From: Clemens Ladisch <clemens@ladisch.de>
To: Prarit Bhargava <prarit@redhat.com>
Cc: linux-kernel@vger.kernel.org
Subject: Re: [PATCH] hpet, allow user controlled mmap for user processes
Date: Sat, 16 Mar 2013 10:54:57 +0100 [thread overview]
Message-ID: <51444171.1080905@ladisch.de> (raw)
In-Reply-To: <1363377610-19196-1-git-send-email-prarit@redhat.com>
Prarit Bhargava wrote:
> The CONFIG_HPET_MMAP Kconfig option exposes the memory map of the HPET
> registers to userspace. The Kconfig help points out that in some cases this
> can be a security risk as some systems may erroneously configure the map such
> that additional data is exposed to userspace.
I'm not aware of any such system (but cannot rule out the possibility).
> In an effort to mitigate this risk, and due to the low number of users
> of the MMAP functionality I've introduced a kernel parameter,
> hpet_mmap_enable, that is required in order to actually have the HPET
> MMAP exposed.
This introduces a regression for all users. At least make the default
state (allowed/forbidden) configurable.
Also, this patch makes the Kconfig help text a lie.
Regards,
Clemens
next prev parent reply other threads:[~2013-03-16 9:56 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
2013-03-15 20:00 [PATCH] hpet, allow user controlled mmap for user processes Prarit Bhargava
2013-03-16 9:54 ` Clemens Ladisch [this message]
2013-03-18 12:24 ` Prarit Bhargava
2013-03-19 7:43 ` Clemens Ladisch
2013-03-19 14:21 ` Prarit Bhargava
2013-03-19 14:51 ` Clemens Ladisch
2013-03-22 13:32 ` Prarit Bhargava
2013-08-29 6:01 ` Matt Wilson
2013-09-13 0:00 ` Prarit Bhargava
2013-09-29 20:28 ` [PATCH] hpet: " Clemens Ladisch
2013-03-19 14:49 ` [PATCH] hpet, " Prarit Bhargava
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=51444171.1080905@ladisch.de \
--to=clemens@ladisch.de \
--cc=linux-kernel@vger.kernel.org \
--cc=prarit@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.