Thread (9 messages) 9 messages, 3 authors, 2014-05-30

Re: Pondering per-process vsyscall disablement

flat view

From: Andy Lutomirski <hidden>
Date: 2014-05-30 20:01:10
Also in: lkml

On Wed, May 28, 2014 at 2:45 PM, H. Peter Anvin [off-list ref] wrote:
On 05/23/2014 09:40 AM, Andy Lutomirski wrote:
quoted
I don't think this should be something configured by the
administrator, unless the administrator is the builder of a kiosky
thing like Chromium OS.  In that case, the administrator can use
vsyscall=none.

I think this should be handled by either libc or the toolchain, hence
the suggestions of a syscall or an ELF header.
We could mimic the NX stack stuff, but it would have a lot of false
negatives, simply because very few things would actually poke at the
vsyscall page.

The NX stuff uses a dummy program header in the ELF image.

On the other hand, you could make the argument that anything compiled
with a new toolchain simply should not use the vsyscall page, and just
unconditionally set the opt-out bit (header) in question.

It might be better to have some kind of flags field (which a number of
architectures use) than keep using dummy program headers, though.
Do the flags go in the ELF loader or in the executable we're running?
Or both (and, if both, do we and them or or them)?

I think the interpreter makes a little more sense in general: for the
most part, use of vsyscalls is a property of the runtime environment,
not of the program being run.  But maybe this is naive.

--Andy
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help