€•o›Œsphinx.addnodes”Œdocument”“”)�”}”(Œ rawsource”Œ”Œchildren”]”(Œ translations”Œ LanguagesNode”“”)�”}”(hhh]”(hŒ pending_xref”“”)�”}”(hhh]”Œdocutils.nodes”ŒText”“”ŒChinese (Simplified)”…”�”}”Œparent”hsbaŒ attributes”}”(Œids”]”Œclasses”]”Œnames”]”Œdupnames”]”Œbackrefs”]”Œ refdomain”Œstd”Œreftype”Œdoc”Œ reftarget”Œ"/translations/zh_CN/arch/arm64/gcs”Œmodname”NŒ classname”NŒ refexplicit”ˆuŒtagname”hhh ubh)�”}”(hhh]”hŒChinese (Traditional)”…”�”}”hh2sbah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”h)Œreftype”h+Œ reftarget”Œ"/translations/zh_TW/arch/arm64/gcs”Œmodname”NŒ classname”NŒ refexplicit”ˆuh1hhh ubh)�”}”(hhh]”hŒItalian”…”�”}”hhFsbah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”h)Œreftype”h+Œ reftarget”Œ"/translations/it_IT/arch/arm64/gcs”Œmodname”NŒ classname”NŒ refexplicit”ˆuh1hhh ubh)�”}”(hhh]”hŒJapanese”…”�”}”hhZsbah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”h)Œreftype”h+Œ reftarget”Œ"/translations/ja_JP/arch/arm64/gcs”Œmodname”NŒ classname”NŒ refexplicit”ˆuh1hhh ubh)�”}”(hhh]”hŒKorean”…”�”}”hhnsbah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”h)Œreftype”h+Œ reftarget”Œ"/translations/ko_KR/arch/arm64/gcs”Œmodname”NŒ classname”NŒ refexplicit”ˆuh1hhh ubh)�”}”(hhh]”hŒPortuguese (Brazilian)”…”�”}”hh‚sbah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”h)Œreftype”h+Œ reftarget”Œ"/translations/pt_BR/arch/arm64/gcs”Œmodname”NŒ classname”NŒ refexplicit”ˆuh1hhh ubh)�”}”(hhh]”hŒSpanish”…”�”}”hh–sbah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”h)Œreftype”h+Œ reftarget”Œ"/translations/sp_SP/arch/arm64/gcs”Œmodname”NŒ classname”NŒ refexplicit”ˆuh1hhh ubeh}”(h]”h ]”h"]”h$]”h&]”Œcurrent_language”ŒEnglish”uh1h hhŒ _document”hŒsource”NŒline”NubhŒsection”“”)�”}”(hhh]”(hŒtitle”“”)�”}”(hŒ/Guarded Control Stack support for AArch64 Linux”h]”hŒ/Guarded Control Stack support for AArch64 Linux”…”�”}”(hh¼h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hºhh·h²hh³Œubhû)�”}”(hhh]”(j)�”}”(hŒ¦GCS is enabled and disabled for a thread via the PR_SET_SHADOW_STACK_STATUS prctl(), this takes a single flags argument specifying which GCS features should be used. ”h]”hÌ)�”}”(hŒ¥GCS is enabled and disabled for a thread via the PR_SET_SHADOW_STACK_STATUS prctl(), this takes a single flags argument specifying which GCS features should be used.”h]”hŒ¥GCS is enabled and disabled for a thread via the PR_SET_SHADOW_STACK_STATUS prctl(), this takes a single flags argument specifying which GCS features should be used.”…”�”}”(hjIh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K@hjEubah}”(h]”h ]”h"]”h$]”h&]”uh1hÿhjBh²hh³hÊh´Nubj)�”}”(hŒ´When set PR_SHADOW_STACK_ENABLE flag allocates a Guarded Control Stack and enables GCS for the thread, enabling the functionality controlled by GCSCRE0_EL1.{nTR, RVCHKEN, PCRSEL}. ”h]”hÌ)�”}”(hŒ³When set PR_SHADOW_STACK_ENABLE flag allocates a Guarded Control Stack and enables GCS for the thread, enabling the functionality controlled by GCSCRE0_EL1.{nTR, RVCHKEN, PCRSEL}.”h]”hŒ³When set PR_SHADOW_STACK_ENABLE flag allocates a Guarded Control Stack and enables GCS for the thread, enabling the functionality controlled by GCSCRE0_EL1.{nTR, RVCHKEN, PCRSEL}.”…”�”}”(hjah²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´KDhj]ubah}”(h]”h ]”h"]”h$]”h&]”uh1hÿhjBh²hh³hÊh´Nubj)�”}”(hŒ‚When set the PR_SHADOW_STACK_PUSH flag enables the functionality controlled by GCSCRE0_EL1.PUSHMEn, allowing explicit GCS pushes. ”h]”hÌ)�”}”(hŒ�When set the PR_SHADOW_STACK_PUSH flag enables the functionality controlled by GCSCRE0_EL1.PUSHMEn, allowing explicit GCS pushes.”h]”hŒ�When set the PR_SHADOW_STACK_PUSH flag enables the functionality controlled by GCSCRE0_EL1.PUSHMEn, allowing explicit GCS pushes.”…”�”}”(hjyh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´KHhjuubah}”(h]”h ]”h"]”h$]”h&]”uh1hÿhjBh²hh³hÊh´Nubj)�”}”(hŒšWhen set the PR_SHADOW_STACK_WRITE flag enables the functionality controlled by GCSCRE0_EL1.STREn, allowing explicit stores to the Guarded Control Stack. ”h]”hÌ)�”}”(hŒ™When set the PR_SHADOW_STACK_WRITE flag enables the functionality controlled by GCSCRE0_EL1.STREn, allowing explicit stores to the Guarded Control Stack.”h]”hŒ™When set the PR_SHADOW_STACK_WRITE flag enables the functionality controlled by GCSCRE0_EL1.STREn, allowing explicit stores to the Guarded Control Stack.”…”�”}”(hj‘h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´KKhj�ubah}”(h]”h ]”h"]”h$]”h&]”uh1hÿhjBh²hh³hÊh´Nubj)�”}”(hŒKAny unknown flags will cause PR_SET_SHADOW_STACK_STATUS to return -EINVAL. ”h]”hÌ)�”}”(hŒJAny unknown flags will cause PR_SET_SHADOW_STACK_STATUS to return -EINVAL.”h]”hŒJAny unknown flags will cause PR_SET_SHADOW_STACK_STATUS to return -EINVAL.”…”�”}”(hj©h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´KNhj¥ubah}”(h]”h ]”h"]”h$]”h&]”uh1hÿhjBh²hh³hÊh´Nubj)�”}”(hŒÌPR_LOCK_SHADOW_STACK_STATUS is passed a bitmask of features with the same values as used for PR_SET_SHADOW_STACK_STATUS. Any future changes to the status of the specified GCS mode bits will be rejected. ”h]”hÌ)�”}”(hŒËPR_LOCK_SHADOW_STACK_STATUS is passed a bitmask of features with the same values as used for PR_SET_SHADOW_STACK_STATUS. Any future changes to the status of the specified GCS mode bits will be rejected.”h]”hŒËPR_LOCK_SHADOW_STACK_STATUS is passed a bitmask of features with the same values as used for PR_SET_SHADOW_STACK_STATUS. Any future changes to the status of the specified GCS mode bits will be rejected.”…”�”}”(hjÁh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´KPhj½ubah}”(h]”h ]”h"]”h$]”h&]”uh1hÿhjBh²hh³hÊh´Nubj)�”}”(hŒzPR_LOCK_SHADOW_STACK_STATUS allows any bit to be locked, this allows userspace to prevent changes to any future features. ”h]”hÌ)�”}”(hŒyPR_LOCK_SHADOW_STACK_STATUS allows any bit to be locked, this allows userspace to prevent changes to any future features.”h]”hŒyPR_LOCK_SHADOW_STACK_STATUS allows any bit to be locked, this allows userspace to prevent changes to any future features.”…”�”}”(hjÙh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´KThjÕubah}”(h]”h ]”h"]”h$]”h&]”uh1hÿhjBh²hh³hÊh´Nubj)�”}”(hŒMThere is no support for a process to remove a lock that has been set for it. ”h]”hÌ)�”}”(hŒLThere is no support for a process to remove a lock that has been set for it.”h]”hŒLThere is no support for a process to remove a lock that has been set for it.”…”�”}”(hjñh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´KWhjíubah}”(h]”h ]”h"]”h$]”h&]”uh1hÿhjBh²hh³hÊh´Nubj)�”}”(hŒ’PR_SET_SHADOW_STACK_STATUS and PR_LOCK_SHADOW_STACK_STATUS affect only the thread that called them, any other running threads will be unaffected. ”h]”hÌ)�”}”(hŒ‘PR_SET_SHADOW_STACK_STATUS and PR_LOCK_SHADOW_STACK_STATUS affect only the thread that called them, any other running threads will be unaffected.”h]”hŒ‘PR_SET_SHADOW_STACK_STATUS and PR_LOCK_SHADOW_STACK_STATUS affect only the thread that called them, any other running threads will be unaffected.”…”�”}”(hj h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´KZhjubah}”(h]”h ]”h"]”h$]”h&]”uh1hÿhjBh²hh³hÊh´Nubj)�”}”(hŒKNew threads inherit the GCS configuration of the thread that created them. ”h]”hÌ)�”}”(hŒJNew threads inherit the GCS configuration of the thread that created them.”h]”hŒJNew threads inherit the GCS configuration of the thread that created them.”…”�”}”(hj!h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K]hjubah}”(h]”h ]”h"]”h$]”h&]”uh1hÿhjBh²hh³hÊh´Nubj)�”}”(hŒGCS is disabled on exec(). ”h]”hÌ)�”}”(hŒGCS is disabled on exec().”h]”hŒGCS is disabled on exec().”…”�”}”(hj9h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K_hj5ubah}”(h]”h ]”h"]”h$]”h&]”uh1hÿhjBh²hh³hÊh´Nubj)�”}”(hŒ¯The current GCS configuration for a thread may be read with the PR_GET_SHADOW_STACK_STATUS prctl(), this returns the same flags that are passed to PR_SET_SHADOW_STACK_STATUS. ”h]”hÌ)�”}”(hŒ®The current GCS configuration for a thread may be read with the PR_GET_SHADOW_STACK_STATUS prctl(), this returns the same flags that are passed to PR_SET_SHADOW_STACK_STATUS.”h]”hŒ®The current GCS configuration for a thread may be read with the PR_GET_SHADOW_STACK_STATUS prctl(), this returns the same flags that are passed to PR_SET_SHADOW_STACK_STATUS.”…”�”}”(hjQh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´KahjMubah}”(h]”h ]”h"]”h$]”h&]”uh1hÿhjBh²hh³hÊh´Nubj)�”}”(hŒôIf GCS is disabled for a thread after having previously been enabled then the stack will remain allocated for the lifetime of the thread. At present any attempt to reenable GCS for the thread will be rejected, this may be revisited in future. ”h]”hÌ)�”}”(hŒóIf GCS is disabled for a thread after having previously been enabled then the stack will remain allocated for the lifetime of the thread. At present any attempt to reenable GCS for the thread will be rejected, this may be revisited in future.”h]”hŒóIf GCS is disabled for a thread after having previously been enabled then the stack will remain allocated for the lifetime of the thread. At present any attempt to reenable GCS for the thread will be rejected, this may be revisited in future.”…”�”}”(hjih²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´Kehjeubah}”(h]”h ]”h"]”h$]”h&]”uh1hÿhjBh²hh³hÊh´Nubj)�”}”(hX'It should be noted that since enabling GCS will result in GCS becoming active immediately it is not normally possible to return from the function that invoked the prctl() that enabled GCS. It is expected that the normal usage will be that GCS is enabled very early in execution of a program. ”h]”hÌ)�”}”(hX$It should be noted that since enabling GCS will result in GCS becoming active immediately it is not normally possible to return from the function that invoked the prctl() that enabled GCS. It is expected that the normal usage will be that GCS is enabled very early in execution of a program.”h]”hX$It should be noted that since enabling GCS will result in GCS becoming active immediately it is not normally possible to return from the function that invoked the prctl() that enabled GCS. It is expected that the normal usage will be that GCS is enabled very early in execution of a program.”…”�”}”(hj�h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´Kjhj}ubah}”(h]”h ]”h"]”h$]”h&]”uh1hÿhjBh²hh³hÊh´Nubeh}”(h]”h ]”h"]”h$]”h&]”j'j(uh1húh³hÊh´K@hj1h²hubeh}”(h]”Œ-enabling-and-disabling-guarded-control-stacks”ah ]”h"]”Œ02. enabling and disabling guarded control stacks”ah$]”h&]”uh1hµhh·h²hh³hÊh´K>ubh¶)�”}”(hhh]”(h»)�”}”(hŒ(3. Allocation of Guarded Control Stacks”h]”hŒ(3. Allocation of Guarded Control Stacks”…”�”}”(hj¦h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hºhj£h²hh³hÊh´Krubhû)�”}”(hhh]”(j)�”}”(hŒœWhen GCS is enabled for a thread a new Guarded Control Stack will be allocated for it of half the standard stack size or 2 gigabytes, whichever is smaller. ”h]”hÌ)�”}”(hŒ›When GCS is enabled for a thread a new Guarded Control Stack will be allocated for it of half the standard stack size or 2 gigabytes, whichever is smaller.”h]”hŒ›When GCS is enabled for a thread a new Guarded Control Stack will be allocated for it of half the standard stack size or 2 gigabytes, whichever is smaller.”…”�”}”(hj»h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´Kthj·ubah}”(h]”h ]”h"]”h$]”h&]”uh1hÿhj´h²hh³hÊh´Nubj)�”}”(hŒ¯When a new thread is created by a thread which has GCS enabled then a new Guarded Control Stack will be allocated for the new thread with half the size of the standard stack. ”h]”hÌ)�”}”(hŒ®When a new thread is created by a thread which has GCS enabled then a new Guarded Control Stack will be allocated for the new thread with half the size of the standard stack.”h]”hŒ®When a new thread is created by a thread which has GCS enabled then a new Guarded Control Stack will be allocated for the new thread with half the size of the standard stack.”…”�”}”(hjÓh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´KxhjÏubah}”(h]”h ]”h"]”h$]”h&]”uh1hÿhj´h²hh³hÊh´Nubj)�”}”(hŒóWhen a stack is allocated by enabling GCS or during thread creation then the top 8 bytes of the stack will be initialised to 0 and GCSPR_EL0 will be set to point to the address of this 0 value, this can be used to detect the top of the stack. ”h]”hÌ)�”}”(hŒòWhen a stack is allocated by enabling GCS or during thread creation then the top 8 bytes of the stack will be initialised to 0 and GCSPR_EL0 will be set to point to the address of this 0 value, this can be used to detect the top of the stack.”h]”hŒòWhen a stack is allocated by enabling GCS or during thread creation then the top 8 bytes of the stack will be initialised to 0 and GCSPR_EL0 will be set to point to the address of this 0 value, this can be used to detect the top of the stack.”…”�”}”(hjëh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K|hjçubah}”(h]”h ]”h"]”h$]”h&]”uh1hÿhj´h²hh³hÊh´Nubj)�”}”(hŒ]Additional Guarded Control Stacks can be allocated using the map_shadow_stack() system call. ”h]”hÌ)�”}”(hŒ\Additional Guarded Control Stacks can be allocated using the map_shadow_stack() system call.”h]”hŒ\Additional Guarded Control Stacks can be allocated using the map_shadow_stack() system call.”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K�hjÿubah}”(h]”h ]”h"]”h$]”h&]”uh1hÿhj´h²hh³hÊh´Nubj)�”}”(hXæStacks allocated using map_shadow_stack() can optionally have an end of stack marker and cap placed at the top of the stack. If the flag SHADOW_STACK_SET_TOKEN is specified a cap will be placed on the stack, if SHADOW_STACK_SET_MARKER is not specified the cap will be the top 8 bytes of the stack and if it is specified then the cap will be the next 8 bytes. While specifying just SHADOW_STACK_SET_MARKER by itself is valid since the marker is all bits 0 it has no observable effect. ”h]”hÌ)�”}”(hXåStacks allocated using map_shadow_stack() can optionally have an end of stack marker and cap placed at the top of the stack. If the flag SHADOW_STACK_SET_TOKEN is specified a cap will be placed on the stack, if SHADOW_STACK_SET_MARKER is not specified the cap will be the top 8 bytes of the stack and if it is specified then the cap will be the next 8 bytes. While specifying just SHADOW_STACK_SET_MARKER by itself is valid since the marker is all bits 0 it has no observable effect.”h]”hXåStacks allocated using map_shadow_stack() can optionally have an end of stack marker and cap placed at the top of the stack. If the flag SHADOW_STACK_SET_TOKEN is specified a cap will be placed on the stack, if SHADOW_STACK_SET_MARKER is not specified the cap will be the top 8 bytes of the stack and if it is specified then the cap will be the next 8 bytes. While specifying just SHADOW_STACK_SET_MARKER by itself is valid since the marker is all bits 0 it has no observable effect.”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K„hjubah}”(h]”h ]”h"]”h$]”h&]”uh1hÿhj´h²hh³hÊh´Nubj)�”}”(hŒ‹Stacks allocated using map_shadow_stack() must have a size which is a multiple of 8 bytes larger than 8 bytes and must be 8 bytes aligned. ”h]”hÌ)�”}”(hŒŠStacks allocated using map_shadow_stack() must have a size which is a multiple of 8 bytes larger than 8 bytes and must be 8 bytes aligned.”h]”hŒŠStacks allocated using map_shadow_stack() must have a size which is a multiple of 8 bytes larger than 8 bytes and must be 8 bytes aligned.”…”�”}”(hj3h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´KŒhj/ubah}”(h]”h ]”h"]”h$]”h&]”uh1hÿhj´h²hh³hÊh´Nubj)�”}”(hŒrAn address can be specified to map_shadow_stack(), if one is provided then it must be aligned to a page boundary. ”h]”hÌ)�”}”(hŒqAn address can be specified to map_shadow_stack(), if one is provided then it must be aligned to a page boundary.”h]”hŒqAn address can be specified to map_shadow_stack(), if one is provided then it must be aligned to a page boundary.”…”�”}”(hjKh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K�hjGubah}”(h]”h ]”h"]”h$]”h&]”uh1hÿhj´h²hh³hÊh´Nubj)�”}”(hŒÓWhen a thread is freed the Guarded Control Stack initially allocated for that thread will be freed. Note carefully that if the stack has been switched this may not be the stack currently in use by the thread. ”h]”hÌ)�”}”(hŒÑWhen a thread is freed the Guarded Control Stack initially allocated for that thread will be freed. Note carefully that if the stack has been switched this may not be the stack currently in use by the thread.”h]”hŒÑWhen a thread is freed the Guarded Control Stack initially allocated for that thread will be freed. Note carefully that if the stack has been switched this may not be the stack currently in use by the thread.”…”�”}”(hjch²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K’hj_ubah}”(h]”h ]”h"]”h$]”h&]”uh1hÿhj´h²hh³hÊh´Nubeh}”(h]”h ]”h"]”h$]”h&]”j'j(uh1húh³hÊh´Kthj£h²hubeh}”(h]”Œ$allocation-of-guarded-control-stacks”ah ]”h"]”Œ'3. allocation of guarded control stacks”ah$]”h&]”uh1hµhh·h²hh³hÊh´Krubh¶)�”}”(hhh]”(h»)�”}”(hŒ4. Signal handling”h]”hŒ4. Signal handling”…”�”}”(hjˆh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hºhj…h²hh³hÊh´K˜ubhû)�”}”(hhh]”(j)�”}”(hŒ¹A new signal frame record gcs_context encodes the current GCS mode and pointer for the interrupted context on signal delivery. This will always be present on systems that support GCS. ”h]”hÌ)�”}”(hŒ¸A new signal frame record gcs_context encodes the current GCS mode and pointer for the interrupted context on signal delivery. This will always be present on systems that support GCS.”h]”hŒ¸A new signal frame record gcs_context encodes the current GCS mode and pointer for the interrupted context on signal delivery. This will always be present on systems that support GCS.”