SETSSBSY

Mark Shadow Stack Busy

stableVMJITAOTinstruction

Encodings

OpcodeInstructionOp/En64-bitCompat/LegacyDescription
F3 0F 01 E8SETSSBSYZOValidValidSet busy flag in supervisor shadow stack token reference by IA32_PL0_SSP.

Measured cost

Loading measurements from arch-data...

Description

The SETSSBSY instruction verifies the presence of a non-busy supervisor shadow stack token at the address in the IA32_PL0_SSP MSR and marks it busy. Following successful execution of the instruction, the SSP is set to the value of the IA32_PL0_SSP MSR.

This instruction cannot be executed when FRED transitions are enabled. FRED transitions do not use supervisor shadow stack tokens.

Operation

IF CR4.CET = 0 OR CR4.FRED = 1
    THEN #UD; FI;

IF IA32_S_CET.SH_STK_EN = 0
    THEN #UD; FI;

IF CPL > 0
    THEN GP(0); FI;

SSP_LA = IA32_PL0_SSP
If SSP_LA not aligned to 8 bytes

    THEN #GP(0); FI;

expected_token_value = SSP_LA              (* busy bit must not be set *)

new_token_value  = SSP_LA | BUSY_BIT       (* set busy bit; bit position 0 *)

IF shadow_stack_lock_cmpxchg8B(SSP_LA, new_token_value, expected_token_value) != expected_token_value

THEN #CP(SETSSBSY); FI;

SSP = SSP_LA

Flags affected

None.

C/C++ Compiler Intrinsic Equivalent SETSSBSYvoid _setssbsy(void);

Exceptions

Protected mode
#UDIf the LOCK prefix is used. If CR4.CET = 0. IF IA32_S_CET.SH_STK_EN = 0.
#GP(0)If IA32_PL0_SSP not aligned to 8 bytes. If CPL is not 0.
#CP(setssbsy)If busy bit in token is set.
#PF(fault-code)If the address in token is not below 4 GBytes. If a page fault occurs.
Real address mode
#UDThe SETSSBSY instruction is not recognized in real-address mode.
Virtual-8086 mode
#UDThe SETSSBSY instruction is not recognized in virtual-8086 mode.
Compatibility mode
#UDIf the LOCK prefix is used. If CR4.CET = 0. IF IA32_S_CET.SH_STK_EN = 0. If CR4.FRED = 1.
#GP(0)If IA32_PL0_SSP not aligned to 8 bytes. If CPL is not 0.
#CP(setssbsy)If busy bit in token is set. If the address in token is not below 4 GBytes. #PF(fault-code) If a page fault occurs.
64-bit mode
Same as compatibility mode exceptions (except there is no check on the token address).

Sources