Skip to content

fix(windows-memory): classify pages after masking protection modifiers - #706

Merged
Karib0u merged 4 commits into
mainfrom
claude/rustinel-issue-613-2c78a0
Oct 7, 2026
Merged

Karib0u merged 4 commits into
mainfrom
claude/rustinel-issue-613-2c78a0

Conversation

@Karib0u

@Karib0u Karib0u commented Oct 7, 2026

Copy link
Copy Markdown
Owner

Closes #613

Changes

  • New src/memory/protection.rs: masks the base protection (low byte) from the modifier bits, then classifies. Guard is checked first, then no-access, then readable bases. Pure u32 logic, so the unit tests run on every host.
  • src/memory/windows.rs uses it in place of the exact-match is_readable/is_writable/is_executable.
  • A per-process debug summary: eligible, excluded_protection, excluded_kind (never read) versus read_failed.
  • docs/configuration.md documents which committed Windows regions are scanned.

Testing

  • Unit tests: every readable base with and without PAGE_NOCACHE, PAGE_WRITECOMBINE, and PAGE_TARGETS_INVALID; guard excluded for every base; no-access and execute-only excluded.
  • cargo test --lib memory:: passes on macOS; cargo clippy --target x86_64-pc-windows-gnu --all-targets -- -D clippy::all is clean.
  • Not done: the Windows VM check from the acceptance criteria (a real modified page considered for scanning). That still needs a run on lab-windows.

Mask the page-protection modifier bits before classifying, so readable
pages carrying PAGE_NOCACHE or PAGE_WRITECOMBINE are scanned.
Guard, no-access, and execute-only pages stay excluded.
Log per-process region counts that separate excluded regions from failed reads.

Closes #613
Commit private pages with PAGE_NOCACHE and PAGE_WRITECOMBINE, and guard and
no-access pages, then assert by address whether the reader returns them.
@Karib0u

Karib0u commented Oct 7, 2026

Copy link
Copy Markdown
Owner Author

Windows VM check done on lab-windows: cargo test --lib memory:: passes (12/12), including two new in-process tests that commit real pages and check whether the reader returns them. Pages with PAGE_NOCACHE and PAGE_WRITECOMBINE are scanned; PAGE_GUARD and PAGE_NOACCESS pages are not.

@Karib0u
Karib0u merged commit 8847e18 into main Oct 7, 2026
17 checks passed
@Karib0u
Karib0u deleted the claude/rustinel-issue-613-2c78a0 branch October 7, 2026 11:36
@Karib0u Karib0u added the bug Something isn't working label Oct 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(windows-memory): classify pages after masking protection modifiers

1 participant