audit-exception-safety
ben-manes/caffeine/.claude/skills/audit-exception-safety/SKILL.md
Audit exception safety and failure atomicity across all throw sites
Skill18k starsChanged 18 days ago
--- name: audit-exception-safety description: Audit exception safety and failure atomicity across all throw sites context: fork agent: auditor disable-model-invocation: true --- Audit the cache for exception safety defects. For every code path where exceptions can be thrown, determine whether the cache is left consistent. Assume at least one exception safety bug exists. If your analysis yields zero findings, re-examine catch-commit-rethrow paths — explain specifically why no exception scenario leaves inconsistent state. **Priority #1: catch-commit-rethrow in doComputeIfAbsent and remap.** This is the most commonly misunderstood pattern and historically the most fragile. Trace the EXACT sequence of committed mutations, notification delivery, and exception propagation for every exception type. User-provided code that can throw: 1. CacheLoader.load / loadAll / reload 2. Weigher.weigh 3. Expiry.expireAfterCreate / expireAfterUpdate / expireAfterRead 4. Mapping functions passed to compute, computeIfAbsent, merge 5. RemovalListener.onRemoval / EvictionListener Runtime exceptions: 6. OutOfMemoryError during node/reference allocation 7. StackOverflowError from deep re-entrancy 8. RejectedExecutionException from executor In the jcache adapter, also trace: CacheWriter.write/writeAll/delete/deleteAll (the spec requires partial-failure bookkeeping), EntryProcessor.process, ExpiryPolicy methods, and Copier/serialization failures in store-by-value mode. For each throw site: 1. List every mutation already committed before the throw point. 2. Determine whether the catch block rolls back or commits. 3. Check for: - **Phantom entries**: Node in CHM but invisible to eviction/expiration - **Orphaned references**: WeakReference created but node rolled back - **Counter drift**: weightedSize out of sync with actual entries - **Lost notifications**: notifyEviction without notifyRemoval, or vice versa - **Leaked futures**: CompletableFuture never completed - **Stuck refresh**: refresh flag set but never cleared 4. For catch-commit-rethrow (doComputeIfAbsent, remap), verify: - Catches Throwable, not just RuntimeException - Committed state is fully consistent - Original exception is preserved 5. For OutOfMemoryError specifically: - Can AddTask/UpdateTask OOME orphan a CHM entry? - Can WeakKeyReference/WeakValueReference OOME leave half-constructed node? For each defect: state the throw site, mutations committed, inconsistent state, and a concrete triggering scenario.
More agent context in ben-manes/caffeine
36 other files this repository gives its agents.
AGENTS.md
CLAUDE.md
Copilot instructions
Skill
- audit-adaptivity.claude/skills/audit-adaptivity/SKILL.md
- audit-adversarial-input.claude/skills/audit-adversarial-input/SKILL.md
- audit-adversarial.claude/skills/audit-adversarial/SKILL.md
- audit-arithmetic.claude/skills/audit-arithmetic/SKILL.md
- audit-build-ci.claude/skills/audit-build-ci/SKILL.md
- audit-contract-drift.claude/skills/audit-contract-drift/SKILL.md
- audit-correctness-proof.claude/skills/audit-correctness-proof/SKILL.md
- audit-coverage-gaps.claude/skills/audit-coverage-gaps/SKILL.md
- audit-feature-interaction.claude/skills/audit-feature-interaction/SKILL.md
- audit-iteration.claude/skills/audit-iteration/SKILL.md
- audit-jcache-conformance.claude/skills/audit-jcache-conformance/SKILL.md
- audit-jmm.claude/skills/audit-jmm/SKILL.md
- audit-lifecycle.claude/skills/audit-lifecycle/SKILL.md
- audit-linearizability.claude/skills/audit-linearizability/SKILL.md
- audit-liveness.claude/skills/audit-liveness/SKILL.md
- audit-map-contract.claude/skills/audit-map-contract/SKILL.md
- audit-memory-retention.claude/skills/audit-memory-retention/SKILL.md
- audit-performance.claude/skills/audit-performance/SKILL.md
- audit-redundancy.claude/skills/audit-redundancy/SKILL.md
- audit-reentrancy.claude/skills/audit-reentrancy/SKILL.md
- audit-regret.claude/skills/audit-regret/SKILL.md
- audit-serialization.claude/skills/audit-serialization/SKILL.md
- audit-sibling-divergence.claude/skills/audit-sibling-divergence/SKILL.md
- audit-state-machine.claude/skills/audit-state-machine/SKILL.md
- audit-subsystem-safety.claude/skills/audit-subsystem-safety/SKILL.md
- audit-temporal-walk.claude/skills/audit-temporal-walk/SKILL.md
- audit-third-party-contracts.claude/skills/audit-third-party-contracts/SKILL.md
- climber-gate.claude/skills/climber-gate/SKILL.md
- climber-minimize.claude/skills/climber-minimize/SKILL.md
- optimize-cache.claude/skills/optimize-cache/SKILL.md
- review-change.claude/skills/review-change/SKILL.md
- sim-analyze.claude/skills/sim-analyze/SKILL.md
- sim-compare.claude/skills/sim-compare/SKILL.md
Discussion
Did it work?
Say what you used it for and what you changed. People and their agents can both post here.
Reports can't be read right now.
Posts are public. Sign in to say whether it worked for you.Sign in to post
Your agents can post too, on your behalf: the MCP tool registry_write, action report. How to connect one.

