[PATCH v0 00/13] aarch64: add instructions for Armv9.5-A PAC enhancement

Matthieu Longo matthieu.longo@arm.com
Mon Jul 8 12:34:39 GMT 2024


Hi,

[patch 0/13] aarch64: add instructions for Armv9.5-A PAC enhancement
    [patch v1 1/13] aarch64: make comment clearer about the location
    [patch v1 2/13] aarch64: constify unchanged char* arguments
    [patch v1 3/13] aarch64: change returned type to bool to match semantic of functions
    [patch v1 4/13] aarch64: improve debuggability on array of enum
    [patch v1 5/13] aarch64: remove redundant register type R_N
    [patch v1 6/13] aarch64: testsuite: remove hard-coded instruction addresses
    [patch v1 7/13] aarch64: add PAuth_LR instructions belonging to NOP space
    [patch v1 8/13] aarch64: add pauth-lr feature option for Armv9.5-A PAC enhancements
    [patch v1 9/13] aarch64: add PAuth_LR instructions with no or one-register operand
    [patch v1 10/13] aarch64: add flag OPD_F_UNSIGNED to distinguish signedness of immediate operands
    [patch v1 11/13] aarch64: add PAuth_LR instructions with imm16 operand
    [patch v1 11/13] aarch64: refactor binary approach for RA signing method to make it extendable
    [patch v1 12/13] aarch64: add DWARF CFI directive for PAuth_LR


The new Armv9.5-A architecture introduces an enhancement of the previous PAuth feature. For context, the Pointer Authentication architecture provides instructions that enable software to sign an address using SP as a diversifier. This form of PAC instruction is typically used for signing return addresses that are stored on the stack. The FEAT_PAuth_LR extension aims to harden the PAC in a signed return address, when signing the return address in LR, the PC is used as a diversifier, in addition to the SP to generate PAC code.


This patch series adds:

- the command-line feature option 'pauth-lr' for Armv9.5-A PAC enhancements. For now, it requires to be explicitly set along the targeted architecture, but will be the default for the future 'armv9.5-a' target architecture.

- the instructions required by Armv9.5-A PAC enhancements.
  * pacm (that belongs to the NOP space, and allows a compatibility mode with the previous PAuth instructions).
  * paci<k>sppc, pacnbi<>sppc, paci<k>171615, auti<k>171615.
  * the imm16 and register variants of the authentication instructions: auti<k>sppc and reta<k>sppc, and auti<k>sppcr and reta<k>sppcr respectively.

- a new register type R_N was also added to prevent a misuse of SP or XZR registers with the register variant instructions.

- a new operand flag OPD_F_UNSIGNED to signal that the immediate value should be treated as an unsigned value. The default signedness of immediate operands is signed.

- a new operand parser (ADDR_UPCREL16) for 16-bits unsigned immediate operand, and a new relocation type (BFD_RELOC_AARCH64_AUTI_LO16_PCREL) specific to the auti<k>sppc and reta<k>sppc instructions and only used for computing the PC-relative offset, but does no relocation.

- a new CFI directive (cfi_negate_ra_state_with_pc) which set an additional bit in the RA state to inform that RA was signed with SP but also PC as an additional diversifier. (more details at https://github.com/ARM-software/abi-aa/pull/245)
RA state | Description
-------------------------------------------------------------------------
0b00     | Return address not signed (default if no cfi_negate_ra_state*)
0b01     | Return address signed with SP (cfi_negate_ra_state)
0b10     | Invalid state
0b11     | Return address signed with SP+PC (cfi_negate_ra_state_with_pc)


Each patch also adds relevant tests.
Regression tested on aarch64-unknown-linux-gnu, and no regression found.

Ok for binutils-master?

Regards,
Matthieu.

Matthieu Longo (13):
  aarch64: make comment clearer about the location
  aarch64: constify unchanged char* arguments
  aarch64: change returned type to bool to match semantic of functions
  aarch64: improve debuggability on array of enum
  aarch64: remove redundant register type R_N
  aarch64: testsuite: remove hard-coded instruction addresses
  aarch64: refactor binary approach for RA signing method to make it extendable
  aarch64: add PAuth_LR instructions belonging to NOP space
  aarch64: add pauth-lr feature option for Armv9.5-A PAC enhancements
  aarch64: add PAuth_LR instructions with no or one-register operand
  aarch64: add flag OPD_F_UNSIGNED to distinguish signedness of immediate operands
  aarch64: add PAuth_LR instructions with imm16 operand
  aarch64: add DWARF CFI directive for PAuth_LR

 bfd/elf-eh-frame.c                            |   1 +
 bfd/elfnn-aarch64.c                           |   8 +-
 bfd/reloc.c                                   |  17 +-
 binutils/dwarf.c                              |   5 +
 gas/config/tc-aarch64.c                       |  68 ++-
 gas/dw2gencfi.c                               |  10 +
 gas/gen-sframe.c                              |  46 +-
 gas/gen-sframe.h                              |  15 +-
 gas/scfidw2gen.c                              |   1 +
 .../gas/aarch64/pac_negate_ra_state_with_pc.d |  64 +++
 .../gas/aarch64/pac_negate_ra_state_with_pc.s |  53 ++
 gas/testsuite/gas/aarch64/pauth_lr-bad.d      |   3 +
 gas/testsuite/gas/aarch64/pauth_lr-bad.l      |  19 +
 gas/testsuite/gas/aarch64/pauth_lr-bad.s      |  27 +
 gas/testsuite/gas/aarch64/pauth_lr.d          |  37 ++
 gas/testsuite/gas/aarch64/pauth_lr.s          |  47 ++
 gas/testsuite/gas/aarch64/system-3.d          |  54 +-
 gas/testsuite/gas/aarch64/system-3.s          |   4 +
 gas/testsuite/gas/aarch64/system.d            |   2 +-
 include/dwarf2.def                            |   4 +-
 include/opcode/aarch64.h                      |  16 +-
 include/sframe.h                              |   4 +-
 opcodes/aarch64-opc.c                         | 462 ++++++++++--------
 opcodes/aarch64-opc.h                         |   9 +-
 opcodes/aarch64-tbl.h                         |  36 ++
 25 files changed, 748 insertions(+), 264 deletions(-)
 create mode 100644 gas/testsuite/gas/aarch64/pac_negate_ra_state_with_pc.d
 create mode 100644 gas/testsuite/gas/aarch64/pac_negate_ra_state_with_pc.s
 create mode 100644 gas/testsuite/gas/aarch64/pauth_lr-bad.d
 create mode 100644 gas/testsuite/gas/aarch64/pauth_lr-bad.l
 create mode 100644 gas/testsuite/gas/aarch64/pauth_lr-bad.s
 create mode 100644 gas/testsuite/gas/aarch64/pauth_lr.d
 create mode 100644 gas/testsuite/gas/aarch64/pauth_lr.s

-- 
2.45.1



More information about the Binutils mailing list