1*6777b538SAndroid Build Coastguard Worker // Copyright 2012 The Chromium Authors
2*6777b538SAndroid Build Coastguard Worker // Use of this source code is governed by a BSD-style license that can be
3*6777b538SAndroid Build Coastguard Worker // found in the LICENSE file.
4*6777b538SAndroid Build Coastguard Worker
5*6777b538SAndroid Build Coastguard Worker #ifndef BASE_COMPILER_SPECIFIC_H_
6*6777b538SAndroid Build Coastguard Worker #define BASE_COMPILER_SPECIFIC_H_
7*6777b538SAndroid Build Coastguard Worker
8*6777b538SAndroid Build Coastguard Worker #include "build/build_config.h"
9*6777b538SAndroid Build Coastguard Worker
10*6777b538SAndroid Build Coastguard Worker #if defined(COMPILER_MSVC) && !defined(__clang__)
11*6777b538SAndroid Build Coastguard Worker #error "Only clang-cl is supported on Windows, see https://crbug.com/988071"
12*6777b538SAndroid Build Coastguard Worker #endif
13*6777b538SAndroid Build Coastguard Worker
14*6777b538SAndroid Build Coastguard Worker // This is a wrapper around `__has_cpp_attribute`, which can be used to test for
15*6777b538SAndroid Build Coastguard Worker // the presence of an attribute. In case the compiler does not support this
16*6777b538SAndroid Build Coastguard Worker // macro it will simply evaluate to 0.
17*6777b538SAndroid Build Coastguard Worker //
18*6777b538SAndroid Build Coastguard Worker // References:
19*6777b538SAndroid Build Coastguard Worker // https://wg21.link/sd6#testing-for-the-presence-of-an-attribute-__has_cpp_attribute
20*6777b538SAndroid Build Coastguard Worker // https://wg21.link/cpp.cond#:__has_cpp_attribute
21*6777b538SAndroid Build Coastguard Worker #if defined(__has_cpp_attribute)
22*6777b538SAndroid Build Coastguard Worker #define HAS_CPP_ATTRIBUTE(x) __has_cpp_attribute(x)
23*6777b538SAndroid Build Coastguard Worker #else
24*6777b538SAndroid Build Coastguard Worker #define HAS_CPP_ATTRIBUTE(x) 0
25*6777b538SAndroid Build Coastguard Worker #endif
26*6777b538SAndroid Build Coastguard Worker
27*6777b538SAndroid Build Coastguard Worker // A wrapper around `__has_attribute`, similar to HAS_CPP_ATTRIBUTE.
28*6777b538SAndroid Build Coastguard Worker #if defined(__has_attribute)
29*6777b538SAndroid Build Coastguard Worker #define HAS_ATTRIBUTE(x) __has_attribute(x)
30*6777b538SAndroid Build Coastguard Worker #else
31*6777b538SAndroid Build Coastguard Worker #define HAS_ATTRIBUTE(x) 0
32*6777b538SAndroid Build Coastguard Worker #endif
33*6777b538SAndroid Build Coastguard Worker
34*6777b538SAndroid Build Coastguard Worker // A wrapper around `__has_builtin`, similar to HAS_CPP_ATTRIBUTE.
35*6777b538SAndroid Build Coastguard Worker #if defined(__has_builtin)
36*6777b538SAndroid Build Coastguard Worker #define HAS_BUILTIN(x) __has_builtin(x)
37*6777b538SAndroid Build Coastguard Worker #else
38*6777b538SAndroid Build Coastguard Worker #define HAS_BUILTIN(x) 0
39*6777b538SAndroid Build Coastguard Worker #endif
40*6777b538SAndroid Build Coastguard Worker
41*6777b538SAndroid Build Coastguard Worker // Annotate a function indicating it should not be inlined.
42*6777b538SAndroid Build Coastguard Worker // Use like:
43*6777b538SAndroid Build Coastguard Worker // NOINLINE void DoStuff() { ... }
44*6777b538SAndroid Build Coastguard Worker #if defined(__clang__) && HAS_ATTRIBUTE(noinline)
45*6777b538SAndroid Build Coastguard Worker #define NOINLINE [[clang::noinline]]
46*6777b538SAndroid Build Coastguard Worker #elif defined(COMPILER_GCC) && HAS_ATTRIBUTE(noinline)
47*6777b538SAndroid Build Coastguard Worker #define NOINLINE __attribute__((noinline))
48*6777b538SAndroid Build Coastguard Worker #elif defined(COMPILER_MSVC)
49*6777b538SAndroid Build Coastguard Worker #define NOINLINE __declspec(noinline)
50*6777b538SAndroid Build Coastguard Worker #else
51*6777b538SAndroid Build Coastguard Worker #define NOINLINE
52*6777b538SAndroid Build Coastguard Worker #endif
53*6777b538SAndroid Build Coastguard Worker
54*6777b538SAndroid Build Coastguard Worker // Annotate a function indicating it should not be optimized.
55*6777b538SAndroid Build Coastguard Worker #if defined(__clang__) && HAS_ATTRIBUTE(optnone)
56*6777b538SAndroid Build Coastguard Worker #define NOOPT [[clang::optnone]]
57*6777b538SAndroid Build Coastguard Worker #elif defined(COMPILER_GCC) && HAS_ATTRIBUTE(optimize)
58*6777b538SAndroid Build Coastguard Worker #define NOOPT __attribute__((optimize(0)))
59*6777b538SAndroid Build Coastguard Worker #else
60*6777b538SAndroid Build Coastguard Worker #define NOOPT
61*6777b538SAndroid Build Coastguard Worker #endif
62*6777b538SAndroid Build Coastguard Worker
63*6777b538SAndroid Build Coastguard Worker #if defined(__clang__) && defined(NDEBUG) && HAS_ATTRIBUTE(always_inline)
64*6777b538SAndroid Build Coastguard Worker #define ALWAYS_INLINE [[clang::always_inline]] inline
65*6777b538SAndroid Build Coastguard Worker #elif defined(COMPILER_GCC) && defined(NDEBUG) && HAS_ATTRIBUTE(always_inline)
66*6777b538SAndroid Build Coastguard Worker #define ALWAYS_INLINE inline __attribute__((__always_inline__))
67*6777b538SAndroid Build Coastguard Worker #elif defined(COMPILER_MSVC) && defined(NDEBUG)
68*6777b538SAndroid Build Coastguard Worker #define ALWAYS_INLINE __forceinline
69*6777b538SAndroid Build Coastguard Worker #else
70*6777b538SAndroid Build Coastguard Worker #define ALWAYS_INLINE inline
71*6777b538SAndroid Build Coastguard Worker #endif
72*6777b538SAndroid Build Coastguard Worker
73*6777b538SAndroid Build Coastguard Worker // Annotate a function indicating it should never be tail called. Useful to make
74*6777b538SAndroid Build Coastguard Worker // sure callers of the annotated function are never omitted from call-stacks.
75*6777b538SAndroid Build Coastguard Worker // To provide the complementary behavior (prevent the annotated function from
76*6777b538SAndroid Build Coastguard Worker // being omitted) look at NOINLINE. Also note that this doesn't prevent code
77*6777b538SAndroid Build Coastguard Worker // folding of multiple identical caller functions into a single signature. To
78*6777b538SAndroid Build Coastguard Worker // prevent code folding, see NO_CODE_FOLDING() in base/debug/alias.h.
79*6777b538SAndroid Build Coastguard Worker // Use like:
80*6777b538SAndroid Build Coastguard Worker // NOT_TAIL_CALLED void FooBar();
81*6777b538SAndroid Build Coastguard Worker #if defined(__clang__) && HAS_ATTRIBUTE(not_tail_called)
82*6777b538SAndroid Build Coastguard Worker #define NOT_TAIL_CALLED [[clang::not_tail_called]]
83*6777b538SAndroid Build Coastguard Worker #else
84*6777b538SAndroid Build Coastguard Worker #define NOT_TAIL_CALLED
85*6777b538SAndroid Build Coastguard Worker #endif
86*6777b538SAndroid Build Coastguard Worker
87*6777b538SAndroid Build Coastguard Worker // Specify memory alignment for structs, classes, etc.
88*6777b538SAndroid Build Coastguard Worker // Use like:
89*6777b538SAndroid Build Coastguard Worker // class ALIGNAS(16) MyClass { ... }
90*6777b538SAndroid Build Coastguard Worker // ALIGNAS(16) int array[4];
91*6777b538SAndroid Build Coastguard Worker //
92*6777b538SAndroid Build Coastguard Worker // In most places you can use the C++11 keyword "alignas", which is preferred.
93*6777b538SAndroid Build Coastguard Worker //
94*6777b538SAndroid Build Coastguard Worker // Historically, compilers had trouble mixing __attribute__((...)) syntax with
95*6777b538SAndroid Build Coastguard Worker // alignas(...) syntax. However, at least Clang is very accepting nowadays. It
96*6777b538SAndroid Build Coastguard Worker // may be that this macro can be removed entirely.
97*6777b538SAndroid Build Coastguard Worker #if defined(__clang__)
98*6777b538SAndroid Build Coastguard Worker #define ALIGNAS(byte_alignment) alignas(byte_alignment)
99*6777b538SAndroid Build Coastguard Worker #elif defined(COMPILER_MSVC)
100*6777b538SAndroid Build Coastguard Worker #define ALIGNAS(byte_alignment) __declspec(align(byte_alignment))
101*6777b538SAndroid Build Coastguard Worker #elif defined(COMPILER_GCC) && HAS_ATTRIBUTE(aligned)
102*6777b538SAndroid Build Coastguard Worker #define ALIGNAS(byte_alignment) __attribute__((aligned(byte_alignment)))
103*6777b538SAndroid Build Coastguard Worker #endif
104*6777b538SAndroid Build Coastguard Worker
105*6777b538SAndroid Build Coastguard Worker // In case the compiler supports it NO_UNIQUE_ADDRESS evaluates to the C++20
106*6777b538SAndroid Build Coastguard Worker // attribute [[no_unique_address]]. This allows annotating data members so that
107*6777b538SAndroid Build Coastguard Worker // they need not have an address distinct from all other non-static data members
108*6777b538SAndroid Build Coastguard Worker // of its class.
109*6777b538SAndroid Build Coastguard Worker //
110*6777b538SAndroid Build Coastguard Worker // References:
111*6777b538SAndroid Build Coastguard Worker // * https://en.cppreference.com/w/cpp/language/attributes/no_unique_address
112*6777b538SAndroid Build Coastguard Worker // * https://wg21.link/dcl.attr.nouniqueaddr
113*6777b538SAndroid Build Coastguard Worker #if defined(COMPILER_MSVC) && HAS_CPP_ATTRIBUTE(msvc::no_unique_address)
114*6777b538SAndroid Build Coastguard Worker // Unfortunately MSVC ignores [[no_unique_address]] (see
115*6777b538SAndroid Build Coastguard Worker // https://devblogs.microsoft.com/cppblog/msvc-cpp20-and-the-std-cpp20-switch/#msvc-extensions-and-abi),
116*6777b538SAndroid Build Coastguard Worker // and clang-cl matches it for ABI compatibility reasons. We need to prefer
117*6777b538SAndroid Build Coastguard Worker // [[msvc::no_unique_address]] when available if we actually want any effect.
118*6777b538SAndroid Build Coastguard Worker #define NO_UNIQUE_ADDRESS [[msvc::no_unique_address]]
119*6777b538SAndroid Build Coastguard Worker #elif HAS_CPP_ATTRIBUTE(no_unique_address)
120*6777b538SAndroid Build Coastguard Worker #define NO_UNIQUE_ADDRESS [[no_unique_address]]
121*6777b538SAndroid Build Coastguard Worker #else
122*6777b538SAndroid Build Coastguard Worker #define NO_UNIQUE_ADDRESS
123*6777b538SAndroid Build Coastguard Worker #endif
124*6777b538SAndroid Build Coastguard Worker
125*6777b538SAndroid Build Coastguard Worker // Tells the compiler a function is using a printf-style format string.
126*6777b538SAndroid Build Coastguard Worker // |format_param| is the one-based index of the format string parameter;
127*6777b538SAndroid Build Coastguard Worker // |dots_param| is the one-based index of the "..." parameter.
128*6777b538SAndroid Build Coastguard Worker // For v*printf functions (which take a va_list), pass 0 for dots_param.
129*6777b538SAndroid Build Coastguard Worker // (This is undocumented but matches what the system C headers do.)
130*6777b538SAndroid Build Coastguard Worker // For member functions, the implicit this parameter counts as index 1.
131*6777b538SAndroid Build Coastguard Worker #if (defined(COMPILER_GCC) || defined(__clang__)) && HAS_ATTRIBUTE(format)
132*6777b538SAndroid Build Coastguard Worker #define PRINTF_FORMAT(format_param, dots_param) \
133*6777b538SAndroid Build Coastguard Worker __attribute__((format(printf, format_param, dots_param)))
134*6777b538SAndroid Build Coastguard Worker #else
135*6777b538SAndroid Build Coastguard Worker #define PRINTF_FORMAT(format_param, dots_param)
136*6777b538SAndroid Build Coastguard Worker #endif
137*6777b538SAndroid Build Coastguard Worker
138*6777b538SAndroid Build Coastguard Worker // WPRINTF_FORMAT is the same, but for wide format strings.
139*6777b538SAndroid Build Coastguard Worker // This doesn't appear to yet be implemented in any compiler.
140*6777b538SAndroid Build Coastguard Worker // See http://gcc.gnu.org/bugzilla/show_bug.cgi?id=38308 .
141*6777b538SAndroid Build Coastguard Worker #define WPRINTF_FORMAT(format_param, dots_param)
142*6777b538SAndroid Build Coastguard Worker // If available, it would look like:
143*6777b538SAndroid Build Coastguard Worker // __attribute__((format(wprintf, format_param, dots_param)))
144*6777b538SAndroid Build Coastguard Worker
145*6777b538SAndroid Build Coastguard Worker // Sanitizers annotations.
146*6777b538SAndroid Build Coastguard Worker #if HAS_ATTRIBUTE(no_sanitize)
147*6777b538SAndroid Build Coastguard Worker #define NO_SANITIZE(what) __attribute__((no_sanitize(what)))
148*6777b538SAndroid Build Coastguard Worker #endif
149*6777b538SAndroid Build Coastguard Worker #if !defined(NO_SANITIZE)
150*6777b538SAndroid Build Coastguard Worker #define NO_SANITIZE(what)
151*6777b538SAndroid Build Coastguard Worker #endif
152*6777b538SAndroid Build Coastguard Worker
153*6777b538SAndroid Build Coastguard Worker // MemorySanitizer annotations.
