Re: [PATCH] arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates
From: Will Deacon
Date: Thu Jul 16 2026 - 07:53:36 EST
On Thu, Jul 16, 2026 at 10:57:34AM +0800, Jinjie Ruan wrote:
> On 7/14/2026 10:35 PM, Will Deacon wrote:
> > diff --git a/arch/arm64/kernel/ptrace.c b/arch/arm64/kernel/ptrace.c
> > index 4d08598e2891..57e8c6714d44 100644
> > --- a/arch/arm64/kernel/ptrace.c
> > +++ b/arch/arm64/kernel/ptrace.c
> > @@ -2408,6 +2408,21 @@ static void report_syscall_exit(struct pt_regs *regs)
> > }
> > }
> >
> > +static void update_syscall_orig_x0_after_ptrace(struct pt_regs *regs)
> > +{
> > + /*
> > + * Keep orig_x0 authoritative so that seccomp (via
> > + * syscall_get_arguments()), audit and the restart path all see the same
> > + * first argument the syscall is dispatched with, even if it has been
> > + * updated by a tracer. Skip this for NO_SYSCALL (set either by the user
> > + * or the tracer), as regs[0] holds the return value (see the comment in
> > + * el0_svc_common()) and can be unwound using syscall_rollback().
> > + * For compat tasks, orig_r0 is provided directly through GPR index 17.
> > + */
> > + if (!is_compat_task() && regs->syscallno != NO_SYSCALL)
> > + regs->orig_x0 = regs->regs[0];
> > +}
> > +
> > int syscall_trace_enter(struct pt_regs *regs)
> > {
> > unsigned long flags = read_thread_flags();
> > @@ -2417,12 +2432,21 @@ int syscall_trace_enter(struct pt_regs *regs)
> > ret = report_syscall_entry(regs);
> > if (ret || (flags & _TIF_SYSCALL_EMU))
> > return NO_SYSCALL;
> > +
> > + /*
> > + * Ensure ptrace changes to x0 are visible to seccomp
> > + * ptrace exits (SECCOMP_RET_TRACE).
> > + */
> > + update_syscall_orig_x0_after_ptrace(regs);
> > }
> >
> > /* Do the secure computing after ptrace; failures should be fast. */
> > if (secure_computing() == -1)
> > return NO_SYSCALL;
> >
> > + /* Ensure seccomp updates to x0 are visible to audit. */
> > + update_syscall_orig_x0_after_ptrace(regs);
>
> I think unconditionally updating orig_x0 here is unnecessary, we could
> Expand seccomp check in place as below the same as generic entry.
Let's leave any micro-optimisations for later, please. We're going to
need to backport this fix _way_ back, so I've been trying to keep it as
simple as possible. You're also going to end up replacing all of this
with the generic entry code, anyway.
I'll send a v2 with the comment changes shortly, then hopefully I can
send it as a fix for stable.
Thanks,
Will