…”�”}”(hj�h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´Kšhj™ubah}”(h]”h ]”h"]”h$]”h&]”uh1hÿhj–h²hh³hÊh´Nubj)�”}”(hŒŽThe record contains a flag field which reports the current GCS configuration for the interrupted context as PR_GET_SHADOW_STACK_STATUS would. ”h]”hÌ)�”}”(hŒ�The record contains a flag field which reports the current GCS configuration for the interrupted context as PR_GET_SHADOW_STACK_STATUS would.”h]”hŒ�The record contains a flag field which reports the current GCS configuration for the interrupted context as PR_GET_SHADOW_STACK_STATUS would.”…”�”}”(hjµh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´Kžhj±ubah}”(h]”h ]”h"]”h$]”h&]”uh1hÿhj–h²hh³hÊh´Nubj)�”}”(hŒVThe signal handler is run with the same GCS configuration as the interrupted context. ”h]”hÌ)�”}”(hŒUThe signal handler is run with the same GCS configuration as the interrupted context.”h]”hŒUThe signal handler is run with the same GCS configuration as the interrupted context.”…”�”}”(hjÍh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K¡hjÉubah}”(h]”h ]”h"]”h$]”h&]”uh1hÿhj–h²hh³hÊh´Nubj)�”}”(hX When GCS is enabled for the interrupted thread a signal handling specific GCS cap token will be written to the GCS, this is an architectural GCS cap with the token type (bits 0..11) all clear. The GCSPR_EL0 reported in the signal frame will point to this cap token. ”h]”hÌ)�”}”(hX When GCS is enabled for the interrupted thread a signal handling specific GCS cap token will be written to the GCS, this is an architectural GCS cap with the token type (bits 0..11) all clear. The GCSPR_EL0 reported in the signal frame will point to this cap token.”h]”hX When GCS is enabled for the interrupted thread a signal handling specific GCS cap token will be written to the GCS, this is an architectural GCS cap with the token type (bits 0..11) all clear. The GCSPR_EL0 reported in the signal frame will point to this cap token.”…”�”}”(hjåh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K¤hjáubah}”(h]”h ]”h"]”h$]”h&]”uh1hÿhj–h²hh³hÊh´Nubj)�”}”(hŒEThe signal handler will use the same GCS as the interrupted context. ”h]”hÌ)�”}”(hŒDThe signal handler will use the same GCS as the interrupted context.”h]”hŒDThe signal handler will use the same GCS as the interrupted context.”…”�”}”(hjýh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K©hjùubah}”(h]”h ]”h"]”h$]”h&]”uh1hÿhj–h²hh³hÊh´Nubj)�”}”(hŒöWhen GCS is enabled on signal entry a frame with the address of the signal return handler will be pushed onto the GCS, allowing return from the signal handler via RET as normal. This will not be reported in the gcs_context in the signal frame. ”h]”hÌ)�”}”(hŒôWhen GCS is enabled on signal entry a frame with the address of the signal return handler will be pushed onto the GCS, allowing return from the signal handler via RET as normal. This will not be reported in the gcs_context in the signal frame.”h]”hŒôWhen GCS is enabled on signal entry a frame with the address of the signal return handler will be pushed onto the GCS, allowing return from the signal handler via RET as normal. This will not be reported in the gcs_context in the signal frame.”