[llvm] [BOLT] Rework user-facing documentation of BOLT gadget scanner (PR #176446)

Anatoly Trosinenko via llvm-commits llvm-commits at lists.llvm.org
Mon May 4 09:51:17 PDT 2026


================
@@ -61,126 +64,680 @@ The security scanners implemented in `llvm-bolt-binary-analysis` aim to enable
 the testing of security hardening in arbitrary programs and not just specific
 examples.
 
+### Pointer Authentication
+
+[Pointer Authentication](https://clang.llvm.org/docs/PointerAuthentication.html)
+is intended to make it harder for an attacker to replace pointers at run time.
+This is achieved by making it possible for the compiler or the programmer to
+produce a *signed* pointer from a raw one, and then to probabilistically
+*authenticate the signature* at another site in the program.
+On AArch64 this is achieved by injecting a cryptographic hash, called a
+["Pointer Authentication Code" (PAC)](https://llsoftsec.github.io/llsoftsecbook/#sec:pointer-authentication),
+to the upper bits of the pointer.
+While this approach can be applied to any pointers in the program, the most
+frequent use case, at least in C and C++, is protecting the code pointers.
+The language rules for such pointers are more restrictive, thus allowing the
+compiler to implement various hardenings transparently to the programmer.
+
+Probably the most simple variant of hardening based on Pointer Authentication is
+[`pac-ret`](https://llsoftsec.github.io/llsoftsecbook/#sec:pac-ret), a security
+hardening scheme implemented in compilers such as GCC and Clang, using the
+command line option `-mbranch-protection=pac-ret`. This option is enabled by
+default on most widely used Linux distributions. The hardening scheme mitigates
----------------
atrosinenko wrote:

Reworded this paragraph and added a note to the top, thanks. Furthermore, mentioning that `llvm-bolt-binary-analysis` currently targets AArch64 only at the very beginning of this document should save a bit of time for non-AArch64 users :)

https://github.com/llvm/llvm-project/pull/176446


More information about the llvm-commits mailing list