nonvacuity.sh 60 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363
  1. #!/bin/sh
  2. # nonvacuity.sh -- prove the runtime checks can actually fail.
  3. #
  4. # A test that has never been seen red is not a test. This script breaks the
  5. # runtime on purpose, once per check, and asserts that the check goes red and
  6. # says something useful about the breakage. Then it restores the source and
  7. # asserts everything is green again.
  8. #
  9. # Each mutation below is a real bug that was in this file at some point, not an
  10. # invented one. That is the point: these are the mistakes we actually make
  11. # with 16-bit ModRM, so these are the ones the checks have to catch.
  12. #
  13. # audit_helpers.py name-versus-decode: catches a wrong ModRM that still
  14. # decodes cleanly, and both halves of a name that admits
  15. # an operand at all - `34 02' where the name promises
  16. # `34 01', and `35 01' where the row's opcode gate admits
  17. # only 34h. Both rows are new, and a row nobody has seen
  18. # reject anything accepts whatever it is shown.
  19. # audit_helpers.py coverage: catches a helper that has silently
  20. # dropped OUT of the audit, which is a green report about
  21. # a subject nobody looked at
  22. # run_com_tests.sh the .COM layout: catches a header that cannot be
  23. # located, a runtime size that disagrees with the image,
  24. # and an entry jump that starts in the wrong place
  25. # check_runtime.py golden: catches the same thing in the built
  26. # image
  27. # check_runtime.py decode sweep: catches a wrong instruction LENGTH
  28. # check_runtime.py branch targets: catches a wrong fixup
  29. # check_runtime.py entry goldens: catches a broken prologue
  30. # probe/modrm11.py the mod=11 table: catches the ModRM column itself
  31. # going wrong, which no amount of decoding will show
  32. # check_framedisp.py the BP disp rule: catches a displacement that reads
  33. # a different address than the symbol table named
  34. # rt_exec.py the BP contract: catches an entry that borrows BP to
  35. # reach its argument and does not hand it back. The bytes
  36. # are well formed, the golden is satisfied, the audit says
  37. # every helper emits what its name says, and the machine
  38. # triple-faults on the second call - so nothing short of
  39. # running it, or of stating the register contract
  40. # explicitly, can see it.
  41. # check_8086.py the 8086 opcodes: catches a conditional branch or a
  42. # SETcc emitted as `0F 8x'/`0F 9x', which are 386-only.
  43. # Nothing else here can: qemu-system-i386's lowest CPU
  44. # model is 486, where both are ordinary instructions, and
  45. # FCML's -m16 mode is a 386 too. Clause H additionally
  46. # catches the branch polarity being inverted, which is
  47. # still a legal opcode and therefore invisible to every
  48. # shape-based check.
  49. # run_com_exec.py behaviour: catches a*b that emits an ADD, `>'
  50. # and `>=' swapped, REPEAT..UNTIL that stops after one
  51. # pass, two procedures whose parameters collide, a left
  52. # operand overwritten by the right one's code (SaveLeft),
  53. # and a boolean `not' lowered as the integer one. Every
  54. # one of them sat in a fixture that COMPILED and was
  55. # never RUN, with every byte-level check green.
  56. # run_exec86.py behaviour (Exec86): catches the interpreter's OWN
  57. # reading of the machine: JE inverted in Exec86's Cond,
  58. # which swaps the two arms of every `=' in every program
  59. # while the emitted bytes, the sizes and every
  60. # byte-level check stay green. The image is fine; only
  61. # the thing reading it is wrong, so nothing that looks at
  62. # the image can fail this one.
  63. # runtest.py the R key: catches CmdRun poking nothing into
  64. # the interpreter at all, which faults on the first step
  65. # and prints "interpreter fault" instead of the guest's
  66. # answer. It is the only case here that needs a rebuilt
  67. # SHELL rather than a rebuilt compiler or runtime.
  68. #
  69. # The mod=11 cases do not need a rebuild -- they read the probe sources
  70. # directly -- so they are cheap, and they are the ones that matter most: the
  71. # table they guard is the one thing in this project that was wrong in the
  72. # documentation while the code was right, and a table that is wrong in the
  73. # code produces bytes that decode perfectly.
  74. #
  75. # Usage: tests/nonvacuity.sh (from shell/; leaves Runtime.mod restored)
  76. set -u
  77. cd "$(dirname "$0")/.." || exit 1
  78. GM2=/home/eric/bin/Modula2/Gm2/bin/gm2
  79. SAVED=../tmp/nonvacuity.Runtime.mod
  80. PROBE=../tmp/nonvacuity.rtprobe
  81. DUMP=../tmp/nonvacuity.dump
  82. # Exec86.mod is UNTRACKED, so unlike Runtime.mod git cannot put a botched
  83. # mutation back: the copy taken here is the only correct one in existence.
  84. # Shell.mod is tracked but is mutated by the R-key case below, and a trap that
  85. # restored only the sources would leave tpshell BUILT FROM the mutation - so
  86. # the trap rebuilds too. All three copies live in the project's own tmp/ and
  87. # are taken here, before the first mutation, rather than beside each case.
  88. mkdir -p ../tmp
  89. SAVED_E=../tmp/nonvacuity.Exec86.mod
  90. SAVED_SH=../tmp/nonvacuity.Shell.mod
  91. cp Runtime.mod "$SAVED" || exit 1
  92. cp Exec86.mod "$SAVED_E" || exit 1
  93. cp Shell.mod "$SAVED_SH" || exit 1
  94. restore_all () {
  95. cp "$SAVED" Runtime.mod
  96. cp "$SAVED_E" Exec86.mod
  97. cp "$SAVED_SH" Shell.mod
  98. "$GM2" -fiso -c Runtime.mod >/dev/null 2>&1
  99. "$GM2" -fiso -c Exec86.mod >/dev/null 2>&1
  100. # The shell is rebuilt as well: a test that runs against a binary built
  101. # from a half-restored tree is reporting on the mutation, not on the code.
  102. make >/dev/null 2>&1
  103. }
  104. trap restore_all EXIT
  105. pass=0
  106. fail=0
  107. # mutate <file> <sed-expr> -- apply a deliberate breakage and INSIST it landed.
  108. #
  109. # Four cases in this file were already dead when first run, all the same way:
  110. # the helper they name had been renamed or reformatted since the case was
  111. # written, the sed matched nothing, the source was unchanged, and the check
  112. # correctly passed - so the harness reported "NOT NON-VACUOUS" and, worse, a
  113. # reader skimming the output could take "the check still passed" for a passing
  114. # test. A case that cannot fire is worse than no case: it is a claim of
  115. # coverage that was never tested.
  116. #
  117. # So the mutation is verified, not assumed. If the file is byte-identical
  118. # afterwards, that is reported as a FAILURE of the harness, naming the sed, and
  119. # the case is not run - because running it would only produce a meaningless
  120. # green. The message says what to do (fix the sed) rather than what it found.
  121. mutate () {
  122. mf=$1
  123. msed=$2
  124. cp "$mf" ../tmp/nonvacuity.mut.bak
  125. sed -i "$msed" "$mf"
  126. if cmp -s "$mf" ../tmp/nonvacuity.mut.bak; then
  127. echo " BROKEN CASE: the mutation did not change $mf"
  128. echo " sed: $msed"
  129. echo " the named code has probably been renamed or reformatted -"
  130. echo " fix this case, it is asserting nothing"
  131. fail=$((fail + 1))
  132. return 1
  133. fi
  134. return 0
  135. }
  136. # rebuild <label> -- re-emit the runtime and dump it
  137. rebuild () {
  138. "$GM2" -fiso -c Runtime.mod >/dev/null 2>&1 || return 1
  139. "$GM2" -fiso -o "$PROBE" tests/RtProbe.mod Runtime.o Posix.o \
  140. >/dev/null 2>&1 || return 1
  141. "$PROBE" > "$DUMP" || return 1
  142. return 0
  143. }
  144. # expect_red <label> <pattern> <checker-cmd...>
  145. # <pattern> is a grep the failure output must match, so a check cannot
  146. # "pass" by failing for some unrelated reason.
  147. expect_red () {
  148. label=$1
  149. want=$2
  150. shift 2
  151. if out=$("$@" 2>&1); then
  152. echo "NOT NON-VACUOUS: $label -- the check still passed"
  153. fail=$((fail + 1))
  154. elif ! printf '%s\n' "$out" | grep -qi "$want"; then
  155. echo "WRONG FAILURE: $label -- went red, but not for the stated reason"
  156. printf '%s\n' "$out" | sed 's/^/ /'
  157. fail=$((fail + 1))
  158. else
  159. echo " ok: $label"
  160. printf '%s\n' "$out" | grep -im1 "$want" | sed 's/^/ /'
  161. pass=$((pass + 1))
  162. fi
  163. }
  164. echo "== each mutation must turn the named check red"
  165. echo
  166. # --- 1. name-versus-decode -------------------------------------------
  167. # MovSiBx was `89 DC`, which is MOV SP,BX. Two bytes either way, decodes
  168. # cleanly, and no structural check can see it.
