Twenty-eight programs built twice -- once plain, once sanitized -- and compared on output and exit status, plus two positive controls that are the only reason a clean result means anything: an out-of-bounds read that must report, and a shift by the width of the type that must not, because UBSan cannot see hand-written IR and this file would otherwise be claiming coverage it does not have. Its own alias rather than dune test. A sanitized program is a statically linked 1.8MB binary and takes tens of seconds to link; the sweep is nine minutes against the existing suite's seconds, and a test nobody will wait for is a test nobody runs. dune build --root . @sanitize. The checked sweep is clean. The unchecked variant -- ASan alone, with Flan's own bounds checks off -- catches three of bounds.flan's six deliberate out-of-bounds cases and is listed with why for the other three: a global has a right redzone and nothing to its left, so arr[-1] is invisible; a read past a string constant folds away entirely at -O2 and is caught only at -O0; and a reversed slice reads nothing at all. ASan is not a substitute for the bounds checks, and now there is a table saying which half it covers.
Description
Languages
OCaml
67.2%
Emacs Lisp
15.2%
C
10.4%
HTML
2.9%
Standard ML
2.8%
Other
1.5%