1fa82cce7SThomas Gleixner // SPDX-License-Identifier: GPL-2.0-only
238addce8SEmese Revfy /*
338addce8SEmese Revfy  * Copyright 2012-2016 by the PaX Team <[email protected]>
438addce8SEmese Revfy  * Copyright 2016 by Emese Revfy <[email protected]>
538addce8SEmese Revfy  *
638addce8SEmese Revfy  * Note: the choice of the license means that the compilation process is
738addce8SEmese Revfy  *       NOT 'eligible' as defined by gcc's library exception to the GPL v3,
838addce8SEmese Revfy  *       but for the kernel it doesn't matter since it doesn't link against
938addce8SEmese Revfy  *       any of the gcc libraries
1038addce8SEmese Revfy  *
1138addce8SEmese Revfy  * This gcc plugin helps generate a little bit of entropy from program state,
1238addce8SEmese Revfy  * used throughout the uptime of the kernel. Here is an instrumentation example:
1338addce8SEmese Revfy  *
1438addce8SEmese Revfy  * before:
1538addce8SEmese Revfy  * void __latent_entropy test(int argc, char *argv[])
1638addce8SEmese Revfy  * {
1738addce8SEmese Revfy  *	if (argc <= 1)
1838addce8SEmese Revfy  *		printf("%s: no command arguments :(\n", *argv);
1938addce8SEmese Revfy  *	else
20*782ce431SKonstantin Runov  *		printf("%s: %d command arguments!\n", *argv, argc - 1);
2138addce8SEmese Revfy  * }
2238addce8SEmese Revfy  *
2338addce8SEmese Revfy  * after:
2438addce8SEmese Revfy  * void __latent_entropy test(int argc, char *argv[])
2538addce8SEmese Revfy  * {
2638addce8SEmese Revfy  *	// latent_entropy_execute() 1.
2738addce8SEmese Revfy  *	unsigned long local_entropy;
2838addce8SEmese Revfy  *	// init_local_entropy() 1.
2938addce8SEmese Revfy  *	void *local_entropy_frameaddr;
3038addce8SEmese Revfy  *	// init_local_entropy() 3.
3138addce8SEmese Revfy  *	unsigned long tmp_latent_entropy;
3238addce8SEmese Revfy  *
3338addce8SEmese Revfy  *	// init_local_entropy() 2.
3438addce8SEmese Revfy  *	local_entropy_frameaddr = __builtin_frame_address(0);
3538addce8SEmese Revfy  *	local_entropy = (unsigned long) local_entropy_frameaddr;
3638addce8SEmese Revfy  *
3738addce8SEmese Revfy  *	// init_local_entropy() 4.
3838addce8SEmese Revfy  *	tmp_latent_entropy = latent_entropy;
3938addce8SEmese Revfy  *	// init_local_entropy() 5.
4038addce8SEmese Revfy  *	local_entropy ^= tmp_latent_entropy;
4138addce8SEmese Revfy  *
4238addce8SEmese Revfy  *	// latent_entropy_execute() 3.
4338addce8SEmese Revfy  *	if (argc <= 1) {
4438addce8SEmese Revfy  *		// perturb_local_entropy()
4538addce8SEmese Revfy  *		local_entropy += 4623067384293424948;
4638addce8SEmese Revfy  *		printf("%s: no command arguments :(\n", *argv);
4738addce8SEmese Revfy  *		// perturb_local_entropy()
4838addce8SEmese Revfy  *	} else {
4938addce8SEmese Revfy  *		local_entropy ^= 3896280633962944730;
50*782ce431SKonstantin Runov  *		printf("%s: %d command arguments!\n", *argv, argc - 1);
5138addce8SEmese Revfy  *	}
5238addce8SEmese Revfy  *
5338addce8SEmese Revfy  *	// latent_entropy_execute() 4.
5438addce8SEmese Revfy  *	tmp_latent_entropy = rol(tmp_latent_entropy, local_entropy);
5538addce8SEmese Revfy  *	latent_entropy = tmp_latent_entropy;
5638addce8SEmese Revfy  * }
5738addce8SEmese Revfy  *
5838addce8SEmese Revfy  * TODO:
5938addce8SEmese Revfy  * - add ipa pass to identify not explicitly marked candidate functions
6038addce8SEmese Revfy  * - mix in more program state (function arguments/return values,
6138addce8SEmese Revfy  *   loop variables, etc)
6238addce8SEmese Revfy  * - more instrumentation control via attribute parameters
6338addce8SEmese Revfy  *
6438addce8SEmese Revfy  * BUGS:
6538addce8SEmese Revfy  * - none known
6638addce8SEmese Revfy  *
6738addce8SEmese Revfy  * Options:
6838addce8SEmese Revfy  * -fplugin-arg-latent_entropy_plugin-disable
6938addce8SEmese Revfy  *
7038addce8SEmese Revfy  * Attribute: __attribute__((latent_entropy))
7138addce8SEmese Revfy  *  The latent_entropy gcc attribute can be only on functions and variables.
7238addce8SEmese Revfy  *  If it is on a function then the plugin will instrument it. If the attribute
7338addce8SEmese Revfy  *  is on a variable then the plugin will initialize it with a random value.
7438addce8SEmese Revfy  *  The variable must be an integer, an integer array type or a structure
7538addce8SEmese Revfy  *  with integer fields.
