Fixed-length instructions makes it a much easier task.
The post Windows on AArch64 also provides for hot-patching, but it’s much simpler than on x86 appeared first on The Old New Thing.
I have noted in the past that x86-32 and x86-64 versions of Windows are careful to start each function with a patch point. But what about AArch64 (known in Windows as arm64)?
Windows also inserts patch points for functions on AArch64, but they are much simpler due to the fixed-length instruction set. You don’t have to worry about patching an instruction when the instruction pointer happens to be in the middle of the byte sequence, because the instruction pointer is never in the middle of the byte sequence. The instruction pointer is always on a multiple of 4.
Therefore, there is no special restriction on the first instruction of a function. All instructions meet the requirements of being atomically updatable without risk of the instruction pointer being in the middle of the instruction.
Before each function is a patch space of 12 bytes, which is exactly enough for a three-instruction trampoline:
; overwrite the patch space with these three instructions
adrp xip0, PageStart(replacement)
add xip0, xip0, PageOffset(replacement)
br xip0
function_entry_point:
; overwrite the function entry point with one instruction
br $-12 ; jump to the patch space
The xip0 register is one of the two intra-procedure call scratch registers, and the convention is that this register can be clobbered by any branch instruction. Since the caller had to use a branch instruction to reach function_entry_point in the first place, it cannot be using xip0 for anything, so we are free to clobber xip0 as part of our trampoline.
Bonus chatter: The first instruction at the function entry point is almost certainly pacibsp, the pointer authentication instruction for signing the return address to make code more resistant to ROP attacks and attacks that overwrite the return address.

Raymond has been involved in the evolution of Windows for more than 30 years. In 2003, he began a Web site known as The Old New Thing which has grown in popularity far beyond his wildest imagination, a development which still gives him the heebie-jeebies. The Web site spawned a book, coincidentally also titled The Old New Thing (Addison Wesley 2007). He occasionally appears on the Windows Dev Docs Twitter account to tell stories which convey no useful information.
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | Windows on Itanium also provided for hot-patching, in an even simpler way | 0 | 10.2 | 01-10-2026 |
| 2 | Why is there no Windows hot-patching support for other architectures like 32-bit ARM and MIPS? | 0 | 9.06 | 02-10-2026 |
| 3 | If somebody tries to hot-patch an already-hot-patched function, how do they avoid conflicts? | 0 | 12.97 | 05-10-2026 |
| 4 | No, really, you need to pass all unhandled messages to DefWindowProc, part 2 | 0 | 5.84 | 24-09-2026 |
| 5 | Debugging walkthrough: Access violation on nonsense instruction, episode 3 | 0 | 7.89 | 25-09-2026 |
| 6 | As a general rule, calling product support while drunk is not recommended | 0 | 4.56 | 29-09-2026 |
| 7 | AMD Posts GCC Compiler Patches For AVX10V1AUX ISA Support | 0 | 11.85 | 24-09-2026 |
| 8 | Why does the compiler sometimes use ud2 and sometimes int 3 for code that shouldn’t execute? | 0 | 7.7 | 06-10-2026 |
| 9 | Windows-Update 26H2 ist da – und mit ihm drei fiese Bugs | 0 | 14.99 | 01-10-2026 |
| 10 | Microsoft Fixes File History Backup Failures Caused by September Windows Updates | 0 | 5.56 | 25-09-2026 |