From: Andrew Morton <akpm@osdl.org>
To: andrea@cpushare.com
Cc: linux-kernel@vger.kernel.org
Subject: Re: secure computing for 2.6.7
Date: Sun, 4 Jul 2004 14:35:26 -0700 [thread overview]
Message-ID: <20040704143526.62d00790.akpm@osdl.org> (raw)
In-Reply-To: <20040704173903.GE7281@dualathlon.random>
andrea@cpushare.com wrote:
>
> I need this new kernel feature for a reseach spare time project I'm
> developing in the weekends. The fast path cost is basically only the
> s/testb/testw/ change in entry.S. (and even that might be removed with a
> more signficant effort but I don't think anybody could worry about that
> change).
>
> This might be better off for 2.7 but I would like if people could have a
> look, and it's simple enough that it might be included in 2.6 too later
> on. (it just need to be ported to the other archs, only x86 is
> implemented here, but that's easy)
>
> Especially I would like to know if anybody can see an hole in this. This
> is an order of magnitude more secure of chroot and of capabilities and
> much simpler and it doesn't require root privilegies to activate. I
> wasn't forced to take secure computing down into kernel space but I
> believe it's the simplest and most secure and most efficient approch. An
> userspace alternative would been to elaborate this below bytecode
> userspace approch but besides being an order of magnitude slower it also
> is a lot more complicated and less secure, and it keeps into the
> equation the virtual machine that executes the code later on:
>
> http://aspn.activestate.com/ASPN/Cookbook/Python/Recipe/286134
I'm not sure what to say about this, really.
Of course, yes, the patch is sufficiently safe and simple for it to be
mergeable in 2.6, if this is the way we want to do secure computing. I'd
wonder whether the API should be syscall-based rather than /proc-based, and
whether there should be a config option for it.
But the wider questions are stuff like "where is all this coming from",
"where will it all end up" and "what are the alternatives".
next prev parent reply other threads:[~2004-07-04 21:36 UTC|newest]
Thread overview: 42+ messages / expand[flat|nested] mbox.gz Atom feed top
2004-07-04 17:39 secure computing for 2.6.7 andrea
2004-07-04 21:35 ` Andrew Morton [this message]
2004-07-04 23:32 ` andrea
2004-07-05 0:37 ` Phy Prabab
2004-10-12 14:24 ` Andrea Arcangeli
2004-10-12 15:32 ` Rik van Riel
2004-10-12 15:59 ` Andrea Arcangeli
2004-10-12 16:28 ` Rik van Riel
2004-10-12 17:46 ` Andrea Arcangeli
2004-10-12 18:04 ` Rik van Riel
2004-10-12 18:10 ` Rik van Riel
2004-10-12 18:29 ` Andrea Arcangeli
2004-07-07 19:27 ` Hans Reiser
2004-08-01 10:22 ` Andrea Arcangeli
2004-08-01 12:01 ` chris
2004-08-01 15:01 ` Andrea Arcangeli
2004-08-01 17:29 ` chris
2004-08-01 18:52 ` Bernd Eckenfels
2004-08-01 20:45 ` Alan Cox
2004-08-01 23:10 ` Andrea Arcangeli
2004-08-01 23:08 ` Alan Cox
2004-08-02 10:25 ` Andrea Arcangeli
2004-08-01 23:06 ` Andrea Arcangeli
2004-08-02 6:52 ` David Wagner
2004-08-03 12:48 ` Stephen Smalley
2004-08-01 14:55 ` Bernd Eckenfels
2004-08-01 15:51 ` Andrea Arcangeli
2004-08-01 17:24 ` Bernd Eckenfels
2004-08-02 3:17 ` Horst von Brand
2004-08-02 16:31 ` Andrea Arcangeli
2004-08-03 12:40 ` Stephen Smalley
2004-08-03 21:02 ` Alexander Lyamin
2004-08-05 11:47 ` Stephen Smalley
2004-08-04 8:57 ` Hans Reiser
2004-08-05 11:48 ` Stephen Smalley
2004-08-07 23:20 ` Hans Reiser
2004-08-09 12:35 ` Stephen Smalley
[not found] <2ejhQ-4lc-5@gated-at.bofh.it>
[not found] ` <2fqhq-1RU-45@gated-at.bofh.it>
[not found] ` <2olLt-4wI-5@gated-at.bofh.it>
2004-08-02 0:05 ` Andi Kleen
2004-08-02 10:19 ` Andrea Arcangeli
2004-08-02 19:06 ` Rik van Riel
2004-08-02 21:35 ` Andrea Arcangeli
2004-08-04 13:18 ` V13
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20040704143526.62d00790.akpm@osdl.org \
--to=akpm@osdl.org \
--cc=andrea@cpushare.com \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.