Re: [PATCH v2] x86/shstk: shadow stack enabling write return code change

From: Edgecombe, Rick P

Date: Tue Jul 07 2026 - 14:57:32 EST


On Tue, 2026-07-07 at 13:45 -0500, Bill Roberts wrote:
> The WRSS instruction (the special instruction that writes to shadow stacks)
> cannot be used in userspace unless IA32_U_CET.SH_STK_EN=1 (user shadow
> stack is enabled). So the kernel *should* return -EINVAL to userspace if
> it tries to enable it when shadow stack is disabled. However, currently,
> it will return -EPERM. But, that error code doesn't fit the condition as
> the failure is due to an invalid state change request not a permission
> issue.
>
> Investigating userspace call sites, like glibc and criu (checkpoint code),
> they do not rely on this specific error message, nor could a userspace
> effectively utilize this specific return error code to indicate a
> difference in "I cannot enable write because of invalid permissions"
> versus "I cannot enable write because the shadow stack is disabled".
>
> Signed-off-by: Bill Roberts <bill.roberts@xxxxxxx>

Reviewed-by: Rick Edgecombe <rick.p.edgecombe@xxxxxxxxx>

> ---
> arch/x86/kernel/shstk.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/arch/x86/kernel/shstk.c b/arch/x86/kernel/shstk.c
> index 0ca64900192f..eb690ba90180 100644
> --- a/arch/x86/kernel/shstk.c
> +++ b/arch/x86/kernel/shstk.c
> @@ -490,7 +490,7 @@ static int wrss_control(bool enable)
> * when disabling.
> */
> if (!features_enabled(ARCH_SHSTK_SHSTK))
> - return -EPERM;
> + return -EINVAL;
>
> /* Already enabled/disabled? */
> if (features_enabled(ARCH_SHSTK_WRSS) == enable)