On Sun, 27 Sep 2026 17:00:31 -0700
Zhengchuan Liang <[email protected]> wrote:
> Count-only perf tracepoint events can be opened without tracepoint
> permission because they do not sample raw event data. Their SET_FILTER
> ioctl still parses .function predicates. Numeric operands call
> kallsyms_lookup_size_offset(), making ioctl success an oracle for
> recovering the randomized kernel text base. Symbolic operands resolve
> hidden symbol addresses and can also match user-controlled event fields
> against those addresses.
>
> Pass the perf origin through filter parsing and require
> perf_allow_tracepoint() before resolving either form of .function
> operand. Ordinary perf count filters and tracefs event filters retain
> their existing behavior.
>
> Fixes: e6745a4da964 ("tracing: Add a way to filter function addresses to
> function names")
> Cc: [email protected]
> Assisted-by: LLM
> Signed-off-by: Zhengchuan Liang <[email protected]>
> ---
> kernel/trace/trace_events_filter.c | 39 ++++++++++++++++++++++--------
NAK.
This is a perf issue and not a ftrace issue. It should not touch any
code in kernel/trace/* for the fix.
Looks to me the code that calls ftrace_profile_set_filter() from
kernel/events/core.c should not be allowed by unprivileged users.
-- Steve