From nobody Tue Aug 25 16:00:37 2026 X-Original-To: dev-commits-src-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4hTsvB39wbz6pbdd for ; Tue, 25 Aug 2026 16:00:38 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR2" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4hTsv95HtLz43FB for ; Tue, 25 Aug 2026 16:00:37 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1787673637; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=Ah0Poxz/ogEGyvE5fRkMT0dEJiQx9a1aK/BS0sQAyms=; b=pPSqE/+1Vn+knl+qifa4uTlL4I3nX7MIb3Hz0OXgqfZ8XflLWfA5aS/yVUXHqnsIpeYanT SYOQmBgi4FJt70ke46Q/O7gshvaDGGzuND1Jwj0S9HfZbdvN3oRA6ratlwaAgcdYG73naF I/ZfeQn6UUytkXWptUnPFl6W1ehOhtuBRhFVliQ0Pmgavv2Lb+TPB92bS2LwIT5YyIupFq +BsQyWsUb8X/zMmwmQ3bDxXh8evbSkJXGqfihrSmJHj+hf87ppItOe900Ul/C4L+S5A7C5 RgZe54PTPKfOoSP24i8zGQBJRpBAd9WFcnlPU+8RzqAlkq+mmcerf5Uivs2iiA== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1787673637; a=rsa-sha256; cv=none; b=WiVlzK99LGYWSVgD/CvpKxBVyNPZycgjYZLqjMDSwblMgYaCBOm0rQOIuzbM7uqoZ7V5qy oGyZqK2LEgF/j614ZIeXGFbzXqe8PqgIPa7iUK8sIew9cJ7WpIaOR4whWemWC4M1nXS92z SOQRrv4XfhSdYUhcsaVn/lkPTSF1EUEi/AKQ/Z9R8HiloSEHpCdSDnvzZimXMTwkrDApS/ 0FshFauDw3dSWUXu1B3XTcXN+jGlW7C4czgFPpk5brbGPP/6icCC/Y6bD6ToTlKdKBcZwt JKsw0nWPNPp2kF3ZrL0M9+kD0oSTq3yqXmHoiZrPrvYFhRZ6+zJfx3XUootdcQ== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1787673637; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=Ah0Poxz/ogEGyvE5fRkMT0dEJiQx9a1aK/BS0sQAyms=; b=B2pybZy/LUQB83ZILhm6FEE2nA60fr3Qfy9PWwnl/YJw/hDVRw59NkzOlvqiUSfLiL2NTS VIrzo8izdJOHW7q42I4P6xITt2nm989iBAkuebxk5Nz/InBl/NdAKjII0aRFA16OtKO29n im5gPNVcNTOWYW618Xw4Iv9POsyzIzESL4Nw5epDWbZ06comCqWtDHz+dRNP7C0auHv3Cs b/1WuGAT46LWb/4d06PJshK2epq/EqYjMBkOZK/h0uKDiiJcNB3UX9FT0znsMu2wyham8p 49pZo9eXuL9i2pl5SSkYmFWIlakx3rSlmv7Q1WZsUg3UcAbzD+PZz+JCfUaE+w== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4hTsv945bQzxZV for ; Tue, 25 Aug 2026 16:00:37 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 321e4 by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Tue, 25 Aug 2026 16:00:37 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-branches@FreeBSD.org From: Mark Johnston Subject: git: 77528485e86d - releng/14.5 - hwpmc: Fix the execve handler List-Id: Commit messages for all branches of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-all@freebsd.org Sender: owner-dev-commits-src-all@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: markj X-Git-Repository: src X-Git-Refname: refs/heads/releng/14.5 X-Git-Reftype: branch X-Git-Commit: 77528485e86dea0dc5ca1aefb18b0b8927325531 Auto-Submitted: auto-generated Date: Tue, 25 Aug 2026 16:00:37 +0000 Message-Id: <6a8dbc25.321e4.7dd08dbf@gitrepo.freebsd.org> The branch releng/14.5 has been updated by markj: URL: https://cgit.FreeBSD.org/src/commit/?id=77528485e86dea0dc5ca1aefb18b0b8927325531 commit 77528485e86dea0dc5ca1aefb18b0b8927325531 Author: Mark Johnston AuthorDate: 2026-08-24 14:57:16 +0000 Commit: Mark Johnston CommitDate: 2026-08-24 19:02:58 +0000 hwpmc: Fix the execve handler When a process execve()s, pmc_process_exec() is supposed to evaluate whether the new image is setuid/setgid and if so, whether to detach PMCs. This was handled by pmc_can_attach(), which is effectively an open-coded copy of cr_xids_subset(). Unfortunately, the test of the result of this function was inverted, with the result that we'd detach PMCs only if the predicate said it was okay to do so. It appears the bug has always been there; it seems the intent was to return 0 on "success", i.e., it is okay to attach the PMCs, much like p_candebug(). Commits 1c3c698ba4c4 and 1c40b15971f0 obscured this a bit. I think this check is trying to be too clever. Let's make it simpler: simply do not attach PMCs unless the owner is privileged. This is