No description
  • C 48.8%
  • C++ 15.9%
  • LLVM 11.8%
  • Assembly 4.3%
  • HTML 2.9%
  • Other 15%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
2026-09-05 21:36:52 -07:00
.ci
.github
benchmarkData Re-record benchmarkData/libcrypto.3.dylib.zst with zstd 1.5.7 2026-08-31 09:12:03 -07:00
bolt
clang Improve sarcasm's architecture detection and add explicit target selection flags 2026-08-29 20:08:01 -07:00
clang-tools-extra
cmake
compiler-rt
cross-project-tests
filc Skip a test that is failing for now on ARM64, and remove a test that is clearly broken. 2026-09-06 01:44:20 +00:00
flang
libc
libclc
libcxx
libcxxabi
libpas Fix pidfd_send_signal to allow a null siginfo. 2026-08-28 16:04:54 -07:00
libunwind
lld
lldb
llvm Add NEON multi-vector accesses and enable NEON in a bunch of projects. 2026-09-04 22:20:10 +00:00
llvm-libgcc
mlir
offload
openmp
optfil Make sure optfil and pizlix build projey. 2026-09-05 21:36:52 -07:00
pizlix Make sure optfil and pizlix build projey. 2026-09-05 21:36:52 -07:00
polly
projects Rebase brotli to 1.2.0 in projeny mode 2026-09-05 21:02:25 -07:00
pstl
runtimes
third-party
utils/bazel
yolounwind
.clang-format
.clang-tidy
.git-blame-ignore-revs
.gitattributes
.gitignore
.mailmap
build_abseil.sh
build_ada.sh
build_all.sh
build_all_fast.sh
build_all_fast_glibc.sh
build_all_glibc.sh
build_all_slow.sh OpenSSL 3.6.4 builds with assembly enabled through sarcasm; suite passes 2026-09-04 21:40:03 -07:00
build_all_slow_glibc.sh
build_and_test_base.sh
build_attr.sh
build_base.sh Add projeny to the Fil-C build system. 2026-09-04 15:24:24 -07:00
build_base_glibc.sh
build_bash.sh Upgrade the version of bash in our corpus to 5.3 2026-08-30 09:12:35 -07:00
build_benchmarks.sh
build_binutils.sh Upgrade the version of binutils in our corpus to 2.47 2026-08-26 08:08:17 +00:00
build_bison.sh
build_blake3.sh Port up to jpeg-turbo to ARM64. 2026-09-04 03:23:30 +00:00
build_brotli.sh Rebase brotli to 1.2.0 in projeny mode 2026-09-05 21:02:25 -07:00
build_busybox.sh
build_bzip2.sh
build_bzip3.sh
build_check.sh
build_clang.sh
build_cmake.sh
build_compiler_rt.sh
build_coreutils.sh Upgrade the version of coreutils in our corpus to 9.11 2026-08-29 19:30:03 -07:00
build_cpython.sh
build_curl.sh Upgrade the version of curl in our corpus to 8.22.0 2026-09-03 04:11:57 +00:00
build_cxx.sh
build_dash.sh Switch dash to use projeny. 2026-09-05 10:15:11 -07:00
build_diffutils.sh Upgrade the version of diffutils in our corpus to 3.12 2026-08-29 14:17:43 -07:00
build_elfutils.sh
build_emacs.sh
build_expat.sh
build_ffi.sh Fix copyright header in build_libffi.sh. 2026-09-04 20:02:46 -07:00
build_ffmpeg.sh
build_filbox1.sh
build_filbox1_podman.sh
build_gettext.sh
build_git.sh Upgrade the version of git in our corpus to 2.55.0 2026-08-23 09:23:04 -07:00
build_glibc_extras.sh
build_gmp.sh
build_grep.sh Upgrade the version of grep in our corpus to 3.12 2026-08-29 06:09:19 +00:00
build_icu.sh Upgrade the version of icu in our corpus to 78.3 2026-08-30 21:36:16 -07:00
build_image_base_system.sh
build_image_build_env.sh
build_jpeg-6b.sh
build_jpeg-turbo.sh Add NEON multi-vector accesses and enable NEON in a bunch of projects. 2026-09-04 22:20:10 +00:00
build_libarchive.sh
build_libcap.sh
build_libedit.sh
build_libevent.sh Upgrade the version of libevent in our corpus to 2.1.13 2026-08-27 06:54:16 +00:00
build_libpipeline.sh
build_libpng.sh Add NEON multi-vector accesses and enable NEON in a bunch of projects. 2026-09-04 22:20:10 +00:00
build_libuev.sh
build_libuv.sh Upgrade the version of libuv in our corpus to 1.52.1 2026-09-04 15:23:02 -07:00
build_libwebp.sh Add NEON multi-vector accesses and enable NEON in a bunch of projects. 2026-09-04 22:20:10 +00:00
