Skip to content

Own pending WebSocket bytes across writer threads - #258

Merged
relh merged 1 commit into
masterfrom
relh/shared-websocket-frame-storage
Oct 3, 2026
Merged

relh merged 1 commit into
masterfrom
relh/shared-websocket-frame-storage

Conversation

@relh

@relh relh commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Babel’s short-lived scripted decision worker crashed while replacing a pending WebSocket frame allocated by another thread. The stack ended in Nim’s thread-local allocator during sendFrame. Borrowing the socket alone reproduced the same crash.

Store pending upgrade/frame bytes with explicit libc ownership and retain their length/offset across partial writes. Serialized writers can now change threads without freeing another thread’s Nim string. The receive owner, TLS checks, deadlines, and protocol remain unchanged.

Validation:

  • 23 real transport cases pass with libcurl 8.5 and official Bookworm 7.88.1, including alternating exited workers/main cleanup/pongs and partial writes after worker exit.
  • The exact Babel scripted whole episode fails before and passes after: eight applied decisions and four clean player exits. All 15 native whole-game cases pass after, including 32768 prompt IDs and malformed sampling/usage metadata.
  • Transport elapsed assertions now measure the probe’s monotonic clock, excluding Docker startup. The unchanged upgrade deadline remains 600ms.
  • Remote commands: nim c --debugger:native --parallelBuild:1 --threads:on --mm:orc -o:probe tests/support/native_websocket_probe.nim; python3 tests/test_native_websocket.py ./probe.
  • Proofs: Zephyrus /tmp/coworld-websocket-storage-v1/{test-fixed-v9.log,test-bookworm-v10.log} and /tmp/coworld-babel-websocket-v2/{test-scripted.log,test-native.log}. Failed baseline and harness runs are preserved separately.

Runs used finite owned lanes totaling at most two CPUs and 2GiB, Nice19. Native fixtures carry no authenticated model authority. Game images must pin and qualify this source separately; no production release.

Independent coordinator source review and exact input-hash-bound whole Babel reproduction passed. The unchanged game/fixture with old pointer-borrow-only player exits1; the fixed player exits0. Unit 873e8225c000412aa2b4faafc8298a75 finished0, Nice19/1CPU/1GiB/180s. Proof: Zephyrus /tmp/coworld-babel-root-pending-review-ae0ad31/proof.json. Every source/image adopter remains responsible for a fresh pinned runtime gate; no production publication/reupload is included.

Co-authored-by: GPT-6 <gpt-6@openai.com>
@relh
relh merged commit 15be367 into master Oct 3, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant