From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-oi1-f202.google.com (mail-oi1-f202.google.com [209.85.167.202]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id F09883B42FC for ; Mon, 15 Jun 2026 19:37:28 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.167.202 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781552250; cv=none; b=NZfPeSMnjE8OLMFr5bOcqHQQtjVzV7FjGrmOYg/J5MgrM6gqeFh9aA+7iCLEYJMIKQ1ELS7xIf4juVnWO9Z8dbEsEoEP08qFsXoNbPHAkX+EaIniJaHPR1vCQoW4i1v5mlwo8D1wTPFVZm5RQIoBmW4GEX6jPgnKGEUJSTBwjPk= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781552250; c=relaxed/simple; bh=bXzVMvf00CwaDW2BdpcjOitoe3RTqdjV/Gub/nx2BFM=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=kQTsbdFRNcvDcr9r0E9kKLAng696jmJIaHYB5FIQ6DJAdfZdiG4BM8keqaZUe5+AsFiiLH7F6xMp/b9CPImKjJ/srOy16cC5NDYXk0f+MiMmVQuotPoATitfQTcpZHUFZ0518y+b55veta5fesQA8h9jN5CpOo4yxpbnhFI5ECA= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--avagin.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=lexj3otv; arc=none smtp.client-ip=209.85.167.202 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--avagin.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="lexj3otv" Received: by mail-oi1-f202.google.com with SMTP id 5614622812f47-48651d7d505so5661262b6e.0 for ; Mon, 15 Jun 2026 12:37:28 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1781552248; x=1782157048; darn=vger.kernel.org; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:from:to:cc:subject:date:message-id:reply-to; bh=ha+0I+6ZDIJiKCZ5+IILJRvoIGkLQAgCmsAOlCVxgqY=; b=lexj3otvNyLNJr/iDGNPvvLvVuDalNYtUiEptiThShNX9NIhSl57utaBtiBaBJ2Aj3 G2ZDb07MUYvWPjT1sURAJkd42DbRtuLnngx/ZeI8D9wpNEdhZPqHJjywh6m5dOZt87i6 Uz4r4rP7ajxCiwbOkc9wlJKgEfIODSMAkPsWhAdIcLlVcj6tgcszfNmwsTFFwULFHWS9 IHr9s7ezELYG9S7mqUKB2WZmRZ/219ipy8rGuKBAgKwrb9zgTGY79lDAQVYzBo3dr6OV D2Z32dYvp+3u8/EKbGt2l2/5oNNHkuoh2l2/AKbznFUXXU7J803KcAK/qbApm2+5K/Je BxHQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1781552248; x=1782157048; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=ha+0I+6ZDIJiKCZ5+IILJRvoIGkLQAgCmsAOlCVxgqY=; b=N93/6x6sKnTTMEWIoQhj+QQ8uvC9l0Z7brymTPUhptrX0pT2dT1pdm9BjpohM5I4L+ CKnSqeQd4MColY2ASaZ6Bzbew5bFkicD4sNtnTya7ltJzV1qaV1GinxEtnZctPqpesSq LtPIMulg+uUvZ/S4b1kyYGCUeBmclRVi7agev2676V4/Wn+hOoFyW/qvr3RShNWqEXdm Iy7pM1emnewZOmtxALa000XdyF6r1hGMPXpEikFZc/YAv/k0Kiy0B+c0SDH+i2IYH4Zb K+4TRrNovaSHTVkqgmbSM6GLys5IbUFquIpiKNNxbdHA/YPYMWDeISnTE5u+SnChwoZG dYhA== X-Gm-Message-State: AOJu0YxOogPgrLqofZuc9a3jTG02zxL3wN9l8fC3fnnE7KBxej07cYPm /ijd+x14kTHgJHum7RixEX/818pdsIFCgfp4qNUadfjeQP5dLQwarrWLx+RxHenmfEE/D0F1yuB ZJvXb7w== X-Received: from iog19-n1.prod.google.com ([2002:a05:6602:80d3:10b0:998:cd1c:ff96]) (user=avagin job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6808:1454:b0:485:5982:4cfc with SMTP id 5614622812f47-48741be6334mr8179218b6e.33.1781552247642; Mon, 15 Jun 2026 12:37:27 -0700 (PDT) Date: Mon, 15 Jun 2026 19:37:10 +0000 In-Reply-To: <20260615193716.1843340-1-avagin@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260615193716.1843340-1-avagin@google.com> X-Mailer: git-send-email 2.54.0.1189.g8c84645362-goog Message-ID: <20260615193716.1843340-5-avagin@google.com> Subject: [PATCH 04/10] x86/fpu: Document reasoning of FX-only fallback From: Andrei Vagin To: Thomas Gleixner , Ingo Molnar , Borislav Petkov , "Chang S. Bae" Cc: linux-kernel@vger.kernel.org, criu@lists.linux.dev, Dave Hansen , x86@kernel.org, Andrei Vagin , "H. Peter Anvin" Content-Type: text/plain; charset="UTF-8" Add a comment to check_xstate_in_sigframe() to explain reasoning behind falling back to the FX-only state when signal frame metadata is inconsistent. The fallback is intended to preserve backward compatibility with legacy user-space processes that are not aware of XSAVE states and might only fill or copy just the legacy FP state. This fallback is dangerous as it can trigger silent corruptions of user-space state by resetting extended registers if the process was using them but the frame metadata was malformed. XSAVE was introduced 15 years ago, we may need to consider removing this fallback entirely or introducing a sysctl to enable/disable it. Signed-off-by: Andrei Vagin --- arch/x86/kernel/fpu/signal.c | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/arch/x86/kernel/fpu/signal.c b/arch/x86/kernel/fpu/signal.c index 6a14b528ac7f..85021c5ea649 100644 --- a/arch/x86/kernel/fpu/signal.c +++ b/arch/x86/kernel/fpu/signal.c @@ -54,6 +54,14 @@ static inline bool check_xstate_in_sigframe(struct fxregs_state __user *buf_fx, if (likely(magic2 == FP_XSTATE_MAGIC2)) return true; err_setfx: + /* + * The fallback to FX-only state is used to preserve backward + * compatibility with user-space processes that are not aware of xsave + * states. + * + * In all other cases, returning false (to trigger SIGSEGV) is + * preferred to avoid silent user-space state corruption. + */ trace_x86_fpu_xstate_check_failed(x86_task_fpu(current)); /* Set the parameters for fx only state */ -- 2.54.0.1189.g8c84645362-goog