feat(stack,runtime): per-shape actor stacks — Stack::new(reserve, guard), Config knobs, pool rule (RFC 019 §1)
Stack takes an explicit (reserve, guard) shape, both page-rounded and
stored; usable_base derives from the stored guard. Guard default raised
4 KiB -> 64 KiB (DEFAULT_STACK_GUARD): probestack makes one page enough
for Rust frames, but an unprobed C frame can leap a page in one sub rsp
— the motivating SQLite segfault. Reserve default stays 64 KiB
(DEFAULT_STACK_RESERVE); ACTOR_STACK_SIZE retired.
Config::{stack_reserve, stack_guard} thread the runtime defaults into
RuntimeInner pre-rounded. All acquisition/recycling now goes through
acquire_stack/recycle_stack carrying the pool rule: only default-shaped
stacks are pooled (pooled ⇒ default-shaped by induction); custom shapes
mmap fresh and munmap at death. Pool lock still dropped before any mmap.
No public spawn API change (SpawnOpts is the next commit).
Tests: shape rounding + accessors, wide-guard faults at both ends
(subprocess), Config::stack_reserve permits >64 KiB recursion that
previously could only segfault.
This commit is contained in:
+5
-5
@@ -23,7 +23,7 @@ extern "C-unwind" fn actor_simple() {
|
||||
#[test]
|
||||
fn actor_runs_and_returns_to_scheduler() {
|
||||
reset_log();
|
||||
let stack = Stack::new(64 * 1024).unwrap();
|
||||
let stack = Stack::new(64 * 1024, 4096).unwrap();
|
||||
let sp = init_actor_stack(stack.top(), actor_simple);
|
||||
set_actor_sp(sp);
|
||||
unsafe { switch_to_actor() };
|
||||
@@ -40,7 +40,7 @@ extern "C-unwind" fn actor_two_steps() {
|
||||
#[test]
|
||||
fn actor_yields_and_resumes() {
|
||||
reset_log();
|
||||
let stack = Stack::new(64 * 1024).unwrap();
|
||||
let stack = Stack::new(64 * 1024, 4096).unwrap();
|
||||
let sp = init_actor_stack(stack.top(), actor_two_steps);
|
||||
set_actor_sp(sp);
|
||||
|
||||
@@ -85,7 +85,7 @@ extern "C-unwind" fn actor_reg_check() {
|
||||
|
||||
#[test]
|
||||
fn callee_saved_registers_survive_yield() {
|
||||
let stack = Stack::new(64 * 1024).unwrap();
|
||||
let stack = Stack::new(64 * 1024, 4096).unwrap();
|
||||
let sp = init_actor_stack(stack.top(), actor_reg_check);
|
||||
set_actor_sp(sp);
|
||||
unsafe { switch_to_actor(); switch_to_actor(); }
|
||||
@@ -117,8 +117,8 @@ extern "C-unwind" fn actor_b() {
|
||||
|
||||
#[test]
|
||||
fn two_actors_dont_corrupt_each_other() {
|
||||
let stack_a = Stack::new(64 * 1024).unwrap();
|
||||
let stack_b = Stack::new(64 * 1024).unwrap();
|
||||
let stack_a = Stack::new(64 * 1024, 4096).unwrap();
|
||||
let stack_b = Stack::new(64 * 1024, 4096).unwrap();
|
||||
|
||||
let sp_a = init_actor_stack(stack_a.top(), actor_a);
|
||||
let sp_b = init_actor_stack(stack_b.top(), actor_b);
|
||||
|
||||
@@ -517,3 +517,35 @@ fn runtime_reusable_after_root_panic() {
|
||||
r.run(move || ran_t.store(true, Ordering::Relaxed));
|
||||
assert!(ran.load(Ordering::Relaxed), "runtime unusable after root panic");
|
||||
}
|
||||
|
||||
// ---------------------------------------------------------------------------
|
||||
// RFC 019 — Config stack knobs
|
||||
// ---------------------------------------------------------------------------
|
||||
|
||||
/// Burn ~`frames` × 4 KiB of stack; probestack touches pages in order so
|
||||
/// exceeding the reserve would hit the guard and SIGSEGV the process.
