fix(lint): trailing-label CFG guard and the goroutine alias

Assisted-by: GLM 5.3
This commit is contained in:
2026-09-19 23:49:19 +02:00
parent a8bfd54ed2
commit eb8b0cd316
4 changed files with 176 additions and 15 deletions
+119 -2
View File
@@ -3,7 +3,12 @@
package lint
import "testing"
import (
"testing"
"sourcedock.dev/petrbalvin/gasm-devkit/arch"
"sourcedock.dev/petrbalvin/gasm-devkit/parser"
)
// TestRegisterClobber checks the register-clobber audit is calibrated to the
// Go ABI (cmd/compile/abi-internal.md), not the platform ABI: Go's
@@ -134,6 +139,95 @@ func TestRegisterClobber(t *testing.T) {
}
}
// TestRegisterClobberGoroutineAlias checks the architectural alias `g` for
// the goroutine register. go tool asm accepts it on every architecture
// (lowercase only), and on arm64, riscv64 and loong64 it is the only
// spelling of the register at all, so a clobber written through the alias
// must be audited exactly like the numeric one.
func TestRegisterClobberGoroutineAlias(t *testing.T) {
// amd64: `g` is R14, a runtime-class register: the NOSPLIT-leaf pattern
// of the runtime's own assembly stays unflagged, a call makes it a
// hazard.
leaf := lintSrc(t, "#include \"textflag.h\"\n"+
"TEXT ·f(SB), NOSPLIT, $0\n"+
"\tMOVQ AX, g\n"+
"\tRET\n")
if codes(leaf)[CodeRegisterClobber] != 0 {
t.Fatalf("amd64 g in a NOSPLIT leaf must not be flagged: %+v", leaf)
}
withCall := lintSrc(t, "#include \"textflag.h\"\n"+
"TEXT ·f(SB), NOSPLIT, $0\n"+
"\tMOVQ AX, g\n"+
"\tCALL ·h(SB)\n"+
"\tRET\n")
if codes(withCall)[CodeRegisterClobber] != 1 {
t.Fatalf("amd64 unsaved g with a call should be flagged: %+v", withCall)
}
// arm64, riscv64, loong64: the goroutine register is always-fixed, so an
// unsaved write through the alias is flagged; a bare read is not.
for _, tc := range []struct{ filename, src string }{
{"t_arm64.s", "#include \"textflag.h\"\n" + "TEXT ·f(SB), NOSPLIT, $0\n" + "\tMOVD R0, g\n" + "\tRET\n"},
{"t_riscv64.s", "#include \"textflag.h\"\n" + "TEXT ·f(SB), NOSPLIT, $0\n" + "\tMOV X5, g\n" + "\tRET\n"},
{"t_loong64.s", "#include \"textflag.h\"\n" + "TEXT ·f(SB), NOSPLIT, $0\n" + "\tMOVV R5, g\n" + "\tRET\n"},
} {
if got := codes(lintSrcArch(t, tc.filename, tc.src))[CodeRegisterClobber]; got != 1 {
t.Fatalf("%s: unsaved write to g should be flagged once, got %d", tc.filename, got)
}
}
armRead := lintSrcArch(t, "t_arm64.s", "#include \"textflag.h\"\n"+
"TEXT ·f(SB), NOSPLIT, $0\n"+
"\tMOVD g, R1\n"+
"\tRET\n")
if codes(armRead)[CodeRegisterClobber] != 0 {
t.Fatalf("reading g must not be flagged: %+v", armRead)
}
}
// TestBranchToTrailingLabel pins the CFG guard for a label that ends a
// function body: no block is flushed for it, and the liveness dataflow must
// not index past the block list on the edge a branch to it would carry.
func TestBranchToTrailingLabel(t *testing.T) {
diags := lintSrc(t, "#include \"textflag.h\"\n"+
"TEXT ·f(SB), NOSPLIT, $0\n"+
"\tJMP done\n"+
"done:\n")
if codes(diags)[CodeRegisterClobber] != 0 {
t.Fatalf("branch to a trailing label must not be flagged: %+v", diags)
}
}
// TestConditionalBranchToTrailingLabel exercises a multi-operand conditional
// branch (CBZ R0, done): the branch target is the last bare-symbol operand,
// so the taken edge is wired to the trailing label and the guard of
// TestBranchToTrailingLabel is what keeps the dataflow in range. The run
// doubles as the termination check for the fixed-point loop.
func TestConditionalBranchToTrailingLabel(t *testing.T) {
diags := lintSrcArch(t, "t_arm64.s", "#include \"textflag.h\"\n"+
"TEXT ·f(SB), NOSPLIT, $0\n"+
"\tCBZ R0, done\n"+
"\tRET\n"+
"done:\n")
if codes(diags)[CodeRegisterClobber] != 0 {
t.Fatalf("conditional branch to a trailing label must not be flagged: %+v", diags)
}
}
// TestMalformedTextNoSymbol checks that a TEXT line without a symbol name,
// which the parser keeps in the tree under a "?" placeholder, lints without
// a panic and still reports the ordinary findings.
func TestMalformedTextNoSymbol(t *testing.T) {
f, _ := parser.Parse("test_amd64.s", "// func f(a int) int\nTEXT $0\n\tMOVQ AX, BX\n")
diags := File(f, Config{Arch: arch.AMD64})
c := codes(diags)
if c[CodeMissingRet] != 1 {
t.Fatalf("malformed TEXT should report missing-ret, got %+v", diags)
}
if c[CodeABI0RegisterArgs] != 1 {
t.Fatalf("malformed TEXT should report abi0-register-args, got %+v", diags)
}
}
// TestFuncdata validates the FUNCDATA/PCDATA structural checks.
func TestFuncdata(t *testing.T) {
// Well formed: no findings.
@@ -164,7 +258,8 @@ func TestFuncdata(t *testing.T) {
t.Fatal("PCDATA with a register value should be flagged")
}
// FUNCDATA index out of range.
// FUNCDATA index out of range: the Go 1.27 runtime defines 0-7
// (FUNCDATA_WrapInfo) and PCDATA 0-4 (PCDATA_PanicBounds).
bad3 := lintSrc(t, "#include \"textflag.h\"\n"+
"TEXT ·f(SB), NOSPLIT, $0\n"+
"\tFUNCDATA $99, gclocals·abc(SB)\n"+
@@ -172,4 +267,26 @@ func TestFuncdata(t *testing.T) {
if codes(bad3)[CodeFuncdata] == 0 {
t.Fatal("out-of-range FUNCDATA index should be flagged")
}
fdHigh := lintSrc(t, "#include \"textflag.h\"\n"+
"TEXT ·f(SB), NOSPLIT, $0\n"+
"\tFUNCDATA $7, gclocals·abc(SB)\n"+
"\tPCDATA $4, $0\n"+
"\tRET\n")
if codes(fdHigh)[CodeFuncdata] != 0 {
t.Fatalf("the highest defined FUNCDATA/PCDATA indices must pass: %+v", fdHigh)
}
fdOver := lintSrc(t, "#include \"textflag.h\"\n"+
"TEXT ·f(SB), NOSPLIT, $0\n"+
"\tFUNCDATA $8, gclocals·abc(SB)\n"+
"\tRET\n")
if codes(fdOver)[CodeFuncdata] != 1 {
t.Fatal("FUNCDATA index above FUNCDATA_WrapInfo should be flagged")
}
pcOver := lintSrc(t, "#include \"textflag.h\"\n"+
"TEXT ·f(SB), NOSPLIT, $0\n"+
"\tPCDATA $5, $0\n"+
"\tRET\n")
if codes(pcOver)[CodeFuncdata] != 1 {
t.Fatal("PCDATA index above PCDATA_PanicBounds should be flagged")
}
}