Calling Nested Functions on GCC Without an Executable Stack

Indirect Calling of Nested Functions on GCC Without Executable Stack

Martin Uecker explores a hack to support nested functions on older GCC versions without requiring an executable stack. By extracting the code address and static chain from the trampoline that GCC generates, and using `__builtin_call_with_static_chain`, the trampoline can be bypassed, allowing the stack to be cleared with `patchelf --clear-execstack`. He also proposes using trampolines as function descriptors, interpreting them at call sites. Implemented in his experimental library noplate.

In some sense we could say that instead of invoking the trampoline, we are _interpreting_ the code of the trampoline at the call site using a super simple interpreter that only can interpret this specific code sequence and that is so simple that it can be inlined.
  1. inigyou

    Self-modifying code is cool. It's a shame we had to disable it for security.

  2. mananaysiempre

    Related: previous article in the series, https://news.ycombinator.com/item?id=49308685 (103 points, 47 comments)

  3. gue5t

    At first, I was annoyed by having to read AT&T syntax. Then I was disoriented by realizing the next snippet was in AT&T syntax without the '%' sigil for registers. But the technique is cool.

  4. Dwedit

    What do you need the executable stack for? You call using a function pointer, there's no executable read/write memory involved in using a function pointer.

More from this day

2026-08-29