[PATCH v5 0/2] PTRACE_SET_SYSCALL_INFO: add support for seccomp syscall skipping

Michal Suchánek msuchanek at suse.de
Fri Jul 10 15:38:32 UTC 2026


On Thu, Jul 09, 2026 at 12:09:47PM +0200, Renzo Davoli wrote:
> PTRACE_SET_SYSCALL_INFO is a generic ptrace API that complements
> PTRACE_GET_SYSCALL_INFO by allowing a tracer to modify details of a
> system call in which the tracee is currently blocked.
> 
> The API is designed to let tracers inspect and modify system call
> information in a simple, architecture-agnostic manner.
> 
> The current implementation only supports modifying the subset of
> system call information needed by strace: the system call number,
> arguments, and return value.
> 
> This patch set extends PTRACE_SET_SYSCALL_INFO with support for
> skipping a system call.
> 
> When a seccomp filter returns SECCOMP_RET_TRACE, the tracer receives,
> via PTRACE_GET_SYSCALL_INFO, a struct ptrace_syscall_info with
> op == PTRACE_SYSCALL_INFO_SECCOMP.
> 
> The tracer can skip the system call by setting the system call number
> to -1. However, the current PTRACE_SET_SYSCALL_INFO interface does not
> provide a way to specify the return value or error code that should be
> reported to the tracee after skipping the call.

Hello,

this will not work at least on powerpc, and possibly s390x.

On these architectures the syscall number and the syscall return value
share the same register.

seccomp can skip a syscall by returning -1 from __secure_computing()
which is then interpreted by the caller as a reason to skip further
syscall processing, in particular interpretinfg the return value set in
the registers as the syscall number.

However, the tracing hook in seccomp does not return anything, in
particular it does not change the return value of __secure_computing().

                /* Allow the BPF to provide the event message */
                ptrace_event(PTRACE_EVENT_SECCOMP, data);

If the skip was propagated all the way to here so that the
__secure_computing() could indicate to skip the signal it would work.

Other ways to rework the setting of the return value are possible. eg.
it was suggested to add a special field to pt_regs to hold the syscall
return value, and only copy it to the register at syscall exit.

Thanks

Michal


> 
> This patchset extends PTRACE_SET_SYSCALL_INFO to support skipping a system call
> triggered via seccomp.
> 
> When a tracer retrieves a ptrace_syscall_info structure with 'op' set to
> PTRACE_SYSCALL_INFO_SECCOMP, it can now choose to skip the system call.  To do
> this, the tracer changes 'op' to PTRACE_SYSCALL_INFO_EXIT and populates the
> exit union fields (rval and is_error) to define the return value and error
> status for the tracee.
> 
> System call suppression via PTRACE_SYSCALL_INFO_ENTRY is currently not
> implemented.  On some architectures (e.g. MIPS), when a system call is
> skipped by setting the syscall number to -1 at the entry stop, the
> architecture entry path unconditionally overwrites the return value
> register with -ENOSYS, clobbering any custom return value set by the
> tracer at the entry stop.
> 
> This patchset is a new version of the proposed patchset entitled:
> ptrace_set_syscall_info: add support for seccomp syscall skipping and
> instruction pointer modification
> The patchset has been split in two:
> syscall skipping(this)
> instruction pointer modification (it will be updated soon)
> 
> Changes in v5:
> * reworded the explanation for not supporting PTRACE_SYSCALL_INFO_ENTRY yet.
> * selftests/ptrace: removed a redundant check.
> 
> Changes in v4:
> * Reworded the commit messages for clarity.
> * Renamed the local variable child_op to op in ptrace_set_syscall_info()
> * Clean up and improve the coding style of selftests/ptrace/set_syscall_info.c
>   (suggested by Dmitry V. Levin)
> 
> Changes in v3:
> * restrict the syscall skipping feature to PTRACE_SYSCALL_INFO_SECCOMP
> 
> Changes in v2:
> bugfix: _NONE -> _EXIT transition was erroneously permitted
> 
> Changes since the previous patchset v2:
> * bugfix: skip_syscall init value
> * fix comments
> 
> Changes in (previous patchset) v2:
> * use PTRACE_SYSCALL_INFO_EXIT instead of a new tag
> * fixed most of the comments from sashiko.dev
> 
> Renzo Davoli (2):
>   ptrace: add PTRACE_SET_SYSCALL_INFO syscall skipping support
>   selftests/ptrace: add a test case for PTRACE_SET_SYSCALL_INFO syscall
>     skipping
> 
>  kernel/ptrace.c                               |  27 ++-
>  .../selftests/ptrace/set_syscall_info.c       | 172 +++++++++++++++++-
>  2 files changed, 193 insertions(+), 6 deletions(-)
> 
> -- 
> 2.53.0
> 


More information about the Strace-devel mailing list