From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-oi1-f201.google.com (mail-oi1-f201.google.com [209.85.167.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id EBD6930C617 for ; Mon, 15 Jun 2026 19:37:28 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.167.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781552251; cv=none; b=p5VkZ9RX34RdNGnjHUZFGhWaNDBIz39Io2Yr+lax6sV+1SZmgVa8RO/WW7gDlzANFver1NW/56VeXnsXDMoq/CuRTp7QDNGEPNLQRQUsz5rbSuc1NfdwcR9qY9ykxCqGqxqub0aPr9UY6Bn4uAycn6C8Wo/+J2qpvMY/C8p4Les= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781552251; c=relaxed/simple; bh=bXzVMvf00CwaDW2BdpcjOitoe3RTqdjV/Gub/nx2BFM=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=ZJbm2McqPtXwOg0l6jrAIMezyjGWnV9BnKOblrJv9YAUn6nrjFvFnaNWhq/PkKEMiU097NnzOfvnUJmtSK7nkxlgjwb6tpJ2KsYrLD2vz0mly2XLfTJcRPEei89ugo8mqLTZE6iCcpchm93kPxWs9oCYHrxBesWEVlyJwkmM/8U= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--avagin.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=sidq4yuN; arc=none smtp.client-ip=209.85.167.201 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--avagin.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="sidq4yuN" Received: by mail-oi1-f201.google.com with SMTP id 5614622812f47-48687e7f161so7446798b6e.2 for ; Mon, 15 Jun 2026 12:37:28 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1781552248; x=1782157048; darn=lists.linux.dev; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:from:to:cc:subject:date:message-id:reply-to; bh=ha+0I+6ZDIJiKCZ5+IILJRvoIGkLQAgCmsAOlCVxgqY=; b=sidq4yuNJ90Pg4BHmPCF752RXgjp4v75qvDjTKCo+aSUKGJmV63NZF4jWhjzBspKCT 3kydKDbEo+wy+Za1lM/+sIBcOMaXgHB3nqVYjaL0ghYOweGj6gHQQXBHv565jLTu/FZ8 RerSSCdOcecJeeN2KNO98iawNgyzCa0Xkw74bzU8GmHbXajWF8/MlGDjqDH0sAT+1GDI d+FqsDju0xvWpXpDTUymMlZre/ZvvkRPpZoKizac39lhtNzOzQ95sN8qUwtSvKWy6kmc IyhPos6UL6KOZ01PI7U2DuKu2XXprx4+ak1jvQlSFj7GA2CPrvVL+GOrB3R8zCYyTbr0 3CmA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1781552248; x=1782157048; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=ha+0I+6ZDIJiKCZ5+IILJRvoIGkLQAgCmsAOlCVxgqY=; b=WHU309YUshklgzPYqGlg8vJD5B0wm6JQfttoKP8RHeQ6lqCqvQRrYXeclN72LD5L5K TeQnxwg4EKvcsI5Rkfg9a12rwr4U+vbfF4yQGLJkBiHo7CstCJCmYAbJDmvi0NIog8WO uP64rhprZrK/CF+TNlspQqe9G+XE867QaXSo77j2eRgdkTBfuEw510ZzfaTC8ucRO30V Zow7+xnF0eY+Tm3/3ActuVIgUjVHRqCtlwSuRidW+/C6FYIlNVaoIQDI4m6IHRNqLHHU X/X3FnTjpGAdeKUAPA2cusgJFnkrvDzC/zhVQqvOtpK8k7iCtC7Of+d17j/fdXM6M12Q vITw== X-Forwarded-Encrypted: i=1; AFNElJ9y9Os15vlU/iFc9cBi+3yLEjC9bYeBtTcfG1xFJbkquvpwnEuMDjAP3ZEJw6VMepjk1MrV@lists.linux.dev X-Gm-Message-State: AOJu0Yym5RHCWftIoM+2LYFWRK+Ad5gMT1Ugxq1YCcF5U8TA9dyK6ifR HRxaqJsVRIJJzP/ppjG5/TJXqBwTZAz40kxDY+ELlaWOcbOfku8E83vLHOfRKVv5vL865x7y8Db xozA/HQ== X-Received: from iog19-n1.prod.google.com ([2002:a05:6602:80d3:10b0:998:cd1c:ff96]) (user=avagin job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6808:1454:b0:485:5982:4cfc with SMTP id 5614622812f47-48741be6334mr8179218b6e.33.1781552247642; Mon, 15 Jun 2026 12:37:27 -0700 (PDT) Date: Mon, 15 Jun 2026 19:37:10 +0000 In-Reply-To: <20260615193716.1843340-1-avagin@google.com> Precedence: bulk X-Mailing-List: criu@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260615193716.1843340-1-avagin@google.com> X-Mailer: git-send-email 2.54.0.1189.g8c84645362-goog Message-ID: <20260615193716.1843340-5-avagin@google.com> Subject: [PATCH 04/10] x86/fpu: Document reasoning of FX-only fallback From: Andrei Vagin To: Thomas Gleixner , Ingo Molnar , Borislav Petkov , "Chang S. Bae" Cc: linux-kernel@vger.kernel.org, criu@lists.linux.dev, Dave Hansen , x86@kernel.org, Andrei Vagin , "H. Peter Anvin" Content-Type: text/plain; charset="UTF-8" Add a comment to check_xstate_in_sigframe() to explain reasoning behind falling back to the FX-only state when signal frame metadata is inconsistent. The fallback is intended to preserve backward compatibility with legacy user-space processes that are not aware of XSAVE states and might only fill or copy just the legacy FP state. This fallback is dangerous as it can trigger silent corruptions of user-space state by resetting extended registers if the process was using them but the frame metadata was malformed. XSAVE was introduced 15 years ago, we may need to consider removing this fallback entirely or introducing a sysctl to enable/disable it. Signed-off-by: Andrei Vagin --- arch/x86/kernel/fpu/signal.c | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/arch/x86/kernel/fpu/signal.c b/arch/x86/kernel/fpu/signal.c index 6a14b528ac7f..85021c5ea649 100644 --- a/arch/x86/kernel/fpu/signal.c +++ b/arch/x86/kernel/fpu/signal.c @@ -54,6 +54,14 @@ static inline bool check_xstate_in_sigframe(struct fxregs_state __user *buf_fx, if (likely(magic2 == FP_XSTATE_MAGIC2)) return true; err_setfx: + /* + * The fallback to FX-only state is used to preserve backward + * compatibility with user-space processes that are not aware of xsave + * states. + * + * In all other cases, returning false (to trigger SIGSEGV) is + * preferred to avoid silent user-space state corruption. + */ trace_x86_fpu_xstate_check_failed(x86_task_fpu(current)); /* Set the parameters for fx only state */ -- 2.54.0.1189.g8c84645362-goog