mirror of
https://github.com/netbirdio/gvisor.git
synced 2026-05-22 17:12:49 -07:00
The systrap platform like the ptrace platform uses stub processes to manage the user address space. The difference is how they intercept system calls and other events like memory faults, exceptions, etc. In case of systrap, all events that have to be handled by the Sentry trigger signals that are handled by a custom signal handler installed on stub processes. The signal handler switches control to the Sentry. Here are a few other optimizations: * On x86, system calls can be replaced with a function call to remove overhead of signals. * For fast interactions of sentry and stub processes, futex wait/wake can be a bottle neck, so we use a polling mode. The platform is launched for the purpose of testing and gathering initial feedback. It is not yet ready for use in production. PiperOrigin-RevId: 511650064
50 lines
2.3 KiB
Go
50 lines
2.3 KiB
Go
// Copyright 2021 The gVisor Authors.
|
|
//
|
|
// Licensed under the Apache License, Version 2.0 (the "License");
|
|
// you may not use this file except in compliance with the License.
|
|
// You may obtain a copy of the License at
|
|
//
|
|
// http://www.apache.org/licenses/LICENSE-2.0
|
|
//
|
|
// Unless required by applicable law or agreed to in writing, software
|
|
// distributed under the License is distributed on an "AS IS" BASIS,
|
|
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
// See the License for the specific language governing permissions and
|
|
// limitations under the License.
|
|
|
|
// Package usertrap implements the library to replace syscall instructions with
|
|
// function calls.
|
|
//
|
|
// The most often used pattern of performing a system call is a sequence of two
|
|
// instruction: mov sysno, %eax; syscall. The size of the mov instruction is 5
|
|
// bytes and the size of the syscall instruction is 2 bytes. These two
|
|
// instruction can be replaced with a single jmp instruction with an absolute
|
|
// address below 2 gigabytes.
|
|
//
|
|
// Here is a few tricks:
|
|
// - The GS register is used to access a per-thread memory.
|
|
// - The syscall instruction is replaced with the "jmp *%ds:offset" instruction.
|
|
// On x86_64, ds is always zero. offset is a 32-bit signed integer. This
|
|
// means that a service mapping for a table with syscall trampolines has to
|
|
// be mapped below 2GB.
|
|
// - We can't touch a process stack, so we have to use the jmp instruction
|
|
// instead of callq and generate a new function call for each replaced
|
|
// instruction. Each trampoline contains a syscall number and an return
|
|
// address.
|
|
// - The address for the syscall table is set so that the syscall instruction
|
|
// is replaced on an invalid instruction. This allows us to handle races
|
|
// when two threads are executing the same syscall concurrently. And this
|
|
// allows us to restart a syscall if it has been interrupted by a signal.
|
|
//
|
|
// +checkalignedignore
|
|
package usertrap
|
|
|
|
import "fmt"
|
|
|
|
var (
|
|
// ErrFaultRestart indicates that the current stub thread has to be restarted.
|
|
ErrFaultRestart = fmt.Errorf("need to restart stub thread")
|
|
// ErrFaultSyscall indicates that the current fault has to be handled as a system call.
|
|
ErrFaultSyscall = fmt.Errorf("need to handle as syscall")
|
|
)
|