From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-oi1-f202.google.com (mail-oi1-f202.google.com [209.85.167.202]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1A2AC3B42FC for ; Mon, 15 Jun 2026 19:37:37 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.167.202 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781552260; cv=none; b=PZHjyRmIotagk6GyyHmtjf6jg4wKIA9qnRE55wi0lvlXPwvkd2QDck6tbnfIPzuvcuApgYvgC9LduwUEcxskpxSW9NzaRKyn1Ax+tK+6zIuKamzqof8BKtj3ly6mQERQNCZUyq2U3n+EyLJ1wV+Op85IhvQ0FKZg0VqF1U/iQmk= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781552260; c=relaxed/simple; bh=NHt0vZ1Ltm/gQV39HJkjefrkirx2BoxzKydrn1QM0wU=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=tEeKYhIptKKma3BalPZcfWa4P6EJaQSeCUEMTc4Y2Dqd4nayKbYNUztu9DmjVJtejVVryWCRZUrc/TgLOFu+11EPOpTeAjg/wEmTgvA0fvnPM9KxJYy53d/cLxJzq7v4qhR9eAXId2iKKdT8Zj0duejmzYxHBzBPg7f971U/X5Y= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--avagin.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=n5mHVscr; arc=none smtp.client-ip=209.85.167.202 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--avagin.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="n5mHVscr" Received: by mail-oi1-f202.google.com with SMTP id 5614622812f47-4863c8d459eso3918942b6e.3 for ; Mon, 15 Jun 2026 12:37:36 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1781552256; x=1782157056; darn=lists.linux.dev; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:from:to:cc:subject:date:message-id:reply-to; bh=pkEM6/4vRnWHsxPwymmU+f7NCSNhQj17Xg5t7cTI7xg=; b=n5mHVscrGCNiBWTFZ3f9osY4jRu6nhz1CkSsx1eKC41+9zkExQEaeL9+QCHdBa2pUP rOnXEFWMS/gdj62JNtmjCpOdOuq4pCWe2ufhDRgQvWijjp54ybpS3eCV1C3yPaP7q7VC bdIU9Zd6hJBqiPCV0dmAhR7D2yzgXgbyzXQR4HhNpkMvlMh603pxjru0trxnvtc1e4GQ ROugNYSsNGNvH1w1yjuhoFg1k2m7XTRhbcAqP8BbZeRdEtK6oqCf+M+SdUzoq4JaldMj nAZhFEaKd/SZkywWcJzp1O5Rwenprhtqu4udJrM+TLN9aFyzvsa6kpyIYXx387FPzBN+ 8crQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1781552256; x=1782157056; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=pkEM6/4vRnWHsxPwymmU+f7NCSNhQj17Xg5t7cTI7xg=; b=V59n4qmtsCMoS3yAb8utksKPLPJtXq7w2fFp40lX/7ZNC0NozbIaiG6fhCiBDBTyII QbwRQQuOMtOaqAYBVmT4UA8K1587R6yvl535PJFXPmQzvJm3yxEL8EjnJPN9vD1dYh+Q aHfgWcv0FPD1NjFb1DN0lnF11QLD5ecSIiDo0tbubAkF5ljymD3SnSAw8/EL0Y74d7TW fco2VVEZEcOge6w/SXUDHJc/m9Ce3+ZADFawNMLgcpFPezt+3RLd/1awL4aRlhJbzNro o/umw9iIQ3CIC+1n/3AjqWToJEJ+o739e8hulFWtuEm3D2bi4czo17IR53v327RCzJDR rqWA== X-Forwarded-Encrypted: i=1; AFNElJ+0FnUK/27/zEozEnY1CqTInT8oP1e/QeHxwcLawcmgiShNcLqF8fRO8s7vlIREBijuRvF/@lists.linux.dev X-Gm-Message-State: AOJu0Yw0ybQGjiLcjtk7c0/I4M4dz8pNu92XnS10bBjufH5e/FzMSsax wZgTSY+8yKDQrRmv7a3Oo0X9D4Ay/NOx5kXnSr/qS9Qtw7Ht7JUZV7elRzUL+Mi7UbcnIQqWo24 YaRcJ5A== X-Received: from jabjz5.prod.google.com ([2002:a05:6638:a385:b0:5e2:9f74:d3aa]) (user=avagin job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6808:1486:b0:482:6b8a:33a6 with SMTP id 5614622812f47-48741b05e11mr10904664b6e.23.1781552255940; Mon, 15 Jun 2026 12:37:35 -0700 (PDT) Date: Mon, 15 Jun 2026 19:37:15 +0000 In-Reply-To: <20260615193716.1843340-1-avagin@google.com> Precedence: bulk X-Mailing-List: criu@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260615193716.1843340-1-avagin@google.com> X-Mailer: git-send-email 2.54.0.1189.g8c84645362-goog Message-ID: <20260615193716.1843340-10-avagin@google.com> Subject: [PATCH 09/10] x86/fpu: Allow restoring signal frames with larger xstate_size From: Andrei Vagin To: Thomas Gleixner , Ingo Molnar , Borislav Petkov , "Chang S. Bae" Cc: linux-kernel@vger.kernel.org, criu@lists.linux.dev, Dave Hansen , x86@kernel.org, Andrei Vagin , "H. Peter Anvin" Content-Type: text/plain; charset="UTF-8" The kernel previously enforced that the xstate_size in the signal frame must not exceed the current task's fpstate->user_size. This prevents restoring signal frames that were saved on another CPU (in case of container/process migration) with a different (larger) set of enabled xstate features, even if the features to be restored are compatible. Relax this restriction by removing the strict check against user_size. The previous commit introduced infrastructure to calculate the actual required size based on the intersection of requested and supported features. We now rely on that validation and only require that the provided xstate_size is sufficient for the active features. Signed-off-by: Andrei Vagin --- arch/x86/kernel/fpu/signal.c | 13 +++++++++++-- 1 file changed, 11 insertions(+), 2 deletions(-) diff --git a/arch/x86/kernel/fpu/signal.c b/arch/x86/kernel/fpu/signal.c index 1e7cc114c186..083f03d2d002 100644 --- a/arch/x86/kernel/fpu/signal.c +++ b/arch/x86/kernel/fpu/signal.c @@ -36,14 +36,23 @@ static inline bool check_xstate_in_sigframe(struct fxregs_state __user *buf_fx, if (__copy_from_user(fx_sw, &buf_fx->sw_reserved[0], sizeof(*fx_sw))) return false; - /* Check for the first magic field and other error scenarios. */ + /* Check for the first magic field and other error scenarios. + * + * Do not enforce that fx_sw->xstate_size matches the task's + * fpstate->user_size. The frame could be saved on another CPU with a + * different set of xtate features. The actual set of used features is + * defined in the xsave header. If the buffer contains any unsupported + * feature states, it will be rejected. + */ if (fx_sw->magic1 != FP_XSTATE_MAGIC1 || fx_sw->xstate_size < min_xstate_size || - fx_sw->xstate_size > fpstate->user_size || fx_sw->xstate_size > fx_sw->extended_size || fx_sw->extended_size - fx_sw->xstate_size < FP_XSTATE_MAGIC2_SIZE) goto err_setfx; + if (!access_ok(buf_fx, fx_sw->extended_size)) + goto err_setfx; + /* * Check for the presence of second magic word at the end of memory * layout. This detects the case where the user just copied the legacy -- 2.54.0.1189.g8c84645362-goog