|
| 1 | +# 2026-09-19 — The reporter cannot report its own absence. Ask the loader directly instead. |
| 2 | + |
| 3 | +Round: `2026-09-19-exception-reports-instead-of-aborting-p0` |
| 4 | +Adopted proposal: `2026-09-19-exception-reports-instead-of-aborting#p0` — |
| 5 | +*"Bound the exception-construction recursion when the fallback class itself is unloadable."* |
| 6 | + |
| 7 | +## The proposal was right, and this round is the first time it was measured |
| 8 | + |
| 9 | +The round that filed it wrote, in its own worklog: *"This is read off the call graph, **not measured** |
| 10 | +— constructing a JVM whose loader lacks that class needs a custom loader harness, which was out of |
| 11 | +this round's scope."* That harness is `test_jvm_hiding` in `test-utils`, added here. With it: |
| 12 | + |
| 13 | +| loader | result | |
| 14 | +|---|---| |
| 15 | +| hides `java/lang/NoClassDefFoundError`, cap 5 / 20 / 60 / 120 | completes — **6 / 21 / 61 / 121** round trips through the cycle | |
| 16 | +| same, cap 160 or 200 | ★ `thread has overflowed its stack` · `fatal runtime error: stack overflow, aborting` · **SIGABRT** | |
| 17 | + |
| 18 | +So the cycle is real, it has no floor, and it kills the process somewhere between **121 and 160** |
| 19 | +levels. `load_class` reports a class it cannot provide by calling |
| 20 | +`Jvm::exception("java/lang/NoClassDefFoundError", …)`; building that exception goes back through the |
| 21 | +loader; if the loader cannot provide *that* class either, the two call each other forever. |
| 22 | + |
| 23 | +## Two attempts that measurement rejected |
| 24 | + |
| 25 | +Neither was wrong on paper. Both were wrong in the tree. |
| 26 | + |
| 27 | +**1. Add it to `Jvm::new`'s `bootstrap_classes`.** Six tests failed instantly. The panic line mapped |
| 28 | +to `threads.get_mut(&thread_id).unwrap()` — resolving a class runs its initialisation, which needs |
| 29 | +the thread attached *below* that list. The list is for definitions that need nothing. |
| 30 | + |
| 31 | +**2. Resolve it after the system class loader, so the registry answers later.** Normal startup passed |
| 32 | +(6/6), and for every loader that *can* provide the class the cycle does become unreachable. But |
| 33 | +against the hiding loader it **still overflowed the stack** — only now during construction. The |
| 34 | +proposal's stated benefit is *"a clear failure instead of a stack overflow"*, and this was the same |
| 35 | +stack overflow at a different time. |
| 36 | + |
| 37 | +The reason is the shape of the problem, not the placement: **the reporting path cannot report the |
| 38 | +absence of the reporter.** `resolve_class` hands failure to `Jvm::exception`, which is the cycle. |
| 39 | + |
| 40 | +## What was built |
| 41 | + |
| 42 | +Ask the loader **directly**, bypassing the exception machinery, before resolving: |
| 43 | + |
| 44 | +```rust |
| 45 | +assert!( |
| 46 | + jvm.inner.bootstrap_class_loader.load_class(&jvm, "java/lang/NoClassDefFoundError").await?.is_some(), |
| 47 | + "the class set has no java/lang/NoClassDefFoundError, which is the class this runtime reports \ |
| 48 | + every other missing class with. …that recursion has no floor (measured: 121 round trips, then \ |
| 49 | + the process aborts on a stack overflow). Add it to the class set." |
| 50 | +); |
| 51 | +jvm.resolve_class("java/lang/NoClassDefFoundError").await?; |
| 52 | +``` |
| 53 | + |
| 54 | +One direct question turns the condition into an immediate, named failure; the `resolve_class` that |
| 55 | +follows registers the class so the loader is never asked again on an error path. |
| 56 | + |
| 57 | +**Changed: 3 files.** `jvm/src/jvm.rs` (the check + comment), `test-utils/src/lib.rs` (the harness), |
| 58 | +`jvm/tests/test_exception_fallback_recursion.rs` (new, 1 test). |
| 59 | + |
| 60 | +## Axis — bidirectional, on the product path |
| 61 | + |
| 62 | +| form of `Jvm::new` | a class set without the reporter | |
| 63 | +|---|---| |
| 64 | +| before | `stack overflow, aborting` — **SIGABRT, the test binary dies** | |
| 65 | +| after | panics at construction with the message above — `should_panic` test passes | |
| 66 | + |
| 67 | +Reverting the check does not merely fail the test, it **takes the test binary down**, which is |
| 68 | +exactly the failure a host used to get. Normal startup is unaffected: `test_string` 6/6 before and |
| 69 | +after. |
| 70 | + |
| 71 | +## What this costs |
| 72 | + |
| 73 | +- **It is a panic, and `AGENTS.md` says library code should not panic.** Stated plainly because it is |
| 74 | + a real conflict. The alternatives were measured and rejected: returning `Err` is impossible here — |
| 75 | + `JavaError` carries a `ClassInstance`, and the missing class is precisely what would have to be |
| 76 | + instantiated — and adding a non-exception variant was rejected by the round that landed |
| 77 | + `Jvm::exception`, because it silently changes 460 `let…else` sites. `Jvm::new` already `.unwrap()`s |
| 78 | + for the same class of failure on its six bootstrap classes, so this is the file's existing answer |
| 79 | + to "the class set is unusable", now with a message instead of `called Option::unwrap() on a None value`. |
| 80 | +- **One more class is resolved at every JVM startup**, for a condition that no complete class set |
| 81 | + will ever hit. |
| 82 | +- **It fails earlier than strictly necessary.** A host whose class set lacks the reporter but which |
| 83 | + never takes an error path used to run fine; now it cannot construct a JVM at all. That is a |
| 84 | + deliberate trade — the alternative is that it runs until an error path aborts it. |
| 85 | +- **The bound is on this cycle only.** Nothing here prevents a different pair of classes from |
| 86 | + recursing the same way; `java/lang/String` is the obvious candidate, since `exception()` builds the |
| 87 | + message string first. Not measured, not claimed, filed below. |
| 88 | + |
| 89 | +## Effort |
| 90 | + |
| 91 | +The proposal estimated **M**. That was right, and not for the reason it gave: the harness was the |
| 92 | +easy part (~40 lines). The cost was that **the first two designs had to be measured to be rejected**. |
0 commit comments