writeonce/docs/stories/language-runtime-database
shoney.arickathil 00214bd68e fix(vm): marshal cross-shard actor messages (language 41) — the double free
Root cause (decision 1): cross-shard send/call/monitor pointer-shared the
message into the receiver's shard (e->payload = msg_val), so a worker read and
eventually dropped an object living in the sender's arena — a double free, then
a class-0 forge, then a modulo self-route livelock, all downstream of that one
broken invariant ("VM heaps are never read cross-shard", which wo_db_rpc keeps).

- actor_marshal: the sender encodes the message into an arena-independent neutral
  form (wo_db_val_encode, the same marshal wo_db_rpc uses) and drops its own
  original — no pointer crosses an arena boundary, so the double-free class is
  gone by construction. actor_unmarshal rebuilds it in the receiver's arena
  (wo_val_decode_vm) and frees the neutral. Applied to the 4 cross-shard
  producers (send x2, call, monitor) + the 3 consumers (kinds 0/5/7). Same-shard
  paths untouched (the WO_SHARDS=1 fast path never failed). Call replies are
  scalars by contract, so kind 6 needs no marshal.
- eng_settle_inboxes: undrained kind-0/5/7 payloads at teardown are the neutral
  form now — free with wo_db_val_free, not wo_drop_obj (caught by ASan mid-fix).
- decision 2: wo_route_free traps a shard_id >= nshards header (a corrupt/freed
  block) instead of self-routing it into the settle livelock.
- proof: tests/regress/lang-41/cross-shard-marshal.wo (a multi<Text> sent +
  called cross-shard, both sides drop) — clean 12x/5x under WO_SHARDS=4 + ASan;
  shard-settle repro still clean 8x; full runtime suite 0 fail (same-shard
  byte-unchanged). `just db-actor` extended with the new fixture.
- unblocks porch 9. Follow-ups: poison-on-free (decision 3), corpus fixture (4).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
(cherry picked from commit 63065ff75799f7f43b2bce6de61e77856799566f)
2026-09-15 01:16:13 +02:00
..
00-story.md docs(databasev2): third track — the database beyond RAM, with per-table storage modes 2026-08-26 20:52:48 +02:00
01-principles-doc.md docs(stories): add readiness, retire status: refine, sweep all 47 iterations 2026-08-27 16:54:45 +02:00
02-vm-core.md docs(stories): add readiness, retire status: refine, sweep all 47 iterations 2026-08-27 16:54:45 +02:00
03-compiler-front.md docs(stories): add readiness, retire status: refine, sweep all 47 iterations 2026-08-27 16:54:45 +02:00
04-single-binary-e2e.md docs(stories): add readiness, retire status: refine, sweep all 47 iterations 2026-08-27 16:54:45 +02:00
05-language-surface.md docs(stories): add readiness, retire status: refine, sweep all 47 iterations 2026-08-27 16:54:45 +02:00
06-program-mode-stdlib.md docs(stories): add readiness, retire status: refine, sweep all 47 iterations 2026-08-27 16:54:45 +02:00
07-logwatcher-proof.md docs(stories): add readiness, retire status: refine, sweep all 47 iterations 2026-08-27 16:54:45 +02:00
07b-inferred-gc-mark-sweep.md docs(stories): add readiness, retire status: refine, sweep all 47 iterations 2026-08-27 16:54:45 +02:00
08-shard-actor-runtime.md docs(stories): add readiness, retire status: refine, sweep all 47 iterations 2026-08-27 16:54:45 +02:00
09-database-engine.md docs(stories): add readiness, retire status: refine, sweep all 47 iterations 2026-08-27 16:54:45 +02:00
09b-table-relations-query.md docs(stories): add readiness, retire status: refine, sweep all 47 iterations 2026-08-27 16:54:45 +02:00
11-fibers.md docs(stories): add readiness, retire status: refine, sweep all 47 iterations 2026-08-27 16:54:45 +02:00
15-deps-package-manager.md docs(stories): add readiness, retire status: refine, sweep all 47 iterations 2026-08-27 16:54:45 +02:00
16-web-framework.md docs(stories): add readiness, retire status: refine, sweep all 47 iterations 2026-08-27 16:54:45 +02:00
17-library-projects-internal.md docs(stories): add readiness, retire status: refine, sweep all 47 iterations 2026-08-27 16:54:45 +02:00
18-memory-db-features.md docs(stories): add readiness, retire status: refine, sweep all 47 iterations 2026-08-27 16:54:45 +02:00
19-missing-scalar-types.md docs(stories): add readiness, retire status: refine, sweep all 47 iterations 2026-08-27 16:54:45 +02:00
22-durability-throughput-scale.md docs(stories): add readiness, retire status: refine, sweep all 47 iterations 2026-08-27 16:54:45 +02:00
24-chat-websocket-workload.md Merge master into db-residency-doctrine — and close the two half-exposed features 2026-08-29 10:14:25 +02:00
26-blue-green-deploy.md docs(stories): add readiness, retire status: refine, sweep all 47 iterations 2026-08-27 16:54:45 +02:00
28-skillhost-host-workload.md docs(stories): add readiness, retire status: refine, sweep all 47 iterations 2026-08-27 16:54:45 +02:00
29-compile-time-metaprogramming.md docs(stories): add readiness, retire status: refine, sweep all 47 iterations 2026-08-27 16:54:45 +02:00
31-actor-lifecycle.md Merge master into db-residency-doctrine — and close the two half-exposed features 2026-08-29 10:14:25 +02:00
34-crypto-builtins.md docs(rv2-tls): rv2 9 COMPLETE (both directions); retire proxy doctrine; jarvis-after-porch 2026-09-15 01:16:13 +02:00
35-net-runtime-seams.md docs(stories): add readiness, retire status: refine, sweep all 47 iterations 2026-08-27 16:54:45 +02:00
36-operator-parity.md docs(stories): add readiness, retire status: refine, sweep all 47 iterations 2026-08-27 16:54:45 +02:00
37-wo-html-components.md docs(stories): add readiness, retire status: refine, sweep all 47 iterations 2026-08-27 16:54:45 +02:00
38-content-platform-capabilities.md docs(rv2-tls): rv2 9 COMPLETE (both directions); retire proxy doctrine; jarvis-after-porch 2026-09-15 01:16:13 +02:00
39-web-framework-parity.md docs(stories): add readiness, retire status: refine, sweep all 47 iterations 2026-08-27 16:54:45 +02:00
40-shutdown-drain-guarantee.md feat(runtime): the shutdown drain guarantee — iteration 40 2026-08-27 23:43:45 +02:00
41-actor-arena-crash.md fix(vm): marshal cross-shard actor messages (language 41) — the double free 2026-09-15 01:16:13 +02:00
42-bounded-subprocess.md docs(lang42): close out iteration 42 2026-09-01 22:19:25 +02:00