Skip to content

Glossary

Branch target identification (BTI)

An ARMv8.5 feature that forces indirect branches to land on a bti landing-pad instruction, invalidating mid-function gadgets on the forward edge.

Branch target identification (BTI) is an AArch64 feature that protects the forward edge of control flow. When enabled, an indirect branch (br, blr) may only transfer control to a bti instruction, which the compiler places at legitimate entry points. A gadget in the middle of a function does not begin with bti, so using it as an indirect-branch target raises a Branch Target exception.

BTI removes the large supply of mid-function gadgets that jump-oriented and return-oriented programming rely on, though it is coarse-grained — it permits any valid landing pad, so whole-function reuse can remain possible. It complements pointer authentication, which protects the backward edge, and both are enabled with -mbranch-protection=standard. See PAC and BTI.