On Mon, 6 Jul 2026 17:52:58 GMT, Ashay Rane <[email protected]> wrote:
> This patch adds MSVC's "/guard:signret" flag to the C/C++ compilation
> flags so that the VM code includes signing and authentication
> instructions to ensure that the return address is not tampered by any
> callee. Specifically, MSVC chooses signing using the B key, so every
> non-leaf function starts with the `pacibsp` instruction (for signining
> the return address) and ends with the `autibsp` instruction (for
> authenticating the return address). Both `pacibsp` and `autibsp`
> instructions are in the NOP space, so older AArch64 processors that do
> not support these instructions shouldn't be impacted by these
> instructions.
>
> As a matter of slight detail, this patch adds the "/guard:signret" flag
> only when the OpenJDK build is passed the "--enable-branch-protection"
> flag, which is off by default. Consequently, this change will not
> impact ordinary builds of OpenJDK.
>
> I've validated this patch by running the test/jdk:tier{1,2,3},
> test/hotspot/jtreg:tier{1,2,3}, test/langtools:tier{1,2,3}, and
> test/lib-test:tier1 tests with branch protection enabled. This patch
> does not introduce any new failures.
>
> ---------
> - [x] I confirm that I make this contribution in accordance with the [OpenJDK
> Interim AI Policy](https://openjdk.org/legal/ai).
This pull request has now been integrated.
Changeset: aa0fbef9
Author: Ashay Rane <[email protected]>
Committer: David Holmes <[email protected]>
URL:
https://git.openjdk.org/jdk/commit/aa0fbef91aa8d4f69353c40cd01a6d3b502fc477
Stats: 93 lines in 7 files changed: 79 ins; 1 del; 13 mod
8387792: Enable PAC-RET for VM code on Windows/ARM64
Reviewed-by: haosun, erikj
-------------
PR: https://git.openjdk.org/jdk/pull/31795