FalconCore is an experimental, security-minded programming language and embeddable runtime built in Rust.
v1.4 strengthens the artifact and package trust boundaries introduced in v1.3. FCBC bytecode is now structurally verified before VM execution, and package locks can be checked against manifests before dependency use.
- FCBC bytecode verifier module
- VM execution gate: malformed bytecode is rejected before dispatch
- constant-index, jump-target, repeat-target and function-entry validation
- function call arity validation during bytecode verification
- required
Haltvalidation for executable artifacts - structured bytecode verification runtime error
- manifest ↔ lockfile consistency verification
- missing dependency detection
- undeclared lock entry detection
- simple version requirement matching
- registry-source checksum requirement
- version bumped to
1.4.0
Falcon source
↓
Lexer → Parser → Module Linker
↓
Type / Symbol checks
↓
AST Optimizer
↓
Bytecode Compiler
↓
FCBC serialize/load
↓
Bytecode Verifier
↓
Capability-aware VM
↓
Explicit host capability policy
The VM does not execute an externally loaded artifact until the verifier accepts its structural invariants. Sensitive operations still require explicit host capabilities; verification does not grant permissions.
lock.verify_against(&manifest)?;The check ensures every manifest dependency is locked exactly once, its simple requirement matches the locked version, no undeclared package is present, and registry dependencies carry a checksum.
cargo run -- eval 'print 2 + 3 * 4'
cargo run -- run examples/hello.falcon
cargo run -- build examples/hello.falcon
cargo run -- inspect examples/hello.fbc
cargo run -- run-fbc examples/hello.fbc
cargo run -- check examples/hello.falcon
cargo run -- --versioncargo fmt --all
cargo test
cargo clippy --all-targets --all-features -- -D warnings- Lexer / parser foundation
- Bytecode compiler
- Hardened stack VM
- Function calls and call frames
- Float / bool / null runtime values
- CI configuration
- Developer CLI
- Bytecode disassembler
- Structured compiler diagnostics foundation
- Module/import resolver foundation
- Module-aware
checkandbuild - FCBC bytecode serialization and versioning
- Module symbol table foundation
- Export validation
- Capability registry / policy foundation
- Package manifest / lock primitives
- Qualified symbol resolver foundation
- Namespace syntax
- Cross-module linking and CLI integration
- Deterministic package-lock serialization
- Capability usage snapshots and batch authorization
- Compiler constant-folding optimizer
- Capability-aware VM dispatch foundation
- FCBC bytecode structural verification
- Manifest / lock consistency verification
- Immutable-constant assignment enforcement
- Registry-backed dependency resolution
- Full semantic version solver
- FCBC v3
- Bytecode optimization passes beyond constant folding
- Native/AOT backend stabilization
- Language server / editor integration
- Standard library and package registry
Apache License 2.0.