t_futex_robust.c revision 1.2 1 1.2 thorpej /* $NetBSD: t_futex_robust.c,v 1.2 2020/05/01 01:44:30 thorpej Exp $ */
2 1.1 thorpej
3 1.1 thorpej /*-
4 1.1 thorpej * Copyright (c) 2019 The NetBSD Foundation, Inc.
5 1.1 thorpej * All rights reserved.
6 1.1 thorpej *
7 1.1 thorpej * Redistribution and use in source and binary forms, with or without
8 1.1 thorpej * modification, are permitted provided that the following conditions
9 1.1 thorpej * are met:
10 1.1 thorpej * 1. Redistributions of source code must retain the above copyright
11 1.1 thorpej * notice, this list of conditions and the following disclaimer.
12 1.1 thorpej * 2. Redistributions in binary form must reproduce the above copyright
13 1.1 thorpej * notice, this list of conditions and the following disclaimer in the
14 1.1 thorpej * documentation and/or other materials provided with the distribution.
15 1.1 thorpej *
16 1.1 thorpej * THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS
17 1.1 thorpej * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
18 1.1 thorpej * TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
19 1.1 thorpej * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS
20 1.1 thorpej * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
21 1.1 thorpej * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
22 1.1 thorpej * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
23 1.1 thorpej * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
24 1.1 thorpej * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
25 1.1 thorpej * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
26 1.1 thorpej * POSSIBILITY OF SUCH DAMAGE.
27 1.1 thorpej */
28 1.1 thorpej
29 1.1 thorpej #include <sys/cdefs.h>
30 1.1 thorpej __COPYRIGHT("@(#) Copyright (c) 2019\
31 1.1 thorpej The NetBSD Foundation, inc. All rights reserved.");
32 1.2 thorpej __RCSID("$NetBSD: t_futex_robust.c,v 1.2 2020/05/01 01:44:30 thorpej Exp $");
33 1.1 thorpej
34 1.1 thorpej #include <sys/mman.h>
35 1.1 thorpej #include <errno.h>
36 1.1 thorpej #include <lwp.h>
37 1.1 thorpej #include <stdio.h>
38 1.1 thorpej #include <time.h>
39 1.1 thorpej
40 1.1 thorpej #include <atf-c.h>
41 1.1 thorpej
42 1.1 thorpej #include <libc/include/futex_private.h>
43 1.1 thorpej
44 1.1 thorpej #define STACK_SIZE 65536
45 1.1 thorpej #define NLOCKS 16
46 1.1 thorpej
47 1.1 thorpej struct futex_lock_pos {
48 1.1 thorpej struct futex_robust_list list;
49 1.1 thorpej int fword;
50 1.1 thorpej };
51 1.1 thorpej struct futex_lock_pos pos_locks[NLOCKS];
52 1.1 thorpej
53 1.1 thorpej struct futex_lock_neg {
54 1.1 thorpej int fword;
55 1.1 thorpej struct futex_robust_list list;
56 1.1 thorpej };
57 1.1 thorpej struct futex_lock_neg neg_locks[NLOCKS];
58 1.1 thorpej
59 1.1 thorpej struct lwp_data {
60 1.1 thorpej ucontext_t context;
61 1.1 thorpej void *stack_base;
62 1.1 thorpej lwpid_t lwpid;
63 1.1 thorpej lwpid_t threadid;
64 1.1 thorpej struct futex_robust_list_head rhead;
65 1.1 thorpej
66 1.1 thorpej /* Results to be asserted by main thread. */
67 1.1 thorpej bool set_robust_list_failed;
68 1.1 thorpej };
69 1.1 thorpej
70 1.1 thorpej struct lwp_data lwp_data;
71 1.1 thorpej
72 1.1 thorpej static void
73 1.1 thorpej setup_lwp_context(void (*func)(void *))
74 1.1 thorpej {
75 1.1 thorpej
76 1.1 thorpej memset(&lwp_data, 0, sizeof(lwp_data));
77 1.1 thorpej lwp_data.stack_base = mmap(NULL, STACK_SIZE,
78 1.1 thorpej PROT_READ | PROT_WRITE,
79 1.1 thorpej MAP_ANON | MAP_STACK | MAP_PRIVATE, -1, 0);
80 1.1 thorpej ATF_REQUIRE(lwp_data.stack_base != MAP_FAILED);
81 1.1 thorpej _lwp_makecontext(&lwp_data.context, func,
82 1.1 thorpej &lwp_data, NULL, lwp_data.stack_base, STACK_SIZE);
83 1.1 thorpej lwp_data.threadid = 0;
84 1.1 thorpej }
85 1.1 thorpej
86 1.1 thorpej static void
87 1.1 thorpej do_cleanup(void)
88 1.1 thorpej {
89 1.1 thorpej if (lwp_data.stack_base != NULL &&
90 1.1 thorpej lwp_data.stack_base != MAP_FAILED) {
91 1.1 thorpej (void) munmap(lwp_data.stack_base, STACK_SIZE);
92 1.1 thorpej }
93 1.1 thorpej memset(&lwp_data, 0, sizeof(lwp_data));
94 1.1 thorpej memset(pos_locks, 0, sizeof(pos_locks));
95 1.1 thorpej memset(neg_locks, 0, sizeof(neg_locks));
96 1.1 thorpej }
97 1.1 thorpej
98 1.1 thorpej static void
99 1.1 thorpej test_pos_robust_list(void *arg)
100 1.1 thorpej {
101 1.1 thorpej struct lwp_data *d = arg;
102 1.1 thorpej int i;
103 1.1 thorpej
104 1.1 thorpej d->rhead.list.next = &d->rhead.list;
105 1.1 thorpej d->rhead.futex_offset = offsetof(struct futex_lock_pos, fword) -
106 1.1 thorpej offsetof(struct futex_lock_pos, list);
107 1.1 thorpej d->rhead.pending_list = NULL;
108 1.1 thorpej
109 1.1 thorpej if (__futex_set_robust_list(&d->rhead, sizeof(d->rhead)) != 0) {
110 1.1 thorpej d->set_robust_list_failed = true;
111 1.1 thorpej _lwp_exit();
112 1.1 thorpej }
113 1.1 thorpej
114 1.1 thorpej memset(pos_locks, 0, sizeof(pos_locks));
115 1.1 thorpej
116 1.1 thorpej d->threadid = _lwp_self();
117 1.1 thorpej
118 1.1 thorpej for (i = 0; i < NLOCKS-1; i++) {
119 1.1 thorpej pos_locks[i].fword = _lwp_self();
120 1.1 thorpej pos_locks[i].list.next = d->rhead.list.next;
121 1.1 thorpej d->rhead.list.next = &pos_locks[i].list;
122 1.1 thorpej }
123 1.1 thorpej
124 1.1 thorpej pos_locks[i].fword = _lwp_self();
125 1.1 thorpej d->rhead.pending_list = &pos_locks[i].list;
126 1.1 thorpej
127 1.1 thorpej _lwp_exit();
128 1.1 thorpej }
129 1.1 thorpej
130 1.1 thorpej static void
131 1.1 thorpej test_neg_robust_list(void *arg)
132 1.1 thorpej {
133 1.1 thorpej struct lwp_data *d = arg;
134 1.1 thorpej int i;
135 1.1 thorpej
136 1.1 thorpej d->rhead.list.next = &d->rhead.list;
137 1.1 thorpej d->rhead.futex_offset = offsetof(struct futex_lock_neg, fword) -
138 1.1 thorpej offsetof(struct futex_lock_neg, list);
139 1.1 thorpej d->rhead.pending_list = NULL;
140 1.1 thorpej
141 1.1 thorpej if (__futex_set_robust_list(&d->rhead, sizeof(d->rhead)) != 0) {
142 1.1 thorpej d->set_robust_list_failed = true;
143 1.1 thorpej _lwp_exit();
144 1.1 thorpej }
145 1.1 thorpej
146 1.1 thorpej memset(neg_locks, 0, sizeof(neg_locks));
147 1.1 thorpej
148 1.1 thorpej d->threadid = _lwp_self();
149 1.1 thorpej
150 1.1 thorpej for (i = 0; i < NLOCKS-1; i++) {
151 1.1 thorpej neg_locks[i].fword = _lwp_self();
152 1.1 thorpej neg_locks[i].list.next = d->rhead.list.next;
153 1.1 thorpej d->rhead.list.next = &neg_locks[i].list;
154 1.1 thorpej }
155 1.1 thorpej
156 1.1 thorpej neg_locks[i].fword = _lwp_self();
157 1.1 thorpej d->rhead.pending_list = &neg_locks[i].list;
158 1.1 thorpej
159 1.1 thorpej _lwp_exit();
160 1.1 thorpej }
161 1.1 thorpej
162 1.1 thorpej static void
163 1.1 thorpej test_unmapped_robust_list(void *arg)
164 1.1 thorpej {
165 1.1 thorpej struct lwp_data *d = arg;
166 1.1 thorpej
167 1.1 thorpej d->rhead.list.next = &d->rhead.list;
168 1.1 thorpej d->rhead.futex_offset = offsetof(struct futex_lock_pos, fword) -
169 1.1 thorpej offsetof(struct futex_lock_pos, list);
170 1.1 thorpej d->rhead.pending_list = NULL;
171 1.1 thorpej
172 1.1 thorpej if (__futex_set_robust_list((void *)sizeof(d->rhead),
173 1.1 thorpej sizeof(d->rhead)) != 0) {
174 1.1 thorpej d->set_robust_list_failed = true;
175 1.1 thorpej _lwp_exit();
176 1.1 thorpej }
177 1.1 thorpej
178 1.1 thorpej memset(pos_locks, 0, sizeof(pos_locks));
179 1.1 thorpej
180 1.1 thorpej d->threadid = _lwp_self();
181 1.1 thorpej
182 1.1 thorpej _lwp_exit();
183 1.1 thorpej }
184 1.1 thorpej
185 1.1 thorpej static void
186 1.1 thorpej test_evil_circular_robust_list(void *arg)
187 1.1 thorpej {
188 1.1 thorpej struct lwp_data *d = arg;
189 1.1 thorpej int i;
190 1.1 thorpej
191 1.1 thorpej d->rhead.list.next = &d->rhead.list;
192 1.1 thorpej d->rhead.futex_offset = offsetof(struct futex_lock_pos, fword) -
