|
PebbleOS
|
Thread-mode privilege control. More...
Functions | |
| static bool | mcu_state_is_thread_privileged (void) |
| Check whether thread mode is privileged. | |
| void | mcu_state_set_thread_privilege (bool privilege) |
| Set the thread-mode privilege bit in the CONTROL register. | |
| bool | mcu_state_is_privileged (void) |
| Check whether the CPU currently runs privileged. | |
| void | mcu_call_unprivileged (void(*fn)(void *), void *ctx) |
| Call a function in unprivileged thread mode while the caller stays privileged. | |
Thread-mode privilege control.
Thread-mode privilege is CONTROL.nPRIV; exception handlers always run privileged. On host builds (unit tests) code is always privileged.
| void mcu_call_unprivileged | ( | void(*)(void *) | fn, |
| void * | ctx | ||
| ) |
Call a function in unprivileged thread mode while the caller stays privileged.
Use it to invoke untrusted callbacks (e.g. JavaScript FFI dispatch) so that any kernel-memory or peripheral access inside fn faults the MPU instead of silently succeeding under the runtime's privileged context.
Must be called from privileged thread mode (asserts and behaves unpredictably otherwise). Privilege is restored on return through a re-entry SVC that is private to this helper: it is not part of the normal syscall island, and is accepted only while this helper is active for the current task.
| fn | Function to call. |
| ctx | Argument passed to fn. |
| bool mcu_state_is_privileged | ( | void | ) |
Check whether the CPU currently runs privileged.
|
inlinestatic |
Check whether thread mode is privileged.
Ignores whether an exception handler is running; see mcu_state_is_privileged().
| void mcu_state_set_thread_privilege | ( | bool | privilege | ) |
Set the thread-mode privilege bit in the CONTROL register.
Dropping privilege is always possible; raising it requires already being privileged.
| privilege | true for privileged, false for unprivileged. |