From: "Philippe Elie" <phil.el@wanadoo.fr>
To: "Bill Davidsen" <davidsen@tmr.com>,
"John Levon" <movement@marcelothewonderpenguin.com>
Cc: "Linux Kernel Mailing List" <linux-kernel@vger.kernel.org>
Subject: Re: Two fixes for 2.4.19-pre5-ac3
Date: Mon, 8 Apr 2002 18:06:18 +0200 [thread overview]
Message-ID: <00a801c1df17$55295ae0$95dc0e50@machine1> (raw)
In-Reply-To: <Pine.LNX.3.96.1020408104259.21476B-100000@gatekeeper.tmr.com>
From: "Bill Davidsen" <davidsen@tmr.com>
Sent: Monday, April 08, 2002 4:48 PM
> On Sun, 7 Apr 2002, John Levon wrote:
>
> > But what about the recent discussion on the removal of sys_call_table ?
> >
> > (I believe it was along the lines of "it's ugly, prevent it ...", "ah,
> > but it has real uses, so why can't it stay as deprecated/unadvised ?"
> > "*no response*").
> >
> > I'm a bit disappointed this has just gone in without any real discussion
> > on the usefulness of this for certain circumstances :(
>
> Sure, removing that would break a lot of cracker software. Oh wait,
> maybe that's a good thing...
It's really easy for cracker to patch sys_call even if it the table is not
exported. Not exporting the sys call table is just to encourage good
programming technics not a protection against machiavel things.
> For legitimate use, if any, a compile-time optional system call could be
> added requiring a capability to use, and programs which are currently
> doing that (AFS?) can be converted to use another f/s interface. I have
> seen a few mentions of software which DO use that capability, I'm not sure
> I've seen one which can be done no other way.
As stated oprofile needs it, there is no other efficient way to track exec,
mmap and other sys call needed for profiler. I hope a consensus can
be reach : explain than unloading module wich patch the sys call table
are unsafe on SMP, discourage the use of sys call table patch, but do
not forbid that.
--
Philippe Elie
next prev parent reply other threads:[~2002-04-08 16:06 UTC|newest]
Thread overview: 33+ messages / expand[flat|nested] mbox.gz Atom feed top
2002-04-07 16:43 Two fixes for 2.4.19-pre5-ac3 Steven N. Hirsch
2002-04-07 17:11 ` Christoph Hellwig
2002-04-07 17:14 ` arjan
2002-04-07 17:42 ` Alan Cox
2002-04-07 17:27 ` arjan
2002-04-07 17:48 ` Alexander Viro
2002-04-07 17:33 ` John Levon
2002-04-07 19:18 ` Alan Cox
2002-04-07 19:23 ` John Levon
2002-04-07 19:42 ` Alan Cox
2002-04-07 19:32 ` John Levon
2002-04-07 19:58 ` Alan Cox
2002-04-07 19:40 ` Jan Harkes
2002-04-07 20:01 ` Alan Cox
2002-04-07 20:13 ` Jan Harkes
2002-04-07 19:49 ` Alan Cox
2002-04-07 19:41 ` John Levon
2002-04-07 19:55 ` Muli Ben-Yehuda
2002-04-07 20:29 ` Alan Cox
2002-04-07 20:23 ` Muli Ben-Yehuda
2002-04-07 20:51 ` Alan Cox
2002-04-07 23:03 ` Anton Altaparmakov
2002-04-08 6:27 ` Muli Ben-Yehuda
2002-04-07 20:02 ` Alan Cox
2002-04-07 20:10 ` Eric W. Biederman
2002-04-07 23:06 ` John Levon
2002-04-07 19:44 ` Steven N. Hirsch
2002-04-08 14:48 ` Bill Davidsen
2002-04-08 16:06 ` Philippe Elie [this message]
2002-04-08 17:53 ` Eric W. Biederman
2002-04-08 18:07 ` John Levon
2002-04-07 23:31 ` Erik Tews
[not found] <20020407193245.GA21570@compsoc.man.ac.uk.suse.lists.linux.kernel>
[not found] ` <E16uIoN-0006b3-00@the-village.bc.nu.suse.lists.linux.kernel>
2002-04-07 21:34 ` Andi Kleen
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to='00a801c1df17$55295ae0$95dc0e50@machine1' \
--to=phil.el@wanadoo.fr \
--cc=davidsen@tmr.com \
--cc=linux-kernel@vger.kernel.org \
--cc=movement@marcelothewonderpenguin.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox