[PATCH 1/4] aarch64: add configure checks for BTI support
Adhemerval Zanella Netto
adhemerval.zanella@linaro.org
Mon Nov 10 14:31:53 GMT 2025
This looks ok, thanks.
Reviewed-by: Adhemerval Zanella <adhemerval.zanella@linaro.org>
On 31/10/25 16:37, Yury Khrustalev wrote:
> ---
> configure | 98 ++++++++++++++++++++++++++++++++++++++++++++++++++++
> configure.ac | 17 +++++++++
> 2 files changed, 115 insertions(+)
>
> diff --git a/configure b/configure
> index 85bfeec8a9..40696cbc3d 100755
> --- a/configure
> +++ b/configure
> @@ -9180,6 +9180,104 @@ printf "%s\n" "$libc_linker_feature" >&6; }
> config_vars="$config_vars
> load-address-ldflag = $libc_cv_load_address_ldflag"
>
> +# Check if compilers support BTI in branch protection:
> +
> +{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking if compiler supports -mbranch-protection=bti" >&5
> +printf %s "checking if compiler supports -mbranch-protection=bti... " >&6; }
> +if test ${libc_cv_cc_bti+y}
> +then :
> + printf %s "(cached) " >&6
> +else case e in #(
> + e) if { ac_try='${CC-cc} -Werror -mbranch-protection=bti -xc /dev/null -S -o /dev/null'
> + { { eval echo "\"\$as_me\":${as_lineno-$LINENO}: \"$ac_try\""; } >&5
> + (eval $ac_try) 2>&5
> + ac_status=$?
> + printf "%s\n" "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
> + test $ac_status = 0; }; }
> +then :
> + libc_cv_cc_bti=yes
> +else case e in #(
> + e) libc_cv_cc_bti=no ;;
> +esac
> +fi ;;
> +esac
> +fi
> +{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $libc_cv_cc_bti" >&5
> +printf "%s\n" "$libc_cv_cc_bti" >&6; }
> +if test "$TEST_CC" = "$CC"; then
> + libc_cv_test_cc_bti=$libc_cv_cc_bti
> +else
> +
> +saved_CC="$CC"
> +CC="$TEST_CC"
> +{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking if compiler supports -mbranch-protection=bti in testing" >&5
> +printf %s "checking if compiler supports -mbranch-protection=bti in testing... " >&6; }
> +if test ${libc_cv_test_cc_bti+y}
> +then :
> + printf %s "(cached) " >&6
> +else case e in #(
> + e) if { ac_try='${CC-cc} -Werror -mbranch-protection=bti -xc /dev/null -S -o /dev/null'
> + { { eval echo "\"\$as_me\":${as_lineno-$LINENO}: \"$ac_try\""; } >&5
> + (eval $ac_try) 2>&5
> + ac_status=$?
> + printf "%s\n" "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
> + test $ac_status = 0; }; }
> +then :
> + libc_cv_test_cc_bti=yes
> +else case e in #(
> + e) libc_cv_test_cc_bti=no ;;
> +esac
> +fi ;;
> +esac
> +fi
> +{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $libc_cv_test_cc_bti" >&5
> +printf "%s\n" "$libc_cv_test_cc_bti" >&6; }
> +
> +CC="$saved_CC"
> +
> +fi
> +
> +config_vars="$config_vars
> +have-cc-bti = $libc_cv_cc_bti"
> +config_vars="$config_vars
> +have-test-cc-bti = $libc_cv_test_cc_bti"
> +
> +# Check if linker supports BTI marking
> +{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking for linker that supports -z force-bti" >&5
> +printf %s "checking for linker that supports -z force-bti... " >&6; }
> +libc_linker_feature=no
> +cat > conftest.c <<EOF
> +int _start (void) { return 42; }
> +EOF
> +if { ac_try='${CC-cc} $CFLAGS $CPPFLAGS $LDFLAGS $no_ssp
> + -Wl,-z,force-bti -nostdlib -nostartfiles
> + -fPIC -shared -o conftest.so conftest.c
> + 1>&5'
> + { { eval echo "\"\$as_me\":${as_lineno-$LINENO}: \"$ac_try\""; } >&5
> + (eval $ac_try) 2>&5
> + ac_status=$?
> + printf "%s\n" "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
> + test $ac_status = 0; }; }
> +then
> + if ${CC-cc} $CFLAGS $CPPFLAGS $LDFLAGS $no_ssp -Wl,-z,force-bti -nostdlib \
> + -nostartfiles -fPIC -shared -o conftest.so conftest.c 2>&1 \
> + | grep "warning: -z force-bti ignored" > /dev/null 2>&1; then
> + true
> + else
> + libc_linker_feature=yes
> + fi
> +fi
> +rm -f conftest*
> +if test $libc_linker_feature = yes; then
> + libc_cv_ld_bti=yes
> +else
> + libc_cv_ld_bti=no
> +fi
> +{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $libc_linker_feature" >&5
> +printf "%s\n" "$libc_linker_feature" >&6; }
> +config_vars="$config_vars
> +have-ld-bti = $libc_cv_ld_bti"
> +
> # Check if compilers support GCS in branch protection:
>
> { printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking if compiler supports -mbranch-protection=gcs" >&5
> diff --git a/configure.ac b/configure.ac
> index 2cb49f49bc..5475798dcc 100644
> --- a/configure.ac
> +++ b/configure.ac
> @@ -2068,6 +2068,23 @@ LIBC_LINKER_FEATURE([-Ttext-segment=$libc_cv_pde_load_address],
> [libc_cv_load_address_ldflag=])
> LIBC_CONFIG_VAR([load-address-ldflag], [$libc_cv_load_address_ldflag])
>
> +# Check if compilers support BTI in branch protection:
> +LIBC_TRY_CC_AND_TEST_CC_OPTION([if compiler supports -mbranch-protection=bti],
> + [-Werror -mbranch-protection=bti],
> + libc_cv_cc_bti,
> + [libc_cv_cc_bti=yes],
> + [libc_cv_cc_bti=no],
> + libc_cv_test_cc_bti,
> + [libc_cv_test_cc_bti=yes],
> + [libc_cv_test_cc_bti=no])
> +LIBC_CONFIG_VAR([have-cc-bti], [$libc_cv_cc_bti])
> +LIBC_CONFIG_VAR([have-test-cc-bti], [$libc_cv_test_cc_bti])
> +
> +# Check if linker supports BTI marking
> +LIBC_LINKER_FEATURE([-z force-bti], [-Wl,-z,force-bti],
> + [libc_cv_ld_bti=yes], [libc_cv_ld_bti=no])
> +LIBC_CONFIG_VAR([have-ld-bti], [$libc_cv_ld_bti])
> +
> # Check if compilers support GCS in branch protection:
> LIBC_TRY_CC_AND_TEST_CC_OPTION([if compiler supports -mbranch-protection=gcs],
> [-Werror -mbranch-protection=gcs],
More information about the Libc-alpha
mailing list