From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 93221329392 for ; Thu, 12 Feb 2026 13:05:56 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.129.124 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1770901557; cv=none; b=J5VVmZsVmG3AWi0yo9Q3wbVO7alsjIp01dirj1JUhi8AvptVG9XZsSSeMd1ZjXgH4VpQ+3aihyjREfQObS/JnnAV251BDmVEoFwVwy+DaqbIK/mmOsJu+hFLgzpWR/ke3GstXBShfg4UidwDldynB+/S5dIHw2Bo6X+27mb35ps= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1770901557; c=relaxed/simple; bh=fubshRHZOK3xcw1lnexFbYnDXHYBcCIwqojSGjudTdg=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=nBbGNRnjcC5pVDaqg8bJmTAOGCVdv+PoQ2ge0wu/lYwcn3SG0eyWqza6GCdg0sZW+R9iA8rFZZSq6DIwvxYHm3Bp6MQrBwL09xWszyojvdm5hwQ+QZXa7+WDT1hy4Yv2xU1sfSByhhEVUFMCdL+G+OYi6uwAUjupk+UR13El+80= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=DT4rVY1a; dkim=pass (2048-bit key) header.d=redhat.com header.i=@redhat.com header.b=mwRf3Cc6; arc=none smtp.client-ip=170.10.129.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="DT4rVY1a"; dkim=pass (2048-bit key) header.d=redhat.com header.i=@redhat.com header.b="mwRf3Cc6" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1770901555; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=fAwi/lFTFJWF8aYR9HamB7ruEzLXva1BZO763+SUKAI=; b=DT4rVY1aom1S17w11VGFPLSe1/gS2d9J5VfjkhVWIHfzmHMYsZbUygGn0ABl6BYPBVo5JQ 2SyCAIiX2AR9v/DjReG3icHosN2lzql6u55EwnWHIUoYpTEZUtN6lsQTdhEXSjhnh8Rh7Z uFWxoOoTH49YDpN7rJmue97cIs16rcM= Received: from mail-wm1-f69.google.com (mail-wm1-f69.google.com [209.85.128.69]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-607-AOVuEshvOTekMjfiZuvfUg-1; Thu, 12 Feb 2026 08:05:53 -0500 X-MC-Unique: AOVuEshvOTekMjfiZuvfUg-1 X-Mimecast-MFC-AGG-ID: AOVuEshvOTekMjfiZuvfUg_1770901552 Received: by mail-wm1-f69.google.com with SMTP id 5b1f17b1804b1-482eec44485so24083495e9.3 for ; Thu, 12 Feb 2026 05:05:53 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1770901552; x=1771506352; darn=vger.kernel.org; h=content-transfer-encoding:in-reply-to:content-language:from :references:cc:to:subject:user-agent:mime-version:date:message-id :from:to:cc:subject:date:message-id:reply-to; bh=fAwi/lFTFJWF8aYR9HamB7ruEzLXva1BZO763+SUKAI=; b=mwRf3Cc6iWRUG+N8VN114AYMDprcEVmzkdLBljH0nLfXPLlgLoRM9R8KqiVtM+NXSy GASI8i5vbVZcprp7OSYKYdrabwb+izvESRs42C+QWjwDszgaWlx/r/WPBRaw8QwsEjbG JJx9JGScmG9E8SAwzjdS9AZyrCosPYZdzwwTrq37S74NHdUwqNPB5C1hZ0we5ioFHHk+ JuqpvB3dNb5Dw7DHdFenPgQYHhaWbtWe9Xi+KOfwn8f7rIT5UAAlJIqquDEEALaLijVO b7EaJo+twHvPOYuiEDesBL8PWtmIjcxvhJZxXKQ7sUF/DAH1/et5RbAjJJbx++uJQF1r 3rpg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1770901552; x=1771506352; h=content-transfer-encoding:in-reply-to:content-language:from :references:cc:to:subject:user-agent:mime-version:date:message-id :x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=fAwi/lFTFJWF8aYR9HamB7ruEzLXva1BZO763+SUKAI=; b=ElcdzfnMNd339Tx+MrL4F50YS5j8pSd0zTI5cJu+2x37xC05iVrNcBXhFAEfVJJ6Bs EhwzFo3LSSWAYSChuh5fB/uz1/cVRyKxVV7VQst1SsFUcQTF057AynU/4DPmpCz7Ku1b 4RuJrNfyS1VUJfebLVcqMejJSpxcP3cSm4WtLkk0osCLpcTxgCH8QAwvnau66H1+d95g P3XSLhPOPC31KFDfEq2XEVfoJjAdgMsNn2S2tPbRjXvlLJsWtI1J19UjfPP54cjkvgYs jOy9xkYU0L0n0ovJzFj5Pue/gFwOxDAW7dRjuX7ytWucIKgPZOCNR2GBho88KYkOlVcC UEpg== X-Forwarded-Encrypted: i=1; AJvYcCUw0FFr1/PaQMDqh6C0covqj5QMpUliklLt8axsxARFv4OCIX8+fYeDWyKGpRlJg4TAZxMHZ+eLwLFpSVo=@vger.kernel.org X-Gm-Message-State: AOJu0Yzppasmw0YOb/t54IeKVSOBQAsC1aMpKQAVlqPStep+B5gEiSzB TIDjHiIbuYY1QEzhRTVePw/IVQ/sN/CahU2B6s8vSO61XDx+Tl8JQoDKpXp2rFBRvo+qM11k2+y ttWaK77C2hVuwh5FTv4NZhCS8xr0FHpUacuA7LbrIpxasrxQxiRJkN7bXZaZzWb0/sQ== X-Gm-Gg: AZuq6aLJshq6uuBcvdARH5Mn5HaWHhQXf82fRKUkJ6DHZ/ugTp1C0STvdUOGGYBZ8V8 