Re: [PATCH v2] x86/shstk: shadow stack enabling write return code change
From: Bill Roberts
Date: Wed Jul 08 2026 - 17:01:42 EST
On 7/8/26 11:46 AM, Dave Hansen wrote:
On 7/7/26 11:45, Bill Roberts wrote:
The WRSS instruction (the special instruction that writes to shadow stacks)Hi Bill,
cannot be used in userspace unless IA32_U_CET.SH_STK_EN=1 (user shadow
stack is enabled). So the kernel *should* return -EINVAL to userspace if
it tries to enable it when shadow stack is disabled. However, currently,
it will return -EPERM. But, that error code doesn't fit the condition as
the failure is due to an invalid state change request not a permission
issue.
Investigating userspace call sites, like glibc and criu (checkpoint code),
they do not rely on this specific error message, nor could a userspace
effectively utilize this specific return error code to indicate a
difference in "I cannot enable write because of invalid permissions"
versus "I cannot enable write because the shadow stack is disabled".
Thanks for the patch. One bit of context I'd appreciate: why do you
care? Were you just auditing the code and something seemed wrong? Were
you doing some ARM code and noticed a mismatch?
What motivated the change?
Hi Dave, long time no see. So the motivation for the patches is around
adding LSM controls on disabling or making the shadow stack writable.
So, as part of that work, which will be forthcoming very soon, is
supporting the prctl interface for x86 shadow stack controls, so that
the LSMs are arch agnostic. This also provides a common userspace
shadow stack API for all archs currently supporting this feature (x86, arm64, riscv).
This would also let things, like glibc, have a common UAPI.
It's important to note that this work I describe, leaves the arch_prctl interface
intact, and it will need an lsm hook for controls via arch_prctl. This way both
paths behave the same way.
Now for this patch. I noticed this issue when I was doing negative testing
from userspace via prctl and the return value didn't match what was in
the pcrtl man page.
Thanks,
Bill