2012-05-22 17:19:09 +00:00
|
|
|
//===- BoundsChecking.cpp - Instrumentation for run-time bounds checking --===//
|
|
|
|
//
|
|
|
|
// The LLVM Compiler Infrastructure
|
|
|
|
//
|
|
|
|
// This file is distributed under the University of Illinois Open Source
|
|
|
|
// License. See LICENSE.TXT for details.
|
|
|
|
//
|
|
|
|
//===----------------------------------------------------------------------===//
|
|
|
|
//
|
|
|
|
// This file implements a pass that instruments the code to perform run-time
|
|
|
|
// bounds checking on loads, stores, and other memory intrinsics.
|
|
|
|
//
|
|
|
|
//===----------------------------------------------------------------------===//
|
|
|
|
|
|
|
|
#define DEBUG_TYPE "bounds-checking"
|
2012-06-29 12:38:19 +00:00
|
|
|
#include "llvm/IRBuilder.h"
|
|
|
|
#include "llvm/Intrinsics.h"
|
|
|
|
#include "llvm/Pass.h"
|
2012-05-22 17:19:09 +00:00
|
|
|
#include "llvm/ADT/Statistic.h"
|
2012-06-21 15:59:53 +00:00
|
|
|
#include "llvm/Analysis/MemoryBuiltins.h"
|
2012-05-31 22:58:48 +00:00
|
|
|
#include "llvm/Support/CommandLine.h"
|
2012-05-22 17:19:09 +00:00
|
|
|
#include "llvm/Support/Debug.h"
|
|
|
|
#include "llvm/Support/InstIterator.h"
|
|
|
|
#include "llvm/Support/TargetFolder.h"
|
2012-06-29 12:38:19 +00:00
|
|
|
#include "llvm/Support/raw_ostream.h"
|
2012-10-08 16:38:25 +00:00
|
|
|
#include "llvm/DataLayout.h"
|
2012-08-29 15:32:21 +00:00
|
|
|
#include "llvm/Target/TargetLibraryInfo.h"
|
2012-07-20 22:39:33 +00:00
|
|
|
#include "llvm/Transforms/Instrumentation.h"
|
2012-05-22 17:19:09 +00:00
|
|
|
using namespace llvm;
|
|
|
|
|
2012-06-21 15:59:53 +00:00
|
|
|
static cl::opt<bool> SingleTrapBB("bounds-checking-single-trap",
|
|
|
|
cl::desc("Use one trap block per function"));
|
2012-05-31 22:58:48 +00:00
|
|
|
|
2012-05-22 17:19:09 +00:00
|
|
|
STATISTIC(ChecksAdded, "Bounds checks added");
|
|
|
|
STATISTIC(ChecksSkipped, "Bounds checks skipped");
|
|
|
|
STATISTIC(ChecksUnable, "Bounds checks unable to add");
|
|
|
|
|
|
|
|
typedef IRBuilder<true, TargetFolder> BuilderTy;
|
|
|
|
|
|
|
|
namespace {
|
|
|
|
struct BoundsChecking : public FunctionPass {
|
|
|
|
static char ID;
|
|
|
|
|
2012-11-23 10:47:35 +00:00
|
|
|
BoundsChecking() : FunctionPass(ID) {
|
2012-05-22 17:19:09 +00:00
|
|
|
initializeBoundsCheckingPass(*PassRegistry::getPassRegistry());
|
|
|
|
}
|
|
|
|
|
|
|
|
virtual bool runOnFunction(Function &F);
|
|
|
|
|
|
|
|
virtual void getAnalysisUsage(AnalysisUsage &AU) const {
|
