ludic/runtime/native
Orkuncakilkaya b0b0b62bce feat(lang): L7 memory is safe unless it says unsafe
The typed buffers are slices: words/floats/fixeds/doubles/pointers(n) make
zeroed, bounds-checked []int/[]float/... and the type names mean them. buffer(n)
is a []byte, with text_of, Fs.read_bytes/write_bytes and view(xs, start, n).
bytes(), indexing a raw pointer or bytes, free, resize, Memory.*, raw file calls,
data_of and C externs are refused outside unsafe { } / unsafe function, and a
project's own files may write unsafe only with --unsafe; the runtime and packages
are the platform. A slice passed to an extern goes as its data.

What the change found: Sync's atomics on a slice header, words(n) uninitialised,
input's fixed axes in ints, truetype's fixed outlines as ints, skin matrices
typed int, gl_shader's source table made from raw bytes. render3d gets safe
entry points (safe_api.ludic). Rendering is byte-identical; a frame costs the same.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-24 12:53:27 +03:00
..
atlas.ludic feat(lang): L7 memory is safe unless it says unsafe 2026-09-24 12:53:27 +03:00
audio.ll feat: per-voice audio, outlines for what is not an actor, and a coast 2026-09-11 15:25:46 +03:00
audio.ludic feat(lang): L7 memory is safe unless it says unsafe 2026-09-24 12:53:27 +03:00
audio_win.ll feat(windows): sound, through XAudio2 2026-09-13 02:42:48 +03:00
base64.ludic feat(lang): L4 type checker between parse and emit 2026-09-24 01:34:49 +03:00
bignum.ludic feat(lang): L4 type checker between parse and emit 2026-09-24 01:34:49 +03:00
bytes.ludic feat(lang): L7 memory is safe unless it says unsafe 2026-09-24 12:53:27 +03:00
cocoa.ll fix(runtime): the wheel on macOS did nothing, or everything 2026-09-20 01:24:37 +03:00
core.ludic feat(lang): L7 memory is safe unless it says unsafe 2026-09-24 12:53:27 +03:00
dict.ludic feat(lang): L7 memory is safe unless it says unsafe 2026-09-24 12:53:27 +03:00
fx.ludic refactor(runtime,packages,examples): named constants, package enums, idiom sweep 2026-09-05 01:12:26 +03:00
gl.ll carry: the runtime and render3d work Maroon Lake builds against 2026-09-23 15:55:02 +03:00
gl.ludic feat(lang): L7 memory is safe unless it says unsafe 2026-09-24 12:53:27 +03:00
gl_api.ludic feat(lang): L4 type checker between parse and emit 2026-09-24 01:34:49 +03:00
gl_thunks.ll feat(gl): OpenGL 4.1 and the ludic.render3d renderer 2026-09-10 03:31:12 +03:00
gl_thunks_win.ll feat(windows): Gl.* on Windows, through WGL and a driver-filled thunk table 2026-09-13 02:10:36 +03:00
gl_win.ll carry: the runtime and render3d work Maroon Lake builds against 2026-09-23 15:55:02 +03:00
gl_win_nowin.ll fix(window): the title a program passes to gl_open / gvk_open reaches the window 2026-09-17 14:02:23 +03:00
grid.ludic refactor(runtime,packages,examples): named constants, package enums, idiom sweep 2026-09-05 01:12:26 +03:00
http.ll feat(launcher): Process.*, Http.save_to/received/expected, App.window_hide/show 2026-09-17 13:32:23 +03:00
http.ludic feat(lang): L7 memory is safe unless it says unsafe 2026-09-24 12:53:27 +03:00
http_win.ll feat(launcher): Process.*, Http.save_to/received/expected, App.window_hide/show 2026-09-17 13:32:23 +03:00
image.ludic feat(lang): L7 memory is safe unless it says unsafe 2026-09-24 12:53:27 +03:00
inflate.ludic feat(lang): L7 memory is safe unless it says unsafe 2026-09-24 12:53:27 +03:00
input.ludic feat(lang): L7 memory is safe unless it says unsafe 2026-09-24 12:53:27 +03:00
jobs.ludic feat(lang): L7 memory is safe unless it says unsafe 2026-09-24 12:53:27 +03:00
light.ludic feat(lang): L7 memory is safe unless it says unsafe 2026-09-24 12:53:27 +03:00
namespaces.ludic feat(lang): L7 memory is safe unless it says unsafe 2026-09-24 12:53:27 +03:00
numeric.ludic refactor(runtime,packages,examples): named constants, package enums, idiom sweep 2026-09-05 01:12:26 +03:00
