WRUSSD, WRUSSQ

Write to User Shadow Stack

stableVMJITAOTinstruction

Encodings

OpcodeInstructionOp/En64-bitCompat/LegacyDescription
66 0F 38 F5 !(11):rrr:bbbWRUSSD m32, r32MRValidValidWrite 4 bytes to shadow stack.
66 REX.W 0F 38 F5 !(11):rrr:bbbWRUSSQ m64, r64MRValidNot encodableWrite 8 bytes to shadow stack.

Operand encoding

Each mode is a value of the Op/En column above. It says which field of the encoded instruction carries each operand, in the order they are written, and whether the instruction reads it, writes it or both.

MR

  1. modrm.rm escrituraModRM byte, r/m field (bits 2-0); with the SIB byte and the displacement when the mod field asks for them
  2. modrm.reg lecturaModRM byte, reg field (bits 5-3)

Measured cost

Loading measurements from arch-data...

Description

Writes bytes in register source to a user shadow stack pag.

Operation

IF CR4.CET = 0
    THEN #UD; FI;

IF CPL > 0
    THEN #GP(0); FI;

DEST_LA = Linear_Address(mem operand)
IF (operand size is 64 bit)

    THEN
          (* Destination not 8B aligned *)
          IF DEST_LA[2:0]
                THEN GP(0); FI;
          Shadow_stack_store 8 bytes of SRC to DEST_LA as user-mode access;

    ELSE
          (* Destination not 4B aligned *)
          IF DEST_LA[1:0]
                THEN GP(0); FI;
          Shadow_stack_store 4 bytes of SRC[31:0] to DEST_LA as user-mode access;

FI;

Flags affected

None.

C/C++ Compiler Intrinsic Equivalent

WRUSSD void _wrussd(__int32, void ); WRUSSQ void _wrussq(__int64, void );

Exceptions

Protected mode
#UDIf the LOCK prefix is used. If CR4.CET = 0.
#GP(0)If a memory operand effective address is outside the CS, DS, ES, FS, or GS segment limit. If destination is located in a non-writeable segment. If the DS, ES, FS, or GS register is used to access memory and it contains a NULL segment selector. If linear address of destination is not 4 byte aligned. If CPL is not 0.
#SS(0)If a memory operand effective address is outside the SS segment limit. #PF(fault-code) If destination is not a user shadow stack. Other terminal and non-terminal faults.
Real address mode
#UDThe WRUSS instruction is not recognized in real-address mode.
Virtual-8086 mode
#UDThe WRUSS instruction is not recognized in virtual-8086 mode.
Compatibility mode
#UDIf the LOCK prefix is used. If CR4.CET = 0.
#GP(0)If a memory address is in a non-canonical form. If linear address of destination is not 4 byte aligned. If CPL is not 0.
#SS(0)If a memory address referencing the SS segment is in a non-canonical form. #PF(fault-code) If destination is not a user shadow stack. Other terminal and non-terminal faults.
64-bit mode
#UDIf the LOCK prefix is used. If CR4.CET = 0.
#GP(0)If a memory address is in a non-canonical form. If linear address of destination is not 4 byte aligned. If CPL is not 0. #PF(fault-code) If destination is not a user shadow stack. Other terminal and non-terminal faults.

Sources