Tricks like these are going to become less common with execute-only mapping of .text slowly proliferating through the industry (iOS, OpenBSD).
Though i386 is unlikely to ever become execute-only.
Though i386 is unlikely to ever become execute-only.
Give the PaX project some credit, since they had it before OpenBSD did. Windows has had it for a while also, since XP.
I didn’t know that and cannot find anything that confirms this. You have a source?
On recent Intel processors, it is possible to execute-only protect pages using Intel MPK (Memory-Protection Keys) by having pages with a key be read-only in the page table but "access disable" in the PKRU register. PKRU is accessible from user mode though.
AFAIK, the only (still) mainstream CPU arch with reliable execute-only protection is RISC-V. (I would like to be wrong, and see it on e.g. ARM as well)