Skip to content

Check fuzzer invariants at every pageheap_lock drop, not only in subprograms. - #1152

Merged
copybara-service[bot] merged 1 commit into
masterfrom
test_988868459
Sep 29, 2026
Merged

copybara-service[bot] merged 1 commit into
masterfrom
test_988868459

Conversation

@copybara-service

@copybara-service copybara-service Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

Check fuzzer invariants at every pageheap_lock drop, not only in subprograms.

The HugePageFiller and HugePageAwareAllocator fuzzers checked their invariants
after each instruction, so the accounting the allocator exposes while
pageheap_lock is dropped was only examined when a reentrant subprogram happened
to be queued for that drop. Check it unconditionally from OnLockDropped, before
any subprogram runs: another thread could take the lock at every drop, whether
or not the fuzzer interleaves work there. The filler also invokes two of its
hooks under the lock (VMA naming when retiring a tracker, IsHugepageBacked
from Print); those hooks now skip the check themselves, with TODOs to move
the calls off the lock, rather than relying on OnLockDropped to notice.

A counter distinguishes these checks from the top level so the relaxation
that already applies inside a subprogram, unmapped_pages() running ahead of
released_set in the filler fuzzer, applies to them too. The filler fuzzer's
teardown now retires each allocation's live pages before Put, as Deallocate
does, since the final Put unbacks the remainder of a partially released
hugepage with the lock dropped.

The allocator fuzzer also models HugePageAwareAllocator::Delete of a donated
span longer than a hugepage: the whole hugepages go back to HugeCache, which
unbacks them with the lock dropped when over its limit, before the span's tail
goes back to the filler, so the tail reads as used at those drops. Which of
the Deletes a subprogram interrupted have reached the filler is not observable,
so any subset of their tails may be held. SlackHeldDuringCacheRelease pins the
single-Delete case.

@copybara-service
copybara-service Bot force-pushed the test_988868459 branch 9 times, most recently from c670769 to 7d2c98c Compare September 29, 2026 04:10
…rograms.

The HugePageFiller and HugePageAwareAllocator fuzzers checked their invariants
after each instruction, so the accounting the allocator exposes while
pageheap_lock is dropped was only examined when a reentrant subprogram happened
to be queued for that drop. Check it unconditionally from OnLockDropped, before
any subprogram runs: another thread could take the lock at every drop, whether
or not the fuzzer interleaves work there.  The filler also invokes two of its
hooks under the lock (VMA naming when retiring a tracker, IsHugepageBacked
from Print); those hooks now skip the check themselves, with TODOs to move
the calls off the lock, rather than relying on OnLockDropped to notice.

A counter distinguishes these checks from the top level so the relaxation
that already applies inside a subprogram, unmapped_pages() running ahead of
released_set in the filler fuzzer, applies to them too. The filler fuzzer's
teardown now retires each allocation's live pages before Put, as Deallocate
does, since the final Put unbacks the remainder of a partially released
hugepage with the lock dropped.

The allocator fuzzer also models HugePageAwareAllocator::Delete of a donated
span longer than a hugepage: the whole hugepages go back to HugeCache, which
unbacks them with the lock dropped when over its limit, before the span's tail
goes back to the filler, so the tail reads as used at those drops. Which of
the Deletes a subprogram interrupted have reached the filler is not observable,
so any subset of their tails may be held. SlackHeldDuringCacheRelease pins the
single-Delete case.

PiperOrigin-RevId: 990033193
@copybara-service
copybara-service Bot merged commit 6722b50 into master Sep 29, 2026
19 checks passed
@copybara-service
copybara-service Bot deleted the test_988868459 branch September 29, 2026 04:35

This branch was successfully deployed

1 active deployment
github-pages — 6722b50b Deployed Sep 29, 2026 by github-pages[bot] via deploy #2824
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant