From nobody Mon Mar 23 21:25:01 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) client-ip=192.237.175.120; envelope-from=xen-devel-bounces@lists.xenproject.org; helo=lists.xenproject.org; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass(p=reject dis=none) header.from=citrix.com ARC-Seal: i=1; a=rsa-sha256; t=1773923181; cv=none; d=zohomail.com; s=zohoarc; b=cJU6oaLzSsg/R/mZI4iunwAF+XWeT4J6Y7onl1wu5ckB5ub9al0OpRkkHwlCCYhFaM9H5Q2PDdYB4zYd1LjFa0FzNGmC7aCHluEKMbbeP22O3R6pbuD6r6uou5ueAgglN5he0l8hHJ0W9KD/6hCG+rSi1og5ElsGdw7h8ieb/v8= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1773923181; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=DfzaREpgue5aOwMwONNRYs0JWFfpCu2AsihViVXhTqA=; b=RhWTn5U8aVAltj8WLrmFgkRaSIqdtzaifoWOy5s/tRz/kQfj/iYAVuzU1de2Hey/TX+gaQgubRRtchchiNqXzSS938InYq/bSyvgYzK8eVq8zKRYFBIdsLjne/XIpISS8u+5+F1vsOKO7zGJUvfi+VuAEWac4VQrcxGmnW03HME= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) by mx.zohomail.com with SMTPS id 1773923181768978.8369064543956; Thu, 19 Mar 2026 05:26:21 -0700 (PDT) Received: from list by lists.xenproject.org with outflank-mailman.1257011.1551460 (Exim 4.92) (envelope-from ) id 1w3CRp-0007r6-0R; Thu, 19 Mar 2026 12:25:57 +0000 Received: by outflank-mailman (output) from mailman id 1257011.1551460; Thu, 19 Mar 2026 12:25:56 +0000 Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1w3CRo-0007qz-Th; Thu, 19 Mar 2026 12:25:56 +0000 Received: by outflank-mailman (input) for mailman id 1257011; Thu, 19 Mar 2026 12:25:55 +0000 Received: from se1-gles-sth1-in.inumbo.com ([159.253.27.254] helo=se1-gles-sth1.inumbo.com) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1w3CRn-0007dl-I3 for xen-devel@lists.xenproject.org; Thu, 19 Mar 2026 12:25:55 +0000 Received: from mail-wm1-x32a.google.com (mail-wm1-x32a.google.com [2a00:1450:4864:20::32a]) by se1-gles-sth1.inumbo.com (Halon) with ESMTPS id c65eee1b-238e-11f1-b164-2bf370ae4941; Thu, 19 Mar 2026 13:25:54 +0100 (CET) Received: by mail-wm1-x32a.google.com with SMTP id 5b1f17b1804b1-486fd5360d4so2517205e9.1 for ; Thu, 19 Mar 2026 05:25:54 -0700 (PDT) Received: from localhost.localdomain (host-92-22-18-152.as13285.net. [92.22.18.152]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-486f8c350aesm60831395e9.4.2026.03.19.05.25.53 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 19 Mar 2026 05:25:53 -0700 (PDT) X-Outflank-Mailman: Message body and most headers restored to incoming version X-BeenThere: xen-devel@lists.xenproject.org List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Precedence: list Sender: "Xen-devel" X-Inumbo-ID: c65eee1b-238e-11f1-b164-2bf370ae4941 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=citrix.com; s=google; t=1773923154; x=1774527954; darn=lists.xenproject.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=DfzaREpgue5aOwMwONNRYs0JWFfpCu2AsihViVXhTqA=; b=jQulXTJyAiUaesbJ/uWRJCcVcZYa0XFWr2GPcdU795QS1uWDctqVWOANEC9FppQubO c95d4KXGMqEGbBy8FScP30iD/eo0Lf9iJnWICgJUpkzJxCpcuT1xKcNgBfKjEhczmCv3 MbwqenpmksJmr736mcQ65dt1UCuPv9/vD7LWI= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1773923154; x=1774527954; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=DfzaREpgue5aOwMwONNRYs0JWFfpCu2AsihViVXhTqA=; b=CVQ5iQ6mX3pWXjT7j0lGE8EKwVGN9evUQYt+QHHwF8B4uRJQXp7Gkvu/HwZqmmBegU 13GpALh5ISMg+U2i9PQuuwtANVrhF66kuRvRWmR02Bmdb6uDSJLPvYix1OLa+F/Wd+p9 CqTXaeDbsirBrMicwAklwPB9ShzcsGSVWEn6ytrPsgUZdxI54RzsA0xRxasQqePOnmJ+ QECoRGtEF+4GSAY1Is0nxtegWMN3MirVhTGsiLep4IdxCXqv2sfYKoRG5lBE8YeSpXCi lpKvulOxlAJvQFiSUGUvMXeDyADr78yvb6c5c9WnoYWTKRQXlb4CMt5r4H9S3wH2Nz6f 7e1w== X-Gm-Message-State: AOJu0YxdGigkZCYa9lb1a+3z4Ldq+mNQ9rYauoiVtyvIvsYDWG+p1fOP 9GojqEUe+2gctSVhqIum2kQqpiABHEQI/tcF4Qj8DvxBSI7gOqLoiZ2ljL+9IaFppXFoqYV2zY6 ajwse X-Gm-Gg: ATEYQzxOoZZmPz7Dq7nnY2zQk/hPTNsybZlQ3PXJ45NQFisVaeUiOBVUxYDsKcGVptM 55jhlyiAAUJw5Jqw3uFvK7DgRDb1PcZsLeNOm+NyrbfBLnAT53vjlX+EpVXq3mSzG6UNKp/enSp 2Os960FhCqZ+77J20OAbQQPOcOXIA8P/A1Dstd2oLExem1S+L+y62MxlYh9OZlMsM2v/d1ux2pA EO4Kpul0kN3o9EXi6aZAhjIatpfRLSmUFxo8n4ynLzBQ5MMmJkFs3QnizTVKrP9O8L5NtMmwus0 B5rOMIHHrqfZR0s4araOYeSOYL9L/lTQHvBWbbrm+oM59l5GV7yA5RSo4Cw2Eb6F42UhGSxe6RS 9neXWBVB/nxeD7CDSfNdU9Py1l27OT15w9yDYmFxslkyzKfvKDl0o1T/nXNYekSHsC+UTBwbB1P GzQpWgs4l8KyKOi1pW8+hf0NfuHrgdDU8Jm0eJj0NTbWOLOI0vxXsx0WCL9tlcUQKOqkIQmxw= X-Received: by 2002:a05:600c:8218:b0:47e:e57d:404 with SMTP id 5b1f17b1804b1-486f4475336mr131451655e9.16.1773923153601; Thu, 19 Mar 2026 05:25:53 -0700 (PDT) From: Andrew Cooper To: Xen-devel Cc: Andrew Cooper , Jan Beulich , =?UTF-8?q?Roger=20Pau=20Monn=C3=A9?= Subject: [PATCH 3/4] x86/kexec: Invalidate the IDT earlier in kexec_reloc() Date: Thu, 19 Mar 2026 12:25:48 +0000 Message-Id: <20260319122549.922724-4-andrew.cooper3@citrix.com> X-Mailer: git-send-email 2.39.5 In-Reply-To: <20260319122549.922724-1-andrew.cooper3@citrix.com> References: <20260319122549.922724-1-andrew.cooper3@citrix.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-ZohoMail-DKIM: pass (identity @citrix.com) X-ZM-MESSAGEID: 1773923183707154100 After switching stack, it is not safe to run any exception handlers, because attempts to access the cpu_info block are out-of-bounds and will generate w= ild accesses. Invalidating the IDT in the common path means there's no need to do so again in the 32bit path, so drop compat_mode_idt entirely. Signed-off-by: Andrew Cooper --- CC: Jan Beulich CC: Roger Pau Monn=C3=A9 --- xen/arch/x86/x86_64/kexec_reloc.S | 17 ++++++++++------- 1 file changed, 10 insertions(+), 7 deletions(-) diff --git a/xen/arch/x86/x86_64/kexec_reloc.S b/xen/arch/x86/x86_64/kexec_= reloc.S index d0951ea1e1c4..7a6dd2cbe736 100644 --- a/xen/arch/x86/x86_64/kexec_reloc.S +++ b/xen/arch/x86/x86_64/kexec_reloc.S @@ -44,6 +44,16 @@ FUNC(kexec_reloc, PAGE_SIZE) =20 movq %rcx, %rbp =20 + /* + * Invalidate the IDT. After switching off Xen's stacks, the + * exception handlers are unsafe to use, because there's no way to + * perform arithmetic on the stack pointer to find the cpu_info bl= ock. + */ + push $0 + pushw $0 + lidt (%rsp) + add $10, %rsp + /* * Move to the identity mapped stack. * @@ -94,8 +104,6 @@ FUNC(kexec_reloc, PAGE_SIZE) jmp *%rbp =20 .L_call_32_bit: - /* Setup IDT. */ - lidt compat_mode_idt(%rip) =20 /* Load compat GDT. */ leaq compat_mode_gdt(%rip), %rax @@ -202,11 +210,6 @@ DATA_LOCAL(compat_mode_gdt, 8) .Lcompat_mode_gdt_end: END(compat_mode_gdt) =20 -DATA_LOCAL(compat_mode_idt) - .word 0 /* limit */ - .long 0 /* base */ -END(compat_mode_idt) - /* * 16 words of stack are more than enough. */ --=20 2.39.5