Skip to content

Arm64:[PAC-RET]Fix ARM64 epilog detection and PAC signing SP recovery - #135088

Merged
jkotas merged 4 commits into
dotnet:mainfrom
SwapnilGaikwad:github-fix-134912
Oct 6, 2026
Merged

jkotas merged 4 commits into
dotnet:mainfrom
SwapnilGaikwad:github-fix-134912

Conversation

@SwapnilGaikwad

Copy link
Copy Markdown
Contributor

Fixes: #134912

  • Stop treating SP adjustments as evidence of an epilog: they may occur during stack allocation in the function body.
  • Continue rejecting hijacking after FP or LR has been restored.
  • For NativeAOT assert that signing SP equals CFA.
  • Use the caller SP recovered by unwinding to sign hijacked return addresses. This avoids reconstructing signing SP from frame offsets.

Fixes: dotnet#134912

- Stop treating SP adjustments as evidence of an epilog: they may occur
during stack allocation in the function body.
- Continue rejecting hijacking after FP or LR has been restored.
- For NativeAOT assert that signing SP equals CFA.
- Use the caller SP recovered by unwinding to sign hijacked return
addresses. This avoids reconstructing signing SP from frame offsets.
@dotnet-policy-service dotnet-policy-service Bot added the community-contribution Indicates that the PR has been added by a community member label Oct 2, 2026
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 6 pipeline(s).
10 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @agocke, @dotnet/ilc-contrib
See info in area-owners.md if you want to be subscribed.

@SwapnilGaikwad

Copy link
Copy Markdown
Contributor Author

cc: @dotnet/arm64-contrib @jkotas @dhartglassMSFT

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The new CFA invariant breaks PAC-enabled ARM64 OSR prologs and can produce invalid hijack signatures.

Review effort: Balanced
Findings: 1 High severity

Open (1)
What changed in this PR

Fixes ARM64 PAC return-address hijacking and epilog detection in NativeAOT.

Changes:

  • Refines ARM64 epilog detection.
  • Recovers PAC signing SP through unwinding.
  • Adds signing-SP/CFA assertions.
File Description
CorInfoImpl.RyuJit.cs Validates PAC CFI assumptions.
UnixNativeCodeManager.cpp Updates epilog detection and PAC signing-SP recovery.
unwindarm64.cpp Asserts PAC occurs before frame setup.

Comment thread src/coreclr/jit/unwindarm64.cpp
Comment thread src/coreclr/nativeaot/Runtime/unix/UnixNativeCodeManager.cpp
@jkotas

jkotas commented Oct 6, 2026

Copy link
Copy Markdown
Member

/azp run runtime-nativeaot-outerloop

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).

@jkotas
jkotas merged commit 4cc1f5a into dotnet:main Oct 6, 2026
162 of 166 checks passed
@jkotas

jkotas commented Oct 6, 2026

Copy link
Copy Markdown
Member

Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-NativeAOT-coreclr community-contribution Indicates that the PR has been added by a community member

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Assertion 'codeManager->IsUnwindable(pvAddress) || runtime->IsConservativeStackReportingEnabled()' in System.Runtime.Tests on ARM64

3 participants