Skip to main content

Module ptrauth

Module ptrauth 

Source
Expand description

Pointer-authentication (arm64e) helpers.

arm64e encodes a signature in the top 16 bits of a pointer. When dyld applies fixups it replaces the signature with the authenticated target, so pointers read from memory in a live process are plain VAs. Static analysis, though, often sees the raw on-disk form and must strip the signature bits before dereferencing the pointer or comparing it against a VA.

This module exposes the stripping operation as a single, testable helper rather than scattering bit-masking through metadata readers. Call strip_ptrauth on any u64 that was read directly from the binary on an arm64e image and is meant to be interpreted as a VA.

Functionsยง

has_ptrauth_bits
Whether a u64 has any bits set that arm64e would interpret as pointer-auth metadata. A false return means strip_ptrauth is a no-op.
strip_ptrauth
Strip the pointer-authentication signature from an arm64e pointer.