[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[PATCH v4 3/4] x86/traps: reduce indentation in fixup_exception_return()


  • To: "xen-devel@xxxxxxxxxxxxxxxxxxxx" <xen-devel@xxxxxxxxxxxxxxxxxxxx>
  • From: Jan Beulich <jbeulich@xxxxxxxx>
  • Date: Mon, 27 Jul 2026 12:27:18 +0200
  • Authentication-results: eu.smtp.expurgate.cloud; dkim=pass header.s=google header.d=suse.com header.i="@suse.com" header.h="Content-Transfer-Encoding:Content-Type:In-Reply-To:Autocrypt:Content-Language:References:Cc:To:From:Subject:User-Agent:MIME-Version:Date:Message-ID"
  • Autocrypt: addr=jbeulich@xxxxxxxx; keydata= xsDiBFk3nEQRBADAEaSw6zC/EJkiwGPXbWtPxl2xCdSoeepS07jW8UgcHNurfHvUzogEq5xk hu507c3BarVjyWCJOylMNR98Yd8VqD9UfmX0Hb8/BrA+Hl6/DB/eqGptrf4BSRwcZQM32aZK 7Pj2XbGWIUrZrd70x1eAP9QE3P79Y2oLrsCgbZJfEwCgvz9JjGmQqQkRiTVzlZVCJYcyGGsD /0tbFCzD2h20ahe8rC1gbb3K3qk+LpBtvjBu1RY9drYk0NymiGbJWZgab6t1jM7sk2vuf0Py O9Hf9XBmK0uE9IgMaiCpc32XV9oASz6UJebwkX+zF2jG5I1BfnO9g7KlotcA/v5ClMjgo6Gl MDY4HxoSRu3i1cqqSDtVlt+AOVBJBACrZcnHAUSuCXBPy0jOlBhxPqRWv6ND4c9PH1xjQ3NP nxJuMBS8rnNg22uyfAgmBKNLpLgAGVRMZGaGoJObGf72s6TeIqKJo/LtggAS9qAUiuKVnygo 3wjfkS9A3DRO+SpU7JqWdsveeIQyeyEJ/8PTowmSQLakF+3fote9ybzd880fSmFuIEJldWxp Y2ggPGpiZXVsaWNoQHN1c2UuY29tPsJgBBMRAgAgBQJZN5xEAhsDBgsJCAcDAgQVAggDBBYC AwECHgECF4AACgkQoDSui/t3IH4J+wCfQ5jHdEjCRHj23O/5ttg9r9OIruwAn3103WUITZee e7Sbg12UgcQ5lv7SzsFNBFk3nEQQCACCuTjCjFOUdi5Nm244F+78kLghRcin/awv+IrTcIWF hUpSs1Y91iQQ7KItirz5uwCPlwejSJDQJLIS+QtJHaXDXeV6NI0Uef1hP20+y8qydDiVkv6l IreXjTb7DvksRgJNvCkWtYnlS3mYvQ9NzS9PhyALWbXnH6sIJd2O9lKS1Mrfq+y0IXCP10eS FFGg+Av3IQeFatkJAyju0PPthyTqxSI4lZYuJVPknzgaeuJv/2NccrPvmeDg6Coe7ZIeQ8Yj t0ARxu2xytAkkLCel1Lz1WLmwLstV30g80nkgZf/wr+/BXJW/oIvRlonUkxv+IbBM3dX2OV8 AmRv1ySWPTP7AAMFB/9PQK/VtlNUJvg8GXj9ootzrteGfVZVVT4XBJkfwBcpC/XcPzldjv+3 HYudvpdNK3lLujXeA5fLOH+Z/G9WBc5pFVSMocI71I8bT8lIAzreg0WvkWg5V2WZsUMlnDL9 mpwIGFhlbM3gfDMs7MPMu8YQRFVdUvtSpaAs8OFfGQ0ia3LGZcjA6Ik2+xcqscEJzNH+qh8V m5jjp28yZgaqTaRbg3M/+MTbMpicpZuqF4rnB0AQD12/3BNWDR6bmh+EkYSMcEIpQmBM51qM EKYTQGybRCjpnKHGOxG0rfFY1085mBDZCH5Kx0cl0HVJuQKC+dV2ZY5AqjcKwAxpE75MLFkr wkkEGBECAAkFAlk3nEQCGwwACgkQoDSui/t3IH7nnwCfcJWUDUFKdCsBH/E5d+0ZnMQi+G0A nAuWpQkjM1ASeQwSHEeAWPgskBQL
  • Cc: Andrew Cooper <andrew.cooper3@xxxxxxxxxx>, Teddy Astie <teddy.astie@xxxxxxxxxx>, Roger Pau Monné <roger@xxxxxxxxxxxxxx>
  • Delivery-date: Mon, 27 Jul 2026 10:27:22 +0000
  • List-id: Xen developer discussion <xen-devel.lists.xenproject.org>

