diff mbox series

[for-9.0] meson.build: Disable -fzero-call-used-regs on OpenBSD

Message ID 20240411120819.56417-1-thuth@redhat.com
State New
Headers show
Series [for-9.0] meson.build: Disable -fzero-call-used-regs on OpenBSD | expand

Commit Message

Thomas Huth April 11, 2024, 12:08 p.m. UTC
QEMU currently does not work on OpenBSD since the -fzero-call-used-regs
option that we added to meson.build recently does not work with the
"retguard" extension from OpenBSD's Clang. Thus let's disable the
-fzero-call-used-regs here until there's a better solution available.

Resolves: https://gitlab.com/qemu-project/qemu/-/issues/2278
Signed-off-by: Thomas Huth <thuth@redhat.com>
---
 Note: Given that we're close to the release, I think the host_os check
 is the best we can do ... the problem does not seem to trigger in all
 functions, only if certain registers are used by the compiler, so a
 more sophisticated check here seems to be too fragile to me right now.

 meson.build | 6 +++++-
 1 file changed, 5 insertions(+), 1 deletion(-)

Comments

Thomas Huth April 11, 2024, 12:12 p.m. UTC | #1
On 11/04/2024 14.08, Thomas Huth wrote:
> QEMU currently does not work on OpenBSD since the -fzero-call-used-regs

That should be "OpenBSD 7.5" ... older versions are fine since they are 
using an older version of Clang that does not have -fzero-call-used-regs 
yet, I think.

  Thomas


> option that we added to meson.build recently does not work with the
> "retguard" extension from OpenBSD's Clang. Thus let's disable the
> -fzero-call-used-regs here until there's a better solution available.
> 
> Resolves: https://gitlab.com/qemu-project/qemu/-/issues/2278
> Signed-off-by: Thomas Huth <thuth@redhat.com>
> ---
>   Note: Given that we're close to the release, I think the host_os check
>   is the best we can do ... the problem does not seem to trigger in all
>   functions, only if certain registers are used by the compiler, so a
>   more sophisticated check here seems to be too fragile to me right now.
> 
>   meson.build | 6 +++++-
>   1 file changed, 5 insertions(+), 1 deletion(-)
> 
> diff --git a/meson.build b/meson.build
> index c9c3217ba4..91a0aa64c6 100644
> --- a/meson.build
> +++ b/meson.build
> @@ -562,7 +562,11 @@ hardening_flags = [
>   #
>   # NB: Clang 17 is broken and SEGVs
>   # https://github.com/llvm/llvm-project/issues/75168
> -if cc.compiles('extern struct { void (*cb)(void); } s; void f(void) { s.cb(); }',
> +#
> +# NB2: This clashes with the "retguard" extension of OpenBSD's Clang
> +# https://gitlab.com/qemu-project/qemu/-/issues/2278
> +if host_os != 'openbsd' and \
> +   cc.compiles('extern struct { void (*cb)(void); } s; void f(void) { s.cb(); }',
>                  name: '-fzero-call-used-regs=used-gpr',
>                  args: ['-O2', '-fzero-call-used-regs=used-gpr'])
>       hardening_flags += '-fzero-call-used-regs=used-gpr'
Philippe Mathieu-Daudé April 11, 2024, 2:56 p.m. UTC | #2
On 11/4/24 14:08, Thomas Huth wrote:
> QEMU currently does not work on OpenBSD since the -fzero-call-used-regs
> option that we added to meson.build recently does not work with the
> "retguard" extension from OpenBSD's Clang. Thus let's disable the
> -fzero-call-used-regs here until there's a better solution available.
> 
> Resolves: https://gitlab.com/qemu-project/qemu/-/issues/2278
> Signed-off-by: Thomas Huth <thuth@redhat.com>
> ---
>   Note: Given that we're close to the release, I think the host_os check
>   is the best we can do ... the problem does not seem to trigger in all
>   functions, only if certain registers are used by the compiler, so a
>   more sophisticated check here seems to be too fragile to me right now.
> 
>   meson.build | 6 +++++-
>   1 file changed, 5 insertions(+), 1 deletion(-)
> 
> diff --git a/meson.build b/meson.build
> index c9c3217ba4..91a0aa64c6 100644
> --- a/meson.build
> +++ b/meson.build
> @@ -562,7 +562,11 @@ hardening_flags = [
>   #
>   # NB: Clang 17 is broken and SEGVs
>   # https://github.com/llvm/llvm-project/issues/75168
> -if cc.compiles('extern struct { void (*cb)(void); } s; void f(void) { s.cb(); }',
> +#
> +# NB2: This clashes with the "retguard" extension of OpenBSD's Clang
> +# https://gitlab.com/qemu-project/qemu/-/issues/2278
> +if host_os != 'openbsd' and \
> +   cc.compiles('extern struct { void (*cb)(void); } s; void f(void) { s.cb(); }',
>                  name: '-fzero-call-used-regs=used-gpr',
>                  args: ['-O2', '-fzero-call-used-regs=used-gpr'])
>       hardening_flags += '-fzero-call-used-regs=used-gpr'

Reviewed-by: Philippe Mathieu-Daudé <philmd@linaro.org>
Brad Smith April 11, 2024, 8:28 p.m. UTC | #3
On 4/11/2024 8:12 AM, Thomas Huth wrote:
> On 11/04/2024 14.08, Thomas Huth wrote:
>> QEMU currently does not work on OpenBSD since the -fzero-call-used-regs
>
> That should be "OpenBSD 7.5" ... older versions are fine since they 
> are using an older version of Clang that does not have 
> -fzero-call-used-regs yet, I think.

About the compiler version that is correct. Between 7.4 and 7.5 we 
upgraded from Clang 13 to 16.

-fzero-call-used-regs  was added with the 15 release.

https://github.com/llvm/llvm-project/commit/deaf22bc0e306bc44c70d2503e9364b5ed312c49

Retguard is also used to mitigate ROP exploits and is enabled by default.

https://www.openbsd.org/papers/asiabsdcon2019-rop-paper.pdf
Paolo Bonzini April 12, 2024, 10:02 a.m. UTC | #4
Queued, thanks.

Paolo
diff mbox series

Patch

diff --git a/meson.build b/meson.build
index c9c3217ba4..91a0aa64c6 100644
--- a/meson.build
+++ b/meson.build
@@ -562,7 +562,11 @@  hardening_flags = [
 #
 # NB: Clang 17 is broken and SEGVs
 # https://github.com/llvm/llvm-project/issues/75168
-if cc.compiles('extern struct { void (*cb)(void); } s; void f(void) { s.cb(); }',
+#
+# NB2: This clashes with the "retguard" extension of OpenBSD's Clang
+# https://gitlab.com/qemu-project/qemu/-/issues/2278
+if host_os != 'openbsd' and \
+   cc.compiles('extern struct { void (*cb)(void); } s; void f(void) { s.cb(); }',
                name: '-fzero-call-used-regs=used-gpr',
                args: ['-O2', '-fzero-call-used-regs=used-gpr'])
     hardening_flags += '-fzero-call-used-regs=used-gpr'