From: "Chang S. Bae" <chang.seok.bae@intel.com>
To: Andrei Vagin <avagin@google.com>,
Thomas Gleixner <tglx@kernel.org>,
"Ingo Molnar" <mingo@redhat.com>, Borislav Petkov <bp@alien8.de>
Cc: <linux-kernel@vger.kernel.org>, <criu@lists.linux.dev>,
Dave Hansen <dave.hansen@linux.intel.com>, <x86@kernel.org>,
Alexander Mikhalitsyn <alexander@mihalicyn.com>,
"H. Peter Anvin" <hpa@zytor.com>
Subject: Re: [PATCH 7/8] x86/fpu: Pre-fault only required size of xstate buffer
Date: Wed, 2 Sep 2026 14:15:55 -0700 [thread overview]
Message-ID: <36269f7b-a76f-47ee-93da-2f6bdc3d111f@intel.com> (raw)
In-Reply-To: <20260817042048.1579415-8-avagin@google.com>
On 8/16/2026 9:20 PM, Andrei Vagin wrote:
> The kernel previously used the default task FPU state size (user_size)
> to fault in the user buffer when restoring FPU registers from a signal
> frame. This can lead to attempting to fault in memory past the end of
> the actual frame if the frame was smaller than the default size.
>
> Introduce consistency checks to calculate the actual required size for
> the features enabled in the xfeatures mask, ensure that the provided
> xstate_size is sufficient, and shrink it to the actual required size.
> Use this validated size to fault in the user buffer.
>
> Keep the strict check that the provided xstate_size does not exceed the
> default user_size for now.
I think this consistency check should have been there already. Thanks!
Reviewed-by: Chang S. Bae <chang.seok.bae@intel.com>
Thanks,
Chang
next prev parent reply other threads:[~2026-09-02 21:16 UTC|newest]
Thread overview: 16+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-17 4:20 [PATCH v4 0/8] x86/fpu: Restore and reinforce signal frame portability Andrei Vagin
2026-08-17 4:20 ` [PATCH 1/8] x86/fpu: Document " Andrei Vagin
2026-09-02 21:15 ` Chang S. Bae
2026-09-03 4:51 ` Borislav Petkov
2026-08-17 4:20 ` [PATCH 2/8] x86/fpu: Clean up and rename variables in signal frame handling Andrei Vagin
2026-08-17 4:20 ` [PATCH 3/8] x86/fpu: Split __fpu_restore_sig to extract compat path Andrei Vagin
2026-09-02 21:15 ` Chang S. Bae
2026-08-17 4:20 ` [PATCH 4/8] x86/fpu: Document reasoning of FX-only fallback Andrei Vagin
2026-09-02 21:15 ` Chang S. Bae
2026-08-17 4:20 ` [PATCH 5/8] selftests/x86: Add a test for signal frame FPU portability Andrei Vagin
2026-08-17 4:20 ` [PATCH 6/8] x86/fpu: Fix potential underflow in xstate_calculate_size() Andrei Vagin
2026-09-02 21:15 ` Chang S. Bae
2026-08-17 4:20 ` [PATCH 7/8] x86/fpu: Pre-fault only required size of xstate buffer Andrei Vagin
2026-09-02 21:15 ` Chang S. Bae [this message]
2026-08-17 4:20 ` [PATCH 8/8] selftests/x86: Add a sigframe insufficient xstate_size test Andrei Vagin
2026-09-02 21:16 ` Chang S. Bae
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=36269f7b-a76f-47ee-93da-2f6bdc3d111f@intel.com \
--to=chang.seok.bae@intel.com \
--cc=alexander@mihalicyn.com \
--cc=avagin@google.com \
--cc=bp@alien8.de \
--cc=criu@lists.linux.dev \
--cc=dave.hansen@linux.intel.com \
--cc=hpa@zytor.com \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@redhat.com \
--cc=tglx@kernel.org \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.