7638addce8SEmese Revfy  */
7738addce8SEmese Revfy 
7838addce8SEmese Revfy #include "gcc-common.h"
7938addce8SEmese Revfy 
80da7389acSKees Cook __visible int plugin_is_GPL_compatible;
8138addce8SEmese Revfy 
8238addce8SEmese Revfy static GTY(()) tree latent_entropy_decl;
8338addce8SEmese Revfy 
8438addce8SEmese Revfy static struct plugin_info latent_entropy_plugin_info = {
85d37aa2efSMasahiro Yamada 	.version	= PLUGIN_VERSION,
8638addce8SEmese Revfy 	.help		= "disable\tturn off latent entropy instrumentation\n",
8738addce8SEmese Revfy };
8838addce8SEmese Revfy 
89c40160f2SJason A. Donenfeld static unsigned HOST_WIDE_INT deterministic_seed;
90c40160f2SJason A. Donenfeld static unsigned HOST_WIDE_INT rnd_buf[32];
91c40160f2SJason A. Donenfeld static size_t rnd_idx = ARRAY_SIZE(rnd_buf);
92c40160f2SJason A. Donenfeld static int urandom_fd = -1;
93c40160f2SJason A. Donenfeld 
get_random_const(void)9438addce8SEmese Revfy static unsigned HOST_WIDE_INT get_random_const(void)
9538addce8SEmese Revfy {
96c40160f2SJason A. Donenfeld 	if (deterministic_seed) {
97c40160f2SJason A. Donenfeld 		unsigned HOST_WIDE_INT w = deterministic_seed;
98c40160f2SJason A. Donenfeld 		w ^= w << 13;
99c40160f2SJason A. Donenfeld 		w ^= w >> 7;
100c40160f2SJason A. Donenfeld 		w ^= w << 17;
101c40160f2SJason A. Donenfeld 		deterministic_seed = w;
102c40160f2SJason A. Donenfeld 		return deterministic_seed;
10338addce8SEmese Revfy 	}
10438addce8SEmese Revfy 
105c40160f2SJason A. Donenfeld 	if (urandom_fd < 0) {
106c40160f2SJason A. Donenfeld 		urandom_fd = open("/dev/urandom", O_RDONLY);
107c40160f2SJason A. Donenfeld 		gcc_assert(urandom_fd >= 0);
108c40160f2SJason A. Donenfeld 	}
109c40160f2SJason A. Donenfeld 	if (rnd_idx >= ARRAY_SIZE(rnd_buf)) {
110c40160f2SJason A. Donenfeld 		gcc_assert(read(urandom_fd, rnd_buf, sizeof(rnd_buf)) == sizeof(rnd_buf));
111c40160f2SJason A. Donenfeld 		rnd_idx = 0;
112c40160f2SJason A. Donenfeld 	}
113c40160f2SJason A. Donenfeld 	return rnd_buf[rnd_idx++];
11438addce8SEmese Revfy }
11538addce8SEmese Revfy 
tree_get_random_const(tree type)11638addce8SEmese Revfy static tree tree_get_random_const(tree type)
11738addce8SEmese Revfy {
11838addce8SEmese Revfy 	unsigned long long mask;
11938addce8SEmese Revfy 
12038addce8SEmese Revfy 	mask = 1ULL << (TREE_INT_CST_LOW(TYPE_SIZE(type)) - 1);
12138addce8SEmese Revfy 	mask = 2 * (mask - 1) + 1;
12238addce8SEmese Revfy 
12338addce8SEmese Revfy 	if (TYPE_UNSIGNED(type))
12438addce8SEmese Revfy 		return build_int_cstu(type, mask & get_random_const());
12538addce8SEmese Revfy 	return build_int_cst(type, mask & get_random_const());
12638addce8SEmese Revfy }
12738addce8SEmese Revfy 
handle_latent_entropy_attribute(tree * node,tree name,tree args __unused,int flags __unused,bool * no_add_attrs)12838addce8SEmese Revfy static tree handle_latent_entropy_attribute(tree *node, tree name,
12938addce8SEmese Revfy 						tree args __unused,
13038addce8SEmese Revfy 						int flags __unused,
13138addce8SEmese Revfy 						bool *no_add_attrs)
13238addce8SEmese Revfy {
13338addce8SEmese Revfy 	tree type;
13438addce8SEmese Revfy 	vec<constructor_elt, va_gc> *vals;
13538addce8SEmese Revfy 
13638addce8SEmese Revfy 	switch (TREE_CODE(*node)) {
13738addce8SEmese Revfy 	default:
13838addce8SEmese Revfy 		*no_add_attrs = true;
13938addce8SEmese Revfy 		error("%qE attribute only applies to functions and variables",
14038addce8SEmese Revfy 			name);
14138addce8SEmese Revfy 		break;
14238addce8SEmese Revfy 
14338addce8SEmese Revfy 	case VAR_DECL:
14438addce8SEmese Revfy 		if (DECL_INITIAL(*node)) {
14538addce8SEmese Revfy 			*no_add_attrs = true;
14638addce8SEmese Revfy 			error("variable %qD with %qE attribute must not be initialized",
14738addce8SEmese Revfy 				*node, name);
14838addce8SEmese Revfy 			break;
14938addce8SEmese Revfy 		}
15038addce8SEmese Revfy 
15138addce8SEmese Revfy 		if (!TREE_STATIC(*node)) {
15238addce8SEmese Revfy 			*no_add_attrs = true;
15338addce8SEmese Revfy 			error("variable %qD with %qE attribute must not be local",
15438addce8SEmese Revfy 				*node, name);
15538addce8SEmese Revfy 			break;
15638addce8SEmese Revfy 		}
15738addce8SEmese Revfy 
15838addce8SEmese Revfy 		type = TREE_TYPE(*node);
15938addce8SEmese Revfy 		switch (TREE_CODE(type)) {
16038addce8SEmese Revfy 		default:
16138addce8SEmese Revfy 			*no_add_attrs = true;
16238addce8SEmese Revfy 			error("variable %qD with %qE attribute must be an integer or a fixed length integer array type or a fixed sized structure with integer fields",
16338addce8SEmese Revfy 				*node, name);
16438addce8SEmese Revfy 			break;
16538addce8SEmese Revfy 
16638addce8SEmese Revfy 		case RECORD_TYPE: {
16738addce8SEmese Revfy 			tree fld, lst = TYPE_FIELDS(type);
16838addce8SEmese Revfy 			unsigned int nelt = 0;
16938addce8SEmese Revfy 
17038addce8SEmese Revfy 			for (fld = lst; fld; nelt++, fld = TREE_CHAIN(fld)) {
17138addce8SEmese Revfy 				tree fieldtype;
17238addce8SEmese Revfy 
17338addce8SEmese Revfy 				fieldtype = TREE_TYPE(fld);
17438addce8SEmese Revfy 				if (TREE_CODE(fieldtype) == INTEGER_TYPE)
17538addce8SEmese Revfy 					continue;
17638addce8SEmese Revfy 
17738addce8SEmese Revfy 				*no_add_attrs = true;
17838addce8SEmese Revfy 				error("structure variable %qD with %qE attribute has a non-integer field %qE",
17938addce8SEmese Revfy 					*node, name, fld);
18038addce8SEmese Revfy 				break;
18138addce8SEmese Revfy 			}
18238addce8SEmese Revfy 
18338addce8SEmese Revfy 			if (fld)
18438addce8SEmese Revfy 				break;
18538addce8SEmese Revfy 
18638addce8SEmese Revfy 			vec_alloc(vals, nelt);
18738addce8SEmese Revfy 
18838addce8SEmese Revfy 			for (fld = lst; fld; fld = TREE_CHAIN(fld)) {
18938addce8SEmese Revfy 				tree random_const, fld_t = TREE_TYPE(fld);
19038addce8SEmese Revfy 
19138addce8SEmese Revfy 				random_const = tree_get_random_const(fld_t);
19238addce8SEmese Revfy 				CONSTRUCTOR_APPEND_ELT(vals, fld, random_const);
19338addce8SEmese Revfy 			}
19438addce8SEmese Revfy 
19538addce8SEmese Revfy 			/* Initialize the fields with random constants */
19638addce8SEmese Revfy 			DECL_INITIAL(*node) = build_constructor(type, vals);
19738addce8SEmese Revfy 			break;
19838addce8SEmese Revfy 		}
19938addce8SEmese Revfy 
20038addce8SEmese Revfy 		/* Initialize the variable with a random constant */
20138addce8SEmese Revfy 		case INTEGER_TYPE:
20238addce8SEmese Revfy 			DECL_INITIAL(*node) = tree_get_random_const(type);
20338addce8SEmese Revfy 			break;
20438addce8SEmese Revfy 
20538addce8SEmese Revfy 		case ARRAY_TYPE: {
20638addce8SEmese Revfy 			tree elt_type, array_size, elt_size;
20738addce8SEmese Revfy 			unsigned int i, nelt;
20838addce8SEmese Revfy 			HOST_WIDE_INT array_size_int, elt_size_int;
20938addce8SEmese Revfy 
21038addce8SEmese Revfy 			elt_type = TREE_TYPE(type);
21138addce8SEmese Revfy 			elt_size = TYPE_SIZE_UNIT(TREE_TYPE(type));
21238addce8SEmese Revfy 			array_size = TYPE_SIZE_UNIT(type);
21338addce8SEmese Revfy 
21438addce8SEmese Revfy 			if (TREE_CODE(elt_type) != INTEGER_TYPE || !array_size
21538addce8SEmese Revfy 				|| TREE_CODE(array_size) != INTEGER_CST) {
21638addce8SEmese Revfy 				*no_add_attrs = true;
21738addce8SEmese Revfy 				error("array variable %qD with %qE attribute must be a fixed length integer array type",
21838addce8SEmese Revfy 					*node, name);
21938addce8SEmese Revfy 				break;
22038addce8SEmese Revfy 			}
22138addce8SEmese Revfy 
22238addce8SEmese Revfy 			array_size_int = TREE_INT_CST_LOW(array_size);
22338addce8SEmese Revfy 			elt_size_int = TREE_INT_CST_LOW(elt_size);
22438addce8SEmese Revfy 			nelt = array_size_int / elt_size_int;
22538addce8SEmese Revfy 
22638addce8SEmese Revfy 			vec_alloc(vals, nelt);
22738addce8SEmese Revfy 
22838addce8SEmese Revfy 			for (i = 0; i < nelt; i++) {
22938addce8SEmese Revfy 				tree cst = size_int(i);
23038addce8SEmese Revfy 				tree rand_cst = tree_get_random_const(elt_type);
23138addce8SEmese Revfy 
23238addce8SEmese Revfy 				CONSTRUCTOR_APPEND_ELT(vals, cst, rand_cst);
23338addce8SEmese Revfy 			}
23438addce8SEmese Revfy 
23538addce8SEmese Revfy 			/*
23638addce8SEmese Revfy 			 * Initialize the elements of the array with random
23738addce8SEmese Revfy 			 * constants
23838addce8SEmese Revfy 			 */
