snapshot: sagernet/gvisor v0.0.0-20250811.0-sing-box-mod.1
Содержимое пина, зафиксированного в go.mod sing-box-lx, одним коммитом без истории. Полная история SagerNet/gvisor — 1.45 ГБ и клонируется в каждой CI-джобе; наша дельта — одна вставка в одну функцию, история для неё не нужна. Module path github.com/sagernet/gvisor сохранён намеренно: на него опирается replace-директива суперпроекта. Патч поверх — отдельным коммитом, чтобы дельта читалась одним git show и переносилась на новый пин копированием. SPECS/TASKS/048-GVISOR_HANDSHAKE_NIL_CRASH
This commit is contained in:
commit
2c4ae3b0a4
712 changed files with 185689 additions and 0 deletions
113
pkg/sighandling/sighandling.go
Normal file
113
pkg/sighandling/sighandling.go
Normal file
|
|
@ -0,0 +1,113 @@
|
|||
// Copyright 2018 The gVisor Authors.
|
||||
//
|
||||
// Licensed under the Apache License, Version 2.0 (the "License");
|
||||
// you may not use this file except in compliance with the License.
|
||||
// You may obtain a copy of the License at
|
||||
//
|
||||
// http://www.apache.org/licenses/LICENSE-2.0
|
||||
//
|
||||
// Unless required by applicable law or agreed to in writing, software
|
||||
// distributed under the License is distributed on an "AS IS" BASIS,
|
||||
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
// See the License for the specific language governing permissions and
|
||||
// limitations under the License.
|
||||
|
||||
// Package sighandling contains helpers for handling signals to applications.
|
||||
package sighandling
|
||||
|
||||
import (
|
||||
"os"
|
||||
"os/signal"
|
||||
"reflect"
|
||||
|
||||
"github.com/sagernet/gvisor/pkg/abi/linux"
|
||||
"golang.org/x/sys/unix"
|
||||
)
|
||||
|
||||
// numSignals is the number of normal (non-realtime) signals on Linux.
|
||||
const numSignals = 32
|
||||
|
||||
// handleSignals listens for incoming signals and calls the given handler
|
||||
// function.
|
||||
//
|
||||
// It stops when the stop channel is closed. The done channel is closed once it
|
||||
// will no longer deliver signals to k.
|
||||
func handleSignals(sigchans []chan os.Signal, handler func(linux.Signal), stop, done chan struct{}) {
|
||||
// Build a select case.
|
||||
sc := []reflect.SelectCase{{Dir: reflect.SelectRecv, Chan: reflect.ValueOf(stop)}}
|
||||
for _, sigchan := range sigchans {
|
||||
sc = append(sc, reflect.SelectCase{Dir: reflect.SelectRecv, Chan: reflect.ValueOf(sigchan)})
|
||||
}
|
||||
|
||||
for {
|
||||
// Wait for a notification.
|
||||
index, _, ok := reflect.Select(sc)
|
||||
|
||||
// Was it the stop channel?
|
||||
if index == 0 {
|
||||
if !ok {
|
||||
// Stop forwarding and notify that it's done.
|
||||
close(done)
|
||||
return
|
||||
}
|
||||
continue
|
||||
}
|
||||
|
||||
// How about a different close?
|
||||
if !ok {
|
||||
panic("signal channel closed unexpectedly")
|
||||
}
|
||||
|
||||
// Otherwise, it was a signal on channel N. Index 0 represents the stop
|
||||
// channel, so index N represents the channel for signal N.
|
||||
handler(linux.Signal(index))
|
||||
}
|
||||
}
|
||||
|
||||
// StartSignalForwarding ensures that synchronous signals are passed to the
|
||||
// given handler function and returns a callback that stops signal delivery.
|
||||
//
|
||||
// Note that this function permanently takes over signal handling. After the
|
||||
// stop callback, signals revert to the default Go runtime behavior, which
|
||||
// cannot be overridden with external calls to signal.Notify.
|
||||
func StartSignalForwarding(handler func(linux.Signal)) func() {
|
||||
stop := make(chan struct{})
|
||||
done := make(chan struct{})
|
||||
|
||||
// Register individual channels. One channel per standard signal is
|
||||
// required as os.Notify() is non-blocking and may drop signals. To avoid
|
||||
// this, standard signals have to be queued separately. Channel size 1 is
|
||||
// enough for standard signals as their semantics allow de-duplication.
|
||||
//
|
||||
// External real-time signals are not supported. We rely on the go-runtime
|
||||
// for their handling.
|
||||
//
|
||||
// We do not forward some signals that are likely induced by the behavior
|
||||
// of the forwarding process.
|
||||
var sigchans []chan os.Signal
|
||||
for sig := 1; sig <= numSignals+1; sig++ {
|
||||
sigchan := make(chan os.Signal, 1)
|
||||
sigchans = append(sigchans, sigchan)
|
||||
|
||||
// SIGURG is used by Go's runtime scheduler.
|
||||
if sig == int(linux.SIGURG) {
|
||||
continue
|
||||
}
|
||||
// SIGPIPE is received when sending to disconnected host pipes/sockets.
|
||||
if sig == int(linux.SIGPIPE) {
|
||||
continue
|
||||
}
|
||||
// SIGCHLD is received when a child of the forwarding process exits.
|
||||
if sig == int(linux.SIGCHLD) {
|
||||
continue
|
||||
}
|
||||
signal.Notify(sigchan, unix.Signal(sig))
|
||||
}
|
||||
// Start up our listener.
|
||||
go handleSignals(sigchans, handler, stop, done) // S/R-SAFE: synchronized by Kernel.extMu.
|
||||
|
||||
return func() {
|
||||
close(stop)
|
||||
<-done
|
||||
}
|
||||
}
|
||||
40
pkg/sighandling/sighandling_darwin.go
Normal file
40
pkg/sighandling/sighandling_darwin.go
Normal file
|
|
@ -0,0 +1,40 @@
|
|||
// Copyright 2021 The gVisor Authors.
|
||||
//
|
||||
// Licensed under the Apache License, Version 2.0 (the "License");
|
||||
// you may not use this file except in compliance with the License.
|
||||
// You may obtain a copy of the License at
|
||||
//
|
||||
// http://www.apache.org/licenses/LICENSE-2.0
|
||||
//
|
||||
// Unless required by applicable law or agreed to in writing, software
|
||||
// distributed under the License is distributed on an "AS IS" BASIS,
|
||||
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
// See the License for the specific language governing permissions and
|
||||
// limitations under the License.
|
||||
|
||||
//go:build darwin
|
||||
// +build darwin
|
||||
|
||||
package sighandling
|
||||
|
||||
import (
|
||||
"errors"
|
||||
|
||||
"golang.org/x/sys/unix"
|
||||
)
|
||||
|
||||
// IgnoreChildStop sets the SA_NOCLDSTOP flag, causing child processes to not
|
||||
// generate SIGCHLD when they stop.
|
||||
func IgnoreChildStop() error {
|
||||
return errors.New("IgnoreChildStop not supported on Darwin")
|
||||
}
|
||||
|
||||
// ReplaceSignalHandler replaces the existing signal handler for the provided
|
||||
// signal with the function pointer at `handler`. This bypasses the Go runtime
|
||||
// signal handlers, and should only be used for low-level signal handlers where
|
||||
// use of signal.Notify is not appropriate.
|
||||
//
|
||||
// It stores the value of the previously set handler in previous.
|
||||
func ReplaceSignalHandler(sig unix.Signal, handler uintptr, previous *uintptr) error {
|
||||
return errors.New("ReplaceSignalHandler not supported on Darwin")
|
||||
}
|
||||
103
pkg/sighandling/sighandling_linux_unsafe.go
Normal file
103
pkg/sighandling/sighandling_linux_unsafe.go
Normal file
|
|
@ -0,0 +1,103 @@
|
|||
// Copyright 2018 The gVisor Authors.
|
||||
//
|
||||
// Licensed under the Apache License, Version 2.0 (the "License");
|
||||
// you may not use this file except in compliance with the License.
|
||||
// You may obtain a copy of the License at
|
||||
//
|
||||
// http://www.apache.org/licenses/LICENSE-2.0
|
||||
//
|
||||
// Unless required by applicable law or agreed to in writing, software
|
||||
// distributed under the License is distributed on an "AS IS" BASIS,
|
||||
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
// See the License for the specific language governing permissions and
|
||||
// limitations under the License.
|
||||
|
||||
//go:build linux
|
||||
// +build linux
|
||||
|
||||
package sighandling
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
"os"
|
||||
"unsafe"
|
||||
|
||||
"github.com/sagernet/gvisor/pkg/abi/linux"
|
||||
"golang.org/x/sys/unix"
|
||||
)
|
||||
|
||||
// IgnoreChildStop sets the SA_NOCLDSTOP flag, causing child processes to not
|
||||
// generate SIGCHLD when they stop.
