FAILURE MAP
← Case archive

FA-90342 / Garbage collector invariants / Member archive

Insertion barrier: barrier shades the source object · case 02

An object stored into an already-black object is freed while still referenced.

Member previewVariant 2 · 3 implementations · 7 checks per implementation

Case contract

Incremental tri-colour mark-sweep with a Dijkstra insertion barrier. start: every object white, roots shaded grey. mark k: up to k worklist steps (pop a grey object, shade its white children, blacken it). store src i dst: while marking, shade dst before writing. alloc id k: new object with k null fields, black while marking (allocate-black), otherwise white. root id: add a root, shaded if marking. unroot id removes a root. finish: drain the worklist, free all white objects, stop marking. Return the freed ids per finish and the surviving ids.

Why this case matters

Incremental collectors are only safe if barriers and allocation colour preserve the tri-colour invariant.

One recorded failure

Sample boundary fixture

This sample comes from the broken implementation of a controlled reproducer.

Boundary fixtureActualExpectedOutcome
regression: pointer stored into a black object{"freed": [[24, 25, 26]], "live": [21, 22, 23]}{"freed": [[26]], "live": [21, 22, 23, 24, 25]}Failed

MEMBER ARCHIVE

The complete case is available to members.

This record includes three runnable implementations, regression fixtures, execution results, and source hashes.

Member access is invitation-based. Sign in with your invited account to inspect the sources.

Sign in to the archive ↗