build_libxml2.sh Rebase libxml2 to 2.15.4 in projeny mode 2026-09-05 14:45:10 -07:00
build_lua.sh
build_lute.sh Fix some copyrights 2026-08-15 13:44:10 -07:00
build_lz4.sh
build_m4.sh Fix some copyrights 2026-08-15 13:44:10 -07:00
build_make.sh
build_mg.sh
build_minilute.sh Add a minimal version of Lute, called minilute, that is just enough to run SaRCAsm. 2026-08-21 20:26:32 -07:00
build_ncurses.sh Upgrade the version of ncurses in our corpus to 6.6 2026-08-30 20:52:50 +00:00
build_nghttp2.sh Upgrade the version of nghttp2 in our corpus to 1.70.0 2026-08-24 17:06:52 -07:00
build_openjpeg.sh
build_openssh.sh
build_openssl.sh Make build_all.sh build up through curl on ARM64. 2026-09-04 17:40:04 +00:00
build_openssl364.sh OpenSSL 3.6.4 builds with assembly enabled through sarcasm; suite passes 2026-09-04 21:40:03 -07:00
build_os_include.sh
build_pcre.sh
build_pcre2.sh Upgrade the version of pcre2 in our corpus to 10.48 2026-09-04 10:34:19 -07:00
build_perl.sh Upgrade the version of curl in our corpus to 8.22.0 2026-09-03 04:11:57 +00:00
build_pkgconf.sh Switch pkgconf to use projeny. 2026-09-05 09:01:58 -07:00
build_postgres.sh
build_procps.sh Upgrade the version of procps-ng in our corpus to 4.0.7 2026-08-28 16:05:24 -07:00
build_projeny.sh Add projeny to the Fil-C build system. 2026-09-04 15:24:24 -07:00
build_projeny_yolo.sh Add projeny to the Fil-C build system. 2026-09-04 15:24:24 -07:00
build_quickjs.sh
build_ruby.sh Fix ruby build when HOME is unset or empty 2026-08-15 13:44:07 -07:00
build_runtime.sh
build_sarcasm.sh Make sarcasm the default assembler, add -yolo-assembler escape hatch 2026-08-29 08:07:23 -07:00
build_sed.sh Upgrade the version of sed in our corpus to 4.10 2026-08-27 20:11:20 -07:00
build_shadow.sh
build_simdjson.sh
build_simdutf.sh
build_sqlite.sh
build_tar.sh
build_tcl.sh
build_texinfo.sh
build_tiff.sh
build_tmux.sh
build_toybox.sh
build_user_glibc.sh Make sarcasm the default assembler, add -yolo-assembler escape hatch 2026-08-29 08:07:23 -07:00
build_usermusl.sh Make sarcasm the default assembler, add -yolo-assembler escape hatch 2026-08-29 08:07:23 -07:00
build_util_linux.sh
build_vim.sh
build_wg14_signals.sh
build_xcrypt.sh Upgrade the version of libxcrypt in our corpus to 4.5.2 2026-08-31 17:33:25 -07:00
build_xml_parser.sh
build_xxhash.sh
build_xz.sh Upgrade the version of xz in our corpus to 5.8.3 2026-08-27 13:25:06 -07:00
build_yaml.sh
build_yolo_glibc.sh
build_yolo_glibc_incremental.sh
build_yolomusl.sh
build_yolounwind.sh
build_zlib.sh Upgrade the version of zlib in our corpus to 1.3.2 2026-08-25 17:52:42 -07:00
build_zsh.sh Upgrade the version of zsh in our corpus to 5.9.2 2026-09-02 07:48:41 +00:00
build_zstd.sh Upgrade the version of zstd in our corpus to 1.5.7 2026-08-31 09:12:02 -07:00
CLAUDE.md
configure_cmake_project.sh
configure_llvm.sh
configure_llvm_glibc.sh
containers.md
count-project-lines
disable_inlining_opts.txt
Dockerfile-base-system
Dockerfile-build-env
enter_container.sh
enter_container_base_system.sh
enter_container_build_env.sh
extract_source.sh
fix-checkout-on-case-insensitive-fs.sh Add a script to work around checking out the Fil-C repo on a case insensitive fs 2026-08-21 10:57:28 -07:00
fix_clang.sh
fix_yolo_glibc.sh
gimso_semantics.md
install-cxx-freebsd.sh
install-cxx-linux.sh
install-cxx-macosx.sh
install-cxx-openbsd.sh
invisicap.txt
invisicaps_by_example.md
LLVM-LICENSE.txt
Manifesto.md
package-build.sh Install minilute and sarcasm in /opt/fil, the Fil-C distro, and pizlix 2026-08-29 17:35:55 +00:00
package-source.sh
pyproject.toml
README.md
reset_container.sh
SECURITY.md Clarify security policy 2026-08-23 17:17:23 -07:00
setup_glibc.sh
T800.txt Document the sarcasm development flow 2026-08-29 20:08:01 -07:00
test43.md
versioning-checklist.md

