Bug 2508469

Summary: Enable Shadow Stack by Default on x86_64
Product: [Fedora] Fedora Reporter: Aoife Moloney <amoloney>
Component: Changes TrackingAssignee: Arjun Shankar <ashankar>
Status: ASSIGNED --- QA Contact:
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: rawhideCC: ashankar
Target Milestone: ---Flags: amoloney: needinfo-
fedora-admin-xmlrpc: mirror+
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 2520385    

Description Aoife Moloney 2026-07-29 16:04:03 UTC
This is a tracking bug for Change: Enable Shadow Stack by Default on x86_64
For more details, see: https://fedoraproject.org/wiki/Changes/ShadowStack

This change enables Shadow Stack protection on applications and libraries built with gcc (C, C++), clang (C, C++), and rustc (Rust) by default on x86_64 machines that support it on Fedora Linux 45. The dynamic linker or static startup routines will activate Shadow Stack for any process whose binary and shared library dependencies are all built with Shadow Stack support (marked with ELF metadata), protecting processes by default whenever possible.

If you encounter a bug related to this Change, please do not comment here. Instead create a new bug and set it to block this bug.

Comment 1 Aoife Moloney 2026-08-31 10:17:12 UTC
Hi Arjun, has the work for this change been completed for F45? Or would you like to retarget to F46?

Comment 2 Aoife Moloney 2026-08-31 16:59:44 UTC
removing needinfo as this change is retargeting F46