12 KiB
Bug hunt, 2026-09-18
Five search agents swept the runtime, checker, backends, dev loop, and Emacs client. Everything below was either executed to failure or traced to the exact line. The five marked DISPATCHED have fix lanes; the rest are recorded here and wait.
Dispatched
1. borrowed grants the borrow flag to whole subtrees — moves inside container targets vanish
Repealed, not fixed (2026-09-18): the flow analysis this hole lived in was removed wholesale
(spec-memory.md, "The repeal"). The trigger programs now compile by design and misbehave at run time.
lib/check.ml:2062-2076. The flag gates both moved (2003) and global_borrow (2033),
and is set across the entire checking of the target: the index argument of at, the base
of any Field. A move nested there is never recorded.
Confirmed by execution, two programs:
(println (at rows (eat w)))then(free w)— double free, exit 134.- Same shape with a move-only global
g: accepted,gfreed,(len g)reads a freed header, exit 0 silent. Defeats the rule test/test_flan.ml:1067-1068 pins.
Fix direction: narrow the flag to the target's own read — restore ctx.borrow for the
index of at; treat Field as simple only when its base chain bottoms out at a Var.
2. A while condition is move-checked outside in_loop — double free on iteration two
Fixed, then repealed (2026-09-18): the fix merged (47cb46a) and was removed the same day with the
whole flow analysis. The trigger compiles and aborts in the allocator at run time, by design.
lib/check.ml:1688-1691. The condition is checked before in_loop is entered, but
emit re-runs it every trip (emit.ml:1838). A condition that moves a local frees it
once per iteration. Confirmed: glibc double-free abort, exit 134.
dotimes' count (2504) and loop's inits (2561) are also outside but evaluate once — correct.
Fix: check the condition inside in_loop.
3. A checked declaration that fails to build or deliver leaves a NULL cell the session will call
lib/session.ml:601 commits t.program before Dev.eval builds (dev.ml:603 can raise)
or delivers (dev.ml:596 can refuse — e.g. queue full at vendor/agent/flan_agent.c:1186,
which a parked program guarantees after 64 installs since nothing drains the ring while
parked). The session keeps the declaration; the process never got the body; the next
thunk's install prologue interns the name with cell = NULL (runtime/flan_dev.c:65)
and body_of calls through it with no null test (emit.ml:1472) — jump to address 0
on the game thread. Nearest reachable mechanism to FIX.org's transient SIGSEGV; the
stranded-Vec hypothesis there was read out and refuted (reloads never redefine a host
global; storage addresses are stable; global_borrow holds).
Related, same lane: the queue-full refusal says "the program is not calling agent/poll",
which is the wrong cause for a parked program.
4. The merged build never drains the program's stdout pipe while serving a request
fd 1 is a 64K pipe whose only reader is accept_loop's select (lib/dev.ml:2739), not
running while serve handles a request. eval_expr's wait (664-672) and
run_render_thunk's wait (1026-1036) poll for five seconds and never drain, so a
program that prints (sand.flan does) blocks in flan_write_stdout, stalls the frame
thread for the whole timeout, and gets the false diagnostic "is it calling (agent/poll)?".
Same root on the exit path: flan_merged_exit/park fflush(NULL) before
program_state = PROGRAM_PARKED (dev.ml:3000/3017/3024), so a full pipe delays the park
and rerun refuses a finished program as "already running".
Also same family: rt_die (runtime/flan_rt.c:384-388) starts with fflush(stdout) —
a bounds trap can hang on the full pipe — and calls exit(134), the route die_now
documents as unsafe (atexit/ELF destructors want the loader lock a dlopening thread may
hold); it should _exit like the break loop does.
5. x86 shifts are always 64-bit, so the count is masked to 63 instead of width−1
lib/x86.ml:2530-2534 / shift_cl at 369 (rex ~w:true unconditionally). The comment
claims the hardware masks to operand width; it masks to 63. emit.ml:2041 masks to
bits-1 explicitly (NEXT.md "Sharp edges" records this as the language's rule). Six
confirmed divergences, e.g. (<< x 32) on i32: LLVM 1, x86 0; (>> i8min 8): LLVM
-128, x86 -1. Invisible because spike/x86/survey.sh:80 never globs spike/js/*.flan,
where p1-int-semantics.flan already catches it — widen the glob in the same lane.
Same wide-compute root, second divergence: float→int overflow under --no-bounds-checks
gives 0 on x86 (64-bit cvttsd2si then truncate) vs INT_MIN on LLVM. Acknowledged-UB
territory; fix or record, the lane's call.
Recorded, not scheduled
- Region guard never asks about elements — repealed, not fixed (2026-09-18): with the flow
analysis gone,
freeof anatresult is no longer a checker question; the mixed-allocator construction is legal and its misuse is a run-time matter. (lib/check.ml:1272, refusals 4092/4165): a heap-backed inner Vec pushed into an arena-backed outer passes the guard;atthen hands out an owning header,freeaccepts it, and the later read is a confirmed UAF (printed garbage). Breaks the premise stated in the clone note at check.ml:4152. Candidate fixes: refusefreeof a non-binding target, or region-check the element atpush/put. Sixth on the list; needs a deliberate mixed-allocator construction. - Reversed slice under
--no-bounds-checks— fixed. Thelo <= hitest is a representation invariant, not a bounds check, but sat behindif f.md.checksin both backends (emit.ml:1037,x86.ml:2164; same for SliceFromPtr'sn >= 0), so a negative-length slice reached user code. Split in both backends:hi <= lenstays behind the flag,lo <= hiandn >= 0are now emitted in every build, through the same slice-failure path.flan_vec_as_slicewas the model. See "A slice's length word is a count" in docs/BUILT.md. — fixed. Compaction now also asks whether there is an eighth of a table's worth of dead to reclaim, so a table full of live blocks stops thrashing the epoch;reg leakslies at >3072 live blocksflan_dev_reg_by_typereturns −1 with an unread count rather than zero rows, and the agent refuses in a sentence; a note dropped by a genuinely full table says so on stderr once.test/dev_limits.c regfullpins it under a writer thread: 3100 live blocks, 200 asks, 199 wrong before and 200 right after.- Emacs framing: a truncated frame raises wrong-type instead of the timeout message
and leaves the partial frame in the buffer, desyncing every later request by one frame
(
flan-dev.el:220);extract-replyreads before it deletes, so an unreadable payload wedges the connection permanently (:187). One ordering fix covers both. - Emacs poll vs watch:
flan-dev--pollbypassesflan-dev-settle-hookand consumes the watch's reply; the two consumers stay swapped for the session (flan-dev.el:406). Alsorequestreconnects before running the settle hook — 30s freeze after a daemon restart with the watch armed. - C-x C-e at point-min installs an empty declaration (
flan-dev.el:1745backward-sexpno-op unchecked); same predicate fires inside strings and misjudges narrowed buffers. flan-connect+flan-dev-quitkill two sessions (flan-dev.el:721): quit sendsclosedown the current connection and kills the daemon it started for another program.— FIXED. The gate was checked three round trips before the render thunk ran, and nothing held the break across the ~300ms build, so areg atTOCTOUrestartin between let the thunk chase freed memory with the gate's blessing. The sound fix is agent-side: the render job now carries the condition it was built under.inspectby address delivers its module asstopped-only <path>, the job header keeps the flag, andflan_agent_polldrops such a job — counted, handle closed, nothing installed and nothing called — whendepthis 0 at the moment it is claimed. That read is sound rather than narrower: only the game thread polls and only the game thread raisesdepth, sodepth > 0seen inside a poll means this thread is parked in the break loop and cannot be running a frame. The daemon reads therefusalscount either side of the delivery and surfaces the agent's own sentence — "the program resumed while this inspection was being built — stop it again and re-ask" — instead of the timeout's wrong-cause "is it calling (agent/poll)?".reg at's depth gate stays as the front door.locals,globalsandinspectby slot are deliberately not stopped-only: they hold no address, re-deriving the frame throughsnap_topor binding a global by name at thunk-run time, so they carry no blessing that can expire. Pinned intest_agent.ml, where a stopped-only job delivered to a program that is definitively running is dropped while the eval module beside it installs — one install, not two.defenum values never range-checked to i32— FIXED. Every resolved member value, explicit or autoincremented, is range-checked against i32 in the parser before the collision scan, so the scan compares the numbers the program will actually have. Out of range is refused by name (parse/enum-value-out-of-range); explicit-duplicate aliasing stays legal.- NaN sign — fixed. LLVM constant-folded
0.0/0.0tonan, x86 computed-nan— a stdout DIFFER on a two-line program. Resolved by canonicalizing the printed form rather than the arithmetic:flan_f64_to_bytesand the two dev emitters render any NaN as unsignednan, which is whatformat-f64in the prelude always did. Pinned intest/programs/format.flan. See docs/BUILT.md. - x86's slice-from-ptr refusal is the wrong sentence:
x86.mlstill reports a negative promise throughflan_slice_error— "slice [0 -2) is out of bounds for length 0", naming a range and a length the caller never wrote — whereemit.mlhas its ownflan_slice_promise_error. Same condition and same exit on both sides, only the text differs. The survey cannot see it:bounds.flanpicks its case out of(at args 1)andsurvey.shruns every program with no arguments, so nothing in the corpus reaches then = -2case on the x86 path. Noticed while making the check unconditional (which did not change what it prints); the fix is onebounds_callwith one extra instead of three. emit.ml:3369transient test ignoresnew_globals: on theretains=falsepath a module first to intern a global gets dlclosed; zero-init makes it moot today, a literal init would dangle.- x86 to-bytes helper-return clobber:
(defn numstr [n] (string (i64->bytes n)))works on LLVM, garbage on x86 — documented caller's-problem UB, but the divergence makes the documented edge invisible. - map-grow at log2cap>=40 quotes a stale failure (
flan_rt.c:2438, pre-dates yesterday).
JS backend (deprioritised 2026-09-18, do not schedule)
lib/js.ml:889still matches 1-arg*ToBytes; commit81b807fmade them 2-arg, so every number-printing program is refused — JS corpus MATCH went 24 → 3 and@jsstays green because a refusal counts as success. Needs a MATCH floor in strict mode.- f32 literals keep double precision (
js.ml:671discards the fkind;Math.froundit). - The cast-range trap quotes the cast's column, not the operand's (
js.ml:1077).
Verified clean, don't re-hunt
flan_map_remove (two randomized ASan harnesses incl. non-power-of-two cells, zero
mismatches), the grow-path overflow guards, the seqlock protocol itself, the park/rerun
condvar, to_bytes's 64-byte slot arithmetic, elisp multibyte framing (unibyte
throughout, tested), JS struct value semantics and 64-bit integer semantics (broad
probes), division sign/INT_MIN traps at all widths, if/match dead-set joins,
defer's kill-at-registration, index widening rules.