How a program sits in virtual memory
Summary
Gustavo Duarte explains virtual address space, kernel space, stack, heap, mappings and address randomisation using a Linux process as an example. A 32-bit address space theoretically covers four gigabytes. Linux splits it between user space and kernel space.
Ideas
- Every process sees its own virtual address space.
- Page tables translate virtual addresses into physical memory.
- A protected address range keeps kernel code permanently reachable.
- The stack stores call frames and typically grows downwards.
- The heap serves dynamic memory requests and grows on demand.
- Memory mappings bring libraries and files into the address space.
Insights
- Virtual memory isolates processes and abstracts scarce hardware at the same time.
- Address spaces describe possible mappings, not actually used RAM.
- Security mechanisms use the same translation layer as memory management.
- 32-bit limits restrict programs long before physical memory is fully used.
Facts
- ASLR moves the stack, heap and mappings randomly.
- A context switch activates the page tables of the next process.
Recommendations
- Read process mappings via /proc and suitable debugger commands.
- Distinguish virtual address space, resident memory and file cache.
- Enable ASLR and non-executable memory regions on production systems.
References
Links to the original source and the Web Archive open in a new tab.