From: Pavel Machek <pavel@suse.cz>
To: Jesse Pollard <pollard@tomcat.admin.navo.hpc.mil>,
root@mauve.demon.co.uk, linux-kernel@vger.kernel.org
Subject: swsusp [was Re: Switching Kernels without Rebooting?]
Date: Fri, 13 Jul 2001 01:21:05 +0200 [thread overview]
Message-ID: <20010713012105.B122@bug.ucw.cz> (raw)
In-Reply-To: <200107121211.NAA10270@mauve.demon.co.uk> <200107121254.HAA89768@tomcat.admin.navo.hpc.mil> <20010712101513.A439@alcove.wittsend.com>
In-Reply-To: <20010712101513.A439@alcove.wittsend.com>; from Michael H. Warfield on Thu, Jul 12, 2001 at 10:15:13AM -0400
Hi!
> > That sounds more like a memory dump to disk, and reload after power restored.
> > Either that or possibly a separate power supply for RAM (something like a
> > trickle discharge capacitor; I've read that some capacitors can hold a charge
> > for about 3 days. Whether that would work for a large RAM or not, I have no
> > idea).
>
> It's a suspend to disk. Lots of Laptops can do it and my Toshiba
> Tecra 8100 can do it from the BIOS if I have a magic Windows partition with
> an appropriate suspend file in it (which would be unencrypted, which would
> be unacceptable - so I had to look for a Linux solution for the suspend
> to disk problem).
>
> Check out the swsusp project up at Source Forge
> <http://sourceforge.net/projects/swsusp/>. It allows me to suspend
> into the swap space by hitting Alt-SysRQ-D. Great for changing
> batteries on laptops (and, no, normal suspend does not survive a battery
> change) but also REALLY GREAT for forensic security analysis of compromised
> systems. I hit the console of a compromised system and hit Alt-SysRq-D
> and it flushs the dirty buffers, dumps memory to swap (preserving all
> my "volatiles") and the shuts down. I can snapshot the hard drive and
> then restart the system where it left off for live running analysis. If
> that gets screwed up, I can restore the image again and restart again from
> the same spot again. I've also got all the memory and CPU state in that
> disk image for "in-vitro" analysis by tools like Weitse's "The Coroner's
> Toolkit".
>
> But that doesn't solve ANY of the problems with changing the kernel
> itself. Suspending and restoring the system is the easy part (and swsusp
> still has some problems restoring X Windows). Restoring a system to
> a different kernel is orders of magnitude worse, if not down right
> impossible for all the reasons given over internal structures and
> interfaces.
>
> I would LOVE to have something like swsusp in the main line kernel,
> however, just so I didn't have to convince IT departments to apply this
> custom kernel patch to their production systems BEFORE they get their butts
> kicked by some snott nosed script kiddie. :-/
Patience. swsusp is needed for ACPI S4 support. And I guess ACPI S4 is
good enough reason to push it to Linus.
Pavel
--
I'm pavel@ucw.cz. "In my country we have almost anarchy and I don't care."
Panos Katsaloulis describing me w.r.t. patents at discuss@linmodems.org
next prev parent reply other threads:[~2001-07-13 20:37 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2001-07-12 1:03 Switching Kernels without Rebooting? Torrey Hoffman
2001-07-12 1:24 ` C. Slater
2001-07-12 10:07 ` Jesse Pollard
2001-07-12 12:11 ` Ian Stirling
2001-07-12 12:54 ` Jesse Pollard
2001-07-12 14:15 ` Michael H. Warfield
2001-07-12 23:21 ` Pavel Machek [this message]
2001-07-12 23:17 ` Pavel Machek
2001-07-12 20:47 ` Wilfried Weissmann
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20010713012105.B122@bug.ucw.cz \
--to=pavel@suse.cz \
--cc=linux-kernel@vger.kernel.org \
--cc=pollard@tomcat.admin.navo.hpc.mil \
--cc=root@mauve.demon.co.uk \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.