154*6777b538SAndroid Build Coastguard Worker #if defined(MEMORY_SANITIZER) && !BUILDFLAG(IS_NACL)
155*6777b538SAndroid Build Coastguard Worker #include <sanitizer/msan_interface.h>
156*6777b538SAndroid Build Coastguard Worker
157*6777b538SAndroid Build Coastguard Worker // Mark a memory region fully initialized.
158*6777b538SAndroid Build Coastguard Worker // Use this to annotate code that deliberately reads uninitialized data, for
159*6777b538SAndroid Build Coastguard Worker // example a GC scavenging root set pointers from the stack.
160*6777b538SAndroid Build Coastguard Worker #define MSAN_UNPOISON(p, size) __msan_unpoison(p, size)
161*6777b538SAndroid Build Coastguard Worker
162*6777b538SAndroid Build Coastguard Worker // Check a memory region for initializedness, as if it was being used here.
163*6777b538SAndroid Build Coastguard Worker // If any bits are uninitialized, crash with an MSan report.
164*6777b538SAndroid Build Coastguard Worker // Use this to sanitize data which MSan won't be able to track, e.g. before
165*6777b538SAndroid Build Coastguard Worker // passing data to another process via shared memory.
166*6777b538SAndroid Build Coastguard Worker #define MSAN_CHECK_MEM_IS_INITIALIZED(p, size) \
167*6777b538SAndroid Build Coastguard Worker __msan_check_mem_is_initialized(p, size)
168*6777b538SAndroid Build Coastguard Worker #else // MEMORY_SANITIZER
169*6777b538SAndroid Build Coastguard Worker #define MSAN_UNPOISON(p, size)
170*6777b538SAndroid Build Coastguard Worker #define MSAN_CHECK_MEM_IS_INITIALIZED(p, size)
171*6777b538SAndroid Build Coastguard Worker #endif // MEMORY_SANITIZER
172*6777b538SAndroid Build Coastguard Worker
173*6777b538SAndroid Build Coastguard Worker // DISABLE_CFI_PERF -- Disable Control Flow Integrity for perf reasons.
174*6777b538SAndroid Build Coastguard Worker #if !defined(DISABLE_CFI_PERF)
175*6777b538SAndroid Build Coastguard Worker #if defined(__clang__) && defined(OFFICIAL_BUILD)
176*6777b538SAndroid Build Coastguard Worker #define DISABLE_CFI_PERF NO_SANITIZE("cfi")
177*6777b538SAndroid Build Coastguard Worker #else
178*6777b538SAndroid Build Coastguard Worker #define DISABLE_CFI_PERF
179*6777b538SAndroid Build Coastguard Worker #endif
180*6777b538SAndroid Build Coastguard Worker #endif
181*6777b538SAndroid Build Coastguard Worker
182*6777b538SAndroid Build Coastguard Worker // DISABLE_CFI_ICALL -- Disable Control Flow Integrity indirect call checks.
183*6777b538SAndroid Build Coastguard Worker // Security Note: if you just need to allow calling of dlsym functions use
184*6777b538SAndroid Build Coastguard Worker // DISABLE_CFI_DLSYM.
185*6777b538SAndroid Build Coastguard Worker #if !defined(DISABLE_CFI_ICALL)
186*6777b538SAndroid Build Coastguard Worker #if BUILDFLAG(IS_WIN)
187*6777b538SAndroid Build Coastguard Worker // Windows also needs __declspec(guard(nocf)).
188*6777b538SAndroid Build Coastguard Worker #define DISABLE_CFI_ICALL NO_SANITIZE("cfi-icall") __declspec(guard(nocf))
189*6777b538SAndroid Build Coastguard Worker #else
190*6777b538SAndroid Build Coastguard Worker #define DISABLE_CFI_ICALL NO_SANITIZE("cfi-icall")
191*6777b538SAndroid Build Coastguard Worker #endif
192*6777b538SAndroid Build Coastguard Worker #endif
193*6777b538SAndroid Build Coastguard Worker #if !defined(DISABLE_CFI_ICALL)
194*6777b538SAndroid Build Coastguard Worker #define DISABLE_CFI_ICALL
195*6777b538SAndroid Build Coastguard Worker #endif
196*6777b538SAndroid Build Coastguard Worker
197*6777b538SAndroid Build Coastguard Worker // DISABLE_CFI_DLSYM -- applies DISABLE_CFI_ICALL on platforms where dlsym
198*6777b538SAndroid Build Coastguard Worker // functions must be called. Retains CFI checks on platforms where loaded
199*6777b538SAndroid Build Coastguard Worker // modules participate in CFI (e.g. Windows).
200*6777b538SAndroid Build Coastguard Worker #if !defined(DISABLE_CFI_DLSYM)
201*6777b538SAndroid Build Coastguard Worker #if BUILDFLAG(IS_WIN)
202*6777b538SAndroid Build Coastguard Worker // Windows modules register functions when loaded so can be checked by CFG.
203*6777b538SAndroid Build Coastguard Worker #define DISABLE_CFI_DLSYM
204*6777b538SAndroid Build Coastguard Worker #else
205*6777b538SAndroid Build Coastguard Worker #define DISABLE_CFI_DLSYM DISABLE_CFI_ICALL
206*6777b538SAndroid Build Coastguard Worker #endif
207*6777b538SAndroid Build Coastguard Worker #endif
208*6777b538SAndroid Build Coastguard Worker #if !defined(DISABLE_CFI_DLSYM)
209*6777b538SAndroid Build Coastguard Worker #define DISABLE_CFI_DLSYM
210*6777b538SAndroid Build Coastguard Worker #endif
211*6777b538SAndroid Build Coastguard Worker
212*6777b538SAndroid Build Coastguard Worker // Macro useful for writing cross-platform function pointers.
213*6777b538SAndroid Build Coastguard Worker #if !defined(CDECL)
214*6777b538SAndroid Build Coastguard Worker #if BUILDFLAG(IS_WIN)
215*6777b538SAndroid Build Coastguard Worker #define CDECL __cdecl
216*6777b538SAndroid Build Coastguard Worker #else // BUILDFLAG(IS_WIN)
217*6777b538SAndroid Build Coastguard Worker #define CDECL
218*6777b538SAndroid Build Coastguard Worker #endif // BUILDFLAG(IS_WIN)
219*6777b538SAndroid Build Coastguard Worker #endif // !defined(CDECL)
220*6777b538SAndroid Build Coastguard Worker
221*6777b538SAndroid Build Coastguard Worker // Macro for hinting that an expression is likely to be false.
222*6777b538SAndroid Build Coastguard Worker #if !defined(UNLIKELY)
223*6777b538SAndroid Build Coastguard Worker #if defined(COMPILER_GCC) || defined(__clang__)
224*6777b538SAndroid Build Coastguard Worker #define UNLIKELY(x) __builtin_expect(!!(x), 0)
225*6777b538SAndroid Build Coastguard Worker #else
226*6777b538SAndroid Build Coastguard Worker #define UNLIKELY(x) (x)
227*6777b538SAndroid Build Coastguard Worker #endif // defined(COMPILER_GCC)
228*6777b538SAndroid Build Coastguard Worker #endif // !defined(UNLIKELY)
229*6777b538SAndroid Build Coastguard Worker
230*6777b538SAndroid Build Coastguard Worker #if !defined(LIKELY)
231*6777b538SAndroid Build Coastguard Worker #if defined(COMPILER_GCC) || defined(__clang__)
232*6777b538SAndroid Build Coastguard Worker #define LIKELY(x) __builtin_expect(!!(x), 1)
233*6777b538SAndroid Build Coastguard Worker #else
234*6777b538SAndroid Build Coastguard Worker #define LIKELY(x) (x)
235*6777b538SAndroid Build Coastguard Worker #endif // defined(COMPILER_GCC)
236*6777b538SAndroid Build Coastguard Worker #endif // !defined(LIKELY)
237*6777b538SAndroid Build Coastguard Worker
238*6777b538SAndroid Build Coastguard Worker // Compiler feature-detection.
239*6777b538SAndroid Build Coastguard Worker // clang.llvm.org/docs/LanguageExtensions.html#has-feature-and-has-extension
240*6777b538SAndroid Build Coastguard Worker #if defined(__has_feature)
241*6777b538SAndroid Build Coastguard Worker #define HAS_FEATURE(FEATURE) __has_feature(FEATURE)
242*6777b538SAndroid Build Coastguard Worker #else
243*6777b538SAndroid Build Coastguard Worker #define HAS_FEATURE(FEATURE) 0
244*6777b538SAndroid Build Coastguard Worker #endif
245*6777b538SAndroid Build Coastguard Worker
246*6777b538SAndroid Build Coastguard Worker #if defined(COMPILER_GCC)
247*6777b538SAndroid Build Coastguard Worker #define PRETTY_FUNCTION __PRETTY_FUNCTION__
248*6777b538SAndroid Build Coastguard Worker #elif defined(COMPILER_MSVC)
249*6777b538SAndroid Build Coastguard Worker #define PRETTY_FUNCTION __FUNCSIG__
250*6777b538SAndroid Build Coastguard Worker #else
251*6777b538SAndroid Build Coastguard Worker // See https://en.cppreference.com/w/c/language/function_definition#func
252*6777b538SAndroid Build Coastguard Worker #define PRETTY_FUNCTION __func__
253*6777b538SAndroid Build Coastguard Worker #endif
254*6777b538SAndroid Build Coastguard Worker
255*6777b538SAndroid Build Coastguard Worker #if !defined(CPU_ARM_NEON)
256*6777b538SAndroid Build Coastguard Worker #if defined(__arm__)
257*6777b538SAndroid Build Coastguard Worker #if !defined(__ARMEB__) && !defined(__ARM_EABI__) && !defined(__EABI__) && \
258*6777b538SAndroid Build Coastguard Worker !defined(__VFP_FP__) && !defined(_WIN32_WCE) && !defined(ANDROID)
259*6777b538SAndroid Build Coastguard Worker #error Chromium does not support middle endian architecture
260*6777b538SAndroid Build Coastguard Worker #endif
261*6777b538SAndroid Build Coastguard Worker #if defined(__ARM_NEON__)
262*6777b538SAndroid Build Coastguard Worker #define CPU_ARM_NEON 1
263*6777b538SAndroid Build Coastguard Worker #endif
264*6777b538SAndroid Build Coastguard Worker #endif // defined(__arm__)
265*6777b538SAndroid Build Coastguard Worker #endif // !defined(CPU_ARM_NEON)
266*6777b538SAndroid Build Coastguard Worker
267*6777b538SAndroid Build Coastguard Worker #if !defined(HAVE_MIPS_MSA_INTRINSICS)
268*6777b538SAndroid Build Coastguard Worker #if defined(__mips_msa) && defined(__mips_isa_rev) && (__mips_isa_rev >= 5)
269*6777b538SAndroid Build Coastguard Worker #define HAVE_MIPS_MSA_INTRINSICS 1
270*6777b538SAndroid Build Coastguard Worker #endif
271*6777b538SAndroid Build Coastguard Worker #endif
272*6777b538SAndroid Build Coastguard Worker
273*6777b538SAndroid Build Coastguard Worker #if defined(__clang__) && HAS_ATTRIBUTE(uninitialized)
274*6777b538SAndroid Build Coastguard Worker // Attribute "uninitialized" disables -ftrivial-auto-var-init=pattern for
275*6777b538SAndroid Build Coastguard Worker // the specified variable.
276*6777b538SAndroid Build Coastguard Worker // Library-wide alternative is
277*6777b538SAndroid Build Coastguard Worker // 'configs -= [ "//build/config/compiler:default_init_stack_vars" ]' in .gn
278*6777b538SAndroid Build Coastguard Worker // file.
279*6777b538SAndroid Build Coastguard Worker //
280*6777b538SAndroid Build Coastguard Worker // See "init_stack_vars" in build/config/compiler/BUILD.gn and
281*6777b538SAndroid Build Coastguard Worker // http://crbug.com/977230
282*6777b538SAndroid Build Coastguard Worker // "init_stack_vars" is enabled for non-official builds and we hope to enable it
283*6777b538SAndroid Build Coastguard Worker // in official build in 2020 as well. The flag writes fixed pattern into
284*6777b538SAndroid Build Coastguard Worker // uninitialized parts of all local variables. In rare cases such initialization
285*6777b538SAndroid Build Coastguard Worker // is undesirable and attribute can be used:
286*6777b538SAndroid Build Coastguard Worker // 1. Degraded performance
287*6777b538SAndroid Build Coastguard Worker // In most cases compiler is able to remove additional stores. E.g. if memory is
288*6777b538SAndroid Build Coastguard Worker // never accessed or properly initialized later. Preserved stores mostly will
289*6777b538SAndroid Build Coastguard Worker // not affect program performance. However if compiler failed on some
290*6777b538SAndroid Build Coastguard Worker // performance critical code we can get a visible regression in a benchmark.
291*6777b538SAndroid Build Coastguard Worker // 2. memset, memcpy calls
292*6777b538SAndroid Build Coastguard Worker // Compiler may replaces some memory writes with memset or memcpy calls. This is
293*6777b538SAndroid Build Coastguard Worker // not -ftrivial-auto-var-init specific, but it can happen more likely with the
294*6777b538SAndroid Build Coastguard Worker // flag. It can be a problem if code is not linked with C run-time library.
295*6777b538SAndroid Build Coastguard Worker //
296*6777b538SAndroid Build Coastguard Worker // Note: The flag is security risk mitigation feature. So in future the
297*6777b538SAndroid Build Coastguard Worker // attribute uses should be avoided when possible. However to enable this
298*6777b538SAndroid Build Coastguard Worker // mitigation on the most of the code we need to be less strict now and minimize
299*6777b538SAndroid Build Coastguard Worker // number of exceptions later. So if in doubt feel free to use attribute, but
300*6777b538SAndroid Build Coastguard Worker // please document the problem for someone who is going to cleanup it later.
301*6777b538SAndroid Build Coastguard Worker // E.g. platform, bot, benchmark or test name in patch description or next to
302*6777b538SAndroid Build Coastguard Worker // the attribute.
303*6777b538SAndroid Build Coastguard Worker #define STACK_UNINITIALIZED [[clang::uninitialized]]
304*6777b538SAndroid Build Coastguard Worker #else
305*6777b538SAndroid Build Coastguard Worker #define STACK_UNINITIALIZED
306*6777b538SAndroid Build Coastguard Worker #endif
307*6777b538SAndroid Build Coastguard Worker
308*6777b538SAndroid Build Coastguard Worker // Attribute "no_stack_protector" disables -fstack-protector for the specified
309*6777b538SAndroid Build Coastguard Worker // function.
310*6777b538SAndroid Build Coastguard Worker //
311*6777b538SAndroid Build Coastguard Worker // "stack_protector" is enabled on most POSIX builds. The flag adds a canary
312*6777b538SAndroid Build Coastguard Worker // to each stack frame, which on function return is checked against a reference
313*6777b538SAndroid Build Coastguard Worker // canary. If the canaries do not match, it's likely that a stack buffer
314*6777b538SAndroid Build Coastguard Worker // overflow has occurred, so immediately crashing will prevent exploitation in
315*6777b538SAndroid Build Coastguard Worker // many cases.
316*6777b538SAndroid Build Coastguard Worker //
317*6777b538SAndroid Build Coastguard Worker // In some cases it's desirable to remove this, e.g. on hot functions, or if
318*6777b538SAndroid Build Coastguard Worker // we have purposely changed the reference canary.
319*6777b538SAndroid Build Coastguard Worker #if defined(COMPILER_GCC) || defined(__clang__)
320*6777b538SAndroid Build Coastguard Worker #if HAS_ATTRIBUTE(__no_stack_protector__)
321*6777b538SAndroid Build Coastguard Worker #define NO_STACK_PROTECTOR __attribute__((__no_stack_protector__))
322*6777b538SAndroid Build Coastguard Worker #else
323*6777b538SAndroid Build Coastguard Worker #define NO_STACK_PROTECTOR __attribute__((__optimize__("-fno-stack-protector")))
324*6777b538SAndroid Build Coastguard Worker #endif
325*6777b538SAndroid Build Coastguard Worker #else
326*6777b538SAndroid Build Coastguard Worker #define NO_STACK_PROTECTOR
327*6777b538SAndroid Build Coastguard Worker #endif
328*6777b538SAndroid Build Coastguard Worker
329*6777b538SAndroid Build Coastguard Worker // The ANALYZER_ASSUME_TRUE(bool arg) macro adds compiler-specific hints
330*6777b538SAndroid Build Coastguard Worker // to Clang which control what code paths are statically analyzed,
331*6777b538SAndroid Build Coastguard Worker // and is meant to be used in conjunction with assert & assert-like functions.
332*6777b538SAndroid Build Coastguard Worker // The expression is passed straight through if analysis isn't enabled.
333*6777b538SAndroid Build Coastguard Worker //
334*6777b538SAndroid Build Coastguard Worker // ANALYZER_SKIP_THIS_PATH() suppresses static analysis for the current
335*6777b538SAndroid Build Coastguard Worker // codepath and any other branching codepaths that might follow.
336*6777b538SAndroid Build Coastguard Worker #if defined(__clang_analyzer__)
337*6777b538SAndroid Build Coastguard Worker
AnalyzerNoReturn()338*6777b538SAndroid Build Coastguard Worker inline constexpr bool AnalyzerNoReturn() __attribute__((analyzer_noreturn)) {
339*6777b538SAndroid Build Coastguard Worker return false;
340*6777b538SAndroid Build Coastguard Worker }
341*6777b538SAndroid Build Coastguard Worker
AnalyzerAssumeTrue(bool arg)342*6777b538SAndroid Build Coastguard Worker inline constexpr bool AnalyzerAssumeTrue(bool arg) {
343*6777b538SAndroid Build Coastguard Worker // AnalyzerNoReturn() is invoked and analysis is terminated if |arg| is
344*6777b538SAndroid Build Coastguard Worker // false.
345*6777b538SAndroid Build Coastguard Worker return arg || AnalyzerNoReturn();
346*6777b538SAndroid Build Coastguard Worker }
347*6777b538SAndroid Build Coastguard Worker
348*6777b538SAndroid Build Coastguard Worker #define ANALYZER_ASSUME_TRUE(arg) ::AnalyzerAssumeTrue(!!(arg))
349*6777b538SAndroid Build Coastguard Worker #define ANALYZER_SKIP_THIS_PATH() static_cast<void>(::AnalyzerNoReturn())
350*6777b538SAndroid Build Coastguard Worker
351*6777b538SAndroid Build Coastguard Worker #else // !defined(__clang_analyzer__)
352*6777b538SAndroid Build Coastguard Worker
353*6777b538SAndroid Build Coastguard Worker #define ANALYZER_ASSUME_TRUE(arg) (arg)
354*6777b538SAndroid Build Coastguard Worker #define ANALYZER_SKIP_THIS_PATH()
355*6777b538SAndroid Build Coastguard Worker
356*6777b538SAndroid Build Coastguard Worker #endif // defined(__clang_analyzer__)
357*6777b538SAndroid Build Coastguard Worker
358*6777b538SAndroid Build Coastguard Worker // Use nomerge attribute to disable optimization of merging multiple same calls.
359*6777b538SAndroid Build Coastguard Worker #if defined(__clang__) && HAS_ATTRIBUTE(nomerge)
360*6777b538SAndroid Build Coastguard Worker #define NOMERGE [[clang::nomerge]]
361*6777b538SAndroid Build Coastguard Worker #else
362*6777b538SAndroid Build Coastguard Worker #define NOMERGE
363*6777b538SAndroid Build Coastguard Worker #endif
364*6777b538SAndroid Build Coastguard Worker
365*6777b538SAndroid Build Coastguard Worker // Marks a type as being eligible for the "trivial" ABI despite having a
366*6777b538SAndroid Build Coastguard Worker // non-trivial destructor or copy/move constructor. Such types can be relocated
367*6777b538SAndroid Build Coastguard Worker // after construction by simply copying their memory, which makes them eligible
368*6777b538SAndroid Build Coastguard Worker // to be passed in registers. The canonical example is std::unique_ptr.
369*6777b538SAndroid Build Coastguard Worker //
370*6777b538SAndroid Build Coastguard Worker // Use with caution; this has some subtle effects on constructor/destructor
371*6777b538SAndroid Build Coastguard Worker // ordering and will be very incorrect if the type relies on its address
372*6777b538SAndroid Build Coastguard Worker // remaining constant. When used as a function argument (by value), the value
373*6777b538SAndroid Build Coastguard Worker // may be constructed in the caller's stack frame, passed in a register, and
374*6777b538SAndroid Build Coastguard Worker // then used and destructed in the callee's stack frame. A similar thing can
375*6777b538SAndroid Build Coastguard Worker // occur when values are returned.
376*6777b538SAndroid Build Coastguard Worker //
377*6777b538SAndroid Build Coastguard Worker // TRIVIAL_ABI is not needed for types which have a trivial destructor and
378*6777b538SAndroid Build Coastguard Worker // copy/move constructors, such as base::TimeTicks and other POD.
379*6777b538SAndroid Build Coastguard Worker //
380*6777b538SAndroid Build Coastguard Worker // It is also not likely to be effective on types too large to be passed in one
381*6777b538SAndroid Build Coastguard Worker // or two registers on typical target ABIs.
382*6777b538SAndroid Build Coastguard Worker //
383*6777b538SAndroid Build Coastguard Worker // See also:
384*6777b538SAndroid Build Coastguard Worker // https://clang.llvm.org/docs/AttributeReference.html#trivial-abi
385*6777b538SAndroid Build Coastguard Worker // https://libcxx.llvm.org/docs/DesignDocs/UniquePtrTrivialAbi.html
386*6777b538SAndroid Build Coastguard Worker #if defined(__clang__) && HAS_ATTRIBUTE(trivial_abi)
387*6777b538SAndroid Build Coastguard Worker #define TRIVIAL_ABI [[clang::trivial_abi]]
388*6777b538SAndroid Build Coastguard Worker #else
389*6777b538SAndroid Build Coastguard Worker #define TRIVIAL_ABI
390*6777b538SAndroid Build Coastguard Worker #endif
391*6777b538SAndroid Build Coastguard Worker
392*6777b538SAndroid Build Coastguard Worker // Detect whether a type is trivially relocatable, ie. a move-and-destroy
393*6777b538SAndroid Build Coastguard Worker // sequence can replaced with memmove(). This can be used to optimise the
394*6777b538SAndroid Build Coastguard Worker // implementation of containers. This is automatically true for types that were
395*6777b538SAndroid Build Coastguard Worker // defined with TRIVIAL_ABI such as scoped_refptr.
