Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1472949

Re: [PATCH 1/2] tracing/syscalls: allow multiple syscall numbers per syscall

From Andy Lutomirski <luto@amacapital.net>
Newsgroups linux.kernel
Subject Re: [PATCH 1/2] tracing/syscalls: allow multiple syscall numbers per syscall
Date 2016-08-31 02:10 +0200
Message-ID <sc1gl-3sb-1@gated-at.bofh.it> (permalink)
References (8 earlier) <sbZoe-2i7-5@gated-at.bofh.it> <sbZoe-2i7-21@gated-at.bofh.it> <sbZRg-2t6-51@gated-at.bofh.it> <sc0kh-2Sd-5@gated-at.bofh.it> <sc0DE-30k-7@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On Tue, Aug 30, 2016 at 4:28 PM, Steven Rostedt <rostedt@goodmis.org> wrote:
> On Tue, 30 Aug 2016 16:09:04 -0700
> Andy Lutomirski <luto@amacapital.net> wrote:
>
>> But none of this should be a problem at all for MIPS, right?  AFAICT
>> the only problem for MIPS is that there *is* a mapping from metadata
>> to nr.  If that mapping got removed, MIPS should just work, right?
>
> Wait, where's the mapping of metadata to nr. I don't see that, nor do I
> see a need for that. The issue is that we have metadata that expresses
> how to record a syscall, and we map syscall nr to metadata, because
> when tracing is active, the only thing we have to find that metadata is
> the syscall nr.

It's in init_ftrace_syscalls():

        meta->syscall_nr = i;

and everything that uses that.  I think that this is the main problem
that the patch that started this thread changes, and I think that
deleting it would be cleaner than this patch.

>
> Now if a syscall nr has more than one way to record (a single nr for
> multiple syscalls), then we get into trouble. That's why we have
> trouble with compat syscalls. The same number maps to different
> syscalls, and we don't know how to differentiate that.

>
>
>>
>> For x86 compat, I think that adding arch should be sufficient.
>> Specifically, rather than having just one enter_syscall_files array,
>> have one per audit arch.  Then call syscall_get_arch() as well as
>> syscall_get_nr() and use both to lookup the metadata.  AFAIK this
>> should work on all architectures, although you might need some arch
>> helpers to enumerate all the arches and their respective syscall
>> tables (and max syscall nrs).
>
> OK, if the regs can get us to the arch, then this might work.
>
> That is, perhaps we can have multiple tables (not really sure how to
> make that happen in an arch agnostic way), and then have two functions:
>
> trace_get_syscall_nr(current, regs)
> trace_get_syscall_arch(current, regs)

Sadly, syscall_get_arch() doesn't take a regs parameter -- it looks at
current.  If it were made more general, it would need a task pointer,
not a regs pointer, but would just looking at current be okay for
tracing?

syscall_get_arch() does work on all archs that support seccomp filters, though.

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

[PATCH 1/2] tracing/syscalls: allow multiple syscall numbers per syscall Marcin Nowakowski <marcin.nowakowski@imgtec.com> - 2016-08-29 11:40 +0200
  Re: [PATCH 1/2] tracing/syscalls: allow multiple syscall numbers per syscall Andy Lutomirski <luto@amacapital.net> - 2016-08-30 02:00 +0200
    Re: [PATCH 1/2] tracing/syscalls: allow multiple syscall numbers per  syscall Marcin Nowakowski <marcin.nowakowski@imgtec.com> - 2016-08-30 10:20 +0200
      Re: [PATCH 1/2] tracing/syscalls: allow multiple syscall numbers per syscall Andy Lutomirski <luto@amacapital.net> - 2016-08-30 21:00 +0200
        Re: [PATCH 1/2] tracing/syscalls: allow multiple syscall numbers  per syscall Steven Rostedt <rostedt@goodmis.org> - 2016-08-30 21:40 +0200
          Re: [PATCH 1/2] tracing/syscalls: allow multiple syscall numbers per syscall Andy Lutomirski <luto@amacapital.net> - 2016-08-30 22:00 +0200
            Re: [PATCH 1/2] tracing/syscalls: allow multiple syscall numbers  per syscall Steven Rostedt <rostedt@goodmis.org> - 2016-08-30 23:00 +0200
              Re: [PATCH 1/2] tracing/syscalls: allow multiple syscall numbers per syscall Andy Lutomirski <luto@amacapital.net> - 2016-08-30 23:50 +0200
                Re: [PATCH 1/2] tracing/syscalls: allow multiple syscall numbers  per syscall Steven Rostedt <rostedt@goodmis.org> - 2016-08-31 00:10 +0200
                Re: [PATCH 1/2] tracing/syscalls: allow multiple syscall numbers per syscall Andy Lutomirski <luto@amacapital.net> - 2016-08-31 00:10 +0200
                Re: [PATCH 1/2] tracing/syscalls: allow multiple syscall numbers  per syscall Steven Rostedt <rostedt@goodmis.org> - 2016-08-31 00:40 +0200
                Re: [PATCH 1/2] tracing/syscalls: allow multiple syscall numbers per syscall Andy Lutomirski <luto@amacapital.net> - 2016-08-31 01:10 +0200
                Re: [PATCH 1/2] tracing/syscalls: allow multiple syscall numbers  per syscall Steven Rostedt <rostedt@goodmis.org> - 2016-08-31 01:30 +0200
                Re: [PATCH 1/2] tracing/syscalls: allow multiple syscall numbers per syscall Andy Lutomirski <luto@amacapital.net> - 2016-08-31 02:10 +0200
                Re: [PATCH 1/2] tracing/syscalls: allow multiple syscall numbers per  syscall Marcin Nowakowski <marcin.nowakowski@imgtec.com> - 2016-08-31 16:10 +0200
                Re: [PATCH 1/2] tracing/syscalls: allow multiple syscall numbers per  syscall Marcin Nowakowski <marcin.nowakowski@imgtec.com> - 2016-08-31 09:20 +0200
            Re: [PATCH 1/2] tracing/syscalls: allow multiple syscall numbers per syscall Arnd Bergmann <arnd@arndb.de> - 2016-08-31 10:30 +0200
              Re: [PATCH 1/2] tracing/syscalls: allow multiple syscall numbers  per syscall Steven Rostedt <rostedt@goodmis.org> - 2016-09-01 17:30 +0200

csiph-web