Skip to content

Refactor: Use physical pointer abstraction in LVBS - #817

Merged
Sangho Lee (sangho2) merged 25 commits into
mainfrom
sanghle/lvbs/vmap_copy
Jul 11, 2026
Merged

Refactor: Use physical pointer abstraction in LVBS#817
Sangho Lee (sangho2) merged 25 commits into
mainfrom
sanghle/lvbs/vmap_copy

Conversation

@sangho2

@sangho2Sangho Lee (sangho2) commented Apr 28, 2026

Copy link
Copy Markdown
Contributor

This PR lets the LVBS platform (i.e., HEKI/HVCI) use physical pointer abstraction to access VTL0 memory. This is equivalent to the OP-TEE shim's normal-world memory access such that it is not only safer than the legacy VTL0 memory copy functions (i.e., copy_(slice_)(from|to)_vtl0_phys) but also supporting virtually contiguous access of non-contiguous physical page frames.

@sangho2Sangho Lee (sangho2) added the must-not-merge:prototype An experimental/proof-of-concept PR that must not be merged. label Apr 28, 2026
@sangho2
Sangho Lee (sangho2)force-pushed the sanghle/lvbs/vmap_copy branch 2 times, most recently from 29c61b5 to e42c3a0CompareMay 1, 2026 15:51
@sangho2Sangho Lee (sangho2) changed the title [DRAFT] Use physical pointer abstraction in HVCI/HEKIUse physical pointer abstraction in HVCI/HEKIMay 1, 2026
@sangho2Sangho Lee (sangho2) changed the title Use physical pointer abstraction in HVCI/HEKIUse safe physical pointer abstraction in HVCI/HEKIMay 1, 2026
@sangho2Sangho Lee (sangho2) removed the must-not-merge:prototype An experimental/proof-of-concept PR that must not be merged. label May 1, 2026
@sangho2
Sangho Lee (sangho2) marked this pull request as ready for review May 1, 2026 20:11
@sangho2Sangho Lee (sangho2) added must-not-merge:prototype An experimental/proof-of-concept PR that must not be merged. and removed must-not-merge:prototype An experimental/proof-of-concept PR that must not be merged. labels May 1, 2026
@sangho2Sangho Lee (sangho2) changed the title Use safe physical pointer abstraction in HVCI/HEKIUse physical pointer abstraction in HVCI/HEKIMay 1, 2026
@sangho2Sangho Lee (sangho2) changed the title Use physical pointer abstraction in HVCI/HEKIUse physical pointer abstraction in LVBSMay 15, 2026
Comment threadlitebox_common_linux/src/physical_pointers.rs Outdated
Comment threadlitebox_platform_lvbs/src/mshv/vsm.rs
@sangho2Sangho Lee (sangho2) added must-not-merge:undergoing-restructuring Known deeper set of changes are happening on this PR before it is mergeable again and removed must-not-merge:undergoing-restructuring Known deeper set of changes are happening on this PR before it is mergeable again labels May 15, 2026
@sangho2
Sangho Lee (sangho2)force-pushed the sanghle/lvbs/vmap_copy branch 2 times, most recently from c6fd071 to 24e1d87CompareMay 21, 2026 20:58

@wdcuiWeidong Cui (wdcui) left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. I left some comments. Thanks!

Comment threadlitebox_common_linux/src/physical_pointers.rs Outdated
Comment threadlitebox_platform_lvbs/src/mshv/ringbuffer.rs Outdated
Comment threadlitebox_platform_lvbs/src/mshv/vsm.rs Outdated
@sangho2Sangho Lee (sangho2) added the must-not-merge:undergoing-restructuring Known deeper set of changes are happening on this PR before it is mergeable again label Jun 15, 2026

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I took a pass over the entirety of physical_pointers.rs, not just the diff of this PR. In summary, I think this is close to a neat and (in the future) sound abstraction with rich pointer semantics over dynamically mapped physical memory.

Happy to discuss my comments below, I'll go over the remaining changes soon. I don't think any of these is critical to be addressed in this PR, instead I'm happy to implement the changes in a follow-up PR!

Comment threadlitebox_common_linux/src/physical_pointers.rs
Comment threadlitebox_common_linux/src/physical_pointers.rs Outdated
Comment threadlitebox_common_linux/src/physical_pointers.rs Outdated
Comment threadlitebox_common_linux/src/physical_pointers.rs
Comment threadlitebox_common_linux/src/physical_pointers.rs
Comment threadlitebox_common_linux/src/physical_pointers.rs
Comment threadlitebox_common_linux/src/physical_pointers.rs
Comment threadlitebox_common_linux/src/physical_pointers.rs
Comment threadlitebox_common_linux/src/physical_pointers.rs Outdated

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the rest of the PR. I realize some of my feedback might be obsolete due to #824, so I'll check that out next. Should I create a PR to address the left-over comments targeting this same sanghle/lvbs/vmap_copy branch?

Comment threadlitebox_platform_lvbs/src/mshv/ringbuffer.rs
Comment threadlitebox_platform_lvbs/src/mshv/ringbuffer.rs
Comment threadlitebox_common_linux/src/vmap.rs Outdated
Comment threadlitebox_common_linux/src/vmap.rs Outdated
Comment threadlitebox_platform_lvbs/src/mshv/vsm.rs
Comment threadlitebox_platform_lvbs/src/lib.rs Outdated
Comment threadlitebox_shim_optee/src/lib.rs Outdated
@sangho2Sangho Lee (sangho2) removed the must-not-merge:undergoing-restructuring Known deeper set of changes are happening on this PR before it is mergeable again label Jun 26, 2026
@github-actions

Copy link
Copy Markdown

🤖 SemverChecks 🤖 ⚠️ Potential breaking API changes detected ⚠️

Click for details
--- failure enum_variant_missing: pub enum variant removed or renamed ---
Description:
A publicly-visible enum has at least one variant that is no longer available under its prior name. It may have been renamed or removed entirely.
ref: https://doc.rust-lang.org/cargo/reference/semver.html#item-remove
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/enum_variant_missing.ron
Failed in:
variant PhysPointerError::UnalignedPhysicalAddress, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_common_linux/src/vmap.rs:150
variant PhysPointerError::UnalignedOffset, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_common_linux/src/vmap.rs:152
variant PhysPointerError::NoMappingInfo, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_common_linux/src/vmap.rs:166
--- failure struct_missing: pub struct removed or renamed ---
Description:
A publicly-visible struct cannot be imported by its prior path. A `pub use` may have been removed, or the struct itself may have been renamed or removed entirely.
ref: https://doc.rust-lang.org/cargo/reference/semver.html#item-remove
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/struct_missing.ron
Failed in:
struct litebox_common_linux::vmap::PhysPageMapInfo, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_common_linux/src/vmap.rs:95
--- failure trait_associated_type_added: non-sealed public trait added associated type without default value ---
Description:
A non-sealed trait has gained an associated type without a default value, which breaks downstream implementations of the trait
ref: https://doc.rust-lang.org/cargo/reference/semver.html#trait-new-item-no-default
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/trait_associated_type_added.ron
Failed in:
trait associated type litebox_common_linux::vmap::VmapManager::MapInfo in file /home/runner/work/litebox/litebox/litebox_common_linux/src/vmap.rs:22
--- failure trait_method_default_impl_removed: pub trait default method impl removed ---
Description:
A method's default impl in an unsealed trait has been removed, breaking trait implementations that relied on that default
ref: https://doc.rust-lang.org/book/ch10-02-traits.html#default-implementations
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/trait_method_default_impl_removed.ron
Failed in:
trait method litebox_common_linux::vmap::VmapManager::validate_unowned in file /home/runner/work/litebox/litebox/litebox_common_linux/src/vmap.rs:79
trait method litebox_common_linux::vmap::VmapManager::protect in file /home/runner/work/litebox/litebox/litebox_common_linux/src/vmap.rs:96
--- failure trait_unsafe_added: pub trait became unsafe ---
Description:
A publicly-visible trait became `unsafe`, so implementing it now requires an `unsafe impl` block.
ref: https://doc.rust-lang.org/book/ch19-01-unsafe-rust.html#implementing-an-unsafe-trait
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/trait_unsafe_added.ron
Failed in:
trait litebox_common_linux::vmap::VmapManager in file /home/runner/work/litebox/litebox/litebox_common_linux/src/vmap.rs:19
--- failure feature_missing: package feature removed or renamed ---
Description:
A feature has been removed from this package's Cargo.toml. This will break downstream crates which enable that feature.
ref: https://doc.rust-lang.org/cargo/reference/semver.html#cargo-feature-remove
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/feature_missing.ron
Failed in:
feature optee_syscall in the package's Cargo.toml
--- failure inherent_method_missing: pub method removed or renamed ---
Description:
A publicly-visible method or associated fn is no longer available under its prior name. It may have been renamed or removed entirely.
ref: https://doc.rust-lang.org/cargo/reference/semver.html#item-remove
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/inherent_method_missing.ron
Failed in:
LinuxKernel::copy_from_vtl0_phys, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_platform_lvbs/src/lib.rs:725
LinuxKernel::copy_to_vtl0_phys, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_platform_lvbs/src/lib.rs:765
LinuxKernel::copy_slice_to_vtl0_phys, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_platform_lvbs/src/lib.rs:800
LinuxKernel::copy_slice_from_vtl0_phys, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_platform_lvbs/src/lib.rs:835
--- failure module_missing: pub module removed or renamed ---
Description:
A publicly-visible module cannot be imported by its prior path. A `pub use` may have been removed, or the module may have been renamed, removed, or made non-public.
ref: https://doc.rust-lang.org/cargo/reference/semver.html#item-remove
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/module_missing.ron
Failed in:
mod litebox_shim_optee::ptr, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_shim_optee/src/ptr.rs:4
--- failure struct_missing: pub struct removed or renamed ---
Description:
A publicly-visible struct cannot be imported by its prior path. A `pub use` may have been removed, or the struct itself may have been renamed or removed entirely.
ref: https://doc.rust-lang.org/cargo/reference/semver.html#item-remove
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/struct_missing.ron
Failed in:
struct litebox_shim_optee::ptr::PhysConstPtr, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_shim_optee/src/ptr.rs:499
struct litebox_shim_optee::NormalWorldConstPtr, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_shim_optee/src/ptr.rs:499
struct litebox_shim_optee::ptr::PhysMutPtr, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_shim_optee/src/ptr.rs:107
struct litebox_shim_optee::NormalWorldMutPtr, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_shim_optee/src/ptr.rs:107

@sangho2
Sangho Lee (sangho2) added this pull request to the merge queueJul 11, 2026
Merged via the queue into main with commit d63ea37Jul 11, 2026
15 of 18 checks passed
@sangho2
Sangho Lee (sangho2) deleted the sanghle/lvbs/vmap_copy branch July 11, 2026 00:12
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@sangho2@lschuermann@wdcui
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Refactor: Use physical pointer abstraction in LVBS by sangho2 · Pull Request #817 · microsoft/litebox · GitHub
Skip to content

Refactor: Use physical pointer abstraction in LVBS - #817

Merged
Sangho Lee (sangho2) merged 25 commits into
mainfrom
sanghle/lvbs/vmap_copy
Jul 11, 2026
Merged

Refactor: Use physical pointer abstraction in LVBS#817
Sangho Lee (sangho2) merged 25 commits into
mainfrom
sanghle/lvbs/vmap_copy

Conversation

@sangho2

@sangho2Sangho Lee (sangho2) commented Apr 28, 2026

Copy link
Copy Markdown
Contributor

This PR lets the LVBS platform (i.e., HEKI/HVCI) use physical pointer abstraction to access VTL0 memory. This is equivalent to the OP-TEE shim's normal-world memory access such that it is not only safer than the legacy VTL0 memory copy functions (i.e., copy_(slice_)(from|to)_vtl0_phys) but also supporting virtually contiguous access of non-contiguous physical page frames.