|
||||
#[inline(never)]
|
||||
fn burn_stack(frames: usize) -> u64 {
|
||||
let mut local = [0u8; 4096];
|
||||
local[0] = frames as u8;
|
||||
let below = if frames == 0 { 0 } else { burn_stack(frames - 1) };
|
||||
std::hint::black_box(&mut local);
|
||||
below.wrapping_add(local[0] as u64)
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn config_stack_reserve_permits_deep_recursion() {
|
||||
// ~256 KiB of frames: four times the old fixed 64 KiB reserve. With
|
||||
// Config::stack_reserve raised this must complete; before RFC 019 it
|
||||
// could only segfault.
|
||||
let rt = smarm::runtime::init(Config::exact(1).stack_reserve(1024 * 1024));
|
||||
let done = Arc::new(AtomicBool::new(false));
|
||||
let done2 = done.clone();
|
||||
rt.run(move || {
|
||||
spawn(move || {
|
||||
std::hint::black_box(burn_stack(64));
|
||||
done2.store(true, Ordering::SeqCst);
|
||||
}).join();
|
||||
});
|
||||
assert!(done.load(Ordering::SeqCst));
|
||||
}
|
||||
|
||||
+77
-9
@@ -7,13 +7,13 @@ use smarm::stack::Stack;
|
||||
|
||||
#[test]
|
||||
fn top_is_16_byte_aligned() {
|
||||
let s = Stack::new(64 * 1024).unwrap();
|
||||
let s = Stack::new(64 * 1024, 4096).unwrap();
|
||||
assert_eq!(s.top() as usize % 16, 0);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn top_is_within_allocation() {
|
||||
let s = Stack::new(64 * 1024).unwrap();
|
||||
let s = Stack::new(64 * 1024, 4096).unwrap();
|
||||
let top = s.top() as usize;
|
||||
let base = s.usable_base() as usize;
|
||||
assert!(top > base);
|
||||
@@ -22,7 +22,7 @@ fn top_is_within_allocation() {
|
||||
|
||||
#[test]
|
||||
fn write_and_read_top_of_stack() {
|
||||
let s = Stack::new(64 * 1024).unwrap();
|
||||
let s = Stack::new(64 * 1024, 4096).unwrap();
|
||||
let sentinel: u64 = 0xDEAD_BEEF_CAFE_1234;
|
||||
unsafe {
|
||||
let ptr = s.top().sub(8) as *mut u64;
|
||||
@@ -33,7 +33,7 @@ fn write_and_read_top_of_stack() {
|
||||
|
||||
#[test]
|
||||
fn write_and_read_bottom_of_usable_region() {
|
||||
let s = Stack::new(64 * 1024).unwrap();
|
||||
let s = Stack::new(64 * 1024, 4096).unwrap();
|
||||
let sentinel: u64 = 0x0102_0304_0506_0708;
|
||||
unsafe {
|
||||
let ptr = s.usable_base() as *mut u64;
|
||||
@@ -44,17 +44,17 @@ fn write_and_read_bottom_of_usable_region() {
|
||||
|
||||
#[test]
|
||||
fn small_stack_allocates() {
|
||||
assert!(Stack::new(4096).is_ok());
|
||||
assert!(Stack::new(4096, 4096).is_ok());
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn large_stack_allocates() {
|
||||
assert!(Stack::new(8 * 1024 * 1024).is_ok());
|
||||
assert!(Stack::new(8 * 1024 * 1024, 4096).is_ok());
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn stack_size_at_least_requested() {
|
||||
let s = Stack::new(64 * 1024).unwrap();
|
||||
let s = Stack::new(64 * 1024, 4096).unwrap();
|
||||
assert!(s.stack_size() >= 64 * 1024);
|
||||
}
|
||||
|
||||
@@ -68,15 +68,28 @@ use std::process::Command;
|
||||
fn run_as_child_if_requested() {
|
||||
match env::var("SMARM_SUBTEST").as_deref() {
|
||||
Ok("guard_page_direct") => {
|
||||
let s = Stack::new(64 * 1024).unwrap();
|
||||
let s = Stack::new(64 * 1024, 4096).unwrap();
|
||||
unsafe {
|
||||
let guard_ptr = s.usable_base().sub(1);
|
||||
guard_ptr.write_volatile(0xAB);
|
||||
}
|
||||
std::process::exit(0);
|
||||
}
|
||||
Ok("wide_guard_top") => {
|
||||
// One byte below the usable region, 64 KiB guard: must fault.
