All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Zhengchuan Liang" <zcliangcn@gmail.com>
Cc: linux-perf-users@vger.kernel.org
Subject: Re: [PATCH 1/1] perf/core: Require kernel access for text poke events
Date: Mon, 28 Sep 2026 18:09:27 +0000	[thread overview]
Message-ID: <20260928180928.3F4411F000FF@smtp.kernel.org> (raw)
In-Reply-To: <99131354c41e23188f778b92f90363775b482395.1790573390.git.zcliangcn@gmail.com>

> Perf events with exclude_kernel=1 can be opened without kernel perf
> access. However, exclude_kernel does not suppress text-poke sideband
> records. Every PERF_RECORD_TEXT_POKE is marked PERF_RECORD_MISC_KERNEL
> and contains a raw kernel instruction address.
> 
> An unprivileged task can therefore open and mmap a task-local software
> event with text_poke=1. Both opening a count-only tracepoint event and
> configuring UDP GRO for ESP-in-UDP cause updates to inline static calls;
> the observer receives the relocated addresses of the modified instructions.
> For a known kernel image, any such address reveals the runtime kernel
> text base despite KASLR.
> 
> Call perf_allow_kernel() whenever attr.text_poke is set, regardless of
> exclude_kernel. Events that neither monitor kernel execution nor request
> text-poke records retain their existing permissions.
> 
> Fixes: e17d43b93e54 ("perf: Add perf text poke event")
> Cc: stable@vger.kernel.org
> Assisted-by: LLM
> Signed-off-by: Zhengchuan Liang <zcliangcn@gmail.com>

Sashiko has reviewed this patch and found no issues. It looks great!

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/cover.1790573390.git.zcliangcn@gmail.com?part=1


  reply	other threads:[~2026-09-28 18:09 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-28 17:59 [PATCH 0/1] perf/core: Text-poke events expose the kernel text base Zhengchuan Liang
2026-09-28 17:59 ` [PATCH 1/1] perf/core: Require kernel access for text poke events Zhengchuan Liang
2026-09-28 18:09   ` sashiko-bot [this message]
2026-10-01 10:37   ` Peter Zijlstra

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260928180928.3F4411F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=linux-perf-users@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=zcliangcn@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.