From nobody Sat Jul 25 23:05:54 2026 Received: from galois.linutronix.de (Galois.linutronix.de [193.142.43.55]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BD1353ADBA4; Sun, 12 Jul 2026 12:44:14 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=193.142.43.55 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783860257; cv=none; b=Id4mJuIz10eOUC5z/P49URxpo3EZxq2egCvX3O1d7IV8UWs5CTruA5dyvHGyKcR1f2bJZJQj4pbVrlI+3S6qyCm7Pkm+K7Vxq7ARPQHpFOrvB9/3jWa/Yqk/h8951S/m3JQXlKXWzO9k78dz9B/rlyO6gOv75mvXxxyJ1tvFfPM= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783860257; c=relaxed/simple; bh=GELjSU20Q+q+8W9L01SdDSLS+ZEonDIUr7iOfooyhSA=; h=Date:From:To:Subject:Cc:In-Reply-To:References:MIME-Version: Message-ID:Content-Type; b=RvAxvcF5h2pAuq6c7UGxNrjVTGRE2V6NxTW6tAC3EqroJjfSM6ZUKKwRmkP7rsCt26w/5fwE3R6KPIMFKijKA1q//4XnRcFhHcQckUOPw16fkvV3wdT9KJWL1EIOplSHo0VZkwJYYS8PWDMVEdYqVtXczPLNrvHZ9b3nQRKXRdc= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linutronix.de; spf=pass smtp.mailfrom=linutronix.de; dkim=pass (2048-bit key) header.d=linutronix.de header.i=@linutronix.de header.b=H/JTyJ3u; dkim=permerror (0-bit key) header.d=linutronix.de header.i=@linutronix.de header.b=KFgIEqkg; arc=none smtp.client-ip=193.142.43.55 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linutronix.de Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linutronix.de Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=linutronix.de header.i=@linutronix.de header.b="H/JTyJ3u"; dkim=permerror (0-bit key) header.d=linutronix.de header.i=@linutronix.de header.b="KFgIEqkg" Date: Sun, 12 Jul 2026 12:44:11 -0000 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linutronix.de; s=2020; t=1783860253; h=from:from:sender:sender:reply-to:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=XAbVE8tCXItgbhDdOx75m/+jkqkm8eX8nNZMXvqptNc=; b=H/JTyJ3umQsQJRseRYlxw+TEjsIKsMJqDkEptQxUrxLkzfEcF30/nDwiYZtF71Nl9+vv0q OV+sX+xHQoFxE9vA6H7Y0gIAnphCBgHYzRFBYLiBslaFN7ShVQhYXOzUI1IIKioHVmunwN McJ7gPojUZGmQcII5htaepgX0Q+neB5iOVO30c3l+IHra/U+FbXnmTKpzqrPjOLVf5/ZZp MlxCNySLjQZLeB+txRRel/mpGRAycFw61PwcW5lQ0mSVk5SN2xOebeC4dgUTsJT+swPKcM Wfjar30cvnf2XhGffIvjGmJPHLx704qvlEhMAgqQnLpVyqbVI2dDIq6GQIpEaA== DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=linutronix.de; s=2020e; t=1783860253; h=from:from:sender:sender:reply-to:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=XAbVE8tCXItgbhDdOx75m/+jkqkm8eX8nNZMXvqptNc=; b=KFgIEqkgxorsZ2khbwYxgZYiNxK8OiWLoyTpz0ZH+Qzy5481lph9qr99UBnpcgKDr+R5wX rEnv7kbaZGIgCmAA== From: "tip-bot2 for Thomas Gleixner" Sender: tip-bot2@linutronix.de Reply-to: linux-kernel@vger.kernel.org To: linux-tip-commits@vger.kernel.org Subject: [tip: core/entry] entry: Provide [syscall_]enter_from_user_mode_randomize_stack() Cc: Thomas Gleixner , "Mukesh Kumar Chaurasiya (IBM)" , Radu Rendec , Jinjie Ruan , philmd@oss.qualcomm.com, x86@kernel.org, linux-kernel@vger.kernel.org In-Reply-To: <20260707190253.816918647@kernel.org> References: <20260707190253.816918647@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Message-ID: <178386025174.1844600.17589709975959838530.tip-bot2@tip-bot2> Robot-ID: Robot-Unsubscribe: Contact to get blacklisted from these emails Precedence: bulk Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable The following commit has been merged into the core/entry branch of tip: Commit-ID: 855c103f86275a55eba115cabb86eb84f8236933 Gitweb: https://git.kernel.org/tip/855c103f86275a55eba115cabb86eb84f= 8236933 Author: Thomas Gleixner AuthorDate: Tue, 07 Jul 2026 21:06:07 +02:00 Committer: Thomas Gleixner CommitterDate: Sun, 12 Jul 2026 12:38:01 +02:00 entry: Provide [syscall_]enter_from_user_mode_randomize_stack() Randomizing the syscall stack can only happen after state is established via enter_from_user_mode() or syscall_enter_from_user_mode(). The earlier it happens the better. Provide two new macros to consolidate that: - enter_from_user_mode_randomize_stack() enter_from_user_mode(); add_random_kstack_offset_irqsoff(); - syscall_enter_from_user_mode_randomize_stack() enter_from_user_mode_randomize_stack(); syscall_enter_from_user_mode_work(); to reduce boiler plate code. Those are macros and not inline functions as the latter would limit the stack randomization scope to the inline function itself. Signed-off-by: Thomas Gleixner Tested-by: Mukesh Kumar Chaurasiya (IBM) Reviewed-by: Radu Rendec Reviewed-by: Jinjie Ruan Reviewed-by: Philippe Mathieu-Daud=C3=A9 Reviewed-by: Mukesh Kumar Chaurasiya (IBM) Link: https://patch.msgid.link/20260707190253.816918647@kernel.org --- include/linux/entry-common.h | 56 +++++++++++++++++++++++++++++++++++- 1 file changed, 56 insertions(+) diff --git a/include/linux/entry-common.h b/include/linux/entry-common.h index 9336516..166b1ed 100644 --- a/include/linux/entry-common.h +++ b/include/linux/entry-common.h @@ -6,6 +6,7 @@ #include #include #include +#include #include #include #include @@ -150,6 +151,61 @@ static __always_inline long syscall_enter_from_user_mo= de_work(struct pt_regs *re } =20 /** + * enter_from_user_mode_randomize_stack - Establish state and add stack ra= ndomization + * before invoking syscall_enter_from_user_mode_work() + * @regs: Pointer to currents pt_regs + * + * Invoked from architecture specific syscall entry code with interrupts + * disabled. The calling code has to be non-instrumentable. When the funct= ion + * returns all state is correct, interrupts are still disabled and the + * subsequent functions can be instrumented. + * + * Implemented as a macro so that the stack randomization is effective + * throughout the function in which it is invoked. An inline would only ma= ke it + * effective in the scope of the inline function. + */ +#define enter_from_user_mode_randomize_stack(regs) \ +do { \ + enter_from_user_mode(regs); \ + instrumentation_begin(); \ + add_random_kstack_offset_irqsoff(); \ + instrumentation_end(); \ +} while (0) + +/** + * syscall_enter_from_user_mode_randomize_stack - Establish state and chec= k and handle work + * before invoking a syscall + * @regs: Pointer to currents pt_regs + * @syscall: The syscall number + * + * Invoked from architecture specific syscall entry code with interrupts + * disabled. The calling code has to be non-instrumentable. When the + * function returns all state is correct, interrupts are enabled and the + * subsequent functions can be instrumented. + * + * This is the combination of enter_from_user_mode_randomize_stack() and + * syscall_enter_from_user_mode_work() to be used when there is no + * architecture specific work to be done between the two. + * + * Returns: The original or a modified syscall number. See + * syscall_enter_from_user_mode_work() for further explanation. + * + * Implemented as a macro to make stack randomization effective in the cal= ling + * scope. + */ +#define syscall_enter_from_user_mode_randomize_stack(regs, syscall) \ +({ \ + enter_from_user_mode_randomize_stack(regs); \ + \ + instrumentation_begin(); \ + local_irq_enable(); \ + long _ret =3D syscall_enter_from_user_mode_work(regs, syscall); \ + instrumentation_end(); \ + \ + _ret; \ +}) + +/** * syscall_enter_from_user_mode - Establish state and check and handle work * before invoking a syscall * @regs: Pointer to currents pt_regs