linux-arm-kernel.lists.infradead.org archive mirror
 help / color / mirror / Atom feed
* arm syscall fast path can miss a ptrace syscall-exit
@ 2015-05-14 19:13 Josh Stone
  2015-05-14 19:35 ` Russell King - ARM Linux
  0 siblings, 1 reply; 22+ messages in thread
From: Josh Stone @ 2015-05-14 19:13 UTC (permalink / raw)
  To: linux-arm-kernel

Hi,

I've discovered a case where both arm and arm64 will miss a ptrace
syscall-exit that they should report.  If the syscall is entered without
TIF_SYSCALL_TRACE set, then it goes on the fast path.  It's then
possible to have TIF_SYSCALL_TRACE added in the middle of the syscall,
but ret_fast_syscall doesn't check this flag again.

For instance, with PTRACE_O_TRACEFORK set, we could enter a fork() and
report PTRACE_EVENT_FORK to the tracer from do_fork(), in the middle of
the syscall.  That tracer may resume with PTRACE_SYSCALL, which sets
TIF_SYSCALL_TRACE; then do_fork() returns, and we *should* then get a
ptrace syscall-exit-stop.  But with arm and arm64, the syscall fast path
doesn't notice the added flag and just returns.

The attached program demonstrates the bug.  Note that it's important not
to have any other slow-path flags either, like TIF_SYSCALL_AUDIT.  On
x86_64, this program outputs:

  event-syscall-exit: stopped 18
  event-syscall-exit: ptrace event 1
  event-syscall-exit: syscall
  event-syscall-exit: stopped 11
  event-syscall-exit: signaled 11

But I confirmed that if you get arm64 on the fast path, that syscall
event will be missing.

Does my diagnosis sound reasonable?  I'm no arm expert, so I hesitate to
attempt patching entry.S myself, but I'd be happy to test patches.

Thanks,
Josh Stone
-------------- next part --------------
A non-text attachment was scrubbed...
Name: event-syscall-exit.c
Type: text/x-csrc
Size: 2048 bytes
Desc: not available
URL: <http://lists.infradead.org/pipermail/linux-arm-kernel/attachments/20150514/7c1f6fb2/attachment.bin>

^ permalink raw reply	[flat|nested] 22+ messages in thread

end of thread, other threads:[~2015-06-23  0:15 UTC | newest]

Thread overview: 22+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2015-05-14 19:13 arm syscall fast path can miss a ptrace syscall-exit Josh Stone
2015-05-14 19:35 ` Russell King - ARM Linux
2015-05-14 21:08   ` Josh Stone
2015-05-26 22:38     ` Josh Stone
2015-05-28 10:37       ` Russell King - ARM Linux
2015-05-29 20:13         ` Josh Stone
2015-06-01 10:24           ` Will Deacon
2015-06-03  1:01             ` [PATCH] arm64: fix missing syscall trace exit Josh Stone
2015-06-03  1:11               ` Josh Stone
2015-06-03  9:52                 ` Will Deacon
2015-06-03 20:03                   ` Josh Stone
2015-06-04 10:06                 ` Russell King - ARM Linux
2015-06-04 17:14                   ` Josh Stone
2015-06-04 23:17                     ` Josh Stone
2015-06-05 15:38                       ` Will Deacon
2015-06-05 17:52                         ` Tom Lendacky
2015-06-05 21:28                         ` Josh Stone
2015-06-08 10:21                           ` Will Deacon
2015-06-08 16:37                             ` Josh Stone
2015-06-08 16:43                               ` Catalin Marinas
2015-06-23  0:08                   ` [PATCH] ARM: enable_irq before ret_fast_syscall tracing Josh Stone
2015-06-23  0:15                     ` Josh Stone

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).