- cap 1024 (WO_MAILBOX override at boot): sender-side atomic reserve/release on every path — same-shard, cross-shard envelope, OOM rollbacks; full mailbox traps the SENDER catchably; delivery pop releases; overshoot bounded by in-flight sends (disclosed) - test_mailbox 12/0: exact cap single-threaded, two racing senders win exactly cap slots, drain/refill clean - corpus run/mailbox-full-trap: parked sleeper, send loop catches "actor mailbox full" after >= 1024 sends - pre-existing compiler bug found + fixed: a try ARM yielding a Text PLACE (bare e.msg, try box.field) aliased a register the arm's scope end freed — ASan use-after-free, SEGV on the next unwind's double-walk; emit_try now applies copy_place_text to both arm results; pinned by corpus run/catch-msg-place - db-bench driver: msgrate keeps iteration 22's unbounded-flood contract via WO_MAILBOX=MSG_N (the cap is 24's policy, not 22's) - battery 12/12 fresh-built Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
25 lines
762 B
Text
25 lines
762 B
Text
-- iteration 24 fix pin: a try ARM's value that is a Text PLACE must be
|
|
-- copied out before the arm's scope dies. The catch half: bare `e.msg`
|
|
-- aliased the Error record's field, the record dropped at arm end, and
|
|
-- the binding dangled (ASan use-after-free, then a double-walk SEGV on
|
|
-- the next unwind). The body half: `try box.name catch ...` aliased the
|
|
-- box's field across the same boundary.
|
|
use fs
|
|
|
|
class Box {
|
|
name: Text
|
|
}
|
|
|
|
fn read_place(b: Box) -> Text {
|
|
return try b.name catch (e) "unreachable";
|
|
}
|
|
|
|
fn main() -> Int {
|
|
let r = try fs.read_all("/nonexistent-woc-fixture", 10) catch (e) e.msg;
|
|
print("caught: ${r}");
|
|
let b = Box { name: "boxed" };
|
|
let t = read_place(b);
|
|
print("place: ${t}");
|
|
print("still: ${b.name}");
|
|
return 0;
|
|
}
|