193 1.1 thorpej offsetof(struct futex_lock_pos, list);
194 1.1 thorpej d->rhead.pending_list = NULL;
195 1.1 thorpej
196 1.1 thorpej if (__futex_set_robust_list(&d->rhead, sizeof(d->rhead)) != 0) {
197 1.1 thorpej d->set_robust_list_failed = true;
198 1.1 thorpej _lwp_exit();
199 1.1 thorpej }
200 1.1 thorpej
201 1.1 thorpej memset(pos_locks, 0, sizeof(pos_locks));
202 1.1 thorpej
203 1.1 thorpej d->threadid = _lwp_self();
204 1.1 thorpej
205 1.1 thorpej for (i = 0; i < NLOCKS; i++) {
206 1.1 thorpej pos_locks[i].fword = _lwp_self();
207 1.1 thorpej pos_locks[i].list.next = d->rhead.list.next;
208 1.1 thorpej d->rhead.list.next = &pos_locks[i].list;
209 1.1 thorpej }
210 1.1 thorpej
211 1.1 thorpej /* Make a loop. */
212 1.1 thorpej pos_locks[0].list.next = pos_locks[NLOCKS-1].list.next;
213 1.1 thorpej
214 1.1 thorpej _lwp_exit();
215 1.1 thorpej }
216 1.1 thorpej
217 1.1 thorpej static void
218 1.1 thorpej test_bad_pending_robust_list(void *arg)
219 1.1 thorpej {
220 1.1 thorpej struct lwp_data *d = arg;
221 1.1 thorpej int i;
222 1.1 thorpej
223 1.1 thorpej d->rhead.list.next = &d->rhead.list;
224 1.1 thorpej d->rhead.futex_offset = offsetof(struct futex_lock_pos, fword) -
225 1.1 thorpej offsetof(struct futex_lock_pos, list);
226 1.1 thorpej d->rhead.pending_list = NULL;
227 1.1 thorpej
228 1.1 thorpej if (__futex_set_robust_list(&d->rhead, sizeof(d->rhead)) != 0) {
229 1.1 thorpej d->set_robust_list_failed = true;
230 1.1 thorpej _lwp_exit();
231 1.1 thorpej }
232 1.1 thorpej
233 1.1 thorpej memset(pos_locks, 0, sizeof(pos_locks));
234 1.1 thorpej
235 1.1 thorpej d->threadid = _lwp_self();
236 1.1 thorpej
237 1.1 thorpej for (i = 0; i < NLOCKS; i++) {
238 1.1 thorpej pos_locks[i].fword = _lwp_self();
239 1.1 thorpej pos_locks[i].list.next = d->rhead.list.next;
240 1.1 thorpej d->rhead.list.next = &pos_locks[i].list;
241 1.1 thorpej }
242 1.1 thorpej
243 1.1 thorpej d->rhead.pending_list = (void *)sizeof(d->rhead);
244 1.1 thorpej
245 1.1 thorpej _lwp_exit();
246 1.1 thorpej }
247 1.1 thorpej
248 1.1 thorpej ATF_TC_WITH_CLEANUP(futex_robust_positive);
249 1.1 thorpej ATF_TC_HEAD(futex_robust_positive, tc)
250 1.1 thorpej {
251 1.1 thorpej atf_tc_set_md_var(tc, "descr",
252 1.1 thorpej "checks futex robust list with positive futex word offset");
253 1.1 thorpej }
254 1.1 thorpej
255 1.1 thorpej ATF_TC_BODY(futex_robust_positive, tc)
256 1.1 thorpej {
257 1.1 thorpej int i;
258 1.1 thorpej
259 1.1 thorpej setup_lwp_context(test_pos_robust_list);
260 1.1 thorpej
261 1.1 thorpej ATF_REQUIRE(_lwp_create(&lwp_data.context, 0, &lwp_data.lwpid) == 0);
