Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1237161 > unrolled thread

[PATCH v1] perf report: Fix owner error when reading perf.data

Started byTaeung Song <treeze.taeung@gmail.com>
First post2015-10-01 11:10 +0200
Last post2015-10-01 15:00 +0200
Articles 4 — 3 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH v1] perf report: Fix owner error when reading perf.data Taeung Song <treeze.taeung@gmail.com> - 2015-10-01 11:10 +0200
    Re: [PATCH v1] perf report: Fix owner error when reading perf.data Ingo Molnar <mingo@kernel.org> - 2015-10-01 11:20 +0200
      Re: [PATCH v1] perf report: Fix owner error when reading perf.data Taeung Song <treeze.taeung@gmail.com> - 2015-10-01 14:30 +0200
        Re: [PATCH v1] perf report: Fix owner error when reading perf.data Arnaldo Carvalho de Melo <acme@kernel.org> - 2015-10-01 15:00 +0200

#1237161 — [PATCH v1] perf report: Fix owner error when reading perf.data

FromTaeung Song <treeze.taeung@gmail.com>
Date2015-10-01 11:10 +0200
Subject[PATCH v1] perf report: Fix owner error when reading perf.data
Message-ID<qeI2e-7Z7-13@gated-at.bofh.it>
If perf.data file is owned by some user,
it can't be read even if current user is root.
A 'st_uid' from fstat() is user ID of the file owner.
Therefore use getuid() instead of st_uid to check if
user of the calling 'perf' process is root or not.

Signed-off-by: Taeung Song <treeze.taeung@gmail.com>
---
 tools/perf/util/data.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/tools/perf/util/data.c b/tools/perf/util/data.c
index 1921942..91ebe4e 100644
--- a/tools/perf/util/data.c
+++ b/tools/perf/util/data.c
@@ -67,7 +67,7 @@ static int open_file_read(struct perf_data_file *file)
 	if (fstat(fd, &st) < 0)
 		goto out_close;
 
-	if (!file->force && st.st_uid && (st.st_uid != geteuid())) {
+	if (!file->force && getuid() && (st.st_uid != geteuid())) {
 		pr_err("File %s not owned by current user or root (use -f to override)\n",
 		       file->path);
 		goto out_close;
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [next] | [standalone]


#1237170

FromIngo Molnar <mingo@kernel.org>
Date2015-10-01 11:20 +0200
Message-ID<qeIbU-8aj-25@gated-at.bofh.it>
In reply to#1237161
* Taeung Song <treeze.taeung@gmail.com> wrote:

> If perf.data file is owned by some user,
> it can't be read even if current user is root.

That's intentional: to keep a malicious local user from passing a perf.data to 
root who does 'perf report' accidentally or in the wrong directory.

root can copy or chown it to himself - or we could add some --really-force flag 
for that.

Thanks,

	Ingo
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1237378

FromTaeung Song <treeze.taeung@gmail.com>
Date2015-10-01 14:30 +0200
Message-ID<qeL9N-3Vj-27@gated-at.bofh.it>
In reply to#1237170
> On Oct 1, 2015, at 6:10 PM, Ingo Molnar <mingo@kernel.org> wrote:
> 
> 
> * Taeung Song <treeze.taeung@gmail.com> wrote:
> 
>> If perf.data file is owned by some user,
>> it can't be read even if current user is root.
> 
> That's intentional: to keep a malicious local user from passing a perf.data to 
> root who does 'perf report' accidentally or in the wrong directory.
> 
> root can copy or chown it to himself - or we could add some --really-force flag 
> for that.

I got it.
I didn’t know its intention.

Thanks,
Taeung

> 
> Thanks,
> 
> 	Ingo

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1237405

FromArnaldo Carvalho de Melo <acme@kernel.org>
Date2015-10-01 15:00 +0200
Message-ID<qeLCO-4xp-33@gated-at.bofh.it>
In reply to#1237378
Em Thu, Oct 01, 2015 at 09:26:26PM +0900, Taeung Song escreveu:
> > On Oct 1, 2015, at 6:10 PM, Ingo Molnar <mingo@kernel.org> wrote:
> > * Taeung Song <treeze.taeung@gmail.com> wrote:

> >> If perf.data file is owned by some user,
> >> it can't be read even if current user is root.

> > That's intentional: to keep a malicious local user from passing a perf.data to 
> > root who does 'perf report' accidentally or in the wrong directory.

> > root can copy or chown it to himself - or we could add some --really-force flag 
> > for that.

> I got it.
> I didn’t know its intention.

Feel free to transform Ingo's comment in a C source code comment right
besides the code doing that check, this way when someone else thinks
this is wrong, like you did, the comment will clarify things.

- Arnaldo
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web