From nobody Mon Aug 24 12:05:08 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) client-ip=192.237.175.120; envelope-from=xen-devel-bounces@lists.xenproject.org; helo=lists.xenproject.org; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass(p=quarantine dis=none) header.from=suse.com ARC-Seal: i=1; a=rsa-sha256; t=1785148023; cv=none; d=zohomail.com; s=zohoarc; b=JgJBHu+n7LRTt5PHR+6pGD4R/LO3JMINMaJnDP6k3phRuYj0cj577sVkbGqAJooSM0VfDITEpRnmWTQ4FgpCkfizzoXtGcTajk/1qdgKDQbs+Rz3crBcpdqUq0LkBXh6kPYeYM6OVglfTEjpdXz6Zs8RLy11NXfWn6nsY3WrLHc= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785148023; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=Eq3L92UEoRxPUDevKKidczlzaLrrDa3AHj+IVLVm+uI=; b=CQfD+v6X7LuEhfo5VYblmTDn7rx6wVDa9X/5P8sARW2Sfbfw8v+Ipj9UYpcvbyd3EZtJTs3eAb+ywi7BgJFcUugSKSRHvrEAcQ0mxPEzyz9fIVqcUfJHzf54DsjbwtUVhU/Fu8/JEhHg4ITIsIgdj/Dzfh496pE6uYwMMjdPIaw= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) by mx.zohomail.com with SMTPS id 1785148023331873.770859958656; Mon, 27 Jul 2026 03:27:03 -0700 (PDT) Received: from list by lists.xenproject.org with outflank-mailman.1371542.1619036 (Exim 4.92) (envelope-from ) id 1woIXn-0000th-NC; Mon, 27 Jul 2026 10:26:47 +0000 Received: by outflank-mailman (output) from mailman id 1371542.1619036; Mon, 27 Jul 2026 10:26:47 +0000 Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1woIXn-0000ta-KJ; Mon, 27 Jul 2026 10:26:47 +0000 Received: by outflank-mailman (input) for mailman id 1371542; Mon, 27 Jul 2026 10:26:46 +0000 Received: from mx.expurgate.net ([194.145.224.10]) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1woIXl-0000tL-SI for xen-devel@lists.xenproject.org; Mon, 27 Jul 2026 10:26:45 +0000 Received: from mx.expurgate.net (helo=localhost) by mx.expurgate.net with esmtp id 1woIXl-00DYXp-8V for xen-devel@lists.xenproject.org; Mon, 27 Jul 2026 12:26:45 +0200 Received: from [10.42.69.2] (helo=localhost) by localhost with ESMTP (eXpurgate MTA 0.9.1) (envelope-from ) id 6a673253-5cb7-0a2a0a5109dd-0a2a4502c71e-26 for ; Mon, 27 Jul 2026 12:26:45 +0200 Received: from [209.85.221.51] (helo=mail-wr1-f51.google.com) by tlsNG-720697.mxtls.expurgate.net with ESMTPS (eXpurgate 4.57.1) (envelope-from ) id 6a673265-6ca4-0a2a45020019-d155dd33b461-3 for ; Mon, 27 Jul 2026 12:26:45 +0200 Received: by mail-wr1-f51.google.com with SMTP id ffacd0b85a97d-47f81a3ccf9so1543691f8f.0 for ; Mon, 27 Jul 2026 03:26:45 -0700 (PDT) Received: from [10.156.60.236] (ip-037-024-206-209.um08.pools.vodafone-ip.de. [37.24.206.209]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-47f9c4fe4c5sm28224132f8f.12.2026.07.27.03.26.43 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Mon, 27 Jul 2026 03:26:44 -0700 (PDT) X-Outflank-Mailman: Message body and most headers restored to incoming version X-BeenThere: xen-devel@lists.xenproject.org List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Precedence: list Sender: "Xen-devel" Authentication-Results: eu.smtp.expurgate.cloud; dkim=pass header.s=google header.d=suse.com header.i="@suse.com" header.h="Content-Transfer-Encoding:Content-Type:In-Reply-To:Autocrypt:Content-Language:References:Cc:To:From:Subject:User-Agent:MIME-Version:Date:Message-ID" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.com; s=google; t=1785148004; x=1785752804; darn=lists.xenproject.org; h=content-transfer-encoding:content-type:in-reply-to:autocrypt :content-language:references:cc:to:from:subject:user-agent :mime-version:date:message-id:from:to:cc:subject:date:message-id :reply-to:content-type; bh=Eq3L92UEoRxPUDevKKidczlzaLrrDa3AHj+IVLVm+uI=; b=DaGdObOTAXmM5M+BJUbSGDeIQgCvWBe/d1LjvpdwyQh6GWVdg2qSX0s91djEQmsK9i Rxzs459hWzo37t5h7PVDdOB2gKuHsxN9rXOo4W1lfkrjnCj3wvsOu8SVhz74JxcJJK42 Sdq0iEJV7Qf610f3tj5tq4N2+bZGAB7PKa3Rt07xvFd2+O/AL5n6X2haqFFu6zE8hew9 Uc8NmFc1k1UVHXJ1zGGZ1OE7QX570x2EW9H838Mm7olv5IboRK66nUKZoxCd0c/cCk8y xdCyEIWEvfDQi8D8NbSYA+x0U368Mulj0CycA6GsbYMjPT0MUu5pdpPlp9hzieheMnpq mlfA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785148004; x=1785752804; h=content-transfer-encoding:content-type:in-reply-to:autocrypt :content-language:references:cc:to:from:subject:user-agent :mime-version:date:message-id:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to:content-type; bh=Eq3L92UEoRxPUDevKKidczlzaLrrDa3AHj+IVLVm+uI=; b=e7Tjjtgh8HkeIooV7XSp/bpkCPaik2USpkioBNNcVa8mx8GHAOxM6a/R3eaT4D7LOZ n7rbDAlHUcFvjsF8+1cxFFN/8aNeOAQnVlrHb4K3pMmY7B6d4tEdn3XIUhSzOgpTfbHV Bvcmd+2GM6YbNUmwzinSmSUXHa+zvD+w/IulHaD2QjMcHtZvIwcNkDwiD+BG5jwUCJcn MpIChFMhHxSV4gcuqrTMdYxDR1FEftGt6apZprG0ALFLSjq2RzPLED3KDSU9/DoiXIyG /nTPwY4rK+i49MGVG4hTRybf48nUamlp/FCRX/zymMj/Wi19b12c+Cox6Hf9RcAprAM0 oT6A== X-Gm-Message-State: AOJu0YzVlJU4p1Y92Pol5v4Dgj7rWd4b6e6vuSnk/kSxlLBD3ePqQLjD 91gh3uZJ6MdOqHLME5J/MXtJG36uM8Sexl9TvS2NjZ26DcKsNhKrzwqhsQ3DfOTXP1aOMU7kDAe RfytCjA== X-Gm-Gg: AR+sD13KsGBKZGcVm4Y009IGmiBKCcp2n5eGb9eilfFdUBAkSXtaNIJZ8pw/N7LDkGT z9dkKryVWUL3Qxg532kWa5gKSiJf4m4pLVZmQC8XII7jMY6tWiq9lIpO6xwIDHBkYNuAzgNknyp K9p9llciHLWXCDMYGrgocqI0Uj8YFVAaaPrg5Ovtr/8MH8TqiT/MZoP9F2wnTEbeaq9ZUMeT42g gzhpEW8mMUqKbfF62eRTCTgytTD6aGIg1bCzq9/MxUcPRy32s80Anht7n9aK7oOT1nj394a4ChU JKODGkvPHHeuCW7uXWj8f3ubV6BlSAablfXNOkJRq4XE3pOrIAEO6GXj+erdl7I3ypn5xrIkC5c ucKBUwZZYEttPRPdgVZJ8ycx7/0pWT6xa6X3Azk+b8t3W+5IM+cXVoI7C5mk+6yptSSTOVa95Bq 6GA3jGUvN3pFQoBqiE1rRykeS7r+9Snx36k5Rkc2zyLTiaQC784pG4kJd9SUtxqgOfUg== X-Received: by 2002:a05:6000:480d:b0:476:681c:4642 with SMTP id ffacd0b85a97d-47f9feabd4dmr9936682f8f.44.1785148004570; Mon, 27 Jul 2026 03:26:44 -0700 (PDT) Message-ID: <26f23087-e864-47de-84b9-0e3dc10dc941@suse.com> Date: Mon, 27 Jul 2026 12:26:43 +0200 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: [PATCH v4 1/4] x86: record SSP at non-guest entry points From: Jan Beulich To: "xen-devel@lists.xenproject.org" Cc: Andrew Cooper , Teddy Astie , =?UTF-8?Q?Roger_Pau_Monn=C3=A9?= References: Content-Language: en-US Autocrypt: addr=jbeulich@suse.com; keydata= xsDiBFk3nEQRBADAEaSw6zC/EJkiwGPXbWtPxl2xCdSoeepS07jW8UgcHNurfHvUzogEq5xk hu507c3BarVjyWCJOylMNR98Yd8VqD9UfmX0Hb8/BrA+Hl6/DB/eqGptrf4BSRwcZQM32aZK 7Pj2XbGWIUrZrd70x1eAP9QE3P79Y2oLrsCgbZJfEwCgvz9JjGmQqQkRiTVzlZVCJYcyGGsD /0tbFCzD2h20ahe8rC1gbb3K3qk+LpBtvjBu1RY9drYk0NymiGbJWZgab6t1jM7sk2vuf0Py O9Hf9XBmK0uE9IgMaiCpc32XV9oASz6UJebwkX+zF2jG5I1BfnO9g7KlotcA/v5ClMjgo6Gl MDY4HxoSRu3i1cqqSDtVlt+AOVBJBACrZcnHAUSuCXBPy0jOlBhxPqRWv6ND4c9PH1xjQ3NP nxJuMBS8rnNg22uyfAgmBKNLpLgAGVRMZGaGoJObGf72s6TeIqKJo/LtggAS9qAUiuKVnygo 3wjfkS9A3DRO+SpU7JqWdsveeIQyeyEJ/8PTowmSQLakF+3fote9ybzd880fSmFuIEJldWxp Y2ggPGpiZXVsaWNoQHN1c2UuY29tPsJgBBMRAgAgBQJZN5xEAhsDBgsJCAcDAgQVAggDBBYC AwECHgECF4AACgkQoDSui/t3IH4J+wCfQ5jHdEjCRHj23O/5ttg9r9OIruwAn3103WUITZee e7Sbg12UgcQ5lv7SzsFNBFk3nEQQCACCuTjCjFOUdi5Nm244F+78kLghRcin/awv+IrTcIWF hUpSs1Y91iQQ7KItirz5uwCPlwejSJDQJLIS+QtJHaXDXeV6NI0Uef1hP20+y8qydDiVkv6l IreXjTb7DvksRgJNvCkWtYnlS3mYvQ9NzS9PhyALWbXnH6sIJd2O9lKS1Mrfq+y0IXCP10eS FFGg+Av3IQeFatkJAyju0PPthyTqxSI4lZYuJVPknzgaeuJv/2NccrPvmeDg6Coe7ZIeQ8Yj t0ARxu2xytAkkLCel1Lz1WLmwLstV30g80nkgZf/wr+/BXJW/oIvRlonUkxv+IbBM3dX2OV8 AmRv1ySWPTP7AAMFB/9PQK/VtlNUJvg8GXj9ootzrteGfVZVVT4XBJkfwBcpC/XcPzldjv+3 HYudvpdNK3lLujXeA5fLOH+Z/G9WBc5pFVSMocI71I8bT8lIAzreg0WvkWg5V2WZsUMlnDL9 mpwIGFhlbM3gfDMs7MPMu8YQRFVdUvtSpaAs8OFfGQ0ia3LGZcjA6Ik2+xcqscEJzNH+qh8V m5jjp28yZgaqTaRbg3M/+MTbMpicpZuqF4rnB0AQD12/3BNWDR6bmh+EkYSMcEIpQmBM51qM EKYTQGybRCjpnKHGOxG0rfFY1085mBDZCH5Kx0cl0HVJuQKC+dV2ZY5AqjcKwAxpE75MLFkr wkkEGBECAAkFAlk3nEQCGwwACgkQoDSui/t3IH7nnwCfcJWUDUFKdCsBH/E5d+0ZnMQi+G0A nAuWpQkjM1ASeQwSHEeAWPgskBQL In-Reply-To: Content-Transfer-Encoding: quoted-printable X-purgate-ID: tlsNG-720697/1785148005-319CB2AC-99764C5A/0/0 X-purgate-type: clean X-purgate-size: 6127 X-ZohoMail-DKIM: pass (identity @suse.com) X-ZM-MESSAGEID: 1785148023829158500 Content-Type: text/plain; charset="utf-8" We will want to use that value for call trace generation, and likely also to eliminate the somewhat fragile shadow stack searching done in fixup_exception_return(). For those purposes, guest-only entry points do not need to record that value. To keep the saving code simple, record our own SSP that corresponds to an exception frame, pointing to the top of the shadow stack counterpart of what the CPU has saved on the regular stack. Consuming code can then work its way from there. In SAVE_ALL / RESTORE_ALL simply drop the use of UREGS_r15. We want the full size in all cases, so what exactly the top-of-stack field is going to be (whose UREGS_* is 0 anyway) doesn't matter this much there. This way we don't need to distinguish between XEN_SHSTK=3Dy and XEN_SHSTK=3Dn. Signed-off-by: Jan Beulich --- v4: Re-base. v3: Put new field at the front of struct cpu_user_regs. v2: Add comment ahead of SAVE_ALL. Add comma between its parameters. Re-base. --- a/xen/arch/x86/hvm/svm/entry.S +++ b/xen/arch/x86/hvm/svm/entry.S @@ -89,7 +89,7 @@ __UNLIKELY_END(nsvm_hap) =20 vmrun =20 - PUSH_AND_CLEAR_GPRS + PUSH_AND_CLEAR_GPRS ssp=3D0 =20 GET_CURRENT(bx) =20 --- a/xen/arch/x86/hvm/vmx/entry.S +++ b/xen/arch/x86/hvm/vmx/entry.S @@ -22,7 +22,7 @@ #include =20 FUNC(vmx_asm_vmexit_handler) - PUSH_AND_CLEAR_GPRS + PUSH_AND_CLEAR_GPRS ssp=3D0 =20 mov %cr2,%rax GET_CURRENT(bx) @@ -157,7 +157,7 @@ UNLIKELY_END(realmode) =20 .Lvmx_vmentry_fail: sti - PUSH_AND_CLEAR_GPRS + PUSH_AND_CLEAR_GPRS ssp=3D0 =20 /* * SPEC_CTRL_ENTRY notes --- a/xen/arch/x86/include/asm/asm_defns.h +++ b/xen/arch/x86/include/asm/asm_defns.h @@ -220,9 +220,11 @@ static always_inline void stac(void) =20 #ifdef __ASSEMBLER__ /* - * Push and clear GPRs + * Push and clear GPRs. + * + * Use sites may override ssp to 0. It should never be overridden to 1. */ -.macro PUSH_AND_CLEAR_GPRS +.macro PUSH_AND_CLEAR_GPRS ssp=3DIS_ENABLED(CONFIG_XEN_SHSTK) push %rdi xor %edi, %edi push %rsi @@ -233,6 +235,9 @@ static always_inline void stac(void) xor %ecx, %ecx push %rax xor %eax, %eax + .if \ssp + rdsspq %rcx + .endif push %r8 xor %r8d, %r8d push %r9 @@ -259,12 +264,18 @@ static always_inline void stac(void) xor %r14d, %r14d push %r15 xor %r15d, %r15d +#ifdef CONFIG_XEN_SHSTK + push %rcx +#endif .endm =20 /* * POP GPRs from a UREGS_* frame on the stack. Does not modify flags. */ .macro POP_GPRS skip_rax=3D0 +#ifdef CONFIG_XEN_SHSTK + pop %rcx +#endif pop %r15 pop %r14 pop %r13 --- a/xen/arch/x86/include/asm/cpu-user-regs.h +++ b/xen/arch/x86/include/asm/cpu-user-regs.h @@ -11,6 +11,15 @@ */ struct cpu_user_regs { +#ifdef CONFIG_XEN_SHSTK + /* + * This points _at_ the corresponding shadow stack frame; it is _not_ = the + * outer context's SSP. That, if the outer context has CET-SS enabled, + * is stored in the top slot of the pointed to shadow stack. + */ + uint64_t entry_ssp; +#endif + union { uint64_t r15; uint32_t r15d; uint16_t r15w; uint8_t r15b= ; }; union { uint64_t r14; uint32_t r14d; uint16_t r14w; uint8_t r14b= ; }; union { uint64_t r13; uint32_t r13d; uint16_t r13w; uint8_t r13b= ; }; --- a/xen/arch/x86/x86_64/asm-offsets.c +++ b/xen/arch/x86/x86_64/asm-offsets.c @@ -53,6 +53,9 @@ void __dummy__(void) OFFSET(UREGS_eflags, struct cpu_user_regs, rflags); OFFSET(UREGS_rsp, struct cpu_user_regs, rsp); OFFSET(UREGS_ss, struct cpu_user_regs, ss); +#ifdef CONFIG_XEN_SHSTK + OFFSET(UREGS_entry_ssp, struct cpu_user_regs, entry_ssp); +#endif DEFINE(UREGS_kernel_sizeof, sizeof(struct cpu_user_regs)); BLANK(); =20 --- a/xen/arch/x86/x86_64/compat/entry.S +++ b/xen/arch/x86/x86_64/compat/entry.S @@ -18,7 +18,7 @@ FUNC(entry_int82) ALTERNATIVE "", clac, X86_FEATURE_XEN_SMAP pushq $0 movb $HYPERCALL_VECTOR, EFRAME_entry_vector(%rsp) - PUSH_AND_CLEAR_GPRS + PUSH_AND_CLEAR_GPRS ssp=3D0 =20 GET_STACK_END(14) =20 --- a/xen/arch/x86/x86_64/entry.S +++ b/xen/arch/x86/x86_64/entry.S @@ -305,7 +305,7 @@ FUNC(lstar_enter) pushq $0 BUILD_BUG_ON(TRAP_syscall & 0xff) movb $TRAP_syscall >> 8, EFRAME_entry_vector + 1(%rsp) - PUSH_AND_CLEAR_GPRS + PUSH_AND_CLEAR_GPRS ssp=3D0 =20 GET_STACK_END(14) =20 @@ -345,7 +345,7 @@ FUNC(cstar_enter) pushq $0 BUILD_BUG_ON(TRAP_syscall & 0xff) movb $TRAP_syscall >> 8, EFRAME_entry_vector + 1(%rsp) - PUSH_AND_CLEAR_GPRS + PUSH_AND_CLEAR_GPRS ssp=3D0 =20 GET_STACK_END(14) =20 @@ -390,7 +390,7 @@ LABEL(sysenter_eflags_saved, 0) pushq $0 BUILD_BUG_ON(TRAP_syscall & 0xff) movb $TRAP_syscall >> 8, EFRAME_entry_vector + 1(%rsp) - PUSH_AND_CLEAR_GPRS + PUSH_AND_CLEAR_GPRS ssp=3D0 =20 GET_STACK_END(14) =20 @@ -447,7 +447,7 @@ FUNC(entry_int80) ALTERNATIVE "", clac, X86_FEATURE_XEN_SMAP pushq $0 movb $0x80, EFRAME_entry_vector(%rsp) - PUSH_AND_CLEAR_GPRS + PUSH_AND_CLEAR_GPRS