From: Muli Ben-Yehuda <mulix@actcom.co.il>
To: Greg KH <greg@kroah.com>
Cc: Linux-Kernel <linux-kernel@vger.kernel.org>
Subject: Re: export of sys_call_table
Date: Fri, 4 Oct 2002 07:53:29 +0300 [thread overview]
Message-ID: <20021004045329.GI15215@actcom.co.il> (raw)
In-Reply-To: <20021004044652.GA3556@kroah.com>
[-- Attachment #1: Type: text/plain, Size: 1864 bytes --]
On Thu, Oct 03, 2002 at 09:46:53PM -0700, Greg KH wrote:
> On Fri, Oct 04, 2002 at 07:05:03AM +0300, Muli Ben-Yehuda wrote:
> >
> > http://marc.theaimsgroup.com/?l=kernelnewbies&m=102267164910800&w=2,
>
> You didn't read my post to that same thread did you:
>
> http://marc.theaimsgroup.com/?l=kernelnewbies&m=102130770415962
I did, and considered using LSM, but decided not to since, as you
mention below, it doesn't give me the capabilities I need.
> And for the most part, the people on kernelnewbies have given up on
> trying to explain to new people why this does not work. I know I sure
> have :)
As I've written, I maintain that it does work on *some* archs (atomic
pointer updates are required) and with certain precautions (no module
unload).
> > http://marc.theaimsgroup.com/?l=linux-kernel&m=101821127019203&w=2
> >
> > [2] Can the LSM hooks be used for notification and modification on
> > every system call's entry and exit?
>
> No. See the LSM mailing list archives for why we did not decide to do
> this. (hint, you don't really achieve what you want to by doing
> this.)
Well, since I want to hook every system call, I get exactly what I
want ;-)
I'm not doing access policies or security. I'm doing "who is deleting
my file?" and "who is calling settimeoday on my router once in a blue
moon.", and even "if process foo calls getpid(), tell it's actually
process bar".
> If you _really_ want to hook things like this, look at LTT or dprobes.
> They should work just fine for you.
Neither is in the core kernel (AFAIK), and I'm not sure how useful
they are for a module only solution. I'll take a look, though.
Thanks,
Muli.
--
Muli Ben-Yehuda http://www.mulix.org/
mulix@mulix.org:~$ sctrace strace /bin/foo http://syscalltrack.sf.net/
Quis custodes ipsos custodiet?
[-- Attachment #2: Type: application/pgp-signature, Size: 189 bytes --]
next prev parent reply other threads:[~2002-10-04 4:49 UTC|newest]
Thread overview: 60+ messages / expand[flat|nested] mbox.gz Atom feed top
2002-10-03 21:39 export of sys_call_table Brian F. G. Bidulock
2002-10-03 22:02 ` Alan Cox
2002-10-03 23:06 ` Brian F. G. Bidulock
2002-10-04 9:10 ` Arjan van de Ven
2002-10-04 11:19 ` Brian F. G. Bidulock
2002-10-04 11:31 ` Arjan van de Ven
2002-10-04 11:55 ` Brian F. G. Bidulock
2002-10-04 13:00 ` Alan Cox
2002-10-03 23:10 ` Michal Jaegermann
2002-10-04 0:32 ` Andy Pfiffer
2002-10-04 9:20 ` Arjan van de Ven
2002-10-06 14:17 ` Kasper Dupont
2003-01-03 8:28 ` Eric W. Biederman
2002-10-04 21:06 ` David S. Miller
2002-10-04 21:44 ` Brian F. G. Bidulock
2002-10-12 5:43 ` Eric Blade
2002-10-03 22:14 ` Robert Love
2002-10-03 22:23 ` Robert Love
2002-10-03 22:24 ` Patrick Mochel
2002-10-03 22:15 ` Greg KH
2002-10-03 22:27 ` Dave Jones
2002-10-03 22:27 ` Robert Love
2002-10-03 22:58 ` John Levon
2002-10-03 23:10 ` Alexander Viro
2002-10-03 23:14 ` John Levon
2002-10-04 4:05 ` Muli Ben-Yehuda
2002-10-04 4:46 ` Greg KH
2002-10-04 4:53 ` Muli Ben-Yehuda [this message]
2002-10-03 23:35 ` Dave Jones
2002-10-03 23:50 ` John Levon
2002-10-04 0:17 ` Brian F. G. Bidulock
[not found] ` <mailman.1033691043.6446.linux-kernel2news@redhat.com>
2002-10-04 4:03 ` Pete Zaitcev
2002-10-04 5:32 ` Brian F. G. Bidulock
2002-10-04 11:42 ` John Levon
2002-10-04 12:03 ` Brian F. G. Bidulock
2002-10-04 13:02 ` Alan Cox
2002-10-04 17:36 ` Pete Zaitcev
2002-10-05 1:39 ` John Levon
2002-10-04 13:58 ` Christoph Hellwig
2002-10-04 15:15 ` Brian F. G. Bidulock
2002-10-04 15:28 ` Christoph Hellwig
2002-10-04 16:19 ` Brian F. G. Bidulock
2002-10-04 16:25 ` Christoph Hellwig
[not found] <20021003153943.E22418@openss7.org.suse.lists.linux.kernel>
[not found] ` <1033682560.28850.32.camel@irongate.swansea.linux.org.uk.suse.lists.linux.kernel>
[not found] ` <20021003170608.A30759@openss7.org.suse.lists.linux.kernel>
[not found] ` <1033722612.1853.1.camel@localhost.localdomain.suse.lists.linux.kernel>
[not found] ` <20021004051932.A13743@openss7.org.suse.lists.linux.kernel>
2002-10-04 13:01 ` Andi Kleen
2002-10-04 13:11 ` Brian F. G. Bidulock
2002-10-04 13:15 ` Andi Kleen
2002-10-04 13:22 ` Brian F. G. Bidulock
2002-10-04 14:11 ` Andi Kleen
2002-10-04 14:31 ` Brian F. G. Bidulock
[not found] ` <20021003221525.GA2221@kroah.com.suse.lists.linux.kernel>
[not found] ` <20021003222716.GB14919@suse.de.suse.lists.linux.kernel>
[not found] ` <1033684027.1247.43.camel@phantasy.suse.lists.linux.kernel>
[not found] ` <20021003233504.GA20570@suse.de.suse.lists.linux.kernel>
[not found] ` <20021003235022.GA82187@compsoc.man.ac.uk.suse.lists.linux.kernel>
[not found] ` <mailman.1033691043.6446.linux-kernel2news@redhat.com.suse.lists.linux.kernel>
[not found] ` <200210040403.g9443Vu03329@devserv.devel.redhat.com.suse.lists.linux.kernel>
[not found] ` <20021003233221.C31444@openss7.org.suse.lists.linux.kernel>
[not found] ` <20021004133657.B17216@devserv.devel.redhat.com.suse.lists.linux.kernel>
2002-10-04 18:14 ` Andi Kleen
2002-10-04 18:46 ` Alan Cox
2002-10-04 18:45 ` Alexander Viro
2002-10-04 19:15 ` Brian F. G. Bidulock
2002-10-04 19:26 ` Andi Kleen
2002-10-04 19:37 ` Pete Zaitcev
2002-10-04 19:43 ` Robert Love
2002-10-04 22:21 ` David S. Miller
2002-10-04 22:41 ` Brian F. G. Bidulock
2002-10-04 22:38 ` David S. Miller
-- strict thread matches above, loose matches on Subject: below --
2002-10-04 21:54 Mark Veltzer
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20021004045329.GI15215@actcom.co.il \
--to=mulix@actcom.co.il \
--cc=greg@kroah.com \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.