Prevent unauthorized termination of active GPU debug sessions.
Previously, users with /dev/kfd access could terminate another process's
debug session without proper ownership or ptrace authorization.

Signed-off-by: Gang Ba <[email protected]>
---
 drivers/gpu/drm/amd/amdkfd/kfd_chardev.c | 10 +++++++---
 1 file changed, 7 insertions(+), 3 deletions(-)

diff --git a/drivers/gpu/drm/amd/amdkfd/kfd_chardev.c 
b/drivers/gpu/drm/amd/amdkfd/kfd_chardev.c
index 7d058d93e219..05dd0b6a87f0 100644
--- a/drivers/gpu/drm/amd/amdkfd/kfd_chardev.c
+++ b/drivers/gpu/drm/amd/amdkfd/kfd_chardev.c
@@ -3112,10 +3112,14 @@ static int kfd_ioctl_set_debug_trap(struct file *filep, 
struct kfd_process *p, v
                goto out;
        }
 
-       /* Check if target is still PTRACED. */
+       /*
+        * Verify debugger has permission to debug target process.
+        * For cross-process debugging, require active ptrace relationship.
+        * This applies to ALL operations to prevent unauthorized interference.
+        */
        rcu_read_lock();
-       if (target != p && args->op != KFD_IOC_DBG_TRAP_DISABLE
-                               && ptrace_parent(target->lead_thread) != 
current) {
+       if (target != p && ptrace_parent(target->lead_thread) != current
+                       && target->debugger_process != p) {
                pr_err("PID %i is not PTRACED and cannot be debugged\n", 
args->pid);
                r = -EPERM;
        }
-- 
2.54.0

Reply via email to