|
||||
let s = Stack::new(64 * 1024, 64 * 1024).unwrap();
|
||||
unsafe { s.usable_base().sub(1).write_volatile(0xAB); }
|
||||
std::process::exit(0);
|
||||
}
|
||||
Ok("wide_guard_bottom") => {
|
||||
// The very bottom page of a 64 KiB guard: an unprobed C-style
|
||||
// leap over a small guard lands here — must still fault.
|
||||
let s = Stack::new(64 * 1024, 64 * 1024).unwrap();
|
||||
unsafe { s.usable_base().sub(64 * 1024).write_volatile(0xAB); }
|
||||
std::process::exit(0);
|
||||
}
|
||||
Ok("stack_overflow") => {
|
||||
let s = Stack::new(64 * 1024).unwrap();
|
||||
let s = Stack::new(64 * 1024, 4096).unwrap();
|
||||
unsafe {
|
||||
let mut ptr = s.top().sub(1);
|
||||
let stop = s.usable_base().sub(1);
|
||||
@@ -121,3 +134,58 @@ fn stack_overflow_causes_sigsegv() {
|
||||
assert_eq!(status.signal(), Some(11), "expected SIGSEGV, got: {:?}", status);
|
||||
}
|
||||
}
|
||||
|
||||
// ---------------------------------------------------------------------------
|
||||
// RFC 019 — explicit shape: rounding, guard accessor, wide-guard coverage.
|
||||
// ---------------------------------------------------------------------------
|
||||
|
||||
#[test]
|
||||
fn sizes_round_up_to_page() {
|
||||
let s = Stack::new(64 * 1024 + 1, 4096 + 1).unwrap();
|
||||
assert_eq!(s.stack_size() % 4096, 0);
|
||||
assert_eq!(s.guard_size() % 4096, 0);
|
||||
assert!(s.stack_size() >= 64 * 1024 + 1);
|
||||
assert!(s.guard_size() >= 4096 + 1);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn shape_reports_rounded_sizes() {
|
||||
let s = Stack::new(64 * 1024, 64 * 1024).unwrap();
|
||||
assert_eq!(s.shape(), (64 * 1024, 64 * 1024));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn usable_base_sits_above_guard() {
|
||||
let s = Stack::new(64 * 1024, 64 * 1024).unwrap();
|
||||
// The usable region must start exactly guard_size above the mapping
|
||||
// base: a write at usable_base is legal, one byte below is not (the
|
||||
// subprocess tests below prove the "not").
|
||||
let sentinel: u64 = 0x1111_2222_3333_4444;
|
||||
unsafe {
|
||||
let ptr = s.usable_base() as *mut u64;
|
||||
ptr.write_volatile(sentinel);
|
||||
assert_eq!(ptr.read_volatile(), sentinel);
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn wide_guard_faults_at_top() {
|
||||
run_as_child_if_requested();
|
||||
let status = spawn_subtest("wide_guard_top");
|
||||
#[cfg(unix)]
|
||||
{
|
||||
use std::os::unix::process::ExitStatusExt;
|
||||
assert_eq!(status.signal(), Some(11), "expected SIGSEGV, got: {:?}", status);
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn wide_guard_faults_at_bottom() {
|
||||
run_as_child_if_requested();
|
||||
let status = spawn_subtest("wide_guard_bottom");
|
||||
#[cfg(unix)]
|
||||
{
|
||||
use std::os::unix::process::ExitStatusExt;
|
||||
assert_eq!(status.signal(), Some(11), "expected SIGSEGV, got: {:?}", status);
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user