Skip to content

Commit e645d46

Browse files
committed
tests/lapi: add coroutine test
The patch adds a fuzzing tests for Lua coroutine library.
1 parent bfac9d7 commit e645d46

File tree

1 file changed

+177
-0
lines changed

1 file changed

+177
-0
lines changed

tests/lapi/coroutine_test.lua

Lines changed: 177 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,177 @@
1+
--[[
2+
SPDX-License-Identifier: ISC
3+
Copyright (c) 2023-2025, Sergey Bronnikov.
4+
5+
2.6 – Coroutines
6+
https://www.lua.org/manual/5.3/manual.html#2.6
7+
8+
Computation of stack limit when entering a coroutine is wrong,
9+
https://github.com/lua/lua/commit/e1d8770f12542d34a3e32b825c95b93f8a341ee1
10+
11+
C-stack overflow with deep nesting of coroutine.close,
12+
https://www.lua.org/bugs.html#5.4.4-9
13+
14+
C stack overflow (again),
15+
https://github.com/lua/lua/commit/34affe7a63fc5d842580a9f23616d057e17dfe27
16+
17+
When a coroutine tries to resume a non-suspended coroutine,
18+
it can do some mess (and break C assertions) before detecting the error,
19+
https://www.lua.org/bugs.html#5.3.3-4
20+
21+
debug.getlocal on a coroutine suspended in a hook can crash the interpreter,
22+
https://www.lua.org/bugs.html#5.3.0-2
23+
24+
Suspended __le metamethod can give wrong result,
25+
https://www.lua.org/bugs.html#5.3.0-3
26+
27+
Resuming the running coroutine makes it unyieldable,
28+
https://www.lua.org/bugs.html#5.2.2-8
29+
30+
pcall may not restore previous error function when inside coroutines,
31+
https://www.lua.org/bugs.html#5.2.1-2
32+
33+
Wrong handling of nCcalls in coroutines,
34+
https://www.lua.org/bugs.html#5.2.0-4
35+
36+
coroutine.resume pushes element without ensuring stack size,
37+
https://www.lua.org/bugs.html#5.1.3-2
38+
39+
Recursive coroutines may overflow C stack,
40+
https://www.lua.org/bugs.html#5.1.2-4
41+
42+
Stand-alone interpreter shows incorrect error message when the
43+
"message" is a coroutine,
44+
https://www.lua.org/bugs.html#5.1.2-12
45+
46+
Debug hooks may get wrong when mixed with coroutines,
47+
https://www.lua.org/bugs.html#5.1-7
48+
49+
Values held in open upvalues of suspended threads may be
50+
incorrectly collected,
51+
https://www.lua.org/bugs.html#5.0.2-3
52+
53+
Attempt to resume a running coroutine crashes Lua,
54+
https://www.lua.org/bugs.html#5.0-2
55+
56+
debug.getlocal on a coroutine suspended in a hook can crash the interpreter,
57+
https://www.lua.org/bugs.html#5.3.0-2
58+
59+
debug.sethook/gethook may overflow the thread's stack,
60+
https://www.lua.org/bugs.html#5.1.2-13
61+
62+
Memory hoarding when creating Lua hooks for coroutines,
63+
https://www.lua.org/bugs.html#5.2.0-1
64+
65+
Synopsis:
66+
67+
coroutine.close(co)
68+
coroutine.create(f)
69+
coroutine.isyieldable([co])
70+
coroutine.resume(co [, val1, ...])
71+
coroutine.running()
72+
coroutine.status(co)
73+
coroutine.wrap(f)
74+
coroutine.yield(...)
75+
]]
76+
77+
local luzer = require("luzer")
78+
local test_lib = require("lib")
79+
80+
local CORO_OBJECTS
81+
82+
-- Possible coroutine statuses, described in Lua 5.1 Reference Manual,
83+
-- https://www.lua.org/manual/5.4/manual.html#6.2
84+
local CORO_STATUS = {
85+
DEAD = "dead",
86+
NORMAL = "normal",
87+
RUNNING = "running",
88+
SUSPENDED = "suspended",
89+
}
90+
91+
local CORO_ACTION_NAME = {
92+
"close",
93+
"create",
94+
"resume",
95+
"yield",
96+
}
97+
98+
-- Forward declaration.
99+
local coro_function
100+
101+
local function hook_func(_event)
102+
-- Accessing Locals,
103+
-- https://www.lua.org/pil/23.1.1.html.
104+
local level = 2
105+
local i = 1
106+
while true do
107+
local name, _ = debug.getlocal(level, i)
108+
if not name then break end
109+
i = i + 1
110+
end
111+
-- Accessing Upvalues,
112+
-- https://www.lua.org/pil/23.1.2.html
113+
local func = debug.getinfo(level).func
114+
i = 1
115+
while true do
116+
local name, _ = debug.getupvalue(func, i)
117+
if not name then break end
118+
i = i + 1
119+
end
120+
end
121+
122+
local function sethook(co, fdp)
123+
local set_hook = fdp:consume_boolean()
124+
local hook_args = {}
125+
if not set_hook then
126+
return
127+
end
128+
table.insert(hook_args, hook_func)
129+
table.insert(hook_args, fdp:oneof({"c", "r", "l"}))
130+
debug.sethook(co, unpack(hook_args))
131+
end
132+
133+
local function coro_random_action(fdp, coro_max_number)
134+
local action = fdp:oneof(CORO_ACTION_NAME)
135+
if action == "create" or #CORO_OBJECTS < coro_max_number then
136+
local co = coroutine.create(coro_function)
137+
table.insert(CORO_OBJECTS, co)
138+
end
139+
140+
action = fdp:oneof(CORO_ACTION_NAME)
141+
local co, co_idx = fdp:oneof(CORO_OBJECTS)
142+
if coroutine.status(co) == CORO_STATUS["DEAD"] then
143+
assert(co_idx)
144+
table.remove(CORO_OBJECTS, co_idx)
145+
return
146+
elseif action == "close" then
147+
coroutine.close(co)
148+
elseif action == "yield" and coroutine.isyieldable(co) then
149+
coroutine.yield(co)
150+
elseif action == "resume" then
151+
coroutine.resume(co)
152+
end
153+
sethook(co, fdp)
154+
end
155+
156+
coro_function = function(fdp, coro_max_number)
157+
local iter = fdp:consume_integer(1, test_lib.MAX_INT)
158+
for _ = 1, iter do
159+
coro_random_action(fdp, coro_max_number)
160+
end
161+
end
162+
163+
local function TestOneInput(buf, _size)
164+
CORO_OBJECTS = {}
165+
local fdp = luzer.FuzzedDataProvider(buf)
166+
local coro_max_number = fdp:consume_integer(1, 1000)
167+
local co = coroutine.create(coro_function)
168+
table.insert(CORO_OBJECTS, co)
169+
-- The function `coroutine.resume` starts the execution of
170+
-- a coroutine, changing its state from suspended to running.
171+
coroutine.resume(co, fdp, coro_max_number)
172+
end
173+
174+
local args = {
175+
artifact_prefix = "coroutine_",
176+
}
177+
luzer.Fuzz(TestOneInput, nil, args)

0 commit comments

Comments
 (0)