On Tue, 06 Oct 2026 22:03:15 -0700, Kyle Zeng <[email protected]> wrote: > perf_trace_event_perm() allows tracepoint counters that do not request > PERF_SAMPLE_RAW without raw tracepoint permissions. A self-targeted > event with exclude_kernel=1 can therefore reach the filter compiler even > at perf_event_paranoid=2. > > The .function suffix resolves its operand through kallsyms. The result > of a numeric filter discloses whether an address belongs to a known > kernel symbol range, allowing the randomized kernel image base to be > recovered. A named filter also exposes the resolved range through the > counter when the tracepoint field is controlled by the caller. > > Pointer-string filters expose kernel memory in the same way. A caller > can supply a kernel address as the filename argument to openat() and > install a string filter on sys_enter_openat. Without .ustring, the > filter uses strncpy_from_kernel_nofault() on that address. Whether the > counter increments reveals whether the kernel bytes match the pattern. > The nofault copy prevents faults but does not authorize disclosure. > > Pass the filter's perf origin to the predicate parser and require > perf_allow_tracepoint() before resolving a .function operand or creating > a kernel-pointer string predicate. This uses the existing sysctl, > initial-namespace capability and LSM policy for raw tracepoint access. > Keep ordinary counting filters, explicit user-string predicates and > filters created through the separately controlled tracefs interfaces > unchanged. > > Fixes: e6745a4da964 ("tracing: Add a way to filter function addresses to > function names") > Fixes: 5967bd5c4239 ("tracing: Let filter_assign_type() detect > FILTER_PTR_STRING") > Cc: [email protected] > Assisted-by: LLM > Signed-off-by: Kyle Zeng <[email protected]>
Looks good to me. Reviewed-by: Masami Hiramatsu (Google) <[email protected]> Thanks! -- Masami Hiramatsu (Google) <[email protected]>
