TECHNOLOGIES FOR OBJECT-ORIENTED MEMORY MANAGEMENT WITH EXTENDED SEGMENTATION
Technologies for memory management with memory protection extension include a computing device having a processor with one or more protection extensions. The processor may load a logical address including a segment base, effective limit, and effective address and generate a linear address as a function of the logical address with the effective limit as a mask. The processor may switch to a new task described by a task state segment extension. The task state extension may specify a low-latency segmentation mode. The processor may prohibit access to a descriptor in a local descriptor table with a descriptor privilege level lower than the current privilege level of the processor. The computing device may load a secure enclave using secure enclave support of the processor. The secure enclave may load an unsandbox and a sandboxed application in a user privilege level of the processor. Other embodiments are described and claimed.
1 . An apparatus comprising:
a processor coupled to a memory, the processor comprising a protection domain manager circuitry, the protection domain manager circuitry to:
switch to a new protection domain, wherein the new protection domain comprises a unit of code and data that is used by multiple software threads;
load a segmentation state of the processor for the new protection domain from a domain object segment, wherein the segmentation state comprises a local descriptor table selector and a code segment selector;
load an entry point instruction pointer for the new protection domain from the domain object segment;
determine whether a subsystem identifier of the domain object segment is different from a current subsystem identifier of a current protection domain;
index a subsystem table in the memory with the subsystem identifier to retrieve a subsystem table entry in response to a determination that the subsystem identifier of the domain object segment is different from the current subsystem identifier;
load a stack segmentation state from the subsystem table entry in response to indexing of the subsystem table, wherein the stack segmentation state comprises a stack segment selector and a stack pointer; and
activate a low-latency segmentation mode in response to the indexing of the subsystem table, wherein the subsystem table entry is indicative of the low-latency segmentation mode, wherein to load the logical address comprises to load the logical address in response to activation of the low-latency segmentation mode.
2 . The apparatus of claim 1 , wherein the protection domain manager circuitry is further to store a current stack pointer of the processor in the subsystem table in response to a determination that the subsystem identifier of the domain object segment is different from the current subsystem identifier, wherein to load the stack segmentation state further comprises to load the stack segmentation state in response to storage of the current stack pointer.
3 . The apparatus of claim 1 , wherein the protection domain manager circuitry is further to store a stack limit in the subsystem table in response to the determination that the subsystem identifier of the domain object segment is different from the current subsystem identifier.
4 . A method comprising:
switching, by a processor of a computing device, to a new protection domain, wherein the new protection domain comprises a unit of code and data that is used by multiple software threads;
loading, by the processor, a segmentation state of the processor for the new protection domain from a domain object segment, wherein the segmentation state comprises a local descriptor table selector and a code segment selector;
loading, by the processor, an entry point instruction pointer for the new protection domain from the domain object segment;
determining, by the processor, whether a subsystem identifier of the domain object segment is different from a current subsystem identifier of a current protection domain;
indexing, by the processor, a subsystem table in a memory of the computing device with the subsystem identifier to retrieve a subsystem table entry in response to determining that the subsystem identifier of the domain object segment is different from the current subsystem identifier;
loading, by the processor, a stack segmentation state from the subsystem table entry in response to indexing the subsystem table, wherein the stack segmentation state comprises a stack segment selector and a stack pointer; and
activating, by the processor, a low-latency segmentation mode in response to indexing the subsystem table, wherein the subsystem table entry is indicative of the low-latency segmentation mode; wherein loading the logical address comprises loading the logical address in response to activating the low-latency segmentation mode.
5 . The method of claim 4 , further comprising storing, by the processor, a current stack pointer of the processor in the subsystem table in response to determining that the subsystem identifier of the domain object segment is different from the current subsystem identifier, wherein loading the stack segmentation state further comprises loading the stack segmentation state in response to storing the current stack pointer.
6 . The method of claim 4 , further comprising storing, by the processor, a stack limit in the subsystem table in response to determining that the subsystem identifier of the domain object segment is different from the current subsystem identifier.
7 . At least one computer-readable medium having stored thereon instructions which, when executed, cause a computing device to perform operations comprising:
switching to a new protection domain, wherein the new protection domain comprises a unit of code and data that is used by multiple software threads;
loading a segmentation state of the processor for the new protection domain from a domain object segment, wherein the segmentation state comprises a local descriptor table selector and a code segment selector;
loading an entry point instruction pointer for the new protection domain from the domain object segment;
determining whether a subsystem identifier of the domain object segment is different from a current subsystem identifier of a current protection domain;
indexing a subsystem table in a memory of the computing device with the subsystem identifier to retrieve a subsystem table entry in response to determining that the subsystem identifier of the domain object segment is different from the current subsystem identifier;
loading a stack segmentation state from the subsystem table entry in response to indexing the subsystem table, wherein the stack segmentation state comprises a stack segment selector and a stack pointer; and
activating a low-latency segmentation mode in response to indexing the subsystem table, wherein the subsystem table entry is indicative of the low-latency segmentation mode; wherein loading the logical address comprises loading the logical address in response to activating the low-latency segmentation mode.
8 . The computer-readable medium of claim 7 , wherein the operations further comprise storing a current stack pointer of the processor in the subsystem table in response to determining that the subsystem identifier of the domain object segment is different from the current subsystem identifier, wherein loading the stack segmentation state further comprises loading the stack segmentation state in response to storing the current stack pointer.
9 . The computer-readable medium of claim 7 , wherein the operations further comprise storing a stack limit in the subsystem table in response to determining that the subsystem identifier of the domain object segment is different from the current subsystem identifier.
10 . A data processing system comprising:
one or more processors;
a memory coupled to the one or more processors, the one or more processors to:
switch to a new protection domain, wherein the new protection domain comprises a unit of code and data that is used by multiple software threads;
load a segmentation state of the processor for the new protection domain from a domain object segment, wherein the segmentation state comprises a local descriptor table selector and a code segment selector;
load an entry point instruction pointer for the new protection domain from the domain object segment;
determine whether a subsystem identifier of the domain object segment is different from a current subsystem identifier of a current protection domain;
index a subsystem table in the memory with the subsystem identifier to retrieve a subsystem table entry in response to a determination that the subsystem identifier of the domain object segment is different from the current subsystem identifier;
load a stack segmentation state from the subsystem table entry in response to indexing of the subsystem table, wherein the stack segmentation state comprises a stack segment selector and a stack pointer; and
activate a low-latency segmentation mode in response to the indexing of the subsystem table, wherein the subsystem table entry is indicative of the low-latency segmentation mode, wherein to load the logical address comprises to load the logical address in response to activation of the low-latency segmentation mode.
11 . The data processing system of claim 10 , wherein the one or more processors are further to store a current stack pointer of the processor in the subsystem table in response to a determination that the subsystem identifier of the domain object segment is different from the current subsystem identifier, wherein to load the stack segmentation state further comprises to load the stack segmentation state in response to storage of the current stack pointer.
12 . The data processing system of claim 10 , wherein the one or more processors are further to store a stack limit in the subsystem table in response to the determination that the subsystem identifier of the domain object segment is different from the current subsystem identifier.