[llvm] c862266 - [MergeFunctions] Fix merging functions with different KCFI type identifiers (#217665)

via llvm-commits llvm-commits at lists.llvm.org
Wed Aug 26 08:01:39 PDT 2026


Author: Lane0218
Date: 2026-08-26T08:01:32-07:00
New Revision: c862266fb95d3e5cabbcbfc1c8033276518f4681

URL: https://github.com/llvm/llvm-project/commit/c862266fb95d3e5cabbcbfc1c8033276518f4681
DIFF: https://github.com/llvm/llvm-project/commit/c862266fb95d3e5cabbcbfc1c8033276518f4681.diff

LOG: [MergeFunctions] Fix merging functions with different KCFI type identifiers (#217665)

MergeFunctions currently merges functions with identical bodies even
when
their function-level !kcfi_type metadata contains different type
identifiers.

This can redirect calls or function pointers to a function with a
mismatched
KCFI type identifier, potentially causing KCFI checks to fail at
runtime.

Compare function-level !kcfi_type metadata in FunctionComparator so that
functions with different KCFI type identifiers are not merged.

Add a minimal regression test covering two identical functions with
different
KCFI type identifiers.

Fixes #217629

Added: 
    llvm/test/Transforms/MergeFunc/kcfi-function-merging.ll

Modified: 
    llvm/docs/MergeFunctions.md
    llvm/lib/Transforms/Utils/FunctionComparator.cpp

Removed: 
    


################################################################################
diff  --git a/llvm/docs/MergeFunctions.md b/llvm/docs/MergeFunctions.md
index bb39e40032894..adc8bcec7c5d4 100644
--- a/llvm/docs/MergeFunctions.md
+++ b/llvm/docs/MergeFunctions.md
@@ -279,6 +279,8 @@ properties to be compared on this stage:
    - *Variable arguments*. *LHS* and *RHS* should be both either with or
      without *var-args*.
    - *Calling convention* should be the same.
+   - *KCFI type metadata*. Function-level `!kcfi_type` metadata, if present,
+     should be identical.
 
 2. Function type. Checked by `FunctionComparator::cmpType(Type*, Type*)`
 method. It checks return type and parameters type; the method itself will be

diff  --git a/llvm/lib/Transforms/Utils/FunctionComparator.cpp b/llvm/lib/Transforms/Utils/FunctionComparator.cpp
index 679d4dbfeff54..20f0f6235a870 100644
--- a/llvm/lib/Transforms/Utils/FunctionComparator.cpp
+++ b/llvm/lib/Transforms/Utils/FunctionComparator.cpp
@@ -999,6 +999,10 @@ int FunctionComparator::compareSignature() const {
   if (int Res = cmpAttrs(FnL->getAttributes(), FnR->getAttributes()))
     return Res;
 
+  if (int Res = cmpMDNode(FnL->getMetadata(LLVMContext::MD_kcfi_type),
+                          FnR->getMetadata(LLVMContext::MD_kcfi_type)))
+    return Res;
+
   if (int Res = cmpNumbers(FnL->hasGC(), FnR->hasGC()))
     return Res;
 

