Skip to main content

Module userslice

Module userslice 

Source
Expand description

Userspace pointer validation for Strat9-OS.

The UserSlice pattern (inspired by RedoxOS usercopy.rs) ensures the kernel never dereferences a raw userspace pointer without first checking:

  1. Range: The entire region lies in the user half (< USER_SPACE_END)
  2. Overflow: base + len doesn’t wrap around
  3. Mapping: Every page in the region is present in the active page tables with the requested permissions (read or write)

After validation, UserSlice provides safe copy operations that transfer data between userspace and kernel buffers.

§Example

ⓘ
// In a syscall handler:
let user_buf = UserSliceRead::new(buf_ptr, buf_len)?;
let mut kernel_buf = [0u8; 256];
let n = user_buf.copy_to(&mut kernel_buf)?;

Structs§

UserAccessGuard
RAII guard that disables Supervisor Mode Access Prevention (SMAP) on creation and re-enables it on drop. Ensures AC is restored on all code paths including panics and early returns.
UserSliceRead
A validated read-only reference to a user-space memory region.
UserSliceReadWrite
A validated read-write reference to a user-space memory region.
UserSliceWrite
A validated writable reference to a user-space memory region.

Enums§

Access 🔒
Permission requirements for a user memory region.
UserSliceError
Errors that can occur when constructing or using a UserSlice.

Constants§

MAX_USER_SLICE_LEN 🔒
Maximum length allowed for a single UserSlice (16 MiB).
USER_SPACE_END
End of user-accessible virtual address space.

Traits§

UserPod
Marker trait for types whose every bit pattern is valid (POD / plain old data).

Functions§

check_pages_mapped 🔒
Walk the active page tables to verify that every 4 KiB page covering [base, base+len) is mapped with at least required_flags.
validate_user_region 🔒
Validate that a user memory region [base, base+len) is: