Linux s390 Architecture development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Michal Suchanek" <msuchanek@suse.de>
Cc: "Heiko Carstens" <hca@linux.ibm.com>,
	linux-s390@vger.kernel.org, "Vasily Gorbik" <gor@linux.ibm.com>,
	"Alexander Gordeev" <agordeev@linux.ibm.com>
Subject: Re: [PATCH] seccomp: Fix syscall skip logic on ptrace
Date: Tue, 21 Jul 2026 11:05:51 +0000	[thread overview]
Message-ID: <20260721110551.812411F000E9@smtp.kernel.org> (raw)
In-Reply-To: <al9NlZi20xHMvla2@kunlun.suse.cz>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Critical] Removing the explicit check for tracer-injected negative syscall numbers breaks ptrace syscall emulation by erroneously re-evaluating the seccomp BPF filter against a `-1` syscall number.
--

--- Patch [1]: [PATCH] seccomp: Fix syscall skip logic on ptrace ---
commit e1c90f3fd79c2a1c1deae6adb363b4de34006c48
Author: Michal Suchanek <msuchanek@suse.de>

seccomp: Fix syscall skip logic on ptrace

This commit removes the explicit check for negative syscall numbers after a
ptrace stop in the seccomp filter. This allows architectures where the return
value overlaps with the syscall number or arguments to exit without flagging
the syscall as skipped.

> diff --git a/kernel/seccomp.c b/kernel/seccomp.c
> index 25f62867a16d9..4d3ad6113b216 100644
> --- a/kernel/seccomp.c
> +++ b/kernel/seccomp.c
> @@ -1318,11 +1318,8 @@ static int __seccomp_filter(int this_syscall, const bool recheck_after_trace)
>  		 */
>  		if (fatal_signal_pending(current))
>  			goto skip;
> -		/* Check if the tracer forced the syscall to be skipped. */
> -		this_syscall = syscall_get_nr(current, current_pt_regs());
> -		if (this_syscall < 0)
> -			goto skip;
>  
> +		this_syscall = syscall_get_nr(current, current_pt_regs());

[Severity: Critical]
By removing this check, does this break ptrace syscall emulation?

The standard mechanism for syscall emulation using ptrace and seccomp (used
by gVisor, User-Mode Linux, proot, and strace) involves changing the syscall
number to -1 to skip the real kernel syscall and setting a custom return
value.

Without this check, when the tracee resumes and re-enters __seccomp_filter(),
the -1 syscall number will fall through to the BPF evaluation below. Since
most seccomp profiles use strict allowlists, won't this cause the -1 syscall
to hit the default action (like SECCOMP_RET_KILL_PROCESS or
SECCOMP_RET_ERRNO) instead of skipping it?

Could this lead to tracees being unexpectedly killed or having their preset
return values overwritten?

>  		/*
>  		 * Recheck the syscall, since it may have changed. This
>  		 * intentionally uses a NULL struct seccomp_data to force

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/al9NlZi20xHMvla2@kunlun.suse.cz?part=1

      reply	other threads:[~2026-07-21 11:05 UTC|newest]

