PebbleOS
Loading...
Searching...
No Matches
Functions
Privilege

Thread-mode privilege control. More...

Functions

static bool mcu_state_is_thread_privileged (void)
 Check whether thread mode is privileged.
 
void mcu_state_set_thread_privilege (bool privilege)
 Set the thread-mode privilege bit in the CONTROL register.
 
bool mcu_state_is_privileged (void)
 Check whether the CPU currently runs privileged.
 
void mcu_call_unprivileged (void(*fn)(void *), void *ctx)
 Call a function in unprivileged thread mode while the caller stays privileged.
 

Detailed Description

Thread-mode privilege control.

Thread-mode privilege is CONTROL.nPRIV; exception handlers always run privileged. On host builds (unit tests) code is always privileged.

static void prv_callback(void *ctx) {
// runs unprivileged: kernel memory and peripherals fault here
}
mcu_call_unprivileged(prv_callback, ctx);
void mcu_call_unprivileged(void(*fn)(void *), void *ctx)
Call a function in unprivileged thread mode while the caller stays privileged.

Function Documentation

◆ mcu_call_unprivileged()

void mcu_call_unprivileged ( void(*)(void *)  fn,
void *  ctx 
)

Call a function in unprivileged thread mode while the caller stays privileged.

Use it to invoke untrusted callbacks (e.g. JavaScript FFI dispatch) so that any kernel-memory or peripheral access inside fn faults the MPU instead of silently succeeding under the runtime's privileged context.

Must be called from privileged thread mode (asserts and behaves unpredictably otherwise). Privilege is restored on return through a re-entry SVC that is private to this helper: it is not part of the normal syscall island, and is accepted only while this helper is active for the current task.

Parameters
fnFunction to call.
ctxArgument passed to fn.

◆ mcu_state_is_privileged()

bool mcu_state_is_privileged ( void  )

Check whether the CPU currently runs privileged.

Returns
true in privileged thread mode or in an exception handler.

◆ mcu_state_is_thread_privileged()

static bool mcu_state_is_thread_privileged ( void  )
inlinestatic

Check whether thread mode is privileged.

Ignores whether an exception handler is running; see mcu_state_is_privileged().

Returns
true if CONTROL.nPRIV is clear.

◆ mcu_state_set_thread_privilege()

void mcu_state_set_thread_privilege ( bool  privilege)

Set the thread-mode privilege bit in the CONTROL register.

Dropping privilege is always possible; raising it requires already being privileged.

Parameters
privilegetrue for privileged, false for unprivileged.