Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 7 additions & 2 deletions .github/workflows/dep_build_guests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -54,14 +54,15 @@ jobs:
run: |
sudo chown -R $(id -u):$(id -g) /opt/cargo || true

# cargo-hyperlight builds a custom sysroot for x86_64-hyperlight-none target.
# cargo-hyperlight builds a custom sysroot for the Hyperlight guest target.
# rust-cache cleans "anything not a dependency" from target dirs, removing the sysroot.
# We cache sysroot separately to avoid rebuilding it (~10s) on every run.
- name: Sysroot cache
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: |
src/tests/rust_guests/target/sysroot
src/tests/rust_guests/target-non-pie/sysroot
key: sysroot-linux-${{ inputs.arch }}-${{ inputs.config }}-${{ hashFiles('rust-toolchain.toml') }}

- name: Rust cache
Expand All @@ -87,6 +88,11 @@ jobs:
just build-rust-guests ${{ inputs.config }}
just move-rust-guests ${{ inputs.config }}

- name: Build non-PIE Rust guests
run: |
just build-rust-guests-non-pie ${{ inputs.config }}
just move-rust-guests-non-pie ${{ inputs.config }}

Comment on lines +91 to +95
- name: Build C guests
run: |
just build-c-guests ${{ inputs.config }}
Expand All @@ -108,4 +114,3 @@ jobs:
path: src/tests/c_guests/bin/${{ inputs.config }}/
retention-days: 1
if-no-files-found: error

1 change: 1 addition & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -454,6 +454,7 @@ $RECYCLE.BIN/

# Rust build artifacts
**/**target
**/**target-non-pie
libhyperlight_host.so
libhyperlight_host.d
hyperlight_host.dll
Expand Down
19 changes: 18 additions & 1 deletion Justfile
Original file line number Diff line number Diff line change
Expand Up @@ -50,7 +50,7 @@ build target=default-target:
{{ cargo-cmd }} build --profile={{ if target == "debug" { "dev" } else { target } }} {{ target-triple-flag }}

# build testing guest binaries
guests: build-and-move-rust-guests build-and-move-c-guests
guests: build-and-move-rust-guests build-and-move-rust-guests-non-pie build-and-move-c-guests

# Ensure the pinned cargo-hyperlight is installed. We compare the *actual*
# installed binary's reported version instead of relying on `cargo install`
Expand All @@ -75,6 +75,23 @@ build-rust-guests target=default-target features="": (ensure-cargo-hyperlight)
build-and-move-rust-guests: (build-rust-guests "debug") (move-rust-guests "debug") (build-rust-guests "release") (move-rust-guests "release")
build-and-move-c-guests: (build-c-guests "debug") (move-c-guests "debug") (build-c-guests "release") (move-c-guests "release")

# Build non-PIE variants of rust guests for testing ELF VA mapping.
# NOTE: non-PIE guests are x86_64-only; aarch64 is not yet supported.
# Phase 1 builds the sysroot without RUSTFLAGS (avoids RUSTFLAGS leaking
# into the sysroot wrapper build in cargo-hyperlight).
# Phase 2 uses plain cargo with --sysroot and non-PIE link flags.
build-rust-guests-non-pie target=default-target: (ensure-cargo-hyperlight)
cd src/tests/rust_guests/simpleguest && cargo hyperlight build --target-dir ../target-non-pie --profile={{ if target == "debug" { "dev" } else { target } }}
{{ if os() == "windows" { "$env:RUSTC_BOOTSTRAP=1; $env:RUSTFLAGS='--sysroot=' + (Resolve-Path src/tests/rust_guests/target-non-pie/sysroot).Path + ' -C relocation-model=static -C link-args=--no-pie -C link-args=--image-base=0x1000000 --cfg=hyperlight --check-cfg=cfg(hyperlight) -Clink-args=-eentrypoint';" } else { "" } }} cd src/tests/rust_guests/simpleguest && {{ if os() == "windows" { "" } else { "RUSTC_BOOTSTRAP=1 RUSTFLAGS=\"--sysroot=$(cd .. && pwd)/target-non-pie/sysroot -C relocation-model=static -C link-args=--no-pie -C link-args=--image-base=0x1000000 --cfg=hyperlight --check-cfg=cfg(hyperlight) -Clink-args=-eentrypoint\"" } }} cargo build --target {{ hyperlight-target }} --target-dir ../target-non-pie/build --profile={{ if target == "debug" { "dev" } else { target } }}

non_pie_guests_target := "src/tests/rust_guests/target-non-pie/build/" + hyperlight-target

