[llvm] [SafeStack] Don't move a scalable byval argument to the unsafe stack (PR #225067)

Jakob Koschel via llvm-commits llvm-commits at lists.llvm.org
Wed Sep 23 06:24:59 PDT 2026


================
@@ -418,8 +418,13 @@ void SafeStack::findInsts(Function &F,
   for (Argument &Arg : F.args()) {
     if (!Arg.hasByValAttr())
       continue;
-    uint64_t Size = DL.getTypeStoreSize(Arg.getParamByValType());
-    if (IsSafeStackAlloca(&Arg, Size))
+    TypeSize Size = DL.getTypeStoreSize(Arg.getParamByValType());
+    // The unsafe stack frame is laid out at compile time, so an argument of a
----------------
jakos-sec wrote:

I'd make this comment more explicit and also highlight that this has potential security implications of keeping this on the safe stack. e.g.:

> SafeStack lays out the unsafe frame itself, using constant byte offsets from the unsafe stack pointer, so it cannot represent an object whose size is a multiple of vscale. Leave scalable byval arguments on the regular stack instead of crashing. This means such an object is not protected by safe stack even when its address escapes.

https://github.com/llvm/llvm-project/pull/225067


More information about the llvm-commits mailing list