Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1440612 > unrolled thread

[PATCH 0/4] x86/fpu/xstate: Fix XSAVES issues - Part 3

Started by"Fenghua Yu" <fenghua.yu@intel.com>
First post2016-07-11 15:20 +0200
Last post2016-07-11 18:20 +0200
Articles 7 — 2 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH 0/4] x86/fpu/xstate: Fix XSAVES issues - Part 3 "Fenghua Yu" <fenghua.yu@intel.com> - 2016-07-11 15:20 +0200
    [PATCH 1/4] x86/fpu/xstate: Fix __fpu_restore_sig() for XSAVES "Fenghua Yu" <fenghua.yu@intel.com> - 2016-07-11 15:20 +0200
      [tip:x86/fpu] x86/fpu/xstate: Fix __fpu_restore_sig() for XSAVES tip-bot for Yu-cheng Yu <tipbot@zytor.com> - 2016-07-11 18:20 +0200
    [PATCH 2/4] x86/fpu/xstate: Return NULL for disabled xstate component address "Fenghua Yu" <fenghua.yu@intel.com> - 2016-07-11 15:20 +0200
      [tip:x86/fpu] x86/fpu/xstate: Return NULL for disabled xstate  component address tip-bot for Yu-cheng Yu <tipbot@zytor.com> - 2016-07-11 18:20 +0200
    [PATCH 3/4] x86/fpu/xstate: Fix fpstate_init() for XRSTORS "Fenghua Yu" <fenghua.yu@intel.com> - 2016-07-11 15:20 +0200
      [tip:x86/fpu] x86/fpu/xstate: Fix fpstate_init() for XRSTORS tip-bot for Yu-cheng Yu <tipbot@zytor.com> - 2016-07-11 18:20 +0200

#1440612 — [PATCH 0/4] x86/fpu/xstate: Fix XSAVES issues - Part 3

From"Fenghua Yu" <fenghua.yu@intel.com>
Date2016-07-11 15:20 +0200
Subject[PATCH 0/4] x86/fpu/xstate: Fix XSAVES issues - Part 3
Message-ID<rTJhU-7vn-11@gated-at.bofh.it>
From: Yu-cheng Yu <yu-cheng.yu@intel.com>

** Based on tip/master **

This is Part 3 of previous 13 XSAVES patches. Break it down to
smaller series. There are no code changes; only minor fixes in
the titles.

Yu-cheng Yu (4):
  x86/fpu/xstate: Fix __fpu_restore_sig() for XSAVES
  x86/fpu/xstate: Return NULL for disabled xstate component address
  x86/fpu/xstate: Fix fpstate_init() for XRSTORS
  x86/fpu/xstate: Re-enable XSAVES

 arch/x86/include/asm/fpu/types.h |  6 ++++++
 arch/x86/kernel/fpu/core.c       |  8 ++++++++
 arch/x86/kernel/fpu/init.c       | 15 ---------------
 arch/x86/kernel/fpu/signal.c     | 11 +++++++++--
 arch/x86/kernel/fpu/xstate.c     | 14 ++++++++++++++
 5 files changed, 37 insertions(+), 17 deletions(-)

-- 
2.5.0

[toc] | [next] | [standalone]


#1440613 — [PATCH 1/4] x86/fpu/xstate: Fix __fpu_restore_sig() for XSAVES

From"Fenghua Yu" <fenghua.yu@intel.com>
Date2016-07-11 15:20 +0200
Subject[PATCH 1/4] x86/fpu/xstate: Fix __fpu_restore_sig() for XSAVES
Message-ID<rTJhU-7vn-21@gated-at.bofh.it>
In reply to#1440612
From: Yu-cheng Yu <yu-cheng.yu@intel.com>

When the kernel is using XSAVES compacted format, we cannot do
__copy_from_user() from a signal frame, which has standard-format data.
Fix it by using copyin_to_xsaves(), which converts between formats and
filters out all supervisor states that we do not allow userspace to
write.

