1//==- X86ReturnThunks.cpp - Replace rets with thunks or inline thunks --=//
2//
3// Part of the LLVM Project, under the Apache License v2.0 with LLVM Exceptions.
4// See https://llvm.org/LICENSE.txt for license information.
5// SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception
6//
7//===----------------------------------------------------------------------===//
8/// \file
9///
10/// Pass that replaces ret instructions with a jmp to __x86_return_thunk.
11///
12/// This corresponds to -mfunction-return=thunk-extern or
13/// __attribute__((function_return("thunk-extern").
14///
15/// This pass is a minimal implementation necessary to help mitigate
16/// RetBleed for the Linux kernel.
17///
18/// Should support for thunk or thunk-inline be necessary in the future, then
19/// this pass should be combined with x86-retpoline-thunks which already has
20/// machinery to emit thunks. Until then, YAGNI.
21///
22/// This pass is very similar to x86-lvi-ret.
23///
24//===----------------------------------------------------------------------===//
25
26#include "X86.h"
27#include "X86InstrInfo.h"
28#include "X86Subtarget.h"
29#include "llvm/ADT/SmallVector.h"
30#include "llvm/ADT/StringRef.h"
31#include "llvm/CodeGen/MachineBasicBlock.h"
32#include "llvm/CodeGen/MachineFunction.h"
33#include "llvm/CodeGen/MachineFunctionPass.h"
34#include "llvm/CodeGen/MachineInstr.h"
35#include "llvm/CodeGen/MachineInstrBuilder.h"
36#include "llvm/CodeGen/MachineModuleInfo.h"
37#include "llvm/IR/Module.h"
38#include "llvm/MC/MCInstrDesc.h"
39#include "llvm/Support/Debug.h"
40#include "llvm/TargetParser/Triple.h"
41
42using namespace llvm;
43
44#define PASS_KEY "x86-return-thunks"
45#define DEBUG_TYPE PASS_KEY
46
47constexpr StringRef X86ReturnThunksPassName = "X86 Return Thunks";
48
49namespace {
50struct X86ReturnThunksLegacy final : public MachineFunctionPass {
51 static char ID;
52 X86ReturnThunksLegacy() : MachineFunctionPass(ID) {}
53 StringRef getPassName() const override { return X86ReturnThunksPassName; }
54 bool runOnMachineFunction(MachineFunction &MF) override;
55};
56} // namespace
57
58char X86ReturnThunksLegacy::ID = 0;
59
60static bool runX86ReturnThunks(MachineFunction &MF) {
61 LLVM_DEBUG(dbgs() << X86ReturnThunksPassName << "\n");
62
63 bool Modified = false;
64
65 if (!MF.getFunction().hasFnAttribute(Kind: llvm::Attribute::FnRetThunkExtern))
66 return Modified;
67
68 StringRef ThunkName = "__x86_return_thunk";
69 if (MF.getFunction().getName() == ThunkName)
70 return Modified;
71
72 const auto &ST = MF.getSubtarget<X86Subtarget>();
73 const bool Is64Bit = ST.getTargetTriple().isX86_64();
74 const unsigned RetOpc = Is64Bit ? X86::RET64 : X86::RET32;
75 SmallVector<MachineInstr *, 16> Rets;
76
77 for (MachineBasicBlock &MBB : MF)
78 for (MachineInstr &Term : MBB.terminators())
79 if (Term.getOpcode() == RetOpc)
80 Rets.push_back(Elt: &Term);
81
82 bool IndCS =
83 MF.getFunction().getParent()->getModuleFlag(Key: "indirect_branch_cs_prefix");
84 const MCInstrDesc &CS = ST.getInstrInfo()->get(Opcode: X86::CS_PREFIX);
85 const MCInstrDesc &JMP = ST.getInstrInfo()->get(Opcode: X86::TAILJMPd);
86
87 for (MachineInstr *Ret : Rets) {
88 if (IndCS)
89 BuildMI(BB: Ret->getParent(), MIMD: Ret->getDebugLoc(), MCID: CS);
90 BuildMI(BB: Ret->getParent(), MIMD: Ret->getDebugLoc(), MCID: JMP)
91 .addExternalSymbol(FnName: ThunkName.data());
92 Ret->eraseFromParent();
93 Modified = true;
94 }
95
96 return Modified;
97}
98
99bool X86ReturnThunksLegacy::runOnMachineFunction(MachineFunction &MF) {
100 return runX86ReturnThunks(MF);
101}
102
103PreservedAnalyses
104X86ReturnThunksPass::run(MachineFunction &MF,
105 MachineFunctionAnalysisManager &MFAM) {
106 return runX86ReturnThunks(MF) ? getMachineFunctionPassPreservedAnalyses()
107 .preserveSet<CFGAnalyses>()
108 : PreservedAnalyses::all();
109}
110
111INITIALIZE_PASS(X86ReturnThunksLegacy, PASS_KEY, "X86 Return Thunks", false,
112 false)
113
114FunctionPass *llvm::createX86ReturnThunksLegacyPass() {
115 return new X86ReturnThunksLegacy();
116}
117