xref: /xnu-10002.81.5/EXTERNAL_HEADERS/ptrauth.h (revision 5e3eaea39dcf651e66cb99ba7d70e32cc4a99587)
1*5e3eaea3SApple OSS Distributions /*===---- ptrauth.h - Pointer authentication -------------------------------===
2*5e3eaea3SApple OSS Distributions  *
3*5e3eaea3SApple OSS Distributions  * Permission is hereby granted, free of charge, to any person obtaining a copy
4*5e3eaea3SApple OSS Distributions  * of this software and associated documentation files (the "Software"), to deal
5*5e3eaea3SApple OSS Distributions  * in the Software without restriction, including without limitation the rights
6*5e3eaea3SApple OSS Distributions  * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
7*5e3eaea3SApple OSS Distributions  * copies of the Software, and to permit persons to whom the Software is
8*5e3eaea3SApple OSS Distributions  * furnished to do so, subject to the following conditions:
9*5e3eaea3SApple OSS Distributions  *
10*5e3eaea3SApple OSS Distributions  * The above copyright notice and this permission notice shall be included in
11*5e3eaea3SApple OSS Distributions  * all copies or substantial portions of the Software.
12*5e3eaea3SApple OSS Distributions  *
13*5e3eaea3SApple OSS Distributions  * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
14*5e3eaea3SApple OSS Distributions  * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
15*5e3eaea3SApple OSS Distributions  * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
16*5e3eaea3SApple OSS Distributions  * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
17*5e3eaea3SApple OSS Distributions  * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
18*5e3eaea3SApple OSS Distributions  * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
19*5e3eaea3SApple OSS Distributions  * THE SOFTWARE.
20*5e3eaea3SApple OSS Distributions  *
21*5e3eaea3SApple OSS Distributions  *===-----------------------------------------------------------------------===
22*5e3eaea3SApple OSS Distributions  */
23*5e3eaea3SApple OSS Distributions 
24*5e3eaea3SApple OSS Distributions #ifndef __PTRAUTH_H
25*5e3eaea3SApple OSS Distributions #define __PTRAUTH_H
26*5e3eaea3SApple OSS Distributions 
27*5e3eaea3SApple OSS Distributions #include <stdint.h>
28*5e3eaea3SApple OSS Distributions 
29*5e3eaea3SApple OSS Distributions typedef enum {
30*5e3eaea3SApple OSS Distributions   ptrauth_key_asia = 0,
31*5e3eaea3SApple OSS Distributions   ptrauth_key_asib = 1,
32*5e3eaea3SApple OSS Distributions   ptrauth_key_asda = 2,
33*5e3eaea3SApple OSS Distributions   ptrauth_key_asdb = 3,
34*5e3eaea3SApple OSS Distributions 
35*5e3eaea3SApple OSS Distributions   /* A process-independent key which can be used to sign code pointers.
36*5e3eaea3SApple OSS Distributions      Signing and authenticating with this key is a no-op in processes
37*5e3eaea3SApple OSS Distributions      which disable ABI pointer authentication. */
38*5e3eaea3SApple OSS Distributions   ptrauth_key_process_independent_code = ptrauth_key_asia,
39*5e3eaea3SApple OSS Distributions 
40*5e3eaea3SApple OSS Distributions   /* A process-specific key which can be used to sign code pointers.
41*5e3eaea3SApple OSS Distributions      Signing and authenticating with this key is enforced even in processes
42*5e3eaea3SApple OSS Distributions      which disable ABI pointer authentication. */
43*5e3eaea3SApple OSS Distributions   ptrauth_key_process_dependent_code = ptrauth_key_asib,
44*5e3eaea3SApple OSS Distributions 
45*5e3eaea3SApple OSS Distributions   /* A process-independent key which can be used to sign data pointers.
46*5e3eaea3SApple OSS Distributions      Signing and authenticating with this key is a no-op in processes
47*5e3eaea3SApple OSS Distributions      which disable ABI pointer authentication. */
48*5e3eaea3SApple OSS Distributions   ptrauth_key_process_independent_data = ptrauth_key_asda,
49*5e3eaea3SApple OSS Distributions 
50*5e3eaea3SApple OSS Distributions   /* A process-specific key which can be used to sign data pointers.
