On 02/16/2012 01:28 PM, Markus Gutschke wrote:
I think, the documentation said that as soon as prctl() is used to set
a bpf filter for system calls, it automatically disallows system calls
using an entry point other than the one used by this particular
prctl().
I was trying to come up with scenarios where this particular approach
causes problem, but I can't think of any off the top of my head. So,
it might actually turn out to be a very elegant way to reduce the
attack surface of the kernel. If we are really worried about userspace
compatibility, we could make the kernel send a signal instead of
terminating the program, if the wrong entry point was used; not sure
if that is needed, though.
Let's see... we're building an entire pattern-matching engine and then
randomly disallowing its use because we didn't build in the right bits?
Sorry, that's asinine.
Put the bloody bit in there and let the pattern program make that decision.
-hpa
--
H. Peter Anvin, Intel Open Source Technology Center
I work for Intel. I don't speak on their behalf.