Signed-off-by: Yu-cheng Yu <yu-cheng.yu@intel.com>
Signed-off-by: Fenghua Yu <fenghua.yu@intel.com>
Reviewed-by: Dave Hansen <dave.hansen@intel.com>
---
 arch/x86/kernel/fpu/signal.c | 11 +++++++++--
 1 file changed, 9 insertions(+), 2 deletions(-)

diff --git a/arch/x86/kernel/fpu/signal.c b/arch/x86/kernel/fpu/signal.c
index 8aa96cb..9e231d8 100644
--- a/arch/x86/kernel/fpu/signal.c
+++ b/arch/x86/kernel/fpu/signal.c
@@ -323,8 +323,15 @@ static int __fpu__restore_sig(void __user *buf, void __user *buf_fx, int size)
 		 */
 		fpu__drop(fpu);
 
-		if (__copy_from_user(&fpu->state.xsave, buf_fx, state_size) ||
-		    __copy_from_user(&env, buf, sizeof(env))) {
+		if (using_compacted_format()) {
+			err = copyin_to_xsaves(NULL, buf_fx,
+					       &fpu->state.xsave);
+		} else {
+			err = __copy_from_user(&fpu->state.xsave,
+					       buf_fx, state_size);
+		}
+
+		if (err || __copy_from_user(&env, buf, sizeof(env))) {
 			fpstate_init(&fpu->state);
 			trace_x86_fpu_init_state(fpu);
 			err = -1;
-- 
2.5.0

[toc] | [prev] | [next] | [standalone]


#1440742 — [tip:x86/fpu] x86/fpu/xstate: Fix __fpu_restore_sig() for XSAVES

Fromtip-bot for Yu-cheng Yu <tipbot@zytor.com>
Date2016-07-11 18:20 +0200
Subject[tip:x86/fpu] x86/fpu/xstate: Fix __fpu_restore_sig() for XSAVES
Message-ID<rTM66-10U-13@gated-at.bofh.it>
In reply to#1440613
Commit-ID:  1fc2b67b43d5001b92b3a002b988884ad0137e99
Gitweb:     http://git.kernel.org/tip/1fc2b67b43d5001b92b3a002b988884ad0137e99
Author:     Yu-cheng Yu <yu-cheng.yu@intel.com>
AuthorDate: Mon, 11 Jul 2016 09:18:54 -0700
Committer:  Ingo Molnar <mingo@kernel.org>
CommitDate: Mon, 11 Jul 2016 16:43:59 +0200

x86/fpu/xstate: Fix __fpu_restore_sig() for XSAVES

When the kernel is using XSAVES compacted format, we cannot do
__copy_from_user() from a signal frame, which has standard-format data.
Fix it by using copyin_to_xsaves(), which converts between formats and
filters out all supervisor states that we do not allow userspace to
write.

Signed-off-by: Yu-cheng Yu <yu-cheng.yu@intel.com>
Signed-off-by: Fenghua Yu <fenghua.yu@intel.com>
Reviewed-by: Dave Hansen <dave.hansen@intel.com>
Cc: H. Peter Anvin <h.peter.anvin@intel.com>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Ravi V Shankar <ravi.v.shankar@intel.com>
Cc: Thomas Gleixner <tglx@linutronix.de>
Link: http://lkml.kernel.org/r/1468253937-40008-2-git-send-email-fenghua.yu@intel.com
Signed-off-by: Ingo Molnar <mingo@kernel.org>
---
 arch/x86/kernel/fpu/signal.c | 11 +++++++++--
 1 file changed, 9 insertions(+), 2 deletions(-)

diff --git a/arch/x86/kernel/fpu/signal.c b/arch/x86/kernel/fpu/signal.c
index 8aa96cb..9e231d8 100644
--- a/arch/x86/kernel/fpu/signal.c
+++ b/arch/x86/kernel/fpu/signal.c
@@ -323,8 +323,15 @@ static int __fpu__restore_sig(void __user *buf, void __user *buf_fx, int size)
 		 */
 		fpu__drop(fpu);
 
