# Step: strict implementation-vs-definition signature checks Tag `v3-sigcheck`. Suite **129/129**; fixpoint **OK** (`bootstrap/fixpoint.sh`, image **2,102,326 bytes**). ## What changed An `IMPLEMENTATION` procedure heading must now match its `DEFINITION` (or exported `FORWARD`) beyond arity: - **result type**, **formal count**, each **formal type**, and each formal's **`VAR`-ness**. Mismatch → new semantic error **235 `implementation does not match definition`**. Before, only the *arity* was effectively covered and a differing result type or parameter type was silently accepted (a real separate-compilation hazard). ## How it works - `ResumeProc` (the implementation heading resuming a DEFINITION procedure) snapshots the definition signature into the symbol: `snapRes` (result), `snapT[]`/`snapV[]` (formal types / VAR-ness), `nSnap`, and sets `fsnap`. - The implementation heading re-enters its own formals; as each formal's type becomes known (`FixPending`), the formal is compared against the snapshot. `SetProcRes` compares the result type (and is the backstop for a parameterless heading). - Comparisons use `FormalOk` (value formals: same type, both integer-family, or string-compatible) and `VarParamOk` (VAR formals); a mismatched `VAR`-ness is caught directly. InvalidType is treated as "no evidence" so a single root error is not multiplied. - Signatures are bounded to `MaxSnap = 16` formals (self-hosting uses far fewer). ## Deliberate leniency - `INTEGER`/`CARDINAL` are accepted interchangeably for **value** formals and results: V3 models them as one integer family (a per- type split would reject the compiler's own valid-looking source). For `VAR` formals the types must match exactly. - `VAR` open arrays vs fixed arrays still follow `VarParamOk` (a fixed array is an acceptable actual for an open formal). ## Tests `tests/{sig.def,sig.mod,sig_prog.mod}` + `expect_fail_files sig`: `sig.mod` declares `Add(a,b):CHAR` where the definition says `:INTEGER`, and `Fill(buf:ARRAY OF CHAR;n:CARDINAL)` where the definition has `VAR buf`. Both report 235. Exact-match sessions still compile (verified with the full `m5` case). ## Notes - Error 231 is already "opaque type outside definition", so the signature mismatch got its own code, 235. - `qbe`/`.ssa` output is suppressed when 235 fires (the session is rejected before codegen), matching other semantic errors. ## Files `compiler/src/SymTab.def`/`.mod` (`ResumeProc` snapshot, `FixPending` and `SetProcRes` returning the check result, `FormalOk`, `MaxSnap`), `compiler/src/M2.atg` (report 235 at `SetProcRes`/`FixPending`), `compiler/src/compiler.frm` (message 235), `compiler/tests/{sig.def,sig.mod,sig_prog.mod}`, `compiler/run_tests.sh`, `docs/features.md`.