3 Commits

Author SHA1 Message Date
6dc22d5dbb Test ignored-error storage across translation units
Some checks failed
libakerror CI Build / cmake_build (push) Has been cancelled
libakerror CI Build / sanitizer (push) Has been cancelled
libakerror CI Build / coverage (push) Has been cancelled
libakerror CI Build / mutation_test (push) Has been cancelled
2026-08-05 23:35:04 -04:00
576722ee06 Pass CMake arguments to mutation builds
Some checks failed
libakerror CI Build / cmake_build (push) Successful in 2m57s
libakerror CI Build / sanitizer (push) Successful in 3m4s
libakerror CI Build / coverage (push) Successful in 2m49s
libakerror CI Build / mutation_test (push) Has been cancelled
2026-08-05 13:42:12 -04:00
07fdc82973 Add ASan and UBSan CI coverage
All checks were successful
libakerror CI Build / cmake_build (push) Successful in 2m52s
libakerror CI Build / sanitizer (push) Successful in 2m56s
libakerror CI Build / coverage (push) Successful in 2m57s
libakerror CI Build / mutation_test (push) Successful in 37m44s
2026-08-05 13:41:34 -04:00
11 changed files with 97 additions and 136 deletions

View File

@@ -37,6 +37,23 @@ jobs:
fail_on_failure: 'true' fail_on_failure: 'true'
- run: echo "🍏 This job's status is ${{ job.status }}." - run: echo "🍏 This job's status is ${{ job.status }}."
sanitizer:
runs-on: ubuntu-latest
steps:
- name: Check out repository code
uses: actions/checkout@v4
- name: dependencies
run: |
sudo apt-get update -y
sudo apt-get install -y cmake gcc moreutils
- name: build with AddressSanitizer and UBSan
run: |
cmake -S . -B build/asan -DAKERR_SANITIZE=address,undefined
cmake --build build/asan
- name: test with AddressSanitizer and UBSan
run: ctest --test-dir build/asan --output-on-failure
- run: echo "🍏 This job's status is ${{ job.status }}."
coverage: coverage:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:

View File

@@ -158,18 +158,10 @@ add_custom_command(
VERBATIM VERBATIM
) )
# More than one library target consumes the generated sources below. Route
# them through one explicit prerequisite so parallel Make builds cannot invoke
# the same generator twice and interleave writes to errno.c.
add_custom_target(akerror_generated
DEPENDS ${GENERATED_ERRNO_C} ${GENERATED_AKERROR_H}
)
add_library(akerror SHARED add_library(akerror SHARED
src/error.c src/error.c
${GENERATED_ERRNO_C} ${GENERATED_ERRNO_C}
) )
add_dependencies(akerror akerror_generated)
target_include_directories(akerror PUBLIC target_include_directories(akerror PUBLIC
$<BUILD_INTERFACE:${GENERATED_DIR}/include> $<BUILD_INTERFACE:${GENERATED_DIR}/include>
@@ -208,32 +200,6 @@ set_target_properties(akerror PROPERTIES
akerr_instrument_for_coverage(akerror) akerr_instrument_for_coverage(akerror)
akerr_instrument_for_sanitizers(akerror) akerr_instrument_for_sanitizers(akerror)
# akerr_init() must terminate if it cannot reserve the library-owned status
# band. The production table sizes are deliberately PRIVATE, so exercise that
# otherwise unreachable startup failure with a second library target whose
# private registries cannot accept even the first reservation. Keeping this a
# distinct target is the test: no compile definition leaks into consumers or
# weakens the production library.
add_library(akerror_init_failure SHARED
src/error.c
${GENERATED_ERRNO_C}
)
add_dependencies(akerror_init_failure akerror_generated)
target_include_directories(akerror_init_failure PUBLIC
${GENERATED_DIR}/include
)
target_compile_definitions(akerror_init_failure
PUBLIC AKERR_USE_STDLIB=${AKERR_USE_STDLIB}
PRIVATE AKERR_STATUS_NAME_SLOTS=8
PRIVATE AKERR_MAX_RESERVED_STATUS_RANGES=0
PRIVATE ${AKERR_THREADS_DEFINE}
)
if(AKERR_THREAD_SAFE)
target_link_libraries(akerror_init_failure PRIVATE Threads::Threads)
endif()
akerr_instrument_for_coverage(akerror_init_failure)
akerr_instrument_for_sanitizers(akerror_init_failure)
# Each test is one source file in tests/ built into test_<name> and registered # Each test is one source file in tests/ built into test_<name> and registered
# as CTest <name>. Tests expected to abort (unhandled error / contract # as CTest <name>. Tests expected to abort (unhandled error / contract
# violation) go in AKERR_WILL_FAIL_TESTS; all others must exit 0. # violation) go in AKERR_WILL_FAIL_TESTS; all others must exit 0.
@@ -261,7 +227,6 @@ set(AKERR_TESTS
err_registry_init_order err_registry_init_order
err_status_exception err_status_exception
err_copy_string err_copy_string
err_init_reservation_fatal
err_library_status_fatal err_library_status_fatal
err_refcount_double_fail err_refcount_double_fail
err_stacktrace_bounds err_stacktrace_bounds
@@ -289,18 +254,13 @@ endif()
set(AKERR_WILL_FAIL_TESTS set(AKERR_WILL_FAIL_TESTS
err_trace err_trace
err_improper_closure err_improper_closure
err_init_reservation_fatal
err_library_status_fatal err_library_status_fatal
) )
foreach(_test IN LISTS AKERR_TESTS) foreach(_test IN LISTS AKERR_TESTS)
add_executable(test_${_test} tests/${_test}.c) add_executable(test_${_test} tests/${_test}.c)
target_include_directories(test_${_test} PRIVATE ${CMAKE_CURRENT_SOURCE_DIR}/tests) target_include_directories(test_${_test} PRIVATE ${CMAKE_CURRENT_SOURCE_DIR}/tests)
if(_test STREQUAL "err_init_reservation_fatal") target_link_libraries(test_${_test} PRIVATE akerror)
target_link_libraries(test_${_test} PRIVATE akerror_init_failure)
else()
target_link_libraries(test_${_test} PRIVATE akerror)
endif()
if(AKERR_THREAD_SAFE) if(AKERR_THREAD_SAFE)