Thread overview: 104+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-07 19:05 [patch 00/18] entry: Consolidate and rework syscall entry handling Thomas Gleixner
2026-07-07 19:05 ` [patch 01/18] powerpc: Move stack randomization after syscall_enter_from_user_mode() Thomas Gleixner
2026-07-08 14:07   ` Shrikanth Hegde
2026-07-08 17:22   ` Radu Rendec
2026-07-09  1:20   ` Jinjie Ruan
2026-07-09 11:12   ` Philippe Mathieu-Daudé
2026-07-09 18:32   ` Mukesh Kumar Chaurasiya
2026-07-07 19:06 ` [patch 02/18] randomize_kstack: Provide add_random_kstack_offset_irqsoff() Thomas Gleixner
2026-07-08 17:24   ` Radu Rendec
2026-07-09  2:13   ` Jinjie Ruan
2026-07-09 16:23   ` Kees Cook
2026-07-09 18:34   ` Mukesh Kumar Chaurasiya
2026-07-07 19:06 ` [patch 03/18] entry: Provide [syscall_]enter_from_user_mode_randomize_stack() Thomas Gleixner
2026-07-08 17:26   ` Radu Rendec
2026-07-09  2:34   ` Jinjie Ruan
2026-07-09  3:46   ` Jinjie Ruan
2026-07-09 11:15   ` Philippe Mathieu-Daudé
2026-07-09 20:16   ` Mukesh Kumar Chaurasiya
2026-07-07 19:06 ` [patch 04/18] loongarch/syscall: Use syscall_enter_from_user_mode_randomize_stack() Thomas Gleixner
2026-07-08 18:37   ` Radu Rendec
2026-07-09  2:37   ` Jinjie Ruan
2026-07-09 11:15   ` Philippe Mathieu-Daudé
2026-07-09 18:40   ` Mukesh Kumar Chaurasiya
2026-07-07 19:06 ` [patch 05/18] powerpc/syscall: " Thomas Gleixner
2026-07-08 18:35   ` Radu Rendec
2026-07-09  2:38   ` Jinjie Ruan
2026-07-09 11:16   ` Philippe Mathieu-Daudé
2026-07-09 18:41   ` Mukesh Kumar Chaurasiya
2026-07-07 19:06 ` [patch 06/18] riscv/syscall: " Thomas Gleixner
2026-07-08 20:57   ` Radu Rendec
2026-07-09  2:38   ` Jinjie Ruan
2026-07-09 11:16   ` Philippe Mathieu-Daudé
2026-07-09 18:42   ` Mukesh Kumar Chaurasiya
2026-07-13  7:06   ` Guo Ren
2026-07-07 19:06 ` [patch 07/18] s390/syscall: Use enter_from_user_mode_randomize_stack() Thomas Gleixner
2026-07-08  6:47   ` Sven Schnelle
2026-07-08 20:57   ` Radu Rendec
2026-07-09  2:39   ` Jinjie Ruan
2026-07-09  2:46   ` Jinjie Ruan
2026-07-09 11:17     ` Philippe Mathieu-Daudé
2026-07-09 18:43   ` Mukesh Kumar Chaurasiya
2026-07-07 19:06 ` [patch 08/18] x86/syscall: Use [syscall_]enter_from_user_mode_randomize_stack() Thomas Gleixner
2026-07-08 20:59   ` Radu Rendec
2026-07-09  2:44   ` Jinjie Ruan
2026-07-09 11:18   ` Philippe Mathieu-Daudé
2026-07-09 18:45   ` Mukesh Kumar Chaurasiya
2026-07-07 19:06 ` [patch 09/18] entry: Remove syscall_enter_from_user_mode() Thomas Gleixner
2026-07-08 21:21   ` Radu Rendec
2026-07-08 22:08     ` Thomas Gleixner
2026-07-09  2:49   ` Jinjie Ruan
2026-07-09 18:49   ` Mukesh Kumar Chaurasiya
2026-07-07 19:06 ` [patch 10/18] entry: Use syscall number instead of rereading it Thomas Gleixner
2026-07-08 21:39   ` Radu Rendec
2026-07-09  2:55   ` Jinjie Ruan
2026-07-09 11:20   ` Philippe Mathieu-Daudé
2026-07-09 11:22     ` Philippe Mathieu-Daudé
2026-07-09 18:50   ` Mukesh Kumar Chaurasiya
2026-07-07 19:06 ` [patch 11/18] seccomp, treewide: Rename and convert __secure_computing() to return boolean Thomas Gleixner
2026-07-08  1:43   ` Jinjie Ruan
2026-07-08  9:15     ` Thomas Gleixner
2026-07-08 16:04       ` Oleg Nesterov
2026-07-08 21:49         ` Thomas Gleixner
2026-07-09 16:22   ` Kees Cook
2026-07-09 19:10   ` Mukesh Kumar Chaurasiya
2026-07-07 19:06 ` [patch 12/18] ptrace, treewide: Rename ptrace_report_syscall_entry() to ptrace_report_syscall_permit_entry() Thomas Gleixner
2026-07-08 15:46   ` Oleg Nesterov
2026-07-09  1:41   ` Jinjie Ruan
2026-07-09  8:41   ` Geert Uytterhoeven
2026-07-09 17:03   ` Radu Rendec
2026-07-09 19:22   ` Mukesh Kumar Chaurasiya
2026-07-10 10:42   ` Michal Suchánek
2026-07-10 11:16     ` Oleg Nesterov
2026-07-07 19:06 ` [patch 13/18] entry: Make trace_syscall_enter() return type bool Thomas Gleixner
2026-07-08 15:52   ` Michal Suchánek
2026-07-08 20:34     ` Thomas Gleixner
2026-07-08 23:14       ` Thomas Gleixner
2026-07-09 16:26         ` David Laight
2026-07-10 11:01       ` Michal Suchánek
2026-07-10 11:40         ` Oleg Nesterov
2026-07-10 12:32           ` Michal Suchánek
2026-07-10 12:52             ` Oleg Nesterov
2026-07-10 15:20               ` Michal Suchánek
2026-07-11 20:33         ` Thomas Gleixner
2026-07-14  8:20           ` Michal Suchánek
2026-07-07 19:06 ` [patch 14/18] entry: Make return type of syscall_trace_enter() bool Thomas Gleixner
2026-07-09 19:36   ` Mukesh Kumar Chaurasiya
2026-07-07 19:06 ` [patch 15/18] x86/entry: Make syscall functions static Thomas Gleixner
2026-07-09  1:47   ` Jinjie Ruan
2026-07-09 19:43   ` Mukesh Kumar Chaurasiya
2026-07-07 19:07 ` [patch 16/18] x86/entry: Get rid of the sys_ni_syscall() indirection Thomas Gleixner
2026-07-09  2:03   ` Jinjie Ruan
2026-07-07 19:07 ` [patch 17/18] x86/entry: Simplify the syscall number logic Thomas Gleixner
2026-07-07 19:07 ` [patch 18/18] entry, treewide: Make syscall_enter_from_user_mode[_work]() indicate syscall execution Thomas Gleixner
2026-07-08  5:21   ` Shrikanth Hegde
2026-07-08  9:16     ` Thomas Gleixner
2026-07-09 19:49   ` Mukesh Kumar Chaurasiya
2026-07-09 20:15 ` [patch 00/18] entry: Consolidate and rework syscall entry handling Mukesh Kumar Chaurasiya
2026-07-11 12:29 ` Magnus Lindholm
2026-07-19 11:25 ` Magnus Lindholm
2026-07-20 19:21   ` Thomas Gleixner
2026-07-20 22:01     ` Magnus Lindholm
2026-07-21  8:17       ` Thomas Gleixner
2026-07-21 10:44 ` [PATCH] seccomp: Fix syscall skip logic on ptrace Michal Suchanek
2026-07-21 11:05   ` sashiko-bot [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260721110551.812411F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=agordeev@linux.ibm.com \
    --cc=gor@linux.ibm.com \
    --cc=hca@linux.ibm.com \
    --cc=linux-s390@vger.kernel.org \
    --cc=msuchanek@suse.de \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox