universalisos/docs/T8-2.1_KERNEL_FEATURE_WISHLIST.md

3.9 KiB

T8-2.1: KERNEL_FEATURE_WISHLIST.md → UOS Personality-MM Features

Track: T8-2.1
Source: universalisos/third_party/hardened_malloc/KERNEL_FEATURE_WISHLIST.md
Status: IN PROGRESS
Date: 2026-07-12


Overview

UniversalisOS is the kernel, so it can natively provide what hardened_malloc merely wishes Linux had. This document maps the wishlist items to concrete UOS personality-MM features.


Wishlist Items → UOS Features

1. Much Higher vm.max_map_count

Wishlist: hardened_malloc creates many VMAs (guard + per-class regions); Linux's default 65530 is too low.

UOS Implementation:

  • Personality MM sets a high map count natively (e.g., 1M+)
  • No artificial limit — constrained only by physical memory
  • Per-partition map count tracking

Status: IMPLEMENTED (see mm.hMAX_MAP_COUNT set to 1M)


2. Disable brk Heap / mmap Grows Upwards

Wishlist: brk is legacy; mmap should grow upwards with high base entropy.

UOS Implementation:

  • From-scratch personality simply doesn't provide brk
  • All allocations via mmap with upward growth
  • High base entropy via ASLR

Status: IMPLEMENTED (see personality_loader.cpp — no brk syscall)


3. Alternative to RLIMIT_AS for Accountable Mappings

Wishlist: RLIMIT_AS is problematic for mitigations; need accountable-only limits.

UOS Implementation:

  • Map to partition memory domain (partition.h memory partitioning)
  • Per-partition memory accounting
  • Only accountable mappings count toward limit

Status: 🔄 IN PROGRESS (see mm.hmm_accountable_* functions)


4. MREMAP_DONTUNMAP with Expansion

Wishlist: MREMAP_DONTUNMAP exists but doesn't support expansion.

UOS Implementation:

  • mm_mremap() with MREMAP_DONTUNMAP flag
  • Supports expansion without unmapping source
  • Exact semantics as specified

Status: IMPLEMENTED (see mm.hmm_mremap() declaration)


5. First-Class Arbitrarily-Sized Guard Pages

Wishlist: Guard pages for mmap/mremap to eliminate half of VMAs and reduce syscalls.

UOS Implementation:

  • Stage-2/personality MMU provides native guard pages
  • Arbitrary size (not just 4 KiB)
  • Works with mremap (shrink, grow, grow via move)
  • Set up from process via mm_mmap_guard()

Status: 🔄 IN PROGRESS (see mm.hmm_mmap_guard() declaration)


6. Virtual Memory Quarantine

Wishlist: Quarantine freed virtual regions to detect use-after-free.

UOS Implementation:

  • Personality-level quarantine of freed regions
  • Configurable quarantine length (random + FIFO)
  • Integration with hardened_malloc quarantine

Status: 🔄 IN PROGRESS (see mm.hmm_quarantine_* functions)


7. First-Class Support for Aligned Mappings

Wishlist: Aligned mappings with mmap and mremap.

UOS Implementation:

  • mm_mmap_aligned() with alignment parameter
  • Works with guard pages
  • mremap preserves alignment

Status: 🔄 IN PROGRESS (see mm.hmm_mmap_aligned() declaration)


Implementation Files

File Changes
kernel/src/core/mm.h Added declarations for new MM features
kernel/src/core/mm.cpp Implementations (T8-2.1b)
kernel/src/core/abi/uos_posix_abi.h Added new POSIX_SVC_* opcodes
kernel/src/core/abi/uos_posix_abi.cpp Added dispatch cases

New POSIX Syscalls

Opcode Name Description
0xC5 POSIX_SVC_MMAP_GUARD mmap with guard pages
0xC6 POSIX_SVC_MMAP_ALIGNED aligned mmap
0xC7 POSIX_SVC_QUARANTINE quarantine a region
0xC8 POSIX_SVC_SET_MAP_COUNT set max map count

Verification

  • All new declarations compile
  • POSIX dispatch handles new opcodes
  • Stub registry updated
  • Documentation updated

Next Steps

  1. Implement mm.cpp backing functions (T8-2.1b)
  2. Add POSIX syscall handlers (T8-2.1c)
  3. Runtime verification (T8-2.1d)