From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1755194AbbIMLJh (ORCPT ); Sun, 13 Sep 2015 07:09:37 -0400 Received: from terminus.zytor.com ([198.137.202.10]:43792 "EHLO terminus.zytor.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751655AbbIMLJg (ORCPT ); Sun, 13 Sep 2015 07:09:36 -0400 Date: Sun, 13 Sep 2015 04:08:47 -0700 From: tip-bot for Alexander Shishkin Message-ID: Cc: eranian@google.com, acme@redhat.com, vincent.weaver@maine.edu, torvalds@linux-foundation.org, mingo@kernel.org, acme@infradead.org, peterz@infradead.org, tglx@linutronix.de, jolsa@redhat.com, linux-kernel@vger.kernel.org, alexander.shishkin@linux.intel.com, hpa@zytor.com Reply-To: mingo@kernel.org, acme@infradead.org, eranian@google.com, acme@redhat.com, torvalds@linux-foundation.org, vincent.weaver@maine.edu, hpa@zytor.com, linux-kernel@vger.kernel.org, alexander.shishkin@linux.intel.com, peterz@infradead.org, tglx@linutronix.de, jolsa@redhat.com In-Reply-To: <1441030168-6853-3-git-send-email-alexander.shishkin@linux.intel.com> References: <1441030168-6853-3-git-send-email-alexander.shishkin@linux.intel.com> To: linux-tip-commits@vger.kernel.org Subject: [tip:perf/core] perf/x86/intel/bts: Disallow use by unprivileged users on paranoid systems Git-Commit-ID: d2878d642a4edd1d57c691dc3e4d7847cbf9d442 X-Mailer: tip-git-log-daemon Robot-ID: Robot-Unsubscribe: Contact to get blacklisted from these emails MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Content-Type: text/plain; charset=UTF-8 Content-Disposition: inline Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Commit-ID: d2878d642a4edd1d57c691dc3e4d7847cbf9d442 Gitweb: http://git.kernel.org/tip/d2878d642a4edd1d57c691dc3e4d7847cbf9d442 Author: Alexander Shishkin AuthorDate: Mon, 31 Aug 2015 17:09:28 +0300 Committer: Ingo Molnar CommitDate: Sun, 13 Sep 2015 11:27:22 +0200 perf/x86/intel/bts: Disallow use by unprivileged users on paranoid systems BTS leaks kernel addresses even in userspace-only mode due to imprecise IP sampling, so sometimes syscall entry points or page fault handler addresses end up in a userspace trace. Now, intel_bts driver exports trace data zero-copy, it does not scan through it to filter out the kernel addresses and it's would be a O(n) job. To work around this situation, this patch forbids the use of intel_bts driver by unprivileged users on systems with the paranoid setting above the (kernel's) default "1", which still allows kernel profiling. In other words, using intel_bts driver implies kernel tracing, regardless of the "exclude_kernel" attribute setting. Signed-off-by: Alexander Shishkin Signed-off-by: Peter Zijlstra (Intel) Cc: Arnaldo Carvalho de Melo Cc: Arnaldo Carvalho de Melo Cc: Jiri Olsa Cc: Linus Torvalds Cc: Peter Zijlstra Cc: Stephane Eranian Cc: Thomas Gleixner Cc: Vince Weaver Cc: hpa@zytor.com Link: http://lkml.kernel.org/r/1441030168-6853-3-git-send-email-alexander.shishkin@linux.intel.com Signed-off-by: Ingo Molnar --- arch/x86/kernel/cpu/perf_event_intel_bts.c | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/arch/x86/kernel/cpu/perf_event_intel_bts.c b/arch/x86/kernel/cpu/perf_event_intel_bts.c index d1c0f25..2cad71d 100644 --- a/arch/x86/kernel/cpu/perf_event_intel_bts.c +++ b/arch/x86/kernel/cpu/perf_event_intel_bts.c @@ -495,6 +495,19 @@ static int bts_event_init(struct perf_event *event) if (x86_add_exclusive(x86_lbr_exclusive_bts)) return -EBUSY; + /* + * BTS leaks kernel addresses even when CPL0 tracing is + * disabled, so disallow intel_bts driver for unprivileged + * users on paranoid systems since it provides trace data + * to the user in a zero-copy fashion. + * + * Note that the default paranoia setting permits unprivileged + * users to profile the kernel. + */ + if (event->attr.exclude_kernel && perf_paranoid_kernel() && + !capable(CAP_SYS_ADMIN)) + return -EACCES; + ret = x86_reserve_hardware(); if (ret) { x86_del_exclusive(x86_lbr_exclusive_bts);