On Wed, Jul 15, 2026 at 7:52 PM Kees Cook <[email protected]> wrote: > ARM32 GCC KCFI[1] violations currently show as generic "Oops - undefined > instruction" errors, making debugging CFI failures difficult. Add a proper > KCFI trap handler similar to the aarch64 implementation to provide clear > CFI error messages, including the call target and the expected type.
Reviewed-by: Linus Walleij <[email protected]> > Clang and GCC trap CFI failures differently on ARM32. Clang lowers > its checks to a BKPT, handled via the breakpoint/prefetch-abort path > in hw_breakpoint.c, which cannot recover the target or expected type > and so must report via report_cfi_failure_noaddr(). GCC instead lowers > KCFI checks to a UDF (undefined instruction) whose immediate encodes > the registers involved, so the handler can decode it and call the full > report_cfi_failure() with the target and expected type. Aha, that explains a few things. The UDF is a better approach for ARM I think (Russell will know best). As noted from earlier conversation the breakpoint usecase overloading on ARM is a mess, and we would certainly like to avoid it if possible, albeit I have a patch in Russell's patch tracker to paper it over. Do you think that long term we could switch Clang to do what GCC does? Yours, Linus Walleij