The earlier "x86/traps: use entry_ssp in fixup_exception_return()" left
unnecessary scopes and hence unnecessarily deep indentation. While that
was intentional (to improve readabilirty of the diff), rectify this now.

Signed-off-by: Jan Beulich <jbeulich@xxxxxxxx>
---
v4: New.

--- a/xen/arch/x86/traps.c
+++ b/xen/arch/x86/traps.c
@@ -1175,90 +1175,86 @@ static void fixup_exception_return(struc
                                    unsigned long fixup, unsigned long stub_ra)
 {
 #ifdef CONFIG_XEN_SHSTK
+    unsigned long ssp = rdssp();
+
+    if ( ssp != SSP_NO_SHSTK )
     {
-        unsigned long ssp = rdssp();
+        unsigned long *ptr = _p(regs->entry_ssp);
+        unsigned long primary_shstk =
+            (ssp & ~(STACK_SIZE - 1)) +
+            (PRIMARY_SHSTK_SLOT + 1) * PAGE_SIZE - 8;
+
+        BUG_ON((regs->entry_ssp ^ primary_shstk) >>
+               (PAGE_SHIFT + STACK_ORDER));
+
+        /*
+         * The shstk currently looks like this:
+         *
+         *   tok  [Supervisor token, == &tok | BUSY, only with FRED inactive]
+         *   ...  [Pointed to by SSP for most exceptions, empty in IST cases]
+         *   %cs  [== regs->cs]
+         *   %rip [== regs->rip]
+         *   SSP  [Pointed to by entry_ssp; Likely points to 3 slots
+         *         higher, above %cs]
+         *   ...  [call tree to this function, likely 2/3 slots]
+         *
+         * and we want to overwrite %rip with fixup.  There are two
+         * complications:
+         *   1) We cant depend on SSP values, because they won't differ by
+         *      3 slots if the exception is taken on an IST stack.
+         *   2) There are synthetic (unrealistic but not impossible)
+         *      scenarios where %rip can end up in the call tree to this
+         *      function, so we can't check against regs->rip alone.
+         *
+         * Check for both regs->rip and regs->cs matching.
+         */
+        BUG_ON(ptr[1] != regs->rip || ptr[2] != regs->cs);
+
+        wrss(fixup, &ptr[1]);
+
+        if ( !stub_ra )
+            goto shstk_done;
+
+        /*
+         * Stub recovery ought to happen only when the outer context
+         * was on the main shadow stack.  We need to also "pop" the
+         * stub's return address from the interrupted context's shadow
+         * stack.  That is,
+         * - if we're still on the main stack, we need to move the
+         *   entire stack (up to and including the exception frame)
+         *   up by one slot, incrementing the original SSP in the
+         *   exception frame,
+         * - if we're on an IST stack, we need to increment the
+         *   original SSP.
+         */
+        BUG_ON((ptr[0] ^ primary_shstk) >> PAGE_SHIFT);
 