396*6777b538SAndroid Build Coastguard Worker //
397*6777b538SAndroid Build Coastguard Worker // See also:
398*6777b538SAndroid Build Coastguard Worker // https://www.open-std.org/jtc1/sc22/wg21/docs/papers/2023/p1144r8.html
399*6777b538SAndroid Build Coastguard Worker // https://clang.llvm.org/docs/LanguageExtensions.html#:~:text=__is_trivially_relocatable
400*6777b538SAndroid Build Coastguard Worker #if defined(__clang__) && HAS_BUILTIN(__is_trivially_relocatable)
401*6777b538SAndroid Build Coastguard Worker #define IS_TRIVIALLY_RELOCATABLE(t) __is_trivially_relocatable(t)
402*6777b538SAndroid Build Coastguard Worker #else
403*6777b538SAndroid Build Coastguard Worker #define IS_TRIVIALLY_RELOCATABLE(t) false
404*6777b538SAndroid Build Coastguard Worker #endif
405*6777b538SAndroid Build Coastguard Worker
406*6777b538SAndroid Build Coastguard Worker // Marks a member function as reinitializing a moved-from variable.
407*6777b538SAndroid Build Coastguard Worker // See also
408*6777b538SAndroid Build Coastguard Worker // https://clang.llvm.org/extra/clang-tidy/checks/bugprone/use-after-move.html#reinitialization
409*6777b538SAndroid Build Coastguard Worker #if defined(__clang__) && HAS_ATTRIBUTE(reinitializes)
410*6777b538SAndroid Build Coastguard Worker #define REINITIALIZES_AFTER_MOVE [[clang::reinitializes]]
411*6777b538SAndroid Build Coastguard Worker #else
412*6777b538SAndroid Build Coastguard Worker #define REINITIALIZES_AFTER_MOVE
413*6777b538SAndroid Build Coastguard Worker #endif
414*6777b538SAndroid Build Coastguard Worker
415*6777b538SAndroid Build Coastguard Worker #if defined(__clang__)
416*6777b538SAndroid Build Coastguard Worker #define GSL_OWNER [[gsl::Owner]]
417*6777b538SAndroid Build Coastguard Worker #define GSL_POINTER [[gsl::Pointer]]
418*6777b538SAndroid Build Coastguard Worker #else
419*6777b538SAndroid Build Coastguard Worker #define GSL_OWNER
420*6777b538SAndroid Build Coastguard Worker #define GSL_POINTER
421*6777b538SAndroid Build Coastguard Worker #endif
422*6777b538SAndroid Build Coastguard Worker
423*6777b538SAndroid Build Coastguard Worker // Adds the "logically_const" tag to a symbol's mangled name. The "Mutable
424*6777b538SAndroid Build Coastguard Worker // Constants" check [1] detects instances of constants that aren't in .rodata,
425*6777b538SAndroid Build Coastguard Worker // e.g. due to a missing `const`. Using this tag suppresses the check for this
426*6777b538SAndroid Build Coastguard Worker // symbol, allowing it to live outside .rodata without a warning.
427*6777b538SAndroid Build Coastguard Worker //
428*6777b538SAndroid Build Coastguard Worker // [1]:
429*6777b538SAndroid Build Coastguard Worker // https://crsrc.org/c/docs/speed/binary_size/android_binary_size_trybot.md#Mutable-Constants
430*6777b538SAndroid Build Coastguard Worker #if defined(COMPILER_GCC) || defined(__clang__)
431*6777b538SAndroid Build Coastguard Worker #define LOGICALLY_CONST [[gnu::abi_tag("logically_const")]]
432*6777b538SAndroid Build Coastguard Worker #else
433*6777b538SAndroid Build Coastguard Worker #define LOGICALLY_CONST
434*6777b538SAndroid Build Coastguard Worker #endif
435*6777b538SAndroid Build Coastguard Worker
436*6777b538SAndroid Build Coastguard Worker // preserve_most clang's calling convention. Reduces register pressure for the
437*6777b538SAndroid Build Coastguard Worker // caller and as such can be used for cold calls. Support for the
438*6777b538SAndroid Build Coastguard Worker // "preserve_most" attribute is limited:
439*6777b538SAndroid Build Coastguard Worker // - 32-bit platforms do not implement it,
440*6777b538SAndroid Build Coastguard Worker // - component builds fail because _dl_runtime_resolve() clobbers registers,
441*6777b538SAndroid Build Coastguard Worker // - there are crashes on arm64 on Windows (https://crbug.com/v8/14065), which
442*6777b538SAndroid Build Coastguard Worker // can hopefully be fixed in the future.
443*6777b538SAndroid Build Coastguard Worker // Additionally, the initial implementation in clang <= 16 overwrote the return
444*6777b538SAndroid Build Coastguard Worker // register(s) in the epilogue of a preserve_most function, so we only use
445*6777b538SAndroid Build Coastguard Worker // preserve_most in clang >= 17 (see https://reviews.llvm.org/D143425).
446*6777b538SAndroid Build Coastguard Worker // Clang only supports preserve_most on X86-64 and AArch64 for now.
447*6777b538SAndroid Build Coastguard Worker // See https://clang.llvm.org/docs/AttributeReference.html#preserve-most for
448*6777b538SAndroid Build Coastguard Worker // more details.
449*6777b538SAndroid Build Coastguard Worker #if (defined(ARCH_CPU_ARM64) || defined(ARCH_CPU_X86_64)) && \
450*6777b538SAndroid Build Coastguard Worker !(BUILDFLAG(IS_WIN) && defined(ARCH_CPU_ARM64)) && \
451*6777b538SAndroid Build Coastguard Worker !defined(COMPONENT_BUILD) && defined(__clang__) && \
452*6777b538SAndroid Build Coastguard Worker __clang_major__ >= 17 && HAS_ATTRIBUTE(preserve_most)
453*6777b538SAndroid Build Coastguard Worker #define PRESERVE_MOST __attribute__((preserve_most))
454*6777b538SAndroid Build Coastguard Worker #else
455*6777b538SAndroid Build Coastguard Worker #define PRESERVE_MOST
456*6777b538SAndroid Build Coastguard Worker #endif
457*6777b538SAndroid Build Coastguard Worker
458*6777b538SAndroid Build Coastguard Worker // Mark parameters or return types as having a lifetime attached to the class.
459*6777b538SAndroid Build Coastguard Worker //
460*6777b538SAndroid Build Coastguard Worker // When used to mark a method's pointer/reference parameter, the compiler is
461*6777b538SAndroid Build Coastguard Worker // made aware that it will be stored internally in the class and the pointee
462*6777b538SAndroid Build Coastguard Worker // must outlive the class. Typically used on constructor arguments. It should
463*6777b538SAndroid Build Coastguard Worker // appear to the right of the parameter's variable name.