51*5e3eaea3SApple OSS Distributions      Signing and authenticating with this key is a no-op in processes
52*5e3eaea3SApple OSS Distributions      which disable ABI pointer authentication. */
53*5e3eaea3SApple OSS Distributions   ptrauth_key_process_dependent_data = ptrauth_key_asdb,
54*5e3eaea3SApple OSS Distributions 
55*5e3eaea3SApple OSS Distributions   /* The key used to sign C function pointers.
56*5e3eaea3SApple OSS Distributions      The extra data is always 0. */
57*5e3eaea3SApple OSS Distributions   ptrauth_key_function_pointer = ptrauth_key_process_independent_code,
58*5e3eaea3SApple OSS Distributions 
59*5e3eaea3SApple OSS Distributions   /* The key used to sign return addresses on the stack.
60*5e3eaea3SApple OSS Distributions      The extra data is based on the storage address of the return address.
61*5e3eaea3SApple OSS Distributions      On ARM64, that is always the storage address of the return address plus 8
62*5e3eaea3SApple OSS Distributions      (or, in other words, the value of the stack pointer on function entry) */
63*5e3eaea3SApple OSS Distributions   ptrauth_key_return_address = ptrauth_key_process_dependent_code,
64*5e3eaea3SApple OSS Distributions 
65*5e3eaea3SApple OSS Distributions   /* The key used to sign frame pointers on the stack.
66*5e3eaea3SApple OSS Distributions      The extra data is based on the storage address of the frame pointer.
67*5e3eaea3SApple OSS Distributions      On ARM64, that is always the storage address of the frame pointer plus 16
68*5e3eaea3SApple OSS Distributions      (or, in other words, the value of the stack pointer on function entry) */
69*5e3eaea3SApple OSS Distributions   ptrauth_key_frame_pointer = ptrauth_key_process_dependent_data,
70*5e3eaea3SApple OSS Distributions 
71*5e3eaea3SApple OSS Distributions   /* The key used to sign block function pointers, including:
72*5e3eaea3SApple OSS Distributions        invocation functions,
73*5e3eaea3SApple OSS Distributions        block object copy functions,
74*5e3eaea3SApple OSS Distributions        block object destroy functions,
75*5e3eaea3SApple OSS Distributions        __block variable copy functions, and
76*5e3eaea3SApple OSS Distributions        __block variable destroy functions.
77*5e3eaea3SApple OSS Distributions      The extra data is always the address at which the function pointer
78*5e3eaea3SApple OSS Distributions      is stored.
79*5e3eaea3SApple OSS Distributions 
80*5e3eaea3SApple OSS Distributions      Note that block object pointers themselves (i.e. the direct
81*5e3eaea3SApple OSS Distributions      representations of values of block-pointer type) are not signed. */
82*5e3eaea3SApple OSS Distributions   ptrauth_key_block_function = ptrauth_key_asia,
83*5e3eaea3SApple OSS Distributions 
84*5e3eaea3SApple OSS Distributions   /* The key used to sign C++ v-table pointers.
85*5e3eaea3SApple OSS Distributions      The extra data is always 0. */
86*5e3eaea3SApple OSS Distributions   ptrauth_key_cxx_vtable_pointer = ptrauth_key_asda,
87*5e3eaea3SApple OSS Distributions 
88*5e3eaea3SApple OSS Distributions   /* Other pointers signed under the ABI use private ABI rules. */
89*5e3eaea3SApple OSS Distributions 
90*5e3eaea3SApple OSS Distributions } ptrauth_key;
91*5e3eaea3SApple OSS Distributions 
92*5e3eaea3SApple OSS Distributions /* An integer type of the appropriate size for an extra-data argument. */
93*5e3eaea3SApple OSS Distributions typedef uintptr_t ptrauth_extra_data_t;
94*5e3eaea3SApple OSS Distributions 
95*5e3eaea3SApple OSS Distributions /* An integer type of the appropriate size for a generic signature. */
96*5e3eaea3SApple OSS Distributions typedef uintptr_t ptrauth_generic_signature_t;
97*5e3eaea3SApple OSS Distributions 
98*5e3eaea3SApple OSS Distributions /* A signed pointer value embeds the original pointer together with
99*5e3eaea3SApple OSS Distributions    a signature that attests to the validity of that pointer.  Because
100*5e3eaea3SApple OSS Distributions    this signature must use only "spare" bits of the pointer, a
101*5e3eaea3SApple OSS Distributions    signature's validity is probabilistic in practice: it is unlikely
102*5e3eaea3SApple OSS Distributions    but still plausible that an invalidly-derived signature will
103*5e3eaea3SApple OSS Distributions    somehow equal the correct signature and therefore successfully
104*5e3eaea3SApple OSS Distributions    authenticate.  Nonetheless, this scheme provides a strong degree
105*5e3eaea3SApple OSS Distributions    of protection against certain kinds of attacks. */
106*5e3eaea3SApple OSS Distributions 
107*5e3eaea3SApple OSS Distributions /* Authenticating a pointer that was not signed with the given key
108*5e3eaea3SApple OSS Distributions    and extra-data value will (likely) fail.  However, an
109*5e3eaea3SApple OSS Distributions    authentication failure will not lead immediately to a trap.