@sangho2Sangho Lee (sangho2) added the must-not-merge:prototype An experimental/proof-of-concept PR that must not be merged. label Apr 28, 2026
@sangho2
Sangho Lee (sangho2)force-pushed the sanghle/lvbs/vmap_copy branch 2 times, most recently from 29c61b5 to e42c3a0CompareMay 1, 2026 15:51
@sangho2Sangho Lee (sangho2) changed the title [DRAFT] Use physical pointer abstraction in HVCI/HEKIUse physical pointer abstraction in HVCI/HEKIMay 1, 2026
@sangho2Sangho Lee (sangho2) changed the title Use physical pointer abstraction in HVCI/HEKIUse safe physical pointer abstraction in HVCI/HEKIMay 1, 2026
@sangho2Sangho Lee (sangho2) removed the must-not-merge:prototype An experimental/proof-of-concept PR that must not be merged. label May 1, 2026
@sangho2
Sangho Lee (sangho2) marked this pull request as ready for review May 1, 2026 20:11
@sangho2Sangho Lee (sangho2) added must-not-merge:prototype An experimental/proof-of-concept PR that must not be merged. and removed must-not-merge:prototype An experimental/proof-of-concept PR that must not be merged. labels May 1, 2026
@sangho2Sangho Lee (sangho2) changed the title Use safe physical pointer abstraction in HVCI/HEKIUse physical pointer abstraction in HVCI/HEKIMay 1, 2026
@sangho2Sangho Lee (sangho2) changed the title Use physical pointer abstraction in HVCI/HEKIUse physical pointer abstraction in LVBSMay 15, 2026
Comment threadlitebox_common_linux/src/physical_pointers.rs Outdated
Comment threadlitebox_platform_lvbs/src/mshv/vsm.rs
@sangho2Sangho Lee (sangho2) added must-not-merge:undergoing-restructuring Known deeper set of changes are happening on this PR before it is mergeable again and removed must-not-merge:undergoing-restructuring Known deeper set of changes are happening on this PR before it is mergeable again labels May 15, 2026
@sangho2
Sangho Lee (sangho2)force-pushed the sanghle/lvbs/vmap_copy branch 2 times, most recently from c6fd071 to 24e1d87CompareMay 21, 2026 20:58

@wdcuiWeidong Cui (wdcui) left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. I left some comments. Thanks!

Comment threadlitebox_common_linux/src/physical_pointers.rs Outdated
Comment threadlitebox_platform_lvbs/src/mshv/ringbuffer.rs Outdated
Comment threadlitebox_platform_lvbs/src/mshv/vsm.rs Outdated
@sangho2Sangho Lee (sangho2) added the must-not-merge:undergoing-restructuring Known deeper set of changes are happening on this PR before it is mergeable again label Jun 15, 2026

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I took a pass over the entirety of physical_pointers.rs, not just the diff of this PR. In summary, I think this is close to a neat and (in the future) sound abstraction with rich pointer semantics over dynamically mapped physical memory.

Happy to discuss my comments below, I'll go over the remaining changes soon. I don't think any of these is critical to be addressed in this PR, instead I'm happy to implement the changes in a follow-up PR!

Comment threadlitebox_common_linux/src/physical_pointers.rs
Comment threadlitebox_common_linux/src/physical_pointers.rs Outdated
Comment threadlitebox_common_linux/src/physical_pointers.rs Outdated
Comment threadlitebox_common_linux/src/physical_pointers.rs
Comment threadlitebox_common_linux/src/physical_pointers.rs
Comment threadlitebox_common_linux/src/physical_pointers.rs
Comment threadlitebox_common_linux/src/physical_pointers.rs
Comment threadlitebox_common_linux/src/physical_pointers.rs
Comment threadlitebox_common_linux/src/physical_pointers.rs Outdated

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the rest of the PR. I realize some of my feedback might be obsolete due to #824, so I'll check that out next. Should I create a PR to address the left-over comments targeting this same sanghle/lvbs/vmap_copy branch?

Comment threadlitebox_platform_lvbs/src/mshv/ringbuffer.rs
Comment threadlitebox_platform_lvbs/src/mshv/ringbuffer.rs
Comment threadlitebox_common_linux/src/vmap.rs Outdated
Comment threadlitebox_common_linux/src/vmap.rs Outdated
Comment threadlitebox_platform_lvbs/src/mshv/vsm.rs
Comment threadlitebox_platform_lvbs/src/lib.rs Outdated
Comment threadlitebox_shim_optee/src/lib.rs Outdated
@sangho2Sangho Lee (sangho2) removed the must-not-merge:undergoing-restructuring Known deeper set of changes are happening on this PR before it is mergeable again label Jun 26, 2026
@github-actions

Copy link
Copy Markdown

🤖 SemverChecks 🤖 ⚠️ Potential breaking API changes detected ⚠️

Click for details
--- failure enum_variant_missing: pub enum variant removed or renamed ---
Description:
A publicly-visible enum has at least one variant that is no longer available under its prior name. It may have been renamed or removed entirely.
ref: https://doc.rust-lang.org/cargo/reference/semver.html#item-remove
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/enum_variant_missing.ron
Failed in:
variant PhysPointerError::UnalignedPhysicalAddress, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_common_linux/src/vmap.rs:150
variant PhysPointerError::UnalignedOffset, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_common_linux/src/vmap.rs:152
variant PhysPointerError::NoMappingInfo, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_common_linux/src/vmap.rs:166
--- failure struct_missing: pub struct removed or renamed ---
Description:
A publicly-visible struct cannot be imported by its prior path. A `pub use` may have been removed, or the struct itself may have been renamed or removed entirely.
ref: https://doc.rust-lang.org/cargo/reference/semver.html#item-remove
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/struct_missing.ron
Failed in:
struct litebox_common_linux::vmap::PhysPageMapInfo, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_common_linux/src/vmap.rs:95
--- failure trait_associated_type_added: non-sealed public trait added associated type without default value ---
Description:
A non-sealed trait has gained an associated type without a default value, which breaks downstream implementations of the trait
ref: https://doc.rust-lang.org/cargo/reference/semver.html#trait-new-item-no-default
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/trait_associated_type_added.ron
Failed in:
trait associated type litebox_common_linux::vmap::VmapManager::MapInfo in file /home/runner/work/litebox/litebox/litebox_common_linux/src/vmap.rs:22
--- failure trait_method_default_impl_removed: pub trait default method impl removed ---
Description:
A method's default impl in an unsealed trait has been removed, breaking trait implementations that relied on that default
ref: https://doc.rust-lang.org/book/ch10-02-traits.html#default-implementations
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/trait_method_default_impl_removed.ron
Failed in:
trait method litebox_common_linux::vmap::VmapManager::validate_unowned in file /home/runner/work/litebox/litebox/litebox_common_linux/src/vmap.rs:79
trait method litebox_common_linux::vmap::VmapManager::protect in file /home/runner/work/litebox/litebox/litebox_common_linux/src/vmap.rs:96
--- failure trait_unsafe_added: pub trait became unsafe ---
Description:
A publicly-visible trait became `unsafe`, so implementing it now requires an `unsafe impl` block.
ref: https://doc.rust-lang.org/book/ch19-01-unsafe-rust.html#implementing-an-unsafe-trait
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/trait_unsafe_added.ron
Failed in:
trait litebox_common_linux::vmap::VmapManager in file /home/runner/work/litebox/litebox/litebox_common_linux/src/vmap.rs:19
--- failure feature_missing: package feature removed or renamed ---
Description:
A feature has been removed from this package's Cargo.toml. This will break downstream crates which enable that feature.
ref: https://doc.rust-lang.org/cargo/reference/semver.html#cargo-feature-remove
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/feature_missing.ron
Failed in:
feature optee_syscall in the package's Cargo.toml
--- failure inherent_method_missing: pub method removed or renamed ---
Description:
A publicly-visible method or associated fn is no longer available under its prior name. It may have been renamed or removed entirely.
ref: https://doc.rust-lang.org/cargo/reference/semver.html#item-remove
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/inherent_method_missing.ron
Failed in:
LinuxKernel::copy_from_vtl0_phys, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_platform_lvbs/src/lib.rs:725
LinuxKernel::copy_to_vtl0_phys, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_platform_lvbs/src/lib.rs:765
LinuxKernel::copy_slice_to_vtl0_phys, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_platform_lvbs/src/lib.rs:800
LinuxKernel::copy_slice_from_vtl0_phys, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_platform_lvbs/src/lib.rs:835
--- failure module_missing: pub module removed or renamed ---
Description:
A publicly-visible module cannot be imported by its prior path. A `pub use` may have been removed, or the module may have been renamed, removed, or made non-public.
ref: https://doc.rust-lang.org/cargo/reference/semver.html#item-remove
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/module_missing.ron
Failed in:
mod litebox_shim_optee::ptr, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_shim_optee/src/ptr.rs:4
--- failure struct_missing: pub struct removed or renamed ---
Description:
A publicly-visible struct cannot be imported by its prior path. A `pub use` may have been removed, or the struct itself may have been renamed or removed entirely.
ref: https://doc.rust-lang.org/cargo/reference/semver.html#item-remove
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/struct_missing.ron
Failed in:
struct litebox_shim_optee::ptr::PhysConstPtr, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_shim_optee/src/ptr.rs:499
struct litebox_shim_optee::NormalWorldConstPtr, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_shim_optee/src/ptr.rs:499
struct litebox_shim_optee::ptr::PhysMutPtr, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_shim_optee/src/ptr.rs:107
struct litebox_shim_optee::NormalWorldMutPtr, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_shim_optee/src/ptr.rs:107

@sangho2
Sangho Lee (sangho2) added this pull request to the merge queueJul 11, 2026
Merged via the queue into main with commit d63ea37Jul 11, 2026
15 of 18 checks passed
@sangho2
Sangho Lee (sangho2) deleted the sanghle/lvbs/vmap_copy branch July 11, 2026 00:12
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@sangho2@lschuermann@wdcui
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Refactor: Use physical pointer abstraction in LVBS by sangho2 · Pull Request #817 · microsoft/litebox · GitHub
Skip to content

Refactor: Use physical pointer abstraction in LVBS - #817

Merged
Sangho Lee (sangho2) merged 25 commits into
mainfrom
sanghle/lvbs/vmap_copy
Jul 11, 2026
Merged

Refactor: Use physical pointer abstraction in LVBS#817
Sangho Lee (sangho2) merged 25 commits into
mainfrom
sanghle/lvbs/vmap_copy

Conversation

@sangho2

@sangho2Sangho Lee (sangho2) commented Apr 28, 2026

Copy link
Copy Markdown
Contributor

This PR lets the LVBS platform (i.e., HEKI/HVCI) use physical pointer abstraction to access VTL0 memory. This is equivalent to the OP-TEE shim's normal-world memory access such that it is not only safer than the legacy VTL0 memory copy functions (i.e., copy_(slice_)(from|to)_vtl0_phys) but also supporting virtually contiguous access of non-contiguous physical page frames.

