[PATCH v7 14/14] aarch64: add NEWS entry about branch protection support
Adhemerval Zanella
adhemerval.zanella@linaro.org
Wed Jul 8 13:48:54 GMT 2020
On 08/07/2020 09:14, Szabolcs Nagy wrote:
> This is a new security feature that relies on architecture
> extensions and needs glibc to be built with a gcc configured
> with branch protection.
LGTM, thanks. I think I have acked patches, is there still a missing one?
Otherwise I think the patchset it ok to be pushed upstream.
> ---
> NEWS | 11 +++++++++++
> 1 file changed, 11 insertions(+)
>
> diff --git a/NEWS b/NEWS
> index d7282b4ad5..5083f5eacf 100644
> --- a/NEWS
> +++ b/NEWS
> @@ -67,6 +67,17 @@ Major new features:
> They should be used instead of sys_errlist and sys_nerr, both are
> thread and async-signal safe. These functions are GNU extensions.
>
> +* AArch64 now supports standard branch protection security hardening
> + in glibc when it is built with a GCC that is configured with
> + --enable-standard-branch-protection. This includes branch target
> + identification (BTI) and pointer authentication for return addresses
> + (PAC-RET). They require armv8.5-a and armv8.3-a architecture
> + extensions respectively for the protection to be effective,
> + otherwise the used instructions are nops. User code can use PAC-RET
> + without libc support, but BTI requires a libc that is built with BTI
> + support, otherwise runtime objects linked into user code will not be
> + BTI compatible.
> +
> Deprecated and removed features, and other changes affecting compatibility:
>
> * The deprecated <sys/sysctl.h> header and the sysctl function have been
>
Ok.
More information about the Libc-alpha
mailing list