Repository navigation
seqlock-fix-4: the optimistic descent must not dereference a null child - #1872
Merged
swapnilpaliwal-sd merged 1 commit intoOct 9, 2026
Merged
Conversation
The parallel crash finally captured (java -j8, darwin-arm64, under souffle -g memory load): btree::insert's descent reads the child pointer under a still-unvalidated optimistic lease and immediately dereferences it for the next lease — ldapr of the child's seqlock version at address null+8. A concurrent split can expose a null slot; on x86's strong ordering the window effectively never opens, on arm64 under memory pressure it does (js 3/10 and java 2/4 observed). The guard treats a null child as a failed validation and restarts the insert — the same contract every other torn read in the descent already follows. Applied to BTree.h and its BTreeDelete.h twin. Defense in depth, same overlay: the flyweight fetch returns a static empty value for a speculative (out-of-range or unassigned) index instead of dereferencing the slot, and the generic record unpack returns zeroed storage instead of an empty record's null data(). Engine id salt moves to +seqlock-fix-4; the engine-package stub carries the new anchors, and build-engines.yml applies and asserts the same extracted patch (its awk anchor also repaired: the heredoc's import line had changed under it). Validation on a 1.2M-LOC java subject, keycloak-sized facts, identical and interleaved conditions under a souffle -g load loop: unfixed engine 8/10 segfaults, fix-4 engine 0/10, and every output relation of fix-4 serial AND parallel sorted-identical to the fix-3 serial reference. Co-authored-by: axiomcode-bot[bot] <334110751+axiomcode-bot[bot]@users.noreply.github.com>
swapnilpaliwal-sd
requested review from
JaredHLZhang,
Whua689 and
suyashpaliwal26
as code owners
October 8, 2026 21:17
Contributor
Author
|
The javascript leg repeats the result: under the same interleaved load loop the unfixed engine segfaulted 3/10 while fix-4 ran 0/10, and the fix-4 parallel output is sorted-identical to the unfixed serial reference across every relation. Both crashing languages now validate the same way. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #1869 — the parallel-solve crash is root-caused, captured, fixed and validated against a live reproduction.
The capture (lldb, java
-j8, darwin-arm64, under asouffle -gmemory-load loop — the missing repro ingredient):insert's descent readsnext = cur->getChild(idx)under a still-unvalidated optimistic lease and immediately dereferences it (next->lock.start_read()). A concurrent split can expose a null child slot; x86's ordering keeps the window closed, arm64 under memory pressure opens it. This explains every observation: javascript 3/10 and java 2/4 crash rates, a different rule each time, arm64-only, pressure-gated, serial always clean.The fix (overlay
seqlock-fix-4, engine-id salted): a null child is treated as a failed validation and the insert restarts — the same contract the descent already follows for torn reads. Applied toBTree.handBTreeDelete.h. Defense in depth in the same overlay: the flyweightfetchtolerates speculative indices (static empty value) and generic recordunpackreturns zeroed storage rather than an empty record's nulldata().Validation, 1.2M-LOC java subject, interleaved runs under the identical load loop:
-j8-j8and fix-4 serial AND parallel outputs are sorted-identical to the fix-3 serial reference across every relation. The engine-package stub test carries the new anchors (green), and build-engines.yml applies the same awk-extracted patch with per-file assertions — its awk anchor is also repaired (the heredoc's import line had drifted under it, which would have failed the next release build loudly).
With this in, the parallel-by-default gate from #1861 stands safely for 0.1.9.