262 1.1 thorpej ATF_REQUIRE(_lwp_wait(lwp_data.lwpid, NULL) == 0);
263 1.1 thorpej
264 1.1 thorpej ATF_REQUIRE(lwp_data.set_robust_list_failed == false);
265 1.1 thorpej
266 1.1 thorpej for (i = 0; i < NLOCKS; i++) {
267 1.1 thorpej ATF_REQUIRE((pos_locks[i].fword & FUTEX_TID_MASK) ==
268 1.1 thorpej lwp_data.threadid);
269 1.1 thorpej ATF_REQUIRE((pos_locks[i].fword & FUTEX_OWNER_DIED) != 0);
270 1.1 thorpej }
271 1.1 thorpej }
272 1.1 thorpej
273 1.1 thorpej ATF_TC_CLEANUP(futex_robust_positive, tc)
274 1.1 thorpej {
275 1.1 thorpej do_cleanup();
276 1.1 thorpej }
277 1.1 thorpej
278 1.1 thorpej ATF_TC_WITH_CLEANUP(futex_robust_negative);
279 1.1 thorpej ATF_TC_HEAD(futex_robust_negative, tc)
280 1.1 thorpej {
281 1.1 thorpej atf_tc_set_md_var(tc, "descr",
282 1.1 thorpej "checks futex robust list with negative futex word offset");
283 1.1 thorpej }
284 1.1 thorpej
285 1.1 thorpej ATF_TC_BODY(futex_robust_negative, tc)
286 1.1 thorpej {
287 1.1 thorpej int i;
288 1.1 thorpej
289 1.1 thorpej setup_lwp_context(test_neg_robust_list);
290 1.1 thorpej
291 1.1 thorpej ATF_REQUIRE(_lwp_create(&lwp_data.context, 0, &lwp_data.lwpid) == 0);
292 1.1 thorpej ATF_REQUIRE(_lwp_wait(lwp_data.lwpid, NULL) == 0);
293 1.1 thorpej
294 1.1 thorpej ATF_REQUIRE(lwp_data.set_robust_list_failed == false);
295 1.1 thorpej
296 1.1 thorpej for (i = 0; i < NLOCKS; i++) {
297 1.1 thorpej ATF_REQUIRE((neg_locks[i].fword & FUTEX_TID_MASK) ==
298 1.1 thorpej lwp_data.threadid);
299 1.1 thorpej ATF_REQUIRE((neg_locks[i].fword & FUTEX_OWNER_DIED) != 0);
300 1.1 thorpej }
301 1.1 thorpej }
302 1.1 thorpej
303 1.1 thorpej ATF_TC_CLEANUP(futex_robust_negative, tc)
304 1.1 thorpej {
305 1.1 thorpej do_cleanup();
306 1.1 thorpej }
307 1.1 thorpej
308 1.1 thorpej ATF_TC_WITH_CLEANUP(futex_robust_unmapped);
309 1.1 thorpej ATF_TC_HEAD(futex_robust_unmapped, tc)
310 1.1 thorpej {
311 1.1 thorpej atf_tc_set_md_var(tc, "descr",
312 1.1 thorpej "checks futex robust list with unmapped robust list pointer");
313 1.1 thorpej }
314 1.1 thorpej
315 1.1 thorpej ATF_TC_BODY(futex_robust_unmapped, tc)
316 1.1 thorpej {
317 1.1 thorpej
318 1.1 thorpej setup_lwp_context(test_unmapped_robust_list);
319 1.1 thorpej
320 1.1 thorpej ATF_REQUIRE(_lwp_create(&lwp_data.context, 0, &lwp_data.lwpid) == 0);
321 1.1 thorpej ATF_REQUIRE(_lwp_wait(lwp_data.lwpid, NULL) == 0);
322 1.1 thorpej
323 1.1 thorpej ATF_REQUIRE(lwp_data.set_robust_list_failed == false);
324 1.1 thorpej
325 1.1 thorpej /*
326 1.1 thorpej * No additional validation; just exercises a code path
327 1.1 thorpej * in the kernel.
