From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from va-1-115.ptr.blmpb.com (va-1-115.ptr.blmpb.com [209.127.230.115]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id EBB493AE6FD for ; Thu, 8 Oct 2026 06:00:15 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.127.230.115 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1791439218; cv=none; b=R7jJ0I2CzeKhskYNnc44vUxtmF2hLPoOWmf7fNvWoaa5kwBpK/Va0wvGgRJmoP1PDnkfPLc2O4XdXX9FAPWpRClYXv3M4V6gihmHk7BOVGtjM85bnaaF9sq2M4U3BX2IXbK2rpfD/Kl4tVffxUWGhuO3iC3n0JX+5jvFOrS2wcI= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1791439218; c=relaxed/simple; bh=atopTEU82pKWj1hIlC0ATvjBX+nda9tdm3dbSc/Tkbk=; h=Cc:Mime-Version:From:Subject:Date:Message-Id:To:Content-Type; b=Flqe77/iCiZ7XogL9LOmm6zTlRRoeQqkAxqp1kZjUDXeam3lKC8bQigatwTnsplfIYHTiEQI8MGXpy00JowMy/Cek0UM78kIGszsJM26RXQwVqHjoZSj5kFWbWXQ1YruzGWlQobjtu4isjbeycrXK3lnZHwLiL11HZcwa3ffpXo= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=bytedance.com; spf=pass smtp.mailfrom=bytedance.com; dkim=pass (2048-bit key) header.d=bytedance.com header.i=@bytedance.com header.b=GzDaP0Mu; arc=none smtp.client-ip=209.127.230.115 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=bytedance.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=bytedance.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=bytedance.com header.i=@bytedance.com header.b="GzDaP0Mu" DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; s=2212171451; d=bytedance.com; t=1791439206; h=from:subject: mime-version:from:date:message-id:subject:to:cc:reply-to:content-type: mime-version:in-reply-to:message-id; bh=IJJMdUiSpOAuCXacXIpmuvPEGQiEu8gSCHcioGm/R8A=; b=GzDaP0MuMFZrBT6NzCgqmQX8upaOIGvOJ+tWxAvwkCi/TZPbZYOObmMLz5zNUNRvfH1J+q rWaL5X6GUcJkP/+LFvAXI8Kow5l1Op96F1duVuAHaLNH9D0I5rHnGToWYfSh5ImxdjpuVh YEn/A0tDHt3Rr9B5AapozYOhb/S0FKNcd8j/r+E2wge0B8PSidEN+mF53H+JQhU+Ccmpdl pvZmIMcxc/jbsJHDvMKSsGxIIdohxnh5kRdhgXECaW3ebge151czD8PT5FpN5dLub4a4gy oQVm2BbMGRDgtZtZphIl74NZl7q/2rvVICLjhDVwvtdBUuii+UhQk5ZGpnC+xw== X-Original-From: Guixiong Wei Cc: "Guixiong Wei" , "Thomas Gleixner" , "Ingo Molnar" , "Borislav Petkov" , "Dave Hansen" , "H . Peter Anvin" , "Chang S . Bae" , "Shuah Khan" , , Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 From: "Guixiong Wei" Subject: [PATCH v2 0/2] x86/fpu: Fix dynamic fpstate leak on exec() Date: Thu, 8 Oct 2026 13:59:34 +0800 Message-Id: Content-Transfer-Encoding: 7bit X-Mailer: git-send-email 2.55.0 To: Content-Type: text/plain; charset=UTF-8 X-Lms-Return-Path: An exec() after using an XFD-controlled xfeature resets fpu->fpstate to its embedded storage without freeing the dynamically allocated state. Fix the leak in fpstate_reset() and add an AMX regression selftest. The fix preserves the old pointer, installs and initializes the embedded fpstate, and then frees the detached allocation. Since fpstate_reset() now owns cleanup, fpu_clone() initializes dst_fpu->fpstate to NULL before invoking it. The selftest performs ten XTILEDATA request, XRSTOR and self-exec cycles in the same task and checks the associated /proc/vmallocinfo entries. It fails with 10 leaked allocations on the unfixed kernel and passes with zero on the fixed kernel. Changes since v1: - Rename the fix and describe the memory leak explicitly. - Move cleanup into fpstate_reset(). - Detach the old fpstate before freeing it. - Initialize dst_fpu->fpstate to NULL before resetting it. - Add the requested AMX regression selftest as a separate patch. v1: https://lore.kernel.org/r/20260929151013.81562-2-weiguixiong@bytedance.com Guixiong Wei (2): x86/fpu: Fix memory leak with dynamic fpstate and exec() selftests/x86/amx: Test dynamic fpstate cleanup across exec() arch/x86/include/asm/fpu/api.h | 6 +- arch/x86/kernel/fpu/core.c | 5 ++ arch/x86/kernel/fpu/xstate.c | 10 +-- arch/x86/kernel/process.c | 2 +- tools/testing/selftests/x86/amx.c | 144 +++++++++++++++++++++++++++++- 5 files changed, 156 insertions(+), 11 deletions(-) base-commit: 72d3fcf802c45d00b300f25b848a93c3a2bd7c7e -- 2.50.1 (Apple Git-155)