Count-only perf tracepoint events can be opened without tracepoint
permission because they do not sample raw event data. Their SET_FILTER
ioctl still parses .function predicates. Numeric operands call
kallsyms_lookup_size_offset(), making ioctl success an oracle for
recovering the randomized kernel text base. Symbolic operands resolve
hidden symbol addresses and can also match user-controlled event fields
against those addresses.
Pass the perf origin through filter parsing and require
perf_allow_tracepoint() before resolving either form of .function
operand. Ordinary perf count filters and tracefs event filters retain
their existing behavior.
Fixes: e6745a4da964 ("tracing: Add a way to filter function addresses to function names")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Zhengchuan Liang <redacted>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/cover.1790553331.git.zcliangcn@gmail.com?part=1