When I read Intel's X86 programmer's manual, see the following for interrupt & interrupt return with stack switching:
interrupt:
If a stack switch does occur, the processor does the following:
- Temporarily saves (internally) the current contents of the SS, ESP, EFLAGS, CS, and EIP registers.
- Loads the segment selector and stack pointer for the new stack (that is, the stack for the privilege level being called) from the TSS into the SS and ESP registers and switches to the new stack.
- Pushes the temporarily saved SS, ESP, EFLAGS, CS, and EIP values for the interrupted procedure’s stack onto the new stack.
- Pushes an error code on the new stack (if appropriate).
- Loads the segment selector for the new code segment and the new instruction pointer (from the interrupt gate or trap gate) into the CS and EIP registers, respectively.
- If the call is through an interrupt gate, clears the IF flag in the EFLAGS register.
- Begins execution of the handler procedure at the new privilege level.
On return:
- Performs a privilege check.
- Restores the CS and EIP registers to their values prior to the interrupt or exception.
- Restores the EFLAGS register.
- Restores the SS and ESP registers to their values prior to the interrupt or exception, resulting in a stack switch back to the stack of the interrupted procedure.
- Resumes execution of the interrupted procedure.
For example, one linux process P:
- It's initially in kernel mode
- It returns to user mode by
iret. But from the manual, there is no change to TSS - It traps into kernel by
int. Here it needs to find the kernel stack fromESP & SSin TSS. How is this kernel stack value set up, since they are not stored to TSS in step 2?