V12
Critical #1: duplicate shard workers. A shard queues a lookup, then a wait. With one worker per shard, consuming the wait proves the lookup finished. But the enclave doesn't prevent us from spawning a duplicate: 1. Worker A starts a lookup. 2. Worker B consumes the wait. 3. The query frees its result buffer. 4. Worker A resumes and writes 56 bytes into freed memory. We groom the heap to reuse the freed memory as a protobuf workspace, replacing a pointer and length with host-chosen values. The protobuf encoder in a normal client response path then copies out the bytes we selected.