464*6777b538SAndroid Build Coastguard Worker //
465*6777b538SAndroid Build Coastguard Worker // Example:
466*6777b538SAndroid Build Coastguard Worker // ```
467*6777b538SAndroid Build Coastguard Worker // struct S {
468*6777b538SAndroid Build Coastguard Worker // S(int* p LIFETIME_BOUND) : ptr_(p) {}
469*6777b538SAndroid Build Coastguard Worker //
470*6777b538SAndroid Build Coastguard Worker // int* ptr_;
471*6777b538SAndroid Build Coastguard Worker // };
472*6777b538SAndroid Build Coastguard Worker // ```
473*6777b538SAndroid Build Coastguard Worker //
474*6777b538SAndroid Build Coastguard Worker // When used on a method with a return value, the compiler is made aware that
475*6777b538SAndroid Build Coastguard Worker // the returned type is/has a pointer to the internals of the class, and must
476*6777b538SAndroid Build Coastguard Worker // not outlive the class object. It should appear after any method qualifiers.
477*6777b538SAndroid Build Coastguard Worker //
478*6777b538SAndroid Build Coastguard Worker // Example:
479*6777b538SAndroid Build Coastguard Worker // ```
480*6777b538SAndroid Build Coastguard Worker // struct S {
481*6777b538SAndroid Build Coastguard Worker // int* GetPtr() const LIFETIME_BOUND { return i_; };
482*6777b538SAndroid Build Coastguard Worker //
483*6777b538SAndroid Build Coastguard Worker // int i_;
484*6777b538SAndroid Build Coastguard Worker // };
485*6777b538SAndroid Build Coastguard Worker // ```
486*6777b538SAndroid Build Coastguard Worker //
487*6777b538SAndroid Build Coastguard Worker // This allows the compiler to warn in (a limited set of) cases where the
488*6777b538SAndroid Build Coastguard Worker // pointer would otherwise be left dangling, especially in cases where the
489*6777b538SAndroid Build Coastguard Worker // pointee would be a destroyed temporary.
490*6777b538SAndroid Build Coastguard Worker //
491*6777b538SAndroid Build Coastguard Worker // Docs: https://clang.llvm.org/docs/AttributeReference.html#lifetimebound
492*6777b538SAndroid Build Coastguard Worker #if defined(__clang__)
493*6777b538SAndroid Build Coastguard Worker #define LIFETIME_BOUND [[clang::lifetimebound]]
494*6777b538SAndroid Build Coastguard Worker #else
495*6777b538SAndroid Build Coastguard Worker #define LIFETIME_BOUND
496*6777b538SAndroid Build Coastguard Worker #endif
497*6777b538SAndroid Build Coastguard Worker
498*6777b538SAndroid Build Coastguard Worker // Mark a function as pure, meaning that it does not have side effects, meaning
499*6777b538SAndroid Build Coastguard Worker // that it does not write anything external to the function's local variables
500*6777b538SAndroid Build Coastguard Worker // and return value.
501*6777b538SAndroid Build Coastguard Worker //
502*6777b538SAndroid Build Coastguard Worker // WARNING: If this attribute is mis-used it will result in UB and
503*6777b538SAndroid Build Coastguard Worker // miscompilation, as the optimizator may fold multiple calls into one and
504*6777b538SAndroid Build Coastguard Worker // reorder them inappropriately. This shouldn't appear outside of key vocabulary
505*6777b538SAndroid Build Coastguard Worker // types. It allows callers to work with the vocab type directly, and call its
506*6777b538SAndroid Build Coastguard Worker // methods without having to worry about caching things into local variables in
507*6777b538SAndroid Build Coastguard Worker // hot code.
508*6777b538SAndroid Build Coastguard Worker //
509*6777b538SAndroid Build Coastguard Worker // This attribute must not appear on functions that make use of function
510*6777b538SAndroid Build Coastguard Worker // pointers, virtual methods, or methods of templates (including operators like
511*6777b538SAndroid Build Coastguard Worker // comparison), as the "pure" function can not know what those functions do and
512*6777b538SAndroid Build Coastguard Worker // can not guarantee there will never be sideeffects.
513*6777b538SAndroid Build Coastguard Worker #if defined(COMPILER_GCC) || defined(__clang__)
514*6777b538SAndroid Build Coastguard Worker #define PURE_FUNCTION [[gnu::pure]]
515*6777b538SAndroid Build Coastguard Worker #else
516*6777b538SAndroid Build Coastguard Worker #define PURE_FUNCTION
517*6777b538SAndroid Build Coastguard Worker #endif
518*6777b538SAndroid Build Coastguard Worker
519*6777b538SAndroid Build Coastguard Worker // Functions should be marked with UNSAFE_BUFFER_USAGE when they lead to
520*6777b538SAndroid Build Coastguard Worker // out-of-bounds bugs when called with incorrect inputs.
521*6777b538SAndroid Build Coastguard Worker //
522*6777b538SAndroid Build Coastguard Worker // Ideally such functions should be paired with a safer version that works with
523*6777b538SAndroid Build Coastguard Worker // safe primitives like `base::span`. Otherwise, another safer coding pattern
524*6777b538SAndroid Build Coastguard Worker // should be documented along side the use of `UNSAFE_BUFFER_USAGE`.
525*6777b538SAndroid Build Coastguard Worker //
526*6777b538SAndroid Build Coastguard Worker // All functions marked with UNSAFE_BUFFER_USAGE should come with a safety
527*6777b538SAndroid Build Coastguard Worker // comment that explains the requirements of the function to prevent an
528*6777b538SAndroid Build Coastguard Worker // out-of-bounds bug. For example:
529*6777b538SAndroid Build Coastguard Worker // ```
530*6777b538SAndroid Build Coastguard Worker // // Function to do things between `input` and `end`.
531*6777b538SAndroid Build Coastguard Worker // //
532*6777b538SAndroid Build Coastguard Worker // // # Safety
533*6777b538SAndroid Build Coastguard Worker // // The `input` must point to an array with size at least 5. The `end` must
534*6777b538SAndroid Build Coastguard Worker // // point within the same allocation of `input` and not come before `input`.
535*6777b538SAndroid Build Coastguard Worker // ```
536*6777b538SAndroid Build Coastguard Worker //
537*6777b538SAndroid Build Coastguard Worker // The requirements described in the safety comment must be sufficient to
538*6777b538SAndroid Build Coastguard Worker // guarantee that the function never goes out of bounds. Annotating a function
539*6777b538SAndroid Build Coastguard Worker // in this way means that all callers will be required to wrap the call in an
540*6777b538SAndroid Build Coastguard Worker // `UNSAFE_BUFFERS()` macro (see below), with a comment justifying how it meets
541*6777b538SAndroid Build Coastguard Worker // the requirements.
542*6777b538SAndroid Build Coastguard Worker #if defined(__clang__) && HAS_ATTRIBUTE(unsafe_buffer_usage)
543*6777b538SAndroid Build Coastguard Worker #define UNSAFE_BUFFER_USAGE [[clang::unsafe_buffer_usage]]
544*6777b538SAndroid Build Coastguard Worker #else
545*6777b538SAndroid Build Coastguard Worker #define UNSAFE_BUFFER_USAGE
546*6777b538SAndroid Build Coastguard Worker #endif
547*6777b538SAndroid Build Coastguard Worker
548*6777b538SAndroid Build Coastguard Worker // UNSAFE_BUFFERS() wraps code that violates the -Wunsafe-buffer-usage warning,
549*6777b538SAndroid Build Coastguard Worker // such as:
550*6777b538SAndroid Build Coastguard Worker // - pointer arithmetic,
551*6777b538SAndroid Build Coastguard Worker // - pointer subscripting, and
552*6777b538SAndroid Build Coastguard Worker // - calls to functions annotated with UNSAFE_BUFFER_USAGE.
