Skip to content

Enable pointer authentication on ARM64 #42888

Description

@jgowdy

What is the problem this feature will solve?

ARM64v8.3 supports Pointer Authentication with the PACIASP and AUTIASP instructions which are interpreted as NOP instructions on pre 8.3 architectures. These instructions sign the stack pointer and validate the stack pointer prior to return to mitigate return oriented programming.

GCC supports these options on arm64 / aarch64. The legacy option was -msign-return-address=[all | non-leaf | none] and the modern option is -mbranch-protection=none|standard|pac-ret[+leaf+b-key]|bti

I would like to suggest that the arm64 build be modified to include -mbranch-protection=pac-ret with the -march being set to ARMv8.2 or earlier or not configured, so that GCC will generate PACIASP and AUTIASP instructions. It is critical that -march=armv8.3 or higher not be passed or the non-backwards compatible RETAA instruction will be generated.

What is the feature you are proposing to solve the problem?

The benefit of enabling pointer authentication for the stack pointer on ARM64 would be to mitigate return oriented programming attacks against the Node.js runtime.

What alternatives have you considered?

Presently we are pursuing custom compiles of the Node.js runtime for the new Graviton3 CPUs that support pointer authentication in AWS.

Activity

  1. RaisinTen commented on May 1, 2022

    @RaisinTen
    Member

    Will this affect performance?
    What will happen if this setting is enabled and someone still attempts to take advantage of an already present buffer overflow?

  2. moved this to Pending Triage in Node.js feature requestson May 4, 2022
  3. jgowdy commented on May 5, 2022

    @jgowdy
    Author

    The performance impact is very small, we've had difficulty measuring it versus variance in runs of our benchmark suite. It's an additional assembly language instruction at the beginning and end of each method that does a small amount of math in hardware. If the CPU doesn't support PAC, the instructions are treated as NOPs.

    If the stack pointer is modified by an attacker, when the function is about to return it executes the AUTIASP instruction which will detect the modified stack pointer and the process will signal and abort.

  4. RaisinTen commented on May 6, 2022

    @RaisinTen
    Member

    Hmm, I don't immediately see any problem with enabling this. Would you like to send a PR? We could have more reviews there.

  5. nxhack commented on Aug 26, 2022

    @nxhack

    This modification results in an error in the case of cross-compilation. (#43200)

    'host_arch': 'x64'
    'target_arch': 'arm64',

    g++: error: unrecognized command line option '-msign-return-address=all'
    
  6. josh-hemphill commented on Dec 6, 2022

    @josh-hemphill

    Is there a workaround for this unrecognized command line option '-msign-return-address=all' error?

  7. added a commit that references this issue on Dec 6, 2022
  8. bnoordhuis commented on Dec 6, 2022

    @bnoordhuis
    Member

    Untested, but #45756 hopefully fixes it. Please test.

  9. github-actions commented on Jun 5, 2023

    @github-actions
    Contributor

    There has been no activity on this feature request for 5 months and it is unlikely to be implemented. It will be closed 6 months after the last non-automated comment.

    For more information on how the project manages feature requests, please consult the feature request management document.

  10. added
    staleIssues and PRs marked stale due to inactivity and scheduled for automatic closure.
    on Jun 5, 2023
  11. github-actions commented on Jul 5, 2023

    @github-actions
    Contributor

    There has been no activity on this feature request and it is being closed. If you feel closing this issue is not the right thing to do, please leave a comment.

    For more information on how the project manages feature requests, please consult the feature request management document.

  12. added a commit that references this issue on Dec 22, 2023
  13. added a commit that references this issue on Jan 2, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    feature requestIssues requesting new Node.js features.staleIssues and PRs marked stale due to inactivity and scheduled for automatic closure.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions