[llvm] [AArch64] Codegen for AArch64 Return Address Signing Hardening (PR #176187)

Anatoly Trosinenko via llvm-commits llvm-commits at lists.llvm.org
Wed Sep 9 09:50:22 PDT 2026


================
@@ -548,6 +563,99 @@ bool AArch64PointerAuthImpl::run(MachineFunction &MF) {
     Modified = true;
   }
 
+  Modified |= emitSignReturnAddressHardening(MF);
+
+  return Modified;
+}
+
+bool AArch64PointerAuthImpl::emitSignReturnAddressHardening(
+    MachineFunction &MF) {
+  const auto *FI = MF.getInfo<AArch64FunctionInfo>();
+  assert(FI && "FI can't be null");
+  if (!FI->shouldSignReturnAddress(MF) || !FI->shouldHardenSignReturnAddress())
+    return false;
+  assert(Subtarget && "Subtarget must be initialized");
+
+  RegScavenger RS;
+  bool Modified = false;
+  for (MachineBasicBlock &MBB : MF) {
+    MachineBasicBlock::iterator RetInstIter = MBB.getFirstTerminator();
+
+    if (RetInstIter == MBB.end() || RetInstIter->getOpcode() != AArch64::RET)
+      continue;
+
+    assert(RetInstIter->getOperand(0).getReg() == AArch64::LR &&
+           "Return instruction must be returning via LR");
+
+    MachineBasicBlock::iterator InsertionPoint = RetInstIter;
+    // In the case of Windows SEH, the hardening sequence does not immediately
+    // precede the return instruction. Instead, it precedes the SEH_EpilogEnd
+    // pseudo-instruction, which itself is expected to be the predecessor of
+    // the return. Plus, each instruction in the sequence needs one SEH_Nop.
+    const bool NeedsWinCFI = MF.hasWinCFI();
+    if (NeedsWinCFI) {
+      --InsertionPoint;
+      assert(InsertionPoint->getOpcode() == AArch64::SEH_EpilogEnd);
+    }
+    DebugLoc DL = InsertionPoint->getDebugLoc();
+    const auto emitSEHNopIfRequired = [&, NeedsWinCFI]() {
----------------
atrosinenko wrote:

`[&, NeedsWinCFI]` -- explicitly copying `NeedsWinCFI` looks redundant.

[nit] Lambda's name should _probably_ start with upper case letter (as it is a local variable). I cannot find an explicit style guide whether lambda counts as a "variable" or "function" but `clang-tidy` seems to emit warnings for `functionStyle` names.

https://github.com/llvm/llvm-project/pull/176187


More information about the llvm-commits mailing list