ssp=3D0 =20 GET_STACK_END(14) =20 --- a/xen/arch/x86/x86_64/entry-fred.S +++ b/xen/arch/x86/x86_64/entry-fred.S @@ -11,7 +11,7 @@ /* The Ring3 entry point is required to be 4k aligned. */ =20 FUNC(entry_FRED_R3, 4096) - PUSH_AND_CLEAR_GPRS + PUSH_AND_CLEAR_GPRS ssp=3D0 =20 mov %rsp, %rdi call entry_from_pv @@ -54,7 +54,7 @@ LABEL(eretu, 0) END(eretu_exit_to_guest) =20 FUNC(eretu_error_dom_crash) - PUSH_AND_CLEAR_GPRS + PUSH_AND_CLEAR_GPRS ssp=3D0 sti call asm_domain_crash_synchronous /* Does not return */ END(eretu_error_dom_crash) From nobody Mon Aug 24 12:05:08 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) client-ip=192.237.175.120; envelope-from=xen-devel-bounces@lists.xenproject.org; helo=lists.xenproject.org; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass(p=quarantine dis=none) header.from=suse.com ARC-Seal: i=1; a=rsa-sha256; t=1785148040; cv=none; d=zohomail.com; s=zohoarc; b=NUI/jFjPSR9Pq5Zw3RhosvxO/2ck47QFk+sB3xU4l5H2KrApgc4/umcwZFnKaTMRCUw+AbeVxdU4pRsoFWFTWGgyPvZCDWVhZwZuraw9UJ0ITmlw+LkCN6hqRetzzXl51or3k5KmYeyHwVESnh0Nm2g+2JAAWJHJuw6RbAlYo4Y= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785148040; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=MgcXWj5vqnP+4zvYUktX5k7TuUXNjhHYEeS80l/cLOs=; b=gDBwrNU0WN3Sh75JOCeqwL664tc38sEKX7gqO0/g3JGBvVWMto3ssIK47C7qpqHh0vLFFu0rlNh4cn9TTaR9bEkhJocVo8F2YyBcmPJ2wRVv66TIe7XNrxmVkWMLZ+jzYCiGkCQuTQhgXNhKMFSJeZbBmyIKBtUpkVOpBbTTqX0= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) by mx.zohomail.com with SMTPS id 17851480402340.7665703333326519; Mon, 27 Jul 2026 03:27:20 -0700 (PDT) Received: from list by lists.xenproject.org with outflank-mailman.1371545.1619045 (Exim 4.92) (envelope-from ) id 1woIY6-0001Gs-Tq; Mon, 27 Jul 2026 10:27:06 +0000 Received: by outflank-mailman (output) from mailman id 1371545.1619045; Mon, 27 Jul 2026 10:27:06 +0000 Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1woIY6-0001Gl-RC; Mon, 27 Jul 2026 10:27:06 +0000 Received: by outflank-mailman (input) for mailman id 1371545; Mon, 27 Jul 2026 10:27:05 +0000 Received: from mx.expurgate.net ([194.145.224.20]) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1woIY5-0001FI-51 for xen-devel@lists.xenproject.org; Mon, 27 Jul 2026 10:27:05 +0000 Received: from mx.expurgate.net (helo=localhost) by mx.expurgate.net with esmtp id 1woIY4-000tj7-Hv for xen-devel@lists.xenproject.org; Mon, 27 Jul 2026 12:27:04 +0200 Received: from [10.42.69.9] (helo=localhost) by localhost with ESMTP (eXpurgate MTA 0.9.1) (envelope-from ) id 6a673277-5cb7-0a2a0a5109dd-0a2a4509e17c-10 for ; Mon, 27 Jul 2026 12:27:04 +0200 Received: from [209.85.128.44] (helo=mail-wm1-f44.google.com) by tlsNG-bad1c0.mxtls.expurgate.net with ESMTPS (eXpurgate 4.57.1) (envelope-from ) id 6a673278-be1a-0a2a45090019-d155802ce90d-3 for ; Mon, 27 Jul 2026 12:27:04 +0200 Received: by mail-wm1-f44.google.com with SMTP id 5b1f17b1804b1-4955de8797cso15396365e9.3 for ; Mon, 27 Jul 2026 03:27:04 -0700 (PDT) Received: from [10.156.60.236] (ip-037-024-206-209.um08.pools.vodafone-ip.de. [37.24.206.209]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-496b499cc49sm239774435e9.9.2026.07.27.03.27.03 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Mon, 27 Jul 2026 03:27:03 -0700 (PDT) X-Outflank-Mailman: Message body and most headers restored to incoming version X-BeenThere: xen-devel@lists.xenproject.org List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Precedence: list Sender: "Xen-devel" Authentication-Results: eu.smtp.expurgate.cloud; dkim=pass header.s=google header.d=suse.com header.i="@suse.com" header.h="Content-Transfer-Encoding:Content-Type:In-Reply-To:Autocrypt:Content-Language:References:Cc:To:From:Subject:User-Agent:MIME-Version:Date:Message-ID" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.com; s=google; t=1785148024; x=1785752824; darn=lists.xenproject.org; h=content-transfer-encoding:content-type:in-reply-to:autocrypt :content-language:references:cc:to:from:subject:user-agent :mime-version:date:message-id:from:to:cc:subject:date:message-id :reply-to:content-type; bh=MgcXWj5vqnP+4zvYUktX5k7TuUXNjhHYEeS80l/cLOs=; b=afG9qVNUStF4s0dDBTtkepAZmquBZfkIiyl9tusYIPnkQs5zjffWVLnp/e7jhKZpJT 4bae1XomRmPuKyXpcbt8w1m/7ql1Blo9pdbnY6h9pycAAjvsiPyBaOzjOjWOV+YWVY4O ieZd4rBdOOZ8mylrgvTAZQyAJO/JcGe110QmmfL0GTRxfx2qrwie1X+YWP/TTcqoD6q2 tntmRjQcyLh+wV+c5dH1VsEXhe7Kj7X4jy7bfTJ/VGOdRabboHTPL4af+hNEYaD8j67z wx0zmhfCKlXQ5DEWTy3k5MdybnMMLPUgwLxqWZQdnZ39QwNCLVR9YH9gNeKoXEak8Bxh 4tFg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785148024; x=1785752824; h=content-transfer-encoding:content-type:in-reply-to:autocrypt :content-language:references:cc:to:from:subject:user-agent :mime-version:date:message-id:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to:content-type; bh=MgcXWj5vqnP+4zvYUktX5k7TuUXNjhHYEeS80l/cLOs=; b=pVEw5r5uTsFjdwnQw0WKoAE66cn+sfveprML+1Aws4TpsyGpUsYMlAlUOdWbQ4casJ 3KcwUgGYljK21GW6V1ncat/vp49zvcU4yrUWXRXfMYF9MEOWVsyGFI5pQruWVDdxFqan ODczxyr+Gic6HLiJx8HVTvi0ubDzIeaidkAuJYG8YovCTzLeLSApnybhEHyUkmZPTBQJ fRPIjNRlHdBF0Vg07zBuJh/4M3x6vW1v87a33wcKirIPlO133FU+WdE089S+HFMMKEJV LLCiF1sIwMpFz+PppGktSRCJESQ2npzSOqwMdzELF+HbsDIAsuvinFVTsPRg1a9Zowv1 fnZw== X-Gm-Message-State: AOJu0YxubXqt4NovywVnxdFjGmmASGHWRxVaOd8Nl6LrOwSk3pANCML8 9kIA70KuAxYM0vBsx06Wi1P9ZlJ2iGMLf6DBhXVe9s6EqW5f7Qpjitov+eFv99CtehaBzOvSy9+ byDEGAg== X-Gm-Gg: AR+sD102XxdqgWEPZnqNsx+CDqUOCYWFhevaJN6FC9UX3oYK4ptxcz3DrR9HoVMOY98 qZ4qH9OXeTEdHQB8zBkLDxiYLI5n3fHLbOLILDPl2GEL84bfIgZIGjmM40uHx9HZwV8uWQ6G1VF dvCntbiASnq249tSDU2kV1MXAMU0c+iilRtghT5QZ7C2gLfirScM5kAa4ttCDy6QPwdrHExImUX zJVcdeQ4JtGIzsd6T0r/NQT6JfhevWcoBNZfFlwrK8IZCTwFyWm0XAyJHOzhiAXUbvVHxfJIPcz KBe3vud7ERmjhUvvfmTPcgN6KVIihv0OH1ZSZxkyL8ZWRPP3PDhIGa4lAiAHT0R9OlyKLfRn7WR BefgCaWzCpzzusZq4DLq7MmPeBMrnSmWwWfasWUMhDsMdS1/E+W4Bh2zA74cKIIJZZ3mP10BPz6 DmHGkz3RtZ/Bv1TXWlgoLQtDIUaarKolozywKNJ3PimjyxZQWiuMeM+uPgy0KnC7WtE5MQhV7rR 36C X-Received: by 2002:a05:600c:1392:b0:493:e79e:da98 with SMTP id 5b1f17b1804b1-496bd6d22fdmr53277045e9.39.1785148023951; Mon, 27 Jul 2026 03:27:03 -0700 (PDT) Message-ID: <96f66873-5c50-4044-93f9-bcd3de717656@suse.com> Date: Mon, 27 Jul 2026 12:27:02 +0200 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: [PATCH v4 2/4] x86/traps: use entry_ssp in fixup_exception_return() From: Jan Beulich To: "xen-devel@lists.xenproject.org" Cc: Andrew Cooper , Teddy Astie , =?UTF-8?Q?Roger_Pau_Monn=C3=A9?= References: Content-Language: en-US Autocrypt: addr=jbeulich@suse.com; keydata= xsDiBFk3nEQRBADAEaSw6zC/EJkiwGPXbWtPxl2xCdSoeepS07jW8UgcHNurfHvUzogEq5xk hu507c3BarVjyWCJOylMNR98Yd8VqD9UfmX0Hb8/BrA+Hl6/DB/eqGptrf4BSRwcZQM32aZK 7Pj2XbGWIUrZrd70x1eAP9QE3P79Y2oLrsCgbZJfEwCgvz9JjGmQqQkRiTVzlZVCJYcyGGsD /0tbFCzD2h20ahe8rC1gbb3K3qk+LpBtvjBu1RY9drYk0NymiGbJWZgab6t1jM7sk2vuf0Py O9Hf9XBmK0uE9IgMaiCpc32XV9oASz6UJebwkX+zF2jG5I1BfnO9g7KlotcA/v5ClMjgo6Gl MDY4HxoSRu3i1cqqSDtVlt+AOVBJBACrZcnHAUSuCXBPy0jOlBhxPqRWv6ND4c9PH1xjQ3NP nxJuMBS8rnNg22uyfAgmBKNLpLgAGVRMZGaGoJObGf72s6TeIqKJo/LtggAS9qAUiuKVnygo 3wjfkS9A3DRO+SpU7JqWdsveeIQyeyEJ/8PTowmSQLakF+3fote9ybzd880fSmFuIEJldWxp Y2ggPGpiZXVsaWNoQHN1c2UuY29tPsJgBBMRAgAgBQJZN5xEAhsDBgsJCAcDAgQVAggDBBYC AwECHgECF4AACgkQoDSui/t3IH4J+wCfQ5jHdEjCRHj23O/5ttg9r9OIruwAn3103WUITZee e7Sbg12UgcQ5lv7SzsFNBFk3nEQQCACCuTjCjFOUdi5Nm244F+78kLghRcin/awv+IrTcIWF hUpSs1Y91iQQ7KItirz5uwCPlwejSJDQJLIS+QtJHaXDXeV6NI0Uef1hP20+y8qydDiVkv6l IreXjTb7DvksRgJNvCkWtYnlS3mYvQ9NzS9PhyALWbXnH6sIJd2O9lKS1Mrfq+y0IXCP10eS FFGg+Av3IQeFatkJAyju0PPthyTqxSI4lZYuJVPknzgaeuJv/2NccrPvmeDg6Coe7ZIeQ8Yj t0ARxu2xytAkkLCel1Lz1WLmwLstV30g80nkgZf/wr+/BXJW/oIvRlonUkxv+IbBM3dX2OV8 AmRv1ySWPTP7AAMFB/9PQK/VtlNUJvg8GXj9ootzrteGfVZVVT4XBJkfwBcpC/XcPzldjv+3 HYudvpdNK3lLujXeA5fLOH+Z/G9WBc5pFVSMocI71I8bT8lIAzreg0WvkWg5V2WZsUMlnDL9 mpwIGFhlbM3gfDMs7MPMu8YQRFVdUvtSpaAs8OFfGQ0ia3LGZcjA6Ik2+xcqscEJzNH+qh8V m5jjp28yZgaqTaRbg3M/+MTbMpicpZuqF4rnB0AQD12/3BNWDR6bmh+EkYSMcEIpQmBM51qM EKYTQGybRCjpnKHGOxG0rfFY1085mBDZCH5Kx0cl0HVJuQKC+dV2ZY5AqjcKwAxpE75MLFkr wkkEGBECAAkFAlk3nEQCGwwACgkQoDSui/t3IH7nnwCfcJWUDUFKdCsBH/E5d+0ZnMQi+G0A nAuWpQkjM1ASeQwSHEeAWPgskBQL In-Reply-To: Content-Transfer-Encoding: quoted-printable X-purgate-ID: tlsNG-bad1c0/1785148024-FC610034-78C03261/0/0 X-purgate-type: clean X-purgate-size: 5932 X-ZohoMail-DKIM: pass (identity @suse.com) X-ZM-MESSAGEID: 1785148041991158500 Content-Type: text/plain; charset="utf-8" With the value recorded on entry there's no need anymore to go hunt for the respective exception frame on the shadow stack. By deriving "ptr" from that field (without any offset), it then ends up pointing one slot lower than before. Therefore all array indexes need incrementing, nicely doing away with all the negative ones. Signed-off-by: Jan Beulich Reviewed-by: Andrew Cooper --- Indentation of the prior inner (but not innermost) if()'s body is deliberately left untouched, to aid review. It'll be adjusted in a separate follow-on patch. --- v3: Relax the first BUG_ON(). v2: IS_ENABLED() -> #ifdef. Re-base. --- a/xen/arch/x86/traps.c +++ b/xen/arch/x86/traps.c @@ -690,19 +690,6 @@ unsigned long get_stack_trace_bottom(uns } } =20 -static unsigned long get_shstk_bottom(unsigned long sp) -{ - /* SAF-11-safe */ - switch ( get_stack_page(sp) ) - { -#ifdef CONFIG_XEN_SHSTK - case 0: return ROUNDUP(sp, IST_SHSTK_SIZE) - sizeof(unsigned long); - case 5: return ROUNDUP(sp, PAGE_SIZE) - sizeof(unsigned long); -#endif - default: return sp - sizeof(unsigned long); - } -} - unsigned long get_stack_dump_bottom(unsigned long sp) { switch ( get_stack_page(sp) ) @@ -1187,26 +1174,29 @@ void asmlinkage noreturn do_unhandled_tr static void fixup_exception_return(struct cpu_user_regs *regs, unsigned long fixup, unsigned long stub= _ra) { - if ( IS_ENABLED(CONFIG_XEN_SHSTK) ) +#ifdef CONFIG_XEN_SHSTK { - unsigned long ssp, *ptr, *base; + unsigned long ssp =3D rdssp(); =20 - if ( (ssp =3D rdssp()) =3D=3D SSP_NO_SHSTK ) - goto shstk_done; + if ( ssp !=3D SSP_NO_SHSTK ) + { + unsigned long *ptr =3D _p(regs->entry_ssp); + unsigned long primary_shstk =3D + (ssp & ~(STACK_SIZE - 1)) + + (PRIMARY_SHSTK_SLOT + 1) * PAGE_SIZE - 8; =20 - ptr =3D _p(ssp); - base =3D _p(get_shstk_bottom(ssp)); + BUG_ON((regs->entry_ssp ^ primary_shstk) >> + (PAGE_SHIFT + STACK_ORDER)); =20 - for ( ; ptr < base; ++ptr ) - { /* - * Search for %rip. The shstk currently looks like this: + * The shstk currently looks like this: * * tok [Supervisor token, =3D=3D &tok | BUSY, only with FRE= D inactive] * ... [Pointed to by SSP for most exceptions, empty in IST= cases] * %cs [=3D=3D regs->cs] * %rip [=3D=3D regs->rip] - * SSP [Likely points to 3 slots higher, above %cs] + * SSP [Pointed to by entry_ssp; Likely points to 3 slots + * higher, above %cs] * ... [call tree to this function, likely 2/3 slots] * * and we want to overwrite %rip with fixup. There are two @@ -1219,13 +1209,10 @@ static void fixup_exception_return(struc * * Check for both regs->rip and regs->cs matching. */ - if ( ptr[0] =3D=3D regs->rip && ptr[1] =3D=3D regs->cs ) - { - unsigned long primary_shstk =3D - (ssp & ~(STACK_SIZE - 1)) + - (PRIMARY_SHSTK_SLOT + 1) * PAGE_SIZE - 8; + BUG_ON(ptr[1] !=3D regs->rip || ptr[2] !=3D regs->cs); =20 - wrss(fixup, ptr); + { + wrss(fixup, &ptr[1]); =20 if ( !stub_ra ) goto shstk_done; @@ -1242,7 +1229,7 @@ static void fixup_exception_return(struc * - if we're on an IST stack, we need to increment the * original SSP. */ - BUG_ON((ptr[-1] ^ primary_shstk) >> PAGE_SHIFT); + BUG_ON((ptr[0] ^ primary_shstk) >> PAGE_SHIFT); =20 if ( (ssp ^ primary_shstk) >> PAGE_SHIFT ) { @@ -1251,39 +1238,30 @@ static void fixup_exception_return(struc * addresses actually match. Then increment the inter= rupted * context's SSP. */ - BUG_ON(stub_ra !=3D *(unsigned long*)ptr[-1]); - wrss(ptr[-1] + 8, &ptr[-1]); + BUG_ON(stub_ra !=3D *(unsigned long*)ptr[0]); + wrss(ptr[0] + 8, &ptr[0]); goto shstk_done; } =20 /* Make sure the two return addresses actually match. */ - BUG_ON(stub_ra !=3D ptr[2]); + BUG_ON(stub_ra !=3D ptr[3]); =20 /* Move exception frame, updating SSP there. */ - wrss(ptr[1], &ptr[2]); /* %cs */ - wrss(ptr[0], &ptr[1]); /* %rip */ - wrss(ptr[-1] + 8, &ptr[0]); /* SSP */ + wrss(ptr[2], &ptr[3]); /* %cs */ + wrss(ptr[1], &ptr[2]); /* %rip */ + wrss(ptr[0] + 8, &ptr[1]); /* SSP */ =20 /* Move all newer entries. */ - while ( --ptr !=3D _p(ssp) ) - wrss(ptr[-1], &ptr[0]); + while ( ptr-- !