Skip to content

Arm64:[PAC-RET]Fix ARM64 epilog detection and PAC signing SP recovery - #135088

Open
SwapnilGaikwad wants to merge 4 commits into
dotnet:mainfrom
SwapnilGaikwad:github-fix-134912
Open

SwapnilGaikwad wants to merge 4 commits into
dotnet:mainfrom
SwapnilGaikwad:github-fix-134912

Conversation

@SwapnilGaikwad

Copy link
Copy Markdown
Contributor

Fixes: #134912

  • Stop treating SP adjustments as evidence of an epilog: they may occur during stack allocation in the function body.
  • Continue rejecting hijacking after FP or LR has been restored.
  • For NativeAOT assert that signing SP equals CFA.
  • Use the caller SP recovered by unwinding to sign hijacked return addresses. This avoids reconstructing signing SP from frame offsets.

Fixes: dotnet#134912

- Stop treating SP adjustments as evidence of an epilog: they may occur
during stack allocation in the function body.
- Continue rejecting hijacking after FP or LR has been restored.
- For NativeAOT assert that signing SP equals CFA.
- Use the caller SP recovered by unwinding to sign hijacked return
addresses. This avoids reconstructing signing SP from frame offsets.
@dotnet-policy-service dotnet-policy-service Bot added the community-contribution Indicates that the PR has been added by a community member label Oct 2, 2026
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 6 pipeline(s).
10 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @agocke, @dotnet/ilc-contrib
See info in area-owners.md if you want to be subscribed.

@SwapnilGaikwad

Copy link
Copy Markdown
Contributor Author

cc: @dotnet/arm64-contrib @jkotas @dhartglassMSFT

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The new CFA invariant breaks PAC-enabled ARM64 OSR prologs and can produce invalid hijack signatures.

Review effort: Balanced
Findings: 1 High severity

Open (1)
What changed in this PR

Fixes ARM64 PAC return-address hijacking and epilog detection in NativeAOT.

Changes:

  • Refines ARM64 epilog detection.
  • Recovers PAC signing SP through unwinding.
  • Adds signing-SP/CFA assertions.
File Description
CorInfoImpl.RyuJit.cs Validates PAC CFI assumptions.
UnixNativeCodeManager.cpp Updates epilog detection and PAC signing-SP recovery.
unwindarm64.cpp Asserts PAC occurs before frame setup.

UNATIVE_OFFSET cbProlog = unwindGetCurrentOffset(func);
// Sign before frame setup so signing SP == CFA.
// Stack probes may precede PAC because they do not change SP.
assert(func->cfiCodes->empty());

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This check is in generateCFIUnwindCodes() that's true on Unix NativeAOT. We do not have OSR for NativeAOT so it's safe to assert no cfi codes are present to ensure SP == CFA.

Comment thread src/coreclr/nativeaot/Runtime/unix/UnixNativeCodeManager.cpp
@jkotas

jkotas commented Oct 6, 2026

Copy link
Copy Markdown
Member

/azp run runtime-nativeaot-outerloop

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-NativeAOT-coreclr community-contribution Indicates that the PR has been added by a community member

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Assertion 'codeManager->IsUnwindable(pvAddress) || runtime->IsConservativeStackReportingEnabled()' in System.Runtime.Tests on ARM64

3 participants