From nobody Mon Sep 28 13:17:47 2026 Received: from va-1-113.ptr.blmpb.com (va-1-113.ptr.blmpb.com [209.127.230.113]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id CF73E47CC7F for ; Fri, 21 Aug 2026 10:43:14 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.127.230.113 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787309003; cv=none; b=B6XVlFSfrVcmPW7kNFlYmMwsmHv5IOJw3O33zbIgSR/I98mmuVSjWMjMQ3XQXNtjAnSC9s/WCdFpeRYAPSdtl/zleDNUwYrvPiAxPG1tiCTPEXyM1W50Oerc/L4AUdSniJrFXwOgxs7pNWY2JljlcVrTxkZCR81bNK3X2Kw+740= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787309003; c=relaxed/simple; bh=eb/FbkcQ1yOfds5otd9WzCnx2gHZinJnmqDUexxdOaQ=; h=To:Cc:Message-Id:Subject:Mime-Version:From:Date:Content-Type; b=SSaWnWxZT6FvwF/prXpS0Qi8G00oberK/+WAKY5aBlXI/otn3GGC8eHsEXrpXMrgENju3IANrJDsqJFX0nJOQpB56XLjR3TJUOxSMOTGdbjA78IS7BBRWoBKYTd7KoHsZKeu3joqirLMAMv2MUMUt0hj7O6UFQirlmwQpaZ/1fU= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=bytedance.com; spf=pass smtp.mailfrom=bytedance.com; dkim=pass (2048-bit key) header.d=bytedance.com header.i=@bytedance.com header.b=CNRHJPdj; arc=none smtp.client-ip=209.127.230.113 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=bytedance.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=bytedance.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=bytedance.com header.i=@bytedance.com header.b="CNRHJPdj" DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; s=2212171451; d=bytedance.com; t=1787308986; h=from:subject: mime-version:from:date:message-id:subject:to:cc:reply-to:content-type: mime-version:in-reply-to:message-id; bh=9z9/dVo62CkO35NnOydRcLhfvu3cyK6bVROTYKEbxeE=; b=CNRHJPdjlMKSLh0JtHEZo8Iv0bXHLt+42O3VuT6rgEzTp72rLl7oWZ9505HKqtpCwHFLia PslW3Dtz8wv4BmmGZstEIInCk8W003kedh/ruOHrmb1WGddsx7169SoohyUASe5RTywHr0 T33xyHr4F2B1uwX51FDiHgp5XtUVBDW0cytAPfoqAuAr1iVkNMdwHPj7Z3BHO/lLzSg+Tz 4ARzScegD6wCZOl4Al4J8NgUCe0x8NMgw64Q13nveMsabZ2WpJT0Rmmwoj8Zj+iOhKqovc PxNyNmw8TFQMVwdYFJAcBlz8ZHlRW0U6SB85m5bz9AWsq/wxNLnuQvyTUpRNFw== To: "Thomas Gleixner" , "Ingo Molnar" , "Borislav Petkov" , "Dave Hansen" , , "Shuah Khan" Cc: "H . Peter Anvin" , "Andy Lutomirski" , "Kiryl Shutsemau" , , , "Guixiong Wei" X-Mailer: git-send-email 2.50.1 Message-Id: <20260821104246.59955-2-weiguixiong@bytedance.com> Content-Transfer-Encoding: quoted-printable Subject: [PATCH] selftests/x86: Skip sysret_rip fall-through probes that hit the stack Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 X-Lms-Return-Path: From: "Guixiong Wei" Date: Fri, 21 Aug 2026 18:42:47 +0800 X-Original-From: Guixiong Wei Content-Type: text/plain; charset="utf-8" test_syscall_fallthrough_to() relocates the syscall trampoline page to a target high address with mremap(MREMAP_MAYMOVE | MREMAP_FIXED). Like MAP_FIXED, MREMAP_FIXED silently unmaps whatever already occupies the destination. The extra self-test at (1<<47) - 2*PAGE_SIZE remaps to 0x7fffffffd000, and the i=3D=3D47 interesting case at (1<<47) - PAGE_SIZE remaps to 0x7fffffffe000. Both sit just below STACK_TOP_MAX (0x7ffffffff000). With ASLR enabled the stack is randomized elsewhere and these addresses are free, so the remap is harmless. With ASLR disabled the stack lives at its fixed default location and overlaps them, so the remap unmaps the stack and the process dies with SIGSEGV (exit 139) before the test can observe anything. Probe the trampoline and fall-through pages with mincore() and skip any target whose destination is already in use. With ASLR enabled -- the default -- the stack sits elsewhere, so every case still runs. With ASLR disabled only the two cases that collide with the stack are skipped; the noncanonical cases that actually exercise the kernel's SYSRET handling live far above the stack and always run. Fixes: 660602140103 ("selftests/x86: Add a selftest for SYSRET to noncanoni= cal addresses") Signed-off-by: Guixiong Wei --- tools/testing/selftests/x86/sysret_rip.c | 28 ++++++++++++++++++++++++ 1 file changed, 28 insertions(+) diff --git a/tools/testing/selftests/x86/sysret_rip.c b/tools/testing/selft= ests/x86/sysret_rip.c index 2e423a335e1c..e4bd3ed881f4 100644 --- a/tools/testing/selftests/x86/sysret_rip.c +++ b/tools/testing/selftests/x86/sysret_rip.c @@ -94,6 +94,17 @@ static void sigsegv_for_fallthrough(int sig, siginfo_t *= info, void *ctx_void) siglongjmp(jmpbuf, 1); } =20 +static bool address_is_mapped(unsigned long addr) +{ + unsigned char vec; + + /* + * mincore() succeeds only when the whole range is mapped and fails + * with ENOMEM when the page is not mapped. + */ + return mincore((void *)addr, 4096, &vec) =3D=3D 0; +} + static void test_syscall_fallthrough_to(unsigned long ip) { void *new_address =3D (void *)(ip - 4096); @@ -101,6 +112,23 @@ static void test_syscall_fallthrough_to(unsigned long = ip) =20 printf("[RUN]\tTrying a SYSCALL that falls through to 0x%lx\n", ip); =20 + /* + * MREMAP_FIXED, like MAP_FIXED, silently unmaps whatever already + * occupies the destination. With ASLR disabled the stack lives at + * the top of the address space and overlaps the high addresses + * exercised here, so a blind remap would clobber the stack and take + * the test down with a SIGSEGV. Skip any target whose trampoline or + * landing page is already in use; the noncanonical cases that + * actually probe the kernel sit far above the stack and are + * unaffected. + */ + if (address_is_mapped((unsigned long)new_address) || + address_is_mapped(ip)) { + printf("[SKIP]\t0x%lx: address space near the stack is in use (ASLR off?= )\n", + ip); + return; + } + ret =3D mremap((void *)current_test_page_addr, 4096, 4096, MREMAP_MAYMOVE | MREMAP_FIXED, new_address); if (ret =3D=3D MAP_FAILED) { base-commit: f5bbbfec59b4e2fb7520a91de3df8a6174325d6a --=20 2.50.1 (Apple Git-155)