The audit's sharpest finding was structural, not a bug: a fully green suite had hidden six real defects because it contains no attacker. Every device case asserts that a driver handed its own hardware can drive it. None asked what a process handed NOTHING can do. device-authority-test is that process. It is spawned with no device and asserts what it therefore cannot do: it cannot give away a device another task holds, nor a free one, because the kernel's rule is that you may give away what you hold and the device's state is irrelevant to a process holding nothing. Asserted across every device the machine actually has, so it cannot pass by accident of which one happened to be free at boot — six on QEMU, none of them its. A positive control runs first. device_enumerate works from this process, so the refusals below it are decisions rather than a syscall path that is simply broken here; without it, "everything failed" would read identically to "the assertions are meaningless". A nonexistent device is refused as NoSuchDevice rather than NotHeld, because a refusal that cannot name its own rule is what cost a debugging session on the Ryzen. What it deliberately does not assert, and says so in its header: device_claim is still first-come-first-served at this point in the run. That is the hole D6 closes, and the claim half of the invariant joins this fixture then. Asserting it now would be writing a test that documents the bug. Verified to discriminate: removing the holder check flips "every transfer by a non-holder is refused" while the positive control keeps passing. Suite 117 -> 118.
16 lines
655 B
Zig
16 lines
655 B
Zig
.{
|
|
.name = .device_authority_test,
|
|
.version = "0.0.0",
|
|
.fingerprint = 0x4acbba0c105a1462, // Changing this has security and trust implications.
|
|
.minimum_zig_version = "0.16.0",
|
|
.dependencies = .{
|
|
// build-support supplies the shared recipe; kernel is implicit in
|
|
// every binary (the root shim + link script live there). The rest
|
|
// are exactly the homes of this binary's declared imports.
|
|
.@"build-support" = .{ .path = "../../../../build-support" },
|
|
.kernel = .{ .path = "../../../../library/kernel" },
|
|
.device = .{ .path = "../../../../library/device" },
|
|
},
|
|
.paths = .{""},
|
|
}
|