Copy-on-Pin: The Missing Piece for Correct Copy-on-Write
David Hildenbrand, Martin Schulz, Nadav Amit
Abstract
Operating systems utilize Copy-on-Write (COW) to conserve memory and improve performance. During the last two decades, a series of COW-related bugs - which compromised security, corrupted memory and degraded performance - was found. The majority of these bugs are related to page "pinning", which operating systems employ to access process memory efficiently and to perform direct I/O. Unfortunately, the true cause of these bugs is not well understood, resulting in incomplete bug fixes. We show this by: (1) surveying previously reported pinning-related COW bugs; (2) uncovering new such bugs in Linux, FreeBSD, and NetBSD; and (3) showing that they occur because the COW logic does not consider page pinnings correctly, resulting in incorrect behavior (e.g., I/O of stale data). We then address the underlying problem by deriving when/how shared pages must be copied and under which conditions pinned pages can be shared to maintain correctness. Based on this assessment, we introduce the "Copy-on-Pin (COP)" scheme, an extension of the COW mechanism that handles pinned pages correctly by ensuring pinned pages and shared pages are mutually exclusive. However, we find that a naive implementation of this scheme hampers performance and increases complexity if pages are copied only when strictly necessary. To compensate, we introduce a relaxed-COP design, which does not require precise tracking of page sharing, maintains correctness without increasing complexity, and (while potentially needlessly copying pages in some corner cases) marginally improves performance. Our relaxed-COP solution has been integrated into Linux 5.19.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext fde0307e-0dcf-4a2d-a6ef-f44f10189855Cited by top-tier papers1
Ask how each one uses itBuilds on4
- Dedup Est Machina: Memory Deduplication as an Advanced Exploitation VectorErik Bosman, Kaveh Razavi, Herbert Bos, Cristiano GiuffridaS&P 2016 · 252 citations
- Designing New Operating Primitives to Improve Fuzzing PerformanceWen Xu, Sanidhya Kashyap, Changwoo Min, Taesoo KimCCS 2017 · 139 citations
- On-demand-fork: a microsecond fork for memory-intensive and latency-sensitive applicationsKaiyang Zhao, Sishuai Gong, Pedro FonsecaEuroSys 2021 · 25 citations
- WINNIE : Fuzzing Windows Applications with Harness Synthesis and Fast CloningJinho Jung, Stephen Tong, Hong Hu, Jungwon Lim et al.NDSS 2021
Related papers
- Lelantus: Fine-Granularity Copy-On-Write Operations for Secure Non-Volatile MemoriesJian Zhou, Amro Awad, Jun WangISCA 2020 · 7 citations
- Detecting Kernel Refcount Bugs with Two-Dimensional Consistency CheckingXin Tan, Yuan Zhang, Xiyu Yang, Kangjie Lu et al.USENIX Security 2021 · 26 citations
- Static Detection of Unsafe DMA Accesses in Device DriversJia-Ju Bai, Tuo Li, Kangjie Lu, Shi-Min HuUSENIX Security 2021 · 28 citations
- How to Copy Memory? Coordinated Asynchronous Copy as a First-Class OS ServiceJingkai He, Yunpeng Dong, Dong Du, Mo Zou et al.SOSP 2025 · 2 citations
- Don't shoot down TLB shootdowns!Nadav Amit, Amy Tai, Michael WeiEuroSys 2020 · 32 citations
