From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S933128AbcHJSME (ORCPT ); Wed, 10 Aug 2016 14:12:04 -0400 Received: from terminus.zytor.com ([198.137.202.10]:56690 "EHLO terminus.zytor.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S932853AbcHJSLs (ORCPT ); Wed, 10 Aug 2016 14:11:48 -0400 Date: Wed, 10 Aug 2016 11:10:51 -0700 From: tip-bot for Borislav Petkov Message-ID: Cc: brgerst@gmail.com, jpoimboe@redhat.com, tglx@linutronix.de, torvalds@linux-foundation.org, hpa@zytor.com, dvlasenk@redhat.com, peterz@infradead.org, mingo@kernel.org, luto@kernel.org, linux-kernel@vger.kernel.org, bp@alien8.de, bp@suse.de, luto@amacapital.net Reply-To: peterz@infradead.org, luto@kernel.org, mingo@kernel.org, linux-kernel@vger.kernel.org, brgerst@gmail.com, tglx@linutronix.de, jpoimboe@redhat.com, torvalds@linux-foundation.org, hpa@zytor.com, dvlasenk@redhat.com, luto@amacapital.net, bp@suse.de, bp@alien8.de In-Reply-To: <20160803171429.GA2590@nazgul.tnic> References: <20160803171429.GA2590@nazgul.tnic> To: linux-tip-commits@vger.kernel.org Subject: [tip:x86/urgent] x86/entry: Clarify the RF saving/restoring situation with SYSCALL/SYSRET Git-Commit-ID: 3e035305875cfa8a58c1ca573d0cfa6a7f201f27 X-Mailer: tip-git-log-daemon Robot-ID: Robot-Unsubscribe: Contact to get blacklisted from these emails MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Content-Type: text/plain; charset=UTF-8 Content-Disposition: inline Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Commit-ID: 3e035305875cfa8a58c1ca573d0cfa6a7f201f27 Gitweb: http://git.kernel.org/tip/3e035305875cfa8a58c1ca573d0cfa6a7f201f27 Author: Borislav Petkov AuthorDate: Wed, 3 Aug 2016 19:14:29 +0200 Committer: Ingo Molnar CommitDate: Wed, 10 Aug 2016 15:53:43 +0200 x86/entry: Clarify the RF saving/restoring situation with SYSCALL/SYSRET Clarify why exactly RF cannot be restored properly by SYSRET to avoid confusion. No functionality change. Signed-off-by: Borislav Petkov Acked-by: Andy Lutomirski Cc: Andy Lutomirski Cc: Borislav Petkov Cc: Brian Gerst Cc: Denys Vlasenko Cc: H. Peter Anvin Cc: Josh Poimboeuf Cc: Linus Torvalds Cc: Peter Zijlstra Cc: Thomas Gleixner Link: http://lkml.kernel.org/r/20160803171429.GA2590@nazgul.tnic Signed-off-by: Ingo Molnar --- arch/x86/entry/entry_64.S | 14 +++++++++----- 1 file changed, 9 insertions(+), 5 deletions(-) diff --git a/arch/x86/entry/entry_64.S b/arch/x86/entry/entry_64.S index 9f85827..d172c61 100644 --- a/arch/x86/entry/entry_64.S +++ b/arch/x86/entry/entry_64.S @@ -288,11 +288,15 @@ return_from_SYSCALL_64: jne opportunistic_sysret_failed /* - * SYSRET can't restore RF. SYSRET can restore TF, but unlike IRET, - * restoring TF results in a trap from userspace immediately after - * SYSRET. This would cause an infinite loop whenever #DB happens - * with register state that satisfies the opportunistic SYSRET - * conditions. For example, single-stepping this user code: + * SYSCALL clears RF when it saves RFLAGS in R11 and SYSRET cannot + * restore RF properly. If the slowpath sets it for whatever reason, we + * need to restore it correctly. + * + * SYSRET can restore TF, but unlike IRET, restoring TF results in a + * trap from userspace immediately after SYSRET. This would cause an + * infinite loop whenever #DB happens with register state that satisfies + * the opportunistic SYSRET conditions. For example, single-stepping + * this user code: * * movq $stuck_here, %rcx * pushfq