From mboxrd@z Thu Jan 1 00:00:00 1970 From: Lionel Landwerlin Subject: Re: [Intel-gfx] [PATCH v3 4/7] drm/i915/perf: open access for CAP_SYS_PERFMON privileged process Date: Tue, 17 Dec 2019 11:45:20 +0200 Message-ID: <503ad40c-d94e-df1d-1541-730c002ad3b7@intel.com> References: Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8; format=flowed Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: Content-Language: en-US Sender: linux-kernel-owner@vger.kernel.org To: Alexey Budankov , Peter Zijlstra , Arnaldo Carvalho de Melo , Ingo Molnar , "jani.nikula@linux.intel.com" , "joonas.lahtinen@linux.intel.com" , "rodrigo.vivi@intel.com" , Alexei Starovoitov , Benjamin Herrenschmidt , Paul Mackerras , Michael Ellerman , Serge Hallyn , James Morris , Casey Schaufler Cc: songliubraving@fb.com, Andi Kleen , Kees Cook , "linux-parisc@vger.kernel.org" , Jann Horn , Alexander Shishkin , "linuxppc-dev@lists.ozlabs.org" , intel-gfx@lists.freedesktop.org, Igor Lubashev , linux-kernel@vger.kernel.org, Stephane Eranian , "linux-perf-users@vger.kernel.org" , "selinux@vger.kernel.org" , "linux-security-module@vger.kernel.org" , Namhyung Kim , Thomas Gleixner , Brendan Gregg List-Id: linux-perf-users.vger.kernel.org On 16/12/2019 22:03, Alexey Budankov wrote: > Open access to i915_perf monitoring for CAP_SYS_PERFMON privileged processes. > For backward compatibility reasons access to i915_perf subsystem remains open > for CAP_SYS_ADMIN privileged processes but CAP_SYS_ADMIN usage for secure > i915_perf monitoring is discouraged with respect to CAP_SYS_PERFMON capability. > > Signed-off-by: Alexey Budankov Assuming people are fine with this new cap, I like this idea of a lighter privilege for i915-perf. -Lionel