]> git.proxmox.com Git - mirror_ubuntu-artful-kernel.git/blame - arch/x86/kernel/xsave.c
x86: xsave: fix error condition in save_i387_xstate()
[mirror_ubuntu-artful-kernel.git] / arch / x86 / kernel / xsave.c
CommitLineData
dc1e35c6
SS
1/*
2 * xsave/xrstor support.
3 *
4 * Author: Suresh Siddha <suresh.b.siddha@intel.com>
5 */
6#include <linux/bootmem.h>
7#include <linux/compat.h>
8#include <asm/i387.h>
c37b5efe
SS
9#ifdef CONFIG_IA32_EMULATION
10#include <asm/sigcontext32.h>
11#endif
6152e4b1 12#include <asm/xcr.h>
dc1e35c6
SS
13
14/*
15 * Supported feature mask by the CPU and the kernel.
16 */
6152e4b1 17u64 pcntxt_mask;
dc1e35c6 18
c37b5efe
SS
19struct _fpx_sw_bytes fx_sw_reserved;
20#ifdef CONFIG_IA32_EMULATION
21struct _fpx_sw_bytes fx_sw_reserved_ia32;
22#endif
23
24/*
25 * Check for the presence of extended state information in the
26 * user fpstate pointer in the sigcontext.
27 */
28int check_for_xstate(struct i387_fxsave_struct __user *buf,
29 void __user *fpstate,
30 struct _fpx_sw_bytes *fx_sw_user)
31{
32 int min_xstate_size = sizeof(struct i387_fxsave_struct) +
33 sizeof(struct xsave_hdr_struct);
34 unsigned int magic2;
35 int err;
36
37 err = __copy_from_user(fx_sw_user, &buf->sw_reserved[0],
38 sizeof(struct _fpx_sw_bytes));
39
40 if (err)
41 return err;
42
43 /*
44 * First Magic check failed.
45 */
46 if (fx_sw_user->magic1 != FP_XSTATE_MAGIC1)
47 return -1;
48
49 /*
50 * Check for error scenarios.
51 */
52 if (fx_sw_user->xstate_size < min_xstate_size ||
53 fx_sw_user->xstate_size > xstate_size ||
54 fx_sw_user->xstate_size > fx_sw_user->extended_size)
55 return -1;
56
57 err = __get_user(magic2, (__u32 *) (((void *)fpstate) +
58 fx_sw_user->extended_size -
59 FP_XSTATE_MAGIC2_SIZE));
60 /*
61 * Check for the presence of second magic word at the end of memory
62 * layout. This detects the case where the user just copied the legacy
63 * fpstate layout with out copying the extended state information
64 * in the memory layout.
65 */
66 if (err || magic2 != FP_XSTATE_MAGIC2)
67 return -1;
68
69 return 0;
70}
71
ab513701
SS
72#ifdef CONFIG_X86_64
73/*
74 * Signal frame handlers.
75 */
76
77int save_i387_xstate(void __user *buf)
78{
79 struct task_struct *tsk = current;
80 int err = 0;
81
82 if (!access_ok(VERIFY_WRITE, buf, sig_xstate_size))
83 return -EACCES;
84
f65bc214 85 BUG_ON(sig_xstate_size < xstate_size);
ab513701 86
c37b5efe 87 if ((unsigned long)buf % 64)
ab513701
SS
88 printk("save_i387_xstate: bad fpstate %p\n", buf);
89
90 if (!used_math())
91 return 0;
92 clear_used_math(); /* trigger finit */
93 if (task_thread_info(tsk)->status & TS_USEDFPU) {
ed405958
SS
94 /*
95 * Start with clearing the user buffer. This will present a
96 * clean context for the bytes not touched by the fxsave/xsave.
97 */
98 __clear_user(buf, sig_xstate_size);
99
c37b5efe
SS
100 if (task_thread_info(tsk)->status & TS_XSAVE)
101 err = xsave_user(buf);
102 else
103 err = fxsave_user(buf);
104
ab513701
SS
105 if (err)
106 return err;
107 task_thread_info(tsk)->status &= ~TS_USEDFPU;
108 stts();
109 } else {
110 if (__copy_to_user(buf, &tsk->thread.xstate->fxsave,
111 xstate_size))
112 return -1;
113 }
c37b5efe
SS
114
115 if (task_thread_info(tsk)->status & TS_XSAVE) {
116 struct _fpstate __user *fx = buf;
117
118 err = __copy_to_user(&fx->sw_reserved, &fx_sw_reserved,
119 sizeof(struct _fpx_sw_bytes));
120
121 err |= __put_user(FP_XSTATE_MAGIC2,
122 (__u32 __user *) (buf + sig_xstate_size
123 - FP_XSTATE_MAGIC2_SIZE));
f364eada
SS
124 if (err)
125 return err;
c37b5efe
SS
126 }
127
ab513701
SS
128 return 1;
129}
130
c37b5efe
SS
131/*
132 * Restore the extended state if present. Otherwise, restore the FP/SSE
133 * state.
134 */
135int restore_user_xstate(void __user *buf)
136{
137 struct _fpx_sw_bytes fx_sw_user;
6152e4b1 138 u64 mask;
c37b5efe
SS
139 int err;
140
141 if (((unsigned long)buf % 64) ||
142 check_for_xstate(buf, buf, &fx_sw_user))
143 goto fx_only;
144
6152e4b1 145 mask = fx_sw_user.xstate_bv;
c37b5efe
SS
146
147 /*
148 * restore the state passed by the user.
149 */
6152e4b1 150 err = xrestore_user(buf, mask);
c37b5efe
SS
151 if (err)
152 return err;
153
154 /*
155 * init the state skipped by the user.
156 */
6152e4b1 157 mask = pcntxt_mask & ~mask;
c37b5efe 158
6152e4b1 159 xrstor_state(init_xstate_buf, mask);
c37b5efe
SS
160
161 return 0;
162
163fx_only:
164 /*
165 * couldn't find the extended state information in the
166 * memory layout. Restore just the FP/SSE and init all
167 * the other extended state.
168 */
6152e4b1 169 xrstor_state(init_xstate_buf, pcntxt_mask & ~XSTATE_FPSSE);
c37b5efe
SS
170 return fxrstor_checking((__force struct i387_fxsave_struct *)buf);
171}
172
ab513701
SS
173/*
174 * This restores directly out of user space. Exceptions are handled.
175 */
176int restore_i387_xstate(void __user *buf)
177{
178 struct task_struct *tsk = current;
c37b5efe 179 int err = 0;
ab513701
SS
180
181 if (!buf) {
c37b5efe
SS
182 if (used_math())
183 goto clear;
ab513701
SS
184 return 0;
185 } else
186 if (!access_ok(VERIFY_READ, buf, sig_xstate_size))
187 return -EACCES;
188
189 if (!used_math()) {
190 err = init_fpu(tsk);
191 if (err)
192 return err;
193 }
194
195 if (!(task_thread_info(current)->status & TS_USEDFPU)) {
196 clts();
197 task_thread_info(current)->status |= TS_USEDFPU;
198 }
c37b5efe
SS
199 if (task_thread_info(tsk)->status & TS_XSAVE)
200 err = restore_user_xstate(buf);
201 else
202 err = fxrstor_checking((__force struct i387_fxsave_struct *)
203 buf);
ab513701
SS
204 if (unlikely(err)) {
205 /*
206 * Encountered an error while doing the restore from the
207 * user buffer, clear the fpu state.
208 */
c37b5efe 209clear:
ab513701
SS
210 clear_fpu(tsk);
211 clear_used_math();
212 }
213 return err;
214}
215#endif
216
c37b5efe
SS
217/*
218 * Prepare the SW reserved portion of the fxsave memory layout, indicating
219 * the presence of the extended state information in the memory layout
220 * pointed by the fpstate pointer in the sigcontext.
221 * This will be saved when ever the FP and extended state context is
222 * saved on the user stack during the signal handler delivery to the user.
223 */
224void prepare_fx_sw_frame(void)
225{
226 int size_extended = (xstate_size - sizeof(struct i387_fxsave_struct)) +
227 FP_XSTATE_MAGIC2_SIZE;
228
229 sig_xstate_size = sizeof(struct _fpstate) + size_extended;
230
231#ifdef CONFIG_IA32_EMULATION
232 sig_xstate_ia32_size = sizeof(struct _fpstate_ia32) + size_extended;
233#endif
234
235 memset(&fx_sw_reserved, 0, sizeof(fx_sw_reserved));
236
237 fx_sw_reserved.magic1 = FP_XSTATE_MAGIC1;
238 fx_sw_reserved.extended_size = sig_xstate_size;
6152e4b1 239 fx_sw_reserved.xstate_bv = pcntxt_mask;
c37b5efe
SS
240 fx_sw_reserved.xstate_size = xstate_size;
241#ifdef CONFIG_IA32_EMULATION
242 memcpy(&fx_sw_reserved_ia32, &fx_sw_reserved,
243 sizeof(struct _fpx_sw_bytes));
244 fx_sw_reserved_ia32.extended_size = sig_xstate_ia32_size;
245#endif
246}
247
dc1e35c6
SS
248/*
249 * Represents init state for the supported extended state.
250 */
251struct xsave_struct *init_xstate_buf;
252
3c1c7f10
SS
253#ifdef CONFIG_X86_64
254unsigned int sig_xstate_size = sizeof(struct _fpstate);
255#endif
256
dc1e35c6
SS
257/*
258 * Enable the extended processor state save/restore feature
259 */
260void __cpuinit xsave_init(void)
261{
262 if (!cpu_has_xsave)
263 return;
264
265 set_in_cr4(X86_CR4_OSXSAVE);
266
267 /*
268 * Enable all the features that the HW is capable of
269 * and the Linux kernel is aware of.
dc1e35c6 270 */
6152e4b1 271 xsetbv(XCR_XFEATURE_ENABLED_MASK, pcntxt_mask);
dc1e35c6
SS
272}
273
274/*
275 * setup the xstate image representing the init state
276 */
a19aac85 277static void __init setup_xstate_init(void)
dc1e35c6
SS
278{
279 init_xstate_buf = alloc_bootmem(xstate_size);
280 init_xstate_buf->i387.mxcsr = MXCSR_DEFAULT;
281}
282
283/*
284 * Enable and initialize the xsave feature.
285 */
286void __init xsave_cntxt_init(void)
287{
288 unsigned int eax, ebx, ecx, edx;
289
290 cpuid_count(0xd, 0, &eax, &ebx, &ecx, &edx);
6152e4b1 291 pcntxt_mask = eax + ((u64)edx << 32);
dc1e35c6 292
6152e4b1
PA
293 if ((pcntxt_mask & XSTATE_FPSSE) != XSTATE_FPSSE) {
294 printk(KERN_ERR "FP/SSE not shown under xsave features 0x%llx\n",
295 pcntxt_mask);
dc1e35c6
SS
296 BUG();
297 }
298
299 /*
300 * for now OS knows only about FP/SSE
301 */
6152e4b1 302 pcntxt_mask = pcntxt_mask & XCNTXT_MASK;
dc1e35c6
SS
303 xsave_init();
304
305 /*
306 * Recompute the context size for enabled features
307 */
308 cpuid_count(0xd, 0, &eax, &ebx, &ecx, &edx);
dc1e35c6
SS
309 xstate_size = ebx;
310
c37b5efe
SS
311 prepare_fx_sw_frame();
312
dc1e35c6
SS
313 setup_xstate_init();
314
6152e4b1 315 printk(KERN_INFO "xsave/xrstor: enabled xstate_bv 0x%llx, "
dc1e35c6 316 "cntxt size 0x%x\n",
6152e4b1 317 pcntxt_mask, xstate_size);
dc1e35c6 318}