Repository navigation
Conversation
This was referenced Jul 10, 2026
This comment has been minimized.
This comment has been minimized.
jchlanda
force-pushed
the
jakub/pac_ty_disc_PR_8
branch
2 times, most recently
from
July 14, 2026 07:36
7527456 to
979ff1f
Compare
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
jchlanda
force-pushed
the
jakub/pac_ty_disc_PR_8
branch
from
July 14, 2026 08:55
979ff1f to
0e9fa4d
Compare
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
jchlanda
force-pushed
the
jakub/pac_ty_disc_PR_8
branch
from
July 17, 2026 07:08
0e9fa4d to
753b459
Compare
This comment has been minimized.
This comment has been minimized.
jchlanda
force-pushed
the
jakub/pac_ty_disc_PR_8
branch
8 times, most recently
from
July 23, 2026 07:48
e07a163 to
fa14e50
Compare
cezarbbb
reviewed
Sep 23, 2026
Contributor
There was a problem hiding this comment.
On the aarch64 Linux platform, there is no float128, only long double is 128-bit, so it will only send e, not g.
Windows and Apple targets should be excluded, see #163193
| 16 => enc.push_str("DF16_"), | ||
| 32 => enc.push(b'f'), | ||
| 64 => enc.push(b'd'), | ||
| 128 => enc.push(b'g'), |
Contributor
There was a problem hiding this comment.
Suggested change
| 128 => enc.push(b'g'), | |
| 128 => match tcx.sess.target.arch { | |
| Arch::AArch64 if !is_like_darwin && !is_like_windows => enc.push(b'e'), | |
| _ => enc.push(b'g'), | |
| }, |
| // NO_DISC: @{{.*}}T_2D = constant ptr ptrauth (ptr @f_2d, i32 0), align 8 | ||
| #[used] | ||
| static T_2D: fn_2d = f_2d; | ||
| // discriminator: 51179 (0xC7EB), encoding: FggE |
Contributor
There was a problem hiding this comment.
Suggested change
| // discriminator: 51179 (0xC7EB), encoding: FggE | |
| // discriminator: 25877 (0x6515), encoding: FeeE |
| #[used] | ||
| static T_2D: fn_2d = f_2d; | ||
| // discriminator: 51179 (0xC7EB), encoding: FggE | ||
| // DISC: @{{.*}}T_LD = constant ptr ptrauth (ptr @f_ld, i32 0, i64 51179), align 8 |
| // DISC: %{{.*}} = call double ptrauth (ptr @f_2d, i32 0, i64 38695)(double {{.*}}, double {{.*}}) {{.*}} [ "ptrauth"(i32 0, i64 38695) ] | ||
| // NO_DISC: %{{.*}} = call double ptrauth (ptr @f_2d, i32 0)(double {{.*}}, double {{.*}}) {{.*}} [ "ptrauth"(i32 0, i64 0) ] | ||
| let _ = T_2D(1.0, 2.0); | ||
| // DISC: %{{.*}} = call fp128 ptrauth (ptr @f_ld, i32 0, i64 51179)(fp128 {{.*}}) {{.*}} [ "ptrauth"(i32 0, i64 51179) ] |
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This patch introduces the following: * Extends `FnAbi` (`callconv`) with a `ptrauth_type_discriminator` field. This field is only used when emitting pointer authentication call bundles. It is stored in `FnAbi` because the call site is not guaranteed to have access to an `Instance`, so the discriminator cannot always be computed on demand. * Adds support for `llvm.ptrauth.resign`. This intrinsic will be used when support for semantic transmute is added. * Performs a minor API redesign as groundwork for allowing call sites to modify schemas in place.
Also tighten the handling of enums.
Collaborator
|
This PR was rebased onto a different main commit. Here's a range-diff highlighting what actually changed. Rebasing is a normal part of keeping PRs up to date, so no action is needed—this note is just to help reviewers. |
Also remove error messages/tests that used to guarded it.
The codegen now walks the layout of static initializer types to find extern "C" function pointer fields, computes their type discriminators, and applies those discriminators when emitting authenticated function pointer relocations. Also make sure that type discrimination is never applied to init/fini entries.
This covers standalone function pointer constants, promoted temporaries, immutable and mutable statics, arrays of function pointers, and mixed structs containing function pointers. Consult pauth-fn-ptr-type-discrimination-static-allocs.rs test for example uses. Revolves around threading PAC information through: * static_addr_of (StaticCodegenMethods) * from_const and from_const_alloc (both on rustc_codegen_ssa::mir::operand / OperandRef)
Also a fix for non function (closure, coroutines, etc) in discriminator_input. Fix in v-table assert.
Meaning if two types are ABI compatible they must have the same encoding and hash value. Provide a ui test which groups the function pointers by the ABI compatibility rules and enforces the rule.
And corresponding doc_example.
This comment has been minimized.
This comment has been minimized.
Implement pointer authentication resigning for function pointer transmutes that differ in their discriminators. Resigning only happens for function pointers (their transparent wrappers and Option<T>). Aggregates (even those containing function pointer members) are deliberately kept as opaque values with no resigning.
Recognize raw pointers as 0-discriminated. Also, when canonicalizing, move away from hard coded Option<T> check to a generic variant with 2 fields and correct niche.
…addr` call sites Fill in function pointer type discriminators logic across remaining `get_fn_addr` call sites and explicitly avoid applying it where discrimination is not meaningful. Some uses of `get_fn_addr` are intentionally left unsigned, including the EH personality function, entry wrappers, and compiler-generated Rust ABI shims.
And update to the main pauthtest document: * list new tests * remove the need for patching `libc` as the changes to it already went in. Unfortunately `cc-rs` is held back by `compiler/rustc_llvm/Cargo.toml` which pins to an old version: `cc = "=1.2.16"`
The [RFC](rust-lang/rfcs#3453) specifies that it should be represented according to IEEE 754 `binary16`, so it should land on `DF16_` (corresponding to C's `_Float16`, C++'s `std::float16_t` and LLVM's `half`). At the same time add f128 test, that was missing.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
View all comments
Adds tests for function pointer type discrimination.
Also updates the main pauthtest document to:
libc, since those changes have already landed; andcc-rsstill requires patching becausecompiler/rustc_llvm/Cargo.tomlpinsccto the older version=1.2.16.This is part 8 of a sequence of 8 PRs that together implement support for function pointer type discrimination:
Useful links:
pauthtestintroduction: Introduce aarch64-unknown-linux-pauthtest target #155722