On Sun, 27 Sep 2026 17:00:31 -0700
Zhengchuan Liang [off-list ref] wrote:
Count-only perf tracepoint events can be opened without tracepoint
permission because they do not sample raw event data. Their SET_FILTER
ioctl still parses .function predicates. Numeric operands call
kallsyms_lookup_size_offset(), making ioctl success an oracle for
recovering the randomized kernel text base. Symbolic operands resolve
hidden symbol addresses and can also match user-controlled event fields
against those addresses.
Pass the perf origin through filter parsing and require
perf_allow_tracepoint() before resolving either form of .function
operand. Ordinary perf count filters and tracefs event filters retain
their existing behavior.
Fixes: e6745a4da964 ("tracing: Add a way to filter function addresses to function names")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Zhengchuan Liang <redacted>
---
kernel/trace/trace_events_filter.c | 39 ++++++++++++++++++++++--------
NAK.
This is a perf issue and not a ftrace issue. It should not touch any
code in kernel/trace/* for the fix.
Looks to me the code that calls ftrace_profile_set_filter() from
kernel/events/core.c should not be allowed by unprivileged users.
-- Steve