From patchwork Tue Aug 3 15:58:21 2021 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Martin Doucha X-Patchwork-Id: 1513000 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@bilbo.ozlabs.org Authentication-Results: ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=lists.linux.it (client-ip=2001:1418:10:5::2; helo=picard.linux.it; envelope-from=ltp-bounces+incoming=patchwork.ozlabs.org@lists.linux.it; receiver=) Authentication-Results: ozlabs.org; dkim=fail reason="signature verification failed" (1024-bit key; unprotected) header.d=suse.cz header.i=@suse.cz header.a=rsa-sha256 header.s=susede2_rsa header.b=hOyzpoN6; dkim=fail reason="signature verification failed" header.d=suse.cz header.i=@suse.cz header.a=ed25519-sha256 header.s=susede2_ed25519 header.b=FJ1xYu/B; dkim-atps=neutral Received: from picard.linux.it (picard.linux.it [IPv6:2001:1418:10:5::2]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits)) (No client certificate requested) by ozlabs.org (Postfix) with ESMTPS id 4GfKKf6dJ2z9sPf for ; Wed, 4 Aug 2021 01:58:29 +1000 (AEST) Received: from picard.linux.it (localhost [IPv6:::1]) by picard.linux.it (Postfix) with ESMTP id 93B693C8140 for ; Tue, 3 Aug 2021 17:58:26 +0200 (CEST) X-Original-To: ltp@lists.linux.it Delivered-To: ltp@picard.linux.it Received: from in-2.smtp.seeweb.it (in-2.smtp.seeweb.it [IPv6:2001:4b78:1:20::2]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits)) (No client certificate requested) by picard.linux.it (Postfix) with ESMTPS id 776673C55BB for ; Tue, 3 Aug 2021 17:58:24 +0200 (CEST) Received: from smtp-out2.suse.de (smtp-out2.suse.de [195.135.220.29]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by in-2.smtp.seeweb.it (Postfix) with ESMTPS id D57316003FE for ; Tue, 3 Aug 2021 17:58:23 +0200 (CEST) Received: from imap2.suse-dmz.suse.de (imap2.suse-dmz.suse.de [192.168.254.74]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-521) server-digest SHA512) (No client certificate requested) by smtp-out2.suse.de (Postfix) with ESMTPS id 1179C200E9 for ; Tue, 3 Aug 2021 15:58:23 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.cz; s=susede2_rsa; t=1628006303; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc: mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=RaOe6k33SsZgcQvUkxR32frkLvc2vWdH/OsAUFgwf+g=; b=hOyzpoN6VT/JXBRSuhsm7FbTg5kwokFrbYTjQtI/Sbv/E9eHRReM/OctyXUWdu0A0U9EgL J01leBefoFzPgq4ssq7NGsG6Ec3p1n65YHnehBS4zNIrOgPqrTEBTv6xv5yu7LrT8v0UIm cM/dCj3ggiR4tBtKAh6ZQxYIA8ePM8I= DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=suse.cz; s=susede2_ed25519; t=1628006303; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc: mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=RaOe6k33SsZgcQvUkxR32frkLvc2vWdH/OsAUFgwf+g=; b=FJ1xYu/B/C+HV13QJoevyhjYHBeDkYpniTJfH0DO6YIAIrYMyvK/81Ogu5j3iihCUeIxSQ OeqYjdmGOZ6xBJAQ== Received: from imap2.suse-dmz.suse.de (imap2.suse-dmz.suse.de [192.168.254.74]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-521) server-digest SHA512) (No client certificate requested) by imap2.suse-dmz.suse.de (Postfix) with ESMTPS id E47AA13B0A for ; Tue, 3 Aug 2021 15:58:22 +0000 (UTC) Received: from dovecot-director2.suse.de ([192.168.254.65]) by imap2.suse-dmz.suse.de with ESMTPSA id LTHtNJ5nCWHYHAAAMHmgww (envelope-from ) for ; Tue, 03 Aug 2021 15:58:22 +0000 From: Martin Doucha To: ltp@lists.linux.it Date: Tue, 3 Aug 2021 17:58:21 +0200 Message-Id: <20210803155822.1973-1-mdoucha@suse.cz> X-Mailer: git-send-email 2.32.0 MIME-Version: 1.0 X-Virus-Scanned: clamav-milter 0.102.4 at in-2.smtp.seeweb.it X-Virus-Status: Clean X-Spam-Status: No, score=0.1 required=7.0 