Thread (6 messages) 6 messages, 4 authors, 12d ago

Re: [BUG] audit/powerpc: WARNING at kernel/auditsc.c:1995 (__audit_syscall_entry) during BPF kselftests (test_progs)

From: Venkat <hidden>
Date: 2026-09-18 07:42:23
Also in: bpf

Hi Daniel, Paul

Hope all is well with your family, Paul, please take care.
On 17 Sep 2026, at 9:40 PM, Paul Moore [off-list ref] wrote:

[NOTE: correcting the audit mailing list address to audit@vger ...]

On September 17, 2026 12:06:18 PM Paul Moore [off-list ref] wrote:
quoted
On September 17, 2026 10:03:59 AM Daniel Borkmann [off-list ref] wrote:
quoted
Hi Venkat,

On 9/17/26 3:01 PM, Venkat Rao Bagalkote wrote:
quoted
Hi all,

IBM CI has reported a kernel warning triggered in __audit_syscall_entry()
on a PowerPC 64 (ppc64le, POWER9 pSeries guest) system while running the
BPF kselftest suite (test_progs).

Environment:


Kernel version: 7.3.0-rc3-g238650ef6c7c (PREEMPT)
Architecture: ppc64le (POWER9 - IBM,8375-42A pSeries / phyp)
Workload: BPF selftests (tools/testing/selftests/bpf/test_progs)


Problem Description:


During syscall entry processing (system_call_exception ->
syscall_enter_audit -> __audit_syscall_entry), the kernel hit
WARN_ON(context->context != AUDIT_CTX_UNUSED) at kernel/auditsc.c:1995,
indicating that the task's audit context was not reset to AUDIT_CTX_UNUSED
prior to entering the new syscall.
Hm, based on the trace feels somewhat unrelated to bpf, but were you able
to bisect in
case it can be reliably reproduced? Which tree is this, linux-next or
bpf/bpf-next?
This was tested on the mainline Linux tree (Linus' tree, commit 238650ef6c7c).

Regarding bisection and reproducibility: the warning does not reproduce when running individual tests in isolation (e.g. running kfunc_module_order alone is clean). It is only observed intermittently during the full BPF selftests suite run (test_progs / test_progs-no_alu32), so I haven't been able to bisect it to a specific commit yet.
quoted
Thanks for the report Venkat.

Unfortunately due to some unexpected family medical issues I'm not able to
look into this very closely at the moment (triaging mail on my phone), but
the related audit code has been fairly stable lately so it seems a bit odd.

I do know that Thomas Gleixner (CC'd) did some work recently on the syscall
entry code (audit related commit below), perhaps that may be a place to start?

https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=6f25517010ddd3f8080d7e06b9b1cb1b64b73772

FWIW, I haven't seen this in any of my testing on x86 or ARM, have you seen
this on other arches besides Power? Also, as Daniel already mentioned, more
information on the tree would be helpful.
We have only tested and observed this on PowerPC (ppc64le, POWER9 pSeries guest).

Attached is the .config file.

Attachments

Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help