From: Shrikanth Hegde <sshegde@linux.ibm.com>
To: Mukesh Kumar Chaurasiya <mkchauras@gmail.com>
Cc: tglx@kernel.org, maddy@linux.ibm.com,
linuxppc-dev@lists.ozlabs.org, linux-kernel@vger.kernel.org,
chleroy@kernel.org, sbhat@linux.ibm.com
Subject: Re: [PATCH] powerpc/entry: Clear TIF_SYSCALL_RET before syscall error return
Date: Mon, 31 Aug 2026 14:34:10 +0530 [thread overview]
Message-ID: <46786528-4e56-4df3-b142-bcf047bacbb0@linux.ibm.com> (raw)
In-Reply-To: <apUBdKP1ytHSvuQd@li-1a3e774c-28e4-11b2-a85c-acc9f2883e29.ibm.com>
On 8/31/26 10:09 AM, Mukesh Kumar Chaurasiya wrote:
> On Fri, Aug 28, 2026 at 11:08:11AM +0530, Shrikanth Hegde wrote:
>> Shivaprasad reported a boot failure due to userspace processes crash on
>> abort() from libc.so.6. It was bisected to merge request
>> commit '3424d8c18a7d ("Merge tag 'core-entry-2026-08-17' of
>> git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip")'
>>
>> Upon checking the merge, when syscall_enter_from_user_mode_randomize_stack
>> fails, which could happen when a tracer like seccomp or ptrace intercepts
>> and skips the syscall, the code returns to userspace immediately without
>> clearing the intermediate flag which was set.
>>
>> When the next syscall is made, it immediately aborts the valid syscall
>> since the flag is still set. Hence clear the flag on occurrence of first
>> failure.
>>
>> Reported-by: Shivaprasad G Bhat <sbhat@linux.ibm.com>
>> Closes: https://lore.kernel.org/all/e301014d-568f-4ed5-bc64-b8a85ca0b1e1@linux.ibm.com/
>> Fixes: 3424d8c18a7d ("Merge tag 'core-entry-2026-08-17' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip")
>> Signed-off-by: Shrikanth Hegde <sshegde@linux.ibm.com>
>> ---
>> PS: I have kept the block below since earlier code was checking it
>> regardless of result of syscall_enter_from_user_mode. If it turns out
>> to be a redundant, it can be removed later.
>>
> I think it is redundant as of now. The TIF_SYSCALL_RET flag is set when
> error is set by the ptrace or seccomp, If the error value is set then
> the syscall_enter_from_user_mode_randomize_stack will return false.
> Hence the next check will become redundant.
>
> I also see that TIF_SYSCALL_RET is also set when processing the ptrace
> syscall, Which can leave the flag set for next syscall execution. Which
> can again trigger the same issue.
>
I believe it is a pre-existing bug which can be fixed independent of this issue.
Since merge request broke the userspace it is better we fix it right away and
this pre-existing issue fix can be done subsequently.
No?
> Regards,
> Mukesh
>> arch/powerpc/kernel/syscall.c | 4 +++-
>> 1 file changed, 3 insertions(+), 1 deletion(-)
>>
>> diff --git a/arch/powerpc/kernel/syscall.c b/arch/powerpc/kernel/syscall.c
>> index 4916c205c4bb..fbefe1927b10 100644
>> --- a/arch/powerpc/kernel/syscall.c
>> +++ b/arch/powerpc/kernel/syscall.c
>> @@ -18,8 +18,10 @@ notrace long system_call_exception(struct pt_regs *regs, unsigned long r0)
>> long ret;
>> syscall_fn f;
>>
>> - if (unlikely(!syscall_enter_from_user_mode_randomize_stack(regs, &r0)))
>> + if (unlikely(!syscall_enter_from_user_mode_randomize_stack(regs, &r0))) {
>> + clear_thread_flag(TIF_SYSCALL_RET);
>> return syscall_get_error(current, regs);
>> + }
>>
>> if (unlikely(test_and_clear_thread_flag(TIF_SYSCALL_RET)))
>> return syscall_get_error(current, regs);
>> --
>> 2.47.3
>>
next prev parent reply other threads:[~2026-08-31 9:04 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-28 5:38 Shrikanth Hegde
2026-08-29 6:01 ` Shivaprasad G Bhat
2026-08-31 4:39 ` Mukesh Kumar Chaurasiya
2026-08-31 9:04 ` Shrikanth Hegde [this message]
2026-09-01 7:13 ` Mukesh Kumar Chaurasiya
2026-09-01 9:17 ` Venkat
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=46786528-4e56-4df3-b142-bcf047bacbb0@linux.ibm.com \
--to=sshegde@linux.ibm.com \
--cc=chleroy@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linuxppc-dev@lists.ozlabs.org \
--cc=maddy@linux.ibm.com \
--cc=mkchauras@gmail.com \
--cc=sbhat@linux.ibm.com \
--cc=tglx@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®