The primitives whose hand-rolled versions caused the bugs.
github.com/sjgant80-hub/fallhardened →Four adversarial audit passes across the estate's engines found the same classes of bug over and over — and nearly every one came from re-implementing a primitive by hand and getting it subtly wrong. This module is the one correct implementation of each, so a build imports it instead of re-inventing the sharp edge.
| Hand-rolled bug the audits found | Primitive that fixes it |
|---|---|
| A 32-bit content hash that collided by ~65k items and silently cross-bound content | strongHash |
String(obj) flattening every object to "[object Object]" | strongHash · safeString |
| verify() throwing on null / BigInt / circular / a toxic getter | guard(fn, fallback) |
| localeCompare ordering Unicode-equal keys differently per machine, breaking a seal | codeCompare · byKey |
| An id suffix that could itself re-collide with a crafted id | uniqueId |
| Consistent-hash ring positions from a weak/biased hash | unitHash |
import { strongHash, guard, safeString, codeCompare, uniqueId, unitHash } from 'fallhardened';
strongHash({ any: 'content' }) // 128-bit hex; THROWS on circular/BigInt so the caller isolates it
guard(verify, { valid: false }) // verify() that returns the fallback instead of throwing (sync OR async)
safeString(toxic) // '' even if toString() throws — never a crash, never "[object Object]"
codeCompare(a, b) // -1|0|1 by code unit — locale-independent, seal-safe
uniqueId('node', usedSet) // an id not in the set, disambiguated by a suffix that loops until unique
The audit lesson was not "these functions had bugs" — it was that every engine re-derived them and each re-derivation reintroduced a different subtle failure. One audited, fuzzed, mutation-tested implementation, imported everywhere, files the sharp edge off once. A new failure mode is fixed here, and the whole estate inherits the fix. Verified by witness.