[Merge] (MGPipe, P5): integrate package w1

This commit is contained in:
2026-09-11 15:56:17 -04:00
7 changed files with 4352 additions and 138 deletions
+452 -15
View File
@@ -6,11 +6,39 @@
// SPDX-License-Identifier: LGPL-3.0-only
// End of Source File Header
// P5 package w1: MGPCaps's two blob serializers, the pair MGPipeTypes.h:134-136 defers to
// this phase by name ("Their serializers land with the transport (P5)").
//
// THE FORMAT, and every part of it is a refusal rather than a guess. It is
// ProgramArtifactsCodec's shape on purpose - that codec is the tree's one worked example of a
// wire format that has survived a real transport, so copying it is cheaper than being
// original and much cheaper than being wrong:
//
// * a VERSION word first, and the two TABLE DIMENSIONS second, so a peer whose
// TextureInternalFormat enum grew is a mismatch AT READ TIME rather than a silent shear
// that reads one format's capabilities as another's;
// * length-prefixed everything, with the count checked against the bytes that REMAIN before
// a single element is reserved, so a corrupt count cannot become a four-billion-element
// resize;
// * SPARSE for all three capability tables. The dense form is
// 2 * targets * formats * 8 bytes plus the sample-count lists - with 13 targets and 77
// internal formats that is ~16 KiB of mostly zeroes, PER CONTEXT AND PER CAPS
// INVALIDATION, because R-12 makes a re-arriving snapshot the invalidation rather than a
// once-per-process cost. The tables are overwhelmingly empty, so what crosses is
// (index, value) pairs and the decoder Clear()s first;
// * little-endian by memcpy of fixed-width scalars, which is what every other MobileGL wire
// struct already assumes and what the ABI fingerprint below makes checkable;
// * every decoder returns FALSE on truncation, a bad version, a dimension mismatch, an
// out-of-range index or TRAILING BYTES THE FORMAT DOES NOT ACCOUNT FOR. These bytes
// arrive over a wire and the outputs are left in a defined, default state on a refusal.
#include "CapsCodec.h"
#include <MGGitHash.h>
#include <MG_Util/Debug/Log.h>
#include <cstdlib>
#include <cstring>
namespace MobileGL::MG_Remote {
@@ -29,28 +57,437 @@ namespace MobileGL::MG_Remote {
static_assert(MG_Pipe::kMGPipeSubsystemsMigratedAtP4a <= 0xFFFFull,
"the subsystem mask no longer fits CallMask's sixteen consumer bits");
#define MGP5_C0_STUB(what) \
do { \
MGLOG_F("MGPipe: Fatal{UnimplementedCapsCodec, \"%s\"} - P5 package w1 has not landed " \
"this yet; c0 shipped the signature only", \
what); \
std::abort(); \
} while (0)
namespace {
Bool EncodeFormatCapabilities(const MG_Backend::FormatCapabilityCache&, Vector<Uint8>&) {
MGP5_C0_STUB("EncodeFormatCapabilities");
// Bumped whenever the bytes change in a way a previous reader would misread. A reader
// that sees a different word REFUSES; it never tries to guess a layout.
constexpr Uint32 kFormatCapabilitiesCodecVersion = 1;
constexpr Uint32 kRendererInfoCodecVersion = 1;
// A count is never believed before it is weighed against the bytes that are left. The
// largest legal element count in either blob is bounded by the tables' own dimensions,
// but a String's length is not, so the reader checks bytes rather than a constant.
class Writer {
public:
explicit Writer(Vector<Uint8>& out) : m_out(out) {}
void Raw(const void* bytes, SizeT size) {
if (size == 0) {
return;
}
const auto* p = static_cast<const Uint8*>(bytes);
m_out.insert(m_out.end(), p, p + size);
}
void U8(Uint8 v) { Raw(&v, sizeof(v)); }
void U32(Uint32 v) { Raw(&v, sizeof(v)); }
void U64(Uint64 v) { Raw(&v, sizeof(v)); }
void I32(Int32 v) { Raw(&v, sizeof(v)); }
void Str(const String& s) {
U32(static_cast<Uint32>(s.size()));
Raw(s.data(), s.size());
}
void OptStr(const Optional<String>& s) {
U8(s.has_value() ? 1u : 0u);
if (s.has_value()) {
Str(*s);
}
}
private:
Vector<Uint8>& m_out;
};
class Reader {
public:
Reader(const void* bytes, Uint64 size)
: m_p(static_cast<const Uint8*>(bytes)), m_left(bytes != nullptr ? size : 0) {}
Bool Raw(void* out, Uint64 size) {
if (!m_ok || size > m_left) {
m_ok = false;
return false;
}
std::memcpy(out, m_p, static_cast<SizeT>(size));
m_p += size;
m_left -= size;
return true;
}
Bool U8(Uint8& v) { return Raw(&v, sizeof(v)); }
Bool U32(Uint32& v) { return Raw(&v, sizeof(v)); }
Bool U64(Uint64& v) { return Raw(&v, sizeof(v)); }
Bool I32(Int32& v) { return Raw(&v, sizeof(v)); }
Bool Str(String& s) {
Uint32 length = 0;
if (!U32(length)) {
return false;
}
// THE CHECK THAT MATTERS: the count is weighed against the bytes that remain
// BEFORE the string is sized, so a corrupt length is a refusal rather than a
// four-gigabyte allocation.
