HomePhabricator

Add Forward Control-Flow Integrity.

Description

Add Forward Control-Flow Integrity.

This commit adds a new pass that can inject checks before indirect calls to
make sure that these calls target known locations. It supports three types of
checks and, at compile time, it can take the name of a custom function to call
when an indirect call check fails. The default failure function ignores the
error and continues.

This pass incidentally moves the function JumpInstrTables::transformType from
private to public and makes it static (with a new argument that specifies the
table type to use); this is so that the CFI code can transform function types
at call sites to determine which jump-instruction table to use for the check at
that site.

Also, this removes support for jumptables in ARM, pending further performance
analysis and discussion.

Review: http://reviews.llvm.org/D4167

Details

Committed
tmroederNov 11 2014, 1:08 PM
Parents
rL221707: [llvm-mc] Fixing case where if a file ended with non-newline whitespace or a…
Branches
Unknown
Tags
Unknown

Event Timeline