process.ll feat(launcher): Process.*, Http.save_to/received/expected, App.window_hide/show 2026-09-17 13:32:23 +03:00
process.ludic feat(lang): L7 memory is safe unless it says unsafe 2026-09-24 12:53:27 +03:00
process_win.ll feat(launcher): Process.*, Http.save_to/received/expected, App.window_hide/show 2026-09-17 13:32:23 +03:00
query.ludic refactor(runtime,packages,examples): named constants, package enums, idiom sweep 2026-09-05 01:12:26 +03:00
reflect_io.ludic refactor(runtime,packages,examples): named constants, package enums, idiom sweep 2026-09-05 01:12:26 +03:00
regex.ludic refactor(runtime,packages,examples): named constants, package enums, idiom sweep 2026-09-05 01:12:26 +03:00
regex_vm.ludic feat(lang): L4 type checker between parse and emit 2026-09-24 01:34:49 +03:00
systems.ludic feat(lang): L7 memory is safe unless it says unsafe 2026-09-24 12:53:27 +03:00
systems_bounds.ludic refactor(runtime,packages,examples): named constants, package enums, idiom sweep 2026-09-05 01:12:26 +03:00
systems_light.ludic refactor(runtime,packages,examples): named constants, package enums, idiom sweep 2026-09-05 01:12:26 +03:00
systems_move.ludic refactor(runtime,packages,examples): named constants, package enums, idiom sweep 2026-09-05 01:12:26 +03:00
systems_sprite.ludic refactor(runtime,packages,examples): named constants, package enums, idiom sweep 2026-09-05 01:12:26 +03:00
systems_tileskin.ludic refactor(runtime,packages,examples): named constants, package enums, idiom sweep 2026-09-05 01:12:26 +03:00
threads.ll feat(jobs): real OS threads - Job.parallel_for, fn name, thread-safe Sync 2026-09-15 13:52:22 +03:00
threads_win.ll feat(jobs): real OS threads - Job.parallel_for, fn name, thread-safe Sync 2026-09-15 13:52:22 +03:00
tiled.ludic feat(lang): L4 type checker between parse and emit 2026-09-24 01:34:49 +03:00
tiled_spawn.ludic refactor(runtime,packages,examples): named constants, package enums, idiom sweep 2026-09-05 01:12:26 +03:00
truetype.ludic feat(lang): L7 memory is safe unless it says unsafe 2026-09-24 12:53:27 +03:00
truetype_raster.ludic refactor(runtime,packages,examples): named constants, package enums, idiom sweep 2026-09-05 01:12:26 +03:00
tween.ludic refactor(runtime,packages,examples): named constants, package enums, idiom sweep 2026-09-05 01:12:26 +03:00
udp.ll feat(udp): Udp.* - polled IPv4 datagrams on macOS and Windows 2026-09-17 11:16:14 +03:00
udp.ludic feat(lang): L7 memory is safe unless it says unsafe 2026-09-24 12:53:27 +03:00
udp_win.ll feat(udp): Udp.* - polled IPv4 datagrams on macOS and Windows 2026-09-17 11:16:14 +03:00
ui.ludic feat(lang): L7 memory is safe unless it says unsafe 2026-09-24 12:53:27 +03:00
ui_draw.ludic refactor(runtime,packages,examples): named constants, package enums, idiom sweep 2026-09-05 01:12:26 +03:00
value.ludic feat(lang): L4 type checker between parse and emit 2026-09-24 01:34:49 +03:00
vk.ludic feat(vk): call shapes for the acceleration-structure commands the interposer lacks 2026-09-15 20:22:12 +03:00
vk_api.ludic feat(vk): Vk.* - Vulkan 1.0-1.4 generated from the registry, loaded at run time 2026-09-15 09:52:12 +03:00
vk_mac.ll feat(vk): call shapes for the acceleration-structure commands the interposer lacks 2026-09-15 20:22:12 +03:00
vk_thunks.ll feat(vk): Vk.* - Vulkan 1.0-1.4 generated from the registry, loaded at run time 2026-09-15 09:52:12 +03:00
vk_win.ll feat(vk): call shapes for the acceleration-structure commands the interposer lacks 2026-09-15 20:22:12 +03:00
win32.ll carry: the runtime and render3d work Maroon Lake builds against 2026-09-23 15:55:02 +03:00
win32_gl.ll feat(windows): a window sized by the display's scale, as a Retina Mac does 2026-09-13 02:46:00 +03:00
xml.ludic feat(lang): L4 type checker between parse and emit 2026-09-24 01:34:49 +03:00
zstd.ludic refactor(runtime,packages,examples): named constants, package enums, idiom sweep 2026-09-05 01:12:26 +03:00