=3D _p(ssp) ) + wrss(ptr[0], &ptr[1]); =20 /* Finally account for our own stack having shifted up. */ asm volatile ( "incsspd %0" :: "r" (2) ); - - goto shstk_done; } } - - /* - * We failed to locate and fix up the shadow IRET frame. This cou= ld - * be due to shadow stack corruption, or bad logic above. We cann= ot - * continue executing the interrupted context. - */ - BUG(); - } shstk_done: +#endif /* CONFIG_XEN_SHSTK */ =20 /* Fixup the regular stack. */ regs->rip =3D fixup; From nobody Mon Aug 24 12:05:08 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) client-ip=192.237.175.120; envelope-from=xen-devel-bounces@lists.xenproject.org; helo=lists.xenproject.org; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass(p=quarantine dis=none) header.from=suse.com ARC-Seal: i=1; a=rsa-sha256; t=1785148058; cv=none; d=zohomail.com; s=zohoarc; b=iwMSsFeIc36HWqEli/8m8ZSG7s0K+h53Mu3iuihN+N0RRjnIKpX0aaAEAg6SJZBLscaHNdQNKtCL1x/QUtxQ+mPQjuKS8/T7c+IzC/zHqEuYyTEo335XwUNuByPdBkcH1oE39Xz9wb4jQtF9CVZ02mDoAKVtuf3A+BFAJi9pmeI= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785148058; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=AqSjmcCLXigH7zyg0H7IqSqKdhTEi7QtkMIfRzneltA=; b=Rp6R6aB3DU+MZP5CagQleoWOVFAmCJPlaUm70jfbN6rH6rL3nf4ol0qPOmWBIcjOMnjYRx5wYUdNWiH2zHHZdyg0oXKgYyWAYGbOtu2LFpst8xh69u0sbFi/5NQz9wHbygTR7z7Fa3vpOpjuh7VjcJwrMFGG4eQRvgXiTkORRYs= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) by mx.zohomail.com with SMTPS id 1785148058060841.4151796150139; Mon, 27 Jul 2026 03:27:38 -0700 (PDT) Received: from list by lists.xenproject.org with outflank-mailman.1371551.1619055 (Exim 4.92) (envelope-from ) id 1woIYM-0001ea-8Z; Mon, 27 Jul 2026 10:27:22 +0000 Received: by outflank-mailman (output) from mailman id 1371551.1619055; Mon, 27 Jul 2026 10:27:22 +0000 Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1woIYM-0001eT-5s; Mon, 27 Jul 2026 10:27:22 +0000 Received: by outflank-mailman (input) for mailman id 1371551; Mon, 27 Jul 2026 10:27:20 +0000 Received: from mx.expurgate.net ([195.190.135.20]) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1woIYK-0001dv-KV for xen-devel@lists.xenproject.org; Mon, 27 Jul 2026 10:27:20 +0000 Received: from mx.expurgate.net (helo=localhost) by mx.expurgate.net with esmtp id 1woIYK-00GveR-18 for xen-devel@lists.xenproject.org; Mon, 27 Jul 2026 12:27:20 +0200 Received: from [10.42.69.12] (helo=localhost) by localhost with ESMTP (eXpurgate MTA 0.9.1) (envelope-from ) id 6a673282-e002-0a2a0a5209dd-0a2a450c89b0-12 for ; Mon, 27 Jul 2026 12:27:20 +0200 Received: from [209.85.221.49] (helo=mail-wr1-f49.google.com) by tlsNG-d25034.mxtls.expurgate.net with ESMTPS (eXpurgate 4.57.1) (envelope-from ) id 6a673287-f479-0a2a450c0019-d155dd31c516-3 for ; Mon, 27 Jul 2026 12:27:19 +0200 Received: by mail-wr1-f49.google.com with SMTP id ffacd0b85a97d-47640541585so1572009f8f.1 for ; Mon, 27 Jul 2026 03:27:19 -0700 (PDT) Received: from [10.156.60.236] (ip-037-024-206-209.um08.pools.vodafone-ip.de. [37.24.206.209]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-47f85bb5a46sm46860374f8f.9.2026.07.27.03.27.18 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Mon, 27 Jul 2026 03:27:19 -0700 (PDT) X-Outflank-Mailman: Message body and most headers restored to incoming version X-BeenThere: xen-devel@lists.xenproject.org List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Precedence: list Sender: "Xen-devel" Authentication-Results: eu.smtp.expurgate.cloud; dkim=pass header.s=google header.d=suse.com header.i="@suse.com" header.h="Content-Transfer-Encoding:Content-Type:In-Reply-To:Autocrypt:Content-Language:References:Cc:To:From:Subject:User-Agent:MIME-Version:Date:Message-ID" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.com; s=google; t=1785148039; x=1785752839; darn=lists.xenproject.org; h=content-transfer-encoding:content-type:in-reply-to:autocrypt :content-language:references:cc:to:from:subject:user-agent :mime-version:date:message-id:from:to:cc:subject:date:message-id :reply-to:content-type; bh=AqSjmcCLXigH7zyg0H7IqSqKdhTEi7QtkMIfRzneltA=; b=gOG9lr80GHfvCbOVLhoUNysTGWWBI1IX4mU0qBvJImtRGuf9EtWtJjw/W985QRgEtI d3DGEwEcDlZu6pDhdLIDzmYP+ptBFbedizAWPsdaQjuQPPTryASXYT++iPsq/QEJnF3q y0VoMtICgoyNwmAoKXFQPGWvjYr7uXM6ayg3k6hwLB9yr9fi/TxyNdYg3WkDDKycpHqK 8RZuIYzBXw51VEOFFHcAiNJjyhpK5zwbU921pJ8Juf+YfQBuP379TFULghZox5Ju5uNE Xf7iP5s3ZThuDZi37eYUk6eDf5ni6tnzO1qHZQ/FhRU0JeR6KC3AqLLaspLYlicUUg4H KLDA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785148039; x=1785752839; h=content-transfer-encoding:content-type:in-reply-to:autocrypt :content-language:references:cc:to:from:subject:user-agent :mime-version:date:message-id:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to:content-type; bh=AqSjmcCLXigH7zyg0H7IqSqKdhTEi7QtkMIfRzneltA=; b=gj+GUGPIBH+VPXd7bTsmWHPEoiCcrDLNWeGuIhmpH+vGyGCzLioZZDLkNKOFr5SxxB rLTBoV8OJtTV5gkRnIRYQhHyni4CwBTFuWTBg7w9EOBR3w8epFmEY/uE28H9yBt4sTjh ETnFrsCaFDXiQutoG8VAH1n5p81jq1fgJ47XUAZfI2lM8ByELDj35osnY/7a6iWbkIDA SvyCUkKxs61W5+gaRPnXj2obcdmxMnhxRW7Zr0OftASIeCM5gzkQxANL4sGNip8tw1mz CsaDM7W3s+yecru0bIHuXTGCK1v9TYp4VsrI/jaHS+npM/mElN9kc/MIq4IS7BIgCZjb vb/g== X-Gm-Message-State: AOJu0YyxT1CgEwjv9y9Lq3xuEKAU9QexT9gT2x01YlBIvtGhFVy5GiiV QHDgnXi8gZirLjg672Z0Ulgx0yaAUUx517BH28jASYUqXD5NGHUgDiDOr1YdnByWUncGBno4Rq3 mbdbIFQ== X-Gm-Gg: AR+sD11C1QBCq8ZYb5gLQhJZOxTAdSyib+MrCXGYbQ3k6P9HvfPUZKpYIrbYjZOADDN Djq1KkKYXupaRXiZZ0yLG0DBuUN4GadoBsf6nuWxaikUkdW/E86l3RDiQVaoLCwnvFw2J1BbbJU 8QKUbko9dB4Tqdh8HmDBBpuxcpEDAnojWid++fCzPnXS2Q/hiSvgVew79IBMI3PlFUUXS9M+J4t /uSDAa61Qdt9nCcZsO2KauVjOmVL70C1tIY0CsBQhe6ibLFI6QB5aICeJPhtn9AyQJTaTVDk1gJ gP6VYQB2O32Nscd0ELNkrud2KDEP2DvdhSUgH81oMhKrCmYoOgbTgn0W+IH965EEaSOzF+CYsKD SpN5yVRcMH/WmckS2K2oG9bCGLnBPr01kJcGjA54RP3z4YzYnanVNiv7wevLq4li33X930REJGA u0UamGE3B/DOYnb5Ut2eQ92GrY7cK9OFE0KaD9LTHnFdrn6XnKKqVWZVIC8P6TuPtdIgk8RGHbG Wfn X-Received: by 2002:a05:6000:1a86:b0:47f:97a4:f121 with SMTP id ffacd0b85a97d-47f9feb5316mr9148793f8f.30.1785148039425; Mon, 27 Jul 2026 03:27:19 -0700 (PDT) Message-ID: Date: Mon, 27 Jul 2026 12:27:18 +0200 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: [PATCH v4 3/4] x86/traps: reduce indentation in fixup_exception_return() From: Jan Beulich To: "xen-devel@lists.xenproject.org" Cc: Andrew Cooper , Teddy Astie , =?UTF-8?Q?Roger_Pau_Monn=C3=A9?