From 69e35653347153785e71aa0f28e360e9a5b93597 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Mon, 11 May 2026 00:44:28 -0400 Subject: [PATCH 1/2] WIP: R3 gate #21: int refinement overflow proven parametric --- .../int_literal_cardinality_test.rs | 53 ++++++++++++++++--- 1 file changed, 47 insertions(+), 6 deletions(-) diff --git a/src/v3/compiler/tests/integration/int_literal_cardinality_test.rs b/src/v3/compiler/tests/integration/int_literal_cardinality_test.rs index e3ca336753a..889faf8489b 100644 --- a/src/v3/compiler/tests/integration/int_literal_cardinality_test.rs +++ b/src/v3/compiler/tests/integration/int_literal_cardinality_test.rs @@ -465,12 +465,13 @@ fn out_of_range_uint8_literal_emits_magnitude_diagnostic() { /// same typed [`MagnitudeOutOfRange`](v3_compiler::diagnostics::Diagnostic::MagnitudeOutOfRange) /// diagnostic. **UInt64** literals above `i64::MAX` that still fit in `u64` /// are accepted under the decimal-string literal carrier (R3 gate #22; -/// see `uint64_upper_half_literal_tokenizes_and_narrows`). **UInt128** / -/// full **Int128** overflow cases that remain outside the representable -/// surface continue to use the same magnitude / range machinery. `UInt128` -/// is still included here for its source-representable lower-bound overflow -/// (`-1`). Alias coverage is representative rather than exhaustive so this -/// receipt stays under the CI per-test wall-clock ratchet. +/// see `uint64_upper_half_literal_tokenizes_and_narrows`), while literals +/// above the declared width fail through the same range-fact path. The 128-bit +/// cases prove the same machinery is not tied to the host `i128` boundary: +/// both signed `Int128` overflow and unsigned `UInt128` overflow compare as +/// decimal [`BigInt`](num_bigint::BigInt) magnitudes. Alias coverage is +/// representative rather than exhaustive so this receipt stays under the CI +/// per-test wall-clock ratchet. #[test] fn int_refinement_overflow_is_proven_parametric_for_representable_widths() { let cases = [ @@ -506,6 +507,30 @@ fn int_refinement_overflow_is_proven_parametric_for_representable_widths() { max: "2147483647", check_alias: true, }, + IntegerOverflowCase { + ty: "Int64", + target: "i64", + literal: "9223372036854775808", + min: "-9223372036854775808", + max: "9223372036854775807", + check_alias: true, + }, + IntegerOverflowCase { + ty: "Int128", + target: "i128", + literal: "170141183460469231731687303715884105728", + min: "-170141183460469231731687303715884105728", + max: "170141183460469231731687303715884105727", + check_alias: false, + }, + IntegerOverflowCase { + ty: "Int128", + target: "i128", + literal: "-170141183460469231731687303715884105729", + min: "-170141183460469231731687303715884105728", + max: "170141183460469231731687303715884105727", + check_alias: false, + }, IntegerOverflowCase { ty: "UInt8", target: "u8", @@ -538,6 +563,14 @@ fn int_refinement_overflow_is_proven_parametric_for_representable_widths() { max: "4294967295", check_alias: true, }, + IntegerOverflowCase { + ty: "UInt64", + target: "u64", + literal: "18446744073709551616", + min: "0", + max: "18446744073709551615", + check_alias: true, + }, IntegerOverflowCase { ty: "UInt64", target: "u64", @@ -546,6 +579,14 @@ fn int_refinement_overflow_is_proven_parametric_for_representable_widths() { max: "18446744073709551615", check_alias: false, }, + IntegerOverflowCase { + ty: "UInt128", + target: "u128", + literal: "340282366920938463463374607431768211456", + min: "0", + max: "340282366920938463463374607431768211455", + check_alias: false, + }, IntegerOverflowCase { ty: "UInt128", target: "u128", From 74de0f4ff1e5e4d0b6a72351c1770993a783dcba Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Mon, 11 May 2026 04:47:11 +0000 Subject: [PATCH 2/2] Fix gate 21 overflow receipt bounds --- .../int_literal_cardinality_test.rs | 24 ++++--------------- 1 file changed, 4 insertions(+), 20 deletions(-) diff --git a/src/v3/compiler/tests/integration/int_literal_cardinality_test.rs b/src/v3/compiler/tests/integration/int_literal_cardinality_test.rs index 889faf8489b..546226fd1f7 100644 --- a/src/v3/compiler/tests/integration/int_literal_cardinality_test.rs +++ b/src/v3/compiler/tests/integration/int_literal_cardinality_test.rs @@ -468,10 +468,10 @@ fn out_of_range_uint8_literal_emits_magnitude_diagnostic() { /// see `uint64_upper_half_literal_tokenizes_and_narrows`), while literals /// above the declared width fail through the same range-fact path. The 128-bit /// cases prove the same machinery is not tied to the host `i128` boundary: -/// both signed `Int128` overflow and unsigned `UInt128` overflow compare as -/// decimal [`BigInt`](num_bigint::BigInt) magnitudes. Alias coverage is -/// representative rather than exhaustive so this receipt stays under the CI -/// per-test wall-clock ratchet. +/// signed `Int128::MAX + 1` compares as a decimal [`BigInt`](num_bigint::BigInt) +/// magnitude, while `UInt128` still participates through its representable +/// lower-bound overflow (`-1`). Alias coverage is representative rather than +/// exhaustive so this receipt stays under the CI per-test wall-clock ratchet. #[test] fn int_refinement_overflow_is_proven_parametric_for_representable_widths() { let cases = [ @@ -523,14 +523,6 @@ fn int_refinement_overflow_is_proven_parametric_for_representable_widths() { max: "170141183460469231731687303715884105727", check_alias: false, }, - IntegerOverflowCase { - ty: "Int128", - target: "i128", - literal: "-170141183460469231731687303715884105729", - min: "-170141183460469231731687303715884105728", - max: "170141183460469231731687303715884105727", - check_alias: false, - }, IntegerOverflowCase { ty: "UInt8", target: "u8", @@ -579,14 +571,6 @@ fn int_refinement_overflow_is_proven_parametric_for_representable_widths() { max: "18446744073709551615", check_alias: false, }, - IntegerOverflowCase { - ty: "UInt128", - target: "u128", - literal: "340282366920938463463374607431768211456", - min: "0", - max: "340282366920938463463374607431768211455", - check_alias: false, - }, IntegerOverflowCase { ty: "UInt128", target: "u128",