Re: [PATCH 1/3] x86/shstk: ban ia32 sigreturn when shadow stack is enabled

From: Edgecombe, Rick P

Date: Fri Oct 09 2026 - 18:14:23 EST


On Fri, 2026-10-09 at 11:36 +0000, Richard Patel wrote:
> On Thu, Oct 08, 2026 at 11:11:41PM +0000, Edgecombe, Rick P wrote:
> > On Thu, 2026-10-08 at 22:47 +0000, Richard Patel wrote:
> > > > But today setting EIP to an arbitrary point is fairly easy. But even in a
> > > > future
> > > > case of IBT enabled, shadow stack would still need enhancements for the
> > > > normal
> > > > 64 bit runtime to prevent this.
> > >
> > > What do you think of creating a shadow stack frame on signal delivery
> > > and popping that on sigreturn? I suppose that would need siglongjmp
> > > modifications and probably break CRIU. :(
> >
> > Yes I didn't know they did not parse the shadow stack signal frame
> > appropriately. That is unfortunate. But we can still evolve the shadow stack ABI
> > by adding new modes to the enable prctl if we want.
>
> In the case of CRIU, they are not only parsing
>

Ah so the parsing is right, but they don't add the extra frames?

> , but crafting their own
> frames on the shadow stack. I suppose we can keep the kernel's parser
> lenient so it works with older CRIU frames even after IBT enablement.

Yea we would need a backwards compatible frame. The real sigframes have the same
problems to solve.