Skip to content

fix(segment): merged free span keeps its neighbour's purged flag (released as 2.2.6) - #54

Open
Ttimmahlax wants to merge 2 commits into
mainfrom
fix/purged-merge-flag
Open

Ttimmahlax wants to merge 2 commits into
mainfrom
fix/purged-merge-flag

Conversation

@Ttimmahlax

Copy link
Copy Markdown
Contributor

Brings main up to date with 2.2.6, which is already on crates.io.

2.2.6 = 2.2.5 + this fix, cut from the rusty_alloc-v2.2.5 tag and published by hand (tags rusty_alloc-v2.2.6 / rusty_alloc-api-v2.2.6 on 61ae839; CI on that exact tree via draft #53), because main carries the speed work from #51, which is held for a week.

The fix (mechanism B of docs/plans/recommit-failure-ignored.md): span_free merges a freed span with free neighbours, and when the merged span is not re-purged as a whole (the purge fails, or purging was switched off at runtime) it kept a clear purged flag over a decommitted neighbour; the next tenant wrote to it. Reproduced on Windows as 0xc0000005 STATUS_ACCESS_VIOLATION. Now the merged start keeps the flag if any part was purged. Cost: ~2 Ir per span_free; opscan unchanged; perl +0.002 %.

Tests: two merge tests (poisoned: both fail with the fix disabled), a test-only "fail the next N purges" hook, and the re-commit tests now hold the arena tests' lock (they raced ~1 in 12 without it; 30/30 clean with it).

Second commit: main's version moves to 2.2.6 and the changelogs get a 2.2.6 section; the speed work stays under Unreleased, so release-plz proposes its own version after 2.2.6.

🤖 Generated with Claude Code

tim-almond-house and others added 2 commits October 9, 2026 10:13
Mechanism B of docs/plans/recommit-failure-ignored.md. span_recommit reads
only a free span's FIRST slot. span_free merges with free neighbours and
re-purges the whole merged span, but not when the purge fails or purging was
switched off at runtime; the merged span then kept its first part's clear
flag over a decommitted neighbour, and the next tenant wrote to it.
Reproduced on Windows as 0xc0000005 STATUS_ACCESS_VIOLATION, the field
crash's exception. The merged start now keeps the flag if any part was
purged (a spurious flag only re-commits committed memory).

Tests: two merge tests (a failed re-purge via a new test-only "fail the next
N purges" hook in os::purge; purging turned off at runtime), poisoned: both
fail with the fix disabled. They and the mechanism-A test set the
process-wide purge_delay, so all three hold arena::adopt_tests::lock, which
also stops them taking a chunk from an arena an adoption test has just
adopted (each raced about 1 run in 12 without it; 30/30 clean with it).

Cost: about 2 Ir per span_free. Opscan unchanged on every op; allocator Ir
perl +455 (0.002 %), Endless Sky +68. Unsafe census +10, all test-only.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2.2.6 (2.2.5 + the merged-span purge fix) was cut from the 2.2.5 tag and
published by hand, so the speed work held on main for a week did not ship
with it. main's version and changelogs now say so; the speed work stays
under Unreleased for its own release.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants