blob: b3b3527152314968df1ae8b3830dba3c4250236e (
plain) (
blame)
pre { line-height: 125%; }
td.linenos .normal { color: inherit; background-color: transparent; padding-left: 5px; padding-right: 5px; }
span.linenos { color: inherit; background-color: transparent; padding-left: 5px; padding-right: 5px; }
td.linenos .special { color: #000000; background-color: #ffffc0; padding-left: 5px; padding-right: 5px; }
span.linenos.special { color: #000000; background-color: #ffffc0; padding-left: 5px; padding-right: 5px; }
.highlight .hll { background-color: #ffffcc }
.highlight .c { color: #888888 } /* Comment */
.highlight .err { color: #a61717; background-color: #e3d2d2 } /* Error */
.highlight .k { color: #008800; font-weight: bold } /* Keyword */
.highlight .ch { color: #888888 } /* Comment.Hashbang */
.highlight .cm { color: #888888 } /* Comment.Multiline */
.highlight .cp { color: #cc0000; font-weight: bold } /* Comment.Preproc */
.highlight .cpf { color: #888888 } /* Comment.PreprocFile */
.highlight .c1 { color: #888888 } /* Comment.Single */
.highlight .cs { color: #cc0000; font-weight: bold; background-color: #fff0f0 } /* Comment.Special */
.highlight .gd { color: #000000; background-color: #ffdddd } /* Generic.Deleted */
.highlight .ge { font-style: italic } /* Generic.Emph */
.highlight .ges { font-weight: bold; font-style: italic } /* Generic.EmphStrong */
.highlight .gr { color: #aa0000 } /* Generic.Error */
.highlight .gh { color: #333333 } /* Generic.Heading */
.highlight .gi { color: #000000; background-color: #ddffdd } /* Generic.Inserted */
.highlight .go { color: #888888 } /* Generic.Output */
.highlight .gp { color: #555555 } /* Generic.Prompt */
.highlight .gs { font-weight: bold } /* Generic.Strong */
.hi== Goal
A memory-safe language with a simple translator to x86 that can be feasibly written in x86.
== Definitions of terms
Memory-safe: it should be impossible to:
a) create a pointer out of arbitrary data, or
b) to access heap memory after it's been freed.
Simple: do all the work in a 2-pass translator:
Pass 1: check each instruction's types in isolation.
Pass 2: emit code for each instruction in isolation.
== types
int
char
(address _)
(array _ n)
(ref _)
== implications
addresses can't be saved to stack or global,
or included in compound types
or used across a call (to eliminate possibility of free)
<reg x> : (address T) <- advance <reg/mem> : (array T), <reg offset> : (index T)
arrays require a size
(ref array _) may not include a size
argv has type (array (ref array char))
variables on stack, heap and global are references. The name points at the
address. Use '*' to get at the value.
instructions performing lookups write to register, so that we can reuse the register for temporaries
instructions performing lookups can't read from the register they write to.
But most instructions read from the register they write to?! (in-out params)
== open questions
If bounds checks can take multiple instructions, why not perform array
indexing in a single statement in the language?
But we want addresses as intermediate points to combine instructions with.
Maybe disallow addresses to function calls, but allow addresses to non-heap
structures to be used spanning function calls and labels.
That's just for ergonomics. Doesn't add new capability.