-
Notifications
You must be signed in to change notification settings - Fork 0
Shared-memory failure hardening: crash isolation, strict decoding, recovery, re-upgrade, soak #35
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
776c199
1a2e1b7
96dc47f
03c6224
0004833
f514628
81a4d98
8a52d1a
f4d7f88
3555515
a9da6cd
340194c
073258b
643225b
e75f917
6ce4174
c4c743e
7cd828a
c252efd
babdf81
acd7ce7
a2c1dbc
a3316f5
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,24 @@ | ||
| # Serialize the shared-memory crash tests. commentlint: allow(JUDGE) | ||
| [test-groups] | ||
| shm-crash = { max-threads = 1 } | ||
|
|
||
| [[profile.default.overrides]] | ||
| filter = 'package(mc-host) and binary(shm_failure_modes)' | ||
| test-group = 'shm-crash' | ||
|
|
||
| # The soak binary uses shm-crash serialization. commentlint: allow(JUDGE) | ||
| [[profile.default.overrides]] | ||
| filter = 'package(mc-host) and binary(shm_soak)' | ||
| test-group = 'shm-crash' | ||
| slow-timeout = { period = "120s", terminate-after = 5 } | ||
|
|
||
| # Run the ignored full soak with: | ||
| # cargo nextest run -P shm-soak --run-ignored ignored-only | ||
| # commentlint: allow(JUDGE) | ||
| [profile.shm-soak] | ||
| default-filter = 'package(mc-host) and binary(shm_soak) and test(full_soak_cycles_conserve_resources)' | ||
|
|
||
| [[profile.shm-soak.overrides]] | ||
| filter = 'package(mc-host) and binary(shm_soak)' | ||
| test-group = 'shm-crash' | ||
| slow-timeout = { period = "300s", terminate-after = 12 } |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,81 @@ | ||
| name: SHM hardening opt-in | ||
|
|
||
| on: | ||
| workflow_dispatch: | ||
| inputs: | ||
| soak_cycles: | ||
| description: Measured soak cycles (MC_SHM_SOAK_CYCLES) | ||
| required: false | ||
| default: "1000" | ||
| fuzz_seconds: | ||
| description: Per-target libFuzzer -max_total_time seconds | ||
| required: false | ||
| default: "60" | ||
|
|
||
| permissions: | ||
| contents: read | ||
|
|
||
| jobs: | ||
| full-soak: | ||
| name: Full resource soak (Linux, provisional ring tuple) | ||
| runs-on: ubuntu-latest | ||
| timeout-minutes: 180 | ||
| steps: | ||
| - uses: actions/checkout@v5 | ||
| with: | ||
| persist-credentials: false | ||
|
|
||
| - uses: dtolnay/rust-toolchain@stable | ||
|
|
||
| - uses: taiki-e/install-action@nextest | ||
|
|
||
| - name: Provision metadata-only sibling stubs | ||
| run: sh scripts/provision-rust-ci-stubs.sh | ||
|
|
||
| - name: Ignored full soak (shm-soak nextest profile) | ||
| env: | ||
| MC_SHM_SOAK_CYCLES: ${{ inputs.soak_cycles }} | ||
| run: cargo nextest run -P shm-soak --run-ignored ignored-only | ||
|
|
||
| bounded-fuzz: | ||
| name: Bounded libFuzzer campaign (nested fuzz workspace) | ||
| runs-on: ubuntu-latest | ||
| timeout-minutes: 60 | ||
| steps: | ||
| - uses: actions/checkout@v5 | ||
| with: | ||
| persist-credentials: false | ||
|
|
||
| - uses: dtolnay/rust-toolchain@nightly | ||
|
|
||
| - name: Install cargo-fuzz | ||
| run: cargo install cargo-fuzz --locked | ||
|
|
||
| - name: Nested fuzz workspace fmt and build | ||
| working-directory: crates/mc-shm-transport/fuzz | ||
| run: | | ||
| cargo fmt --check | ||
| cargo check --locked | ||
|
|
||
| - name: Bounded fuzz per target | ||
| working-directory: crates/mc-shm-transport | ||
| env: | ||
| FUZZ_SECONDS: ${{ inputs.fuzz_seconds }} | ||
| run: | | ||
| case "$FUZZ_SECONDS" in | ||
| ''|*[!0-9]*) | ||
| echo "fuzz_seconds must be an unsigned integer, got: $FUZZ_SECONDS" >&2 | ||
| exit 1 | ||
| ;; | ||
|
Comment on lines
+65
to
+69
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
If a manual dispatch supplies Useful? React with 👍 / 👎.
Owner
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Fixed in c4c743e — the workflow now rejects |
||
| esac | ||
| # libFuzzer's -max_total_time bounds the run only when positive; | ||
| # zero would run the first target until the workflow timeout and | ||
| # starve the remaining targets. | ||
| if [ "$FUZZ_SECONDS" -eq 0 ]; then | ||
| echo "fuzz_seconds must be a positive number of seconds" >&2 | ||
| exit 1 | ||
| fi | ||
| for target in frame_descriptor provider_grant provider_sample; do | ||
| cargo +nightly fuzz run "$target" -- \ | ||
| -max_total_time="$FUZZ_SECONDS" | ||
| done | ||
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Uh oh!
There was an error while loading. Please reload this page.