1 // SPDX-License-Identifier: GPL-2.0-only
3 * Corrupt the XSTATE header in a signal frame
5 * Based on analysis and a test case from Thomas Gleixner.
20 static inline void __cpuid(unsigned int *eax, unsigned int *ebx,
21 unsigned int *ecx, unsigned int *edx)
29 : "0" (*eax), "2" (*ecx));
32 static inline int xsave_enabled(void)
34 unsigned int eax, ebx, ecx, edx;
38 __cpuid(&eax, &ebx, &ecx, &edx);
40 /* Is CR4.OSXSAVE enabled ? */
41 return ecx & (1U << 27);
44 static void sethandler(int sig, void (*handler)(int, siginfo_t *, void *),
49 memset(&sa, 0, sizeof(sa));
50 sa.sa_sigaction = handler;
51 sa.sa_flags = SA_SIGINFO | flags;
52 sigemptyset(&sa.sa_mask);
53 if (sigaction(sig, &sa, 0))
57 static void sigusr1(int sig, siginfo_t *info, void *uc_void)
59 ucontext_t *uc = uc_void;
60 uint8_t *fpstate = (uint8_t *)uc->uc_mcontext.fpregs;
61 uint64_t *xfeatures = (uint64_t *)(fpstate + 512);
63 printf("\tWreck XSTATE header\n");
64 /* Wreck the first reserved bytes in the header */
65 *(xfeatures + 2) = 0xfffffff;
68 static void sigsegv(int sig, siginfo_t *info, void *uc_void)
70 printf("\tGot SIGSEGV\n");
77 sethandler(SIGUSR1, sigusr1, 0);
78 sethandler(SIGSEGV, sigsegv, 0);
80 if (!xsave_enabled()) {
81 printf("[SKIP] CR4.OSXSAVE disabled.\n");
89 * Enforce that the child runs on the same CPU
90 * which in turn forces a schedule.
92 sched_setaffinity(getpid(), sizeof(set), &set);
94 printf("[RUN]\tSend ourselves a signal\n");
97 printf("[OK]\tBack from the signal. Now schedule.\n");
104 waitpid(child, NULL, 0);
105 printf("[OK]\tBack in the main thread.\n");
108 * We could try to confirm that extended state is still preserved
109 * when we schedule. For now, the only indication of failure is
110 * a warning in the kernel logs.