> Count-only perf tracepoint events can be opened without tracepoint
> permission because they do not sample raw event data. Their SET_FILTER
> ioctl still parses .function predicates. Numeric operands call
> kallsyms_lookup_size_offset(), making ioctl success an oracle for
> recovering the randomized kernel text base. Symbolic operands resolve
> hidden symbol addresses and can also match user-controlled event fields
> against those addresses.
>
> Pass the perf origin through filter parsing and require
> perf_allow_tracepoint() before resolving either form of .function
> operand. Ordinary perf count filters and tracefs event filters retain
> their existing behavior.
>
> Fixes: e6745a4da964 ("tracing: Add a way to filter function addresses to
> function names")
> Cc: [email protected]
> Assisted-by: LLM
> Signed-off-by: Zhengchuan Liang <[email protected]>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review ยท
https://sashiko.dev/#/patchset/[email protected]?part=1