1840 Commits

Author SHA1 Message Date
Anthony Green
e21a39dd59
Update generate-darwin-source-and-headers.py 2025-05-25 11:43:42 -04:00
Anthony Green
f9c60855da Add custom github issue labels for gail 2025-05-24 08:11:37 -04:00
Anthony Green
c6f1610509 feat(testsuite): add mingw64-align.c to test alignment in structs 2025-04-27 08:59:12 -04:00
Anthony Green
571177adcb feat(testsuite): add longjmp test to Makefile and implement longjmp test code 2025-04-27 08:30:35 -04:00
David Tenty
562cb53b5d
Add initializer (#904) 2025-04-25 05:07:57 -04:00
Peter Bergner
aea22de28e
powerpc: Fix closures on powerpc64-linux when statically linking (#900) (#902)
Closures on powerpc64-linux using static trampolines do not work when
statically linking libffi.  The problem is the usage of tramp_globals.text
in libffi assumes it contains the entry point address of the first trampoline.
Powerpc's ffi_tramp_arch code returns &trampoline_code_table which for ABIs
that use function descriptors, ends up returning trampoline_code_table's
function descriptor address instead of its entry point address.  Update
the code to always return the entry point address for all ABIs.
2025-04-18 11:09:45 -04:00
Sam James
a431b47822
pa: add .note.GNU-stack marker to linux.S (#899)
Similarly to f515eac04cf8e5f594d5d9dee5fb7dfc3a186a4c, add a .note.GNU-stack
marker to pa/linux.S as it doesn't need an executable stack. Absence of the
note means that GNU Binutils will consider it as needing an executable stack
and mark it as such automatically.

When building libffi on HPPA with `-Wl,--warn-warn-execstack`, we get:
```
ld: warning: src/pa/.libs/linux.o: missing .note.GNU-stack section implies executable stack
ld: NOTE: This behaviour is deprecated and will be removed in a future version of the linker
```

That becomes more problematic with glibc-2.41 which forbids dlopen()
of a library with an executable stack, and libffi is commonly dlopen()'d,
especially by Python.

I suspect the reason it didn't show up on Debian is that since February,
Debian has been building Binutils with --disable-default-execstack.

Bug: https://bugs.gentoo.org/953805
Bug: https://github.com/libffi/libffi/issues/898
2025-04-15 05:30:27 -04:00
Sam James
6a99edb808
testsuite: add two tests to Makefile.am (#893)
* Add libffi.call/overread.c and libffi.call/x32.c to Makefile.am
  so they're included in dist tarballs

* Fix indentation and rewrap
v3.4.8
2025-04-09 22:44:45 -04:00
Anthony Green
bfb5b005a0 feat: Update version of libffi to 3.4.8 with various fixes and enhancements 2025-04-09 10:32:42 -04:00
Peter Bergner
3429ed6b94
powerpc: Add static trampoline support (#894) (#895)
Add static trampoline support to all three powerpc Linux ABIs, specifically
powerpc-linux (32-bit SYSV BE), powerpc64-linux (64-bit ELFv1 BE) and
powerpc64le-linux (64-bit ELFv2 LE).  This follows the s390x implementation
and does not introduce a ffi_closure_*_alt function, but rather jumps
directly to the ffi_closure_* function itself.  If compiling with
--with-gcc-arch=power10 and pc-relative is enabled, we use a simpler and
smaller trampoline that utilizes Power10's new pc-relative load instructions.
2025-04-08 06:52:37 -04:00
mikulas-patocka
bb1a84ed97
Add the "ABI_ATTR" attribute to called functions (#891) (#892)
I accidentally omitted the "ABI_ATTR" attribute, so that the testsuite
fails when testing the Microsoft ABI.

Fixes: fe203ffbb2bd ("Fix bugs in the x86-64 and x32 target (#887) (#889)")

Signed-off-by: Mikulas Patocka <mikulas@twibright.com>
2025-03-30 06:07:59 -04:00
mikulas-patocka
fe203ffbb2
Fix bugs in the x86-64 and x32 target (#887) (#889)
This commit fixes two bugs in ffi in the x86-64 target. The bugs were
introduced by the commit d21881f55ed4a44d464c9091871e69b0bb47611a ("Fix
x86/ffi64 calls with 6 gp and some sse registers").

The first bug is that when we pass an argument with less than 8 bytes,
ffi will read memory beyond argument end, causing a crash if the argument
is located just before the end of the mapped region.

The second bug is in the x32 ABI - pointers in x32 are 4-byte, but GCC
assumes that the pointer values in the registers are zero-extended. ffi
doesn't respect this assumption, causing crashes in the called library.

For example, when we compile this function for x32:
int fn(int *a)
{
	if (a)
		return *a;
	return -1;
}
we get this code:
fn:
	testq   %rdi, %rdi
	je      .L3
	movl    (%edi), %eax
	ret
.L3:
	movl    $-1, %eax
	ret
When we call this function using ffi with the argument NULL, the function
crashes because top 4 bytes of the RDI register are not cleared.


Fixes: d21881f55ed4 ("Fix x86/ffi64 calls with 6 gp and some sse registers (#848)")

Signed-off-by: Mikulas Patocka <mikulas@twibright.com>
2025-03-26 20:31:49 -04:00
Nikita Samusev
cf69efabca
Update the Simple Example to fix a compile error (#886)
Fixes the following error:
candidate function not viable: no known conversion from 'int (const char *)' to 'void (*)()' for 2nd argument
2025-03-08 06:41:02 -05:00
fossdd
89c99d738f
MIPS: Dont import asm/sgidefs.h on linux (#885)
Removed from Linux since Linux 3.7

Ref: https://web.git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=61730c538f8281efa7ac12596da9f3f9a31b9272
2025-02-28 16:10:10 -05:00
Bill Roberts
5ceddf4071
aarch64: add PAC to GNU Notes (#882)
While PAC was enabled, the bit to indicate support in the GNU Notes
section of the ELF was missing.

Before:
readelf -n ./aarch64-unknown-linux-gnu/.libs/libffi.so

Displaying notes found in: .note.gnu.property
  Owner                Data size 	Description
  GNU                  0x00000010	NT_GNU_PROPERTY_TYPE_0
      Properties: AArch64 feature: BTI

This was caused by this file not having PAC indicated in GNU Notes and
the linker discarding it:
File: ./aarch64-unknown-linux-gnu/src/aarch64/sysv.o

Displaying notes found in: .note.gnu.property
  Owner                Data size        Description
  GNU                  0x00000010       NT_GNU_PROPERTY_TYPE_0
      Properties: AArch64 feature: BTI

Now it has it:
File: ./aarch64-unknown-linux-gnu/src/aarch64/sysv.o

Displaying notes found in: .note.gnu.property
  Owner                Data size        Description
  GNU                  0x00000010       NT_GNU_PROPERTY_TYPE_0
      Properties: AArch64 feature: BTI, PAC

As well as the output shared object:
readelf -n ./aarch64-unknown-linux-gnu/.libs/libffi.so

Displaying notes found in: .note.gnu.property
  Owner                Data size 	Description
  GNU                  0x00000010	NT_GNU_PROPERTY_TYPE_0
      Properties: AArch64 feature: BTI, PAC

Fixes: #881

Signed-off-by: Bill Roberts <bill.roberts@arm.com>
2025-02-20 05:25:21 -05:00
Anthony Green
1716f81e9a feat: remove nios2 support
Acked-by: Anthony Green <green@moxielogic.com>
v3.4.7
2025-02-08 11:32:05 -05:00
Anthony Green
252c0f4636 chore: Bump version to 3.4.7 and update change log 2025-02-08 09:37:58 -05:00
Kleis Auke Wolthuizen
adfe4489c1
Emscripten: remove support for -sWASM_BIGINT=0 (#874)
* Emscripten: cleanup

* Emscripten: remove support for `-sWASM_BIGINT=0`

* Emscripten: remove redundant CircleCI config

* Emscripten: modernize CI

* Ensure test helper methods are static

Similar to #644.

* Fix test failures in `cls_multi_{s,u}shortchar`
2025-01-31 15:41:56 -05:00
Matthew Flatt
2f34cf639c
x86 Darwin returns structs of size 1, 2, 4, and 8 in registers (#876) 2025-01-31 15:40:40 -05:00
zye2-sc
a0d8074a67
Disable go closures on Android (#877)
* x18 register shouldn't be used on Android due to the shadow call stack feature in llvm
* https://source.android.com/docs/security/test/shadow-call-stack
2025-01-31 15:40:00 -05:00
杨萧玉
d77b9fefa2
Fix config.sub on Apple platforms (#860)
* update config.sub

* update config.sub
2024-12-13 05:38:01 -05:00
Satadru Pramanik, DO, MPH, MEng
593cb01a46
Add mold linker to linker checks. (#866)
Signed-off-by: Satadru Pramanik <satadru@gmail.com>
2024-12-13 05:37:15 -05:00
Icenowy Zheng
f515eac04c
MIPS: add .note.GNU-stack section to assembly sources (#872)
To build ELF shared libraries that do not require executable stack on
MIPS, every object file linked should have a .note.GNU-stack section,
otherwise the linker defaults to executable stack.