@move-rust-guests-non-pie target=default-target:
{{ if os() == "windows" { "New-Item -ItemType Directory -Path " + rust_guests_bin_dir + "/" + target + "/non_pie -Force | Out-Null" } else { "mkdir -p " + rust_guests_bin_dir + "/" + target + "/non_pie" } }}
cp {{ non_pie_guests_target }}/{{ target }}/simpleguest {{ rust_guests_bin_dir }}/{{ target }}/non_pie/

build-and-move-rust-guests-non-pie: (build-rust-guests-non-pie "debug") (move-rust-guests-non-pie "debug") (build-rust-guests-non-pie "release") (move-rust-guests-non-pie "release")

clean: clean-rust

clean-rust:
Expand Down
15 changes: 5 additions & 10 deletions src/hyperlight_host/src/hypervisor/hyperlight_vm/x86_64.rs
Original file line number Diff line number Diff line change
Expand Up @@ -720,10 +720,9 @@ pub(super) mod debug {
.dbg_mem_access_fn
.try_lock()
.map_err(|_| ProcessDebugRequestError::TryLockError(file!(), line!()))?
.layout
.get_guest_code_address();
.code_virt_base;

Ok(DebugResponse::GetCodeSectionOffset(offset as u64))
Ok(DebugResponse::GetCodeSectionOffset(offset))
}
DebugMsg::ReadAddr(addr, len) => {
let mut data = vec![0u8; len];
Expand Down Expand Up @@ -930,7 +929,7 @@ mod tests {
use crate::hypervisor::regs::{CommonSegmentRegister, CommonTableRegister, MXCSR_DEFAULT};
use crate::hypervisor::virtual_machine::VirtualMachine;
use crate::mem::layout::SandboxMemoryLayout;
use crate::mem::memory_region::{GuestMemoryRegion, MemoryRegionFlags};
use crate::mem::memory_region::MemoryRegionFlags;
use crate::mem::mgr::{GuestPageTableBuffer, SandboxMemoryManager};
use crate::mem::ptr::RawPtr;
use crate::mem::shared_mem::{ExclusiveSharedMemory, ReadonlySharedMemory};
Expand Down Expand Up @@ -1494,16 +1493,12 @@ mod tests {
let pt_base_gpa = layout.get_pt_base_gpa();
let pt_buf = GuestPageTableBuffer::new(pt_base_gpa as usize);

for rgn in layout
.get_memory_regions_::<GuestMemoryRegion>(())
.unwrap()
.iter()
{
for rgn in layout.get_memory_regions().unwrap().iter() {
let readable = rgn.flags.contains(MemoryRegionFlags::READ);
let writable = rgn.flags.contains(MemoryRegionFlags::WRITE);
let executable = rgn.flags.contains(MemoryRegionFlags::EXECUTE);
let mapping = Mapping {
phys_base: rgn.guest_region.start as u64,
phys_base: rgn.host_region.start as u64,
virt_base: rgn.guest_region.start as u64,
len: rgn.guest_region.len() as u64,
kind: MappingKind::Basic(BasicMapping {
Expand Down
9 changes: 9 additions & 0 deletions src/hyperlight_host/src/mem/elf.rs
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,7 @@ limitations under the License.
#[cfg(feature = "mem_profile")]
use std::sync::Arc;

use goblin::elf::header::ET_DYN;
#[cfg(target_arch = "aarch64")]
use goblin::elf::reloc::{R_AARCH64_NONE, R_AARCH64_RELATIVE};
#[cfg(target_arch = "x86_64")]
Expand All @@ -42,6 +43,8 @@ pub(crate) struct ElfInfo {
shdrs: Vec<ResolvedSectionHeader>,
entry: u64,
relocs: Vec<Reloc>,
/// Whether this is a position-independent executable (ET_DYN).
is_pie: bool,
/// The hyperlight version string embedded by `hyperlight-guest-bin`, if
/// present. Used to detect version/ABI mismatches between guest and host.
guest_bin_version: Option<String>,
Expand Down Expand Up @@ -143,6 +146,7 @@ impl ElfInfo {
.collect(),
entry: elf.entry,
relocs,
is_pie: elf.header.e_type == ET_DYN,
guest_bin_version,
})
}
Expand All @@ -168,6 +172,11 @@ impl ElfInfo {
self.entry
}

/// Returns whether this is a position-independent executable (ET_DYN).
pub(crate) fn is_pie(&self) -> bool {
self.is_pie
}