= References: Content-Language: en-US Autocrypt: addr=jbeulich@suse.com; keydata= xsDiBFk3nEQRBADAEaSw6zC/EJkiwGPXbWtPxl2xCdSoeepS07jW8UgcHNurfHvUzogEq5xk hu507c3BarVjyWCJOylMNR98Yd8VqD9UfmX0Hb8/BrA+Hl6/DB/eqGptrf4BSRwcZQM32aZK 7Pj2XbGWIUrZrd70x1eAP9QE3P79Y2oLrsCgbZJfEwCgvz9JjGmQqQkRiTVzlZVCJYcyGGsD /0tbFCzD2h20ahe8rC1gbb3K3qk+LpBtvjBu1RY9drYk0NymiGbJWZgab6t1jM7sk2vuf0Py O9Hf9XBmK0uE9IgMaiCpc32XV9oASz6UJebwkX+zF2jG5I1BfnO9g7KlotcA/v5ClMjgo6Gl MDY4HxoSRu3i1cqqSDtVlt+AOVBJBACrZcnHAUSuCXBPy0jOlBhxPqRWv6ND4c9PH1xjQ3NP nxJuMBS8rnNg22uyfAgmBKNLpLgAGVRMZGaGoJObGf72s6TeIqKJo/LtggAS9qAUiuKVnygo 3wjfkS9A3DRO+SpU7JqWdsveeIQyeyEJ/8PTowmSQLakF+3fote9ybzd880fSmFuIEJldWxp Y2ggPGpiZXVsaWNoQHN1c2UuY29tPsJgBBMRAgAgBQJZN5xEAhsDBgsJCAcDAgQVAggDBBYC AwECHgECF4AACgkQoDSui/t3IH4J+wCfQ5jHdEjCRHj23O/5ttg9r9OIruwAn3103WUITZee e7Sbg12UgcQ5lv7SzsFNBFk3nEQQCACCuTjCjFOUdi5Nm244F+78kLghRcin/awv+IrTcIWF hUpSs1Y91iQQ7KItirz5uwCPlwejSJDQJLIS+QtJHaXDXeV6NI0Uef1hP20+y8qydDiVkv6l IreXjTb7DvksRgJNvCkWtYnlS3mYvQ9NzS9PhyALWbXnH6sIJd2O9lKS1Mrfq+y0IXCP10eS FFGg+Av3IQeFatkJAyju0PPthyTqxSI4lZYuJVPknzgaeuJv/2NccrPvmeDg6Coe7ZIeQ8Yj t0ARxu2xytAkkLCel1Lz1WLmwLstV30g80nkgZf/wr+/BXJW/oIvRlonUkxv+IbBM3dX2OV8 AmRv1ySWPTP7AAMFB/9PQK/VtlNUJvg8GXj9ootzrteGfVZVVT4XBJkfwBcpC/XcPzldjv+3 HYudvpdNK3lLujXeA5fLOH+Z/G9WBc5pFVSMocI71I8bT8lIAzreg0WvkWg5V2WZsUMlnDL9 mpwIGFhlbM3gfDMs7MPMu8YQRFVdUvtSpaAs8OFfGQ0ia3LGZcjA6Ik2+xcqscEJzNH+qh8V m5jjp28yZgaqTaRbg3M/+MTbMpicpZuqF4rnB0AQD12/3BNWDR6bmh+EkYSMcEIpQmBM51qM EKYTQGybRCjpnKHGOxG0rfFY1085mBDZCH5Kx0cl0HVJuQKC+dV2ZY5AqjcKwAxpE75MLFkr wkkEGBECAAkFAlk3nEQCGwwACgkQoDSui/t3IH7nnwCfcJWUDUFKdCsBH/E5d+0ZnMQi+G0A nAuWpQkjM1ASeQwSHEeAWPgskBQL In-Reply-To: Content-Transfer-Encoding: quoted-printable X-purgate-ID: tlsNG-d25034/1785148039-012C8A5B-52362AE6/0/0 X-purgate-type: clean X-purgate-size: 7408 X-ZohoMail-DKIM: pass (identity @suse.com) X-ZM-MESSAGEID: 1785148059972158500 Content-Type: text/plain; charset="utf-8" The earlier "x86/traps: use entry_ssp in fixup_exception_return()" left unnecessary scopes and hence unnecessarily deep indentation. While that was intentional (to improve readabilirty of the diff), rectify this now. Signed-off-by: Jan Beulich --- v4: New. --- a/xen/arch/x86/traps.c +++ b/xen/arch/x86/traps.c @@ -1175,90 +1175,86 @@ static void fixup_exception_return(struc unsigned long fixup, unsigned long stub= _ra) { #ifdef CONFIG_XEN_SHSTK + unsigned long ssp =3D rdssp(); + + if ( ssp !=3D SSP_NO_SHSTK ) { - unsigned long ssp =3D rdssp(); + unsigned long *ptr =3D _p(regs->entry_ssp); + unsigned long primary_shstk =3D + (ssp & ~(STACK_SIZE - 1)) + + (PRIMARY_SHSTK_SLOT + 1) * PAGE_SIZE - 8; + + BUG_ON((regs->entry_ssp ^ primary_shstk) >> + (PAGE_SHIFT + STACK_ORDER)); + + /* + * The shstk currently looks like this: + * + * tok [Supervisor token, =3D=3D &tok | BUSY, only with FRED in= active] + * ... [Pointed to by SSP for most exceptions, empty in IST cas= es] + * %cs [=3D=3D regs->cs] + * %rip [=3D=3D regs->rip] + * SSP [Pointed to by entry_ssp; Likely points to 3 slots + * higher, above %cs] + * ... [call tree to this function, likely 2/3 slots] + * + * and we want to overwrite %rip with fixup. There are two + * complications: + * 1) We cant depend on SSP values, because they won't differ by + * 3 slots if the exception is taken on an IST stack. + * 2) There are synthetic (unrealistic but not impossible) + * scenarios where %rip can end up in the call tree to this + * function, so we can't check against regs->rip alone. + * + * Check for both regs->rip and regs->cs matching. + */ + BUG_ON(ptr[1] !=3D regs->rip || ptr[2] !=3D regs->cs); + + wrss(fixup, &ptr[1]); + + if ( !stub_ra ) + goto shstk_done; + + /* + * Stub recovery ought to happen only when the outer context + * was on the main shadow stack. We need to also "pop" the + * stub's return address from the interrupted context's shadow + * stack. That is, + * - if we're still on the main stack, we need to move the + * entire stack (up to and including the exception frame) + * up by one slot, incrementing the original SSP in the + * exception frame, + * - if we're on an IST stack, we need to increment the + * original SSP. + */ + BUG_ON((ptr[0] ^ primary_shstk) >> PAGE_SHIFT); =20 - if ( ssp !=3D SSP_NO_SHSTK ) + if ( (ssp ^ primary_shstk) >> PAGE_SHIFT ) { - unsigned long *ptr =3D _p(regs->entry_ssp); - unsigned long primary_shstk =3D - (ssp & ~(STACK_SIZE - 1)) + - (PRIMARY_SHSTK_SLOT + 1) * PAGE_SIZE - 8; - - BUG_ON((regs->entry_ssp ^ primary_shstk) >> - (PAGE_SHIFT + STACK_ORDER)); - /* - * The shstk currently looks like this: - * - * tok [Supervisor token, =3D=3D &tok | BUSY, only with FRE= D inactive] - * ... [Pointed to by SSP for most exceptions, empty in IST= cases] - * %cs [=3D=3D regs->cs] - * %rip [=3D=3D regs->rip] - * SSP [Pointed to by entry_ssp; Likely points to 3 slots - * higher, above %cs] - * ... [call tree to this function, likely 2/3 slots] - * - * and we want to overwrite %rip with fixup. There are two - * complications: - * 1) We cant depend on SSP values, because they won't diffe= r by - * 3 slots if the exception is taken on an IST stack. - * 2) There are synthetic (unrealistic but not impossible) - * scenarios where %rip can end up in the call tree to th= is - * function, so we can't check against regs->rip alone. - * - * Check for both regs->rip and regs->cs matching. + * We're on an IST stack. First make sure the two return + * addresses actually match. Then increment the interrupted + * context's SSP. */ - BUG_ON(ptr[1] !=3D regs->rip || ptr[2] !=3D regs->cs); + BUG_ON(stub_ra !=3D *(unsigned long*)ptr[0]); + wrss(ptr[0] + 8, &ptr[0]); + goto shstk_done; + } =20 - { - wrss(fixup, &ptr[1]); + /* Make sure the two return addresses actually match. */ + BUG_ON(stub_ra !=3D ptr[3]); =20 - if ( !stub_ra ) - goto shstk_done; + /* Move exception frame, updating SSP there. */ + wrss(ptr[2], &ptr[3]); /* %cs */ + wrss(ptr[1], &ptr[2]); /* %rip */ + wrss(ptr[0] + 8, &ptr[1]); /* SSP */ + + /* Move all newer entries. */ + while ( ptr-- !=3D _p(ssp) ) + wrss(ptr[0], &ptr[1]); =20 - /* - * Stub recovery ought to happen only when the outer conte= xt - * was on the main shadow stack. We need to also "pop" the - * stub's return address from the interrupted context's sh= adow - * stack. That is, - * - if we're still on the main stack, we need to move the - * entire stack (up to and including the exception frame) - * up by one slot, incrementing the original SSP in the - * exception frame, - * - if we're on an IST stack, we need to increment the - * original SSP. - */ - BUG_ON((ptr[0] ^ primary_shstk) >> PAGE_SHIFT); - - if ( (ssp ^ primary_shstk) >> PAGE_SHIFT ) - { - /* - * We're on an IST stack. First make sure the two ret= urn - * addresses actually match. Then increment the inter= rupted - * context's SSP. - */ - BUG_ON(stub_ra !=3D *(unsigned long*)ptr[0]); - wrss(ptr[0] + 8, &ptr[0]); - goto shstk_done; - } - - /* Make sure the two return addresses actually match. */ - BUG_ON(stub_ra !=3D ptr[3]); - - /* Move exception frame, updating SSP there. */ - wrss(ptr[2], &ptr[3]); /* %cs */ - wrss(ptr[1], &ptr[2]); /* %rip */ - wrss(ptr[0] + 8, &ptr[1]); /* SSP */ - - /* Move all newer entries. */ - while ( ptr-- !=3D _p(ssp) ) - wrss(ptr[0], &ptr[1]); - - /* Finally account for our own stack having shifted up. */ - asm volatile ( "incsspd %0" :: "r" (2) ); - } - } + /* Finally account for our own stack having shifted up. */ + asm volatile ( "incsspd %0" :: "r" (2) ); } shstk_done: #endif /* CONFIG_XEN_SHSTK */ From nobody Mon Aug 24 12:05:08 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) client-ip=192.237.175.120; envelope-from=xen-devel-bounces@lists.xenproject.org; helo=lists.xenproject.org; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass(p=quarantine dis=none) header.from=suse.com ARC-Seal: i=1; a=rsa-sha256; t=1785148072; cv=none; d=zohomail.com; s=zohoarc; b=NSx5B1e/civztL+iP80sjnelQhEZ73wNTlMfFUVmnB1xdwOqRM9IEOJU6Z1eL2r8JeTbH8jbxBHmaHcqT90YLZCwVJ/QqAXZFMn4L3wwFuW2ZXsTlNxCHvXicEonLEVBcCXTyC9OauIcWLQdPd+hiUObjFWYWDqBYS54gtyRBCw= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785148072; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=y40rikzKdW41I0gcKC+jqL54qXX/dn+hAUR30HB1xyE=; b=Yo07co9dKc64pYloA5a1NsYurDrJsG1BoK0wdZKn6Lz7jPCD1r1ras9FGdUGTXjyy/lMuuqbPGoikqFTM12Mzk4pJyi9hjBf3lbbaRxnzcBado5dsO0iRXPVvuxiukmA8hyIiLSc/qAgTY0r5EmczXDM/FDOutNOKPDOSlSFZks= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) by mx.zohomail.com with SMTPS id 1785148072445917.1377017597416; Mon, 27 Jul 2026 03:27:52 -0700 (PDT) Received: from list by lists.xenproject.org with outflank-mailman.1371562.1619063 (Exim 4.92) (envelope-from ) id 1woIYf-0002RN-G8; Mon, 27 Jul 2026 10:27:41 +0000 Received: by outflank-mailman (output) from mailman id 1371562.1619063; Mon, 27 Jul 2026 10:27:41 +0000 Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1woIYf-0002Qf-Cm; Mon, 27 Jul 2026 10:27:41 +0000 Received: by outflank-mailman (input) for mailman id 1371562; Mon, 27 Jul 2026 10:27:40 +0000 Received: from mx.expurgate.net ([194.145.224.10]) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1woIYe-0002PL-B5 for xen-devel@lists.xenproject.org; Mon, 27 Jul 2026 10:27:40 +0000 Received: from mx.expurgate.net (helo=localhost) by mx.expurgate.net with esmtp id 1woIYd-003N6b-O9 for xen-devel@lists.xenproject.org; Mon, 27 Jul 2026 12:27:39 +0200 Received: from [10.42.69.5] (helo=localhost) by localhost with ESMTP (eXpurgate MTA 0.9.1) (envelope-from ) id 6a673293-bab6-0a2a0a5309dd-0a2a45059aa8-36 for ; Mon, 27 Jul 2026 12:27:39 +0200 Received: from [209.85.128.51] (helo=mail-wm1-f51.google.com) by tlsNG-c201ff.mxtls.expurgate.net with ESMTPS (eXpurgate 4.57.1) (envelope-from ) id 6a67329b-4cb1-0a2a45050019-d1558033e18a-3 for ; Mon, 27 Jul 2026 12:27:39 +0200 Received: by mail-wm1-f51.google.com with SMTP id 5b1f17b1804b1-49554ebb87dso23340315e9.3 for ; Mon, 27 Jul 2026 03:27:39 -0700 (PDT) Received: from [10.156.60.236] (ip-037-024-206-209.um08.pools.vodafone-ip.de. [37.24.206.209]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-496b49a6e17sm204668195e9.13.2026.07.27.03.27.38 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Mon, 27 Jul 2026 03:27:38 -0700 (PDT) X-Outflank-Mailman: Message body and most headers restored to incoming version X-BeenThere: xen-devel@lists.xenproject.org List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Precedence: list Sender: "Xen-devel" Authentication-Results: eu.smtp.expurgate.cloud; dkim=pass header.s=google header.d=suse.com header.i="@suse.com" header.h="Content-Transfer-Encoding:Content-Type:In-Reply-To:Autocrypt:Content-Language:References:Cc:To:From:Subject:User-Agent:MIME-Version:Date:Message-ID" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.com; s=google; t=1785148059; x=1785752859; darn=lists.xenproject.org; h=content-transfer-encoding:content-type:in-reply-to:autocrypt :content-language:references:cc:to:from:subject:user-agent :mime-version:date:message-id:from:to:cc:subject:date:message-id :reply-to:content-type; bh=y40rikzKdW41I0gcKC+jqL54qXX/dn+hAUR30HB1xyE=; b=eN1HgbjSNoKcDbMR551t7P/VdBvPAI7V6So8cCmSHKbRbC3XKdwbAU239kcKwTEHMR IAjKMfWNRvC5U4B0NIaOPxLj/nCfqyvWI9q4qpTA9VLE3HkxWJtE02yQQSnt+SkO7zsk k9+URCIfURbTCF5qh6YWYApUIE9TbcSi/MJ54flyokOSmy9xxxGvzHKAzMC1lf4mZxXB 2hI0Hq1uHYO4tByD6livb6yYTmBpUlpiXyOGh1U/YxuY4cbuE2aheNDY9Y/RD3XtF4sx CbuZR58/q7MGGvuZpFYz1UsBTqG7fFXU98gvIEmxmYso9S1z5kopUMHg4THCHa4C8SOm 0Ckw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785148059; x=1785752859; h=content-transfer-encoding:content-type:in-reply-to:autocrypt :content-language:references:cc:to:from:subject:user-agent :mime-version:date:message-id:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to:content-type; bh=y40rikzKdW41I0gcKC+jqL54qXX/dn+hAUR30HB1xyE=; b=W3SGXKiFqyzCdyQvYZqACNyMI3zv8/wLqgtogactHW6IO7DaPGXHU+1qs95anKBpvk L9ZfWzvcaMkKiRI9Lsong81D2kwbhphd7DpyqyYvYCVvsjNfzBr9ZMCNP1Ci181U/Q7V JUNv9OKhbd9aAg1WbxnSZRO7W/RPZ+Huos+msi6G7JZl9ydeye2uMT3x1IKwXAHeLADx VDBk7BM33Qr6zha2vDUWAku9oeF2fx36QdbWaei5uq67LMkMKzYozwYfG9KXdJSbNgLq zbUz53A28BWhbKvKr5qTTp21GnQaxcPgg/eeG+tLmV6Wp42404xnGzyzlT6yq8PviDG8 Ca8g== X-Gm-Message-State: AOJu0YyrN1RTlc45W18AEnaLWlM0bXA/SDq2+oi32WTp47LFNuMvEtzA v2ZLh0xhw0otFFydYHWtrvtNh43uCSyyhEMaAn0wpwNvV7Usah2RMeLCmFaWrYpUeFrdqkrL169 7ybW3fg== X-Gm-Gg: AR+sD11NaT/kSG4+eoj648xaaSYTmcvWrmZTBhYRUUfNqOhluLuam567zwkQjizJ43S TRcxiTmwEvih5C6DmpgBue4/QUF2uKMu6jUzHTqPLHPlVuho1FbYp90UAOU9N/9FqxWQfQI71kl wVUozRLQYgK3+lzH2HWd38J4oYlz2WNX6Ig8VDLNd4tKOSOx7kd7vWv95W62Kl4mJvvdTDgrE/i 3jJsFXiW0i2Hhm/nJCLpyslLCT1xEGmafSvklCzESUT1jlLBy9u44ymGEn0dLLrq/+xZN9uPz9Z KZmSTBJaNVEJMbGENh1CIjHn4fQmLgSFysJF4dP62aHcyiUY+6UjMzGC8gSWTCgT3dvv5FxhGk2 MxuHE6kLrrzPwvwGygayyzzNhGZq4NDcMdH5rgWOaAkxHpFqRzg7TPeDfHUPmnmB7mNXf9bfa6s pofw9XgL8VkACCiThRBuk7kukOgxFfyJ0jXhJRFcQ6WqPqpBbNFtpJcJ/OWdsSedzfMA== X-Received: by 2002:a05:600c:1986:b0:496:c249:ddb7 with SMTP id 5b1f17b1804b1-496c249dfaemr12725075e9.6.1785148059174; Mon, 27 Jul 2026 03:27:39 -0700 (PDT) Message-ID: Date: Mon, 27 Jul 2026 12:27:38 +0200 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: [PATCH v4 4/4] x86: prefer shadow stack for producing call traces From: Jan Beulich To: "xen-devel@lists.xenproject.org" Cc: Andrew Cooper , Teddy Astie , =?UTF-8?Q?Roger_Pau_Monn=C3=A9?= References: Content-Language: en-US Autocrypt: addr=jbeulich@suse.com; keydata= xsDiBFk3nEQRBADAEaSw6zC/EJkiwGPXbWtPxl2xCdSoeepS07jW8UgcHNurfHvUzogEq5xk hu507c3BarVjyWCJOylMNR98Yd8VqD9UfmX0Hb8/BrA+Hl6/DB/eqGptrf4BSRwcZQM32aZK 7Pj2XbGWIUrZrd70x1eAP9QE3P79Y2oLrsCgbZJfEwCgvz9JjGmQqQkRiTVzlZVCJYcyGGsD /0tbFCzD2h20ahe8rC1gbb3K3qk+LpBtvjBu1RY9drYk0NymiGbJWZgab6t1jM7sk2vuf0Py O9Hf9XBmK0uE9IgMaiCpc32XV9oASz6UJebwkX+zF2jG5I1BfnO9g7KlotcA/v5ClMjgo6Gl MDY4HxoSRu3i1cqqSDtVlt+AOVBJBACrZcnHAUSuCXBPy0jOlBhxPqRWv6ND4c9PH1xjQ3NP nxJuMBS8rnNg22uyfAgmBKNLpLgAGVRMZGaGoJObGf72s6TeIqKJo/LtggAS9qAUiuKVnygo 3wjfkS9A3DRO+SpU7JqWdsveeIQyeyEJ/8PTowmSQLakF+3fote9ybzd880fSmFuIEJldWxp Y2ggPGpiZXVsaWNoQHN1c2UuY29tPsJgBBMRAgAgBQJZN5xEAhsDBgsJCAcDAgQVAggDBBYC AwECHgECF4AACgkQoDSui/t3IH4J+wCfQ5jHdEjCRHj23O/5ttg9r9OIruwAn3103WUITZee e7Sbg12UgcQ5lv7SzsFNBFk3nEQQCACCuTjCjFOUdi5Nm244F+78kLghRcin/awv+IrTcIWF hUpSs1Y91iQQ7KItirz5uwCPlwejSJDQJLIS+QtJHaXDXeV6NI0Uef1hP20+y8qydDiVkv6l IreXjTb7DvksRgJNvCkWtYnlS3mYvQ9NzS9PhyALWbXnH6sIJd2O9lKS1Mrfq+y0IXCP10eS FFGg+Av3IQeFatkJAyju0PPthyTqxSI4lZYuJVPknzgaeuJv/2NccrPvmeDg6Coe7ZIeQ8Yj t0ARxu2xytAkkLCel1Lz1WLmwLstV30g80nkgZf/wr+/BXJW/oIvRlonUkxv+IbBM3dX2OV8 AmRv1ySWPTP7AAMFB/9PQK/VtlNUJvg8GXj9ootzrteGfVZVVT4XBJkfwBcpC/XcPzldjv+3 HYudvpdNK3lLujXeA5fLOH+Z/G9WBc5pFVSMocI71I8bT8lIAzreg0WvkWg5V2WZsUMlnDL9 mpwIGFhlbM3gfDMs7MPMu8YQRFVdUvtSpaAs8OFfGQ0ia3LGZcjA6Ik2+xcqscEJzNH+qh8V m5jjp28yZgaqTaRbg3M/+MTbMpicpZuqF4rnB0AQD12/3BNWDR6bmh+EkYSMcEIpQmBM51qM EKYTQGybRCjpnKHGOxG0rfFY1085mBDZCH5Kx0cl0HVJuQKC+dV2ZY5AqjcKwAxpE75MLFkr wkkEGBECAAkFAlk3nEQCGwwACgkQoDSui/t3IH7nnwCfcJWUDUFKdCsBH/E5d+0ZnMQi+G0A nAuWpQkjM1ASeQwSHEeAWPgskBQL In-Reply-To: Content-Transfer-Encoding: quoted-printable X-purgate-ID: tlsNG-c201ff/1785148059-F7CB82A1-D626C62C/0/0 X-purgate-type: clean X-purgate-size: 4605 X-ZohoMail-DKIM: pass (identity @suse.com) X-ZM-MESSAGEID: 1785148073833158500 Content-Type: text/plain; charset="utf-8" Shadow stacks contain little more than return addresses, and they in particular allow precise call traces also with FRAME_POINTER=3Dn: (XEN) Xen call trace: (XEN) [] R extable.c#search_one_extable+0x70/0x73 (XEN) [] C search_exception_table+0xc2/0x177 (XEN) [] C traps.c#extable_fixup.isra.0+0x18/0x6c (XEN) [] C do_invalid_op+0xab/0x106 (XEN) [] C x86_64/entry.S#handle_exception_saved+0x88/= 0xf4 (XEN) [] E ffff82d07fffe044 (XEN) [] C stub_selftest+0xd0/0x168 (XEN) [] C setup.c#init_done+0x116/0x15a as opposed to this counterpart (earlier during the same boot, before CET is enabled): (XEN) Xen call trace: (XEN) [] R extable.c#search_one_extable+0x70/0x73 (XEN) [] S search_exception_table+0xc2/0x177 (XEN) [] S traps.c#extable_fixup.isra.0+0x18/0x6c (XEN) [] S do_invalid_op+0xab/0x106 (XEN) [] S x86_64/entry.S#handle_exception_saved+0x88/= 0xf4 (XEN) [] S stub_selftest+0xd0/0x168 (XEN) [] S do_initcalls+0x29/0x38 (XEN) [] S __start_xen+0x1c72/0x2235 (XEN) [] S __high_start+0xb7/0xc0 (note the entirely missing entry for the stub itself [1]; sadly there are no stray entries there). [1] Arguably we could teach FRAME_POINTER=3Dn traces to recognize stubs as well. But not FRAME_POINTER=3Dy ones. In fact, what's missing there isn't the stub itself, but (of course) its immediate caller. Signed-off-by: Jan Beulich --- While the 'E' for exception frames is probably okay, I'm not overly happy with the 'C' (for CET). I would have preferred 'S' (for shadow), but we use that character already. As an alternative to suppressing output for the top level exception frame, adding the new code ahead of the 'R' output line (and then also ahead of the stack top read) could be considered. Quite likely a number of other uses of is_active_kernel_text() also want amending with in_stub(). --- v3: Correct "link to other shadow stack" check. Don't log a line for the (impossible) PV case. Add example stack trace to description. v2: IS_ENABLED() -> #ifdef. Re-base. --- a/xen/arch/x86/traps.c +++ b/xen/arch/x86/traps.c @@ -48,6 +48,7 @@ #include #include #include +#include #include #include #include @@ -705,6 +706,13 @@ unsigned long get_stack_dump_bottom(unsi } } =20 +#ifdef CONFIG_XEN_SHSTK +static bool in_stub(unsigned long addr) +{ + return !((this_cpu(stubs.addr) ^ addr) >> STUB_BUF_SHIFT); +} +#endif + #if !defined(CONFIG_FRAME_POINTER) =20 /* @@ -797,6 +805,49 @@ static void show_trace(const struct cpu_ !is_active_kernel_text(tos) ) printk(" [<%p>] R %pS\n", _p(regs->rip), _p(regs->rip)); =20 +#ifdef CONFIG_XEN_SHSTK + if ( rdssp() !=3D SSP_NO_SHSTK ) + { + const unsigned long *ptr =3D _p(regs->entry_ssp); + unsigned int n; + + for ( n =3D 0; (unsigned long)ptr & (PAGE_SIZE - sizeof(*ptr)); ++= n ) + { + unsigned long val =3D *ptr; + + if ( is_active_kernel_text(val) || in_stub(val) ) + { + /* Normal return address entry. */ + printk(" [<%p>] C %pS\n", _p(val), _p(val)); + ++ptr; + } + else if ( !((val ^ (unsigned long)ptr) >> + (PAGE_SHIFT + STACK_ORDER)) ) + { + if ( val & (sizeof(val) - 1) ) + { + /* Most likely a supervisor token. */ + break; + } + + /* + * Ought to be a hypervisor interruption frame. But don't + * (re)log the current frame's %rip. + */ + if ( n || ptr[1] !=3D regs->rip ) + printk(" [<%p>] E %pS\n", _p(ptr[1]), _p(ptr[1])); + ptr =3D _p(val); + } + else /* Bogus. */ + break; + } + + /* Fall back to legacy stack trace if nothing was logged at all. */ + if ( n ) + return; + } +#endif /* CONFIG_XEN_SHSTK */ + if ( fault ) { printk(" [Fault on access]\n");