Skip to main content

mnemosyne_core/policy/
impls.rs

1//! Concrete ZST policy implementations.
2//!
3//! Each type is a Zero-Sized Type (ZST) — `size_of::<StandardPolicy>() == 0` —
4//! with all flags as `const bool` items that the compiler resolves at
5//! monomorphization. Compile-time assertions below verify the zero-cost
6//! contract for [`StandardPolicy`].
7
8use super::alloc_policy::AllocPolicy;
9use super::mitigations;
10use super::private;
11
12/// Zero-Sized Type (ZST) representing the standard allocation policy with
13/// maximum performance.
14///
15/// All flags are `false`; every policy-guarded branch is dead code and is
16/// eliminated at compile time. `StandardPolicy` allocations and frees pay no
17/// poisoning or zeroing cost.
18#[derive(Clone, Copy, Debug, Default, Eq, PartialEq)]
19pub struct StandardPolicy;
20
21impl private::Sealed for StandardPolicy {}
22impl AllocPolicy for StandardPolicy {
23    const ENABLE_POISONING: bool = false;
24    const ZERO_INITIALIZE: bool = false;
25    /// Keep 4 committed free segments warm for rapid free-then-allocate bursts.
26    const SEGMENT_POOL_WARM_THRESHOLD: usize = 4;
27    const POLICY_NAME: &'static str = "standard";
28    const MITIGATION_FLAGS: u32 = mitigations::NONE;
29}
30
31/// Zero-Sized Type (ZST) representing a secure allocation policy with memory
32/// poisoning and zero-initialization.
33#[derive(Clone, Copy, Debug, Default, Eq, PartialEq)]
34pub struct SecurePolicy;
35
36impl private::Sealed for SecurePolicy {}
37impl AllocPolicy for SecurePolicy {
38    const ENABLE_POISONING: bool = true;
39    const ZERO_INITIALIZE: bool = true;
40    const RANDOMIZE_ALLOCATION: bool = true;
41    const POLICY_NAME: &'static str = "secure";
42    const MITIGATION_FLAGS: u32 =
43        mitigations::POISONING | mitigations::ZERO_INIT | mitigations::RANDOMIZE_ALLOCATION;
44}
45
46/// Zero-Sized Type (ZST) representing a hardened allocation policy with memory
47/// poisoning, zero-initialization, and free-list XOR encryption.
48///
49/// The freelist encryption uses a triangular XOR key:
50/// `page_address ^ per_thread_seed ^ process_key`, where both seeds come from
51/// OS entropy via `std::collections::hash_map::RandomState`.
52#[derive(Clone, Copy, Debug, Default, Eq, PartialEq)]
53pub struct HardenedPolicy;
54
55impl private::Sealed for HardenedPolicy {}
56impl AllocPolicy for HardenedPolicy {
57    const ENABLE_POISONING: bool = true;
58    const ZERO_INITIALIZE: bool = true;
59    const ENABLE_FREE_LIST_ENCRYPTION: bool = true;
60    const RANDOMIZE_ALLOCATION: bool = true;
61    /// Page-waking hysteresis: a full page does not re-enter the active list
62    /// until at least `capacity / WAKE_DENOMINATOR` blocks have been freed.
63    /// This widens the temporal window between free and realloc, making
64    /// use-after-free and LIFO heap-spray exploits harder to land.
65    /// Zero-cost in `StandardPolicy` (branch eliminated at monomorphization).
66    const DELAY_PAGE_WAKE: bool = true;
67    const POLICY_NAME: &'static str = "hardened";
68    /// All currently implemented mitigations active.
69    const MITIGATION_FLAGS: u32 = mitigations::IMPLEMENTED;
70}
71
72// ── Compile-time zero-cost assertions ─────────────────────────────────────────
73//
74// These `const _: ()` blocks evaluate during compilation; a policy that
75// accidentally sets `ENABLE_POISONING = true` in `StandardPolicy` would fail
76// to build rather than silently incur a performance regression.
77
78const _: () = assert!(
79    !StandardPolicy::ENABLE_POISONING,
80    "StandardPolicy must have ENABLE_POISONING = false (zero-cost guarantee)"
81);
82const _: () = assert!(
83    !StandardPolicy::ZERO_INITIALIZE,
84    "StandardPolicy must have ZERO_INITIALIZE = false (zero-cost guarantee)"
85);
86const _: () = assert!(
87    !StandardPolicy::ENABLE_FREE_LIST_ENCRYPTION,
88    "StandardPolicy must have ENABLE_FREE_LIST_ENCRYPTION = false (zero-cost guarantee)"
89);
90const _: () = assert!(
91    core::mem::size_of::<StandardPolicy>() == 0,
92    "StandardPolicy must be a ZST"
93);
94const _: () = assert!(
95    core::mem::size_of::<SecurePolicy>() == 0,
96    "SecurePolicy must be a ZST"
97);
98const _: () = assert!(
99    core::mem::size_of::<HardenedPolicy>() == 0,
100    "HardenedPolicy must be a ZST"
101);
102const _: () = assert!(
103    StandardPolicy::MITIGATION_FLAGS == mitigations::NONE,
104    "StandardPolicy::MITIGATION_FLAGS must be NONE"
105);
106const _: () = assert!(
107    HardenedPolicy::MITIGATION_FLAGS == mitigations::IMPLEMENTED,
108    "HardenedPolicy::MITIGATION_FLAGS must equal mitigations::IMPLEMENTED"
109);