The Linux Kernel Mailing List
 help / color / mirror / Atom feed
From: Aruna Ramakrishna <aruna.ramakrishna@oracle.com>
To: linux-kernel@vger.kernel.org
Cc: x86@kernel.org, dave.hansen@linux.intel.com, tglx@linutronix.de,
	mingo@kernel.org, keith.lucas@oracle.com,
	aruna.ramakrishna@oracle.com
Subject: [PATCH v5 3/5] x86/pkeys: Update PKRU to enable minimally required pkeys before XSAVE
Date: Thu,  6 Jun 2024 22:40:33 +0000	[thread overview]
Message-ID: <20240606224035.3238985-4-aruna.ramakrishna@oracle.com> (raw)
In-Reply-To: <20240606224035.3238985-1-aruna.ramakrishna@oracle.com>

If the alternate signal stack is protected by a different pkey than the
current execution stack, copying xsave data to the sigaltstack will fail
if its pkey is not enabled. Enable the extra pkey needed, before xsave,
so that the signal handler accessibility is not dictated by the PKRU
value that the thread sets up. But this updated PKRU value is also
pushed onto the sigframe, so overwrite that with the original, user-defined
PKRU value so that the value restored from sigcontext does not have the extra
pkey enabled.

Signed-off-by: Aruna Ramakrishna <aruna.ramakrishna@oracle.com>
---
 arch/x86/kernel/fpu/signal.c | 10 ++++++++--
 arch/x86/kernel/signal.c     | 10 +++++++++-
 2 files changed, 17 insertions(+), 3 deletions(-)

diff --git a/arch/x86/kernel/fpu/signal.c b/arch/x86/kernel/fpu/signal.c
index b0b254b931fd..1065ab995305 100644
--- a/arch/x86/kernel/fpu/signal.c
+++ b/arch/x86/kernel/fpu/signal.c
@@ -168,8 +168,14 @@ static inline bool save_xstate_epilog(void __user *buf, int ia32_frame,
 
 static inline int copy_fpregs_to_sigframe(struct xregs_state __user *buf, u32 pkru)
 {
-	if (use_xsave())
-		return xsave_to_user_sigframe(buf);
+	int err = 0;
+
+	if (use_xsave()) {
+		err = xsave_to_user_sigframe(buf);
+		if (!err)
+			err = update_pkru_in_sigframe(buf, pkru);
+		return err;
+	}
 
 	if (use_fxsr())
 		return fxsave_to_user_sigframe((struct fxregs_state __user *) buf);
diff --git a/arch/x86/kernel/signal.c b/arch/x86/kernel/signal.c
index 3fa66b2fe753..659faf076b48 100644
--- a/arch/x86/kernel/signal.c
+++ b/arch/x86/kernel/signal.c
@@ -243,8 +243,8 @@ static void
 handle_signal(struct ksignal *ksig, struct pt_regs *regs)
 {
 	struct fpu *fpu = &current->thread.fpu;
-	u32 pkru = read_pkru();
 	bool stepping, failed;
+	u32 pkru;
 
 	if (v8086_mode(regs))
 		save_v86_state((struct kernel_vm86_regs *) regs, VM86_SIGNAL);
@@ -280,6 +280,8 @@ handle_signal(struct ksignal *ksig, struct pt_regs *regs)
 	if (stepping)
 		user_disable_single_step(current);
 
+	/* Update PKRU to enable access to the alternate signal stack. */
+	pkru = sig_prepare_pkru();
 	failed = (setup_rt_frame(ksig, regs, pkru) < 0);
 	if (!failed) {
 		/*
@@ -297,6 +299,12 @@ handle_signal(struct ksignal *ksig, struct pt_regs *regs)
 		 * Ensure the signal handler starts with the new fpu state.
 		 */
 		fpu__clear_user_states(fpu);
+	} else {
+		/*
+		 * Restore PKRU to the original, user-defined value; disable
+		 * extra pkeys enabled for the alternate signal stack, if any.
+		 */
+		write_pkru(pkru);
 	}
 	signal_setup_done(failed, ksig, stepping);
 }
-- 
2.39.3


  parent reply	other threads:[~2024-06-06 22:40 UTC|newest]

Thread overview: 20+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2024-06-06 22:40 [PATCH v5 0/5] x86/pkeys: update PKRU to enable pkey 0 before XSAVE Aruna Ramakrishna
2024-06-06 22:40 ` [PATCH v5 1/5] x86/pkeys: Add PKRU as a parameter in signal handling functions Aruna Ramakrishna
2024-06-10 21:31   ` Re " jeffxu
2024-06-11 13:56     ` Aruna Ramakrishna
2024-06-11 21:26       ` Jeff Xu
2024-06-06 22:40 ` [PATCH v5 2/5] x86/pkeys: Add helper functions to update PKRU on sigframe Aruna Ramakrishna
2024-06-10 21:39   ` Re " jeffxu
2024-06-11 14:05     ` Aruna Ramakrishna
2024-06-11 22:13       ` Jeff Xu
2024-06-17 16:43         ` Aruna Ramakrishna
2024-06-20 19:23           ` Jeff Xu
2024-06-06 22:40 ` Aruna Ramakrishna [this message]
2024-06-06 22:40 ` [PATCH v5 4/5] x86/pkeys: Restore altstack before sigcontext Aruna Ramakrishna
2024-06-10 21:44   ` Re " jeffxu
2024-06-11 14:08     ` Aruna Ramakrishna
2024-06-11 22:16       ` Jeff Xu
2024-06-06 22:40 ` [PATCH v5 5/5] selftests/mm: Add new testcases for pkeys Aruna Ramakrishna
2024-06-10 21:21 ` Re [PATCH v5 0/5] x86/pkeys: update PKRU to enable pkey 0 before XSAVE jeffxu
2024-06-26 16:51 ` Aruna Ramakrishna
2024-06-26 16:56   ` Dave Hansen

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20240606224035.3238985-4-aruna.ramakrishna@oracle.com \
    --to=aruna.ramakrishna@oracle.com \
    --cc=dave.hansen@linux.intel.com \
    --cc=keith.lucas@oracle.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=mingo@kernel.org \
    --cc=tglx@linutronix.de \
    --cc=x86@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox