On Tue, 06 Oct 2026 22:03:15 -0700, Kyle Zeng <[email protected]> wrote:
> perf_trace_event_perm() allows tracepoint counters that do not request
> PERF_SAMPLE_RAW without raw tracepoint permissions. A self-targeted
> event with exclude_kernel=1 can therefore reach the filter compiler even
> at perf_event_paranoid=2.
>
> The .function suffix resolves its operand through kallsyms. The result
> of a numeric filter discloses whether an address belongs to a known
> kernel symbol range, allowing the randomized kernel image base to be
> recovered. A named filter also exposes the resolved range through the
> counter when the tracepoint field is controlled by the caller.
>
> Pointer-string filters expose kernel memory in the same way. A caller
> can supply a kernel address as the filename argument to openat() and
> install a string filter on sys_enter_openat. Without .ustring, the
> filter uses strncpy_from_kernel_nofault() on that address. Whether the
> counter increments reveals whether the kernel bytes match the pattern.
> The nofault copy prevents faults but does not authorize disclosure.
>
> Pass the filter's perf origin to the predicate parser and require
> perf_allow_tracepoint() before resolving a .function operand or creating
> a kernel-pointer string predicate. This uses the existing sysctl,
> initial-namespace capability and LSM policy for raw tracepoint access.
> Keep ordinary counting filters, explicit user-string predicates and
> filters created through the separately controlled tracefs interfaces
> unchanged.
>
> Fixes: e6745a4da964 ("tracing: Add a way to filter function addresses to 
> function names")
> Fixes: 5967bd5c4239 ("tracing: Let filter_assign_type() detect 
> FILTER_PTR_STRING")
> Cc: [email protected]
> Assisted-by: LLM
> Signed-off-by: Kyle Zeng <[email protected]>

Looks good to me.

Reviewed-by: Masami Hiramatsu (Google) <[email protected]>

Thanks!

-- 
Masami Hiramatsu (Google) <[email protected]>

Reply via email to