tests=DKIM_SIGNED,DKIM_VALID, DKIM_VALID_AU,DKIM_VALID_EF,SPF_HELO_NONE,SPF_PASS autolearn=disabled version=3.4.4 X-Spam-Checker-Version: SpamAssassin 3.4.4 (2020-01-24) on in-2.smtp.seeweb.it Subject: [LTP] [PATCH v2 1/2] Add test for CVE 2020-25704 X-BeenThere: ltp@lists.linux.it X-Mailman-Version: 2.1.29 Precedence: list List-Id: Linux Test Project List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: ltp-bounces+incoming=patchwork.ozlabs.org@lists.linux.it Sender: "ltp" Fixes #740 Signed-off-by: Martin Doucha --- Changes since v1: - Use memory statistics from /proc/meminfo instead of sysinfo() runtest/cve | 2 + runtest/syscalls | 3 + .../syscalls/perf_event_open/.gitignore | 1 + .../perf_event_open/perf_event_open.h | 39 +++++++++ .../perf_event_open/perf_event_open03.c | 84 +++++++++++++++++++ 5 files changed, 129 insertions(+) create mode 100644 testcases/kernel/syscalls/perf_event_open/perf_event_open.h create mode 100644 testcases/kernel/syscalls/perf_event_open/perf_event_open03.c diff --git a/runtest/cve b/runtest/cve index 5b7bf5323..e0d3723de 100644 --- a/runtest/cve +++ b/runtest/cve @@ -67,3 +67,5 @@ cve-2020-25705 icmp_rate_limit01 cve-2020-29373 io_uring02 cve-2021-3444 bpf_prog05 cve-2021-26708 vsock01 +# Tests below may cause kernel memory leak +cve-2020-25704 perf_event_open03 diff --git a/runtest/syscalls b/runtest/syscalls index b379b2d90..5e3ac517f 100644 --- a/runtest/syscalls +++ b/runtest/syscalls @@ -1737,3 +1737,6 @@ membarrier01 membarrier01 io_uring01 io_uring01 io_uring02 io_uring02 + +# Tests below may cause kernel memory leak +perf_event_open03 perf_event_open03 diff --git a/testcases/kernel/syscalls/perf_event_open/.gitignore b/testcases/kernel/syscalls/perf_event_open/.gitignore index 057690063..a1e5987b6 100644 --- a/testcases/kernel/syscalls/perf_event_open/.gitignore +++ b/testcases/kernel/syscalls/perf_event_open/.gitignore @@ -1,2 +1,3 @@ /perf_event_open01 /perf_event_open02 +/perf_event_open03 diff --git a/testcases/kernel/syscalls/perf_event_open/perf_event_open.h b/testcases/kernel/syscalls/perf_event_open/perf_event_open.h new file mode 100644 index 000000000..02f0dd72e --- /dev/null +++ b/testcases/kernel/syscalls/perf_event_open/perf_event_open.h @@ -0,0 +1,39 @@ +/* SPDX-License-Identifier: GPL-2.0-or-later */ +/* + * Copyright (c) 2021 SUSE LLC + * + * Common definitions for perf_event_open tests + */ + +#ifndef _PERF_EVENT_OPEN_H +#define _PERF_EVENT_OPEN_H + +#include +#include +#include + +static int perf_event_open(struct perf_event_attr *event, pid_t pid, + int cpu, int group_fd, unsigned long flags) +{ + int ret; + + ret = tst_syscall(__NR_perf_event_open, event, pid, cpu, + group_fd, flags); + + if (ret != -1) + return ret; + + tst_res(TINFO, "%s event.type: %"PRIu32 + ", event.config: %"PRIu64, __func__, (uint32_t)event->type, + (uint64_t)event->config); + if (errno == ENOENT || errno == ENODEV) { + tst_brk(TCONF | TERRNO, "%s type/config not supported", + __func__); + } + tst_brk(TBROK | TERRNO, "%s failed", __func__); + + /* unreachable */ + return -1; +} + +#endif /* _PERF_EVENT_OPEN_H */ diff --git a/testcases/kernel/syscalls/perf_event_open/perf_event_open03.c b/testcases/kernel/syscalls/perf_event_open/perf_event_open03.c new file mode 100644 index 000000000..f58bea79e --- /dev/null +++ b/testcases/kernel/syscalls/perf_event_open/perf_event_open03.c @@ -0,0 +1,84 @@ +// SPDX-License-Identifier: GPL-2.0-or-later +/* + * Copyright (c) 2021 SUSE LLC + * + * CVE-2020-25704 + * + * Check for memory leak in PERF_EVENT_IOC_SET_FILTER ioctl command. Fixed in: + * + * commit 7bdb157cdebbf95a1cd94ed2e01b338714075d00 + * Author: kiyin(尹亮) + * Date: Wed Nov 4 08:23:22 