[PATCH 1/3] x86/shstk: ban ia32 sigreturn when shadow stack is enabled

From: Richard Patel

Date: Thu Oct 08 2026 - 16:22:41 EST


When returning from a signal via x32 or x64 rt_sigreturn, the
shadow-stack-restore token is validated, but ia32 (rt_)sigreturn
do not call restore_signal_shadow_stack().

With IA32_EMULATION, 'int $0x80' allows ia32 sigreturn in 64-bit
mode, which could defeat sigreturn protection.

Refuse ia32 sigreturn by forcing a SIGSEGV instead.

Fixes: 05e36022c054 ("x86/shstk: Handle signals for shadow stack")
Signed-off-by: Richard Patel <ripatel@xxxxxxx>
---
arch/x86/kernel/signal_32.c | 4 ++++
1 file changed, 4 insertions(+)

diff --git a/arch/x86/kernel/signal_32.c b/arch/x86/kernel/signal_32.c
index 8e87ab586437..a28e750b4e6d 100644
--- a/arch/x86/kernel/signal_32.c
+++ b/arch/x86/kernel/signal_32.c
@@ -32,6 +32,7 @@
#include <asm/sighandling.h>
#include <asm/smap.h>
#include <asm/gsseg.h>
+#include <asm/shstk.h>

/*
* The first GDT descriptor is reserved as 'NULL descriptor'. As bits 0
@@ -109,6 +110,9 @@ static bool ia32_restore_sigcontext(struct pt_regs *regs,
{
struct sigcontext_32 sc;

+ if (shstk_is_enabled())
+ return false;
+
/* Always make any pending restarted system calls return -EINTR */
current->restart_block.fn = do_no_restart_syscall;

--
2.52.0