entry: Rework trace_syscall_enter()

Reread the syscall number from pt_regs and stop returning the eventually
modified syscall number.

That moves the reread to the end of syscall_trace_enter() and prepares for
moving it to the call site.

No functional change.

Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Tested-by: Michal Suchánek <msuchanek@suse.de>
Reviewed-by: Jinjie Ruan <ruanjinjie@huawei.com>
Link: https://patch.msgid.link/20260712141346.639115923@kernel.org
This commit is contained in:
Thomas Gleixner
2026-07-20 20:38:40 +02:00
parent 6f25517010
commit dfc98c7a46
2 changed files with 6 additions and 13 deletions
+4 -6
View File
@@ -58,7 +58,7 @@ static __always_inline bool arch_ptrace_report_syscall_permit_entry(struct pt_re
}
#endif
long trace_syscall_enter(struct pt_regs *regs, long syscall);
void trace_syscall_enter(struct pt_regs *regs);
void trace_syscall_exit(struct pt_regs *regs, long ret);
void syscall_enter_audit(struct pt_regs *regs);
@@ -99,16 +99,14 @@ static __always_inline long syscall_trace_enter(struct pt_regs *regs, unsigned l
return -1L;
}
/* Either of the above might have changed the syscall number */
syscall = syscall_get_nr(current, regs);
if (unlikely(work & SYSCALL_WORK_SYSCALL_TRACEPOINT))
syscall = trace_syscall_enter(regs, syscall);
trace_syscall_enter(regs);
if (unlikely(audit_context()))
syscall_enter_audit(regs);
return syscall;
/* Either of the above might have changed the syscall number */
return syscall_get_nr(current, regs);
}
/**
+2 -7
View File
@@ -8,14 +8,9 @@
/* Out of line to prevent tracepoint code duplication */
long trace_syscall_enter(struct pt_regs *regs, long syscall)
void trace_syscall_enter(struct pt_regs *regs)
{
trace_sys_enter(regs, syscall);
/*
* Probes or BPF hooks in the tracepoint may have changed the
* system call number. Reread it.
*/
return syscall_get_nr(current, regs);
trace_sys_enter(regs, syscall_get_nr(current, regs));
}
void trace_syscall_exit(struct pt_regs *regs, long ret)