Repository navigation
feat!: ship C ABI 3 and schema 0.10 on a consolidated engine - #51
Merged
Merged
Conversation
BREAKING CHANGE: the C ABI moves to revision 3, the IDL schema to 0.10.0,
and every generated package changes shape.
- Identity drives every name. The library's package name, C symbol prefix,
and native library name come from its Cargo.toml (Rust producers) or
`[package]` in weaveffi.toml (IDLs). Every C symbol and type is
`{prefix}_...`, including the runtime, so any number of WeaveFFI-built
libraries can share a process; no generated package is named after
WeaveFFI.
- ABI 3: strings cross as (ptr, len) UTF-8 runs freed with
`{prefix}_free_bytes` (no `free_string`, no NUL stripping); a new `-5`
cancelled code; reference-counted cancel tokens whose cancellation drops the
future; exactly-once async completion even when a spawner drops a future;
per-module contract checksums every consumer verifies at load; leak
counters (`{prefix}_debug_live`) behind the `leak-check` feature.
- Validation: a global C symbol table rejects every collision (flattened
module paths, async completion types, iterator symbols, constants, buffer
helpers); qualified names must match their module; float map keys and
synchronous `cancellable` functions are rejected. Resolved types carry
absolute names.
- Producer macro: thunks are `unsafe extern "C"` and hidden; the prefix is the
crate name; `export_runtime!` is a proc macro; error messages come from
`Display`; callback methods may return `Result<T, ForeignError>`; borrowed
`&str`/`&[u8]` parameters are zero-copy; a type referenced from a sibling
module tree must be a record or rich enum (a compile error with guidance
replaces a silent ABI mismatch); iterators are synchronized; buffers use
memcpy fast paths.
- Crates: 18 crates become 6 (`weaveffi`, `weaveffi-abi`, `weaveffi-macros`,
`weaveffi-model`, `weaveffi-gen`, `weaveffi-cli`); the proc macro no longer
pulls YAML, TOML, JSON Schema, miette, or rayon into producer builds.
- Generators: every target is ported to ABI 3 with identity-driven names,
standalone packages, cancellation wired to the language's idiom,
use-after-free-safe object lifetimes, and fixed runtime code moved into real
source files. Node and Wasm share one JS layer; Wasm loads without
experimental flags; C gains a generated value-buffer helper header; C++
includes the C header; Swift is Sendable and packages an XCFramework for
iOS; Kotlin uses per-module objects, reachability-safe calls, and supports
Android API 21 and the JVM; .NET uses SafeHandle and LibraryImport; Python
binds prototypes once and passes bytes without per-byte loops; Go takes a
context.Context; Dart callbacks are safe from other threads where the VM
allows; Ruby releases the GVL around blocking calls.
- CLI: a `[project]` table (input, out, targets) so bare `weaveffi generate`
works; `weaveffi init`; the orchestrator renders in memory, writes only
changed files, and removes files it no longer generates; `diff --target`
without running hooks; `package` defaults to the host (or the platforms in
`--binaries`) and assembles a Swift XCFramework for iOS slices.
- Tests and CI: one CLI test binary; brittle prose tests removed; snapshot
fixtures compile-checked with every language's toolchain; conformance split
per language with per-lane timeouts and leak assertions, run on Linux and
macOS; release-plz and prebuilt binaries replace semantic-release.
- Docs rewritten for the new design (about 60 percent smaller).
- Replace expression-position bail! (an error on Rust 1.99) with Err(miette!). - Force LF checkouts so include_str! runtime templates render identically on Windows, and normalize generated output paths to forward slashes. - Install the Dart SDK directly; setup-dart can't run inside a composite action. - Update the yanked yoke-derive 0.8.3 to 0.8.4.
…aunch The test let another thread destroy the consumer's token before the launcher adopted it, a use-after-free the contract forbids; it now races cancel and destroy against the running future instead. Also normalize path separators in the Swift identity test for Windows.
This was referenced Oct 3, 2026
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This is the overhaul from the repo analysis: C ABI revision 3 and IDL schema 0.10.0, built on a consolidated engine. It's one squashed commit, breaking by design (pre-1.0), with no compatibility shims.
Excluding snapshots: 557 files changed, +54K / −79K lines. Snapshots, mostly regenerated: 395 files, +77K / −55K.
Why
The analysis found problems the README didn't mention:
boolas 32 bits.weaveffi_*runtime symbols, so two WeaveFFI libraries couldn't share one process.What changed
Identity
Cargo.toml(Rust producers) or[package](IDLs).{prefix}_…, including the runtime.ABI 3 (see
docs/src/reference/abi.md)(ptr, len)and freed with{prefix}_free_bytes.-5cancelled code.Validation
cancellablefunctions are rejected.Macro
unsafeand doc-hidden.Display.Result<T, ForeignError>.&strand&[u8]parameters are zero-copy.Crates
weaveffi,-abi,-macros,-model,-gen,-cli.Generators
packagebuilds an XCFramework when iOS slices are included.CLI
weaveffi init.[project]table (input,out,targets), so bareweaveffi generateworks.diff --targetwithout running hooks.packagedefaults to the host, or to the platforms already in--binaries.Tests and CI
Docs
Verification (local, macOS)
cargo fmt --check,cargo clippy --workspace --all-targets -D warnings,cargo doc(with-D warnings -D rustdoc::all), andcargo machete: clean.cargo insta test --workspace --check: all pass.bash scripts/check-fixtures.sh: 55 of 55 pass (5 fixtures × 11 targets).bash conformance/run.sh: 61 of 61 lanes pass across all 11 languages, each ending with every leak counter at zero. The C and C++ lanes run under ASan/UBSan.weaveffi package --target swift --platforms ios-arm64,ios-sim-arm64,darwin-x64assembled an XCFramework thatswift buildlinks against.Not done, or not verified
cargo deny(not installed) and the new CI workflows themselves (the matrix, the composite toolchain action, the Android NDK job, release-plz, and binary releases).{PREFIX}_LIBRARYis a build-time setting for Go, Swift and C++, because they link the library rather than load it.kotlincand CMake.