From: Muli Ben-Yehuda <mulix@actcom.co.il>
To: Greg KH <greg@kroah.com>
Cc: Linux-Kernel <linux-kernel@vger.kernel.org>
Subject: Re: export of sys_call_table
Date: Fri, 4 Oct 2002 07:53:29 +0300 [thread overview]
Message-ID: <20021004045329.GI15215@actcom.co.il> (raw)
In-Reply-To: <20021004044652.GA3556@kroah.com>
[-- Attachment #1: Type: text/plain, Size: 1864 bytes --]
On Thu, Oct 03, 2002 at 09:46:53PM -0700, Greg KH wrote:
> On Fri, Oct 04, 2002 at 07:05:03AM +0300, Muli Ben-Yehuda wrote:
> >
> > http://marc.theaimsgroup.com/?l=kernelnewbies&m=102267164910800&w=2,
>
> You didn't read my post to that same thread did you:
>
> http://marc.theaimsgroup.com/?l=kernelnewbies&m=102130770415962
I did, and considered using LSM, but decided not to since, as you
mention below, it doesn't give me the capabilities I need.
> And for the most part, the people on kernelnewbies have given up on
> trying to explain to new people why this does not work. I know I sure
> have :)
As I've written, I maintain that it does work on *some* archs (atomic
pointer updates are required) and with certain precautions (no module
unload).
> > http://marc.theaimsgroup.com/?l=linux-kernel&m=101821127019203&w=2
> >
> > [2] Can the LSM hooks be used for notification and modification on
> > every system call's entry and exit?
>
> No. See the LSM mailing list archives for why we did not decide to do
> this. (hint, you don't really achieve what you want to by doing
> this.)
Well, since I want to hook every system call, I get exactly what I
want ;-)
I'm not doing access policies or security. I'm doing "who is deleting
my file?" and "who is calling settimeoday on my router once in a blue
moon.", and even "if process foo calls getpid(), tell it's actually
process bar".
> If you _really_ want to hook things like this, look at LTT or dprobes.
> They should work just fine for you.
Neither is in the core kernel (AFAIK), and I'm not sure how useful
they are for a module only solution. I'll take a look, though.
Thanks,
Muli.
--
Muli Ben-Yehuda http://www.mulix.org/
mulix@mulix.org:~$ sctrace strace /bin/foo http://syscalltrack.sf.net/
Quis custodes ipsos custodiet?
[-- Attachment #2: Type: application/pgp-signature, Size: 189 bytes --]
next prev parent reply other threads:[~2002-10-04 4:49 UTC|newest]
Thread overview: 60+ messages / expand[flat|nested] mbox.gz Atom feed top
2002-10-03 21:39 export of sys_call_table Brian F. G. Bidulock
2002-10-03 22:02 ` Alan Cox
2002-10-03 23:06 ` Brian F. G. Bidulock
2002-10-04 9:10 ` Arjan van de Ven
2002-10-04 11:19 ` Brian F. G. Bidulock
2002-10-04 11:31 ` Arjan van de Ven
2002-10-04 11:55 ` Brian F. G. Bidulock
2002-10-04 13:00 ` Alan Cox
2002-10-03 23:10 ` Michal Jaegermann
2002-10-04 0:32 ` Andy Pfiffer
2002-10-04 9:20 ` Arjan van de Ven
2002-10-06 14:17 ` Kasper Dupont
2003-01-03 8:28 ` Eric W. Biederman
2002-10-04 21:06 ` David S. Miller
2002-10-04 21:44 ` Brian F. G. Bidulock