if (length > m_left) {
m_ok = false;
return false;
}
s.assign(reinterpret_cast<const char*>(m_p), static_cast<SizeT>(length));
m_p += length;
m_left -= length;
return true;
}
Bool OptStr(Optional<String>& s) {
Uint8 present = 0;
if (!U8(present)) {
return false;
}
if (present == 0) {
s.reset();
return true;
}
String value;
if (!Str(value)) {
return false;
}
s = Move(value);
return true;
}
// How many elements of `elementBytes` could still possibly be there. The gate a
// length-prefixed array is held to before it reserves anything.
Uint64 RoomFor(Uint64 elementBytes) const {
return elementBytes == 0 ? 0 : m_left / elementBytes;
}
Bool Ok() const { return m_ok; }
Uint64 Left() const { return m_left; }
// Trailing bytes the format does not account for are a REFUSAL: they mean the
// writer and the reader disagree about the shape, and the half that was read is
// not trustworthy just because it parsed.
Bool Finished() const { return m_ok && m_left == 0; }
private:
const Uint8* m_p = nullptr;
Uint64 m_left = 0;
Bool m_ok = true;
};
using MG_Backend::FormatCapabilityCache;
using MG_Backend::FormatCapabilityFlags;
constexpr Uint64 kFormatCells = static_cast<Uint64>(MG_Backend::kFormatCapabilityTargetCount) *
static_cast<Uint64>(MG_Backend::kFormatCapabilityFormatCount);
// FNV-1a, the same mixer the tree already uses for build-stamp style fingerprints.
constexpr Uint64 kFnvOffset = 1469598103934665603ull;
constexpr Uint64 kFnvPrime = 1099511628211ull;
Uint64 FnvBytes(Uint64 hash, const void* bytes, SizeT size) {
const auto* p = static_cast<const Uint8*>(bytes);
for (SizeT i = 0; i < size; ++i) {
hash ^= static_cast<Uint64>(p[i]);
hash *= kFnvPrime;
}
return hash;
}
Uint64 FnvU64(Uint64 hash, Uint64 value) { return FnvBytes(hash, &value, sizeof(value)); }
} // namespace
// ---------------------------------------------------------------------------------
// FormatCapabilityCache
// ---------------------------------------------------------------------------------
Bool EncodeFormatCapabilities(const FormatCapabilityCache& cache, Vector<Uint8>& out) {
Writer w(out);
w.U32(kFormatCapabilitiesCodecVersion);
w.U32(static_cast<Uint32>(MG_Backend::kFormatCapabilityTargetCount));
w.U32(static_cast<Uint32>(MG_Backend::kFormatCapabilityFormatCount));
w.U32(0); // reserved, keeps the header 16 bytes and 8-aligned for the pairs below
// The two flag tables, sparse. A cell is written only when it is non-zero, so what
// crosses is proportional to what the driver actually supports rather than to the
// square of two enum spaces.
const auto writeTable = [&](const MG_Backend::FormatCapabilityTable& table) {
Uint32 populated = 0;
for (SizeT t = 0; t < MG_Backend::kFormatCapabilityTargetCount; ++t) {
for (SizeT f = 0; f < MG_Backend::kFormatCapabilityFormatCount; ++f) {
if (table[t][f].GetRaw() != 0) {
++populated;
}
}
}
w.U32(populated);
for (SizeT t = 0; t < MG_Backend::kFormatCapabilityTargetCount; ++t) {
for (SizeT f = 0; f < MG_Backend::kFormatCapabilityFormatCount; ++f) {
const Uint64 raw = static_cast<Uint64>(table[t][f].GetRaw());
if (raw == 0) {
continue;
}
w.U32(static_cast<Uint32>(t * MG_Backend::kFormatCapabilityFormatCount + f));
w.U64(raw);
}
}
};
writeTable(cache.FullCaps);
writeTable(cache.CaveatCaps);
// The sample-count lists: the Vector<Int> that is the reason this cannot be a memcpy.
