[PATCH RFC POC 06/50] arm64: commit fds on syscall exit
From: Christian Brauner
Date: Tue Sep 15 2026 - 07:43:05 EST
Add TIF_FD_SLOTS to the syscall work bits. el0_svc_common() rereads
the flags after the system call and takes the trace exit for any of
them. So a task that reserved descriptors ends up in
syscall_trace_exit() which commits them before audit and the ptrace exit
stop.
Signed-off-by: Christian Brauner (Amutable) <brauner@xxxxxxxxxx>
---
arch/arm64/include/asm/thread_info.h | 4 +++-
arch/arm64/kernel/ptrace.c | 4 ++++
2 files changed, 7 insertions(+), 1 deletion(-)
diff --git a/arch/arm64/include/asm/thread_info.h b/arch/arm64/include/asm/thread_info.h
index 5d7fe3e153c8..e48006eb98a8 100644
--- a/arch/arm64/include/asm/thread_info.h
+++ b/arch/arm64/include/asm/thread_info.h
@@ -74,6 +74,7 @@ void arch_setup_new_exec(void);
#define TIF_SECCOMP 11 /* syscall secure computing */
#define TIF_SYSCALL_EMU 12 /* syscall emulation active */
#define TIF_PATCH_PENDING 13 /* pending live patching update */
+#define TIF_FD_SLOTS 14 /* syscall prepared descriptors */
#define TIF_MEMDIE 18 /* is terminating due to OOM killer */
#define TIF_FREEZE 19
#define TIF_RESTORE_SIGMASK 20
@@ -107,10 +108,11 @@ void arch_setup_new_exec(void);
#define _TIF_MTE_ASYNC_FAULT (1 << TIF_MTE_ASYNC_FAULT)
#define _TIF_NOTIFY_SIGNAL (1 << TIF_NOTIFY_SIGNAL)
#define _TIF_TSC_SIGSEGV (1 << TIF_TSC_SIGSEGV)
+#define _TIF_FD_SLOTS (1 << TIF_FD_SLOTS)
#define _TIF_SYSCALL_WORK (_TIF_SYSCALL_TRACE | _TIF_SYSCALL_AUDIT | \
_TIF_SYSCALL_TRACEPOINT | _TIF_SECCOMP | \
- _TIF_SYSCALL_EMU)
+ _TIF_SYSCALL_EMU | _TIF_FD_SLOTS)
#ifdef CONFIG_SHADOW_CALL_STACK
#define INIT_SCS \
diff --git a/arch/arm64/kernel/ptrace.c b/arch/arm64/kernel/ptrace.c
index f743cbec1c3a..3bedfed977d4 100644
--- a/arch/arm64/kernel/ptrace.c
+++ b/arch/arm64/kernel/ptrace.c
@@ -28,6 +28,7 @@
#include <linux/hw_breakpoint.h>
#include <linux/regset.h>
#include <linux/elf.h>
+#include <linux/file.h>
#include <linux/rseq.h>
#include <asm/compat.h>
@@ -2486,6 +2487,9 @@ void syscall_trace_exit(struct pt_regs *regs)
{
unsigned long flags = read_thread_flags();
+ if (flags & _TIF_FD_SLOTS)
+ fd_slots_commit(regs);
+
audit_syscall_exit(regs);
if (flags & _TIF_SYSCALL_TRACEPOINT)
--
2.53.0