{"id":112744,"date":"2026-09-30T07:00:00","date_gmt":"2026-09-30T14:00:00","guid":{"rendered":"https:\/\/devblogs.microsoft.com\/oldnewthing\/?p=112744"},"modified":"2026-09-30T21:58:42","modified_gmt":"2026-10-01T04:58:42","slug":"20260930-00","status":"publish","type":"post","link":"https:\/\/devblogs.microsoft.com\/oldnewthing\/20260930-00\/?p=112744\/","title":{"rendered":"Windows on AArch64 also provides for hot-patching, but it&#8217;s much simpler than on x86"},"content":{"rendered":"<p>I have noted in the past that <a title=\"Why do Windows functions all begin with a pointless MOV EDI, EDI instruction?\" href=\"https:\/\/devblogs.microsoft.com\/oldnewthing\/20110921-00\/?p=9583\"> x86-32<\/a> and <a title=\"Why don't Windows functions begin with a pointless MOV EDI,EDI instruction on x86-64?\" href=\"https:\/\/devblogs.microsoft.com\/oldnewthing\/20221109-00\/?p=107373\"> x86-64<\/a> versions of Windows are careful to start each function with a patch point. But what about AArch64 (known in Windows as arm64)?<\/p>\n<p>Windows also inserts patch points for functions on AArch64, but they are much simpler due to the fixed-length instruction set. You don&#8217;t have to worry about patching an instruction when the instruction pointer happens to be in the middle of the byte sequence, because the instruction pointer is <i>never<\/i> in the middle of the byte sequence. The instruction pointer is always on a multiple of 4.<\/p>\n<p>Therefore, there is no special restriction on the first instruction of a function. All instructions meet the requirements of being atomically updatable without risk of the instruction pointer being in the middle of the instruction.<\/p>\n<p>Before each function is a patch space of 12 bytes, which is <a title=\"The AArch64 processor (aka arm64), part 15: Control transfer\" href=\"https:\/\/devblogs.microsoft.com\/oldnewthing\/20220815-00\/?p=106975\"> exactly enough for a three-instruction trampoline<\/a>:<\/p>\n<pre>; overwrite the patch space with these three instructions\r\n    adrp    xip0, PageStart(replacement)\r\n    add     xip0, xip0, PageOffset(replacement)\r\n    br      xip0\r\n\r\nfunction_entry_point:\r\n; overwrite the function entry point with one instruction\r\n    br      $-12 ; jump to the patch space\r\n<\/pre>\n<p>The <code>xip0<\/code> register is <a title=\"The AArch64 processor (aka arm64), part 1: Introduction\" href=\"https:\/\/devblogs.microsoft.com\/oldnewthing\/20220726-00\/?p=106898\"> one of the two intra-procedure call scratch registers<\/a>, and the convention is that this register can be clobbered by any branch instruction. Since the caller had to use a branch instruction to reach <code>function_<wbr \/>entry_<wbr \/>point<\/code> in the first place, it cannot be using <code>xip0<\/code> for anything, so we are free to clobber <code>xip0<\/code> as part of our trampoline.<\/p>\n<p><b>Bonus chatter<\/b>: The first instruction at the function entry point is almost certainly <code>pacibsp<\/code>, the <a title=\"The AArch64 processor (aka arm64), part 18: Return address protection\" href=\"https:\/\/devblogs.microsoft.com\/oldnewthing\/20220819-00\/?p=107020\"> pointer authentication instruction for signing the return address<\/a> to make code more resistant to ROP attacks and attacks that overwrite the return address.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Fixed-length instructions makes it a much easier task.<\/p>\n","protected":false},"author":1069,"featured_media":111744,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[26],"class_list":["post-112744","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-oldnewthing","tag-other"],"acf":[],"blog_post_summary":"<p>Fixed-length instructions makes it a much easier task.<\/p>\n","_links":{"self":[{"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/posts\/112744","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/users\/1069"}],"replies":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/comments?post=112744"}],"version-history":[{"count":1,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/posts\/112744\/revisions"}],"predecessor-version":[{"id":112745,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/posts\/112744\/revisions\/112745"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/media\/111744"}],"wp:attachment":[{"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/media?parent=112744"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/categories?post=112744"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/tags?post=112744"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}