  169. cp "$SAVED" Runtime.mod
  170. mutate Runtime.mod 's|B (0DEH) END MovSiBx|B (0DCH) END MovSiBx|'
  171. expect_red "audit_helpers catches MovSiBx emitting MOV SP,BX" \
  172. "MovSiBx" python3 tests/audit_helpers.py
  173. # CmpSiBx had the identical mistake, which is how you know a single fix is
  174. # not enough -- the same misreading was written twice.
  175. cp "$SAVED" Runtime.mod
  176. mutate Runtime.mod 's|B (39H) ; B (0DEH) END CmpSiBx|B (39H) ; B (0DCH) END CmpSiBx|'
  177. expect_red "audit_helpers catches CmpSiBx emitting CMP SP,BX" \
  178. "CmpSiBx" python3 tests/audit_helpers.py
  179. # --- 2. golden, and entry goldens ------------------------------------
  180. # MovDlAl was `88 C0` = MOV AL,AL instead of MOV DL,AL. This is the case that
  181. # motivated runtime.golden: the sweep stayed in sync, every branch target
  182. # stayed on a boundary, no entry's first bytes moved, and the size did not
  183. # change. The target helper was MovAlDh when this case was written, which is
  184. # the fourth way a case here can rot - see the note on `mutate` below.
  185. cp "$SAVED" Runtime.mod
  186. mutate Runtime.mod 's|PROCEDURE MovDlAl ; BEGIN B (88H) ; B (0C2H)|PROCEDURE MovDlAl ; BEGIN B (88H) ; B (0C0H)|'
  187. rebuild
  188. expect_red "runtime.golden catches MOV AL,AL" \
  189. "mov al,al" python3 tests/check_runtime.py "$DUMP"
  190. # initmem opened with the mis-emitted MovSiAx, so its entry golden was the
  191. # thing that noticed the prologue was a no-op.
  192. cp "$SAVED" Runtime.mod
  193. mutate Runtime.mod 's|B (0F0H) END MovSiAx|B (0C0H) END MovSiAx|'
  194. rebuild
  195. expect_red "check_runtime catches a broken initmem prologue" \
  196. "mov ax,ax" python3 tests/check_runtime.py "$DUMP"
  197. # --- 3. decode sweep / length ----------------------------------------
  198. # StDiDl was `88 97` = [BX+disp16],DL: mod=10, so the instruction needs a
  199. # disp16 it was not given, and the sweep loses sync two bytes later.
  200. cp "$SAVED" Runtime.mod
  201. mutate Runtime.mod 's|PROCEDURE StDiDl ; BEGIN B (88H) ; B (15H)|PROCEDURE StDiDl ; BEGIN B (88H) ; B (97H)|'
  202. rebuild
  203. expect_red "decode sweep catches a mod=10 byte move with no displacement" \
  204. "mov byte ptr \[bx+5b5fh\],dl" python3 tests/check_runtime.py "$DUMP"
  205. # --- 4. branch targets ------------------------------------------------
  206. # FixUp measures a rel8 from the end of the instruction, one byte past the
  207. # displacement field. Drop the +1 and every short branch lands one byte into
  208. # its target, which for a 3-byte instruction means the middle of it. The
  209. # bytes themselves are all perfectly well formed -- only the fixups are
  210. # wrong -- so this is the one failure mode the golden cannot be expected to
  211. # catch on its own.
  212. cp "$SAVED" Runtime.mod
  213. mutate Runtime.mod 's|rel := (t + 100H - (fix \[i\].place + 1)) MOD 100H|rel := (t + 100H - fix [i].place) MOD 100H|'
  214. rebuild
  215. expect_red "branch check catches rel8 fixups measured from the wrong byte" \
  216. "not an instruction boundary" \
  217. python3 tests/check_runtime.py "$DUMP"
  218. echo
  219. echo "== everything restored and green again"
  220. cp "$SAVED" Runtime.mod
  221. if rebuild; then
  222. if python3 tests/audit_helpers.py >/dev/null 2>&1 &&
  223. python3 tests/check_runtime.py "$DUMP" >/dev/null 2>&1; then
  224. echo " ok: both checks pass on the restored source"
  225. pass=$((pass + 1))
  226. else
  227. echo "NOT RESTORED: a check is red after restoring Runtime.mod"
  228. fail=$((fail + 1))
  229. fi
  230. else
  231. echo "NOT RESTORED: the runtime would not rebuild"
  232. fail=$((fail + 1))
  233. fi
  234. echo
  235. echo "== the mod=11 table (probe/modrm11.py)"
  236. # These mutate the probe's own sources, not the runtime, so there is no
  237. # rebuild in the loop. SAVED_PY / SAVED_S are restored after each case.
  238. SAVED_PY=../tmp/nonvacuity.modrm11.py
  239. SAVED_S=../tmp/nonvacuity.modrm11.s
  240. cp tests/probe/modrm11.py "$SAVED_PY" || exit 1
  241. cp tests/probe/modrm11.s "$SAVED_S" || exit 1
  242. M11="python3 tests/probe/modrm11.py"
  243. restore_probe () {
  244. cp "$SAVED_PY" tests/probe/modrm11.py
  245. cp "$SAVED_S" tests/probe/modrm11.s
  246. }
  247. # 1. one cell of the table moved
  248. mutate tests/probe/modrm11.py 's|"Si", "Di"\]$|"Bp", "Di"]|'
  249. expect_red "anchor pins a moved table cell" \
  250. "anchor ADD SI, 2" $M11
  251. restore_probe
  252. # 2. the table this project actually shipped: AX dropped off the front and a
  253. # duplicate BX invented at the end, which shifts every code down by one
  254. mutate tests/probe/modrm11.py 's|^REG = .*$|REG = ["Cx", "Dx", "Bx", "Sp", "Bp", "Si", "Di", "Bx"]|'
  255. expect_red "the table shifted by one (AX dropped, BX duplicated)" \
  256. "anchor MOV SP, BP" $M11
  257. restore_probe
  258. # 3. the .s edited to contradict the table. This is the case that shows why
  259. # the hard-coded EXPECT bytes exist: the assembler encodes the new claim
  260. # correctly, so comparing the .s against `as` alone can never fail here.
  261. mutate tests/probe/modrm11.s 's|movw %sp, %di # reg 100|movw %bp, %di # reg 100|'
  262. expect_red "probe source edited away from the recorded bytes" \
  263. "expected 89 E7" $M11
  264. restore_probe
  265. # 4. the 8-bit list edited, which is a different table from the word one
  266. mutate tests/probe/modrm11.s 's|movb %al, %dl # 88 C2 -> DL := AL|movb %al, %bl # was DL|'
  267. expect_red "the 8-bit register list edited" \
  268. "expected 88 C2" $M11
  269. restore_probe
  270. # 5. an anchor's recorded byte corrupted, so the anchor can no longer
  271. # corroborate itself
  272. mutate tests/probe/modrm11.py 's|"8B EC", "8B E5"|"8B ED", "8B E5"|'
  273. expect_red "anchor byte no longer matches the emitted code" \
  274. "expected 8B ED" $M11
  275. restore_probe
  276. if $M11 >/dev/null 2>&1; then
  277. echo " ok: modrm11.py passes on the restored probe sources"
  278. pass=$((pass + 1))
  279. else
  280. echo "NOT RESTORED: modrm11.py is red after restoring its sources"
  281. $M11 2>&1 | sed 's/^/ /'
  282. fail=$((fail + 1))
  283. fi
  284. echo
  285. echo "== the BP displacement rule (check_framedisp.py)"
  286. # This one is about Compiler.mod rather than the runtime, and it needs the
  287. # whole toolchain rebuilt (comtest, not rtprobe), so it gets its own rebuild.
  288. SAVED_C=../tmp/nonvacuity.Compiler.mod
  289. cp Compiler.mod "$SAVED_C" || exit 1
  290. rebuild_compiler () {
  291. $GM2 -fiso -c Compiler.mod >/dev/null 2>&1 || return 1
  292. $GM2 -fiso -fgen-module-list=tests/ct.lst -o /dev/null \
  293. tests/ComTest.mod TextBuf.o Posix.o Compiler.o Runtime.o Linker.o \
  294. >/dev/null 2>&1
  295. $GM2 -fiso -fuse-list=tests/ct.lst -o comtest \
  296. tests/ComTest.mod TextBuf.o Posix.o Compiler.o Runtime.o Linker.o \
  297. >/dev/null 2>&1 || return 1
  298. return 0
  299. }
  300. # 1. the original bug: `off MOD 100H`, always disp8. Restores exactly the code
  301. # that was there before EmBpDisp existed. t28's [BP+128] read becomes
  302. # [BP-128], which is the failure this whole check is named after.
  303. python3 - "$SAVED_C" <<'PYEOF'
  304. import sys
  305. p = 'Compiler.mod'
  306. s = open(p).read()
  307. old = """BEGIN
  308. IF off <= 127 THEN
  309. Ebyte (46H) ; Ebyte (VAL (BYTE, off))
  310. ELSE
  311. Ebyte (86H) ; Eword (off)
  312. END
  313. END EmBpDisp ;"""
  314. new = """VAR disp : CARDINAL ;
  315. BEGIN
  316. disp := off MOD 100H ;
  317. Ebyte (46H) ; Ebyte (VAL (BYTE, disp))
  318. END EmBpDisp ;"""
  319. assert old in s, "EmBpDisp body not found -- update this mutation"
  320. open(p, 'w').write(s.replace(old, new))
  321. PYEOF
  322. if rebuild_compiler; then
  323. expect_red "displacement truncation reads a different address" \
  324. "no 8B access at \[BP+128\]" python3 tests/check_framedisp.py
  325. else
  326. echo " FAIL: the compiler would not rebuild with the truncation"
  327. fail=$((fail + 1))
  328. fi
  329. cp "$SAVED_C" Compiler.mod
  330. # 2. the other half of the rule: always use the 4-byte form, ignoring the
  331. # <= 127 case. This is over-cautious rather than wrong, so the checker must
  332. # still be happy -- which is worth asserting, because a check that only
  333. # ever fails on a smaller encoding is a check that pins one answer instead
  334. # of the rule.
  335. python3 - <<'PYEOF'
  336. p = 'Compiler.mod'
  337. s = open(p).read()
  338. old = """ IF off <= 127 THEN
  339. Ebyte (46H) ; Ebyte (VAL (BYTE, off))
  340. ELSE
  341. Ebyte (86H) ; Eword (off)
  342. END"""
  343. new = """ Ebyte (86H) ; Eword (off)"""
  344. assert old in s, "EmBpDisp branch not found -- update this mutation"
  345. open(p, 'w').write(s.replace(old, new))
  346. PYEOF
  347. if rebuild_compiler; then
  348. if python3 tests/check_framedisp.py >/dev/null 2>&1; then
  349. echo " ok: always-disp16 is accepted, so the check pins the rule"
  350. echo " and not one particular encoding"
  351. pass=$((pass + 1))
  352. else
  353. echo " FAIL: check_framedisp rejects a safe, over-long encoding"
  354. python3 tests/check_framedisp.py 2>&1 | sed 's/^/ /'
  355. fail=$((fail + 1))
  356. fi
  357. else
  358. echo " FAIL: the compiler would not rebuild with always-disp16"
  359. fail=$((fail + 1))
  360. fi
  361. cp "$SAVED_C" Compiler.mod
  362. if rebuild_compiler; then
  363. if python3 tests/check_framedisp.py >/dev/null 2>&1; then
  364. echo " ok: check_framedisp passes on the restored source"
  365. pass=$((pass + 1))
  366. else
  367. echo "NOT RESTORED: check_framedisp is red after restoring Compiler.mod"
  368. python3 tests/check_framedisp.py 2>&1 | sed 's/^/ /'
  369. fail=$((fail + 1))
  370. fi
  371. else
  372. echo "NOT RESTORED: the compiler would not rebuild"
  373. fail=$((fail + 1))
  374. fi
  375. # --- 3. the operator bugs the nine dead fixtures were hiding ------------
  376. echo
  377. echo "== the bugs the never-executed fixtures were hiding"
  378. echo
  379. # A different KIND of case from everything above. The others break the code
  380. # and assert a byte-level check notices; these break the code and assert a
  381. # BEHAVIOURAL check notices, which is the only kind that could have found them.
  382. # Each of the original four shipped with a green compile matrix, a passing .COM
  383. # layout check, a passing golden and a passing emitter audit:
  384. #
  385. # OpMul = 1 `a * b` emitted ADD AX,CX. `*' and `+' both numbered
  386. # their operator 1, and BinOpEmit cannot see which
  387. # precedence level called it, so every multiplication
  388. # dispatched to the addition. The constant-folding arm was
  389. # correct, which is why `n * n' with n a CONST was right and
  390. # `a * a' with a a variable was not -- and t08_const is the
  391. # only fixture that ever multiplied.
  392. # 9Dh / 9FH `>' got SETGE and `>=' got SETG: swapped, one letter
  393. # apart in the mnemonic. Only a==b could see it.
  394. # JNZ -> body REPEAT..UNTIL looped back while the condition was TRUE,
  395. # which is WHILE, so the body ran once and stopped.
  396. #
  397. # They are mutated back to the original defect and run_com_exec.py must go red
  398. # on the exact fixture that pins the behaviour. The fourth (HideLocals) is a
  399. # scoping bug rather than an operator bug; it was hiding in the same place.
  400. #
  401. # Two joined them when the operand-lifetime and `not' fixes landed, each run
  402. # red by hand before it was written down here, and each with the same property
  403. # as the four above -- green everywhere except execution:
  404. #
  405. # SaveLeft's park `(p > q) or (q > p)' evaluated `(q > p) or (q > p)'. A
  406. # kind-2 value exists only in AX, and the right operand's
  407. # code is emitted before the two are ever brought together,
  408. # so without the push the left one is simply gone.
  409. # neglevel's split `not' on a boolean emitted the INTEGER `not', which left
  410. # 0FFFEh where a boolean belongs, and wrbool reads anything
  411. # non-zero as TRUE -- so `not (a = a)' answered TRUE and so
  412. # did every other `not'.
  413. mutate_compiler () { # reuse mutate's verified-change discipline on Compiler.mod
  414. mf=Compiler.mod
  415. msed=$1
  416. cp "$SAVED_C" ../tmp/nonvacuity.mut2.bak
  417. sed -i "$msed" "$mf"
  418. if cmp -s "$mf" ../tmp/nonvacuity.mut2.bak; then
  419. echo " BROKEN CASE: the mutation did not change Compiler.mod"
  420. echo " sed: $msed"
  421. echo " the named code has probably been renamed or reformatted -"
  422. echo " fix this case, it is asserting nothing"
  423. fail=$((fail + 1))
  424. return 1
  425. fi
  426. return 0
  427. }
  428. # The SETcc swap and the HideLocals removal are done in python rather than
  429. # with sed: both need to match source text containing `*` and `(` in a way that
  430. # is tedious and fragile as a regex, and a case whose only failure mode is a
  431. # malformed sed is a case that silently asserts nothing.
  432. #
  433. # And a python helper fails in a way sed does not: a syntax error in the helper
  434. # is a non-zero exit, `if mutate_foo; then` is simply false, and the case is
  435. # SKIPPED -- with no failure counted and nothing on stdout but whatever python
  436. # printed. That is how the SETcc case spent its first run: an apostrophe in an
  437. # assert message ("the `>' arm") closed the string early, python died, the
  438. # compiler was never broken, and the suite still reported 0 failed. A skipped
  439. # case and a passing case look the same in the total. So each helper below
  440. # fails LOUDLY: a non-zero exit from python is reported as a BROKEN CASE and
  441. # counted, never swallowed.
  442. #
  443. # Each one also counts its targets before replacing. `assert s != before' only
  444. # says the file changed; with two edits it would pass if just one of them
  445. # landed, and with two identical HideLocals call sites it would happily delete
  446. # the wrong one -- still a changed file, still a working compiler, still green
  447. # for the wrong reason.
  448. mutate_cc_swap () {
  449. if python3 - <<'PYX'
  450. p = 'Compiler.mod'
  451. s = open(p).read()
  452. GT = 'EmSetcc (9FH) ; (* > SETG *)' # the greater-than arm
  453. GE = 'EmSetcc (9DH) ; (* >= SETGE *)' # the greater-equal arm
  454. assert s.count(GT) == 1, 'expected 1 greater-than arm, found %d' % s.count(GT)
  455. assert s.count(GE) == 1, 'expected 1 greater-equal arm, found %d' % s.count(GE)
  456. s = s.replace(GT, GT.replace('9FH', '9DH'))
  457. s = s.replace(GE, GE.replace('9DH', '9FH'))
  458. open(p, 'w').write(s)
  459. PYX
  460. then
  461. return 0
  462. fi
  463. echo " BROKEN CASE: the SETcc swap did not apply"
  464. echo " the two EmSetcc arms are probably renamed or reformatted -"
  465. echo " fix this case, it is asserting nothing"
  466. fail=$((fail + 1))
  467. return 1
  468. }
  469. mutate_no_hidelocals () {
  470. if python3 - <<'PYX'
  471. p = 'Compiler.mod'
  472. s = open(p).read()
  473. # Two HideLocals calls exist. Only the body-exit one may go: deleting the
  474. # FORWARD one instead would still change the file, still rebuild, and still
  475. # leave t13_proc compiling, so the case would go green for the wrong reason.
  476. HL = ' HideLocals (nestMark) ; (* parameters and locals stop here *)\n'
  477. assert s.count(HL) == 1, 'expected 1 body-exit HideLocals, found %d' % s.count(HL)
  478. open(p, 'w').write(s.replace(HL, ''))
  479. PYX
  480. then
  481. return 0
  482. fi
  483. echo " BROKEN CASE: HideLocals was not removed"
  484. echo " the call or its comment has probably been reformatted -"
  485. echo " fix this case, it is asserting nothing"
  486. fail=$((fail + 1))
  487. return 1
  488. }
  489. cp "$SAVED_C" Compiler.mod
  490. if mutate_compiler 's|^ op := OpMul ; DropCh| op := OpAdd ; DropCh|'; then
  491. if rebuild_compiler; then
  492. expect_red "execution catches '*' emitting an ADD (t08_const, n*n)" \
  493. "t08_const" python3 tests/run_com_exec.py t08_const
  494. # t08 only ever multiplied two CONSTANTS, which is the one path that was
  495. # never wrong, because BinOpEmit folds it. So the case above is close
  496. # to vacuous: it proves the mutation changed the binary, not that the
  497. # emitted multiply is covered. The check that matters needs a
  498. # VARIABLE operand, and no shipped fixture has one -- which is why the
  499. # bug survived at all. So this writes a throwaway fixture that
  500. # multiplies a variable, runs it, and asserts the multiply is right.
  501. # The fixture is deleted afterwards; it is here to close the coverage
  502. # hole, not to become a permanent test (that is what a real fixture
  503. # with a `*' in it would be for).
  504. cat > tests/fixtures/zzmul.pas <<'ZZEOF'
  505. program zzmul;
  506. var a : integer ;
  507. begin
  508. a := 7 ;
  509. writeln (a * 6)
  510. end.
  511. ZZEOF
  512. printf '42\r\n' > tests/fixtures/zzmul.out
  513. expect_red "execution catches '*' on a VARIABLE (the unfolded path)" \
  514. "zzmul" python3 tests/run_com_exec.py zzmul
  515. rm -f tests/fixtures/zzmul.pas tests/fixtures/zzmul.out
  516. else
  517. echo " FAIL: the compiler would not rebuild with OpAdd for '*'"
  518. fail=$((fail + 1))
  519. fi
  520. fi
  521. cp "$SAVED_C" Compiler.mod
  522. cp "$SAVED_C" Compiler.mod
  523. if mutate_cc_swap; then
  524. if rebuild_compiler; then
  525. expect_red "execution catches '>' and '>=' swapped (t09_if)" \
  526. "t09_if" python3 tests/run_com_exec.py t09_if
  527. else
  528. echo " FAIL: the compiler would not rebuild with the SETcc swap"
  529. fail=$((fail + 1))
  530. fi
  531. fi
  532. cp "$SAVED_C" Compiler.mod
  533. cp "$SAVED_C" Compiler.mod
  534. if mutate_compiler 's| DropC (EmJcc (84H, L1)) ; (\* JZ -> body again \*)| zj := EmJcc (85H, L1) ;|'; then
  535. if rebuild_compiler; then
  536. expect_red "execution catches REPEAT..UNTIL exiting after one pass (t12)" \
  537. "t12_repeat" python3 tests/run_com_exec.py t12_repeat
  538. else
  539. echo " FAIL: the compiler would not rebuild with the JNZ repeat"
  540. fail=$((fail + 1))
  541. fi
  542. fi
  543. cp "$SAVED_C" Compiler.mod
  544. # The fourth: sibling procedures shared one parameter namespace, because a
  545. # finished procedure's symbols were left at a level Search still accepts.
  546. # Removing HideLocals puts two procedures' `a : integer' back in collision.
  547. cp "$SAVED_C" Compiler.mod
  548. if mutate_no_hidelocals; then
  549. if rebuild_compiler; then
  550. expect_red "a duplicate parameter in two procedures is a compile error again" \
  551. "ERROR 41" python3 tests/run_com_exec.py t13_proc
  552. else
  553. echo " FAIL: the compiler would not rebuild without HideLocals"
  554. fail=$((fail + 1))
  555. fi
  556. else
  557. echo " FAIL: could not remove HideLocals to test the scoping fix"
  558. fail=$((fail + 1))
  559. fi
  560. # M6: the LEFT operand, parked for the right one. kind 2 means "this value
  561. # exists in AX and nowhere else", and the right-hand operand's code is emitted
  562. # between recognizing the operator and using both operands - so without
  563. # SaveLeft's push the left value is overwritten before it is ever read, and
  564. # LoadPair's kind-4 shape can never trigger. `(p > q) or (q > p)' then
  565. # evaluates `(q > p) or (q > p)'. Every byte, every size and the whole compile
  566. # matrix stay green: nothing is malformed, the value is simply the wrong one.
  567. cp "$SAVED_C" Compiler.mod
  568. if python3 - <<'PYX'
  569. p = 'Compiler.mod'
  570. s = open(p).read()
  571. old = """BEGIN
  572. IF left.kind = 2 THEN
  573. EmPushAx () ;
  574. left.kind := 4 (* 4 = on the top of the stack *)
  575. END
  576. END SaveLeft ;"""
  577. new = """BEGIN
  578. (* MUTATION: the park is unreachable, so nothing survives the parse *)
  579. IF left.kind = 99 THEN
  580. EmPushAx () ;
  581. left.kind := 4
  582. END
  583. END SaveLeft ;"""
  584. assert s.count(old) == 1, 'SaveLeft body found %d times -- update this mutation' % s.count(old)
  585. open(p, 'w').write(s.replace(old, new))
  586. PYX
  587. then
  588. if rebuild_compiler; then
  589. expect_red "execution catches a left operand clobbered by the right one" \
  590. "t34_arith" python3 tests/run_com_exec.py t34_arith
  591. else
  592. echo " FAIL: the compiler would not rebuild without SaveLeft's push"
  593. fail=$((fail + 1))
  594. fi
  595. else
  596. echo " BROKEN CASE: the SaveLeft mutation did not apply"
  597. fail=$((fail + 1))
  598. fi
  599. cp "$SAVED_C" Compiler.mod
  600. # M7: the type split in TPSRC9's neglevel, wrong half. A boolean NOT lowered
  601. # as the INTEGER one leaves 0FFFEh/0FFFFh, and wrbool tests [BP+4] <> 0 - so
  602. # `not (a = a)' answers TRUE, and so does every other `not'. One instruction,
  603. # same length, same sizes, and the compile matrix cannot see it because both
  604. # halves emit well-formed code for a type the parser already accepted.
  605. cp "$SAVED_C" Compiler.mod
  606. if python3 - <<'PYX'
  607. p = 'Compiler.mod'
  608. s = open(p).read()
  609. old = """ IF r.cls = TBool THEN
  610. LoadAtom (r) ;
  611. EmXorAl01 () ;"""
  612. new = """ IF r.cls = TBool THEN
  613. LoadAtom (r) ;
  614. EmNotAx () ; (* MUTATION: integer NOT on a boolean *)"""
  615. assert s.count(old) == 1, 'the TBool arm of ParseNeg found %d times -- update this mutation' % s.count(old)
  616. open(p, 'w').write(s.replace(old, new))
  617. PYX
  618. then
  619. if rebuild_compiler; then
  620. expect_red "execution catches a boolean NOT lowered as an integer one" \
  621. "t35_not" python3 tests/run_com_exec.py t35_not
  622. else
  623. echo " FAIL: the compiler would not rebuild with EmNotAx for a boolean"
  624. fail=$((fail + 1))
  625. fi
  626. else
  627. echo " BROKEN CASE: the neglevel type-split mutation did not apply"
  628. fail=$((fail + 1))
  629. fi
  630. cp "$SAVED_C" Compiler.mod
  631. if rebuild_compiler; then
  632. if python3 tests/run_com_exec.py >/dev/null 2>&1; then
  633. # No count: the matrix grows every time a fixture is added, and a
  634. # number here would be right only until the next one.
  635. echo " ok: every executed fixture passes on the restored compiler"
  636. pass=$((pass + 1))
  637. else
  638. echo "NOT RESTORED: run_com_exec.py is red after restoring Compiler.mod"
  639. python3 tests/run_com_exec.py 2>&1 | grep -i fail | head -3 | sed 's/^/ /'
  640. fail=$((fail + 1))
  641. fi
  642. else
  643. echo "NOT RESTORED: the compiler would not rebuild"
  644. fail=$((fail + 1))
  645. fi
  646. echo
  647. echo "== the second execution oracle (run_exec86.py)"
  648. # Everything above runs the image under qemu-system-i386. This one runs the
  649. # SAME image inside shell/Exec86.mod, this project's own in-process 8086
  650. # interpreter, and requires its output to agree with BOTH the hand-derived .out
  651. # and qemu, byte for byte. Two execution checks that could only ever agree
  652. # with each other would be one check: the point of this one is that it was
  653. # written against the 8086's own reference rather than against qemu, whose
  654. # lowest CPU model is a 486 and whose `0F 84' is an ordinary JZ.
  655. #
  656. # So the only mutation worth writing here is one qemu cannot make at all - the
  657. # interpreter's own reading of the machine. Cond is that reading: nibble 4 is
  658. # JE, and inverting it swaps the two arms of every `=' in every program. The
  659. # emitted bytes, the sizes and the compile matrix are untouched, because
  660. # nothing is emitted here - the fault is in who interprets it.
  661. #
  662. # Exec86.mod is recompiled explicitly rather than left to the harness:
  663. # ensure_exec86run() notices the source changed and RELINKS, but does not
  664. # recompile it, so a mutated source with a stale object would link the good
  665. # interpreter straight back in and stay green - which is the trap its own
  666. # docstring records, and the reason this case compiles first.
  667. #
  668. # SAVED_E itself was taken at the top of this file, next to the EXIT trap that
  669. # puts it back.
