The following commit has been merged into the x86/urgent branch of tip:

Commit-ID:     cb05143bdf428f280a5d519c82abf196d7871c11
Gitweb:        
https://git.kernel.org/tip/cb05143bdf428f280a5d519c82abf196d7871c11
Author:        Peter Zijlstra <[email protected]>
AuthorDate:    Tue, 27 Oct 2020 19:33:30 +01:00
Committer:     Thomas Gleixner <[email protected]>
CommitterDate: Tue, 27 Oct 2020 23:15:24 +01:00

x86/debug: Fix DR_STEP vs ptrace_get_debugreg(6)

Commit d53d9bc0cf78 ("x86/debug: Change thread.debugreg6 to
thread.virtual_dr6") changed the semantics of the variable from random
collection of bits, to exactly only those bits that ptrace() needs.

Unfortunately this lost DR_STEP for PTRACE_{BLOCK,SINGLE}STEP.

Furthermore, it turns out that userspace expects DR_STEP to be
unconditionally available, even for manual TF usage outside of
PTRACE_{BLOCK,SINGLE}_STEP.

Fixes: d53d9bc0cf78 ("x86/debug: Change thread.debugreg6 to thread.virtual_dr6")
Reported-by: Kyle Huey <[email protected]>
Signed-off-by: Peter Zijlstra (Intel) <[email protected]>
Signed-off-by: Thomas Gleixner <[email protected]>
Tested-by: Kyle Huey <[email protected]> 
Link: 
https://lore.kernel.org/r/[email protected]

---
 arch/x86/kernel/traps.c |  9 ++++++---
 1 file changed, 6 insertions(+), 3 deletions(-)

diff --git a/arch/x86/kernel/traps.c b/arch/x86/kernel/traps.c
index 32b2d39..e19df6c 100644
--- a/arch/x86/kernel/traps.c
+++ b/arch/x86/kernel/traps.c
@@ -937,10 +937,13 @@ static __always_inline void exc_debug_user(struct pt_regs 
*regs,
        instrumentation_begin();
 
        /*
-        * Clear the virtual DR6 value, ptrace() routines will set bits here
-        * for things it wants signals for.
+        * Start the virtual/ptrace DR6 value with just the DR_STEP mask
+        * of the real DR6. ptrace_triggered() will set the DR_TRAPn bits.
+        *
+        * Userspace expects DR_STEP to be visible in ptrace_get_debugreg(6)
+        * even if it is not the result of PTRACE_SINGLESTEP.
         */
-       current->thread.virtual_dr6 = 0;
+       current->thread.virtual_dr6 = (dr6 & DR_STEP);
 
        /*
         * The SDM says "The processor clears the BTF flag when it

Reply via email to