casaroli opened a new pull request, #20384:
URL: https://github.com/apache/nuttx/pull/20384
## Summary
In a protected build a module loaded by `exec()` runs as a user task, and
the ELF loader puts it in the text and data heaps (`CONFIG_ARCH_USE_TEXT_HEAP`,
`CONFIG_ARCH_USE_DATA_HEAP`), which on MPS are SRAM2. Nothing gave user code
access to SRAM2: the only grant, in `arm_addregion()`, exists only with
`CONFIG_MM_REGIONS > 1`, and it uses `mpu_user_intsram()`, which on ARMv8-M is
execute-never. So on `mps3-an547:knsh` every module faulted on its first
instruction.
This maps SRAM2 for user code to read, write and execute when either heap is
in use. Privileged execution stays allowed, because a kernel module loaded
with `insmod` lands in the same heaps. The first commit is whitespace only: it
fixes one older nxstyle error in the file.
## Impact
Only a protected MPS build with `CONFIG_ARCH_USE_TEXT_HEAP` or
`CONFIG_ARCH_USE_DATA_HEAP` changes. Today that can only be `mps3-an547`.
SRAM2 becomes writable and executable from user mode. A kernel module
loaded into it is therefore not protected from user code, which is the price of
one heap serving both.
## Testing
`mps3-an547:knsh` under QEMU with `CONFIG_ELF`, both heaps and the ROMFS
variant of `examples/elf`. (That variant is gated on `BUILD_FLAT` in apps, and
the gate was lifted locally for the test.)
```
before: * Executing errno
arm_memfault: Instruction access violation
Assertion failed ... task: errno process: errno 0x21000001
after: * Executing errno, hello, signal, struct, hello++1, hello++2,
hello++3, mutex, pthread, task
Memory Usage End-of-Test:
```
`tools/checkpatch.sh -c -u -m -g` passes.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]