Managing memory permissions

EP4573458A1Pending Publication Date: 2025-06-25HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
EP2023717089
Authority / Receiving Office
EP · EP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-03-31
Publication Date
2025-06-25

AI Technical Summary

Technical Problem

Current memory management systems face performance issues due to inefficiencies in managing changing memory permissions, particularly in scenarios like Just-In-Time (JIT) compilation, where frequent updates to Translation Look-aside Buffers (TLBs) and page table entries are required, leading to performance bottlenecks and increased complexity, especially when dealing with user-mode processes and existing general-purpose processor designs.

Method used

Implementing multiple address spaces with varying memory permissions for a process, allowing for seamless switching between them without flushing TLBs or interfering with hardware optimizations, using a mechanism that maintains 'nigh-copies' of address spaces with the same virtual-physical mappings but different permissions, and utilizing an interface between the operating system and the JIT compiler to manage these permissions.

Benefits of technology

This approach eliminates full context switching overhead, reduces the need for TLB flushing, and maintains hardware optimization benefits, enabling efficient memory management without additional processor design complexities, thus enhancing performance and security by isolating memory access permissions effectively.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2023058498_03102024_PF_FP_ABST
    Figure EP2023058498_03102024_PF_FP_ABST
Patent Text Reader

Abstract

In some examples, a method comprises providing, by an operating system, multiple address spaces for a process of an application to be executed, each of the multiple address spaces comprising respective different access permissions.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] MANAGING MEMORY PERMISSIONS

[0002] TECHNICAL FIELD

[0003] The present disclosure relates, in general, to managing memory permissions in a processor.

[0004] BACKGROUND

[0005] Modem processors (CPU) and multitasking operating systems (OS) provide memory protection, isolation and dynamic allocation through virtual memory. Namely, each process is given a distinct address space which is their virtual view of memory. Within a given address space, the operating system manages the different physical memory granules that the corresponding process can access, with which permissions: read, write and / or execute; and with which attributes: caching, sharing, and such.

[0006] Computing systems often utilize memory management units (MMUs) for translating virtual addresses into physical addresses. In addition to performing translations, MMUs may also control memory access permissions. However, managing memory access permissions is associated with a number of performance issues relating to efficiency and latency.

[0007] SUMMARY

[0008] An objective of the present disclosure is to support changing sets of memory mappings quickly without flushing the Translation Look-aside Buffers (or more generally, without interfering with hardware optimisations of the virtual memory functionality), and with existing normal general- purpose processors.

[0009] The foregoing and other objectives are achieved by the features of the independent claims.

[0010] Further implementation forms are apparent from the dependent claims, the description and the Figures.

[0011] A first aspect of the present disclosure provides a method comprising providing, by an operating system, multiple address spaces for a process of an application to be executed, each of the multiple address spaces comprising respective different access permissions. Accordingly, full context switching overhead can be eliminated. Furthermore, there are no restrictions on architecture, design and implementation of a compiler to isolate the compiler function from the generated code.

[0012] In an implementation of the first aspect, the operating system may maintain a description of the different access permissions for the process.

[0013] Each address space of the multiple address spaces may correspond to a mode of the process, the process comprising a plurality of modes.

[0014] The process may indicate to the operating system when to switch from one of the multiple address spaces to another of the multiple address spaces, based on the mode.

[0015] A compiler associated with the process may provide the different access permissions to the operating system for memory mapping.

[0016] Each of the multiple address spaces may relate to a single memory location in a physical memory.

[0017] The method may further comprise allocating, by the operating system, an address space identifier, ASID, for each of the multiple address spaces.

[0018] The method may further comprise providing, by a hypervisor, multiple address spaces for a virtual machine, each of the multiple address spaces comprising respective different access permissions.

[0019] The method may comprise maintaining a description of the different access permissions for the virtual machine.

[0020] The method may comprise allocating, by a hypervisor, a virtual machine identification, VMID, for each of the multiple address spaces.

[0021] A second aspect of the present disclosure provides an apparatus configured to perform the method described herein.

[0022] The compiler may comprise a just-in-time, JIT, compiler.

[0023] The apparatus may be arranged to assign the access permissions using flags.

