From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 514212F5A06 for ; Wed, 10 Dec 2025 18:10:55 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.129.124 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1765390257; cv=none; b=h/qROOk/AiL5Cj9Oj5IqaVRVCgpOKyq276x0oNJGEtxjDKXQ9YtP3MTnRsPmYftusDCiUpDfssQyauZ2IWW9d6NzHkM9uOX5PQE5kJhUXtR72e9ABQX0jZkQZ2W9xGJ3nhWZZo3opno3NlqejuPGVfWRFjbk+ZivVsO38UaKeTQ= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1765390257; c=relaxed/simple; bh=xV8FeAEJvABcbI94iv4JdQwqOdcY20ORR37Ibj3bpOY=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=lFwIIs03AZngprGgppBHM7Dh6+acnIAzp1lI0u5+2QCsmLFvTIiL/3oBvoIGkXpM87tI9xtORetdKtH1PH2oM5JiG8YiazWwcnS2iQ5WBjQaeME0X93X7PQKHITze1ase+c/tQwL/qs+O/AQxzXbBYwFwEFx0Pnitz+90Kp3gFQ= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=McpsIJLC; dkim=pass (2048-bit key) header.d=redhat.com header.i=@redhat.com header.b=p6gk6oWr; arc=none smtp.client-ip=170.10.129.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="McpsIJLC"; dkim=pass (2048-bit key) header.d=redhat.com header.i=@redhat.com header.b="p6gk6oWr" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1765390254; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=+JDXolFvYToa3N4Up5yZoz5aLabDxuH9KGdZibcWMIw=; b=McpsIJLCe7pMGF2PMct/FzxVTHJM/8JAD6ZtTCH6/mg7nc/gtH1lyEcQ9VNGXf2ey0OBqG ImNTsj8ghdDdErQJBBT/f3LKjyE7has7lOwkvqknyiqIXGaMntgyWonxmLDoRdvjmeIpWr HbfTqcDIWYFmeXkGFSR+4oYaZZzSvAc= Received: from mail-pf1-f200.google.com (mail-pf1-f200.google.com [209.85.210.200]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-447-BRZ3feC0Noe55VwMWHa9Cg-1; Wed, 10 Dec 2025 13:10:53 -0500 X-MC-Unique: BRZ3feC0Noe55VwMWHa9Cg-1 X-Mimecast-MFC-AGG-ID: BRZ3feC0Noe55VwMWHa9Cg_1765390252 Received: by mail-pf1-f200.google.com with SMTP id d2e1a72fcca58-7c240728e2aso99619b3a.3 for ; Wed, 10 Dec 2025 10:10:53 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1765390252; x=1765995052; darn=vger.kernel.org; h=content-transfer-encoding:in-reply-to:from:content-language :references:cc:to:subject:user-agent:mime-version:date:message-id :from:to:cc:subject:date:message-id:reply-to; bh=+JDXolFvYToa3N4Up5yZoz5aLabDxuH9KGdZibcWMIw=; b=p6gk6oWrup2GPYR2G3SUIPMYZzr17YYZW4xunziE8luJJfrSdncXJWRXEocgLdi7pC I2iMy2wtrwBQg/x25FdO2muwam/aNZLb/VrHjvNKTSv2mZS/nWkfOv+wgz12v78PLGpS nCFClnqQeD8MQEYDeffJiH9ehNDiwhJcNsb9Vw3AhXIeqsiGbcYdhfmMEbqb1yatYB1A wlMRy+WCu7SeiQlfSHJQ407lT8VJXoYbncEof5viun4YreKdNd9Qnkc6xQ/Uvt4ZHZt7 OF0+EMBwTbGuZABrUqR8eRduhCjPdU/jv4yX02+UOQTByANR4WJfM7ucnx0KR88eNwae jiRg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1765390252; x=1765995052; h=content-transfer-encoding:in-reply-to:from:content-language :references:cc:to:subject:user-agent:mime-version:date:message-id :x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=+JDXolFvYToa3N4Up5yZoz5aLabDxuH9KGdZibcWMIw=; b=fqRWEBmKsO/4IT+SlQg0eZ6W6F23aYKYxPe9b4ykiRTVYO8tIH2twDaksLypSAnFhK /opaFQhxACNK+aFg3qmX6QQn/3EO0nCe138VA7jro7JZHsjjQewaF+HEael6Z1Hcs1jg 9HIAbUHHN8sBAnlwBqgNEiJxchsvaw7MRNfgPHDRATyzZQXJuJZaDedcfj92xDU1+oFk YWePWoCpuryLEtYH7OeZqfcciMBlFqruHz3jc0IDhTpBjtJLemdJ4h0IZhDDIeIt3fDf c1Hu7YXfzOBTI5vuvLSRo1nHRQ7RFe9f2v4AVI6onDET4tr7qqutEz6qU8PK3ZEIPYgb kgvw== X-Gm-Message-State: AOJu0Yx90Bxv7eoqdTG8L4RZcC1DzIytJnYlAwB2iYaNEWtKy9U0DmCA ybqQjcQ+WAX7f9catqaA4LPPiGJcpwkHUsX2l0lvbq+Cq7/GB9ReoVMBTa+ll2nZni9OmQ0DTl0 d5TnuwNiu+INZKW49o1MAYsgkyxAxPq0sWkYWbcQc1S4uOYUzA3JdOIW5+VOP1bps8Q== X-Gm-Gg: ASbGnctKyoEueaTJ3hvOzeNZIreBKXlcoVlAS0dVxbBwlIBDI0gTBVzPkUFJJZLOpD9 hZ9WPbNgkibTWLtxaZ1WhvdIVeW92c9rYz11kwOgF4Eo8fnwR82cKbCc7tO1XmpYd8+CWJqHZPp QDnVGdXGJqxtNd0T1QoJYGwyhjq8fdw1POk4icTBCELHwmA78EOPREEoHH7/PC8b90NyCrJdWGx UbV3G36HgQxcrW2kPSVKz1L2bgkZl9pc56AEf/NfssZCAzeMCZI1CqpfUx06QRAjGwzx1Zd7buZ /+uLmn3rxulG7mSkiW1xyeIih3dTEbusTeRgp6xndUIO5dD7kQ6TOCy2bd7YvRx9K+Kd5MacLRi f6coIT5EhII8I+PYNSJlX+RQs X-Received: by 2002:a05:6a00:845:b0:792:574d:b12 with SMTP id d2e1a72fcca58-7f22d204db8mr3112119b3a.10.1765390251940; Wed, 10 Dec 2025 10:10:51 -0800 (PST) X-Google-Smtp-Source: AGHT+IEYs6sCyW+pPWJZ7h+WItvNX+krQXSVqaQvfrO+4k5L5BJr149fn44WwXC1n26fGUofB/nBaA== X-Received: by 2002:a05:6a00:845:b0:792:574d:b12 with SMTP id d2e1a72fcca58-7f22d204db8mr3112093b3a.10.1765390251513; Wed, 10 Dec 2025 10:10:51 -0800 (PST) Received: from [192.168.3.252] ([74.75.144.57]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-7f4c54802adsm177801b3a.60.2025.12.10.10.10.46 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Wed, 10 Dec 2025 10:10:50 -0800 (PST) Message-ID: Date: Wed, 10 Dec 2025 13:10:44 -0500 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [tboot-devel] [PATCH 1/1] Disable CET when calling tboot shutdown procedure. To: Bagas Sanjaya , ning.sun@intel.com, tboot-devel@lists.sourceforge.net Cc: linux-kernel@vger.kernel.org, rppt@kernel.org, tglx@linutronix.de, mingo@kernel.org, bp@alien8.de, michal.camacho.romero@linux.intel.com References: <20251017073619.547993-1-michal.camacho.romero@linux.intel.com> Content-Language: en-US From: Tony Camuso In-Reply-To: Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit On 11/24/2025 7:34 PM, Bagas Sanjaya wrote: > On Thu, Nov 13, 2025 at 09:37:14AM -0500, Tony Camuso wrote: >> The tboot->shutdown_entry is effectively bios code and CET needs to be >> disabled before calling it. >> >> It resolves TBOOT shutdown failure bug, reported on the SLES (SUSE Linux >> Enterprise Server) 16.0 OS. OS power off, called by the "init 0" command, >> was failing, due to activated Intel Control-Flow Enforcement Technology >> (CET). >> Disabling CET has allowed to execute OS and TBOOT shutdown properly. > > Are ``systemctl poweroff`` and ``shutdown -P`` are also affected? > > Confused... > Yes, all shutdown methods on kernels launched with tboot, on systems that expose the CPU ibt flag to kernels v6.12+ will cause the stack trace appended below. The stack trace demonstrates that CET enforcement collides with legacy BIOS shutdown code that lacks ENDBR markers. The kernel BUG at cet.c:102 is a direct result of CET being active when jumping into tboot->shutdown_entry. Legacy BIOS/tboot code without ENDBR now traps, requiring CET to be disabled around that call. The patch: Prevents CET from falsely trapping on non-CET BIOS code. Maintains system stability during shutdown. Preserves CET protection elsewhere, only disabling it for the narrow window where legacy firmware must run. [ 169.420078] reboot: Power down [ 169.427516] Missing ENDBR: 0x8041d0 [ 169.431128] ------------[ cut here ]------------ [ 169.435805] kernel BUG at arch/x86/kernel/cet.c:102! [ 169.440840] Oops: invalid opcode: 0000 [#1] SMP NOPTI [ 169.445966] CPU: 0 UID: 0 PID: 3354 Comm: poweroff Kdump: loaded Not tainted 6.12.0-124.8.1.el10_1.x86_64 #1 PREEMPT(voluntary) [ 169.457580] Hardware name: Dell Inc. PowerEdge R570/03TJR3, BIOS 1.2.1 01/23/2025 [ 169.465113] RIP: 0010:exc_control_protection+0x18c/0x190 [ 169.470490] Code: 1c ff 45 31 c9 49 89 d8 b9 09 00 00 00 48 8b 93 80 00 00 00 be 63 00 00 00 48 c7 c7 a4 85 e5 a4 e8 79 92 30 ff e9 02 ff ff ff <0f> 0b 66 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 66 0f [ 169.489292] RSP: 0018:ff55b3cba167fa88 EFLAGS: 00010002 [ 169.494581] RAX: 0000000000000017 RBX: ff55b3cba167faa8 RCX: 00000000ffff7fff [ 169.501765] RDX: 0000000000000000 RSI: 0000000000000003 RDI: 0000000000000001 [ 169.508949] RBP: 0000000000000003 R08: 0000000000000000 R09: ffffffffa59e2b08 [ 169.516132] R10: ffffffffa5922ac8 R11: 0000000000000003 R12: 0000000000000000 [ 169.523316] R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000 [ 169.530514] FS: 00007f5f9a122140(0000) GS:ff39175c2de00000(0000) knlGS:0000000000000000 [ 169.538659] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 169.544454] CR2: 0000559386dc5320 CR3: 000000010fbe2000 CR4: 0000000000f71ef0 [ 169.551651] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 169.558835] DR3: 0000000000000000 DR6: 00000000fffe07f0 DR7: 0000000000000400 [ 169.566019] PKRU: 55555554 [ 169.568784] Call Trace: [ 169.571295] [ 169.573458] ? show_trace_log_lvl+0x1b0/0x2f0 [ 169.577880] ? show_trace_log_lvl+0x1b0/0x2f0 [ 169.582301] ? asm_exc_control_protection+0x26/0x30 [ 169.587244] ? exc_control_protection+0x18c/0x190 [ 169.592011] ? __die_body.cold+0x8/0x12 [ 169.595910] ? die+0x2e/0x50 [ 169.598863] ? do_trap+0xca/0x110 [ 169.602243] ? do_error_trap+0x65/0x80 [ 169.606049] ? exc_control_protection+0x18c/0x190 [ 169.610816] ? exc_invalid_op+0x50/0x70 [ 169.614715] ? exc_control_protection+0x18c/0x190 [ 169.619482] ? asm_exc_invalid_op+0x1a/0x20 [ 169.623728] ? exc_control_protection+0x18c/0x190 [ 169.628496] ? exc_control_protection+0x14f/0x190 [ 169.633263] asm_exc_control_protection+0x26/0x30 [ 169.638030] RIP: 0010:0x8041d0 [ 169.641142] Code: Unable to access opcode bytes at 0x8041a6. [ 169.646857] RSP: 0018:ff55b3cba167fb50 EFLAGS: 00010007 [ 169.652144] RAX: 00000000008041d0 RBX: 0000000000000000 RCX: 0000000000000005 [ 169.659341] RDX: 00c6e8a7c0000000 RSI: 0000000000000001 RDI: ffffffffff1ff000 [ 169.666525] RBP: 0000000000000005 R08: 0000000000000000 R09: 000000000000ffff [ 169.673709] R10: 0000000000000000 R11: ffffffffffff0000 R12: 0000000000002001 [ 169.680906] R13: ffffffffa5ae02c8 R14: 00000000ffffffff R15: 0000000000000000 [ 169.688091] ? tboot_shutdown+0x5b/0x140 [ 169.692084] ? tboot_sleep+0x12c/0x140 [ 169.695890] ? acpi_os_enter_sleep+0x2b/0x60 [ 169.700221] ? acpi_hw_legacy_sleep+0x140/0x1c0 [ 169.704816] ? acpi_power_off+0x16/0x40 [ 169.708715] ? sys_off_notify+0x48/0x70 [ 169.712615] ? notifier_call_chain+0x5a/0xd0 [ 169.716943] ? atomic_notifier_call_chain+0x32/0x50 [ 169.721885] ? do_kernel_power_off+0x3e/0x50 [ 169.726213] ? native_machine_power_off+0x21/0x40 [ 169.730983] ? __do_sys_reboot+0x1d2/0x240 [ 169.735151] ? do_syscall_64+0x7d/0x160 [ 169.739053] ? syscall_exit_work+0xf3/0x120 [ 169.743302] ? syscall_exit_to_user_mode+0x32/0x190 [ 169.748243] ? do_syscall_64+0x89/0x160 [ 169.752143] ? __count_memcg_events+0xdf/0x170 [ 169.756645] ? handle_mm_fault+0x256/0x370 [ 169.760813] ? do_user_addr_fault+0x347/0x640 [ 169.765235] ? exc_page_fault+0x73/0x160 [ 169.769228] ? entry_SYSCALL_64_after_hwframe+0x76/0x7e