Code is written by models now. C+ is built around the complete agent development loop: understand code, change it, validate and build it, drive the running application, inspect the outcome, and repeat — while keeping every change legible enough for a person to audit.
A compiled, statically typed systems language: native machine code through LLVM, no VM, no garbage collector, manual memory made safe by a borrow checker, two-way C interop.
v0.0.28 · Facet on AppKit, UIKit, Android, GTK, and Win32$ cpc hello.cplus -o hello $ ./hello hello, world
Native applications through Facet on AppKit, UIKit, Android, GTK, and Win32.
Natively compiled services with no GC and predictable memory.
Fast, memory-safe CLI tools, compiled to a single native binary by the cpc compiler.
Native speed, no runtime tax.
C+ compiles directly to native code through LLVM. The borrow checker and restrict markers give the optimizer the aliasing guarantees it needs to vectorize hot loops. No annotations to remember, just the ones the type system already proved.
// noalias hot loop, vectorizes cleanly fn axpy(n: usize, a: f32, restrict x: *f32, restrict y: *f32) { var i: usize = 0; while i < n { y[i] = a * x[i] + y[i]; i = i +% 1; } }
Concise code, few ways to go wrong.
Structs, methods, generics, and pattern matching, with no overloading, no implicit conversions, and no closures to reason about. Fewer ways to write it wrong, and exact, numbered diagnostics when you do.
struct Point { x: i32, y: i32 } impl Point { fn translate(ref this, dx: i32, dy: i32) { this.x = this.x +% dx; this.y = this.y +% dy; } }
Why "safer," not "safe."
C+ is not a sandbox, and does not pretend to be. Raw pointers, foreign calls, and other operations that can cause undefined behaviour stay your responsibility. The difference from C is that each one is visible in the source itself (a raw-pointer dereference, a pointer cast, an extern call), so nothing dangerous hides from a reviewer. What the language does remove outright: no null, no exceptions, no uninitialized reads, and a borrow checker that enforces aliasing-xor-mutation so data races don't compile, with Drop / defer for deterministic cleanup. That is the whole claim, and the reason the word is "safer," not "safe": far fewer ways to crash by accident, and the operations that still can are the ones you can see.
struct Buf { ptr: *u8, len: usize } impl Buf { // runs automatically on scope exit fn drop(ref this) { free(this.ptr); } } fn main() -> i32 { let b: Buf = make_buf(); defer #println("cleaning up"); return 0; }
Audio callbacks, control loops, and frame hot paths can't afford a hidden allocation or a lock. Mark a function #[realtime] and the compiler proves it across the entire transitive call graph: no heap allocation, no blocking, no unbounded recursion, no unknown calls. Not a lint. A compile error.
#[no_alloc] · rejects any path to malloc#[no_block] · rejects locks, waits, and blocking I/O#[max_stack(N)] · bounded, ABI-accurate frame sizevendor/rt#[realtime] PID run on an ESP32
// compiler-checked: a violation won't compile const GAIN: f32 = 0.5f32; #[realtime] fn process_frame(n: usize, restrict input: *f32x4, restrict output: *f32x4) { let gain: f32x4 = f32x4::splat(GAIN); var i: usize = 0; while i < n { output[i] = input[i].mul(gain); // pure SIMD math i = i +% 1; } // Vec::new / lock / sleep here → E0901 / E0907 }
C+ calls C, Objective-C, and Metal directly through extern fn, with no binding layer and no glue generator. And because cpc emits standard C-ABI object files, existing C and C++ projects link C+ straight back: drop a .o into a CMake build and replace functions one symbol at a time, until the binary stands on its own. And when wrapping a whole system framework by hand would mean pages of declarations, cpc-bindgen generates the C+ package for you, reading Objective-C, Swift, GObject/GIR, and pkg-config C interfaces and bridging objects, collections, delegates, and blocks both ways.
// ① C+ calls C, no bindings extern fn cblas_sdot(n: i32, x: *f32, ix: i32, y: *f32, iy: i32) -> f32;
// ② C links C+ back, a plain C symbol export extern fn cplus_dot(restrict a: *f32, restrict b: *f32, n: usize) -> f32 { // ... emits `cplus_dot` for clang / CMake to link return 0.0f32; }
No GC, no runtime overhead. A single-threaded raytracer, release build, on Apple Silicon.
Ray Tracing in One Weekend · 800×450 · 32 spp · release build, Apple Silicon.
Install the cpc toolchain and build your first program in seconds.
# macOS (Apple Silicon) $ brew install netdur/cplus/cplus $ cpc --version
Prebuilt binaries, no toolchain to build. Supported hosts: macOS M-series, Linux x86-64 (.deb), and Windows x86-64 (.zip). A macOS host cross-compiles to iOS through Xcode; Android and ESP32 builds use their target toolchains. Linux and Windows builds are on the GitHub releases page.
Every feature C+ leaves out removes a class of mistake: no closures means no capture semantics to get wrong, no overloading means one name resolves to one signature, no implicit conversions means every width change is visible in the source. Ownership is on every parameter, every crash-capable operation is visible in the source, and imports name their source.
What looks verbose is deliberate. Parameter ownership, binding types, and operations such as wrapping +% are visible in the source, so the same code reads the same way to a person and to a model. There is no clever shorthand to learn and no hidden control flow to infer.
When something is wrong, the compiler is exact about it: diagnostics are numbered, spanned, and machine-readable, and cpc check --diagnostics=json makes them trivial to act on. The compiler is part of writing the code, not just the gate at the end.
$ cpc check --diagnostics=json // one JSON object per diagnostic, ready to repair { "code": "E0305", "level": "error", "span": { "file": "main.cplus", "line": 4, "col": 5 }, "message": "cannot assign to immutable binding `total`; declare it as `var`" }
Optimizing for agents is not only about generating source with fewer tokens or shortening one compile step. C+ gives an agent a structured path through the whole job: understand resolved code, edit it, validate cheaply, build and run it, exercise real behavior through the live agent surface, inspect exposed state and events, then use that evidence for the next change.
cpc query and cpc mcp expose the compiler's resolved code graphcpc check returns precise diagnostics; cpc build produces the executableunderstand code ↓ cpc query / cpc mcp modify code ↓ edit source validate cheaply ↓ cpc check produce executable ↓ cpc build run application ↓ connect to live agent surface exercise real behavior ↓ click / type / invoke actions inspect outcome ↓ read exposed state / events / results expected? ├─ yes → continue └─ no → query → edit → check → build → run again
Built in the open. Contribute and get involved.