110*5e3eaea3SApple OSS Distributions    Instead, it will yield a value which is guaranteed to trap
111*5e3eaea3SApple OSS Distributions    if actually dereferenced. */
112*5e3eaea3SApple OSS Distributions 
113*5e3eaea3SApple OSS Distributions /* The null function pointer is always the all-zero bit pattern.
114*5e3eaea3SApple OSS Distributions    Signing an all-zero bit pattern will embed a (likely) non-zero
115*5e3eaea3SApple OSS Distributions    signature in the result, and so the result will not seem to be
116*5e3eaea3SApple OSS Distributions    a null function pointer.  Authenticating this value will yield
117*5e3eaea3SApple OSS Distributions    a null function pointer back.  However, authenticating an
118*5e3eaea3SApple OSS Distributions    all-zero bit pattern will probably fail, because the
119*5e3eaea3SApple OSS Distributions    authentication will expect a (likely) non-zero signature to
120*5e3eaea3SApple OSS Distributions    embedded in the value.
121*5e3eaea3SApple OSS Distributions 
122*5e3eaea3SApple OSS Distributions    Because of this, if a pointer may validly be null, you should
123*5e3eaea3SApple OSS Distributions    check for null before attempting to authenticate it. */
124*5e3eaea3SApple OSS Distributions 
125*5e3eaea3SApple OSS Distributions #ifdef __PTRAUTH_INTRINSICS__
126*5e3eaea3SApple OSS Distributions 
127*5e3eaea3SApple OSS Distributions /* Strip the signature from a value without authenticating it.
128*5e3eaea3SApple OSS Distributions 
129*5e3eaea3SApple OSS Distributions    If the value is a function pointer, the result will not be a
130*5e3eaea3SApple OSS Distributions    legal function pointer because of the missing signature, and
131*5e3eaea3SApple OSS Distributions    attempting to call it will result in an authentication failure.
132*5e3eaea3SApple OSS Distributions 
133*5e3eaea3SApple OSS Distributions    The value must be an expression of pointer type.
134*5e3eaea3SApple OSS Distributions    The key must be a constant expression of type ptrauth_key.
135*5e3eaea3SApple OSS Distributions    The result will have the same type as the original value. */
136*5e3eaea3SApple OSS Distributions #define ptrauth_strip(__value, __key) \
137*5e3eaea3SApple OSS Distributions   __builtin_ptrauth_strip(__value, __key)
138*5e3eaea3SApple OSS Distributions 
139*5e3eaea3SApple OSS Distributions /* Blend a pointer and a small integer to form a new extra-data
140*5e3eaea3SApple OSS Distributions    discriminator.  Not all bits of the inputs are guaranteed to
141*5e3eaea3SApple OSS Distributions    contribute to the result.
142*5e3eaea3SApple OSS Distributions 
143*5e3eaea3SApple OSS Distributions    On ARM64, only the low 16 bits of the integer will be considered.
144*5e3eaea3SApple OSS Distributions 
145*5e3eaea3SApple OSS Distributions    For the purposes of ptrauth_sign_constant, the result of calling
146*5e3eaea3SApple OSS Distributions    this function is considered a constant expression if the arguments
147*5e3eaea3SApple OSS Distributions    are constant.  Some restrictions may be imposed on the pointer.
148*5e3eaea3SApple OSS Distributions 
149*5e3eaea3SApple OSS Distributions    The first argument must be an expression of pointer type.
150*5e3eaea3SApple OSS Distributions    The second argument must be an expression of integer type.
151*5e3eaea3SApple OSS Distributions    The result will have type uintptr_t. */
152*5e3eaea3SApple OSS Distributions #define ptrauth_blend_discriminator(__pointer, __integer) \
153*5e3eaea3SApple OSS Distributions   __builtin_ptrauth_blend_discriminator(__pointer, __integer)
154*5e3eaea3SApple OSS Distributions 
155*5e3eaea3SApple OSS Distributions /* Compute the 16-bit integer discriminator of the given type.
156*5e3eaea3SApple OSS Distributions 
157*5e3eaea3SApple OSS Distributions    The argument must be a type.
158*5e3eaea3SApple OSS Distributions */
159*5e3eaea3SApple OSS Distributions #if __has_builtin(__builtin_ptrauth_type_discriminator)
160*5e3eaea3SApple OSS Distributions #define ptrauth_type_discriminator(__type) \
161*5e3eaea3SApple OSS Distributions   __builtin_ptrauth_type_discriminator(__type)
162*5e3eaea3SApple OSS Distributions #else
163*5e3eaea3SApple OSS Distributions #define ptrauth_type_discriminator(__type) ((uintptr_t)0)
164*5e3eaea3SApple OSS Distributions #endif
165*5e3eaea3SApple OSS Distributions 
166*5e3eaea3SApple OSS Distributions /* Compute the constant discriminator used by Clang to sign pointers with the
167*5e3eaea3SApple OSS Distributions    given C function pointer type.
168*5e3eaea3SApple OSS Distributions 
169*5e3eaea3SApple OSS Distributions    A call to this function is an integer constant expression*/
170*5e3eaea3SApple OSS Distributions #if __has_feature(ptrauth_function_pointer_type_discrimination)
171*5e3eaea3SApple OSS Distributions #define ptrauth_function_pointer_type_discriminator(__type) \
172*5e3eaea3SApple OSS Distributions   __builtin_ptrauth_type_discriminator(__type)
173*5e3eaea3SApple OSS Distributions #else
174*5e3eaea3SApple OSS Distributions #define ptrauth_function_pointer_type_discriminator(__type) ((uintptr_t)0)
175*5e3eaea3SApple OSS Distributions #endif
176*5e3eaea3SApple OSS Distributions 
177*5e3eaea3SApple OSS Distributions /* Add a signature to the given pointer value using a specific key,
178*5e3eaea3SApple OSS Distributions    using the given extra data as a salt to the signing process.
179*5e3eaea3SApple OSS Distributions 
180*5e3eaea3SApple OSS Distributions    The value must be a constant expression of pointer type.
181*5e3eaea3SApple OSS Distributions    The key must be a constant expression of type ptrauth_key.
182*5e3eaea3SApple OSS Distributions    The extra data must be a constant expression of pointer or integer type;
183*5e3eaea3SApple OSS Distributions    if an integer, it will be coerced to ptrauth_extra_data_t.
184*5e3eaea3SApple OSS Distributions    The result will have the same type as the original value.
185*5e3eaea3SApple OSS Distributions 
186*5e3eaea3SApple OSS Distributions    This is a constant expression if the extra data is an integer or
187*5e3eaea3SApple OSS Distributions    null pointer constant. */
188*5e3eaea3SApple OSS Distributions #define ptrauth_sign_constant(__value, __key, __data) \
189*5e3eaea3SApple OSS Distributions   __builtin_ptrauth_sign_constant(__value, __key, __data)
190*5e3eaea3SApple OSS Distributions 
191*5e3eaea3SApple OSS Distributions /* Add a signature to the given pointer value using a specific key,
192*5e3eaea3SApple OSS Distributions    using the given extra data as a salt to the signing process.
193*5e3eaea3SApple OSS Distributions 
194*5e3eaea3SApple OSS Distributions    This operation does not authenticate the original value and is
195*5e3eaea3SApple OSS Distributions    therefore potentially insecure if an attacker could possibly
196*5e3eaea3SApple OSS Distributions    control that value.
197*5e3eaea3SApple OSS Distributions 
198*5e3eaea3SApple OSS Distributions    The value must be an expression of pointer type.
199*5e3eaea3SApple OSS Distributions    The key must be a constant expression of type ptrauth_key.
200*5e3eaea3SApple OSS Distributions    The extra data must be an expression of pointer or integer type;
201*5e3eaea3SApple OSS Distributions    if an integer, it will be coerced to ptrauth_extra_data_t.
202*5e3eaea3SApple OSS Distributions    The result will have the same type as the original value. */
203*5e3eaea3SApple OSS Distributions #define ptrauth_sign_unauthenticated(__value, __key, __data) \
204*5e3eaea3SApple OSS Distributions   __builtin_ptrauth_sign_unauthenticated(__value, __key, __data)
205*5e3eaea3SApple OSS Distributions 
206*5e3eaea3SApple OSS Distributions /* Authenticate a pointer using one scheme and resign it using another.
207*5e3eaea3SApple OSS Distributions 
208*5e3eaea3SApple OSS Distributions    If the result is subsequently authenticated using the new scheme, that
209*5e3eaea3SApple OSS Distributions    authentication is guaranteed to fail if and only if the initial
210*5e3eaea3SApple OSS Distributions    authentication failed.
211*5e3eaea3SApple OSS Distributions 
212*5e3eaea3SApple OSS Distributions    The value must be an expression of pointer type.
213*5e3eaea3SApple OSS Distributions    The key must be a constant expression of type ptrauth_key.
214*5e3eaea3SApple OSS Distributions    The extra data must be an expression of pointer or integer type;
215*5e3eaea3SApple OSS Distributions    if an integer, it will be coerced to ptrauth_extra_data_t.
216*5e3eaea3SApple OSS Distributions    The result will have the same type as the original value.
217*5e3eaea3SApple OSS Distributions 
218*5e3eaea3SApple OSS Distributions    This operation is guaranteed to not leave the intermediate value
219*5e3eaea3SApple OSS Distributions    available for attack before it is re-signed.
220*5e3eaea3SApple OSS Distributions 
221*5e3eaea3SApple OSS Distributions    Do not pass a null pointer to this function. A null pointer
222*5e3eaea3SApple OSS Distributions    will not successfully authenticate. */
223*5e3eaea3SApple OSS Distributions #define ptrauth_auth_and_resign(__value, __old_key, __old_data, __new_key, __new_data) \
224*5e3eaea3SApple OSS Distributions   __builtin_ptrauth_auth_and_resign(__value, __old_key, __old_data, __new_key, __new_data)
225*5e3eaea3SApple OSS Distributions 
226*5e3eaea3SApple OSS Distributions /* Authenticate a pointer using one scheme and resign it as a C
227*5e3eaea3SApple OSS Distributions    function pointer.
228*5e3eaea3SApple OSS Distributions 
229*5e3eaea3SApple OSS Distributions    If the result is subsequently authenticated using the new scheme, that
230*5e3eaea3SApple OSS Distributions    authentication is guaranteed to fail if and only if the initial
231*5e3eaea3SApple OSS Distributions    authentication failed.
232*5e3eaea3SApple OSS Distributions 
233*5e3eaea3SApple OSS Distributions    The value must be an expression of function pointer type.
234*5e3eaea3SApple OSS Distributions    The key must be a constant expression of type ptrauth_key.
235*5e3eaea3SApple OSS Distributions    The extra data must be an expression of pointer or integer type;
236*5e3eaea3SApple OSS Distributions    if an integer, it will be coerced to ptrauth_extra_data_t.
237*5e3eaea3SApple OSS Distributions    The result will have the same type as the original value.
238*5e3eaea3SApple OSS Distributions 
239*5e3eaea3SApple OSS Distributions    This operation is guaranteed to not leave the intermediate value
240*5e3eaea3SApple OSS Distributions    available for attack before it is re-signed. Additionally, if this
241*5e3eaea3SApple OSS Distributions    expression is used syntactically as the function expression in a
242*5e3eaea3SApple OSS Distributions    call, only a single authentication will be performed. */
243*5e3eaea3SApple OSS Distributions #define ptrauth_auth_function(__value, __old_key, __old_data) \
244*5e3eaea3SApple OSS Distributions   ptrauth_auth_and_resign(__value, __old_key, __old_data, ptrauth_key_function_pointer, 0)
245*5e3eaea3SApple OSS Distributions 
246*5e3eaea3SApple OSS Distributions /* Cast a pointer to the given type without changing any signature.
247*5e3eaea3SApple OSS Distributions 
248*5e3eaea3SApple OSS Distributions    The type must have the same size as a pointer type.
249*5e3eaea3SApple OSS Distributions    The type of value must have the same size as a pointer type, and will be
250*5e3eaea3SApple OSS Distributions    converted to an rvalue prior to the cast.
251*5e3eaea3SApple OSS Distributions    The result has type given by the first argument.
