Compiles to portable C
U is a systems language where the safe path and the fast path are the same path. Write the obvious code — the compiler handles memory, concurrency, and vectorization. No garbage collector — cycles prevented at compile time. No data races, no ceremony. LLMs generate correct U on the first try because the defaults are already safe.
// Parameters are read-only by default.
// Shared without a lock, copied without a care.
f describe(cfg: Config) -> S
r => "{{cfg.name}} v{{cfg.version}}"
// +V says: these lanes are independent.
// The C that comes out uses real SIMD.
f scaleAll(arr: [I +V] +R) -> [I +V] +R
r => arr.map(val => val * 3)
Every safety property comes from one system: modifiers on types. No separate borrow checker, no async runtime, no SIMD intrinsics to learn. One mechanism, six benefits.
Variables live on the stack by default — fast, automatic, freed when the
function returns. When you need a value to outlive the function, add
+R and the compiler tracks who's using it (like Swift's ARC).
Circular references — the classic memory leak — are caught at compile time,
not at runtime. No garbage collector, no pauses, no manual memory management.
Prefix any call with a to run it as a fiber — a lightweight
async task. There's no async/await split, no colored functions,
no thread pool boilerplate. A function that works synchronously works
asynchronously too — the caller decides, not the definition. Fibers suspend
and resume automatically; the compiler handles the scheduling.
Add +V and the compiler processes your data in parallel lanes
automatically. The emitted C uses vector types that become SSE or AVX on
x86, NEON on ARM, and WebAssembly SIMD in the browser. You don't write
intrinsics or platform-specific code — just annotate the data. If the
operation can't safely vectorize, you get a compile error, not a silent
wrong result.
+R(GPU) puts data in device memory and turns a
.map() into a GPU compute shader. The same code runs in the
browser through WebGPU and natively through Dawn — one source file, every
device. No CUDA toolkit, no separate shader language, no manual buffer
management. If the data doesn't fit the GPU model, the compiler tells you.
Parameters can't be changed. Fields outside your own instance can't be
changed. To make something mutable, you write +M — an explicit
opt-in, visible at the declaration. Shared state goes through atomic
<< patches. Data races are compile errors, not crashes
you discover in production at 3 AM.
U emits ordinary C11 that you can read, debug, and compile with the toolchain you already have — gcc, clang, MSVC. No virtual machine, no runtime library to ship, no dependency on a specific OS version. The same source also compiles to WebAssembly through Emscripten, so one codebase runs natively and in the browser.
Garbage collection. Null exceptions. Data races. Async coloring. SQL injection.
Off-by-one errors. Each one has a state-of-the-art solution — and each solution has a cost.
U eliminates all 26 at the root, through the same modifier system, and they compound:
-M prevents races AND enables vectorization. -E enables memoization AND
deterministic testing. There is one way to do each thing, and that one way composes with everything else.
Pick one. The code below is real, and so is the C beside it — both come straight out of the compiler.
No framework, no ORM boilerplate, no threading library. The handler is a function. The query compiles to parameterized SQL. The transaction retries on conflict automatically.
// ── Schema ────────────────────────────────────────── d User : Database.Row name: S email: S score: I // ── Handlers — pure functions: Request in, Response out ── f list_users(req: Request) -> Response users = Database.Query({ store: "users" }) .select(["name", "email", "score"]) .orderBy("score", "DESC") .limit(50) .fetchAll() r => Response({ body: JSON.encode(users) }) f create_user(req: Request) -> Response ! ValidationError body = JSON.decode(req.body) body.name.len < 1 ? x ValidationError("name required") user = User({ name: body.name, email: body.email, score: 0 }) user.save() r => Response({ status: 201, body: JSON.encode(user) }) f award_points(req: Request) -> Response // Transaction: both users update atomically, or neither does << ( sender = Database.Query({ store: "users" }).where("email", "=", req.query["from"]).fetchRow() recipient = Database.Query({ store: "users" }).where("email", "=", req.query["to"]).fetchRow() sender.score < 10 ? x Rollback("not enough points") sender << { score: sender.score - 10 } recipient << { score: recipient.score + 10 } ) r => Response({ body: "transferred" }) // ── Start ─────────────────────────────────────────── f main() -> none serve(8080, { "GET /users": list_users, "POST /users": create_user, "POST /award": award_points })
What the compiler enforces in this code — without a single annotation beyond what you see:
• req is -M (parameter default) — handlers can't corrupt the request
• sender.score read inside << ( ) is a snapshot — retries on conflict automatically
• sender << { score: ... } is an atomic MVCC patch — no lock, no mutex
• Rollback exits the transaction cleanly — neither update applies
• ! ValidationError in the signature — the caller knows exactly what can fail
• The query builder compiles to parameterized SQL — no injection, ever
Today's AI coding tools spend 54% of their tokens re-reading your codebase. U eliminates that cost. The modifier system makes every function's contract mechanical and exact — no LLM needed to build the dependency graph, verify changes, or generate documentation. When LLMs are used, the cost is paid once and cached forever.
u keyword — the 13th keywordu f marks a function as AI-managed. The LLM generates the body.
The compiler verifies it against the type system, the modifier constraints, and
the dependency graph. The result is cached — zero tokens on subsequent builds.
Remove u to take over. Add it to delegate. One letter toggles the
human-AI boundary.
/// Rank by relevance. Prefer exact matches.
u f search(query: S, items: [Product]) -> [Product]
// Human writes the wiring
f main()
serve(8080, {
"GET /search": (req) => Response.json(
search(req.query["q"], catalog())
)
})
QU's Q type uses rational numbers — no floating-point rounding,
no epsilon comparisons, no 0.1 + 0.2 ≠ 0.3 bugs. Financial calculations,
fee splits, and voting weights are exact by default. The underlying algorithm is
described in Quotient
Tree Arithmetic (arXiv:2607.22612) — deferred division with bounded symbolic
depth and cross-subtree cancellation.
// Q arithmetic is exact — no rounding fee = amount * 3 / 100 // exactly 3%, not 2.9999... split = total / 3 // keeps the rational, never truncates fee == amount * 3 / 100 // true, always — exact comparison
U is the language. Safebots is the platform. The modifier system connects them.
+E(capabilities) — controlled I/O through typed middleware with M-of-N
governed policies. The compile-time sandbox that replaces DeterministicJS and WASM isolation.
U proves the code is safe. The Safebox enforces it. Users' data stays in their Safebox. The compiler is the first line of defense — not the last.
Safeboxes, Streams, Grokers, micropayments — the full stack for AI-native applications where trust is structural, not promised.
U is a working reference compiler, not a finished product. The status page is deliberately blunt about which features run, which are simplified, and which are still stubs — every row names its own limits.
The full reference: types, modifiers, memory model, concurrency, error handling, and the reasoning behind each choice.
How u2c is built — parser, linter, code generation, the runtime, and the decisions that shaped them.
Every feature marked Works, Simplified, or Placeholder, with the exact scope and the test that backs it.
Notes on running U in the browser: the WebAssembly path, the playground, and what still has to land.
A short tour that starts at functions and ends with a GPU kernel, with runnable snippets the whole way.
Small, copyable programs that show one idea each — and a link format for sharing your own.