From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-ot1-f69.google.com (mail-ot1-f69.google.com [209.85.210.69]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6B1093112B2 for ; Mon, 17 Aug 2026 04:21:01 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.69 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786940465; cv=none; b=NP4psGwaun+NkWNLFqxd95x0PjCNdZST0doxBriNDvOsxahJ3u96ffPUTqEFrKMq+YGAYfkJhNtEYafhng82xOePFpRSNSGf9UD+Rn/TvIj5qOsfMrthT4eemJ+nzKJAaD6WIoORbfPqURw+Gp4YUA0mOD5zk18zCeNuTNp1Vo0= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786940465; c=relaxed/simple; bh=svYz+QsX7dtpedtqHqww6ZTpPVUveypQSsJmW25Hjvg=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=Q+A1z5eRhw9GrusbdGII1Ti69jlGaEMhfA+tY/Xs+AIP7hf2YBsQjEY6ZSZnh8ThmYQqfGSsrJwACeDdE5n9NISwscenM96sPEjTDsk+W3oaPssPVmF/NB0LciUW1UcZ+dw+RK87Kjxk201CHbyTB+Vi73BcC2ug9LPsGTp0J2M= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--avagin.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=QUXAB4Aj; arc=none smtp.client-ip=209.85.210.69 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--avagin.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="QUXAB4Aj" Received: by mail-ot1-f69.google.com with SMTP id 46e09a7af769-7e9dc0f5900so6974838a34.0 for ; Sun, 16 Aug 2026 21:21:01 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1786940460; x=1787545260; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=CoyS/Te2F5yF1AVsXNnrALUu84hJAgdlObRwg/dPksI=; b=QUXAB4AjdHHXhpbMAU6kfyHqtswrJ40bwjSnjKtXfAWwDTYOmafX3gRhA4hGVd9LTU daHX00Fx7aTGiRN4T8LcrED3PYyEwj77PzxAn/t36xA75RGT7VfyrLRU7fuC5Q5vZyGO mw82S/PsAKxcYwTJCtXUwLR0CT3aU0LfA4FDxMShONQ1s7LDz/rK2mBkMw357VKSvaiK 6/tUF/VU4S/utw/pb7dh0oVjkp8S82ooL6Sh+0LUW/q9WcFrZ9Kk848+ZLn018eXyZ+7 kREL+6MI5wIOvVIc9dJRVBxrg6MTLe6YGycVTE51sWcMhAidqdkCSg27T6FoMwVIu5Yl T6oA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786940460; x=1787545260; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=CoyS/Te2F5yF1AVsXNnrALUu84hJAgdlObRwg/dPksI=; b=MYUWbV/sJOT4QK/Pbk3P43kde8d0VQG9+e96rXRaJXNYaRknRhKEHWFRMIpC5vAl44 bYWVT7er31j05ySuo+dKjzTZH1LpGy3mmghxQw7nXbvgRhplNz35h1zTHOq2EO9ljRez I3klXo7RBx/+U1PyV9yEf4UrOjBe7nqKX3pKRbxhNoU5y7pCXqrmiOQbyZCAJL7llgRh XOrvB8taOt0RL7SrWBBuYVX6gR3Nbq4//arQA5ZXaXtziUVLV05eY5ppNxfnW7++Be8f K9Wpj1U5/TM2aH0F7ycGbP5r+P5dF4MNMPFPpa9WtuuP/yGZ+QBzYOLcRouIQ0ko63Aw uNwQ== X-Gm-Message-State: AOJu0YyauGkgjfnhq4c6ntR9pGPS/DsVQ212CZ9kbvIq9OAIKbZBnabv QDuZW5dLf3uOcU26CArVB0ztFPUoSyYNNBx1Wcqfn4LGbmRsjV1jkhhUBlm9GF5/kiSabfckIu4 iOlwRJg== X-Received: from ilbeo25-n2.prod.google.com ([2002:a05:6e02:2919:20b0:509:545b:77b5]) (user=avagin job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6820:2d03:b0:6a9:fa7f:faaf with SMTP id 006d021491bc7-6b0c5a8f072mr17604962eaf.5.1786940460025; Sun, 16 Aug 2026 21:21:00 -0700 (PDT) Date: Mon, 17 Aug 2026 04:20:44 +0000 In-Reply-To: <20260817042048.1579415-1-avagin@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260817042048.1579415-1-avagin@google.com> X-Mailer: git-send-email 2.55.0.691.gc56d675ccc-goog Message-ID: <20260817042048.1579415-5-avagin@google.com> Subject: [PATCH 4/8] x86/fpu: Document reasoning of FX-only fallback From: Andrei Vagin To: Thomas Gleixner , Ingo Molnar , Borislav Petkov , "Chang S. Bae" Cc: linux-kernel@vger.kernel.org, criu@lists.linux.dev, Dave Hansen , x86@kernel.org, Andrei Vagin , Alexander Mikhalitsyn , "H. Peter Anvin" Content-Type: text/plain; charset="UTF-8" Add a comment to check_xstate_in_sigframe() to explain reasoning behind falling back to the FX-only state when signal frame metadata is inconsistent. The fallback is intended to preserve backward compatibility with legacy user-space processes that are not aware of XSAVE states and might only fill or copy just the legacy FP state. This fallback is dangerous as it can trigger silent corruptions of user-space state by resetting extended registers if the process was using them but the frame metadata was malformed. Reviewed-by: Alexander Mikhalitsyn Signed-off-by: Andrei Vagin --- arch/x86/kernel/fpu/signal.c | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/arch/x86/kernel/fpu/signal.c b/arch/x86/kernel/fpu/signal.c index 6a14b528ac7f..85021c5ea649 100644 --- a/arch/x86/kernel/fpu/signal.c +++ b/arch/x86/kernel/fpu/signal.c @@ -54,6 +54,14 @@ static inline bool check_xstate_in_sigframe(struct fxregs_state __user *buf_fx, if (likely(magic2 == FP_XSTATE_MAGIC2)) return true; err_setfx: + /* + * The fallback to FX-only state is used to preserve backward + * compatibility with user-space processes that are not aware of xsave + * states. + * + * In all other cases, returning false (to trigger SIGSEGV) is + * preferred to avoid silent user-space state corruption. + */ trace_x86_fpu_xstate_check_failed(x86_task_fpu(current)); /* Set the parameters for fx only state */ -- 2.55.0.691.gc56d675ccc-goog