Skip to content

Commit 8ecbfa6

Browse files
authored
Hot-patch __ref_* variables should be placed in .rdata, not .data (#151008)
This is a refinment of #145565 . That PR added support for "Windows Secure Hot-patching". In this design, functions that are compiled for hot-patching need to be modified when they access mutable global variables. The modification is to insert a level of indirection, the so-called `__ref_*` variables. Ref variables are supposed to be inserted into the `.rdata` section, not `.data`. This provides a degree of protection against modification (accidental or malicious) of ref variables during program execution. When the Windows hot-patch subsystem loads a module as a hot-patch, it finds all ref variables and changes the page protections for the pages containing them to read/write. Then it sets the ref variables to point to the real variable locations within the base image. Then it changes page protections back to read-only. This relies on the variables being placed in the `.rdata` section, not `.data`. However, it is still important that the LLVM `GlobalVariable` that is created for the ref variable be created with `isConstant = false`. This prevents LLVM from optimizing accesses to the `GlobalVariable`, i.e. assuming that the variable can never change and thus inlining its value into expressions that would ordinarily dereference it. That optimization would defeat the purpose of hot-patching, so `isConstant = false` is still the correct value for these ref variables.
1 parent ee63c1f commit 8ecbfa6

File tree

1 file changed

+13
-0
lines changed

1 file changed

+13
-0
lines changed

llvm/lib/CodeGen/WindowsSecureHotPatching.cpp

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -369,6 +369,19 @@ static GlobalVariable *getOrCreateRefVariable(
369369
AddrOfOldGV, Twine("__ref_").concat(GV->getName()),
370370
nullptr, GlobalVariable::NotThreadLocal);
371371

372+
// RefGV is created with isConstant = false, but we want to place RefGV into
373+
// .rdata, not .data. It is important that the GlobalVariable be mutable
374+
// from the compiler's point of view, so that the optimizer does not remove
375+
// the global variable entirely and replace all references to it with its
376+
// initial value.
377+
//
378+
// When the Windows hot-patch loader applies a hot-patch, it maps the
379+
// pages of .rdata as read/write so that it can set each __ref_* variable
380+
// to point to the original variable in the base image. Afterward, pages in
381+
// .rdata are remapped as read-only. This protects the __ref_* variables from
382+
// being overwritten during execution.
383+
RefGV->setSection(".rdata");
384+
372385
// Create debug info for the replacement global variable.
373386
DataLayout Layout = M->getDataLayout();
374387
DIType *DebugType = DebugInfo.createPointerType(

0 commit comments

Comments
 (0)