bk99.de entertain the web since 1997

How a program sits in virtual memory

Summary

Gustavo Duarte explains virtual address space, kernel space, stack, heap, mappings and address randomisation using a Linux process as an example. A 32-bit address space theoretically covers four gigabytes. Linux splits it between user space and kernel space.

Ideas

  • Every process sees its own virtual address space.
  • Page tables translate virtual addresses into physical memory.
  • A protected address range keeps kernel code permanently reachable.
  • The stack stores call frames and typically grows downwards.
  • The heap serves dynamic memory requests and grows on demand.
  • Memory mappings bring libraries and files into the address space.

Insights

  • Virtual memory isolates processes and abstracts scarce hardware at the same time.
  • Address spaces describe possible mappings, not actually used RAM.
  • Security mechanisms use the same translation layer as memory management.
  • 32-bit limits restrict programs long before physical memory is fully used.

Facts

  • ASLR moves the stack, heap and mappings randomly.
  • A context switch activates the page tables of the next process.

Recommendations

  • Read process mappings via /proc and suitable debugger commands.
  • Distinguish virtual address space, resident memory and file cache.
  • Enable ASLR and non-executable memory regions on production systems.

References

Read the original article

Search the Web Archive