@sangho2Sangho Lee (sangho2) added the must-not-merge:prototype An experimental/proof-of-concept PR that must not be merged. label Apr 28, 2026
@sangho2
Sangho Lee (sangho2)force-pushed the sanghle/lvbs/vmap_copy branch 2 times, most recently from 29c61b5 to e42c3a0CompareMay 1, 2026 15:51
@sangho2Sangho Lee (sangho2) changed the title [DRAFT] Use physical pointer abstraction in HVCI/HEKIUse physical pointer abstraction in HVCI/HEKIMay 1, 2026
@sangho2Sangho Lee (sangho2) changed the title Use physical pointer abstraction in HVCI/HEKIUse safe physical pointer abstraction in HVCI/HEKIMay 1, 2026
@sangho2Sangho Lee (sangho2) removed the must-not-merge:prototype An experimental/proof-of-concept PR that must not be merged. label May 1, 2026
@sangho2
Sangho Lee (sangho2) marked this pull request as ready for review May 1, 2026 20:11
@sangho2Sangho Lee (sangho2) added must-not-merge:prototype An experimental/proof-of-concept PR that must not be merged. and removed must-not-merge:prototype An experimental/proof-of-concept PR that must not be merged. labels May 1, 2026
@sangho2Sangho Lee (sangho2) changed the title Use safe physical pointer abstraction in HVCI/HEKIUse physical pointer abstraction in HVCI/HEKIMay 1, 2026
@sangho2Sangho Lee (sangho2) changed the title Use physical pointer abstraction in HVCI/HEKIUse physical pointer abstraction in LVBSMay 15, 2026
Comment threadlitebox_common_linux/src/physical_pointers.rs Outdated
Comment threadlitebox_platform_lvbs/src/mshv/vsm.rs
@sangho2Sangho Lee (sangho2) added must-not-merge:undergoing-restructuring Known deeper set of changes are happening on this PR before it is mergeable again and removed must-not-merge:undergoing-restructuring Known deeper set of changes are happening on this PR before it is mergeable again labels May 15, 2026
@sangho2
Sangho Lee (sangho2)force-pushed the sanghle/lvbs/vmap_copy branch 2 times, most recently from c6fd071 to 24e1d87CompareMay 21, 2026 20:58

@wdcuiWeidong Cui (wdcui) left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. I left some comments. Thanks!

Comment threadlitebox_common_linux/src/physical_pointers.rs Outdated
Comment threadlitebox_platform_lvbs/src/mshv/ringbuffer.rs Outdated
Comment threadlitebox_platform_lvbs/src/mshv/vsm.rs Outdated
@sangho2Sangho Lee (sangho2) added the must-not-merge:undergoing-restructuring Known deeper set of changes are happening on this PR before it is mergeable again label Jun 15, 2026

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I took a pass over the entirety of physical_pointers.rs, not just the diff of this PR. In summary, I think this is close to a neat and (in the future) sound abstraction with rich pointer semantics over dynamically mapped physical memory.

Happy to discuss my comments below, I'll go over the remaining changes soon. I don't think any of these is critical to be addressed in this PR, instead I'm happy to implement the changes in a follow-up PR!

Comment threadlitebox_common_linux/src/physical_pointers.rs
Comment threadlitebox_common_linux/src/physical_pointers.rs Outdated
Comment threadlitebox_common_linux/src/physical_pointers.rs Outdated
Comment threadlitebox_common_linux/src/physical_pointers.rs
Comment threadlitebox_common_linux/src/physical_pointers.rs
Comment threadlitebox_common_linux/src/physical_pointers.rs
Comment threadlitebox_common_linux/src/physical_pointers.rs
Comment threadlitebox_common_linux/src/physical_pointers.rs
Comment threadlitebox_common_linux/src/physical_pointers.rs Outdated

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the rest of the PR. I realize some of my feedback might be obsolete due to #824, so I'll check that out next. Should I create a PR to address the left-over comments targeting this same sanghle/lvbs/vmap_copy branch?

Comment threadlitebox_platform_lvbs/src/mshv/ringbuffer.rs
Comment threadlitebox_platform_lvbs/src/mshv/ringbuffer.rs
Comment threadlitebox_common_linux/src/vmap.rs Outdated
Comment threadlitebox_common_linux/src/vmap.rs Outdated
Comment threadlitebox_platform_lvbs/src/mshv/vsm.rs
Comment threadlitebox_platform_lvbs/src/lib.rs Outdated
Comment threadlitebox_shim_optee/src/lib.rs Outdated
@sangho2Sangho Lee (sangho2) removed the must-not-merge:undergoing-restructuring Known deeper set of changes are happening on this PR before it is mergeable again label Jun 26, 2026
@github-actions

Copy link
Copy Markdown

🤖 SemverChecks 🤖 ⚠️ Potential breaking API changes detected ⚠️

Click for details
--- failure enum_variant_missing: pub enum variant removed or renamed ---
Description:
A publicly-visible enum has at least one variant that is no longer available under its prior name. It may have been renamed or removed entirely.
ref: https://doc.rust-lang.org/cargo/reference/semver.html#item-remove
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/enum_variant_missing.ron
Failed in:
variant PhysPointerError::UnalignedPhysicalAddress, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_common_linux/src/vmap.rs:150
variant PhysPointerError::UnalignedOffset, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_common_linux/src/vmap.rs:152
variant PhysPointerError::NoMappingInfo, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_common_linux/src/vmap.rs:166
--- failure struct_missing: pub struct removed or renamed ---
Description:
A publicly-visible struct cannot be imported by its prior path. A `pub use` may have been removed, or the struct itself may have been renamed or removed entirely.
ref: https://doc.rust-lang.org/cargo/reference/semver.html#item-remove
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/struct_missing.ron
Failed in:
struct litebox_common_linux::vmap::PhysPageMapInfo, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_common_linux/src/vmap.rs:95
--- failure trait_associated_type_added: non-sealed public trait added associated type without default value ---
Description:
A non-sealed trait has gained an associated type without a default value, which breaks downstream implementations of the trait
ref: https://doc.rust-lang.org/cargo/reference/semver.html#trait-new-item-no-default
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/trait_associated_type_added.ron
Failed in:
trait associated type litebox_common_linux::vmap::VmapManager::MapInfo in file /home/runner/work/litebox/litebox/litebox_common_linux/src/vmap.rs:22
--- failure trait_method_default_impl_removed: pub trait default method impl removed ---
Description:
A method's default impl in an unsealed trait has been removed, breaking trait implementations that relied on that default
ref: https://doc.rust-lang.org/book/ch10-02-traits.html#default-implementations
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/trait_method_default_impl_removed.ron
Failed in:
trait method litebox_common_linux::vmap::VmapManager::validate_unowned in file /home/runner/work/litebox/litebox/litebox_common_linux/src/vmap.rs:79
trait method litebox_common_linux::vmap::VmapManager::protect in file /home/runner/work/litebox/litebox/litebox_common_linux/src/vmap.rs:96
--- failure trait_unsafe_added: pub trait became unsafe ---
Description:
A publicly-visible trait became `unsafe`, so implementing it now requires an `unsafe impl` block.
ref: https://doc.rust-lang.org/book/ch19-01-unsafe-rust.html#implementing-an-unsafe-trait
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/trait_unsafe_added.ron
Failed in:
trait litebox_common_linux::vmap::VmapManager in file /home/runner/work/litebox/litebox/litebox_common_linux/src/vmap.rs:19
--- failure feature_missing: package feature removed or renamed ---
Description:
A feature has been removed from this package's Cargo.toml. This will break downstream crates which enable that feature.
ref: https://doc.rust-lang.org/cargo/reference/semver.html#cargo-feature-remove
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/feature_missing.ron
Failed in:
feature optee_syscall in the package's Cargo.toml
--- failure inherent_method_missing: pub method removed or renamed ---
Description:
A publicly-visible method or associated fn is no longer available under its prior name. It may have been renamed or removed entirely.
ref: https://doc.rust-lang.org/cargo/reference/semver.html#item-remove
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/inherent_method_missing.ron
Failed in:
LinuxKernel::copy_from_vtl0_phys, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_platform_lvbs/src/lib.rs:725
LinuxKernel::copy_to_vtl0_phys, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_platform_lvbs/src/lib.rs:765
LinuxKernel::copy_slice_to_vtl0_phys, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_platform_lvbs/src/lib.rs:800
LinuxKernel::copy_slice_from_vtl0_phys, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_platform_lvbs/src/lib.rs:835
--- failure module_missing: pub module removed or renamed ---
Description:
A publicly-visible module cannot be imported by its prior path. A `pub use` may have been removed, or the module may have been renamed, removed, or made non-public.
ref: https://doc.rust-lang.org/cargo/reference/semver.html#item-remove
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/module_missing.ron
Failed in:
mod litebox_shim_optee::ptr, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_shim_optee/src/ptr.rs:4
--- failure struct_missing: pub struct removed or renamed ---
Description:
A publicly-visible struct cannot be imported by its prior path. A `pub use` may have been removed, or the struct itself may have been renamed or removed entirely.
ref: https://doc.rust-lang.org/cargo/reference/semver.html#item-remove
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/struct_missing.ron
Failed in:
struct litebox_shim_optee::ptr::PhysConstPtr, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_shim_optee/src/ptr.rs:499
struct litebox_shim_optee::NormalWorldConstPtr, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_shim_optee/src/ptr.rs:499
struct litebox_shim_optee::ptr::PhysMutPtr, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_shim_optee/src/ptr.rs:107
struct litebox_shim_optee::NormalWorldMutPtr, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_shim_optee/src/ptr.rs:107

@sangho2
Sangho Lee (sangho2) added this pull request to the merge queueJul 11, 2026
Merged via the queue into main with commit d63ea37Jul 11, 2026
15 of 18 checks passed
@sangho2
Sangho Lee (sangho2) deleted the sanghle/lvbs/vmap_copy branch July 11, 2026 00:12
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@sangho2@lschuermann@wdcui
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Refactor: Use physical pointer abstraction in LVBS by sangho2 · Pull Request #817 · microsoft/litebox · GitHub
Skip to content

Refactor: Use physical pointer abstraction in LVBS - #817

Merged
Sangho Lee (sangho2) merged 25 commits into
mainfrom
sanghle/lvbs/vmap_copy
Jul 11, 2026
Merged

Refactor: Use physical pointer abstraction in LVBS#817
Sangho Lee (sangho2) merged 25 commits into
mainfrom
sanghle/lvbs/vmap_copy

Conversation

@sangho2

@sangho2Sangho Lee (sangho2) commented Apr 28, 2026

Copy link
Copy Markdown
Contributor

This PR lets the LVBS platform (i.e., HEKI/HVCI) use physical pointer abstraction to access VTL0 memory. This is equivalent to the OP-TEE shim's normal-world memory access such that it is not only safer than the legacy VTL0 memory copy functions (i.e., copy_(slice_)(from|to)_vtl0_phys) but also supporting virtually contiguous access of non-contiguous physical page frames.

