v1.3.0 — fail-closed codegen memory-safety
BuildC now refuses to emit C that crashes, hangs, or returns a stale value.
Where it used to miscompile, it either rejects the program at compile time or
traps at run time with the exact panic text.
Highlights
- Integer divide-by-zero and
MIN / -1trap instead of faulting the hardware or
hanging, and every array index is bounds-checked. - A non-exhaustive scalar
matchis caught at compile time where coverage can be
proven, and aborts cleanly where it cannot, instead of reading an
uninitialised local. - A vector of an aggregate element is rejected rather than miscompiled, and
aggregate and call-argument literals build at the correct element width. - About twenty parser fixes widen the accepted grammar:
if letstatements,
turbofish on paths, associated type bindings,async moveblocks, labeled
loops, struct literals in scrutinee position, and more. - Type and effect diagnostics now point at
line:colwith a caret. - Tool-call and model-boundary receipt read paths with executed Monte Carlo
intervals.
Run it
buildc your_program.bld --target c -o out.c
Evidence
Green on CI across lint, format, and the test matrix on Ubuntu and Windows. Full
suite: 1780 passing, 0 failing on the release tree. Every memory-safety fix
ships a control test that passes on the pre-fix binary and fails only after the
fix, so a regression that reopened the hole turns the control red.
Not in this release
Flags and bitflags, resume / with, the macro expander, and the shader-block
DSL are held for a language-surface decision.
Full changelog: v1.2.0...v1.3.0