noCV
SFFI-101 · Establish the machine contract

Write the buffer ownership table before exposing the binding

Practice briefTaskFoundational

JavaScript and Rust both believe the other side frees an output buffer when conversion throws.

Focused work estimate
1h 30m + prerequisites
Priority in the scenario
Medium
Engineering practice
FFI · Ownership · Resource cleanup

Estimated field mix

  • Systems programming70%
  • Developer tooling30%

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Your next step

Review it, then add it to your workspace.

The board opens an editable draft; nothing is saved until you confirm it. Sign-in and workspace permissions apply, and Demo boards remain ephemeral.

Project context

A fictional desktop backup tool calls a small Rust compression library from Node.js. The binding leaks buffers on exceptions and treats ABI mismatches as corrupted input. Build against generated byte arrays and a local native library; no production archive format or user files are supplied.

Setup prerequisites

  • FFI ownership
  • Binary compatibility
  • Error handling

Preceding work

No earlier ticket is required. Complete the project setup above.

Acceptance criteria

  • Document owner for every input, output, error, and callback value
  • Each transfer has one release operation and allowed thread
  • Borrowed memory cannot outlive its originating call

Implementation constraints

  • Do not infer ownership from constness or language garbage collection.

Verification to include

  • Trace success and error paths through the ownership table.
  • Inject failure after native allocation and verify exactly one release.

Deliverables

  • FFI ownership contract and allocation counter test

Rollout and recovery

Keep the pure-language fallback until every path has an owner.

Value of the work

For the engineer: Practice language-boundary contracts, native resource safety and version negotiation.

For the team: Review a binding that fails safely and can be rolled back before native code enters additional application paths.

Evidence boundaries

Outcome Evidence: Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.

Ownership Evidence: Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.