Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
fzy — a systems programming language prioritizing verifiable correctness, determinism, and performance | Kitploit
Tools/GitHubGitHub/saint0x/fzy
Static AnalysisDynamic Analysis (Sandboxing)Code AnalysisReverse EngineeringDebuggersWeb SecurityFuzzingCryptographyBinary AnalysisSupply Chain SecurityLearning & Education
16242 months agoNot yet reviewed
GitHub
saint0x/fzy

fzy

a systems programming language prioritizing verifiable correctness, determinism, and performance

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

fzy (fozzylang)

General-purpose systems language and production toolchain with a memory-safe-by-default shipped safe-language surface, verifiable correctness, deterministic execution, and replay-first debugging built in.

fzy ships one production CLI, fz, for both compiler workflows and deterministic validation. Correctness, determinism, replay, incident artifacts, and production evidence are part of the normal workflow rather than an afterthought. For a quick visual tour of the language, open the shipped FZL showcase in your browser with open fzl-showcase.html. For the short argument for why you might pick it, see WHYFZY.md.

Repository architecture policy is typed internally and JSON at real boundaries only.

Start Here

  • Install: INSTALL.md
  • Full manual: USAGE.md
  • Why fzy: WHYFZY.md
  • Syntax and command examples: CODE.md
  • Production workflow: docs/production-workflow-v1.md
  • GPU programming and validation: docs/gpu-v1.md
  • Safety and trust model: docs/system-safety-trust-model-v1.md
  • Unsafe authoring: docs/unsafe-contract-authoring-v1.md
  • Stability tiers: docs/language-stability-v1.md
  • Workspace policy inheritance: docs/workspace-policy-v1.md
  • Operational insights: docs/operational-insights-v1.md
  • fzyllm: saint0x/fzyllm

Install

Recommended install:

curl -fsSL https://raw.githubusercontent.com/saint0x/fzy/main/install.sh | sh

That installs fz to ~/.local/bin, updates PATH if needed, and verifies the install with fz version and fz env.

Source fallback:

curl -fsSL https://raw.githubusercontent.com/saint0x/fzy/main/install.sh | sh -s -- --from-source

Quick Look

Want the fastest overview? Open fzl-showcase.html with open fzl-showcase.html, skim WHYFZY.md for the product argument, then use the sample below as a compact executable sketch.

use core.log;
use core.path;
use core.process;
use core.time;

enum Mode {
    Fast,
    Safe,
}

trait Scorer {
    fn score(endpoint: Url) -> i32;
}

struct HttpScorer {}

impl Scorer for HttpScorer {
    fn score(endpoint: Url) -> i32 {
        discard endpoint;
        return 7;
    }
}

struct Config<TEndpoint> {
    retries: i32,
    endpoint: TEndpoint,
    mode: Mode,
}

fn weight(mode: Mode) -> i32 {
    match mode {
        Mode::Fast => return 3,
        Mode::Safe => return 1,
        _ => return 1,
    }
}

async fn boost(v: i32) -> i32 {
    checkpoint()
    return v + 1
}

fn normalize<T: Scorer>(cfg: Config<Url>) -> i32 {
    return weight(cfg.mode) + T.score(cfg.endpoint)
}

async fn run_once(cfg: Config<Url>) -> i32 {
    let base = normalize<HttpScorer>(cfg)
    return await boost(base)
}

fn main() -> i32 {
    let cfg = Config { retries: 4, endpoint: url.parse("https://example.test"), mode: Mode::Fast }
    let now = time.now()
    let out_path = path.join("tmp", "score.log")
    let mode = process.argv_or(1, "showcase")
    let score = normalize<HttpScorer>(cfg)
    log.info("snippet.run", out_path)
    discard mode
    discard run_once
    if score + now > 0 then return score
    return score
}

For broader language coverage, use CODE.md, examples/, and the browser-friendly FZL showcase.