252*5e3eaea3SApple OSS Distributions 
253*5e3eaea3SApple OSS Distributions    The result has an identical bit-pattern to the input pointer. */
254*5e3eaea3SApple OSS Distributions #define ptrauth_nop_cast(__type, __value)        \
255*5e3eaea3SApple OSS Distributions   ({ union {                                     \
256*5e3eaea3SApple OSS Distributions       typeof(__value) __fptr;                    \
257*5e3eaea3SApple OSS Distributions       typeof(__type) __opaque;                   \
258*5e3eaea3SApple OSS Distributions   } __storage;                                   \
259*5e3eaea3SApple OSS Distributions   __storage.__fptr = (__value);                  \
260*5e3eaea3SApple OSS Distributions   __storage.__opaque; })
261*5e3eaea3SApple OSS Distributions 
262*5e3eaea3SApple OSS Distributions /* Authenticate a data pointer.
263*5e3eaea3SApple OSS Distributions 
264*5e3eaea3SApple OSS Distributions    The value must be an expression of non-function pointer type.
265*5e3eaea3SApple OSS Distributions    The key must be a constant expression of type ptrauth_key.
266*5e3eaea3SApple OSS Distributions    The extra data must be an expression of pointer or integer type;
267*5e3eaea3SApple OSS Distributions    if an integer, it will be coerced to ptrauth_extra_data_t.
268*5e3eaea3SApple OSS Distributions    The result will have the same type as the original value.
269*5e3eaea3SApple OSS Distributions 
270*5e3eaea3SApple OSS Distributions    If the authentication fails, dereferencing the resulting pointer
271*5e3eaea3SApple OSS Distributions    will fail. */
272*5e3eaea3SApple OSS Distributions #define ptrauth_auth_data(__value, __old_key, __old_data) \
273*5e3eaea3SApple OSS Distributions   __builtin_ptrauth_auth(__value, __old_key, __old_data)
274*5e3eaea3SApple OSS Distributions 
275*5e3eaea3SApple OSS Distributions /* Return an extra-discriminator value which can validly be used
276*5e3eaea3SApple OSS Distributions    as the second argument to ptrauth_blend_discriminator or the
277*5e3eaea3SApple OSS Distributions    third argument to the __ptrauth qualifier.
278*5e3eaea3SApple OSS Distributions 
279*5e3eaea3SApple OSS Distributions    The argument must be a string literal.
280*5e3eaea3SApple OSS Distributions    A call to this function is an integer constant expression. */
281*5e3eaea3SApple OSS Distributions #define ptrauth_string_discriminator(__string) \
282*5e3eaea3SApple OSS Distributions   __builtin_ptrauth_string_discriminator(__string)
283*5e3eaea3SApple OSS Distributions 
284*5e3eaea3SApple OSS Distributions /* Compute a full pointer-width generic signature for the given
285*5e3eaea3SApple OSS Distributions    value, using the given data as a salt.
286*5e3eaea3SApple OSS Distributions 
287*5e3eaea3SApple OSS Distributions    This generic signature is process-independent, but may not be
288*5e3eaea3SApple OSS Distributions    consistent across reboots.
289*5e3eaea3SApple OSS Distributions 
290*5e3eaea3SApple OSS Distributions    This can be used to validate the integrity of arbitrary data
291*5e3eaea3SApple OSS Distributions    by storing a signature for that data together with it.  Because
292*5e3eaea3SApple OSS Distributions    the signature is pointer-sized, if the stored signature matches
293*5e3eaea3SApple OSS Distributions    the result of re-signing the current data, a match provides very
294*5e3eaea3SApple OSS Distributions    strong evidence that the data has not been corrupted.
295*5e3eaea3SApple OSS Distributions 
296*5e3eaea3SApple OSS Distributions    The value must be an expression of pointer or integer type; if
297*5e3eaea3SApple OSS Distributions    an integer, it will be coerced to uintptr_t.
298*5e3eaea3SApple OSS Distributions    The extra data must be an expression of pointer or integer type;
299*5e3eaea3SApple OSS Distributions    if an integer, it will be coerced to ptrauth_extra_data_t.
300*5e3eaea3SApple OSS Distributions    The result will have type ptrauth_generic_signature_t.
301*5e3eaea3SApple OSS Distributions 
302*5e3eaea3SApple OSS Distributions    This operation will compute a meaningful signature even in processes
303*5e3eaea3SApple OSS Distributions    which disable ABI pointer authentication. */
304*5e3eaea3SApple OSS Distributions #define ptrauth_sign_generic_data(__value, __data) \
305*5e3eaea3SApple OSS Distributions   __builtin_ptrauth_sign_generic_data(__value, __data)
306*5e3eaea3SApple OSS Distributions 
307*5e3eaea3SApple OSS Distributions 
308*5e3eaea3SApple OSS Distributions /* Define some standard __ptrauth qualifiers used in the ABI. */
309*5e3eaea3SApple OSS Distributions #define __ptrauth_function_pointer            \
310*5e3eaea3SApple OSS Distributions   __ptrauth(ptrauth_key_function_pointer,0,0)
311*5e3eaea3SApple OSS Distributions #define __ptrauth_return_address              \
312*5e3eaea3SApple OSS Distributions   __ptrauth(ptrauth_key_return_address,1,0)
313*5e3eaea3SApple OSS Distributions #define __ptrauth_block_invocation_pointer    \
314*5e3eaea3SApple OSS Distributions   __ptrauth(ptrauth_key_function_pointer,1,0)
315*5e3eaea3SApple OSS Distributions #define __ptrauth_block_copy_helper           \
316*5e3eaea3SApple OSS Distributions   __ptrauth(ptrauth_key_function_pointer,1,0)
317*5e3eaea3SApple OSS Distributions #define __ptrauth_block_destroy_helper        \
318*5e3eaea3SApple OSS Distributions   __ptrauth(ptrauth_key_function_pointer,1,0)
319*5e3eaea3SApple OSS Distributions #define __ptrauth_block_byref_copy_helper     \
320*5e3eaea3SApple OSS Distributions   __ptrauth(ptrauth_key_function_pointer,1,0)
321*5e3eaea3SApple OSS Distributions #define __ptrauth_block_byref_destroy_helper  \
322*5e3eaea3SApple OSS Distributions   __ptrauth(ptrauth_key_function_pointer,1,0)
323*5e3eaea3SApple OSS Distributions #define __ptrauth_objc_method_list_imp        \
324*5e3eaea3SApple OSS Distributions   __ptrauth(ptrauth_key_function_pointer,1,0)
325*5e3eaea3SApple OSS Distributions #define __ptrauth_cxx_vtable_pointer          \
326*5e3eaea3SApple OSS Distributions   __ptrauth(ptrauth_key_cxx_vtable_pointer,0,0)
327*5e3eaea3SApple OSS Distributions #define __ptrauth_cxx_vtt_vtable_pointer      \
328*5e3eaea3SApple OSS Distributions   __ptrauth(ptrauth_key_cxx_vtable_pointer,0,0)
329*5e3eaea3SApple OSS Distributions #define __ptrauth_swift_heap_object_destructor \
330*5e3eaea3SApple OSS Distributions   __ptrauth(ptrauth_key_function_pointer,1,0xbbbf)
331*5e3eaea3SApple OSS Distributions 
332*5e3eaea3SApple OSS Distributions /* Some situations in the C++ and Swift ABIs use declaration-specific
333*5e3eaea3SApple OSS Distributions    or type-specific extra discriminators. */
334*5e3eaea3SApple OSS Distributions #define __ptrauth_cxx_virtual_function_pointer(__declkey) \
335*5e3eaea3SApple OSS Distributions   __ptrauth(ptrauth_key_function_pointer,1,__declkey)
336*5e3eaea3SApple OSS Distributions #define __ptrauth_swift_function_pointer(__typekey) \
337*5e3eaea3SApple OSS Distributions   __ptrauth(ptrauth_key_function_pointer,0,__typekey)
338*5e3eaea3SApple OSS Distributions #define __ptrauth_swift_class_method_pointer(__declkey) \
339*5e3eaea3SApple OSS Distributions   __ptrauth(ptrauth_key_function_pointer,1,__declkey)
340*5e3eaea3SApple OSS Distributions #define __ptrauth_swift_protocol_witness_function_pointer(__declkey) \
341*5e3eaea3SApple OSS Distributions   __ptrauth(ptrauth_key_function_pointer,1,__declkey)
342*5e3eaea3SApple OSS Distributions #define __ptrauth_swift_value_witness_function_pointer(__key) \
