From: sashiko-bot@kernel.org
To: "Ricardo Robaina" <rrobaina@redhat.com>
Cc: audit@vger.kernel.org, bpf@vger.kernel.org
Subject: Re: [PATCH 10/13] sh: pass all six syscall args to audit_syscall_entry()
Date: Thu, 13 Aug 2026 17:24:47 +0000 [thread overview]
Message-ID: <20260813172447.AA5EE1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <be964ca4e6854db2a66cbba4af1ff2fdd769e752.1786626275.git.rrobaina@redhat.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] This problem wasn't introduced by this patch, but the `sys_enter` tracepoint is incorrectly invoked with the 5th syscall argument (`regs->regs[0]`) instead of the system call number, allowing userspace to spoof syscall trace events.
--
--- Patch [10]: [PATCH 10/13] sh: pass all six syscall args to audit_syscall_entry() ---
commit 3f32d157a274ce4c78e2758720926d9048ca177a
Author: Ricardo Robaina <rrobaina@redhat.com>
sh: pass all six syscall args to audit_syscall_entry()
This commit updates the audit_syscall_entry() call to forward the 5th
and 6th syscall arguments. This aligns with the audit core which now
logs all six arguments.
> diff --git a/arch/sh/kernel/ptrace_32.c b/arch/sh/kernel/ptrace_32.c
> index 06f765d71a295..3efefd67b457c 100644
> --- a/arch/sh/kernel/ptrace_32.c
> +++ b/arch/sh/kernel/ptrace_32.c
> @@ -467,7 +467,8 @@ asmlinkage long do_syscall_trace_enter(struct pt_regs *regs)
> trace_sys_enter(regs, regs->regs[0]);
[Severity: High]
This is a pre-existing issue in do_syscall_trace_enter(), but is
trace_sys_enter() receiving the correct system call number here?
Since regs->regs[0] holds the 5th syscall argument on SuperH, passing it
here means security monitoring tools attached to the sys_enter tracepoint
might receive an incorrect, user-controlled syscall number. Could a local
unprivileged attacker exploit this by placing a sensitive syscall number
in the actual syscall register and a benign one in r0 to bypass security
auditing?
>
> audit_syscall_entry(regs->regs[3], regs->regs[4], regs->regs[5],
> - regs->regs[6], regs->regs[7]);
> + regs->regs[6], regs->regs[7],
> + regs->regs[0], regs->regs[1]);
>
> return 0;
> }
--
Sashiko AI review · https://sashiko.dev/#/patchset/cover.1786626275.git.rrobaina@redhat.com?part=10
next prev parent reply other threads:[~2026-08-13 17:24 UTC|newest]
Thread overview: 27+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-13 17:02 [PATCH 00/13] audit: log all six syscall arguments in the SYSCALL record Ricardo Robaina
2026-08-13 17:02 ` [PATCH 01/13] " Ricardo Robaina
2026-08-13 17:20 ` sashiko-bot
2026-08-13 17:02 ` [PATCH 02/13] alpha: pass all six syscall args to audit_syscall_entry() Ricardo Robaina
2026-08-13 17:18 ` sashiko-bot
2026-08-13 17:02 ` [PATCH 03/13] arm: " Ricardo Robaina
2026-08-13 17:20 ` sashiko-bot
2026-08-13 17:02 ` [PATCH 04/13] arm64: " Ricardo Robaina
2026-08-13 17:17 ` sashiko-bot
2026-08-13 17:02 ` [PATCH 05/13] csky: " Ricardo Robaina
2026-08-13 17:16 ` sashiko-bot
2026-08-13 17:02 ` [PATCH 06/13] microblaze: " Ricardo Robaina
2026-08-13 17:15 ` sashiko-bot
2026-08-13 17:02 ` [PATCH 07/13] mips: " Ricardo Robaina
2026-08-13 17:15 ` sashiko-bot
2026-08-13 17:02 ` [PATCH 08/13] openrisc: " Ricardo Robaina
2026-08-13 17:20 ` sashiko-bot
2026-08-13 17:02 ` [PATCH 09/13] parisc: " Ricardo Robaina
2026-08-13 17:13 ` sashiko-bot
2026-08-13 17:03 ` [PATCH 10/13] sh: " Ricardo Robaina
2026-08-13 17:24 ` sashiko-bot [this message]
2026-08-13 17:03 ` [PATCH 11/13] sparc64: " Ricardo Robaina
2026-08-13 17:26 ` sashiko-bot
2026-08-13 17:03 ` [PATCH 12/13] um: " Ricardo Robaina
2026-08-13 17:19 ` sashiko-bot
2026-08-13 17:03 ` [PATCH 13/13] xtensa: " Ricardo Robaina
2026-08-13 17:23 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260813172447.AA5EE1F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=audit@vger.kernel.org \
--cc=bpf@vger.kernel.org \
--cc=rrobaina@redhat.com \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox