entry: Rework syscall_audit_enter()

Move it out of line and let it reread the syscall number on it's own. That
makes the low level entry code denser and allows to move the reread to the
call site of syscall_trace_enter() once the tracer is fixed up.

To prevent the compiler from putting audit_context() out of line and
thereby breaking dead code elimination, mark audit_context()
__always_inline.

Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Tested-by: Michal Suchánek <msuchanek@suse.de>
Reviewed-by: Jinjie Ruan <ruanjinjie@huawei.com>
Link: https://patch.msgid.link/20260712141346.576865340@kernel.org
This commit is contained in:
Thomas Gleixner
2026-07-20 20:38:40 +02:00
parent 8383e05af7
commit 6f25517010
2 changed files with 15 additions and 11 deletions
+3 -11
View File
@@ -60,16 +60,7 @@ static __always_inline bool arch_ptrace_report_syscall_permit_entry(struct pt_re
long trace_syscall_enter(struct pt_regs *regs, long syscall);
void trace_syscall_exit(struct pt_regs *regs, long ret);
static inline void syscall_enter_audit(struct pt_regs *regs, long syscall)
{
if (unlikely(audit_context())) {
unsigned long args[6];
syscall_get_arguments(current, regs, args);
audit_syscall_entry(syscall, args[0], args[1], args[2], args[3]);
}
}
void syscall_enter_audit(struct pt_regs *regs);
static __always_inline long syscall_trace_enter(struct pt_regs *regs, unsigned long work,
long syscall)
@@ -114,7 +105,8 @@ static __always_inline long syscall_trace_enter(struct pt_regs *regs, unsigned l
if (unlikely(work & SYSCALL_WORK_SYSCALL_TRACEPOINT))
syscall = trace_syscall_enter(regs, syscall);
syscall_enter_audit(regs, syscall);
if (unlikely(audit_context()))
syscall_enter_audit(regs);
return syscall;
}
+12
View File
@@ -1,5 +1,6 @@
// SPDX-License-Identifier: GPL-2.0
#include <linux/audit.h>
#include <linux/entry-common.h>
#define CREATE_TRACE_POINTS
@@ -21,3 +22,14 @@ void trace_syscall_exit(struct pt_regs *regs, long ret)
{
trace_sys_exit(regs, ret);
}
#ifdef CONFIG_AUDITSYSCALL
void syscall_enter_audit(struct pt_regs *regs)
{
long syscall = syscall_get_nr(current, regs);
unsigned long args[6];
syscall_get_arguments(current, regs, args);
__audit_syscall_entry(syscall, args[0], args[1], args[2], args[3]);
}
#endif