lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20150706105517.GZ3644@twins.programming.kicks-ass.net>
Date:	Mon, 6 Jul 2015 12:55:17 +0200
From:	Peter Zijlstra <peterz@...radead.org>
To:	"Liang, Kan" <kan.liang@...el.com>
Cc:	Vince Weaver <vincent.weaver@...ne.edu>,
	"linux-kernel@...r.kernel.org" <linux-kernel@...r.kernel.org>,
	Ingo Molnar <mingo@...hat.com>,
	Arnaldo Carvalho de Melo <acme@...nel.org>,
	Stephane Eranian <eranian@...il.com>
Subject: Re: perf: fuzzer triggered warning in intel_pmu_drain_pebs_nhm()

On Fri, Jul 03, 2015 at 08:08:27PM +0000, Liang, Kan wrote:
> If we cleared the last bit, we not only drain the buffer but also decrease 
> the event->ctx->pmu, which is used to flush the PEBS buffer during
> context switches.
> We need to disable cpuc->pebs_enabled before changing 
> event->ctx->pmu as below.
> 

Indeed, mind sending a proper patch so I can press 'A' on it?

> diff --git a/arch/x86/kernel/cpu/perf_event_intel_ds.c 
> b/arch/x86/kernel/cpu/perf_event_intel_ds.c
> index 71fc402..76285c1 100644
> --- a/arch/x86/kernel/cpu/perf_event_intel_ds.c
> +++ b/arch/x86/kernel/cpu/perf_event_intel_ds.c
> @@ -754,6 +754,11 @@ void intel_pmu_pebs_disable(struct 
> perf_event *event)
>         struct cpu_hw_events *cpuc = this_cpu_ptr(&cpu_hw_events);
>         struct hw_perf_event *hwc = &event->hw;
>         struct debug_store *ds = cpuc->ds;
> +       bool large_pebs = ds->pebs_interrupt_threshold >
> +                         ds->pebs_buffer_base + x86_pmu.pebs_record_size;
> +
> +       if (large_pebs)
> +               intel_pmu_drain_pebs_buffer();
> 
>         cpuc->pebs_enabled &= ~(1ULL << hwc->idx);
> 
> @@ -762,12 +767,8 @@ void intel_pmu_pebs_disable(struct 
> perf_event *event)
>         else if (event->hw.flags & PERF_X86_EVENT_PEBS_ST)
>                 cpuc->pebs_enabled &= ~(1ULL << 63);
> 
> -       if (ds->pebs_interrupt_threshold >
> -           ds->pebs_buffer_base + x86_pmu.pebs_record_size) {
> -               intel_pmu_drain_pebs_buffer();
> -               if (!pebs_is_enabled(cpuc))
> -                       perf_sched_cb_dec(event->ctx->pmu);
> -       }
> +       if (large_pebs && !pebs_is_enabled(cpuc))
> +               perf_sched_cb_dec(event->ctx->pmu);
> 
>         if (cpuc->enabled)
>                 wrmsrl(MSR_IA32_PEBS_ENABLE, cpuc->pebs_enabled);
> 
> 
> 
> Thanks,
> Kan
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@...r.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