/// Returns the hyperlight version string embedded in the guest binary, if
/// present. Used to detect version/ABI mismatches between guest and host.
pub(crate) fn guest_bin_version(&self) -> Option<&str> {
Expand Down
6 changes: 6 additions & 0 deletions src/hyperlight_host/src/mem/exe.rs
Original file line number Diff line number Diff line change
Expand Up @@ -89,6 +89,12 @@ impl ExeInfo {
ExeInfo::Elf(elf) => Offset::from(elf.entrypoint_va()),
}
}
/// Returns whether this is a position-independent executable (ET_DYN).
pub fn is_pie(&self) -> bool {
match self {
ExeInfo::Elf(elf) => elf.is_pie(),
}
}
/// Returns the base virtual address of the loaded binary (lowest PT_LOAD p_vaddr).
pub fn base_va(&self) -> u64 {
match self {
Expand Down
107 changes: 99 additions & 8 deletions src/hyperlight_host/src/mem/layout.rs
Original file line number Diff line number Diff line change
Expand Up @@ -66,10 +66,10 @@ use std::mem::size_of;
use hyperlight_common::mem::{HyperlightPEB, PAGE_SIZE_USIZE};
use tracing::{Span, instrument};

use super::memory_region::MemoryRegionType::{Code, Heap, InitData, Peb};
use super::memory_region::MemoryRegionType::{self, Code, Heap, InitData, Peb};
use super::memory_region::{
DEFAULT_GUEST_BLOB_MEM_FLAGS, MemoryRegion, MemoryRegion_, MemoryRegionFlags, MemoryRegionKind,
MemoryRegionVecBuilder,
DEFAULT_GUEST_BLOB_MEM_FLAGS, GuestMemoryRegion, MemoryRegion, MemoryRegion_,
MemoryRegionFlags, MemoryRegionVecBuilder,
};
#[cfg(readable_shared_mem)]
use super::shared_mem::HostSharedMemory;
Expand Down Expand Up @@ -469,11 +469,8 @@ impl SandboxMemoryLayout {

/// Returns the memory regions associated with this memory layout,
/// suitable for passing to a hypervisor for mapping into memory
pub(crate) fn get_memory_regions_<K: MemoryRegionKind>(
&self,
host_base: K::HostBaseType,
) -> Result<Vec<MemoryRegion_<K>>> {
let mut builder = MemoryRegionVecBuilder::new(Self::BASE_ADDRESS, host_base);
pub(crate) fn get_memory_regions(&self) -> Result<Vec<MemoryRegion_<GuestMemoryRegion>>> {
let mut builder = MemoryRegionVecBuilder::new(Self::BASE_ADDRESS, Self::BASE_ADDRESS);

// code
let peb_offset = builder.push_page_aligned(
Expand Down Expand Up @@ -555,6 +552,97 @@ impl SandboxMemoryLayout {
Ok(builder.build())
}

/// Compute the virtual base address for the code region, validate
/// that it does not overlap any other memory region, and return the
/// guest memory regions with the Code region's `guest_virt_addr`
/// already set to the computed virtual base.
///
/// For PIE binaries, a random page-aligned address is chosen within
/// 47-bit canonical user space (ASLR). For non-PIE binaries, the
/// code appears at the ELF's declared virtual address (`elf_base_va`).
///
/// In both cases the resulting virtual range is validated against all
/// non-Code memory regions to prevent overlap.
///
/// Returns `(code_virt_base, regions)`.
pub(crate) fn get_guest_regions_with_code_va(
&self,
is_pie: bool,
elf_base_va: u64,
loaded_size: u64,
) -> Result<(u64, Vec<MemoryRegion_<GuestMemoryRegion>>)> {
let code_size_pages = loaded_size.div_ceil(PAGE_SIZE_USIZE as u64);
let code_virt_base = if !is_pie {
elf_base_va
} else {
// Pick a random page-aligned address within 47-bit canonical user space.
// Lower bound: 0x1000000 (16 MiB, above all identity-mapped layout regions)
// Upper bound: accounts for code region size so it doesn't overflow
use rand::RngExt;
let mut rng = rand::rng();
let min_page = 0x1000_u64; // 0x1000 * PAGE_SIZE = 0x1000000
let max_page = 0x7_FFFF_FFFF_u64
.checked_sub(code_size_pages)
.ok_or_else(|| {
new_error!(
"PIE code region too large ({} pages) for ASLR randomization",
code_size_pages
)
})?;
let page_number = rng.random_range(min_page..max_page);
page_number
.checked_mul(PAGE_SIZE_USIZE as u64)
.ok_or_else(|| new_error!("ASLR page number overflow"))?
};

let mut regions = self.get_memory_regions()?;