-		if (__copy_from_user(&fpu->state.xsave, buf_fx, state_size) ||
-		    __copy_from_user(&env, buf, sizeof(env))) {
+		if (using_compacted_format()) {
+			err = copyin_to_xsaves(NULL, buf_fx,
+					       &fpu->state.xsave);
+		} else {
+			err = __copy_from_user(&fpu->state.xsave,
+					       buf_fx, state_size);
+		}
+
+		if (err || __copy_from_user(&env, buf, sizeof(env))) {
 			fpstate_init(&fpu->state);
 			trace_x86_fpu_init_state(fpu);
 			err = -1;

[toc] | [prev] | [next] | [standalone]


#1440614 — [PATCH 2/4] x86/fpu/xstate: Return NULL for disabled xstate component address

From"Fenghua Yu" <fenghua.yu@intel.com>
Date2016-07-11 15:20 +0200
Subject[PATCH 2/4] x86/fpu/xstate: Return NULL for disabled xstate component address
Message-ID<rTJhU-7vn-23@gated-at.bofh.it>
In reply to#1440612
From: Yu-cheng Yu <yu-cheng.yu@intel.com>

It is an error to request a disabled XSAVE/XSAVES component address.
For that case, make __raw_xsave_addr() return a NULL and issue a
warning.

Signed-off-by: Yu-cheng Yu <yu-cheng.yu@intel.com>
Signed-off-by: Fenghua Yu <fenghua.yu@intel.com>
Reviewed-by: Dave Hansen <dave.hansen@intel.com>
---
 arch/x86/kernel/fpu/xstate.c | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/arch/x86/kernel/fpu/xstate.c b/arch/x86/kernel/fpu/xstate.c
index f8d1aff..4fb8dd7 100644
--- a/arch/x86/kernel/fpu/xstate.c
+++ b/arch/x86/kernel/fpu/xstate.c
@@ -760,6 +760,11 @@ void *__raw_xsave_addr(struct xregs_state *xsave, int xstate_feature_mask)
 {
 	int feature_nr = fls64(xstate_feature_mask) - 1;
 
+	if (!xfeature_enabled(feature_nr)) {
+		WARN_ON_FPU(1);
+		return NULL;
+	}
+
 	return (void *)xsave + xstate_comp_offsets[feature_nr];
 }
 /*
-- 
2.5.0

[toc] | [prev] | [next] | [standalone]


#1440744 — [tip:x86/fpu] x86/fpu/xstate: Return NULL for disabled xstate component address

Fromtip-bot for Yu-cheng Yu <tipbot@zytor.com>
Date2016-07-11 18:20 +0200
Subject[tip:x86/fpu] x86/fpu/xstate: Return NULL for disabled xstate component address
Message-ID<rTM66-10U-15@gated-at.bofh.it>
In reply to#1440614
Commit-ID:  5060b91513b866f774da15dfd82157864c4b1683
Gitweb:     http://git.kernel.org/tip/5060b91513b866f774da15dfd82157864c4b1683
Author:     Yu-cheng Yu <yu-cheng.yu@intel.com>
AuthorDate: Mon, 11 Jul 2016 09:18:55 -0700
Committer:  Ingo Molnar <mingo@kernel.org>
CommitDate: Mon, 11 Jul 2016 16:44:00 +0200

x86/fpu/xstate: Return NULL for disabled xstate component address

It is an error to request a disabled XSAVE/XSAVES component address.
For that case, make __raw_xsave_addr() return a NULL and issue a
warning.

Signed-off-by: Yu-cheng Yu <yu-cheng.yu@intel.com>
Signed-off-by: Fenghua Yu <fenghua.yu@intel.com>
Reviewed-by: Dave Hansen <dave.hansen@intel.com>
Cc: H. Peter Anvin <h.peter.anvin@intel.com>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Ravi V Shankar <ravi.v.shankar@intel.com>
Cc: Thomas Gleixner <tglx@linutronix.de>
Link: http://lkml.kernel.org/r/1468253937-40008-3-git-send-email-fenghua.yu@intel.com
Signed-off-by: Ingo Molnar <mingo@kernel.org>
---
 arch/x86/kernel/fpu/xstate.c | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/arch/x86/kernel/fpu/xstate.c b/arch/x86/kernel/fpu/xstate.c
index f8d1aff..4fb8dd7 100644
--- a/arch/x86/kernel/fpu/xstate.c
+++ b/arch/x86/kernel/fpu/xstate.c
@@ -760,6 +760,11 @@ void *__raw_xsave_addr(struct xregs_state *xsave, int xstate_feature_mask)
 {
 	int feature_nr = fls64(xstate_feature_mask) - 1;
 