|
||||
func IgnoreChildStop() error {
|
||||
var sa linux.SigAction
|
||||
|
||||
// Get the existing signal handler information, and set the flag.
|
||||
if _, _, e := unix.RawSyscall6(unix.SYS_RT_SIGACTION, uintptr(unix.SIGCHLD), 0, uintptr(unsafe.Pointer(&sa)), linux.SignalSetSize, 0, 0); e != 0 {
|
||||
return e
|
||||
}
|
||||
sa.Flags |= linux.SA_NOCLDSTOP
|
||||
if _, _, e := unix.RawSyscall6(unix.SYS_RT_SIGACTION, uintptr(unix.SIGCHLD), uintptr(unsafe.Pointer(&sa)), 0, linux.SignalSetSize, 0, 0); e != 0 {
|
||||
return e
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
// ReplaceSignalHandler replaces the existing signal handler for the provided
|
||||
// signal with the function pointer at `handler`. This bypasses the Go runtime
|
||||
// signal handlers, and should only be used for low-level signal handlers where
|
||||
// use of signal.Notify is not appropriate.
|
||||
//
|
||||
// It stores the value of the previously set handler in previous.
|
||||
func ReplaceSignalHandler(sig unix.Signal, handler uintptr, previous *uintptr) error {
|
||||
var sa linux.SigAction
|
||||
const maskLen = 8
|
||||
|
||||
// Get the existing signal handler information, and save the current
|
||||
// handler. Once we replace it, we will use this pointer to fall back to
|
||||
// it when we receive other signals.
|
||||
if _, _, e := unix.RawSyscall6(unix.SYS_RT_SIGACTION, uintptr(sig), 0, uintptr(unsafe.Pointer(&sa)), maskLen, 0, 0); e != 0 {
|
||||
return e
|
||||
}
|
||||
|
||||
// Fail if there isn't a previous handler.
|
||||
if sa.Handler == 0 {
|
||||
return fmt.Errorf("previous handler for signal %x isn't set", sig)
|
||||
}
|
||||
|
||||
*previous = uintptr(sa.Handler)
|
||||
|
||||
// Install our own handler.
|
||||
sa.Handler = uint64(handler)
|
||||
if _, _, e := unix.RawSyscall6(unix.SYS_RT_SIGACTION, uintptr(sig), uintptr(unsafe.Pointer(&sa)), 0, maskLen, 0, 0); e != 0 {
|
||||
return e
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
// KillItself sends SIGKILL to the current process, bypassing the init process
|
||||
// restriction.
|
||||
//
|
||||
// The standard `kill(getpid(), SIGKILL)` syscall doesn't work when the current
|
||||
// process is the init process within its PID namespace. This is a "known"
|
||||
// Linux feature.
|
||||
//
|
||||
// This function uses the rt_tgqueueinfo syscall to send a "kernel-generated"
|
||||
// SIGKILL.
|
||||
func KillItself() error {
|
||||
pid := os.Getpid()
|
||||
tid, _, _ := unix.RawSyscall(unix.SYS_GETTID, 0, 0, 0)
|
||||
info := linux.SignalInfo{Code: linux.SI_KERNEL}
|
||||
// The current thread can send a fake kernel siginfo to itself.
|
||||
if _, _, e := unix.RawSyscall6(
|
||||
unix.SYS_RT_TGSIGQUEUEINFO,
|
||||
uintptr(pid), uintptr(tid),
|
||||
uintptr(linux.SIGKILL),
|
||||
uintptr(unsafe.Pointer(&info)),
|
||||
0, 0,
|
||||
); e != 0 {
|
||||
return e
|
||||
}
|
||||
panic("unreachable")
|
||||
}
|
||||
|
|
@ -0,0 +1,6 @@
|
|||
// automatically generated by stateify.
|
||||
|
||||
//go:build linux
|
||||
// +build linux
|
||||
|
||||
package sighandling
|
||||
6
pkg/sighandling/sighandling_state_autogen.go
Normal file
6
pkg/sighandling/sighandling_state_autogen.go
Normal file
|
|
@ -0,0 +1,6 @@
|
|||
// automatically generated by stateify.
|
||||
|
||||
//go:build darwin
|
||||
// +build darwin
|
||||
|
||||
package sighandling
|
||||
Loading…
Add table
Add a link
Reference in a new issue