Evidence-Carrying Portability Contracts for Compiler Security Instrumentation: Differential Reconstruction of Shadow Call Stack Protocols
Compiler security instrumentation is portable only when the compiler, application binary interface, runtime, loader, operating system, and hardware preserve the same security contract. We present Evidence-Carrying Portability Contracts (ECPC), a machine-readable method that binds each versioned configuration to seven return-integrity obligations, typed cross-layer facts, authoritative decision rules, executable transition witnesses, and field-level provenance. We retrospectively evaluated eight shadow call stack configurations across x86_64, AArch64, and RISC-V. Three implications emerge: pointer publication order determines whether asynchronous handlers can corrupt slot ownership; capture, edge coverage, and slot ownership are independent properties; and hardware enforcement relocates obligations into loader, lifecycle, and non-local-control-flow support rather than eliminating them. The reconstruction distinguishes two ownership defects in the LLVM RISC-V D84414 draft, one in the landed 2020 form and none after D149099; a glibc commit-interval case identifies restore token search and RSTORSSP as decisive for cross-context longjmp. The Compact TLS x86_64 configuration is evaluated only as a specified design because its submitted artefacts conflict and implementation source is unavailable; we make no performance or production-readiness claim for it. Artefact version 2.1.0 and 30 semantic tests make every reported classification regenerable. The study demonstrates traceable retrospective discrimination among known states, not prospective defect-discovery accuracy.
Authors
- Răzvan Rughiniş (ORCID: https://orcid.org/0000-0003-2794-280X)
- Dinu Țurcanu (ORCID: https://orcid.org/0000-0001-5540-4246)
- Ebru Resul (ORCID: https://orcid.org/0009-0008-6499-2279)
- Ștefan-Darius Iordache
Institutions
- Technical University of Moldova (MD)
- Academia Oamenilor de Știință din România (RO)
- Universitatea Națională de Știință și Tehnologie Politehnica București (RO)
Publication Details
- Journal
- Information
- Published
- 2026-09-13
- DOI
- https://doi.org/10.3390/info17090887
- Primary Topic
- Security and Verification in Computing
- Type
- article
- Field-Weighted Citation Impact
- 0.00