feat(sigsafe): allocate safely inside intercepted libc calls - #596
Open
wan9chi wants to merge 4 commits into
Open
feat(sigsafe): allocate safely inside intercepted libc calls#596wan9chi wants to merge 4 commits into
wan9chi wants to merge 4 commits into
Conversation
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
fspy benchmarklinuxmacoswindows |
wan9chi
force-pushed
the
claude/fspy-libc-async-signal-safe-129134
branch
from
August 9, 2026 01:00
5a2d5e3 to
2e51e33
Compare
wan9chi
force-pushed
the
claude/fspy-libc-async-signal-safe-129134
branch
from
August 9, 2026 01:11
2e51e33 to
252bea9
Compare
wan9chi
force-pushed
the
claude/fspy-libc-async-signal-safe-129134
branch
from
August 9, 2026 01:29
252bea9 to
4da71f0
Compare
wan9chi
force-pushed
the
claude/fspy-libc-async-signal-safe-129134
branch
from
August 9, 2026 01:33
4da71f0 to
81ea504
Compare
wan9chi
force-pushed
the
claude/fspy-libc-async-signal-safe-129134
branch
2 times, most recently
from
August 9, 2026 01:42
3562a1d to
9e93e64
Compare
Member
Author
|
Alternative implementation for comparison: #599 installs a lock-free |
wan9chi
force-pushed
the
claude/fspy-libc-async-signal-safe-129134
branch
from
August 9, 2026 03:07
9e93e64 to
94dbffb
Compare
wan9chi
changed the base branch from
main
to
claude/fspy-benchmark-access-relative
August 9, 2026 03:09
wan9chi
force-pushed
the
claude/fspy-libc-async-signal-safe-129134
branch
2 times, most recently
from
August 9, 2026 03:21
39af197 to
2ff6465
Compare
wan9chi
added a commit
that referenced
this pull request
Aug 9, 2026
## Motivation The `access` suite opens an absolute path, which the tracker serves with a borrowed pointer — the code that resolves a file descriptor's directory and joins it with a relative pathname never runs, so that lane has been unmeasured. Upcoming changes ([#596](#596)) modify exactly that lane, so it needs a benchmark row before those land. ## What this does Adds an `access-relative` suite: the target opens a bare filename with the filesystem root as its working directory, forcing the working-directory lookup and the join. Root as the working directory makes the resolved path byte-identical to the absolute suite's, so the two rows differ only in the work being priced, not in what gets captured — and validation asserts the same captured path in both modes. The launcher grows a `--relative` flag instead of a new binary: the harness compares two builds of the same launcher source, so one parameterized binary keeps both suites measured by identical code. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
wan9chi
force-pushed
the
claude/fspy-libc-async-signal-safe-129134
branch
from
August 9, 2026 03:33
2ff6465 to
d390c01
Compare
…or the preload library The preload library interposes libc functions that POSIX declares async-signal-safe (open, stat, execve, ...), so its Rust allocations must not take libc malloc's locks: a signal handler, or the child of fork() in a multithreaded process, would deadlock on locks held by suspended or vanished threads. fspy_alloc routes every allocation in the preload cdylib through a lock-free size-class pool: power-of-two classes carve blocks from 1 MiB slabs, freed blocks recycle through per-class Treiber free lists made ABA-resistant by a 40-bit generation tag, and larger or over-aligned requests map directly. All memory comes from anonymous mappings issued as raw syscalls via rustix's linux_raw backend — on Linux the allocator relies on nothing from libc, discovering even the page size with an mprotect probe (no getauxval, no /proc, no minimum kernel version). macOS goes through the thin libSystem stubs, its only syscall interface. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…unk pool Rework fspy_alloc from a size-class global allocator into three layers: MmapAllocator (stateless, every allocation is a fresh kernel mapping), ChunkPool (a lock-free cache of 64 KiB chunks), and arena(), the only public entry, which hands each intercepted call its own bump arena (bump_scope::Bump) drawing chunks from the process-wide pool. Use the arena for the first preload call site: joining a directory and a relative path when resolving fd-relative opens. Add an access-relative benchmark suite so this lane — working-directory resolution plus path joining — is measured; the existing absolute-path suite never enters it. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
wan9chi
force-pushed
the
claude/fspy-libc-async-signal-safe-129134
branch
2 times, most recently
from
August 9, 2026 03:52
7a57a18 to
7d5d985
Compare
… wrappers The allocator is the first piece of a broader need: the preload library runs inside intercepted libc calls, so everything it uses must work in signal handlers, in the child of fork() in a multithreaded process, and before libc has finished initializing. sigsafe is where such code now lives. fspy_alloc becomes sigsafe::alloc, and the mmap/munmap/page-size calls it makes move behind sigsafe::mm and sigsafe::param, the first safe syscall wrappers the crate offers on its own. sigsafe promises that on Linux none of its calls go through libc, and enforces the promise at compile time: lib.rs references rustix::runtime, a module that exists only in rustix's raw-syscall backend, so any build configuration that selects rustix's libc backend — including a feature enabled outside this repository, which no build script can see — fails to compile instead of silently keeping libc in the picture. The README explains the purpose, the rules, and the enforcement. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
wan9chi
force-pushed
the
claude/fspy-libc-async-signal-safe-129134
branch
3 times, most recently
from
August 9, 2026 06:32
1071b8a to
8a21e7c
Compare
The first use of the arena: `to_c_str_array` builds the NULL-terminated argv/envp pointer arrays that an intercepted exec hands to the real call, then drops them when that call returns — a temporary whose lifetime is already exactly a bump arena's. Building it must not go through libc malloc. Exec runs in the child of fork() in multithreaded programs (posix_spawn forks then execs), where malloc's lock may be held by a thread that no longer exists. Both platforms take this path, on every intercepted exec. The strings the array points at are still owned by `Exec` and still come from malloc; converting them, and the rest of the preload, is follow-up work. This change establishes the crate, the layers, and the lifetime discipline in the smallest place they all apply. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
wan9chi
force-pushed
the
claude/fspy-libc-async-signal-safe-129134
branch
from
August 9, 2026 06:34
8a21e7c to
aa221e7
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Part of #605 — this lands the malloc-class fix (the largest of the hazards there); the lazy-dlsym, hot-path panic, TLS reentrancy, and posix_spawn-thread items remain follow-ups.
The benchmark suite that prices this change merged in #602.
Motivation
The preload library runs inside libc calls such as
open,stat, andexecve. Programs are allowed to make these calls from a signal handler, or in the child offork()in a program with many threads. In both situations, using libc'smalloccan hang the program forever: the lock insidemallocmay be held by a thread that is paused or no longer exists. The preload library still allocates throughmalloctoday, so a traced program can hang in exactly these situations.What this does
Adds a new crate,
sigsafe: Unix syscall wrappers that are safe to call where libc is not — in signal handlers, in fork children, before libc has finished initializing. Its README states the three rules everything in it follows: syscalls only (never through libc on Linux), no locks and no hidden state, and no global allocation.The no-libc rule is enforced at compile time. rustix can be built with a libc backend, and anything in the dependency graph — including crates outside this repository — can select it; no build script can detect the feature-unification case. So
sigsafe'slib.rsreferencesrustix::runtime, a module that exists only in rustix's raw-syscall build: selecting the libc backend makes the crate fail to compile instead of silently losing the guarantee.On top of the first wrappers (
mm::mmap_anonymous,mm::munmap,param::page_size) sitssigsafe::alloc, allocation that never touches malloc, in three layers with only the top exposed:MmapAllocator— every allocation asks the kernel for fresh memory pages throughsigsafe::mm. It keeps no state of its own, so there is nothing a signal or afork()can catch locked or half-written.ChunkPool— keeps up to 64 freed 64 KiB chunks in a fixed array of atomic pointers, so the next call can reuse memory without asking the kernel again. Taking or returning a chunk is one atomic swap per slot, never a lock, and a thread that disappears mid-operation can strand at most the one chunk it held.alloc::arena()— the only public function. It hands one intercepted call its own bump arena (abump_scope::Bump) that draws chunks from the pool and returns them when the call ends. Values allocated in the arena cannot outlive the call; the borrow checker enforces it.Uses the arena in one place to start:
RawExec::to_c_str_array, which builds the NULL-terminated argv/envp pointer arrays that an intercepted exec hands to the real call, then drops them when it returns. That temporary's lifetime is already exactly a bump arena's, so the change is nine lines and adds nounsafe.It has to come off malloc because exec runs in the child of
fork()in multithreaded programs —posix_spawnforks then execs — where malloc's lock may be held by a thread that no longer exists. Both platforms take this path on every intercepted exec.The strings the array points at are still owned by
Execand still come from malloc, as does the rest of the preload; converting them is follow-up. This change establishes the crate, the layers, and the lifetime discipline in the smallest place all three apply.Benchmark
The
access-relativesuite (#602) was added while this PR still used the arena for the fd-relative join, and it earned its keep twice: an early run showed +29% on Linux, which turned out to be the preload building without optimizations (fixed by #597), and the corrected runs showed the arena join costing ~+3% overPathBuf::push— which is why the join reverted and the arena moved toexecveat. The investigation is written up in this comment's thread. With the join reverted, both suites should sit at baseline.Commits
The first commit is an earlier version of the allocator — one lock-free size-class allocator installed as the preload's
#[global_allocator]— kept so the two designs can be compared; #599 measured that design end to end and lost. The second commit replaces it with the arena design above. The third moves the allocator into the newsigsafecrate assigsafe::alloc, addsmm/paramand the compile-time backend enforcement, and adds the README. The fourth moves the arena use from the join toexecveatand fixes the dangling pointer there.🤖 Generated with Claude Code