Skip to main content

apply_segment_permissions

Function apply_segment_permissions 

Source
fn apply_segment_permissions(
    user_as: &AddressSpace,
    page_start: u64,
    page_count: usize,
    flags: VmaFlags,
) -> Result<(), &'static str>
Expand description

Performs the apply segment permissions operation.

§SMP / TLB invariants (DO NOT BREAK)

During ELF loading, the caller (the loader) is the sole user of the target AddressSpace: the address space was just created with AddressSpace::new_user and is not yet attached to any task. Because of this, the function only performs a local TLB invalidation on the current CPU when CR3 matches the address space.

§Hard constraint

This function MUST NOT be reused as a generic mprotect after the image has started executing. Once a user task has been scheduled, the address space may be active on another CPU and a local-only flush would let stale writable mappings survive on remote CPUs, breaking RELRO guarantees and creating an exploitable window. A future mprotect implementation must use the cross-CPU TLB shootdown path (tlb::shootdown_range) instead of this helper.