fn call_ifunc_resolver(
user_as: &AddressSpace,
resolver_vaddr: u64,
) -> Result<u64, &'static str>Expand description
Calls a user-space IFUNC resolver function and returns its result.
The resolver is located at resolver_vaddr in the user address space.
All RELATIVE relocations for this binary must have been applied first so
that the resolver’s own calls/addresses are correct.
§Security note (audit 2026-09-07)
IFUNC resolvers execute as ordinary user-space functions, but this helper calls them from Ring 0 via HHDM. A malicious or corrupted resolver can read/write kernel memory and escalate privileges. This is acceptable for a single-address-space kernel that loads only trusted binaries, but must NOT be used if untrusted ELF images are ever loaded.
To make accidental misuse hard, the helper enforces, at runtime, that
the resolver lives in a PT_LOAD marked as non-writable & executable
(resolvers must be .text, never .data). A hostile binary that
plants an IFUNC resolver in a writable page will fail this check.
Future hardening:
- compile the resolver under a sandbox (no
syscall, noiret); - require an opt-in build flag (
features = "ifunc_resolver") so the unsafe code path is absent by default in production kernels.