You do that by making the type system more sophisticated.
If you have a really important invariant that you really don't want to be violated due to run-time behavior/input, it's a huge benefit to have a compiler that can statically check that it actually can't be. That's one of the main benefits of having type systems, not just describing the shape of data structures in memory.
C is a bad language to do this with for various reasons, but as a simple example:
char* buf = malloc(SIZE);
free(buf);
free(buf);
There is absolutely no reason why static analysis should not be able to see what the problem is here.How will you find such violations if opaque comes from so or some ffi, so compiler can't see through? you can't. It's heuristics. Sound type system is much stronger
Christ. Even rust makes ffi unsafe.
I mean you can annotate it if you want. Just tell the analyzer in a separate file, get the variable at this line on this file has these guarantees.
You could even annotate dependencies that didn't use your static analyzer. You could track custom invariants that your language designer didn't put in the type system.
Which is why every library that wraps C APIs provides safe wrappers that express the implicit expectations within Rust's type system. Yes the low-level calls are unsafe, of course they are, but then we expose them with a safe interface that consumers actually use.
``` ((void()(void) free)(buf); ((void()(void) free)(buf); ```
It's been my experience people invested in static analysis think of it like some wholly additive extension.
Compiler-independent static analysis is code applying rules. Someone has to write all the rules, align them with the language and the compiler. The user rarely reads the static analyzer's code or full rule definitions and is blissfully unaware of the full set of disconnects, inconsistences, and gaps between the coverage of the two.
They only notice divergence in the analysis when it generates a false-positive warning or error.
Static analysis adds compilation overhead. Sure, but I'd hazard that re-reading and in to some degree repeating the parsing/translation process that the compiler is going to do also introduces overhead.
There are some languages that demonstrate sta-by-compiler capabilities with heinous compile times, but it doesn't have to be that way. We can engineer better, but at some point it requires a price. Better comments, boilerplate of some kind or another, annotating intent over idiom.
A complex type system isn't ideal; with the right set of primitives you can achieve sophistication without complexity.
``` Freeable buf = malloc(SIZE); free(buf); // compiler error, you didn't check buf isn't valid. free(buf); // compiler error still if you fixed the above, free makes buf invalid. ```
"Making the compiler do STA makes it slow". I don't think that's proven one way or the other. There are examples both ways. "complex" type systems frequently have slow compilers, but if you look more closely that's usually because they're trying to compensate for the disconnect between organically emerged complexity in their under-designed type systems.
The compiler could interpret all unsafe via it but then it would be very slow, defeating the point.
Can't is a strong word. You could 100% put it in the compiler. Yet you don't (for the reasonable reasons you give). The line between compiler static analysis and non-compiler static analysis is a design decision. "defeating the point" is a subjective and pragmatic decision, not one rooted in safety absolutism.
buf_create(SIZE)
and
buf_destroy(buf)
now the compiler has to infer that buf_create creates a lifetime and buf_destroy destroys it.
we're back to Rust's Box.
Do you not understand what static analysis is?
And if you don't take every problem seriously, and do a full investigation, then you are risking a real problem that you don't fix, which can turn into... a runtime crash.
Now, sure, you could have some kind of annotations in the comments or something, and a static analyzer that checked those, and you could get that to check pretty much anything that can be checked statically. But at that point, it's not really part of the language, is it?
I think the compiler was written from scratch though.
Sounds like a great language for an AI to use then :)
Is the intent that applications developed with this are compiled for target hardware on a machine-specific basis?
e.g. I define a machine file for my i5 and GTX3080, and another machine file for my gnarly datacenter rack, and the compiler compiles specifically for each?
That way the same source file is "provable" for different hardware configurations without relying on a runtime to be identicallu implemented?
Vx gives you the power to do so, but one can be conservative by putting all the values in the fleet/*.vx files to extreme values. An analogy to that would be when we compile for X86-64, we can specify `-mcpu` otherwise by default the compiler picks a conservative backend.
Vx allows one to define compute elements(number of cores, etc), memory elements (number of distinct memory elements, hierarchy if any) and their relationship (placement, ownership etc). Together they define the toplogoy of a machine. Toplogy goes into machine description files (see https://github.com/vx-lang/Vx/tree/main/fleet) and the compiler uses them to 'monomorphize' the program based on that topology.
A bit tangential, but I really *really* appreciate them making this distinction, and wish more people did this. Way too many tools try to advertise themselves as all things for all people, catering to all use cases, and that helps nobody.
> On Apple's unified memory that transfer compiles to almost nothing. It is still written down, because data locality should be provable by reading the source rather than by profiling the binary.
How does profiling the binary play into this? Elsewhere the hypothesis is "it crashes", whereas profiling is about performance.
> Most languages treat the accelerator as infrastructure: you write math, and a large opaque runtime decides how to ship it. Vx treats it as semantics.
What does that mean? Vx doesn't treat the accelerator as infrastructure? Vx doesn't have a large opaque runtime? "You write math, Vx treats it as semantics". I don't understand that.
- "Most compilers hard-code a cost model. Vx reads one. A machine file describes the memory hierarchy and interconnect of a real part, and the compiler admits or rejects placements against it." I also designed it so that the target system is described by a single file that is picked up by the static analysis - cool!
- "Where data lives is part of its type" also doing that - when I got my project to an mvp state; I need to check out how vxlang does what it does: do they use a literal typesystem, or also compile checks outside of that? If its a type system, is it a dependent type system, or another flavor?
Yet another motivation to finally get my side project starting (forth-adjacent, many similar claims with regards to compile-time checks as vxlang; however, I still have to achieve that, while they already seem to have at least those and more in place; kudos to the vxlang team!)
I've actually created some experimental DSL embeddings around this idea before as I find it a fascinating area. Skimming through the Vx docs it seems like it is moving some of the abstract machine into the type system for greater flexibility.
It's important to note that there was a huge shift from RISC to CISC to speed decode and then to vectorization and virtualization. The former was driven at first to allow higher single threaded clock speeds, and then when that hit a power wall ~2004 to raise data throughput and allow multi-threading (which required code changes), and then multiple virtual machines.
Oh don’t forget we need to think of the future… Make sure we can run on GPUs.
Try not to sound too LLMy.
Don’t mess up.”
I wish you luck I guess
This is collaboration in the same fashion as a group project in school. One kid never shows up or does any work and expects to put their name on it.
It’s hard to take you all seriously when your first instinct is to pop open an llm to even name your project. I mean c’mon that’s the funnest part!
Every chip? For example if I target an Intel Meteor Lake (I'm not picking a niche one), does it compile for this CPU, its integrated NPU and its Arc GPU?
Every chip? I bet it can't target analog chips, what with the pointer talk and all...