1 /* Copyright (c) 2008-2022. The SimGrid Team. All rights reserved. */
3 /* This program is free software; you can redistribute it and/or modify it
4 * under the terms of the license (GNU LGPL) which comes with this package. */
6 #include "src/mc/ModelChecker.hpp"
7 #include "src/mc/explo/Exploration.hpp"
8 #include "src/mc/explo/LivenessChecker.hpp"
9 #include "src/mc/mc_config.hpp"
10 #include "src/mc/mc_exit.hpp"
11 #include "src/mc/mc_private.hpp"
12 #include "src/mc/remote/RemoteProcess.hpp"
13 #include "src/mc/transition/TransitionComm.hpp"
14 #include "xbt/automaton.hpp"
15 #include "xbt/system_error.hpp"
19 #include <sys/ptrace.h>
22 XBT_LOG_NEW_DEFAULT_SUBCATEGORY(mc_ModelChecker, mc, "ModelChecker");
24 ::simgrid::mc::ModelChecker* mc_model_checker = nullptr;
27 # define WAITPID_CHECKED_FLAGS __WALL
29 # define WAITPID_CHECKED_FLAGS 0
32 namespace simgrid::mc {
34 ModelChecker::ModelChecker(std::unique_ptr<RemoteProcess> remote_simulation, int sockfd)
35 : checker_side_(sockfd), remote_process_(std::move(remote_simulation))
39 void ModelChecker::start()
42 [](evutil_socket_t sig, short events, void* arg) {
43 auto mc = static_cast<simgrid::mc::ModelChecker*>(arg);
44 if (events == EV_READ) {
45 std::array<char, MC_MESSAGE_LENGTH> buffer;
46 ssize_t size = mc->checker_side_.get_channel().receive(buffer.data(), buffer.size(), false);
47 if (size == -1 && errno != EAGAIN)
48 throw simgrid::xbt::errno_error();
50 if (not mc->handle_message(buffer.data(), size))
51 mc->checker_side_.break_loop();
52 } else if (events == EV_SIGNAL) {
56 xbt_die("Unexpected event");
61 XBT_DEBUG("Waiting for the model-checked process");
64 // The model-checked process SIGSTOP itself to signal it's ready:
65 const pid_t pid = remote_process_->pid();
67 xbt_assert(waitpid(pid, &status, WAITPID_CHECKED_FLAGS) == pid && WIFSTOPPED(status) && WSTOPSIG(status) == SIGSTOP,
68 "Could not wait model-checked process");
70 if (not _sg_mc_dot_output_file.get().empty()) {
71 dot_output_ = fopen(_sg_mc_dot_output_file.get().c_str(), "w");
72 xbt_assert(dot_output_ != nullptr, "Error open dot output file: %s", strerror(errno));
74 fprintf(dot_output_, "digraph graphname{\n fixedsize=true; rankdir=TB; ranksep=.25; edge [fontsize=12]; node "
75 "[fontsize=10, shape=circle,width=.5 ]; graph [resolution=20, fontsize=10];\n");
82 ptrace(PTRACE_SETOPTIONS, pid, nullptr, PTRACE_O_TRACEEXIT);
83 ptrace(PTRACE_CONT, pid, 0, 0);
85 ptrace(PT_CONTINUE, pid, (caddr_t)1, 0);
87 # error "no ptrace equivalent coded for this platform"
89 xbt_assert(errno == 0,
90 "Ptrace does not seem to be usable in your setup (errno: %d). "
91 "If you run from within a docker, adding `--cap-add SYS_PTRACE` to the docker line may help. "
92 "If it does not help, please report this bug.",
96 void ModelChecker::dot_output(const char* fmt, ...)
98 if (dot_output_ != nullptr) {
101 vfprintf(dot_output_, fmt, ap);
106 static constexpr auto ignored_local_variables = {
107 std::make_pair("e", "*"),
108 std::make_pair("_log_ev", "*"),
110 /* Ignore local variable about time used for tracing */
111 std::make_pair("start_time", "*"),
114 void ModelChecker::setup_ignore()
116 const RemoteProcess& process = this->get_remote_process();
117 for (auto const& [var, frame] : ignored_local_variables)
118 process.ignore_local_variable(var, frame);
120 /* Static variable used for tracing */
121 process.ignore_global_variable("counter");
124 void ModelChecker::shutdown()
126 XBT_DEBUG("Shutting down model-checker");
128 RemoteProcess& process = get_remote_process();
129 if (process.running()) {
130 XBT_DEBUG("Killing process");
132 kill(process.pid(), SIGKILL);
137 void ModelChecker::resume()
139 if (checker_side_.get_channel().send(MessageType::CONTINUE) != 0)
140 throw xbt::errno_error();
141 remote_process_->clear_cache();
144 static void MC_report_crash(Exploration* explorer, int status)
146 XBT_INFO("**************************");
147 XBT_INFO("** CRASH IN THE PROGRAM **");
148 XBT_INFO("**************************");
149 if (WIFSIGNALED(status))
150 XBT_INFO("From signal: %s", strsignal(WTERMSIG(status)));
151 else if (WIFEXITED(status))
152 XBT_INFO("From exit: %i", WEXITSTATUS(status));
153 if (not xbt_log_no_loc)
154 XBT_INFO("%s core dump was generated by the system.", WCOREDUMP(status) ? "A" : "No");
156 XBT_INFO("Counter-example execution trace:");
157 for (auto const& s : explorer->get_textual_trace())
158 XBT_INFO(" %s", s.c_str());
159 XBT_INFO("Path = %s", explorer->get_record_trace().to_string().c_str());
160 explorer->log_state();
161 if (xbt_log_no_loc) {
162 XBT_INFO("Stack trace not displayed because you passed --log=no_loc");
164 XBT_INFO("Stack trace:");
165 mc_model_checker->get_remote_process().dump_stack();
170 bool ModelChecker::handle_message(const char* buffer, ssize_t size)
172 s_mc_message_t base_message;
173 xbt_assert(size >= (ssize_t)sizeof(base_message), "Broken message");
174 memcpy(&base_message, buffer, sizeof(base_message));
176 switch(base_message.type) {
177 case MessageType::INITIAL_ADDRESSES: {
178 s_mc_message_initial_addresses_t message;
179 xbt_assert(size == sizeof(message), "Broken message. Got %d bytes instead of %d.", (int)size, (int)sizeof(message));
180 memcpy(&message, buffer, sizeof(message));
182 get_remote_process().init(message.mmalloc_default_mdp, message.maxpid);
186 case MessageType::IGNORE_HEAP: {
187 s_mc_message_ignore_heap_t message;
188 xbt_assert(size == sizeof(message), "Broken message");
189 memcpy(&message, buffer, sizeof(message));
191 IgnoredHeapRegion region;
192 region.block = message.block;
193 region.fragment = message.fragment;
194 region.address = message.address;
195 region.size = message.size;
196 get_remote_process().ignore_heap(region);
200 case MessageType::UNIGNORE_HEAP: {
201 s_mc_message_ignore_memory_t message;
202 xbt_assert(size == sizeof(message), "Broken message");
203 memcpy(&message, buffer, sizeof(message));
204 get_remote_process().unignore_heap((void*)(std::uintptr_t)message.addr, message.size);
208 case MessageType::IGNORE_MEMORY: {
209 s_mc_message_ignore_memory_t message;
210 xbt_assert(size == sizeof(message), "Broken message");
211 memcpy(&message, buffer, sizeof(message));
212 this->get_remote_process().ignore_region(message.addr, message.size);
216 case MessageType::STACK_REGION: {
217 s_mc_message_stack_region_t message;
218 xbt_assert(size == sizeof(message), "Broken message");
219 memcpy(&message, buffer, sizeof(message));
220 this->get_remote_process().stack_areas().push_back(message.stack_region);
223 case MessageType::REGISTER_SYMBOL: {
224 s_mc_message_register_symbol_t message;
225 xbt_assert(size == sizeof(message), "Broken message");
226 memcpy(&message, buffer, sizeof(message));
227 xbt_assert(not message.callback, "Support for client-side function proposition is not implemented.");
228 XBT_DEBUG("Received symbol: %s", message.name.data());
230 LivenessChecker::automaton_register_symbol(get_remote_process(), message.name.data(), remote((int*)message.data));
234 case MessageType::WAITING:
237 case MessageType::ASSERTION_FAILED:
238 XBT_INFO("**************************");
239 XBT_INFO("*** PROPERTY NOT VALID ***");
240 XBT_INFO("**************************");
241 XBT_INFO("Counter-example execution trace:");
242 for (auto const& s : get_exploration()->get_textual_trace())
243 XBT_INFO(" %s", s.c_str());
244 XBT_INFO("Path = %s", get_exploration()->get_record_trace().to_string().c_str());
245 exploration_->log_state();
247 this->exit(SIMGRID_MC_EXIT_SAFETY);
250 xbt_die("Unexpected message from model-checked application");
255 /** Terminate the model-checker application */
256 void ModelChecker::exit(int status)
262 void ModelChecker::handle_waitpid()
264 XBT_DEBUG("Check for wait event");
267 while ((pid = waitpid(-1, &status, WNOHANG)) != 0) {
269 if (errno == ECHILD) {
271 xbt_assert(not this->get_remote_process().running(), "Inconsistent state");
274 XBT_ERROR("Could not wait for pid");
275 throw simgrid::xbt::errno_error();
279 if (pid == this->get_remote_process().pid()) {
280 // From PTRACE_O_TRACEEXIT:
282 if (status>>8 == (SIGTRAP | (PTRACE_EVENT_EXIT<<8))) {
283 xbt_assert(ptrace(PTRACE_GETEVENTMSG, remote_process_->pid(), 0, &status) != -1, "Could not get exit status");
284 if (WIFSIGNALED(status)) {
285 MC_report_crash(exploration_, status);
286 this->get_remote_process().terminate();
287 this->exit(SIMGRID_MC_EXIT_PROGRAM_CRASH);
292 // We don't care about signals, just reinject them:
293 if (WIFSTOPPED(status)) {
294 XBT_DEBUG("Stopped with signal %i", (int) WSTOPSIG(status));
297 ptrace(PTRACE_CONT, remote_process_->pid(), 0, WSTOPSIG(status));
299 ptrace(PT_CONTINUE, remote_process_->pid(), (caddr_t)1, WSTOPSIG(status));
301 xbt_assert(errno == 0, "Could not PTRACE_CONT");
304 else if (WIFSIGNALED(status)) {
305 MC_report_crash(exploration_, status);
306 this->get_remote_process().terminate();
307 this->exit(SIMGRID_MC_EXIT_PROGRAM_CRASH);
308 } else if (WIFEXITED(status)) {
309 XBT_DEBUG("Child process is over");
310 this->get_remote_process().terminate();
316 void ModelChecker::wait_for_requests()
319 if (this->get_remote_process().running())
320 checker_side_.dispatch();
323 Transition* ModelChecker::handle_simcall(aid_t aid, int times_considered, bool new_transition)
325 s_mc_message_simcall_execute_t m;
326 memset(&m, 0, sizeof(m));
327 m.type = MessageType::SIMCALL_EXECUTE;
329 m.times_considered_ = times_considered;
330 checker_side_.get_channel().send(m);
332 this->remote_process_->clear_cache();
333 if (this->remote_process_->running())
334 checker_side_.dispatch(); // The app may send messages while processing the transition
336 s_mc_message_simcall_execute_answer_t answer;
337 ssize_t s = checker_side_.get_channel().receive(answer);
338 xbt_assert(s != -1, "Could not receive message");
339 xbt_assert(s == sizeof(answer) && answer.type == MessageType::SIMCALL_EXECUTE_ANSWER,
340 "Received unexpected message %s (%i, size=%i) "
341 "expected MessageType::SIMCALL_EXECUTE_ANSWER (%i, size=%i)",
342 to_c_str(answer.type), (int)answer.type, (int)s, (int)MessageType::SIMCALL_EXECUTE_ANSWER,
343 (int)sizeof(answer));
345 if (new_transition) {
346 std::stringstream stream(answer.buffer.data());
347 return deserialize_transition(aid, times_considered, stream);
352 void ModelChecker::finalize_app(bool terminate_asap)
354 s_mc_message_int_t m;
355 memset(&m, 0, sizeof m);
356 m.type = MessageType::FINALIZE;
357 m.value = terminate_asap;
358 xbt_assert(checker_side_.get_channel().send(m) == 0, "Could not ask the app to finalize on need");
360 s_mc_message_t answer;
361 ssize_t s = checker_side_.get_channel().receive(answer);
362 xbt_assert(s != -1, "Could not receive answer to FINALIZE");
363 xbt_assert(s == sizeof(answer) && answer.type == MessageType::FINALIZE_REPLY,
364 "Received unexpected message %s (%i, size=%i) expected MessageType::FINALIZE_REPLY (%i, size=%i)",
365 to_c_str(answer.type), (int)answer.type, (int)s, (int)MessageType::FINALIZE_REPLY, (int)sizeof(answer));
368 } // namespace simgrid::mc