Thread (47 messages) 47 messages, 9 authors, 2025-01-17

Re: Crash when attaching uretprobes to processes running in Docker

From: Oleg Nesterov <oleg@redhat.com>
Date: 2025-01-14 20:40:04
Also in: bpf, linux-api, lkml

On 01/14, Andrii Nakryiko wrote:
Should we just fix whoever is blocking kernel-internal special syscall
(sys_uretprobe)?
Well, we can add __NR_uretprobe to mode1_syscalls[] but this won't
really help.

We can't "fix" the existing user-space setups which can nack any
"unnecessary/unknown" syscall.
What would happen if someone blocked that other
special kernel-internal syscall for signal handling (can't remember
the name,
sys_rt_sigreturn().

Yes, the task will crash after return from the signal handler if this
syscall is filtered out.

But, unlike sys_uretprobe(), sys_rt_sigreturn() is old, so the existing
setups must know that sigreturn() should be respected...

Oleg.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help