target_link_libraries(test_${_test} PRIVATE Threads::Threads) target_link_libraries(test_${_test} PRIVATE Threads::Threads)
endif() endif()
@@ -322,6 +282,22 @@ foreach(_test IN LISTS AKERR_TESTS)
endif() endif()
endforeach() endforeach()
# The ignored-error slot is declared in the public header but must have one
# library definition. Compare its address from two translation units, and
# compile the consumer-facing test with all ordinary warnings enabled: a
# header-local TLS definition would both duplicate storage and warn when unused.
add_executable(test_err_ignore_multitu
tests/err_ignore_multitu.c
tests/err_ignore_multitu_helper.c)
target_include_directories(test_err_ignore_multitu
PRIVATE ${CMAKE_CURRENT_SOURCE_DIR}/tests)
target_link_libraries(test_err_ignore_multitu PRIVATE akerror)
target_compile_options(test_err_ignore_multitu PRIVATE -Wall -Wextra -Werror)
if(AKERR_THREAD_SAFE)
target_link_libraries(test_err_ignore_multitu PRIVATE Threads::Threads)
endif()
add_test(NAME err_ignore_multitu COMMAND test_err_ignore_multitu)
# HANDLE_GROUP deliberately enters the next case label. Keep that public macro # HANDLE_GROUP deliberately enters the next case label. Keep that public macro
# compiling with the warning enabled, so a future macro edit cannot restore the # compiling with the warning enabled, so a future macro edit cannot restore the
# warning for consumers which adopt -Wextra. # warning for consumers which adopt -Wextra.
@@ -345,14 +321,7 @@ if(Python3_FOUND)
# The script configures and drives its own instrumented build tree (under # The script configures and drives its own instrumented build tree (under
# ${CMAKE_BINARY_DIR}/coverage) so this build's binaries and its coverage # ${CMAKE_BINARY_DIR}/coverage) so this build's binaries and its coverage
# counters can never be stale or half-instrumented. Reports via gcov. # counters can never be stale or half-instrumented. Reports via gcov.
# Keep the convenient generic name at the top level, but namespace it when add_custom_target(coverage
# embedded so a parent project can provide its own coverage target.
if(CMAKE_SOURCE_DIR STREQUAL CMAKE_CURRENT_SOURCE_DIR)
set(AKERR_COVERAGE_TARGET coverage)
else()
set(AKERR_COVERAGE_TARGET akerror_coverage)
endif()
add_custom_target(${AKERR_COVERAGE_TARGET}
COMMAND ${Python3_EXECUTABLE} COMMAND ${Python3_EXECUTABLE}
${CMAKE_CURRENT_SOURCE_DIR}/scripts/coverage.py ${CMAKE_CURRENT_SOURCE_DIR}/scripts/coverage.py
--source-root ${CMAKE_CURRENT_SOURCE_DIR} --source-root ${CMAKE_CURRENT_SOURCE_DIR}
@@ -384,6 +353,7 @@ if(Python3_FOUND)
) )
endif() endif()
set(main_lib_dest "lib/my_library-${MY_LIBRARY_VERSION}")
install(TARGETS akerror install(TARGETS akerror
EXPORT akerrorTargets EXPORT akerrorTargets
ARCHIVE DESTINATION ${CMAKE_INSTALL_LIBDIR} ARCHIVE DESTINATION ${CMAKE_INSTALL_LIBDIR}
@@ -407,17 +377,8 @@ configure_package_config_file(
INSTALL_DESTINATION ${akerror_install_cmakedir} INSTALL_DESTINATION ${akerror_install_cmakedir}
) )
# The SOVERSION is the project major version, so packages with the same major
# are ABI-compatible and a different major must be rejected.
write_basic_package_version_file(
"${CMAKE_CURRENT_BINARY_DIR}/akerrorConfigVersion.cmake"
VERSION ${PROJECT_VERSION}
COMPATIBILITY SameMajorVersion
)
install(FILES install(FILES
"${CMAKE_CURRENT_BINARY_DIR}/akerrorConfig.cmake" "${CMAKE_CURRENT_BINARY_DIR}/akerrorConfig.cmake"
"${CMAKE_CURRENT_BINARY_DIR}/akerrorConfigVersion.cmake"
DESTINATION ${akerror_install_cmakedir} DESTINATION ${akerror_install_cmakedir}
) )

View File

@@ -132,11 +132,6 @@ One recursive lock covers both the pool and the registry, so error
correctness there is worth more than throughput, but a program that raises correctness there is worth more than throughput, but a program that raises
errors in a hot loop will feel it. errors in a hot loop will feel it.
Releasing the last reference to a context remains serialized under that same
pool lock, but it now resets only the handled/status/reported state, the string
heads, and the stack-trace cursor. It no longer wipes the whole context buffer,
so release is a fixed handful of stores rather than a tens-of-kilobytes write.
The per-thread last-ditch context is a whole `akerr_ErrorContext` (tens of The per-thread last-ditch context is a whole `akerr_ErrorContext` (tens of
kilobytes) in thread-local storage, allocated per thread on first use of the kilobytes) in thread-local storage, allocated per thread on first use of the
library from that thread. library from that thread.

View File

@@ -25,6 +25,8 @@ Usage:
--work DIR scratch dir for the mutated copy (default: a temp dir) --work DIR scratch dir for the mutated copy (default: a temp dir)
--timeout SECONDS per-suite ctest timeout (default: 120) --timeout SECONDS per-suite ctest timeout (default: 120)
--threshold PCT exit non-zero if mutation score < PCT (default: 0 = off) --threshold PCT exit non-zero if mutation score < PCT (default: 0 = off)
--cmake-arg ARG pass an additional argument to the mutant CMake configure;
repeat for multiple arguments (e.g. -DAKERR_SANITIZE=thread)
--list only list the mutants that would be run, then exit --list only list the mutants that would be run, then exit
--keep keep the scratch working copy on exit (for debugging) --keep keep the scratch working copy on exit (for debugging)
-j N (reserved) currently runs sequentially -j N (reserved) currently runs sequentially
@@ -199,10 +201,11 @@ def generate_mutants(root, rel_target):
# --------------------------------------------------------------------------- # # --------------------------------------------------------------------------- #
class Runner: class Runner:
def __init__(self, work, timeout): def __init__(self, work, timeout, cmake_args):
self.work = work self.work = work
self.build = os.path.join(work, "build") self.build = os.path.join(work, "build")
self.timeout = timeout self.timeout = timeout
self.cmake_args = cmake_args
def _run(self, cmd, timeout=None): def _run(self, cmd, timeout=None):
return subprocess.run( return subprocess.run(
@@ -211,7 +214,8 @@ class Runner:
) )
def configure(self): def configure(self):
r = self._run(["cmake", "-S", ".", "-B", "build"], timeout=self.timeout) r = self._run(["cmake", "-S", ".", "-B", "build", *self.cmake_args],
timeout=self.timeout)
return r.returncode == 0, r.stdout return r.returncode == 0, r.stdout
def build_and_test(self): def build_and_test(self):
@@ -307,6 +311,8 @@ def main():
ap.add_argument("--work", default=None) ap.add_argument("--work", default=None)
ap.add_argument("--timeout", type=int, default=120) ap.add_argument("--timeout", type=int, default=120)
ap.add_argument("--threshold", type=float, default=0.0) ap.add_argument("--threshold", type=float, default=0.0)
ap.add_argument("--cmake-arg", action="append", default=[],
help="pass an argument to the mutant CMake configure; repeatable")
ap.add_argument("--junit", default=None, ap.add_argument("--junit", default=None,
help="write a JUnit XML report to this path") help="write a JUnit XML report to this path")
ap.add_argument("--max-mutants", type=int, default=0, ap.add_argument("--max-mutants", type=int, default=0,
@@ -354,7 +360,7 @@ def main():
print(f"\nCopying sources to scratch dir: {work}") print(f"\nCopying sources to scratch dir: {work}")
copy_tree(root, work) copy_tree(root, work)
runner = Runner(work, args.timeout) runner = Runner(work, args.timeout, args.cmake_arg)
print("Configuring baseline ...") print("Configuring baseline ...")
ok, out = runner.configure() ok, out = runner.configure()

View File

@@ -88,10 +88,7 @@ typedef struct
static akerr_StatusName akerr_status_names[AKERR_STATUS_NAME_SLOTS]; static akerr_StatusName akerr_status_names[AKERR_STATUS_NAME_SLOTS];
static int akerr_status_name_count; static int akerr_status_name_count;
/* C has no portable zero-length arrays. Keep one unused physical slot when a static akerr_StatusRange akerr_status_ranges[AKERR_MAX_RESERVED_STATUS_RANGES];
* test build sets the logical capacity to zero to drive init's fatal path. */
static akerr_StatusRange akerr_status_ranges[
AKERR_MAX_RESERVED_STATUS_RANGES > 0 ? AKERR_MAX_RESERVED_STATUS_RANGES : 1];
static int akerr_status_range_count; static int akerr_status_range_count;
akerr_ErrorContext AKERR_ARRAY_ERROR[AKERR_MAX_ARRAY_ERROR]; akerr_ErrorContext AKERR_ARRAY_ERROR[AKERR_MAX_ARRAY_ERROR];
@@ -380,10 +377,10 @@ akerr_ErrorContext *akerr_next_error()
} }
/* /*
* The reset returns the slot to the pool, so it and the decrement that triggers * The wipe returns the slot to the pool, so it and the decrement that triggers
* it are one operation under the lock. Otherwise a thread that saw the count * it are one operation under the lock. Otherwise a thread that saw the count
* reach zero could be handed the slot by akerr_next_error() and start writing * reach zero could be handed the slot by akerr_next_error() and start writing
* its error into it while the releasing thread was still resetting it. * its error into it while the releasing thread was still memsetting it.
*/ */
akerr_ErrorContext *akerr_release_error(akerr_ErrorContext *err) akerr_ErrorContext *akerr_release_error(akerr_ErrorContext *err)
{ {
@@ -401,13 +398,7 @@ akerr_ErrorContext *akerr_release_error(akerr_ErrorContext *err)
} }
if ( err->refcount == 0 ) { if ( err->refcount == 0 ) {
oldid = err->arrayid; oldid = err->arrayid;
err->handled = false; memset(err, 0x00, sizeof(akerr_ErrorContext));
err->status = 0;
err->reported = false;
err->message[0] = '\0';
err->fname[0] = '\0';
err->function[0] = '\0';
err->stacktracebuf[0] = '\0';
err->stacktracebufptr = (char *)&err->stacktracebuf; err->stacktracebufptr = (char *)&err->stacktracebuf;
err->arrayid = oldid; err->arrayid = oldid;
remaining = NULL; remaining = NULL;
@@ -673,7 +664,7 @@ static akerr_ErrorContext AKERR_NOIGNORE *akerr_reserve_status_range_locked(int
"must not overflow int)", "must not overflow int)",
count, first_status, owner == NULL ? "(null)" : owner, count, first_status, owner == NULL ? "(null)" : owner,
AKERR_MAX_STATUS_RANGE_OWNER_LENGTH); AKERR_MAX_STATUS_RANGE_OWNER_LENGTH);
last_status = first_status + count - 1; last_status = first_status + (count - 1);
for ( int i = 0; i < akerr_status_range_count; i++ ) { for ( int i = 0; i < akerr_status_range_count; i++ ) {
if ( first_status <= akerr_status_ranges[i].last && if ( first_status <= akerr_status_ranges[i].last &&

View File

@@ -32,6 +32,9 @@ scripts/mutation_test.py --target src/error.c --list
# Gate CI: exit non-zero if the score drops below 90% # Gate CI: exit non-zero if the score drops below 90%
scripts/mutation_test.py --threshold 90 scripts/mutation_test.py --threshold 90
# Check concurrency mutants under ThreadSanitizer
scripts/mutation_test.py --cmake-arg=-DAKERR_SANITIZE=thread
``` ```
Via CMake (configures a build first if needed): Via CMake (configures a build first if needed):
@@ -40,8 +43,10 @@ Via CMake (configures a build first if needed):
cmake --build build --target mutation cmake --build build --target mutation
``` ```
Useful flags: `--timeout SECONDS` (per-suite build+test cap; a mutant that Useful flags: `--cmake-arg ARG` (pass a CMake configure argument to every
hangs is counted as killed), `--keep` (retain the scratch copy for debugging), mutant build; repeat it for multiple arguments), `--timeout SECONDS` (per-suite
build+test cap; a mutant that hangs is counted as killed), `--keep` (retain the
scratch copy for debugging),
`--work DIR` (use a specific scratch directory), `--junit FILE` (write a JUnit `--work DIR` (use a specific scratch directory), `--junit FILE` (write a JUnit
XML report — surviving mutants appear as failing test cases). XML report — surviving mutants appear as failing test cases).

View File

@@ -0,0 +1,18 @@
#include "akerror.h"
#include "err_ignore_multitu.h"
#include <stdio.h>
int main(void)
{
akerr_ErrorContext **main_address = &__akerr_last_ignored;
akerr_ErrorContext **helper_address = akerr_multitu_snapshot_address();
if ( main_address != helper_address ) {
fprintf(stderr,
"CHECK FAILED: ignored-error storage differs between translation units\n");
return 1;
}
fprintf(stderr, "err_ignore_multitu ok\n");
return 0;
}

View File

@@ -0,0 +1,8 @@
#ifndef AKERR_TEST_IGNORE_MULTITU_H
#define AKERR_TEST_IGNORE_MULTITU_H
#include "akerror.h"
akerr_ErrorContext **akerr_multitu_snapshot_address(void);
#endif

View File

@@ -0,0 +1,6 @@
#include "err_ignore_multitu.h"
akerr_ErrorContext **akerr_multitu_snapshot_address(void)
{
return &__akerr_last_ignored;
}

View File

@@ -1,20 +0,0 @@
#include "akerror.h"
#include <stdio.h>
/*
* This executable links to akerror_init_failure, a test-only library target
* with no status-range slots. The first reservation in akerr_init() must be
* terminal: continuing would leave every library status unowned and make all
* subsequent name registrations invalid.
*
* CTest marks this WILL_FAIL. Reaching the message and returning zero means
* initialization swallowed its own reservation failure.
*/
int main(void)
{
akerr_init();
fprintf(stderr, "err_init_reservation_fatal: akerr_init did not terminate\n");
return 0;
}

View File

@@ -1,32 +1,24 @@
#include "akerror.h" #include "akerror.h"
#include "err_capture.h" #include "err_capture.h"
#include <string.h>
/* /*
* Releasing an error context back to the pool must reset the state that affects * Releasing an error context back to the pool must wipe it, so the next caller
* the next caller. In particular, a handled error must not make a fresh error * that checks it out never sees stale status/message/stacktrace from a previous
* look handled when its slot is recycled. * error. Mutation testing showed the clearing memset in akerr_release_error
* could be deleted without any test noticing.
*/ */
static int unhandled_calls = 0;
static int unhandled_status = 0;
static void test_unhandled_handler(akerr_ErrorContext *errctx)
{
unhandled_calls++;
unhandled_status = (errctx != NULL) ? errctx->status : 0;
}
akerr_ErrorContext *boom(void) akerr_ErrorContext *boom(void)
{ {
PREPARE_ERROR(e); PREPARE_ERROR(e);
FAIL_RETURN(e, AKERR_VALUE, "first error is handled"); FAIL_RETURN(e, AKERR_VALUE, "stale dirty message that must not survive");
} }
int main(void) int main(void)
{ {
akerr_capture_install(); akerr_capture_install();
akerr_init(); akerr_init();
akerr_handler_unhandled_error = &test_unhandled_handler;
/* Raise and fully handle an error; FINISH_NORETURN releases it to the pool. */ /* Raise and fully handle an error; FINISH_NORETURN releases it to the pool. */
PREPARE_ERROR(e); PREPARE_ERROR(e);
@@ -40,31 +32,13 @@ int main(void)
AKERR_CHECK(e == NULL); AKERR_CHECK(e == NULL);
/* A fresh error in the recycled slot must not inherit handled=true. */ /* The next context handed out is the slot we just released: it must be clean. */
PREPARE_ERROR(fresh);
ATTEMPT {
CATCH(fresh, boom());
} CLEANUP {
} PROCESS(fresh) {
} FINISH_NORETURN(fresh);
AKERR_CHECK(unhandled_calls == 1);
AKERR_CHECK(unhandled_status == AKERR_VALUE);
AKERR_CHECK(fresh == NULL);
/* The next context handed out is the same slot, with recycle state reset. */
akerr_ErrorContext *slot = akerr_next_error(); akerr_ErrorContext *slot = akerr_next_error();
AKERR_CHECK(slot != NULL); AKERR_CHECK(slot != NULL);
AKERR_CHECK(slot->handled == false);
AKERR_CHECK(slot->status == 0); AKERR_CHECK(slot->status == 0);
AKERR_CHECK(slot->reported == false);
AKERR_CHECK(slot->message[0] == '\0'); AKERR_CHECK(slot->message[0] == '\0');
AKERR_CHECK(slot->fname[0] == '\0');
AKERR_CHECK(slot->function[0] == '\0');
AKERR_CHECK(slot->stacktracebuf[0] == '\0'); AKERR_CHECK(slot->stacktracebuf[0] == '\0');
AKERR_CHECK(slot->stacktracebufptr == (char *)&slot->stacktracebuf); AKERR_CHECK(strstr(slot->message, "stale dirty message") == NULL);
RELEASE_ERROR(slot);
AKERR_CHECK(akerr_slots_in_use() == 0);
fprintf(stderr, "err_release_clears ok\n"); fprintf(stderr, "err_release_clears ok\n");
return 0; return 0;