how, e.g., ktrace works. I do not think it's worth trying to be more sophisticated than this unless we can generalize the policy in a way that's applicable to other subsystems. Also fix a bug at the end of pmc_process_exec(): pmc_detach_one_process() will call pmc_remove_process_descriptor() for us. Approved by: re (cperciva) Approved by: so Security: FreeBSD-SA-26:56.hwpmc Security: CVE-2026-58089 Reported by: netchild Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D59102 --- sys/dev/hwpmc/hwpmc_mod.c | 72 ++++++++--------------------------------------- sys/kern/kern_exec.c | 2 +- 2 files changed, 13 insertions(+), 61 deletions(-) diff --git a/sys/dev/hwpmc/hwpmc_mod.c b/sys/dev/hwpmc/hwpmc_mod.c index 916b86c4d0e8..216430e3ef5c 100644 --- a/sys/dev/hwpmc/hwpmc_mod.c +++ b/sys/dev/hwpmc/hwpmc_mod.c @@ -211,7 +211,6 @@ static int pmc_attach_one_process(struct proc *p, struct pmc *pm); static bool pmc_can_allocate_row(int ri, enum pmc_mode mode); static bool pmc_can_allocate_rowindex(struct proc *p, unsigned int ri, int cpu); -static bool pmc_can_attach(struct pmc *pm, struct proc *p); static void pmc_capture_user_callchain(int cpu, int soft, struct trapframe *tf); static void pmc_cleanup(void); @@ -1028,60 +1027,6 @@ pmc_unlink_target_process(struct pmc *pm, struct pmc_process *pp) } } -/* - * Check if PMC 'pm' may be attached to target process 't'. - */ - -static bool -pmc_can_attach(struct pmc *pm, struct proc *t) -{ - struct proc *o; /* pmc owner */ - struct ucred *oc, *tc; /* owner, target credentials */ - bool decline_attach; - - /* - * A PMC's owner can always attach that PMC to itself. - */ - - if ((o = pm->pm_owner->po_owner) == t) - return (true); - - PROC_LOCK(o); - oc = o->p_ucred; - crhold(oc); - PROC_UNLOCK(o); - - PROC_LOCK(t); - tc = t->p_ucred; - crhold(tc); - PROC_UNLOCK(t); - - /* - * The effective uid of the PMC owner should match at least one - * of the {effective,real,saved} uids of the target process. - */ - - decline_attach = oc->cr_uid != tc->cr_uid && - oc->cr_uid != tc->cr_svuid && - oc->cr_uid != tc->cr_ruid; - - /* - * Every one of the target's group ids, must be in the owner's - * group list. - */ - for (int i = 1; !decline_attach && i < tc->cr_ngroups; i++) - decline_attach = !groupmember(tc->cr_groups[i], oc); - if (!decline_attach) - decline_attach = !groupmember(tc->cr_gid, oc) || - !groupmember(tc->cr_rgid, oc) || - !groupmember(tc->cr_svgid, oc); - - crfree(tc); - crfree(oc); - - return (!decline_attach); -} - /* * Attach a process to a PMC. */ @@ -1445,10 +1390,19 @@ pmc_process_exec(struct thread *td, struct pmckern_procexec *pk) */ for (ri = 0; ri < md->pmd_npmc; ri++) { if ((pm = pp->pp_pmcs[ri].pp_pmc) != NULL) { - if (pmc_can_attach(pm, td->td_proc)) { + struct proc *owner; + struct ucred *cred; + + owner = pm->pm_owner->po_owner; + PROC_LOCK(owner); + cred = crhold(owner->p_ucred); + PROC_UNLOCK(owner); + + if (priv_check_cred(cred, PRIV_DEBUG_DIFFCRED) != 0) pmc_detach_one_process(td->td_proc, pm, PMC_FLAG_NONE); - } + + crfree(cred); } } @@ -1461,10 +1415,8 @@ pmc_process_exec(struct thread *td, struct pmckern_procexec *pk) * PMCs, we can remove the process entry and free * up space. */ - if (pp->pp_refcnt == 0) { - pmc_remove_process_descriptor(pp); + if (pp->pp_refcnt == 0) pmc_destroy_process_descriptor(pp); - } } /* diff --git a/sys/kern/kern_exec.c b/sys/kern/kern_exec.c index 3cedf7ee36f5..1c70c98ba20c 100644 --- a/sys/kern/kern_exec.c +++ b/sys/kern/kern_exec.c @@ -993,7 +993,7 @@ interpret: */ if (PMC_SYSTEM_SAMPLING_ACTIVE() || PMC_PROC_IS_USING_PMCS(p)) { VOP_UNLOCK(imgp->vp); - pe.pm_credentialschanged = credential_changing; + pe.pm_credentialschanged = imgp->credential_setid; pe.pm_baseaddr = imgp->reloc_base; pe.pm_dynaddr = imgp->et_dyn_addr;