+	if (!xfeature_enabled(feature_nr)) {
+		WARN_ON_FPU(1);
+		return NULL;
+	}
+
 	return (void *)xsave + xstate_comp_offsets[feature_nr];
 }
 /*

[toc] | [prev] | [next] | [standalone]


#1440615 — [PATCH 3/4] x86/fpu/xstate: Fix fpstate_init() for XRSTORS

From"Fenghua Yu" <fenghua.yu@intel.com>
Date2016-07-11 15:20 +0200
Subject[PATCH 3/4] x86/fpu/xstate: Fix fpstate_init() for XRSTORS
Message-ID<rTJhU-7vn-25@gated-at.bofh.it>
In reply to#1440612
From: Yu-cheng Yu <yu-cheng.yu@intel.com>

In XSAVES mode if fpstate_init() is used to initialize a
task's extended state area, xsave.header.xcomp_bv[63] must
be set. Otherwise, when the task is scheduled, a warning is
triggered from copy_kernel_to_xregs().

One such test case is: setting an invalid extended state
through PTRACE. When xstateregs_set() rejects the syscall
and re-initializes the task's extended state area. This triggers
the warning mentioned above.

Signed-off-by: Yu-cheng Yu <yu-cheng.yu@intel.com>
Signed-off-by: Fenghua Yu <fenghua.yu@intel.com>
Reviewed-by: Dave Hansen <dave.hansen@intel.com>
---
 arch/x86/include/asm/fpu/types.h | 6 ++++++
 arch/x86/kernel/fpu/core.c       | 8 ++++++++
 2 files changed, 14 insertions(+)

diff --git a/arch/x86/include/asm/fpu/types.h b/arch/x86/include/asm/fpu/types.h
index 12dd648..48df486 100644
--- a/arch/x86/include/asm/fpu/types.h
+++ b/arch/x86/include/asm/fpu/types.h
@@ -232,6 +232,12 @@ struct xstate_header {
 } __attribute__((packed));
 
 /*
+ * xstate_header.xcomp_bv[63] indicates that the extended_state_area
+ * is in compacted format.
+ */
+#define XCOMP_BV_COMPACTED_FORMAT ((u64)1 << 63)
+
+/*
  * This is our most modern FPU state format, as saved by the XSAVE
  * and restored by the XRSTOR instructions.
  *
diff --git a/arch/x86/kernel/fpu/core.c b/arch/x86/kernel/fpu/core.c
index c759bd0..3fc03a0 100644
--- a/arch/x86/kernel/fpu/core.c
+++ b/arch/x86/kernel/fpu/core.c
@@ -8,6 +8,7 @@
 #include <asm/fpu/internal.h>
 #include <asm/fpu/regset.h>
 #include <asm/fpu/signal.h>
+#include <asm/fpu/types.h>
 #include <asm/traps.h>
 
 #include <linux/hardirq.h>
@@ -229,6 +230,13 @@ void fpstate_init(union fpregs_state *state)
 
 	memset(state, 0, fpu_kernel_xstate_size);
 
+	/*
+	 * XRSTORS requires that this bit is set in xcomp_bv, or
+	 * it will #GP. Make sure it is replaced after the memset().
+	 */
+	if (static_cpu_has(X86_FEATURE_XSAVES))
+		state->xsave.header.xcomp_bv = XCOMP_BV_COMPACTED_FORMAT;
+
 	if (static_cpu_has(X86_FEATURE_FXSR))
 		fpstate_init_fxstate(&state->fxsave);
 	else
-- 
2.5.0

[toc] | [prev] | [next] | [standalone]


#1440743 — [tip:x86/fpu] x86/fpu/xstate: Fix fpstate_init() for XRSTORS

Fromtip-bot for Yu-cheng Yu <tipbot@zytor.com>
Date2016-07-11 18:20 +0200
Subject[tip:x86/fpu] x86/fpu/xstate: Fix fpstate_init() for XRSTORS
Message-ID<rTM66-10U-17@gated-at.bofh.it>
In reply to#1440615
Commit-ID:  35ac2d7ba787eb4b7418a5a6f5919c25e10a780a
Gitweb:     http://git.kernel.org/tip/35ac2d7ba787eb4b7418a5a6f5919c25e10a780a
Author:     Yu-cheng Yu <yu-cheng.yu@intel.com>
AuthorDate: Mon, 11 Jul 2016 09:18:56 -0700
Committer:  Ingo Molnar <mingo@kernel.org>
CommitDate: Mon, 11 Jul 2016 16:44:00 +0200

x86/fpu/xstate: Fix fpstate_init() for XRSTORS

In XSAVES mode if fpstate_init() is used to initialize a
task's extended state area, xsave.header.xcomp_bv[63] must
be set. Otherwise, when the task is scheduled, a warning is
triggered from copy_kernel_to_xregs().

One such test case is: setting an invalid extended state
through PTRACE. When xstateregs_set() rejects the syscall
and re-initializes the task's extended state area. This triggers
the warning mentioned above.

Signed-off-by: Yu-cheng Yu <yu-cheng.yu@intel.com>
Signed-off-by: Fenghua Yu <fenghua.yu@intel.com>
Reviewed-by: Dave Hansen <dave.hansen@intel.com>
Cc: H. Peter Anvin <h.peter.anvin@intel.com>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Ravi V Shankar <ravi.v.shankar@intel.com>
Cc: Thomas Gleixner <tglx@linutronix.de>
Link: http://lkml.kernel.org/r/1468253937-40008-4-git-send-email-fenghua.yu@intel.com
Signed-off-by: Ingo Molnar <mingo@kernel.org>
---
 arch/x86/include/asm/fpu/types.h | 6 ++++++
 arch/x86/kernel/fpu/core.c       | 8 ++++++++
 2 files changed, 14 insertions(+)

diff --git a/arch/x86/include/asm/fpu/types.h b/arch/x86/include/asm/fpu/types.h
index 12dd648..48df486 100644
--- a/arch/x86/include/asm/fpu/types.h
+++ b/arch/x86/include/asm/fpu/types.h
@@ -232,6 +232,12 @@ struct xstate_header {
 } __attribute__((packed));
 
 /*
+ * xstate_header.xcomp_bv[63] indicates that the extended_state_area
+ * is in compacted format.
+ */
+#define XCOMP_BV_COMPACTED_FORMAT ((u64)1 << 63)
+
+/*
  * This is our most modern FPU state format, as saved by the XSAVE
  * and restored by the XRSTOR instructions.
  *
diff --git a/arch/x86/kernel/fpu/core.c b/arch/x86/kernel/fpu/core.c
index c759bd0..3fc03a0 100644
--- a/arch/x86/kernel/fpu/core.c
+++ b/arch/x86/kernel/fpu/core.c
@@ -8,6 +8,7 @@
 #include <asm/fpu/internal.h>
 #include <asm/fpu/regset.h>
 #include <asm/fpu/signal.h>
+#include <asm/fpu/types.h>
 #include <asm/traps.h>
 
 #include <linux/hardirq.h>
@@ -229,6 +230,13 @@ void fpstate_init(union fpregs_state *state)
 
 	memset(state, 0, fpu_kernel_xstate_size);
 
+	/*
+	 * XRSTORS requires that this bit is set in xcomp_bv, or
+	 * it will #GP. Make sure it is replaced after the memset().
+	 */
+	if (static_cpu_has(X86_FEATURE_XSAVES))
+		state->xsave.header.xcomp_bv = XCOMP_BV_COMPACTED_FORMAT;
+
 	if (static_cpu_has(X86_FEATURE_FXSR))
 		fpstate_init_fxstate(&state->fxsave);
 	else

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web