Uint32 populated = 0;
for (SizeT t = 0; t < MG_Backend::kFormatCapabilityTargetCount; ++t) {
for (SizeT f = 0; f < MG_Backend::kFormatCapabilityFormatCount; ++f) {
if (!cache.SampleCounts[t][f].empty()) {
++populated;
}
}
}
w.U32(populated);
for (SizeT t = 0; t < MG_Backend::kFormatCapabilityTargetCount; ++t) {
for (SizeT f = 0; f < MG_Backend::kFormatCapabilityFormatCount; ++f) {
const Vector<Int>& counts = cache.SampleCounts[t][f];
if (counts.empty()) {
continue;
}
w.U32(static_cast<Uint32>(t * MG_Backend::kFormatCapabilityFormatCount + f));
w.U32(static_cast<Uint32>(counts.size()));
for (const Int value : counts) {
w.I32(static_cast<Int32>(value));
}
}
}
return true;
}
Bool DecodeFormatCapabilities(const void*, Uint64, MG_Backend::FormatCapabilityCache&) {
MGP5_C0_STUB("DecodeFormatCapabilities");
Bool DecodeFormatCapabilities(const void* bytes, Uint64 size, FormatCapabilityCache& out) {
out.Clear();
Reader r(bytes, size);
Uint32 version = 0;
Uint32 targets = 0;
Uint32 formats = 0;
Uint32 reserved = 0;
if (!r.U32(version) || !r.U32(targets) || !r.U32(formats) || !r.U32(reserved)) {
return false;
}
if (version != kFormatCapabilitiesCodecVersion) {
MGLOG_E("MG_Remote caps: format-capability blob is version %u, this build reads %u",
version, kFormatCapabilitiesCodecVersion);
return false;
}
if (targets != MG_Backend::kFormatCapabilityTargetCount ||
formats != MG_Backend::kFormatCapabilityFormatCount) {
// Not a corrupt stream: a peer whose TextureTarget or TextureInternalFormat enum
// is a different size. Reading it anyway shears every cell onto a neighbouring
// format, which is exactly the failure the ABI fingerprint exists to make loud.
MGLOG_E("MG_Remote caps: format-capability blob is %ux%u, this build is %llux%llu",
targets, formats,
static_cast<unsigned long long>(MG_Backend::kFormatCapabilityTargetCount),
static_cast<unsigned long long>(MG_Backend::kFormatCapabilityFormatCount));
return false;
}
const auto readTable = [&](MG_Backend::FormatCapabilityTable& table) -> Bool {
Uint32 populated = 0;
if (!r.U32(populated)) {
return false;
}
if (populated > r.RoomFor(sizeof(Uint32) + sizeof(Uint64))) {
return false;
}
for (Uint32 i = 0; i < populated; ++i) {
Uint32 index = 0;
Uint64 raw = 0;
if (!r.U32(index) || !r.U64(raw)) {
return false;
}
if (static_cast<Uint64>(index) >= kFormatCells) {
return false;
}
table[index / MG_Backend::kFormatCapabilityFormatCount]
[index % MG_Backend::kFormatCapabilityFormatCount] =
FormatCapabilityFlags(raw);
}
return true;
};
if (!readTable(out.FullCaps) || !readTable(out.CaveatCaps)) {
out.Clear();
return false;
}
Uint32 populated = 0;
if (!r.U32(populated) || populated > r.RoomFor(2 * sizeof(Uint32))) {
out.Clear();
return false;
}
for (Uint32 i = 0; i < populated; ++i) {
Uint32 index = 0;
Uint32 count = 0;
if (!r.U32(index) || !r.U32(count)) {
out.Clear();
return false;
}
if (static_cast<Uint64>(index) >= kFormatCells || count > r.RoomFor(sizeof(Int32))) {
out.Clear();
return false;
}
Vector<Int>& counts = out.SampleCounts[index / MG_Backend::kFormatCapabilityFormatCount]
[index % MG_Backend::kFormatCapabilityFormatCount];
counts.resize(static_cast<SizeT>(count));
for (Uint32 j = 0; j < count; ++j) {
Int32 value = 0;
if (!r.I32(value)) {
out.Clear();
return false;
}
counts[j] = static_cast<Int>(value);
}
}
if (!r.Finished()) {
MGLOG_E("MG_Remote caps: format-capability blob has %llu trailing bytes the format "
"does not account for",
static_cast<unsigned long long>(r.Left()));
out.Clear();
return false;
}
return true;
}
Bool EncodeRendererInfo(const RendererInfo&, Vector<Uint8>&) { MGP5_C0_STUB("EncodeRendererInfo"); }
// ---------------------------------------------------------------------------------
// RendererInfo
// ---------------------------------------------------------------------------------
Bool DecodeRendererInfo(const void*, Uint64, RendererInfo&) { MGP5_C0_STUB("DecodeRendererInfo"); }
namespace {
Uint64 CapsAbiFingerprint() { MGP5_C0_STUB("CapsAbiFingerprint"); }
void WriteVersion(Writer& w, const Version& v) {
w.I32(static_cast<Int32>(v.Major));
w.I32(static_cast<Int32>(v.Minor));
w.I32(static_cast<Int32>(v.Patch));
w.OptStr(v.Suffix);
w.U8(v.Type.has_value() ? 1u : 0u);
w.U8(v.Type.has_value() ? static_cast<Uint8>(*v.Type) : 0u);
}
#undef MGP5_C0_STUB
Bool ReadVersion(Reader& r, Version& v) {
Int32 major = 0;
Int32 minor = 0;
Int32 patch = 0;