2012-10-08 16:38:25 +00:00
|
|
|
AU.addRequired<DataLayout>();
|
2012-08-29 15:32:21 +00:00
|
|
|
AU.addRequired<TargetLibraryInfo>();
|
2012-05-22 17:19:09 +00:00
|
|
|
}
|
2012-05-22 22:02:19 +00:00
|
|
|
|
|
|
|
private:
|
2012-10-08 16:38:25 +00:00
|
|
|
const DataLayout *TD;
|
2012-08-29 15:32:21 +00:00
|
|
|
const TargetLibraryInfo *TLI;
|
2012-06-21 15:59:53 +00:00
|
|
|
ObjectSizeOffsetEvaluator *ObjSizeEval;
|
2012-05-22 22:02:19 +00:00
|
|
|
BuilderTy *Builder;
|
2012-06-23 00:12:34 +00:00
|
|
|
Instruction *Inst;
|
2012-05-22 22:02:19 +00:00
|
|
|
BasicBlock *TrapBB;
|
|
|
|
|
|
|
|
BasicBlock *getTrapBB();
|
2012-05-23 16:24:52 +00:00
|
|
|
void emitBranchToTrap(Value *Cmp = 0);
|
2012-05-31 22:45:40 +00:00
|
|
|
bool computeAllocSize(Value *Ptr, APInt &Offset, Value* &OffsetValue,
|
|
|
|
APInt &Size, Value* &SizeValue);
|
2012-05-22 22:02:19 +00:00
|
|
|
bool instrument(Value *Ptr, Value *Val);
|
2012-05-22 17:19:09 +00:00
|
|
|
};
|
|
|
|
}
|
|
|
|
|
|
|
|
char BoundsChecking::ID = 0;
|
2012-07-03 17:30:18 +00:00
|
|
|
INITIALIZE_PASS(BoundsChecking, "bounds-checking", "Run-time bounds checking",
|
|
|
|
false, false)
|
2012-05-22 17:19:09 +00:00
|
|
|
|
|
|
|
|
|
|
|
/// getTrapBB - create a basic block that traps. All overflowing conditions
|
|
|
|
/// branch to this block. There's only one trap block per function.
|
|
|
|
BasicBlock *BoundsChecking::getTrapBB() {
|
2012-06-21 15:59:53 +00:00
|
|
|
if (TrapBB && SingleTrapBB)
|
2012-05-22 17:19:09 +00:00
|
|
|
return TrapBB;
|
|
|
|
|
2012-06-23 00:12:34 +00:00
|
|
|
Function *Fn = Inst->getParent()->getParent();
|
2012-05-22 17:19:09 +00:00
|
|
|
BasicBlock::iterator PrevInsertPoint = Builder->GetInsertPoint();
|
|
|
|
TrapBB = BasicBlock::Create(Fn->getContext(), "trap", Fn);
|
|
|
|
Builder->SetInsertPoint(TrapBB);
|
|
|
|
|
|
|
|
llvm::Value *F = Intrinsic::getDeclaration(Fn->getParent(), Intrinsic::trap);
|
|
|
|
CallInst *TrapCall = Builder->CreateCall(F);
|
|
|
|
TrapCall->setDoesNotReturn();
|
|
|
|
TrapCall->setDoesNotThrow();
|
2012-06-23 00:12:34 +00:00
|
|
|
TrapCall->setDebugLoc(Inst->getDebugLoc());
|
2012-05-22 17:19:09 +00:00
|
|
|
Builder->CreateUnreachable();
|
|
|
|
|
|
|
|
Builder->SetInsertPoint(PrevInsertPoint);
|
|
|
|
return TrapBB;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
2012-05-23 16:24:52 +00:00
|
|
|
/// emitBranchToTrap - emit a branch instruction to a trap block.
|
|
|
|
/// If Cmp is non-null, perform a jump only if its value evaluates to true.
