ludic/docs/language/structure/kw-unsafe.md
Orkuncakilkaya e2528c1b10 docs/language: a page for every keyword and attribute the vocabulary has
Keywords: module uses friend export internal numbers unsafe mut port bind action
reducer registry of as from def open alias component prop view (structure),
shows lasts then loads (scenes), system (ecs), dispatch (control), true false
null (operators). Attributes: @Ref @OneOf @Range @Unit @Asset @Color, @Node /
@Clip / @Material, @Tint @Derived, @Text / @Multiline, @Key, @AppendOnly /
@ByKey, @PerMap / @Chunked, @frame @max, @owns / @creates / @releases,
@deterministic @alloc_ok. Each is in tools/docgen/inventory.json; every fence
that is not marked skip parses (ludicc --fmt). annot-clearcolor's token loses its
quotes, which no reader strips.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-29 23:59:47 +03:00

696 B


id: kw-unsafe name: unsafe category: structure kind: keyword tokens: unsafe sig: unsafe function f() { } / unsafe { ... } tip: Raw memory is allowed inside: bytes(), free, Memory.*, indexing a pointer, calling C. order: 57

Ludic's memory is safe unless code says unsafe: raw allocation, freeing, pointer indexing and foreign calls are compile errors elsewhere. An unsafe function or an unsafe { ... } block allows them inside, and only packages and the runtime are trusted to write it; a program's own files need --unsafe.

# doc-check: skip — needs --unsafe
unsafe function raw(n: int) -> pointer { return bytes(n) }