Commit Graph
12 Commits
Author SHA1 Message Date
Rich Felker 0ab97350f0 mq_notify: block all (application) signals in the worker thread
until the mq notification event arrives, it is mandatory that signals
be blocked. otherwise, a signal can be received, and its handler
executed, in a thread which does not yet exist on the abstract
machine.

after the point of the event arriving, having signals blocked is not a
conformance requirement but a QoI requirement. while the application
can unblock any signals it wants unblocked in the event handler
thread, if they did not start out blocked, it could not block them
without a race window where they are momentarily unblocked, and this
would preclude controlled delivery or other forms of acceptance
(sigwait, etc.) anywhere in the application.
2023-02-12 15:05:39 -05:00
Rich Felker 711673ee77 mq_notify: join worker thread before returning in error path
this avoids leaving behind transient resource consumption whose
cleanup is subject to scheduling behavior.
2023-02-12 15:05:38 -05:00
Rich Felker 8c0c9c69a1 mq_notify: rework to fix use-after-close/double-close bugs
in the error path where the mq_notify syscall fails, the initiating
thread may have closed the socket before the worker thread calls recv
on it. even in the absence of such a race, if the recv call failed,
e.g. due to seccomp policy blocking it, the worker thread could
proceed to close, producing a double-close condition.

this can all be simplified by moving the mq_notify syscall into the
new thread, so that the error case does not require pthread_cancel.
now, the initiating thread only needs to read back the error status
after waiting for the worker thread to consume its arguments.
2023-02-12 15:05:38 -05:00
Rich Felker fde6891e59 mq_notify: use semaphore instead of barrier to sync args consumption
semaphores are a much lighter primitive, and more idiomatic with
current usage in the code base.
2023-02-11 13:00:37 -05:00
Rich Felker 2ab90de7ac mq_timedsend, mq_timedreceive: add time64, decouple 32-bit time_t
time64 syscall is used only if it's the only one defined for the arch,
or if the requested absolute timeout does not fit in 32 bits. on
current 32-bit archs where time_t is a 32-bit type, this makes it
statically unreachable.

on 64-bit archs, there is no change to the code after preprocessing.
on current 32-bit archs, the timeout is passed via an intermediate
copy to remove the assumption that time_t is a 32-bit type.
2019-07-28 17:09:30 -04:00
Rich Felker 400c5e5c83 use restrict everywhere it's required by c99 and/or posix 2008
to deal with the fact that the public headers may be used with pre-c99
compilers, __restrict is used in place of restrict, and defined
appropriately for any supported compiler. we also avoid the form
[restrict] since older versions of gcc rejected it due to a bug in the
original c99 standard, and instead use the form *restrict.
2012-09-06 22:44:55 -04:00
Rich Felker 8b71121910 fix longstanding missing static in mq_notify (namespace pollution) 2012-04-29 00:20:53 -04:00
Rich Felker 4d95a58524 const correctness in mq_notify
why did gcc allow this invalid assignment to compile in the first place?
2011-06-25 09:23:36 -04:00
Rich Felker e1d2a8e239 mq names without leading / have impl-def behavior; allowing them is easier 2011-06-07 15:07:54 -04:00
Rich Felker 86f8c72bb1 mq send/recv functions are cancellation points 2011-06-07 11:14:39 -04:00
Rich Felker ede353d8e5 implement mq_notify 2011-06-07 02:42:55 -04:00
Rich Felker ab11386aaa add support for POSIX message queues, except mq_notify 2011-06-07 01:52:27 -04:00