- src/signal.rs: process-global SA_SIGINFO|SA_ONSTACK handler installed once
at runtime::init (before any scheduler thread -> unracing PRIOR save);
per-scheduler-thread 64 KiB sigaltstack registered at schedule_loop entry
(a guard hit leaves no stack to handle on). Async-signal-safe throughout:
classification is plain loads (const-init TLS Cell + slot atomics), print
is fixed-buffer itoa + one write(2), death is SIG_DFL + refault at the
same instruction (core-dumpable, correct wait status).
- Two-tier classification (agreed): in-guard = definitive; OVERSHOOT window
below the guard = 'unprobed (FFI?) frame stepped over it' probable
attribution -- the RFC's motivating incident (cargo-vendored gz, not
SQLite as the RFC text says) faults there under a small guard. Pure
classify() fn, 5 adversarial units incl. saturation at low addresses.
- DEFAULT_STACK_GUARD 64 KiB -> 1 MiB (agreed): kernel stack_guard_gap
anchor post-Stack-Clash; PROT_NONE is VA-only (no RSS, no page tables,
no overcommit charge) so width is free at any actor count.
- Unclassified faults reinstate the PRIOR sigaction and refault (agreed):
std's own OS-thread overflow diagnostics survive our presence.
- Slot: diag_{stack_top,stack_reserve,stack_guard,pid} atomics written in
install_actor pre-publish; readable without the cold lock (Stack lives
under it); only consulted while CURRENT_SLOT points at the slot, so
never stale where read. preempt::current_slot_ptr ungated from
smarm-causal (now also the classifier's anchor).
- build.rs + cc (agreed Q3): canary/canary.c, 96 KiB local touched low-end
first, -fno-stack-clash-protection pinned so hardened toolchains don't
probe the canary into uselessness.
- tests/stack_diag.rs: subprocess x4 -- Rust recursion tier-1; FFI canary
tier-1 at defaults (1 MiB guard catches the jump); tier-2 at guard=4 KiB
('stepped over', reproduces the incident); clean at reserve=256 KiB
(the §1 knob is the fix, same frame).
FLAGGED (Claude-solo calls):
- OVERSHOOT_SLOP = 1 MiB (matches guard default/kernel gap; beyond it
attribution would be dishonest).
- Altstack 64 KiB, mmap'd once per OS thread, never freed (bounded by
thread count; reused across run()s via TLS flag).
- Foreign-fault reinstate permanently deregisters our handler; accepted --
the process is dying either way.
- Diag geometry as 4 slot atomics (install-time cost only) over a per-switch
TLS snapshot (hot-path stores).
111 lines
2.7 KiB
TOML
111 lines
2.7 KiB
TOML
[package]
|
||
name = "smarm"
|
||
version = "0.5.0"
|
||
edition = "2021"
|
||
rust-version = "1.95"
|
||
|
||
[lints.rust]
|
||
unexpected_cfgs = { level = "warn", check-cfg = ["cfg(loom)"] }
|
||
|
||
[lints.clippy]
|
||
# Library code must never hide a panic behind unwrap/expect. Both are denied; an
|
||
# intentional panic is written explicitly as `match { Err(e) => panic!(..) }`.
|
||
# panic!/unreachable! are deliberately left un-linted as the blessed explicit
|
||
# form. Enforced on the library target only (`cargo clippy --lib`); tests and
|
||
# examples unwrap freely and are not gated.
|
||
unwrap_used = "deny"
|
||
expect_used = "deny"
|
||
|
||
[features]
|
||
default = ["rq-mutex"]
|
||
smarm-trace = []
|
||
# RFC 007: native causal profiling. Zero cost when off (cf. smarm-trace): the
|
||
# hook in `maybe_preempt` and the resume-path fast-forward compile away; the
|
||
# two Slot ledger fields exist regardless and stay 0 (budget_cycles precedent).
|
||
smarm-causal = []
|
||
# RFC 016 Chunk 2: cycle-accurate per-actor time-budget accounting. Off by
|
||
# default — it costs two extra RDTSC reads per actor resume on the hot path
|
||
# (D6). The `ActorInfo.budget_cycles` field exists regardless; it just stays 0
|
||
# unless this is enabled.
|
||
budget-accounting = []
|
||
# RFC 016 Chunk 4: the live observer gen_server (src/observer.rs). Off by
|
||
# default (DECISION D10) — the read primitive (Chunks 1–3) is always present
|
||
# and unflagged; only the optional gen_server transport sits behind this, so a
|
||
# release build pays nothing for an observer it never starts.
|
||
observer = []
|
||
# Run-queue selection: exactly one, compile-time (see src/run_queue.rs).
|
||
# Non-default variants need --no-default-features (features are additive).
|
||
rq-mutex = []
|
||
rq-mpmc = []
|
||
rq-striped = []
|
||
|
||
[build-dependencies]
|
||
cc = "1"
|
||
|
||
[dependencies]
|
||
libc = "0.2"
|
||
|
||
[target.'cfg(loom)'.dependencies]
|
||
loom = "0.7"
|
||
|
||
[dev-dependencies]
|
||
libc = "0.2"
|
||
tokio = { version = "1", features = ["rt", "rt-multi-thread", "macros", "sync", "time"] }
|
||
|
||
[profile.dev]
|
||
panic = "unwind"
|
||
|
||
[profile.release]
|
||
panic = "unwind"
|
||
lto = "thin"
|
||
codegen-units = 1
|
||
|
||
[[bench]]
|
||
name = "primes"
|
||
harness = false
|
||
|
||
[[bench]]
|
||
name = "multi_scheduler"
|
||
harness = false
|
||
|
||
[[bench]]
|
||
name = "general"
|
||
harness = false
|
||
|
||
[[bench]]
|
||
name = "smarm_favored"
|
||
harness = false
|
||
|
||
[[bench]]
|
||
name = "tokio_favored"
|
||
harness = false
|
||
|
||
[[bench]]
|
||
name = "rq_micro"
|
||
harness = false
|
||
|
||
[[bench]]
|
||
name = "rq_runtime"
|
||
harness = false
|
||
|
||
[[bench]]
|
||
name = "switch_cost"
|
||
harness = false
|
||
|
||
# RFC 016 Chunk 4 — the live observer dump. Needs the optional gen_server.
|
||
[[example]]
|
||
name = "observer"
|
||
required-features = ["observer"]
|
||
|
||
[[example]]
|
||
name = "causal_pipeline"
|
||
required-features = ["smarm-causal"]
|
||
|
||
[[example]]
|
||
name = "causal_attrib_probe"
|
||
required-features = ["smarm-causal"]
|
||
|
||
[[example]]
|
||
name = "causal_probe"
|
||
required-features = ["smarm-causal"]
|