// Verify the code mapping does not conflict with other mappings
// (both non-PIE with declared VA and PIE with randomized ASLR base).
let code_virt_end = code_virt_base.checked_add(loaded_size).ok_or_else(|| {
new_error!(
"Code mapping overflow: base {:#x} + size {:#x}",
code_virt_base,
loaded_size
)
})?;
for rgn in regions.iter() {
if rgn.region_type == MemoryRegionType::Code {
continue;
}
let rgn_start = rgn.guest_region.start as u64;
let rgn_end = rgn_start.saturating_add(rgn.guest_region.len() as u64);
if code_virt_base < rgn_end && rgn_start < code_virt_end {
return Err(new_error!(
"Code mapping [{:#x}, {:#x}) conflicts with {:?} region [{:#x}, {:#x})",
code_virt_base,
code_virt_end,
rgn.region_type,
rgn_start,
rgn_end,
));
}
}

// Override the Code region's GVA (guest_region) to code_virt_base.
// host_region retains the GPA from the builder.
for rgn in regions.iter_mut() {
if rgn.region_type == MemoryRegionType::Code {
let len = rgn.guest_region.len();
rgn.guest_region = code_virt_base as usize..(code_virt_base as usize + len);
}
}

tracing::debug!(
code_virt_base = format_args!("{:#x}", code_virt_base),
elf_base_va = format_args!("{:#x}", elf_base_va),
is_pie,
"code region virtual base address"
);

Ok((code_virt_base, regions))
}

#[instrument(err(Debug), skip_all, parent = Span::current(), level= "Trace")]
pub(crate) fn write_init_data(&self, out: &mut [u8], bytes: &[u8]) -> Result<()> {
out[self.init_data_offset()..self.init_data_offset() + self.init_data_size]
Expand Down Expand Up @@ -678,6 +766,9 @@ impl SandboxMemoryLayout {
}

/// Guest address of the code section in the sandbox.
/// Used by WHP (Windows) and mem_profile feature; not called on
/// minimal Linux feature sets, hence the allow.
#[allow(dead_code)]
pub(crate) fn get_guest_code_address(&self) -> usize {
Self::BASE_ADDRESS + self.guest_code_offset()
}
Expand Down
21 changes: 14 additions & 7 deletions src/hyperlight_host/src/mem/memory_region.rs
Original file line number Diff line number Diff line change
Expand Up @@ -282,20 +282,26 @@ impl MemoryRegionKind for HostGuestMemoryRegion {
pub(crate) struct GuestMemoryRegion {}

impl MemoryRegionKind for GuestMemoryRegion {
type HostBaseType = ();
type HostBaseType = usize;

fn add(_base: Self::HostBaseType, _size: usize) -> Self::HostBaseType {}
fn add(base: Self::HostBaseType, size: usize) -> Self::HostBaseType {
base + size
}
}

/// represents a single memory region inside the guest. All memory within a region has
/// the same memory permissions
#[derive(Debug, Clone, PartialEq, Eq, Hash)]
pub struct MemoryRegion_<K: MemoryRegionKind> {
/// the range of guest memory addresses
/// The range of guest addresses. For `GuestMemoryRegion` this is
/// the guest virtual address range (GVA). For `HostGuestMemoryRegion`
/// and `CrashDumpMemoryRegion` this is the guest physical address
/// range (GPA) or GVA depending on the variant.
pub guest_region: Range<usize>,
/// the range of host memory addresses
///
/// Note that Range<()> = () x () = ().
/// The range of host-side addresses. For `HostGuestMemoryRegion` this
/// is the host virtual address range (HVA). For `GuestMemoryRegion`
/// this is the guest physical address range (GPA). For
/// `CrashDumpMemoryRegion` this is the HVA.
pub host_region: Range<K::HostBaseType>,
/// memory access flags for the given region
pub flags: MemoryRegionFlags,
Expand Down Expand Up @@ -367,8 +373,9 @@ impl<K: MemoryRegionKind> MemoryRegionVecBuilder<K> {
// we know this is safe because we check if the regions are empty above
let last_region = self.regions.last().unwrap();
let host_end = <K as MemoryRegionKind>::add(last_region.host_region.end, size);
let guest_start = last_region.guest_region.end;
let new_region = MemoryRegion_ {
guest_region: last_region.guest_region.end..last_region.guest_region.end + size,
guest_region: guest_start..guest_start + size,
host_region: last_region.host_region.end..host_end,
flags,
region_type,
Expand Down
Loading
Loading