a systems programming language prioritizing verifiable correctness, determinism, and performance
General-purpose systems language and production toolchain with a memory-safe-by-default shipped safe-language surface, verifiable correctness, deterministic execution, and replay-first debugging built in.
fzy ships one production CLI, fz, for both compiler workflows and deterministic validation. Correctness, determinism, replay, incident artifacts, and production evidence are part of the normal workflow rather than an afterthought. For a quick visual tour of the language, open the shipped FZL showcase in your browser with open fzl-showcase.html. For the short argument for why you might pick it, see WHYFZY.md.
Repository architecture policy is typed internally and JSON at real boundaries only.
INSTALL.mdUSAGE.mdWHYFZY.mdCODE.mddocs/production-workflow-v1.mddocs/gpu-v1.mddocs/system-safety-trust-model-v1.mddocs/unsafe-contract-authoring-v1.mddocs/language-stability-v1.mddocs/workspace-policy-v1.mddocs/operational-insights-v1.mdfzyllm: saint0x/fzyllmRecommended install:
curl -fsSL https://raw.githubusercontent.com/saint0x/fzy/main/install.sh | sh
That installs fz to ~/.local/bin, updates PATH if needed, and verifies the install with fz version and fz env.
Source fallback:
curl -fsSL https://raw.githubusercontent.com/saint0x/fzy/main/install.sh | sh -s -- --from-source
Want the fastest overview? Open fzl-showcase.html with open fzl-showcase.html, skim WHYFZY.md for the product argument, then use the sample below as a compact executable sketch.
use core.log;
use core.path;
use core.process;
use core.time;
enum Mode {
Fast,
Safe,
}
trait Scorer {
fn score(endpoint: Url) -> i32;
}
struct HttpScorer {}
impl Scorer for HttpScorer {
fn score(endpoint: Url) -> i32 {
discard endpoint;
return 7;
}
}
struct Config<TEndpoint> {
retries: i32,
endpoint: TEndpoint,
mode: Mode,
}
fn weight(mode: Mode) -> i32 {
match mode {
Mode::Fast => return 3,
Mode::Safe => return 1,
_ => return 1,
}
}
async fn boost(v: i32) -> i32 {
checkpoint()
return v + 1
}
fn normalize<T: Scorer>(cfg: Config<Url>) -> i32 {
return weight(cfg.mode) + T.score(cfg.endpoint)
}
async fn run_once(cfg: Config<Url>) -> i32 {
let base = normalize<HttpScorer>(cfg)
return await boost(base)
}
fn main() -> i32 {
let cfg = Config { retries: 4, endpoint: url.parse("https://example.test"), mode: Mode::Fast }
let now = time.now()
let out_path = path.join("tmp", "score.log")
let mode = process.argv_or(1, "showcase")
let score = normalize<HttpScorer>(cfg)
log.info("snippet.run", out_path)
discard mode
discard run_once
if score + now > 0 then return score
return score
}
For broader language coverage, use CODE.md, examples/, and the browser-friendly FZL showcase.
Framework packages follow normal package rules: declare them in fozzy.toml under [deps], then import them in source with use fzbounds;, use fzweb;, and similar package names. Direct source checks such as fz check src/services/mod.fzy --json now validate through the owning package context, so dependency imports and sibling modules behave the same way they do in full-project checks.
fz: compiler CLI for build, run, test, verify, docs, IR, RPC, headers, ABI checks, and morefz fmt, fz doc gencrates/parser, crates/ast, crates/hir, crates/fircrates/verifiercrates/runtimecrates/drivertests/*.fozzy.jsonImplemented and validated today:
alloc(...) / free(...)defer semantics across normal code and unsafe { ... } islands, so deterministic cleanup is enforced rather than merely documentedalloc(...) / free(...) flows and verifier-visible lifecycle checksfifo, random, coverage_guidedrpc_send, rpc_recv, rpc_deadline, rpc_canceltest blocksmod declarationspubext c fn signaturesfz rpc gencore.crypto and core.security, including secure random, hashing, HMAC, constant-time compare, and URL-safe encodingsfzweb production web framework modules for app routing, cookies, sessions, multipart uploads, persistence, SSE, websockets, and OpenAPI exportfz run executes native output directly with live text streaming or JSON capturepython3 scripts/direct_memory_architecture_gate.pypython3 scripts/direct_memory_perf_gate.pycore.gpu, with live Metal execution on Apple plus shared spirv/nvptx adapter contractsfzy is set up to support these production claims today:
alloc(...) / free(...) stay in safe code when the compiler can still verify ownership, provenance, and cleanup executionfzweb plus security primitives that keep session/cookie/auth flows inside the supported runtime surfaceSee also:
docs/system-safety-trust-model-v1.mddocs/production-memory-model-v1.mddocs/production-workflow-v1.md