Files
danos/test/system/services/vfs-test/vfs-test.zig
T
Daniel Samson 60b41c0e82 kernel: mounts have owners — V0 of the volume-manager plan
fs_unmount was gated by nothing but the /protocol carve-out: any process
could unmount any prefix — latent with one mount owner, an obvious
cross-tenant hole once volumes multiply. Each backend mount now records the
mounting task, and the syscall layer enforces two rules that keep the
restart story intact: only the owner unmounts (a dead owner's mount is
swept lazily by resolution — strangers gain nothing by racing that), and a
mount may be REPLACED only by its live owner or after its owner died (the
respawned-filesystem path; displacement of a live mount would be worse than
unmounting it). Kernel-installed mounts are never displaceable.

The vfs-test park role is the discrimination: with the volume provably
mounted it attempts the foreign unmount, requires the refusal AND the
subtree still resolving, and withholds its "parked" marker otherwise —
against the ungated kernel the unmount was ALLOWED and vfs-client-death
fails; with the gate, green. (Its verification handle closes immediately:
the kernel test string-matches "released 1 handle(s)".)
2026-08-09 16:16:14 +01:00

114 lines
4.1 KiB
Zig

//! /test/system/services/vfs-test — a ring-3 client that proves the kernel VFS
//! end to end through the plain `file_system` API: resolve its OWN binary under
//! the kernel-served /test mount, check its metadata, read its ELF magic, and
//! list /system/services. On success it heartbeats "vfstest: ok" so the kernel
//! test can observe it; on failure it reports what went wrong.
//!
//! The "park" role (the fat-client-death test): open a file on the FAT volume,
//! then hold the handle forever without closing — the kill and the fat
//! server's release-on-death sweep are the point.
const std = @import("std");
const fs = @import("file-system");
const process = @import("process");
const time = @import("time");
const logging = @import("logging");
pub fn main(init: process.Init) void {
if (init.arguments.count > 1) {
park();
return;
}
// Our own binary, resolved through the kernel mount table.
const self_path = "/test/system/services/vfs-test";
var file = fs.open(self_path, .{}) orelse {
_ = logging.write("vfstest: open of own binary failed\n");
return;
};
defer file.close();
const attributes = file.attributes() orelse {
_ = logging.write("vfstest: attributes failed\n");
return;
};
if (attributes.kind != .regular or attributes.size == 0) {
_ = logging.write("vfstest: bad attributes\n");
return;
}
var header: [4]u8 = undefined;
const n = file.read(&header) orelse 0;
if (n != 4 or header[0] != 0x7f or header[1] != 'E' or header[2] != 'L' or header[3] != 'F') {
_ = logging.write("vfstest: ELF magic mismatch\n");
return;
}
// The write refusal: the initrd trees are read-only by construction.
if (file.write("x") != null or fs.open("/test/system/services/new-file", .{ .create = true }) != null) {
_ = logging.write("vfstest: the initrd tree accepted a write\n");
return;
}
// Listing: /system/services contains init.
var saw_init = false;
if (fs.openDirectory("/system/services")) |listing| {
var directory = listing;
defer directory.close();
var entry: fs.Entry = .{};
while (directory.next(&entry)) {
if (std.mem.eql(u8, entry.name(), "init")) saw_init = true;
}
}
if (!saw_init) {
_ = logging.write("vfstest: /system/services listing missed init\n");
return;
}
while (true) {
_ = logging.write("vfstest: ok\n");
time.sleepMillis(1000);
}
}
fn park() void {
// The storage chain (usb -> block -> fat -> mounts) takes a few seconds;
// retry until the volume appears.
var parked: ?fs.File = null;
var tries: u32 = 0;
while (parked == null and tries < 1000) : (tries += 1) {
parked = fs.open("/volumes/usb/parked", .{ .create = true });
if (parked == null) time.sleepMillis(20);
}
if (parked == null) {
_ = logging.write("vfstest: park open failed\n");
return;
}
// Mount ownership (V0, docs/volume-manager-plan.md): the volume is
// provably mounted (the parked file just opened on it), it is FAT's mount,
// and this process is not fat — unmounting it must be REFUSED and the
// subtree must still resolve afterwards. Bailing here withholds the
// "parked" marker, which fails the vfs-client-death case: before the
// ownership gate existed, any process could unmount any prefix, and this
// fixture would have deleted the volume out from under the whole boot.
if (fs.fsUnmount("/volumes/usb")) {
_ = logging.write("vfstest: foreign unmount was ALLOWED\n");
return;
}
if (fs.open("/volumes/usb/parked", .{})) |resolved| {
var verification = resolved;
verification.close(); // the park below must be the client's ONLY open
// handle — the kernel test string-matches "released 1 handle(s)".
} else {
_ = logging.write("vfstest: /volumes/usb gone after refused unmount\n");
return;
}
_ = logging.write("vfstest: foreign unmount refused\n");
while (true) {
_ = logging.write("vfstest: parked\n");
time.sleepMillis(500);
}
}