From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wm1-f44.google.com (mail-wm1-f44.google.com [209.85.128.44]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 72D1428726E for ; Wed, 29 Jul 2026 00:43:23 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.44 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785285805; cv=none; b=e1BiEriDo8YF/U9TL623nbrPYseVtejWnL9mHzHJL1qJPBULgBnAxHjhLqz0pqFoSv95G9w0ukrvb0nErchu6mgACNZBEwnHvN0WGEBO1Zl/8cjyQtKzbERqEvV3bcHmjBeIgJybtYKotsXbrg/XWUpp7iGDPMrvTlDBzC5v5GQ= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785285805; c=relaxed/simple; bh=3/X/mr/YLaMPqkwboLnuUiwo3mFws+Ie2fvug+qqqyc=; h=From:To:Cc:Subject:Date:Message-Id:MIME-Version; b=XL2O2WgTMBfHO+4Ec7dsg+9bZql0UdUDq+rB3aCLmTEwiBZ2OTngPiWaU605c/BUW+GxFNdUx92EjtpKYSFYU6rv3VvTs/szUYJnX2IY3LLooPOr0Bto9NqLxtU4r+kmq80v2386TiHBYlp0m5LltV25VoAEC9If9zfs+2bFDOs= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=n5i7eNVI; arc=none smtp.client-ip=209.85.128.44 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="n5i7eNVI" Received: by mail-wm1-f44.google.com with SMTP id 5b1f17b1804b1-49555a0e68bso1760305e9.2 for ; Tue, 28 Jul 2026 17:43:23 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785285802; x=1785890602; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=7jYWGw53POFllg0ieqjSR4fZVEzdVp2GRfz+60jKrRk=; b=n5i7eNVIzxaXm9Sfx5OK2GexSelUK52YQs6LxUo60a/ysjqhbZZ2EFYT/bTFleP1b9 qgiBamvaC96ItttPI+vVKL7lj16lqrf3Beg4p5LflWAtUOqg1SkPAsr9WFRr1e6WavKk t7lqm6Zy2I2GsQqpNv7ZbXM2wPGXjrfIBVO4VmBVYbg4XTeDkFtiqgWeEOml/FV8cbyx fGkdv/gKhsL9dfQxheMpLpdyqluXtaz3pplZuGRQ3NSBzbU+fFufBvvJYW3I4aAFKrjK ptghdFW+xcHu2Rq+v+RJO3H3L7bmqg1QPCmVGlbBAMNGn7cCOC1aBjTuML6UcmKxqnG6 Muug== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785285802; x=1785890602; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=7jYWGw53POFllg0ieqjSR4fZVEzdVp2GRfz+60jKrRk=; b=lmBvGQuhCEO5rfB7mFqYPwwDZ4dtypTtapulf8CFq9xcgwtqFBjeWbjiupjODDzbjs JGyRngPudjoJ33msMt+HgExX8F5VtuXpr+dFNEHjQ4Ay8DHyOlDQ3alnMJm+Ay8euSdc HtBwDKtsjbExMlO57C/wdxsrZOhM4tbCPXQbENFaVlVlwd2Y9mDZpVcAvAHppTiv6fe3 z9d9qug8lYyEnmi07VzlgjQB7JiJNER5iDboyvbKwMhV5OVe1nibbYFUQUnZamxjVgoq gJ9T3jgc7SD1zzISlAdp6S1Ca1H64G7oDe27St3dWyRfLyfRz6CWP7TYxX1MlGUkKrvR k/1A== X-Forwarded-Encrypted: i=1; AHgh+Rr3c/ZZeRQAR+YkwPuJeV+RKhoY7F839VkJpIHY7qGOkuhFjzat/xH17NE2GUU8S6/d3Y23fbNNDTGVX3k=@vger.kernel.org X-Gm-Message-State: AOJu0YxeQnbonpFvasDD+VPo5JdXgS8+HpCmmn4EM+RD41RASLh1o8hC AbVb/Eku56CC9sIK264BNxOiH4y40Q4geolIyihDxb82pwFjAYxgyQ4E X-Gm-Gg: AR+sD10JJGCaY38tSwjK6YLBJGISOdp/4gIJkiUpuGHds4vx1Fxc2ylwXXIqFMG9ZBD UfwRYTIiZfjh4FHP6oqU3DIy8J9AlZzZiT3jDYyzgE3urz4itlW/ceJ5MD+YoxB6OvlulFi77KN hMve6sVq7RIXjm4zlxsqPrf5v5iGfiShgh9SyMNdBKF+UpGNqX8CBhSeLjrmKiEqKbq784YshGI KV0X3m7FeAPBgQ8Ah+Q0o1AV5qCm46mOt7okdWEri9o3mqQqb5TV+nyxpZR9nyltmqiWMJ8iuxZ MpWq2Y2iggDImX5cR2sitJSptn5asg6ElRajoAornMmlenSpu7fBb1Ug1m+Og5Oaiq9mpQZmbxt UzkSyPExonMADUgyPy7ajkvSVDeUq7rZ2OIQWQIiCtU3YHgwuqnExpYE5vOCNsvIji/WcfZ80gT PcI9AS1ffSA3xKAaE612JT6cih48HSb+LBRS2sSgcuM1IelHuSoupp/wHuLpXAi9t9R5QZADpjG W2Ah76QMcY+wFEzSyzm/h/k7+qc3tAVMqqkyOTDIbwIit62OmP+VgKcDEMFRawMU2JbeXIRBqyX rPygU0JBlFjyml2QWuVJfGVyLhBKusUKPZ9Nu5vKU03cy3+Ucu/igAsSWGCD00iL80Y0GjICWhO Ozn2B0A== X-Received: by 2002:a05:600c:3b1f:b0:495:4cba:e288 with SMTP id 5b1f17b1804b1-496c653eb6amr48053165e9.15.1785285801374; Tue, 28 Jul 2026 17:43:21 -0700 (PDT) Received: from MacBook-Pro-von-Karl.localdomain (dynamic-2a02-3100-b323-2b01-0d98-9fe8-a4cd-78ab.310.pool.telefonica.de. [2a02:3100:b323:2b01:d98:9fe8:a4cd:78ab]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-47fb6aa3a88sm2827343f8f.6.2026.07.28.17.43.20 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Tue, 28 Jul 2026 17:43:20 -0700 (PDT) From: Karl Mehltretter To: Catalin Marinas , Will Deacon Cc: Mark Rutland , Mark Brown , Oleg Nesterov , Shuah Khan , linux-arm-kernel@lists.infradead.org, linux-kselftest@vger.kernel.org, linux-kernel@vger.kernel.org, Karl Mehltretter Subject: [PATCH 1/2] arm64/fpsimd: ptrace: Fix inactive SVE and SSVE regsets Date: Wed, 29 Jul 2026 02:42:54 +0200 Message-Id: <20260729004255.15630-1-kmehltretter@gmail.com> X-Mailer: git-send-email 2.39.5 (Apple Git-154) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit sve_init_header_from_task() takes header as a pointer, so for the inactive mode header->size = sizeof(header); stores 8 rather than sizeof(struct user_sve_header), which is 16. Userspace sees an impossible size smaller than the header it describes. The inactive-mode check in sve_get_common() compares header.size against sizeof(header) as well, but there header is a struct, so the check can never fire. Reads of NT_ARM_SVE and NT_ARM_SSVE for the inactive mode therefore still return the other mode's FPSIMD data, exactly the situation the check was added to prevent. Fix the size, and make the check return the remaining membuf space instead of 0, which regset_get() would interpret as the entire (zero-filled) buffer having been populated. Fixes: b93e685ecff7 ("arm64/fpsimd: ptrace: Do not present register data for inactive mode") Assisted-by: Claude:claude-opus-5 Signed-off-by: Karl Mehltretter --- Found by inspection while reviewing arch/arm64. Confirmed in the generated code: building arch/arm64/kernel/ptrace.o with arm64 defconfig and gcc 15.2.0 and disassembling sve_get_common shows the inactive branch storing a literal 8 into header.size, and no compare against 16 anywhere - the compiler constant-folds the check away entirely and falls straight through to __fpr_get(). That is a machine-checked demonstration that the early return can never fire. Runtime tested under QEMU TCG with -cpu max,sme=on. Before this change, PTRACE_GETREGSET(NT_ARM_SSVE) on a tracee outside streaming mode returned header.size == 8 and copied the 528-byte NT_PRFPREG payload. Afterwards, header.size is 16 and bytes in the userspace buffer after the header are left untouched. arch/arm64/kernel/ptrace.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/arch/arm64/kernel/ptrace.c b/arch/arm64/kernel/ptrace.c index 4d08598e2891..2a72c61a8af9 100644 --- a/arch/arm64/kernel/ptrace.c +++ b/arch/arm64/kernel/ptrace.c @@ -801,7 +801,7 @@ static void sve_init_header_from_task(struct user_sve_header *header, if (active) header->size = SVE_PT_SIZE(vq, header->flags); else - header->size = sizeof(header); + header->size = sizeof(*header); header->max_size = SVE_PT_SIZE(sve_vq_from_vl(header->max_vl), SVE_PT_REGS_SVE); } @@ -837,7 +837,7 @@ static int sve_get_common(struct task_struct *target, * from the other mode to userspace. */ if (header.size == sizeof(header)) - return 0; + return to.left; switch ((header.flags & SVE_PT_REGS_MASK)) { case SVE_PT_REGS_FPSIMD: -- 2.51.0