  670. if python3 - <<'PYX'
  671. p = 'Exec86.mod'
  672. s = open(p).read()
  673. old = "| 4H : r := ZF"
  674. new = "| 4H : r := NOT ZF (* MUTATION: JE inverted *)"
  675. assert s.count(old) == 1, 'the JE arm of Cond found %d times -- update this mutation' % s.count(old)
  676. open(p, 'w').write(s.replace(old, new))
  677. PYX
  678. then
  679. if $GM2 -fiso -c Exec86.mod >/dev/null 2>&1; then
  680. expect_red "the interpreter's own oracle catches JE inverted" \
  681. "t33_cmpops" python3 tests/run_exec86.py t33_cmpops
  682. else
  683. echo " FAIL: Exec86.mod would not compile with JE inverted"
  684. fail=$((fail + 1))
  685. fi
  686. else
  687. echo " BROKEN CASE: the Cond JE mutation did not apply"
  688. fail=$((fail + 1))
  689. fi
  690. cp "$SAVED_E" Exec86.mod
  691. # And the check on the RESTORED interpreter, because a green above could also
  692. # come from a mutation that never took and an object left mutated by a run
  693. # that died in between.
  694. if $GM2 -fiso -c Exec86.mod >/dev/null 2>&1; then
  695. if python3 tests/run_exec86.py >/dev/null 2>&1; then
  696. echo " ok: run_exec86 green on the restored interpreter"
  697. pass=$((pass + 1))
  698. else
  699. echo "NOT RESTORED: run_exec86.py is red after restoring Exec86.mod"
  700. python3 tests/run_exec86.py 2>&1 | grep -i "fail" | head -3 | sed 's/^/ /'
  701. fail=$((fail + 1))
  702. fi
  703. else
  704. echo "NOT RESTORED: Exec86.mod would not recompile"
  705. fail=$((fail + 1))
  706. fi
  707. echo
  708. echo "== the R key: compile, poke, run, report (runtest.py)"
  709. # The only check in the project that exercises CmdRun. Everything above looks
  710. # at bytes, or at what qemu says the image does; this one drives the shell
  711. # through a pty the way a person would, presses R, and compares the GUEST's
  712. # output against the fixture's hand-derived .out - so it fails on things no
  713. # byte check can see and no file records either, because R writes no file at
  714. # all (which is itself asserted).
  715. #
  716. # The mutation is the poke loop's count. With n = 0 nothing is copied into
  717. # the interpreter, loadHi stays where Clear86 left it - 0100h - and Run86
  718. # faults on its very first step, "execution left the loaded image", before the
  719. # guest has executed a single instruction. That is fast and deterministic, which
  720. # matters: the obvious alternative (poking the image somewhere else) leaves the
  721. # machine executing zeros and buys a step-limit timeout instead of a finding.
  722. cp "$SAVED_SH" Shell.mod
  723. if python3 - <<'PYX'
  724. p = 'Shell.mod'
  725. s = open(p).read()
  726. old = " n := LinkSize () ;"
  727. new = " n := 0 ; (* MUTATION: nothing is poked *)"
  728. assert s.count(old) == 1, 'the poke count in CmdRun found %d times -- update this mutation' % s.count(old)
  729. open(p, 'w').write(s.replace(old, new))
  730. PYX
  731. then
  732. if make > ../tmp/nonvacuity.make.log 2>&1; then
  733. expect_red "the R check catches an image that was never poked" \
  734. "AH=4Ch exit" python3 tests/runtest.py
  735. else
  736. echo " FAIL: the shell would not rebuild with the poke loop neutered"
  737. tail -5 ../tmp/nonvacuity.make.log | sed 's/^/ /'
  738. fail=$((fail + 1))
  739. fi
  740. else
  741. echo " BROKEN CASE: the CmdRun poke mutation did not apply"
  742. fail=$((fail + 1))
  743. fi
  744. cp "$SAVED_SH" Shell.mod
  745. if make > ../tmp/nonvacuity.make.log 2>&1; then
  746. if python3 tests/runtest.py >/dev/null 2>&1; then
  747. echo " ok: runtest green on the restored shell"
  748. pass=$((pass + 1))
  749. else
  750. echo "NOT RESTORED: runtest.py is red after restoring Shell.mod"
  751. python3 tests/runtest.py 2>&1 | grep -i "fail" | head -3 | sed 's/^/ /'
  752. fail=$((fail + 1))
  753. fi
  754. else
  755. echo "NOT RESTORED: the shell would not rebuild"
  756. tail -5 ../tmp/nonvacuity.make.log | sed 's/^/ /'
  757. fail=$((fail + 1))
  758. fi
  759. echo
  760. echo "== 8086 legality of the conditional lowering (check_8086.py)"
  761. # This whole section exists because of a fault that every other check in the
  762. # project was blind to, and being blunt about WHY is the point of listing it.
  763. #
  764. # EmJcc and EmSetcc emitted `0F 8x rel16' and `0F 9x rel8'. `0F' is a
  765. # 386-and-later opcode prefix; the 8086 has none. So EVERY conditional branch
  766. # and EVERY comparison in EVERY compiled program was an illegal instruction on
  767. # the machine this compiler targets. And all of the following were green while
  768. # it was: the compile matrix, the .COM layout checker, the runtime golden, the
  769. # emitter audit, and the whole execution suite answering correctly under qemu.
  770. #
  771. # Two reasons, and the second is the one worth keeping:
  772. # 1. qemu-system-i386 has no 8086 model. Its lowest is 486, where `0F 84' is
  773. # a perfectly ordinary JZ. So the execution oracle CANNOT see this class
  774. # of fault, ever.
  775. # 2. FCML is this project's INDEPENDENT disassembler, and FCML's -m16 mode is
  776. # a 386. The one tool whose job is to say "this is not a real instruction"
  777. # was architecturally guaranteed to agree with the bug.
  778. #
  779. # So a check was needed that asks the question nothing else was asking. The
  780. # five mutations below are the mutations that check has to catch, and each was
  781. # run by hand and confirmed red BEFORE this section existed.
  782. #
  783. # M4 and M5 are the interesting pair. M4 is a fault this project actually
  784. # introduced while fixing the above: EmJcc jumps TO its target, but the 8086
  785. # shape steps OVER a 3-byte EJMP, so the naive port inverts every conditional
  786. # in every program. It was caught by execution, not by any byte check. M5 is
  787. # the partial version -- the inversion dropped for the IF and CASE sites only,
  788. # kept for FOR -- and MEASURING that is what produced clause H, because the
  789. # check was blind to M5 as first written: IF declares nibble 4, CASE declares
  790. # 5, they negate into each other, and both are declared, so nothing complained
  791. # while every conditional in every program took the wrong path. FOR declares
  792. # C and F, whose negations D and E are declared for nothing at all, so the
  793. # whole-suite version was caught by luck.
  794. #
  795. # Note these need `rebuild_compiler' only to refresh comtest; check_8086.py
  796. # relinks the fixtures itself. Getting that wrong is how this section's first
  797. # draft reported a mutation as VACUOUS: the build was skipped, a stale comtest
  798. # ran the GOOD compiler, and the check passed. A helper that exits non-zero
  799. # makes `if mutate_x; then' false and the case is silently skipped, which looks
  800. # exactly like a pass -- so rebuild_compiler is checked, not assumed.
  801. # M1: the original defect, restored verbatim.
  802. cp "$SAVED_C" Compiler.mod
  803. if python3 - <<'PYX'
  804. p = 'Compiler.mod'
  805. s = open(p).read()
  806. old = """ Ebyte (JccShortInv (cc)) ; (* Jcc_s, taken when cc does NOT hold *)
  807. Ebyte (03H) ; (* rel8: step over the 3-byte EJMP *)
  808. RETURN EmJmpNear (target) (* target = 0 => forward, see above *)"""
  809. new = """ Ebyte (0FH) ; Ebyte (cc) ; Eword (0) ;
  810. IF target = 0 THEN
  811. RETURN nPatch
  812. END ;
  813. RETURN 0"""
  814. assert s.count(old) == 1, 'EmJcc body found %d times -- update this mutation' % s.count(old)
  815. open(p, 'w').write(s.replace(old, new))
  816. PYX
  817. then
  818. if rebuild_compiler; then
  819. expect_red "check_8086 catches a 0F 8x branch (the original bug)" \
  820. "0F 84" python3 tests/check_8086.py
  821. else
  822. echo " FAIL: the compiler would not rebuild with the 0F branch"
  823. fail=$((fail + 1))
  824. fi
  825. else
  826. echo " BROKEN CASE: the 0F branch mutation did not apply"
  827. fail=$((fail + 1))
  828. fi
  829. cp "$SAVED_C" Compiler.mod
  830. # M2: the other original defect, SETcc plus the MOV AH,0 it needed.
  831. cp "$SAVED_C" Compiler.mod
  832. if python3 - <<'PYX'
  833. p = 'Compiler.mod'
  834. s = open(p).read()
  835. old = """ Ebyte (0B8H) ; Eword (1) ; (* MOV AX,#0001 *)
  836. Ebyte (JccShort (cc)) ; (* taken when the comparison HOLDS *)
  837. Ebyte (01H) ; (* rel8: step over the DEC AX *)
  838. Ebyte (48H) (* DEC AX *)"""
  839. new = """ Ebyte (0FH) ; Ebyte (cc) ; Ebyte (0C0H) ;
  840. EmMovAh0 ()"""
  841. assert s.count(old) == 1, 'EmSetcc body found %d times -- update this mutation' % s.count(old)
  842. open(p, 'w').write(s.replace(old, new))
  843. PYX
  844. then
  845. if rebuild_compiler; then
  846. expect_red "check_8086 catches a 0F 9x SETcc (the original bug)" \
  847. "0F 9F C0" python3 tests/check_8086.py
  848. else
  849. echo " FAIL: the compiler would not rebuild with the 0F SETcc"
  850. fail=$((fail + 1))
  851. fi
  852. else
  853. echo " BROKEN CASE: the 0F SETcc mutation did not apply"
  854. fail=$((fail + 1))
  855. fi
  856. cp "$SAVED_C" Compiler.mod
  857. # M4: the polarity inversion, everywhere. Note the expected text is clause H's,
  858. # not a shape complaint: every byte here is a legal 8086 shape, which is the
  859. # entire reason a separate clause had to be written.
  860. cp "$SAVED_C" Compiler.mod
  861. if python3 - <<'PYX'
  862. p = 'Compiler.mod'
  863. s = open(p).read()
  864. old = ' Ebyte (JccShortInv (cc)) ; (* Jcc_s, taken when cc does NOT hold *)'
  865. new = ' Ebyte (JccShort (cc)) ; (* MUTATION: inversion dropped *)'
  866. assert s.count(old) == 1, 'EmJcc Ebyte found %d times -- update this mutation' % s.count(old)
  867. open(p, 'w').write(s.replace(old, new))
  868. PYX
  869. then
  870. if rebuild_compiler; then
  871. expect_red "clause H catches the branch polarity inverted everywhere" \
  872. "but reading the source says" python3 tests/check_8086.py
  873. else
  874. echo " FAIL: the compiler would not rebuild with the inversion dropped"
  875. fail=$((fail + 1))
  876. fi
  877. else
  878. echo " BROKEN CASE: the polarity mutation did not apply"
  879. fail=$((fail + 1))
  880. fi
  881. cp "$SAVED_C" Compiler.mod
  882. # M5: the same inversion dropped for the IF and CASE sites ONLY. This one is
  883. # the reason clause H exists: it was run by hand and the check stayed GREEN,
  884. # and FOR's C/F nibbles were the only reason the whole-suite version (M4)
  885. # happened to be caught.
  886. cp "$SAVED_C" Compiler.mod
  887. if python3 - <<'PYX'
  888. p = 'Compiler.mod'
  889. s = open(p).read()
  890. old = ' Ebyte (JccShortInv (cc)) ; (* Jcc_s, taken when cc does NOT hold *)'
  891. new = """ IF (cc = 84H) OR (cc = 85H) THEN
  892. Ebyte (JccShort (cc)) (* MUTATION: no inversion here *)
  893. ELSE
  894. Ebyte (JccShortInv (cc))
  895. END ;"""
  896. assert s.count(old) == 1, 'EmJcc Ebyte found %d times -- update this mutation' % s.count(old)
  897. open(p, 'w').write(s.replace(old, new))
  898. PYX
  899. then
  900. if rebuild_compiler; then
  901. expect_red "clause H catches the inversion dropped for IF and CASE only" \
  902. "t22_case" python3 tests/check_8086.py
  903. else
  904. echo " FAIL: the compiler would not rebuild with the partial inversion"
  905. fail=$((fail + 1))
  906. fi
  907. else
  908. echo " BROKEN CASE: the partial-inversion mutation did not apply"
  909. fail=$((fail + 1))
  910. fi
  911. cp "$SAVED_C" Compiler.mod
  912. # And the check on the RESTORED compiler, so a green above cannot come from a
  913. # mutation that failed to take and left the real defect in place.
  914. if rebuild_compiler; then
  915. if python3 tests/check_8086.py >/dev/null 2>&1; then
  916. echo " ok: check_8086 green on the restored compiler"
  917. pass=$((pass + 1))
  918. else
  919. echo "NOT RESTORED: check_8086.py is red after restoring Compiler.mod"
  920. python3 tests/check_8086.py 2>&1 | grep -m3 -- ' - ' | sed 's/^/ /'
  921. fail=$((fail + 1))
  922. fi
  923. else
  924. echo "NOT RESTORED: the compiler would not rebuild"
  925. fail=$((fail + 1))
  926. fi
  927. echo
  928. echo "== the emitter-name audit of Compiler.mod (audit_helpers.py)"
  929. # These need no rebuild: the audit reads the SOURCE, not the built object, so
  930. # they are the cheapest cases here and they cover the module the audit used
  931. # not to look at at all. That is the point of the section: the audit reported
  932. # "every helper agrees with its name" for a module it had never examined, and
  933. # EmXchgAxCx was `93` (XCHG BX,AX) under a name that says XCHG AX,CX for the
  934. # whole life of the project. Two of these five are for faults that were real.
  935. SAVED_C2=../tmp/nonvacuity.Compiler.mod.2
  936. SAVED_R2=../tmp/nonvacuity.Runtime.mod.2
  937. cp Compiler.mod "$SAVED_C2" || exit 1
  938. cp Runtime.mod "$SAVED_R2" || exit 1
  939. restore_audit_sources () {
  940. cp "$SAVED_C2" Compiler.mod
  941. cp "$SAVED_R2" Runtime.mod
  942. }
  943. AUD="python3 tests/audit_helpers.py"
  944. # 1. THE fault. 91h is XCHG AX,CX; 93h is XCHG BX,AX. Both are one byte, so
  945. # the compile matrix never moved and the byte counts never moved.
  946. cp "$SAVED_C2" Compiler.mod
  947. mutate Compiler.mod 's|^ Ebyte (91H)$| Ebyte (93H)|'
  948. expect_red "audit catches XchgAxCx emitting XCHG BX,AX" \
  949. "exchanges Ax and Bx" $AUD
  950. restore_audit_sources
  951. # 2. the coverage check itself. A parameter list that find_helpers does not
  952. # accept is exactly how the real emitter was missed, and the inventory is
  953. # scanned separately on purpose so this can be caught. Without the
  954. # independent scan this case is silent, because both lists would come from
  955. # the same parser and agree that the helper does not exist.
  956. cp "$SAVED_C2" Compiler.mod
  957. mutate Compiler.mod 's|^PROCEDURE EmXchgAxCx () ;$|PROCEDURE EmXchgAxCx (why : CARDINAL) ;|'
  958. expect_red "audit reports an emitter it cannot reach, rather than skipping it" \
  959. "never examined it" $AUD
  960. restore_audit_sources
  961. # 3. EmXchgAxDx was named EmMoveAxDx, which said MOV where the bytes say XCHG.
  962. # 93h here is XCHG AX,BX - one letter away, the exact class of mistake the
  963. # name is supposed to make impossible.
  964. cp "$SAVED_C2" Compiler.mod
  965. mutate Compiler.mod 's|^ Ebyte (92H)$| Ebyte (93H)|'
  966. expect_red "audit catches XchgAxDx emitting XCHG BX,AX" \
  967. "XchgAxDx" $AUD
  968. restore_audit_sources
  969. # 4. CmpArgW0's [BP+2] written as the 386 SIB form, which decodes on a 8086 as
  970. # [SI+24h]. A real bug: the runtime was clearing the wrong memory.
  971. cp "$SAVED_R2" Runtime.mod
  972. mutate Runtime.mod 's| B (83H) ; B (7EH) ; B (2) ; B (0) ;| B (83H) ; B (7CH) ; B (24) ; B (0) ; B (0) ;|'
  973. expect_red "audit catches the [SI+24h] encoding of [BP+2]" \
  974. "memory base is 'si" $AUD
  975. restore_audit_sources
  976. # 5. MovAxSp is POP then PUSH, because MOV AX,[SP] does not exist on an 8086.
  977. # Dropping the POP leaves the stack one word short - a fault in the shape,
  978. # not in a byte value.
  979. cp "$SAVED_C2" Compiler.mod
  980. python3 - <<'PYEOF'
  981. p='Compiler.mod'; s=open(p).read()
  982. a=" Ebyte (58H) ; (* POP AX *)\n"
  983. assert s.count(a)==1, "EmMovAxSp POP line not found -- update this mutation"
  984. open(p,'w').write(s.replace(a, ""))
  985. PYEOF
  986. expect_red "audit catches MovAxSp with its POP missing" \
  987. "MovAxSp" $AUD
  988. restore_audit_sources
  989. # 6. The two-instruction shape: IDIV is CWD then IDIV, and dropping the CWD
  990. # leaves an un-sign-extended dividend in DX:AX. Both are still present as
  991. # a two-step spec, so a missing step has to be visible.
  992. cp "$SAVED_C2" Compiler.mod
  993. mutate Compiler.mod 's| Ebyte (99H) ; Ebyte (0F7H) ; Ebyte (0F9H)| Ebyte (0F7H) ; Ebyte (0F9H)|'
  994. expect_red "audit catches IDiv without the CWD that extends the dividend" \
  995. "IDivAxCx" $AUD
  996. restore_audit_sources
  997. # 7. The byte under EmXorAl01's name, and the row in PATTERNS that was added
  998. # to admit it. `34 01' is XOR AL,#01 - the boolean NOT, and the one emitter
  999. # in Compiler.mod with no ModRM byte at all. A grammar row nobody has ever
  1000. # seen reject anything cannot be trusted to accept only the truth, so here
  1001. # is the rejection: `34 02' is the same length, decodes just as cleanly, and
  1002. # `not x' would flip bit 1 instead of bit 0.
