[llvm] r341116 - SafeStack: Prevent OOB reads with mem intrinsics

Vlad Tsyrklevich via llvm-commits llvm-commits at lists.llvm.org
Thu Aug 30 13:44:51 PDT 2018


Author: vlad.tsyrklevich
Date: Thu Aug 30 13:44:51 2018
New Revision: 341116

URL: http://llvm.org/viewvc/llvm-project?rev=341116&view=rev
Log:
SafeStack: Prevent OOB reads with mem intrinsics

Summary:
Currently, the SafeStack analysis disallows out-of-bounds writes but not
out-of-bounds reads for mem intrinsics like llvm.memcpy. This could
cause leaks of pointers to the safe stack by leaking spilled registers/
frame pointers. Check for allocas used as source or destination pointers
to mem intrinsics.

Reviewers: eugenis

Reviewed By: eugenis

Subscribers: pcc, llvm-commits, kcc

Differential Revision: https://reviews.llvm.org/D51334

Added:
    llvm/trunk/test/Transforms/SafeStack/X86/memintrinsic-oob-read.ll
Modified:
    llvm/trunk/lib/CodeGen/SafeStack.cpp

Modified: llvm/trunk/lib/CodeGen/SafeStack.cpp
URL: http://llvm.org/viewvc/llvm-project/llvm/trunk/lib/CodeGen/SafeStack.cpp?rev=341116&r1=341115&r2=341116&view=diff
==============================================================================
--- llvm/trunk/lib/CodeGen/SafeStack.cpp (original)
+++ llvm/trunk/lib/CodeGen/SafeStack.cpp Thu Aug 30 13:44:51 2018
@@ -260,8 +260,14 @@ bool SafeStack::IsAccessSafe(Value *Addr
 bool SafeStack::IsMemIntrinsicSafe(const MemIntrinsic *MI, const Use &U,
                                    const Value *AllocaPtr,
                                    uint64_t AllocaSize) {
-  // All MemIntrinsics have destination address in Arg0 and size in Arg2.
-  if (MI->getRawDest() != U) return true;
+  if (auto MTI = dyn_cast<MemTransferInst>(MI)) {
+    if (MTI->getRawSource() != U && MTI->getRawDest() != U)
+      return true;
+  } else {
+    if (MI->getRawDest() != U)
+      return true;
+  }
+
   const auto *Len = dyn_cast<ConstantInt>(MI->getLength());
   // Non-constant size => unsafe. FIXME: try SCEV getRange.
   if (!Len) return false;

Added: llvm/trunk/test/Transforms/SafeStack/X86/memintrinsic-oob-read.ll
URL: http://llvm.org/viewvc/llvm-project/llvm/trunk/test/Transforms/SafeStack/X86/memintrinsic-oob-read.ll?rev=341116&view=auto
==============================================================================
--- llvm/trunk/test/Transforms/SafeStack/X86/memintrinsic-oob-read.ll (added)
+++ llvm/trunk/test/Transforms/SafeStack/X86/memintrinsic-oob-read.ll Thu Aug 30 13:44:51 2018
@@ -0,0 +1,14 @@
+; RUN: opt -safe-stack -S -mtriple=i386-pc-linux-gnu < %s -o - | FileCheck %s
+; RUN: opt -safe-stack -S -mtriple=x86_64-pc-linux-gnu < %s -o - | FileCheck %s
+
+target datalayout = "e-m:e-i64:64-f80:128-n8:16:32:64-S128"
+target triple = "x86_64-unknown-linux-gnu"
+
+declare void @llvm.memcpy.p0i8.p0i8.i64(i8* nocapture writeonly, i8* nocapture readonly, i64, i1)
+
+; CHECK: __safestack_unsafe_stack_ptr
+define void @oob_read(i8* %ptr) safestack {
+  %1 = alloca i8
+  call void @llvm.memcpy.p0i8.p0i8.i64(i8* align 1 %ptr, i8* align 1 %1, i64 4, i1 false)
+  ret void
+}




More information about the llvm-commits mailing list