-
Notifications
You must be signed in to change notification settings - Fork 74
Flags for retpoline mitigation #868
Copy link
Copy link
Closed
Labels
T-compilerAdd this label so rfcbot knows to poll the compiler teamAdd this label so rfcbot knows to poll the compiler teammajor-changeA proposal to make a major change to rustcA proposal to make a major change to rustcmajor-change-acceptedA major change proposal that was acceptedA major change proposal that was accepted
Metadata
Metadata
Assignees
Labels
T-compilerAdd this label so rfcbot knows to poll the compiler teamAdd this label so rfcbot knows to poll the compiler teammajor-changeA proposal to make a major change to rustcA proposal to make a major change to rustcmajor-change-acceptedA major change proposal that was acceptedA major change proposal that was accepted
Type
Fields
Give feedbackNo fields configured for issues without a type.
Proposal
Add two new flags to the compiler called
-Zretpolineand-Zretpoline-external-thunkto configure the compiler to generate return trampolines. The retpoline mitigation is used to mitigate a sidechannel vulnerability known as "Spectre".The flags will be implemented by enabling the following LLVM target features:
-Zretpoline-external-thunkenables+retpoline-external-thunk,+retpoline-indirect-branches,+retpoline-indirect-calls.-Zretpolineenables+retpoline-indirect-branches,+retpoline-indirect-calls.The naming of these flags is taken from clang, where they are called
-mretpolineand-mretpoline-external-thunkrespectively. For uncommon flags such as these, I believe matching the clang names is the best approach. Note that on clang, the latter flag implies the former.I suggest that the flags should utilize the target modifier infrastructure to prevent mixing compilation units with and without the flags because such misuse breaks the mitigation. However, the flag to opt-out from this check does not necessarily need the word "unsafe" because it's not actually part of the ABI
These flags are added with the intent of later stabilizing them, hence this MCP.
The Rust issue for this feature is rust-lang/rust#116852.
Comparison to GCC:
-mretpolineis equivalent to-mindirect-branch=thunk-inline -mindirect-branch-registeron gcc.-mretpoline-external-thunkis equivalent to-mindirect-branch=thunk-extern -mindirect-branch-registeron gcc.Process
The main points of the Major Change Process are as follows:
@rustbot second.-C flag, then full team check-off is required.@rfcbot fcp mergeon either the MCP or the PR.You can read more about Major Change Proposals on forge.