From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-oi1-f201.google.com (mail-oi1-f201.google.com [209.85.167.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 25C3C3B47C9 for ; Mon, 15 Jun 2026 19:37:37 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.167.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781552262; cv=none; b=iEEidR0+CKCqa+6Rte6Fh2458ASouB7uLHr3/ktK09G2DQblDLOCp4Otd/gK3unbpL1hYcZQfLu++rwSjTfN/D9965SXmpSndJxnoFFsGWlfX/NT3IHz/raI38w15FY3hRwYLfz0GU4i3QaOtSdKii/iED8UT47Q/CbBgYdjkjo= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781552262; c=relaxed/simple; bh=NHt0vZ1Ltm/gQV39HJkjefrkirx2BoxzKydrn1QM0wU=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=FjCs4t3BOMlmhgOcohQS11RqcMCYCaQGURkFVGP2nQbQ4IBmsANDzL2EuKiInI3TFgo2xfXPOUx4cQacD4cZ0iiKinWRc/9SGcUCEjzMaZvK874u2Ynffln/IIQyNXtYC1cZT+xmG3bpp1+2zCSVHIUl5M5xCBarWlB9O65X/ow= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--avagin.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=d8ux5BHl; arc=none smtp.client-ip=209.85.167.201 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--avagin.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="d8ux5BHl" Received: by mail-oi1-f201.google.com with SMTP id 5614622812f47-48637dce961so4205804b6e.0 for ; Mon, 15 Jun 2026 12:37:36 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1781552256; x=1782157056; darn=vger.kernel.org; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:from:to:cc:subject:date:message-id:reply-to; bh=pkEM6/4vRnWHsxPwymmU+f7NCSNhQj17Xg5t7cTI7xg=; b=d8ux5BHluVKW5uSvSWZcrrtPU/XTCERfQ7LyiY3Onpfga/I8vS3eEoZieONAgNraUR 9pT/0qshjGNbqyHkCeqke+fZPkftNUaKD6kd414Cr0qtTLPluCapklmsKIZQjHHm6Sdc m4ZOlLTlatHajjTJcgC1TiMqWD72XqMMK4ntWzM6JTdJxBCrXsYqm8MATUfl0TOxMPjq 71NyfL1ZfDzEtxRsEz97ZynKJ+3wPQ55gPZOEJiHR6wnZv9F5UIpfkI2GxKll8o/BqQe WvZmmTgGp1pCcs8QtN9O0cydnMmLyG7qUtFm0VCrgqlXct8h/spM6Ir61O7pEVQoYbjn AzMQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1781552256; x=1782157056; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=pkEM6/4vRnWHsxPwymmU+f7NCSNhQj17Xg5t7cTI7xg=; b=dX4Y9rgyWYvIHDCWN/Wtgn04kb6REfZuXBtyNVer5+hpNnx/yydVrKAAIQ/jhs/ojR Z+PcSPBFhn49ifdl5sRHJh7FAMPoxg9/PIkoT+68jRQTSdJhu7zzrqHPYm+eZWDChUqD j8uFJRZDD6UANxWhwjWy1Fut59SPxt7CcqTyNSlr/uhnDUpklum2pb66zhlRn+MPoMWG X3p+Rq6wYWEob8oBD/QZH7HXHceSiAZyIUfC2+iYk8VKrorkeg8awMD920svvgKppeK1 YBJVSNu2s3tb6LgfrvzrADTv01IP1+6gspmgkVa59iq7HgYpICtqp1ParJjdyWoUl7cU F2lg== X-Gm-Message-State: AOJu0YyGHkr8SW32HN0Nru3gp17Xspc0uaj7FalXrv3aheFSY+x+WbBw tOe28vXPApcnbkSHmhLo9Zm0j/fokZF2ucjJZyosgj8eOviiFZhF+6Hdnsee+uN9OEwFEmkq4q1 H1gQqCw== X-Received: from jabjz5.prod.google.com ([2002:a05:6638:a385:b0:5e2:9f74:d3aa]) (user=avagin job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6808:1486:b0:482:6b8a:33a6 with SMTP id 5614622812f47-48741b05e11mr10904664b6e.23.1781552255940; Mon, 15 Jun 2026 12:37:35 -0700 (PDT) Date: Mon, 15 Jun 2026 19:37:15 +0000 In-Reply-To: <20260615193716.1843340-1-avagin@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260615193716.1843340-1-avagin@google.com> X-Mailer: git-send-email 2.54.0.1189.g8c84645362-goog Message-ID: <20260615193716.1843340-10-avagin@google.com> Subject: [PATCH 09/10] x86/fpu: Allow restoring signal frames with larger xstate_size From: Andrei Vagin To: Thomas Gleixner , Ingo Molnar , Borislav Petkov , "Chang S. Bae" Cc: linux-kernel@vger.kernel.org, criu@lists.linux.dev, Dave Hansen , x86@kernel.org, Andrei Vagin , "H. Peter Anvin" Content-Type: text/plain; charset="UTF-8" The kernel previously enforced that the xstate_size in the signal frame must not exceed the current task's fpstate->user_size. This prevents restoring signal frames that were saved on another CPU (in case of container/process migration) with a different (larger) set of enabled xstate features, even if the features to be restored are compatible. Relax this restriction by removing the strict check against user_size. The previous commit introduced infrastructure to calculate the actual required size based on the intersection of requested and supported features. We now rely on that validation and only require that the provided xstate_size is sufficient for the active features. Signed-off-by: Andrei Vagin --- arch/x86/kernel/fpu/signal.c | 13 +++++++++++-- 1 file changed, 11 insertions(+), 2 deletions(-) diff --git a/arch/x86/kernel/fpu/signal.c b/arch/x86/kernel/fpu/signal.c index 1e7cc114c186..083f03d2d002 100644 --- a/arch/x86/kernel/fpu/signal.c +++ b/arch/x86/kernel/fpu/signal.c @@ -36,14 +36,23 @@ static inline bool check_xstate_in_sigframe(struct fxregs_state __user *buf_fx, if (__copy_from_user(fx_sw, &buf_fx->sw_reserved[0], sizeof(*fx_sw))) return false; - /* Check for the first magic field and other error scenarios. */ + /* Check for the first magic field and other error scenarios. + * + * Do not enforce that fx_sw->xstate_size matches the task's + * fpstate->user_size. The frame could be saved on another CPU with a + * different set of xtate features. The actual set of used features is + * defined in the xsave header. If the buffer contains any unsupported + * feature states, it will be rejected. + */ if (fx_sw->magic1 != FP_XSTATE_MAGIC1 || fx_sw->xstate_size < min_xstate_size || - fx_sw->xstate_size > fpstate->user_size || fx_sw->xstate_size > fx_sw->extended_size || fx_sw->extended_size - fx_sw->xstate_size < FP_XSTATE_MAGIC2_SIZE) goto err_setfx; + if (!access_ok(buf_fx, fx_sw->extended_size)) + goto err_setfx; + /* * Check for the presence of second magic word at the end of memory * layout. This detects the case where the user just copied the legacy -- 2.54.0.1189.g8c84645362-goog