Skip to content

Cob v0.0.3 (EOL)

Choose a tag to compare

@github-actions github-actions released this 31 Aug 01:01
· 53 commits to main since this release

⚠️ ARCHIVED / END OF LIFE (EOL)

NOTICE: This version is preserved strictly for historical reference. It will not receive future patches. Please migrate to the secure v0.0.3 bug fix 1 Release.


ℹ️ Hey There is a new version out v0.0.3 bug fix 1 available, we recommend upgrading to that version.

Cob Language v0.0.3 — Project Obsidian Falcon

A corn-themed hybrid language with Python-style indentation, an interpreter, a native compiler, and a package manager.

What's new in v0.0.3

popcorn_comp: dropped embedded TCC, now spawns a real compiler

Earlier versions statically linked TCC's own compiler source (libtcc.c) directly into popcorn_comp. That's gone — popcorn_comp now transpiles a .strawberry file to plain C and spawns a real C compiler as a subprocess to produce the native executable.

  • Default backend is Zig's zig cc — a Clang-based drop-in C compiler that bundles libc/CRT files for essentially every target in a single install. That's what makes CobOS/CobArch cross-compiling a plain -target flag instead of needing a separately installed cross-toolchain per platform.
  • Compiler resolution order: --cc <path> → $CobCC → $CobOS/$CobArch (looked up in a table of Zig target triples) → plain zig cc on PATH for native builds.
  • Linux targets default to musl libc, not glibc — produces fully static binaries with no runtime libc dependency.
  • Windows ARM32 is not supported (cut this cycle — it was also the target we were least confident Zig fully supports).
  • --emit-c <path.c> still works, for inspecting the generated C.
CobOS=windows CobArch=amd64 popcorn_comp prog.strawberry -o prog.exe
# -> spawns: zig cc -target x86_64-windows-gnu ...

farmer: real in-process zip extraction via miniz, plus zip-slip protection

farmer harvest used to shell out to unzip (Unix) or Expand-Archive (Windows) to extract downloaded packages. It now extracts in-process using the statically-linked miniz library instead — one less external tool required on the system.

  • Every extracted archive entry's path is checked against zip-slip path traversal before anything is written to disk. A malicious ../../../../etc/whatever entry is rejected outright, with nothing written outside the destination directory.
  • Nested directories inside a package zip are now handled correctly regardless of whether the archive includes explicit directory entries.
  • The package registry now lives in its own dedicated repo, pixel-pulse-labs/cpi — farmer's default base URL was updated to match. Override anytime with $COB_FARMER_BASE_URL.

Documentation site

docs/index.html in this repo is now real language and tool reference documentation — every keyword (pop, set, while, shuck, harvest/trash, the _MakeCache directive) and all three CLI tools, each with usage and flags. The package-registry landing page that used to live here moved to the cpi repo, where it belongs.

Vendored libraries (not yet wired into Cob's language)

Added under vendor/ as embeddable/linkable libraries, per project decision. None of these have Cob-facing keywords yet — that's a separate design step.

  • SQLite 3.53.4 — the single-file amalgamation build (sqlite3.c/sqlite3.h).
  • Tcl 9.0.4 and Tk 9.0 — full source distributions, built via their own configure/make (make tcl, make tk targets added to the Makefile). Tk requires real X11 development headers on the build machine.
  • miniz 3.1.1 — backs farmer's zip extraction (see above).

CI

  • cob_interp, farmer, and popcorn_comp all build across the full 9-target matrix (Windows/Linux/macOS × amd64/386/arm64/arm as applicable — down from 10 after cutting Windows ARM32).
  • A real end-to-end smoke test now runs for popcorn_comp on native Linux amd64: compile a .cob program, run it through popcorn_comp, diff the output against the interpreter.
  • Fixed a bug in the TCC upstream-sync workflow where a conftest.c file ./configure genuinely needs was being silently dropped on every sync, because TCC's own vendored .gitignore has a conftest* pattern that collaterally matched the tracked source file. (Now moot for this repo specifically, since popcorn_comp no longer depends on TCC at all — but the underlying .gitignore-collision lesson is worth knowing if vendoring other C projects.)

Known gaps, stated plainly

  • You need Zig installed for popcorn_comp's default backend to work. This wasn't testable end-to-end in the environment these notes were written in (no network access to ziglang.org) — the command-construction logic was verified against a stub, but real compiles need verification on an actual machine with Zig installed.
  • SQLite/Tcl/Tk are buildable, not usable from Cob yet. No sqlopen, no Tcl shuck-equivalent, no Tk widget keywords. Proving they build and link was this cycle's scope.
  • popcorn_comp isn't smoke-tested on the other 8 targets in CI — only native Linux amd64, since that's the only target whose output can actually execute on the CI runner without emulation.

Upgrading from v0.0.2

If you have scripts calling popcorn_comp and relying on the old CobOS/CobArch → cross-gcc-binary-name behavior, note that resolution now targets Zig triples instead. Install Zig, or pass --cc <path>/$CobCC to keep using a specific compiler directly.


Binaries are provided per-platform in this release. Verify downloads against checksums.txt.