From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp-out2.suse.de (smtp-out2.suse.de [195.135.223.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 554FB47A0A9 for ; Tue, 21 Jul 2026 10:10:48 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=195.135.223.131 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784628654; cv=none; b=DwRJ6eIxxsxB59HNGT/m6FBg/RVOKtAjzzGqn3QhsV0Ah2kR/rv2/PS5a9Pt2caPOlvsDOl4bFN7iTcG+kfljd6LslrHsyBAUDuawpulQ6/IJI9K9eoLNwBS8G+wFkBnSnjgOEuREsQPrhCUZ6mkvWvGPu5Nzq93TOfaQMwx46g= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784628654; c=relaxed/simple; bh=yyTz1/4pjGZqJ2R18hk7Ofr9iZjY+QpyQNTZGtXgOyU=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=C7yOATF6NohGOx9INOjQi7hAbC8GsoSedbIMRSFy7DeUXAefCRnZtQIicjqLm6dzReAkr6IYcKs158+9E4HrBfMna+/Ixr+rRpOvewP98+jF0kw8h9rCOqc3Xn710E3fzsSYbQF6iuyDsMexx3aRwEmdgtHiV9poyefMC0WdzP8= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=suse.de; spf=pass smtp.mailfrom=suse.de; dkim=pass (1024-bit key) header.d=suse.de header.i=@suse.de header.b=iKLoOBzu; dkim=permerror (0-bit key) header.d=suse.de header.i=@suse.de header.b=IP/19JTu; dkim=pass (1024-bit key) header.d=suse.de header.i=@suse.de header.b=OztlXaeg; dkim=permerror (0-bit key) header.d=suse.de header.i=@suse.de header.b=+X5o+lIz; arc=none smtp.client-ip=195.135.223.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=suse.de Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=suse.de Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=suse.de header.i=@suse.de header.b="iKLoOBzu"; dkim=permerror (0-bit key) header.d=suse.de header.i=@suse.de header.b="IP/19JTu"; dkim=pass (1024-bit key) header.d=suse.de header.i=@suse.de header.b="OztlXaeg"; dkim=permerror (0-bit key) header.d=suse.de header.i=@suse.de header.b="+X5o+lIz" Received: from kunlun.suse.cz (unknown [IPv6:2a07:de40:b306:2000::2]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (prime256v1) server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by smtp-out2.suse.de (Postfix) with ESMTPS id DF83F3DF9; Tue, 21 Jul 2026 10:10:43 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_rsa; t=1784628645; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=UGzFNw0WQMoZN+5CtpXDTXg4AYd3vMMyskX0oK0yzNE=; b=iKLoOBzuN0Wp1t1OYSVyfNrZneTofgDmYtk+QEx09sm08u2NcVe5qyDlXNcU1BL7a/gZJg 2Bk22EJJrqsnNSREqBcBLLUyUvilR8H9rV4tNsg3jRkZ5wK4YBW9CXcSVBQcSVyNM85+6M QpdV7LxxhmJoMf6wT/Ur8kV6elT2nXE= DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_ed25519; t=1784628645; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=UGzFNw0WQMoZN+5CtpXDTXg4AYd3vMMyskX0oK0yzNE=; b=IP/19JTu5BaoFeTSkn6JD4Hk7hM/2z3/HMdAABqGtB4vblFVnhAFEEjWWuPvqhXVREfKrU NGlGDsbUMylLLECg== Authentication-Results: smtp-out2.suse.de; dkim=pass header.d=suse.de header.s=susede2_rsa header.b=OztlXaeg; dkim=pass header.d=suse.de header.s=susede2_ed25519 header.b=+X5o+lIz DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_rsa; t=1784628643; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=UGzFNw0WQMoZN+5CtpXDTXg4AYd3vMMyskX0oK0yzNE=; b=OztlXaegskJp2nhi54W1cAIpdmhxst4WDMfwmOv1Lcei+SkE1HyCxg133GZm+leEwSEgNL L0ph/vUxDUPGugQ+HcplB5l0OAiNIr43HY456pY/yO3yYDerFp44COXYpO4int2K+HEr/N mcotXQ4VGU7SoblRYTHGBzG4uGumZK4= DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_ed25519; t=1784628643; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=UGzFNw0WQMoZN+5CtpXDTXg4AYd3vMMyskX0oK0yzNE=; b=+X5o+lIzGjjrR8hnk6ce7+LtbHnK6Tg83pmO8qVGHkkUcuNc0NJQiA4T+MG9k7Fr6bTwJl twEX8JTX5lS1gjCQ== Date: Tue, 21 Jul 2026 12:10:42 +0200 From: Michal =?iso-8859-1?Q?Such=E1nek?= To: Renzo Davoli Cc: linux-kernel@vger.kernel.org, Andrew Morton , Oleg Nesterov , Shuah Khan , Alexey Gladkov , Eugene Syromyatnikov , Davide Berardi , strace-devel@lists.strace.io, "Dmitry V . Levin" Subject: Re: [PATCH v5 0/2] PTRACE_SET_SYSCALL_INFO: add support for seccomp syscall skipping Message-ID: References: <20260709100949.94345-1-renzo@cs.unibo.it> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=iso-8859-1 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: X-Spam-Flag: YES X-Rspamd-Action: add header X-Spam-Level: *************** X-Rspamd-Server: rspamd2.dmz-prg2.suse.org X-Spamd-Result: default: False [15.62 / 50.00]; SPAM_FLAG(5.00)[]; NEURAL_SPAM_LONG(3.50)[1.000]; BAYES_HAM(-3.00)[100.00%]; HFILTER_HOSTNAME_UNKNOWN(2.50)[]; RDNS_NONE(2.00)[]; NEURAL_SPAM_SHORT(1.93)[0.643]; SUSPICIOUS_RECIPS(1.50)[]; ONCE_RECEIVED(1.20)[]; HFILTER_HELO_IP_A(1.00)[kunlun.suse.cz]; HFILTER_HELO_NORES_A_OR_MX(0.30)[kunlun.suse.cz]; R_DKIM_ALLOW(-0.20)[suse.de:s=susede2_rsa,suse.de:s=susede2_ed25519]; MIME_GOOD(-0.10)[text/plain]; MX_GOOD(-0.01)[]; MIME_TRACE(0.00)[0:+]; FUZZY_RATELIMITED(0.00)[rspamd.com]; ARC_NA(0.00)[]; RBL_SPAMHAUS_BLOCKED_OPENRESOLVER(0.00)[2a07:de40:b306:2000::2:from]; DKIM_SIGNED(0.00)[suse.de:s=susede2_rsa,suse.de:s=susede2_ed25519]; TO_MATCH_ENVRCPT_ALL(0.00)[]; FREEMAIL_ENVRCPT(0.00)[gmail.com]; FREEMAIL_CC(0.00)[vger.kernel.org,linux-foundation.org,redhat.com,kernel.org,gmail.com,lists.strace.io,strace.io]; DNSWL_BLOCKED(0.00)[2a07:de40:b306:2000::2:from]; FROM_EQ_ENVFROM(0.00)[]; FROM_HAS_DN(0.00)[]; TO_DN_SOME(0.00)[]; RCPT_COUNT_SEVEN(0.00)[10]; TAGGED_RCPT(0.00)[]; RCVD_COUNT_ZERO(0.00)[0]; DKIM_TRACE(0.00)[suse.de:+]; MISSING_XM_UA(0.00)[]; DBL_BLOCKED_OPENRESOLVER(0.00)[suse.de:dkim,kunlun.suse.cz:helo,kunlun.suse.cz:mid] X-Spamd-Bar: +++++++++++++++ X-Rspamd-Queue-Id: DF83F3DF9 X-Spam-Score: 15.62 X-Spam: Yes On Fri, Jul 10, 2026 at 06:49:11PM +0200, Renzo Davoli wrote: > Hi Michal, > I am not an expert of the powerpc architecture. > > On Fri, Jul 10, 2026 at 05:38:32PM +0200, Michal Suchánek wrote: > > On these architectures the syscall number and the syscall return value > > share the same register. > > Reading the file arch/powerpc/include/asm/syscall.h > the functions > syscall_get_nr() > syscall_set_nr() > read and write regs->gpr[0] > > while > syscall_get_return_value() > syscall_set_return_value() > read and write regs->gpr[3] (and one bit in regs->ccr as an error flag). > > Am I missing another part of the entry/exit path where the two overlap? Ok, so it has the other varian of the problem. The syscall return value overlaps a parameter. In any case it has this problem: On and other architectures the syscall number, the syscall arguments, and the syscall return value are disjunct. These architectures use this platform-specific to preset teh syscall return value at the very start of syscall processing, before entry ptrace and seccomp. On architectures where there is an overlap between the syscall number or arguments and the return value the return value cannot be preset before entry ptrace and seccomp because these need the syscall number abd arguments. On these platforms the tracer may change the registers in one way or another but there is no guarantee that when the syscall number is invalid, or -1 as is the value traditionally used to skip a syscall that there is a meaningful return value set. The -ENOSYS when handling an invalid syscal is set only after the entry ptrace and seccomp, overwriting any value that ptrace may have set. The SECCOMP_SET_MODE_FILTER SECCOMP_RET_ERRNO can accomplish setting areturn value and skipping the syscall because it changes the return value of __secure_computing() indicating that the return value has been set, and the syscall number or parameters in the registers must not be used anymore, and the syscall skipped. As ptrace does not have any way to return something it does not have this option. There are some workarounds possible. One is setting another flag in pt_regs to indicate the same as SECCOMP_RET_ERRNO: https://lore.kernel.org/all/20260714075935.1830145-1-mkchauras@gmail.com/ another is storing the return value otside of the registers allowing it to be set in advance: https://lore.kernel.org/all/20260715133830.2619853-1-svens@linux.ibm.com/ but as of now the architectures that have this overlap are not required to apply one of these workarounds, and not all do AFAIK. Note there is a piece of bogus code in seccomp that incorrectly skips syscalls when returning from ptrace: /* Allow the BPF to provide the event message */ ptrace_event(PTRACE_EVENT_SECCOMP, data); /* * The delivery of a fatal signal during event * notification may silently skip tracer notification, * which could leave us with a potentially unmodified * syscall that the tracer would have liked to have * changed. Since the process is about to die, we just * force the syscall to be skipped and let the signal * kill the process and correctly handle any tracer exit * notifications. */ if (fatal_signal_pending(current)) goto skip; /* Check if the tracer forced the syscall to be skipped. */ this_syscall = syscall_get_nr(current, current_pt_regs()); if (this_syscall < 0) goto skip; This does not work correctly when the return value of the syscal is not preset before calling __secure_computing() Thanks Michal