diff options
| author | Gabriel Schneider <[email protected]> | 2026-09-21 23:53:58 -0300 |
|---|---|---|
| committer | Gabriel Schneider <[email protected]> | 2026-10-01 00:12:14 -0300 |
| commit | 16717a555695ef666e9d2cd1bacc762a2ab15f4b (patch) | |
| tree | bc1dcfa686610e87ed81b8b4f4a11be9475a5655 /test | |
| parent | e714bbfa8b7cbf9970053cfbabbb9b1f02a2290e (diff) | |
| download | pardes-16717a555695ef666e9d2cd1bacc762a2ab15f4b.tar.gz pardes-16717a555695ef666e9d2cd1bacc762a2ab15f4b.zip | |
Fixes from three adversarial reviews, and a destructive one among them
The registry sweep could delete a live socket, anywhere on the filesystem. A
reviewer reproduced it: a socket that is bound but has not reached listen(2)
answers ECONNREFUSED exactly like a dead one -- that window is every server's
startup -- and the sweep then followed the entry's symlink and unlinked
whatever absolute path it named. It now follows a target only into the
directory our own sockets live in and only to a `pardes-9p-*.sock` name, it
re-probes immediately before deleting rather than trusting a probe that is by
then several syscalls old, and a readlink that exactly filled its buffer is
treated as the truncation it is. The test grew a case for an entry whose
target is not ours: the entry goes, the file does not.
Ctrl-V in raw tty mode was a black hole when the yank register was empty --
neither typed nor forwarded -- so vim's visual block, readline's quoted-insert
and every other program's Ctrl-V simply vanished. With nothing to paste the
chord belongs to the program again.
The lone-ESC flush added earlier was dead code. vaxis already returns Escape
for a one-byte 0x1b (`Parser.parseGround` asserts `input.len == 1`), so the
carried byte it waited for can never exist; a reviewer showed a 3 ms gap and a
60 ms gap behaving identically. Removed rather than left to imply a guarantee
it never provided.
A shell whose editor is gone can start one again. Naming a live but
unreachable session made `pardes <file>` exit 1, which let a stale environment
variable lock someone out of their own editor; it falls through to an ordinary
session, as it did before the variable existed.
Also: the macOS ABI check for `pardes_topbar_pane_border_px` had been replaced
by a duplicate of the line above it; `--startup` now fails on a leak the way
every other measurement in that file does, and stops calling its maximum a p95
below twenty samples; the served README and the skill no longer tell you to
write to `data` with `>`, which truncates the whole body before the write
lands; `docs/v9fs.md` described the allocate-on-walk design that was rejected;
and `test/fs.py` keys nesting off `PARDES_PID`, so its forwarding case stops
passing only when the runner happens to be inside a live pardes.
fs-test now reaches its one documented pre-existing failure instead of dying
early. Suite 778/783 with the two known crashes.
Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
Diffstat (limited to 'test')
| -rw-r--r-- | test/fs.py | 19 | ||||
| -rw-r--r-- | test/perf.zig | 9 |
2 files changed, 23 insertions, 5 deletions
@@ -470,7 +470,13 @@ def test(binary, quic=False): spaced = child_dir / 'space name.txt' spaced.write_bytes(b'first line\nsecond line\n') env = os.environ.copy() - env.update(PARDES_9P=str(address), PARDES_PANE='1', PARDES_FORWARD_LOOK='1') + # PARDES_PID is what says "you are inside a pardes"; the socket + # and the pane only say how to reach it. Without the pid the child + # starts its own session, so this test used to pass only when the + # runner itself happened to be running inside one. + status = dict(line.split(maxsplit=1) for line in client.read('/status').decode().splitlines()) + env.update(PARDES_9P=str(address), PARDES_PANE='1', PARDES_PID=status['pid']) + env.pop('PARDES_FORWARD_LOOK', None) for word, expected, selected, reuse in [('space name.txt:2:4', spaced.read_bytes(), [14, 14], False), ('/n/self/pane/1/body', b'initial\n', None, False), ('/virtual/pane/1/body:1:2-4', b'initial\n', [1, 4], True)]: @@ -518,7 +524,7 @@ def test(binary, quic=False): assert time.monotonic() < deadline, 'forwarding fixture Dump did not finish' time.sleep(.005) before = client.read('/index') - inherited = {key: env[key] for key in ['PARDES_9P', 'PARDES_PANE', 'PARDES_FORWARD_LOOK']} + inherited = {key: env[key] for key in ['PARDES_9P', 'PARDES_PANE', 'PARDES_PID']} cases = [ ('mount', ['--mount=peer=' + str(address), '/n/peer/pane/1/body'], None), ('name', ['--9p=forwarded-name'], 'forwarded-name'), @@ -543,7 +549,10 @@ def test(binary, quic=False): assert local.read('/index') == before assert local.read('/pane/1/body') == b'initial\n' else: - assert len(index) == (3 if name == 'shells' else 1), index + # A bare tty launch is a shell plus the empty text pane + # the boot puts under it; --shells=3 is the classic + # three-shell layout and has no scratch. + assert len(index) == (3 if name == 'shells' else 2), index if name in ['tcp', 'quic']: assert (name + '!127.0.0.1!').encode() in local.read('/listeners') assert client.read('/index') == before @@ -554,7 +563,9 @@ def test(binary, quic=False): ('stale-missing', dict(inherited, PARDES_9P=str(root / 'absent.sock')), 'missing-child-file.txt'), ('stale-noarg', dict(inherited, PARDES_9P=str(root / 'absent.sock')), None), ('stale-pane', dict(inherited, PARDES_PANE='4294967295'), str(spaced)), - ('disabled', dict(inherited, PARDES_FORWARD_LOOK='0'), str(spaced)), + # No pid means "not inside a pardes at all", which is what + # --nested withholds and what a plain shell has. + ('not-nested', {k: v for k, v in inherited.items() if k != 'PARDES_PID'}, str(spaced)), ]: with session(binary, root, name, tty=True, inherited=identity, launch=['--tty', *([word] if word else [])]) as (local, local_address): diff --git a/test/perf.zig b/test/perf.zig index 8f463204..5ac38ccf 100644 --- a/test/perf.zig +++ b/test/perf.zig @@ -200,6 +200,10 @@ fn measureStartup(io: std.Io, reps: usize, json: bool) !void { bytes += counter.bytes; peak = @max(peak, counter.peak); } + // Every other measurement in this file checks the session gave + // everything back; a boot that leaks is exactly what a startup + // benchmark should be the first to notice. + if (counter.live != 0) return error.LeakedStartupMemory; } std.mem.sort(u64, init_samples, {}, std.sort.asc(u64)); std.mem.sort(u64, frame_samples, {}, std.sort.asc(u64)); @@ -212,7 +216,10 @@ fn measureStartup(io: std.Io, reps: usize, json: bool) !void { .reps = reps, .cold_ns = cold_ns, .init_median_ns = init_samples[reps / 2], - .init_p95_ns = init_samples[@min(reps - 1, reps * 95 / 100)], + // A p95 needs at least twenty samples to be one; below that this + // is the maximum and says so rather than dressing it up. + .init_p95_ns = if (reps >= 20) init_samples[reps * 95 / 100] else init_samples[reps - 1], + .init_max_ns = init_samples[reps - 1], .frame_median_ns = frame_samples[reps / 2], .allocations = calls / reps, .allocated_bytes = bytes / reps, |
