feat(lang): L7 memory is safe unless it says unsafe

The typed buffers are slices: words/floats/fixeds/doubles/pointers(n) make
zeroed, bounds-checked []int/[]float/... and the type names mean them. buffer(n)
is a []byte, with text_of, Fs.read_bytes/write_bytes and view(xs, start, n).
bytes(), indexing a raw pointer or bytes, free, resize, Memory.*, raw file calls,
data_of and C externs are refused outside unsafe { } / unsafe function, and a
project's own files may write unsafe only with --unsafe; the runtime and packages
are the platform. A slice passed to an extern goes as its data.

What the change found: Sync's atomics on a slice header, words(n) uninitialised,
input's fixed axes in ints, truetype's fixed outlines as ints, skin matrices
typed int, gl_shader's source table made from raw bytes. render3d gets safe
entry points (safe_api.ludic). Rendering is byte-identical; a frame costs the same.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Orkun ÇAKILKAYA 2026-09-24 12:53:27 +03:00
parent 9259808f80
commit b0b0b62bce
70 changed files with 69189 additions and 64569 deletions

View file

@ -6,11 +6,11 @@ program UdpDemo {
let pa = Udp.port(a)
let pb = Udp.port(b)
let lo = Udp.ip("127.0.0.1")
let out = Memory.bytes(16)
Memory.poke(out, 0, 104)
Memory.poke(out, 1, 105)
let out = buffer(16)
out[0] = 104
out[1] = 105
let sent = Udp.send(a, lo, pb, out, 2)
let inb = Memory.bytes(64)
let inb = buffer(64)
var got = 0
var tries = 0
while got == 0 and tries < 200000 { got = Udp.recv(b, inb, 64); tries += 1 }
@ -20,7 +20,7 @@ program UdpDemo {
tries = 0
while back == 0 and tries < 200000 { back = Udp.recv(a, out, 16); tries += 1 }
let bad = Udp.ip("1.2.3") == 0 and Udp.ip("300.1.1.1") == 0
print(`{sent} {got} {Memory.peek(inb, 0)} {Memory.peek(inb, 1)} {from_ok} {back} {Udp.ip_text(lo)} {bad} {Udp.recv(a, out, 16)} {pa > 0}`)
print(`{sent} {got} {inb[0]} {inb[1]} {from_ok} {back} {Udp.ip_text(lo)} {bad} {Udp.recv(a, out, 16)} {pa > 0}`)
Udp.close(a)
Udp.close(b)
}