343*5e3eaea3SApple OSS Distributions   __ptrauth(ptrauth_key_function_pointer,1,__key)
344*5e3eaea3SApple OSS Distributions 
345*5e3eaea3SApple OSS Distributions #else
346*5e3eaea3SApple OSS Distributions 
347*5e3eaea3SApple OSS Distributions #define ptrauth_strip(__value, __key) ({ (void)__key; __value; })
348*5e3eaea3SApple OSS Distributions #define ptrauth_blend_discriminator(__pointer, __integer) ({ (void)__pointer; (void)__integer; (uintptr_t)0; })
349*5e3eaea3SApple OSS Distributions #define ptrauth_type_discriminator(__type) ((uintptr_t)0)
350*5e3eaea3SApple OSS Distributions #define ptrauth_function_pointer_type_discriminator(__type) ((uintptr_t)0)
351*5e3eaea3SApple OSS Distributions #define ptrauth_sign_constant(__value, __key, __data) ({ (void)__key; (void)__data; __value; })
352*5e3eaea3SApple OSS Distributions #define ptrauth_sign_unauthenticated(__value, __key, __data) ({ (void)__key; (void)__data; __value; })
353*5e3eaea3SApple OSS Distributions #define ptrauth_auth_and_resign(__value, __old_key, __old_data, __new_key, __new_data) ({ \
354*5e3eaea3SApple OSS Distributions       (void)__old_key; \
355*5e3eaea3SApple OSS Distributions       (void)__old_data; \
356*5e3eaea3SApple OSS Distributions       (void)__new_key; \
357*5e3eaea3SApple OSS Distributions       (void)__new_data; \
358*5e3eaea3SApple OSS Distributions       __value; })
359*5e3eaea3SApple OSS Distributions #define ptrauth_auth_function(__value, __old_key, __old_data) ({ (void)__old_key; (void)__old_data; __value; })
360*5e3eaea3SApple OSS Distributions #define ptrauth_nop_cast(__type, __value) ((__type)__value)
361*5e3eaea3SApple OSS Distributions #define ptrauth_auth_data(__value, __old_key, __old_data) ({ (void)__old_key; (void)__old_data; __value; })
362*5e3eaea3SApple OSS Distributions #define ptrauth_string_discriminator(__string) ({ (void)__string; (int)0; })
363*5e3eaea3SApple OSS Distributions #define ptrauth_sign_generic_data(__value, __data) ({ (void)__value; (void)__data; (ptrauth_generic_signature_t)0; })
364*5e3eaea3SApple OSS Distributions 
365*5e3eaea3SApple OSS Distributions #define __ptrauth_function_pointer
366*5e3eaea3SApple OSS Distributions #define __ptrauth_return_address
367*5e3eaea3SApple OSS Distributions #define __ptrauth_block_invocation_pointer
368*5e3eaea3SApple OSS Distributions #define __ptrauth_block_copy_helper
369*5e3eaea3SApple OSS Distributions #define __ptrauth_block_destroy_helper
370*5e3eaea3SApple OSS Distributions #define __ptrauth_block_byref_copy_helper
371*5e3eaea3SApple OSS Distributions #define __ptrauth_block_byref_destroy_helper
372*5e3eaea3SApple OSS Distributions #define __ptrauth_objc_method_list_imp
373*5e3eaea3SApple OSS Distributions #define __ptrauth_cxx_vtable_pointer
374*5e3eaea3SApple OSS Distributions #define __ptrauth_cxx_vtt_vtable_pointer
375*5e3eaea3SApple OSS Distributions #define __ptrauth_swift_heap_object_destructor
376*5e3eaea3SApple OSS Distributions #define __ptrauth_cxx_virtual_function_pointer(__declkey)
377*5e3eaea3SApple OSS Distributions #define __ptrauth_swift_function_pointer(__typekey)
378*5e3eaea3SApple OSS Distributions #define __ptrauth_swift_class_method_pointer(__declkey)
379*5e3eaea3SApple OSS Distributions #define __ptrauth_swift_protocol_witness_function_pointer(__declkey)
380*5e3eaea3SApple OSS Distributions #define __ptrauth_swift_value_witness_function_pointer(__key)
381*5e3eaea3SApple OSS Distributions 
382*5e3eaea3SApple OSS Distributions #endif /* __PTRAUTH_INTRINSICS__ */
383*5e3eaea3SApple OSS Distributions 
384*5e3eaea3SApple OSS Distributions #endif /* __PTRAUTH_H */
385