2002-10-12 5:43 ` Eric Blade
2002-10-03 22:14 ` Robert Love
2002-10-03 22:23 ` Robert Love
2002-10-03 22:24 ` Patrick Mochel
2002-10-03 22:15 ` Greg KH
2002-10-03 22:27 ` Dave Jones
2002-10-03 22:27 ` Robert Love
2002-10-03 22:58 ` John Levon
2002-10-03 23:10 ` Alexander Viro
2002-10-03 23:14 ` John Levon
2002-10-04 4:05 ` Muli Ben-Yehuda
2002-10-04 4:46 ` Greg KH
2002-10-04 4:53 ` Muli Ben-Yehuda [this message]
2002-10-03 23:35 ` Dave Jones
2002-10-03 23:50 ` John Levon
2002-10-04 0:17 ` Brian F. G. Bidulock
[not found] ` <mailman.1033691043.6446.linux-kernel2news@redhat.com>
2002-10-04 4:03 ` Pete Zaitcev
2002-10-04 5:32 ` Brian F. G. Bidulock
2002-10-04 11:42 ` John Levon
2002-10-04 12:03 ` Brian F. G. Bidulock
2002-10-04 13:02 ` Alan Cox
2002-10-04 17:36 ` Pete Zaitcev
2002-10-05 1:39 ` John Levon
2002-10-04 13:58 ` Christoph Hellwig
2002-10-04 15:15 ` Brian F. G. Bidulock
2002-10-04 15:28 ` Christoph Hellwig
2002-10-04 16:19 ` Brian F. G. Bidulock
2002-10-04 16:25 ` Christoph Hellwig
[not found] <20021003153943.E22418@openss7.org.suse.lists.linux.kernel>
[not found] ` <1033682560.28850.32.camel@irongate.swansea.linux.org.uk.suse.lists.linux.kernel>
[not found] ` <20021003170608.A30759@openss7.org.suse.lists.linux.kernel>
[not found] ` <1033722612.1853.1.camel@localhost.localdomain.suse.lists.linux.kernel>
[not found] ` <20021004051932.A13743@openss7.org.suse.lists.linux.kernel>
2002-10-04 13:01 ` Andi Kleen
2002-10-04 13:11 ` Brian F. G. Bidulock
2002-10-04 13:15 ` Andi Kleen
2002-10-04 13:22 ` Brian F. G. Bidulock
2002-10-04 14:11 ` Andi Kleen
2002-10-04 14:31 ` Brian F. G. Bidulock
[not found] ` <20021003221525.GA2221@kroah.com.suse.lists.linux.kernel>
[not found] ` <20021003222716.GB14919@suse.de.suse.lists.linux.kernel>
[not found] ` <1033684027.1247.43.camel@phantasy.suse.lists.linux.kernel>
[not found] ` <20021003233504.GA20570@suse.de.suse.lists.linux.kernel>
[not found] ` <20021003235022.GA82187@compsoc.man.ac.uk.suse.lists.linux.kernel>
[not found] ` <mailman.1033691043.6446.linux-kernel2news@redhat.com.suse.lists.linux.kernel>
[not found] ` <200210040403.g9443Vu03329@devserv.devel.redhat.com.suse.lists.linux.kernel>
[not found] ` <20021003233221.C31444@openss7.org.suse.lists.linux.kernel>
[not found] ` <20021004133657.B17216@devserv.devel.redhat.com.suse.lists.linux.kernel>
2002-10-04 18:14 ` Andi Kleen
2002-10-04 18:46 ` Alan Cox
2002-10-04 18:45 ` Alexander Viro
2002-10-04 19:15 ` Brian F. G. Bidulock
2002-10-04 19:26 ` Andi Kleen
2002-10-04 19:37 ` Pete Zaitcev
2002-10-04 19:43 ` Robert Love
2002-10-04 22:21 ` David S. Miller
2002-10-04 22:41 ` Brian F. G. Bidulock
2002-10-04 22:38 ` David S. Miller
-- strict thread matches above, loose matches on Subject: below --
2002-10-04 21:54 Mark Veltzer
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20021004045329.GI15215@actcom.co.il \
--to=mulix@actcom.co.il \
--cc=greg@kroah.com \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox