From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-oo1-f70.google.com (mail-oo1-f70.google.com [209.85.161.70]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 52D832EEE89 for ; Mon, 17 Aug 2026 04:20:57 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.161.70 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786940458; cv=none; b=IqPWfVmaFEg+bYwXN0j9+Ll+ncChMntWUKj5EROyZ4ye6nrfTBCnGcvWgkSXHKaUZ2hqlBzJJw2qQTBQ4X9NBg9EyBYmDuBHJM9GB9Lo9vXVRNS0/Eoy3lc49ssUGUg08xzQZKLHi7bJbHj3Axm+30f5580agx7OKhUo29wtHMk= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786940458; c=relaxed/simple; bh=a8gFujA8Bs5nsQfKBIWsepKRRJUrGzW7hYMzDrFsXcg=; h=Date:Mime-Version:Message-ID:Subject:From:To:Cc:Content-Type; b=lhJgICLg3DCUETGTEJsuBUWZlMwXq6q0vjRf7N/4q/lymWoD67eth2HmTxvXVX3jMNcrALqa6YoInyV2J/HqynCzKpuwQvPqbI/CVmjeW0UW4vO98ea86es2BnmM+kv4xzLQ2IB+V6amgg9BQsTc1rjxMSVb3JTtfbaWcLf3Kj8= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--avagin.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=CCHrlDdl; arc=none smtp.client-ip=209.85.161.70 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--avagin.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="CCHrlDdl" Received: by mail-oo1-f70.google.com with SMTP id 006d021491bc7-6ae35c7b9a9so960597eaf.2 for ; Sun, 16 Aug 2026 21:20:57 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1786940456; x=1787545256; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:mime-version:date:from :to:cc:subject:date:message-id:reply-to:content-type; bh=yZUnYZgWelpqyOWb6p64DuzNqG2Pdc5MDPeSyZ3QwG4=; b=CCHrlDdl3L1XeAfIebsDKVNHsuMx+XyMPy8+X0Pnl68LvGB4Oybbyxv14pJlYlTMLa i5lucvDeHE0yazvBlE269XLbtY/c+2cVJRCj8giPN6wnxgQ6FwnoSBJZMNtTdgttOx7m UuUWIT6Z5+l0VxKsuYoyajICxskiJlsFvQP5OzoK25tGFii4cE4VgKeplyL164Xe4JjP YWqQmsfAndb3K3JGMC24Iva3Odvvz392v6nQdqaE451btzDzi5b/jt43Ec+sGqugLFjY BHKELutuh3wGq3QGGkRzCnaDAZ81ml8uI/KqBnJ1OT7l3dDcv/6PjTtxdVMc+erXSz51 0y6A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786940456; x=1787545256; h=content-type:cc:to:from:subject:message-id:mime-version:date :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=yZUnYZgWelpqyOWb6p64DuzNqG2Pdc5MDPeSyZ3QwG4=; b=Si609qLhSDfbLVwNzwOtQ1xnuGFFTRS+czhpkjeS3SvDMh7u5DhPWIjCLYMRHC6Uda zy8rkEUVHmktaHPTFlYuFKoeu/oQLHhpH+wOzcXFzORTa2/fiQFCuExmBX9IchJJW6vP ZVBqBOnwA8HxDB6COQa89tzU/EI87cZFTEt9logIwh2Ucbl9PDdFB+j1kl5fKjxIk/Jm E3TCCWHTQcgG7cwTU06Admlpy8+uU2nYyjW+hJU7sW9wGaYum57FekLukDnJ8meW6dpt pVSzAYFrFqapJ8YgzSgg9WIEGvV4uuXtm44OA9ErWjSTI5ELR4fFV1Jz0sFIeG4bb1Dw CbWA== X-Gm-Message-State: AOJu0YwRHHxsHf5YybwlK4LVt7mRQfZTFo6NVK7ElonJMYe5PHU2GMu6 vk7Ac4RSxm3t1gtv11rXD0AvKrW+c4F6TCZlvOICof8V3xR6QZnuduqPSONdQqFHzv8HdwuoV1c cblWpIg== X-Received: from iowk17.prod.google.com ([2002:a05:6602:2d91:b0:9a7:ea14:7cf5]) (user=avagin job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6820:1ca8:b0:6b0:fcdd:2da7 with SMTP id 006d021491bc7-6b0fcdd349amr9134321eaf.7.1786940455898; Sun, 16 Aug 2026 21:20:55 -0700 (PDT) Date: Mon, 17 Aug 2026 04:20:40 +0000 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 X-Mailer: git-send-email 2.55.0.691.gc56d675ccc-goog Message-ID: <20260817042048.1579415-1-avagin@google.com> Subject: [PATCH v4 0/8] x86/fpu: Restore and reinforce signal frame portability From: Andrei Vagin To: Thomas Gleixner , Ingo Molnar , Borislav Petkov , "Chang S. Bae" Cc: linux-kernel@vger.kernel.org, criu@lists.linux.dev, Dave Hansen , x86@kernel.org, Andrei Vagin , Alexander Mikhalitsyn , "H. Peter Anvin" Content-Type: text/plain; charset="UTF-8" The x86 signal frame is designed to be self-describing. The xstate_size field in the software-reserved bytes indicates the actual size of the xstate context and is used by the kernel to locate the FP_XSTATE_MAGIC2 marker during signal return. This design is required to provide portability of signal frames across different machines. For example, a process checkpointed on a system with fewer xstate features and restored on a system with more features will have a signal frame on its stack that is smaller than the destination host's default. By relying on the frame's internal xstate_size, the kernel can correctly validate and restore such frames. This series restores and improves signal frame portability. The goal is to allow process migration across CPUs with heterogeneous FPU capabilities, as long as the process only uses features supported by both systems. This version addresses the original issues by pre-faulting only the required size of the xstate buffer (rather than the default task size), and includes cleanups requested by Ingo Molnar. v4: - Update documentation to describe architectural XSAVE layout constraints and feature repurposing (e.g. MPX vs APX). - The patch "x86/fpu: Allow restoring signal frames with larger xstate_size" will be sent in a separate series. - Address sashiko comments. v3: - Include cleanups and refactoring of signal frame handling code as requested by Ingo Molnar. - Fix potential underflow in xstate_calculate_size() v2: - Address sashiko comments. - 44eeff9bc467 ("Revert "x86/fpu: Refine and simplify the magic number check during signal return"") has been merged. Cc: Alexander Mikhalitsyn Cc: Borislav Petkov Cc: "Chang S. Bae" Cc: Dave Hansen Cc: "H. Peter Anvin" Cc: Ingo Molnar Cc: Thomas Gleixner Andrei Vagin (8): x86/fpu: Document signal frame portability x86/fpu: Clean up and rename variables in signal frame handling x86/fpu: Split __fpu_restore_sig to extract compat path x86/fpu: Document reasoning of FX-only fallback selftests/x86: Add a test for signal frame FPU portability x86/fpu: Fix potential underflow in xstate_calculate_size() x86/fpu: Pre-fault only required size of xstate buffer selftests/x86: Add a sigframe insufficient xstate_size test Documentation/arch/x86/xstate.rst | 16 ++ arch/x86/include/uapi/asm/sigcontext.h | 17 ++ arch/x86/kernel/fpu/signal.c | 130 ++++++++--- arch/x86/kernel/fpu/xstate.c | 9 +- arch/x86/kernel/fpu/xstate.h | 2 + tools/testing/selftests/x86/Makefile | 5 +- .../selftests/x86/sigframe_fpu_portability.c | 229 ++++++++++++++++++ tools/testing/selftests/x86/xstate.c | 5 - tools/testing/selftests/x86/xstate.h | 12 + 9 files changed, 378 insertions(+), 47 deletions(-) create mode 100644 tools/testing/selftests/x86/sigframe_fpu_portability.c -- 2.54.0.1189.g8c84645362-goog