Thread (53 messages) 53 messages, 8 authors, 2012-02-27

Re: [PATCH v10 07/11] signal, x86: add SIGSYS info and make it synchronous.

From: Roland McGrath <hidden>
Date: 2012-02-23 00:11:26
Also in: lkml, netdev

On Wed, Feb 22, 2012 at 3:38 PM, Andrew Lutomirski [off-list ref] wrote:
I wonder if it would be helpful to change the semantics of RET_KILL
slightly.  Rather than killing via do_exit, what if it killed via a
forcibly-fatal SIGSYS?  That way, the parent's waitid() / SIGCHLD
would indicate CLD_KILLED with si_status == SIGSYS.  The parent could
check that and report that the child was probably compromised.
That would be better.  But it is certainly a more complex code path, which
makes the security weenies twitch.  As to concrete issues, any "normal"
path needs the changes that are maybe pending from Oleg to make it actually
abort the syscall instead of completing it before getting to the signal path.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help