pub struct HardenedPolicy;Expand description
Zero-Sized Type (ZST) representing a hardened allocation policy with memory poisoning, zero-initialization, and free-list XOR encryption.
The freelist encryption uses a triangular XOR key:
page_address ^ per_thread_seed ^ process_key, where both seeds come from
OS entropy via std::collections::hash_map::RandomState.
Trait Implementations§
Source§impl AllocPolicy for HardenedPolicy
impl AllocPolicy for HardenedPolicy
Source§const DELAY_PAGE_WAKE: bool = true
const DELAY_PAGE_WAKE: bool = true
Page-waking hysteresis: a full page does not re-enter the active list
until at least capacity / WAKE_DENOMINATOR blocks have been freed.
This widens the temporal window between free and realloc, making
use-after-free and LIFO heap-spray exploits harder to land.
Zero-cost in StandardPolicy (branch eliminated at monomorphization).
Source§const MITIGATION_FLAGS: u32 = mitigations::IMPLEMENTED
const MITIGATION_FLAGS: u32 = mitigations::IMPLEMENTED
All currently implemented mitigations active.
Source§const ENABLE_POISONING: bool = true
const ENABLE_POISONING: bool = true
If true, write poison bytes to memory on allocation and deallocation to
detect heap corruption.
Source§const ZERO_INITIALIZE: bool = true
const ZERO_INITIALIZE: bool = true
If true, zero-initialize all memory allocations.
Source§const ENABLE_FREE_LIST_ENCRYPTION: bool = true
const ENABLE_FREE_LIST_ENCRYPTION: bool = true
If true, encrypt free list next pointers using the per-segment XOR key.
Source§const RANDOMIZE_ALLOCATION: bool = true
const RANDOMIZE_ALLOCATION: bool = true
If true, randomize the allocation order of blocks in a page.
Source§const POLICY_NAME: &'static str = "hardened"
const POLICY_NAME: &'static str = "hardened"
Human-readable name for this policy. Zero-cost — inlined by the compiler.
Source§const POISON_FREE_BYTE: u8 = 0xDE
const POISON_FREE_BYTE: u8 = 0xDE
Byte pattern to write into memory when it is freed.
Source§const POISON_ALLOC_BYTE: u8 = 0xAD
const POISON_ALLOC_BYTE: u8 = 0xAD
Byte pattern to write into memory when it is allocated.
Source§const WAKE_DENOMINATOR: u16 = 4
const WAKE_DENOMINATOR: u16 = 4
Denominator for the page-wake hysteresis.
Source§const SEGMENT_POOL_WARM_THRESHOLD: usize = 0
const SEGMENT_POOL_WARM_THRESHOLD: usize = 0
Minimum warm segments kept in the pool after a
purge_lazy call.Source§const GWP_SAMPLE_RATE: u32 = 0
const GWP_SAMPLE_RATE: u32 = 0
Probabilistic guard-page sampling rate (GWP-ASan hook).
0 disables. Inspired by snmalloc 0.7.2 gwp_asan.h.Source§const MAX_ALLOC_SIZE_LIMIT: usize = 0
const MAX_ALLOC_SIZE_LIMIT: usize = 0
Maximum allocation size this policy will serve without a panic/error. Read more
Source§const POLICY_FINGERPRINT: u64 = _
const POLICY_FINGERPRINT: u64 = _
Compile-time configuration fingerprint. Read more
Source§impl Clone for HardenedPolicy
impl Clone for HardenedPolicy
Source§fn clone(&self) -> HardenedPolicy
fn clone(&self) -> HardenedPolicy
Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
Performs copy-assignment from
source. Read moreimpl Copy for HardenedPolicy
Source§impl Debug for HardenedPolicy
impl Debug for HardenedPolicy
Source§impl Default for HardenedPolicy
impl Default for HardenedPolicy
Source§fn default() -> HardenedPolicy
fn default() -> HardenedPolicy
Returns the “default value” for a type. Read more
impl Eq for HardenedPolicy
Source§impl PartialEq for HardenedPolicy
impl PartialEq for HardenedPolicy
Source§impl PolicySlotSelection<CudaDeviceBackend> for HardenedPolicy
impl PolicySlotSelection<CudaDeviceBackend> for HardenedPolicy
Source§fn with_allocator<R>(
f: impl FnOnce(&mut ThreadAllocator<CudaDeviceBackend>) -> R,
) -> Option<R>
fn with_allocator<R>( f: impl FnOnce(&mut ThreadAllocator<CudaDeviceBackend>) -> R, ) -> Option<R>
Runs
f with access to the allocator cache selected for this policy.Source§unsafe fn with_allocator_unguarded<R>(
f: impl FnOnce(&mut ThreadAllocator<CudaDeviceBackend>) -> R,
) -> Option<R>
unsafe fn with_allocator_unguarded<R>( f: impl FnOnce(&mut ThreadAllocator<CudaDeviceBackend>) -> R, ) -> Option<R>
Runs
f with access to the selected policy cache without arming the
re-entrancy gate. Read moreSource§fn get_allocator_ptr() -> *mut c_void
fn get_allocator_ptr() -> *mut c_void
Returns the initialized allocator pointer for this policy’s TLS slot.
