[llvm] [LFI][AArch64] Add rewrites for control flow (PR #192602)

Peter Smith via llvm-commits llvm-commits at lists.llvm.org
Mon Apr 20 02:51:58 PDT 2026


================
@@ -111,6 +111,58 @@ void AArch64MCLFIRewriter::emitMov(MCRegister Dest, MCRegister Src,
   emitInst(Inst, Out, STI);
 }
 
+// {br,blr} xN
+// ->
+// add x28, x27, wN, uxtw
+// {br,blr} x28
+void AArch64MCLFIRewriter::rewriteIndirectBranch(const MCInst &Inst,
+                                                 MCStreamer &Out,
+                                                 const MCSubtargetInfo &STI) {
+  if (!Inst.getOperand(0).isReg())
+    return error(Inst, "unsupported instruction: expected target register");
+  MCRegister BranchReg = Inst.getOperand(0).getReg();
+
+  // Guard the branch target through X28.
+  emitAddMask(LFIAddrReg, BranchReg, Out, STI);
+  emitBranch(Inst.getOpcode(), LFIAddrReg, Out, STI);
+}
+
+void AArch64MCLFIRewriter::rewriteCall(const MCInst &Inst, MCStreamer &Out,
+                                       const MCSubtargetInfo &STI) {
+  if (Inst.getOperand(0).isReg())
+    rewriteIndirectBranch(Inst, Out, STI);
+  else
+    emitInst(Inst, Out, STI);
+}
+
+// ret xN (where xN != x30)
+// ->
+// add x28, x27, wN, uxtw
+// ret x28
+//
+// ret (x30) is safe since x30 is always within the sandbox.
+void AArch64MCLFIRewriter::rewriteReturn(const MCInst &Inst, MCStreamer &Out,
+                                         const MCSubtargetInfo &STI) {
+  if (Inst.getNumOperands() == 0 || !Inst.getOperand(0).isReg())
----------------
smithp35 wrote:

In v9.5 the `retaasppc` and `retabsppc` instructions take an extra operand (immediate or register) describing the offset to the instruction that signed the return address. They are guaranteed to operate on LR and not an arbitrary register though.

If there's a guard that limits programs to the initial LFI supported archiecture armv8.1-a then we won't encounter these, and it could be an assert.


https://github.com/llvm/llvm-project/pull/192602


More information about the llvm-commits mailing list