@sangho2Sangho Lee (sangho2) added the must-not-merge:prototype An experimental/proof-of-concept PR that must not be merged. label Apr 28, 2026
@sangho2
Sangho Lee (sangho2)force-pushed the sanghle/lvbs/vmap_copy branch 2 times, most recently from 29c61b5 to e42c3a0CompareMay 1, 2026 15:51
@sangho2Sangho Lee (sangho2) changed the title [DRAFT] Use physical pointer abstraction in HVCI/HEKIUse physical pointer abstraction in HVCI/HEKIMay 1, 2026
@sangho2Sangho Lee (sangho2) changed the title Use physical pointer abstraction in HVCI/HEKIUse safe physical pointer abstraction in HVCI/HEKIMay 1, 2026
@sangho2Sangho Lee (sangho2) removed the must-not-merge:prototype An experimental/proof-of-concept PR that must not be merged. label May 1, 2026
@sangho2
Sangho Lee (sangho2) marked this pull request as ready for review May 1, 2026 20:11
@sangho2Sangho Lee (sangho2) added must-not-merge:prototype An experimental/proof-of-concept PR that must not be merged. and removed must-not-merge:prototype An experimental/proof-of-concept PR that must not be merged. labels May 1, 2026
@sangho2Sangho Lee (sangho2) changed the title Use safe physical pointer abstraction in HVCI/HEKIUse physical pointer abstraction in HVCI/HEKIMay 1, 2026
@sangho2Sangho Lee (sangho2) changed the title Use physical pointer abstraction in HVCI/HEKIUse physical pointer abstraction in LVBSMay 15, 2026
Comment threadlitebox_common_linux/src/physical_pointers.rs Outdated
Comment threadlitebox_platform_lvbs/src/mshv/vsm.rs
@sangho2Sangho Lee (sangho2) added must-not-merge:undergoing-restructuring Known deeper set of changes are happening on this PR before it is mergeable again and removed must-not-merge:undergoing-restructuring Known deeper set of changes are happening on this PR before it is mergeable again labels May 15, 2026
@sangho2
Sangho Lee (sangho2)force-pushed the sanghle/lvbs/vmap_copy branch 2 times, most recently from c6fd071 to 24e1d87CompareMay 21, 2026 20:58

@wdcuiWeidong Cui (wdcui) left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. I left some comments. Thanks!

Comment threadlitebox_common_linux/src/physical_pointers.rs Outdated
Comment threadlitebox_platform_lvbs/src/mshv/ringbuffer.rs Outdated
Comment threadlitebox_platform_lvbs/src/mshv/vsm.rs Outdated
@sangho2Sangho Lee (sangho2) added the must-not-merge:undergoing-restructuring Known deeper set of changes are happening on this PR before it is mergeable again label Jun 15, 2026

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I took a pass over the entirety of physical_pointers.rs, not just the diff of this PR. In summary, I think this is close to a neat and (in the future) sound abstraction with rich pointer semantics over dynamically mapped physical memory.

Happy to discuss my comments below, I'll go over the remaining changes soon. I don't think any of these is critical to be addressed in this PR, instead I'm happy to implement the changes in a follow-up PR!

Comment threadlitebox_common_linux/src/physical_pointers.rs
Comment threadlitebox_common_linux/src/physical_pointers.rs Outdated
Comment threadlitebox_common_linux/src/physical_pointers.rs Outdated
Comment threadlitebox_common_linux/src/physical_pointers.rs
Comment threadlitebox_common_linux/src/physical_pointers.rs
Comment threadlitebox_common_linux/src/physical_pointers.rs
Comment threadlitebox_common_linux/src/physical_pointers.rs
Comment threadlitebox_common_linux/src/physical_pointers.rs
Comment threadlitebox_common_linux/src/physical_pointers.rs Outdated

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the rest of the PR. I realize some of my feedback might be obsolete due to #824, so I'll check that out next. Should I create a PR to address the left-over comments targeting this same sanghle/lvbs/vmap_copy branch?

Comment threadlitebox_platform_lvbs/src/mshv/ringbuffer.rs
Comment threadlitebox_platform_lvbs/src/mshv/ringbuffer.rs
Comment threadlitebox_common_linux/src/vmap.rs Outdated
Comment threadlitebox_common_linux/src/vmap.rs Outdated
Comment threadlitebox_platform_lvbs/src/mshv/vsm.rs
Comment threadlitebox_platform_lvbs/src/lib.rs Outdated
Comment threadlitebox_shim_optee/src/lib.rs Outdated
@sangho2Sangho Lee (sangho2) removed the must-not-merge:undergoing-restructuring Known deeper set of changes are happening on this PR before it is mergeable again label Jun 26, 2026
@github-actions

Copy link
Copy Markdown

🤖 SemverChecks 🤖 ⚠️ Potential breaking API changes detected ⚠️

Click for details
--- failure enum_variant_missing: pub enum variant removed or renamed ---
Description:
A publicly-visible enum has at least one variant that is no longer available under its prior name. It may have been renamed or removed entirely.
ref: https://doc.rust-lang.org/cargo/reference/semver.html#item-remove
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/enum_variant_missing.ron
Failed in:
variant PhysPointerError::UnalignedPhysicalAddress, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_common_linux/src/vmap.rs:150
variant PhysPointerError::UnalignedOffset, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_common_linux/src/vmap.rs:152
variant PhysPointerError::NoMappingInfo, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_common_linux/src/vmap.rs:166
--- failure struct_missing: pub struct removed or renamed ---
Description:
A publicly-visible struct cannot be imported by its prior path. A `pub use` may have been removed, or the struct itself may have been renamed or removed entirely.
ref: https://doc.rust-lang.org/cargo/reference/semver.html#item-remove
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/struct_missing.ron
Failed in:
struct litebox_common_linux::vmap::PhysPageMapInfo, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_common_linux/src/vmap.rs:95
--- failure trait_associated_type_added: non-sealed public trait added associated type without default value ---
Description:
A non-sealed trait has gained an associated type without a default value, which breaks downstream implementations of the trait
ref: https://doc.rust-lang.org/cargo/reference/semver.html#trait-new-item-no-default
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/trait_associated_type_added.ron
Failed in:
trait associated type litebox_common_linux::vmap::VmapManager::MapInfo in file /home/runner/work/litebox/litebox/litebox_common_linux/src/vmap.rs:22
--- failure trait_method_default_impl_removed: pub trait default method impl removed ---
Description:
A method's default impl in an unsealed trait has been removed, breaking trait implementations that relied on that default
ref: https://doc.rust-lang.org/book/ch10-02-traits.html#default-implementations
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/trait_method_default_impl_removed.ron
Failed in:
trait method litebox_common_linux::vmap::VmapManager::validate_unowned in file /home/runner/work/litebox/litebox/litebox_common_linux/src/vmap.rs:79
trait method litebox_common_linux::vmap::VmapManager::protect in file /home/runner/work/litebox/litebox/litebox_common_linux/src/vmap.rs:96
--- failure trait_unsafe_added: pub trait became unsafe ---
Description:
A publicly-visible trait became `unsafe`, so implementing it now requires an `unsafe impl` block.
ref: https://doc.rust-lang.org/book/ch19-01-unsafe-rust.html#implementing-an-unsafe-trait
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/trait_unsafe_added.ron
Failed in:
trait litebox_common_linux::vmap::VmapManager in file /home/runner/work/litebox/litebox/litebox_common_linux/src/vmap.rs:19
--- failure feature_missing: package feature removed or renamed ---
Description:
A feature has been removed from this package's Cargo.toml. This will break downstream crates which enable that feature.
ref: https://doc.rust-lang.org/cargo/reference/semver.html#cargo-feature-remove
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/feature_missing.ron
Failed in:
feature optee_syscall in the package's Cargo.toml
--- failure inherent_method_missing: pub method removed or renamed ---
Description:
A publicly-visible method or associated fn is no longer available under its prior name. It may have been renamed or removed entirely.
ref: https://doc.rust-lang.org/cargo/reference/semver.html#item-remove
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/inherent_method_missing.ron
Failed in:
LinuxKernel::copy_from_vtl0_phys, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_platform_lvbs/src/lib.rs:725
LinuxKernel::copy_to_vtl0_phys, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_platform_lvbs/src/lib.rs:765
LinuxKernel::copy_slice_to_vtl0_phys, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_platform_lvbs/src/lib.rs:800
LinuxKernel::copy_slice_from_vtl0_phys, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_platform_lvbs/src/lib.rs:835
--- failure module_missing: pub module removed or renamed ---
Description:
A publicly-visible module cannot be imported by its prior path. A `pub use` may have been removed, or the module may have been renamed, removed, or made non-public.
ref: https://doc.rust-lang.org/cargo/reference/semver.html#item-remove
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/module_missing.ron
Failed in:
mod litebox_shim_optee::ptr, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_shim_optee/src/ptr.rs:4
--- failure struct_missing: pub struct removed or renamed ---
Description:
A publicly-visible struct cannot be imported by its prior path. A `pub use` may have been removed, or the struct itself may have been renamed or removed entirely.
ref: https://doc.rust-lang.org/cargo/reference/semver.html#item-remove
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/struct_missing.ron
Failed in:
struct litebox_shim_optee::ptr::PhysConstPtr, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_shim_optee/src/ptr.rs:499
struct litebox_shim_optee::NormalWorldConstPtr, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_shim_optee/src/ptr.rs:499
struct litebox_shim_optee::ptr::PhysMutPtr, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_shim_optee/src/ptr.rs:107
struct litebox_shim_optee::NormalWorldMutPtr, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_shim_optee/src/ptr.rs:107

@sangho2
Sangho Lee (sangho2) added this pull request to the merge queueJul 11, 2026
Merged via the queue into main with commit d63ea37Jul 11, 2026
15 of 18 checks passed
@sangho2
Sangho Lee (sangho2) deleted the sanghle/lvbs/vmap_copy branch July 11, 2026 00:12
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@sangho2@lschuermann@wdcui
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' Refactor: Use physical pointer abstraction in LVBS by sangho2 · Pull Request #817 · microsoft/litebox · GitHub
Skip to content

Refactor: Use physical pointer abstraction in LVBS - #817

Merged
Sangho Lee (sangho2) merged 25 commits into
mainfrom
sanghle/lvbs/vmap_copy
Jul 11, 2026
Merged

Refactor: Use physical pointer abstraction in LVBS#817
Sangho Lee (sangho2) merged 25 commits into
mainfrom
sanghle/lvbs/vmap_copy

Conversation

@sangho2

@sangho2Sangho Lee (sangho2) commented Apr 28, 2026

Copy link
Copy Markdown
Contributor

This PR lets the LVBS platform (i.e., HEKI/HVCI) use physical pointer abstraction to access VTL0 memory. This is equivalent to the OP-TEE shim's normal-world memory access such that it is not only safer than the legacy VTL0 memory copy functions (i.e., copy_(slice_)(from|to)_vtl0_phys) but also supporting virtually contiguous access of non-contiguous physical page frames.

@sangho2Sangho Lee (sangho2) added the must-not-merge:prototype An experimental/proof-of-concept PR that must not be merged. label Apr 28, 2026
@sangho2
Sangho Lee (sangho2)force-pushed the sanghle/lvbs/vmap_copy branch 2 times, most recently from 29c61b5 to e42c3a0CompareMay 1, 2026 15:51
@sangho2Sangho Lee (sangho2) changed the title [DRAFT] Use physical pointer abstraction in HVCI/HEKIUse physical pointer abstraction in HVCI/HEKIMay 1, 2026
@sangho2Sangho Lee (sangho2) changed the title Use physical pointer abstraction in HVCI/HEKIUse safe physical pointer abstraction in HVCI/HEKIMay 1, 2026
@sangho2Sangho Lee (sangho2) removed the must-not-merge:prototype An experimental/proof-of-concept PR that must not be merged. label May 1, 2026
@sangho2
Sangho Lee (sangho2) marked this pull request as ready for review May 1, 2026 20:11
@sangho2Sangho Lee (sangho2) added must-not-merge:prototype An experimental/proof-of-concept PR that must not be merged. and removed must-not-merge:prototype An experimental/proof-of-concept PR that must not be merged. labels May 1, 2026
@sangho2Sangho Lee (sangho2) changed the title Use safe physical pointer abstraction in HVCI/HEKIUse physical pointer abstraction in HVCI/HEKIMay 1, 2026
@sangho2Sangho Lee (sangho2) changed the title Use physical pointer abstraction in HVCI/HEKIUse physical pointer abstraction in LVBSMay 15, 2026
Comment threadlitebox_common_linux/src/physical_pointers.rs Outdated
Comment threadlitebox_platform_lvbs/src/mshv/vsm.rs
@sangho2Sangho Lee (sangho2) added must-not-merge:undergoing-restructuring Known deeper set of changes are happening on this PR before it is mergeable again and removed must-not-merge:undergoing-restructuring Known deeper set of changes are happening on this PR before it is mergeable again labels May 15, 2026
@sangho2
Sangho Lee (sangho2)force-pushed the sanghle/lvbs/vmap_copy branch 2 times, most recently from c6fd071 to 24e1d87CompareMay 21, 2026 20:58

@wdcuiWeidong Cui (wdcui) left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. I left some comments. Thanks!

Comment threadlitebox_common_linux/src/physical_pointers.rs Outdated
Comment threadlitebox_platform_lvbs/src/mshv/ringbuffer.rs Outdated
Comment threadlitebox_platform_lvbs/src/mshv/vsm.rs Outdated
@sangho2Sangho Lee (sangho2) added the must-not-merge:undergoing-restructuring Known deeper set of changes are happening on this PR before it is mergeable again label Jun 15, 2026

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I took a pass over the entirety of physical_pointers.rs, not just the diff of this PR. In summary, I think this is close to a neat and (in the future) sound abstraction with rich pointer semantics over dynamically mapped physical memory.

Happy to discuss my comments below, I'll go over the remaining changes soon. I don't think any of these is critical to be addressed in this PR, instead I'm happy to implement the changes in a follow-up PR!

Comment threadlitebox_common_linux/src/physical_pointers.rs
Comment threadlitebox_common_linux/src/physical_pointers.rs Outdated
Comment threadlitebox_common_linux/src/physical_pointers.rs Outdated
Comment threadlitebox_common_linux/src/physical_pointers.rs
Comment threadlitebox_common_linux/src/physical_pointers.rs
Comment threadlitebox_common_linux/src/physical_pointers.rs
Comment threadlitebox_common_linux/src/physical_pointers.rs
Comment threadlitebox_common_linux/src/physical_pointers.rs
Comment threadlitebox_common_linux/src/physical_pointers.rs Outdated

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the rest of the PR. I realize some of my feedback might be obsolete due to #824, so I'll check that out next. Should I create a PR to address the left-over comments targeting this same sanghle/lvbs/vmap_copy branch?

Comment threadlitebox_platform_lvbs/src/mshv/ringbuffer.rs
Comment threadlitebox_platform_lvbs/src/mshv/ringbuffer.rs
Comment threadlitebox_common_linux/src/vmap.rs Outdated
Comment threadlitebox_common_linux/src/vmap.rs Outdated
Comment threadlitebox_platform_lvbs/src/mshv/vsm.rs
Comment threadlitebox_platform_lvbs/src/lib.rs Outdated
Comment threadlitebox_shim_optee/src/lib.rs Outdated
@sangho2Sangho Lee (sangho2) removed the must-not-merge:undergoing-restructuring Known deeper set of changes are happening on this PR before it is mergeable again label Jun 26, 2026
@github-actions

Copy link
Copy Markdown

🤖 SemverChecks 🤖 ⚠️ Potential breaking API changes detected ⚠️

Click for details
--- failure enum_variant_missing: pub enum variant removed or renamed ---
Description:
A publicly-visible enum has at least one variant that is no longer available under its prior name. It may have been renamed or removed entirely.
ref: https://doc.rust-lang.org/cargo/reference/semver.html#item-remove
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/enum_variant_missing.ron
Failed in:
variant PhysPointerError::UnalignedPhysicalAddress, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_common_linux/src/vmap.rs:150
variant PhysPointerError::UnalignedOffset, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_common_linux/src/vmap.rs:152
variant PhysPointerError::NoMappingInfo, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_common_linux/src/vmap.rs:166
--- failure struct_missing: pub struct removed or renamed ---
Description:
A publicly-visible struct cannot be imported by its prior path. A `pub use` may have been removed, or the struct itself may have been renamed or removed entirely.
ref: https://doc.rust-lang.org/cargo/reference/semver.html#item-remove
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/struct_missing.ron
Failed in:
struct litebox_common_linux::vmap::PhysPageMapInfo, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_common_linux/src/vmap.rs:95
--- failure trait_associated_type_added: non-sealed public trait added associated type without default value ---
Description:
A non-sealed trait has gained an associated type without a default value, which breaks downstream implementations of the trait
ref: https://doc.rust-lang.org/cargo/reference/semver.html#trait-new-item-no-default
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/trait_associated_type_added.ron
Failed in:
trait associated type litebox_common_linux::vmap::VmapManager::MapInfo in file /home/runner/work/litebox/litebox/litebox_common_linux/src/vmap.rs:22
--- failure trait_method_default_impl_removed: pub trait default method impl removed ---
Description:
A method's default impl in an unsealed trait has been removed, breaking trait implementations that relied on that default
ref: https://doc.rust-lang.org/book/ch10-02-traits.html#default-implementations
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/trait_method_default_impl_removed.ron
Failed in:
trait method litebox_common_linux::vmap::VmapManager::validate_unowned in file /home/runner/work/litebox/litebox/litebox_common_linux/src/vmap.rs:79
trait method litebox_common_linux::vmap::VmapManager::protect in file /home/runner/work/litebox/litebox/litebox_common_linux/src/vmap.rs:96
--- failure trait_unsafe_added: pub trait became unsafe ---
Description:
A publicly-visible trait became `unsafe`, so implementing it now requires an `unsafe impl` block.
ref: https://doc.rust-lang.org/book/ch19-01-unsafe-rust.html#implementing-an-unsafe-trait
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/trait_unsafe_added.ron
Failed in:
trait litebox_common_linux::vmap::VmapManager in file /home/runner/work/litebox/litebox/litebox_common_linux/src/vmap.rs:19
--- failure feature_missing: package feature removed or renamed ---
Description:
A feature has been removed from this package's Cargo.toml. This will break downstream crates which enable that feature.
ref: https://doc.rust-lang.org/cargo/reference/semver.html#cargo-feature-remove
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/feature_missing.ron
Failed in:
feature optee_syscall in the package's Cargo.toml
--- failure inherent_method_missing: pub method removed or renamed ---
Description:
A publicly-visible method or associated fn is no longer available under its prior name. It may have been renamed or removed entirely.
ref: https://doc.rust-lang.org/cargo/reference/semver.html#item-remove
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/inherent_method_missing.ron
Failed in:
LinuxKernel::copy_from_vtl0_phys, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_platform_lvbs/src/lib.rs:725
LinuxKernel::copy_to_vtl0_phys, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_platform_lvbs/src/lib.rs:765
LinuxKernel::copy_slice_to_vtl0_phys, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_platform_lvbs/src/lib.rs:800
LinuxKernel::copy_slice_from_vtl0_phys, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_platform_lvbs/src/lib.rs:835
--- failure module_missing: pub module removed or renamed ---
Description:
A publicly-visible module cannot be imported by its prior path. A `pub use` may have been removed, or the module may have been renamed, removed, or made non-public.
ref: https://doc.rust-lang.org/cargo/reference/semver.html#item-remove
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/module_missing.ron
Failed in:
mod litebox_shim_optee::ptr, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_shim_optee/src/ptr.rs:4
--- failure struct_missing: pub struct removed or renamed ---
Description:
A publicly-visible struct cannot be imported by its prior path. A `pub use` may have been removed, or the struct itself may have been renamed or removed entirely.
ref: https://doc.rust-lang.org/cargo/reference/semver.html#item-remove
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/struct_missing.ron
Failed in:
struct litebox_shim_optee::ptr::PhysConstPtr, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_shim_optee/src/ptr.rs:499
struct litebox_shim_optee::NormalWorldConstPtr, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_shim_optee/src/ptr.rs:499
struct litebox_shim_optee::ptr::PhysMutPtr, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_shim_optee/src/ptr.rs:107
struct litebox_shim_optee::NormalWorldMutPtr, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_shim_optee/src/ptr.rs:107

@sangho2
Sangho Lee (sangho2) added this pull request to the merge queueJul 11, 2026
Merged via the queue into main with commit d63ea37Jul 11, 2026
15 of 18 checks passed
@sangho2
Sangho Lee (sangho2) deleted the sanghle/lvbs/vmap_copy branch July 11, 2026 00:12
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@sangho2@lschuermann@wdcui
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Refactor: Use physical pointer abstraction in LVBS by sangho2 · Pull Request #817 · microsoft/litebox · GitHub
Skip to content

Refactor: Use physical pointer abstraction in LVBS - #817

Merged
Sangho Lee (sangho2) merged 25 commits into
mainfrom
sanghle/lvbs/vmap_copy
Jul 11, 2026
Merged

Refactor: Use physical pointer abstraction in LVBS#817
Sangho Lee (sangho2) merged 25 commits into
mainfrom
sanghle/lvbs/vmap_copy

Conversation

@sangho2

@sangho2Sangho Lee (sangho2) commented Apr 28, 2026

Copy link
Copy Markdown
Contributor

This PR lets the LVBS platform (i.e., HEKI/HVCI) use physical pointer abstraction to access VTL0 memory. This is equivalent to the OP-TEE shim's normal-world memory access such that it is not only safer than the legacy VTL0 memory copy functions (i.e., copy_(slice_)(from|to)_vtl0_phys) but also supporting virtually contiguous access of non-contiguous physical page frames.

