On Tue, 06 Oct 2026 15:40:05 -0700, Kyle Zeng <[email protected]> wrote:
> A task-bound, counting-only syscall tracepoint can be opened without
> permission to read raw kernel tracepoint data. Setting exclude_kernel
> does not prevent its filter from running: perf_syscall_enter() submits
> the saved user-mode registers.
>
> Pointer-string filters use FILTER_PRED_FN_PCHAR by default, which reads
> through strncpy_from_kernel_nofault(). For sys_enter_openat, for example,
> the filename field comes directly from a syscall argument. An
> unprivileged caller can pass a kernel address, install a filter such as
> 'filename ~ "Linux version*"', and use the event count to test the
> contents of kernel memory, even with perf_event_paranoid=2.
>
> Check the compiled filter before installing it and require the same
> kernel and raw-tracepoint permissions as access to raw kernel tracepoint
> data for FILTER_PRED_FN_PCHAR. Inspect every predicate so that other
> events, operators, and boolean expressions cannot bypass the check.
> Return the permission error through the existing cleanup path before
> publishing the filter.
>
> Keep user-pointer (.ustring) and record-local predicates available under
> the existing policy. This leaves tracefs filtering and authorized kernel
> string filtering unchanged.
>
> Fixes: 5967bd5c4239 ("tracing: Let filter_assign_type() detect 
> FILTER_PTR_STRING")
> Assisted-by: Codex:gpt-6-astra
> Signed-off-by: Kyle Zeng <[email protected]>

Looks good to me.

Reviewed-by: Masami Hiramatsu (Google) <[email protected]>

Thanks,


-- 
Masami Hiramatsu (Google) <[email protected]>

Reply via email to