fn apply_segment_permissions(
user_as: &AddressSpace,
page_start: u64,
page_count: usize,
flags: VmaFlags,
) -> Result<(), &'static str>Expand description
Performs the apply segment permissions operation.
§SMP / TLB invariants (DO NOT BREAK)
During ELF loading, the caller (the loader) is the sole user of the
target AddressSpace: the address space was just created with
AddressSpace::new_user and is not yet attached to any task. Because
of this, the function only performs a local TLB invalidation on the
current CPU when CR3 matches the address space.
§Hard constraint
This function MUST NOT be reused as a generic mprotect after the
image has started executing. Once a user task has been scheduled,
the address space may be active on another CPU and a local-only flush
would let stale writable mappings survive on remote CPUs, breaking
RELRO guarantees and creating an exploitable window. A future
mprotect implementation must use the cross-CPU TLB shootdown path
(tlb::shootdown_range) instead of this helper.