From nobody Sun Feb 8 04:12:01 2026 Received: from mail-ed1-f44.google.com (mail-ed1-f44.google.com [209.85.208.44]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BE19E20C029 for ; Tue, 23 Dec 2025 20:20:49 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.208.44 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1766521251; cv=none; b=M+hOU5xKtU73GfkD2p/hU9m8Wx+hZ/hnBvnfdqtXoaXE9gqRUmhPYkYmdz14NqXmZfY8L03NUlX0BUDA8jfPiqMkFmFB3Uczb1BV5x5J0RiTRl65RwCu1ee0c3oSfYMUfh246mF+E59udz+ZZHLC2vCoY0YoncOh6GdbnCOtKrQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1766521251; c=relaxed/simple; bh=LlyjlclXGN692O2SWEY8ay9uEe4c6AvrD+APt6+mDlw=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=l4+eMc9t2ZybC6gUmag5Tean3+t7AGRGTUwIbQ6vqIkMPAIsd/gXQnZTgT8vg7KSZd4jfE07YrFjiMh4dTUTqTQGpJCKkvBVu65GiOg8pBVcYafaL+VzFcFe4r0rm8XVsAu4ycH7ptlhgT1PjXlvfQoR0iYFXswWNjzTpVziEfA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=mBzDseei; arc=none smtp.client-ip=209.85.208.44 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="mBzDseei" Received: by mail-ed1-f44.google.com with SMTP id 4fb4d7f45d1cf-64b92abe63aso7585523a12.0 for ; Tue, 23 Dec 2025 12:20:49 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1766521248; x=1767126048; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=8t2IfrlBya6NzOo6SZSiTUH90/X3W1rsvlXvoEG82FU=; b=mBzDseeiCluj4WAL9r6QDrkKDIWRdzSA5eysO02qmxulEy+sZzxYKTOIUb2lKLNZDi ItLN9C5g39X+nGLsWu5Q95kcov+CFw0l+ztdaYwF51Ldl4lnXCm3ksem6DvuKElUxSZt HOINPIzs+b852G4raf3Y/IqyW3u4GvQNs17nO5eYGk65dvRNmyN6JoeRd3VZ2pwh36Ua NS+BhhyGuYHDRfonB1E58uqeBL2j/qp8nmwDDcHEyP7fmDevBMWOjE1YloeG6nowd7km lacsOYC3encjWnXB+FN+d2YQ9z+7RwLH6rHvLKOOQJmE0+pdKK+8Hja9g8ungVG7EvsF XVuQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1766521248; x=1767126048; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=8t2IfrlBya6NzOo6SZSiTUH90/X3W1rsvlXvoEG82FU=; b=eGzCgqhAl/TzEMLX0USM7tyfjsILK2j4X7XMrNwdyt9uDZzIlinKvYbplxhj/23la7 r//vmSPrY/vHdsTCH7QllgYX6rVm9JibzJZGhdoXnjk+grt8VLiZGJX0d0nnWUAPBeHu jXDfFFmGzG5W44soxGRXqGYRlxIv2lUJblu7UgiLi8cmJNXr+TdimCSKlHnPRM6phk8o On7nvrN1Obwrys96sMtkpsiov3C7pLyh5RRfkswyBdEINWjUWEkGqACBEW0F/Cj0bVTT dzOzEWxhNhzTOLTxzthr5buPQeG+sq4gt8RX1VegLcr7HEIFBfnOfOfvoAZ3/BSQAukV S2Eg== X-Forwarded-Encrypted: i=1; AJvYcCXicjK16lE8BT0kVoKCkCho2vRWfv9qqUPKwUv5yv3E0bQuv6GdyUnWYJPCpz4MCW+DYy7rDNuBLhF4440=@vger.kernel.org X-Gm-Message-State: AOJu0Ywj2+MiJV3IuGzV+8GlzxwUA1FKEX9SFMH954CdbYqLh2ZZVwBz EvoqjKBfqqMRQZbSslPmkUkE4Nu5TtSfs2mP+Q92gtmcb9SP25rkhA/v X-Gm-Gg: AY/fxX5S7PG1CHfjBVDVrdr/NqJFg/0Yh+avQxieBd9RrgmzwPad8YxKUsEnDiFeVpe 9bwsp8FwAeRB76prPhJbuxZoBhpNgTbLgdLwIW39j92xYal6gMUyYvDZ1y224Ejy1QhZQScTey3 L4fC6CUKoSNsuHiovAjERB+iO95iY29rA85DHCzKbXhT+m/oCrW02QokRmrXOAxPM1ad8ZZaG/F Wr4RP94klJwncBQRSjmIkjHKt59iOtUsHMlC6zD0HXH8oKay2v5e+uYk9U5mKNlZXWr0Dtv+d14 jeJlWOciF5m4vPebhrM2IsHeTAjbbnDPw4EWYBz2znMebRq4E6dPWRWXFduZVa09wmH0EKOmd2Z m8/uTsIjILSd89LTGwzgXv2Orv36zDMTNoLRj/2AUXgXk3hvjaEOT795rYvzX3A9WWHGcp9e7kZ cynasYfdSO4BiJ2XBQkgTkauRvYw23kbG21JRhMZzx+EQ= X-Google-Smtp-Source: AGHT+IERetNfHsRXNnmsuixwV63EZ9aUKbNhPYULrI+e6CG2A/WjJrZfzbnUT2ZksmfOEyavTT51iQ== X-Received: by 2002:a05:6402:2787:b0:64d:1fcf:3eda with SMTP id 4fb4d7f45d1cf-64d1fcf41d4mr9844158a12.22.1766521247825; Tue, 23 Dec 2025 12:20:47 -0800 (PST) Received: from fedora ([46.248.82.114]) by smtp.gmail.com with ESMTPSA id 4fb4d7f45d1cf-64b91599844sm14707177a12.25.2025.12.23.12.20.46 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 23 Dec 2025 12:20:46 -0800 (PST) From: Uros Bizjak To: x86@kernel.org, linux-kernel@vger.kernel.org Cc: Uros Bizjak , Thomas Gleixner , Ingo Molnar , Borislav Petkov , Dave Hansen , "H. Peter Anvin" Subject: [PATCH 1/3] x86/boot: replace FS/GS inline asm with segment-qualified accesses Date: Tue, 23 Dec 2025 21:18:56 +0100 Message-ID: <20251223202038.91200-2-ubizjak@gmail.com> X-Mailer: git-send-email 2.52.0 In-Reply-To: <20251223202038.91200-1-ubizjak@gmail.com> References: <20251223202038.91200-1-ubizjak@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable GCC treats absolute addresses smaller than min-pagesize param (defaulting to 4kB) as assumed results of pointer arithmetics from NULL. The following code, when compiled with -O2 -Warray-bounds (included in -Wall): int foo (void) { return *(int *)0x123; } will emit a rather cryptic warning: warning: array subscript 0 is outside array bounds of =E2=80=98int[0]=E2=80= =99 [-Warray-bounds=3D] 1 | int foo (void) { return *(int *)0x123; } | ^~~~~~~~~~~~~ cc1: note: source object is likely at address zero Currently, the warning is supressed by the GCC specific RELOC_HIDE() macro that obfuscates arithmetic on a variable address so that GCC doesn't recognize the original var, and make assumptions about it. The GCC specific RELOC_HIDE() macro was introduced to work around certain ppc64 specific compiler bug in pre-4.1 GCC. This bug was fixed long ago, and replacing GCC specific macro with a generic one triggers the above warning in vga_recalc_vertical(). To solve the issue, replace open-coded inline assembly used for FS/GS memory accesses in arch/x86/boot/boot.h with segment-qualified pointer dereferences. The compiler allows pointer arithmetic from NULL in __seg_fs and __seg_gs named address spaces. Using __seg_fs and __seg_gs also simplifies the code, improves readability, and allows the compiler to reason better about the memory accesses. Explicit "memory" clobbers are also added to FS/GS segment register updates and repe cmpsb helpers to prevent incorrect reordering. No functional changes intended. Signed-off-by: Uros Bizjak Cc: Thomas Gleixner Cc: Ingo Molnar Cc: Borislav Petkov Cc: Dave Hansen Cc: "H. Peter Anvin" --- arch/x86/boot/boot.h | 58 ++++++++++++++------------------------------ 1 file changed, 18 insertions(+), 40 deletions(-) diff --git a/arch/x86/boot/boot.h b/arch/x86/boot/boot.h index 8e3eab34dff4..6f39048f0481 100644 --- a/arch/x86/boot/boot.h +++ b/arch/x86/boot/boot.h @@ -53,7 +53,7 @@ static inline u16 ds(void) =20 static inline void set_fs(u16 seg) { - asm volatile("movw %0,%%fs" : : "rm" (seg)); + asm volatile("movw %0,%%fs" : : "rm" (seg) : "memory"); } static inline u16 fs(void) { @@ -64,7 +64,7 @@ static inline u16 fs(void) =20 static inline void set_gs(u16 seg) { - asm volatile("movw %0,%%gs" : : "rm" (seg)); + asm volatile("movw %0,%%gs" : : "rm" (seg) : "memory"); } static inline u16 gs(void) { @@ -77,78 +77,54 @@ typedef unsigned int addr_t; =20 static inline u8 rdfs8(addr_t addr) { - u8 *ptr =3D (u8 *)absolute_pointer(addr); - u8 v; - asm