gvisor-lx/pkg/abi/linux/limits.go
Leadaxe 117243aa02 snapshot: sagernet/gvisor v0.0.0-20260727.0-sing-box-mod.1 + SPEC 048 guard
Обновление снапшота с v0.0.0-20250811.0 на пин, которого требует
sing-box после мержа 235 коммитов (upstream d620bbbf2 "Update gvisor to
20260727.0"). Прежний снапшот был взят 2026-08-04 ровно с той версии,
на которой тогда стоял апстрим; разрыв возник 2026-08-05 вместе с его
бампом.

За год апстрим-gvisor изменил ~14 000 строк в 292 файлах. Значимое для
нас — сетевой стек: tcp/connect.go (PMTU-discovery + исправление
начального RTT/RTO: раньше задержка ACK внутри стека завышала стартовый
таймаут на несколько RTT), tcp/snd.go, tcp/rcv.go, stack/conntrack.go,
stack/packet_buffer.go. Всего 30 файлов в TCP и 37 в stack.

Баг SPEC 048 апстрим НЕ исправил — проверено по коду новой версии:
handleConnecting по-прежнему проверяет состояние endpoint'а, но не ep.h,
а performHandshake так же зануляет h и отпускает мьютекс до Close().
Поэтому guard перенесён (12 строк) вместе со своим тестом (45 строк).

Red/green проверен на новой базе: без guard'а тест падает с той же
nil-паникой, что в полевом крашдампе; с ним зелёный.
2026-08-05 14:53:31 +03:00

93 lines
3 KiB
Go

// Copyright 2018 The gVisor Authors.
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
package linux
import (
"structs"
)
// Resources for getrlimit(2)/setrlimit(2)/prlimit(2).
const (
RLIMIT_CPU = 0
RLIMIT_FSIZE = 1
RLIMIT_DATA = 2
RLIMIT_STACK = 3
RLIMIT_CORE = 4
RLIMIT_RSS = 5
RLIMIT_NPROC = 6
RLIMIT_NOFILE = 7
RLIMIT_MEMLOCK = 8
RLIMIT_AS = 9
RLIMIT_LOCKS = 10
RLIMIT_SIGPENDING = 11
RLIMIT_MSGQUEUE = 12
RLIMIT_NICE = 13
RLIMIT_RTPRIO = 14
RLIMIT_RTTIME = 15
)
// RLimit corresponds to Linux's struct rlimit.
type RLimit struct {
_ structs.HostLayout
// Cur specifies the soft limit.
Cur uint64
// Max specifies the hard limit.
Max uint64
}
const (
// RLimInfinity is RLIM_INFINITY on Linux.
RLimInfinity = ^uint64(0)
// DefaultStackSoftLimit is called _STK_LIM in Linux.
DefaultStackSoftLimit = 8 * 1024 * 1024
// DefaultNprocLimit is defined in kernel/fork.c:set_max_threads, and
// called MAX_THREADS / 2 in Linux.
DefaultNprocLimit = FUTEX_TID_MASK / 2
// DefaultNofileSoftLimit is called INR_OPEN_CUR in Linux.
DefaultNofileSoftLimit = 1024
// DefaultNofileHardLimit is called INR_OPEN_MAX in Linux.
DefaultNofileHardLimit = 4096
// DefaultMemlockLimit is called MLOCK_LIMIT in Linux.
DefaultMemlockLimit = 64 * 1024
// DefaultMsgqueueLimit is called MQ_BYTES_MAX in Linux.
DefaultMsgqueueLimit = 819200
)
// InitRLimits is a map of initial rlimits set by Linux in
// include/asm-generic/resource.h.
var InitRLimits = map[int]RLimit{
RLIMIT_CPU: {Cur: RLimInfinity, Max: RLimInfinity},
RLIMIT_FSIZE: {Cur: RLimInfinity, Max: RLimInfinity},
RLIMIT_DATA: {Cur: RLimInfinity, Max: RLimInfinity},
RLIMIT_STACK: {Cur: DefaultStackSoftLimit, Max: RLimInfinity},
RLIMIT_CORE: {Cur: 0, Max: RLimInfinity},
RLIMIT_RSS: {Cur: RLimInfinity, Max: RLimInfinity},
RLIMIT_NPROC: {Cur: DefaultNprocLimit, Max: DefaultNprocLimit},
RLIMIT_NOFILE: {Cur: DefaultNofileSoftLimit, Max: DefaultNofileHardLimit},
RLIMIT_MEMLOCK: {Cur: DefaultMemlockLimit, Max: DefaultMemlockLimit},
RLIMIT_AS: {Cur: RLimInfinity, Max: RLimInfinity},
RLIMIT_LOCKS: {Cur: RLimInfinity, Max: RLimInfinity},
RLIMIT_SIGPENDING: {Cur: 0, Max: 0},
RLIMIT_MSGQUEUE: {Cur: DefaultMsgqueueLimit, Max: DefaultMsgqueueLimit},
RLIMIT_NICE: {Cur: 0, Max: 0},
RLIMIT_RTPRIO: {Cur: 0, Max: 0},
RLIMIT_RTTIME: {Cur: RLimInfinity, Max: RLimInfinity},
}