* [PATCH v2 1/2] arch/x86: handle ARCH_SHSTK_ENABLE explicitly
@ 2026-07-07 19:11 Bill Roberts
2026-07-07 19:11 ` [PATCH v2 2/2] selftest/x86: test ARCH_SHSTK_UNLOCK Bill Roberts
0 siblings, 1 reply; 6+ messages in thread
From: Bill Roberts @ 2026-07-07 19:11 UTC (permalink / raw)
To: rick.p.edgecombe, Thomas Gleixner, Ingo Molnar, Borislav Petkov,
Dave Hansen, x86, H. Peter Anvin
Cc: Bill Roberts, linux-kernel
The arch_prctl() handling for shadow stack operations checks that the
operation being specified is a specific value, except for the
ARCH_SHSTK_ENABLE condition, which is treated like a default case in a
switch.
However, the special handling for ARCH_SHSTK_UNLOCK is only performed when
task != current. As a result, an ARCH_SHSTK_UNLOCK request for the current
task bypasses the unlock check and falls through to the ARCH_SHSTK_ENABLE
path, causing the request to be interpreted as an enable operation
instead.
To fix this, handle ARCH_SHSTK_ENABLE explicitly rather than relying on it
as the default case. This fixes the incorrect dispatch and makes the
operation handling more robust by requiring each operation to be matched
explicitly.
Signed-off-by: Bill Roberts <bill.roberts@arm.com>
---
arch/x86/kernel/shstk.c | 12 +++++++-----
1 file changed, 7 insertions(+), 5 deletions(-)
diff --git a/arch/x86/kernel/shstk.c b/arch/x86/kernel/shstk.c
index 0ca64900192f..65c896d02379 100644
--- a/arch/x86/kernel/shstk.c
+++ b/arch/x86/kernel/shstk.c
@@ -607,11 +607,13 @@ long shstk_prctl(struct task_struct *task, int option, unsigned long arg2)
return -EINVAL;
}
- /* Handle ARCH_SHSTK_ENABLE */
- if (features & ARCH_SHSTK_SHSTK)
- return shstk_setup();
- if (features & ARCH_SHSTK_WRSS)
- return wrss_control(true);
+ if (option == ARCH_SHSTK_ENABLE) {
+ if (features & ARCH_SHSTK_SHSTK)
+ return shstk_setup();
+ if (features & ARCH_SHSTK_WRSS)
+ return wrss_control(true);
+ }
+
return -EINVAL;
}
--
2.54.0
^ permalink raw reply related [flat|nested] 6+ messages in thread* [PATCH v2 2/2] selftest/x86: test ARCH_SHSTK_UNLOCK
2026-07-07 19:11 [PATCH v2 1/2] arch/x86: handle ARCH_SHSTK_ENABLE explicitly Bill Roberts
@ 2026-07-07 19:11 ` Bill Roberts
2026-08-27 23:32 ` Edgecombe, Rick P
0 siblings, 1 reply; 6+ messages in thread
From: Bill Roberts @ 2026-07-07 19:11 UTC (permalink / raw)
To: rick.p.edgecombe, Thomas Gleixner, Ingo Molnar, Borislav Petkov,
Dave Hansen, x86, H. Peter Anvin, Shuah Khan
Cc: Bill Roberts, linux-kernel, linux-kselftest
Test that ARCH_SHSTK_UNLOCK can't be called from normal (non-ptrace)
context.
Signed-off-by: Bill Roberts <bill.roberts@arm.com>
---
tools/testing/selftests/x86/test_shadow_stack.c | 8 ++++++++
1 file changed, 8 insertions(+)
diff --git a/tools/testing/selftests/x86/test_shadow_stack.c b/tools/testing/selftests/x86/test_shadow_stack.c
index 3d6ca33edba4..cbe7ca4ebd90 100644
--- a/tools/testing/selftests/x86/test_shadow_stack.c
+++ b/tools/testing/selftests/x86/test_shadow_stack.c
@@ -1059,6 +1059,14 @@ int main(int argc, char *argv[])
{
int ret = 0;
+ /* Test that ARCH_SHSTK_UNLOCK can't be called from normal (non-ptrace) context. */
+ if (!ARCH_PRCTL(ARCH_SHSTK_UNLOCK, ARCH_SHSTK_SHSTK)) {
+ printf("[FAIL]\tARCH_SHSTK_UNLOCK should fail in a non-ptrace context\n");
+ goto out;
+ }
+
+ printf("[OK]\tCouldn't enable Shadow stack via UNLOCK\n");
+
if (ARCH_PRCTL(ARCH_SHSTK_ENABLE, ARCH_SHSTK_SHSTK)) {
printf("[SKIP]\tCould not enable Shadow stack\n");
return 1;
--
2.54.0
^ permalink raw reply related [flat|nested] 6+ messages in thread* Re: [PATCH v2 2/2] selftest/x86: test ARCH_SHSTK_UNLOCK
2026-07-07 19:11 ` [PATCH v2 2/2] selftest/x86: test ARCH_SHSTK_UNLOCK Bill Roberts
@ 2026-08-27 23:32 ` Edgecombe, Rick P
2026-09-09 18:47 ` Bill Roberts
2026-09-09 20:25 ` Bill Roberts
0 siblings, 2 replies; 6+ messages in thread
From: Edgecombe, Rick P @ 2026-08-27 23:32 UTC (permalink / raw)
To: x86@kernel.org, dave.hansen@linux.intel.com, shuah@kernel.org,
mingo@redhat.com, bp@alien8.de, tglx@kernel.org,
bill.roberts@arm.com, hpa@zytor.com
Cc: linux-kernel@vger.kernel.org, linux-kselftest@vger.kernel.org
On Tue, 2026-07-07 at 14:11 -0500, Bill Roberts wrote:
> Test that ARCH_SHSTK_UNLOCK can't be called from normal (non-ptrace)
> context.