|
|
|
|
void BoundsChecking::emitBranchToTrap(Value *Cmp) {
|
2012-06-21 15:59:53 +00:00
|
|
|
// check if the comparison is always false
|
|
|
|
ConstantInt *C = dyn_cast_or_null<ConstantInt>(Cmp);
|
|
|
|
if (C) {
|
|
|
|
++ChecksSkipped;
|
|
|
|
if (!C->getZExtValue())
|
|
|
|
return;
|
|
|
|
else
|
|
|
|
Cmp = 0; // unconditional branch
|
|
|
|
}
|
|
|
|
|
2012-05-23 16:24:52 +00:00
|
|
|
Instruction *Inst = Builder->GetInsertPoint();
|
|
|
|
BasicBlock *OldBB = Inst->getParent();
|
|
|
|
BasicBlock *Cont = OldBB->splitBasicBlock(Inst);
|
|
|
|
OldBB->getTerminator()->eraseFromParent();
|
|
|
|
|
|
|
|
if (Cmp)
|
|
|
|
BranchInst::Create(getTrapBB(), Cont, Cmp, OldBB);
|
|
|
|
else
|
|
|
|
BranchInst::Create(getTrapBB(), OldBB);
|
|
|
|
}
|
|
|
|
|
|
|
|
|
2012-05-22 22:02:19 +00:00
|
|
|
/// instrument - adds run-time bounds checks to memory accessing instructions.
|
|
|
|
/// Ptr is the pointer that will be read/written, and InstVal is either the
|
|
|
|
/// result from the load or the value being stored. It is used to determine the
|
|
|
|
/// size of memory block that is touched.
|
|
|
|
/// Returns true if any change was made to the IR, false otherwise.
|
2012-05-22 17:19:09 +00:00
|
|
|
bool BoundsChecking::instrument(Value *Ptr, Value *InstVal) {
|
|
|
|
uint64_t NeededSize = TD->getTypeStoreSize(InstVal->getType());
|
|
|
|
DEBUG(dbgs() << "Instrument " << *Ptr << " for " << Twine(NeededSize)
|
|
|
|
<< " bytes\n");
|
|
|
|
|
2012-06-21 15:59:53 +00:00
|
|
|
SizeOffsetEvalType SizeOffset = ObjSizeEval->compute(Ptr);
|
2012-06-01 17:43:31 +00:00
|
|
|
|
2012-06-21 15:59:53 +00:00
|
|
|
if (!ObjSizeEval->bothKnown(SizeOffset)) {
|
2012-05-22 17:19:09 +00:00
|
|
|
++ChecksUnable;
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
|
2012-06-21 15:59:53 +00:00
|
|
|
Value *Size = SizeOffset.first;
|
|
|
|
Value *Offset = SizeOffset.second;
|
2012-07-03 17:30:18 +00:00
|
|
|
ConstantInt *SizeCI = dyn_cast<ConstantInt>(Size);
|
2012-06-21 15:59:53 +00:00
|
|
|
|
2012-10-29 17:31:46 +00:00
|
|
|
Type *IntTy = TD->getIntPtrType(Ptr->getType());
|
2012-06-21 15:59:53 +00:00
|
|
|
Value *NeededSizeVal = ConstantInt::get(IntTy, NeededSize);
|
|
|
|
|
2012-05-31 22:45:40 +00:00
|
|
|
// three checks are required to ensure safety:
|
|
|
|
// . Offset >= 0 (since the offset is given from the base ptr)
|
|
|
|
// . Size >= Offset (unsigned)
|
|
|
|
// . Size - Offset >= NeededSize (unsigned)
|
2012-07-03 17:30:18 +00:00
|
|
|
//
|
|
|
|
// optimization: if Size >= 0 (signed), skip 1st check
|
2012-05-31 22:45:40 +00:00
|
|
|
// FIXME: add NSW/NUW here? -- we dont care if the subtraction overflows
|
2012-06-21 15:59:53 +00:00
|
|
|
Value *ObjSize = Builder->CreateSub(Size, Offset);
|
|
|
|
Value *Cmp2 = Builder->CreateICmpULT(Size, Offset);
|
|
|
|
