universalisos/third_party/hardened_malloc/PROVENANCE.md

43 lines
2.5 KiB
Markdown

# hardened_malloc — Vendored Copy Provenance
**Vendored into:** `universalisos/third_party/hardened_malloc/`
**Date:** 2026-07-11
**Track:** T8-1.1 (hardened_malloc Import & Separation-Model Adoption)
## Source
- **Upstream project:** GrapheneOS `hardened_malloc` — https://github.com/GrapheneOS/hardened_malloc
- **Vendored from (local fork clone):** `portugalfuturista/hardened_malloc` (`git@github.com:portugalfuturista/hardened_malloc.git`)
- **Branch:** `main`
- **Commit:** `1976e09730897c49906dea4ce054ca937c47e0be` (2026-07-10) — "Update README.md to properly use CONFIG_N_ARENA for make invocations"
## What this is
A security-focused general-purpose memory allocator providing the malloc API, hardened
against heap-corruption vulnerabilities. Portable **C23**; supports **Bionic (Android),
musl, and glibc** (explicitly prefers musl). 64-bit only. OpenBSD-malloc-derived design
with per-size-class regions at random bases (PartitionAlloc-inspired).
## License
See `LICENSE` (MIT-style, GrapheneOS) and `CREDITS`. Vendored unmodified except removal
of the `.git/` directory (it was a fork clone). All upstream files preserved:
`Makefile`, `Android.bp`, `config/{default,light}.mk`, `KERNEL_FEATURE_WISHLIST.md`,
`h_malloc.c memory.c pages.c random.c chacha.c util.c new.cc`, `include/`, `test/`,
`preload.sh`, `README.md`, `arm_mte.h`, `memtag.h`, `mutex.h`, `androidtest/`, `third_party/`.
## Why it is vendored (T8)
hardened_malloc is the designated **stepping stone to running multiple concurrent
hardened Android/AOSP/LineageOS/GrapheneOS guests** inside UniversalisOS. It is the only
GrapheneOS component portable across the guest/host boundary (Bionic/musl/glibc). See the
master plan §0.14 and TRACK T8 for the full rationale.
## Integration targets (per deleg_17082fc4 §2.2)
1. **Freestanding EL2 kernel** — NOT a target (no libc, no dynamic allocation).
2. **musl-based POSIX personality** — THE primary import target (standalone `Makefile`,
`CONFIG_SELF_INIT=true`, `N_ARENA=4`).
3. **Host build tools** — opportunistic via `preload.sh` LD_PRELOAD.
4. **Android guests** — inherited via Bionic (`platform_bionic` `h_malloc_wrapper.cpp`);
UniversalisOS's job is to give each guest's Stage-2 MMU the features in
`KERNEL_FEATURE_WISHLIST.md` (guard pages, high map count, mremap semantics).
## Update procedure
To refresh from upstream: re-clone the fork, `cp -a` over this dir, strip `.git/`,
update the commit hash above, and re-run the acceptance gate (`make test`).