@sangho2Sangho Lee (sangho2) added the must-not-merge:prototype An experimental/proof-of-concept PR that must not be merged. label Apr 28, 2026
@sangho2
Sangho Lee (sangho2)force-pushed the sanghle/lvbs/vmap_copy branch 2 times, most recently from 29c61b5 to e42c3a0CompareMay 1, 2026 15:51
@sangho2Sangho Lee (sangho2) changed the title [DRAFT] Use physical pointer abstraction in HVCI/HEKIUse physical pointer abstraction in HVCI/HEKIMay 1, 2026
@sangho2Sangho Lee (sangho2) changed the title Use physical pointer abstraction in HVCI/HEKIUse safe physical pointer abstraction in HVCI/HEKIMay 1, 2026
@sangho2Sangho Lee (sangho2) removed the must-not-merge:prototype An experimental/proof-of-concept PR that must not be merged. label May 1, 2026
@sangho2
Sangho Lee (sangho2) marked this pull request as ready for review May 1, 2026 20:11
@sangho2Sangho Lee (sangho2) added must-not-merge:prototype An experimental/proof-of-concept PR that must not be merged. and removed must-not-merge:prototype An experimental/proof-of-concept PR that must not be merged. labels May 1, 2026
@sangho2Sangho Lee (sangho2) changed the title Use safe physical pointer abstraction in HVCI/HEKIUse physical pointer abstraction in HVCI/HEKIMay 1, 2026
@sangho2Sangho Lee (sangho2) changed the title Use physical pointer abstraction in HVCI/HEKIUse physical pointer abstraction in LVBSMay 15, 2026
Comment threadlitebox_common_linux/src/physical_pointers.rs Outdated
Comment threadlitebox_platform_lvbs/src/mshv/vsm.rs
@sangho2Sangho Lee (sangho2) added must-not-merge:undergoing-restructuring Known deeper set of changes are happening on this PR before it is mergeable again and removed must-not-merge:undergoing-restructuring Known deeper set of changes are happening on this PR before it is mergeable again labels May 15, 2026
@sangho2
Sangho Lee (sangho2)force-pushed the sanghle/lvbs/vmap_copy branch 2 times, most recently from c6fd071 to 24e1d87CompareMay 21, 2026 20:58

@wdcuiWeidong Cui (wdcui) left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. I left some comments. Thanks!

Comment threadlitebox_common_linux/src/physical_pointers.rs Outdated
Comment threadlitebox_platform_lvbs/src/mshv/ringbuffer.rs Outdated
Comment threadlitebox_platform_lvbs/src/mshv/vsm.rs Outdated
@sangho2Sangho Lee (sangho2) added the must-not-merge:undergoing-restructuring Known deeper set of changes are happening on this PR before it is mergeable again label Jun 15, 2026

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I took a pass over the entirety of physical_pointers.rs, not just the diff of this PR. In summary, I think this is close to a neat and (in the future) sound abstraction with rich pointer semantics over dynamically mapped physical memory.

Happy to discuss my comments below, I'll go over the remaining changes soon. I don't think any of these is critical to be addressed in this PR, instead I'm happy to implement the changes in a follow-up PR!

Comment threadlitebox_common_linux/src/physical_pointers.rs
Comment threadlitebox_common_linux/src/physical_pointers.rs Outdated
Comment threadlitebox_common_linux/src/physical_pointers.rs Outdated
Comment threadlitebox_common_linux/src/physical_pointers.rs
Comment threadlitebox_common_linux/src/physical_pointers.rs
Comment threadlitebox_common_linux/src/physical_pointers.rs
Comment threadlitebox_common_linux/src/physical_pointers.rs
Comment threadlitebox_common_linux/src/physical_pointers.rs
Comment threadlitebox_common_linux/src/physical_pointers.rs Outdated

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the rest of the PR. I realize some of my feedback might be obsolete due to #824, so I'll check that out next. Should I create a PR to address the left-over comments targeting this same sanghle/lvbs/vmap_copy branch?

Comment threadlitebox_platform_lvbs/src/mshv/ringbuffer.rs
Comment threadlitebox_platform_lvbs/src/mshv/ringbuffer.rs
Comment threadlitebox_common_linux/src/vmap.rs Outdated
Comment threadlitebox_common_linux/src/vmap.rs Outdated
Comment threadlitebox_platform_lvbs/src/mshv/vsm.rs
Comment threadlitebox_platform_lvbs/src/lib.rs Outdated
Comment threadlitebox_shim_optee/src/lib.rs Outdated
@sangho2Sangho Lee (sangho2) removed the must-not-merge:undergoing-restructuring Known deeper set of changes are happening on this PR before it is mergeable again label Jun 26, 2026
@github-actions

Copy link
Copy Markdown

🤖 SemverChecks 🤖 ⚠️ Potential breaking API changes detected ⚠️

Click for details
--- failure enum_variant_missing: pub enum variant removed or renamed ---
Description:
A publicly-visible enum has at least one variant that is no longer available under its prior name. It may have been renamed or removed entirely.
ref: https://doc.rust-lang.org/cargo/reference/semver.html#item-remove
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/enum_variant_missing.ron
Failed in:
variant PhysPointerError::UnalignedPhysicalAddress, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_common_linux/src/vmap.rs:150
variant PhysPointerError::UnalignedOffset, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_common_linux/src/vmap.rs:152
variant PhysPointerError::NoMappingInfo, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_common_linux/src/vmap.rs:166
--- failure struct_missing: pub struct removed or renamed ---
Description:
A publicly-visible struct cannot be imported by its prior path. A `pub use` may have been removed, or the struct itself may have been renamed or removed entirely.
ref: https://doc.rust-lang.org/cargo/reference/semver.html#item-remove
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/struct_missing.ron
Failed in:
struct litebox_common_linux::vmap::PhysPageMapInfo, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_common_linux/src/vmap.rs:95
--- failure trait_associated_type_added: non-sealed public trait added associated type without default value ---
Description:
A non-sealed trait has gained an associated type without a default value, which breaks downstream implementations of the trait
ref: https://doc.rust-lang.org/cargo/reference/semver.html#trait-new-item-no-default
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/trait_associated_type_added.ron
Failed in:
trait associated type litebox_common_linux::vmap::VmapManager::MapInfo in file /home/runner/work/litebox/litebox/litebox_common_linux/src/vmap.rs:22
--- failure trait_method_default_impl_removed: pub trait default method impl removed ---
Description:
A method's default impl in an unsealed trait has been removed, breaking trait implementations that relied on that default
ref: https://doc.rust-lang.org/book/ch10-02-traits.html#default-implementations
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/trait_method_default_impl_removed.ron
Failed in:
trait method litebox_common_linux::vmap::VmapManager::validate_unowned in file /home/runner/work/litebox/litebox/litebox_common_linux/src/vmap.rs:79
trait method litebox_common_linux::vmap::VmapManager::protect in file /home/runner/work/litebox/litebox/litebox_common_linux/src/vmap.rs:96
--- failure trait_unsafe_added: pub trait became unsafe ---
Description:
A publicly-visible trait became `unsafe`, so implementing it now requires an `unsafe impl` block.
ref: https://doc.rust-lang.org/book/ch19-01-unsafe-rust.html#implementing-an-unsafe-trait
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/trait_unsafe_added.ron
Failed in:
trait litebox_common_linux::vmap::VmapManager in file /home/runner/work/litebox/litebox/litebox_common_linux/src/vmap.rs:19
--- failure feature_missing: package feature removed or renamed ---
Description:
A feature has been removed from this package's Cargo.toml. This will break downstream crates which enable that feature.
ref: https://doc.rust-lang.org/cargo/reference/semver.html#cargo-feature-remove
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/feature_missing.ron
Failed in:
feature optee_syscall in the package's Cargo.toml
--- failure inherent_method_missing: pub method removed or renamed ---
Description:
A publicly-visible method or associated fn is no longer available under its prior name. It may have been renamed or removed entirely.
ref: https://doc.rust-lang.org/cargo/reference/semver.html#item-remove
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/inherent_method_missing.ron
Failed in:
LinuxKernel::copy_from_vtl0_phys, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_platform_lvbs/src/lib.rs:725
LinuxKernel::copy_to_vtl0_phys, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_platform_lvbs/src/lib.rs:765
LinuxKernel::copy_slice_to_vtl0_phys, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_platform_lvbs/src/lib.rs:800
LinuxKernel::copy_slice_from_vtl0_phys, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_platform_lvbs/src/lib.rs:835
--- failure module_missing: pub module removed or renamed ---
Description:
A publicly-visible module cannot be imported by its prior path. A `pub use` may have been removed, or the module may have been renamed, removed, or made non-public.
ref: https://doc.rust-lang.org/cargo/reference/semver.html#item-remove
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/module_missing.ron
Failed in:
mod litebox_shim_optee::ptr, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_shim_optee/src/ptr.rs:4
--- failure struct_missing: pub struct removed or renamed ---
Description:
A publicly-visible struct cannot be imported by its prior path. A `pub use` may have been removed, or the struct itself may have been renamed or removed entirely.
ref: https://doc.rust-lang.org/cargo/reference/semver.html#item-remove
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/struct_missing.ron
Failed in:
struct litebox_shim_optee::ptr::PhysConstPtr, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_shim_optee/src/ptr.rs:499
struct litebox_shim_optee::NormalWorldConstPtr, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_shim_optee/src/ptr.rs:499
struct litebox_shim_optee::ptr::PhysMutPtr, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_shim_optee/src/ptr.rs:107
struct litebox_shim_optee::NormalWorldMutPtr, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_shim_optee/src/ptr.rs:107

@sangho2
Sangho Lee (sangho2) added this pull request to the merge queueJul 11, 2026
Merged via the queue into main with commit d63ea37Jul 11, 2026
15 of 18 checks passed
@sangho2
Sangho Lee (sangho2) deleted the sanghle/lvbs/vmap_copy branch July 11, 2026 00:12
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@sangho2@lschuermann@wdcui
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Refactor: Use physical pointer abstraction in LVBS by sangho2 · Pull Request #817 · microsoft/litebox · GitHub
Skip to content

Refactor: Use physical pointer abstraction in LVBS - #817

Merged
Sangho Lee (sangho2) merged 25 commits into
mainfrom
sanghle/lvbs/vmap_copy
Jul 11, 2026
Merged

Refactor: Use physical pointer abstraction in LVBS#817
Sangho Lee (sangho2) merged 25 commits into
mainfrom
sanghle/lvbs/vmap_copy

Conversation

@sangho2

@sangho2Sangho Lee (sangho2) commented Apr 28, 2026

Copy link
Copy Markdown
Contributor

This PR lets the LVBS platform (i.e., HEKI/HVCI) use physical pointer abstraction to access VTL0 memory. This is equivalent to the OP-TEE shim's normal-world memory access such that it is not only safer than the legacy VTL0 memory copy functions (i.e., copy_(slice_)(from|to)_vtl0_phys) but also supporting virtually contiguous access of non-contiguous physical page frames.

