Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Windows on AArch64 also provides for hot-patching, but it’s much simpler than on x86

Дата публикации: 30-09-2026 14:00:00

Fixed-length instructions makes it a much easier task.
The post Windows on AArch64 also provides for hot-patching, but it’s much simpler than on x86 appeared first on The Old New Thing.


Основное содержимое страницы с новостью.

I have noted in the past that x86-32 and x86-64 versions of Windows are careful to start each function with a patch point. But what about AArch64 (known in Windows as arm64)?

Windows also inserts patch points for functions on AArch64, but they are much simpler due to the fixed-length instruction set. You don’t have to worry about patching an instruction when the instruction pointer happens to be in the middle of the byte sequence, because the instruction pointer is never in the middle of the byte sequence. The instruction pointer is always on a multiple of 4.

Therefore, there is no special restriction on the first instruction of a function. All instructions meet the requirements of being atomically updatable without risk of the instruction pointer being in the middle of the instruction.

Before each function is a patch space of 12 bytes, which is exactly enough for a three-instruction trampoline:

; overwrite the patch space with these three instructions
    adrp    xip0, PageStart(replacement)
    add     xip0, xip0, PageOffset(replacement)
    br      xip0

function_entry_point:
; overwrite the function entry point with one instruction
    br      $-12 ; jump to the patch space

The xip0 register is one of the two intra-procedure call scratch registers, and the convention is that this register can be clobbered by any branch instruction. Since the caller had to use a branch instruction to reach function_entry_point in the first place, it cannot be using xip0 for anything, so we are free to clobber xip0 as part of our trampoline.

Bonus chatter: The first instruction at the function entry point is almost certainly pacibsp, the pointer authentication instruction for signing the return address to make code more resistant to ROP attacks and attacks that overwrite the return address.

Author

Raymond Chen

Raymond has been involved in the evolution of Windows for more than 30 years. In 2003, he began a Web site known as The Old New Thing which has grown in popularity far beyond his wildest imagination, a development which still gives him the heebie-jeebies. The Web site spawned a book, coincidentally also titled The Old New Thing (Addison Wesley 2007). He occasionally appears on the Windows Dev Docs Twitter account to tell stories which convey no useful information.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1Windows on Itanium also provided for hot-patching, in an even simpler way010.201-10-2026
2Why is there no Windows hot-patching support for other architectures like 32-bit ARM and MIPS?09.0602-10-2026
3If somebody tries to hot-patch an already-hot-patched function, how do they avoid conflicts?012.9705-10-2026
4No, really, you need to pass all unhandled messages to DefWindowProc, part 205.8424-09-2026
5Debugging walkthrough: Access violation on nonsense instruction, episode 307.8925-09-2026
6As a general rule, calling product support while drunk is not recommended04.5629-09-2026
7AMD Posts GCC Compiler Patches For AVX10V1AUX ISA Support011.8524-09-2026
8Why does the compiler sometimes use ud2 and sometimes int 3 for code that shouldn’t execute?07.706-10-2026
9Windows-Update 26H2 ist da – und mit ihm drei fiese Bugs014.9901-10-2026
10Microsoft Fixes File History Backup Failures Caused by September Windows Updates05.5625-09-2026

Классификация: . Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 12.77. Источник: blogs.msdn.microsoft.com.