[3.14] gh-139808: Add branch protections for aarch64 in asm_trampoline.S (#130864) - #150189
Conversation
โฆ.S (python#130864) Apply protection against ROP/JOP attacks for aarch64 on asm_trampoline.S. The BTI flag must be applied in assembler sources for this class of attacks to be mitigated on newer aarch64 processors. See also: https://sourceware.org/annobin/annobin.html/Test-branch-protection.html and https://community.arm.com/arm-community-blogs/b/architectures-and-processors-blog/posts/enabling-pac-and-bti-on-aarch64 The 3.14 backport makes Python/jit_unwind.c changes in Python/perf_jit_trampoline.c. Co-authored-by: Victor Stinner <[email protected]> (cherry picked from commit da8477b)
|
I tested this change on Fedora 43 AArch64 with commands: Output: The BTI and PAC protections are present as expected. |
|
The backport looks good, the relevant sections in perf_jit_trampoline.c are exactly identical with jit_unwind.c from the later branches. I've also tested the combination with/without frame pointers and with/without -mbranch-protection=standard, when using the protections, the binary has the proper notes and Perf works across all the paths in all the combons, the frame pointer path and the backup dwarf path. |
|
I merged the PR. @stratakis: Thanks for testing all possible cases! |
|
Thanks @vstinner for the PR ๐ฎ๐.. I'm working now to backport this PR to: 3.13. |
|
GH-150194 is a backport of this pull request to the 3.13 branch. |
โฆe.S (GH-130864) (GH-150189) (#150194) [3.14] gh-139808: Add branch protections for aarch64 in asm_trampoline.S (GH-130864) (GH-150189) gh-139808: Add branch protections for aarch64 in asm_trampoline.S (GH-130864) Apply protection against ROP/JOP attacks for aarch64 on asm_trampoline.S. The BTI flag must be applied in assembler sources for this class of attacks to be mitigated on newer aarch64 processors. See also: https://sourceware.org/annobin/annobin.html/Test-branch-protection.html and https://community.arm.com/arm-community-blogs/b/architectures-and-processors-blog/posts/enabling-pac-and-bti-on-aarch64 The 3.14 backport makes Python/jit_unwind.c changes in Python/perf_jit_trampoline.c. (cherry picked from commit da8477b) (cherry picked from commit c863e96) Co-authored-by: Victor Stinner <[email protected]> Co-authored-by: stratakis <[email protected]>
Apply protection against ROP/JOP attacks for aarch64 on asm_trampoline.S.
The BTI flag must be applied in assembler sources for this class of attacks to be mitigated on newer aarch64 processors.
See also:
https://sourceware.org/annobin/annobin.html/Test-branch-protection.html and
https://community.arm.com/arm-community-blogs/b/architectures-and-processors-blog/posts/enabling-pac-and-bti-on-aarch64
The 3.14 backport makes Python/jit_unwind.c changes in Python/perf_jit_trampoline.c.
(cherry picked from commit da8477b)