From: Peter Zijlstra <peterz@infradead.org>
To: Zhengchuan Liang <zcliangcn@gmail.com>
Cc: Ingo Molnar <mingo@redhat.com>,
Arnaldo Carvalho de Melo <acme@kernel.org>,
Namhyung Kim <namhyung@kernel.org>,
Mark Rutland <mark.rutland@arm.com>,
Alexander Shishkin <alexander.shishkin@linux.intel.com>,
Jiri Olsa <jolsa@kernel.org>, Ian Rogers <irogers@google.com>,
Adrian Hunter <adrian.hunter@intel.com>,
James Clark <james.clark@linaro.org>,
linux-perf-users@vger.kernel.org, linux-kernel@vger.kernel.org,
stable@vger.kernel.org
Subject: Re: [PATCH 1/1] perf/core: Require kernel access for text poke events
Date: Thu, 1 Oct 2026 12:37:57 +0200 [thread overview]
Message-ID: <20261001103757.GV4120091@noisy.programming.kicks-ass.net> (raw)
In-Reply-To: <99131354c41e23188f778b92f90363775b482395.1790573390.git.zcliangcn@gmail.com>
On Mon, Sep 28, 2026 at 10:59:35AM -0700, Zhengchuan Liang wrote:
> Perf events with exclude_kernel=1 can be opened without kernel perf
> access. However, exclude_kernel does not suppress text-poke sideband
> records. Every PERF_RECORD_TEXT_POKE is marked PERF_RECORD_MISC_KERNEL
> and contains a raw kernel instruction address.
>
> An unprivileged task can therefore open and mmap a task-local software
> event with text_poke=1. Both opening a count-only tracepoint event and
> configuring UDP GRO for ESP-in-UDP cause updates to inline static calls;
> the observer receives the relocated addresses of the modified instructions.
> For a known kernel image, any such address reveals the runtime kernel
> text base despite KASLR.
>
> Call perf_allow_kernel() whenever attr.text_poke is set, regardless of
> exclude_kernel. Events that neither monitor kernel execution nor request
> text-poke records retain their existing permissions.
>
> Fixes: e17d43b93e54 ("perf: Add perf text poke event")
> Cc: stable@vger.kernel.org
> Assisted-by: LLM
> Signed-off-by: Zhengchuan Liang <zcliangcn@gmail.com>
Nice one. Thanks!
> kernel/events/core.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/kernel/events/core.c b/kernel/events/core.c
> index 634d2ccbab82..b4e6e8ae3be7 100644
> --- a/kernel/events/core.c
> +++ b/kernel/events/core.c
> @@ -13953,7 +13953,7 @@ SYSCALL_DEFINE5(perf_event_open,
> if (err)
> return err;
>
> - if (!attr.exclude_kernel ||
> + if (!attr.exclude_kernel || attr.text_poke ||
> ((attr.sample_type & PERF_SAMPLE_CALLCHAIN) &&
> !attr.exclude_callchain_kernel)) {
> err = perf_allow_kernel();
> --
> 2.34.1
prev parent reply other threads:[~2026-10-01 10:38 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-28 17:59 [PATCH 0/1] perf/core: Text-poke events expose the kernel text base Zhengchuan Liang
2026-09-28 17:59 ` [PATCH 1/1] perf/core: Require kernel access for text poke events Zhengchuan Liang
2026-09-28 18:09 ` sashiko-bot
2026-10-01 10:37 ` Peter Zijlstra [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261001103757.GV4120091@noisy.programming.kicks-ass.net \
--to=peterz@infradead.org \
--cc=acme@kernel.org \
--cc=adrian.hunter@intel.com \
--cc=alexander.shishkin@linux.intel.com \
--cc=irogers@google.com \
--cc=james.clark@linaro.org \
--cc=jolsa@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-perf-users@vger.kernel.org \
--cc=mark.rutland@arm.com \
--cc=mingo@redhat.com \
--cc=namhyung@kernel.org \
--cc=stable@vger.kernel.org \
--cc=zcliangcn@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.