Move *nix specific implementation to separate module

This commit is contained in:
Jakub Konka
2019-05-19 14:52:41 +02:00
committed by Dan Gohman
parent 3372e47e5a
commit 7605584691
21 changed files with 3184 additions and 2690 deletions

File diff suppressed because it is too large Load Diff

View File

@@ -1,285 +0,0 @@
#![allow(non_camel_case_types)]
#![allow(unused_unsafe)]
use crate::ctx::WasiCtx;
use crate::host;
use nix::libc::{self, c_long};
use std::ffi::{OsStr, OsString};
use std::os::unix::prelude::{OsStrExt, OsStringExt, RawFd};
/// Normalizes a path to ensure that the target path is located under the directory provided.
///
/// This is a workaround for not having Capsicum support in the OS.
pub fn path_get<P: AsRef<OsStr>>(
wasi_ctx: &WasiCtx,
dirfd: host::__wasi_fd_t,
dirflags: host::__wasi_lookupflags_t,
path: P,
needed_base: host::__wasi_rights_t,
needed_inheriting: host::__wasi_rights_t,
needs_final_component: bool,
) -> Result<(RawFd, OsString), host::__wasi_errno_t> {
use nix::errno::Errno;
use nix::fcntl::{openat, readlinkat, OFlag};
use nix::sys::stat::Mode;
const MAX_SYMLINK_EXPANSIONS: usize = 128;
/// close all the intermediate file descriptors, but make sure not to drop either the original
/// dirfd or the one we return (which may be the same dirfd)
fn ret_dir_success(dir_stack: &mut Vec<RawFd>) -> RawFd {
let ret_dir = dir_stack.pop().expect("there is always a dirfd to return");
if let Some(dirfds) = dir_stack.get(1..) {
for dirfd in dirfds {
nix::unistd::close(*dirfd).unwrap_or_else(|e| {
dbg!(e);
});
}
}
ret_dir
}
/// close all file descriptors other than the base directory, and return the errno for
/// convenience with `return`
fn ret_error(
dir_stack: &mut Vec<RawFd>,
errno: host::__wasi_errno_t,
) -> Result<(RawFd, OsString), host::__wasi_errno_t> {
if let Some(dirfds) = dir_stack.get(1..) {
for dirfd in dirfds {
nix::unistd::close(*dirfd).unwrap_or_else(|e| {
dbg!(e);
});
}
}
Err(errno)
}
let dirfe = wasi_ctx.get_fd_entry(dirfd, needed_base, needed_inheriting)?;
// Stack of directory file descriptors. Index 0 always corresponds with the directory provided
// to this function. Entering a directory causes a file descriptor to be pushed, while handling
// ".." entries causes an entry to be popped. Index 0 cannot be popped, as this would imply
// escaping the base directory.
let mut dir_stack = vec![dirfe.fd_object.rawfd];
// Stack of paths left to process. This is initially the `path` argument to this function, but
// any symlinks we encounter are processed by pushing them on the stack.
let mut path_stack = vec![path.as_ref().to_owned().into_vec()];
// Track the number of symlinks we've expanded, so we can return `ELOOP` after too many.
let mut symlink_expansions = 0;
// Buffer to read links into; defined outside of the loop so we don't reallocate it constantly.
let mut readlink_buf = vec![0u8; libc::PATH_MAX as usize + 1];
// TODO: rewrite this using a custom posix path type, with a component iterator that respects
// trailing slashes. This version does way too much allocation, and is way too fiddly.