Source§fn get_allocator_ptr_raw() -> *mut c_void
fn get_allocator_ptr_raw() -> *mut c_void
Returns the raw allocator pointer for this policy’s TLS slot without
forcing lazy initialization.
Source§impl PolicySlotSelection<CudaGddrBackend> for HardenedPolicy
impl PolicySlotSelection<CudaGddrBackend> for HardenedPolicy
Source§fn with_allocator<R>(
f: impl FnOnce(&mut ThreadAllocator<CudaGddrBackend>) -> R,
) -> Option<R>
fn with_allocator<R>( f: impl FnOnce(&mut ThreadAllocator<CudaGddrBackend>) -> R, ) -> Option<R>
Runs
f with access to the allocator cache selected for this policy.Source§unsafe fn with_allocator_unguarded<R>(
f: impl FnOnce(&mut ThreadAllocator<CudaGddrBackend>) -> R,
) -> Option<R>
unsafe fn with_allocator_unguarded<R>( f: impl FnOnce(&mut ThreadAllocator<CudaGddrBackend>) -> R, ) -> Option<R>
Runs
f with access to the selected policy cache without arming the
re-entrancy gate. Read moreSource§fn get_allocator_ptr() -> *mut c_void
fn get_allocator_ptr() -> *mut c_void
Returns the initialized allocator pointer for this policy’s TLS slot.
Source§fn get_allocator_ptr_raw() -> *mut c_void
fn get_allocator_ptr_raw() -> *mut c_void
Returns the raw allocator pointer for this policy’s TLS slot without
forcing lazy initialization.
Source§impl PolicySlotSelection<CudaHbmBackend> for HardenedPolicy
impl PolicySlotSelection<CudaHbmBackend> for HardenedPolicy
Source§fn with_allocator<R>(
f: impl FnOnce(&mut ThreadAllocator<CudaHbmBackend>) -> R,
) -> Option<R>
fn with_allocator<R>( f: impl FnOnce(&mut ThreadAllocator<CudaHbmBackend>) -> R, ) -> Option<R>
Runs
f with access to the allocator cache selected for this policy.Source§unsafe fn with_allocator_unguarded<R>(
f: impl FnOnce(&mut ThreadAllocator<CudaHbmBackend>) -> R,
) -> Option<R>
unsafe fn with_allocator_unguarded<R>( f: impl FnOnce(&mut ThreadAllocator<CudaHbmBackend>) -> R, ) -> Option<R>
Runs
f with access to the selected policy cache without arming the
re-entrancy gate. Read moreSource§fn get_allocator_ptr() -> *mut c_void
fn get_allocator_ptr() -> *mut c_void
Returns the initialized allocator pointer for this policy’s TLS slot.
Source§fn get_allocator_ptr_raw() -> *mut c_void
fn get_allocator_ptr_raw() -> *mut c_void
Returns the raw allocator pointer for this policy’s TLS slot without
forcing lazy initialization.
