AMD General

Reviewed-by: Kent Russell <[email protected]>



> -----Original Message-----
> From: amd-gfx <[email protected]> On Behalf Of Gang Ba
> Sent: July 20, 2026 11:31 AM
> To: [email protected]
> Cc: [email protected]
> Subject: [PATCH] drm/amdkfd: Fix missing authorization check in
> KFD_IOC_DBG_TRAP_DISABLE
>
> Prevent unauthorized termination of active GPU debug sessions.
> Previously, users with /dev/kfd access could terminate another process's
> debug session without proper ownership or ptrace authorization.
>
> Signed-off-by: Gang Ba <[email protected]>
> ---
>  drivers/gpu/drm/amd/amdkfd/kfd_chardev.c | 10 +++++++---
>  1 file changed, 7 insertions(+), 3 deletions(-)
>
> diff --git a/drivers/gpu/drm/amd/amdkfd/kfd_chardev.c
> b/drivers/gpu/drm/amd/amdkfd/kfd_chardev.c
> index 7d058d93e219..05dd0b6a87f0 100644
> --- a/drivers/gpu/drm/amd/amdkfd/kfd_chardev.c
> +++ b/drivers/gpu/drm/amd/amdkfd/kfd_chardev.c
> @@ -3112,10 +3112,14 @@ static int kfd_ioctl_set_debug_trap(struct file 
> *filep,
> struct kfd_process *p, v
>               goto out;
>       }
>
> -     /* Check if target is still PTRACED. */
> +     /*
> +      * Verify debugger has permission to debug target process.
> +      * For cross-process debugging, require active ptrace relationship.
> +      * This applies to ALL operations to prevent unauthorized interference.
> +      */
>       rcu_read_lock();
> -     if (target != p && args->op != KFD_IOC_DBG_TRAP_DISABLE
> -                             && ptrace_parent(target->lead_thread) !=
> current) {
> +     if (target != p && ptrace_parent(target->lead_thread) != current
> +                     && target->debugger_process != p) {
>               pr_err("PID %i is not PTRACED and cannot be debugged\n", args-
> >pid);
>               r = -EPERM;
>       }
> --
> 2.54.0

Reply via email to