mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Andrew Morton <akpm@osdl.org>
To: blaisorblade@yahoo.it
Cc: linux-kernel@vger.kernel.org, blaisorblade@yahoo.it,
	bstroesser@fujitsu-siemens.com, roland@redhat.com
Subject: Re: [patch 1/1] Ptrace - i386: fix "syscall audit" interaction with singlestep
Date: Tue, 30 Aug 2005 19:02:19 -0700	[thread overview]
Message-ID: <20050830190219.56473766.akpm@osdl.org> (raw)
In-Reply-To: <20050726184306.A104421DC16@zion.home.lan>

blaisorblade@yahoo.it wrote:
>
> 
> From: Bodo Stroesser <bstroesser@fujitsu-siemens.com>, Paolo 'Blaisorblade' Giarrusso <blaisorblade@yahoo.it>
> CC: Roland McGrath <roland@redhat.com>
> 
> Avoid giving two traps for singlestep instead of one, when syscall auditing is
> enabled.
> 
> In fact no singlestep trap is sent on syscall entry, only on syscall exit, as
> can be seen in entry.S:
> 
> # Note that in this mask _TIF_SINGLESTEP is not tested !!! <<<<<<<<<<<<<<
>         testb $(_TIF_SYSCALL_TRACE|_TIF_SYSCALL_AUDIT|_TIF_SECCOMP),TI_flags(%ebp)
>         jnz syscall_trace_entry
> 	...
> syscall_trace_entry:
> 	...
> 	call do_syscall_trace
> 
> But auditing a SINGLESTEP'ed process causes do_syscall_trace to be called, so
> the tracer will get one more trap on the syscall entry path, which it
> shouldn't.
> 
> This does not affect (to my knowledge) UML, nor is critical, so this shouldn't
> IMHO go in 2.6.13.
> 
> Signed-off-by: Paolo 'Blaisorblade' Giarrusso <blaisorblade@yahoo.it>
> ---
> 
>  linux-2.6.git-paolo/arch/i386/kernel/ptrace.c |   15 +++++++++++++--
>  1 files changed, 13 insertions(+), 2 deletions(-)
> 
> diff -puN arch/i386/kernel/ptrace.c~sysaudit-singlestep-non-umlhost arch/i386/kernel/ptrace.c
> --- linux-2.6.git/arch/i386/kernel/ptrace.c~sysaudit-singlestep-non-umlhost	2005-07-26 20:22:40.000000000 +0200
> +++ linux-2.6.git-paolo/arch/i386/kernel/ptrace.c	2005-07-26 20:23:44.000000000 +0200
> @@ -683,8 +683,19 @@ void do_syscall_trace(struct pt_regs *re
>  	/* do the secure computing check first */
>  	secure_computing(regs->orig_eax);
>  
> -	if (unlikely(current->audit_context) && entryexit)
> -		audit_syscall_exit(current, AUDITSC_RESULT(regs->eax), regs->eax);
> +	if (unlikely(current->audit_context)) {
> +		if (entryexit)
> +			audit_syscall_exit(current, AUDITSC_RESULT(regs->eax), regs->eax);
> +
> +		/* Debug traps, when using PTRACE_SINGLESTEP, must be sent only
> +		 * on the syscall exit path. Normally, when TIF_SYSCALL_AUDIT is
> +		 * not used, entry.S will call us only on syscall exit, not
> +		 * entry ; so when TIF_SYSCALL_AUDIT is used we must avoid
> +		 * calling send_sigtrap() on syscall entry.
> +		 */
> +		else if (is_singlestep)
> +			goto out;
> +	}
>  

This appears to be a UML patch, applied to x86, which has no `is_singlestep'.

  reply	other threads:[~2005-08-31  2:04 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2005-07-26 18:43 blaisorblade
2005-08-31  2:02 ` Andrew Morton [this message]
2005-09-01 14:49   ` Blaisorblade

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20050830190219.56473766.akpm@osdl.org \
    --to=akpm@osdl.org \
    --cc=blaisorblade@yahoo.it \
    --cc=bstroesser@fujitsu-siemens.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=roland@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®