From: Ross Burton Date: Thu, 20 May 2021 17:15:11 +0000 (+0100) Subject: gcc: enable branch protection by standard X-Git-Tag: uninative-3.3~517 X-Git-Url: https://code.ossystems.io/gitweb?a=commitdiff_plain;h=84e6064cde02b463066d7b63fcf8baf392491327;p=openembedded-core.git gcc: enable branch protection by standard Pass --enable-standard-branch-protection. This is an aarch64-specific option (currently) which does nothing on other targets. On aarch64 this generates code uses BTI/PAC instructions to mitigate Return Orientated Programming attacks. This approach is backwards compatible and the code size/performance impact is typically negliable. More details can be found at https://events.static.linuxfound.org/sites/events/files/slides/slides_23.pdf Signed-off-by: Ross Burton Signed-off-by: Richard Purdie --- diff --git a/meta/recipes-devtools/gcc/gcc-configure-common.inc b/meta/recipes-devtools/gcc/gcc-configure-common.inc index a64c4caf00..dc7f458b25 100644 --- a/meta/recipes-devtools/gcc/gcc-configure-common.inc +++ b/meta/recipes-devtools/gcc/gcc-configure-common.inc @@ -40,6 +40,7 @@ EXTRA_OECONF = "\ ${@get_gcc_mips_plt_setting(bb, d)} \ ${@get_gcc_ppc_plt_settings(bb, d)} \ ${@get_gcc_multiarch_setting(bb, d)} \ + --enable-standard-branch-protection \ " # glibc version is a minimum controlling whether features are enabled.