Instruction pointer returned by profile_pc() can be a random value. This break the assumption than we can safely set struct op_sample.eip field to a magic value to signal to the per-cpu buffer reader side special event like task switch ending up in a segfault in get_task_mm() when profile_pc() return ~0UL. Fixed by sanitizing the sampled eip and reject/log invalid eip. Problem reported by Sami Farin, patch tested by him. Signed-off-by: Philippe Elie <phil.el@wanadoo.fr> Tested-by: Sami Farin <safari-kernel@safari.iki.fi> Cc: <stable@kernel.org> Signed-off-by: Andrew Morton <akpm@linux-foundation.org> Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org> |
||
|---|---|---|
| .. | ||
| buffer_sync.c | ||
| buffer_sync.h | ||
| cpu_buffer.c | ||
| cpu_buffer.h | ||
| event_buffer.c | ||
| event_buffer.h | ||
| oprof.c | ||
| oprof.h | ||
| oprofile_files.c | ||
| oprofile_stats.c | ||
| oprofile_stats.h | ||
| oprofilefs.c | ||
| timer_int.c | ||