Skip to main content

Control

Enum Control 

Source
pub enum Control {
    None,
    Branch,
    Return,
    Full,
    Check,
}
Expand description

Which control flow transfers are checked, which is what -fcf-protection= asks.

Two mechanisms and one flag, because the hardware turns them on together and a program built for one and not the other is a program with a hole in whichever half was left out. The forward edge is an indirect call or jump, and it is checked by a landing pad at every address one is allowed to arrive at, so a corrupted function pointer reaches somewhere somebody meant rather than any byte of the program. The backward edge is a return, and it is checked against a second copy of the return address the program cannot write to, which needs no instructions at all: the machine keeps the copy and the loader turns it on.

Which is why the marker matters as much as the code. An object says in a note which halves it was built for, the linker takes the intersection over every input, and the loader turns on what survives. One object built without the note is enough to turn the whole program’s protection off, so the note goes in even for a mode that changes no instruction.

Variants§

§

None

-fcf-protection=none and -fno-cf-protection, and what a command line that says nothing gets. gcc’s own default is the same on the targets this compiler has a back end for.

§

Branch

-fcf-protection=branch. The forward edge alone: a landing pad at every function, and a note that asks for the check on indirect transfers and not on returns.

§

Return

-fcf-protection=return. The backward edge alone, which is the note and nothing else, since the copy of the return address is the machine’s own and no instruction maintains it.

§

Full

-fcf-protection=full, and what the bare -fcf-protection means. Both halves.

§

Check

-fcf-protection=check. Asks that the compilation be checked for compatibility with the mode rather than built in it, so nothing is instrumented and no note is written, which is exactly what gcc emits for it.

Implementations§

Source§

impl Control

Source

pub const fn branch(self) -> bool

Whether a landing pad goes at the top of every function.

Source

pub const fn ret(self) -> bool

Whether returns are asked to be checked against the machine’s own copy.

Source

pub const fn any(self) -> bool

Whether anything at all is asked for, which is what decides whether the file says what it was built for.

False for the two modes that build nothing. Control::None asks for nothing and Control::Check asks that the compilation be looked at rather than changed, and gcc writes no note for either.

Source

pub const fn as_str(self) -> &'static str

What the argument was spelled as, which is the part after the equals sign.

Trait Implementations§

Source§

impl Clone for Control

Source§

fn clone(&self) -> Control

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Copy for Control

Source§

impl Debug for Control

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Default for Control

Source§

fn default() -> Control

Returns the “default value” for a type. Read more
Source§

impl Display for Control

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Eq for Control

Source§

impl FromStr for Control

Source§

fn from_str(s: &str) -> Result<Self, ()>

Parses the part after -fcf-protection=.

Source§

type Err = ()

The associated error which can be returned from parsing.
Source§

impl Hash for Control

Source§

fn hash<__H: Hasher>(&self, state: &mut __H)

Feeds this value into the given Hasher. Read more
1.3.0 · Source§

fn hash_slice<H>(data: &[Self], state: &mut H)
where H: Hasher, Self: Sized,

Feeds a slice of this type into the given Hasher. Read more
Source§

impl Ord for Control

Source§

fn cmp(&self, other: &Control) -> Ordering

This method returns an Ordering between self and other. Read more
1.21.0 (const: unstable) · Source§

fn max(self, other: Self) -> Self
where Self: Sized,

Compares and returns the maximum of two values. Read more
1.21.0 (const: unstable) · Source§

fn min(self, other: Self) -> Self
where Self: Sized,

Compares and returns the minimum of two values. Read more
1.50.0 (const: unstable) · Source§

fn clamp(self, min: Self, max: Self) -> Self
where Self: Sized,

Restrict a value to a certain interval. Read more
Source§

fn clamp_to<R>(self, range: R) -> Self
where Self: Sized, R: ClampBounds<Self>,

🔬This is a nightly-only experimental API. (clamp_to)
Restrict a value to a certain range. Read more
Source§

impl PartialEq for Control

Source§

fn eq(&self, other: &Control) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl PartialOrd for Control

Source§

fn partial_cmp(&self, other: &Control) -> Option<Ordering>

This method returns an ordering between self and other values if one exists. Read more
1.0.0 (const: unstable) · Source§

fn lt(&self, other: &Rhs) -> bool

Tests less than (for self and other) and is used by the < operator. Read more
1.0.0 (const: unstable) · Source§

fn le(&self, other: &Rhs) -> bool

Tests less than or equal to (for self and other) and is used by the <= operator. Read more
1.0.0 (const: unstable) · Source§

fn gt(&self, other: &Rhs) -> bool

Tests greater than (for self and other) and is used by the > operator. Read more
1.0.0 (const: unstable) · Source§

fn ge(&self, other: &Rhs) -> bool

Tests greater than or equal to (for self and other) and is used by the >= operator. Read more
Source§

impl StructuralPartialEq for Control

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T> ToString for T
where T: Display + ?Sized,

Source§

fn to_string(&self) -> String

Converts the given value to a String. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.