if (!r.I32(major) || !r.I32(minor) || !r.I32(patch)) {
return false;
}
v.Major = static_cast<Int>(major);
v.Minor = static_cast<Int>(minor);
v.Patch = static_cast<Int>(patch);
if (!r.OptStr(v.Suffix)) {
return false;
}
Uint8 hasType = 0;
Uint8 type = 0;
if (!r.U8(hasType) || !r.U8(type)) {
return false;
}
if (hasType != 0) {
v.Type = static_cast<VersionType>(type);
} else {
v.Type.reset();
}
return true;
}
} // namespace
Bool EncodeRendererInfo(const RendererInfo& info, Vector<Uint8>& out) {
Writer w(out);
w.U32(kRendererInfoCodecVersion);
w.Str(info.RendererName);
w.Str(info.BackendName);
w.OptStr(info.ExtraVendor);
WriteVersion(w, info.RendererGLInfo.TargetGLVersion);
WriteVersion(w, info.RendererGLInfo.TargetGLSLVersion);
w.U32(static_cast<Uint32>(info.RendererGLInfo.Extensions.size()));
for (const GLExtension extension : info.RendererGLInfo.Extensions) {
w.U32(static_cast<Uint32>(extension));
}
w.U8(info.RendererGLInfo.IsCompatibilityProfile ? 1u : 0u);
w.U8(info.StaticBackendCapability.AllowVSOnlyPrograms ? 1u : 0u);
return true;
}
Bool DecodeRendererInfo(const void* bytes, Uint64 size, RendererInfo& out) {
out = RendererInfo{};
Reader r(bytes, size);
Uint32 version = 0;
if (!r.U32(version)) {
return false;
}
if (version != kRendererInfoCodecVersion) {
MGLOG_E("MG_Remote caps: renderer-info blob is version %u, this build reads %u", version,
kRendererInfoCodecVersion);
return false;
}
if (!r.Str(out.RendererName) || !r.Str(out.BackendName) || !r.OptStr(out.ExtraVendor) ||
!ReadVersion(r, out.RendererGLInfo.TargetGLVersion) ||
!ReadVersion(r, out.RendererGLInfo.TargetGLSLVersion)) {
out = RendererInfo{};
return false;
}
Uint32 extensionCount = 0;
if (!r.U32(extensionCount) || extensionCount > r.RoomFor(sizeof(Uint32))) {
out = RendererInfo{};
return false;
}
out.RendererGLInfo.Extensions.resize(static_cast<SizeT>(extensionCount));
for (Uint32 i = 0; i < extensionCount; ++i) {
Uint32 value = 0;
if (!r.U32(value)) {
out = RendererInfo{};
return false;
}
out.RendererGLInfo.Extensions[i] = static_cast<GLExtension>(value);
}
Uint8 compatibility = 0;
Uint8 vsOnly = 0;
if (!r.U8(compatibility) || !r.U8(vsOnly)) {
out = RendererInfo{};
return false;
}
out.RendererGLInfo.IsCompatibilityProfile = compatibility != 0;
out.StaticBackendCapability.AllowVSOnlyPrograms = vsOnly != 0;
if (!r.Finished()) {
MGLOG_E("MG_Remote caps: renderer-info blob has %llu trailing bytes the format does "
"not account for",
static_cast<unsigned long long>(r.Left()));
out = RendererInfo{};
return false;
}
return true;
}
// ---------------------------------------------------------------------------------
// The ABI assertion the handshake carries
// ---------------------------------------------------------------------------------
Uint64 CapsAbiFingerprint() {
// MGPCaps has only a COMPOSITIONAL size assertion (MGPipeTypes.h:145-146) because
// DynamicBackendParameters still carries SizeT and GLenum members - P0.5's fixed-width
// rewrite did not happen and P5 does not do it either (table 0's ABI row; the rewrite
// is P7's account). So the caps block's literal size IS ABI-dependent, and this
// fingerprint is what turns that from a latent hazard into a named refusal.
//
// The git stamp is in it because two builds of the same sizes can still disagree about
// a FIELD ORDER, which no sizeof can see; P6's spawn is same-machine and same-binary,
// so it inherits this unchanged rather than needing a looser rule.
Uint64 hash = kFnvOffset;
hash = FnvU64(hash, sizeof(MG_Backend::DynamicBackendParameters));
hash = FnvU64(hash, sizeof(MG_Pipe::MGPCaps));
hash = FnvU64(hash, sizeof(MG_Backend::GLFunctionsTable));
hash = FnvU64(hash, static_cast<Uint64>(MG_Backend::kFormatCapabilityTargetCount));
hash = FnvU64(hash, static_cast<Uint64>(MG_Backend::kFormatCapabilityFormatCount));
hash = FnvU64(hash, kFormatCapabilitiesCodecVersion);
hash = FnvU64(hash, kRendererInfoCodecVersion);
hash = FnvU64(hash, static_cast<Uint64>(MG_Pipe::MGPWireOp::kOpCount));
hash = FnvBytes(hash, GIT_COMMIT_HASH_SHORT, std::strlen(GIT_COMMIT_HASH_SHORT));
return hash;
}
} // namespace MobileGL::MG_Remote
File diff suppressed because it is too large Load Diff
+282 -4
View File
@@ -111,12 +111,83 @@ namespace MobileGL::MG_Remote::Wire {
// R-2.3 arms 1-4 over one record's blobref. Split only; a monolith emission is exempt by
// construction because it never reaches this layer.
