On Mon, 27 Jul 2026 22:51:52 GMT, Ashay Rane <[email protected]> wrote:
>> This patch adds MSVC's "/guard:signret" flag to the C/C++ compilation
>> flags so that the VM code includes signing and authentication
>> instructions to ensure that the return address is not tampered by any
>> callee. Specifically, MSVC chooses signing using the B key, so every
>> non-leaf function starts with the `pacibsp` instruction (for signining
>> the return address) and ends with the `autibsp` instruction (for
>> authenticating the return address). Both `pacibsp` and `autibsp`
>> instructions are in the NOP space, so older AArch64 processors that do
>> not support these instructions shouldn't be impacted by these
>> instructions.
>>
>> As a matter of slight detail, this patch adds the "/guard:signret" flag
>> only when the OpenJDK build is passed the "--enable-branch-protection"
>> flag, which is off by default. Consequently, this change will not
>> impact ordinary builds of OpenJDK.
>>
>> I've validated this patch by running the test/jdk:tier{1,2,3},
>> test/hotspot/jtreg:tier{1,2,3}, test/langtools:tier{1,2,3}, and
>> test/lib-test:tier1 tests with branch protection enabled. This patch
>> does not introduce any new failures.
>>
>> ---------
>> - [x] I confirm that I make this contribution in accordance with the
>> [OpenJDK Interim AI Policy](https://openjdk.org/legal/ai).
>
> Ashay Rane has updated the pull request with a new target base due to a merge
> or a rebase. The incremental webrev excludes the unrelated changes brought in
> by the merge/rebase. The pull request contains nine additional commits since
> the last revision:
>
> - Merge branch 'master' into JDK-8387792-pac-ret-windows-arm64
> - Document "branch protection" as partially supported only on Win/ARM64
> - Clarify that Branch Protection is not fully supported
> - Remove redundant conditional preprocessor guard
>
> This file is only built for Windows/ARM64, so we don't need to check of
> `_M_ARM64`.
> - Drop incorrect comment
> - Merge branch 'master' into JDK-8387792-pac-ret-windows-arm64
> - Remove signature while walking the stack
> - Use separate C{XX} and AS flags for branch protection
> - Add "/guard:signret" to build flags when branch protection is requested
>
> This patch adds MSVC's "/guard:signret" flag to the C/C++ compilation
> flags so that the VM code includes signing and authentication
> instructions to ensure that the return address is not tampered by any
> callee. Specifically, MSVC chooses signing using the B key, so every
> non-leaf function starts with the `pacibsp` instruction (for signining
> the return address) and ends with the `autibsp` instruction (for
> authenticating the return address). Both `pacibsp` and `autibsp`
> instructions are in the NOP space, so older AArch64 processors that do
> not support these instructions shouldn't be impacted by these
> instructions.
>
> As a matter of slight detail, this patch adds the "/guard:signret" flag
> only when the OpenJDK build is passed the "--enable-branch-protection"
> flag, which is off by default. Consequently, this change will not
> impact ordinary builds of OpenJDK.
>
> I've validated this patch by running the test/jdk:tier{1,2,3},
> test/hotspot/jtreg:tier{1,2,3}, test/langtools:tier{1,2,3}, and
> test/lib-test:tier1 tests with branch protection enabled. This patch
> does not introduce any new failures.
LGTM. Thanks.
-------------
Marked as reviewed by haosun (Committer).
PR Review: https://git.openjdk.org/jdk/pull/31795#pullrequestreview-4792804161