23938addce8SEmese Revfy 			DECL_INITIAL(*node) = build_constructor(type, vals);
24038addce8SEmese Revfy 			break;
24138addce8SEmese Revfy 		}
24238addce8SEmese Revfy 		}
24338addce8SEmese Revfy 		break;
24438addce8SEmese Revfy 
24538addce8SEmese Revfy 	case FUNCTION_DECL:
24638addce8SEmese Revfy 		break;
24738addce8SEmese Revfy 	}
24838addce8SEmese Revfy 
24938addce8SEmese Revfy 	return NULL_TREE;
25038addce8SEmese Revfy }
25138addce8SEmese Revfy 
252b8672910SKees Cook static struct attribute_spec latent_entropy_attr = { };
25338addce8SEmese Revfy 
register_attributes(void * event_data __unused,void * data __unused)25438addce8SEmese Revfy static void register_attributes(void *event_data __unused, void *data __unused)
25538addce8SEmese Revfy {
256b8672910SKees Cook 	latent_entropy_attr.name		= "latent_entropy";
257b8672910SKees Cook 	latent_entropy_attr.decl_required	= true;
258b8672910SKees Cook 	latent_entropy_attr.handler		= handle_latent_entropy_attribute;
259b8672910SKees Cook 
26038addce8SEmese Revfy 	register_attribute(&latent_entropy_attr);
26138addce8SEmese Revfy }
26238addce8SEmese Revfy 
latent_entropy_gate(void)26338addce8SEmese Revfy static bool latent_entropy_gate(void)
26438addce8SEmese Revfy {
26538addce8SEmese Revfy 	tree list;
26638addce8SEmese Revfy 
26738addce8SEmese Revfy 	/* don't bother with noreturn functions for now */
26838addce8SEmese Revfy 	if (TREE_THIS_VOLATILE(current_function_decl))
26938addce8SEmese Revfy 		return false;
27038addce8SEmese Revfy 
27138addce8SEmese Revfy 	/* gcc-4.5 doesn't discover some trivial noreturn functions */
27238addce8SEmese Revfy 	if (EDGE_COUNT(EXIT_BLOCK_PTR_FOR_FN(cfun)->preds) == 0)
27338addce8SEmese Revfy 		return false;
27438addce8SEmese Revfy 
27538addce8SEmese Revfy 	list = DECL_ATTRIBUTES(current_function_decl);
27638addce8SEmese Revfy 	return lookup_attribute("latent_entropy", list) != NULL_TREE;
27738addce8SEmese Revfy }
27838addce8SEmese Revfy 
create_var(tree type,const char * name)27938addce8SEmese Revfy static tree create_var(tree type, const char *name)
28038addce8SEmese Revfy {
28138addce8SEmese Revfy 	tree var;
28238addce8SEmese Revfy 
28338addce8SEmese Revfy 	var = create_tmp_var(type, name);
28438addce8SEmese Revfy 	add_referenced_var(var);
28538addce8SEmese Revfy 	mark_sym_for_renaming(var);
28638addce8SEmese Revfy 	return var;
28738addce8SEmese Revfy }
28838addce8SEmese Revfy 
28938addce8SEmese Revfy /*
29038addce8SEmese Revfy  * Set up the next operation and its constant operand to use in the latent
29138addce8SEmese Revfy  * entropy PRNG. When RHS is specified, the request is for perturbing the
29238addce8SEmese Revfy  * local latent entropy variable, otherwise it is for perturbing the global
29338addce8SEmese Revfy  * latent entropy variable where the two operands are already given by the
29438addce8SEmese Revfy  * local and global latent entropy variables themselves.
29538addce8SEmese Revfy  *
29638addce8SEmese Revfy  * The operation is one of add/xor/rol when instrumenting the local entropy
29738addce8SEmese Revfy  * variable and one of add/xor when perturbing the global entropy variable.
29838addce8SEmese Revfy  * Rotation is not used for the latter case because it would transmit less
29938addce8SEmese Revfy  * entropy to the global variable than the other two operations.
30038addce8SEmese Revfy  */
get_op(tree * rhs)30138addce8SEmese Revfy static enum tree_code get_op(tree *rhs)
30238addce8SEmese Revfy {
30338addce8SEmese Revfy 	static enum tree_code op;
30438addce8SEmese Revfy 	unsigned HOST_WIDE_INT random_const;
30538addce8SEmese Revfy 
30638addce8SEmese Revfy 	random_const = get_random_const();
30738addce8SEmese Revfy 
30838addce8SEmese Revfy 	switch (op) {
30938addce8SEmese Revfy 	case BIT_XOR_EXPR:
31038addce8SEmese Revfy 		op = PLUS_EXPR;
31138addce8SEmese Revfy 		break;
31238addce8SEmese Revfy 
31338addce8SEmese Revfy 	case PLUS_EXPR:
31438addce8SEmese Revfy 		if (rhs) {
31538addce8SEmese Revfy 			op = LROTATE_EXPR;
31638addce8SEmese Revfy 			/*
31738addce8SEmese Revfy 			 * This code limits the value of random_const to
