Fedora has approved plans to enable the x86_64 Shadow Stack security feature by default, but has moved the target from Fedora 45 to Fedora 46. As reported by Phoronix, the Fedora Engineering and Steering Committee (FESCo) signed off on the change while requesting an additional release cycle to accommodate compatibility testing across the distribution's broad software stack.

Shadow Stack is a hardware-backed defence available on modern Intel and AMD processors that maintains a protected copy of function return addresses. Its purpose is to block prevalent exploit techniques such as return-oriented programming. With the feature enabled by default, Fedora users would gain this layer of protection automatically without needing to set kernel or compiler flags manually.

The postponement is not a rejection of the feature itself. FESCo's decision grants the ecosystem a full additional cycle to surface and resolve integration issues before Shadow Stack becomes the system-wide default. This gives package maintainers and application developers a concrete window to test their software against a kernel and compiler stack where the protection can be manually activated, helping to catch regressions in language runtimes, JIT compilers, or proprietary binaries before they affect ordinary users.

This approach underscores Fedora's dual role as both an innovation platform and a stabilising force for the wider Linux ecosystem. A clean enablement in Fedora 46 would signal to downstream distributions — most notably Red Hat Enterprise Linux — that the feature has cleared the integration hurdles necessary for production use. A rough rollout, by contrast, could slow adoption across the industry. Fedora is therefore balancing the urgency of hardware-assisted hardening against its obligation to keep the distribution reliable for millions of users.

For developers and maintainers outside the Fedora project, the revised timeline offers a clear preparation window. Testing software against Fedora 45 with Shadow Stack manually enabled is now advisable, as issues found during that cycle can be resolved well before the default flip. A successful deployment in Fedora 46 would also give toolchain authors, security researchers, and enterprise Linux vendors a stronger basis for aligning their own roadmaps with the feature.

The remaining technical work centres on verifying that the kernel, GNU C Library (glibc), compilers, and core user-space packages cooperate cleanly under the protection. Testing is expected to span standard desktop applications, container runtimes, and specialised computational workloads. While the full scope of anticipated incompatibilities has not been detailed publicly, the categories of software most likely to require adjustment include those with non-standard calling conventions or runtime code generation.

Fedora 46 is now the release expected to deliver x86_64 Shadow Stack out of the box. The decision to devote an extra cycle to validation reflects a broader principle in open-source security engineering: a hardening measure is only as good as the stability of the system it protects.


Fedora 已批准預設啟用 x86_64 Shadow Stack 安全功能的計劃,但將目標版本從 Fedora 45 推遲至 Fedora 46。據 Phoronix 報導,Fedora 工程與指導委員會(FESCo)批准了這項變更,同時要求額外一個發行週期,以配合該發行版廣泛軟件堆疊的相容性測試。

Shadow Stack 是一項基於硬件的防禦機制,支援現代 Intel 及 AMD 處理器,能維護函數返回地址的受保護副本。其旨在阻擋如 Return-Oriented Programming(ROP)等普遍的漏洞利用技術。預設啟用此功能後,Fedora 用戶將自動獲得此層保護,無需手動設定核心或編譯器標誌。

此次推遲並非對功能本身的否定。FESCo 的決定賦予整個生態系統一個完整的額外週期,在 Shadow Stack 成為系統範圍預設選項之前,先行識別並解決整合問題。這為套件維護者及應用程式開發者提供了一個明確的時間窗口,在一個可手動啟用保護機制的核心與編譯器堆疊上測試他們的軟件,有助於在影響普通用戶之前,捕捉語言執行環境、JIT 編譯器或專有二進制文件中的回歸問題。

這種策略凸顯了 Fedora 的雙重角色——既是創新平台,也是整個 Linux 生態系統的穩定力量。若能在 Fedora 46 中順利啟用,將向下游發行版——尤其是 Red Hat Enterprise Linux——發出信號,表明該功能已跨越生產環境所需的整合障礙。反之,若推出過程不順,則可能拖慢整個行業的採用步伐。Fedora 因此正在平衡硬件輔助強化的緊迫性與其維持發行版可靠性的責任,以服務數百萬用戶。

對於 Fedora 項目以外的開發者及維護者而言,修訂後的時間表提供了一個明確的準備窗口。現時建議在 Fedora 45 上手動啟用 Shadow Stack 來測試軟件,因為在該週期內發現的問題,可在預設切換之前得到充分解決。若能在 Fedora 46 中成功部署,亦將為工具鏈作者、安全研究人員及企業 Linux 供應商提供更堅實的基礎,以調整他們各自的技術路線圖。

剩餘的技術工作著重於驗證核心、GNU C 函式庫(glibc)、編譯器及核心用戶空間套件在保護機制啟用時能否協同運作。測試預計涵蓋標準桌面應用程式、容器運行時以及專門的計算工作負載。雖然預期的不相容問題尚未完整公開披露,但最可能需要調整的軟件類別包括採用非標準呼叫慣例或具備執行時代碼生成能力的程式。

Fedora 46 現已成為預計開箱即用提供 x86_64 Shadow Stack 保護的版本。撥出額外一個週期進行驗證的決定,反映了一個開源安全工程的更廣泛原則:一項強化措施的價值,取決於其所保護系統的穩定性。

新聞來源 / Original News Source