[PATCH v20 01/15] arm64: ptrace: Drop redundant pseudo-single-step for SYSEMU_SINGLESTEP

From: Jinjie Ruan

Date: Wed Sep 30 2026 - 06:23:31 EST


PTRACE_SYSEMU_SINGLESTEP sets both _TIF_SYSCALL_EMU and _TIF_SINGLESTEP.

With _TIF_SINGLESTEP set, the arm64 syscall-exit path synthesises a
pseudo-single-step exception:

ptrace_report_syscall_exit(regs, 1)
-> user_single_step_report()
-> info.si_signo = SIGTRAP
-> info.si_code = SI_USER
-> force_sig_info(&info)

But for PTRACE_SYSEMU_SINGLESTEP it is redundant: the stop before
the instruction following the SVC is already delivered by the hardware
single-step state machine, so the tracer ends up with two stops
at the same PC as below:

sig=133 si_code=133 SS=0 pc=0x400638 [syscall-enter-stop]
sig=5 si_code=0 SS=0 pc=0x400638 [pseudo-step, dropped here]
sig=5 si_code=2 SS=1 pc=0x400638 [hardware single-step]

The pseudo-step was added by commit ac2081cdc4d9 ("arm64: ptrace:
Consistently use pseudo-singlestep exceptions") because a ptrace stop
taken while a system call is in progress may corrupt the stepping state.
For an emulated system call that cannot happen, as the call never runs:

- No syscall-exit-stop, because _TIF_SINGLESTEP is set

- No seccomp trap, because syscall_trace_enter() returns NO_SYSCALL
when SYSCALL_EMU is set, before the seccomp check

- The syscall body is not executed, so nothing can take a stop while it
is in progress.

Introduce report_single_step(), which returns false when _TIF_SYSCALL_EMU
is set, so the pseudo-step is skipped for the emulated case. This also
matches the generic entry behaviour.

PTRACE_SINGLESTEP and PTRACE_SYSCALL are unaffected:
- PTRACE_SYSCALL: SYSCALL_TRACE is set and _TIF_SINGLESTEP is not, so
the syscall-exit-stop is reported as before and no pseudo-step is
involved;

- PTRACE_SINGLESTEP: _TIF_SINGLESTEP is set but _TIF_SYSCALL_EMU is
not, so the pseudo-step is still synthesised. It is still needed
here, because the system call does execute and the hazard described
above applies.

Cc: Mark Rutland <mark.rutland@xxxxxxx>
Cc: Will Deacon <will@xxxxxxxxxx>
Cc: Catalin Marinas <catalin.marinas@xxxxxxx>
Cc: Oleg Nesterov <oleg@xxxxxxxxxx>
Signed-off-by: Jinjie Ruan <ruanjinjie@xxxxxxxxxx>
---
arch/arm64/kernel/ptrace.c | 12 +++++++++++-
1 file changed, 11 insertions(+), 1 deletion(-)

diff --git a/arch/arm64/kernel/ptrace.c b/arch/arm64/kernel/ptrace.c
index f743cbec1c3a..96462de75d4b 100644
--- a/arch/arm64/kernel/ptrace.c
+++ b/arch/arm64/kernel/ptrace.c
@@ -2482,16 +2482,26 @@ int syscall_trace_enter(struct pt_regs *regs)
return regs->syscallno;
}

+static inline bool report_single_step(unsigned long flags)
+{
+ if (flags & _TIF_SYSCALL_EMU)
+ return false;
+
+ return flags & _TIF_SINGLESTEP;
+}
+
void syscall_trace_exit(struct pt_regs *regs)
{
unsigned long flags = read_thread_flags();
+ bool step;

audit_syscall_exit(regs);

if (flags & _TIF_SYSCALL_TRACEPOINT)
trace_sys_exit(regs, syscall_get_return_value(current, regs));

- if (flags & (_TIF_SYSCALL_TRACE | _TIF_SINGLESTEP))
+ step = report_single_step(flags);
+ if (step || flags & _TIF_SYSCALL_TRACE)
report_syscall_exit(regs);

rseq_syscall(regs);
--
2.34.1