3189988f4d5SKees Cook 			 * the size of a long for the rotation
31938addce8SEmese Revfy 			 */
3209988f4d5SKees Cook 			random_const %= TYPE_PRECISION(long_unsigned_type_node);
32138addce8SEmese Revfy 			break;
32238addce8SEmese Revfy 		}
32338addce8SEmese Revfy 
32438addce8SEmese Revfy 	case LROTATE_EXPR:
32538addce8SEmese Revfy 	default:
32638addce8SEmese Revfy 		op = BIT_XOR_EXPR;
32738addce8SEmese Revfy 		break;
32838addce8SEmese Revfy 	}
32938addce8SEmese Revfy 	if (rhs)
33058bea414SKees Cook 		*rhs = build_int_cstu(long_unsigned_type_node, random_const);
33138addce8SEmese Revfy 	return op;
33238addce8SEmese Revfy }
33338addce8SEmese Revfy 
create_assign(enum tree_code code,tree lhs,tree op1,tree op2)33438addce8SEmese Revfy static gimple create_assign(enum tree_code code, tree lhs, tree op1,
33538addce8SEmese Revfy 				tree op2)
33638addce8SEmese Revfy {
33738addce8SEmese Revfy 	return gimple_build_assign_with_ops(code, lhs, op1, op2);
33838addce8SEmese Revfy }
33938addce8SEmese Revfy 
perturb_local_entropy(basic_block bb,tree local_entropy)34038addce8SEmese Revfy static void perturb_local_entropy(basic_block bb, tree local_entropy)
34138addce8SEmese Revfy {
34238addce8SEmese Revfy 	gimple_stmt_iterator gsi;
34338addce8SEmese Revfy 	gimple assign;
34438addce8SEmese Revfy 	tree rhs;
34538addce8SEmese Revfy 	enum tree_code op;
34638addce8SEmese Revfy 
34738addce8SEmese Revfy 	op = get_op(&rhs);
34838addce8SEmese Revfy 	assign = create_assign(op, local_entropy, local_entropy, rhs);
34938addce8SEmese Revfy 	gsi = gsi_after_labels(bb);
35038addce8SEmese Revfy 	gsi_insert_before(&gsi, assign, GSI_NEW_STMT);
35138addce8SEmese Revfy 	update_stmt(assign);
35238addce8SEmese Revfy }
35338addce8SEmese Revfy 
__perturb_latent_entropy(gimple_stmt_iterator * gsi,tree local_entropy)35438addce8SEmese Revfy static void __perturb_latent_entropy(gimple_stmt_iterator *gsi,
35538addce8SEmese Revfy 					tree local_entropy)
35638addce8SEmese Revfy {
35738addce8SEmese Revfy 	gimple assign;
35838addce8SEmese Revfy 	tree temp;
35938addce8SEmese Revfy 	enum tree_code op;
36038addce8SEmese Revfy 
36138addce8SEmese Revfy 	/* 1. create temporary copy of latent_entropy */
36258bea414SKees Cook 	temp = create_var(long_unsigned_type_node, "temp_latent_entropy");
36338addce8SEmese Revfy 
36438addce8SEmese Revfy 	/* 2. read... */
36538addce8SEmese Revfy 	add_referenced_var(latent_entropy_decl);
36638addce8SEmese Revfy 	mark_sym_for_renaming(latent_entropy_decl);
36738addce8SEmese Revfy 	assign = gimple_build_assign(temp, latent_entropy_decl);
36838addce8SEmese Revfy 	gsi_insert_before(gsi, assign, GSI_NEW_STMT);
36938addce8SEmese Revfy 	update_stmt(assign);
37038addce8SEmese Revfy 
37138addce8SEmese Revfy 	/* 3. ...modify... */
37238addce8SEmese Revfy 	op = get_op(NULL);
37338addce8SEmese Revfy 	assign = create_assign(op, temp, temp, local_entropy);
37438addce8SEmese Revfy 	gsi_insert_after(gsi, assign, GSI_NEW_STMT);
37538addce8SEmese Revfy 	update_stmt(assign);
37638addce8SEmese Revfy 
37738addce8SEmese Revfy 	/* 4. ...write latent_entropy */
37838addce8SEmese Revfy 	assign = gimple_build_assign(latent_entropy_decl, temp);
37938addce8SEmese Revfy 	gsi_insert_after(gsi, assign, GSI_NEW_STMT);
38038addce8SEmese Revfy 	update_stmt(assign);
38138addce8SEmese Revfy }
38238addce8SEmese Revfy 
handle_tail_calls(basic_block bb,tree local_entropy)38338addce8SEmese Revfy static bool handle_tail_calls(basic_block bb, tree local_entropy)
38438addce8SEmese Revfy {
38538addce8SEmese Revfy 	gimple_stmt_iterator gsi;
38638addce8SEmese Revfy 
38738addce8SEmese Revfy 	for (gsi = gsi_start_bb(bb); !gsi_end_p(gsi); gsi_next(&gsi)) {
38838addce8SEmese Revfy 		gcall *call;
38938addce8SEmese Revfy 		gimple stmt = gsi_stmt(gsi);
39038addce8SEmese Revfy 
39138addce8SEmese Revfy 		if (!is_gimple_call(stmt))
39238addce8SEmese Revfy 			continue;
39338addce8SEmese Revfy 
39438addce8SEmese Revfy 		call = as_a_gcall(stmt);
39538addce8SEmese Revfy 		if (!gimple_call_tail_p(call))
39638addce8SEmese Revfy 			continue;
39738addce8SEmese Revfy 
39838addce8SEmese Revfy 		__perturb_latent_entropy(&gsi, local_entropy);