//
// ARMS 3 AND 4 ONLY, PLUS ONE THIS FUNCTION HAD TO INVENT. A blobref is honest when it is
// EITHER fully declared - a real Seg, a non-zero Size and an Offset+Size inside that
// segment - OR fully absent, which is all three fields zero. The third shape, a Seg or an
// Offset with Size == 0, is neither, and it is the shape a monolith emitter produces
// today (Seg = None, Offset = a host address, Size = 0), so under split it has to be
// Fatal rather than "absent": a decoder that read it as absent would silently drop the
// bytes of every record an unconverted emitter sent.
//
// ARM 2 - "Blob.Size == 0 on a CONTENT record" - is NOT here and cannot be: whether a
// record carries content is a property of the record's OTHER fields (ChunkMask, the
// destination range, GlobalUboSize, the stage mask), which this signature does not see.
// RequireDeclaredBlob below is arm 2, and the decoder's per-op arm calls it exactly where
// the payload says content is implied.
void CheckBlobIsHonest(MG_Pipe::MGPWireOp op, const MG_Pipe::MGPBlobRef& blob,
const SegmentTable& segments);
// R-2.3 arm for MGHostSpan. P5's reduced path should produce ZERO host spans
// R-2.3 arm 2: the record's other fields say it carries content, so the blob must be
// declared. Fatal on an absent blob, then CheckBlobIsHonest on a present one.
void RequireDeclaredBlob(MG_Pipe::MGPWireOp op, const MG_Pipe::MGPBlobRef& blob,
const SegmentTable& segments);
// R-2.3 arms 1 and 3 for MGHostSpan. P5's reduced path should produce ZERO host spans
// (kCapNeedsHostIndexBytes / kCapNeedsHostUboBytes are both 0 in P5, table 0), so this
// firing at all is a finding, not just a corruption check.
//
// IT CANNOT DO ARM 4 - it has no segment table - so a span that names a real segment and a
// run PAST THE END OF IT passes this function. Use the overload below on any path that has
// a table; this one exists because c0 shipped the signature and other packages compile
// against it.
void CheckHostSpanIsHonest(const MG_Pipe::MGHostSpan& span);
// All four arms. Arm 4 is the one the signature above cannot express: a span is only
// honest if its Offset+Size actually lies inside the segment it names, and the promise
// WireVerbSink's header makes - that OnDrawVbo is handed a VALIDATED argument list - is
// false without it. Latent in P5 (nothing emits a span) and armed at P8, which is exactly
// when nobody will be reading this file.
void CheckHostSpanIsHonest(const MG_Pipe::MGHostSpan& span, const SegmentTable& segments);
// ---- one record's shape, computed ONCE and read by both sides ----------------------
//
// THE TAIL CROSS-CHECK LIVES HERE AND NOWHERE ELSE (BRIEF §5 w1, contract table 1 group
// B). MGP_WIRE_CHECK_BOUNDS only proves `size >= sizeof(MGPWireRec_X)` - IT CANNOT SEE
// THE TAIL - so a record declaring Count = 4000 while carrying 8 bytes passes it. The
// encoder computes this layout from the payload it is about to write and REFUSES a caller
// whose tails disagree; the decoder computes the same layout from the payload it just
// received and REFUSES a record whose MGPWireRecHeader::Size disagrees. Two readers, one
// arithmetic, so the two sides cannot drift.
//
// EVERY TAIL STARTS 8-BYTE ALIGNED WITHIN THE RECORD, and the encoder zero-fills the gap.
// Eight of the nine kVarTail rows are already aligned by construction (their payload and
// element sizes are multiples of 8); DrawVbo is not - MGPDrawRange is TWELVE bytes, so an
// odd NumDraws leaves the conditional MGHostSpan on a 4-byte boundary, and MGHostSpan
// holds a pointer and two Uint64s. P5 emits no host span at all, so this rule costs
// nothing now and is stated now because the phase that arms kDrawHasUserIndices would
// otherwise have to discover it as a misaligned load on a device.
struct WireRecordLayout {
Uint64 PayloadBytes = 0; // sizeof the op's payload struct
Uint64 TailOffset[2] = {0, 0}; // from the START of the record, header included
Uint64 TailBytes[2] = {0, 0};
Uint32 TailCount = 0;
Uint64 TotalBytes = 0; // header + payload + gaps + tails, rounded up to 8
};
// `payload` must already be known to hold at least the op's payload struct - that is what
// MGP_WIRE_CHECK_BOUNDS proves, and this function is only ever called after it. Returns
// false for an opcode outside the catalogue; a count past its own GL bound is Fatal,
// because a decoder holding such a record has nothing safe left to do with it.
