Skip to content

Arm64: [PAC-RET] Jit Support - #127838

Merged
dhartglassMSFT merged 12 commits into
dotnet:mainfrom
SwapnilGaikwad:github-jit-pac
May 19, 2026
Merged

Arm64: [PAC-RET] Jit Support#127838
dhartglassMSFT merged 12 commits into
dotnet:mainfrom
SwapnilGaikwad:github-jit-pac

Conversation

@SwapnilGaikwad

@SwapnilGaikwadSwapnilGaikwad commented May 5, 2026

Copy link
Copy Markdown
Contributor

As suggested in comment, this PR covers subset of changes from #125436 related to the JIT.

This PR adds support for Pointer Authentication (PAC) on Arm64. Pointer Authentication (PAC) is an Armv8.3+ security feature designed to mitigate Return-Oriented Programming (ROP) attacks by cryptographically signing return addresses. While using PAC, we store a signed return address, instead of the plain address, on the stack and later authenticate it before returning from a function. It ensures control flow returns to the intended caller.

More details on PAC and its role in software security can be found (here).

  • The current implementation of PAC is turned off by default, but can be turned on by setting DOTNET_JitPacEnabled=1.
  • PAC protects link register (LR) by signing it in the prolog (using paciasp) before it is split, using the current SP as the modifier. It then authenticates the LR in the epilog (using autiasp) before the function returns. If the signature is invalid, the execution fails with SIGILL.
  • Changes are limited to JIT.

NOTE: This PR adds part of the changes for PAC support to simply review process as discussed here. However it cannot pass the tests without the remaining parts. Kindly take a look at the CI status of #125436 to ensure correctness.

…/3: JIT changes)
As suggested in [comment](dotnet#125436 (comment)), this PR covers subset of changes from dotnet#125436 related to the JIT.
This PR adds support for Pointer Authentication (PAC) on Arm64. Pointer Authentication (PAC) is an Armv8.3+ security feature designed to mitigate Return-Oriented Programming (ROP) attacks by cryptographically signing return addresses. While using PAC, we store a signed return address, instead of the plain address, on the stack and later authenticate it before returning from a function. It ensures control flow returns to the intended caller.
More details on PAC and its role in software security can be found ([here](https://llsoftsec.github.io/llsoftsecbook/#sec:pointer-authentication)).
- The current implementation of PAC is turned off by default, but can be turned on by setting DOTNET_JitPacEnabled=1.
- PAC protects link register (LR) by signing it in the prolog (using `paciasp`) before it is split, using the current SP as the modifier. It then authenticates the LR in the epilog (using `autiasp`) before the function returns. If the signature is invalid, the execution fails with `SIGILL`.
- Changes are limited to JIT.
@github-actionsgithub-actionsBot added the area-CodeGen-coreclr CLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI label May 5, 2026
@dotnet-policy-servicedotnet-policy-serviceBot added the community-contribution Indicates that the PR has been added by a community member label May 5, 2026
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @JulieLeeMSFT, @jakobbotsch
See info in area-owners.md if you want to be subscribed.

Comment threadsrc/coreclr/jit/unwindarm64.cpp Outdated
Comment threadsrc/coreclr/jit/codegenarm64.cpp
@SwapnilGaikwadSwapnilGaikwad changed the title Arm64: [PAC-RET] Add Pointer Authentication support for Arm64 (Part 1…Arm64: [PAC-RET] Add Pointer Authentication support for Arm64 (Part 1/3): JIT changesMay 8, 2026
@SwapnilGaikwad

Copy link
Copy Markdown
ContributorAuthor

This PR uses parts of #127949. It would be great if we could get PAC encoding PR earlier.

@SwapnilGaikwadSwapnilGaikwad changed the title Arm64: [PAC-RET] Add Pointer Authentication support for Arm64 (Part 1/3): JIT changesArm64: [PAC-RET] Add Pointer Authentication support for Arm64 (Part 1/3): JITMay 8, 2026
@SwapnilGaikwadSwapnilGaikwad changed the title Arm64: [PAC-RET] Add Pointer Authentication support for Arm64 (Part 1/3): JITArm64: [PAC-RET] Add Pointer Authentication support for Arm64 (Part 1/3: JIT)May 8, 2026
@SwapnilGaikwadSwapnilGaikwad changed the title Arm64: [PAC-RET] Add Pointer Authentication support for Arm64 (Part 1/3: JIT)Arm64: [PAC-RET] Jit SupportMay 11, 2026
dhartglassMSFT pushed a commit that referenced this pull request May 13, 2026
This PR adds instruction encodings for Pointer Authentication
instructions, especially the B key variants.
Part of this is useful for #125436 and #127838.
Add encoding for:
1. AUTIB
2. AUTIB1716
3. AUTIBSP
4. AUTIBZ
5. AUTIZB
6. PACIB
7. PACIB1716
8. PACIBSP
9. PACIBZ
10. PACIZB
11. RETAA
12. RETAB
@jakobbotsch

Copy link
Copy Markdown
Member

Can you resolve the conflicts?

Comment threadsrc/coreclr/jit/jitconfigvalues.h Outdated
@dhartglassMSFT
dhartglassMSFT enabled auto-merge (squash) May 19, 2026 00:07
@dhartglassMSFT

Copy link
Copy Markdown
Contributor

/ba-g known infra issues

@dhartglassMSFT
dhartglassMSFT merged commit 286dc15 into dotnet:mainMay 19, 2026
132 of 140 checks passed
@SwapnilGaikwad
SwapnilGaikwad deleted the github-jit-pac branch May 19, 2026 09:09
@dotnet-milestone-botdotnet-milestone-botBot added this to the 11.0-preview6 milestone May 21, 2026
@a74nha74nh mentioned this pull request Jun 3, 2026
20 tasks
@github-actionsgithub-actionsBot locked and limited conversation to collaborators Jun 21, 2026
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-CodeGen-coreclrCLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMIcommunity-contributionIndicates that the PR has been added by a community member

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@SwapnilGaikwad@jakobbotsch@dhartglassMSFT@jkotas@AndyAyersMS
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Arm64: [PAC-RET] Jit Support by SwapnilGaikwad · Pull Request #127838 · dotnet/runtime · GitHub
Skip to content

Arm64: [PAC-RET] Jit Support - #127838

Merged
dhartglassMSFT merged 12 commits into
dotnet:mainfrom
SwapnilGaikwad:github-jit-pac
May 19, 2026
Merged

Arm64: [PAC-RET] Jit Support#127838
dhartglassMSFT merged 12 commits into
dotnet:mainfrom
SwapnilGaikwad:github-jit-pac

Conversation

@SwapnilGaikwad

@SwapnilGaikwadSwapnilGaikwad commented May 5, 2026

Copy link
Copy Markdown
Contributor

As suggested in comment, this PR covers subset of changes from #125436 related to the JIT.

This PR adds support for Pointer Authentication (PAC) on Arm64. Pointer Authentication (PAC) is an Armv8.3+ security feature designed to mitigate Return-Oriented Programming (ROP) attacks by cryptographically signing return addresses. While using PAC, we store a signed return address, instead of the plain address, on the stack and later authenticate it before returning from a function. It ensures control flow returns to the intended caller.

More details on PAC and its role in software security can be found (here).

  • The current implementation of PAC is turned off by default, but can be turned on by setting DOTNET_JitPacEnabled=1.
  • PAC protects link register (LR) by signing it in the prolog (using paciasp) before it is split, using the current SP as the modifier. It then authenticates the LR in the epilog (using autiasp) before the function returns. If the signature is invalid, the execution fails with SIGILL.
  • Changes are limited to JIT.

NOTE: This PR adds part of the changes for PAC support to simply review process as discussed here. However it cannot pass the tests without the remaining parts. Kindly take a look at the CI status of #125436 to ensure correctness.

…/3: JIT changes)
As suggested in [comment](dotnet#125436 (comment)), this PR covers subset of changes from dotnet#125436 related to the JIT.
This PR adds support for Pointer Authentication (PAC) on Arm64. Pointer Authentication (PAC) is an Armv8.3+ security feature designed to mitigate Return-Oriented Programming (ROP) attacks by cryptographically signing return addresses. While using PAC, we store a signed return address, instead of the plain address, on the stack and later authenticate it before returning from a function. It ensures control flow returns to the intended caller.
More details on PAC and its role in software security can be found ([here](https://llsoftsec.github.io/llsoftsecbook/#sec:pointer-authentication)).
- The current implementation of PAC is turned off by default, but can be turned on by setting DOTNET_JitPacEnabled=1.
- PAC protects link register (LR) by signing it in the prolog (using `paciasp`) before it is split, using the current SP as the modifier. It then authenticates the LR in the epilog (using `autiasp`) before the function returns. If the signature is invalid, the execution fails with `SIGILL`.
- Changes are limited to JIT.
@github-actionsgithub-actionsBot added the area-CodeGen-coreclr CLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI label May 5, 2026
@dotnet-policy-servicedotnet-policy-serviceBot added the community-contribution Indicates that the PR has been added by a community member label May 5, 2026
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @JulieLeeMSFT, @jakobbotsch
See info in area-owners.md if you want to be subscribed.

Comment threadsrc/coreclr/jit/unwindarm64.cpp Outdated
Comment threadsrc/coreclr/jit/codegenarm64.cpp
@SwapnilGaikwadSwapnilGaikwad changed the title Arm64: [PAC-RET] Add Pointer Authentication support for Arm64 (Part 1…Arm64: [PAC-RET] Add Pointer Authentication support for Arm64 (Part 1/3): JIT changesMay 8, 2026
@SwapnilGaikwad

Copy link
Copy Markdown
ContributorAuthor

This PR uses parts of #127949. It would be great if we could get PAC encoding PR earlier.

@SwapnilGaikwadSwapnilGaikwad changed the title Arm64: [PAC-RET] Add Pointer Authentication support for Arm64 (Part 1/3): JIT changesArm64: [PAC-RET] Add Pointer Authentication support for Arm64 (Part 1/3): JITMay 8, 2026
@SwapnilGaikwadSwapnilGaikwad changed the title Arm64: [PAC-RET] Add Pointer Authentication support for Arm64 (Part 1/3): JITArm64: [PAC-RET] Add Pointer Authentication support for Arm64 (Part 1/3: JIT)May 8, 2026
@SwapnilGaikwadSwapnilGaikwad changed the title Arm64: [PAC-RET] Add Pointer Authentication support for Arm64 (Part 1/3: JIT)Arm64: [PAC-RET] Jit SupportMay 11, 2026
dhartglassMSFT pushed a commit that referenced this pull request May 13, 2026
This PR adds instruction encodings for Pointer Authentication
instructions, especially the B key variants.
Part of this is useful for #125436 and #127838.
Add encoding for:
1. AUTIB
2. AUTIB1716
3. AUTIBSP
4. AUTIBZ
5. AUTIZB
6. PACIB
7. PACIB1716
8. PACIBSP
9. PACIBZ
10. PACIZB
11. RETAA
12. RETAB
@jakobbotsch

Copy link
Copy Markdown
Member

Can you resolve the conflicts?

