diff --git a/libcxx/src/include/overridable_function.h b/libcxx/src/include/overridable_function.h index c8d9f30c74c3e..bd55c4bb6d8bc 100644 --- a/libcxx/src/include/overridable_function.h +++ b/libcxx/src/include/overridable_function.h @@ -11,11 +11,6 @@ #define _LIBCPP_SRC_INCLUDE_OVERRIDABLE_FUNCTION_H #include <__config> -#include - -#if __has_feature(ptrauth_calls) -# include -#endif #if !defined(_LIBCPP_HAS_NO_PRAGMA_SYSTEM_HEADER) # pragma GCC system_header @@ -42,18 +37,11 @@ // ------------------- // // Let's say we want to check whether a weak function `f` has been overridden by the user. -// The general mechanism works by placing `f`'s definition (in the libc++ built library) -// inside a special section, which we do using the `__section__` attribute via the -// OVERRIDABLE_FUNCTION macro. -// -// Then, when comes the time to check whether the function has been overridden, we take -// the address of the function and we check whether it falls inside the special function -// we created. This can be done by finding pointers to the start and the end of the section -// (which is done differently for ELF and Mach-O), and then checking whether `f` falls -// within those bounds. If it falls within those bounds, then `f` is still inside the -// special section and so it is the version we defined in the libc++ built library, i.e. -// it was not overridden. Otherwise, it was overridden by the user because it falls -// outside of the section. +// The general mechanism works by defining a local symbol `__impl_ref::__impl_` with +// the same address as `f` as a constant expression using direct PC-relative +// materialization thus pointing at the symbol defined in the same TU. At runtime, it +// compares the address of `__impl_ref::__impl_` with the address of `f` loaded from +// GOT: if `f` was overridden by the user in another TU, the addresses will be different. // // Important note // -------------- @@ -63,64 +51,54 @@ // want to be defining special sections inside user's executables which use our headers. // -#if defined(_LIBCPP_OBJECT_FORMAT_MACHO) +#if defined(_LIBCPP_OBJECT_FORMAT_MACHO) || (defined(_LIBCPP_OBJECT_FORMAT_ELF) && !defined(__NVPTX__)) # define _LIBCPP_CAN_DETECT_OVERRIDDEN_FUNCTION 1 -# define OVERRIDABLE_FUNCTION [[gnu::weak, gnu::section("__TEXT,__lcxx_override,regular,pure_instructions")]] +# define OVERRIDABLE_FUNCTION [[gnu::weak]] -_LIBCPP_BEGIN_NAMESPACE_STD template -_LIBCPP_HIDE_FROM_ABI inline bool __is_function_overridden() noexcept { - // Declare two dummy bytes and give them these special `__asm` values. These values are - // defined by the linker, which means that referring to `&__lcxx_override_start` will - // effectively refer to the address where the section starts (and same for the end). - extern char __lcxx_override_start __asm("section$start$__TEXT$__lcxx_override"); - extern char __lcxx_override_end __asm("section$end$__TEXT$__lcxx_override"); - - // Now get a uintptr_t out of these locations, and out of the function pointer. - uintptr_t __start = reinterpret_cast(&__lcxx_override_start); - uintptr_t __end = reinterpret_cast(&__lcxx_override_end); - uintptr_t __ptr = reinterpret_cast(_Func); - -# if __has_feature(ptrauth_calls) - // We must pass a void* to ptrauth_strip since it only accepts a pointer type. Also, in particular, - // we must NOT pass a function pointer, otherwise we will strip the function pointer, and then attempt - // to authenticate and re-sign it when casting it to a uintptr_t again, which will fail because we just - // stripped the function pointer. See rdar://122927845. - __ptr = reinterpret_cast(ptrauth_strip(reinterpret_cast(__ptr), ptrauth_key_function_pointer)); -# endif +_LIBCPP_BEGIN_NAMESPACE_STD + +namespace { - // Finally, the function was overridden if it falls outside of the section's bounds. - return __ptr < __start || __ptr > __end; +// This is used to prevent TBAA from optimizing away the function pointer comparison. +template +[[nodiscard]] inline _LIBCPP_HIDE_FROM_ABI T* __libcpp_launder(T* __ptr) noexcept { + __asm__ volatile("" : "+r"(__ptr)); + return __ptr; } -_LIBCPP_END_NAMESPACE_STD -// The NVPTX linker cannot create '__start/__stop' sections. -#elif defined(_LIBCPP_OBJECT_FORMAT_ELF) && !defined(__NVPTX__) +} // namespace -# define _LIBCPP_CAN_DETECT_OVERRIDDEN_FUNCTION 1 -# define OVERRIDABLE_FUNCTION [[gnu::weak, gnu::section("__lcxx_override")]] +template +struct __impl_ref; -// This is very similar to what we do for Mach-O above. The ELF linker will implicitly define -// variables with those names corresponding to the start and the end of the section. -// -// See https://stackoverflow.com/questions/16552710/how-do-you-get-the-start-and-end-addresses-of-a-custom-elf-section -extern char __start___lcxx_override; -extern char __stop___lcxx_override; +// __impl_ref<...>::__impl_ is expected to be defined elsewhere, so the compiler emits +// assembly references to the mangled symbol with no definition. This template saves us +// the trouble of providing manual declarations for overloads with some other local name +// for each function name being overloaded (operator new, operator new[], etc.). +template +struct __impl_ref<_Func> { + [[gnu::visibility("hidden")]] static _Ret __impl_(_Args...); +}; -_LIBCPP_BEGIN_NAMESPACE_STD +// This takes a function type template argument first so that the second non-type template +// argument (pointer to the public function) gets the benefit of type-aware overload +// resolution, rather than having to use a static_cast. template _LIBCPP_HIDE_FROM_ABI inline bool __is_function_overridden() noexcept { - uintptr_t __start = reinterpret_cast(&__start___lcxx_override); - uintptr_t __end = reinterpret_cast(&__stop___lcxx_override); - uintptr_t __ptr = reinterpret_cast(_Func); - -# if __has_feature(ptrauth_calls) - // We must pass a void* to ptrauth_strip since it only accepts a pointer type. See full explanation above. - __ptr = reinterpret_cast(ptrauth_strip(reinterpret_cast(__ptr), ptrauth_key_function_pointer)); +# if !defined(_LIBCPP_CLANG_VER) || _LIBCPP_CLANG_VER >= 2101 + __asm__("%cc0 = %cc1" : : "X"(__impl_ref<_Func>::__impl_), "X"(_Func)); +# else + __asm__("%c0 = %c1" : : "X"(__impl_ref<_Func>::__impl_), "X"(_Func)); # endif - - return __ptr < __start || __ptr > __end; + // This just has the compiler compare the two symbols. For PIC mode, this will do a + // direct PC-relative materialization for __impl_ref<...>::__impl_ and a GOT load for + // the _Func symbol. The compiler thinks __impl_ref<...>::__impl_ is defined elsewhere + // at link time and will be an undefined symbol. It doesn't know that the __asm__ tells + // the assembler to define it as a local symbol. + return __libcpp_launder(_Func) != __impl_ref<_Func>::__impl_; } + _LIBCPP_END_NAMESPACE_STD #else