loop {
let component = if let Some(cur_path) = path_stack.pop() {
// eprintln!(
// "cur_path = {:?}",
// std::str::from_utf8(cur_path.as_slice()).unwrap()
// );
let mut split = cur_path.splitn(2, |&c| c == '/' as u8);
let head = split.next();
let tail = split.next();
match (head, tail) {
(None, _) => {
// split always returns at least a singleton iterator with an empty slice
panic!("unreachable");
}
// path is empty
(Some([]), None) => {
return ret_error(&mut dir_stack, host::__WASI_ENOENT);
}
// path starts with `/`, is absolute
(Some([]), Some(_)) => {
return ret_error(&mut dir_stack, host::__WASI_ENOTCAPABLE);
}
// the final component of the path with no trailing slash
(Some(component), None) => component.to_vec(),
(Some(component), Some(rest)) => {
if rest.iter().all(|&c| c == '/' as u8) {
// the final component of the path with trailing slashes; put one trailing
// slash back on
let mut component = component.to_vec();
component.push('/' as u8);
component
} else {
// non-final component; push the rest back on the stack
path_stack.push(rest.to_vec());
component.to_vec()
}
}
}
} else {
// if the path stack is ever empty, we return rather than going through the loop again
panic!("unreachable");
};
// eprintln!(
// "component = {:?}",
// std::str::from_utf8(component.as_slice()).unwrap()
// );
match component.as_slice() {
b"." => {
// skip component
}
b".." => {
// pop a directory
let dirfd = dir_stack.pop().expect("dir_stack is never empty");
// we're not allowed to pop past the original directory
if dir_stack.is_empty() {
return ret_error(&mut dir_stack, host::__WASI_ENOTCAPABLE);
} else {
nix::unistd::close(dirfd).unwrap_or_else(|e| {
dbg!(e);
});
}
}
// should the component be a directory? it should if there is more path left to process, or
// if it has a trailing slash and `needs_final_component` is not set
component
if !path_stack.is_empty()
|| (component.ends_with(b"/") && !needs_final_component) =>
{
match openat(
*dir_stack.first().expect("dir_stack is never empty"),
component,
OFlag::O_RDONLY | OFlag::O_DIRECTORY | OFlag::O_NOFOLLOW,
Mode::empty(),
) {
Ok(new_dir) => {
dir_stack.push(new_dir);
continue;
}
Err(e)
// Check to see if it was a symlink. Linux indicates
// this with ENOTDIR because of the O_DIRECTORY flag.
if e.as_errno() == Some(Errno::ELOOP)
|| e.as_errno() == Some(Errno::EMLINK)
|| e.as_errno() == Some(Errno::ENOTDIR) =>
{
// attempt symlink expansion
match readlinkat(
*dir_stack.last().expect("dir_stack is never empty"),
component,
readlink_buf.as_mut_slice(),
) {
Ok(link_path) => {
symlink_expansions += 1;
if symlink_expansions > MAX_SYMLINK_EXPANSIONS {
return ret_error(&mut dir_stack, host::__WASI_ELOOP);
}
let mut link_path = link_path.as_bytes().to_vec();
// append a trailing slash if the component leading to it has one, so
// that we preserve any ENOTDIR that might come from trying to open a
// non-directory
if component.ends_with(b"/") {
link_path.push('/' as u8);
}
path_stack.push(link_path);
continue;
}
Err(e) => {
return ret_error(
&mut dir_stack,
host::errno_from_nix(e.as_errno().unwrap()),
);
}
}
}
Err(e) => {
return ret_error(
&mut dir_stack,
host::errno_from_nix(e.as_errno().unwrap()),
);
}
}
}
// the final component
component => {
// if there's a trailing slash, or if `LOOKUP_SYMLINK_FOLLOW` is set, attempt
// symlink expansion
if component.ends_with(b"/") || (dirflags & host::__WASI_LOOKUP_SYMLINK_FOLLOW) != 0
{
match readlinkat(
*dir_stack.last().expect("dir_stack is never empty"),
component,
readlink_buf.as_mut_slice(),
) {
Ok(link_path) => {
symlink_expansions += 1;
if symlink_expansions > MAX_SYMLINK_EXPANSIONS {
return ret_error(&mut dir_stack, host::__WASI_ELOOP);
}
let mut link_path = link_path.as_bytes().to_vec();
// append a trailing slash if the component leading to it has one, so
// that we preserve any ENOTDIR that might come from trying to open a
// non-directory
if component.ends_with(b"/") {
link_path.push('/' as u8);
}
path_stack.push(link_path);
continue;
}
Err(e) => {
let errno = e.as_errno().unwrap();
if errno != Errno::EINVAL && errno != Errno::ENOENT {
// only return an error if this path is not actually a symlink
return ret_error(&mut dir_stack, host::errno_from_nix(errno));
}
}
}
}
// not a symlink, so we're done;
return Ok((
ret_dir_success(&mut dir_stack),
OsStr::from_bytes(component).to_os_string(),
));
}
}
if path_stack.is_empty() {
// no further components to process. means we've hit a case like "." or "a/..", or if the
// input path has trailing slashes and `needs_final_component` is not set
return Ok((
ret_dir_success(&mut dir_stack),
OsStr::new(".").to_os_string(),
));
} else {
continue;
}
}
}
#[cfg(not(target_os = "macos"))]
pub fn utime_now() -> c_long {
libc::UTIME_NOW
}
#[cfg(target_os = "macos")]
pub fn utime_now() -> c_long {
-1
}
#[cfg(not(target_os = "macos"))]
pub fn utime_omit() -> c_long {
libc::UTIME_OMIT
}
#[cfg(target_os = "macos")]
pub fn utime_omit() -> c_long {
-2
}

View File

@@ -1,16 +1,12 @@
#![allow(non_camel_case_types)]
#![allow(unused_unsafe)]
use crate::ctx::WasiCtx;
use crate::memory::*;
use crate::{host, wasm32};
use crate::wasm32;
use crate::sys::hostcalls as hostcalls_impl;
use cast::From as _0;
use nix::convert_ioctl_res;
use nix::libc::{self, c_int};
use std::cmp;
use std::time::SystemTime;
use wasi_common_cbindgen::wasi_common_cbindgen;
#[wasi_common_cbindgen]
@@ -77,75 +73,17 @@ pub fn clock_res_get(
clock_id: wasm32::__wasi_clockid_t,
resolution_ptr: wasm32::uintptr_t,
) -> wasm32::__wasi_errno_t {
// convert the supported clocks to the libc types, or return EINVAL
let clock_id = match dec_clockid(clock_id) {
host::__WASI_CLOCK_REALTIME => libc::CLOCK_REALTIME,
host::__WASI_CLOCK_MONOTONIC => libc::CLOCK_MONOTONIC,
host::__WASI_CLOCK_PROCESS_CPUTIME_ID => libc::CLOCK_PROCESS_CPUTIME_ID,
host::__WASI_CLOCK_THREAD_CPUTIME_ID => libc::CLOCK_THREAD_CPUTIME_ID,
_ => return wasm32::__WASI_EINVAL,
};
// no `nix` wrapper for clock_getres, so we do it ourselves
let mut timespec = unsafe { std::mem::uninitialized::<libc::timespec>() };
let res = unsafe { libc::clock_getres(clock_id, &mut timespec as *mut libc::timespec) };
if res != 0 {
return wasm32::errno_from_nix(nix::errno::Errno::last());
}
// convert to nanoseconds, returning EOVERFLOW in case of overflow; this is freelancing a bit
// from the spec but seems like it'll be an unusual situation to hit
(timespec.tv_sec as host::__wasi_timestamp_t)
.checked_mul(1_000_000_000)
.and_then(|sec_ns| sec_ns.checked_add(timespec.tv_nsec as host::__wasi_timestamp_t))
.map_or(wasm32::__WASI_EOVERFLOW, |resolution| {
// a supported clock can never return zero; this case will probably never get hit, but
// make sure we follow the spec
if resolution == 0 {
wasm32::__WASI_EINVAL
} else {
enc_timestamp_byref(memory, resolution_ptr, resolution)
.map(|_| wasm32::__WASI_ESUCCESS)
.unwrap_or_else(|e| e)
}
})
hostcalls_impl::clock_res_get(memory, clock_id, resolution_ptr)
}
#[wasi_common_cbindgen]
pub fn clock_time_get(
memory: &mut [u8],
clock_id: wasm32::__wasi_clockid_t,
// ignored for now, but will be useful once we put optional limits on precision to reduce side
// channels
_precision: wasm32::__wasi_timestamp_t,
precision: wasm32::__wasi_timestamp_t,
time_ptr: wasm32::uintptr_t,
) -> wasm32::__wasi_errno_t {
// convert the supported clocks to the libc types, or return EINVAL
let clock_id = match dec_clockid(clock_id) {
host::__WASI_CLOCK_REALTIME => libc::CLOCK_REALTIME,
host::__WASI_CLOCK_MONOTONIC => libc::CLOCK_MONOTONIC,
host::__WASI_CLOCK_PROCESS_CPUTIME_ID => libc::CLOCK_PROCESS_CPUTIME_ID,
host::__WASI_CLOCK_THREAD_CPUTIME_ID => libc::CLOCK_THREAD_CPUTIME_ID,
_ => return wasm32::__WASI_EINVAL,
};
// no `nix` wrapper for clock_getres, so we do it ourselves
let mut timespec = unsafe { std::mem::uninitialized::<libc::timespec>() };
let res = unsafe { libc::clock_gettime(clock_id, &mut timespec as *mut libc::timespec) };
if res != 0 {
return wasm32::errno_from_nix(nix::errno::Errno::last());
}
// convert to nanoseconds, returning EOVERFLOW in case of overflow; this is freelancing a bit
// from the spec but seems like it'll be an unusual situation to hit
(timespec.tv_sec as host::__wasi_timestamp_t)
.checked_mul(1_000_000_000)
.and_then(|sec_ns| sec_ns.checked_add(timespec.tv_nsec as host::__wasi_timestamp_t))
.map_or(wasm32::__WASI_EOVERFLOW, |time| {
enc_timestamp_byref(memory, time_ptr, time)
.map(|_| wasm32::__WASI_ESUCCESS)
.unwrap_or_else(|e| e)
})
hostcalls_impl::clock_time_get(memory, clock_id, precision, time_ptr)
}
#[wasi_common_cbindgen]
@@ -214,88 +152,7 @@ pub fn poll_oneoff(
nsubscriptions: wasm32::size_t,
nevents: wasm32::uintptr_t,
) -> wasm32::__wasi_errno_t {
if nsubscriptions as u64 > wasm32::__wasi_filesize_t::max_value() {
return wasm32::__WASI_EINVAL;
}
enc_pointee(memory, nevents, 0).unwrap();
let input_slice =
dec_slice_of::<wasm32::__wasi_subscription_t>(memory, input, nsubscriptions).unwrap();
let input: Vec<_> = input_slice.iter().map(|x| dec_subscription(x)).collect();
let output_slice =
dec_slice_of_mut::<wasm32::__wasi_event_t>(memory, output, nsubscriptions).unwrap();
let timeout = input
.iter()
.filter_map(|event| match event {
Ok(event) if event.type_ == wasm32::__WASI_EVENTTYPE_CLOCK => Some(ClockEventData {
delay: wasi_clock_to_relative_ns_delay(unsafe { event.u.clock }) / 1_000_000,
userdata: event.userdata,
}),
_ => None,
})
.min_by_key(|event| event.delay);
let fd_events: Vec<_> = input
.iter()
.filter_map(|event| match event {
Ok(event)
if event.type_ == wasm32::__WASI_EVENTTYPE_FD_READ
|| event.type_ == wasm32::__WASI_EVENTTYPE_FD_WRITE =>
{
Some(FdEventData {
fd: unsafe { event.u.fd_readwrite.fd } as c_int,
type_: event.type_,
userdata: event.userdata,
})
}
_ => None,
})
.collect();
if fd_events.is_empty() && timeout.is_none() {
return wasm32::__WASI_ESUCCESS;
}
let mut poll_fds: Vec<_> = fd_events
.iter()
.map(|event| {
let mut flags = nix::poll::EventFlags::empty();
match event.type_ {
wasm32::__WASI_EVENTTYPE_FD_READ => flags.insert(nix::poll::EventFlags::POLLIN),
wasm32::__WASI_EVENTTYPE_FD_WRITE => flags.insert(nix::poll::EventFlags::POLLOUT),
// An event on a file descriptor can currently only be of type FD_READ or FD_WRITE
// Nothing else has been defined in the specification, and these are also the only two
// events we filtered before. If we get something else here, the code has a serious bug.
_ => unreachable!(),
};
nix::poll::PollFd::new(event.fd, flags)
})
.collect();
let timeout = timeout.map(|ClockEventData { delay, userdata }| ClockEventData {
delay: cmp::min(delay, c_int::max_value() as u128),
userdata,
});
let poll_timeout = timeout.map_or(-1, |timeout| timeout.delay as c_int);
let ready = loop {
match nix::poll::poll(&mut poll_fds, poll_timeout) {
Err(_) => {
if nix::errno::Errno::last() == nix::errno::Errno::EINTR {
continue;
}
return wasm32::errno_from_nix(nix::errno::Errno::last());
}
Ok(ready) => break ready as usize,
}
};
let events_count = if ready == 0 {
poll_oneoff_handle_timeout_event(output_slice, timeout)
} else {
let events = fd_events.iter().zip(poll_fds.iter()).take(ready);
poll_oneoff_handle_fd_event(output_slice, events)
};
if let Err(e) = enc_pointee(memory, nevents, events_count) {
return enc_errno(e);
}
wasm32::__WASI_ESUCCESS
hostcalls_impl::poll_oneoff(memory, input, output, nsubscriptions, nevents)
}
#[wasi_common_cbindgen]
@@ -314,6 +171,11 @@ pub fn proc_raise(
unimplemented!("proc_raise")
}
#[wasi_common_cbindgen]
pub fn sched_yield() -> wasm32::__wasi_errno_t {
hostcalls_impl::sched_yield()
}
#[wasi_common_cbindgen]
pub fn random_get(
memory: &mut [u8],
@@ -331,140 +193,3 @@ pub fn random_get(
return wasm32::__WASI_ESUCCESS;
}
#[wasi_common_cbindgen]
pub fn sched_yield() -> wasm32::__wasi_errno_t {
unsafe { libc::sched_yield() };
wasm32::__WASI_ESUCCESS
}
// define the `fionread()` function, equivalent to `ioctl(fd, FIONREAD, *bytes)`
nix::ioctl_read_bad!(fionread, nix::libc::FIONREAD, c_int);
fn wasi_clock_to_relative_ns_delay(
wasi_clock: host::__wasi_subscription_t___wasi_subscription_u___wasi_subscription_u_clock_t,
) -> u128 {
if wasi_clock.flags != wasm32::__WASI_SUBSCRIPTION_CLOCK_ABSTIME {
return wasi_clock.timeout as u128;
}
let now: u128 = SystemTime::now()
.duration_since(SystemTime::UNIX_EPOCH)
.expect("Current date is before the epoch")
.as_nanos();
let deadline = wasi_clock.timeout as u128;
deadline.saturating_sub(now)
}
#[derive(Debug, Copy, Clone)]
struct ClockEventData {
delay: u128,
userdata: host::__wasi_userdata_t,
}
#[derive(Debug, Copy, Clone)]
struct FdEventData {
fd: c_int,
type_: host::__wasi_eventtype_t,
userdata: host::__wasi_userdata_t,
}
fn poll_oneoff_handle_timeout_event(
output_slice: &mut [wasm32::__wasi_event_t],
timeout: Option<ClockEventData>,
) -> wasm32::size_t {
if let Some(ClockEventData { userdata, .. }) = timeout {
let output_event = host::__wasi_event_t {
userdata,
type_: wasm32::__WASI_EVENTTYPE_CLOCK,
error: wasm32::__WASI_ESUCCESS,
u: host::__wasi_event_t___wasi_event_u {
fd_readwrite: host::__wasi_event_t___wasi_event_u___wasi_event_u_fd_readwrite_t {
nbytes: 0,
flags: 0,
},
},
};
output_slice[0] = enc_event(output_event);
1
} else {
// shouldn't happen
0
}
}
fn poll_oneoff_handle_fd_event<'t>(
output_slice: &mut [wasm32::__wasi_event_t],
events: impl Iterator<Item = (&'t FdEventData, &'t nix::poll::PollFd)>,
) -> wasm32::size_t {
let mut output_slice_cur = output_slice.iter_mut();
let mut revents_count = 0;
for (fd_event, poll_fd) in events {
let revents = match poll_fd.revents() {
Some(revents) => revents,
None => continue,
};
let mut nbytes = 0;
if fd_event.type_ == wasm32::__WASI_EVENTTYPE_FD_READ {
let _ = unsafe { fionread(fd_event.fd, &mut nbytes) };
}
let output_event = if revents.contains(nix::poll::EventFlags::POLLNVAL) {
host::__wasi_event_t {
userdata: fd_event.userdata,
type_: fd_event.type_,
error: wasm32::__WASI_EBADF,
u: host::__wasi_event_t___wasi_event_u {
fd_readwrite:
host::__wasi_event_t___wasi_event_u___wasi_event_u_fd_readwrite_t {
nbytes: 0,
flags: wasm32::__WASI_EVENT_FD_READWRITE_HANGUP,
},
},
}
} else if revents.contains(nix::poll::EventFlags::POLLERR) {
host::__wasi_event_t {
userdata: fd_event.userdata,
type_: fd_event.type_,
error: wasm32::__WASI_EIO,
u: host::__wasi_event_t___wasi_event_u {
fd_readwrite:
host::__wasi_event_t___wasi_event_u___wasi_event_u_fd_readwrite_t {
nbytes: 0,
flags: wasm32::__WASI_EVENT_FD_READWRITE_HANGUP,
},
},
}
} else if revents.contains(nix::poll::EventFlags::POLLHUP) {
host::__wasi_event_t {
userdata: fd_event.userdata,
type_: fd_event.type_,
error: wasm32::__WASI_ESUCCESS,
u: host::__wasi_event_t___wasi_event_u {
fd_readwrite:
host::__wasi_event_t___wasi_event_u___wasi_event_u_fd_readwrite_t {
nbytes: 0,
flags: wasm32::__WASI_EVENT_FD_READWRITE_HANGUP,
},
},
}
} else if revents.contains(nix::poll::EventFlags::POLLIN)
| revents.contains(nix::poll::EventFlags::POLLOUT)
{
host::__wasi_event_t {
userdata: fd_event.userdata,
type_: fd_event.type_,
error: wasm32::__WASI_ESUCCESS,
u: host::__wasi_event_t___wasi_event_u {
fd_readwrite:
host::__wasi_event_t___wasi_event_u___wasi_event_u_fd_readwrite_t {
nbytes: nbytes as host::__wasi_filesize_t,
flags: 0,
},
},
}
} else {
continue;
};
*output_slice_cur.next().unwrap() = enc_event(output_event);
revents_count += 1;
}
revents_count
}

View File

@@ -1,7 +1,4 @@
//! Hostcalls that implement
//! [WASI](https://github.com/CraneStation/wasmtime-wasi/blob/wasi/docs/WASI-overview.md).
mod fs;
mod fs_helpers;
mod misc;
mod sock;

View File

@@ -1,9 +1,9 @@
#![allow(non_camel_case_types)]
#![allow(unused_unsafe)]
#![allow(unused)]
use crate::ctx::WasiCtx;
use crate::wasm32;
use crate::sys::hostcalls as hostcalls_impl;
use wasi_common_cbindgen::wasi_common_cbindgen;
#[wasi_common_cbindgen]
@@ -17,7 +17,16 @@ pub fn sock_recv(
ro_datalen: wasm32::uintptr_t,
ro_flags: wasm32::uintptr_t,
) -> wasm32::__wasi_errno_t {
unimplemented!("sock_recv")
hostcalls_impl::sock_recv(
wasi_ctx,
memory,
sock,
ri_data,
ri_data_len,
ri_flags,
ro_datalen,
ro_flags,
)
}
#[wasi_common_cbindgen]
@@ -30,7 +39,15 @@ pub fn sock_send(
si_flags: wasm32::__wasi_siflags_t,
so_datalen: wasm32::uintptr_t,
) -> wasm32::__wasi_errno_t {
unimplemented!("sock_send")
hostcalls_impl::sock_send(
wasi_ctx,
memory,
sock,
si_data,
si_data_len,
si_flags,
so_datalen,
)
}
#[wasi_common_cbindgen]
@@ -40,5 +57,5 @@ pub fn sock_shutdown(
sock: wasm32::__wasi_fd_t,
how: wasm32::__wasi_sdflags_t,
) -> wasm32::__wasi_errno_t {
unimplemented!("sock_shutdown")
hostcalls_impl::sock_shutdown(wasi_ctx, memory, sock, how)
}