🤖 AI Summary
This work addresses a limitation in Scala 3’s capture checking, which lacks a mechanism to classify capabilities by semantic roles, thereby hindering the expression of natural constraints such as “retain only control flow” or “exclude thread-local.” To overcome this, the paper proposes a tree-structured, extensible capability classifier that enables semantic-level filtering and composition of capture sets through *only*/*except* projections and subtree intersection, union, and difference operations. Branch mutual exclusion guarantees decidability of reasoning even in the presence of unknown extensions. The approach extends System Capless with a formal classifier algebra and provides machine-checked proofs of type and effect safety in Lean 4. Integrated into Scala 3, the mechanism has been successfully applied to standard library types such as `Try` and `Future`, significantly enhancing both the expressiveness and practical utility of capture checking.
📝 Abstract
Capture checking in Scala 3 enables lightweight and practical effect and resource tracking by recording capabilities in types. However, the system offers no way to reason about kinds of capabilities. Natural constraints such as "retaining only the control-flow capabilities of this closure" or "excluding all thread-local capabilities from this argument" become inexpressible. Both arise in the Scala 3 standard library: "Try" re-throws caught exceptions, so it retains only the control-flow capabilities of its body, and "Future" must not capture thread-local resources. The inability to state these constraints has kept parts of the library outside capture checking.
We introduce capability classifiers: a tree-structured, user-extensible hierarchy of tags that classify capabilities by their semantic role. Projections filter capture sets by classifier, supporting both inclusion ("c.only[C]") and exclusion ("c.except[C]"). The tree structure enables decidable disjointness reasoning: classifiers on separate branches are guaranteed to be disjoint regardless of unknown extensions elsewhere in the hierarchy. We formalize classifiers as an extension of System Capless, a core calculus for capture checking, introducing a classifier kind algebra based on intersection, union, and subtraction of classifier subtrees. We extend the operational semantics to model exception interception and establish type safety, effect safety, and handler coverage via a big-step proof, fully mechanized in Lean 4. Classifiers are implemented in the Scala 3 capture checker, and we demonstrate their use on standard library types and real-world effect exclusion patterns.