Source§impl PolicySlotSelection<CudaHostPinnedBackend> for HardenedPolicy
impl PolicySlotSelection<CudaHostPinnedBackend> for HardenedPolicy
Source§fn with_allocator<R>(
f: impl FnOnce(&mut ThreadAllocator<CudaHostPinnedBackend>) -> R,
) -> Option<R>
fn with_allocator<R>( f: impl FnOnce(&mut ThreadAllocator<CudaHostPinnedBackend>) -> R, ) -> Option<R>
Runs
f with access to the allocator cache selected for this policy.Source§unsafe fn with_allocator_unguarded<R>(
f: impl FnOnce(&mut ThreadAllocator<CudaHostPinnedBackend>) -> R,
) -> Option<R>
unsafe fn with_allocator_unguarded<R>( f: impl FnOnce(&mut ThreadAllocator<CudaHostPinnedBackend>) -> R, ) -> Option<R>
Runs
f with access to the selected policy cache without arming the
re-entrancy gate. Read moreSource§fn get_allocator_ptr() -> *mut c_void
fn get_allocator_ptr() -> *mut c_void
Returns the initialized allocator pointer for this policy’s TLS slot.
Source§fn get_allocator_ptr_raw() -> *mut c_void
fn get_allocator_ptr_raw() -> *mut c_void
Returns the raw allocator pointer for this policy’s TLS slot without
forcing lazy initialization.
Source§impl PolicySlotSelection<CudaUnifiedBackend> for HardenedPolicy
impl PolicySlotSelection<CudaUnifiedBackend> for HardenedPolicy
Source§fn with_allocator<R>(
f: impl FnOnce(&mut ThreadAllocator<CudaUnifiedBackend>) -> R,
) -> Option<R>
fn with_allocator<R>( f: impl FnOnce(&mut ThreadAllocator<CudaUnifiedBackend>) -> R, ) -> Option<R>
Runs
f with access to the allocator cache selected for this policy.Source§unsafe fn with_allocator_unguarded<R>(
f: impl FnOnce(&mut ThreadAllocator<CudaUnifiedBackend>) -> R,
) -> Option<R>
unsafe fn with_allocator_unguarded<R>( f: impl FnOnce(&mut ThreadAllocator<CudaUnifiedBackend>) -> R, ) -> Option<R>
Runs
f with access to the selected policy cache without arming the
re-entrancy gate. Read moreSource§fn get_allocator_ptr() -> *mut c_void
fn get_allocator_ptr() -> *mut c_void
Returns the initialized allocator pointer for this policy’s TLS slot.
Source§fn get_allocator_ptr_raw() -> *mut c_void
fn get_allocator_ptr_raw() -> *mut c_void
Returns the raw allocator pointer for this policy’s TLS slot without
forcing lazy initialization.
Source§impl PolicySlotSelection<MemoryBackendWrapper> for HardenedPolicy
impl PolicySlotSelection<MemoryBackendWrapper> for HardenedPolicy
Source§fn with_allocator<R>(
f: impl FnOnce(&mut ThreadAllocator<MemoryBackendWrapper>) -> R,
) -> Option<R>
fn with_allocator<R>( f: impl FnOnce(&mut ThreadAllocator<MemoryBackendWrapper>) -> R, ) -> Option<R>
Runs
f with access to the allocator cache selected for this policy.Source§unsafe fn with_allocator_unguarded<R>(
f: impl FnOnce(&mut ThreadAllocator<MemoryBackendWrapper>) -> R,
) -> Option<R>
unsafe fn with_allocator_unguarded<R>( f: impl FnOnce(&mut ThreadAllocator<MemoryBackendWrapper>) -> R, ) -> Option<R>
Runs
f with access to the selected policy cache without arming the
re-entrancy gate. Read moreSource§fn get_allocator_ptr() -> *mut c_void
fn get_allocator_ptr() -> *mut c_void
Returns the initialized allocator pointer for this policy’s TLS slot.
Source§fn get_allocator_ptr_raw() -> *mut c_void
fn get_allocator_ptr_raw() -> *mut c_void
Returns the raw allocator pointer for this policy’s TLS slot without
forcing lazy initialization.
impl StructuralPartialEq for HardenedPolicy
Auto Trait Implementations§
impl Freeze for HardenedPolicy
impl RefUnwindSafe for HardenedPolicy
impl Send for HardenedPolicy
impl Sync for HardenedPolicy
impl Unpin for HardenedPolicy
impl UnsafeUnpin for HardenedPolicy
impl UnwindSafe for HardenedPolicy
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more