public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
From: Solar Designer <solar@openwall.com>
To: "H. Peter Anvin" <hpa@zytor.com>
Cc: Andi Kleen <andi@firstfloor.org>,
	Vasiliy Kulikov <segoon@openwall.com>,
	Thomas Gleixner <tglx@linutronix.de>,
	Ingo Molnar <mingo@redhat.com>, James Morris <jmorris@namei.org>,
	kernel-hardening@lists.openwall.com, x86@kernel.org,
	linux-kernel@vger.kernel.org,
	linux-security-module@vger.kernel.org,
	Will Drewry <wad@chromium.org>
Subject: Re: [RFC] x86: restrict pid namespaces to 32 or 64 bit syscalls
Date: Tue, 16 Aug 2011 00:14:19 +0400	[thread overview]
Message-ID: <20110815201419.GA20296@openwall.com> (raw)
In-Reply-To: <4E496CAC.3030103@zytor.com>

On Mon, Aug 15, 2011 at 11:59:56AM -0700, H. Peter Anvin wrote:
> There is really no bloody difference between i386 vs x86-64 and, say,
> sys_oldstat versus sys_stat, or anything else along those lines.

There is a difference from a sysadmin standpoint: a sysadmin knows that
certain containers have Linux distro userlands for i386 and certain
others for x86-64, so he/she can configure things accordingly.  Even if
a customer using one of those containers installs extra software
packages, this extra software will work just fine as long as it's for
the same ABI.  The same doesn't hold true for sys_oldstat versus
sys_stat, etc.

> Putting in a bunch of ad hoc facilities because of semi-plausible
> performance wins rather than building a sane filtering facility which
> can be optimized as a single path is ridiculous.

I don't mind having a general filtering facility if it gets accepted
into the kernel (somehow Will's patch is not applied yet), and I don't
mind optimizing it to the point where it's not any slower for the "all
syscalls permitted but not all ABIs are" case.  I suspect that the
result of such optimizations will be similar to having these things
implemented separately, though - but I could be wrong.

So how do we proceed from here?  Start by getting Will's patch applied?

Alexander

  reply	other threads:[~2011-08-15 20:14 UTC|newest]

Thread overview: 25+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2011-08-12 15:03 [RFC] x86: restrict pid namespaces to 32 or 64 bit syscalls Vasiliy Kulikov
2011-08-12 20:08 ` H. Peter Anvin
2011-08-13  6:22   ` Vasiliy Kulikov
2011-08-13 15:41     ` H. Peter Anvin
2011-08-13 16:32       ` [kernel-hardening] " Vasiliy Kulikov
2011-08-14  9:09         ` Solar Designer
2011-08-18 14:40         ` [RFC v2] " Vasiliy Kulikov
2011-08-14  2:38       ` [RFC] " Andi Kleen
2011-08-14  5:08         ` H. Peter Anvin
2011-08-14  9:20           ` Solar Designer
2011-08-14 14:48             ` H. Peter Anvin
2011-08-14 15:27               ` Andi Kleen
2011-08-14 15:36                 ` H. Peter Anvin
2011-08-14 23:29                   ` James Morris
2011-08-15  0:18                   ` Andi Kleen
2011-08-15  0:32                     ` [kernel-hardening] " Will Drewry
2011-08-15  0:58                       ` Andi Kleen
2011-08-14 16:08                 ` Vasiliy Kulikov
2011-08-15 18:51               ` Solar Designer
2011-08-15 18:59                 ` H. Peter Anvin
2011-08-15 20:14                   ` Solar Designer [this message]
2011-08-15 20:27                     ` Andi Kleen
2011-08-15 20:48                     ` H. Peter Anvin
2011-08-15 22:13                     ` Eric Paris
2011-08-16  1:18                       ` Andi Kleen

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20110815201419.GA20296@openwall.com \
    --to=solar@openwall.com \
    --cc=andi@firstfloor.org \
    --cc=hpa@zytor.com \
    --cc=jmorris@namei.org \
    --cc=kernel-hardening@lists.openwall.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-security-module@vger.kernel.org \
    --cc=mingo@redhat.com \
    --cc=segoon@openwall.com \
    --cc=tglx@linutronix.de \
    --cc=wad@chromium.org \
    --cc=x86@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox