snapshot: sagernet/gvisor v0.0.0-20250811.0-sing-box-mod.1

Содержимое пина, зафиксированного в go.mod sing-box-lx, одним коммитом
без истории. Полная история SagerNet/gvisor — 1.45 ГБ и клонируется в
каждой CI-джобе; наша дельта — одна вставка в одну функцию, история для
неё не нужна.

Module path github.com/sagernet/gvisor сохранён намеренно: на него
опирается replace-директива суперпроекта.

Патч поверх — отдельным коммитом, чтобы дельта читалась одним git show
и переносилась на новый пин копированием.

SPECS/TASKS/048-GVISOR_HANDSHAKE_NIL_CRASH
This commit is contained in:
Leadaxe 2026-08-04 15:50:08 +03:00
commit 2c4ae3b0a4
712 changed files with 185689 additions and 0 deletions

48
pkg/fsutil/fsutil.go Normal file
View file

@ -0,0 +1,48 @@
// Copyright 2022 The gVisor Authors.
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
// Package fsutil contains filesystem utilities that can be shared between the
// sentry and other sandbox components.
package fsutil
import "golang.org/x/sys/unix"
// DirentHandler is a function that handles a dirent.
type DirentHandler func(ino uint64, off int64, ftype uint8, name string, reclen uint16)
// ForEachDirent retrieves all dirents from dirfd using getdents64(2) and
// invokes handleDirent on them.
func ForEachDirent(dirfd int, handleDirent DirentHandler) error {
var direntsBuf [8192]byte
for {
n, err := unix.Getdents(dirfd, direntsBuf[:])
if err != nil {
return err
}
if n <= 0 {
return nil
}
ParseDirents(direntsBuf[:n], handleDirent)
}
}
// DirentNames retrieves all dirents from dirfd using getdents64(2) and returns
// all the recorded dirent names.
func DirentNames(dirfd int) ([]string, error) {
var names []string
err := ForEachDirent(dirfd, func(_ uint64, _ int64, _ uint8, name string, _ uint16) {
names = append(names, name)
})
return names, err
}

View file

@ -0,0 +1,49 @@
// Copyright 2019 The gVisor Authors.
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
//go:build amd64
// +build amd64
package fsutil
import (
"unsafe"
"github.com/sagernet/gvisor/pkg/syserr"
"golang.org/x/sys/unix"
)
// StatAt is a convenience wrapper around newfstatat(2).
func StatAt(dirFd int, name string) (unix.Stat_t, error) {
nameBytes, err := unix.BytePtrFromString(name)
if err != nil {
return unix.Stat_t{}, err
}
namePtr := unsafe.Pointer(nameBytes)
var stat unix.Stat_t
statPtr := unsafe.Pointer(&stat)
if _, _, errno := unix.Syscall6(
unix.SYS_NEWFSTATAT,
uintptr(dirFd),
uintptr(namePtr),
uintptr(statPtr),
unix.AT_SYMLINK_NOFOLLOW,
0,
0); errno != 0 {
return unix.Stat_t{}, syserr.FromHost(errno).ToError()
}
return stat, nil
}

View file

@ -0,0 +1,6 @@
// automatically generated by stateify.
//go:build amd64
// +build amd64
package fsutil

View file

@ -0,0 +1,49 @@
// Copyright 2019 The gVisor Authors.
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
//go:build arm64
// +build arm64
package fsutil
import (
"unsafe"
"github.com/sagernet/gvisor/pkg/syserr"
"golang.org/x/sys/unix"
)
// StatAt is a convenience wrapper around fstatat(2).
func StatAt(dirFd int, name string) (unix.Stat_t, error) {
nameBytes, err := unix.BytePtrFromString(name)
if err != nil {
return unix.Stat_t{}, err
}
namePtr := unsafe.Pointer(nameBytes)
var stat unix.Stat_t
statPtr := unsafe.Pointer(&stat)
if _, _, errno := unix.Syscall6(
unix.SYS_FSTATAT,
uintptr(dirFd),
uintptr(namePtr),
uintptr(statPtr),
unix.AT_SYMLINK_NOFOLLOW,
0,
0); errno != 0 {
return unix.Stat_t{}, syserr.FromHost(errno).ToError()
}
return stat, nil
}

View file

@ -0,0 +1,6 @@
// automatically generated by stateify.
//go:build arm64
// +build arm64
package fsutil

View file

@ -0,0 +1,3 @@
// automatically generated by stateify.
package fsutil

121
pkg/fsutil/fsutil_unsafe.go Normal file
View file

@ -0,0 +1,121 @@
// Copyright 2018 The gVisor Authors.
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
package fsutil
import (
"unsafe"
"github.com/sagernet/gvisor/pkg/syserr"
"golang.org/x/sys/unix"
)
// UnixDirentMaxSize is the maximum size of unix.Dirent in bytes.
var UnixDirentMaxSize = int(unsafe.Sizeof(unix.Dirent{}))
// Utimensat is a convenience wrapper to make the utimensat(2) syscall. It
// additionally handles empty name.
func Utimensat(dirFd int, name string, times [2]unix.Timespec, flags int) error {
// utimensat(2) doesn't accept empty name, instead name must be nil to make it
// operate directly on 'dirFd' unlike other *at syscalls.
var namePtr unsafe.Pointer
if name != "" {
nameBytes, err := unix.BytePtrFromString(name)
if err != nil {
return err
}
namePtr = unsafe.Pointer(nameBytes)
}
timesPtr := unsafe.Pointer(&times[0])
if _, _, errno := unix.Syscall6(
unix.SYS_UTIMENSAT,
uintptr(dirFd),
uintptr(namePtr),
uintptr(timesPtr),
uintptr(flags),
0,
0); errno != 0 {
return syserr.FromHost(errno).ToError()
}
return nil
}
// RenameAt is a convenience wrapper to make the renameat(2) syscall. It
// additionally handles empty names.
func RenameAt(oldDirFD int, oldName string, newDirFD int, newName string) error {
var oldNamePtr unsafe.Pointer
if oldName != "" {
nameBytes, err := unix.BytePtrFromString(oldName)
if err != nil {
return err
}
oldNamePtr = unsafe.Pointer(nameBytes)
}
var newNamePtr unsafe.Pointer
if newName != "" {
nameBytes, err := unix.BytePtrFromString(newName)
if err != nil {
return err
}
newNamePtr = unsafe.Pointer(nameBytes)
}
if _, _, errno := unix.Syscall6(
unix.SYS_RENAMEAT,
uintptr(oldDirFD),
uintptr(oldNamePtr),
uintptr(newDirFD),
uintptr(newNamePtr),
0,
0); errno != 0 {
return syserr.FromHost(errno).ToError()
}
return nil
}
// ParseDirents parses dirents from buf. buf must have been populated by
// getdents64(2) syscall. It calls the handleDirent callback for each dirent.
func ParseDirents(buf []byte, handleDirent DirentHandler) {
for len(buf) > 0 {
// Interpret the buf populated by unix.Getdents as unix.Dirent.
dirent := *(*unix.Dirent)(unsafe.Pointer(&buf[0]))
// Advance buf for the next dirent.
buf = buf[dirent.Reclen:]
// Extracting the name is pretty tedious...
var nameBuf [unix.NAME_MAX]byte
var nameLen int
for i := 0; i < len(dirent.Name); i++ {
// The name is null terminated.
if dirent.Name[i] == 0 {
nameLen = i
break
}
nameBuf[i] = byte(dirent.Name[i])
}
name := string(nameBuf[:nameLen])
// Skip `.` and `..` entries. It is anyways ignored by the client. We also
// don't want to leak information about `..`.
if name == "." || name == ".." {
continue
}
// Deliver results to caller.
handleDirent(dirent.Ino, dirent.Off, dirent.Type, name, dirent.Reclen)
}
}

View file

@ -0,0 +1,3 @@
// automatically generated by stateify.
package fsutil