Comment threadsrc/coreclr/jit/jitconfigvalues.h Outdated
@dhartglassMSFT
dhartglassMSFT enabled auto-merge (squash) May 19, 2026 00:07
@dhartglassMSFT

Copy link
Copy Markdown
Contributor

/ba-g known infra issues

@dhartglassMSFT
dhartglassMSFT merged commit 286dc15 into dotnet:mainMay 19, 2026
132 of 140 checks passed
@SwapnilGaikwad
SwapnilGaikwad deleted the github-jit-pac branch May 19, 2026 09:09
@dotnet-milestone-botdotnet-milestone-botBot added this to the 11.0-preview6 milestone May 21, 2026
@a74nha74nh mentioned this pull request Jun 3, 2026
20 tasks
@github-actionsgithub-actionsBot locked and limited conversation to collaborators Jun 21, 2026
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-CodeGen-coreclrCLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMIcommunity-contributionIndicates that the PR has been added by a community member

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@SwapnilGaikwad@jakobbotsch@dhartglassMSFT@jkotas@AndyAyersMS
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Arm64: [PAC-RET] Jit Support by SwapnilGaikwad · Pull Request #127838 · dotnet/runtime · GitHub
Skip to content

Arm64: [PAC-RET] Jit Support - #127838

Merged
dhartglassMSFT merged 12 commits into
dotnet:mainfrom
SwapnilGaikwad:github-jit-pac
May 19, 2026
Merged

Arm64: [PAC-RET] Jit Support#127838
dhartglassMSFT merged 12 commits into
dotnet:mainfrom
SwapnilGaikwad:github-jit-pac

Conversation

@SwapnilGaikwad

@SwapnilGaikwadSwapnilGaikwad commented May 5, 2026

Copy link
Copy Markdown
Contributor

As suggested in comment, this PR covers subset of changes from #125436 related to the JIT.

This PR adds support for Pointer Authentication (PAC) on Arm64. Pointer Authentication (PAC) is an Armv8.3+ security feature designed to mitigate Return-Oriented Programming (ROP) attacks by cryptographically signing return addresses. While using PAC, we store a signed return address, instead of the plain address, on the stack and later authenticate it before returning from a function. It ensures control flow returns to the intended caller.

More details on PAC and its role in software security can be found (here).

  • The current implementation of PAC is turned off by default, but can be turned on by setting DOTNET_JitPacEnabled=1.
  • PAC protects link register (LR) by signing it in the prolog (using paciasp) before it is split, using the current SP as the modifier. It then authenticates the LR in the epilog (using autiasp) before the function returns. If the signature is invalid, the execution fails with SIGILL.
  • Changes are limited to JIT.

NOTE: This PR adds part of the changes for PAC support to simply review process as discussed here. However it cannot pass the tests without the remaining parts. Kindly take a look at the CI status of #125436 to ensure correctness.

…/3: JIT changes)
As suggested in [comment](dotnet#125436 (comment)), this PR covers subset of changes from dotnet#125436 related to the JIT.
This PR adds support for Pointer Authentication (PAC) on Arm64. Pointer Authentication (PAC) is an Armv8.3+ security feature designed to mitigate Return-Oriented Programming (ROP) attacks by cryptographically signing return addresses. While using PAC, we store a signed return address, instead of the plain address, on the stack and later authenticate it before returning from a function. It ensures control flow returns to the intended caller.
More details on PAC and its role in software security can be found ([here](https://llsoftsec.github.io/llsoftsecbook/#sec:pointer-authentication)).
- The current implementation of PAC is turned off by default, but can be turned on by setting DOTNET_JitPacEnabled=1.
- PAC protects link register (LR) by signing it in the prolog (using `paciasp`) before it is split, using the current SP as the modifier. It then authenticates the LR in the epilog (using `autiasp`) before the function returns. If the signature is invalid, the execution fails with `SIGILL`.
- Changes are limited to JIT.
@github-actionsgithub-actionsBot added the area-CodeGen-coreclr CLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI label May 5, 2026
@dotnet-policy-servicedotnet-policy-serviceBot added the community-contribution Indicates that the PR has been added by a community member label May 5, 2026
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @JulieLeeMSFT, @jakobbotsch
See info in area-owners.md if you want to be subscribed.

Comment threadsrc/coreclr/jit/unwindarm64.cpp Outdated
Comment threadsrc/coreclr/jit/codegenarm64.cpp
@SwapnilGaikwadSwapnilGaikwad changed the title Arm64: [PAC-RET] Add Pointer Authentication support for Arm64 (Part 1…Arm64: [PAC-RET] Add Pointer Authentication support for Arm64 (Part 1/3): JIT changesMay 8, 2026
@SwapnilGaikwad

Copy link
Copy Markdown
ContributorAuthor

This PR uses parts of #127949. It would be great if we could get PAC encoding PR earlier.

@SwapnilGaikwadSwapnilGaikwad changed the title Arm64: [PAC-RET] Add Pointer Authentication support for Arm64 (Part 1/3): JIT changesArm64: [PAC-RET] Add Pointer Authentication support for Arm64 (Part 1/3): JITMay 8, 2026
@SwapnilGaikwadSwapnilGaikwad changed the title Arm64: [PAC-RET] Add Pointer Authentication support for Arm64 (Part 1/3): JITArm64: [PAC-RET] Add Pointer Authentication support for Arm64 (Part 1/3: JIT)May 8, 2026
@SwapnilGaikwadSwapnilGaikwad changed the title Arm64: [PAC-RET] Add Pointer Authentication support for Arm64 (Part 1/3: JIT)Arm64: [PAC-RET] Jit SupportMay 11, 2026
dhartglassMSFT pushed a commit that referenced this pull request May 13, 2026
This PR adds instruction encodings for Pointer Authentication
instructions, especially the B key variants.
Part of this is useful for #125436 and #127838.
Add encoding for:
1. AUTIB
2. AUTIB1716
3. AUTIBSP
4. AUTIBZ
5. AUTIZB
6. PACIB
7. PACIB1716
8. PACIBSP
9. PACIBZ
10. PACIZB
11. RETAA
12. RETAB
@jakobbotsch

Copy link
Copy Markdown
Member

Can you resolve the conflicts?

Comment threadsrc/coreclr/jit/jitconfigvalues.h Outdated
@dhartglassMSFT
dhartglassMSFT enabled auto-merge (squash) May 19, 2026 00:07
@dhartglassMSFT

Copy link
Copy Markdown
Contributor

/ba-g known infra issues

@dhartglassMSFT
dhartglassMSFT merged commit 286dc15 into dotnet:mainMay 19, 2026
132 of 140 checks passed
@SwapnilGaikwad
SwapnilGaikwad deleted the github-jit-pac branch May 19, 2026 09:09
@dotnet-milestone-botdotnet-milestone-botBot added this to the 11.0-preview6 milestone May 21, 2026
@a74nha74nh mentioned this pull request Jun 3, 2026
20 tasks
@github-actionsgithub-actionsBot locked and limited conversation to collaborators Jun 21, 2026
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-CodeGen-coreclrCLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMIcommunity-contributionIndicates that the PR has been added by a community member

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@SwapnilGaikwad@jakobbotsch@dhartglassMSFT@jkotas@AndyAyersMS
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Arm64: [PAC-RET] Jit Support by SwapnilGaikwad · Pull Request #127838 · dotnet/runtime · GitHub
Skip to content

Arm64: [PAC-RET] Jit Support - #127838

Merged
dhartglassMSFT merged 12 commits into
dotnet:mainfrom
SwapnilGaikwad:github-jit-pac
May 19, 2026
Merged

Arm64: [PAC-RET] Jit Support#127838
dhartglassMSFT merged 12 commits into
dotnet:mainfrom
SwapnilGaikwad:github-jit-pac

Conversation

@SwapnilGaikwad

@SwapnilGaikwadSwapnilGaikwad commented May 5, 2026

Copy link
Copy Markdown
Contributor

As suggested in comment, this PR covers subset of changes from #125436 related to the JIT.

This PR adds support for Pointer Authentication (PAC) on Arm64. Pointer Authentication (PAC) is an Armv8.3+ security feature designed to mitigate Return-Oriented Programming (ROP) attacks by cryptographically signing return addresses. While using PAC, we store a signed return address, instead of the plain address, on the stack and later authenticate it before returning from a function. It ensures control flow returns to the intended caller.

More details on PAC and its role in software security can be found (here).

  • The current implementation of PAC is turned off by default, but can be turned on by setting DOTNET_JitPacEnabled=1.
  • PAC protects link register (LR) by signing it in the prolog (using paciasp) before it is split, using the current SP as the modifier. It then authenticates the LR in the epilog (using autiasp) before the function returns. If the signature is invalid, the execution fails with SIGILL.
  • Changes are limited to JIT.

NOTE: This PR adds part of the changes for PAC support to simply review process as discussed here. However it cannot pass the tests without the remaining parts. Kindly take a look at the CI status of #125436 to ensure correctness.

…/3: JIT changes)
As suggested in [comment](dotnet#125436 (comment)), this PR covers subset of changes from dotnet#125436 related to the JIT.
This PR adds support for Pointer Authentication (PAC) on Arm64. Pointer Authentication (PAC) is an Armv8.3+ security feature designed to mitigate Return-Oriented Programming (ROP) attacks by cryptographically signing return addresses. While using PAC, we store a signed return address, instead of the plain address, on the stack and later authenticate it before returning from a function. It ensures control flow returns to the intended caller.
More details on PAC and its role in software security can be found ([here](https://llsoftsec.github.io/llsoftsecbook/#sec:pointer-authentication)).
- The current implementation of PAC is turned off by default, but can be turned on by setting DOTNET_JitPacEnabled=1.
- PAC protects link register (LR) by signing it in the prolog (using `paciasp`) before it is split, using the current SP as the modifier. It then authenticates the LR in the epilog (using `autiasp`) before the function returns. If the signature is invalid, the execution fails with `SIGILL`.
- Changes are limited to JIT.
@github-actionsgithub-actionsBot added the area-CodeGen-coreclr CLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI label May 5, 2026
@dotnet-policy-servicedotnet-policy-serviceBot added the community-contribution Indicates that the PR has been added by a community member label May 5, 2026
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @JulieLeeMSFT, @jakobbotsch
See info in area-owners.md if you want to be subscribed.

Comment threadsrc/coreclr/jit/unwindarm64.cpp Outdated
Comment threadsrc/coreclr/jit/codegenarm64.cpp
@SwapnilGaikwadSwapnilGaikwad changed the title Arm64: [PAC-RET] Add Pointer Authentication support for Arm64 (Part 1…Arm64: [PAC-RET] Add Pointer Authentication support for Arm64 (Part 1/3): JIT changesMay 8, 2026
@SwapnilGaikwad

Copy link
Copy Markdown
ContributorAuthor

This PR uses parts of #127949. It would be great if we could get PAC encoding PR earlier.

@SwapnilGaikwadSwapnilGaikwad changed the title Arm64: [PAC-RET] Add Pointer Authentication support for Arm64 (Part 1/3): JIT changesArm64: [PAC-RET] Add Pointer Authentication support for Arm64 (Part 1/3): JITMay 8, 2026
@SwapnilGaikwadSwapnilGaikwad changed the title Arm64: [PAC-RET] Add Pointer Authentication support for Arm64 (Part 1/3): JITArm64: [PAC-RET] Add Pointer Authentication support for Arm64 (Part 1/3: JIT)May 8, 2026
@SwapnilGaikwadSwapnilGaikwad changed the title Arm64: [PAC-RET] Add Pointer Authentication support for Arm64 (Part 1/3: JIT)Arm64: [PAC-RET] Jit SupportMay 11, 2026
dhartglassMSFT pushed a commit that referenced this pull request May 13, 2026
This PR adds instruction encodings for Pointer Authentication
instructions, especially the B key variants.
Part of this is useful for #125436 and #127838.
Add encoding for:
1. AUTIB
2. AUTIB1716
3. AUTIBSP
4. AUTIBZ
5. AUTIZB
6. PACIB
7. PACIB1716
8. PACIBSP
9. PACIBZ
10. PACIZB
11. RETAA
12. RETAB
@jakobbotsch

Copy link
Copy Markdown
Member

Can you resolve the conflicts?

Comment threadsrc/coreclr/jit/jitconfigvalues.h Outdated
@dhartglassMSFT
dhartglassMSFT enabled auto-merge (squash) May 19, 2026 00:07
@dhartglassMSFT

Copy link
Copy Markdown
Contributor

/ba-g known infra issues

@dhartglassMSFT
dhartglassMSFT merged commit 286dc15 into dotnet:mainMay 19, 2026
132 of 140 checks passed
@SwapnilGaikwad
SwapnilGaikwad deleted the github-jit-pac branch May 19, 2026 09:09
@dotnet-milestone-botdotnet-milestone-botBot added this to the 11.0-preview6 milestone May 21, 2026
@a74nha74nh mentioned this pull request Jun 3, 2026
20 tasks
@github-actionsgithub-actionsBot locked and limited conversation to collaborators Jun 21, 2026
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-CodeGen-coreclrCLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMIcommunity-contributionIndicates that the PR has been added by a community member

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@SwapnilGaikwad@jakobbotsch@dhartglassMSFT@jkotas@AndyAyersMS
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' Arm64: [PAC-RET] Jit Support by SwapnilGaikwad · Pull Request #127838 · dotnet/runtime · GitHub
Skip to content

Arm64: [PAC-RET] Jit Support - #127838

Merged
dhartglassMSFT merged 12 commits into
dotnet:mainfrom
SwapnilGaikwad:github-jit-pac
May 19, 2026
Merged

Arm64: [PAC-RET] Jit Support#127838
dhartglassMSFT merged 12 commits into
dotnet:mainfrom
SwapnilGaikwad:github-jit-pac

Conversation

@SwapnilGaikwad

@SwapnilGaikwadSwapnilGaikwad commented May 5, 2026

Copy link
Copy Markdown
Contributor

As suggested in comment, this PR covers subset of changes from #125436 related to the JIT.

This PR adds support for Pointer Authentication (PAC) on Arm64. Pointer Authentication (PAC) is an Armv8.3+ security feature designed to mitigate Return-Oriented Programming (ROP) attacks by cryptographically signing return addresses. While using PAC, we store a signed return address, instead of the plain address, on the stack and later authenticate it before returning from a function. It ensures control flow returns to the intended caller.

More details on PAC and its role in software security can be found (here).

  • The current implementation of PAC is turned off by default, but can be turned on by setting DOTNET_JitPacEnabled=1.
  • PAC protects link register (LR) by signing it in the prolog (using paciasp) before it is split, using the current SP as the modifier. It then authenticates the LR in the epilog (using autiasp) before the function returns. If the signature is invalid, the execution fails with SIGILL.
  • Changes are limited to JIT.

NOTE: This PR adds part of the changes for PAC support to simply review process as discussed here. However it cannot pass the tests without the remaining parts. Kindly take a look at the CI status of #125436 to ensure correctness.

