Keywords: module uses friend export internal numbers unsafe mut port bind action reducer registry of as from def open alias component prop view (structure), shows lasts then loads (scenes), system (ecs), dispatch (control), true false null (operators). Attributes: @Ref @OneOf @Range @Unit @Asset @Color, @Node / @Clip / @Material, @Tint @Derived, @Text / @Multiline, @Key, @AppendOnly / @ByKey, @PerMap / @Chunked, @frame @max, @owns / @creates / @releases, @deterministic @alloc_ok. Each is in tools/docgen/inventory.json; every fence that is not marked skip parses (ludicc --fmt). annot-clearcolor's token loses its quotes, which no reader strips. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
17 lines
696 B
Markdown
17 lines
696 B
Markdown
---
|
|
id: kw-unsafe
|
|
name: unsafe
|
|
category: structure
|
|
kind: keyword
|
|
tokens: unsafe
|
|
sig: unsafe function f() { } / unsafe { ... }
|
|
tip: Raw memory is allowed inside: bytes(), free, Memory.*, indexing a pointer, calling C.
|
|
order: 57
|
|
---
|
|
|
|
Ludic's memory is safe unless code says <code>unsafe</code>: raw allocation, freeing, pointer indexing and foreign calls are compile errors elsewhere. An <code>unsafe function</code> or an <code>unsafe { ... }</code> block allows them inside, and only packages and the runtime are trusted to write it; a program's own files need <code>--unsafe</code>.
|
|
|
|
```ludic
|
|
# doc-check: skip — needs --unsafe
|
|
unsafe function raw(n: int) -> pointer { return bytes(n) }
|
|
```
|