Commit 7a70ab5
committed
Added the module user-mode entry, the only way a module reaches the kernel
A module runs in User mode and cannot execute kernel code or touch kernel
memory. When it calls a ThreadX service the call arrives here: SVC 1 raises
privilege, the dispatch function performs the service, SVC 2 drops back to User
mode, and the module continues. Everything the module is allowed to ask for is
decided inside _txm_module_manager_kernel_dispatch, in memory the module cannot
reach.
Derived from the Cortex-R4 module port rather than the Armv8-M one, which is the
right parent for this file specifically. Privilege on Armv8-M is a bit in CONTROL
and the transition rides an exception return; in AArch32 it is the processor mode,
and SVC is how a module asks to change it. The R4 sequence transfers directly
even though its MPU does not.
One improvement over the R4 version, and it is about isolation rather than
memory. That port aligns this function to 4 KB because PMSAv7 regions must be a
power of two in size and aligned to their own size, so the smallest region that
covers the entry without covering its neighbours is a page -- and whatever else
shares that page is then also executable by the module. A base and limit pair has
no such constraint. The function is 64-byte aligned, and the measured privileged
surface a module can execute is 24 bytes.
The kernel entry region's limit is taken from a symbol at the end of the function
rather than from its base. One granule covers 24 bytes so the base would work
today, but if the entry ever grows past 64 bytes, sizing from the base would
leave its tail outside the region and a module would fault on a call it is
entitled to make.
SVC 2 sits between the dispatch and every return path rather than on one of them.
Skipping it would return the module to its own code still privileged, which is
the entire protection gone, so it is unconditional.
The supervisor call vector that recognises SVC 1 and SVC 2 is the next piece and
does not exist yet.
Assisted-by: Claude Code (Opus 5) <noreply@anthropic.com>1 parent d734a67 commit 7a70ab5
2 files changed
Lines changed: 122 additions & 1 deletion
File tree
- ports_module/cortex_r52/gnu/module_manager/src
Lines changed: 13 additions & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
72 | 72 | | |
73 | 73 | | |
74 | 74 | | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
75 | 80 | | |
76 | 81 | | |
77 | 82 | | |
| |||
84 | 89 | | |
85 | 90 | | |
86 | 91 | | |
87 | | - | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
88 | 100 | | |
89 | 101 | | |
90 | 102 | | |
| |||
Lines changed: 109 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
0 commit comments