…/3: JIT changes)
As suggested in [comment](dotnet#125436 (comment)), this PR covers subset of changes from dotnet#125436 related to the JIT.
This PR adds support for Pointer Authentication (PAC) on Arm64. Pointer Authentication (PAC) is an Armv8.3+ security feature designed to mitigate Return-Oriented Programming (ROP) attacks by cryptographically signing return addresses. While using PAC, we store a signed return address, instead of the plain address, on the stack and later authenticate it before returning from a function. It ensures control flow returns to the intended caller.
More details on PAC and its role in software security can be found ([here](https://llsoftsec.github.io/llsoftsecbook/#sec:pointer-authentication)).
- The current implementation of PAC is turned off by default, but can be turned on by setting DOTNET_JitPacEnabled=1.
- PAC protects link register (LR) by signing it in the prolog (using `paciasp`) before it is split, using the current SP as the modifier. It then authenticates the LR in the epilog (using `autiasp`) before the function returns. If the signature is invalid, the execution fails with `SIGILL`.
- Changes are limited to JIT.
@github-actionsgithub-actionsBot added the area-CodeGen-coreclr CLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI label May 5, 2026
@dotnet-policy-servicedotnet-policy-serviceBot added the community-contribution Indicates that the PR has been added by a community member label May 5, 2026
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @JulieLeeMSFT, @jakobbotsch
See info in area-owners.md if you want to be subscribed.

Comment threadsrc/coreclr/jit/unwindarm64.cpp Outdated
Comment threadsrc/coreclr/jit/codegenarm64.cpp
@SwapnilGaikwadSwapnilGaikwad changed the title Arm64: [PAC-RET] Add Pointer Authentication support for Arm64 (Part 1…Arm64: [PAC-RET] Add Pointer Authentication support for Arm64 (Part 1/3): JIT changesMay 8, 2026
@SwapnilGaikwad

Copy link
Copy Markdown
ContributorAuthor

This PR uses parts of #127949. It would be great if we could get PAC encoding PR earlier.

@SwapnilGaikwadSwapnilGaikwad changed the title Arm64: [PAC-RET] Add Pointer Authentication support for Arm64 (Part 1/3): JIT changesArm64: [PAC-RET] Add Pointer Authentication support for Arm64 (Part 1/3): JITMay 8, 2026
@SwapnilGaikwadSwapnilGaikwad changed the title Arm64: [PAC-RET] Add Pointer Authentication support for Arm64 (Part 1/3): JITArm64: [PAC-RET] Add Pointer Authentication support for Arm64 (Part 1/3: JIT)May 8, 2026
@SwapnilGaikwadSwapnilGaikwad changed the title Arm64: [PAC-RET] Add Pointer Authentication support for Arm64 (Part 1/3: JIT)Arm64: [PAC-RET] Jit SupportMay 11, 2026
dhartglassMSFT pushed a commit that referenced this pull request May 13, 2026
This PR adds instruction encodings for Pointer Authentication
instructions, especially the B key variants.
Part of this is useful for #125436 and #127838.
Add encoding for:
1. AUTIB
2. AUTIB1716
3. AUTIBSP
4. AUTIBZ
5. AUTIZB
6. PACIB
7. PACIB1716
8. PACIBSP
9. PACIBZ
10. PACIZB
11. RETAA
12. RETAB
@jakobbotsch

Copy link
Copy Markdown
Member

Can you resolve the conflicts?

Comment threadsrc/coreclr/jit/jitconfigvalues.h Outdated
@dhartglassMSFT
dhartglassMSFT enabled auto-merge (squash) May 19, 2026 00:07
@dhartglassMSFT

Copy link
Copy Markdown
Contributor

/ba-g known infra issues

@dhartglassMSFT
dhartglassMSFT merged commit 286dc15 into dotnet:mainMay 19, 2026
132 of 140 checks passed
@SwapnilGaikwad
SwapnilGaikwad deleted the github-jit-pac branch May 19, 2026 09:09
@dotnet-milestone-botdotnet-milestone-botBot added this to the 11.0-preview6 milestone May 21, 2026
@a74nha74nh mentioned this pull request Jun 3, 2026
20 tasks
@github-actionsgithub-actionsBot locked and limited conversation to collaborators Jun 21, 2026
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-CodeGen-coreclrCLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMIcommunity-contributionIndicates that the PR has been added by a community member

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@SwapnilGaikwad@jakobbotsch@dhartglassMSFT@jkotas@AndyAyersMS
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Arm64: [PAC-RET] Jit Support by SwapnilGaikwad · Pull Request #127838 · dotnet/runtime · GitHub
Skip to content

Arm64: [PAC-RET] Jit Support - #127838

Merged
dhartglassMSFT merged 12 commits into
dotnet:mainfrom
SwapnilGaikwad:github-jit-pac
May 19, 2026
Merged

Arm64: [PAC-RET] Jit Support#127838
dhartglassMSFT merged 12 commits into
dotnet:mainfrom
SwapnilGaikwad:github-jit-pac

Conversation

@SwapnilGaikwad

@SwapnilGaikwadSwapnilGaikwad commented May 5, 2026

Copy link
Copy Markdown
Contributor

As suggested in comment, this PR covers subset of changes from #125436 related to the JIT.

This PR adds support for Pointer Authentication (PAC) on Arm64. Pointer Authentication (PAC) is an Armv8.3+ security feature designed to mitigate Return-Oriented Programming (ROP) attacks by cryptographically signing return addresses. While using PAC, we store a signed return address, instead of the plain address, on the stack and later authenticate it before returning from a function. It ensures control flow returns to the intended caller.

More details on PAC and its role in software security can be found (here).

  • The current implementation of PAC is turned off by default, but can be turned on by setting DOTNET_JitPacEnabled=1.
  • PAC protects link register (LR) by signing it in the prolog (using paciasp) before it is split, using the current SP as the modifier. It then authenticates the LR in the epilog (using autiasp) before the function returns. If the signature is invalid, the execution fails with SIGILL.
  • Changes are limited to JIT.