-        if ( ssp != SSP_NO_SHSTK )
+        if ( (ssp ^ primary_shstk) >> PAGE_SHIFT )
         {
-            unsigned long *ptr = _p(regs->entry_ssp);
-            unsigned long primary_shstk =
-                (ssp & ~(STACK_SIZE - 1)) +
-                (PRIMARY_SHSTK_SLOT + 1) * PAGE_SIZE - 8;
-
-            BUG_ON((regs->entry_ssp ^ primary_shstk) >>
-                   (PAGE_SHIFT + STACK_ORDER));
-
             /*
-             * The shstk currently looks like this:
-             *
-             *   tok  [Supervisor token, == &tok | BUSY, only with FRED 
inactive]
-             *   ...  [Pointed to by SSP for most exceptions, empty in IST 
cases]
-             *   %cs  [== regs->cs]
-             *   %rip [== regs->rip]
-             *   SSP  [Pointed to by entry_ssp; Likely points to 3 slots
-             *         higher, above %cs]
-             *   ...  [call tree to this function, likely 2/3 slots]
-             *
-             * and we want to overwrite %rip with fixup.  There are two
-             * complications:
-             *   1) We cant depend on SSP values, because they won't differ by
-             *      3 slots if the exception is taken on an IST stack.
-             *   2) There are synthetic (unrealistic but not impossible)
-             *      scenarios where %rip can end up in the call tree to this
-             *      function, so we can't check against regs->rip alone.
-             *
-             * Check for both regs->rip and regs->cs matching.
+             * We're on an IST stack.  First make sure the two return
+             * addresses actually match.  Then increment the interrupted
+             * context's SSP.
              */
-            BUG_ON(ptr[1] != regs->rip || ptr[2] != regs->cs);
+            BUG_ON(stub_ra != *(unsigned long*)ptr[0]);
+            wrss(ptr[0] + 8, &ptr[0]);
+            goto shstk_done;
+        }
 
-            {
-                wrss(fixup, &ptr[1]);
+        /* Make sure the two return addresses actually match. */
+        BUG_ON(stub_ra != ptr[3]);
 
-                if ( !stub_ra )
-                    goto shstk_done;
+        /* Move exception frame, updating SSP there. */
+        wrss(ptr[2], &ptr[3]); /* %cs */
+        wrss(ptr[1], &ptr[2]); /* %rip */
+        wrss(ptr[0] + 8, &ptr[1]); /* SSP */
+
+        /* Move all newer entries. */
+        while ( ptr-- != _p(ssp) )
+            wrss(ptr[0], &ptr[1]);
 
-                /*
-                 * Stub recovery ought to happen only when the outer context
-                 * was on the main shadow stack.  We need to also "pop" the
-                 * stub's return address from the interrupted context's shadow
-                 * stack.  That is,
-                 * - if we're still on the main stack, we need to move the
-                 *   entire stack (up to and including the exception frame)
-                 *   up by one slot, incrementing the original SSP in the
-                 *   exception frame,
-                 * - if we're on an IST stack, we need to increment the
-                 *   original SSP.
-                 */
-                BUG_ON((ptr[0] ^ primary_shstk) >> PAGE_SHIFT);
-
-                if ( (ssp ^ primary_shstk) >> PAGE_SHIFT )
-                {
-                    /*
-                     * We're on an IST stack.  First make sure the two return
-                     * addresses actually match.  Then increment the 
interrupted
-                     * context's SSP.
-                     */
-                    BUG_ON(stub_ra != *(unsigned long*)ptr[0]);
-                    wrss(ptr[0] + 8, &ptr[0]);
-                    goto shstk_done;
-                }
-
-                /* Make sure the two return addresses actually match. */
-                BUG_ON(stub_ra != ptr[3]);
-
-                /* Move exception frame, updating SSP there. */
-                wrss(ptr[2], &ptr[3]); /* %cs */
-                wrss(ptr[1], &ptr[2]); /* %rip */
-                wrss(ptr[0] + 8, &ptr[1]); /* SSP */
-
-                /* Move all newer entries. */
-                while ( ptr-- != _p(ssp) )
-                    wrss(ptr[0], &ptr[1]);
-
-                /* Finally account for our own stack having shifted up. */
-                asm volatile ( "incsspd %0" :: "r" (2) );
-            }
-        }
+        /* Finally account for our own stack having shifted up. */
+        asm volatile ( "incsspd %0" :: "r" (2) );
     }
  shstk_done:
 #endif /* CONFIG_XEN_SHSTK */




 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.