2020 +0300 + * + * perf/core: Fix a memory leak in perf_event_parse_addr_filter() + */ + +#include "config.h" +#include "tst_test.h" +#include "lapi/syscalls.h" + +#if HAVE_PERF_EVENT_ATTR +#include "perf_event_open.h" + +#define INTEL_PT_PATH "/sys/bus/event_source/devices/intel_pt/type" + +static int fd = -1; + +static void setup(void) +{ + struct perf_event_attr ev = { + .size = sizeof(struct perf_event_attr), + .exclude_kernel = 1, + .exclude_hv = 1, + .exclude_idle = 1 + }; + + /* intel_pt is currently the only event source that supports filters */ + if (access(INTEL_PT_PATH, F_OK)) + tst_brk(TCONF, "intel_pt is not available"); + + SAFE_FILE_SCANF(INTEL_PT_PATH, "%d", &ev.type); + fd = perf_event_open(&ev, getpid(), -1, -1, 0); +} + +static void run(void) +{ + long diff; + int i; + + diff = SAFE_READ_MEMINFO("MemAvailable:"); + + /* leak about 100MB of RAM */ + for (i = 0; i < 12000000; i++) + ioctl(fd, PERF_EVENT_IOC_SET_FILTER, "filter,0/0@abcd"); + + diff -= SAFE_READ_MEMINFO("MemAvailable:"); + + if (diff > 50 * 1024) + tst_res(TFAIL, "Likely kernel memory leak detected"); + else + tst_res(TPASS, "No memory leak found"); +} + +static void cleanup(void) +{ + if (fd >= 0) + SAFE_CLOSE(fd); +} + +static struct tst_test test = { + .test_all = run, + .setup = setup, + .cleanup = cleanup, + .needs_root = 1, + .tags = (const struct tst_tag[]) { + {"linux-git", "7bdb157cdebb"}, + {"CVE", "2020-25704"}, + {} + } +}; + +#else /* HAVE_PERF_EVENT_ATTR */ +TST_TEST_TCONF("This system doesn't have or " + "struct perf_event_attr is not defined."); +#endif From patchwork Tue Aug 3 15:58:22 2021 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Martin Doucha X-Patchwork-Id: 1513001 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@bilbo.ozlabs.org Authentication-Results: ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=lists.linux.it (client-ip=2001:1418:10:5::2; helo=picard.linux.it; envelope-from=ltp-bounces+incoming=patchwork.ozlabs.org@lists.linux.it; receiver=) Authentication-Results: ozlabs.org; dkim=fail reason="signature verification failed" (1024-bit key; unprotected) header.d=suse.cz header.i=@suse.cz header.a=rsa-sha256 header.s=susede2_rsa header.b=zAyTU56m; dkim=fail reason="signature verification failed" header.d=suse.cz header.i=@suse.cz header.a=ed25519-sha256 header.s=susede2_ed25519 header.b=Jx5KPFO4; dkim-atps=neutral Received: from picard.linux.it (picard.linux.it [IPv6:2001:1418:10:5::2]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits)) (No client certificate requested) by ozlabs.org (Postfix) with ESMTPS id 4GfKKq2yvCz9sPf for ; Wed, 4 Aug 2021 01:58:39 +1000 (AEST) Received: from picard.linux.it (localhost [IPv6:::1]) by picard.linux.it (Postfix) with ESMTP id E560D3C57C1 for ; Tue, 3 Aug 2021 17:58:36 +0200 (CEST) X-Original-To: ltp@lists.linux.it Delivered-To: ltp@picard.linux.it Received: from in-7.smtp.seeweb.it (in-7.smtp.seeweb.it [IPv6:2001:4b78:1:20::7]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits)) (No client certificate requested) by picard.linux.it (Postfix) with ESMTPS id E7B9B3C55BB for ; Tue, 3 Aug 2021 17:58:24 +0200 (CEST) Received: from smtp-out2.suse.de (smtp-out2.suse.de [195.135.220.29]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by in-7.smtp.seeweb.it (Postfix) with ESMTPS id D19D520014C for ; Tue, 3 Aug 2021 17:58:23 +0200 (CEST) Received: from imap2.suse-dmz.suse.de (imap2.suse-dmz.suse.de [192.168.254.74]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-521) server-digest SHA512) (No client certificate requested) by smtp-out2.suse.de (Postfix) with ESMTPS id 20CD5200EA for ; Tue, 3 Aug 2021 15:58:23 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.cz; s=susede2_rsa; t=1628006303; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc: mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=1rSmvm1AA52AFwe1qxJlhqwhW4endIEUwBixBIjpIdI=; b=zAyTU56mMeod699bW8ep43q7XjQO5BvlIAyVgEbAYmC/z57Z/Uln54qMw77FUXJO5BEDpU HgCHUW1yMEPdHC834F3mRx3rVGYT6ZzJ9ygIMcS8K89Sqi7Kx/nYhr3TupEZKrRVCJZvYQ d7C9XsoZGTf7LXhTH3PnX4UObYSbSbg= DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=suse.cz; s=susede2_ed25519; t=1628006303; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc: mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=1rSmvm1AA52AFwe1qxJlhqwhW4endIEUwBixBIjpIdI=; b=Jx5KPFO4WloJKmx8yJBDuTbPG1HHfTP2DB0CNygsrpMI2229fPh6pR2iSeGxRdNBvzZBQS vzjkvkZuM4AWh2Cg== Received: from imap2.suse-dmz.suse.de (imap2.suse-dmz.suse.de [192.168.254.74]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-521) server-digest SHA512) (No client certificate requested) by imap2.suse-dmz.suse.de (Postfix) with ESMTPS id 05B9C13B0E for ; Tue, 3 Aug 2021 15:58:23 +0000 (UTC) Received: from dovecot-director2.suse.de ([192.168.254.65]) by imap2.suse-dmz.suse.de with ESMTPSA id sAdwAJ9nCWHYHAAAMHmgww (envelope-from ) for ; Tue, 03 Aug 2021 15:58:23 +0000 From: Martin Doucha To: ltp@lists.linux.it Date: Tue, 3 Aug 2021 17:58:22 +0200 Message-Id: <20210803155822.1973-2-mdoucha@suse.cz> X-Mailer: git-send-email 2.32.0 In-Reply-To: <20210803155822.1973-1-mdoucha@suse.cz> References: <20210803155822.1973-1-mdoucha@suse.cz> MIME-Version: 1.0 X-Virus-Scanned: clamav-milter 0.102.4 at in-7.smtp.seeweb.it X-Virus-Status: Clean X-Spam-Status: No, score=0.1 required=7.0 tests=DKIM_SIGNED,DKIM_VALID, DKIM_VALID_AU,DKIM_VALID_EF,SPF_HELO_NONE,SPF_PASS autolearn=disabled version=3.4.4 X-Spam-Checker-Version: SpamAssassin 3.4.4 (2020-01-24) on in-7.smtp.seeweb.it Subject: [LTP] [PATCH v2 2/2] perf_event_open02: Use common perf_event_open() wrapper X-BeenThere: ltp@lists.linux.it X-Mailman-Version: 2.1.29 Precedence: list List-Id: Linux Test Project List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: ltp-bounces+incoming=patchwork.ozlabs.org@lists.linux.it Sender: "ltp" Signed-off-by: Martin Doucha --- Changes since v1: None .../perf_event_open/perf_event_open02.c | 28 +------------------ 1 file changed, 1 insertion(+), 27 deletions(-) diff --git a/testcases/kernel/syscalls/perf_event_open/perf_event_open02.c b/testcases/kernel/syscalls/perf_event_open/perf_event_open02.c index eead421ac..7200d35e3 100644 --- a/testcases/kernel/syscalls/perf_event_open/perf_event_open02.c +++ b/testcases/kernel/syscalls/perf_event_open/perf_event_open02.c @@ -29,7 +29,6 @@ #define _GNU_SOURCE #include -#include #include #include #include @@ -47,8 +46,7 @@ #include "lapi/syscalls.h" #if HAVE_PERF_EVENT_ATTR -#include -#include +#include "perf_event_open.h" #define MAX_CTRS 1000 @@ -67,30 +65,6 @@ static int tsk0 = -1, hwfd[MAX_CTRS], tskfd[MAX_CTRS]; static int volatile work_done; static unsigned int est_loops; -static int perf_event_open(struct perf_event_attr *event, pid_t pid, - int cpu, int group_fd, unsigned long flags) -{ - int ret; - - ret = tst_syscall(__NR_perf_event_open, event, pid, cpu, - group_fd, flags); - - if (ret != -1) - return ret; - - tst_res(TINFO, "perf_event_open event.type: %"PRIu32 - ", event.config: %"PRIu64, (uint32_t)event->type, - (uint64_t)event->config); - if (errno == ENOENT || errno == ENODEV) { - tst_brk(TCONF | TERRNO, - "perf_event_open type/config not supported"); - } - tst_brk(TBROK | TERRNO, "perf_event_open failed"); - - /* unreachable */ - return -1; -} - static void all_counters_set(int state) { if (prctl(state) == -1)