# Spectre mitigations in Rust

**URL:** <https://internals.rust-lang.org/t/spectre-mitigations-in-rust/13353>\
**Category:** compiler\
**Created:** [November 9, 2020, 10:38am UTC](https://internals.rust-lang.org/t/spectre-mitigations-in-rust/13353 "2020-11-09T10:38:08Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![sahnaseredini](https://avatars.discourse-cdn.com/v4/letter/s/ea5d25/32.png) [@sahnaseredini](https://internals.rust-lang.org/u/sahnaseredini)\
**Post date:** [November 9, 2020, 10:38am UTC](https://internals.rust-lang.org/t/spectre-mitigations-in-rust/13353/1 "2020-11-09T10:38:08Z")

</div>

I was looking up everywhere and could not find any mitigations for Spectre attack by the Rust compiler(s)! Do you know if there are any mitigations for different kinds of Spectre attacks Specter v1 (Spectre-PHT), v2 (Spectre-BTB), v4 (Spectre-STL) and v5 (Spectre-RSB) at the compiler level for Rust? Looking forward to hearing from you guys 🙂

---

<div class="post-metadata">

**Author:** ![jethrogb](https://avatars.discourse-cdn.com/v4/letter/j/43a26b/32.png) [@jethrogb](https://internals.rust-lang.org/u/jethrogb)\
**Post date:** [November 9, 2020, 11:54am UTC](https://internals.rust-lang.org/t/spectre-mitigations-in-rust/13353/2 "2020-11-09T11:54:02Z")

</div>

There are several mitigations for transient execution attacks available in LLVM and therefore `rustc`.

- [Speculative load hardening](https://github.com/llvm/llvm-project/blob/master/llvm/lib/Target/X86/X86SpeculativeLoadHardening.cpp) (x86-speculative-load-hardening option)
- [Load value injection control flow integrity](https://github.com/llvm/llvm-project/blob/master/llvm/lib/Target/X86/X86LoadValueInjectionRetHardening.cpp) (`lvi-cfi` target feature)
- [Load value injection load hardening](https://github.com/llvm/llvm-project/blob/master/llvm/lib/Target/X86/X86LoadValueInjectionLoadHardening.cpp) (`lvi-load-hardening` target feature)
- [Speculative execution side effect suppression](https://github.com/llvm/llvm-project/blob/master/llvm/lib/Target/X86/X86SpeculativeExecutionSideEffectSuppression.cpp) (`seses` target feature)

For example, the [x86\_64-fortanix-unknown-sgx target](https://github.com/rust-lang/rust/blob/master/compiler/rustc_target/src/spec/x86_64_fortanix_unknown_sgx.rs#L69) enables LVI load hardening & CFI by default.

---

<div class="post-metadata">

**Author:** ![sahnaseredini](https://avatars.discourse-cdn.com/v4/letter/s/ea5d25/32.png) [@sahnaseredini](https://internals.rust-lang.org/u/sahnaseredini)\
**Post date:** [November 9, 2020, 12:34pm UTC](https://internals.rust-lang.org/t/spectre-mitigations-in-rust/13353/3 "2020-11-09T12:34:25Z")

</div>

Thanks. I'm assuming these mitigations are only capable of solving the problem for Spectre v1 and v2. Please correct me if I'm wrong but I think they don't deal with other variants.

---

<div class="post-metadata">

**Author:** ![sahnaseredini](https://avatars.discourse-cdn.com/v4/letter/s/ea5d25/32.png) [@sahnaseredini](https://internals.rust-lang.org/u/sahnaseredini)\
**Post date:** [November 9, 2020, 12:43pm UTC](https://internals.rust-lang.org/t/spectre-mitigations-in-rust/13353/4 "2020-11-09T12:43:15Z")

</div>

I believe that it actually does not mitigate Spectre v2 and it's only a mitigation for Spectre v1.

---

<div class="post-metadata">

**Author:** ![jethrogb](https://avatars.discourse-cdn.com/v4/letter/j/43a26b/32.png) [@jethrogb](https://internals.rust-lang.org/u/jethrogb)\
**Post date:** [November 9, 2020, 1:17pm UTC](https://internals.rust-lang.org/t/spectre-mitigations-in-rust/13353/5 "2020-11-09T13:17:20Z")

</div>

I'd think LVI-CFI deals with some of the later ones?

---

<div class="post-metadata">

**Author:** ![sahnaseredini](https://avatars.discourse-cdn.com/v4/letter/s/ea5d25/32.png) [@sahnaseredini](https://internals.rust-lang.org/u/sahnaseredini)\
**Post date:** [November 9, 2020, 1:32pm UTC](https://internals.rust-lang.org/t/spectre-mitigations-in-rust/13353/6 "2020-11-09T13:32:10Z")

</div>

It replces 'ret', and 'ret' is one of the ways to trigger v2, however we can trigger using call and jump too. So I don't honestly see it as a mitigation to other variants.

---

<div class="post-metadata">

**Author:** ![jethrogb](https://avatars.discourse-cdn.com/v4/letter/j/43a26b/32.png) [@jethrogb](https://internals.rust-lang.org/u/jethrogb)\
**Post date:** [November 9, 2020, 2:12pm UTC](https://internals.rust-lang.org/t/spectre-mitigations-in-rust/13353/7 "2020-11-09T14:12:36Z")

</div>

You can just try it out and see what may or may not be missing?

```rust
pub fn add_1(v: &mut dyn core::ops::AddAssign<i32>) {
    v.add_assign(1);
}

```

with LVI load hardening:

```nohighlight
0000000000000000 <_ZN9indirtest5add_117h35adf97a3c3c13bbE>:
   0:	0f ae e8 lfence 
   3:	48 8b 46 18 mov 0x18(%rsi),%rax
   7:	be 01 00 00 00 mov $0x1,%esi
   c:	ff e0 jmpq *%rax

```

and with LVI-CFI + LVI-LH or SESES:

```nohighlight
0000000000000000 <_ZN9indirtest5add_117h35adf97a3c3c13bbE>:
   0:	0f ae e8 lfence 
   3:	4c 8b 5e 18 mov 0x18(%rsi),%r11
   7:	be 01 00 00 00 mov $0x1,%esi
   c:	e9 00 00 00 00 jmpq 11

0000000000000000 <__llvm_lvi_thunk_r11>:
   0:	0f ae e8 lfence 
   3:	41 ff e3 jmpq *%r11

RELOCATION RECORDS FOR [.text._ZN9indirtest5add_117h35adf97a3c3c13bbE]:
OFFSET TYPE VALUE 
000000000000000d R_X86_64_PLT32 __llvm_lvi_thunk_r11-0x0000000000000004

```

---

<div class="post-metadata">

**Author:** ![jethrogb](https://avatars.discourse-cdn.com/v4/letter/j/43a26b/32.png) [@jethrogb](https://internals.rust-lang.org/u/jethrogb)\
**Post date:** [November 9, 2020, 5:01pm UTC](https://internals.rust-lang.org/t/spectre-mitigations-in-rust/13353/8 "2020-11-09T17:01:57Z")

</div>

Oh and I missed the [retpoline-related features](https://github.com/llvm/llvm-project/blob/master/llvm/lib/Target/X86/X86IndirectThunks.cpp):

- `retpoline-indirect-calls` target feature
- `retpoline-indirect-branches` target feature

---

<div class="post-metadata">

**Author:** ![jessa0](https://sea2.discourse-cdn.com/flex002/user_avatar/internals.rust-lang.org/jessa0/32/7802_2.png) [@jessa0](https://internals.rust-lang.org/u/jessa0)\
**Post date:** [November 9, 2020, 5:38pm UTC](https://internals.rust-lang.org/t/spectre-mitigations-in-rust/13353/9 "2020-11-09T17:38:46Z")

</div>

Side note: there are also [efforts](https://github.com/signalapp/BOLT) to insert more heavy-handed mitigations on compiled binaries (see the commits in that BOLT fork adding the `--lfence-*` options), which incidentally are easier to verify, if the immense performance hit is acceptable depending on the application.

---

<div class="post-metadata">

**Author:** ![system](https://sea2.discourse-cdn.com/flex002/user_avatar/internals.rust-lang.org/system/32/14092_2.png) [@system](https://internals.rust-lang.org/u/system)\
**Post date:** [February 7, 2021, 5:38pm UTC](https://internals.rust-lang.org/t/spectre-mitigations-in-rust/13353/10 "2021-02-07T17:38:48Z")

</div>

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.
