[PATCH v4 1/3] aarch64: Add configure checks for BTI support
Yury Khrustalev
yury.khrustalev@arm.com
Mon Dec 1 16:14:56 GMT 2025
We add configure checks for 3 things:
- Compiler (both CC and TEST_CC) supports -mbranch-protection=bti.
- Linker supports -z force-bti.
- The toolchain supplies object files and target libraries with
the BTI marking.
All three must be true in order for the tests to be valid, so
we check all flags and set the makefile variable accordingly.
Reviewed-by: Adhemerval Zanella <adhemerval.zanella@linaro.org>
---
sysdeps/aarch64/configure | 144 +++++++++++++++++++++++++++++++++++
sysdeps/aarch64/configure.ac | 36 +++++++++
2 files changed, 180 insertions(+)
diff --git a/sysdeps/aarch64/configure b/sysdeps/aarch64/configure
index eecdd324b2..44b833ea1d 100755
--- a/sysdeps/aarch64/configure
+++ b/sysdeps/aarch64/configure
@@ -196,6 +196,150 @@ fi
libc_cv_support_sframe=yes
+# Check if compilers support BTI in branch protection:
+
+{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking if compiler supports -mbranch-protection=bti" >&5
+printf %s "checking if compiler supports -mbranch-protection=bti... " >&6; }
+if test ${libc_cv_cc_bti+y}
+then :
+ printf %s "(cached) " >&6
+else case e in #(
+ e) if { ac_try='${CC-cc} -Werror -mbranch-protection=bti -xc /dev/null -S -o /dev/null'
+ { { eval echo "\"\$as_me\":${as_lineno-$LINENO}: \"$ac_try\""; } >&5
+ (eval $ac_try) 2>&5
+ ac_status=$?
+ printf "%s\n" "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+ test $ac_status = 0; }; }
+then :
+ libc_cv_cc_bti=yes
+else case e in #(
+ e) libc_cv_cc_bti=no ;;
+esac
+fi ;;
+esac
+fi
+{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $libc_cv_cc_bti" >&5
+printf "%s\n" "$libc_cv_cc_bti" >&6; }
+if test "$TEST_CC" = "$CC"; then
+ libc_cv_test_cc_bti=$libc_cv_cc_bti
+else
+
+saved_CC="$CC"
+CC="$TEST_CC"
+{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking if compiler supports -mbranch-protection=bti in testing" >&5
+printf %s "checking if compiler supports -mbranch-protection=bti in testing... " >&6; }
+if test ${libc_cv_test_cc_bti+y}
+then :
+ printf %s "(cached) " >&6
+else case e in #(
+ e) if { ac_try='${CC-cc} -Werror -mbranch-protection=bti -xc /dev/null -S -o /dev/null'
+ { { eval echo "\"\$as_me\":${as_lineno-$LINENO}: \"$ac_try\""; } >&5
+ (eval $ac_try) 2>&5
+ ac_status=$?
+ printf "%s\n" "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+ test $ac_status = 0; }; }
+then :
+ libc_cv_test_cc_bti=yes
+else case e in #(
+ e) libc_cv_test_cc_bti=no
+ ;;
+esac
+fi ;;
+esac
+fi
+{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $libc_cv_test_cc_bti" >&5
+printf "%s\n" "$libc_cv_test_cc_bti" >&6; }
+
+CC="$saved_CC"
+
+fi
+
+
+# Check if linker supports BTI marking
+{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking for linker that supports -z force-bti" >&5
+printf %s "checking for linker that supports -z force-bti... " >&6; }
+libc_linker_feature=no
+cat > conftest.c <<EOF
+int _start (void) { return 42; }
+EOF
+if { ac_try='${CC-cc} $CFLAGS $CPPFLAGS $LDFLAGS $no_ssp
+ -Wl,-z,force-bti -nostdlib -nostartfiles
+ -fPIC -shared -o conftest.so conftest.c
+ 1>&5'
+ { { eval echo "\"\$as_me\":${as_lineno-$LINENO}: \"$ac_try\""; } >&5
+ (eval $ac_try) 2>&5
+ ac_status=$?
+ printf "%s\n" "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+ test $ac_status = 0; }; }
+then
+ if ${CC-cc} $CFLAGS $CPPFLAGS $LDFLAGS $no_ssp -Wl,-z,force-bti -nostdlib \
+ -nostartfiles -fPIC -shared -o conftest.so conftest.c 2>&1 \
+ | grep "warning: -z force-bti ignored" > /dev/null 2>&1; then
+ true
+ else
+ libc_linker_feature=yes
+ fi
+fi
+rm -f conftest*
+if test $libc_linker_feature = yes; then
+ libc_cv_ld_bti=yes
+else
+ libc_cv_ld_bti=no
+
+fi
+{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $libc_linker_feature" >&5
+printf "%s\n" "$libc_linker_feature" >&6; }
+
+# Check if toolchain is enabled to support BTI
+{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking if toolchain is enabled to support BTI" >&5
+printf %s "checking if toolchain is enabled to support BTI... " >&6; }
+libc_elf_property=no
+cat > conftest.c <<EOF
+int foo (void) { return 42; }
+EOF
+if { ac_try='${CC-cc} $CFLAGS $CPPFLAGS $LDFLAGS
+ -fPIC -shared -o conftest.so conftest.c
+ 1>&5'
+ { { eval echo "\"\$as_me\":${as_lineno-$LINENO}: \"$ac_try\""; } >&5
+ (eval $ac_try) 2>&5
+ ac_status=$?
+ printf "%s\n" "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+ test $ac_status = 0; }; }
+then
+ if { ac_try='LC_ALL=C $READELF -n --wide conftest.so | grep "AArch64 feature: .*BTI" 1>&5'
+ { { eval echo "\"\$as_me\":${as_lineno-$LINENO}: \"$ac_try\""; } >&5
+ (eval $ac_try) 2>&5
+ ac_status=$?
+ printf "%s\n" "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+ test $ac_status = 0; }; }
+ then
+ libc_elf_property=yes
+ else
+ libc_elf_property=no
+ fi
+fi
+rm -f conftest*
+if test $libc_elf_property = yes; then
+ libc_cv_bti_supported=yes
+else
+ libc_cv_bti_supported=no
+
+fi
+{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $libc_elf_property" >&5
+printf "%s\n" "$libc_elf_property" >&6; }
+
+if test $libc_cv_cc_bti = yes && \
+ test $libc_cv_test_cc_bti = yes && \
+ test $libc_cv_ld_bti = yes && \
+ test $libc_cv_bti_supported = yes
+then
+ config_vars="$config_vars
+have-test-bti = yes"
+else
+ config_vars="$config_vars
+have-test-bti = no"
+fi
+
# Check if compilers support GCS in branch protection:
{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking if compiler supports -mbranch-protection=gcs" >&5
diff --git a/sysdeps/aarch64/configure.ac b/sysdeps/aarch64/configure.ac
index 8b01aa843d..b9981861f6 100644
--- a/sysdeps/aarch64/configure.ac
+++ b/sysdeps/aarch64/configure.ac
@@ -34,6 +34,42 @@ fi
libc_cv_support_sframe=yes
+# Check if compilers support BTI in branch protection:
+LIBC_TRY_CC_AND_TEST_CC_OPTION(
+ [if compiler supports -mbranch-protection=bti],
+ [-Werror -mbranch-protection=bti],
+ libc_cv_cc_bti,
+ [libc_cv_cc_bti=yes],
+ [libc_cv_cc_bti=no],
+ libc_cv_test_cc_bti,
+ [libc_cv_test_cc_bti=yes],
+ [libc_cv_test_cc_bti=no]
+)
+
+# Check if linker supports BTI marking
+LIBC_LINKER_FEATURE(
+ [-z force-bti], [-Wl,-z,force-bti],
+ [libc_cv_ld_bti=yes], [libc_cv_ld_bti=no]
+)
+
+# Check if toolchain is enabled to support BTI
+LIBC_CHECK_ELF_PROPERTY(
+ [if toolchain is enabled to support BTI],
+ [AArch64 feature: .*BTI],
+ [libc_cv_bti_supported=yes],
+ [libc_cv_bti_supported=no]
+)
+
+if test $libc_cv_cc_bti = yes && \
+ test $libc_cv_test_cc_bti = yes && \
+ test $libc_cv_ld_bti = yes && \
+ test $libc_cv_bti_supported = yes
+then
+ LIBC_CONFIG_VAR([have-test-bti], [yes])
+else
+ LIBC_CONFIG_VAR([have-test-bti], [no])
+fi
+
# Check if compilers support GCS in branch protection:
LIBC_TRY_CC_AND_TEST_CC_OPTION(
[if compiler supports -mbranch-protection=gcs],
--
2.47.3
More information about the Libc-alpha
mailing list