From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1752183AbbDRBG7 (ORCPT ); Fri, 17 Apr 2015 21:06:59 -0400 Received: from mga02.intel.com ([134.134.136.20]:20309 "EHLO mga02.intel.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751396AbbDRBG5 (ORCPT ); Fri, 17 Apr 2015 21:06:57 -0400 X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="5.11,598,1422950400"; d="scan'208";a="482452654" From: Andi Kleen To: x86@kernel.org Cc: linux-kernel@vger.kernel.org, Andi Kleen Subject: [PATCH] x86: Reset FPU on exec Date: Fri, 17 Apr 2015 18:06:54 -0700 Message-Id: <1429319214-27418-1-git-send-email-andi@firstfloor.org> X-Mailer: git-send-email 1.9.3 Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org From: Andi Kleen Currently we don't reset FPU state on exec. This can be seen as a (minor) security issue. The bigger issue however is that the AVX state also does not get reset. So a program that uses SSE without VZEROUPPER may get a large penalty. Always set the FPU to the init state at exec time. For the eager FPU case this restores the init state, for non eager it forces an init on the next FPU use. Signed-off-by: Andi Kleen --- arch/x86/include/asm/elf.h | 4 ++++ arch/x86/kernel/xsave.c | 5 +++++ 2 files changed, 9 insertions(+) diff --git a/arch/x86/include/asm/elf.h b/arch/x86/include/asm/elf.h index ca3347a..56ab629 100644 --- a/arch/x86/include/asm/elf.h +++ b/arch/x86/include/asm/elf.h @@ -90,6 +90,8 @@ extern unsigned int vdso32_enabled; #include +extern void reset_fpu(void); + #ifdef CONFIG_X86_32 #include @@ -110,6 +112,7 @@ extern unsigned int vdso32_enabled; _r->bx = 0; _r->cx = 0; _r->dx = 0; \ _r->si = 0; _r->di = 0; _r->bp = 0; \ _r->ax = 0; \ + reset_fpu(); \ } while (0) /* @@ -178,6 +181,7 @@ static inline void elf_common_init(struct thread_struct *t, t->fs = t->gs = 0; t->fsindex = t->gsindex = 0; t->ds = t->es = ds; + reset_fpu(); } #define ELF_PLAT_INIT(_r, load_addr) \ diff --git a/arch/x86/kernel/xsave.c b/arch/x86/kernel/xsave.c index cdc6cf9..520e505 100644 --- a/arch/x86/kernel/xsave.c +++ b/arch/x86/kernel/xsave.c @@ -741,3 +741,8 @@ void *get_xsave_addr(struct xsave_struct *xsave, int xstate) return (void *)xsave + xstate_comp_offsets[feature]; } EXPORT_SYMBOL_GPL(get_xsave_addr); + +void reset_fpu(void) +{ + drop_init_fpu(current); +} -- 1.9.3