Skip to content

vmem: Add function for modifying mappings in-place - #1874

Merged
syntactically merged 1 commit into
mainfrom
lm/modify-mappings
Oct 2, 2026
Merged

syntactically merged 1 commit into
mainfrom
lm/modify-mappings

Conversation

@syntactically

Copy link
Copy Markdown
Member

This is useful for things like changing the permissions on an existing mapping.

@syntactically
syntactically added this pull request to stack #1875 October 2, 2026 10:51
@syntactically
syntactically requested a review from danbugs as a code owner October 2, 2026 10:51
@syntactically syntactically added the kind/enhancement For PRs adding features, improving functionality, docs, tests, etc. label Oct 2, 2026
@syntactically syntactically added the ready-for-review PR is ready for (re-)review label Oct 2, 2026
@hyperlight-gh-bot

This comment has been minimized.

This is useful for things like changing the permissions on an existing
mapping.

Signed-off-by: Lucy Menon <168595099+syntactically@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 2, 2026 12:29

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Both implementations allocate page tables for unmapped holes, risking guest scratch exhaustion.

Review effort: Balanced
Findings: 2 Medium severity · 3 Low severity

Open (5)
What changed in this PR

Adds in-place page-table mapping updates for guest memory permissions.

Changes:

  • Exposes modify_mapping through common and guest paging APIs.
  • Implements mapping updates for amd64 and AArch64.
  • Reuses AArch64 descriptor decoding.
File Description
src/​hyperlight_guest_bin/​src/​paging.rs Re-exports the guest API.
src/​hyperlight_guest_bin/​src/​arch/​amd64/​paging.rs Adds the amd64 wrapper.
src/​hyperlight_guest_bin/​src/​arch/​aarch64/​paging.rs Adds the AArch64 wrapper.
src/​hyperlight_common/​src/​vmem.rs Documents and exports the common API.
src/​hyperlight_common/​src/​arch/​amd64/​vmem.rs Implements amd64 updates.
src/​hyperlight_common/​src/​arch/​aarch64/​vmem.rs Implements AArch64 updates and shares descriptor decoding.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/hyperlight_common/src/arch/aarch64/vmem.rs
Comment thread src/hyperlight_common/src/arch/amd64/vmem.rs
Comment thread src/hyperlight_common/src/vmem.rs
Comment thread src/hyperlight_guest_bin/src/arch/aarch64/paging.rs
Comment thread src/hyperlight_guest_bin/src/arch/amd64/paging.rs
@hyperlight-gh-bot

Copy link
Copy Markdown

Benchmark Results

Measured commit: 33a6193dc8a7
Baseline commit: 43cf3539bd10

kvm / amd (Linux) (➖ stable)

No benchmark improved or regressed.

Benchmark Results

function_call_codec

encode_control decode_vec_bytes_copy
byte_chunks 787.20 ns (➖ 1.02x slower)
vec_bytes 581.89 ns (➖ 1.00x faster)
373.94 µs (➖ 1.00x faster)

payload_allocation

slot_pool_segmented
262144 530.98 ns (➖ 1.01x faster)
65536 175.80 ns (➖ 1.45x slower)

sandboxes

create_initialized_and_drop
medium 84.35 ms (➖ 1.06x slower)

slot_pool

alloc_dealloc_1500 alloc_dealloc_4096 alloc_dealloc_128
7.83 ns (➖ 1.03x slower) 8.21 ns (➖ 1.04x slower) 8.04 ns (➖ 1.03x slower)

snapshot_files

load_snapshot_unverified
small 93.00 µs (➖ 1.03x slower)

virtq_readonly

slot_pool_segmented_fragmented slot_pool_segmented
262144 7.46 µs (➖ 1.03x slower) 7.40 µs (➖ 1.01x faster)
65536 2.10 µs (➖ 1.01x slower) 2.01 µs (➖ 1.03x slower)

virtq_readwrite

slot_pool_segmented_fragmented slot_pool_segmented
65536 6.58 µs (➖ 1.05x slower) 6.45 µs (➖ 1.03x slower)
8192 1.11 µs (➖ 1.10x slower) 1.07 µs (➖ 1.03x slower)
262144 28.59 µs (➖ 1.07x slower)
kvm / intel (Linux) (➖ stable)

No benchmark improved or regressed.

Benchmark Results

function_call_codec

encode_control decode_vec_bytes_copy
byte_chunks 786.67 ns (➖ 1.05x slower)
vec_bytes 600.21 ns (➖ 1.10x slower)
747.82 µs (➖ 1.08x slower)

payload_allocation

slot_pool_segmented
262144 608.87 ns (➖ 1.06x slower)
65536 164.28 ns (➖ 1.07x slower)

sandboxes

create_initialized_and_drop
medium 81.43 ms (➖ 1.03x slower)

slot_pool

alloc_dealloc_1500 alloc_dealloc_4096 alloc_dealloc_128
8.28 ns (➖ 1.10x slower) 8.28 ns (➖ 1.11x slower) 8.28 ns (➖ 1.10x slower)

snapshot_files

load_snapshot_unverified
small 51.88 µs (➖ 1.06x slower)

virtq_readonly

slot_pool_segmented_fragmented slot_pool_segmented
262144 8.93 µs (➖ 1.04x slower) 8.90 µs (➖ 1.04x slower)
65536 2.50 µs (➖ 1.04x slower) 2.61 µs (➖ 1.09x slower)

virtq_readwrite

slot_pool_segmented_fragmented slot_pool_segmented
65536 8.35 µs (➖ 1.06x slower) 8.35 µs (➖ 1.05x slower)
8192 874.64 ns (➖ 1.04x slower) 836.07 ns (➖ 1.06x slower)
262144 35.56 µs (➖ 1.06x slower)
mshv3 / amd (Linux) (➖ stable)

No benchmark improved or regressed.

Benchmark Results

function_call_codec

encode_control decode_vec_bytes_copy
byte_chunks 951.04 ns (➖ 1.00x faster)
vec_bytes 708.87 ns (➖ 1.00x faster)
271.00 µs (➖ 1.31x faster)

payload_allocation

slot_pool_segmented
262144 721.78 ns (➖ 1.02x faster)
65536 192.08 ns (➖ 1.01x faster)

sandboxes

create_initialized_and_drop
medium 58.06 ms (➖ 1.04x slower)

slot_pool

alloc_dealloc_1500 alloc_dealloc_4096 alloc_dealloc_128
9.75 ns (➖ 1.00x faster) 9.74 ns (➖ 1.00x slower) 10.12 ns (➖ 1.01x faster)

snapshot_files

load_snapshot_unverified
small 85.27 µs (➖ 1.02x slower)

virtq_readonly

slot_pool_segmented_fragmented slot_pool_segmented
262144 10.13 µs (➖ 1.00x slower) 8.79 µs (➖ 1.02x faster)
65536 2.24 µs (➖ 1.01x slower) 2.48 µs (➖ 1.01x faster)

virtq_readwrite

slot_pool_segmented_fragmented slot_pool_segmented
65536 8.41 µs (➖ 1.03x slower) 8.48 µs (➖ 1.05x slower)
8192 1.27 µs (➖ 1.00x slower) 1.32 µs (➖ 1.01x faster)
262144 36.51 µs (➖ 1.00x slower)
mshv3 / intel (Linux) (➖ stable)

No benchmark improved or regressed.

Benchmark Results

function_call_codec

encode_control decode_vec_bytes_copy
byte_chunks 937.22 ns (➖ 1.00x slower)
vec_bytes 688.52 ns (➖ 1.02x slower)
991.64 µs (➖ 1.44x slower)

payload_allocation

slot_pool_segmented
262144 635.10 ns (➖ 1.01x faster)
65536 166.30 ns (➖ 1.01x slower)

sandboxes

create_initialized_and_drop
medium 68.48 ms (➖ 1.10x slower)

slot_pool

alloc_dealloc_1500 alloc_dealloc_4096 alloc_dealloc_128
9.31 ns (➖ 1.03x slower) 8.79 ns (➖ 1.01x slower) 8.86 ns (➖ 1.01x slower)

snapshot_files

load_snapshot_unverified
small 47.51 µs (➖ 1.09x slower)

virtq_readonly

slot_pool_segmented_fragmented slot_pool_segmented
262144 7.80 µs (➖ 1.01x slower) 7.78 µs (➖ 1.03x faster)
65536 2.23 µs (➖ 1.00x faster) 2.27 µs (➖ 1.00x faster)

virtq_readwrite

slot_pool_segmented_fragmented slot_pool_segmented
65536 7.57 µs (➖ 1.01x slower) 7.62 µs (➖ 1.01x slower)
8192 877.69 ns (➖ 1.03x slower) 892.35 ns (➖ 1.01x slower)
262144 37.77 µs (➖ 1.00x faster)
hyperv-ws2025 / amd (Windows) (➖ stable)

No benchmark improved or regressed.

