• Jiri Olsa's avatar
    perf/x86/intel: Disallow precise_ip on BTS events · 472de49f
    Jiri Olsa authored
    Vince reported a crash in the BTS flush code when touching the callchain
    data, which was supposed to be initialized as an 'early' callchain,
    but intel_pmu_drain_bts_buffer() does not do that:
    
      BUG: unable to handle kernel NULL pointer dereference at 0000000000000000
      ...
      Call Trace:
       <IRQ>
       intel_pmu_drain_bts_buffer+0x151/0x220
       ? intel_get_event_constraints+0x219/0x360
       ? perf_assign_events+0xe2/0x2a0
       ? select_idle_sibling+0x22/0x3a0
       ? __update_load_avg_se+0x1ec/0x270
       ? enqueue_task_fair+0x377/0xdd0
       ? cpumask_next_and+0x19/0x20
       ? load_balance+0x134/0x950
       ? check_preempt_curr+0x7a/0x90
       ? ttwu_do_wakeup+0x19/0x140
       x86_pmu_stop+0x3b/0x90
       x86_pmu_del+0x57/0x160
       event_sched_out.isra.106+0x81/0x170
       group_sched_out.part.108+0x51/0xc0
       __perf_event_disable+0x7f/0x160
       event_function+0x8c/0xd0
       remote_function+0x3c/0x50
       flush_smp_call_function_queue+0x35/0xe0
       smp_call_function_single_interrupt+0x3a/0xd0
       call_function_single_interrupt+0xf/0x20
       </IRQ>
    
    It was triggered by fuzzer but can be easily reproduced by:
    
      # perf record -e cpu/branch-instructions/pu -g -c 1
    
    Peter suggested not to allow branch tracing for precise events:
    
     > Now arguably, this is really stupid behaviour. Who in his right mind
     > wants callchain output on BTS entries. And even if they do, BTS +
     > precise_ip is nonsensical.
     >
     > So in my mind disallowing precise_ip on BTS would be the simplest fix.
    Suggested-by: default avatarPeter Zijlstra <peterz@infradead.org>
    Reported-by: default avatarVince Weaver <vincent.weaver@maine.edu>
    Signed-off-by: default avatarJiri Olsa <jolsa@kernel.org>
    Acked-by: default avatarPeter Zijlstra <a.p.zijlstra@chello.nl>
    Cc: <stable@vger.kernel.org>
    Cc: Alexander Shishkin <alexander.shishkin@linux.intel.com>
    Cc: Arnaldo Carvalho de Melo <acme@kernel.org>
    Cc: Arnaldo Carvalho de Melo <acme@redhat.com>
    Cc: Jiri Olsa <jolsa@redhat.com>
    Cc: Linus Torvalds <torvalds@linux-foundation.org>
    Cc: Stephane Eranian <eranian@google.com>
    Cc: Thomas Gleixner <tglx@linutronix.de>
    Fixes: 6cbc304f ("perf/x86/intel: Fix unwind errors from PEBS entries (mk-II)")
    Link: http://lkml.kernel.org/r/20181121101612.16272-3-jolsa@kernel.orgSigned-off-by: default avatarIngo Molnar <mingo@kernel.org>
    472de49f
core.c 130 KB