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K«hjubah}”(h]”h ]”h"]”h$]”h&]”uh1hÿhj–h²hh³hÊh´Nubeh}”(h]”h ]”h"]”h$]”h&]”j'j(uh1húh³hÊh´Kšhj…h²hubeh}”(h]”Œsignal-handling”ah ]”h"]”Œ4. signal handling”ah$]”h&]”uh1hµhh·h²hh³hÊh´K˜ubh¶)�”}”(hhh]”(h»)�”}”(hŒ5. Signal return”h]”hŒ5. Signal return”…”�”}”(hj:h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hºhj7h²hh³hÊh´K²ubhÌ)�”}”(hŒ%When returning from a signal handler:”h]”hŒ%When returning from a signal handler:”…”�”}”(hjHh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K´hj7h²hubhû)�”}”(hhh]”(j)�”}”(hŒ–If there is a gcs_context record in the signal frame then the GCS flags and GCSPR_EL0 will be restored from that context prior to further validation. ”h]”hÌ)�”}”(hŒ•If there is a gcs_context record in the signal frame then the GCS flags and GCSPR_EL0 will be restored from that context prior to further validation.”h]”hŒ•If there is a gcs_context record in the signal frame then the GCS flags and GCSPR_EL0 will be restored from that context prior to further validation.”…”�”}”(hj]h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K¶hjYubah}”(h]”h ]”h"]”h$]”h&]”uh1hÿhjVh²hh³hÊh´Nubj)�”}”(hŒdIf there is no gcs_context record in the signal frame then the GCS configuration will be unchanged. ”h]”hÌ)�”}”(hŒcIf there is no gcs_context record in the signal frame then the GCS configuration will be unchanged.”h]”hŒcIf there is no gcs_context record in the signal frame then the GCS configuration will be unchanged.”…”�”}”(hjuh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´Kºhjqubah}”(h]”h ]”h"]”h$]”h&]”uh1hÿhjVh²hh³hÊh´Nubj)�”}”(hŒ§If GCS is enabled on return from a signal handler then GCSPR_EL0 must point to a valid GCS signal cap record, this will be popped from the GCS prior to signal return. ”h]”hÌ)�”}”(hŒ¦If GCS is enabled on return from a signal handler then GCSPR_EL0 must point to a valid GCS signal cap record, this will be popped from the GCS prior to signal return.”h]”hŒ¦If GCS is enabled on return from a signal handler then GCSPR_EL0 must point to a valid GCS signal cap record, this will be popped from the GCS prior to signal return.”…”�”}”(hj�h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K½hj‰ubah}”(h]”h ]”h"]”h$]”h&]”uh1hÿhjVh²hh³hÊh´Nubj)�”}”(hŒÏIf the GCS configuration is locked when returning from a signal then any attempt to change the GCS configuration will be treated as an error. This is true even if GCS was not enabled prior to signal entry. ”h]”hÌ)�”}”(hŒÎIf the GCS configuration is locked when returning from a signal then any attempt to change the GCS configuration will be treated as an error. This is true even if GCS was not enabled prior to signal entry.”h]”hŒÎIf the GCS configuration is locked when returning from a signal then any attempt to change the GCS configuration will be treated as an error. This is true even if GCS was not enabled prior to signal entry.”…”�”}”(hj¥h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´KÁhj¡ubah}”(h]”h ]”h"]”h$]”h&]”uh1hÿhjVh²hh³hÊh´Nubj)�”}”(hŒiGCS may be disabled via signal return but any attempt to enable GCS via signal return will be rejected. ”h]”hÌ)�”}”(hŒgGCS may be disabled via signal return but any attempt to enable GCS via signal return will be rejected.”h]”hŒgGCS may be disabled via signal return but any attempt to enable GCS via signal return will be rejected.”…”�”}”(hj½h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´KÅhj¹ubah}”(h]”h ]”h"]”h$]”h&]”uh1hÿhjVh²hh³hÊh´Nubeh}”(h]”h ]”h"]”h$]”h&]”j'j(uh1húh³hÊh´K¶hj7h²hubeh}”(h]”Œ signal-return”ah ]”h"]”Œ5. signal return”ah$]”h&]”uh1hµhh·h²hh³hÊh´K²ubh¶)�”}”(hhh]”(h»)�”}”(hŒ6. ptrace extensions”h]”hŒ6. ptrace extensions”…”�”}”(hjâh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hºhjßh²hh³hÊh´KÊubhû)�”}”(hhh]”(j)�”}”(hŒWA new regset NT_ARM_GCS is defined for use with PTRACE_GETREGSET and PTRACE_SETREGSET. ”h]”hÌ)�”}”(hŒVA new regset NT_ARM_GCS is defined for use with PTRACE_GETREGSET and PTRACE_SETREGSET.”h]”hŒVA new regset NT_ARM_GCS is defined for use with PTRACE_GETREGSET and PTRACE_SETREGSET.”…”�”}”(hj÷h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´KÌhjóubah}”(h]”h ]”h"]”h$]”h&]”uh1hÿhjðh²hh³hÊh´Nubj)�”}”(hŒ”The GCS mode, including enable and disable, may be configured via ptrace. If GCS is enabled via ptrace no new GCS will be allocated for the thread. ”h]”hÌ)�”}”(hŒ“The GCS mode, including enable and disable, may be configured via ptrace. If GCS is enabled via ptrace no new GCS will be allocated for the thread.”h]”hŒ“The GCS mode, including enable and disable, may be configured via ptrace. If GCS is enabled via ptrace no new GCS will be allocated for the thread.”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´KÏhj ubah}”(h]”h ]”h"]”h$]”h&]”uh1hÿhjðh²hh³hÊh´Nubj)�”}”(hŒ/smaps.”h]”hÌ)�”}”(hŒTGuarded Control Stack pages will include "ss" in their VmFlags in /proc//smaps.”h]”hŒXGuarded Control Stack pages will include “ssâ€� in their VmFlags in /proc//smaps.”…”�”}”(hj›h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´Kâhj—ubah}”(h]”h ]”h"]”h$]”h&]”uh1hÿhj”h²hh³hÊh´Nubah}”(h]”h ]”h"]”h$]”h&]”j'j(uh1húh³hÊh´Kâhjƒh²hubeh}”(h]”Œproc-extensions”ah ]”h"]”Œ8. /proc extensions”ah$]”h&]”uh1hµhh·h²hh³hÊh´Kàubeh}”(h]”Œ/guarded-control-stack-support-for-aarch64-linux”ah ]”h"]”Œ/guarded control stack support for aarch64 linux”ah$]”h&]”uh1hµhhh²hh³hÊh´Kubeh}”(h]”h ]”h"]”h$]”h&]”Œsource”hÊuh1hŒcurrent_source”NŒ current_line”NŒsettings”Œdocutils.frontend”ŒValues”“”)�”}”(hºNŒ generator”NŒ datestamp”NŒ source_link”NŒ source_url”NŒ toc_backlinks”Œentry”Œfootnote_backlinks”KŒ sectnum_xform”KŒstrip_comments”NŒstrip_elements_with_classes”NŒ strip_classes”NŒ report_level”KŒ halt_level”KŒexit_status_level”KŒdebug”NŒwarning_stream”NŒ traceback”ˆŒinput_encoding”Œ utf-8-sig”Œinput_encoding_error_handler”Œstrict”Œoutput_encoding”Œutf-8”Œoutput_encoding_error_handler”jèŒerror_encoding”Œutf-8”Œerror_encoding_error_handler”Œbackslashreplace”Œ language_code”Œen”Œrecord_dependencies”NŒconfig”NŒ id_prefix”hŒauto_id_prefix”Œid”Œ dump_settings”NŒdump_internals”NŒdump_transforms”NŒdump_pseudo_xml”NŒexpose_internals”NŒstrict_visitor”NŒ_disable_config”NŒ_source”hÊŒ _destination”NŒ _config_files”]”Œ7/var/lib/git/docbuild/linux/Documentation/docutils.conf”aŒfile_insertion_enabled”ˆŒ raw_enabled”KŒline_length_limit”M'Œpep_references”NŒ pep_base_url”Œhttps://peps.python.org/”Œpep_file_url_template”Œpep-%04d”Œrfc_references”NŒ rfc_base_url”Œ&https://datatracker.ietf.org/doc/html/”Œ tab_width”KŒtrim_footnote_reference_space”‰Œsyntax_highlight”Œlong”Œ smart_quotes”ˆŒsmartquotes_locales”]”Œcharacter_level_inline_markup”‰Œdoctitle_xform”‰Œ docinfo_xform”KŒsectsubtitle_xform”‰Œ image_loading”Œlink”Œembed_stylesheet”‰Œcloak_email_addresses”ˆŒsection_self_link”‰Œenv”NubŒreporter”NŒindirect_targets”]”Œsubstitution_defs”}”Œsubstitution_names”}”Œrefnames”}”Œrefids”}”Œnameids”}”(jÂj¿j.j+j j�j‚jj4j1jÜjÙjFjCj€j}jºj·uŒ nametypes”}”(j‰j.‰j ‰j‚‰j4‰j܉jF‰j€‰jº‰uh}”(j¿h·j+héj�j1jj£j1j…jÙj7jCjßj}jIj·jƒuŒ footnote_refs”}”Œ citation_refs”}”Œ autofootnotes”]”Œautofootnote_refs”]”Œsymbol_footnotes”]”Œsymbol_footnote_refs”]”Œ footnotes”]”Œ citations”]”Œautofootnote_start”KŒsymbol_footnote_start”KŒ id_counter”Œ collections”ŒCounter”“”}”…”R”Œparse_messages”]”Œtransform_messages”]”Œ transformer”NŒ include_log”]”Œ decoration”Nh²hub.