Benchmark Results

function_call_codec

encode_control decode_vec_bytes_copy
byte_chunks 1.16 µs (➖ 1.05x slower)
vec_bytes 808.86 ns (➖ 1.20x faster)
2.16 ms (➖ 1.16x faster)

payload_allocation

slot_pool_segmented
262144 787.76 ns (➖ 1.01x faster)
65536 230.98 ns (➖ 1.01x slower)

sandboxes

create_initialized_and_drop
medium 86.79 ms (➖ 1.27x faster)

slot_pool

alloc_dealloc_1500 alloc_dealloc_4096 alloc_dealloc_128
9.97 ns (➖ 1.39x faster) 10.25 ns (➖ 1.03x faster) 10.14 ns (➖ 1.04x faster)

snapshot_files

load_snapshot_unverified
small 701.38 µs (➖ 1.13x faster)

virtq_readonly

slot_pool_segmented_fragmented slot_pool_segmented
262144 9.14 µs (➖ 1.05x slower) 9.24 µs (➖ 1.01x faster)
65536 2.40 µs (➖ 1.06x faster) 2.38 µs (➖ 1.13x faster)

virtq_readwrite

slot_pool_segmented_fragmented slot_pool_segmented
65536 9.02 µs (➖ 1.05x slower) 8.64 µs (➖ 1.01x faster)
8192 1.31 µs (➖ 1.09x faster) 1.33 µs (➖ 1.06x faster)
262144 45.83 µs (➖ 1.18x slower)
hyperv-ws2025 / intel (Windows) (➖ stable)

No benchmark improved or regressed.

Benchmark Results

function_call_codec

encode_control decode_vec_bytes_copy
byte_chunks 1.21 µs (➖ 1.00x faster)
vec_bytes 801.37 ns (➖ 1.04x slower)
3.05 ms (➖ 1.02x faster)

payload_allocation

slot_pool_segmented
262144 755.07 ns (➖ 1.02x slower)
65536 211.61 ns (➖ 1.01x slower)

sandboxes

create_initialized_and_drop
medium 109.58 ms (➖ 1.10x faster)

slot_pool

alloc_dealloc_1500 alloc_dealloc_4096 alloc_dealloc_128
10.20 ns (➖ 1.03x slower) 10.57 ns (➖ 1.05x slower) 10.89 ns (➖ 1.02x slower)

snapshot_files

load_snapshot_unverified
small 602.67 µs (➖ 1.02x faster)

virtq_readonly

slot_pool_segmented_fragmented slot_pool_segmented
262144 7.78 µs (➖ 1.02x slower) 7.70 µs (➖ 1.01x faster)
65536 2.33 µs (➖ 1.03x slower) 2.31 µs (➖ 1.00x faster)

virtq_readwrite

slot_pool_segmented_fragmented slot_pool_segmented
65536 8.62 µs (➖ 1.04x slower) 8.47 µs (➖ 1.00x faster)
8192 1.15 µs (➖ 1.09x faster) 1.22 µs (➖ 1.09x slower)
262144 60.27 µs (➖ 1.40x slower)

Reported by cargo ci bench-report --candidate run:37007006191 --baseline run:36945564806 --config-file bench_report.toml.

Base automatically changed from lm/zero-init-rgns to main October 2, 2026 14:55
@syntactically
syntactically merged commit 33a6193 into main Oct 2, 2026
72 of 78 checks passed
@syntactically
syntactically deleted the lm/modify-mappings branch October 2, 2026 15:45
@github-actions github-actions Bot removed the ready-for-review PR is ready for (re-)review label Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

kind/enhancement For PRs adding features, improving functionality, docs, tests, etc.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants