Thread (4 messages) 4 messages, 3 authors, 7d ago

Re: [PATCH 1/1] tracing: Require tracepoint permission for perf function filters

flat view

From: Steven Rostedt <rostedt@goodmis.org>
Date: 2026-09-29 18:45:14
Also in: linux-perf-users, lkml, stable

On Sun, 27 Sep 2026 17:00:31 -0700
Zhengchuan Liang [off-list ref] wrote:
Count-only perf tracepoint events can be opened without tracepoint
permission because they do not sample raw event data. Their SET_FILTER
ioctl still parses .function predicates. Numeric operands call
kallsyms_lookup_size_offset(), making ioctl success an oracle for
recovering the randomized kernel text base. Symbolic operands resolve
hidden symbol addresses and can also match user-controlled event fields
against those addresses.

Pass the perf origin through filter parsing and require
perf_allow_tracepoint() before resolving either form of .function
operand. Ordinary perf count filters and tracefs event filters retain
their existing behavior.

Fixes: e6745a4da964 ("tracing: Add a way to filter function addresses to function names")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Zhengchuan Liang <redacted>
---
 kernel/trace/trace_events_filter.c | 39 ++++++++++++++++++++++--------
NAK.

This is a perf issue and not a ftrace issue. It should not touch any
code in kernel/trace/* for the fix.

Looks to me the code that calls ftrace_profile_set_filter() from
kernel/events/core.c should not be allowed by unprivileged users.

-- Steve
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help