feat(lang): L7 memory is safe unless it says unsafe
The typed buffers are slices: words/floats/fixeds/doubles/pointers(n) make
zeroed, bounds-checked []int/[]float/... and the type names mean them. buffer(n)
is a []byte, with text_of, Fs.read_bytes/write_bytes and view(xs, start, n).
bytes(), indexing a raw pointer or bytes, free, resize, Memory.*, raw file calls,
data_of and C externs are refused outside unsafe { } / unsafe function, and a
project's own files may write unsafe only with --unsafe; the runtime and packages
are the platform. A slice passed to an extern goes as its data.
What the change found: Sync's atomics on a slice header, words(n) uninitialised,
input's fixed axes in ints, truetype's fixed outlines as ints, skin matrices
typed int, gl_shader's source table made from raw bytes. render3d gets safe
entry points (safe_api.ludic). Rendering is byte-identical; a frame costs the same.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
parent
9259808f80
commit
b0b0b62bce
70 changed files with 69189 additions and 64569 deletions
14
changes/unsafe.md
Normal file
14
changes/unsafe.md
Normal file
|
|
@ -0,0 +1,14 @@
|
|||
bump: minor
|
||||
type: feature
|
||||
**Memory is safe unless it says `unsafe` (L7).** `words(n)`, `floats(n)`, `fixeds(n)`, `doubles(n)`
|
||||
and `pointers(n)` are bounds-checked, zero-filled slices now, and the type names mean those slices;
|
||||
`buffer(n)` is a `[]byte`, with `text_of`, `Fs.read_bytes`, `Fs.write_bytes` and `view(xs, start,
|
||||
count)` beside it. `bytes(n)`, indexing a raw pointer, `free`, `resize`, `Memory.*`, the raw file
|
||||
calls, `data_of` and calling a C `extern` are refused outside `unsafe { }` / `unsafe function`, and
|
||||
a project's own files may write `unsafe` only with `--unsafe`; the runtime and packages are the
|
||||
platform and are unsafe throughout. A slice passed to an extern goes as its data.
|
||||
|
||||
Making the buffers slices found, and this release fixes: `Sync`'s atomics operating on a slice's
|
||||
header rather than its cell; `words(n)` handing back uninitialised memory; `input.ludic` keeping a
|
||||
stick's fixed axes in an int buffer; truetype's fixed outlines allocated as ints; skinning's float
|
||||
matrices typed as ints. Rendering is byte-identical, and a frame costs the same.
|
||||
Loading…
Add table
Add a link
Reference in a new issue