On Fri, Sep 18, 2026 at 4:42 AM Venkat <[email protected]> wrote:
>
> Hi Daniel, Paul
>
> Hope all is well with your family, Paul, please take care.
>
> > On 17 Sep 2026, at 9:40 PM, Paul Moore <[email protected]> wrote:
> >
> > [NOTE: correcting the audit mailing list address to audit@vger ...]
> >
> > On September 17, 2026 12:06:18 PM Paul Moore <[email protected]> wrote:
> >> On September 17, 2026 10:03:59 AM Daniel Borkmann <[email protected]> 
> >> wrote:
> >>> Hi Venkat,
> >>>
> >>> On 9/17/26 3:01 PM, Venkat Rao Bagalkote wrote:
> >>>> Hi all,
> >>>>
> >>>> IBM CI has reported a kernel warning triggered in __audit_syscall_entry()
> >>>> on a PowerPC 64 (ppc64le, POWER9 pSeries guest) system while running the
> >>>> BPF kselftest suite (test_progs).
> >>>>
> >>>> Environment:
> >>>>
> >>>>
> >>>> Kernel version: 7.3.0-rc3-g238650ef6c7c (PREEMPT)
> >>>> Architecture: ppc64le (POWER9 - IBM,8375-42A pSeries / phyp)
> >>>> Workload: BPF selftests (tools/testing/selftests/bpf/test_progs)
> >>>>
> >>>>
> >>>> Problem Description:
> >>>>
> >>>>
> >>>> During syscall entry processing (system_call_exception ->
> >>>> syscall_enter_audit -> __audit_syscall_entry), the kernel hit
> >>>> WARN_ON(context->context != AUDIT_CTX_UNUSED) at kernel/auditsc.c:1995,
> >>>> indicating that the task's audit context was not reset to 
> >>>> AUDIT_CTX_UNUSED
> >>>> prior to entering the new syscall.
> >>>
> >>> Hm, based on the trace feels somewhat unrelated to bpf, but were you able
> >>> to bisect in
> >>> case it can be reliably reproduced? Which tree is this, linux-next or
> >>> bpf/bpf-next?
>
> This was tested on the mainline Linux tree (Linus' tree, commit 238650ef6c7c).
>
> Regarding bisection and reproducibility: the warning does not reproduce when 
> running individual tests in isolation (e.g. running kfunc_module_order alone 
> is clean). It is only observed intermittently during the full BPF selftests 
> suite run (test_progs / test_progs-no_alu32), so I haven't been able to 
> bisect it to a specific commit yet.
>
> >>
> >> Thanks for the report Venkat.
> >>
> >> Unfortunately due to some unexpected family medical issues I'm not able to
> >> look into this very closely at the moment (triaging mail on my phone), but
> >> the related audit code has been fairly stable lately so it seems a bit odd.
> >>
> >> I do know that Thomas Gleixner (CC'd) did some work recently on the syscall
> >> entry code (audit related commit below), perhaps that may be a place to 
> >> start?
> >>
> >> https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=6f25517010ddd3f8080d7e06b9b1cb1b64b73772
> >>
> >> FWIW, I haven't seen this in any of my testing on x86 or ARM, have you seen
> >> this on other arches besides Power? Also, as Daniel already mentioned, more
> >> information on the tree would be helpful.
>
> We have only tested and observed this on PowerPC (ppc64le, POWER9 pSeries 
> guest).
>
> Attached is the .config file.
>
>
> Regards,
> Venkat.
> >>
> >> While I don't have access to a Power system, I'm CC'ing Ricardo Robaina who
> >> also works at IBM/RH and has experience with the audit kernel code. If this
> >> appears to be specific to Power, he might be a good resource to help
> >> diagnose and develop a patch.
> >>
> >>>
> >>>> Trace:
> >>>>
> >>>>
> >>>> [ 1371.387510] ------------[ cut here ]------------
> >>>> [ 1371.387528] WARNING: kernel/auditsc.c:1995 at
> >>>> __audit_syscall_entry+0x50/0x1b0, CPU#17: test_progs/49616
> >>>> [ 1371.387539] Modules linked in: dm_verity(E) dm_bufio(E) 
> >>>> reed_solomon(E)
> >>>> livepatch_sample(EK) tun(E) vrf(E) 8021q(E) garp(E) mrp(E) stp(E) llc(E)
> >>>> veth(E) bonding(E) tls(E) rfkill(E) nft_fib_inet(E) nft_fib_ipv4(E)
> >>>> nft_fib_ipv6(E) nft_fib(E) nft_reject_inet(E) nf_reject_ipv4(E)
> >>>> nf_reject_ipv6(E) nft_reject(E) nft_ct(E) nft_chain_nat(E) hvcs(E)
> >>>> hvcserver(E) pseries_rng(E) vmx_crypto(E) sg(E) drm(E) fuse(E)
> >>>> drm_panel_orientation_quirks(E) xfs(E) sr_mod(E) nvme_tcp(E) sd_mod(E)
> >>>> cdrom(E) nvme_fabrics(E) nvme_core(E) ibmvscsi(E) ibmveth(E)
> >>>> scsi_transport_srp(E) dm_mirror(E) dm_region_hash(E) dm_log(E) dm_mod(E)
> >>>> [last unloaded: bpf_test_modorder_x(OE)]
> >>>> [ 1371.387607] CPU: 17 UID: 0 PID: 49616 Comm: test_progs Tainted: G
> >>>> OE K     7.3.0-rc3-g238650ef6c7c #1 PREEMPT
> >>>> [ 1371.387616] Tainted: [O]=OOT_MODULE, [E]=UNSIGNED_MODULE, 
> >>>> [K]=LIVEPATCH
> >>>> [ 1371.387620] Hardware name: IBM,8375-42A POWER9 (architected) 0x4e0202
> >>>> 0xf000005 of:IBM,FW950.80 (VL950_131) hv:phyp pSeries
> >>>> [ 1371.387626] NIP:  c0000000003e70d0 LR: c000000000352080 CTR:
> >>>> c00000000000cf00
> >>>> [ 1371.387631] REGS: c00000000beafaa0 TRAP: 0700   Tainted: G      OE K
> >>>> (7.3.0-rc3-g238650ef6c7c)
> >>>> [ 1371.387637] MSR:  8000000000029033 <SF,EE,ME,IR,DR,RI,LE>  CR: 
> >>>> 48002824
> >>>> XER: 20040084
> >>>> [ 1371.387650] CFAR: c00000000035207c IRQMASK: 0
> >>>>      GPR00: c000000000034958 c00000000beafd40 c0000000020eb200 
> >>>> c0000000345f4800
> >>>>      GPR04: 00007fffe2a31184 0000000000000081 000000007fffffff 
> >>>> 0000000000000000
> >>>>      GPR08: 0000000000000000 0000000000000001 0000000000000001 
> >>>> 00000000000000dd
> >>>>      GPR12: 0000000000000000 c00000002e99b300 0000000000000000 
> >>>> 0000000000000000
> >>>>      GPR16: 0000000000000000 0000000000000000 0000000000000000 
> >>>> 0000000000000000
> >>>>      GPR20: 0000000000000000 0000000000000000 0000000000000000 
> >>>> 0000000000000000
> >>>>      GPR24: 0000000000000000 0000000000000000 0000000000000000 
> >>>> c0000000345f4800
> >>>>      GPR28: 0000000000000000 00000000000000dd 00000000000000dd 
> >>>> c000000138e0c000
> >>>> [ 1371.387710] NIP [c0000000003e70d0] __audit_syscall_entry+0x50/0x1b0
> >>>> [ 1371.387715] LR [c000000000352080] syscall_enter_audit+0x90/0xd0
> >>>> [ 1371.387722] Call Trace:
> >>>> [ 1371.387725] [c00000000beafd40] [c000000000937050]
> >>>> selinux_task_getpgid+0x80/0xa0 (unreliable)
> >>>> [ 1371.387735] [c00000000beafda0] [c00000000beafde0] 0xc00000000beafde0
> >>>> [ 1371.387741] [c00000000beafe00] [c000000000034958]
> >>>> system_call_exception+0x448/0x480
> >>>> [ 1371.387749] [c00000000beafe50] [c00000000000d05c]
> >>>> system_call_vectored_common+0x15c/0x2ec
> >>>> [ 1371.387757] ---- interrupt: 3000 at 0x7fffab74cbf0
> >>>>
> >>>>
> >>>> Please let me know if additional logs, config, or repro details are 
> >>>> needed.
> >>>>
> >>>> Regards,
> >>>>
> >>>> Venkat.
> >
> > --
> > paul-moore.com
> >
> >
> >
>
Hello eveyone!

Thanks for looping me in, Paul and for sharing more details, Venkat.

At first glance it seems that the audit_context, for some reason, has
not been cleared. I'll reserve a ppc64le machine and look into this
over the next week.

-Ricardo


Reply via email to