writeonce/docs
shoney.arickathil 00214bd68e fix(vm): marshal cross-shard actor messages (language 41) — the double free
Root cause (decision 1): cross-shard send/call/monitor pointer-shared the
message into the receiver's shard (e->payload = msg_val), so a worker read and
eventually dropped an object living in the sender's arena — a double free, then
a class-0 forge, then a modulo self-route livelock, all downstream of that one
broken invariant ("VM heaps are never read cross-shard", which wo_db_rpc keeps).

- actor_marshal: the sender encodes the message into an arena-independent neutral
  form (wo_db_val_encode, the same marshal wo_db_rpc uses) and drops its own
  original — no pointer crosses an arena boundary, so the double-free class is
  gone by construction. actor_unmarshal rebuilds it in the receiver's arena
  (wo_val_decode_vm) and frees the neutral. Applied to the 4 cross-shard
  producers (send x2, call, monitor) + the 3 consumers (kinds 0/5/7). Same-shard
  paths untouched (the WO_SHARDS=1 fast path never failed). Call replies are
  scalars by contract, so kind 6 needs no marshal.
- eng_settle_inboxes: undrained kind-0/5/7 payloads at teardown are the neutral
  form now — free with wo_db_val_free, not wo_drop_obj (caught by ASan mid-fix).
- decision 2: wo_route_free traps a shard_id >= nshards header (a corrupt/freed
  block) instead of self-routing it into the settle livelock.
- proof: tests/regress/lang-41/cross-shard-marshal.wo (a multi<Text> sent +
  called cross-shard, both sides drop) — clean 12x/5x under WO_SHARDS=4 + ASan;
  shard-settle repro still clean 8x; full runtime suite 0 fail (same-shard
  byte-unchanged). `just db-actor` extended with the new fixture.
- unblocks porch 9. Follow-ups: poison-on-free (decision 3), corpus fixture (4).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
(cherry picked from commit 63065ff75799f7f43b2bce6de61e77856799566f)
2026-09-15 01:16:13 +02:00
..
examples feat(tls): net.accept_tls — inbound TLS 1.3 termination (rv2 9 phase G3) 2026-09-15 01:16:13 +02:00
guides docs(site-update): guide for changing the site application 2026-09-15 01:15:30 +02:00
plan docs: jarvis track, runtime-v2 7/8/9, lang-41 fix design, fiber scope-gap 2026-09-15 01:15:31 +02:00
stories fix(vm): marshal cross-shard actor messages (language 41) — the double free 2026-09-15 01:16:13 +02:00
superpowers docs(rt2): close out runtime-v2 1-5 2026-09-15 01:15:30 +02:00
00-code-review.md docs: audit all markdown against the code, fix findings, flatten status folders 2026-08-26 19:20:22 +02:00
00-databasev2-chain-review.md fix(db2-keys): delete on a keys-resident table was memory corruption 2026-08-30 20:37:27 +02:00
00-dependency-graph.md docs(rv2-tls): rv2 9 phase D complete (RSA + ECDSA-P256 verify) 2026-09-15 01:15:31 +02:00
00-doc-audit.md refactor(porch): name the web framework porch, fix the wo.toml identifier claim 2026-08-26 19:36:34 +02:00
00-git-commit-history.md docs(rt2): track-wide brainstorm — all five iterations ready, graph remapped 2026-09-15 01:15:30 +02:00
00-link-audit.md docs: audit all markdown against the code, fix findings, flatten status folders 2026-08-26 19:20:22 +02:00
00-principles.md docs: amend principle 7 — the log is authoritative, residency is declared 2026-08-26 22:42:27 +02:00
01-problem.md docs: remove stale old-runtime docs; abandon the ##ui frontend track 2026-08-17 20:06:36 +02:00
08-project-structure.md docs: audit all markdown against the code, fix findings, flatten status folders 2026-08-26 19:20:22 +02:00
2026-08-27-chat-drain-finding.md fix(chat gate): every leg starts its own server — and it found a real bug 2026-08-27 23:27:46 +02:00