Framework packages follow normal package rules: declare them in fozzy.toml under [deps], then import them in source with use fzbounds;, use fzweb;, and similar package names. Direct source checks such as fz check src/services/mod.fzy --json now validate through the owning package context, so dependency imports and sibling modules behave the same way they do in full-project checks.

What fzy Contains

  • fz: compiler CLI for build, run, test, verify, docs, IR, RPC, headers, ABI checks, and more
  • built-in formatting and docs generation: fz fmt, fz doc gen
  • front-end and IR pipeline: crates/parser, crates/ast, crates/hir, crates/fir
  • verifier and safety enforcement: crates/verifier
  • deterministic runtime primitives: crates/runtime
  • driver and artifact orchestration: crates/driver
  • executable Fozzy scenarios: tests/*.fozzy.json

Current State

Implemented and validated today:

  • general-purpose systems-language scope, not a niche single-domain tool
  • safe by default, with explicit unsafe islands, compiler-generated unsafe inventory/docs, and opt-in manual memory management via alloc(...) / free(...)
  • real runtime defer semantics across normal code and unsafe { ... } islands, so deterministic cleanup is enforced rather than merely documented
  • verifier-enforced ownership, borrow, capability, FFI, and native-lowerability rules
  • explicit manual memory management is supported inside that model, with ownership-aware alloc(...) / free(...) flows and verifier-visible lifecycle checks
  • deterministic trace, replay, and scheduler validation as normal production gates
  • host-backed confidence paths for filesystem, process, and HTTP behavior
  • deterministic scheduler modes: fifo, random, coverage_guided
  • decision artifacts for async, thread, and RPC execution
  • RPC frame events: rpc_send, rpc_recv, rpc_deadline, rpc_cancel
  • explore and shrink metadata for replay/minimization workflows
  • language-native scenario generation from parsed test blocks
  • recursive multi-file module loading from mod declarations
  • C header generation from exported pubext c fn signatures
  • RPC schema, client, and server stub generation via fz rpc gen
  • modern language/runtime surface across ADTs, pattern matching, traits, generics, typed domain modeling, process, terminal, logging, filesystem/path, boundary JSON, and outbound streaming HTTP
  • production crypto/security surface via core.crypto and core.security, including secure random, hashing, HMAC, constant-time compare, and URL-safe encodings
  • fzweb production web framework modules for app routing, cookies, sessions, multipart uploads, persistence, SSE, websockets, and OpenAPI export
  • fz run executes native output directly with live text streaming or JSON capture
  • LLVM and Cranelift native backends with parity-oriented validation
  • direct-memory release gates:
    • python3 scripts/direct_memory_architecture_gate.py
    • python3 scripts/direct_memory_perf_gate.py
  • production GPU surface through core.gpu, with live Metal execution on Apple plus shared spirv/nvptx adapter contracts

Production Claims

fzy is set up to support these production claims today:

  • the shipped safe-language surface is memory-safe by default within the documented verifier/compiler rule scope, with explicit audited unsafe boundaries and opt-in ownership-tracked manual memory management
  • internal compiler/runtime/tooling semantics remain a typed source of truth, with JSON reserved for external boundaries, generated artifacts, and operator-facing machine output
  • alloc(...) / free(...) stay in safe code when the compiler can still verify ownership, provenance, and cleanup execution
  • verifiable correctness through the verifier, diagnostics, deterministic testing, replay, and CI artifacts
  • deterministic execution through recorded traces, replay, and scheduler control
  • general-purpose systems coverage across async/tasks, RPC, ADTs, traits/generics, process control, terminal I/O, logging, filesystem/path, typed internal state, boundary JSON, and streaming HTTP
  • production web/service coverage through fzweb plus security primitives that keep session/cookie/auth flows inside the supported runtime surface

See also:

  • docs/system-safety-trust-model-v1.md
  • docs/production-memory-model-v1.md
  • docs/production-workflow-v1.md

Build And Test

Download Tool