[BUG] Ordinary frame mapping admits destinations outside the user domain #23

Closed
opened 2026-09-22 01:33:21 +02:00 by erikinkinen · 0 comments
Owner

Summary

Ordinary frame mapping admitted destinations outside the user address domain despite otherwise valid caller-local grants. The admission defect is fixed by the Kernel change. Native privilege escalation was not demonstrated.

Reproduction

The retained host regression against Kernel f50535bfcd exercised five out-of-domain destinations with explicit VSpace and managed-frame grants. All five were admitted. The fixture removed unexpected mappings before reporting its failed assertion. A preliminary short-name exact filter ran zero tests and is not reproduction evidence.

Expected and actual behavior

The corrected path rejects an out-of-domain complete page before backing lookup, retention or mapping mutation. Both VSpace-slot and Process-child dispatch share the guard. Alignment and frame-right checks still run first, while page zero and the final complete lower-canonical page remain valid. The original host test failed; the corrected host controls and actual CPL3 denial, valid map/read/unmap and three-grant cleanup sequence pass.

Environment and identity

  • Affected source: Kernel f50535bfcd; introducing revision and last working revision are unknown.
  • Fixed source: signed Kernel commit; coordinated Integration catalog.
  • Architecture: current four-level x86_64 paging; Rust 1.97.1 and original commit-pinned dependencies.
  • Native diagnostic: release image, one TCG CPU and the unchanged 60-second guest limit. Only owned scratch backing is exposed through explicit frame READ/MAP, endpoint SEND and own-VSpace MAP grants.

Evidence and prior checks

Four strict configurations pass 745 default / 769 all-feature tests, with three existing ignored cases. Formatting, host/native Clippy, private rustdoc and thirteen native build profiles pass without warnings. All 172 Integration helpers pass; the later Kernel-only catalog update preserves those helper and Rust sources exactly. The first native fixture attempt failed its pre-entry capability inventory. Its correction declares the new grants, supplies a MAP-only own-VSpace alias after root handles are removed, and checks all three drops without relaxing the inventory or page census. A second attempt reached the syscall checks but its new slots were outside the existing admitted window; the next placement overlapped an earlier derivation destination. The final layout follows the complete earlier grant extent and checks the original window at compile time. All three failed images remain retained. The last adjustments change only native fixture layout; matching native Clippy/build profiles and native private rustdoc pass, while exact unchanged host and production sources retain their strict matrix. Three exact-source native executions pass lifetime, invocation and mapping; both mapping-isolation and sparse contracts pass on the same capture with identical runtime settings. All fifteen native component signatures and normally stripped packaged Kernel identities verify. The unchanged ordinary exec-successor service VM also passes against the complete catalog, with no image warnings and empty QEMU stderr. The manual update passes all 45 tests and 2,431 pages, with no final warnings.

Tracking

Fixed in Kernel PR 3, adopted in Integration PR 12, with documentation in Docs PR 4. Follow-up root construction and bootstrap provenance remain in Kernel issue 22. This bounded fix does not close the broader authority or self-hosting requirements in the phase checklist.

Verified documentation and CI follow-up — 22 September 2026: Kernel documentation and Integration documentation record the accepted native mapping, three-grant cleanup and ordinary exec-successor evidence. Every executable file is identical to the tested implementation; Markdown and diff checks pass. All three failed fixture attempts remain in report 24, separately from the fixed admission defect. The complete manual passes 45 tests and 2,431 pages with no final warnings. The final static inventory covers 3,180 authored code files below 1,000 lines, 259 exact Git pins and the existing direct missing_docs declarations; it does not establish full semantic authority closure.

Original full Integration 1703/1704, source dff878dd3545c4751b3c05d37b2bdd5e21cce548, pass from six complete logs totalling 26,964,178 bytes and zero warnings. Their ext4 quota/links and FAT32 directory scenarios explicitly pass. Earlier timing failures remain retained and their causes are unestablished. Kernel 634/635 report cancelled, with runner context-cancellation messages and four complete logs. No cancellation request was issued during this work; the workflow declares no cancellation policy, and the initiating cause remains unestablished. These runs receive no CI acceptance credit. Current Kernel 636/637 and Docs 1007/1008 pass. Each pair has four complete logs: Kernel totals 773,796 bytes with zero warnings, and Docs totals 774,706 bytes with zero final warnings. Both manual builds retain their initial 35/1/0 LaTeX warning sequence through convergence. Integration 1717–1720 remains queued.

The phase checklist remains at 15/460 accepted leaves, weighted 3.48%. Private hardware roots, complete authority cleanup, measured startup improvement, native external Rust/LLVM/runtime rebuilding and both complete EriX guest-build generations remain open.

## Summary Ordinary frame mapping admitted destinations outside the user address domain despite otherwise valid caller-local grants. The admission defect is fixed by [the Kernel change](https://git.erikinkinen.fi/erix/kernel/commit/ef3fd9293eaf691269fdb9e6b72eb15dac1f3f06). Native privilege escalation was not demonstrated. ## Reproduction The retained host regression against Kernel f50535bfcd9aa57271762bb0b4da7d759d08906e exercised five out-of-domain destinations with explicit VSpace and managed-frame grants. All five were admitted. The fixture removed unexpected mappings before reporting its failed assertion. A preliminary short-name exact filter ran zero tests and is not reproduction evidence. ## Expected and actual behavior The corrected path rejects an out-of-domain complete page before backing lookup, retention or mapping mutation. Both VSpace-slot and Process-child dispatch share the guard. Alignment and frame-right checks still run first, while page zero and the final complete lower-canonical page remain valid. The original host test failed; the corrected host controls and actual CPL3 denial, valid map/read/unmap and three-grant cleanup sequence pass. ## Environment and identity - Affected source: Kernel f50535bfcd9aa57271762bb0b4da7d759d08906e; introducing revision and last working revision are unknown. - Fixed source: [signed Kernel commit](https://git.erikinkinen.fi/erix/kernel/commit/ef3fd9293eaf691269fdb9e6b72eb15dac1f3f06); coordinated [Integration catalog](https://git.erikinkinen.fi/erix/integration/commit/cd560584d034720ac179d5abc6f2a9d965943c63). - Architecture: current four-level x86_64 paging; Rust 1.97.1 and original commit-pinned dependencies. - Native diagnostic: release image, one TCG CPU and the unchanged 60-second guest limit. Only owned scratch backing is exposed through explicit frame READ/MAP, endpoint SEND and own-VSpace MAP grants. ## Evidence and prior checks Four strict configurations pass 745 default / 769 all-feature tests, with three existing ignored cases. Formatting, host/native Clippy, private rustdoc and thirteen native build profiles pass without warnings. All 172 Integration helpers pass; the later Kernel-only catalog update preserves those helper and Rust sources exactly. The first native fixture attempt failed its pre-entry capability inventory. Its correction declares the new grants, supplies a MAP-only own-VSpace alias after root handles are removed, and checks all three drops without relaxing the inventory or page census. A second attempt reached the syscall checks but its new slots were outside the existing admitted window; the next placement overlapped an earlier derivation destination. The final layout follows the complete earlier grant extent and checks the original window at compile time. All three failed images remain retained. The last adjustments change only native fixture layout; matching native Clippy/build profiles and native private rustdoc pass, while exact unchanged host and production sources retain their strict matrix. Three exact-source native executions pass lifetime, invocation and mapping; both mapping-isolation and sparse contracts pass on the same capture with identical runtime settings. All fifteen native component signatures and normally stripped packaged Kernel identities verify. The unchanged ordinary exec-successor service VM also passes against the complete catalog, with no image warnings and empty QEMU stderr. The [manual update](https://git.erikinkinen.fi/erix/docs/commit/043df99baaa9d4539da627fbfe4a234e41e74135) passes all 45 tests and 2,431 pages, with no final warnings. ## Tracking Fixed in [Kernel PR 3](https://git.erikinkinen.fi/erix/kernel/pulls/3), adopted in [Integration PR 12](https://git.erikinkinen.fi/erix/integration/pulls/12), with documentation in [Docs PR 4](https://git.erikinkinen.fi/erix/docs/pulls/4). Follow-up root construction and bootstrap provenance remain in [Kernel issue 22](https://git.erikinkinen.fi/erix/kernel/issues/22). This bounded fix does not close the broader authority or self-hosting requirements in [the phase checklist](https://git.erikinkinen.fi/erix/integration/issues/65). Verified documentation and CI follow-up — 22 September 2026: [Kernel documentation](https://git.erikinkinen.fi/erix/kernel/commit/d0d9e25b71664126c29727265f285df2f5ae7fea) and [Integration documentation](https://git.erikinkinen.fi/erix/integration/commit/c41bb92cd0ff5444c1680bee476a70072529fdb0) record the accepted native mapping, three-grant cleanup and ordinary exec-successor evidence. Every executable file is identical to the tested implementation; Markdown and diff checks pass. All three failed fixture attempts remain in [report 24](https://git.erikinkinen.fi/erix/kernel/issues/24), separately from the fixed [admission defect](https://git.erikinkinen.fi/erix/kernel/issues/23). The complete manual passes 45 tests and 2,431 pages with no final warnings. The final static inventory covers 3,180 authored code files below 1,000 lines, 259 exact Git pins and the existing direct missing_docs declarations; it does not establish full semantic authority closure. Original full Integration [1703](https://git.erikinkinen.fi/erix/integration/actions/runs/1703)/[1704](https://git.erikinkinen.fi/erix/integration/actions/runs/1704), source dff878dd3545c4751b3c05d37b2bdd5e21cce548, pass from six complete logs totalling 26,964,178 bytes and zero warnings. Their ext4 quota/links and FAT32 directory scenarios explicitly pass. Earlier timing failures remain retained and their causes are unestablished. Kernel [634](https://git.erikinkinen.fi/erix/kernel/actions/runs/634)/[635](https://git.erikinkinen.fi/erix/kernel/actions/runs/635) report cancelled, with runner context-cancellation messages and four complete logs. No cancellation request was issued during this work; the workflow declares no cancellation policy, and the initiating cause remains unestablished. These runs receive no CI acceptance credit. Current Kernel [636](https://git.erikinkinen.fi/erix/kernel/actions/runs/636)/[637](https://git.erikinkinen.fi/erix/kernel/actions/runs/637) and Docs [1007](https://git.erikinkinen.fi/erix/docs/actions/runs/1007)/[1008](https://git.erikinkinen.fi/erix/docs/actions/runs/1008) pass. Each pair has four complete logs: Kernel totals 773,796 bytes with zero warnings, and Docs totals 774,706 bytes with zero final warnings. Both manual builds retain their initial 35/1/0 LaTeX warning sequence through convergence. Integration 1717–1720 remains queued. The phase checklist remains at 15/460 accepted leaves, weighted 3.48%. Private hardware roots, complete authority cleanup, measured startup improvement, native external Rust/LLVM/runtime rebuilding and both complete EriX guest-build generations remain open.
erikinkinen 2026-09-22 01:33:21 +02:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
erix/kernel#23
No description provided.