Bool MGPipeWireRecordLayout(MG_Pipe::MGPWireOp op, const void* payload, WireRecordLayout& out);
// The catalogue's own spelling of an opcode, for a Fatal line. Out of range is "<opcode>".
const char* WireOpName(MG_Pipe::MGPWireOp op);
// One tail array. Two of the 71 rows carry two (SetShaderBuffers, SetStreamOutputTargets)
// and DrawVbo carries a conditional second one, which is why EncodeRecord's one-tail form
// could not stay the only one.
struct WireTail {
const void* Bytes = nullptr;
Uint64 Size = 0;
};
// ---- encoder -----------------------------------------------------------------------
//
@@ -150,6 +221,50 @@ namespace MobileGL::MG_Remote::Wire {
Uint64 EncodeRecord(MG_Pipe::MGPWireOp op, const void* payload, Uint64 payloadBytes,
const void* varTail = nullptr, Uint64 varTailBytes = 0);
// The same call for the three rows that carry TWO tails. The one-tail form above is
// this one with tailCount <= 1; nothing is duplicated between them.
//
// The tails a caller hands over are CROSS-CHECKED against the layout the payload
// itself declares (MGPipeWireRecordLayout): a caller whose Count says 4000 while its
// tail holds 8 bytes is Fatal HERE, on the producing side, rather than on a peer that
// can only report a corrupt stream. That is the same arithmetic the decoder runs, so
// the check is real rather than a restatement of the caller's own belief.
Uint64 EncodeRecord(MG_Pipe::MGPWireOp op, const void* payload, Uint64 payloadBytes,
const WireTail* tails, Uint32 tailCount);
// Releases every SEG_STAGE run named by a record the apply side has RETIRED
// (RingControl::retiredSeq, R-9, which this class only ever READS). Called from
// Publish() and whenever StageBytes runs short, so nothing outside this package has to
// remember to; the allocator reclaims behind retiredSeq and nothing else may
// (table 1's "retires" column, R-11).
//
// THE MARK IS HELD ON THIS SIDE, NOT ON THE WIRE. A record does not carry where its
// staged bytes end, so the encoder remembers {seq, stage cursor} per record and
// reclaims to the newest mark whose seq the server has retired. That is exact, needs
// no wire field, and does not depend on the verb barrier - so it keeps working when
// R-1's barrier retires family by family.
//
// SEG_STAGE'S CURSOR TRIPLE IN RingControl IS NOT USED BY EITHER SIDE IN P5, and this
// is the reason. Ring.h makes stageAppliedTail / stageRetiredTail CONSUMER-owned, the
// server never Pops the stage ring (the decoder resolves by offset), and a producer
// that wrote those cursors would be the very shape R-9 forbids one segment over. So
// the allocator below is entirely encoder-local and the triple is left at its
// InitRingControl values. **s1 must not attach a RingConsumer to
// RingCursorSet::Stage**: its m_localTail would never move, and PublishApplied /
// PublishRetired would then walk both cursors BACKWARDS under this allocator.
void ReclaimStagedBytes();
// Staged bytes not yet reclaimed. The number MOBILEGL_IPC_STAGE_MB has to cover.
Uint64 StagedBytesInFlight() const;
// The {seq, cursor} marks the queue is STILL STORING, consumed ones included - not the
// number in flight. Bounded by twice the records in flight, and exposed so a case can
// assert that bound rather than trust the comment, because an unbounded queue here is
// a steady-state leak no SSIM comparison and no two-scenario lane would ever see.
//
// It reports the storage deliberately: the in-flight count stays at one or two while
// the container behind it grows for ever, so a control written against that number
// goes green through exactly the leak it exists to catch.
SizeT StageMarksHeld() const;
// Release-stores the head cursor, then rings the consumer doorbell IF PARKED. The
// order is pinned by RingTest.cpp:446 and must not be swapped: notify-then-publish
// loses the wakeup.
@@ -163,12 +278,30 @@ namespace MobileGL::MG_Remote::Wire {
Uint64 MaxRecordBytesSeen() const;
private:
// {the record's seq, the SEG_STAGE cursor just past everything that record named}.
struct StageMark {
Uint64 Seq = 0;
Uint64 StageCursor = 0;
};
// The SEG_STAGE linear allocator (BRIEF §5 w1's own wording). Monotonic byte counters
// over the segment; the in-segment offset is `cursor % capacity` and a run that would
// straddle the end skips to the boundary, exactly as a ring does, but WITHOUT touching
// RingControl - see ReclaimStagedBytes above.
Uint8* StageAllocate(Uint64 size);
Transport::RingControl* m_control = nullptr;
Transport::RingProducer* m_cmd = nullptr;
Transport::RingProducer* m_stage = nullptr;
SegmentTable* m_segments = nullptr;
Uint64 m_emitSeq = kInvalidSeq;
Uint64 m_maxRecordBytes = 0;
Vector<StageMark> m_stageMarks;
SizeT m_stageMarkFront = 0;
Uint8* m_stageBase = nullptr;
Uint64 m_stageCapacity = 0;
Uint64 m_stageHead = 0; // monotonic bytes allocated
Uint64 m_stageTail = 0; // monotonic bytes reclaimed
};
// ---- decoder -----------------------------------------------------------------------
@@ -189,6 +322,61 @@ namespace MobileGL::MG_Remote::Wire {
virtual void PostReply(Uint64 seq, Int32 status, const void* bytes, Uint64 size) = 0;
};
// ---- the verb sink: the five rows with no MGPipeApply* to delegate to ---------------
//
// The decoder owns NO semantics, so every arm ends in an existing MGPipeApply* free
// function - except five, and they are exactly contract §7's class B: Clear (57), Blit
// (56), ReadPixels (58), DrawVbo (59) and Present (67). Those are GLFunctionsTable VERBS.
// MG_Pipe has no applier for any of them (the 37 MGPipeApply* entry points are the object
// and state families), so for these five P5 writes the first consumer as well as the first
// producer - and the consumer is the SERVER'S backend call, which is v1's, not the codec's.
//
// So the codec does what it can prove and stops there: it bounds-checks, cross-checks the
// tail, resolves the segments and hands over a DECODED, VALIDATED argument list. With no
// sink installed those five arms return false ("this build does not implement it"), which
// is the same answer the other unimplemented rows give.
//
// SetShaderBuffers (38) and SetStreamOutputTargets (39) also have no applier entry point,
// and they deliberately get NO sink method: both are off P5's reduced path (BRIEF §4's
// exclusion list), so inventing a consumer for them would be building a semantics nobody
// can test this phase. Their arms validate both tails - which is the part a later phase
// must not have to re-derive - and return false.
class WireVerbSink {
public:
virtual ~WireVerbSink() = default;
virtual Bool OnClear(const MG_Pipe::MGPClear& clear) {
(void)clear;
return false;
}
virtual Bool OnBlit(const MG_Pipe::MGPBlit& blit) {
(void)blit;
return false;
}
virtual Bool OnPresent(const MG_Pipe::MGPPresent& present) {
(void)present;
return false;
}
// The pixels go back in the reply slot (contract table 1 row 23: the destination is
// ALWAYS SEG_REPLY in P5, which is why MGPReadbackInfo gains no Seg field), so the
// sink is handed the seq and the sink it must answer into.
virtual Bool OnReadPixels(const MG_Pipe::MGPReadbackInfo& info, Uint64 seq, ReplySink* replies) {
(void)info;
(void)seq;
(void)replies;
return false;
}
// `ranges` is info.NumDraws entries. `userIndices` is null unless the record set
// kDrawHasUserIndices - which P5 never does, because the reduced path draws from a
// VBO precisely so no MGHostSpan is produced (table 0's cap-bit row).
virtual Bool OnDrawVbo(const MG_Pipe::MGPDrawInfo& info, const MG_Pipe::MGPDrawRange* ranges,
const MG_Pipe::MGHostSpan* userIndices) {
(void)info;
(void)ranges;
(void)userIndices;
return false;
}
};
// Not thread safe: one decoder on the apply thread, by construction.
class PipeWireDecoder {
public:
@@ -215,16 +403,106 @@ namespace MobileGL::MG_Remote::Wire {
// here Fatals, because a pad that reached the decoder has already been counted.
Bool DecodeAndApply(const Transport::RingRecordView& record);
// Advanced by exactly one per applied non-pad record. P5 FORBIDS BATCHING IT (R-9):
// the verb barrier's waiter reads it, and a batched watermark makes the client wait
// for records the server has not run.
// THE DECODER'S OWN TALLY, NOT THE SHARED WATERMARK. Advanced by exactly one per
// applied non-pad record.
//
// RingControl::appliedSeq has exactly ONE writer - s1's SessionConsumer::ApplyOne, +1
// per record, pads never counted - and this class writes NO RingControl field at all.
// That is deliberate rather than a division of labour: two writers of a watermark is
// how a waiter resumes on a record the server has not run, which is what R-9's "never
// publish a watermark early" forbids, and there is no checksum on this ring that would
// catch it.
//
// Keeping a private count beside the session's is what makes the batching ban
// CHECKABLE instead of merely stated: after every record the two numbers must agree,
// and a single counter could not tell a batched publish from an honest one.
