diff options
author | JF Bastien <jfb@google.com> | 2015-01-14 01:07:26 +0000 |
---|---|---|
committer | JF Bastien <jfb@google.com> | 2015-01-14 01:07:26 +0000 |
commit | dcdd5ad25254e8811fdea76c39a93ecbb992d230 (patch) | |
tree | 203364a0c736a37b118ec4398c1a8c16bd032d7a /llvm/lib/CodeGen/CodeGen.cpp | |
parent | 665026838bbbb861a0b4d23910c352ff0df89d70 (diff) | |
download | bcm5719-llvm-dcdd5ad25254e8811fdea76c39a93ecbb992d230.tar.gz bcm5719-llvm-dcdd5ad25254e8811fdea76c39a93ecbb992d230.zip |
Insert random noops to increase security against ROP attacks (llvm)
A pass that adds random noops to X86 binaries to introduce diversity with the goal of increasing security against most return-oriented programming attacks.
Command line options:
-noop-insertion // Enable noop insertion.
-noop-insertion-percentage=X // X% of assembly instructions will have a noop prepended (default: 50%, requires -noop-insertion)
-max-noops-per-instruction=X // Randomly generate X noops per instruction. ie. roll the dice X times with probability set above (default: 1). This doesn't guarantee X noop instructions.
In addition, the following 'quick switch' in clang enables basic diversity using default settings (currently: noop insertion and schedule randomization; it is intended to be extended in the future).
-fdiversify
This is the llvm part of the patch.
clang part: D3393
http://reviews.llvm.org/D3392
Patch by Stephen Crane (@rinon)
llvm-svn: 225908
Diffstat (limited to 'llvm/lib/CodeGen/CodeGen.cpp')
-rw-r--r-- | llvm/lib/CodeGen/CodeGen.cpp | 1 |
1 files changed, 1 insertions, 0 deletions
diff --git a/llvm/lib/CodeGen/CodeGen.cpp b/llvm/lib/CodeGen/CodeGen.cpp index 307dec548fc..fdb89438115 100644 --- a/llvm/lib/CodeGen/CodeGen.cpp +++ b/llvm/lib/CodeGen/CodeGen.cpp @@ -51,6 +51,7 @@ void llvm::initializeCodeGen(PassRegistry &Registry) { initializeMachineSchedulerPass(Registry); initializeMachineSinkingPass(Registry); initializeMachineVerifierPassPass(Registry); + initializeNoopInsertionPass(Registry); initializeOptimizePHIsPass(Registry); initializePHIEliminationPass(Registry); initializePeepholeOptimizerPass(Registry); |