From: Steven Rostedt <rostedt@goodmis.org>
To: Zhengchuan Liang <zcliangcn@gmail.com>
Cc: Masami Hiramatsu <mhiramat@kernel.org>,
Mathieu Desnoyers <mathieu.desnoyers@efficios.com>,
Ross Zwisler <zwisler@google.com>,
linux-trace-kernel@vger.kernel.org, linux-kernel@vger.kernel.org,
Peter Zijlstra <peterz@infradead.org>,
linux-perf-users@vger.kernel.org, stable@vger.kernel.org
Subject: Re: [PATCH 1/1] tracing: Require tracepoint permission for perf function filters
Date: Tue, 29 Sep 2026 14:45:01 -0400 [thread overview]
Message-ID: <20260929144501.3b8dcaa1@fedora> (raw)
In-Reply-To: <95d3721fa8d4c7a4577ec14e9d7caec4fd0cefcc.1790553331.git.zcliangcn@gmail.com>
On Sun, 27 Sep 2026 17:00:31 -0700
Zhengchuan Liang <zcliangcn@gmail.com> wrote:
> Count-only perf tracepoint events can be opened without tracepoint
> permission because they do not sample raw event data. Their SET_FILTER
> ioctl still parses .function predicates. Numeric operands call
> kallsyms_lookup_size_offset(), making ioctl success an oracle for
> recovering the randomized kernel text base. Symbolic operands resolve
> hidden symbol addresses and can also match user-controlled event fields
> against those addresses.
>
> Pass the perf origin through filter parsing and require
> perf_allow_tracepoint() before resolving either form of .function
> operand. Ordinary perf count filters and tracefs event filters retain
> their existing behavior.
>
> Fixes: e6745a4da964 ("tracing: Add a way to filter function addresses to function names")
> Cc: stable@vger.kernel.org
> Assisted-by: LLM
> Signed-off-by: Zhengchuan Liang <zcliangcn@gmail.com>
> ---
> kernel/trace/trace_events_filter.c | 39 ++++++++++++++++++++++--------
NAK.
This is a perf issue and not a ftrace issue. It should not touch any
code in kernel/trace/* for the fix.
Looks to me the code that calls ftrace_profile_set_filter() from
kernel/events/core.c should not be allowed by unprivileged users.
-- Steve
prev parent reply other threads:[~2026-09-29 18:45 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-28 0:00 [PATCH 0/1] perf tracepoint filter exposes the kernel text base Zhengchuan Liang
2026-09-28 0:00 ` [PATCH 1/1] tracing: Require tracepoint permission for perf function filters Zhengchuan Liang
2026-09-29 18:45 ` Steven Rostedt [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260929144501.3b8dcaa1@fedora \
--to=rostedt@goodmis.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-perf-users@vger.kernel.org \
--cc=linux-trace-kernel@vger.kernel.org \
--cc=mathieu.desnoyers@efficios.com \
--cc=mhiramat@kernel.org \
--cc=peterz@infradead.org \
--cc=stable@vger.kernel.org \
--cc=zcliangcn@gmail.com \
--cc=zwisler@google.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®