Received: by 2002:a05:6a10:6744:0:0:0:0 with SMTP id w4csp3369853pxu; Mon, 19 Oct 2020 10:19:12 -0700 (PDT) X-Google-Smtp-Source: ABdhPJxvOIyXyCW6BCSIvZWkRcvXRkL0Tsn+LKCU0s8DKUXTf4u+3BFfLwDiSU2QoTB0Drvq67+D X-Received: by 2002:a17:906:490e:: with SMTP id b14mr900078ejq.268.1603127952080; Mon, 19 Oct 2020 10:19:12 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1603127952; cv=none; d=google.com; s=arc-20160816; b=FpKWriz69t57SlmsXVOxmoBGJT5Bk72uVlyP/FKoxfIKqV6ulxL6lqnYDlYwzSTvKo T4B453iKaJsHDgGWH3vH3miev7x0JO3rMTNJ7SNe0yBlx8fKEf+6pntQZ2if2nDqng6+ mhLzoQWi/t95gSU+pNvAhgcBcm1D9brxD6LYEHMPMxGEYTuiLR7sPOq26yPQmGR+jwE5 u2E1I4mnxew3KN/c9MjMjqhcGcI+PwClODtuzJIsLSZnsCe3ewa0Z6LYtETbU9sUu/WU +noVHATAlgIcO1XrwLl9Aenb1avZrx8kLNqrAONQIhGaEvitUIbHYnCzYcrIrmq78Bze Jdsw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:content-language :in-reply-to:mime-version:user-agent:date:message-id:organization :references:cc:to:from:subject:ironport-sdr:ironport-sdr; bh=HeDvlYHR8DRZCWLetu6/J/tWjZV6LE+z2vfKtORJMCg=; b=UobKHjfppRmA5JmNX+1zbbTU/t7Bpau9DwVGidLRzBfizM4z/QxXw2o4Joa3kUGl/r 7yGycdOP6WXwgRcWI+thyAuD2X/3K/VLJWOq4fMrlj/2/fOTBlC10RxmMJ9Tb1juP586 m4+lfAcp7mw+/Wq0x2UF27DLPqDCMtE71lbuvAR4g3cgkX++pVSzIKEDTAMMtMGG8LZf qfluATh/G9cfbAcfh5yWwMuQi58OY3odw0b0UPk3nabC6FdGrkfwwvfhj3jsijS0wVLt Sl+iWkqzWKGmje/Yc1BZf84wWjtKYvLU6pelVS9UPFndHCOScZfN6RvKTgOPg5ZUGOxE ZwPQ== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=intel.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id y19si510112eje.678.2020.10.19.10.18.49; Mon, 19 Oct 2020 10:19:12 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=intel.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1730921AbgJSRQx (ORCPT + 99 others); Mon, 19 Oct 2020 13:16:53 -0400 Received: from mga14.intel.com ([192.55.52.115]:8454 "EHLO mga14.intel.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1729916AbgJSRQx (ORCPT ); Mon, 19 Oct 2020 13:16:53 -0400 IronPort-SDR: EpxahJH0l/WkMo5vwlSjdufRMSwRZIPGMoN4qWf4GWt3p9vuCsD7sdOwpBFu1R4b4jIiryH6Td K8KQdyt1P1dA== X-IronPort-AV: E=McAfee;i="6000,8403,9779"; a="166292262" X-IronPort-AV: E=Sophos;i="5.77,395,1596524400"; d="scan'208";a="166292262" X-Amp-Result: SKIPPED(no attachment in message) X-Amp-File-Uploaded: False Received: from orsmga001.jf.intel.com ([10.7.209.18]) by fmsmga103.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 19 Oct 2020 10:16:52 -0700 IronPort-SDR: bDp1p7SGYdaawZ5eDiABL+vAf89c1vOk/gdxqZ52VSsP6zTzTl8d5FG6oRXiOpd4glEGA17JSi H4SwuwhP/iXg== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="5.77,395,1596524400"; d="scan'208";a="392091231" Received: from linux.intel.com ([10.54.29.200]) by orsmga001.jf.intel.com with ESMTP; 19 Oct 2020 10:16:52 -0700 Received: from [10.249.225.38] (abudanko-mobl.ccr.corp.intel.com [10.249.225.38]) by linux.intel.com (Postfix) with ESMTP id 158C8580127; Mon, 19 Oct 2020 10:16:49 -0700 (PDT) Subject: [PATCH v1 1/2] doc/admin-guide: note credentials consolidation under CAP_PERFMON From: Alexey Budankov To: Arnaldo Carvalho de Melo Cc: Jiri Olsa , Namhyung Kim , Alexander Shishkin , Andi Kleen , Peter Zijlstra , Ingo Molnar , linux-kernel , "linux-security-module@vger.kernel.org" , "linux-doc@vger.kernel.org" , linux-man@vger.kernel.org References: <161a51d3-7cdf-f9ee-c438-42bb7404693e@linux.intel.com> Organization: Intel Corp. Message-ID: <2b1a92a1-84ce-5c70-837d-8ffe96849588@linux.intel.com> Date: Mon, 19 Oct 2020 20:16:49 +0300 User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:68.0) Gecko/20100101 Thunderbird/68.12.1 MIME-Version: 1.0 In-Reply-To: <161a51d3-7cdf-f9ee-c438-42bb7404693e@linux.intel.com> Content-Type: text/plain; charset=utf-8 Content-Language: en-US Content-Transfer-Encoding: 7bit Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Add note that starting from Linux v5.9 CAP_PERFMON Linux capability is enough to conduct performance monitoring and observability using perf_events API. Signed-off-by: Alexey Budankov --- Documentation/admin-guide/perf-security.rst | 13 ++++++++----- 1 file changed, 8 insertions(+), 5 deletions(-) diff --git a/Documentation/admin-guide/perf-security.rst b/Documentation/admin-guide/perf-security.rst index 1307b5274a0f..57a65e27eeb9 100644 --- a/Documentation/admin-guide/perf-security.rst +++ b/Documentation/admin-guide/perf-security.rst @@ -84,11 +84,14 @@ capabilities then providing the process with CAP_PERFMON capability singly is recommended as the preferred secure approach to resolve double access denial logging related to usage of performance monitoring and observability. -Unprivileged processes using perf_events system call are also subject -for PTRACE_MODE_READ_REALCREDS ptrace access mode check [7]_ , whose -outcome determines whether monitoring is permitted. So unprivileged -processes provided with CAP_SYS_PTRACE capability are effectively -permitted to pass the check. +Prior Linux v5.9 unprivileged processes using perf_events system call +are also subject for PTRACE_MODE_READ_REALCREDS ptrace access mode check +[7]_ , whose outcome determines whether monitoring is permitted. +So unprivileged processes provided with CAP_SYS_PTRACE capability are +effectively permitted to pass the check. Starting from Linux v5.9 +CAP_SYS_PTRACE capability is not required and CAP_PERFMON is enough to +be provided for processes to make performance monitoring and observability +operations. Other capabilities being granted to unprivileged processes can effectively enable capturing of additional data required for later -- 2.24.1