fix(verify): arm64 stack save, adaptive canary and host gating
Assisted-by: GLM 5.3
This commit is contained in:
@@ -8,7 +8,6 @@ package verify
|
||||
import (
|
||||
"encoding/binary"
|
||||
"fmt"
|
||||
"reflect"
|
||||
"syscall"
|
||||
"unsafe"
|
||||
)
|
||||
@@ -19,15 +18,20 @@ func enterJIT(fn uintptr, stack uintptr)
|
||||
//go:nosplit
|
||||
func leaveJIT()
|
||||
|
||||
var leaveJITAddr uintptr
|
||||
// leaveRawAddr is the raw ABI0 address of leaveJIT, handed over by the
|
||||
// GLOBL/DATA in abi_loong64.s (reflect would return the interposed
|
||||
// ABIInternal wrapper instead: its prologue clobbers the saved-register
|
||||
// window the JIT call depends on).
|
||||
var leaveRawAddr uintptr
|
||||
|
||||
func init() {
|
||||
leaveJITAddr = reflect.ValueOf(leaveJIT).Pointer()
|
||||
}
|
||||
var leaveJITAddr = leaveRawAddr
|
||||
|
||||
const stackPad = 64
|
||||
|
||||
// Call invokes the assembled function at fnAddr with the given ABI0 argument block.
|
||||
//
|
||||
// Not safe for concurrent use: only one JIT call may be in flight at a
|
||||
// time, the trampolines keep the saved registers in package globals.
|
||||
func Call(fnAddr uintptr, args []byte) ([]byte, error) {
|
||||
stackSize := stackPad + 8 + len(args) + 64
|
||||
stackMem, err := syscall.Mmap(-1, 0, stackSize,
|
||||
|
||||
Reference in New Issue
Block a user