  1003. cp "$SAVED_C2" Compiler.mod
  1004. mutate Compiler.mod 's|^ Ebyte (34H) ; Ebyte (01H)| Ebyte (34H) ; Ebyte (02H)|'
  1005. expect_red "audit catches EmXorAl01 emitting xor al,#2 under a name saying #1" \
  1006. "XorAl01" $AUD
  1007. restore_audit_sources
  1008. # 7b. The other half of that row: the opcode gate. 34h is XOR AL,#imm and
  1009. # 35h is XOR AX,#imm - a word, not a byte, under a name that says AL. The
  1010. # row is pinned to {034h} on purpose, and a pin that has never been asked
  1011. # to hold is a pin. The report is the one thing the row above cannot
  1012. # produce: with no reading at all, the helper falls out of the grammar.
  1013. cp "$SAVED_C2" Compiler.mod
  1014. mutate Compiler.mod 's|^ Ebyte (34H) ; Ebyte (01H)| Ebyte (35H) ; Ebyte (01H)|'
  1015. expect_red "the opcode gate rejects XOR AX under an XOR AL name" \
  1016. "no name pattern accepts it" $AUD
  1017. restore_audit_sources
  1018. if $AUD >/dev/null 2>&1; then
  1019. echo " ok: the audit passes on both restored sources"
  1020. pass=$((pass + 1))
  1021. else
  1022. echo "NOT RESTORED: the audit is red after restoring the sources"
  1023. $AUD 2>&1 | sed 's/^/ /'
  1024. fail=$((fail + 1))
  1025. fi
  1026. echo
  1027. echo "== the BP contract rt_exec.py checks before it starts a machine"
  1028. # wrchar and wrbool both borrowed BP to reach their argument -- [SP] is not
  1029. # encodable in 16-bit mode -- and neither saved it. The driver's cursor into
  1030. # the case record lives in BP precisely because BP is the one register an entry
  1031. # may keep, so "wrchar borrowed it and did not give it back" sent the second
  1032. # call to a garbage address, the machine triple-faulted, and the run printed the
  1033. # record header twice and hung. Both the golden and the audit call that shape
  1034. # CORRECT: the bytes are well formed, every branch is on a boundary, the size
  1035. # is unchanged, and the decode says exactly what it says. So the rule is now
  1036. # checked directly, and these two cases are what make that check more than a
  1037. # claim.
  1038. #
  1039. # rt_exec.py needs the whole runtime rebuilt and then boots 36 machines, so this
  1040. # section is the slow one. The baseline comes first and is asserted: a case
  1041. # that mutates a red tree proves nothing.
  1042. SAVED_R3=../tmp/nonvacuity.Runtime.mod.3
  1043. cp Runtime.mod "$SAVED_R3" || exit 1
  1044. if rebuild; then
  1045. if python3 tests/rt_exec.py >/dev/null 2>&1; then
  1046. echo " ok: baseline - rt_exec.py passes on the unmutated runtime"
  1047. pass=$((pass + 1))
  1048. else
  1049. echo " FAIL: the baseline is already red, so the cases below prove"
  1050. echo " nothing - fix the baseline before reading them"
  1051. python3 tests/rt_exec.py 2>&1 | tail -3 | sed 's/^/ /'
  1052. fail=$((fail + 1))
  1053. fi
  1054. else
  1055. echo " FAIL: could not rebuild the runtime for the baseline"
  1056. fail=$((fail + 1))
  1057. fi
  1058. # 1. THE fault: drop the PUSH, exactly as EmitWrChar was written. This is the
  1059. # shape the behavioural case found, so the byte-level check must find it too
  1060. # -- a check that only the expensive test can trip is a check that has not
  1061. # been made to earn its place.
  1062. cp "$SAVED_R3" Runtime.mod
  1063. python3 - <<'PYEOF'
  1064. p = 'Runtime.mod'
  1065. s = open(p).read()
  1066. a = ' M ("wrchar") ;\n PushBp ; MovBpSp ;\n'
  1067. assert s.count(a) == 1, "EmitWrChar prologue not found exactly once"
  1068. open(p, 'w').write(s.replace(a, ' M ("wrchar") ;\n MovBpSp ;\n'))
  1069. PYEOF
  1070. if rebuild; then
  1071. expect_red "the BP contract catches wrchar borrowing BP unsaved" \
  1072. "borrows BP but does not open with" python3 tests/rt_exec.py
  1073. else
  1074. echo " FAIL: the runtime would not rebuild with the PUSH removed"
  1075. fail=$((fail + 1))
  1076. fi
  1077. cp "$SAVED_R3" Runtime.mod
  1078. # 2. The mirror image: push it and never pop it. A different one-instruction
  1079. # omission with the same consequence for a caller, and the reason the rule
  1080. # asks for the 5D and not just the 55.
  1081. cp "$SAVED_R3" Runtime.mod
  1082. mutate Runtime.mod 's|^ MovSpBp ; PopBp ;$| MovSpBp ;|'
  1083. if rebuild; then
  1084. expect_red "the BP contract catches a BP that is pushed and never popped" \
  1085. "pushes BP but never pops it" python3 tests/rt_exec.py
  1086. else
  1087. echo " FAIL: the runtime would not rebuild with the POP removed"
  1088. fail=$((fail + 1))
  1089. fi
  1090. cp "$SAVED_R3" Runtime.mod
  1091. # 3. The scan's other silent failure: a rule that matches nothing looks exactly
  1092. # like a rule that passes. The pattern the check looks for is changed to one
  1093. # the blob does not contain -- MOV BP,DI, which the runtime has no reason to
  1094. # emit -- so the check has examined thirteen entries and matched nothing and
  1095. # MUST say so rather than report a clean sweep. This is the general shape of
  1096. # the fault this project keeps making: a check whose SUBJECT has drifted
  1097. # reports a confident answer about the wrong thing.
  1098. cp "$SAVED_R3" Runtime.mod
  1099. SAVED_X=../tmp/nonvacuity.rt_exec.py
  1100. cp tests/rt_exec.py "$SAVED_X" || exit 1
  1101. mutate tests/rt_exec.py 's|^MOV_BP_SP = b"\\x8b\\xec" .*$|MOV_BP_SP = b"\\x8b\\xed" # MOV BP,DI: never emitted|' \
  1102. expect_red "a check that matched nothing is a failure, not a pass" \
  1103. "matched nothing" python3 tests/rt_exec.py
  1104. cp "$SAVED_X" tests/rt_exec.py
  1105. if rebuild; then
  1106. if python3 tests/rt_exec.py >/dev/null 2>&1; then
  1107. echo " ok: rt_exec.py passes on the restored source"
  1108. pass=$((pass + 1))
  1109. else
  1110. echo "NOT RESTORED: rt_exec.py is red after restoring Runtime.mod"
  1111. python3 tests/rt_exec.py 2>&1 | tail -3 | sed 's/^/ /'
  1112. fail=$((fail + 1))
  1113. fi
  1114. else
  1115. echo "NOT RESTORED: the runtime would not rebuild"
  1116. fail=$((fail + 1))
  1117. fi
  1118. # 4. The GOLDEN and the entry goldens, which are the other half of the same
  1119. # rule. rt_exec.py states the contract; check_runtime.py pins the bytes.
  1120. # They are separate mechanisms and the case below is what shows the golden
  1121. # one works on its own -- a re-baseline of runtime.golden would otherwise
  1122. # have absorbed the new prologues silently, and the next person to bless it
  1123. # would have no way to know the PUSH and POP were ever missing.
  1124. cp "$SAVED_R3" Runtime.mod
  1125. python3 - <<'PYEOF'
  1126. p = 'Runtime.mod'
  1127. s = open(p).read()
  1128. a = ' M ("wrchar") ;\n PushBp ; MovBpSp ;\n MovAlArg4 ;\n MovSpBp ; PopBp ;\n'
  1129. assert s.count(a) == 1, "EmitWrChar frame not found exactly once"
  1130. open(p, 'w').write(s.replace(a, ' M ("wrchar") ;\n MovBpSp ;\n MovAlArg2 ;\n MovSpBp ;\n'))
  1131. PYEOF
  1132. if rebuild; then
  1133. expect_red "the entry golden catches wrchar without its PUSH BP" \
  1134. "entry wrchar starts 8B EC" python3 tests/check_runtime.py "$DUMP"
  1135. else
  1136. echo " FAIL: the runtime would not rebuild with wrchar's frame removed"
  1137. fail=$((fail + 1))
  1138. fi
  1139. cp "$SAVED_R3" Runtime.mod
  1140. echo
  1141. echo "== the .COM layout check, and the runtime size it now measures"
  1142. # The checker used to RESTATE the runtime's size as a literal. It was wrong
  1143. # by 41 bytes for an unknown time, and every one of the 30 .COM files "failed"
  1144. # on a header read out of the code stream. A duplicated constant that has
  1145. # drifted does not fail loudly; it re-reports the same falsehood, in which the
  1146. # real failures hide. The size is now MEASURED from the image.
  1147. #
  1148. # These cases corrupt a real emitted .COM and require the checker to notice.
  1149. # They need the images, so they are built once and copied; the checker has a
  1150. # --check-only mode for exactly this, because its scratch directory is normally
  1151. # deleted on exit and a check that has only ever seen the truth is not a check.
  1152. KEEPDIR=../tmp/nonvacuity.com
  1153. rm -rf "$KEEPDIR"
  1154. TP_COM_KEEP=1 tests/run_com_tests.sh >../tmp/nonvacuity.com.log 2>&1
  1155. KEEP=$(sed -n 's/^TP_COM_KEEP=1: images left in //p' \
  1156. ../tmp/nonvacuity.com.log | tail -1)
  1157. if [ -z "$KEEP" ] || [ ! -d "$KEEP" ]; then
  1158. echo " FAIL: could not obtain emitted .COM images for the layout cases"
  1159. fail=$((fail + 1))
  1160. else
  1161. COMCHK="tests/run_com_tests.sh --check-only"
  1162. # 0. The baseline. Every case below is a claim that a specific assertion
  1163. # turns red, and none of them means anything if the copies of untouched
  1164. # images already fail. (The stale RT_SZ produced exactly that: 30
  1165. # failures that were not findings.) So this is asserted first, and a
  1166. # failure here is reported as a broken baseline rather than a red test.
  1167. #
  1168. # The baseline is also WHERE THE HEADER OFFSET COMES FROM. Cases 1 and 2
  1169. # used to carry it as the literal 435 and 439, which were ENT_SZ + the
  1170. # runtime size at the time -- 432. Two 4-byte changes to the runtime
  1171. # later, both cases were editing the wrong bytes: 435 had become four
  1172. # bytes inside the runtime itself, so case 1 had stopped testing "the
  1173. # header cannot be found" and had started testing "the checker also
  1174. # notices you scribbled on the code", and case 2 had become a no-op
  1175. # that wrote the header where it already was. Both still went red, for
  1176. # reasons the messages did not name, which is the whole problem: a
  1177. # hard-coded offset is a claim about the world that expires silently.
  1178. #
  1179. # So the offset is read back out of the checker's own report on the
  1180. # untouched images, and the expected numbers below are ARITHMETIC ON IT.
  1181. # If the runtime grows again, these cases still test what they say.
  1182. rm -rf "$KEEPDIR"; mkdir -p "$KEEPDIR"
  1183. cp "$KEEP"/*.COM "$KEEP"/raw.txt "$KEEPDIR"/
  1184. BASE_OUT=$($COMCHK "$KEEPDIR" 2>&1)
  1185. if [ $? -eq 0 ]; then
  1186. echo " ok: baseline - untouched copies of the real images all pass"
  1187. pass=$((pass + 1))
  1188. else
  1189. echo " FAIL: the baseline is already red, so the cases below prove"
  1190. echo " nothing - fix the baseline before reading them"
  1191. printf '%s\n' "$BASE_OUT" | grep FAIL | head -3 | sed 's/^/ /'
  1192. fail=$((fail + 1))
  1193. fi
  1194. BASE_RT=$(printf '%s\n' "$BASE_OUT" \
  1195. | sed -n 's/.*measured runtime size: \([0-9][0-9]*\) bytes.*/\1/p' \
  1196. | head -1)
  1197. if [ -z "$BASE_RT" ]; then
  1198. echo " FAIL: the checker did not report the runtime size it measured,"
  1199. echo " so the cases below cannot find the header to edit"
  1200. fail=$((fail + 1))
  1201. BASE_RT=0
  1202. fi
  1203. # The layout constants are ENT_SZ 3 and HDR_SZ 16 (run_com_tests.sh), so the
  1204. # header sits at hdrOff = 3 + rtSz and the entry jump's displacement must be
  1205. # (hdrOff + 16) - 3. The wanted number is therefore computed from the header
  1206. # OFFSET, not from rtSz: the two differ by 3, and getting that backwards
  1207. # produces a plausible-looking expectation three bytes out, which is how
  1208. # this case came to expect "want 452" and then be reported as not proving
  1209. # what it said.
  1210. BASE_OFF=$((3 + BASE_RT))
  1211. # Case 2 claims a runtime four bytes LONGER, so the header - and with it the
  1212. # demanded jump target - moves four bytes further on.
  1213. SHIFTED_WANT=$((BASE_OFF + 4 + 16 - 3))
  1214. echo " (measured runtime size $BASE_RT, header at image offset $BASE_OFF)"
  1215. # 1. Break hdrDS so it no longer ties the header to its own offset. The
  1216. # header must become UNFINDABLE and be reported as such - a checker that
  1217. # fell back to a remembered offset would report a confident number here,
  1218. # which is the failure mode the measurement was introduced to remove.
  1219. rm -rf "$KEEPDIR"; mkdir -p "$KEEPDIR"
  1220. cp "$KEEP"/*.COM "$KEEP"/raw.txt "$KEEPDIR"/
  1221. python3 - "$KEEPDIR/t01_minimal.COM" "$BASE_OFF" <<'PYEOF'
  1222. import sys
  1223. p, off = sys.argv[1], int(sys.argv[2])
  1224. d = bytearray(open(p, 'rb').read())
  1225. d[off + 4:off + 6] = (0x1234).to_bytes(2, 'little') # hdrDS, no longer self-consistent
  1226. open(p, 'wb').write(bytes(d))
  1227. PYEOF
  1228. expect_red "a header that cannot be located is reported, not assumed" \
  1229. "no program header found" $COMCHK "$KEEPDIR"
  1230. # 2. A complete, self-consistent header four bytes later, so the measured
  1231. # runtime size becomes $((BASE_RT + 4)) instead of $BASE_RT. This is the
  1232. # positive half of the same check: the derivation must FOLLOW the file,
  1233. # and the entry jump assertion - expressed in terms of the measurement -
  1234. # must follow it too, demanding $SHIFTED_WANT rather than $((BASE_OFF + 16 - 3)).
  1235. #
  1236. # hdrCS is copied from the header already in the file rather than written
  1237. # as a literal. It used to be the literal 464+100h, which was the image
  1238. # length when the image was 720 bytes; four bytes of runtime later it was
  1239. # 464+100h against a 724-byte image, so this case was ALSO failing on
  1240. # hdrCS, for a reason three lines below the one it was written to test.
  1241. rm -rf "$KEEPDIR"; mkdir -p "$KEEPDIR"
  1242. cp "$KEEP"/*.COM "$KEEP"/raw.txt "$KEEPDIR"/
  1243. python3 - "$KEEPDIR/t01_minimal.COM" "$BASE_OFF" "$SHIFTED_WANT" <<'PYEOF'
  1244. import sys
  1245. p, off, want = sys.argv[1], int(sys.argv[2]), int(sys.argv[3])
  1246. d = bytearray(open(p, 'rb').read())
  1247. hdrCS = int.from_bytes(d[off + 2:off + 4], 'little') # unchanged: still the image end
  1248. off += 4
  1249. ds = off + 0x1000 + 0x100
  1250. w = [1, hdrCS, ds, ds + 4, 0, 0, 0, 0]
  1251. for i, x in enumerate(w):
  1252. d[off + 2 * i:off + 2 * i + 2] = x.to_bytes(2, 'little')
  1253. open(p, 'wb').write(bytes(d))
  1254. PYEOF
  1255. expect_red "the measured runtime size follows the image ($BASE_RT -> $((BASE_RT + 4)))" \
  1256. "want $SHIFTED_WANT" $COMCHK "$KEEPDIR"
  1257. # 3. The entry jump's opcode. One byte, and the only assertion in the
  1258. # project that can see where execution STARTS.
  1259. rm -rf "$KEEPDIR"; mkdir -p "$KEEPDIR"
  1260. cp "$KEEP"/*.COM "$KEEP"/raw.txt "$KEEPDIR"/
  1261. python3 - "$KEEPDIR/t01_minimal.COM" <<'PYEOF'
  1262. import sys
  1263. p = sys.argv[1]
  1264. d = bytearray(open(p, 'rb').read())
  1265. d[0] = 0xEA
  1266. open(p, 'wb').write(bytes(d))
  1267. PYEOF
  1268. expect_red "the entry jump must be E9, not a near JMP" \
  1269. "not the E9 of the entry jump" $COMCHK "$KEEPDIR"
  1270. # 4. The entry jump's target, moved one instruction earlier. A .COM that
  1271. # lands in the middle of the prologue runs, prints something and exits
  1272. # cleanly, so no size or structure check can see this.
  1273. rm -rf "$KEEPDIR"; mkdir -p "$KEEPDIR"
  1274. cp "$KEEP"/*.COM "$KEEP"/raw.txt "$KEEPDIR"/
  1275. python3 - "$KEEPDIR/t01_minimal.COM" <<'PYEOF'
  1276. import sys
  1277. p = sys.argv[1]
  1278. d = bytearray(open(p, 'rb').read())
  1279. d[1:3] = (100).to_bytes(2, 'little')
  1280. open(p, 'wb').write(bytes(d))
  1281. PYEOF
  1282. expect_red "the entry jump must land on the first instruction" \
  1283. "entry jump rel16=100" $COMCHK "$KEEPDIR"
  1284. rm -rf "$KEEPDIR"
  1285. fi
  1286. echo
  1287. echo "non-vacuity: $pass ok, $fail failed"
  1288. [ "$fail" -eq 0 ]