>
> Signed-off-by: Bill Roberts <bill.roberts@arm.com>
> ---
Reviewed-by: Rick Edgecombe <rick.p.edgecombe@intel.com>
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [PATCH v2 2/2] selftest/x86: test ARCH_SHSTK_UNLOCK
2026-08-27 23:32 ` Edgecombe, Rick P
@ 2026-09-09 18:47 ` Bill Roberts
2026-09-09 18:58 ` Edgecombe, Rick P
2026-09-09 20:25 ` Bill Roberts
1 sibling, 1 reply; 6+ messages in thread
From: Bill Roberts @ 2026-09-09 18:47 UTC (permalink / raw)
To: Edgecombe, Rick P, x86@kernel.org, dave.hansen@linux.intel.com,
shuah@kernel.org, mingo@redhat.com, bp@alien8.de, tglx@kernel.org,
hpa@zytor.com
Cc: linux-kernel@vger.kernel.org, linux-kselftest@vger.kernel.org
On 8/27/26 6:32 PM, Edgecombe, Rick P wrote:
> On Tue, 2026-07-07 at 14:11 -0500, Bill Roberts wrote:
>> Test that ARCH_SHSTK_UNLOCK can't be called from normal (non-ptrace)
>> context.
>>
>> Signed-off-by: Bill Roberts <bill.roberts@arm.com>
>> ---
> Reviewed-by: Rick Edgecombe <rick.p.edgecombe@intel.com>
Rick/Dave, bump, any love on this patch series? Thanks.
Lore links for convenience:
- Re: [PATCH v2 1/2] arch/x86: handle ARCH_SHSTK_ENABLE explicitly
-
https://lore.kernel.org/all/d223c3e24650c3d29f162bb7faaac74ccb7bf65a.camel@intel.com/
- Re: [PATCH v2 2/2] selftest/x86: test ARCH_SHSTK_UNLOCK
-
https://lore.kernel.org/all/440cdd41a203589b31e287378de146e18e620176.camel@intel.com/
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [PATCH v2 2/2] selftest/x86: test ARCH_SHSTK_UNLOCK
2026-09-09 18:47 ` Bill Roberts
@ 2026-09-09 18:58 ` Edgecombe, Rick P
0 siblings, 0 replies; 6+ messages in thread
From: Edgecombe, Rick P @ 2026-09-09 18:58 UTC (permalink / raw)
To: bp@alien8.de, dave.hansen@linux.intel.com, shuah@kernel.org,
mingo@redhat.com, x86@kernel.org, tglx@kernel.org,
bill.roberts@arm.com, hpa@zytor.com
Cc: linux-kernel@vger.kernel.org, linux-kselftest@vger.kernel.org
On Wed, 2026-09-09 at 13:47 -0500, Bill Roberts wrote:
> Rick
I replied. Is there something else you need?
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [PATCH v2 2/2] selftest/x86: test ARCH_SHSTK_UNLOCK
2026-08-27 23:32 ` Edgecombe, Rick P
2026-09-09 18:47 ` Bill Roberts
@ 2026-09-09 20:25 ` Bill Roberts
1 sibling, 0 replies; 6+ messages in thread
From: Bill Roberts @ 2026-09-09 20:25 UTC (permalink / raw)
To: Edgecombe, Rick P, x86@kernel.org, dave.hansen@linux.intel.com,
shuah@kernel.org, mingo@redhat.com, bp@alien8.de, tglx@kernel.org,
hpa@zytor.com
Cc: linux-kernel@vger.kernel.org, linux-kselftest@vger.kernel.org
On 8/27/26 6:32 PM, Edgecombe, Rick P wrote:
> On Tue, 2026-07-07 at 14:11 -0500, Bill Roberts wrote:
>> Test that ARCH_SHSTK_UNLOCK can't be called from normal (non-ptrace)
>> context.
>>
>> Signed-off-by: Bill Roberts <bill.roberts@arm.com>
>> ---
> Reviewed-by: Rick Edgecombe <rick.p.edgecombe@intel.com>
Bump, I don't see these acked/staged anywhere.
Links in case you need the patches handy:
1.
https://lore.kernel.org/all/d223c3e24650c3d29f162bb7faaac74ccb7bf65a.camel@intel.com/
2.
https://lore.kernel.org/all/440cdd41a203589b31e287378de146e18e620176.camel@intel.com/
^ permalink raw reply [flat|nested] 6+ messages in thread
end of thread, other threads:[~2026-09-09 20:26 UTC | newest]
Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-07 19:11 [PATCH v2 1/2] arch/x86: handle ARCH_SHSTK_ENABLE explicitly Bill Roberts
2026-07-07 19:11 ` [PATCH v2 2/2] selftest/x86: test ARCH_SHSTK_UNLOCK Bill Roberts
2026-08-27 23:32 ` Edgecombe, Rick P
2026-09-09 18:47 ` Bill Roberts
2026-09-09 18:58 ` Edgecombe, Rick P
2026-09-09 20:25 ` Bill Roberts
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.