Value *Cmp3 = Builder->CreateICmpULT(ObjSize, NeededSizeVal);
|
2012-07-03 17:30:18 +00:00
|
|
|
Value *Or = Builder->CreateOr(Cmp2, Cmp3);
|
|
|
|
if (!SizeCI || SizeCI->getValue().slt(0)) {
|
|
|
|
Value *Cmp1 = Builder->CreateICmpSLT(Offset, ConstantInt::get(IntTy, 0));
|
|
|
|
Or = Builder->CreateOr(Cmp1, Or);
|
|
|
|
}
|
2012-05-23 16:24:52 +00:00
|
|
|
emitBranchToTrap(Or);
|
2012-05-22 17:19:09 +00:00
|
|
|
|
|
|
|
++ChecksAdded;
|
|
|
|
return true;
|
|
|
|
}
|
|
|
|
|
|
|
|
bool BoundsChecking::runOnFunction(Function &F) {
|
2012-10-08 16:38:25 +00:00
|
|
|
TD = &getAnalysis<DataLayout>();
|
2012-08-29 15:32:21 +00:00
|
|
|
TLI = &getAnalysis<TargetLibraryInfo>();
|
2012-05-22 17:19:09 +00:00
|
|
|
|
|
|
|
TrapBB = 0;
|
|
|
|
BuilderTy TheBuilder(F.getContext(), TargetFolder(TD));
|
|
|
|
Builder = &TheBuilder;
|
2012-08-29 15:32:21 +00:00
|
|
|
ObjectSizeOffsetEvaluator TheObjSizeEval(TD, TLI, F.getContext());
|
2012-06-21 15:59:53 +00:00
|
|
|
ObjSizeEval = &TheObjSizeEval;
|
2012-05-22 17:19:09 +00:00
|
|
|
|
|
|
|
// check HANDLE_MEMORY_INST in include/llvm/Instruction.def for memory
|
|
|
|
// touching instructions
|
|
|
|
std::vector<Instruction*> WorkList;
|
|
|
|
for (inst_iterator i = inst_begin(F), e = inst_end(F); i != e; ++i) {
|
|
|
|
Instruction *I = &*i;
|
|
|
|
if (isa<LoadInst>(I) || isa<StoreInst>(I) || isa<AtomicCmpXchgInst>(I) ||
|
|
|
|
isa<AtomicRMWInst>(I))
|
|
|
|
WorkList.push_back(I);
|
|
|
|
}
|
|
|
|
|
|
|
|
bool MadeChange = false;
|
2012-05-22 22:02:19 +00:00
|
|
|
for (std::vector<Instruction*>::iterator i = WorkList.begin(),
|
|
|
|
e = WorkList.end(); i != e; ++i) {
|
2012-06-23 00:12:34 +00:00
|
|
|
Inst = *i;
|
2012-05-22 17:19:09 +00:00
|
|
|
|
2012-06-23 00:12:34 +00:00
|
|
|
Builder->SetInsertPoint(Inst);
|
|
|
|
if (LoadInst *LI = dyn_cast<LoadInst>(Inst)) {
|
2012-05-22 17:19:09 +00:00
|
|
|
MadeChange |= instrument(LI->getPointerOperand(), LI);
|
2012-06-23 00:12:34 +00:00
|
|
|
} else if (StoreInst *SI = dyn_cast<StoreInst>(Inst)) {
|
2012-05-22 17:19:09 +00:00
|
|
|
MadeChange |= instrument(SI->getPointerOperand(), SI->getValueOperand());
|
2012-06-23 00:12:34 +00:00
|
|
|
} else if (AtomicCmpXchgInst *AI = dyn_cast<AtomicCmpXchgInst>(Inst)) {
|
2012-05-22 17:19:09 +00:00
|
|
|
MadeChange |= instrument(AI->getPointerOperand(),AI->getCompareOperand());
|
2012-06-23 00:12:34 +00:00
|
|
|
} else if (AtomicRMWInst *AI = dyn_cast<AtomicRMWInst>(Inst)) {
|
2012-05-22 17:19:09 +00:00
|
|
|
MadeChange |= instrument(AI->getPointerOperand(), AI->getValOperand());
|
|
|
|
} else {
|
|
|
|
llvm_unreachable("unknown Instruction type");
|
|
|
|
}
|
|
|
|
}
|
|
|
|
return MadeChange;
|
|
|
|
}
|
|
|
|
|
2012-11-23 10:47:35 +00:00
|
|
|
FunctionPass *llvm::createBoundsCheckingPass() {
|
|
|
|
return new BoundsChecking();
|
2012-05-22 17:19:09 +00:00
|
|
|
}
|