PTRACE_SYSEMU_SINGLESTEP sets both _TIF_SYSCALL_EMU and _TIF_SINGLESTEP.

With _TIF_SINGLESTEP set, the arm64 syscall-exit path synthesises a
pseudo-single-step exception:

        ptrace_report_syscall_exit(regs, 1)
          -> user_single_step_report()
             -> info.si_signo = SIGTRAP
             -> info.si_code = SI_USER
             -> force_sig_info(&info)

But for PTRACE_SYSEMU_SINGLESTEP it is redundant: the stop before
the instruction following the SVC is already delivered by the hardware
single-step state machine, so the tracer ends up with two stops
at the same PC as below:

        sig=133 si_code=133  SS=0  pc=0x400638   [syscall-enter-stop]
        sig=5   si_code=0    SS=0  pc=0x400638   [pseudo-step, dropped here]
        sig=5   si_code=2    SS=1  pc=0x400638   [hardware single-step]

The pseudo-step was added by commit ac2081cdc4d9 ("arm64: ptrace:
Consistently use pseudo-singlestep exceptions") because a ptrace stop
taken while a system call is in progress may corrupt the stepping state.
For an emulated system call that cannot happen, as the call never runs:

- No syscall-exit-stop, because _TIF_SINGLESTEP is set

- No seccomp trap, because syscall_trace_enter() returns NO_SYSCALL
  when SYSCALL_EMU is set, before the seccomp check

- The syscall body is not executed, so nothing can take a stop while it
  is in progress.

Introduce report_single_step(), which returns false when _TIF_SYSCALL_EMU
is set, so the pseudo-step is skipped for the emulated case. This also
matches the generic entry behaviour.

PTRACE_SINGLESTEP and PTRACE_SYSCALL are unaffected:
- PTRACE_SYSCALL: SYSCALL_TRACE is set and _TIF_SINGLESTEP is not, so
  the syscall-exit-stop is reported as before and no pseudo-step is
  involved;

- PTRACE_SINGLESTEP: _TIF_SINGLESTEP is set but _TIF_SYSCALL_EMU is
  not, so the pseudo-step is still synthesised.  It is still needed
  here, because the system call does execute and the hazard described
  above applies.

Cc: Mark Rutland <[email protected]>
Cc: Will Deacon <[email protected]>
Cc: Catalin Marinas <[email protected]>
Cc: Oleg Nesterov <[email protected]>
Signed-off-by: Jinjie Ruan <[email protected]>
---
 arch/arm64/kernel/ptrace.c | 12 +++++++++++-
 1 file changed, 11 insertions(+), 1 deletion(-)

diff --git a/arch/arm64/kernel/ptrace.c b/arch/arm64/kernel/ptrace.c
index f743cbec1c3a..96462de75d4b 100644
--- a/arch/arm64/kernel/ptrace.c
+++ b/arch/arm64/kernel/ptrace.c
@@ -2482,16 +2482,26 @@ int syscall_trace_enter(struct pt_regs *regs)
        return regs->syscallno;
 }
 
+static inline bool report_single_step(unsigned long flags)
+{
+       if (flags & _TIF_SYSCALL_EMU)
+               return false;
+
+       return flags & _TIF_SINGLESTEP;
+}
+
 void syscall_trace_exit(struct pt_regs *regs)
 {
        unsigned long flags = read_thread_flags();
+       bool step;
 
        audit_syscall_exit(regs);
 
        if (flags & _TIF_SYSCALL_TRACEPOINT)
                trace_sys_exit(regs, syscall_get_return_value(current, regs));
 
-       if (flags & (_TIF_SYSCALL_TRACE | _TIF_SINGLESTEP))
+       step = report_single_step(flags);
+       if (step || flags & _TIF_SYSCALL_TRACE)
                report_syscall_exit(regs);
 
        rseq_syscall(regs);
-- 
2.34.1


Reply via email to