Re: [BUG] audit/powerpc: WARNING at kernel/auditsc.c:1995 (__audit_syscall_entry) during BPF kselftests (test_progs)
From: Venkat <hidden>
Date: 2026-09-18 07:42:23
Also in:
bpf
Hi Daniel, Paul Hope all is well with your family, Paul, please take care.
On 17 Sep 2026, at 9:40 PM, Paul Moore [off-list ref] wrote: [NOTE: correcting the audit mailing list address to audit@vger ...] On September 17, 2026 12:06:18 PM Paul Moore [off-list ref] wrote:quoted
On September 17, 2026 10:03:59 AM Daniel Borkmann [off-list ref] wrote:quoted
Hi Venkat, On 9/17/26 3:01 PM, Venkat Rao Bagalkote wrote:quoted
Hi all, IBM CI has reported a kernel warning triggered in __audit_syscall_entry() on a PowerPC 64 (ppc64le, POWER9 pSeries guest) system while running the BPF kselftest suite (test_progs). Environment: Kernel version: 7.3.0-rc3-g238650ef6c7c (PREEMPT) Architecture: ppc64le (POWER9 - IBM,8375-42A pSeries / phyp) Workload: BPF selftests (tools/testing/selftests/bpf/test_progs) Problem Description: During syscall entry processing (system_call_exception -> syscall_enter_audit -> __audit_syscall_entry), the kernel hit WARN_ON(context->context != AUDIT_CTX_UNUSED) at kernel/auditsc.c:1995, indicating that the task's audit context was not reset to AUDIT_CTX_UNUSED prior to entering the new syscall.Hm, based on the trace feels somewhat unrelated to bpf, but were you able to bisect in case it can be reliably reproduced? Which tree is this, linux-next or bpf/bpf-next?
This was tested on the mainline Linux tree (Linus' tree, commit 238650ef6c7c). Regarding bisection and reproducibility: the warning does not reproduce when running individual tests in isolation (e.g. running kfunc_module_order alone is clean). It is only observed intermittently during the full BPF selftests suite run (test_progs / test_progs-no_alu32), so I haven't been able to bisect it to a specific commit yet.
quoted
Thanks for the report Venkat. Unfortunately due to some unexpected family medical issues I'm not able to look into this very closely at the moment (triaging mail on my phone), but the related audit code has been fairly stable lately so it seems a bit odd. I do know that Thomas Gleixner (CC'd) did some work recently on the syscall entry code (audit related commit below), perhaps that may be a place to start? https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=6f25517010ddd3f8080d7e06b9b1cb1b64b73772 FWIW, I haven't seen this in any of my testing on x86 or ARM, have you seen this on other arches besides Power? Also, as Daniel already mentioned, more information on the tree would be helpful.
We have only tested and observed this on PowerPC (ppc64le, POWER9 pSeries guest). Attached is the .config file.
Attachments
- bpf_audit.txt [text/plain] 194017 bytes · preview
- (unnamed) [text/plain] 3362 bytes · preview