Skip to content

Commit 3dbe8a9

Browse files
committed
tests/lapi: add coroutine test
The patch adds a fuzzing tests for Lua coroutine library.
1 parent bfac9d7 commit 3dbe8a9

File tree

1 file changed

+168
-0
lines changed

1 file changed

+168
-0
lines changed

tests/lapi/coroutine_test.lua

Lines changed: 168 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,168 @@
1+
--[[
2+
SPDX-License-Identifier: ISC
3+
Copyright (c) 2023-2025, Sergey Bronnikov.
4+
5+
2.6 – Coroutines
6+
https://www.lua.org/manual/5.3/manual.html#2.6
7+
8+
Computation of stack limit when entering a coroutine is wrong,
9+
https://github.com/lua/lua/commit/e1d8770f12542d34a3e32b825c95b93f8a341ee1
10+
11+
C-stack overflow with deep nesting of coroutine.close,
12+
https://www.lua.org/bugs.html#5.4.4-9
13+
14+
C stack overflow (again),
15+
https://github.com/lua/lua/commit/34affe7a63fc5d842580a9f23616d057e17dfe27
16+
17+
When a coroutine tries to resume a non-suspended coroutine,
18+
it can do some mess (and break C assertions) before detecting the error,
19+
https://www.lua.org/bugs.html#5.3.3-4
20+
21+
debug.getlocal on a coroutine suspended in a hook can crash the interpreter,
22+
https://www.lua.org/bugs.html#5.3.0-2
23+
24+
Suspended __le metamethod can give wrong result,
25+
https://www.lua.org/bugs.html#5.3.0-3
26+
27+
Resuming the running coroutine makes it unyieldable,
28+
https://www.lua.org/bugs.html#5.2.2-8
29+
30+
pcall may not restore previous error function when inside coroutines,
31+
https://www.lua.org/bugs.html#5.2.1-2
32+
33+
Wrong handling of nCcalls in coroutines,
34+
https://www.lua.org/bugs.html#5.2.0-4
35+
36+
coroutine.resume pushes element without ensuring stack size,
37+
https://www.lua.org/bugs.html#5.1.3-2
38+
39+
Recursive coroutines may overflow C stack,
40+
https://www.lua.org/bugs.html#5.1.2-4
41+
42+
Stand-alone interpreter shows incorrect error message when the
43+
"message" is a coroutine,
44+
https://www.lua.org/bugs.html#5.1.2-12
45+
46+
Debug hooks may get wrong when mixed with coroutines,
47+
https://www.lua.org/bugs.html#5.1-7
48+
49+
Values held in open upvalues of suspended threads may be
50+
incorrectly collected,
51+
https://www.lua.org/bugs.html#5.0.2-3
52+
53+
Attempt to resume a running coroutine crashes Lua,
54+
https://www.lua.org/bugs.html#5.0-2
55+
56+
debug.getlocal on a coroutine suspended in a hook can crash the interpreter,
57+
https://www.lua.org/bugs.html#5.3.0-2
58+
59+
debug.sethook/gethook may overflow the thread's stack,
60+
https://www.lua.org/bugs.html#5.1.2-13
61+
62+
Memory hoarding when creating Lua hooks for coroutines,
63+
https://www.lua.org/bugs.html#5.2.0-1
64+
65+
Synopsis:
66+
67+
coroutine.close(co)
68+
coroutine.create(f)
69+
coroutine.isyieldable([co])
70+
coroutine.resume(co [, val1, ...])
71+
coroutine.running()
72+
coroutine.status(co)
73+
coroutine.wrap(f)
74+
coroutine.yield(...)
75+
]]
76+
77+
local luzer = require("luzer")
78+
local test_lib = require("lib")
79+
80+
local CORO_OBJECTS
81+
82+
-- Possible coroutine statuses, described in Lua 5.1 Reference Manual,
83+
-- https://www.lua.org/manual/5.4/manual.html#6.2
84+
local CORO_STATUS = {
85+
DEAD = "dead",
86+
NORMAL = "normal",
87+
RUNNING = "running",
88+
SUSPENDED = "suspended",
89+
}
90+
91+
local CORO_ACTION_NAME = {
92+
"close",
93+
"create",
94+
"resume",
95+
"yield",
96+
}
97+
98+
-- Forward declaration.
99+
local coro_function
100+
101+
local function hook_func(_event)
102+
local level = 2
103+
local i = 1
104+
while true do
105+
local name, v = debug.getlocal(level, i)
106+
io.stderr:write(name .. "\n")
107+
i = i + 1
108+
end
109+
end
110+
111+
local function sethook(co, fdp)
112+
local set_hook = fdp:consume_boolean()
113+
local hook_args = {}
114+
if not set_hook then
115+
return
116+
end
117+
table.insert(hook_args, hook_func)
118+
table.insert(hook_args, fdp:oneof({"c", "r", "l"}))
119+
debug.sethook(co, unpack(hook_args))
120+
end
121+
122+
local function coro_random_action(fdp, coro_max_number)
123+
local action = fdp:oneof(CORO_ACTION_NAME)
124+
if action == "create" or #CORO_OBJECTS < coro_max_number then
125+
local co = coroutine.create(coro_function)
126+
table.insert(CORO_OBJECTS, co)
127+
end
128+
129+
action = fdp:oneof(CORO_ACTION_NAME)
130+
local co, co_idx = fdp:oneof(CORO_OBJECTS)
131+
if coroutine.status(co) == CORO_STATUS["DEAD"] then
132+
-- FIXME: Remove `coro` in `CORO_OBJECTS`,
133+
-- https://github.com/ligurio/luzer/pull/57.
134+
assert(co_idx)
135+
table.remove(CORO_OBJECTS, co_idx)
136+
return
137+
elseif action == "close" then
138+
coroutine.close(co)
139+
elseif action == "yield" and coroutine.isyieldable(co) then
140+
coroutine.yield(co)
141+
elseif action == "resume" then
142+
coroutine.resume(co)
143+
end
144+
sethook(co, fdp)
145+
end
146+
147+
coro_function = function(fdp, coro_max_number)
148+
local iter = fdp:consume_integer(1, test_lib.MAX_INT)
149+
for _ = 1, iter do
150+
coro_random_action(fdp, coro_max_number)
151+
end
152+
end
153+
154+
local function TestOneInput(buf, _size)
155+
CORO_OBJECTS = {}
156+
local fdp = luzer.FuzzedDataProvider(buf)
157+
local coro_max_number = fdp:consume_integer(1, 1000)
158+
local co = coroutine.create(coro_function)
159+
table.insert(CORO_OBJECTS, co)
160+
-- The function `coroutine.resume` starts the execution of
161+
-- a coroutine, changing its state from suspended to running.
162+
coroutine.resume(co, fdp, coro_max_number)
163+
end
164+
165+
local args = {
166+
artifact_prefix = "coroutine_",
167+
}
168+
luzer.Fuzz(TestOneInput, nil, args)

0 commit comments

Comments
 (0)