Skip to content

v1.3.0 — fail-closed codegen memory-safety

Choose a tag to compare

@HarperZ9 HarperZ9 released this 06 Sep 19:17
· 28 commits to main since this release
a5c7638

BuildC now refuses to emit C that crashes, hangs, or returns a stale value.
Where it used to miscompile, it either rejects the program at compile time or
traps at run time with the exact panic text.

Highlights

  • Integer divide-by-zero and MIN / -1 trap instead of faulting the hardware or
    hanging, and every array index is bounds-checked.
  • A non-exhaustive scalar match is caught at compile time where coverage can be
    proven, and aborts cleanly where it cannot, instead of reading an
    uninitialised local.
  • A vector of an aggregate element is rejected rather than miscompiled, and
    aggregate and call-argument literals build at the correct element width.
  • About twenty parser fixes widen the accepted grammar: if let statements,
    turbofish on paths, associated type bindings, async move blocks, labeled
    loops, struct literals in scrutinee position, and more.
  • Type and effect diagnostics now point at line:col with a caret.
  • Tool-call and model-boundary receipt read paths with executed Monte Carlo
    intervals.

Run it

buildc your_program.bld --target c -o out.c

Evidence

Green on CI across lint, format, and the test matrix on Ubuntu and Windows. Full
suite: 1780 passing, 0 failing on the release tree. Every memory-safety fix
ships a control test that passes on the pre-fix binary and fails only after the
fix, so a regression that reopened the hole turns the control red.

Not in this release

Flags and bitflags, resume / with, the macro expander, and the shader-block
DSL are held for a language-surface decision.

Full changelog: v1.2.0...v1.3.0