diff  --git a/llvm/test/Transforms/MergeFunc/kcfi-function-merging.ll b/llvm/test/Transforms/MergeFunc/kcfi-function-merging.ll
new file mode 100644
index 0000000000000..b7d68128656bb
--- /dev/null
+++ b/llvm/test/Transforms/MergeFunc/kcfi-function-merging.ll
@@ -0,0 +1,112 @@
+; NOTE: Assertions have been autogenerated by utils/update_test_checks.py UTC_ARGS: --version 6
+; RUN: opt -S -passes=mergefunc < %s | FileCheck %s
+
+; Functions with 
diff erent KCFI type identifiers must not be merged.
+
+define internal i32 @a() unnamed_addr !kcfi_type !0 {
+; CHECK-LABEL: define internal i32 @a(
+; CHECK-SAME: ) unnamed_addr !kcfi_type [[META0:![0-9]+]] {
+; CHECK-NEXT:  [[ENTRY:.*:]]
+; CHECK-NEXT:    ret i32 0
+;
+entry:
+  ret i32 0
+}
+
+define internal i32 @b() unnamed_addr !kcfi_type !1 {
+; CHECK-LABEL: define internal i32 @b(
+; CHECK-SAME: ) unnamed_addr !kcfi_type [[META1:![0-9]+]] {
+; CHECK-NEXT:  [[ENTRY:.*:]]
+; CHECK-NEXT:    ret i32 0
+;
+entry:
+  ret i32 0
+}
+
+define i32 @caller() {
+; CHECK-LABEL: define i32 @caller() {
+; CHECK-NEXT:  [[ENTRY:.*:]]
+; CHECK-NEXT:    [[X:%.*]] = call i32 @a()
+; CHECK-NEXT:    [[Y:%.*]] = call i32 @b()
+; CHECK-NEXT:    ret i32 [[Y]]
+;
+entry:
+  %x = call i32 @a()
+  %y = call i32 @b()
+  ret i32 %y
+}
+
+; Functions with matching KCFI type identifiers should still be merged.
+
+define internal i32 @same_a() unnamed_addr !kcfi_type !2 {
+; CHECK-LABEL: define internal i32 @same_a(
+; CHECK-SAME: ) unnamed_addr !kcfi_type [[META2:![0-9]+]] {
+; CHECK-NEXT:  [[ENTRY:.*:]]
+; CHECK-NEXT:    ret i32 0
+;
+entry:
+  ret i32 0
+}
+
+define internal i32 @same_b() unnamed_addr !kcfi_type !2 {
+entry:
+  ret i32 0
+}
+
+define i32 @same_caller() {
+; CHECK-LABEL: define i32 @same_caller() {
+; CHECK-NEXT:  [[ENTRY:.*:]]
+; CHECK-NEXT:    [[X:%.*]] = call i32 @same_a()
+; CHECK-NEXT:    [[Y:%.*]] = call i32 @same_a()
+; CHECK-NEXT:    ret i32 [[Y]]
+;
+entry:
+  %x = call i32 @same_a()
+  %y = call i32 @same_b()
+  ret i32 %y
+}
+
+; A missing KCFI type identifier must not match a present one.
+
+define internal i32 @with_a() unnamed_addr !kcfi_type !3 {
+; CHECK-LABEL: define internal i32 @with_a(
+; CHECK-SAME: ) unnamed_addr !kcfi_type [[META3:![0-9]+]] {
+; CHECK-NEXT:  [[ENTRY:.*:]]
+; CHECK-NEXT:    ret i32 0
+;
+entry:
+  ret i32 0
+}
+
+define internal i32 @without_b() unnamed_addr {
+; CHECK-LABEL: define internal i32 @without_b() unnamed_addr {
+; CHECK-NEXT:  [[ENTRY:.*:]]
+; CHECK-NEXT:    ret i32 0
+;
+entry:
+  ret i32 0
+}
+
+define i32 @mixed_caller() {
+; CHECK-LABEL: define i32 @mixed_caller() {
+; CHECK-NEXT:  [[ENTRY:.*:]]
+; CHECK-NEXT:    [[X:%.*]] = call i32 @with_a()
+; CHECK-NEXT:    [[Y:%.*]] = call i32 @without_b()
+; CHECK-NEXT:    ret i32 [[Y]]
+;
+entry:
+  %x = call i32 @with_a()
+  %y = call i32 @without_b()
+  ret i32 %y
+}
+
+!0 = !{i32 1234}
+!1 = !{i32 6789}
+!2 = !{i32 2468}
+!3 = !{i32 9753}
+;.
+; CHECK: [[META0]] = !{i32 1234}
+; CHECK: [[META1]] = !{i32 6789}
+; CHECK: [[META2]] = !{i32 2468}
+; CHECK: [[META3]] = !{i32 9753}
+;.


        


More information about the llvm-commits mailing list