All of lore.kernel.org
 help / color / mirror / Atom feed
From: Bill Roberts <bill.roberts@arm.com>
To: rick.p.edgecombe@intel.com, Thomas Gleixner <tglx@kernel.org>,
	Ingo Molnar <mingo@redhat.com>, Borislav Petkov <bp@alien8.de>,
	Dave Hansen <dave.hansen@linux.intel.com>,
	x86@kernel.org, "H. Peter Anvin" <hpa@zytor.com>
Cc: Bill Roberts <bill.roberts@arm.com>, linux-kernel@vger.kernel.org
Subject: [PATCH v2 1/2] arch/x86: handle ARCH_SHSTK_ENABLE explicitly
Date: Tue,  7 Jul 2026 14:11:35 -0500	[thread overview]
Message-ID: <20260707191136.1732277-1-bill.roberts@arm.com> (raw)

The arch_prctl() handling for shadow stack operations checks that the
operation being specified is a specific value, except for the
ARCH_SHSTK_ENABLE condition, which is treated like a default case in a
switch.

However, the special handling for ARCH_SHSTK_UNLOCK is only performed when
task != current. As a result, an ARCH_SHSTK_UNLOCK request for the current
task bypasses the unlock check and falls through to the ARCH_SHSTK_ENABLE
path, causing the request to be interpreted as an enable operation
instead.

To fix this, handle ARCH_SHSTK_ENABLE explicitly rather than relying on it
as the default case. This fixes the incorrect dispatch and makes the
operation handling more robust by requiring each operation to be matched
explicitly.

Signed-off-by: Bill Roberts <bill.roberts@arm.com>
---
 arch/x86/kernel/shstk.c | 12 +++++++-----
 1 file changed, 7 insertions(+), 5 deletions(-)

diff --git a/arch/x86/kernel/shstk.c b/arch/x86/kernel/shstk.c
index 0ca64900192f..65c896d02379 100644
--- a/arch/x86/kernel/shstk.c
+++ b/arch/x86/kernel/shstk.c
@@ -607,11 +607,13 @@ long shstk_prctl(struct task_struct *task, int option, unsigned long arg2)
 		return -EINVAL;
 	}
 
-	/* Handle ARCH_SHSTK_ENABLE */
-	if (features & ARCH_SHSTK_SHSTK)
-		return shstk_setup();
-	if (features & ARCH_SHSTK_WRSS)
-		return wrss_control(true);
+	if (option == ARCH_SHSTK_ENABLE) {
+		if (features & ARCH_SHSTK_SHSTK)
+			return shstk_setup();
+		if (features & ARCH_SHSTK_WRSS)
+			return wrss_control(true);
+	}
+
 	return -EINVAL;
 }
 
-- 
2.54.0


             reply	other threads:[~2026-07-07 19:11 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-07 19:11 Bill Roberts [this message]
2026-07-07 19:11 ` [PATCH v2 2/2] selftest/x86: test ARCH_SHSTK_UNLOCK Bill Roberts
2026-08-27 23:32   ` Edgecombe, Rick P
2026-09-09 18:47     ` Bill Roberts
2026-09-09 18:58       ` Edgecombe, Rick P
2026-09-09 20:25     ` Bill Roberts

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260707191136.1732277-1-bill.roberts@arm.com \
    --to=bill.roberts@arm.com \
    --cc=bp@alien8.de \
    --cc=dave.hansen@linux.intel.com \
    --cc=hpa@zytor.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=mingo@redhat.com \
    --cc=rick.p.edgecombe@intel.com \
    --cc=tglx@kernel.org \
    --cc=x86@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.