writeonce/docs/stories
shoney.arickathil 7ad52937b2 fix(db2-keys): delete on a keys-resident table was memory corruption
- wo_row_remove read the id map's value as a slot, but on a keys table
  that value is a LOG OFFSET (hput(t, id, wal_off + 1)). slot_row does
  no bounds check, so a delete indexed t->slabs[] with a byte offset and
  then called db_val_free on whatever it landed on — arbitrary frees,
  not a wrong answer
- keys tables now take their own arm: no slab slot, no bitmap bit, no
  free-list entry to return. The index hook needs the row's values, so
  the row is borrowed from the log for exactly that long
- wo_row_ptr carried the same trap and is public. It cannot refuse keys
  tables outright (insert legitimately calls it while the map still
  holds a slot), so it now detects the offset case — index past the
  slabs, or bitmap bit clear — and returns NULL. Callers all handle NULL
- test_keys_resident_delete pins it; it SEGVs against the old code,
  verified by reverting the fix rather than assumed
- found while auditing every hget() reader before narrowing the loader
  refusal to allow benchmarking. The refusal was justified in the docs
  by "updates are unimplemented" while actually standing in front of
  this too: a guard whose stated reason is narrower than its real one
  gets removed by someone who believes the stated reason

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit 76b8fd944af9ed062467bdf9ab93c2e96dd198cf)
2026-08-30 20:37:27 +02:00
..
databasev2 fix(db2-keys): delete on a keys-resident table was memory corruption 2026-08-30 20:37:27 +02:00
language-runtime-database Merge master into db-residency-doctrine — and close the two half-exposed features 2026-08-29 10:14:25 +02:00
porch docs(db2-keys): reconcile databasev2 and porch markdown with the code 2026-08-30 20:36:55 +02:00
00-status.md docs(db2-keys): reconcile databasev2 and porch markdown with the code 2026-08-30 20:36:55 +02:00
board-views.md docs(stories): add readiness, retire status: refine, sweep all 47 iterations 2026-08-27 16:54:45 +02:00