On Mon, 27 Jul 2026 22:51:52 GMT, Ashay Rane <[email protected]> wrote:

>> This patch adds MSVC's "/guard:signret" flag to the C/C++ compilation
>> flags so that the VM code includes signing and authentication
>> instructions to ensure that the return address is not tampered by any
>> callee.  Specifically, MSVC chooses signing using the B key, so every
>> non-leaf function starts with the `pacibsp` instruction (for signining
>> the return address) and ends with the `autibsp` instruction (for
>> authenticating the return address).  Both `pacibsp` and `autibsp`
>> instructions are in the NOP space, so older AArch64 processors that do
>> not support these instructions shouldn't be impacted by these
>> instructions.
>> 
>> As a matter of slight detail, this patch adds the "/guard:signret" flag
>> only when the OpenJDK build is passed the "--enable-branch-protection"
>> flag, which is off by default.  Consequently, this change will not
>> impact ordinary builds of OpenJDK.
>> 
>> I've validated this patch by running the test/jdk:tier{1,2,3},
>> test/hotspot/jtreg:tier{1,2,3}, test/langtools:tier{1,2,3}, and
>> test/lib-test:tier1 tests with branch protection enabled.  This patch
>> does not introduce any new failures.
>> 
>> ---------
>> - [x] I confirm that I make this contribution in accordance with the 
>> [OpenJDK Interim AI Policy](https://openjdk.org/legal/ai).
>
> Ashay Rane has updated the pull request with a new target base due to a merge 
> or a rebase. The incremental webrev excludes the unrelated changes brought in 
> by the merge/rebase. The pull request contains nine additional commits since 
> the last revision:
> 
>  - Merge branch 'master' into JDK-8387792-pac-ret-windows-arm64
>  - Document "branch protection" as partially supported only on Win/ARM64
>  - Clarify that Branch Protection is not fully supported
>  - Remove redundant conditional preprocessor guard
>    
>    This file is only built for Windows/ARM64, so we don't need to check of
>    `_M_ARM64`.
>  - Drop incorrect comment
>  - Merge branch 'master' into JDK-8387792-pac-ret-windows-arm64
>  - Remove signature while walking the stack
>  - Use separate C{XX} and AS flags for branch protection
>  - Add "/guard:signret" to build flags when branch protection is requested
>    
>    This patch adds MSVC's "/guard:signret" flag to the C/C++ compilation
>    flags so that the VM code includes signing and authentication
>    instructions to ensure that the return address is not tampered by any
>    callee.  Specifically, MSVC chooses signing using the B key, so every
>    non-leaf function starts with the `pacibsp` instruction (for signining
>    the return address) and ends with the `autibsp` instruction (for
>    authenticating the return address).  Both `pacibsp` and `autibsp`
>    instructions are in the NOP space, so older AArch64 processors that do
>    not support these instructions shouldn't be impacted by these
>    instructions.
>    
>    As a matter of slight detail, this patch adds the "/guard:signret" flag
>    only when the OpenJDK build is passed the "--enable-branch-protection"
>    flag, which is off by default.  Consequently, this change will not
>    impact ordinary builds of OpenJDK.
>    
>    I've validated this patch by running the test/jdk:tier{1,2,3},
>    test/hotspot/jtreg:tier{1,2,3}, test/langtools:tier{1,2,3}, and
>    test/lib-test:tier1 tests with branch protection enabled.  This patch
>    does not introduce any new failures.

Marked as reviewed by erikj (Reviewer).

-------------

PR Review: https://git.openjdk.org/jdk/pull/31795#pullrequestreview-4886562414

Reply via email to