PTRACE_SYSEMU_SINGLESTEP sets both _TIF_SYSCALL_EMU and _TIF_SINGLESTEP.
With _TIF_SINGLESTEP set, the arm64 syscall-exit path synthesises a
pseudo-single-step exception:
ptrace_report_syscall_exit(regs, 1)
-> user_single_step_report()
-> info.si_signo = SIGTRAP
-> info.si_code = SI_USER
-> force_sig_info(&info)
But for PTRACE_SYSEMU_SINGLESTEP it is redundant: the stop before
the instruction following the SVC is already delivered by the hardware
single-step state machine, so the tracer ends up with two stops
at the same PC as below:
sig=133 si_code=133 SS=0 pc=0x400638 [syscall-enter-stop]
sig=5 si_code=0 SS=0 pc=0x400638 [pseudo-step, dropped here]
sig=5 si_code=2 SS=1 pc=0x400638 [hardware single-step]
The pseudo-step was added by commit ac2081cdc4d9 ("arm64: ptrace:
Consistently use pseudo-singlestep exceptions") because a ptrace stop
taken while a system call is in progress may corrupt the stepping state.
For an emulated system call that cannot happen, as the call never runs:
- No syscall-exit-stop, because _TIF_SINGLESTEP is set
- No seccomp trap, because syscall_trace_enter() returns NO_SYSCALL
when SYSCALL_EMU is set, before the seccomp check
- The syscall body is not executed, so nothing can take a stop while it
is in progress.
Introduce report_single_step(), which returns false when _TIF_SYSCALL_EMU
is set, so the pseudo-step is skipped for the emulated case. This also
matches the generic entry behaviour.
PTRACE_SINGLESTEP and PTRACE_SYSCALL are unaffected:
- PTRACE_SYSCALL: SYSCALL_TRACE is set and _TIF_SINGLESTEP is not, so
the syscall-exit-stop is reported as before and no pseudo-step is
involved;
- PTRACE_SINGLESTEP: _TIF_SINGLESTEP is set but _TIF_SYSCALL_EMU is
not, so the pseudo-step is still synthesised. It is still needed
here, because the system call does execute and the hazard described
above applies.
Cc: Mark Rutland <[email protected]>
Cc: Will Deacon <[email protected]>
Cc: Catalin Marinas <[email protected]>
Cc: Oleg Nesterov <[email protected]>
Signed-off-by: Jinjie Ruan <[email protected]>
---
arch/arm64/kernel/ptrace.c | 12 +++++++++++-
1 file changed, 11 insertions(+), 1 deletion(-)
diff --git a/arch/arm64/kernel/ptrace.c b/arch/arm64/kernel/ptrace.c
index f743cbec1c3a..96462de75d4b 100644
--- a/arch/arm64/kernel/ptrace.c
+++ b/arch/arm64/kernel/ptrace.c
@@ -2482,16 +2482,26 @@ int syscall_trace_enter(struct pt_regs *regs)
return regs->syscallno;
}
+static inline bool report_single_step(unsigned long flags)
+{
+ if (flags & _TIF_SYSCALL_EMU)
+ return false;
+
+ return flags & _TIF_SINGLESTEP;
+}
+
void syscall_trace_exit(struct pt_regs *regs)
{
unsigned long flags = read_thread_flags();
+ bool step;
audit_syscall_exit(regs);
if (flags & _TIF_SYSCALL_TRACEPOINT)
trace_sys_exit(regs, syscall_get_return_value(current, regs));
- if (flags & (_TIF_SYSCALL_TRACE | _TIF_SINGLESTEP))
+ step = report_single_step(flags);
+ if (step || flags & _TIF_SYSCALL_TRACE)
report_syscall_exit(regs);
rseq_syscall(regs);
--
2.34.1