On Tue, 06 Oct 2026 15:40:05 -0700, Kyle Zeng <[email protected]> wrote: > A task-bound, counting-only syscall tracepoint can be opened without > permission to read raw kernel tracepoint data. Setting exclude_kernel > does not prevent its filter from running: perf_syscall_enter() submits > the saved user-mode registers. > > Pointer-string filters use FILTER_PRED_FN_PCHAR by default, which reads > through strncpy_from_kernel_nofault(). For sys_enter_openat, for example, > the filename field comes directly from a syscall argument. An > unprivileged caller can pass a kernel address, install a filter such as > 'filename ~ "Linux version*"', and use the event count to test the > contents of kernel memory, even with perf_event_paranoid=2. > > Check the compiled filter before installing it and require the same > kernel and raw-tracepoint permissions as access to raw kernel tracepoint > data for FILTER_PRED_FN_PCHAR. Inspect every predicate so that other > events, operators, and boolean expressions cannot bypass the check. > Return the permission error through the existing cleanup path before > publishing the filter. > > Keep user-pointer (.ustring) and record-local predicates available under > the existing policy. This leaves tracefs filtering and authorized kernel > string filtering unchanged. > > Fixes: 5967bd5c4239 ("tracing: Let filter_assign_type() detect > FILTER_PTR_STRING") > Assisted-by: Codex:gpt-6-astra > Signed-off-by: Kyle Zeng <[email protected]>
Looks good to me. Reviewed-by: Masami Hiramatsu (Google) <[email protected]> Thanks, -- Masami Hiramatsu (Google) <[email protected]>
