Skip to main content
Sogen’s memory manager emulates the Windows virtual memory subsystem, providing applications with the familiar Windows memory model while mapping operations to the underlying CPU backend.

Overview

The memory_manager class (defined in memory_manager.hpp:50) sits between Windows syscalls and the CPU backend’s memory interface: It maintains Windows-specific metadata (region types, permissions, committed vs. reserved) while delegating actual memory operations to the backend.

Memory Regions

Region Types

Windows distinguishes between several memory region types (from memory_manager.hpp:20):
Each type has different behavior:
  • private_allocation: Standard heap/stack memory, can be freed with VirtualFree
  • section_view: File-backed memory, must be unmapped with UnmapViewOfSection
  • section_image: Executable images, may have relocations and import tables
  • mmio: Special memory with read/write callbacks (e.g., KUSER_SHARED_DATA)

Reserved vs. Committed

Windows has a two-phase allocation model:
  1. Reserve: Allocate address space but no physical memory
  2. Commit: Allocate actual memory within reserved region
From memory_manager.hpp:66-72.

Region Info

Applications query memory via NtQueryVirtualMemory, which returns:

Memory Permissions

Windows uses fine-grained memory protection flags:
These are translated to backend permissions:

Memory Operations

Allocation

From memory_manager.cpp:

Finding Free Space

When applications request memory without specifying an address:
Address space layout:
From memory_manager.hpp:13-16.

Committing Memory

Decommitting Memory

Protection Changes

Special Memory Regions

KUSER_SHARED_DATA

Windows exposes read-only kernel data at a fixed address (0x7FFE0000). Sogen implements this as MMIO:

Process Environment Block (PEB)

The PEB is allocated in a special segment:

Thread Environment Block (TEB)

Each thread has a TEB accessed via the GS segment register:

Memory-Mapped Files

Sections can be mapped into memory:

Memory Statistics

The memory manager tracks usage:

Layout Versioning

The memory manager maintains a version counter for the memory layout:
This allows other components to detect when the memory layout has changed and invalidate caches.

Next Steps