mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Kees Cook <kees@kernel.org>
To: Magnus Lindholm <linmag7@gmail.com>,
	richard.henderson@linaro.org, mattst88@gmail.com,
	linux-kernel@vger.kernel.org, linux-alpha@vger.kernel.org
Cc: Shuah Khan <shuah@kernel.org>,
	wad@chromium.org, linux-kselftest@vger.kernel.org
Subject: Re: [PATCH v3] selftests/seccomp: add Alpha support to seccomp_bpf
Date: Sat, 10 Oct 2026 10:04:21 -0700	[thread overview]
Message-ID: <3866F071-9B50-4712-B640-EB757068C1B5@kernel.org> (raw)
In-Reply-To: <CA+=Fv5R0fiZuzDLPOZcZt6p1CtSnATELgvns_nKA1qwemKHvWA@mail.gmail.com>



On October 10, 2026 9:24:16 AM PDT, Magnus Lindholm <linmag7@gmail.com> wrote:
>Hi all,
>
>On Sat, Oct 10, 2026 at 3:42 PM Magnus Lindholm <linmag7@gmail.com> wrote:
>>
>> Enable the seccomp BPF selftests on Alpha with a fallback seccomp syscall
>> number and architecture-specific syscall register accessors.
>>
>> Use the NT_PRSTATUS register layout rather than struct pt_regs. The
>> register set contains r0-r30 followed by pc and unique. Read and update
>> the syscall number in r1, and set both r0 and the r19/a3 error flag when
>> synthesizing syscall results.
>>
>> At syscall entry, r19 still contains the fourth syscall argument, so
>> callers setting a synthetic return value must also set the syscall
>> number to -1 to skip execution.
>>
>> Signed-off-by: Magnus Lindholm <linmag7@gmail.com>
>> Reviewed-by: Matt Turner <mattst88@gmail.com>
>> ---
>> Changes in v3:
>> - Drop the /proc/self/syscall availability check and its commit-message
>>   paragraph. Alpha selects HAVE_ARCH_TRACEHOOK.
>> - Document that setting r19/a3 at syscall entry requires callers to also
>>   set the syscall number to -1.
>> - Add Matt Turner's Reviewed-by after addressing his review comments.
>>
>> Changes in v2:
>> - Use the NT_PRSTATUS layout for PTRACE_GETREGSET/PTRACE_SETREGSET.
>> - Set the Alpha return value and error flag together.
>> - Check for /proc/self/syscall at runtime (removed in v3).
>>
>> Validation on AlphaServer ES40, GCC 15.2.1, running
>> 7.3.0-rc1-es40-tsunami-v5a+:
>> - Standard v3 and the original baseline binary both report 98 pass,
>>   1 fail, 12 skip. The common failure is the 30-second timeout in
>>   user_notification_wait_killable_after_reply.
>> - A separate diagnostic build extending only that test's timeout to
>>   180 seconds completes it in 34.938 seconds. The full diagnostic run
>>   reports 99 pass, 0 fail, 12 skip. No timeout change is in this patch.
>>
>>  tools/testing/selftests/seccomp/seccomp_bpf.c | 26 +++++++++++++++++++
>>  1 file changed, 26 insertions(+)
>>
>> diff --git a/tools/testing/selftests/seccomp/seccomp_bpf.c b/tools/testing/selftests/seccomp/seccomp_bpf.c
>> index 0622bc2..79e8eb3 100644
>> --- a/tools/testing/selftests/seccomp/seccomp_bpf.c
>> +++ b/tools/testing/selftests/seccomp/seccomp_bpf.c
>> @@ -136,6 +136,8 @@ struct seccomp_data {
>>  #  define __NR_seccomp 354
>>  # elif defined(__x86_64__)
>>  #  define __NR_seccomp 317
>> +# elif defined(__alpha__)
>> +#  define __NR_seccomp 514
>>  # elif defined(__arm__)
>>  #  define __NR_seccomp 383
>>  # elif defined(__aarch64__)
>> @@ -1754,6 +1756,30 @@ TEST_F(TRACE_poke, getpid_runs_normally)
>>  # define ARCH_REGS             struct user_regs_struct
>>  # define SYSCALL_NUM(_regs)    (_regs).orig_eax
>>  # define SYSCALL_RET(_regs)    (_regs).eax
>> +#elif defined(__alpha__)
>> +/* NT_PRSTATUS contains r0-r30, pc and unique, not struct pt_regs. */
>> +struct alpha_regs {
>> +       unsigned long regs[33];
>> +};
>> +
>> +# define ARCH_REGS             struct alpha_regs
>> +/* The kernel keeps the mutable syscall number in r1. */
>> +# define SYSCALL_NUM(_regs)    ((_regs).regs[1])
>> +# define SYSCALL_RET(_regs)    ((_regs).regs[0])
>> +/*
>> + * Alpha returns positive errno in r0 with the r19/a3 error flag set.
>> + * At a syscall-entry stop, r19 is still the fourth syscall argument.
>> + * Callers must also set the syscall number to -1 to skip the syscall
>> + * before replacing r19 with the error flag.
>> + */
>> +# define SYSCALL_RET_SET(_regs, _val)                          \
>> +       do {                                                    \
>> +               struct alpha_regs *__regs = &(_regs);           \
>> +               long __ret = (_val);                            \
>> +                                                               \
>> +               __regs->regs[0] = __ret < 0 ? -__ret : __ret;   \
>> +               __regs->regs[19] = __ret < 0;                   \
>> +       } while (0)
>>  #elif defined(__arm__)
>>  # define ARCH_REGS             struct pt_regs
>>  # define SYSCALL_NUM(_regs)    (_regs).ARM_r7
>> --
>> 2.43.0
>>
>
>Kees,
>Would you be OK with me taking this patch through my Alpha tree?
>The Alpha kernel support is already upstream.
>
>v3 carries Matt's Reviewed-by. On my ES40, it matches the baseline:
>98 passes, 12 skips and one timeout. Extending that timeout gives
>99 passes and 12 skips; that adjustment is not part of the patch.
>
>Link:
>https://lore.kernel.org/linux-alpha/20261010134214.974565-1-linmag7@gmail.com/
>
>Thanks,
>Magnus

Yup, totally fine. Thank you! 

-Kees

-- 
Kees Cook

      reply	other threads:[~2026-10-10 17:04 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-10 13:42 Magnus Lindholm
2026-10-10 16:24 ` Magnus Lindholm
2026-10-10 17:04   ` Kees Cook [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=3866F071-9B50-4712-B640-EB757068C1B5@kernel.org \
    --to=kees@kernel.org \
    --cc=linmag7@gmail.com \
    --cc=linux-alpha@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-kselftest@vger.kernel.org \
    --cc=mattst88@gmail.com \
    --cc=richard.henderson@linaro.org \
    --cc=shuah@kernel.org \
    --cc=wad@chromium.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®