[0024] An instruction set architecture implemented by a processor of the apparatus may comprise x86- 64, Armv7-VHE, Armv8-A, and RISC-V. A third aspect of the present disclosure provides a computer readable storage medium comprising computer program code, accessible by an apparatus comprising a processor, to provide instructions and / or data to the apparatus, the computer program code configured to, with the processor, cause the apparatus to provide, by an operating system, multiple address spaces for a process of an application to be executed, each of the multiple address spaces comprising respective different access permissions.

[0025] These and other aspects of the invention will be apparent from the embodiment s) described below.

[0026] BRIEF DESCRIPTION OF THE DRAWINGS

[0027] In order that the present invention may be more readily understood, embodiments of the invention will now be described, by way of example, with reference to the accompanying drawings, in which:

[0028] Figure l is a flow chart of a method according to an example; and

[0029] Figure 2 is a schematic representation of an apparatus according to an example.

[0030] Detailed Description

[0031] Example embodiments are described below in sufficient detail to enable those of ordinary skill in the art to embody and implement the systems and processes herein described. It is important to understand that embodiments can be provided in many alternate forms and should not be construed as limited to the examples set forth herein.

[0032] Accordingly, while embodiments can be modified in various ways and take on various alternative forms, specific embodiments thereof are shown in the drawings and described in detail below as examples. There is no intent to limit to the particular forms disclosed. On the contrary, all modifications, equivalents, and alternatives falling within the scope of the appended claims should be included. Elements of the example embodiments are consistently denoted by the same reference numerals throughout the drawings and detailed description where appropriate.

[0033] The terminology used herein to describe embodiments is not intended to limit the scope. The articles “a,” “an,” and “the” are singular in that they have a single referent, however the use of the singular form in the present document should not preclude the presence of more than one referent. In other words, elements referred to in the singular can number one or more, unless the context clearly indicates otherwise. It will be further understood that the terms “comprises,” “comprising,” “includes,” and / or “including,” when used herein, specify the presence of stated features, items, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, items, steps, operations, elements, components, and / or groups thereof.

[0034] Unless otherwise defined, all terms (including technical and scientific terms) used herein are to be interpreted as is customary in the art. It will be further understood that terms in common usage should also be interpreted as is customary in the relevant art and not in an idealized or overly formal sense unless expressly so defined herein.

[0035] On modem instruction set architectures (x86, Arm, RISC-V, etc), the address space is described by the operating system to the hardware Memory Management Unit via “page tables”. In reality, those constitute multiple levels of nested hash tables, with a virtual memory address as the input key. The process of looking up an entry is known as a “page table walk”.

[0036] The page tables themselves are also stored in computer memory. Accordingly, when a running process accesses memory, the MMU must first perform several serialised memory accesses to “walk the page table”. At last, it can verify the permissions and attributes, determine the physical address of the memory that the process intends to access, and the intended memory access can take place.

[0037] To avoid the evident performance bottleneck, modem processor MMU designs feature hardware caching structures known as “Translation Look-aside Buffers” (TLBs). If a memory access matches an existing entry within the TLBs, then the page table walk can be avoided (the exact heuristics by which entries are added and evicted from the cache are trade secrets of processor design companies).

[0038] On the flip side, the operating system must notify the MMU whenever a page table entry is modified, so as to invalidate a potentially stale cache entry within the TLBs. At some point, a page table walk then occurs again to generate an updated cache entry as needed. Essentially, TLBs are optimized for the scenario whereby the memory permissions and mappings of a given process remain constant over time. If memory permissions change often, then TLBs do not improve performance, and even may reduce it. When the OS scheduler switches the running process on a given CPU, the address space changes completely. To avoid having to completely flush the TLB entries every time, the ISA usually defines a cache keying mechanism, such that TLB entries are segregated by process (the key is called ASID on Arm, PCID on Intel / x86).

[0039] The problem however remains when changing memory permissions (and / or physical mappings or attributes) without changing the running process.

[0040] In particular, a “just in time” (JIT) compiler, as is commonly used to run application using some form intermediate code representation, such as Java, .Net, Javascript or WebAssembler may exhibit those circumstances frequently. In those cases, the compiler needs to write memory range containing the generated code for the machine, while the run-time needs to execute the same memory range. Also, the generated code is generally less trusted and should not be able to write those memory range (or those of the compiler).