TRdXxTz98M6pqCOPaD5MDl9MZ0hhvlIJ5O4G8OElfHYoUGg4/512gNzskYXS0f4JiZnUariqcWc tSUmpS9fmnEEAsSHFNAWvhHP9L3iyuMAISvyQhxD6O/7fnd5xbE8RtRXZnDjC55ge/eahEUNCcB luqmnz2WhSFK8QGcsA2u0qfT6rOQ47hCY/NYuhoLTjsWXvHr91o+N9kQNhWC/klZHCoGiFy/ofM mmAjRWooI4ExA9uhVlTYJRoo1pmRHCTncdEsnzpE0lLMJYIVw8dkLk+55AMY/dJyEAJiZfgELkM k0qFVk9rkURhQU0xqYDRX6BqGmBbvdr3y7K0mCw76I6iDOsZMW3BRghJ02FM/zzNz3u0WVVhmkM VXf3KjsA0eWdDDgiiRma3Xtt4/Q5r18ttGWmpOfZFWCuA8w5+bfWtb90B+Jg== X-Received: by 2002:a05:600c:154a:b0:483:348a:d3f3 with SMTP id 5b1f17b1804b1-48367165b8emr29244025e9.18.1770901552246; Thu, 12 Feb 2026 05:05:52 -0800 (PST) X-Received: by 2002:a05:600c:154a:b0:483:348a:d3f3 with SMTP id 5b1f17b1804b1-48367165b8emr29243495e9.18.1770901551816; Thu, 12 Feb 2026 05:05:51 -0800 (PST) Received: from [10.60.241.123] (93-38-190-72.ip72.fastwebnet.it. [93.38.190.72]) by smtp.googlemail.com with ESMTPSA id 5b1f17b1804b1-4835a627c96sm68629315e9.2.2026.02.12.05.05.48 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Thu, 12 Feb 2026 05:05:51 -0800 (PST) Message-ID: <0a1ad845-a15b-4901-a65c-2668580751ed@redhat.com> Date: Thu, 12 Feb 2026 14:05:44 +0100 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH] KVM: x86: Fix incorrect memory constraint for FXSAVE in emulator To: Uros Bizjak , kvm@vger.kernel.org, x86@kernel.org, linux-kernel@vger.kernel.org Cc: Sean Christopherson , Thomas Gleixner , Ingo Molnar , Borislav Petkov , Dave Hansen , "H. Peter Anvin" References: <20260212102854.15790-1-ubizjak@gmail.com> From: Paolo Bonzini Content-Language: en-US In-Reply-To: <20260212102854.15790-1-ubizjak@gmail.com> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit On 2/12/26 11:27, Uros Bizjak wrote: > The inline asm used to invoke FXSAVE in em_fxsave() and fxregs_fixup() > incorrectly specifies the memory operand as read-write ("+m"). FXSAVE > does not read from the destination operand; it only writes the current > FPU state to memory. > > Using a read-write constraint is incorrect and misleading, as it tells > the compiler that the previous contents of the buffer are consumed by > the instruction. In both cases, the buffer passed to FXSAVE is > uninitialized, and marking it as read-write can therefore create a > false dependency on uninitialized memory. > > Fix the constraint to write-only ("=m") to accurately describe the > instruction’s behavior and avoid implying that the buffer is read. IIRC FXSAVE/FXRSTOR may (at least on some microarchitectures?) leave reserved fields untouched. Intel suggests writing zeros first, and then the "+m" constraint would be the right one because "=m" would cause the memset to be dead. Paolo > No functional change intended. > > Signed-off-by: Uros Bizjak > Cc: Sean Christopherson > Cc: Paolo Bonzini > Cc: Thomas Gleixner > Cc: Ingo Molnar > Cc: Borislav Petkov > Cc: Dave Hansen > Cc: "H. Peter Anvin" > --- > arch/x86/kvm/emulate.c | 4 ++-- > 1 file changed, 2 insertions(+), 2 deletions(-) > > diff --git a/arch/x86/kvm/emulate.c b/arch/x86/kvm/emulate.c > index c8e292e9a24d..d60094080e3f 100644 > --- a/arch/x86/kvm/emulate.c > +++ b/arch/x86/kvm/emulate.c > @@ -3717,7 +3717,7 @@ static int em_fxsave(struct x86_emulate_ctxt *ctxt) > > kvm_fpu_get(); > > - rc = asm_safe("fxsave %[fx]", , [fx] "+m"(fx_state)); > + rc = asm_safe("fxsave %[fx]", , [fx] "=m"(fx_state)); > > kvm_fpu_put(); > > @@ -3741,7 +3741,7 @@ static noinline int fxregs_fixup(struct fxregs_state *fx_state, > struct fxregs_state fx_tmp; > int rc; > > - rc = asm_safe("fxsave %[fx]", , [fx] "+m"(fx_tmp)); > + rc = asm_safe("fxsave %[fx]", , [fx] "=m"(fx_tmp)); > memcpy((void *)fx_state + used_size, (void *)&fx_tmp + used_size, > __fxstate_size(16) - used_size); >