From: Robert Bragg <robert@sixbynine.org> To: intel-gfx@lists.freedesktop.org Cc: Daniel Vetter <daniel.vetter@intel.com>, Jani Nikula <jani.nikula@linux.intel.com>, David Airlie <airlied@linux.ie>, Peter Zijlstra <a.p.zijlstra@chello.nl>, Paul Mackerras <paulus@samba.org>, Ingo Molnar <mingo@redhat.com>, Arnaldo Carvalho de Melo <acme@kernel.org>, linux-kernel@vger.kernel.org, dri-devel@lists.freedesktop.org, linux-api@vger.kernel.org Subject: [RFC PATCH 02/11] perf: Add PERF_PMU_CAP_IS_DEVICE flag Date: Thu, 7 May 2015 15:15:45 +0100 [thread overview] Message-ID: <1431008154-6833-3-git-send-email-robert@sixbynine.org> (raw) In-Reply-To: <1431008154-6833-1-git-send-email-robert@sixbynine.org> The PERF_PMU_CAP_IS_DEVICE flag provides pmu drivers a way to declare that they only monitor device specific metrics and since they don't monitor any cpu metrics then perf should bypass any cpu centric security checks, as well as disallow cpu centric attributes. Signed-off-by: Robert Bragg <robert@sixbynine.org> --- include/linux/perf_event.h | 1 + kernel/events/core.c | 39 +++++++++++++++++++++++++++++++++------ 2 files changed, 34 insertions(+), 6 deletions(-) diff --git a/include/linux/perf_event.h b/include/linux/perf_event.h index 2b62198..1af35b4 100644 --- a/include/linux/perf_event.h +++ b/include/linux/perf_event.h @@ -166,6 +166,7 @@ struct perf_event; * pmu::capabilities flags */ #define PERF_PMU_CAP_NO_INTERRUPT 0x01 +#define PERF_PMU_CAP_IS_DEVICE 0x02 /** * struct pmu - generic performance monitoring unit diff --git a/kernel/events/core.c b/kernel/events/core.c index 38c240c..7218b01 100644 --- a/kernel/events/core.c +++ b/kernel/events/core.c @@ -3330,7 +3330,8 @@ find_get_context(struct pmu *pmu, struct task_struct *task, int cpu) if (!task) { /* Must be root to operate on a CPU event: */ - if (perf_paranoid_cpu() && !capable(CAP_SYS_ADMIN)) + if (!(pmu->capabilities & PERF_PMU_CAP_IS_DEVICE) && + perf_paranoid_cpu() && !capable(CAP_SYS_ADMIN)) return ERR_PTR(-EACCES); /* @@ -7475,11 +7476,6 @@ SYSCALL_DEFINE5(perf_event_open, if (err) return err; - if (!attr.exclude_kernel) { - if (perf_paranoid_kernel() && !capable(CAP_SYS_ADMIN)) - return -EACCES; - } - if (attr.freq) { if (attr.sample_freq > sysctl_perf_event_sample_rate) return -EINVAL; @@ -7538,6 +7534,37 @@ SYSCALL_DEFINE5(perf_event_open, goto err_cpus; } + if (event->pmu->capabilities & PERF_PMU_CAP_IS_DEVICE) { + + /* Don't allow cpu centric attributes... */ + if (event->attr.exclude_user || + event->attr.exclude_callchain_user || + event->attr.exclude_kernel || + event->attr.exclude_callchain_kernel || + event->attr.exclude_hv || + event->attr.exclude_idle || + event->attr.exclude_host || + event->attr.exclude_guest || + event->attr.mmap || + event->attr.comm || + event->attr.task) + return -EINVAL; + + if (attr.sample_type & + (PERF_SAMPLE_IP | + PERF_SAMPLE_TID | + PERF_SAMPLE_ADDR | + PERF_SAMPLE_CALLCHAIN | + PERF_SAMPLE_CPU | + PERF_SAMPLE_BRANCH_STACK | + PERF_SAMPLE_REGS_USER | + PERF_SAMPLE_STACK_USER)) + return -EINVAL; + } else if (!attr.exclude_kernel) { + if (perf_paranoid_kernel() && !capable(CAP_SYS_ADMIN)) + return -EACCES; + } + if (flags & PERF_FLAG_PID_CGROUP) { err = perf_cgroup_connect(pid, event, &attr, group_leader); if (err) { -- 2.3.2
WARNING: multiple messages have this Message-ID (diff)
From: Robert Bragg <robert@sixbynine.org> To: intel-gfx@lists.freedesktop.org Cc: Peter Zijlstra <a.p.zijlstra@chello.nl>, David Airlie <airlied@linux.ie>, linux-api@vger.kernel.org, dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, Ingo Molnar <mingo@redhat.com>, Paul Mackerras <paulus@samba.org>, Arnaldo Carvalho de Melo <acme@kernel.org>, Daniel Vetter <daniel.vetter@intel.com> Subject: [RFC PATCH 02/11] perf: Add PERF_PMU_CAP_IS_DEVICE flag Date: Thu, 7 May 2015 15:15:45 +0100 [thread overview] Message-ID: <1431008154-6833-3-git-send-email-robert@sixbynine.org> (raw) In-Reply-To: <1431008154-6833-1-git-send-email-robert@sixbynine.org> The PERF_PMU_CAP_IS_DEVICE flag provides pmu drivers a way to declare that they only monitor device specific metrics and since they don't monitor any cpu metrics then perf should bypass any cpu centric security checks, as well as disallow cpu centric attributes. Signed-off-by: Robert Bragg <robert@sixbynine.org> --- include/linux/perf_event.h | 1 + kernel/events/core.c | 39 +++++++++++++++++++++++++++++++++------ 2 files changed, 34 insertions(+), 6 deletions(-) diff --git a/include/linux/perf_event.h b/include/linux/perf_event.h index 2b62198..1af35b4 100644 --- a/include/linux/perf_event.h +++ b/include/linux/perf_event.h @@ -166,6 +166,7 @@ struct perf_event; * pmu::capabilities flags */ #define PERF_PMU_CAP_NO_INTERRUPT 0x01 +#define PERF_PMU_CAP_IS_DEVICE 0x02 /** * struct pmu - generic performance monitoring unit diff --git a/kernel/events/core.c b/kernel/events/core.c index 38c240c..7218b01 100644 --- a/kernel/events/core.c +++ b/kernel/events/core.c @@ -3330,7 +3330,8 @@ find_get_context(struct pmu *pmu, struct task_struct *task, int cpu) if (!task) { /* Must be root to operate on a CPU event: */ - if (perf_paranoid_cpu() && !capable(CAP_SYS_ADMIN)) + if (!(pmu->capabilities & PERF_PMU_CAP_IS_DEVICE) && + perf_paranoid_cpu() && !capable(CAP_SYS_ADMIN)) return ERR_PTR(-EACCES); /* @@ -7475,11 +7476,6 @@ SYSCALL_DEFINE5(perf_event_open, if (err) return err; - if (!attr.exclude_kernel) { - if (perf_paranoid_kernel() && !capable(CAP_SYS_ADMIN)) - return -EACCES; - } - if (attr.freq) { if (attr.sample_freq > sysctl_perf_event_sample_rate) return -EINVAL; @@ -7538,6 +7534,37 @@ SYSCALL_DEFINE5(perf_event_open, goto err_cpus; } + if (event->pmu->capabilities & PERF_PMU_CAP_IS_DEVICE) { + + /* Don't allow cpu centric attributes... */ + if (event->attr.exclude_user || + event->attr.exclude_callchain_user || + event->attr.exclude_kernel || + event->attr.exclude_callchain_kernel || + event->attr.exclude_hv || + event->attr.exclude_idle || + event->attr.exclude_host || + event->attr.exclude_guest || + event->attr.mmap || + event->attr.comm || + event->attr.task) + return -EINVAL; + + if (attr.sample_type & + (PERF_SAMPLE_IP | + PERF_SAMPLE_TID | + PERF_SAMPLE_ADDR | + PERF_SAMPLE_CALLCHAIN | + PERF_SAMPLE_CPU | + PERF_SAMPLE_BRANCH_STACK | + PERF_SAMPLE_REGS_USER | + PERF_SAMPLE_STACK_USER)) + return -EINVAL; + } else if (!attr.exclude_kernel) { + if (perf_paranoid_kernel() && !capable(CAP_SYS_ADMIN)) + return -EACCES; + } + if (flags & PERF_FLAG_PID_CGROUP) { err = perf_cgroup_connect(pid, event, &attr, group_leader); if (err) { -- 2.3.2 _______________________________________________ Intel-gfx mailing list Intel-gfx@lists.freedesktop.org http://lists.freedesktop.org/mailman/listinfo/intel-gfx
next prev parent reply other threads:[~2015-05-07 14:19 UTC|newest] Thread overview: 63+ messages / expand[flat|nested] mbox.gz Atom feed top 2015-05-07 14:15 [RFC PATCH 00/11] drm/i915: Expose OA metrics via perf PMU Robert Bragg 2015-05-07 14:15 ` Robert Bragg 2015-05-07 14:15 ` [RFC PATCH 01/11] perf: export perf_event_overflow Robert Bragg 2015-05-07 14:15 ` Robert Bragg 2015-05-07 14:15 ` Robert Bragg [this message] 2015-05-07 14:15 ` [RFC PATCH 02/11] perf: Add PERF_PMU_CAP_IS_DEVICE flag Robert Bragg 2015-05-07 14:15 ` [RFC PATCH 03/11] perf: Add PERF_EVENT_IOC_FLUSH ioctl Robert Bragg 2015-05-07 14:15 ` Robert Bragg 2015-05-07 14:20 ` [Intel-gfx] " Chris Wilson 2015-05-07 14:20 ` Chris Wilson 2015-05-18 17:25 ` [RFC PATCH v2] " Robert Bragg 2015-05-18 17:25 ` Robert Bragg 2015-05-20 12:12 ` Ingo Molnar 2015-05-20 12:12 ` Ingo Molnar 2015-05-21 17:40 ` [RFC PATCH] perf: enable fsync to flush buffered samples Robert Bragg 2015-05-21 17:40 ` Robert Bragg 2015-05-07 14:15 ` [RFC PATCH 04/11] perf: Add a PERF_RECORD_DEVICE event type Robert Bragg 2015-05-07 14:15 ` Robert Bragg 2015-05-07 14:15 ` [RFC PATCH 05/11] perf: allow drivers more control over event logging Robert Bragg 2015-05-07 14:15 ` Robert Bragg 2015-05-07 14:15 ` [RFC PATCH 06/11] drm/i915: rename OACONTROL GEN7_OACONTROL Robert Bragg 2015-05-07 14:15 ` Robert Bragg 2015-05-07 14:15 ` [RFC PATCH 07/11] drm/i915: Expose PMU for Observation Architecture Robert Bragg 2015-05-07 14:15 ` Robert Bragg 2015-05-07 14:36 ` [Intel-gfx] " Chris Wilson 2015-05-07 14:36 ` Chris Wilson 2015-05-18 16:21 ` Robert Bragg 2015-05-07 14:58 ` [Intel-gfx] " Chris Wilson 2015-05-07 14:58 ` Chris Wilson 2015-05-18 16:36 ` Robert Bragg 2015-05-18 16:36 ` Robert Bragg 2015-05-18 17:17 ` [RFC PATCH v2] " Robert Bragg 2015-05-18 17:17 ` Robert Bragg 2015-05-18 17:21 ` [RFC PATCH] squash: be more careful stopping oacontrol updates Robert Bragg 2015-05-18 17:21 ` Robert Bragg 2015-05-07 14:15 ` [RFC PATCH 08/11] drm/i915: add OA config for 3D render counters Robert Bragg 2015-05-07 14:15 ` Robert Bragg 2015-05-07 14:15 ` [RFC PATCH 09/11] drm/i915: Add dev.i915.oa_event_paranoid sysctl option Robert Bragg 2015-05-07 14:15 ` Robert Bragg 2015-05-07 14:15 ` [RFC PATCH 10/11] drm/i915: report OA buf overrun + report lost status Robert Bragg 2015-05-07 14:15 ` Robert Bragg 2015-05-07 14:15 ` [RFC PATCH 11/11] WIP: drm/i915: constrain unit gating while using OA Robert Bragg 2015-05-07 14:15 ` Robert Bragg 2015-05-08 16:21 ` [RFC PATCH 00/11] drm/i915: Expose OA metrics via perf PMU Peter Zijlstra 2015-05-08 16:21 ` Peter Zijlstra 2015-05-18 17:29 ` Robert Bragg 2015-05-18 17:29 ` Robert Bragg 2015-05-08 16:24 ` Peter Zijlstra 2015-05-08 16:24 ` Peter Zijlstra 2015-05-15 1:07 ` Robert Bragg 2015-05-15 1:07 ` Robert Bragg 2015-05-19 14:53 ` Peter Zijlstra 2015-05-19 14:53 ` Peter Zijlstra 2015-05-20 23:17 ` Robert Bragg 2015-05-20 23:17 ` Robert Bragg 2015-05-21 8:24 ` [Intel-gfx] " Daniel Vetter 2015-05-21 8:24 ` Daniel Vetter 2015-05-27 15:39 ` Peter Zijlstra 2015-05-27 15:39 ` Peter Zijlstra 2015-05-27 16:41 ` Ingo Molnar 2015-05-27 16:41 ` Ingo Molnar 2015-06-04 18:53 ` [Intel-gfx] " Robert Bragg 2015-06-04 18:53 ` Robert Bragg
Reply instructions: You may reply publicly to this message via plain-text email using any one of the following methods: * Save the following mbox file, import it into your mail client, and reply-to-all from there: mbox Avoid top-posting and favor interleaved quoting: https://en.wikipedia.org/wiki/Posting_style#Interleaved_style * Reply using the --to, --cc, and --in-reply-to switches of git-send-email(1): git send-email \ --in-reply-to=1431008154-6833-3-git-send-email-robert@sixbynine.org \ --to=robert@sixbynine.org \ --cc=a.p.zijlstra@chello.nl \ --cc=acme@kernel.org \ --cc=airlied@linux.ie \ --cc=daniel.vetter@intel.com \ --cc=dri-devel@lists.freedesktop.org \ --cc=intel-gfx@lists.freedesktop.org \ --cc=jani.nikula@linux.intel.com \ --cc=linux-api@vger.kernel.org \ --cc=linux-kernel@vger.kernel.org \ --cc=mingo@redhat.com \ --cc=paulus@samba.org \ /path/to/YOUR_REPLY https://kernel.org/pub/software/scm/git/docs/git-send-email.html * If your mail client supports setting the In-Reply-To header via mailto: links, try the mailto: linkBe sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes, see mirroring instructions on how to clone and mirror all data and code used by this external index.