FAILURE MAP
← Case archive

FA-90513 / Garbage collector invariants / Member archive

Card marking: card chosen from the object header · case 03

Slots that lie in the card after their object's header are recorded against the wrong card.

Member previewVariant 3 · 3 implementations · 6 checks per implementation

Case contract

Two generations. objs maps id -> [generation, address, fields]; a field slot i of an old object lives at address + 8*i and belongs to card (slot address // 64). store writes a field and, when an old object receives a young reference, dirties that slot's card. minor: roots plus young referents of old slots in dirty cards seed a trace through young objects; unreached young objects are freed; survivors age by one and are promoted (addresses from 4096 in 64-byte steps) when age >= tenure; the card set is then rebuilt from every old slot that still references a young object. alloc id creates a young object with one null field; root/unroot edit the root list. Return per-minor {freed, promoted, cards}; following a freed object reports {"dangling": id}.

Why this case matters

Minor collections are only correct if the remembered set covers every old-to-young pointer.

One recorded failure

Sample boundary fixture

This sample comes from the broken implementation of a controlled reproducer.

Boundary fixtureActualExpectedOutcome
regression: old-to-young edge survives two minor collections[{"cards": [2], "freed": [13, 14], "promoted": []}, {"cards": [2], "freed": [], "promoted": []}][{"cards": [3], "freed": [13, 14], "promoted": []}, {"cards": [3], "freed": [], "promoted": []}]Failed

MEMBER ARCHIVE

The complete case is available to members.

This record includes three runnable implementations, regression fixtures, execution results, and source hashes.

Member access is invitation-based. Sign in with your invited account to inspect the sources.

Sign in to the archive ↗