Can they guarantee no JIT code via static analysis as well? Or could someone sneak in a tiny bit of disguised JIT code just to get to this register?
I would assume a huge JITed VM implementation would show up easily in analysis.
They don't provide anyway to mark memory as executable.
Well, they do, because they have to run your code :P You just can't make a new page of code and mark it executable.
The OS only makes pages executable if they come from a signed app. There is no way for the app itself to do that.
If it makes it more clear, my comment was mostly "if your code page has a valid signature you can mark it as executable".
Do you need JIT though? Does Xcode support inline ASM, or various compilers extensions that can read/write a cpu register?
If you put this in your app directly, Apple can just find it and reject it at submission time. If JIT were an option, that wouldn't be enough, because the app could do it at runtime. Since it isn't, there is no way to "hide" something like this from the App Store static analyzer.
Hrm. It seems like inline ASM allows for passing the register name dynamically, though I can't tell for sure. If that's the case, it seems like it would be hard to tell ahead of time, other than "app calls msr/mrs".
Inline assembly must resolve register names at compile time.