39938addce8SEmese Revfy 		return true;
40038addce8SEmese Revfy 	}
40138addce8SEmese Revfy 
40238addce8SEmese Revfy 	return false;
40338addce8SEmese Revfy }
40438addce8SEmese Revfy 
perturb_latent_entropy(tree local_entropy)40538addce8SEmese Revfy static void perturb_latent_entropy(tree local_entropy)
40638addce8SEmese Revfy {
40738addce8SEmese Revfy 	edge_iterator ei;
40838addce8SEmese Revfy 	edge e, last_bb_e;
40938addce8SEmese Revfy 	basic_block last_bb;
41038addce8SEmese Revfy 
41138addce8SEmese Revfy 	gcc_assert(single_pred_p(EXIT_BLOCK_PTR_FOR_FN(cfun)));
41238addce8SEmese Revfy 	last_bb_e = single_pred_edge(EXIT_BLOCK_PTR_FOR_FN(cfun));
41338addce8SEmese Revfy 
41438addce8SEmese Revfy 	FOR_EACH_EDGE(e, ei, last_bb_e->src->preds) {
41538addce8SEmese Revfy 		if (ENTRY_BLOCK_PTR_FOR_FN(cfun) == e->src)
41638addce8SEmese Revfy 			continue;
41738addce8SEmese Revfy 		if (EXIT_BLOCK_PTR_FOR_FN(cfun) == e->src)
41838addce8SEmese Revfy 			continue;
41938addce8SEmese Revfy 
42038addce8SEmese Revfy 		handle_tail_calls(e->src, local_entropy);
42138addce8SEmese Revfy 	}
42238addce8SEmese Revfy 
42338addce8SEmese Revfy 	last_bb = single_pred(EXIT_BLOCK_PTR_FOR_FN(cfun));
42438addce8SEmese Revfy 	if (!handle_tail_calls(last_bb, local_entropy)) {
42538addce8SEmese Revfy 		gimple_stmt_iterator gsi = gsi_last_bb(last_bb);
42638addce8SEmese Revfy 
42738addce8SEmese Revfy 		__perturb_latent_entropy(&gsi, local_entropy);
42838addce8SEmese Revfy 	}
42938addce8SEmese Revfy }
43038addce8SEmese Revfy 
init_local_entropy(basic_block bb,tree local_entropy)43138addce8SEmese Revfy static void init_local_entropy(basic_block bb, tree local_entropy)
43238addce8SEmese Revfy {
43338addce8SEmese Revfy 	gimple assign, call;
43438addce8SEmese Revfy 	tree frame_addr, rand_const, tmp, fndecl, udi_frame_addr;
43538addce8SEmese Revfy 	enum tree_code op;
43638addce8SEmese Revfy 	unsigned HOST_WIDE_INT rand_cst;
43738addce8SEmese Revfy 	gimple_stmt_iterator gsi = gsi_after_labels(bb);
43838addce8SEmese Revfy 
43938addce8SEmese Revfy 	/* 1. create local_entropy_frameaddr */
44038addce8SEmese Revfy 	frame_addr = create_var(ptr_type_node, "local_entropy_frameaddr");
44138addce8SEmese Revfy 
44238addce8SEmese Revfy 	/* 2. local_entropy_frameaddr = __builtin_frame_address() */
44338addce8SEmese Revfy 	fndecl = builtin_decl_implicit(BUILT_IN_FRAME_ADDRESS);
44438addce8SEmese Revfy 	call = gimple_build_call(fndecl, 1, integer_zero_node);
44538addce8SEmese Revfy 	gimple_call_set_lhs(call, frame_addr);
44638addce8SEmese Revfy 	gsi_insert_before(&gsi, call, GSI_NEW_STMT);
44738addce8SEmese Revfy 	update_stmt(call);
44838addce8SEmese Revfy 
44958bea414SKees Cook 	udi_frame_addr = fold_convert(long_unsigned_type_node, frame_addr);
45038addce8SEmese Revfy 	assign = gimple_build_assign(local_entropy, udi_frame_addr);
45138addce8SEmese Revfy 	gsi_insert_after(&gsi, assign, GSI_NEW_STMT);
45238addce8SEmese Revfy 	update_stmt(assign);
45338addce8SEmese Revfy 
45438addce8SEmese Revfy 	/* 3. create temporary copy of latent_entropy */
45558bea414SKees Cook 	tmp = create_var(long_unsigned_type_node, "temp_latent_entropy");
45638addce8SEmese Revfy 
45738addce8SEmese Revfy 	/* 4. read the global entropy variable into local entropy */
45838addce8SEmese Revfy 	add_referenced_var(latent_entropy_decl);
45938addce8SEmese Revfy 	mark_sym_for_renaming(latent_entropy_decl);
46038addce8SEmese Revfy 	assign = gimple_build_assign(tmp, latent_entropy_decl);
46138addce8SEmese Revfy 	gsi_insert_after(&gsi, assign, GSI_NEW_STMT);
46238addce8SEmese Revfy 	update_stmt(assign);
46338addce8SEmese Revfy 
46438addce8SEmese Revfy 	/* 5. mix local_entropy_frameaddr into local entropy */
46538addce8SEmese Revfy 	assign = create_assign(BIT_XOR_EXPR, local_entropy, local_entropy, tmp);
46638addce8SEmese Revfy 	gsi_insert_after(&gsi, assign, GSI_NEW_STMT);
46738addce8SEmese Revfy 	update_stmt(assign);
46838addce8SEmese Revfy 
46938addce8SEmese Revfy 	rand_cst = get_random_const();
47058bea414SKees Cook 	rand_const = build_int_cstu(long_unsigned_type_node, rand_cst);
47138addce8SEmese Revfy 	op = get_op(NULL);
47238addce8SEmese Revfy 	assign = create_assign(op, local_entropy, local_entropy, rand_const);
47338addce8SEmese Revfy 	gsi_insert_after(&gsi, assign, GSI_NEW_STMT);
47438addce8SEmese Revfy 	update_stmt(assign);
47538addce8SEmese Revfy }
47638addce8SEmese Revfy 
create_latent_entropy_decl(void)47738addce8SEmese Revfy static bool create_latent_entropy_decl(void)
47838addce8SEmese Revfy {
47938addce8SEmese Revfy 	varpool_node_ptr node;
48038addce8SEmese Revfy 
48138addce8SEmese Revfy 	if (latent_entropy_decl != NULL_TREE)
48238addce8SEmese Revfy 		return true;
48338addce8SEmese Revfy 
48438addce8SEmese Revfy 	FOR_EACH_VARIABLE(node) {
48538addce8SEmese Revfy 		tree name, var = NODE_DECL(node);
48638addce8SEmese Revfy 
48738addce8SEmese Revfy 		if (DECL_NAME_LENGTH(var) < sizeof("latent_entropy") - 1)
48838addce8SEmese Revfy 			continue;
48938addce8SEmese Revfy 
49038addce8SEmese Revfy 		name = DECL_NAME(var);
49138addce8SEmese Revfy 		if (strcmp(IDENTIFIER_POINTER(name), "latent_entropy"))
49238addce8SEmese Revfy 			continue;
49338addce8SEmese Revfy 
49438addce8SEmese Revfy 		latent_entropy_decl = var;
49538addce8SEmese Revfy 		break;
49638addce8SEmese Revfy 	}
49738addce8SEmese Revfy 
49838addce8SEmese Revfy 	return latent_entropy_decl != NULL_TREE;
49938addce8SEmese Revfy }
50038addce8SEmese Revfy 
latent_entropy_execute(void)50138addce8SEmese Revfy static unsigned int latent_entropy_execute(void)
50238addce8SEmese Revfy {
50338addce8SEmese Revfy 	basic_block bb;
50438addce8SEmese Revfy 	tree local_entropy;
50538addce8SEmese Revfy 
50638addce8SEmese Revfy 	if (!create_latent_entropy_decl())
50738addce8SEmese Revfy 		return 0;
50838addce8SEmese Revfy 
50938addce8SEmese Revfy 	/* prepare for step 2 below */
51038addce8SEmese Revfy 	gcc_assert(single_succ_p(ENTRY_BLOCK_PTR_FOR_FN(cfun)));
51138addce8SEmese Revfy 	bb = single_succ(ENTRY_BLOCK_PTR_FOR_FN(cfun));
51238addce8SEmese Revfy 	if (!single_pred_p(bb)) {
51338addce8SEmese Revfy 		split_edge(single_succ_edge(ENTRY_BLOCK_PTR_FOR_FN(cfun)));
51438addce8SEmese Revfy 		gcc_assert(single_succ_p(ENTRY_BLOCK_PTR_FOR_FN(cfun)));
51538addce8SEmese Revfy 		bb = single_succ(ENTRY_BLOCK_PTR_FOR_FN(cfun));
51638addce8SEmese Revfy 	}
51738addce8SEmese Revfy 
51838addce8SEmese Revfy 	/* 1. create the local entropy variable */
51958bea414SKees Cook 	local_entropy = create_var(long_unsigned_type_node, "local_entropy");
52038addce8SEmese Revfy 
52138addce8SEmese Revfy 	/* 2. initialize the local entropy variable */
52238addce8SEmese Revfy 	init_local_entropy(bb, local_entropy);
52338addce8SEmese Revfy 
52438addce8SEmese Revfy 	bb = bb->next_bb;
52538addce8SEmese Revfy 
52638addce8SEmese Revfy 	/*
52738addce8SEmese Revfy 	 * 3. instrument each BB with an operation on the
52838addce8SEmese Revfy 	 *    local entropy variable
52938addce8SEmese Revfy 	 */
53038addce8SEmese Revfy 	while (bb != EXIT_BLOCK_PTR_FOR_FN(cfun)) {
53138addce8SEmese Revfy 		perturb_local_entropy(bb, local_entropy);
53238addce8SEmese Revfy 		bb = bb->next_bb;
5335477edcaSJason Yan 	}
53438addce8SEmese Revfy 
53538addce8SEmese Revfy 	/* 4. mix local entropy into the global entropy variable */
53638addce8SEmese Revfy 	perturb_latent_entropy(local_entropy);
53738addce8SEmese Revfy 	return 0;
53838addce8SEmese Revfy }
53938addce8SEmese Revfy 
latent_entropy_start_unit(void * gcc_data __unused,void * user_data __unused)54038addce8SEmese Revfy static void latent_entropy_start_unit(void *gcc_data __unused,
54138addce8SEmese Revfy 					void *user_data __unused)
54238addce8SEmese Revfy {
54338addce8SEmese Revfy 	tree type, id;
54438addce8SEmese Revfy 	int quals;
54538addce8SEmese Revfy 
54638addce8SEmese Revfy 	if (in_lto_p)
54738addce8SEmese Revfy 		return;
54838addce8SEmese Revfy 
54958bea414SKees Cook 	/* extern volatile unsigned long latent_entropy */
55058bea414SKees Cook 	quals = TYPE_QUALS(long_unsigned_type_node) | TYPE_QUAL_VOLATILE;
55158bea414SKees Cook 	type = build_qualified_type(long_unsigned_type_node, quals);
55238addce8SEmese Revfy 	id = get_identifier("latent_entropy");
55338addce8SEmese Revfy 	latent_entropy_decl = build_decl(UNKNOWN_LOCATION, VAR_DECL, id, type);