Uint64 AppliedSeq() const;
// v1 installs the backend bridge for contract §7's five class-B verbs. Null - the
// default - makes those five arms return false rather than invent a semantics.
void SetVerbSink(WireVerbSink* sink);
WireVerbSink* VerbSink() const;
// R-2.5 / rule C's mechanical control: with MOBILEGL_IPC_AUDIT=1 every SEG_STAGE byte
// this decoder resolved for a record is overwritten with 0xDD once the applier has
// RETURNED, so an applier that kept the pointer reads 0xDD on the next frame instead
// of bytes that happen to still be there. Off by default; the run is exact - the
// decoder poisons what it resolved, not a conservative window.
void SetAuditPoison(Bool enabled);
Bool AuditPoison() const;
// How many staged bytes this decoder has poisoned. Zero with the audit off, and the
// number a t1 lane asserts is non-zero with it on: an instrumentation that cannot be
// observed to have run is decoration.
//
// WHAT IT ACTUALLY COVERS is "the blob runs the arm resolved", which today is AT MOST
// ONE per record: tails live in SEG_CMD and are never noted, and CreateShaderState's
// six per-stage runs are Fatal rather than resolved, so the one archive is the only
// multi-kilobyte run in the catalogue that reaches it. The array is eight deep so a
// later phase that declares more can fill it without a code change - and overflowing
// it is Fatal rather than a silent drop, because a poison that quietly stopped
// covering a run is the same failure as no poison at all.
Uint64 PoisonedStageBytes() const;
// R-5's acceptance answer for the four Bool-returning appliers - ResourceCreate,
// ResourceRespecify, ResourceSubData, SetTextureParams.
//
// IT DOES NOT RIDE A REPLY SLOT, and that is a contract conflict this package could
// not settle on its own. CONTRACT-P5.md table 0's reply-slot-header row says DECLINED
// "is how the four Bool acceptance entry points say false (R-5)", but PipeCalls.def
// gives none of those four `kReplySlot` - and table 0 ALSO says kMGPipeCallFlags is
// what "every package" reads, so s1 will size ReplyPool from it. Writing
// SEG_REPLY[seq % slots] for a record the pool never reserved a slot for overwrites a
// waiter's answer, and because the slot header stamps the writer's seq for self-check,
// the waiter's check then fails FOR EVER and the barrier hangs rather than returning
// something wrong. So the decoder posts a reply only for rows whose flags say
// kReplySlot (PostReply itself Fatals otherwise) and exposes the acceptance here
// instead. The integrator rules on which half of the contract moves.
Bool LastAcceptanceKnown() const;
Bool LastAcceptance() const;
Uint64 AcceptedRecords() const;
Uint64 DeclinedRecords() const;
// Points MG_Pipe::gMGPipeWireRecordApply at this layer's thunk. Called once from the
// constructor and modelled on SegmentTable::InstallProcessResolver, which is the same
// shape for the same reason; Uninstall belongs beside that one at teardown. The thunk
// is inert without a decoder on the calling thread, so installing it early changes
// nothing for a monolith caller of MGPipeApplyWireRecord.
static void InstallApplyHook();
static void UninstallApplyHook();
private:
Bool ApplyChecked(MG_Pipe::MGPWireOp op, const void* record, Uint64 size);
const void* ResolveOrFatal(MG_Pipe::MGPWireOp op, const MG_Pipe::MGPBlobRef& blob);
void NoteResolvedRun(MG_Pipe::MGPWireOp op, const MG_Pipe::MGPBlobRef& blob);
void PoisonResolvedRuns();
// The ONLY way this class answers a record. Fatals if `op` carries no kReplySlot -
// see LastAcceptanceKnown() for why that is a Fatal and not a log line.
void PostReply(MG_Pipe::MGPWireOp op, Uint64 seq, Int32 status, const void* bytes,
Uint64 size);
friend Bool MGPipeWireRecordApplyThunk(MG_Pipe::MGPWireOp, const void*, Uint64, Uint64);
Transport::RingControl* m_control = nullptr;
SegmentTable* m_segments = nullptr;
ReplySink* m_replies = nullptr;
WireVerbSink* m_verbs = nullptr;
Uint64 m_applySeq = kInvalidSeq;
Bool m_auditPoison = false;
Uint64 m_poisonedBytes = 0;
Bool m_lastAcceptanceKnown = false;
Bool m_lastAcceptance = false;
Uint64 m_accepted = 0;
Uint64 m_declined = 0;
// The SEG_STAGE runs the record being applied resolved, for the 0xDD fill. Eight deep
// so CreateShaderState's seven blob members plus a tail would fit if a later phase
// declares them; today at most one run is ever noted (see PoisonedStageBytes).
MG_Pipe::MGPBlobRef m_resolved[8];
Uint32 m_resolvedCount = 0;
};
// The hook MGPipeApplyWireRecord dispatches to once its generated per-opcode bounds gate
// has passed. Inert unless a decoder is active on the calling thread.
Bool MGPipeWireRecordApplyThunk(MG_Pipe::MGPWireOp op, const void* record, Uint64 size,
Uint64 remaining);
} // namespace MobileGL::MG_Remote::Wire