In fairness, the authors cite another paper for the RAP statement. The cited paper argues that RAP is vulnerable to ret2user attacks, because it doesn't protect register contents on the kernel's interrupt stack. Is that not the case? (I don't know how RAP works personally.)