553*6777b538SAndroid Build Coastguard Worker //
554*6777b538SAndroid Build Coastguard Worker // This indicates code whose bounds correctness cannot be ensured
555*6777b538SAndroid Build Coastguard Worker // systematically, and thus requires manual review.
556*6777b538SAndroid Build Coastguard Worker //
557*6777b538SAndroid Build Coastguard Worker // ** USE OF THIS MACRO SHOULD BE VERY RARE.** This should only be used when
558*6777b538SAndroid Build Coastguard Worker // strictly necessary. Prefer to use `base::span` instead of pointers, or other
559*6777b538SAndroid Build Coastguard Worker // safer coding patterns (like std containers) that avoid the opportunity for
560*6777b538SAndroid Build Coastguard Worker // out-of-bounds bugs to creep into the code. Any use of UNSAFE_BUFFERS() can
561*6777b538SAndroid Build Coastguard Worker // lead to a critical security bug if any assumptions are wrong, or ever become
562*6777b538SAndroid Build Coastguard Worker // wrong in the future.
563*6777b538SAndroid Build Coastguard Worker //
564*6777b538SAndroid Build Coastguard Worker // The macro should be used to wrap the minimum necessary code, to make it clear
565*6777b538SAndroid Build Coastguard Worker // what is unsafe, and prevent accidentally opting extra things out of the
566*6777b538SAndroid Build Coastguard Worker // warning.
567*6777b538SAndroid Build Coastguard Worker //
568*6777b538SAndroid Build Coastguard Worker // All usage of UNSAFE_BUFFERS() should come with a `// SAFETY: ...` comment
569*6777b538SAndroid Build Coastguard Worker // that explains how we have guaranteed that the pointer usage can never go
570*6777b538SAndroid Build Coastguard Worker // out-of-bounds, or that the requirements of the UNSAFE_BUFFER_USAGE function
571*6777b538SAndroid Build Coastguard Worker // are met. The safety comment should allow a reader to check that all
572*6777b538SAndroid Build Coastguard Worker // requirements have been met, using only local invariants. Examples of local
573*6777b538SAndroid Build Coastguard Worker // invariants include:
574*6777b538SAndroid Build Coastguard Worker // - Runtime conditions or CHECKs near the UNSAFE_BUFFERS macros
575*6777b538SAndroid Build Coastguard Worker // - Invariants guaranteed by types in the surrounding code
576*6777b538SAndroid Build Coastguard Worker // - Invariants guaranteed by function calls in the surrounding code
577*6777b538SAndroid Build Coastguard Worker // - Caller requirements, if the containing function is itself marked with
578*6777b538SAndroid Build Coastguard Worker // UNSAFE_BUFFER_USAGE
579*6777b538SAndroid Build Coastguard Worker //
580*6777b538SAndroid Build Coastguard Worker // The last case should be an option of last resort. It is less safe and will
581*6777b538SAndroid Build Coastguard Worker // require the caller also use the UNSAFE_BUFFERS() macro. Prefer directly
582*6777b538SAndroid Build Coastguard Worker // capturing such invariants in types like `base::span`.
583*6777b538SAndroid Build Coastguard Worker //
584*6777b538SAndroid Build Coastguard Worker // Safety explanations may not rely on invariants that are not fully
585*6777b538SAndroid Build Coastguard Worker // encapsulated close to the UNSAFE_BUFFERS() usage. Instead, use safer coding
586*6777b538SAndroid Build Coastguard Worker // patterns or stronger invariants.
587*6777b538SAndroid Build Coastguard Worker #if defined(__clang__)
588*6777b538SAndroid Build Coastguard Worker // clang-format off
589*6777b538SAndroid Build Coastguard Worker // Formatting is off so that we can put each _Pragma on its own line, as
590*6777b538SAndroid Build Coastguard Worker // recommended by the gcc docs.
591*6777b538SAndroid Build Coastguard Worker #define UNSAFE_BUFFERS(...) \
592*6777b538SAndroid Build Coastguard Worker _Pragma("clang unsafe_buffer_usage begin") \
593*6777b538SAndroid Build Coastguard Worker __VA_ARGS__ \
594*6777b538SAndroid Build Coastguard Worker _Pragma("clang unsafe_buffer_usage end")
595*6777b538SAndroid Build Coastguard Worker // clang-format on
596*6777b538SAndroid Build Coastguard Worker #else
597*6777b538SAndroid Build Coastguard Worker #define UNSAFE_BUFFERS(...) __VA_ARGS__
598*6777b538SAndroid Build Coastguard Worker #endif
599*6777b538SAndroid Build Coastguard Worker
600*6777b538SAndroid Build Coastguard Worker // Defines a condition for a function to be checked at compile time if the
601*6777b538SAndroid Build Coastguard Worker // parameter's value is known at compile time. If the condition is failed, the
602*6777b538SAndroid Build Coastguard Worker // function is omitted from the overload set resolution, much like `requires`.
603*6777b538SAndroid Build Coastguard Worker //
604*6777b538SAndroid Build Coastguard Worker // If the parameter is a runtime value, then the condition is unable to be
605*6777b538SAndroid Build Coastguard Worker // checked and the function will be omitted from the overload set resolution.
606*6777b538SAndroid Build Coastguard Worker // This ensures the function can only be called with values known at compile
607*6777b538SAndroid Build Coastguard Worker // time. This is a clang extension.
608*6777b538SAndroid Build Coastguard Worker //
609*6777b538SAndroid Build Coastguard Worker // Example:
610*6777b538SAndroid Build Coastguard Worker // ```
611*6777b538SAndroid Build Coastguard Worker // void f(int a) ENABLE_IF_ATTR(a > 0) {}
612*6777b538SAndroid Build Coastguard Worker // f(1); // Ok.
613*6777b538SAndroid Build Coastguard Worker // f(0); // Error: no valid f() found.
614*6777b538SAndroid Build Coastguard Worker // ```
615*6777b538SAndroid Build Coastguard Worker //
616*6777b538SAndroid Build Coastguard Worker // The `ENABLE_IF_ATTR` annotation is preferred over `consteval` with a check
617*6777b538SAndroid Build Coastguard Worker // that breaks compile because metaprogramming does not observe such checks. So
618*6777b538SAndroid Build Coastguard Worker // with `consteval`, the function looks callable to concepts/type_traits but is
619*6777b538SAndroid Build Coastguard Worker // not and will fail to compile even though it reports it's usable. Whereas
620*6777b538SAndroid Build Coastguard Worker // `ENABLE_IF_ATTR` interacts correctly with metaprogramming. This is especially
621*6777b538SAndroid Build Coastguard Worker // painful for constructors. See also
622*6777b538SAndroid Build Coastguard Worker // https://github.com/chromium/subspace/issues/266.
623*6777b538SAndroid Build Coastguard Worker #if defined(__clang__)
624*6777b538SAndroid Build Coastguard Worker #define ENABLE_IF_ATTR(cond, msg) __attribute__((enable_if(cond, msg)))
625*6777b538SAndroid Build Coastguard Worker #else
626*6777b538SAndroid Build Coastguard Worker #define ENABLE_IF_ATTR(cond, msg)
627*6777b538SAndroid Build Coastguard Worker #endif
628*6777b538SAndroid Build Coastguard Worker
629*6777b538SAndroid Build Coastguard Worker #endif // BASE_COMPILER_SPECIFIC_H_
630