[PATCH v2 0/2] arm64: Implement support for BTI veneers
From: Ard Biesheuvel
Date: Mon Oct 05 2026 - 07:08:22 EST
From: Ard Biesheuvel <ardb@xxxxxxxxxx>
[ Resending this with minimal changes even though some other approaches
were proposed as well. [1][2] Neither of those are appropriate for
backporting, while this series can reasonably be applied to older
kernels. ]
Recent toolchains will omit BTI landing pads from functions with static
linkage that never have their address taken. If a landing pad is needed
nonetheless, it is up to the static linker to emit a BTI veneer withing
direct branching range of the target, and direct the call to the veneer
instead.
Modules are partially linked objects, and so there is no static linker
that can do this for us. Instead, the module loader must see to this.
So implement this for the arm64 module loader. Patch #2 contains a test
module that was used to validate the approach.
Changes since v1:
- make HAVE_LIVE_PATCH depend on !ARM64_BTI_KERNEL, as live patch has
other cases where landing pads may go missing
[1] https://lore.kernel.org/all/cover.1786768375.git.jpoimboe@xxxxxxxxxx/
[2] https://lore.kernel.org/all/20260822135323.795946-11-ardb+git@xxxxxxxxxx/
Cc: Mark Brown <broonie@xxxxxxxxxx>
Cc: Josh Poimboeuf <jpoimboe@xxxxxxxxxx>
Cc: Nick Desaulniers <ndesaulniers@xxxxxxxxxx>
Ard Biesheuvel (2):
arm64: module: Emit BTI veneers for cross-section calls
DONOTMERGE: arm64: module: Test module for BTI veneers
arch/arm64/Kconfig | 7 +-
arch/arm64/include/asm/module.h | 12 ++
arch/arm64/include/asm/module.lds.h | 3 +
arch/arm64/kernel/Makefile | 1 +
arch/arm64/kernel/bti_veneer_test.c | 26 ++++
arch/arm64/kernel/module-plts.c | 128 +++++++++++++++++++-
6 files changed, 167 insertions(+), 10 deletions(-)
create mode 100644 arch/arm64/kernel/bti_veneer_test.c
--
2.56.0.rc1.315.gc6ed9934b7-goog