Repository navigation
Report native stack overflows on every thread #40169
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
robobun
wants to merge
11
commits into
main
Choose a base branch
from
farm/75562ee0/report-native-stack-overflow
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
Changes from all commits
Commits
Show all changes
11 commits
Select commit
Hold shift + click to select a range
9f33df9
Report native stack overflows on every thread and stop the fs.watch a…
robobun 5637560
fs.watch tests: create and remove the deep chains in the test process…
robobun 721bc36
Classify only data faults inside the entered frame as a stack overflo…
robobun f1a0ff1
crash handler tests: no core dump from the two classification tests
robobun 35559a2
fs.watch walk: return the open error from enter, decide at the call site
robobun d482fb1
JSC installs its signal handler with SA_ONSTACK: pin that WebKit buil…
robobun ea85ca0
The compile cache thread registers an alternate signal stack
robobun fe828d1
crash handler tests: an out-of-bounds WebAssembly access throws, alon…
robobun 11f96f5
crash handler tests: the native stack overflow tests do not run in an…
robobun 28b0511
signal_stack: disable the alternate stack with its size, keep a stack…
robobun 2f67eda
fs.watch: leave walk_subtree as on main
robobun File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,87 @@ | ||
| //! Per-thread alternate signal stack for the crash handler. A stack overflow | ||
| //! faults on the guard page, so the kernel can deliver the signal only onto an | ||
| //! alternate stack (`SA_ONSTACK` handler + `sigaltstack(2)` on the thread). | ||
| //! `Output::Source::configure_thread` installs one on every bun thread; the | ||
| //! main thread uses the crash handler's static buffer. | ||
|
robobun marked this conversation as resolved.
|
||
|
|
||
| use core::cell::Cell; | ||
|
|
||
| /// Excludes the guard page below it. The crash handler runs its report on it. | ||
| pub const ALT_STACK_SIZE: usize = 512 * 1024; | ||
|
|
||
| /// This thread's alternate stack mapping; dropped by the thread-local destructor. | ||
| struct Mapping { | ||
| base: *mut libc::c_void, | ||
| len: usize, | ||
| } | ||
|
|
||
| impl Drop for Mapping { | ||
| fn drop(&mut self) { | ||
| let mut disable: libc::stack_t = crate::ffi::zeroed(); | ||
| disable.ss_flags = libc::SS_DISABLE; | ||
| // Darwin's libc rejects a size below MINSIGSTKSZ, also for SS_DISABLE. | ||
| disable.ss_size = ALT_STACK_SIZE; | ||
| // SAFETY: `disable` is a valid `stack_t`; a null `old_ss` is permitted. | ||
| if unsafe { libc::sigaltstack(&raw const disable, core::ptr::null_mut()) } != 0 { | ||
| // Still registered: the kernel can write a signal frame to it. | ||
| return; | ||
| } | ||
| // SAFETY: `base`/`len` describe the mapping `install_for_current_thread` | ||
| // created, and the kernel no longer uses it as a signal stack. | ||
| unsafe { libc::munmap(self.base, self.len) }; | ||
| } | ||
| } | ||
|
|
||
| thread_local! { | ||
| static MAPPING: Cell<Option<Mapping>> = const { Cell::new(None) }; | ||
| } | ||
|
|
||
| /// Register an alternate signal stack for the calling thread. No-op when one is | ||
| /// already active (main thread, a repeat call, or ASAN's). Failure is silent. | ||
|
robobun marked this conversation as resolved.
|
||
| pub fn install_for_current_thread() { | ||
| let mut current: libc::stack_t = crate::ffi::zeroed(); | ||
| // SAFETY: a null `ss` only queries; `current` is a valid out-pointer. | ||
| if unsafe { libc::sigaltstack(core::ptr::null(), &raw mut current) } != 0 | ||
| || current.ss_flags & libc::SS_DISABLE == 0 | ||
| { | ||
| return; | ||
| } | ||
|
|
||
| // SAFETY: `sysconf` has no preconditions. | ||
| let page = match usize::try_from(unsafe { libc::sysconf(libc::_SC_PAGESIZE) }) { | ||
| Ok(page) if page > 0 => page, | ||
| _ => 4096, | ||
| }; | ||
| let len = ALT_STACK_SIZE + page; | ||
| // SAFETY: anonymous private mapping; no file, no fixed address. | ||
| let base = unsafe { | ||
| libc::mmap( | ||
| core::ptr::null_mut(), | ||
| len, | ||
| libc::PROT_READ | libc::PROT_WRITE, | ||
| libc::MAP_PRIVATE | libc::MAP_ANONYMOUS, | ||
| -1, | ||
| 0, | ||
| ) | ||
| }; | ||
| if base == libc::MAP_FAILED { | ||
| return; | ||
| } | ||
| // Guard page: an overflow of the handler itself faults instead of writing | ||
| // into the mapping below. | ||
| // SAFETY: `base` is page-aligned and the first page belongs to the mapping. | ||
| unsafe { libc::mprotect(base, page, libc::PROT_NONE) }; | ||
|
|
||
| let mut stack: libc::stack_t = crate::ffi::zeroed(); | ||
| // SAFETY: `page` is within the mapping of `len` bytes. | ||
| stack.ss_sp = unsafe { base.byte_add(page) }; | ||
| stack.ss_size = ALT_STACK_SIZE; | ||
| // SAFETY: `stack` describes a live, writable mapping; a null `old_ss` is | ||
| // permitted. | ||
| if unsafe { libc::sigaltstack(&raw const stack, core::ptr::null_mut()) } != 0 { | ||
| // SAFETY: the mapping was never registered; nothing else references it. | ||
| unsafe { libc::munmap(base, len) }; | ||
| return; | ||
| } | ||
| MAPPING.with(|slot| slot.set(Some(Mapping { base, len }))); | ||
|
robobun marked this conversation as resolved.
|
||
| } | ||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.