@sangho2Sangho Lee (sangho2) added the must-not-merge:prototype An experimental/proof-of-concept PR that must not be merged. label Apr 28, 2026
@sangho2
Sangho Lee (sangho2)force-pushed the sanghle/lvbs/vmap_copy branch 2 times, most recently from 29c61b5 to e42c3a0CompareMay 1, 2026 15:51
@sangho2Sangho Lee (sangho2) changed the title [DRAFT] Use physical pointer abstraction in HVCI/HEKIUse physical pointer abstraction in HVCI/HEKIMay 1, 2026
@sangho2Sangho Lee (sangho2) changed the title Use physical pointer abstraction in HVCI/HEKIUse safe physical pointer abstraction in HVCI/HEKIMay 1, 2026
@sangho2Sangho Lee (sangho2) removed the must-not-merge:prototype An experimental/proof-of-concept PR that must not be merged. label May 1, 2026
@sangho2
Sangho Lee (sangho2) marked this pull request as ready for review May 1, 2026 20:11
@sangho2Sangho Lee (sangho2) added must-not-merge:prototype An experimental/proof-of-concept PR that must not be merged. and removed must-not-merge:prototype An experimental/proof-of-concept PR that must not be merged. labels May 1, 2026
@sangho2Sangho Lee (sangho2) changed the title Use safe physical pointer abstraction in HVCI/HEKIUse physical pointer abstraction in HVCI/HEKIMay 1, 2026
@sangho2Sangho Lee (sangho2) changed the title Use physical pointer abstraction in HVCI/HEKIUse physical pointer abstraction in LVBSMay 15, 2026
Comment threadlitebox_common_linux/src/physical_pointers.rs Outdated
Comment threadlitebox_platform_lvbs/src/mshv/vsm.rs
@sangho2Sangho Lee (sangho2) added must-not-merge:undergoing-restructuring Known deeper set of changes are happening on this PR before it is mergeable again and removed must-not-merge:undergoing-restructuring Known deeper set of changes are happening on this PR before it is mergeable again labels May 15, 2026
@sangho2
Sangho Lee (sangho2)force-pushed the sanghle/lvbs/vmap_copy branch 2 times, most recently from c6fd071 to 24e1d87CompareMay 21, 2026 20:58

@wdcuiWeidong Cui (wdcui) left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. I left some comments. Thanks!

Comment threadlitebox_common_linux/src/physical_pointers.rs Outdated
Comment threadlitebox_platform_lvbs/src/mshv/ringbuffer.rs Outdated
Comment threadlitebox_platform_lvbs/src/mshv/vsm.rs Outdated
@sangho2Sangho Lee (sangho2) added the must-not-merge:undergoing-restructuring Known deeper set of changes are happening on this PR before it is mergeable again label Jun 15, 2026

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I took a pass over the entirety of physical_pointers.rs, not just the diff of this PR. In summary, I think this is close to a neat and (in the future) sound abstraction with rich pointer semantics over dynamically mapped physical memory.

Happy to discuss my comments below, I'll go over the remaining changes soon. I don't think any of these is critical to be addressed in this PR, instead I'm happy to implement the changes in a follow-up PR!

Comment threadlitebox_common_linux/src/physical_pointers.rs
Comment threadlitebox_common_linux/src/physical_pointers.rs Outdated
Comment threadlitebox_common_linux/src/physical_pointers.rs Outdated
Comment threadlitebox_common_linux/src/physical_pointers.rs
Comment threadlitebox_common_linux/src/physical_pointers.rs
Comment threadlitebox_common_linux/src/physical_pointers.rs
Comment threadlitebox_common_linux/src/physical_pointers.rs
Comment threadlitebox_common_linux/src/physical_pointers.rs
Comment threadlitebox_common_linux/src/physical_pointers.rs Outdated

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the rest of the PR. I realize some of my feedback might be obsolete due to #824, so I'll check that out next. Should I create a PR to address the left-over comments targeting this same sanghle/lvbs/vmap_copy branch?

Comment threadlitebox_platform_lvbs/src/mshv/ringbuffer.rs
Comment threadlitebox_platform_lvbs/src/mshv/ringbuffer.rs
Comment threadlitebox_common_linux/src/vmap.rs Outdated
Comment threadlitebox_common_linux/src/vmap.rs Outdated
Comment threadlitebox_platform_lvbs/src/mshv/vsm.rs
Comment threadlitebox_platform_lvbs/src/lib.rs Outdated
Comment threadlitebox_shim_optee/src/lib.rs Outdated
@sangho2Sangho Lee (sangho2) removed the must-not-merge:undergoing-restructuring Known deeper set of changes are happening on this PR before it is mergeable again label Jun 26, 2026
@github-actions

Copy link
Copy Markdown

🤖 SemverChecks 🤖 ⚠️ Potential breaking API changes detected ⚠️

Click for details
--- failure enum_variant_missing: pub enum variant removed or renamed ---
Description:
A publicly-visible enum has at least one variant that is no longer available under its prior name. It may have been renamed or removed entirely.
ref: https://doc.rust-lang.org/cargo/reference/semver.html#item-remove
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/enum_variant_missing.ron
Failed in:
variant PhysPointerError::UnalignedPhysicalAddress, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_common_linux/src/vmap.rs:150
variant PhysPointerError::UnalignedOffset, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_common_linux/src/vmap.rs:152
variant PhysPointerError::NoMappingInfo, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_common_linux/src/vmap.rs:166
--- failure struct_missing: pub struct removed or renamed ---
Description:
A publicly-visible struct cannot be imported by its prior path. A `pub use` may have been removed, or the struct itself may have been renamed or removed entirely.
ref: https://doc.rust-lang.org/cargo/reference/semver.html#item-remove
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/struct_missing.ron
Failed in:
struct litebox_common_linux::vmap::PhysPageMapInfo, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_common_linux/src/vmap.rs:95
--- failure trait_associated_type_added: non-sealed public trait added associated type without default value ---
Description:
A non-sealed trait has gained an associated type without a default value, which breaks downstream implementations of the trait
ref: https://doc.rust-lang.org/cargo/reference/semver.html#trait-new-item-no-default
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/trait_associated_type_added.ron
Failed in:
trait associated type litebox_common_linux::vmap::VmapManager::MapInfo in file /home/runner/work/litebox/litebox/litebox_common_linux/src/vmap.rs:22
--- failure trait_method_default_impl_removed: pub trait default method impl removed ---
Description:
A method's default impl in an unsealed trait has been removed, breaking trait implementations that relied on that default
ref: https://doc.rust-lang.org/book/ch10-02-traits.html#default-implementations
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/trait_method_default_impl_removed.ron
Failed in:
trait method litebox_common_linux::vmap::VmapManager::validate_unowned in file /home/runner/work/litebox/litebox/litebox_common_linux/src/vmap.rs:79
trait method litebox_common_linux::vmap::VmapManager::protect in file /home/runner/work/litebox/litebox/litebox_common_linux/src/vmap.rs:96
--- failure trait_unsafe_added: pub trait became unsafe ---
Description:
A publicly-visible trait became `unsafe`, so implementing it now requires an `unsafe impl` block.
ref: https://doc.rust-lang.org/book/ch19-01-unsafe-rust.html#implementing-an-unsafe-trait
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/trait_unsafe_added.ron
Failed in:
trait litebox_common_linux::vmap::VmapManager in file /home/runner/work/litebox/litebox/litebox_common_linux/src/vmap.rs:19
--- failure feature_missing: package feature removed or renamed ---
Description:
A feature has been removed from this package's Cargo.toml. This will break downstream crates which enable that feature.
ref: https://doc.rust-lang.org/cargo/reference/semver.html#cargo-feature-remove
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/feature_missing.ron
Failed in:
feature optee_syscall in the package's Cargo.toml
--- failure inherent_method_missing: pub method removed or renamed ---
Description:
A publicly-visible method or associated fn is no longer available under its prior name. It may have been renamed or removed entirely.
ref: https://doc.rust-lang.org/cargo/reference/semver.html#item-remove
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/inherent_method_missing.ron
Failed in:
LinuxKernel::copy_from_vtl0_phys, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_platform_lvbs/src/lib.rs:725
LinuxKernel::copy_to_vtl0_phys, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_platform_lvbs/src/lib.rs:765
LinuxKernel::copy_slice_to_vtl0_phys, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_platform_lvbs/src/lib.rs:800
LinuxKernel::copy_slice_from_vtl0_phys, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_platform_lvbs/src/lib.rs:835
--- failure module_missing: pub module removed or renamed ---
Description:
A publicly-visible module cannot be imported by its prior path. A `pub use` may have been removed, or the module may have been renamed, removed, or made non-public.
ref: https://doc.rust-lang.org/cargo/reference/semver.html#item-remove
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/module_missing.ron
Failed in:
mod litebox_shim_optee::ptr, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_shim_optee/src/ptr.rs:4
--- failure struct_missing: pub struct removed or renamed ---
Description:
A publicly-visible struct cannot be imported by its prior path. A `pub use` may have been removed, or the struct itself may have been renamed or removed entirely.
ref: https://doc.rust-lang.org/cargo/reference/semver.html#item-remove
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/struct_missing.ron
Failed in:
struct litebox_shim_optee::ptr::PhysConstPtr, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_shim_optee/src/ptr.rs:499
struct litebox_shim_optee::NormalWorldConstPtr, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_shim_optee/src/ptr.rs:499
struct litebox_shim_optee::ptr::PhysMutPtr, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_shim_optee/src/ptr.rs:107
struct litebox_shim_optee::NormalWorldMutPtr, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_shim_optee/src/ptr.rs:107

@sangho2
Sangho Lee (sangho2) added this pull request to the merge queueJul 11, 2026
Merged via the queue into main with commit d63ea37Jul 11, 2026
15 of 18 checks passed
@sangho2
Sangho Lee (sangho2) deleted the sanghle/lvbs/vmap_copy branch July 11, 2026 00:12
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@sangho2@lschuermann@wdcui
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); Refactor: Use physical pointer abstraction in LVBS by sangho2 · Pull Request #817 · microsoft/litebox · GitHub
Skip to content

Refactor: Use physical pointer abstraction in LVBS - #817

Merged
Sangho Lee (sangho2) merged 25 commits into
mainfrom
sanghle/lvbs/vmap_copy
Jul 11, 2026
Merged

Refactor: Use physical pointer abstraction in LVBS#817
Sangho Lee (sangho2) merged 25 commits into
mainfrom
sanghle/lvbs/vmap_copy

Conversation

@sangho2

@sangho2Sangho Lee (sangho2) commented Apr 28, 2026

Copy link
Copy Markdown
Contributor

This PR lets the LVBS platform (i.e., HEKI/HVCI) use physical pointer abstraction to access VTL0 memory. This is equivalent to the OP-TEE shim's normal-world memory access such that it is not only safer than the legacy VTL0 memory copy functions (i.e., copy_(slice_)(from|to)_vtl0_phys) but also supporting virtually contiguous access of non-contiguous physical page frames.

@sangho2Sangho Lee (sangho2) added the must-not-merge:prototype An experimental/proof-of-concept PR that must not be merged. label Apr 28, 2026
@sangho2
Sangho Lee (sangho2)force-pushed the sanghle/lvbs/vmap_copy branch 2 times, most recently from 29c61b5 to e42c3a0CompareMay 1, 2026 15:51
@sangho2Sangho Lee (sangho2) changed the title [DRAFT] Use physical pointer abstraction in HVCI/HEKIUse physical pointer abstraction in HVCI/HEKIMay 1, 2026
@sangho2Sangho Lee (sangho2) changed the title Use physical pointer abstraction in HVCI/HEKIUse safe physical pointer abstraction in HVCI/HEKIMay 1, 2026
@sangho2Sangho Lee (sangho2) removed the must-not-merge:prototype An experimental/proof-of-concept PR that must not be merged. label May 1, 2026
@sangho2
Sangho Lee (sangho2) marked this pull request as ready for review May 1, 2026 20:11
@sangho2Sangho Lee (sangho2) added must-not-merge:prototype An experimental/proof-of-concept PR that must not be merged. and removed must-not-merge:prototype An experimental/proof-of-concept PR that must not be merged. labels May 1, 2026
@sangho2Sangho Lee (sangho2) changed the title Use safe physical pointer abstraction in HVCI/HEKIUse physical pointer abstraction in HVCI/HEKIMay 1, 2026
@sangho2Sangho Lee (sangho2) changed the title Use physical pointer abstraction in HVCI/HEKIUse physical pointer abstraction in LVBSMay 15, 2026
Comment threadlitebox_common_linux/src/physical_pointers.rs Outdated
Comment threadlitebox_platform_lvbs/src/mshv/vsm.rs
@sangho2Sangho Lee (sangho2) added must-not-merge:undergoing-restructuring Known deeper set of changes are happening on this PR before it is mergeable again and removed must-not-merge:undergoing-restructuring Known deeper set of changes are happening on this PR before it is mergeable again labels May 15, 2026
@sangho2
Sangho Lee (sangho2)force-pushed the sanghle/lvbs/vmap_copy branch 2 times, most recently from c6fd071 to 24e1d87CompareMay 21, 2026 20:58

@wdcuiWeidong Cui (wdcui) left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. I left some comments. Thanks!

Comment threadlitebox_common_linux/src/physical_pointers.rs Outdated
Comment threadlitebox_platform_lvbs/src/mshv/ringbuffer.rs Outdated
Comment threadlitebox_platform_lvbs/src/mshv/vsm.rs Outdated
@sangho2Sangho Lee (sangho2) added the must-not-merge:undergoing-restructuring Known deeper set of changes are happening on this PR before it is mergeable again label Jun 15, 2026

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I took a pass over the entirety of physical_pointers.rs, not just the diff of this PR. In summary, I think this is close to a neat and (in the future) sound abstraction with rich pointer semantics over dynamically mapped physical memory.

Happy to discuss my comments below, I'll go over the remaining changes soon. I don't think any of these is critical to be addressed in this PR, instead I'm happy to implement the changes in a follow-up PR!

Comment threadlitebox_common_linux/src/physical_pointers.rs
Comment threadlitebox_common_linux/src/physical_pointers.rs Outdated
Comment threadlitebox_common_linux/src/physical_pointers.rs Outdated
Comment threadlitebox_common_linux/src/physical_pointers.rs
Comment threadlitebox_common_linux/src/physical_pointers.rs
Comment threadlitebox_common_linux/src/physical_pointers.rs
Comment threadlitebox_common_linux/src/physical_pointers.rs
Comment threadlitebox_common_linux/src/physical_pointers.rs
Comment threadlitebox_common_linux/src/physical_pointers.rs Outdated

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the rest of the PR. I realize some of my feedback might be obsolete due to #824, so I'll check that out next. Should I create a PR to address the left-over comments targeting this same sanghle/lvbs/vmap_copy branch?

Comment threadlitebox_platform_lvbs/src/mshv/ringbuffer.rs
Comment threadlitebox_platform_lvbs/src/mshv/ringbuffer.rs
Comment threadlitebox_common_linux/src/vmap.rs Outdated
Comment threadlitebox_common_linux/src/vmap.rs Outdated
Comment threadlitebox_platform_lvbs/src/mshv/vsm.rs
Comment threadlitebox_platform_lvbs/src/lib.rs Outdated
Comment threadlitebox_shim_optee/src/lib.rs Outdated
@sangho2Sangho Lee (sangho2) removed the must-not-merge:undergoing-restructuring Known deeper set of changes are happening on this PR before it is mergeable again label Jun 26, 2026
@github-actions

Copy link
Copy Markdown

🤖 SemverChecks 🤖 ⚠️ Potential breaking API changes detected ⚠️

Click for details
--- failure enum_variant_missing: pub enum variant removed or renamed ---
Description:
A publicly-visible enum has at least one variant that is no longer available under its prior name. It may have been renamed or removed entirely.
ref: https://doc.rust-lang.org/cargo/reference/semver.html#item-remove
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/enum_variant_missing.ron
Failed in:
variant PhysPointerError::UnalignedPhysicalAddress, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_common_linux/src/vmap.rs:150
variant PhysPointerError::UnalignedOffset, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_common_linux/src/vmap.rs:152
variant PhysPointerError::NoMappingInfo, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_common_linux/src/vmap.rs:166
--- failure struct_missing: pub struct removed or renamed ---
Description:
A publicly-visible struct cannot be imported by its prior path. A `pub use` may have been removed, or the struct itself may have been renamed or removed entirely.
ref: https://doc.rust-lang.org/cargo/reference/semver.html#item-remove
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/struct_missing.ron
Failed in:
struct litebox_common_linux::vmap::PhysPageMapInfo, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_common_linux/src/vmap.rs:95
--- failure trait_associated_type_added: non-sealed public trait added associated type without default value ---
Description:
A non-sealed trait has gained an associated type without a default value, which breaks downstream implementations of the trait
ref: https://doc.rust-lang.org/cargo/reference/semver.html#trait-new-item-no-default
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/trait_associated_type_added.ron
Failed in:
trait associated type litebox_common_linux::vmap::VmapManager::MapInfo in file /home/runner/work/litebox/litebox/litebox_common_linux/src/vmap.rs:22
--- failure trait_method_default_impl_removed: pub trait default method impl removed ---
Description:
A method's default impl in an unsealed trait has been removed, breaking trait implementations that relied on that default
ref: https://doc.rust-lang.org/book/ch10-02-traits.html#default-implementations
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/trait_method_default_impl_removed.ron
Failed in:
trait method litebox_common_linux::vmap::VmapManager::validate_unowned in file /home/runner/work/litebox/litebox/litebox_common_linux/src/vmap.rs:79
trait method litebox_common_linux::vmap::VmapManager::protect in file /home/runner/work/litebox/litebox/litebox_common_linux/src/vmap.rs:96
--- failure trait_unsafe_added: pub trait became unsafe ---
Description:
A publicly-visible trait became `unsafe`, so implementing it now requires an `unsafe impl` block.
ref: https://doc.rust-lang.org/book/ch19-01-unsafe-rust.html#implementing-an-unsafe-trait
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/trait_unsafe_added.ron
Failed in:
trait litebox_common_linux::vmap::VmapManager in file /home/runner/work/litebox/litebox/litebox_common_linux/src/vmap.rs:19
--- failure feature_missing: package feature removed or renamed ---
Description:
A feature has been removed from this package's Cargo.toml. This will break downstream crates which enable that feature.
ref: https://doc.rust-lang.org/cargo/reference/semver.html#cargo-feature-remove
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/feature_missing.ron
Failed in:
feature optee_syscall in the package's Cargo.toml
--- failure inherent_method_missing: pub method removed or renamed ---
Description:
A publicly-visible method or associated fn is no longer available under its prior name. It may have been renamed or removed entirely.
ref: https://doc.rust-lang.org/cargo/reference/semver.html#item-remove
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/inherent_method_missing.ron
Failed in:
LinuxKernel::copy_from_vtl0_phys, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_platform_lvbs/src/lib.rs:725
LinuxKernel::copy_to_vtl0_phys, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_platform_lvbs/src/lib.rs:765
LinuxKernel::copy_slice_to_vtl0_phys, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_platform_lvbs/src/lib.rs:800
LinuxKernel::copy_slice_from_vtl0_phys, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_platform_lvbs/src/lib.rs:835
--- failure module_missing: pub module removed or renamed ---
Description:
A publicly-visible module cannot be imported by its prior path. A `pub use` may have been removed, or the module may have been renamed, removed, or made non-public.
ref: https://doc.rust-lang.org/cargo/reference/semver.html#item-remove
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/module_missing.ron
Failed in:
mod litebox_shim_optee::ptr, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_shim_optee/src/ptr.rs:4
--- failure struct_missing: pub struct removed or renamed ---
Description:
A publicly-visible struct cannot be imported by its prior path. A `pub use` may have been removed, or the struct itself may have been renamed or removed entirely.
ref: https://doc.rust-lang.org/cargo/reference/semver.html#item-remove
impl: https://github.com/obi1kenobi/cargo-semver-checks/tree/v0.48.0/src/lints/struct_missing.ron
Failed in:
struct litebox_shim_optee::ptr::PhysConstPtr, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_shim_optee/src/ptr.rs:499
struct litebox_shim_optee::NormalWorldConstPtr, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_shim_optee/src/ptr.rs:499
struct litebox_shim_optee::ptr::PhysMutPtr, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_shim_optee/src/ptr.rs:107
struct litebox_shim_optee::NormalWorldMutPtr, previously in file /home/runner/work/litebox/litebox/target/semver-checks/git-main/75e794eba6094f300dacd36e52f63925ecd6878e/litebox_shim_optee/src/ptr.rs:107

@sangho2
Sangho Lee (sangho2) added this pull request to the merge queueJul 11, 2026
Merged via the queue into main with commit d63ea37Jul 11, 2026
15 of 18 checks passed
@sangho2
Sangho Lee (sangho2) deleted the sanghle/lvbs/vmap_copy branch July 11, 2026 00:12
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@sangho2@lschuermann@wdcui