volatile("movb %%fs:%1,%0" : "=3Dq" (v) : "m" (*ptr)); - return v; + return *(__seg_fs u8 *)(__force addr_t)absolute_pointer(addr); } static inline u16 rdfs16(addr_t addr) { - u16 *ptr =3D (u16 *)absolute_pointer(addr); - u16 v; - asm volatile("movw %%fs:%1,%0" : "=3Dr" (v) : "m" (*ptr)); - return v; + return *(__seg_fs u16 *)(__force addr_t)absolute_pointer(addr); } static inline u32 rdfs32(addr_t addr) { - u32 *ptr =3D (u32 *)absolute_pointer(addr); - u32 v; - asm volatile("movl %%fs:%1,%0" : "=3Dr" (v) : "m" (*ptr)); - return v; + return *(__seg_fs u32 *)(__force addr_t)absolute_pointer(addr); } =20 static inline void wrfs8(u8 v, addr_t addr) { - u8 *ptr =3D (u8 *)absolute_pointer(addr); - asm volatile("movb %1,%%fs:%0" : "+m" (*ptr) : "qi" (v)); + *(__seg_fs u8 *)(__force addr_t)absolute_pointer(addr) =3D v; } static inline void wrfs16(u16 v, addr_t addr) { - u16 *ptr =3D (u16 *)absolute_pointer(addr); - asm volatile("movw %1,%%fs:%0" : "+m" (*ptr) : "ri" (v)); + *(__seg_fs u16 *)(__force addr_t)absolute_pointer(addr) =3D v; } static inline void wrfs32(u32 v, addr_t addr) { - u32 *ptr =3D (u32 *)absolute_pointer(addr); - asm volatile("movl %1,%%fs:%0" : "+m" (*ptr) : "ri" (v)); + *(__seg_fs u32 *)(__force addr_t)absolute_pointer(addr) =3D v; } =20 static inline u8 rdgs8(addr_t addr) { - u8 *ptr =3D (u8 *)absolute_pointer(addr); - u8 v; - asm volatile("movb %%gs:%1,%0" : "=3Dq" (v) : "m" (*ptr)); - return v; + return *(__seg_gs u8 *)(__force addr_t)absolute_pointer(addr); } static inline u16 rdgs16(addr_t addr) { - u16 *ptr =3D (u16 *)absolute_pointer(addr); - u16 v; - asm volatile("movw %%gs:%1,%0" : "=3Dr" (v) : "m" (*ptr)); - return v; + return *(__seg_gs u16 *)(__force addr_t)absolute_pointer(addr); } static inline u32 rdgs32(addr_t addr) { - u32 *ptr =3D (u32 *)absolute_pointer(addr); - u32 v; - asm volatile("movl %%gs:%1,%0" : "=3Dr" (v) : "m" (*ptr)); - return v; + return *(__seg_gs u32 *)(__force addr_t)absolute_pointer(addr); } =20 static inline void wrgs8(u8 v, addr_t addr) { - u8 *ptr =3D (u8 *)absolute_pointer(addr); - asm volatile("movb %1,%%gs:%0" : "+m" (*ptr) : "qi" (v)); + *(__seg_gs u8 *)(__force addr_t)absolute_pointer(addr) =3D v; } static inline void wrgs16(u16 v, addr_t addr) { - u16 *ptr =3D (u16 *)absolute_pointer(addr); - asm volatile("movw %1,%%gs:%0" : "+m" (*ptr) : "ri" (v)); + *(__seg_gs u16 *)(__force addr_t)absolute_pointer(addr) =3D v; } static inline void wrgs32(u32 v, addr_t addr) { - u32 *ptr =3D (u32 *)absolute_pointer(addr); - asm volatile("movl %1,%%gs:%0" : "+m" (*ptr) : "ri" (v)); + *(__seg_gs u32 *)(__force addr_t)absolute_pointer(addr) =3D v; } =20 /* Note: these only return true/false, not a signed return value! */ @@ -156,14 +132,16 @@ static inline bool memcmp_fs(const void *s1, addr_t s= 2, size_t len) { bool diff; asm volatile("fs repe cmpsb" - : "=3D@ccnz" (diff), "+D" (s1), "+S" (s2), "+c" (len)); + : "=3D@ccnz" (diff), "+D" (s1), "+S" (s2), "+c" (len) + : : "memory"); return diff; } static inline bool memcmp_gs(const void *s1, addr_t s2, size_t len) { bool diff; asm volatile("gs repe cmpsb" - : "=3D@ccnz" (diff), "+D" (s1), "+S" (s2), "+c" (len)); + : "=3D@ccnz" (diff), "+D" (s1), "+S" (s2), "+c" (len) + : : "memory"); return diff; } =20 --=20 2.52.0