[0041] Not only this requires flushing the TLBs, but it also requires updating a potentially large number of page table entries within the page tables. To do that, the JIT needs to affect a lot of system calls.

[0042] Currently available solutions attempt to address these issues by defining a new system control register which provides a layer of indirection for memory mapping permissions, for example, by designing custom extensions to their processors. The page tables contain an index value in place of the permission flag-bits. A system register of the processor defines the run-time mapping of index values to actual permission flags. However, this typically works only in privileged mode of the operating system and is not suitable for user mode processes. Another drawback of such approach is that it requires a new processor design to implement the functionality in the hardware, therefore being associated with additional costs and an increased complexity.

[0043] According to an example, there is provided a mechanism to allow an application process to switch all its memory mapping permission in a uniform way in a single operation and without flushing the Translation Lookaside Buffers or otherwise interfering with hardware optimisations within a given implementation of virtual memory consisting of a given Memory Management Unit. Furthermore, the mechanism is applicable to existing general purpose / application processor designs. Examples in the present disclosure can be provided as methods, systems or machine-readable instructions, such as any combination of software, hardware, firmware or the like. Such machine-readable instructions may be included on a computer readable storage medium (including but not limited to disc storage, CD-ROM, optical storage, etc.) having computer readable program codes therein or thereon.

[0044] The present disclosure is described with reference to flow charts and / or block diagrams of the method, devices and systems according to examples of the present disclosure. Although the flow diagrams described above show a specific order of execution, the order of execution may differ from that which is depicted. Blocks described in relation to one flow chart may be combined with those of another flow chart. In some examples, some blocks of the flow diagrams may not be necessary and / or additional blocks may be added. It shall be understood that each flow and / or block in the flow charts and / or block diagrams, as well as combinations of the flows and / or diagrams in the flow charts and / or block diagrams can be realized by machine readable instructions.

[0045] The machine-readable instructions may, for example, be executed by a machine such as a general-purpose computer, user equipment such as a smart device, e.g., a smart phone, a special purpose computer, an embedded processor or processors of other programmable data processing devices to realize the functions described in the description and diagrams. In particular, a processor or processing apparatus may execute the machine-readable instructions. Thus, modules of apparatus (for example, a module implementing a comparator unit, or a firewall structure and so on) may be implemented by a processor executing machine readable instructions stored in a memory, or a processor operating in accordance with instructions embedded in logic circuitry. The term 'processor' is to be interpreted broadly to include a CPU, processing unit, ASIC, logic unit, or programmable gate set etc. The methods and modules may all be performed by a single processor or divided amongst several processors.

[0046] Such machine-readable instructions may also be stored in a computer readable storage that can guide the computer or other programmable data processing devices to operate in a specific mode. For example, the instructions may be provided on a non-transitory computer readable storage medium encoded with instructions, executable by a processor.

[0047] To avoid resetting the TLB, rewriting the page tables and placing many system calls, this invention proposes to keep multiple “nigh-copies” of the address spaces for a single process, if the process is a JIT compilation environment. These “nigh-copies” describe multiple address spaces (presumably two), with the same virtual-physical address mappings, but have varying memory permissions for at least some of those mappings. The invention involves an interface between the software / application / process using the invention and the software component in charge of programming virtual memory (presumably the operating system kernel component), to switch between address spaces, without changing the active running process.

[0048] Figure 1 is a flow chart of a method according to an example. In block 101, an operating system (and / or an operating system kernel) provides multiple address spaces for a process of an application to be executed, each of the multiple address spaces comprising respective different access permissions. For example, a first of the multiple address spaces may comprise privileged (higher) access permissions compared with the access permissions of a second of the multiple address spaces, or vice versa.

[0049] Each of the multiple address spaces may relate to the same memory location in a physical memory of an apparatus. In other words, while associated with respective different access permissions, the address spaces may map (or correspond to) the same memory location in the physical memory.

[0050] In existing operating systems, the memory management interface provides means to specify the intended memory permissions for a given memory mapping being created or modified, for instance, as three flags for read, write and execution permissions.

[0051] For understanding the invention, a reference use case of an application running within a Just In Time (JIT) compilation environment on a complex of processors is described. In this scenario, the execution flow of an application may alternate between running the machine code of the JIT compiler to dynamically compile (or recompile) application byte code into machine code and running the machine code thusly generated. Generally speaking, the compiler code will be more trusted than the application code, even though both run within the same process. For instance, the compiler code may be provided by the device vendor or OS vendor, whereas the application code may be provided by a third-party application developer. Accordingly, the JIT code may have more notional permissions and capabilities than the application code.

[0052] JIT compilers have become extremely complex, as many optimisations passes were added to improve the runtime performance of applications. Because of this, many popular JIT compilers have exhibited and most likely will continue to exhibit, implementation or design bugs. Those bugs may be exploited by mal-intent purposefully conceived application code to gain privileges: either gain the additional capabilities of the compiler, or as a step in a privilege escalation attack to even higher privileges.

[0053] A JIT process not using the invention would typically have the memory mappings using the following different permission combinations: read-only for the compiler’s data constants and the generated code’s data constants, read and write for the compiler’s run-time data / state and the generated code’s run-time data, read and execute for compiler’s own code, and read, write, and execute for code generated by the compiler.

[0054] In an implementation of the method, new memory permissions may be defined. For example, in the scenario using the JIT compiler, the following permissions may be distinguished between compiler and generated code. In particular, the code generated by the compiler may have the following permissions: read and execute permissions (not write) when the generated code is running, and read and write permissions (not execute) when the JIT compiler code is running.

[0055] Similar distinctions may be made for non-code data mappings.

[0056] While the above example describes the invention making reference to the JIT compilation environment, the skilled person would readily understand that the invention can also be used for other types of application processes, if they exhibit a similar distinction between different execution modes at run-time (i.e. compilation mode, wherein the compiler’s own code is executed, and running mode, wherein the code generated by the compiler is executed).

[0057] The operating system may maintain a description of the different access permissions for the process. As discussed above, these permissions may relate to writing, reading, and executing. Each address space of the plurality of multiple address spaces may correspond to a mode of the process, the process comprising a plurality of modes. The modes may relate to the origin / type of the code being executed, but are not limited thereto.

[0058] The process may indicate to the operating system when to switch from one of the multiple address spaces to another of the multiple address spaces, based on the mode. For example, based on the mode, the process may indicate to the operating system to switch from a privileged access mode (for example, one that enables writing and executing) to a less privileged access mode (for example, one that enables reading only). The indication may be done by a thread of the process of the application. A compiler associated with the process may provide the different access permissions to the operating system for memory mapping.

[0059] The operating system may provide an address space identifier, ASID, for each of the multiple address spaces. By providing the multiple ASIDs for a single process, the need to flush TLB caches can be eliminated. Flushing the TLB caches loses the performance benefits relating to the use thereof.

[0060] As discussed above, the multiple address spaces may define identical memory mappings, but comprise different access permissions. As such, there is no need to employ a separate mechanism for management of memory mappings. Normal memory management function can apply procedurally to all of the multiple address spaces.

[0061] The method may comprise providing, by a hypervisor, multiple address spaces for a virtual machine, each of the multiple address spaces comprising respective different access permissions. The virtual machine may refer to either an execution environment for a single application which is abstracted from the normal "native" execution environment for normal application (for example, a Java application running inside the JVM, Java Virtual Machine), or to a virtualised computer system (comprising processor, memory, operating system, applications and peripherals) running under a hypervisor. As discussed above, the operating system may provide the ASID for each of the multiple address space permission sets for a given application process. In case the application process comprises a JIT compiler, the virtual machine may designate the execution environment of an application (i.e. first scenario).

[0062] In other words, the invention can also exhibit the multiple address spaces in the second stage of memory translation used by a hypervisor to resolve and constrain the memory accesses of a virtual machine in the form of a full operating system. That is, instead of a process of the application to be executed, the functionality may be provided to qualified virtual machines (VMs). A hypervisor may allocate a virtual machine identification, VMID, for each of the multiple address spaces. The hypervisor may maintain a description of the different access permissions for the virtual machine. In other words, the invention may serve as an interface between the hypervisor managing second stage translation tables, and the qualified VM. Figure 2 is a schematic representation of an apparatus according to an example. The apparatus 200 can be, e.g., a computing system or apparatus, user equipment, a network device (physical or virtual), or part thereof. The apparatus 200 may comprise a processor 203, and a memory 205 coupled to the processor 203 and configured to store instructions or program code 207, executable by the processor 203. The program code 203 may comprise instructions, whereby to cause the apparatus to provide, by an operating system, multiple address spaces for a process of an application to be executed, each of the multiple address spaces comprising respective different access permissions.

[0063] According to an example, machine-readable instructions can be loaded onto a computer or other programmable data processing devices, so that the computer or other programmable data processing devices perform a series of operations to produce computer-implemented processing, thus the instructions executed on the computer or other programmable devices provide an operation for realizing functions specified by flow(s) in the flow charts and / or block(s) in the block diagrams.

[0064] Further, the teachings herein may be implemented in the form of a computer or software product, such as a non-transitory machine-readable storage medium, the computer software or product being stored in a storage medium and comprising a plurality of instructions, e.g., machine readable instructions, for making a computer device implement the methods recited in the examples of the present disclosure.

[0065] In some examples, some methods can be performed in a cloud-computing or network-based environment. Cloud-computing environments may provide various services and applications via the Internet. These cloud-based services (e.g., software as a service, platform as a service, infrastructure as a service, etc.) may be accessible through a web browser or other remote interface of the user equipment for example. Various functions described herein may be provided through a remote desktop environment or any other cloud-based computing environment.

[0066] While various embodiments have been described and / or illustrated herein in the context of fully functional computing systems, one or more of these exemplary embodiments may be distributed as a program product in a variety of forms, regardless of the particular type of computer- readable-storage media used to actually carry out the distribution. The embodiments disclosed herein may also be implemented using software modules that perform certain tasks. These software modules may include script, batch, or other executable files that may be stored on a computer-readable storage medium or in a computing system. In some embodiments, these software modules may configure a computing system to perform one or more of the exemplary embodiments disclosed herein. In addition, one or more of the modules described herein may transform data, physical devices, and / or representations of physical devices from one form to another.

[0067] The preceding description has been provided to enable others skilled in the art to best utilize various aspects of the exemplary embodiments disclosed herein. This exemplary description is not intended to be exhaustive or to be limited to any precise form disclosed. Many modifications and variations are possible without departing from the spirit and scope of the instant disclosure.

[0068] The embodiments disclosed herein should be considered in all respects illustrative and not restrictive. Reference should be made to the appended claims and their equivalents in determining the scope of the instant disclosure.

Claims

CLAIMS1. A method, comprising: providing, by an operating system, multiple address spaces for a process of an application to be executed, each of the multiple address spaces comprising respective different access permissions.

2. The method of claim 1, comprising maintaining, by the operating system, a description of the different access permissions for the process.

3. The method of claim 1 or 2, wherein each address space of the plurality of multiple address spaces corresponds to a mode of the process, the process comprising a plurality of modes.

4. The method of claim 3, wherein the process indicates to the operating system when to switch from one of the multiple address spaces to another of the multiple address spaces, based on the mode.

5. The method of claim 3, wherein a compiler associated with the process provides the different access permissions to the operating system for memory mapping.

6. The method of any preceding claim, wherein each of the multiple address spaces relates to a single memory location in a physical memory.

7. The method of any preceding claim, further comprising allocating, by the operating system, an address space identifier, ASID, for each of the multiple address spaces.

8. The method of any preceding claim, further comprising: providing, by a hypervisor, multiple address spaces for a virtual machine, each of the multiple address spaces comprising respective different access permissions.

9. The method of claim 8, comprising maintaining a description of the different access permissions for the virtual machine.

10. The method of claim 8 or 9, comprising allocating, by the hypervisor, a virtual machine identification, VMID, for each of the multiple address spaces.

11. Apparatus configured to perform the method according to claims 1 to 10.

12. The apparatus of claim 11, wherein the compiler comprises a just-in-time, JIT, compiler.

13. The apparatus of claim 11 or 12, wherein the apparatus is arranged to assign the access permissions using flags.

14. The apparatus of claim 11, 12 or 13, wherein an instruction set architecture implemented by a processor of the apparatus comprises x86-64, Armv7-VHE, Armv8-A, and RISC-V.

15. A computer readable storage medium comprising computer program code, accessible by an apparatus comprising a processor, to provide instructions and / or data to the apparatus, the computer program code configured to, with the processor, cause the apparatus to: provide, by an operating system, multiple address spaces for a process of an application to be executed, each of the multiple address spaces comprising respective different access permissions.