As libffi shouldn't require executable stack, add the .note.GNU-stack
section to the assembly source files under src/mips, like other
architectures.

Signed-off-by: Icenowy Zheng <uwu@icenowy.me>
2024-12-13 05:36:02 -05:00
Eddy S.
458b2ae282
Add static trampoline support for s390 (#862)
* added static trampoline support for s390

* enable static tramp only for  s390x 64bit
2024-11-16 07:03:24 -05:00
Joseph Myers
0859f84312
Fix testsuite for C23 va_start (#861)
In the C23 revision of the C standard, `va_start` ignores its second
argument, which is no longer required (previously the last named
function parameter - which the compiler knows anyway, so it's
redundant information).

This has the consequence for the libffi testsuite, when making GCC
default to `-std=gnu23`, of making two tests fail with warnings about
an unused function argument (only passed to `va_start` and not
otherwise used).  Fix those test failures by explicitly casting the
argument to `void`.
2024-10-24 14:26:58 -04:00
Ivan Tadeu Ferreira Antunes Filho
8308bed5b2
Move cfi_startproc after CNAME(label) (#857)
This is a fix for https://github.com/libffi/libffi/issues/852: error: invalid CFI advance_loc expression on apple targets.

The CFI for darwin arm64 was broken because the CNAME macro was being used after the
cfi_startproc macro.
2024-09-20 06:01:23 -04:00
KJ Tsanaktsidis
01db744b4a
Disable ASAN in ffi_call_int functions (#858)
The pattern for several of the architectures is for ffi_call_int to
stack-allocate some arguments + the registers, and then
ffi_call_$ARCH will pop the top of that structure into registers, and
then adjust the stack pointer such that the alloca'd buffer _becomes_
the stack-passed arguments for the function being called.

If libffi is compiled with ASAN, then there will be a redzone inserted
after the alloca'd buffer which is marked as poisoned. This redzone
appears beyond the end of $sp upon entry to the called function.

If the called function does anything to use this stack memory, ASAN will
notice that it's poisoned and report an error.

This commit fixes the situation (on the architectures that I have access
to) disabling instrumentation for ffi_call_int; that means there will be
no alloca redzone left on the shadow-stack.
2024-09-20 06:00:49 -04:00
Sam James
f7e4992789
testsuite: fix dejagnu directive typo (#859) 2024-09-20 05:58:06 -04:00
Anthony Green
084f36903f Merge remote-tracking branch 'refs/remotes/origin/master' 2024-09-15 12:32:58 -04:00
Anthony Green
92d384df19 Fix floating point compare 2024-09-15 12:32:29 -04:00
Richard Barnes
348e70ef1c
Suppress unused variable warning in dlmalloc.c (#843)
Allows `-Wunused-but-set-variable` to pass
2024-09-15 07:39:51 -04:00
Yuriy Kolerov
30e887f84e
A series of fixes for ARC port (#844)
* arc: Fix warnings

These warnings are fixed:

1. A series of "unused variables".
2. Implicit conversion from a pointer to uint32_t.

Signed-off-by: Yuriy Kolerov <ykolerov@synopsys.com>

* arc: Do not use mov_s and movl_s instructions

mov_s and movl_s instructions use a restricted set of registers.
However, a list of available registers for such instructions for
one ARC target may not match a list for another ARC targets. For
example, it is applicable to ARC700 and ARC HS3x/4x - build
fails because mov_s formats may be incompatible in some cases.

The easiest and the most straightforward way to fix this issue
is to use mov and movl instead of mov_s and movl_s.

Signed-off-by: Yuriy Kolerov <ykolerov@synopsys.com>

---------

Signed-off-by: Yuriy Kolerov <ykolerov@synopsys.com>
2024-09-15 07:39:01 -04:00
dependabot[bot]
377a136969
Bump actions/download-artifact from 3 to 4.1.7 in /.github/workflows (#856)
Bumps [actions/download-artifact](https://github.com/actions/download-artifact) from 3 to 4.1.7.
- [Release notes](https://github.com/actions/download-artifact/releases)
- [Commits](https://github.com/actions/download-artifact/compare/v3...v4.1.7)

---
updated-dependencies:
- dependency-name: actions/download-artifact
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-09-15 07:38:22 -04:00
Yury V. Zaytsev
c7437f671e
configure: fix shared build on Solaris 10 (#846)
GNU tools are often installed with g-prefix on Solaris. Unfortunately, a check
in configure was using grep directly instead of through a variable, which lead
to wrong results due to missing option `-q`. Additionally, the check will fail
silently if `readelf` is not on `PATH` instead of trying `greadelf`.
2024-09-15 07:37:28 -04:00
Anthony Green
63b925fe98 feat(testsuite): add struct_int_float.c to Makefile.am 2024-09-15 07:32:50 -04:00
Anthony Green
efb98a72d8 Robustify floating point comparison in test 2024-09-15 07:31:33 -04:00
kellda
d21881f55e
Fix x86/ffi64 calls with 6 gp and some sse registers (#848)
* Fix x86/ffi64 calls with 6 gp and some sse registers

* Add test demonstating issue when mixing gp and sse registers
2024-09-15 07:29:42 -04:00
Thomas Petazzoni
8a0d029244
OpenRISC/or1k build fixes (#854)
* src/or1k/ffi.c: fix prototype of ffi_call_SYSV()

The current code base of libffi on OpenRISC (or1k) fails to build with
GCC 14.x with the following error:

../src/or1k/ffi.c: In function 'ffi_call':
../src/or1k/ffi.c:167:34: error: passing argument 3 of 'ffi_call_SYSV' from incompatible pointer type [-Wincompatible-pointer-types]
  167 |       ffi_call_SYSV(size, &ecif, ffi_prep_args, rvalue, fn, cif->flags);
      |                                  ^~~~~~~~~~~~~
      |                                  |
      |                                  void * (*)(char *, extended_cif *)
../src/or1k/ffi.c:113:27: note: expected 'void * (*)(int *, extended_cif *)' but argument is of type 'void * (*)(char *, extended_cif *)'
  113 |                           void *(*)(int *, extended_cif *),
      |                           ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

This is due to the fact that ffi_prep_args() is in fact defined as:

  void* ffi_prep_args(char *stack, extended_cif *ecif)

so, let's fix the prototype of the function pointer, which anyway gets
passed to assembly code, so the typing gets lost.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>

* src/or1k/ffi.c: fix incompatible pointer type

The current code base of libffi on OpenRISC (or1k) fails to build with
GCC 14.x with the following error:

../src/or1k/ffi.c: In function 'ffi_closure_SYSV':
../src/or1k/ffi.c:183:22: error: initialization of 'char *' from incompatible pointer type 'int *' [-Wincompatible-pointer-types]
  183 |   char *stack_args = sp;
      |                      ^~

Indeed:

  register int *sp __asm__ ("r17");
  [..]
  char *stack_args = sp;

Adopt the same logic used for:

  char *ptr = (char *) register_args;

which consists in casting to the desired pointer type. Indeed, later
in the code stack_args is assigned to ptr (so they need to be the same
pointer type), and some arithmetic is done on ptr, so changing its
pointer type would change the behavior.

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>

---------

Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2024-09-15 07:22:36 -04:00
Anthony Green
8e3ef965c2 Fix struct args (Rainer Orth) 2024-06-28 04:07:09 -04:00
Martin Storsjö
9c9e8368e4
aarch64: Add a missing no-op define of SIGN_LR_LINUX_ONLY (#838)
This is needed at least if building for Linux, with a toolchain
that doesn't default to having PAC enabled, fixing build errors
since 45d284f2d066cc3a080c5be88e51b4d934349797.
2024-06-04 07:13:08 -04:00
Anthony Green
6993bc14da Import from upstream 2024-06-01 13:42:29 -04:00
Florian
00bf6e6791
A fix to the struct type example (#837)
Section 2.3.2 Structures of the docs declare `ffi_type`'s  `elements` field to be of type `ffi_type **`.
2024-06-01 13:39:24 -04:00
Bill Roberts
45d284f2d0
aarch64: support pointer authentication (#834)
* aarch64: fix callstack in ffi_call_SYSV

The debug stack gets corrupted between the frame and stack pivots, update
the CFI directives so the call stack stays correct in the debugger.

str     x9, [x1, #32] // stack is ffi_call_SYSV() -> ffi_call_int() -> ffi_call_int() -> main() (good)
mov     x29, x1       // stack is ffi_call_SYSV() -> ffi_call_int() -> ffi_call_int() -> ffi_call() -> main() (bad)
mov     sp, x0        // stack is ffi_call_SYSV() -> ffi_call_int() -> ffi_call_int() -> main() (good)

The CFA data needs to be updated around the pivots, after this patch the
callstack stays correct.

