From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-oa1-f74.google.com (mail-oa1-f74.google.com [209.85.160.74]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6309E30C617 for ; Mon, 15 Jun 2026 19:37:23 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.160.74 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781552244; cv=none; b=L1VENUOdE8p83BRvKXc4IxC7ch5a65wbJMqkvQf1fvTM3sXLlWrVmoikJFv4rJulBto0zVxYe9PsgOAuzJ265xEz3ztfJurPf4ASgnvwqFhb8B7Hu4OgT4vNDdez8UM82Un5jYOYzMqlbA7UWatWl2r7hX/5v5gsuF+k+VBtIZk= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781552244; c=relaxed/simple; bh=0Uh32Z84jAaWUbe/B7iFkDeUA0emys6kQtli/o7N2wY=; h=Date:Mime-Version:Message-ID:Subject:From:To:Cc:Content-Type; b=u7n0DnfrIuuv8sh5QKuiAE0BFmG+GohK6TLoDC4sH82atdFt/CuPWg8t5Y31Aj886rHj/ARD6+ixVWuc+KdEJ0coMuNCp9SAVCnVzLwY3f98TjUtOTl+0CwsJZEXVfNpE9TlPTAak7/M4Qvuzsvzu4VqIzLVRtnZQ4rtatVC/jw= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--avagin.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=oWAOa8so; arc=none smtp.client-ip=209.85.160.74 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--avagin.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="oWAOa8so" Received: by mail-oa1-f74.google.com with SMTP id 586e51a60fabf-43cce364a75so5626518fac.2 for ; Mon, 15 Jun 2026 12:37:23 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1781552242; x=1782157042; darn=lists.linux.dev; h=cc:to:from:subject:message-id:mime-version:date:from:to:cc:subject :date:message-id:reply-to; bh=IAufCONdB4S418e+Qv1fSYNL826oe/BmVRUV+6GzhF8=; b=oWAOa8soLsHoBYXb0gPHSYGTrHAJIqDU+vhOAQpdpDxbmXXFaPiyaaEqg7NbMk959g oOLe+Wwidm55Rtc83Bka7DEa58TYvMZuCXSWqoLH3DidzVCsnSp9yis2M38DX3GKKWx5 JvSysHID/khvCtjuW42Q9X29aI/IWzKQ9xsuFyY01tsTo3y6LUsPYT07yCP9TlDhWTL4 G+dg5pgrPNE+sh6p8ZHfgPephJd4aQocIVj8sAqpAGMEnhHCjtH80nOHAbpxd1HS6/2X y7fxei1VVPRmEFuOi0Ik9TD377k0Q+HOun0aHwCl/2SAs0WDRCdTNzaH+daRfZBf96HW v0LA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1781552242; x=1782157042; h=cc:to:from:subject:message-id:mime-version:date:x-gm-message-state :from:to:cc:subject:date:message-id:reply-to; bh=IAufCONdB4S418e+Qv1fSYNL826oe/BmVRUV+6GzhF8=; b=F16R7A6RniMXOTBxqBJtdugUvuO23xYcLToxEvk/KhFdjwZKmPQoF8MBXTpkP+Zkeg Z4+7Qcv4B7dLNvqpVhSEH4LwXz15Gx6KJps6QZQyX7fz9mNxl2EBphb+hWSakNr0wBnt A8RaTAaQ3FaTMMyKWCoQoqw//+Ys1jyCROzoOUFPW9/+XYP7xbbZKnabFewq4DmDSdj7 F1jytqcBbI8i1uFr8s548u5qi0LLJMSmqF27HqNvzVt7n7QXmLZjJFVZ1JN4xJI6aLlW ryIU5S+AqZ2KKT384s846VHBARqfTGWYs5pW0AjdVwZ6HgSE5jHOlFoJl/uKbI9XJGUq nsqw== X-Forwarded-Encrypted: i=1; AFNElJ+51QigoX9x7M7ySop8bp87nX1RTde78KdCgPy9R7zsnTmfiefLnjs7nQtJJ8dnMuLDgfkV@lists.linux.dev X-Gm-Message-State: AOJu0Ywm+dwZtzjichEEFIGA57r5ge6XFSuTHSwurEzLH+x4Bpg1Geru bG0s0jnLK1a9TinJCIm9Ob6dMPyi1k/oIfpGezZKWMBPS15gzBf+6LQj4PK5CfVAd3q9L2prSRY UxjFc0Q== X-Received: from iobp3-n2.prod.google.com ([2002:a05:6602:8683:20b0:96a:7dac:9ef2]) (user=avagin job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6820:80c5:b0:69e:8afe:e994 with SMTP id 006d021491bc7-69edc6ea0e8mr9569363eaf.32.1781552241953; Mon, 15 Jun 2026 12:37:21 -0700 (PDT) Date: Mon, 15 Jun 2026 19:37:06 +0000 Precedence: bulk X-Mailing-List: criu@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 X-Mailer: git-send-email 2.54.0.1189.g8c84645362-goog Message-ID: <20260615193716.1843340-1-avagin@google.com> Subject: [PATCH v3 0/10] x86/fpu: Restore and reinforce signal frame portability From: Andrei Vagin To: Thomas Gleixner , Ingo Molnar , Borislav Petkov , "Chang S. Bae" Cc: linux-kernel@vger.kernel.org, criu@lists.linux.dev, Dave Hansen , x86@kernel.org, Andrei Vagin , "H. Peter Anvin" Content-Type: text/plain; charset="UTF-8" The x86 signal frame is designed to be self-describing. The xstate_size field in the software-reserved bytes indicates the actual size of the xstate context and is used by the kernel to locate the FP_XSTATE_MAGIC2 marker during signal return. This design is required to provide portability of signal frames across different machines. For example, a process checkpointed on a system with fewer xstate features and restored on a system with more features will have a signal frame on its stack that is smaller than the destination host's default. By relying on the frame's internal xstate_size, the kernel can correctly validate and restore such frames. This series restores and improves signal frame portability. The goal is to allow process migration across CPUs with heterogeneous FPU capabilities, as long as the process only uses features supported by both systems. This version addresses the original issues by pre-faulting only the required size of the xstate buffer (rather than the default task size), and includes cleanups requested by Ingo Molnar. v3: - Include cleanups and refactoring of signal frame handling code as requested by Ingo Molnar. - Fix potential underflow in xstate_calculate_size() v2: - Address sashiko comments. - 44eeff9bc467 ("Revert "x86/fpu: Refine and simplify the magic number check during signal return"") has been merged. Cc: Thomas Gleixner Cc: Ingo Molnar Cc: Borislav Petkov Cc: Dave Hansen Cc: "H. Peter Anvin" Cc: "Chang S. Bae" Andrei Vagin (10): x86/fpu: Document signal frame portability x86/fpu: Clean up and rename variables in signal frame handling x86/fpu: Split __fpu_restore_sig to extract compat path x86/fpu: Document reasoning of FX-only fallback x86/fpu: Fix potential underflow in xstate_calculate_size() selftests/x86: Add a test for signal frame FPU portability x86/fpu: Pre-fault only required size of xstate buffer selftests/x86: Add a sigframe insufficient xstate_size test x86/fpu: Allow restoring signal frames with larger xstate_size selftests/x86: Check restoring FPU state with larger xstate_size Documentation/arch/x86/xstate.rst | 13 + arch/x86/include/uapi/asm/sigcontext.h | 13 + arch/x86/kernel/fpu/signal.c | 141 +++++-- arch/x86/kernel/fpu/xstate.c | 9 +- arch/x86/kernel/fpu/xstate.h | 2 + tools/testing/selftests/x86/Makefile | 5 +- .../selftests/x86/sigframe_fpu_portability.c | 345 ++++++++++++++++++ tools/testing/selftests/x86/xstate.c | 5 - tools/testing/selftests/x86/xstate.h | 12 + 9 files changed, 497 insertions(+), 48 deletions(-) create mode 100644 tools/testing/selftests/x86/sigframe_fpu_portability.c -- 2.54.0.1189.g8c84645362-goog