About this project

Hum is an early-stage (0.0.1 pre-alpha) design draft for a systems programming language. Its stated goal is to combine low-level Rust/C++-style power with Python-like readability, static types, explicit effects, memory safety by default, and compiler-generated context aimed at both humans and coding agents. The central idea is that contracts normally written as comments become checked promises. A task can declare sections such as `why`, `targets`, `uses`, `changes`, `needs`, `ensures`, `protects`, `trusts`, `fails when`, `watch for`, `cost`, `allocates`, `avoids`, `tradeoffs`, `optimizes`, `tests`, and `does`. The repository includes a deliberately sabotaged fixture whose `ensures: result == a + b` is violated by a `return a - b` body; running it produces a diagnostic that blames the task implementation rather than the caller. Ownership words (`borrow`, `change`, `consume`) are also treated as checked promises. Local views are narrow: borrowing a field is invalidated by a later write to that field, and borrowing a list element is invalidated by later growth. A writable alias form (`let alias = change record.field`) writes through and is live only through its last straight-line syntactic use. Use-after-move is reported with the move site named. `old(...)` captures a parameter's value at task entry, so a swap that never swaps is caught by its own contract. The README is explicit about limits: `cost:`, `allocates:`, `protects:`, and `trusts:` lines are recorded intent, graph facts, and generated obligations today, not enforced proofs. Checker reports emit an explicit non-claims list so the boundary between checked and declared stays visible. Status: a Milestone 0 Rust bootstrap compiler front-end, with Milestone 1 execution started via `hum run` interpreting the first Formal Core fixtures. The first canonical native slice is `programs/integer_sign.hum`, run with `hum run --native --allow stdout.write ... --args -7`, which checks the source, verifies backend facts, and prints through Cranelift on supported Windows and Linux hosts. The README describes this as one bounded program shape, not general native compilation. The repository is documentation-heavy: architecture, language reference, grammar, schemas for syntax surface, capabilities, target facts, evidence reports, math obligations, resource reports, Core Hum contract/preview/lower/verify, type/effect/ownership/resource checks, IR contract and readiness, backend input/probe/contract, LSP capabilities, doctor, plus decision records, security model, unsafe policy, interop and portability, memory safety model, compile-time strategy, stdlib strategy, runtime profiles, backend strategy, roadmap, governance, and research notes. Tooling includes a TextMate grammar, a planned formatter (`humfmt`), a package manager plan (Nectar), and CLI commands such as `check`, `version`, `explain`, `diagnostics`, `capabilities`, `target-facts`, `core-contract`, `core-preview`, `core-lower`, `core-verify`, and `full-type-check`, several with JSON output. The bootstrap compiler is written in Rust and denies unsafe code by default, with one reviewed, locally allowed unsafe JIT invocation boundary and five pinned Cranelift dependencies. Cargo is the current build and install path, though the README notes Hum should not be positioned as "just a Cargo crate" long-term.