]> git.ipfire.org Git - thirdparty/linux.git/commitdiff
drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE
authorGang Ba <Gang.Ba@amd.com>
Tue, 14 Jul 2026 19:08:57 +0000 (15:08 -0400)
committerAlex Deucher <alexander.deucher@amd.com>
Tue, 28 Jul 2026 23:59:37 +0000 (19:59 -0400)
Prevent unauthorized termination of active GPU debug sessions.
Previously, users with /dev/kfd access could terminate another process's
debug session without proper ownership or ptrace authorization.

Signed-off-by: Gang Ba <Gang.Ba@amd.com>
Reviewed-by: Kent Russell <kent.russell@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit 4db4c5ffd5585b72622ecf6ffedf2da258ee23f5)
Cc: stable@vger.kernel.org
drivers/gpu/drm/amd/amdkfd/kfd_chardev.c

index c7edebd2fd8a4ac07e22f94e8cc953110d05a1c4..e1689b3d2add988aaf31d212cf56e7a8faff0c35 100644 (file)
@@ -3109,10 +3109,14 @@ static int kfd_ioctl_set_debug_trap(struct file *filep, struct kfd_process *p, v
                goto out;
        }
 
-       /* Check if target is still PTRACED. */
+       /*
+        * Verify debugger has permission to debug target process.
+        * For cross-process debugging, require active ptrace relationship.
+        * This applies to ALL operations to prevent unauthorized interference.
+        */
        rcu_read_lock();
-       if (target != p && args->op != KFD_IOC_DBG_TRAP_DISABLE
-                               && ptrace_parent(target->lead_thread) != current) {
+       if (target != p && ptrace_parent(target->lead_thread) != current
+                       && target->debugger_process != p) {
                pr_err("PID %i is not PTRACED and cannot be debugged\n", args->pid);
                r = -EPERM;
        }