NOTE: This PR adds part of the changes for PAC support to simply review process as discussed here. However it cannot pass the tests without the remaining parts. Kindly take a look at the CI status of #125436 to ensure correctness.

…/3: JIT changes)
As suggested in [comment](dotnet#125436 (comment)), this PR covers subset of changes from dotnet#125436 related to the JIT.
This PR adds support for Pointer Authentication (PAC) on Arm64. Pointer Authentication (PAC) is an Armv8.3+ security feature designed to mitigate Return-Oriented Programming (ROP) attacks by cryptographically signing return addresses. While using PAC, we store a signed return address, instead of the plain address, on the stack and later authenticate it before returning from a function. It ensures control flow returns to the intended caller.
More details on PAC and its role in software security can be found ([here](https://llsoftsec.github.io/llsoftsecbook/#sec:pointer-authentication)).
- The current implementation of PAC is turned off by default, but can be turned on by setting DOTNET_JitPacEnabled=1.
- PAC protects link register (LR) by signing it in the prolog (using `paciasp`) before it is split, using the current SP as the modifier. It then authenticates the LR in the epilog (using `autiasp`) before the function returns. If the signature is invalid, the execution fails with `SIGILL`.
- Changes are limited to JIT.
@github-actionsgithub-actionsBot added the area-CodeGen-coreclr CLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI label May 5, 2026
@dotnet-policy-servicedotnet-policy-serviceBot added the community-contribution Indicates that the PR has been added by a community member label May 5, 2026
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @JulieLeeMSFT, @jakobbotsch
See info in area-owners.md if you want to be subscribed.

Comment threadsrc/coreclr/jit/unwindarm64.cpp Outdated
Comment threadsrc/coreclr/jit/codegenarm64.cpp
@SwapnilGaikwadSwapnilGaikwad changed the title Arm64: [PAC-RET] Add Pointer Authentication support for Arm64 (Part 1…Arm64: [PAC-RET] Add Pointer Authentication support for Arm64 (Part 1/3): JIT changesMay 8, 2026
@SwapnilGaikwad

Copy link
Copy Markdown
ContributorAuthor

This PR uses parts of #127949. It would be great if we could get PAC encoding PR earlier.

@SwapnilGaikwadSwapnilGaikwad changed the title Arm64: [PAC-RET] Add Pointer Authentication support for Arm64 (Part 1/3): JIT changesArm64: [PAC-RET] Add Pointer Authentication support for Arm64 (Part 1/3): JITMay 8, 2026
@SwapnilGaikwadSwapnilGaikwad changed the title Arm64: [PAC-RET] Add Pointer Authentication support for Arm64 (Part 1/3): JITArm64: [PAC-RET] Add Pointer Authentication support for Arm64 (Part 1/3: JIT)May 8, 2026
@SwapnilGaikwadSwapnilGaikwad changed the title Arm64: [PAC-RET] Add Pointer Authentication support for Arm64 (Part 1/3: JIT)Arm64: [PAC-RET] Jit SupportMay 11, 2026
dhartglassMSFT pushed a commit that referenced this pull request May 13, 2026
This PR adds instruction encodings for Pointer Authentication
instructions, especially the B key variants.
Part of this is useful for #125436 and #127838.
Add encoding for:
1. AUTIB
2. AUTIB1716
3. AUTIBSP
4. AUTIBZ
5. AUTIZB
6. PACIB
7. PACIB1716
8. PACIBSP
9. PACIBZ
10. PACIZB
11. RETAA
12. RETAB
@jakobbotsch

Copy link
Copy Markdown
Member

Can you resolve the conflicts?

Comment threadsrc/coreclr/jit/jitconfigvalues.h Outdated
@dhartglassMSFT
dhartglassMSFT enabled auto-merge (squash) May 19, 2026 00:07
@dhartglassMSFT

Copy link
Copy Markdown
Contributor

/ba-g known infra issues

@dhartglassMSFT
dhartglassMSFT merged commit 286dc15 into dotnet:mainMay 19, 2026
132 of 140 checks passed
@SwapnilGaikwad
SwapnilGaikwad deleted the github-jit-pac branch May 19, 2026 09:09
@dotnet-milestone-botdotnet-milestone-botBot added this to the 11.0-preview6 milestone May 21, 2026
@a74nha74nh mentioned this pull request Jun 3, 2026
20 tasks
@github-actionsgithub-actionsBot locked and limited conversation to collaborators Jun 21, 2026
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-CodeGen-coreclrCLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMIcommunity-contributionIndicates that the PR has been added by a community member

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@SwapnilGaikwad@jakobbotsch@dhartglassMSFT@jkotas@AndyAyersMS
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); })(); Arm64: [PAC-RET] Jit Support by SwapnilGaikwad · Pull Request #127838 · dotnet/runtime · GitHub
Skip to content

Arm64: [PAC-RET] Jit Support - #127838

Merged
dhartglassMSFT merged 12 commits into
dotnet:mainfrom
SwapnilGaikwad:github-jit-pac
May 19, 2026
Merged

Arm64: [PAC-RET] Jit Support#127838
dhartglassMSFT merged 12 commits into
dotnet:mainfrom
SwapnilGaikwad:github-jit-pac

Conversation

@SwapnilGaikwad

@SwapnilGaikwadSwapnilGaikwad commented May 5, 2026

Copy link
Copy Markdown
Contributor

As suggested in comment, this PR covers subset of changes from #125436 related to the JIT.

This PR adds support for Pointer Authentication (PAC) on Arm64. Pointer Authentication (PAC) is an Armv8.3+ security feature designed to mitigate Return-Oriented Programming (ROP) attacks by cryptographically signing return addresses. While using PAC, we store a signed return address, instead of the plain address, on the stack and later authenticate it before returning from a function. It ensures control flow returns to the intended caller.

More details on PAC and its role in software security can be found (here).

  • The current implementation of PAC is turned off by default, but can be turned on by setting DOTNET_JitPacEnabled=1.
  • PAC protects link register (LR) by signing it in the prolog (using paciasp) before it is split, using the current SP as the modifier. It then authenticates the LR in the epilog (using autiasp) before the function returns. If the signature is invalid, the execution fails with SIGILL.
  • Changes are limited to JIT.

NOTE: This PR adds part of the changes for PAC support to simply review process as discussed here. However it cannot pass the tests without the remaining parts. Kindly take a look at the CI status of #125436 to ensure correctness.

…/3: JIT changes)
As suggested in [comment](dotnet#125436 (comment)), this PR covers subset of changes from dotnet#125436 related to the JIT.
This PR adds support for Pointer Authentication (PAC) on Arm64. Pointer Authentication (PAC) is an Armv8.3+ security feature designed to mitigate Return-Oriented Programming (ROP) attacks by cryptographically signing return addresses. While using PAC, we store a signed return address, instead of the plain address, on the stack and later authenticate it before returning from a function. It ensures control flow returns to the intended caller.
More details on PAC and its role in software security can be found ([here](https://llsoftsec.github.io/llsoftsecbook/#sec:pointer-authentication)).
- The current implementation of PAC is turned off by default, but can be turned on by setting DOTNET_JitPacEnabled=1.
- PAC protects link register (LR) by signing it in the prolog (using `paciasp`) before it is split, using the current SP as the modifier. It then authenticates the LR in the epilog (using `autiasp`) before the function returns. If the signature is invalid, the execution fails with `SIGILL`.
- Changes are limited to JIT.
@github-actionsgithub-actionsBot added the area-CodeGen-coreclr CLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI label May 5, 2026
@dotnet-policy-servicedotnet-policy-serviceBot added the community-contribution Indicates that the PR has been added by a community member label May 5, 2026
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @JulieLeeMSFT, @jakobbotsch
See info in area-owners.md if you want to be subscribed.

Comment threadsrc/coreclr/jit/unwindarm64.cpp Outdated
Comment threadsrc/coreclr/jit/codegenarm64.cpp
@SwapnilGaikwadSwapnilGaikwad changed the title Arm64: [PAC-RET] Add Pointer Authentication support for Arm64 (Part 1…Arm64: [PAC-RET] Add Pointer Authentication support for Arm64 (Part 1/3): JIT changesMay 8, 2026
@SwapnilGaikwad

Copy link
Copy Markdown
ContributorAuthor

This PR uses parts of #127949. It would be great if we could get PAC encoding PR earlier.

@SwapnilGaikwadSwapnilGaikwad changed the title Arm64: [PAC-RET] Add Pointer Authentication support for Arm64 (Part 1/3): JIT changesArm64: [PAC-RET] Add Pointer Authentication support for Arm64 (Part 1/3): JITMay 8, 2026
@SwapnilGaikwadSwapnilGaikwad changed the title Arm64: [PAC-RET] Add Pointer Authentication support for Arm64 (Part 1/3): JITArm64: [PAC-RET] Add Pointer Authentication support for Arm64 (Part 1/3: JIT)May 8, 2026
@SwapnilGaikwadSwapnilGaikwad changed the title Arm64: [PAC-RET] Add Pointer Authentication support for Arm64 (Part 1/3: JIT)Arm64: [PAC-RET] Jit SupportMay 11, 2026
dhartglassMSFT pushed a commit that referenced this pull request May 13, 2026
This PR adds instruction encodings for Pointer Authentication
instructions, especially the B key variants.
Part of this is useful for #125436 and #127838.
Add encoding for:
1. AUTIB
2. AUTIB1716
3. AUTIBSP
4. AUTIBZ
5. AUTIZB
6. PACIB
7. PACIB1716
8. PACIBSP
9. PACIBZ
10. PACIZB
11. RETAA
12. RETAB
@jakobbotsch

Copy link
Copy Markdown
Member

Can you resolve the conflicts?

Comment threadsrc/coreclr/jit/jitconfigvalues.h Outdated
@dhartglassMSFT
dhartglassMSFT enabled auto-merge (squash) May 19, 2026 00:07
@dhartglassMSFT

Copy link
Copy Markdown
Contributor

/ba-g known infra issues

@dhartglassMSFT
dhartglassMSFT merged commit 286dc15 into dotnet:mainMay 19, 2026
132 of 140 checks passed
@SwapnilGaikwad
SwapnilGaikwad deleted the github-jit-pac branch May 19, 2026 09:09
@dotnet-milestone-botdotnet-milestone-botBot added this to the 11.0-preview6 milestone May 21, 2026
@a74nha74nh mentioned this pull request Jun 3, 2026
20 tasks
@github-actionsgithub-actionsBot locked and limited conversation to collaborators Jun 21, 2026
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-CodeGen-coreclrCLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMIcommunity-contributionIndicates that the PR has been added by a community member

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@SwapnilGaikwad@jakobbotsch@dhartglassMSFT@jkotas@AndyAyersMS