
494Run one case with `RUSTNIM_CASE=005 cargo test --test differential --
495--nocapture`. Nim is found at `.nim-toolchain/bin/nim` in the repository root
496or any parent, or via `RUSTNIM_NIM`.
Scaffold rustnim: Rust->Nim transpiler, type mapping 1a218c2 nandi 8h ago497
498## Toolchain
499
500- `rustc` / `cargo` 1.98.1 — system.
501- Nim 2.2.4 — vendored at `.nim-toolchain/` (gitignored; downloaded from
502 nim-lang.org, not installed system-wide). Binary: `.nim-toolchain/bin/nim`.
503
504## Milestone 1
505
506Transpile `base16ct` 1.0.0 — the crate the other transpiler failed on — and
Add enums, Option/Result, `?`, and the machinery base16ct needs around them b0ccd80 nandithebull 7h ago507have its decoder produce byte-identical output to the Rust original.
508
Add display.rs and the alloc half: all of base16ct now goes through afb2a6e nandithebull 6h ago509**Reached.** `tests/cases/026-base16ct-crate/` transpiles **every source file
510of base16ct 1.0.0** — `error.rs`, `lower.rs`, `upper.rs`, `mixed.rs` and
511`display.rs`, each byte-for-byte as published on crates.io, verified with
512`cmp` rather than by eye — together with `lib.rs`'s `decoded_len`,
513`encoded_len` and `decode_inner` verbatim. The `alloc` half is on, via
514`--cfg feature=alloc`. Output is byte-identical to rustc's:
Add enums, Option/Result, `?`, and the machinery base16ct needs around them b0ccd80 nandithebull 7h ago515
Add trait impls and slice iterators; base16ct's decoder now goes through ae9f986 nandithebull 6h ago516```
Add closures and unsafe; base16ct's lower.rs and upper.rs go through 0a375d8 nandithebull 6h ago517lower ok abcd1234 len=4 decode: lower, upper, mixed
518upper-rej err InvalidEncoding ... upper correctly rejects lowercase
519oddlen err InvalidLength / invalid Base16 length <- Debug and Display
520encode ok 6162636431323334 len=8 encode, both cases
521encode_str ok abcd1234 len=8 closure over unsafe, borrowed &str
Add display.rs and the alloc half: all of base16ct now goes through afb2a6e nandithebull 6h ago522Ok([171, 205, 18, 52]) decode_vec \
523abcd1234 encode_string > the alloc half
524ABCD1234 abcd1234 HexDisplay {:X} {:x}
Add trait impls and slice iterators; base16ct's decoder now goes through ae9f986 nandithebull 6h ago525```
Add enums, Option/Result, `?`, and the machinery base16ct needs around them b0ccd80 nandithebull 7h ago526
Add display.rs and the alloc half: all of base16ct now goes through afb2a6e nandithebull 6h ago527Everything lowers as written: `dst.get_mut(..decoded_len(src)?)`,
528`src.chunks_exact(2).zip(dst.iter_mut())`, `*dst = byte as u8`, the returned
529`&'a [u8]` view into the caller's buffer, `encode(src, dst).map(|r| unsafe {
530core::str::from_utf8_unchecked(r) })`, and `HexDisplay`'s `UpperHex` impl
531writing once per byte into the formatter.
Add trait impls and slice iterators; base16ct's decoder now goes through ae9f986 nandithebull 6h ago532
Add display.rs and the alloc half: all of base16ct now goes through afb2a6e nandithebull 6h ago533This is the crate whose six files the transpiler in `findings/` emitted empty
534output for, while exiting 0.