# T8-2.3: Per-Guest Allocator Isolation Audit **Track:** T8-2.3 **Status:** IN PROGRESS **Date:** 2026-07-12 --- ## Overview This audit verifies that each guest's hardened_malloc instance is properly isolated from other guests. Isolation is achieved through: 1. **Stage-2 address space isolation** — Each guest has its own IPA→PA translation 2. **Independent allocator instances** — Each guest's Bionic has its own hardened_malloc 3. **Partition memory domains** — UOS partition.h memory partitioning 4. **Independent randomization** — Each guest gets independent random bases --- ## Isolation Layers ``` ┌─────────────────────────────────────────────────────────────┐ │ Guest A (Android) │ │ ┌─────────────────────────────────────────────────────┐ │ │ │ hardened_malloc Instance A │ │ │ │ - Random base: 0x7f3a2b1c0000 │ │ │ │ - Quarantine queue: [A1, A2, A3, ...] │ │ │ │ - Guard regions: [0x7f3a2b1c0000-0x7f3a2b1c1000] │ │ │ └─────────────────────────────────────────────────────┘ │ │ │ │ │ ▼ │ │ ┌─────────────────────────────────────────────────────┐ │ │ │ Stage-2 MM (IPA→PA) │ │ │ │ - IPA: 0x40000000-0x80000000 │ │ │ │ - PA: 0x40000000-0x80000000 (identity) │ │ │ └─────────────────────────────────────────────────────┘ │ └─────────────────────────────────────────────────────────────┘ │ │ HYPERVISOR BOUNDARY ▼ ┌─────────────────────────────────────────────────────────────┐ │ Guest B (Android) │ │ ┌─────────────────────────────────────────────────────┐ │ │ │ hardened_malloc Instance B │ │ │ │ - Random base: 0x7f8c4d2e0000 (different!) │ │ │ │ - Quarantine queue: [B1, B2, B3, ...] (separate) │ │ │ │ - Guard regions: [0x7f8c4d2e0000-0x7f8c4d2e1000] │ │ │ └─────────────────────────────────────────────────────┘ │ │ │ │ │ ▼ │ │ ┌─────────────────────────────────────────────────────┐ │ │ │ Stage-2 MM (IPA→PA) │ │ │ │ - IPA: 0x40000000-0x80000000 │ │ │ │ - PA: 0x80000000-0xC0000000 (different!) │ │ │ └─────────────────────────────────────────────────────┘ │ └─────────────────────────────────────────────────────────────┘ ``` --- ## Audit Checklist ### 1. Stage-2 Address Space Isolation - [ ] Each guest has independent Stage-2 page tables - [ ] IPA→PA mappings are guest-specific - [ ] No shared mappings between guests (except explicit shared memory) - [ ] Guard pages are per-guest **Verification:** ```c // Check that guest A's IPA 0x40000000 maps to different PA than guest B's assert(guest_a_ipa_to_pa(0x40000000) != guest_b_ipa_to_pa(0x40000000)); ``` ### 2. Independent Allocator Instances - [ ] Each guest's Bionic initializes its own hardened_malloc - [ ] No shared allocator state between guests - [ ] Independent random bases (ASLR) - [ ] Independent quarantine queues **Verification:** ```c // Check that each guest has different random base assert(guest_a_hm_base != guest_b_hm_base); ``` ### 3. Partition Memory Domains - [ ] Each guest is in a separate UOS partition - [ ] Memory domains are isolated - [ ] Accountable memory is per-partition - [ ] No cross-partition memory access **Verification:** ```c // Check that guest A cannot access guest B's memory assert(!mm_validate_access(guest_a_domain, guest_b_addr, size, PERM_READ)); ``` ### 4. Independent Randomization - [ ] Each guest gets independent ASLR - [ ] Guard page placement is randomized per guest - [ ] Quarantine length is randomized per guest - [ ] Slot randomization is per guest **Verification:** ```c // Check that guard pages are at different offsets assert(guest_a_guard_offset != guest_b_guard_offset); ``` --- ## Attack Scenarios ### Scenario 1: Heap Corruption in Guest A **Attack:** Exploit heap corruption in Guest A to read Guest B's memory. **Mitigation:** 1. Stage-2 isolation prevents cross-guest memory access 2. Guest A's hardened_malloc cannot access Guest B's IPA space 3. Even if Guest A escapes its allocator, it cannot reach Guest B **Result:** ✅ CONTAINED ### Scenario 2: Use-After-Free in Guest A **Attack:** Trigger use-after-free in Guest A to leak Guest B's data. **Mitigation:** 1. Guest A's quarantine queue is independent 2. Freed memory in Guest A is quarantined in Guest A's space 3. Guest B's memory is in a different Stage-2 domain **Result:** ✅ CONTAINED ### Scenario 3: Guard Page Bypass in Guest A **Attack:** Bypass guard pages in Guest A to access adjacent memory. **Mitigation:** 1. Guard pages are per-guest 2. Guest A's guard pages don't protect Guest B 3. But Guest A cannot reach Guest B due to Stage-2 isolation **Result:** ✅ CONTAINED ### Scenario 4: Shared Memory Exploit **Attack:** Exploit shared memory between guests to corrupt allocator state. **Mitigation:** 1. Shared memory is explicit and limited 2. Allocator metadata is never shared 3. Each guest's allocator operates on its own private memory **Result:** ✅ CONTAINED --- ## Implementation Files | File | Purpose | |------|---------| | `kernel/src/core/abi/uos_isolation_audit.h` | Audit interface | | `kernel/src/core/abi/uos_isolation_audit.cpp` | Audit implementation | | `kernel/src/core/mm.h` | MM isolation primitives | | `kernel/src/core/partition.h` | Partition isolation | --- ## Audit API ```c /* Run full isolation audit for a guest */ int uos_isolation_audit_run(uint32_t guest_id); /* Check Stage-2 isolation between two guests */ int uos_isolation_check_stage2(uint32_t guest_a, uint32_t guest_b); /* Check allocator independence */ int uos_isolation_check_allocator(uint32_t guest_a, uint32_t guest_b); /* Check partition memory domains */ int uos_isolation_check_partition(uint32_t guest_a, uint32_t guest_b); /* Check randomization independence */ int uos_isolation_check_randomization(uint32_t guest_a, uint32_t guest_b); ``` --- ## Verification Results - [ ] All audit checks pass - [ ] No cross-guest memory access possible - [ ] Independent allocator instances confirmed - [ ] Randomization independence confirmed --- ## References - `universalisos/docs/HARDENED_MALLOC.md` — Config matrix - `universalisos/docs/T8-2.1_KERNEL_FEATURE_WISHLIST.md` — MM features - `universalisos/docs/T8-2.2_ANDROID_INHERITANCE.md` — Android inheritance