211 lines
8.2 KiB
Markdown
211 lines
8.2 KiB
Markdown
# T8-2.3: Per-Guest Allocator Isolation Audit
|
|
|
|
**Track:** T8-2.3
|
|
**Status:** IN PROGRESS
|
|
**Date:** 2026-07-12
|
|
|
|
---
|
|
|
|
## Overview
|
|
|
|
This audit verifies that each guest's hardened_malloc instance is properly isolated from other guests. Isolation is achieved through:
|
|
|
|
1. **Stage-2 address space isolation** — Each guest has its own IPA→PA translation
|
|
2. **Independent allocator instances** — Each guest's Bionic has its own hardened_malloc
|
|
3. **Partition memory domains** — UOS partition.h memory partitioning
|
|
4. **Independent randomization** — Each guest gets independent random bases
|
|
|
|
---
|
|
|
|
## Isolation Layers
|
|
|
|
```
|
|
┌─────────────────────────────────────────────────────────────┐
|
|
│ Guest A (Android) │
|
|
│ ┌─────────────────────────────────────────────────────┐ │
|
|
│ │ hardened_malloc Instance A │ │
|
|
│ │ - Random base: 0x7f3a2b1c0000 │ │
|
|
│ │ - Quarantine queue: [A1, A2, A3, ...] │ │
|
|
│ │ - Guard regions: [0x7f3a2b1c0000-0x7f3a2b1c1000] │ │
|
|
│ └─────────────────────────────────────────────────────┘ │
|
|
│ │ │
|
|
│ ▼ │
|
|
│ ┌─────────────────────────────────────────────────────┐ │
|
|
│ │ Stage-2 MM (IPA→PA) │ │
|
|
│ │ - IPA: 0x40000000-0x80000000 │ │
|
|
│ │ - PA: 0x40000000-0x80000000 (identity) │ │
|
|
│ └─────────────────────────────────────────────────────┘ │
|
|
└─────────────────────────────────────────────────────────────┘
|
|
│
|
|
│ HYPERVISOR BOUNDARY
|
|
▼
|
|
┌─────────────────────────────────────────────────────────────┐
|
|
│ Guest B (Android) │
|
|
│ ┌─────────────────────────────────────────────────────┐ │
|
|
│ │ hardened_malloc Instance B │ │
|
|
│ │ - Random base: 0x7f8c4d2e0000 (different!) │ │
|
|
│ │ - Quarantine queue: [B1, B2, B3, ...] (separate) │ │
|
|
│ │ - Guard regions: [0x7f8c4d2e0000-0x7f8c4d2e1000] │ │
|
|
│ └─────────────────────────────────────────────────────┘ │
|
|
│ │ │
|
|
│ ▼ │
|
|
│ ┌─────────────────────────────────────────────────────┐ │
|
|
│ │ Stage-2 MM (IPA→PA) │ │
|
|
│ │ - IPA: 0x40000000-0x80000000 │ │
|
|
│ │ - PA: 0x80000000-0xC0000000 (different!) │ │
|
|
│ └─────────────────────────────────────────────────────┘ │
|
|
└─────────────────────────────────────────────────────────────┘
|
|
```
|
|
|
|
---
|
|
|
|
## Audit Checklist
|
|
|
|
### 1. Stage-2 Address Space Isolation
|
|
|
|
- [ ] Each guest has independent Stage-2 page tables
|
|
- [ ] IPA→PA mappings are guest-specific
|
|
- [ ] No shared mappings between guests (except explicit shared memory)
|
|
- [ ] Guard pages are per-guest
|
|
|
|
**Verification:**
|
|
```c
|
|
// Check that guest A's IPA 0x40000000 maps to different PA than guest B's
|
|
assert(guest_a_ipa_to_pa(0x40000000) != guest_b_ipa_to_pa(0x40000000));
|
|
```
|
|
|
|
### 2. Independent Allocator Instances
|
|
|
|
- [ ] Each guest's Bionic initializes its own hardened_malloc
|
|
- [ ] No shared allocator state between guests
|
|
- [ ] Independent random bases (ASLR)
|
|
- [ ] Independent quarantine queues
|
|
|
|
**Verification:**
|
|
```c
|
|
// Check that each guest has different random base
|
|
assert(guest_a_hm_base != guest_b_hm_base);
|
|
```
|
|
|
|
### 3. Partition Memory Domains
|
|
|
|
- [ ] Each guest is in a separate UOS partition
|
|
- [ ] Memory domains are isolated
|
|
- [ ] Accountable memory is per-partition
|
|
- [ ] No cross-partition memory access
|
|
|
|
**Verification:**
|
|
```c
|
|
// Check that guest A cannot access guest B's memory
|
|
assert(!mm_validate_access(guest_a_domain, guest_b_addr, size, PERM_READ));
|
|
```
|
|
|
|
### 4. Independent Randomization
|
|
|
|
- [ ] Each guest gets independent ASLR
|
|
- [ ] Guard page placement is randomized per guest
|
|
- [ ] Quarantine length is randomized per guest
|
|
- [ ] Slot randomization is per guest
|
|
|
|
**Verification:**
|
|
```c
|
|
// Check that guard pages are at different offsets
|
|
assert(guest_a_guard_offset != guest_b_guard_offset);
|
|
```
|
|
|
|
---
|
|
|
|
## Attack Scenarios
|
|
|
|
### Scenario 1: Heap Corruption in Guest A
|
|
|
|
**Attack:** Exploit heap corruption in Guest A to read Guest B's memory.
|
|
|
|
**Mitigation:**
|
|
1. Stage-2 isolation prevents cross-guest memory access
|
|
2. Guest A's hardened_malloc cannot access Guest B's IPA space
|
|
3. Even if Guest A escapes its allocator, it cannot reach Guest B
|
|
|
|
**Result:** ✅ CONTAINED
|
|
|
|
### Scenario 2: Use-After-Free in Guest A
|
|
|
|
**Attack:** Trigger use-after-free in Guest A to leak Guest B's data.
|
|
|
|
**Mitigation:**
|
|
1. Guest A's quarantine queue is independent
|
|
2. Freed memory in Guest A is quarantined in Guest A's space
|
|
3. Guest B's memory is in a different Stage-2 domain
|
|
|
|
**Result:** ✅ CONTAINED
|
|
|
|
### Scenario 3: Guard Page Bypass in Guest A
|
|
|
|
**Attack:** Bypass guard pages in Guest A to access adjacent memory.
|
|
|
|
**Mitigation:**
|
|
1. Guard pages are per-guest
|
|
2. Guest A's guard pages don't protect Guest B
|
|
3. But Guest A cannot reach Guest B due to Stage-2 isolation
|
|
|
|
**Result:** ✅ CONTAINED
|
|
|
|
### Scenario 4: Shared Memory Exploit
|
|
|
|
**Attack:** Exploit shared memory between guests to corrupt allocator state.
|
|
|
|
**Mitigation:**
|
|
1. Shared memory is explicit and limited
|
|
2. Allocator metadata is never shared
|
|
3. Each guest's allocator operates on its own private memory
|
|
|
|
**Result:** ✅ CONTAINED
|
|
|
|
---
|
|
|
|
## Implementation Files
|
|
|
|
| File | Purpose |
|
|
|------|---------|
|
|
| `kernel/src/core/abi/uos_isolation_audit.h` | Audit interface |
|
|
| `kernel/src/core/abi/uos_isolation_audit.cpp` | Audit implementation |
|
|
| `kernel/src/core/mm.h` | MM isolation primitives |
|
|
| `kernel/src/core/partition.h` | Partition isolation |
|
|
|
|
---
|
|
|
|
## Audit API
|
|
|
|
```c
|
|
/* Run full isolation audit for a guest */
|
|
int uos_isolation_audit_run(uint32_t guest_id);
|
|
|
|
/* Check Stage-2 isolation between two guests */
|
|
int uos_isolation_check_stage2(uint32_t guest_a, uint32_t guest_b);
|
|
|
|
/* Check allocator independence */
|
|
int uos_isolation_check_allocator(uint32_t guest_a, uint32_t guest_b);
|
|
|
|
/* Check partition memory domains */
|
|
int uos_isolation_check_partition(uint32_t guest_a, uint32_t guest_b);
|
|
|
|
/* Check randomization independence */
|
|
int uos_isolation_check_randomization(uint32_t guest_a, uint32_t guest_b);
|
|
```
|
|
|
|
---
|
|
|
|
## Verification Results
|
|
|
|
- [ ] All audit checks pass
|
|
- [ ] No cross-guest memory access possible
|
|
- [ ] Independent allocator instances confirmed
|
|
- [ ] Randomization independence confirmed
|
|
|
|
---
|
|
|
|
## References
|
|
|
|
- `universalisos/docs/HARDENED_MALLOC.md` — Config matrix
|
|
- `universalisos/docs/T8-2.1_KERNEL_FEATURE_WISHLIST.md` — MM features
|
|
- `universalisos/docs/T8-2.2_ANDROID_INHERITANCE.md` — Android inheritance
|