Re: [PATCH] x86/fpu: Free dynamic fpstate on exec()
From: Guixiong Wei
Date: Wed Sep 30 2026 - 05:44:24 EST
> From: "Chang S. Bae"<chang.seok.bae@xxxxxxxxx>
> Date: Wed, Sep 30, 2026, 14:51
> Subject: Re: [PATCH] x86/fpu: Free dynamic fpstate on exec()
> To: "Guixiong Wei"<weiguixiong@xxxxxxxxxxxxx>, <x86@xxxxxxxxxx>
> Cc: "Thomas Gleixner"<tglx@xxxxxxxxxx>, "Ingo Molnar"<mingo@xxxxxxxxxx>, "Borislav Petkov"<bp@xxxxxxxxx>, "Dave Hansen"<dave.hansen@xxxxxxxxxxxxxxx>, "H . Peter Anvin"<hpa@xxxxxxxxx>, <linux-kernel@xxxxxxxxxxxxxxx>, <stable@xxxxxxxxxxxxxxx>
> On 9/29/2026 8:10 AM, Guixiong Wei wrote:
> > The fpstate embedded in struct fpu only accommodates the default
> > xfeatures. When a task first uses a dynamically enabled xfeature,
> > fpstate_realloc() installs a larger fpstate allocated with vzalloc().
> >
> > fpu_flush_thread() resets fpu->fpstate to the embedded fpstate on exec()
> > without freeing the dynamically allocated one. Once the pointer is
> > overwritten, arch_release_task_struct() cannot free the allocation when
> > the task exits.
>
> Thanks for the finding and fixing this. I see Dave has given good
> suggestions. I think you can follow those into a revision.
Sure. I will add function test_exec to tools/testing/selftests/x86/amx.c,
covering the AMX use and exec sequence in the next revision.
>
> ...
>
> > On an AMX-capable system, 1000 iterations of requesting XTILEDATA
> > permission, executing TILEZERO and calling execve() on the same image
> > left 1000 16 KiB allocations attributed to __xfd_enable_feature() in
> > /proc/vmallocinfo. None remained after this change.
>
> I would be interested in turning this into a selftest if possible. It
> would be great if you could.
>
> Otherwise, I wrote a case (using XRSTOR instead) and then saw that
> amount from fpstate_relloac() in vmallocinfo:
>
> Caller/Module Difference
> ---------------------------------------------------
> fpstate_realloc.constprop.0 (pages=3) +16384000
> ...
>
> BTW, just curious if it happens with real-world applications. The
> permission is revoked on exec(), that is a very edge of the TMUL use if
> so. Is it a case running another application right after matrix
> multiplications?
>
I found this while developing an AMX application that calls exec()
after performing AMX computations.
> Thanks,
> Chang
>