memfd-runner
A minimal Linux library for executing in-memory ELF files using memfd_create and execve.
Overview
memfd-runner provides a simple interface to load and execute ELF binaries directly from memory without writing them to disk. It uses Linux's memfd_create system call to create an anonymous file in memory, writes the ELF data to it, then executes it via the /proc/self/fd/ interface.
Features
- Minimal - <400 lines of code, 1 dependency (syscaller)
- Two execution modes - fork child process or replace current process
no_std- works in embedded and kernel environments
Platform Support
- Linux only - requires
memfd_createsystem call (Linux 3.17+) - x86_64 - tested on x86_64 architecture
Installation
Or add this to your Cargo.toml:
[]
= "0.1.1"
Quick Start
Simple Execution (Fork Mode)
use run;
// Read an ELF binary
let elf_bytes = read.unwrap;
// Execute it and get the exit code
let exit_code = run.unwrap;
println!;
Replace Current Process
use ;
let elf_bytes = read.unwrap;
let options = new.with_replace;
// This will replace the current process - does not return on success
run_with_options.unwrap;
Error Handling
use ;
let invalid_data = b"not an elf file";
match run
API Reference
Functions
-
run<B: AsRef<[u8]>>(bytes: B) -> Result<i32, RunError>- Execute ELF bytes in fork mode, returns child exit code
-
run_with_options<B: AsRef<[u8]>>(bytes: B, options: RunOptions) -> Result<i32, RunError>- Execute ELF bytes with custom options
Types
-
RunOptions- Configuration for executionnew()- Create default options (fork mode)with_replace(bool)- Set replace mode (true = replace process, false = fork child)
-
RunError- Error types with contextFdCreationFailed(i32)- Failed to create memory file descriptorBytesNotWritten(usize, usize)- Write operation failed (written, expected)ExecError(i32)- execve system call failedForkError(i32)- fork system call failedWaitError(i32)- wait4 system call failedInvalidElfFormat- ELF validation failed
How It Works
- Create Memory FD: Uses
memfd_create()to create an anonymous file in memory - Write Data: Writes the ELF bytes to the memory file descriptor
- Execute: Uses
execve()with/proc/self/fd/<fd>path to execute the in-memory file - Wait for Child: In fork mode, waits for child process and returns exit code
⚠️ Limitations: Very basic ELF validation only - complex validation should be done by caller
Examples
For complete usage examples, see the documentation at docs.rs/memfd-runner.
Development
Building
Testing
Linting
Contributing
- Fork the repository
- Create a feature branch
- Make your changes
- Add tests if applicable
- Submit a pull request
License
This project is licensed under the MIT License - see the LICENSE file for details.
Changelog
0.1.1
- Fixed dependency issues
- Updated documentation
- Ready for crates.io publication
0.1.0
- Initial release
- Basic memfd_create + execve functionality
- Fork and replace execution modes
- ELF validation
- Comprehensive error handling