Fil-C 0.684

Fil-C is a fanatically compatible memory-safe implementation of C and C++. Lots of software compiles and runs with Fil-C with zero or minimal changes. All memory safety errors are caught as Fil-C panics. Fil-C achieves this using a combination of concurrent garbage collection and invisible capabilities (each pointer in memory has a corresponding capability, not visible to the C address space). Every fundamental C operation (as seen in LLVM IR) is checked against the capability. Fil-C has no unsafe statement and only limited FFI to unsafe code.

Fil-C is special because:

  • Fil-C achieves full safety with no escape hatches. There is no unsafe keyword in Fil-C that could be used to turn off protections. Linking to unsafe code is severely restricted.

  • Fil-C's capability-based approach achieves a similar level of safety to hardware capabilities like CHERI, except that it runs on stock hardware (X86_64 or ARM64).

  • Fil-C is engineered to prevent memory safety bugs from being used for exploitation rather than just simply flagging them often enough to find bugs. This makes Fil-C different from AddressSanitizer, HWAsan, or MTE, which can all be bypassed by attackers. The key difference that makes this possible is that Fil-C is capability based (so each pointer knows what range of memory it may access, and how it may access it) rather than tag based (where pointer accesses are allowed if they hit valid memory).

  • From a language user standpoint, Fil-C is just C and C++ with GCC/clang extensions. It's more likely than not that your favorite C or C++ program or library compiles in Fil-C with zero changes. The Fil-C compiler is based on clang 20.1.8, so it supports C17 and C++20.

License

The compiler (clang + LLVM) is covered by LLVM-LICENSE.txt. The runtime is covered by PAS-LICENSE.txt (see libpas/LICENSE.txt in the source distribution). In the case of the classic musl-based Fil-C distribution, the musl libc is covered by MUSL-LICENSE.txt (see projects/yolomusl/COPYRIGHT and projects/usermusl/COPYRIGHT in the source distribution). In the case of the /opt/fil distribution, glibc is covered by glibc-LICENSE.txt, and all other included programs are covered by the respective -LICENSE.txt files. The C++ libraries (libc++/libc++abi) are covered by LLVM-LICENSE.txt.

You can fetch the source for the compiler, runtime, libc++/libc++abi, libc (musl and glibc), and all included programs from github. The source distribution also includes many additional programs that have been ported to Fil-C in the projects/ and pizlix/ directories, and they have a variety of licenses. The /opt/fil distribution includes builds of a variety of additional programs and their licenses are in additional-licenses/ in that distribution.

Requirements

Fil-C only works on Linux/X86_64 or Linux/ARM64.

Previous versions worked on Darwin/ARM64 and FreeBSD, but now I'm focusing just on Linux because it allows me to do a more faithful job of implementing libc. There's nothing fundamentally stopping Fil-C from working on other architectures or OSes other than Linux.

Getting Started

If you downloaded Fil-C binaries, run:

./setup.sh

This has a different effect depending on which binary distribution you selected:

  • In case of the classic musl-based distribution (filc-0.684-linux-x86_64.tar.xz or filc-0.684-linux-aarch64.tar.xz), this sets up Fil-C to run in the current directory.

  • In case of the /opt/fil glibc-based distribution (optfil-0.684-linux-x86_64.tar.xz), this sets up Fil-C in /opt/fil.

If you downloaded Fil-C source, run:

./build_all_fast.sh

Then you'll be able to use Fil-C from within this directory.

The binary distribution of Fil-C comes with musl as the libc. Using ./build_all_fast.sh in the source distribution also builds Fil-C using musl. If you are using source, then you can also:

  • ./build_all_fast_glibc.sh - builds a similar setup but with glibc 2.40 as the libc.

  • ./build_all.sh - full musl-based build (also builds lots of software that was ported to Fil-C).

  • ./build_all_glibc.sh - full glibc-based build (builds even more software that was ported to Fil-C).

  • cd pizlix && sudo ./build.sh - builds the Pizlix Linux distribution.

  • cd optfil && sudo ./build.sh - builds the /opt/fil distribution.

Things That Work

Lots of software packages work in Fil-C with zero or minimal changes, including big ones like openssl, CPython, SQLite, and many others. Fil-C is powerful enough to support a fully memory safe Linux userland.

Fil-C has full support for C and C++ plus almost all of the extensions that clang 20 supports. Fil-C has excellent support for atomics and SIMD intrinsics, for example.

Fil-C catches all of the stuff that makes memory safety in C hard, like:

  • Out-of-bounds on the heap or stack.

  • Use-after free (also heap or stack).

  • Type confusion between pointers and non-pointers.

  • Type errors arising from linking.

  • Type errors arising from misuse of va_lists.

  • Pointer races.

  • System calls. All buffers passed to system calls are checked for bounds and type.

  • Lots of other stuff.

Fil-C comes with a reasonably complete POSIX libc and even supports tricky features like threads, signal handling, mmap/munmap, longjmp/setjmp, and C++ exceptions.

Learn More

You can learn more about Fil-C by visiting the website.

You can also e-mail me: pizlo@mac.com

Follow me on Twitter.

File issues at GH.