55438addce8SEmese Revfy 
55538addce8SEmese Revfy 	TREE_STATIC(latent_entropy_decl) = 1;
55638addce8SEmese Revfy 	TREE_PUBLIC(latent_entropy_decl) = 1;
55738addce8SEmese Revfy 	TREE_USED(latent_entropy_decl) = 1;
55838addce8SEmese Revfy 	DECL_PRESERVE_P(latent_entropy_decl) = 1;
55938addce8SEmese Revfy 	TREE_THIS_VOLATILE(latent_entropy_decl) = 1;
56038addce8SEmese Revfy 	DECL_EXTERNAL(latent_entropy_decl) = 1;
56138addce8SEmese Revfy 	DECL_ARTIFICIAL(latent_entropy_decl) = 1;
56238addce8SEmese Revfy 	lang_hooks.decls.pushdecl(latent_entropy_decl);
56338addce8SEmese Revfy }
56438addce8SEmese Revfy 
56538addce8SEmese Revfy #define PASS_NAME latent_entropy
56638addce8SEmese Revfy #define PROPERTIES_REQUIRED PROP_gimple_leh | PROP_cfg
56738addce8SEmese Revfy #define TODO_FLAGS_FINISH TODO_verify_ssa | TODO_verify_stmts | TODO_dump_func \
56838addce8SEmese Revfy 	| TODO_update_ssa
56938addce8SEmese Revfy #include "gcc-generate-gimple-pass.h"
57038addce8SEmese Revfy 
plugin_init(struct plugin_name_args * plugin_info,struct plugin_gcc_version * version)571da7389acSKees Cook __visible int plugin_init(struct plugin_name_args *plugin_info,
57238addce8SEmese Revfy 			  struct plugin_gcc_version *version)
57338addce8SEmese Revfy {
57438addce8SEmese Revfy 	bool enabled = true;
57538addce8SEmese Revfy 	const char * const plugin_name = plugin_info->base_name;
57638addce8SEmese Revfy 	const int argc = plugin_info->argc;
57738addce8SEmese Revfy 	const struct plugin_argument * const argv = plugin_info->argv;
57838addce8SEmese Revfy 	int i;
57938addce8SEmese Revfy 
580c40160f2SJason A. Donenfeld 	/*
581c40160f2SJason A. Donenfeld 	 * Call get_random_seed() with noinit=true, so that this returns
582c40160f2SJason A. Donenfeld 	 * 0 in the case where no seed has been passed via -frandom-seed.
583c40160f2SJason A. Donenfeld 	 */
584c40160f2SJason A. Donenfeld 	deterministic_seed = get_random_seed(true);
585c40160f2SJason A. Donenfeld 
58638addce8SEmese Revfy 	static const struct ggc_root_tab gt_ggc_r_gt_latent_entropy[] = {
58738addce8SEmese Revfy 		{
58838addce8SEmese Revfy 			.base = &latent_entropy_decl,
58938addce8SEmese Revfy 			.nelt = 1,
59038addce8SEmese Revfy 			.stride = sizeof(latent_entropy_decl),
59138addce8SEmese Revfy 			.cb = &gt_ggc_mx_tree_node,
59238addce8SEmese Revfy 			.pchw = &gt_pch_nx_tree_node
59338addce8SEmese Revfy 		},
59438addce8SEmese Revfy 		LAST_GGC_ROOT_TAB
59538addce8SEmese Revfy 	};
59638addce8SEmese Revfy 
5975a45a4c5SKees Cook 	PASS_INFO(latent_entropy, "optimized", 1, PASS_POS_INSERT_BEFORE);
5985a45a4c5SKees Cook 
59938addce8SEmese Revfy 	if (!plugin_default_version_check(version, &gcc_version)) {
60038addce8SEmese Revfy 		error(G_("incompatible gcc/plugin versions"));
60138addce8SEmese Revfy 		return 1;
60238addce8SEmese Revfy 	}
60338addce8SEmese Revfy 
60438addce8SEmese Revfy 	for (i = 0; i < argc; ++i) {
60538addce8SEmese Revfy 		if (!(strcmp(argv[i].key, "disable"))) {
60638addce8SEmese Revfy 			enabled = false;
60738addce8SEmese Revfy 			continue;
60838addce8SEmese Revfy 		}
6099165dabbSMasanari Iida 		error(G_("unknown option '-fplugin-arg-%s-%s'"), plugin_name, argv[i].key);
61038addce8SEmese Revfy 	}
61138addce8SEmese Revfy 
61238addce8SEmese Revfy 	register_callback(plugin_name, PLUGIN_INFO, NULL,
61338addce8SEmese Revfy 				&latent_entropy_plugin_info);
61438addce8SEmese Revfy 	if (enabled) {
61538addce8SEmese Revfy 		register_callback(plugin_name, PLUGIN_START_UNIT,
61638addce8SEmese Revfy 					&latent_entropy_start_unit, NULL);
61738addce8SEmese Revfy 		register_callback(plugin_name, PLUGIN_REGISTER_GGC_ROOTS,
61838addce8SEmese Revfy 				  NULL, (void *)&gt_ggc_r_gt_latent_entropy);
61938addce8SEmese Revfy 		register_callback(plugin_name, PLUGIN_PASS_MANAGER_SETUP, NULL,
62038addce8SEmese Revfy 					&latent_entropy_pass_info);
62138addce8SEmese Revfy 	}
62238addce8SEmese Revfy 	register_callback(plugin_name, PLUGIN_ATTRIBUTES, register_attributes,
62338addce8SEmese Revfy 				NULL);
62438addce8SEmese Revfy 
62538addce8SEmese Revfy 	return 0;
62638addce8SEmese Revfy }
627