hyperlight-dev / hyperlight-dev/hyperlight-wasm

Implement mprotect for wasmtime

Open
#113 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

area/security lifecycle/confirmed
Dominant language
Rust
Stars
728
Forks
39
Avg merge
2d 6h
Merged PRs (30d)
23

Description

Currently, we don't actually make the wasmtime guard regions into proper guard regions: reads/writes to/from them won't actually fault. This can probably be used to escape from wasmtime (but not to escape from the guest, which is the real security boundary), so we should fix this as soon as possible.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No file, test, or entry point is named. Start by locating the Wasmtime guard-region allocation and memory-protection path, then determine how mprotect should be applied. Done means reads and writes to the guard regions fault as intended, with coverage for the protected behavior.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust, wasm
Domain
operating-systems, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.