328 1.1 thorpej */
329 1.1 thorpej }
330 1.1 thorpej
331 1.1 thorpej ATF_TC_CLEANUP(futex_robust_unmapped, tc)
332 1.1 thorpej {
333 1.1 thorpej do_cleanup();
334 1.1 thorpej }
335 1.1 thorpej
336 1.1 thorpej ATF_TC_WITH_CLEANUP(futex_robust_evil_circular);
337 1.1 thorpej ATF_TC_HEAD(futex_robust_evil_circular, tc)
338 1.1 thorpej {
339 1.1 thorpej atf_tc_set_md_var(tc, "descr",
340 1.1 thorpej "checks futex robust list processing faced with a deliberately "
341 1.1 thorpej "ciruclar list");
342 1.1 thorpej }
343 1.1 thorpej
344 1.1 thorpej ATF_TC_BODY(futex_robust_evil_circular, tc)
345 1.1 thorpej {
346 1.1 thorpej int i;
347 1.1 thorpej
348 1.1 thorpej setup_lwp_context(test_evil_circular_robust_list);
349 1.1 thorpej
350 1.1 thorpej ATF_REQUIRE(_lwp_create(&lwp_data.context, 0, &lwp_data.lwpid) == 0);
351 1.1 thorpej ATF_REQUIRE(_lwp_wait(lwp_data.lwpid, NULL) == 0);
352 1.1 thorpej
353 1.1 thorpej ATF_REQUIRE(lwp_data.set_robust_list_failed == false);
354 1.1 thorpej
355 1.1 thorpej for (i = 0; i < NLOCKS; i++) {
356 1.1 thorpej ATF_REQUIRE((pos_locks[i].fword & FUTEX_TID_MASK) ==
357 1.1 thorpej lwp_data.threadid);
358 1.1 thorpej ATF_REQUIRE((pos_locks[i].fword & FUTEX_OWNER_DIED) != 0);
359 1.1 thorpej }
360 1.1 thorpej }
361 1.1 thorpej
362 1.1 thorpej ATF_TC_CLEANUP(futex_robust_evil_circular, tc)
363 1.1 thorpej {
364 1.1 thorpej do_cleanup();
365 1.1 thorpej }
366 1.1 thorpej
367 1.1 thorpej ATF_TC_WITH_CLEANUP(futex_robust_bad_pending);
368 1.1 thorpej ATF_TC_HEAD(futex_robust_bad_pending, tc)
369 1.1 thorpej {
370 1.1 thorpej atf_tc_set_md_var(tc, "descr",
371 1.1 thorpej "checks futex robust list processing with a bad pending pointer");
372 1.1 thorpej }
373 1.1 thorpej
374 1.1 thorpej ATF_TC_BODY(futex_robust_bad_pending, tc)
375 1.1 thorpej {
376 1.1 thorpej int i;
377 1.1 thorpej
378 1.1 thorpej setup_lwp_context(test_bad_pending_robust_list);
379 1.1 thorpej
380 1.1 thorpej ATF_REQUIRE(_lwp_create(&lwp_data.context, 0, &lwp_data.lwpid) == 0);
381 1.1 thorpej ATF_REQUIRE(_lwp_wait(lwp_data.lwpid, NULL) == 0);
382 1.1 thorpej
383 1.1 thorpej ATF_REQUIRE(lwp_data.set_robust_list_failed == false);
384 1.1 thorpej
385 1.1 thorpej for (i = 0; i < NLOCKS; i++) {
386 1.1 thorpej ATF_REQUIRE((pos_locks[i].fword & FUTEX_TID_MASK) ==
387 1.1 thorpej lwp_data.threadid);
388 1.1 thorpej ATF_REQUIRE((pos_locks[i].fword & FUTEX_OWNER_DIED) != 0);
389 1.1 thorpej }
390 1.1 thorpej }
391 1.1 thorpej
392 1.1 thorpej ATF_TC_CLEANUP(futex_robust_bad_pending, tc)
393 1.1 thorpej {
394 1.1 thorpej do_cleanup();
395 1.1 thorpej }
396 1.1 thorpej
397 1.1 thorpej ATF_TP_ADD_TCS(tp)
398 1.1 thorpej {
399 1.1 thorpej ATF_TP_ADD_TC(tp, futex_robust_positive);
400 1.1 thorpej ATF_TP_ADD_TC(tp, futex_robust_negative);
401 1.1 thorpej ATF_TP_ADD_TC(tp, futex_robust_unmapped);
402 1.1 thorpej ATF_TP_ADD_TC(tp, futex_robust_evil_circular);
403 1.1 thorpej ATF_TP_ADD_TC(tp, futex_robust_bad_pending);
404 1.1 thorpej
405 1.1 thorpej return atf_no_error();
406 1.1 thorpej }
407