From 890970de818a0be468d15636116e34d23a7aaf2a Mon Sep 17 00:00:00 2001 From: Pierre De Lancre Date: Mon, 21 Sep 2026 16:10:20 +0300 Subject: [PATCH] harness: fix double free of streamed chunk text (chunk payloads are borrowed per letta.zig contract) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit onProgressEvent freed .chunk text that handleLine also frees via defer — double free corrupted the heap mid-turn; DebugAllocator caught it and the reply tail was silently lost (delivered messages missing their final characters while the CLI transcript held the full text). 👾 Generated with [Letta Code](https://letta.com) Co-Authored-By: Letta Code --- src/matrix_harness.zig | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/src/matrix_harness.zig b/src/matrix_harness.zig index 3cb7eca..782b1e4 100644 --- a/src/matrix_harness.zig +++ b/src/matrix_harness.zig @@ -360,7 +360,9 @@ fn onProgressEvent(ctx: ?*anyopaque, ev: letta.Event) void { p.ret(out); }, .chunk => |c| { - defer p.alloc.free(c); + // NOTE: chunk/step payloads are BORROWED — handleLine frees them + // via defer (same contract as the overlay UI). Freeing here too + // is a double free (heap corruption, silently lost reply tails). _ = p.replyChunk(c, false); }, .step => {}, // legacy pre-formatted lines: superseded by structured