Signed-off-by: Bill Roberts <bill.roberts@arm.com>

* aarch64: remove uneeded CFI directive

This directive doesn't actually set the CFA to anything valid, and
during unwinding this isn't even used. Note that the PAC/Darwin usage
is quite suspect as well, as the CFA is either x1 or x29 after the frame
pivot, and the CFA address is what's used as the modifier when verifying
the PAC. At least this is the behavior on Linux with PAC, I need to
verify ARME ABI unwinding. So for now leave Darwin as is.

Signed-off-by: Bill Roberts <bill.roberts@arm.com>

* ptrauth: rename define for clarity

Rename the HAVE_PTRAUTH define for clarity that its associated with the
ARM64E ABI and not the ARM64 ABI that can be supported on Linux and
enabled with -mbranch-protection=standard.

Signed-off-by: Bill Roberts <bill.roberts@arm.com>

* aarch64: add PAC support to ffi_call_SYSV

Support AARCH64 Pointer Authentication Codes (PAC) within ffi_call_SYSV
and support exception unwinding.

The Linux ABI for PAC is to use paciasp/autiasp instructions which also
have hint space equivelent instructions. They sign the LR (x30) with the
A key and the current stack pointer as the salt. Note that this can also be
configured to use the B key and will use pacibsp/autibsp hint instructions.

The Linux ABI for exception frame data when PAC is enabled assumes that the
Connonical Frame Address, or CFA is equal to the stack pointer. I.E sp is
equal to x29 (fp). When the unwinder is invoked the cfa will point to
the frame which will include the *signed* return address from the LR.
This will then be passed to __builtin_aarch64_autia1716 where the CFA
will be used as the salt and stored to register x16 and register x17
will contain the signed address to demangle. This can be noted in:
  - d6d7afcdbc/libgcc/config/aarch64/aarch64-unwind.h (L56)

The other required portion of this is to indicate to the unwinder that
this is a signed address that needs to go the special demangle route in
the unwinder. This is accomplished by using CFI directive "cfi_window_save"
which marks that frame as being signed.

Putting all of this together is a bit tricky, as the internals of
ffi_call_SYSV the callee allocates its stack and frame and passes it in
arg1 (x0) and arg2 (x1) to the called function, where that function
pivots its stack, so care must be taken to get the sp == fp before
paciasp is called and also restore that state before autiasp is called.

Signed-off-by: Bill Roberts <bill.roberts@arm.com>

---------

Signed-off-by: Bill Roberts <bill.roberts@arm.com>
2024-06-01 13:34:53 -04:00
Bill Roberts
38732240c1
ffi: fix spelling mistake (#833)
Signed-off-by: Bill Roberts <bill.roberts@arm.com>
2024-06-01 13:33:28 -04:00
Bill Roberts
f64141ee3f
Fix bti support (#830)
* bti: add identifier to ffi_closure_SYSV_V_alt

This was missing BTI_C identifier.

Old Code:
ffi_closure_SYSV_V_alt:
0000fffff7f70500:   ldr     x17, [sp, #8]

Signed-off-by: Bill Roberts <bill.roberts@arm.com>

* testsuite: fix whitespace in Makefile.am

Signed-off-by: Bill Roberts <bill.roberts@arm.com>

* aarch64: correct comment describing BTI

The comment is incorrect, BTI is enabled per mapping via mprotect with
PROT_BTI flag set, not per-process. When the loader loads the library,
if the GNU Notes section is missing this, PROT_BTI will not be enabled
for that mapping, but is independent of other mappings.

Signed-off-by: Bill Roberts <bill.roberts@arm.com>

---------

Signed-off-by: Bill Roberts <bill.roberts@arm.com>
2024-03-19 12:44:55 -04:00
Anthony Green
3d0ce1e6fc chore: update version to 3.4.6 and fix long double regression on mips64 and alpha v3.4.6 2024-02-18 09:22:51 -05:00
Anthony Green
94eaedb40e Update sparc64 host 2024-02-18 08:41:04 -05:00
Anthony Green
e1dcf03b46 Update cfarm hostnames 2024-02-18 08:02:45 -05:00
Anthony Green
cd78b53912 Always define long double types. 2024-02-18 07:48:51 -05:00
Anthony Green
012fcaf96c Update v3.4.5 2024-02-15 08:35:02 -05:00